An Ethicast Reacts feature
September put two kinds of pressure on compliance programs at once. In Washington, the SEC’s shareholder-proposal rule and its pay-to-play restrictions on investment advisers proposed to take rules off the books. Meawhile, Treasury and the Justice Department maintained a steady run of sanctions actions and False Claims Act settlements. In Europe, obligations that sat on compliance calendars for years went live in a span of 16 days.
On the enforcement front, Abbott Laboratories agreed to pay nearly $385 million to resolve allegations tied to infant formula manufacturing that speak directly to compliance officers: tests that weren’t run, results that weren’t shared with inspectors, and employees who eventually took their concerns to court.
Below, we cover the developments that matter most for ethics and compliance teams, benchmark them against what World’s Most Ethical Companies® Honorees do, and collect everything else from September in one table.
Iran Sanctions Now Start from ‘No’
Treasury’s Operation Economic Outcast set the pace all month. On Sept. 10, OFAC changed its Iran-related specific licensing policy so that applications are now evaluated with a presumption of denial. The exceptions are limited to what the law requires and narrow circumstances such as risk to life, limb, or environmental safety. Any business plan that assumes a license will eventually come through needs to be re-tested now.
The designations arrived in waves. In early September, OFAC blocked Türkiye-based Golden Global Bank and two subsidiaries for giving the IRGC-Qods Force correspondent banking access to move Iranian oil revenue. On Sept. 8, it designated 36 targets across Iran’s aviation sector, including more than two dozen commercial and private airlines and several foreign cargo providers. OFAC also sanctioned BitBank and affiliated entities for moving Bitcoin to the IRGC.
The Sept. 14 designation of Russia’s VTB Bank under Iran authorities deserves special attention. VTB was already blocked under Russia programs, so the new listing is Treasury’s way of telling foreign financial institutions that are still dealing with VTB to cut those relationships immediately. That warning reaches banks in your payment chain that you may never screen directly.
Enforcement reached individuals, too. A U.S. person paid $1,427,230 to settle 39 apparent violations for providing management consulting to an Iranian software company over 19 virtual meetings. OFAC called the conduct egregious, and an initially unsatisfactory response to its first administrative subpoena counted against him.
Why this matters: Among World’s Most Ethical Companies Honorees, 93% use an online screening tool to track changes in third-party risk. Screening will catch a new Specially Designated Nationals and Blocked Persons (SDN) entry. But will it tell you that a correspondent bank keeps a VTB relationship, or that an employee holds an advisory role at a company in a sanctioned jurisdiction?
What to do this month:
- Inventory every Iran-related activity that depends on a pending or expected specific license, and brief leadership on wind-down options
- Ask non-U.S. banking partners whether they maintain VTB relationships, and document the answers
- Confirm that conflict-of-interest and outside-activity disclosures capture foreign directorships and advisory roles
- Agree on a subpoena-response protocol before you need one; the delay in the $1.43 million case cost mitigation credit
- Update policy, training, and legal citations to OFAC’s new consolidated penalty regulation, 31 CFR Part 505, effective Sept. 25
The False Claims Act Is Auditing Compliance Programs
Four September settlements revolved around what a company certified to the government, and three of them trace back to employee-reported misconduct.
Abbott Laboratories agreed to pay almost $385 million to resolve allegations that it caused false claims by making powder infant formula at its Sturgis, Mich., and Casa Grande, Ariz., facilities out of compliance with regulatory and contractual requirements. DOJ alleged temporary fixes for roof leaks over product areas, spray dryers run with documented cracks, decisions not to test for bacterial growth to avoid positive results, and contamination results withheld from FDA inspectors. $69 million of the payments will go to three Abbot employees to settle their qui tam action over the matter.
Accenture agreed to pay $25 million over allegations that Accenture Federal Services falsely certified compliance with the equal opportunity clause in its federal contracts. DOJ described monthly scorecards that color-coded business units against demographic goals and development programs with eligibility restricted by race or sex. It follows Deloitte’s $21.5 million settlement from late August.
Dompé U.S. agreed to pay $32 million to resolve Anti-Kickback Statute and False Claims Act allegations that it funded Medicare co-pays for its drug Oxervate through two patient assistance foundations. Dompé admitted that employees raised concerns before launch. Its Italian parent self-disclosed the conduct, and both entities received credit for self-disclosure, cooperation, and remediation.
