Skip to content
iclock 17 Minutes - Read Now
idate

September 2026 Regulatory Update: Iran Licensing Starts at No, False Claims Act Settlements Pile Up, and Europe’s Deadlines Arrive

An Ethicast Reacts feature September put two kinds of pressure on compliance programs at once. In Washington, the SEC’s shareholder-proposal […]

Bill Coffin
Bill Coffin Editor-in-Chief, Ethisphere Magazine, Ethisphere
Erica Salmon Byrne, J.D.
Erica Salmon Byrne, J.D. Chief Strategy Officer and Executive Chair, Ethisphere
U.S. Capitol building

An Ethicast Reacts feature

September put two kinds of pressure on compliance programs at once. In Washington, the SEC’s shareholder-proposal rule and its pay-to-play restrictions on investment advisers proposed to take rules off the books. Meawhile, Treasury and the Justice Department maintained a steady run of sanctions actions and False Claims Act settlements. In Europe, obligations that sat on compliance calendars for years went live in a span of 16 days.

On the enforcement front, Abbott Laboratories agreed to pay nearly $385 million to resolve allegations tied to infant formula manufacturing that speak directly to compliance officers: tests that weren’t run, results that weren’t shared with inspectors, and employees who eventually took their concerns to court.

Below, we cover the developments that matter most for ethics and compliance teams, benchmark them against what World’s Most Ethical Companies® Honorees do, and collect everything else from September in one table.

Iran Sanctions Now Start from ‘No’

Treasury’s Operation Economic Outcast set the pace all month. On Sept. 10, OFAC changed its Iran-related specific licensing policy so that applications are now evaluated with a presumption of denial. The exceptions are limited to what the law requires and narrow circumstances such as risk to life, limb, or environmental safety. Any business plan that assumes a license will eventually come through needs to be re-tested now.

The designations arrived in waves. In early September, OFAC blocked Türkiye-based Golden Global Bank and two subsidiaries for giving the IRGC-Qods Force correspondent banking access to move Iranian oil revenue. On Sept. 8, it designated 36 targets across Iran’s aviation sector, including more than two dozen commercial and private airlines and several foreign cargo providers. OFAC also sanctioned BitBank and affiliated entities for moving Bitcoin to the IRGC.

The Sept. 14 designation of Russia’s VTB Bank under Iran authorities deserves special attention. VTB was already blocked under Russia programs, so the new listing is Treasury’s way of telling foreign financial institutions that are still dealing with VTB to cut those relationships immediately. That warning reaches banks in your payment chain that you may never screen directly.

Enforcement reached individuals, too. A U.S. person paid $1,427,230 to settle 39 apparent violations for providing management consulting to an Iranian software company over 19 virtual meetings. OFAC called the conduct egregious, and an initially unsatisfactory response to its first administrative subpoena counted against him.

Why this matters: Among World’s Most Ethical Companies Honorees, 93% use an online screening tool to track changes in third-party risk. Screening will catch a new Specially Designated Nationals and Blocked Persons (SDN) entry. But will it tell you that a correspondent bank keeps a VTB relationship, or that an employee holds an advisory role at a company in a sanctioned jurisdiction?

What to do this month:

  • Inventory every Iran-related activity that depends on a pending or expected specific license, and brief leadership on wind-down options
  • Ask non-U.S. banking partners whether they maintain VTB relationships, and document the answers
  • Confirm that conflict-of-interest and outside-activity disclosures capture foreign directorships and advisory roles
  • Agree on a subpoena-response protocol before you need one; the delay in the $1.43 million case cost mitigation credit
  • Update policy, training, and legal citations to OFAC’s new consolidated penalty regulation, 31 CFR Part 505, effective Sept. 25

The False Claims Act Is Auditing Compliance Programs

Four September settlements revolved around what a company certified to the government, and three of them trace back to employee-reported misconduct.

Abbott Laboratories agreed to pay almost $385 million to resolve allegations that it caused false claims by making powder infant formula at its Sturgis, Mich., and Casa Grande, Ariz., facilities out of compliance with regulatory and contractual requirements. DOJ alleged temporary fixes for roof leaks over product areas, spray dryers run with documented cracks, decisions not to test for bacterial growth to avoid positive results, and contamination results withheld from FDA inspectors. $69 million of the payments will go to three Abbot employees to settle their qui tam action over the matter.

