Wire Stripping

Wire Stripping

Wire Stripping

Wire stripping is the deliberate removal or alteration of identifying details, names, locations, bank codes, from a payment message specifically to prevent a sanctioned party’s involvement from triggering automated screening. Standard Chartered Bank paid over $327 million for this conduct in 2012, then paid again, $1.1 billion, in 2019 for doing the same thing after already settling once. That repeat is the single most important fact about this technique.

Key takeaways

  • Wire stripping removes identifying details from payment messages specifically to defeat automated sanctions screening before it ever runs.
  • A typical scheme routes a payment through an intermediary bank, stripping sanctioned-origin details at the handoff to a US correspondent.
  • Standard Chartered paid over $327 million combined in 2012 for wire stripping, then $1.1 billion in 2019 for repeating the same conduct under active regulatory monitoring.
  • That repeat is the case’s central lesson: a settlement and a compliance monitor don’t automatically fix the underlying culture that produced the violation.
  • HSBC’s parallel case, involving Bank Melli London, shows the technique wasn’t isolated to one institution.
  • Automated screening can’t reliably catch wire stripping, since the identifying data it needs is deliberately removed before the filter ever runs.
  • Effective detection requires process and access controls, monitoring field completeness, restricting message-editing access, auditing routing changes, not better matching algorithms alone.

$327m+

Combined Standard Chartered penalty for its 2012 wire-stripping settlement

Source: OFAC, DOJ, Manhattan DA, Federal Reserve

$1.1bn

Standard Chartered’s 2019 global settlement for repeating wire-stripping conduct, including $657m to OFAC

Source: OFAC, DOJ, UK FCA

What wire stripping actually is

Wire stripping is the deliberate removal, alteration, or omission of identifying information from a payment message specifically so that a sanctioned party’s involvement doesn’t trigger automated sanctions screening. It’s sometimes called payment stripping. The technique doesn’t fool a screening system through technical sophistication; it works by removing the information the screening system needs before that system ever gets a chance to look at it.

The mechanism: a real worked example

A documented U-Turn wire-stripping pattern works roughly as follows: a foreign entity, an Iranian oil company, for example, needs to purchase goods from a US supplier. It sends funds through an Iranian bank to an intermediary bank in a third country, commonly the UK. That intermediary bank then forwards the payment to a US bank to complete the purchase. The stripping happens at exactly that handoff point, from the intermediary bank to the US bank, where the wire details identifying the Iranian origin get removed, or “scrubbed,” from the payment message before it reaches the US institution’s own OFAC screening filter.

The SWIFT message fields actually altered

Wire stripping targets specific fields within standard SWIFT payment message types, commonly MT 103 (customer credit transfers), MT 202 (bank-to-bank transfers), and MT 700 (documentary credits). The fields altered typically include the ordering and beneficiary client’s name, country, and address, along with references to the origin of goods and, in trade-related transactions, the ports involved. Removing or altering these specific fields is what makes an otherwise flaggable transaction look, to an automated filter, like an entirely ordinary, unremarkable payment.

Standard Chartered: the case that defined this term

Standard Chartered Bank’s conduct is the case most compliance literature on wire stripping is actually built around. According to OFAC and New York state regulators, from 2001 to 2007, SCB’s London head office and Dubai branch systematically stripped references to sanctioned locations and entities, principally Iranian, from payment messages before forwarding them to SCB’s own New York branch. One specific technique involved deliberately routing incoming SWIFT messages from Bank Markazi, Iran’s central bank, through a London queue described as “under repair,” requiring manual review, during which bank operators substituted SCB London’s own routing code for Markazi’s, disguising the Iranian central bank’s involvement entirely. In the 2012 settlement, SCB agreed to pay $132 million to OFAC; once payments to the Department of Justice, the Manhattan District Attorney, and the Federal Reserve were included, the combined penalty exceeded $327 million.

The repeat: why the 2019 case matters more than the 2012 one

This is the detail that makes Standard Chartered genuinely instructive rather than just another large fine. Seven years after its first settlement, and while operating under an active compliance monitor specifically imposed to prevent exactly this conduct from recurring, Standard Chartered was found engaging in materially the same wire-stripping practice again. The 2019 settlement totalled $1.1 billion across US and UK authorities, with $657 million of that specifically tied to OFAC. A bank that had already paid hundreds of millions, agreed to a settlement, and operated under direct regulatory supervision still found a way to strip sanctioned-party information from its payment messages a second time. That sequence, not the dollar figures alone, is the case’s real lesson: a settlement and a monitor don’t automatically fix an underlying institutional culture.

Worth knowing. Standard Chartered was operating under an active compliance monitor, installed specifically after its first wire-stripping settlement to prevent recurrence, when regulators found it engaging in materially the same conduct again. The monitor didn’t stop it. That sequence is the clearest evidence available that wire stripping is a personnel and process failure, not a technology gap.

HSBC’s parallel case

Standard Chartered isn’t the only documented example. HSBC’s non-US affiliates were separately found to have deliberately withheld information identifying Bank Melli London, a US-sanctioned Iranian financial institution, from SWIFT cover payments routed through HSBC’s US correspondent account, conduct regulators traced back to the mid-1990s. Had the transfer messages accurately reflected Bank Melli’s involvement, the receiving US institutions could have rejected or blocked the transactions for investigation under standard OFAC screening; stripping that information specifically prevented that check from ever having the chance to work.