Honeywell Aerospace agreed to pay just over $2 million over allegations that a business unit billed the Department of Defense while one of its networks fell short of NIST SP 800-171 cybersecurity requirements. The case began with a suit by a former employee, who receives $375,823.
Regarding rules around whistleblowers, the CFTC finalized a 30% presumption for whistleblower awards of $5 million or less, effective 30 days after Federal Register publication. On Sept. 18, DOJ revised the Justice Manual to say that sub-regulatory guidance can’t create binding legal obligations, and directed government attorneys to seek dismissal of declined qui tam suits that lack merit. That may trim weaker relator cases, but it does not slow DOJ’s own affirmative enforcement, as Abbott and Accenture show.
Why this matters: Ethisphere’s ethical culture data, drawn from more than 1 million survey responses collected from January 2024 through December 2025, found that only 52.4% of respondents who observed misconduct reported it. The relators in these cases are people who did speak up, eventually to the government. A concern that stalls inside your organization is a concern that can resurface as a qui tam complaint.
What to do this month:
- Review your internal investigation metrics to see how long an average report takes to go from initial reporting to investigation close. That time is the window in which an employee has to feel that their concerns are being taken seriously.
- List every certification your organization makes on federal contracts, from equal opportunity to cybersecurity to product quality, and name an owner who can prove each one is true
- Review dashboards, scorecards, slate rules, and development-program eligibility criteria that tie demographic representation to employment decisions
- Trace escalation paths from quality, EHS, and IT security into compliance, and check whether a deferred fix on a known risk ever reaches someone above the site level
- Test whether your internal reporting channel is faster and easier to use than the CFTC’s or the SEC’s, and scrub separation agreements and NDA templates for language that could chill protected reporting
Washington’s Rulebook Is Open for Comment
The SEC spent September proposing to remove rules. On Sept. 16, it proposed rescinding Rule 14a-8, the federal rule that requires public companies to include shareholder proposals in their proxy statements, arguing that it exceeds the Commission’s statutory authority. Paired proposals would give companies more discretion over proxy voting authority. The Commission also proposed rescinding the investment adviser pay-to-play rule, Rule 206(4)-5, with comments due Nov. 9. The comment period closed Sept. 4 on its proposal to let public companies report semiannually on a new Form 10-S; and the CFTC and SEC pushed the Form PF compliance date from Oct. 1, 2026, to July 1, 2027.
Bank regulators are rewriting, too. The FDIC, Federal Reserve, NCUA, and OCC proposed principles-based third-party risk management guidance that would replace the 2023 interagency guidance, with comments due Nov. 16. FinCEN and the banking agencies confirmed that SAR confidentiality doesn’t bar a bank from talking to customers about suspected fraud. And the FTC’s Bureau of Consumer Protection launched a Rule Guidance Program for questions about genuine ambiguities in Commission rules.
A proposed rescission leaves the rule in place. Pay-to-play preclearance, lookback, and recordkeeping controls stay in force until a final rule says otherwise, and MSRB Rule G-37, FINRA Rule 2030, and state and municipal pay-to-play regimes are untouched either way. The real risk this fall is dismantling controls early.
Why this matters: Among World’s Most Ethical Companies Honorees, 96% document a review of current policies, procedures, systems, and controls as part of their ethics and compliance risk assessment. A month of proposed rescissions is a good reason to run that review with two questions attached to each item. What changes if the rule is finalized, and what stays no matter what?
What to do this month:
- Log each proposal above with its comment deadline and decide whether to comment
- Keep political-contribution preclearance running for as long as any regime requires it
- Map your third-party risk program against the proposed guidance; if you serve banks as a vendor, read it for the diligence demands headed your way
- Re-test fraud-operations scripts and account-closure notices against the SAR confidentiality statement
In Europe and the U.K., the Deadlines Arrived
Three EU obligations went live in September:
- Sept. 11: Under the Cyber Resilience Act, manufacturers of connected products sold in the EU must now report actively exploited vulnerabilities and severe security incidents to ENISA and national CSIRTs within 24 hours through the Single Reporting Platform, with follow-up reports due at 72 hours. Fines will reach €15 million or 2.5% of global turnover.
- Sept. 12: Under Article 3(1) of the Data Act, connected products placed on the EU market after this date must be designed so users can access their product data by default, free of charge, in a machine-readable format.
