October 4, 2026 By FinCheck
A bank with one of the largest sanctions compliance operations in the world has just been penalised for the unglamorous failures: a list that lacked identifiers, accounts that stayed open, alerts closed in error and reports that arrived months late. On 11 August 2026 the UK’s Office of Financial Sanctions Implementation (OFSI) fined Citibank N.A.’s London branch £4,732,830.58. If it can happen there, it can happen in your programme.
What OFSI found
The penalty covers 970 payments worth roughly £19.7 million, made between February 2022 and July 2025 in breach of the Russia (Sanctions) (EU Exit) Regulations 2019 and the Global Anti-Corruption Sanctions Regulations 2021. OFSI set a baseline penalty of about £7.9 million and applied a 40% reduction: 20% for voluntary disclosure and 20% for settlement. Roughly £6.9 million of the breaches were not voluntarily disclosed.
The breaches fell into several categories, and none of them is exotic:
- Accounts that should have been restricted. 56 accounts, linked to a designated Russian individual and to PJSC Sovcomflot, were left operating, allowing about £11.3 million in prohibited payments.
- Correspondent routing. Automated systems selected designated Russian banks without rescreening the payment chain, and screening lists lacked Bank Identification Codes.
- Frozen account deductions. 177 transactions, about £135,000, where fees or taxes were taken from restricted accounts.
- Alert handling. Nine payments went through after handler errors, including misapplied sectoral sanctions guidance. A separate anti-corruption alert was escalated to the wrong place and closed.
- Late reporting. Frozen-asset reports to OFSI were late in 53 instances, by an average of 274 days and up to 518 days.
Why this is a controls story, not a sanctions story
OFSI described the control deficiencies as reasonably foreseeable. That phrase matters. The regulator is not asking whether you intended to breach sanctions; it is asking whether a reasonable programme would have caught the gap. A screening list without BICs, or a system that never rescreens an intermediary, is a design flaw someone could have found with a basic test.
The same logic applies in the United States. OFAC is a strict liability regime, and its enforcement guidance treats the quality of a firm’s sanctions compliance programme as a mitigating or aggravating factor. Voluntary self-disclosure remains the largest lever on the penalty, as the 20% discount here shows.
The disclosure and speed lesson
Two numbers in this case deserve a second look. The first is the 274-day average delay in reporting frozen assets. A late report is often the first thing a regulator sees, and it colours how the rest of the file is read. The second is the £6.9 million of breaches that were not voluntarily disclosed. Those are the breaches that carried no discount. Firms that find a problem, size it quickly and tell the authority early keep their options open; firms that wait for the regulator to find it do not.
For smaller firms the practical point is governance. Someone senior should own the sanctions programme, receive monthly testing results and have authority to escalate a suspected breach the same day.
Who should be reading this
This was a global bank, but the failure modes travel down the payments chain. Money service businesses, payment processors, crypto firms and gaming or sweepstakes operators run the same building blocks: a screening list, a matching engine, an alert queue and a restricted-account process. They usually run them with fewer analysts and less testing. Where a sponsor bank, card scheme or payments partner sits above you, expect these lessons to arrive as due diligence questions.
FinCheck’s perspective and way forward
Sanctions failures rarely come from one dramatic mistake. They come from small gaps that nobody owned. Our advice is to treat the Citibank findings as a test plan and work through it in the next 30 days:
- Test screening coverage. Confirm your lists and vendor feeds include BICs, aliases, vessels and ownership-linked entities, and run known designated names through the live system.
- Rescreen the whole payment chain. Check whether intermediaries and correspondents are screened at every hop, not only at onboarding or origination.
- Audit restricted accounts. Reconcile every blocked or frozen account against a written procedure, including fee and tax deductions.
- Sample closed alerts. Re-review a random sample of closed sanctions alerts with a second reviewer and check escalation paths end to end.
- Time your reporting. Measure the gap between a freeze and the report to the authority, and set an internal deadline well inside the legal one.
- Decide your disclosure protocol. Agree in advance who decides on voluntary disclosure, and how quickly, because delay costs the discount.
An independent sanctions and AML review is the fastest way to find these gaps before an examiner or a partner does.
Talk to FinCheck
FinCheck supports MSBs, crypto and FinTech firms, sweepstakes and iGaming operators with Fractional CCO services, AML Independent Audit, AML Program Build, Compliance Outsourcing and Staffing, and MTL Licensing Support. If you would like a sanctions controls health check, message us on LinkedIn.