Trade Intelligence Hub
Trade Intelligence Hub

The Weekly Trade Briefing

← All issues
2026-09-04

Two letters cost Citibank £4.7 million

Their screening system saw "PAO Sovcomflot". The sanctions list said "Sovcomflot". It did not raise a single alert.

On 2 September the Office of Financial Sanctions Implementation published the penalty notice. Citibank N.A., London Branch has been fined £4,732,830.58 for breaches of UK financial sanctions.

WHAT HAPPENED

OFSI imposed the penalty on 11 August 2026 under section 146 of the Policing and Crime Act 2017, for breaches of the Russia (Sanctions) (EU Exit) Regulations 2019 and the Global Anti-Corruption Sanctions Regulations 2021.

In total the bank processed 970 payments worth £19,720,127.43 that OFSI considers were breaches. Most occurred between February and November 2022, in the months after the invasion of Ukraine.

The failures were grouped into eight matters. Three of them are worth any trade professional's attention, because none of them was a decision to break the rules. All three were a control that did not do what everyone assumed it did.

The name did not match. The bank held 32 commercial accounts for 29 entities owned or controlled by PJSC Sovcomflot, the designated Russian shipping company. Its screening system compared its own KYC records, which read "PAO Sovcomflot", against OFSI's consolidated list, which read "Sovcomflot". Because of how the system was calibrated, it did not account for the Russian corporate prefix "PAO" — and so it produced no alerts at all, despite the bank's own records showing the exposure. 328 transactions worth roughly £5.4 million went through.

The money moved faster than the review. Separately, 24 accounts held by 11 companies owned by a designated Russian individual were not promptly restricted. 242 payments worth about £5.9 million were processed. Of that, £4.3 million moved within 24 hours of designation. A backlog had built up in the alert queue at third-level review, where large volumes of potential matches needed manual checking, and some alerts sat unadjudicated for weeks.

A list nobody screened. The bank's automated payment processor chose correspondent banks from an internal routing list. That list included Russian banks that later became designated, and it was not screened against sanctions lists. 19 payments reached Alfa-Bank JSC, PJSC Gazprombank and Credit Bank of Moscow.

There is one more detail that deserves to be read slowly. In May 2022, to cope with alert volumes, the bank temporarily changed its internal guidance so staff no longer had to request a restriction on an account under investigation unless they had evidence of 50% or greater ownership by a designated person. Before that, any account potentially associated with a designated person was restricted on escalation. OFSI found the change increased both the risk of accounts being left unrestricted and how long they stayed that way.

Citibank voluntarily disclosed the majority of the breaches and co-operated with the investigation, earning a 20% discount.

SOURCE

Office of Financial Sanctions Implementation, HM Treasury — Imposition of Monetary Penalty – Citibank, N.A., London Branch, published 2 September 2026; penalty imposed 11 August 2026 under section 146 of the Policing and Crime Act 2017.

WHY THIS MATTERS

You are not a correspondent bank. Read the three failures again anyway, because none of them is about banking.

The first is a name-matching problem. A designated entity was in the records under a local-language corporate prefix, and the screening tool treated it as a different company. Every business screening customers, suppliers, consignees or vessels has that exposure. PAO, OAO, AO, ZAO, OOO, GmbH, SARL — if your tool is matching strings rather than entities, the prefix decides whether you get an alert.

The second is a speed problem. £4.3 million moved in the 24 hours after designation. Designations take effect immediately and are published without warning. If your check on a counterparty happens weekly, or at onboarding and never again, the gap between the list changing and you noticing is the whole risk.

The third is the one most people have. There is a list somewhere in your business — approved hauliers, routing tables, agents, notify parties, group entities — that was assembled once, is used automatically, and has never been screened. Citibank's was inside its payment processor. Yours might be inside your forwarder's booking template.

And the 50% guidance change is the sharpest lesson in the notice. Ownership and control is not a 50% test you apply once. A relaxation made under operational pressure, for sensible-sounding reasons, became an aggravating fact in a multi-million pound penalty four years later.

WHO IS AFFECTED

Any UK business that screens counterparties against the UK Sanctions List — which, since the strict liability standard came into force on 15 June 2022, means any business that could deal with frozen funds or make funds available to a designated person, whether or not it knew. Exporters and importers with Russian, Belarusian or third-country routings, freight forwarders selecting carriers and agents, and anyone relying on a bank or forwarder to catch it for them.

Voluntary disclosure earned Citibank a 20% reduction. That option exists for you too, and it is worth more before OFSI finds it than after.

Stop tracking these changes by hand. The Trade Intelligence Hub turns tariff, customs and compliance shifts like these into a live cockpit for your business.

See plans & pricing → Book a demo or speak to our team →