- Sept. 27: The Empowering Consumers for the Green Transition Directive now bans generic environmental claims such as “eco-friendly” or “biodegradable” without recognized proof, sustainability labels not based on approved certification schemes, and claims about a whole product that are true of only one aspect. It covers advertising, packaging, product names, and websites.
In the U.K., the FCA’s non-financial misconduct rules took effect Sept. 1. The new COCON 1.1.7FR extends the conduct rules in non-banking firms to cover bullying, harassment, and violence against colleagues where there is a sufficient work-related link. For FSMA-authorized firms, harassment is now a regulatory conduct issue as well as an HR one.
Meanwhile, other measures across the continent included:
- The European Data Protection Board adopted draft guidelines for a harmonized, five-step GDPR fining methodology, open for comment until Nov. 13.
- Ireland’s Data Protection Commission fined Google €403 million over location-data processing.
- France’s CNIL fined consultancy EXTIA €300,000 after it mishandled more than three-quarters of 265 erasure requests, most of them from job candidates and former employees.
- And the European Commission proposed the EU Kids Act, which would bar children under 13 from social media, set a minimum account age of 15, and require platforms to prove their services are safe by design, with fines reported at up to 6% of global annual revenue.
Why this matters: Most of these obligations involve teams that don’t report to compliance. Product engineering owns the Data Act and the 24-hour reporting clock. Marketing and packaging own the green claims ban. The EXTIA fine shows how this plays out in privacy: the data at issue belonged to job candidates and former employees, well outside the customer-data perimeter where most privacy programs concentrate.
What to do this month:
- Confirm which products crossed the Sept. 12 Data Act line and that engineering shipped default data access
- Run a live test of the 24-hour Cyber Resilience Act reporting path, including who files on the Single Reporting Platform
- Get a status report from marketing on the green claims audit, including packaging on inventory already in the channel
- For U.K. financial services firms, refresh anti-harassment policies, conduct-breach escalation, and fit-and-proper criteria, and make sure managers understand the FCA’s “reasonable steps” expectation
- Assign an owner for data subject requests from candidates and former employees, and confirm your applicant tracking system deletes records on schedule
Everything Else from September 2026
What to Watch in October and November
- October: The FCA plans a further consultation on its crypto regime to reflect recent legislative amendments
- Mid-October: The 30-day comment period closes on the FTC’s FleetCor consent order
- Nov. 9: Comments due on the SEC’s proposal to rescind the investment adviser pay-to-play rule
- Nov. 13: Comments due on the EDPB’s draft GDPR fining methodology
- Nov. 16: Comments due on the interagency third-party risk management guidance
- Pending Federal Register publication: The 60-day comment clock on the SEC’s Rule 14a-8 proposal, and the 30-day effective date for the CFTC’s whistleblower award rule
Frequently Asked Questions
Does OFAC’s presumption of denial revoke existing Iran licenses?
OFAC’s Sept. 10 change governs how it evaluates Iran-related specific license applications going forward. Anyone operating under an existing license should read its terms closely with counsel, and any activity that depends on a pending or future application should be treated as unlikely to be approved outside the narrow exceptions OFAC named.
Is Rule 14a-8 gone?
No. The SEC has proposed rescinding it, and the rule stays in force while the proposal moves through a 60-day comment period and any final rulemaking. Companies should plan for this proxy season under the current rule while scenario-planning for a shift to proposal rights based on state law and company bylaws.
Does DOJ’s Justice Manual revision reduce False Claims Act exposure?
It narrows two things: theories built on agency guidance documents rather than binding law, and declined qui tam suits that lack legal or factual merit. It doesn’t touch cases DOJ brings itself. The Abbott, Accenture, Dompé, and Honeywell settlements all landed in September.
What counts as an unsubstantiated green claim under the EU ban?
Generic environmental claims such as “eco-friendly,” “green,” or “biodegradable” are banned unless backed by recognized proof of excellent environmental performance. The ban also covers sustainability labels that aren’t based on approved certification schemes and claims about a whole product or business that are true of only one aspect.
Keep Up with Regulatory Change
It’s important to know what rules changes are taking effect, but it’s even more important to know how your program’s response compares with organizations facing the same rules. Members of the Business Ethics Leadership Alliance benchmark their programs against peers and against the practices of World’s Most Ethical Companies Honorees, so they can see where they stand before a regulator asks.
If you missed August’s regulatory roundup, you can read it here.
This roundup covers developments published or reported during September 2026. It is not legal advice. Verify against the linked source before acting.