Accenture agreed to pay $25 million over allegations that Accenture Federal Services falsely certified compliance with the equal opportunity clause in its federal contracts. DOJ described monthly scorecards that color-coded business units against demographic goals and development programs with eligibility restricted by race or sex. It follows Deloitte’s $21.5 million settlement from late August.

Dompé U.S. agreed to pay $32 million to resolve Anti-Kickback Statute and False Claims Act allegations that it funded Medicare co-pays for its drug Oxervate through two patient assistance foundations. Dompé admitted that employees raised concerns before launch. Its Italian parent self-disclosed the conduct, and both entities received credit for self-disclosure, cooperation, and remediation.

Honeywell Aerospace agreed to pay just over $2 million over allegations that a business unit billed the Department of Defense while one of its networks fell short of NIST SP 800-171 cybersecurity requirements. The case began with a suit by a former employee, who receives $375,823.

Regarding rules around whistleblowers, the CFTC finalized a 30% presumption for whistleblower awards of $5 million or less, effective 30 days after Federal Register publication. On Sept. 18, DOJ revised the Justice Manual to say that sub-regulatory guidance can’t create binding legal obligations, and directed government attorneys to seek dismissal of declined qui tam suits that lack merit. That may trim weaker relator cases, but it does not slow DOJ’s own affirmative enforcement, as Abbott and Accenture show.

Why this matters: Ethisphere’s ethical culture data, drawn from more than 1 million survey responses collected from January 2024 through December 2025, found that only 52.4% of respondents who observed misconduct reported it. The relators in these cases are people who did speak up, eventually to the government. A concern that stalls inside your organization is a concern that can resurface as a qui tam complaint.

What to do this month:

  • Review your internal investigation metrics to see how long an average report takes to go from initial reporting to investigation close. That time is the window in which an employee has to feel that their concerns are being taken seriously.
  • List every certification your organization makes on federal contracts, from equal opportunity to cybersecurity to product quality, and name an owner who can prove each one is true
  • Review dashboards, scorecards, slate rules, and development-program eligibility criteria that tie demographic representation to employment decisions
  • Trace escalation paths from quality, EHS, and IT security into compliance, and check whether a deferred fix on a known risk ever reaches someone above the site level
  • Test whether your internal reporting channel is faster and easier to use than the CFTC’s or the SEC’s, and scrub separation agreements and NDA templates for language that could chill protected reporting

Washington’s Rulebook Is Open for Comment

The SEC spent September proposing to remove rules. On Sept. 16, it proposed rescinding Rule 14a-8, the federal rule that requires public companies to include shareholder proposals in their proxy statements, arguing that it exceeds the Commission’s statutory authority. Paired proposals would give companies more discretion over proxy voting authority. The Commission also proposed rescinding the investment adviser pay-to-play rule, Rule 206(4)-5, with comments due Nov. 9. The comment period closed Sept. 4 on its proposal to let public companies report semiannually on a new Form 10-S; and the CFTC and SEC pushed the Form PF compliance date from Oct. 1, 2026, to July 1, 2027.

Bank regulators are rewriting, too. The FDIC, Federal Reserve, NCUA, and OCC proposed principles-based third-party risk management guidance that would replace the 2023 interagency guidance, with comments due Nov. 16. FinCEN and the banking agencies confirmed that SAR confidentiality doesn’t bar a bank from talking to customers about suspected fraud. And the FTC’s Bureau of Consumer Protection launched a Rule Guidance Program for questions about genuine ambiguities in Commission rules.

A proposed rescission leaves the rule in place. Pay-to-play preclearance, lookback, and recordkeeping controls stay in force until a final rule says otherwise, and MSRB Rule G-37, FINRA Rule 2030, and state and municipal pay-to-play regimes are untouched either way. The real risk this fall is dismantling controls early.

