What happened

The UK's Office of Financial Sanctions Implementation fined Citibank's London branch £4,732,830.58 for processing 970 payments worth about £19.7 million in breach of the UK's Russia sanctions regime. OFSI published the penalty notice on 2 September 2026. Most of the payments went through between February and November 2022, in the months following Russia's invasion of Ukraine.

The failures spanned corporate client accounts, correspondent banking and account restrictions. OFSI rated the case Level 4, its highest severity band, and set a baseline penalty of £7,888,050.97. Two discounts followed, 20 percent for voluntary disclosure and cooperation, and a further 20 percent for settling, which brought the final figure down by 40 percent.

In one group of breaches, Citibank failed to restrict 24 accounts held by 11 companies owned or controlled by a designated Russian individual, producing 242 payments worth about £5.9 million. A further 328 transactions worth £5.4 million arose because the bank's screening system did not match Sovcomflot on the sanctions list against PAO Sovcomflot in its own client records, so no alert was ever generated. The bank also processed correspondent banking payments involving designated institutions including Alfa-Bank, Gazprombank and Credit Bank of Moscow, and deducted its own fees and charges from frozen accounts on 177 occasions.

OFSI found no intention to evade sanctions, but concluded the bank should have known or suspected its actions would result in breaches. It accepted that roughly £4.3 million of the payments took place within 24 hours of a designation, a window in which it does not necessarily expect automated systems to stop every transaction. Two groups of breaches worth about £6.9 million came to light only after OFSI approached the bank.

Why this is a GRC story

Sanctions screening is a data quality problem before it is a technology problem. The Sovcomflot example is the one to sit with. The name was on the regulator's list, the same entity sat in the bank's own records under a slightly different name, and the matching logic never connected them. No amount of tuning the screening tool fixes an unresolved entity reference between two systems.

The alert backlog matters too. OFSI described the scale of the sanctions programme as a significant strain on the bank's alert handling and investigation processes, and it treated the bank's high exposure as an aggravating factor. A control that cannot keep up with volume is a known gap, and regulators read it that way.

The 40 percent reduction is the part worth copying. Most of the breaches were self-reported before OFSI asked, the bank cooperated beyond what was requested, and it agreed to settle. Voluntary disclosure is a control with a measurable cash value, and that value was in the millions here.

What to watch

Watch whether OFSI keeps issuing Level 4 ratings for post-2022 backlogs, and whether the remediation commitments in this settlement get tested in future supervisory work. Watch also how other banks respond to the name matching problem, because plenty of sanctions screening programmes rely on fuzzy matching between a vendor list and internal client records that were never cleansed.

The 24 hour designation window is the quieter signal. That OFSI accepts systems cannot stop everything on day one is a useful reference point for firms designing the escalation path they will be judged on.

Attribution: Analysis based on Compliance Week's reporting and the OFSI penalty notice. This article is original commentary, not a repost of the source material.

More daily case studies
← Back to GRC News