Treasury’s latest action against the Sinaloa Cartel offers financial institutions a practical case study in why sanctions and financial crime risk increasingly need to be understood across people, businesses, ownership structures, financial channels, and relationships, not just individual names on a watchlist.
On September 29, 2026, the U.S. Department of the Treasury’s Office of Foreign Assets Control (OFAC) sanctioned 21 individuals and 25 entities connected to the Sinaloa Cartel’s Los Mayos faction, including cartel leadership, facilitators, money launderers, businesses, and individuals Treasury says used political influence or public positions to enable cartel activity.
The number of designations is significant. The structure behind them is more important.
Treasury explicitly described its strategy as a “network-based approach,” targeting not only cartel leadership but organizational nodes, facilitators, corrupt officials, family members, and ostensibly legitimate front persons. Since the beginning of 2025, Treasury says OFAC has taken more than 30 cartel-related actions targeting more than 400 individuals and entities.
For compliance teams, the September action provides a useful picture of what that strategy looks like in practice.
Risk does not appear neatly inside one sanctions list, one customer record, or one transaction. It can extend through ownership, business relationships, money-service providers, political exposure, commercial entities, counterparties, aliases, financial accounts, and transactions that may look ordinary when viewed independently.
The question for financial institutions is therefore broader than whether a screening system can identify a newly designated name.
Can the institution understand the network around that name, determine where it has exposure, and recognize when existing relationships change as new intelligence becomes available?
Treasury is targeting an ecosystem, not just cartel leadership
The September action was taken under both Executive Order 14059, which addresses illicit drugs and their production, and Executive Order 13224, as amended, which targets terrorists and their supporters. The Sinaloa Cartel has been designated as a Foreign Terrorist Organization and Specially Designated Global Terrorist since February 20, 2025.
But Treasury did not limit its September action to senior cartel figures.
The designation reaches into an ecosystem surrounding Los Mayos, including businesses and individuals Treasury says provided financial, operational, or political support. The commercial entities identified span areas such as hotels, money exchanges, security, real estate, entertainment, transportation, restaurants, fuel, and other businesses. Treasury also describes alleged laundering activity involving bulk cash, money exchanges, U.S. business bank accounts, and cryptocurrency.
That diversity matters.
A cartel leader presents an obvious risk once identified.
A seemingly ordinary company, business owner, counterparty, money-services provider, or commercial account may be considerably harder to evaluate if the institution cannot see the relationships surrounding it.
That is the difference between screening a record and understanding risk.
A name match is necessary. It is not the entire investigation.
Sanctions screening remains a foundational control. OFAC itself identifies sanctions screening as one of the most common internal controls organizations use to evaluate customers, intermediaries, counterparties, transactions, supply chains, and other activities.
OFAC also makes clear that an alert is the beginning of an evaluation. Organizations should assess the information available, conduct additional due diligence when appropriate, and determine the action required under the relevant sanctions authority.
The Sinaloa action illustrates why.
Consider a company that does not initially match a name on the SDN List. A conventional screening process may return no sanctions match. But that answer alone says very little about who owns the entity, who operates it, whether a blocked person is involved in the transaction, whether it shares relationships with sanctioned actors, or whether information developed after onboarding has materially changed its risk profile.
The challenge becomes one of context.
A useful risk picture may require sanctions data alongside beneficial ownership, company records, PEP information, adverse media, geographic intelligence, aliases, historical records, relationship data, and transactional information.
The more fragmented those sources are, the more responsibility shifts to investigators to assemble the picture manually.
Ownership makes the universe of sanctions exposure larger than the SDN List
The September designations also reinforce an important distinction between a sanctions list and the broader population of entities that may be blocked.
Under OFAC’s 50 Percent Rule, an entity directly or indirectly owned 50 percent or more in the aggregate by one or more blocked persons is itself considered blocked, even if OFAC has not separately placed the entity on the SDN List. OFAC specifically urges parties evaluating transactions or account relationships to conduct appropriate due diligence to determine relevant ownership stakes.
