• AU
Choose your location?
  • Global Global
  • Australian flag Australia
  • Canadian flag Canada (FR)
  • French flag France
  • German flag Germany
  • Irish flag Ireland
  • Italian flag Italy
  • Polish flag Poland
  • Qatar flag Qatar
  • Spanish flag Spain
  • UAE flag UAE
  • UK flag UK

Strait of Hormuz: Ongoing supply chain disruption and investigations risk

15 September 2026

This article examines the risk of fraud, misconduct and sanctions breaches arising from supply chain disruption, and the corporate investigations response that may follow, before a further article on arbitration.

In our first article in this series, we looked at the litigation risks arising from the ongoing disruption around the Strait of Hormuz.

What is the phantom toll?

Here's something you might not know: Iran’s Strait of Hormuz toll regime is reportedly building a crypto economy potentially worth $20 million a day . The Strait is a critical maritime chokepoint through which roughly 20% of the world's oil and fuel shipments pass, and reports suggest stablecoins are being used to facilitate transit payments.

If accurate, that equates to roughly $7.3 billion a year in transit payments.

Reported to be the first known instance of a nation-state demanding cryptocurrency as payment for transit through an international waterway, the scheme introduces significant compliance risk for the global shipping industry.

Anyone involved in the maritime supply chain, in whatever capacity, should be alive to sanctions risk.

Consider the following:

A global trading company charters a vessel to carry crude oil from the Gulf, and it becomes stranded near the Strait of Hormuz. Under pressure to keep it moving, two individuals on the operations team quietly arrange for a local agent to pay a “transit fee” of $1 a barrel, settled in digital blockchain currency, to secure passage, and wave through shipping documentation that omits the cargo's Gulf origin. A middle-manager in the finance function then books the delayed cargo at an inflated value, showing higher P&L ahead of quarterly earnings reporting. Eight months later, a whistleblower communicates through an internal anonymous hotline that the payment went to an entity designated by the US Office of Foreign Assets Control (OFAC), the documentation was false, and management knew and said nothing to the board, just as they had said nothing in the past about mismarking assets to show a more profitable balance sheet.

You are in-house counsel or compliance, and you are asked to respond. What do you do?

What are the risks?

On 29 July 2026, the US Department of the Treasury announced that the United States had designated the Gulf Marine Insurance Company and Hormuz Safe Marine Services Authority, two Iranian entities backed by the Islamic Revolutionary Guard Corps (IRGC), for running coercive “insurance” schemes that allegedly extort international shipping transiting the Strait, including through threats of vessel seizure and demands for payment in digital assets. The US also designated eight companies operating vessels in Iran’s “shadow fleet”, which transport Iranian crude oil and petrochemical products to China and the UAE, adding to a campaign that has, according to OFAC, sanctioned over 100 vessels this year supporting the US Navy's enforcement of a blockade on Iranian ports and coastline.

Per the above, OFAC has the authority to block the property of designated or blocked persons within the US or in the possession or control of US persons. It can also prohibit transactions by US persons, or within the US, that involve property or interests in property of blocked persons. And it can impose civil or criminal penalties, or take enforcement actions against non-US persons who cause a US person to violate those sanctions, or who themselves evade them (e.g., by obscuring a designated party’s involvement). Whistleblower awards may be available where reports of sanctions violations lead to enforcement action and penalties exceeding US$1 million . Further, there is a real risk that an Iranian toll payment would make funds or economic resources available to a designated entity and therefore amount to a breach of the UK or EU sanctions regime, which similarly carry both criminal and civil consequences.

Risk around the Strait is not limited to the toll payment scheme alone: satellite spoofing, which consists of broadcasting false signals, can distort a vessel’s location and voyage record, undermining sanctions screening and inviting disputes over its true movements which, if identified, would breach sanctions rules. Compliance failures amid recent supply chain disruption can trigger major fines: OFAC’s recent $275 million settlement with Adani Enterprises Limited, an Indian public holding company, arose from petroleum purchases that were Iranian in origin despite being presented as Omani and Iraqi, with red flags including manipulated tracking data and implausible voyage routes. Vessels navigating the Strait may form part of the above-mentioned dark fleet, with the ships themselves being sanctioned, leading to significant direct risk and indirect exposure through chartering, insurance and trading relationships.

So, this brings us back to the original question: what are your next steps?

The internal investigation action plan

What do the first 96 hours look like?

