What happened

The Financial Times published an investigation on 21 September based on hundreds of thousands of internal files from A7, a Russian payments group built after major banks in the country lost Swift access following the 2022 invasion of Ukraine. The files show A7 moved more than $6.9 billion through the international banking system between late 2024 and August 2025. Some payments related to military equipment. Compliance Week notes the flows broke money movement and sanctions rules in several jurisdictions.

The method was not sophisticated. A7 used front companies and existing businesses in the UAE, Hong Kong, Kyrgyzstan and Indonesia to reach banks that still had Swift access. Cash deposited into those accounts settled bills for Russian companies. To survive bank checks, A7 ran an industrial scale forgery operation: counterfeit invoices, a library of corporate stamps, some fake and some lifted from real companies' documents, and rewritten goods descriptions and customs codes. Staff discussed how to remove what they called the "Russian trace," including Cyrillic characters.

One documented example: a February 2025 payment for 500 night vision scopes, worth about Rmb3.6 million, was papered as toughened glass. Around 100 front companies were found making payments, with documents naming at least 100 more. Chinese bank accounts were the destination for just over half the flows. Banks in the records include First Abu Dhabi Bank, where 17 A7 linked entities made more than $1.8 billion of outbound payments, Standard Chartered in Hong Kong at $1.1 billion, and DBS, Citigroup and Deutsche Bank accounts at smaller amounts. When Standard Chartered raised suspicions in February 2025 and closed accounts, A7 shifted volume through the UAE, where further checks met the same forged invoices. A7 was sanctioned by the UK in May 2025 and by the EU in July 2025.

Why this is a GRC story

The control that failed was the sending bank's. Correspondent banking rests on the assumption that each bank has properly verified its own customer. A receiving bank often sees a UAE or Hong Kong company with plausible trade documents, not a sanctioned Russian bank. The forgery was designed to look like ordinary trade, so paper based due diligence found nothing to flag.

Screening only works at the granularity you screen at. Name screening will not catch a model built on third country fronts, changed customs codes and recycled corporate seals. The signals live in behaviour: new counterparties in high risk corridors, invoice descriptions that change after a bank asks a question, and flows that look like layering rather than trade.

The "immune to sanctions" pitch did not hold. A7 marketed itself as a rail beyond Western control, yet the leak shows it leaning on the same banks it claimed to bypass, with paperwork rather than new technology as the workaround.

What to watch

Watch how supervisors and the named banks respond. Their obligations do not depend on whether they knew the ultimate beneficiary; the question is what monitoring existed for these corridors and document patterns. Regulatory action or de risking in the UAE and Hong Kong hubs are next.

Treat trade based payments from high risk jurisdictions as a document integrity problem, not only a name screening problem. If your alert logic cannot compare an invoice description against previous invoices from the same beneficiary, you are relying on a control A7 learned to beat.

Attribution: Analysis based on Compliance Week's reporting and the Financial Times investigation it covers. This article is original commentary, not a repost of the source material.

More daily case studies
← Back to GRC News