This means an institution cannot necessarily establish that an entity is permissible simply because its name does not appear on the list.
Ownership may need to be resolved across multiple layers.
There is also an important boundary that compliance programs should preserve: OFAC’s 50 Percent Rule concerns ownership, not control.
An entity controlled by one or more blocked persons but owned less than 50 percent by blocked persons is not automatically blocked under the 50 Percent Rule. OFAC can separately designate such an entity, however, and OFAC urges caution when dealing with non-blocked entities in which blocked persons hold substantial minority interests or exercise control. Transactions directly or indirectly involving a blocked individual may also remain prohibited even when the entity itself is not automatically blocked.
That distinction is more than a technicality.
It demonstrates why sanctions compliance requires both precise legal rules and sufficient intelligence to understand the facts to which those rules apply.
A screening engine can determine that a name does not appear on the SDN List.
It takes additional information to answer: Who actually owns this company?
Treasury’s network view crosses traditional compliance silos
Another notable feature of the September action is how many different forms of financial crime risk appear inside the same network.
Treasury alleges cartel activity supported through money laundering, commercial businesses, political influence, bribery, public officials, financial intermediaries, U.S. financial accounts, cryptocurrency, and other relationships.
Inside many institutions, those signals may be evaluated through separate processes.
Sanctions teams monitor designated parties. KYC and KYB teams establish customer identity and beneficial ownership. PEP controls assess political exposure. Adverse media programs search for emerging allegations and contextual information. Transaction monitoring looks for suspicious financial behavior. Investigators may then gather information from several systems to determine whether those individual signals form a meaningful pattern.
Criminal networks do not organize themselves according to those compliance functions.
The same person can simultaneously create sanctions, AML, PEP, corruption, adverse media, and counterparty concerns. A business relationship may only become meaningful when information from several of those categories is connected.
Treasury’s enforcement strategy reflects that reality.
Its stated objective is to disrupt multiple parts of a network simultaneously rather than treating leadership, facilitators, businesses, and financial infrastructure as unrelated targets.
For financial institutions, the practical implication is not that every compliance function must become one control.
It is that the underlying intelligence should be capable of connecting the same person, entity, ownership interest, business relationship, and risk signal across those controls.
The risk can change after onboarding
The action also highlights a weakness in purely point-in-time due diligence.
An organization may conduct appropriate screening when an account is opened or a counterparty is approved and find no sanctions issue at that moment.
That does not mean the relationship will remain unchanged.
A person may later be designated. New ownership information may become available. A previously unknown connection may be identified. An associated company may enter the sanctions perimeter. An adverse media report may reveal information that changes the customer’s risk profile.
OFAC has specifically warned that sanctions and sanctions lists can change regularly and that controls adequate at one point in time may no longer be sufficient after new sanctions are imposed or existing sanctions change. Its guidance calls for responsive, regular screening and risk-based steps that account for changes to sanctions and the 50 Percent Rule.
OFAC has made the same point in specific guidance on screening frequency. For example, it notes that screening only at the beginning of an insurance relationship could create exposure when a person is subsequently blocked, and recommends considering additional screening when OFAC sanctions or sanctions lists change.
The principle extends beyond insurance.
Risk is dynamic. Due diligence cannot be treated exclusively as an onboarding event.
The September Sinaloa action creates a simple real-world example.
On September 28, an institution may have had customers, counterparties, beneficial owners, or transaction participants with no direct match to these newly designated parties.
On September 29, the information changed.
A mature compliance program needs a reliable way to determine what changed with it.
Cartel enforcement is becoming a sustained financial-crime priority
The September action should also be viewed alongside other recent Treasury actions rather than in isolation.
In June 2025, FinCEN used authorities under the Fentanyl Sanctions Act and FEND Off Fentanyl Act to identify CIBanco, Intercam Banco, and Vector Casa de Bolsa as primary money laundering concerns in connection with illicit opioid trafficking and prohibit certain fund transmissions involving those institutions. These were FinCEN’s first actions using those authorities.