Why automated screening can’t catch this on its own

This is the structural point that makes wire stripping different from most other screening failures: automated sanctions filters check the information present in a payment message. Wire stripping removes the specific information the filter is built to catch before the message ever reaches the screening step. No amount of improving the matching algorithm itself, better fuzzy matching, tighter thresholds, addresses this failure mode, because the problem isn’t that the filter missed a match. The problem is that the identifying data the filter needed to work with was deliberately removed upstream, by people, before the automated system had anything to check at all.

What actually detects wire stripping

Because the technique defeats automated content screening by design, detection has to look at the process and the people around it rather than the payment data alone: monitoring for anomalies in payment message field completeness, unusually high rates of incomplete or generic beneficiary information from specific branches or correspondent relationships, restricting which staff have the technical ability to manually modify SWIFT message fields in the first place, and auditing message routing changes, particularly cases where messages get rerouted through manual review queues, the exact mechanism SCB used to substitute its own routing code for a sanctioned counterparty’s.

The compliance response that actually works

Given that this is fundamentally a control-design and personnel-access problem rather than a screening-technology problem, an effective response combines procedural and technical controls together: role-based access restrictions on who can edit payment message fields after a transaction enters the system, independent, automated comparison of a payment’s original inbound fields against its outbound fields to flag any material alteration, and genuine whistleblower and internal audit channels, since wire stripping, as both major documented cases show, is carried out by employees who understand exactly what the screening system is looking for and deliberately work around it, not by a technical gap an engineer can simply patch.

Where this shows up in a risk assessment

For a firm’s own risk assessment, wire stripping exposure concentrates specifically around correspondent banking relationships, foreign branches operating in or near sanctioned jurisdictions, and any payment flow involving intermediary banks positioned between a higher-risk originator and a US or other sanctions-enforcing correspondent. Firms relying purely on their own screening technology’s sophistication, without independently verifying the completeness and consistency of the payment data feeding into it, are checking the right tool against data that may have already been compromised before it ever arrived.

Audit payment data integrity before it reaches screening

Check for gaps between what a payment message should contain and what your screening system actually sees.

Try Combined AML Screening →

Frequently asked questions

What is wire stripping?

Wire stripping is the deliberate removal or alteration of identifying details from a payment message, names, locations, bank codes, specifically to prevent a sanctioned party’s involvement from triggering automated screening.

How does a typical wire-stripping scheme actually work?

A common pattern involves a payment routed through an intermediary bank in a third country before reaching a US institution, with identifying details of a sanctioned origin removed at the intermediary-to-US handoff, before the US bank’s own screening filter ever sees the payment.

What happened to Standard Chartered Bank over wire stripping?

SCB paid over $327 million combined in a 2012 settlement for wire stripping Iranian-linked payments between 2001 and 2007, then paid $1.1 billion in 2019, including $657 million to OFAC, for engaging in materially the same conduct again.

Why does the Standard Chartered case matter more the second time?

The 2019 violation happened seven years after the first settlement, while the bank was operating under an active compliance monitor specifically meant to prevent recurrence, showing that a settlement and oversight alone don’t guarantee a fixed institutional culture.

Can automated sanctions screening catch wire stripping?

Not reliably. Wire stripping removes the identifying information a screening filter needs before the payment ever reaches that filter, so improving the matching algorithm itself doesn’t address a problem that happens upstream of screening entirely.

What SWIFT message fields does wire stripping typically alter?

Commonly the ordering and beneficiary client’s name, country, and address, along with references to the origin of goods and involved ports, within message types such as MT 103, MT 202, and MT 700.

What actually detects wire stripping?

Monitoring for anomalies in payment message field completeness, restricting staff access to manually modify SWIFT fields, and auditing unusual message-routing changes, since the technique defeats content-based screening by design.

Is wire stripping limited to Standard Chartered?

No. HSBC was separately found to have withheld identifying information about a sanctioned Iranian bank from SWIFT cover payments dating back to the mid-1990s, a materially similar case.

Read more: our ultimate guides, whitepapers and templates

Related guides and resources to help you act on what you just read.

Last reviewed July 19, 2026 · 12 min read · Written for compliance and risk professionals · By the WhoWiki editorial team

Key takeaway: Wire stripping is the deliberate removal or alteration of identifying details, names, locations, bank codes, from a payment message specifically to prevent a sanctioned party’s involvement from triggering automated screening. Standard Chartered Bank paid over $327 million for this conduct in 2012, then paid again, $1.1 billion, in 2019 for doing the same thing after already settling once. That repeat is the single most important fact about this technique.

Learn & stay current

A compliance reference that keeps up with the regulators

Plain-English explainers, country rules, and data you can cite, updated as the landscape moves.

Comparing tools before you commit?

See how WhoWiki lines up against the platforms you already know, and which free tools fit which job.

See how current your screening could be

Book a walkthrough with our team, or start with the tools today. No account needed to run your first check.