Seven workstreams matter in the first 96 hours and are evergreen features of most significant corporate investigations. External counsel should be considered from the outset.

i. Privilege and communications. Appoint a legal lead, define the client group, mark sensitive materials carefully, and issue a “do not discuss externally” instruction. Careless internal commentary can quickly become disclosable, undermine claims to privilege, or create difficulties in regulatory or civil proceedings. Simply copying lawyers into a communication does not make it privileged. In terms of sanctions risk, lawyers will need to carry out extra checks to ensure that you, the client, are not designated and do not appear on any sanctions list. Lists are updated regularly by government bodies so regular, periodic checks and reviews are required. If the client is designated, there are likely to be restrictions in place concerning representation and whether payment for settlement or fees, both legal and expert, can be advanced without breaching regulations.

ii. Document preservation. Suspend deletion and preserve emails, chats, text messages, whatsapps and other instant messages, shared drives and folders, financial recording systems, hard copies, and any AI chat tools used. Destruction can itself become an offence or an aggravating factor. And be careful about tipping off a subject if an investigation is in progress.

iii. Notification. Consider preparing a notification matrix, which should include external stakeholders such as auditors and insurers. Some notification duties, including to regulators, are immediate or near-immediate, and there can often be little to be gained by waiting for a full investigation to conclude. The decision to notify is nevertheless delicate and should not be rushed. As regards sanctions, make sure that third parties are not designated and be mindful that none of your actions comprise conferring a benefit on a sanctioned third party.

iv. Risk and individuals. Identify preliminary witnesses, leavers, whistleblowers, conflicted managers, and anyone who needs access restricted, or may need to be placed on leave (the operations and finance people in the hypothetical should be handled very carefully, for example). People can destroy evidence and coordinate accounts, so the line manager of a subject should not control the response, and there should be no retaliation against whistleblowers (such as the reporting person in the hypothetical). Consider also whether you need experts to assist with the investigation (e.g., forensic accounting or external IT support).

v. Scope and governance. Put in place focused but reviewable terms of reference, together with an escalation process, budget, decision log and reporting cadence, rather than launching into interviews and document review without a clear written plan. Be clear on the relevant legal landscape (sanctions risk, above) when defining scope. Establish a clear sanctions screening programme which involves monitoring lists and the ownership structures of relevant entities, and identifying whether any sanctioned individual exerts "control" over any of the entities involved. A defined scope of any investigation keeps mission creep in check and gives the investigation defensibility if challenged later, as many internal investigations can be.

vi. Reporting the breach. As regards sanctions, consider whether the facts justify a voluntary self-disclosure to OFAC, which actively encourages disclosure and treats it as a mitigating factor that can reduce the base amount of any civil penalty. Identify each jurisdiction whose sanctions regime may have been engaged and whether parallel disclosure or reporting obligations arise there, seeking advice from local counsel in each relevant jurisdiction (for example, US attorneys, or Swiss or EU sanctions specialists). Any disclosure should be candid, transparent and complete: a report that is late, materially incomplete or prompted by a government inquiry rather than offered voluntarily may not attract the same credit.

vii. Interim remediation. Some steps here will only become possible once the facts are clearer. Stop any ongoing harm (including ensuring no future transit fee payments, as in the hypothetical above), protect assets, halt any control failures, and document each step carefully. Remediation is expected, but premature admissions can undermine the company's litigation position. At the same time, inconsistency or leaks create their own reputational and market risk, so both doing nothing until the final report and over-promising things the facts later contradict carry real risk.

Beyond the first 96 hours

Every investigation moves at its own pace, but broadly speaking, four phases tend to recur:

  • First, triage : the terms of reference and investigation plan, the document preservation notice and custodian list, governance, notification analysis and (depending on lines of reporting) an initial board or audit committee update.
  • Second, collection and interviews : the collection protocol and document review progress, an interview plan and witness materials take shape, and, where relevant, regulators, insurers or auditors may need to be brought in, with the notification matrix updated as needed.
  • Third, a decision point : a findings note (which could be a verbal update or a written report), remediation, and a disciplinary, regulatory or litigation strategy, as appropriate to the facts.
  • Finally, close-out : a file recording the methodology, documents reviewed and lessons learned.

An investigation can take anywhere from a few weeks to several years, but regulators tend to favour quicker resolutions, so it is important to move promptly and decisively. Always verify applicable laws, regulations and guidance against the latest official sources to ensure compliance.

A word on AI

The use of AI can be very helpful for conducting an internal investigation (especially document review) but be aware – as we have written about – that not all AI tools carry the same level of risk. Publicly available tools (think the Claude consumer AI tool) pose the greatest privilege risk and should be kept away from privileged or sensitive investigation material altogether, whereas enterprise or closed AI systems (think your firm’s business Copilot AI tool) can, in principle, be deployed within secure, private environments subject to contractual confidentiality and data protections. Educate your teams, implement clear AI usage policies, and involve lawyers early so AI supports, rather than replaces, legal advice. Agentic AI, meaning systems capable of autonomous, goal driven and adaptive behaviour with limited human input, raises further issues , and the short points there are: control what agents can access, ring-fence sensitive data from general productivity tools, treat prompts and outputs as part of the documentary record, and, once again, retain legal oversight over the process.

Looking ahead

The Iranian toll regime is still nascent, so watch for further OFAC designations, fines, and how quickly compliance controls catch up. Exposure will, we suspect, not stop at the sanctioned entities, as charterers, insurers, banks and others in the supply chain risk being drawn in through facilitation, screening failures or governance gaps.

In the next article of the series, we will explore arbitration and the strategic tools available to parties, including the use of interim measures and procedural tools in fast-moving supply chain disputes.

DWF acts for clients in disputes and investigations arising from supply chain disruption, fraud, and sanctions risk. If you would like to discuss any of the matters above, please reach out to the authors below.

Further Reading