Why this matters: Among World’s Most Ethical Companies Honorees, 96% document a review of current policies, procedures, systems, and controls as part of their ethics and compliance risk assessment. A month of proposed rescissions is a good reason to run that review with two questions attached to each item. What changes if the rule is finalized, and what stays no matter what?

What to do this month:

  • Log each proposal above with its comment deadline and decide whether to comment
  • Keep political-contribution preclearance running for as long as any regime requires it
  • Map your third-party risk program against the proposed guidance; if you serve banks as a vendor, read it for the diligence demands headed your way
  • Re-test fraud-operations scripts and account-closure notices against the SAR confidentiality statement

In Europe and the U.K., the Deadlines Arrived

Three EU obligations went live in September:

  • Sept. 11: Under the Cyber Resilience Act, manufacturers of connected products sold in the EU must now report actively exploited vulnerabilities and severe security incidents to ENISA and national CSIRTs within 24 hours through the Single Reporting Platform, with follow-up reports due at 72 hours. Fines will reach €15 million or 2.5% of global turnover.
  • Sept. 12: Under Article 3(1) of the Data Act, connected products placed on the EU market after this date must be designed so users can access their product data by default, free of charge, in a machine-readable format.
  • Sept. 27: The Empowering Consumers for the Green Transition Directive now bans generic environmental claims such as “eco-friendly” or “biodegradable” without recognized proof, sustainability labels not based on approved certification schemes, and claims about a whole product that are true of only one aspect. It covers advertising, packaging, product names, and websites.

In the U.K., the FCA’s non-financial misconduct rules took effect Sept. 1. The new COCON 1.1.7FR extends the conduct rules in non-banking firms to cover bullying, harassment, and violence against colleagues where there is a sufficient work-related link. For FSMA-authorized firms, harassment is now a regulatory conduct issue as well as an HR one.

Meanwhile, other measures across the continent included:

  • The European Data Protection Board adopted draft guidelines for a harmonized, five-step GDPR fining methodology, open for comment until Nov. 13.
  • Ireland’s Data Protection Commission fined Google €403 million over location-data processing.
  • France’s CNIL fined consultancy EXTIA €300,000 after it mishandled more than three-quarters of 265 erasure requests, most of them from job candidates and former employees.
  • And the European Commission proposed the EU Kids Act, which would bar children under 13 from social media, set a minimum account age of 15, and require platforms to prove their services are safe by design, with fines reported at up to 6% of global annual revenue.

Why this matters: Most of these obligations involve teams that don’t report to compliance. Product engineering owns the Data Act and the 24-hour reporting clock. Marketing and packaging own the green claims ban. The EXTIA fine shows how this plays out in privacy: the data at issue belonged to job candidates and former employees, well outside the customer-data perimeter where most privacy programs concentrate.

What to do this month:

  • Confirm which products crossed the Sept. 12 Data Act line and that engineering shipped default data access
  • Run a live test of the 24-hour Cyber Resilience Act reporting path, including who files on the Single Reporting Platform
  • Get a status report from marketing on the green claims audit, including packaging on inventory already in the channel
  • For U.K. financial services firms, refresh anti-harassment policies, conduct-breach escalation, and fit-and-proper criteria, and make sure managers understand the FCA’s “reasonable steps” expectation
  • Assign an owner for data subject requests from candidates and former employees, and confirm your applicant tracking system deletes records on schedule

