BankingEnforcement & CasesEuropeSanctions

UK OFSI Fines Citibank London £4.73 Million Over 970 Sanctions-Breaching Payments

The UK Office of Financial Sanctions Implementation (OFSI) has imposed a £4,732,830.58 civil monetary penalty on Citibank, N.A., London Branch (CBNA London) for breaches of UK financial sanctions involving 970 payments with a cumulative value of £19,720,127.43.

The penalty was imposed on 11 August 2026 and publicly disclosed on 2 September. OFSI said the breaches involved the Russia (Sanctions) (EU Exit) Regulations 2019 and the Global Anti-Corruption Sanctions Regulations 2021. OFSI assessed the case at Level 4, the highest level in its seriousness framework, describing the overall severity as high and the conduct as aggravating.

Breaches spanned payments, correspondent banking and account controls

According to OFSI’s public penalty notice, the breaches were grouped into eight matters across CBNA London’s corporate banking, correspondent banking, payment processing and account-management operations. The majority occurred between February and November 2022 following Russia’s full-scale invasion of Ukraine, although a smaller group of alert-handling breaches continued through February 2025 and Global Anti-Corruption sanctions breaches occurred in 2025.

Among the largest groups, CBNA London failed to promptly restrict 24 commercial bank accounts held by 11 companies owned or controlled by a designated Russian individual. This resulted in 242 payments worth about £5.9 million, alongside two further payments worth more than £600,000 to a firm owned by that individual. OFSI said about £4.3 million of the £5.9 million was processed within 24 hours of designation, but other breaches continued for several weeks.

The bank also failed to promptly restrict 32 accounts held by 29 entities owned or controlled by designated shipping company PJSC Sovcomflot, resulting in 328 transactions worth about £5.4 million. OFSI identified a screening-calibration issue in which the bank’s system treated “PAO Sovcomflot” in its KYC records as materially different from “Sovcomflot” on the sanctions list, preventing alerts from being generated.

Correspondent-banking failures included payments involving designated Russian financial institutions such as Alfa-Bank, Gazprombank, Credit Bank of Moscow, Rosbank and Russian Agricultural Bank. OFSI said some payments were screened before correspondent banks were automatically added to the payment chain, and the full chain was not re-screened afterwards. In another group, relevant Bank Identification Codes had not been added to internal screening lists.

OFSI also identified nine payments worth about £500,000 where alert handlers made incorrect decisions, a £1.5 million interest-payment case involving an entity owned or controlled by a designated person, and 10 Global Anti-Corruption sanctions-related correspondent-banking payments worth about £300,000 processed between January and July 2025.

OFSI highlights control weaknesses and delayed reporting

OFSI said many breaches arose from specific systems-and-controls weaknesses, alert backlogs, manual processes, configuration problems and human error. In one matter, CBNA London did not report frozen assets to OFSI as soon as practicable on 53 occasions. All were delayed by more than six weeks, 11 were delayed by 518 days, and the average delay was 274 days.

OFSI said it did not consider that CBNA London intended to breach sanctions or sought to circumvent the rules. However, it found that some weaknesses were reasonably foreseeable and could have been identified earlier through more detailed stress-testing and analysis, particularly given the bank’s elevated exposure to Russia-related sanctions risk.

The statutory maximum penalty was £9.86 million, based on the £19.72 million value of the breaches. OFSI set a baseline penalty of £7.89 million, then applied a 20% voluntary-disclosure and cooperation discount and a further 20% settlement discount, reducing the final penalty to £4.73 million. CBNA London voluntarily disclosed the majority of the breaches, cooperated with the investigation and undertook remediation, although OFSI noted that some significant breach groups were not self-reported and some disclosures were delayed or incomplete.

The case provides a detailed example of how sanctions failures can arise not only from list-screening gaps, but from the interaction between KYC data, payment-chain construction, correspondent banking, ownership-and-control analysis, alert handling and frozen-asset reporting. For financial institutions, OFSI’s findings underline the importance of stress-testing sanctions controls against sudden, high-volume designation events rather than assuming systems calibrated for normal conditions will remain effective under severe operational pressure.

Adminrichie

AML Observatory Webmaster, responsible for the website's operations.

Related Articles

Leave a Reply

Back to top button