In July 2026, OFAC announced what Treasury described as its largest action to date against Cartel de Jalisco Nueva Generacion, sanctioning more than 50 individuals and entities tied to leadership, trafficking operations, illicit finance networks, family members, front persons, and businesses.
Then, in September, Treasury again emphasized its network-based strategy against the Sinaloa Cartel.
The instruments are different. The common thread is financial disruption.
Treasury is targeting the infrastructure that allows major criminal organizations to raise, move, conceal, and use money, as well as the people and businesses that facilitate those activities.
That matters to banks, payments companies, fintechs, money-services businesses, corporations, and other organizations with exposure to cross-border counterparties because the compliance challenge increasingly sits at the intersection of sanctions, financial crime, customer risk, and third-party risk.
FTO and SDGT status raises the stakes
The Sinaloa Cartel’s designation as both an FTO and an SDGT adds another dimension.
OFAC guidance states that U.S. persons generally may not engage in transactions with SDGTs or persons otherwise blocked under E.O. 13224 absent authorization. Non-U.S. persons engaging in prohibited transactions subject to U.S. jurisdiction can also face civil or criminal consequences, and foreign financial institutions may face correspondent or payable-through account sanctions if they knowingly facilitate significant transactions for or on behalf of an SDGT.
This does not mean every indirect association with a cartel automatically creates a sanctions violation or material-support case.
It does mean that organizations need enough information to distinguish a remote or irrelevant connection from a relationship that warrants enhanced investigation, escalation, blocking, rejection, reporting, or other action under applicable law and internal policy.
That is fundamentally a data and decisioning problem.
Too little information creates blind spots.
Too much undifferentiated information creates noise.
Compliance teams need context that helps determine which relationship actually matters.
What should compliance leaders test now?
Treasury’s Sinaloa action can be used as a practical stress test for existing controls. Compliance leaders should consider whether their current systems and workflows can answer questions such as:
- Could existing customers and counterparties be rapidly rescreened when OFAC publishes a major designation action?
- Can the organization identify entities that may be blocked through direct or indirect aggregate ownership even when those entities do not appear by name on the SDN List?
- Can investigators see beneficial owners, company relationships, aliases, associated individuals, PEP information, adverse media, and other relevant risk context without rebuilding the relationship manually across multiple tools?
- Can controls distinguish ownership from control and apply the appropriate sanctions rules rather than treating every relationship as equivalent?
- Can the institution identify when information discovered after onboarding materially changes an existing customer or counterparty’s risk?
- When an alert is generated, does the analyst receive enough context to determine materiality, or does the investigation begin with a name and a collection of disconnected searches?
The objective is not to identify every conceivable connection to every designated individual.
It is to give compliance teams enough accurate, timely, and relevant intelligence to understand meaningful exposure and make defensible decisions.
From list screening to risk intelligence
Sanctions lists remain essential. But Treasury’s own enforcement actions increasingly illustrate the limits of treating financial crime risk as a list-matching exercise.
The September 29 designations reveal a network that extends from cartel leadership into businesses, financial facilitators, political relationships, money-service providers, commercial entities, and financial channels. Some risks are explicit because OFAC has named the individual or entity. Others require institutions to understand ownership, relationships, and changing information.
The challenge is therefore not simply detecting a prohibited name.
It is determining how people and organizations are connected, how those connections change risk, and which signals require action.
That is where sanctions screening increasingly intersects with broader risk intelligence.
Sigma360 brings global risk data, watchlist screening, adverse media, entity intelligence, and configurable workflows together to help compliance teams evaluate direct and network-based risk with greater context. Independent analysis from Chartis Research has highlighted Sigma360’s global risk data, entity resolution, multilingual matching, contextual enrichment, and ability to combine structured and unstructured information in screening workflows.
Treasury is showing how it sees cartel risk: as a network.
Financial institutions should be asking whether their compliance infrastructure can see the same thing.