Everything Else from September 2026

DateDevelopmentRegulatorWho it affects
Sept. 1SEC and FDA sign a three-year information-sharing agreement on drugmaker disclosuresSEC, FDAListed pharma and biotech issuers
Sept. 1FTC and 22 states sue Amazon over an alleged hidden ad-auction surchargeFTC, state AGsAd platforms and companies running auction-based pricing
Sept. 1Ohio State pays $2.1 million over undisclosed foreign ties in federal research grantsDOJUniversities and other federal research grant recipients
Sept. 1Federal judge strikes down New York’s Climate Superfund ActFederal court (DOJ challenge)Energy companies facing state climate-liability laws
Sept. 2FinCEN reissues Southwest Border GTO, keeping the $1,000 CTR thresholdFinCENMoney services businesses and retailers offering money transfer in named Texas and New Mexico counties
Sept. 2OFAC flags the Sept. 30 blocked-property report deadline and amends three Venezuela general licensesOFACHolders of blocked property; mining, metals, and commodities firms
Sept. 3OFAC issues Cuba designations and an amended Cuba general license, and removes a Russia-related designationOFACCompanies with Cuba or Russia exposure and sanctions screening teams
Sept. 3FTC extends comment period on personalized-pricing policy to Sept. 25FTCRetail, e-commerce, and travel companies using data-driven pricing
Sept. 4FCA bans and fines adviser £742,700 over unauthorized pension transfer adviceFCAU.K. wealth firms with appointed-representative networks
Sept. 4FTC credits its review with steering an Ohio hospital sale to a different buyerFTCHospital systems and health care acquirers
Sept. 4SHEIN recalls spiral toys that violate the small-ball banCPSCOnline marketplaces and children’s product importers
Sept. 8India’s Supreme Court holds a company can face criminal trial even if the responsible employee isn’t identified (Sanofi India v. CBI)Supreme Court of IndiaMultinationals with Indian operations or public-sector customers in India
Sept. 8CBP issues a withhold release order covering a Chinese distant-water fishing fleet over forced laborCBPSeafood importers, grocers, and food service companies
Sept. 8DOJ issues a second request on Fox’s $22 billion Roku dealDOJ Antitrust DivisionMedia, streaming, and companies planning large acquisitions
Sept. 10SEC Chairman says AI won’t relax the materiality standard for disclosureSECIssuers’ disclosure committees; advisers and broker-dealers using AI
Sept. 10Romania fines Philips nearly €1 million after an employee deleted WhatsApp during a dawn raidRomanian competition authorityAny company that could face an unannounced inspection
Sept. 14Proclamation 11065 changes which Canadian products carry the 50% additional dutyWhite House, CBPU.S. importers of Canadian-origin goods
Sept. 14SBA suspends nearly 870,000 borrowers tied to an estimated $39 billion in suspected pandemic-loan fraudSBA, DOJLenders, fintechs, and recipients of federal relief funds
Sept. 15Alex Saab pleads guilty to laundering bribery proceeds through shell companies and U.S. banksDOJFinancial institutions and companies with Latin America third parties
Sept. 16FCA finalizes guidance (PS26/18) on which crypto activities need authorization; applications open Sept. 30FCACrypto firms, banks with digital-asset desks, and payments firms in the U.K.
Sept. 16FTC publishes price-transparency FAQs for auto dealersFTCAuto retailers, dealer groups, and captive finance arms
Sept. 16Court orders Google to open its ad-tech products to rivals and accept a six-year monitorDOJ Antitrust DivisionDominant platforms and companies negotiating antitrust remedies
Sept. 16FTC order unwinds Beretta’s board seats at rival RugerFTCInvestors with board rights or overlapping directors at competitors
Sept. 17SEC grants a five-year “Innovation Exemption” for tokenized stock trading venuesSECBroker-dealers, exchanges, custodians, and fintechs
Sept. 17Amway pays $225 million over income claims, the FTC’s largest recovery against a multilevel marketerFTCCompanies using direct-selling, affiliate, or referral compensation
Sept. 17FleetCor (Corpay) pays $100 million over hidden fees charged to small-business customersFTCCompanies billing small businesses recurring or usage-based fees
Sept. 17Court raises per-consumer refund caps from $51 to $200 under Amazon’s $2.5 billion Prime settlementFTCSubscription businesses and any company using enrollment or cancellation flows
Sept. 18OFAC ends the Ethiopia sanctions program and authorizes contingent contracts for a Lukoil International saleOFACSanctions screening teams; energy and trading firms
Sept. 18FCA will take over AML supervision of about 60,000 U.K. legal and accounting firms, beginning late 2028FCAU.K. law firms, accountancy practices, and their corporate clients
Sept. 21Twelve state AGs settle with Paramount Skydance, clearing the path for its Warner Bros. Discovery dealState AGs (led by California)Companies pursuing mergers that face state AG review
Sept. 21Former Vitol trader sentenced to four years for bribing Ecuadorian and Mexican officialsDOJEnergy and commodities firms using intermediaries in high-risk markets
Sept. 21Former Nodus Bank CEO sentenced to more than nine years for wire fraud and Venezuela sanctions evasionDOJBanks and fintechs with sanctioned-jurisdiction exposure
Sept. 22DoorDash pays $131.5 million to settle a New York City probe into delivery worker payNew York CityGig-economy platforms and companies relying on independent contractors
Sept. 22SEC censures OTC Link $575,000 over nine years of unremediated Regulation SCI failuresSECMarket infrastructure firms and any program with open exam findings
Sept. 22Steri-Tech pays $700,000 over ethylene oxide emissions at its Puerto Rico facilityDOJMedical device sterilizers and manufacturers subject to the Clean Air Act
Sept. 23Federal judge dismisses Michigan’s climate antitrust suit against oil majors; DOJ praises rulingDOJ, federal courtEnergy companies facing state climate litigation
Sept. 24DOJ moves to intervene in X Corp.’s challenge to the EU’s €120 million Digital Services Act fineDOJU.S. platforms with EU users
Sept. 24TikTok’s £12.7 million children’s-privacy fine becomes finalICOConsumer platforms processing U.K. teen data
Sept. 24FCA crackdown closes 21 CFD firms that misused U.K. authorizationFCAU.K.-authorized trading firms with overseas affiliates or white-label arrangements
Sept. 2444 state AGs settle with Labcorp for $2.29 million over a vendor’s data breachState AGs (led by Connecticut and Delaware)Companies sharing consumer or patient data with vendors
Sept. 28CPSC creates a Chief Enforcement Officer role and names Colette Devine to itCPSCConsumer product makers, importers, and online marketplaces

