On September 21, 2026, Tomás Niembro Concha, the former CEO of Nodus International Bank, a Puerto Rican international bank, was sentenced to 112 months in federal prison and three years of supervised release. He was ordered to forfeit over $16.9 million. Niembro had pleaded guilty in March 2026 to two counts: conspiracy to commit wire fraud and conspiracy to violate the International Emergency Economic Powers Act (IEEPA).
The case involves two distinct schemes. The first was a multi-year internal fraud that ultimately caused Nodus Bank to fail. The second was a Venezuela sanctions evasion scheme with a detail that deserves careful attention from any compliance professional: Niembro obtained legitimate OFAC authorization for part of a transaction with a sanctioned individual, then ran a separate prohibited deal alongside it that OFAC never saw.
The Wire Fraud: Using the Bank as a Personal ATM
According to court filings, from 2017 to 2023 Niembro conspired with others, including Nodus Bank's Board Chairman Juan Ramirez, to siphon funds from the bank for their own benefit. Two mechanisms were used.
The first involved causing Nodus Bank to invest $11 million in a Miami-based lender so that those funds could then be loaned back to Niembro and Ramirez personally. The second involved inducing the bank's board and comptroller to purchase at least 47 promissory notes totaling approximately $25.3 million from Nodus Finance, a Miami-based company that Niembro and Ramirez jointly owned, so they could use the proceeds for themselves.
Both schemes relied on concealment. According to the DOJ, Niembro and his co-conspirators hid from other board members, executives, and OCIF (the Office of the Commissioner of Financial Institutions of Puerto Rico, which regulated the bank) that these investments and loans were in fact benefiting Niembro and Ramirez personally, in violation of Puerto Rican law. When OCIF notified the bank in early March 2023 that it would be placed into liquidation, Niembro and Ramirez fraudulently caused Nodus Bank to accept a loan portfolio from Nodus Finance to pay down the debt from the promissory notes before the bank closed.
"The defendant abused his position as CEO, turning the bank he managed into his own personal ATM and unlawfully transacting with a sanctioned individual. The defendant's crimes undermine the integrity of our financial system, threaten economic prosperity, and harm national security."
Assistant Attorney General A. Tysen Duva, DOJ Criminal Division, March 2026
The Sanctions Evasion: Using an OFAC License as Cover
The second scheme is the more instructive of the two for compliance professionals. Between 2021 and 2023, Niembro conspired with a Specially Designated National who had been designated by OFAC for providing material support to Venezuela's state-owned oil company, PDVSA.
The SDN's company had an outstanding loan of approximately $2.5 million with Nodus Bank that predated the sanctions designation. Niembro and the SDN devised a scheme to resolve that loan through two parallel tracks: one disclosed to OFAC, one not.
The Disclosed Track
Niembro and the SDN sought and obtained OFAC authorization for Nodus Bank to foreclose on the SDN's home in Southampton, New York. That authorization was legitimate. OFAC reviewed it and issued a license.
The Hidden Track
Separately, and without disclosing this to OFAC, Niembro and the SDN reached a private agreement for Nodus Bank to sell the property back to the SDN through a front company for $4 million. That transaction was strictly prohibited by US sanctions and was not licensed by OFAC. According to the DOJ, the OFAC-authorized foreclosure was used as cover for the prohibited sell-back.
This structure is particularly significant from a compliance standpoint. The foreclosure by itself was lawful and authorized. The simultaneous private agreement to reverse that transaction through a front company was not. Compliance controls that evaluate OFAC-authorized transactions in isolation, without assessing whether parallel private agreements exist that alter the ultimate economic outcome, would not catch this scheme.
Three Compliance Lessons the Case Illustrates
An OFAC authorization covers the transaction it licenses, not parallel agreements that alter the economic outcome.
The Nodus Bank case introduces a sanctions evasion structure that compliance programs rarely account for: obtaining a legitimate OFAC license for one component of a transaction while running a separate prohibited transaction alongside it. The OFAC license for the foreclosure was real. The private agreement to sell the property back to the SDN through a front company was not licensed and was strictly prohibited. Consequently, a compliance review that begins and ends with confirming the existence of an OFAC authorization is insufficient for transactions involving SDNs. The full economic picture of the transaction, including any private agreements that reverse or redirect the authorized outcome, requires scrutiny.
When the CEO is the insider threat, board oversight and regulatory reporting are the only compensating controls.
Niembro set the compliance culture at Nodus Bank. He also ran the fraud. The concealment worked for years because the person responsible for ensuring compliance with Puerto Rican banking law was the person directing violations of it. Furthermore, this case connects directly to recent enforcement actions involving insider threats at TD Bank and the Venetian, where front-line employees ignored or suppressed suspicious activity. At the CEO level, the consequences are existential: Nodus Bank no longer exists. The controls that exist for exactly this scenario are independent board oversight, regulator-direct reporting channels that bypass the CEO, and external audit functions that are not answerable to management.
Transactions with customers who become SDNs after account opening require ongoing monitoring of the full loan and asset relationship.
The SDN's $2.5 million loan predated the sanctions designation. After designation, any transaction with that customer or their connected entities became subject to OFAC restrictions. The scheme that Niembro and the SDN constructed was specifically designed to resolve that pre-existing loan relationship in a way that generated economic benefit for the SDN without OFAC's knowledge. For financial institutions with existing customer relationships that include loans, property interests, or other asset-backed arrangements, sanctions designation of a customer is not the end of the compliance issue. It is the beginning of a process to evaluate every element of that relationship for prohibited exposures, with documentation adequate to withstand OFAC scrutiny.
Frequently Asked Questions
What did the Nodus Bank CEO do?
What is IEEPA and how was it violated in the Nodus Bank case?
What is Nodus International Bank and what happened to it?
What does it mean to use an OFAC license as cover for a prohibited transaction?
What is Venezuela's PDVSA and why does it appear in US sanctions?
The Sentinel Perspective
The Nodus Bank case sits at the intersection of two compliance risk categories that Sentinel addresses directly: sanctions screening for existing customer relationships and the ongoing monitoring required when a customer's sanctions status changes.
The SDN relationship in this case predated the sanctions designation. After the SDN was added to OFAC's list, the institution was required to manage all existing transactions and asset relationships in compliance with sanctions requirements. The scheme Niembro constructed exploited the gap between what OFAC authorized and what was happening in a private agreement that ran alongside the authorized transaction.
Sentinel's continuous customer monitoring platform generates alerts when a customer's designation status changes, ensuring that existing loan, asset, and financial relationships are reviewed against current sanctions requirements rather than only against the status at onboarding. For financial institutions managing complex customer relationships including loans, property interests, and multi-party arrangements, that continuous layer is specifically designed for the risk category this case describes.
See How Sentinel Supports OFAC Sanctions Screening and Ongoing Customer Monitoring
Request a demonstration tailored to your institution's sanctions compliance program and existing customer risk management requirements.
Official References
- Former Bank CEO Sentenced to Over 9 Years in Prison for Multimillion-Dollar Wire Fraud Conspiracy and Venezuela Sanctions Evasion Scheme | US Department of Justice, September 21, 2026
- Former Bank CEO Pleads Guilty to Multimillion-Dollar Wire Fraud Conspiracy and Venezuela Sanctions Evasion Scheme | US Department of Justice, March 20, 2026
Truth Technologies provides AML, KYC, OFAC, and sanctions screening compliance solutions through the Sentinel platform. This post is published for informational purposes only and does not constitute legal advice. All facts are sourced exclusively from the official DOJ press releases linked above. No additional facts have been inferred or supplemented from any other source.