News / Citibank’s £4.7M OFSI Fine Exposes Gaps in Sanctions Screening and Payment Controls
Citibank’s £4.7M OFSI Fine Exposes Gaps in Sanctions Screening and Payment Controls
OFSI found that screening gaps, name-matching failures, alert backlogs and payment-control weaknesses allowed 970 payments linked to sanctions breaches to proceed.05 min read
The UK’s Office of Financial Sanctions Implementation (OFSI) has imposed a £4,732,830.58 penalty on Citibank, N.A., London Branch (CBNA London) after identifying weaknesses in sanctions screening, alert management and payment controls. The penalty, imposed on 11 August 2026 and published on 2 September, relates primarily to Russia sanctions breaches between February and November 2022, alongside additional breaches through 2025.
OFSI found that CBNA London processed 970 payments with a cumulative value of £19.72 million in circumstances that breached financial sanctions. The findings covered corporate banking accounts, correspondent banking, internal account charges, payment processing and a principal paying agent role, highlighting weaknesses across multiple stages of the sanctions control process.
Name-Matching and Screening Gaps Allowed Sanctioned Payments to Proceed
One of the clearest screening failures involved PJSC Sovcomflot, where a naming variation prevented the bank’s screening system from generating an alert. CBNA London’s KYC records used “PAO Sovcomflot,” while the OFSI designation listed “Sovcomflot.” The mismatch contributed to 328 transactions worth approximately £5.4 million being processed before the relevant accounts were restricted. The case demonstrates how differences between customer-record names and sanctions-list entries can create a screening blind spot when name matching controls do not adequately account for variations.
The case also shows how screening alerts must translate into timely account restrictions and payment controls. CBNA London failed to promptly restrict 24 accounts linked to a designated Russian individual, resulting in 242 payments worth approximately £5.9 million being processed. OFSI attributed several failures to sanctions alert backlogs, manual processes, incorrect ownership determinations and weaknesses in identifying subsidiary companies connected to designated persons.
OFSI attributed several failures to sanctions alert backlogs, manual processes, incorrect ownership determinations and weaknesses in identifying subsidiary companies connected to designated persons.
Correspondent banking controls presented another weakness. Payment systems could add correspondent banks after initial screening without re-screening the complete payment chain. In other cases, designated banks were identified only through Bank Identification Codes (BICs), which had not been adequately incorporated into internal screening data. These findings show why sanctions controls need to account for both entity names and relevant identifiers, while screening payment information whenever material changes are introduced.
OFSI Findings Extend Beyond Name Screening
OFSI assessed the case as Level 4, its highest seriousness rating, citing the aggregate value of the breaches, repeated failures, weaknesses in systems and controls, and their impact on the effectiveness of the sanctions regime.
The regulator also noted that 53 frozen-asset reports were not submitted as soon as practicable, with delays exceeding six weeks in every case and reaching 518 days in 11 instances.
CBNA London voluntarily disclosed most of the breaches and cooperated with the investigation. OFSI applied a 20% voluntary disclosure and cooperation discount and a further 20% settlement discount, reducing the baseline penalty to £4.73 million.
What this Means for Compliance Teams
The Citibank case demonstrates why sanctions screening needs to go beyond a basic name comparison. Effective controls should account for name variations, aliases, ownership and control relationships, identifiers such as BICs, and changes to payment chains. Screening should also be supported by processes that ensure alerts are investigated, escalated and translated into timely restrictions when a potential sanctions match is identified.
The Sovcomflot finding is particularly instructive: a discrepancy between the name in KYC records and the name on the sanctions designation was sufficient to prevent an alert from being generated. For compliance teams, this highlights the importance of screening technology that can identify relevant name variations while maintaining appropriate controls around identifiers and entity relationships.
The broader lesson is that sanctions compliance is a connected control process. Accurate matching must lead to effective alert handling, investigation, escalation and payment controls. A screening system that identifies names but fails to account for relevant variations, identifiers or changes in payment information can leave material gaps in the control framework.
- September 3, 2026
06 min read
- September 1, 2026
04 min read
Subscribe to our Newsletter
Our best articles, news and stories, delivered to your inbox every week.