What to Watch in October and November

  • October: The FCA plans a further consultation on its crypto regime to reflect recent legislative amendments
  • Mid-October: The 30-day comment period closes on the FTC’s FleetCor consent order
  • Nov. 9: Comments due on the SEC’s proposal to rescind the investment adviser pay-to-play rule
  • Nov. 13: Comments due on the EDPB’s draft GDPR fining methodology
  • Nov. 16: Comments due on the interagency third-party risk management guidance
  • Pending Federal Register publication: The 60-day comment clock on the SEC’s Rule 14a-8 proposal, and the 30-day effective date for the CFTC’s whistleblower award rule

Frequently Asked Questions

Does OFAC’s presumption of denial revoke existing Iran licenses?
OFAC’s Sept. 10 change governs how it evaluates Iran-related specific license applications going forward. Anyone operating under an existing license should read its terms closely with counsel, and any activity that depends on a pending or future application should be treated as unlikely to be approved outside the narrow exceptions OFAC named.

Is Rule 14a-8 gone?
No. The SEC has proposed rescinding it, and the rule stays in force while the proposal moves through a 60-day comment period and any final rulemaking. Companies should plan for this proxy season under the current rule while scenario-planning for a shift to proposal rights based on state law and company bylaws.

Does DOJ’s Justice Manual revision reduce False Claims Act exposure?
It narrows two things: theories built on agency guidance documents rather than binding law, and declined qui tam suits that lack legal or factual merit. It doesn’t touch cases DOJ brings itself. The Abbott, Accenture, Dompé, and Honeywell settlements all landed in September.

What counts as an unsubstantiated green claim under the EU ban?
Generic environmental claims such as “eco-friendly,” “green,” or “biodegradable” are banned unless backed by recognized proof of excellent environmental performance. The ban also covers sustainability labels that aren’t based on approved certification schemes and claims about a whole product or business that are true of only one aspect.

Keep Up with Regulatory Change

It’s important to know what rules changes are taking effect, but it’s even more important to know how your program’s response compares with organizations facing the same rules. Members of the Business Ethics Leadership Alliance benchmark their programs against peers and against the practices of World’s Most Ethical Companies Honorees, so they can see where they stand before a regulator asks.

If you missed August’s regulatory roundup, you can read it here.

This roundup covers developments published or reported during September 2026. It is not legal advice. Verify against the linked source before acting.