- Enforcement
- Financial Crime
- Cross-Border Compliance
The name the screen could not match
The UK's sanctions enforcer fined Citibank's London branch £4.73 million after its screening system decided that "Sovcomflot" and "PAO Sovcomflot" were different companies. In the strict-liability era, a calibration gap like that is all it takes.

UK OFSI · HM Treasury · Russia & Anti-Corruption Sanctions
- Sanctions list
- Sovcomflot
- Bank's KYC record
- PAO Sovcomflot
≠ treated as different · no alert
- £4.73m
- penalty imposed
- 20%
- discount for voluntary disclosure
- Feb to Nov 2022
- core breach window
The bank's system saw "PAO Sovcomflot" in its own customer records and "Sovcomflot" on the Treasury's consolidated list, decided they were different entities because it did not account for the Russian corporate prefix, and never raised an alert.
Source: RegLabs / OFSI penalty notice
Overview
On 11 August 2026, the Office of Financial Sanctions Implementation, the arm of HM Treasury that enforces UK financial sanctions, imposed a penalty of £4,732,830.58 on Citibank, N.A., London Branch. The breaches were of two regimes: the Russia sanctions regulations and the Global Anti-Corruption Sanctions Regulations. They clustered in the nine months after Russia's invasion of Ukraine in February 2022, a period in which the UK designated Russian individuals, companies and banks at a pace and volume the system had never seen. Citi's controls did not keep up, and the bank processed hundreds of payments involving frozen funds and designated entities that should have been stopped.
This was not evasion. OFSI accepted that Citi did not set out to circumvent sanctions; the breaches came from systems-and-controls gaps and human error under extraordinary strain. The bank voluntarily disclosed most of them and cooperated with the investigation, which earned it a 20 percent discount, reducing a penalty of roughly £5.9 million to the £4.73 million imposed. But the size and specificity of the findings make this one of OFSI's largest penalties, and one of the most detailed public maps of how sanctions compliance actually breaks inside a global bank.
The single thread running through the report is a screening system that could not reliably recognise the names it existed to catch, backed by manual processes that buckled under the post-invasion surge. The most emblematic failure is almost absurdly small: the bank's system saw "PAO Sovcomflot" in its own customer records and "Sovcomflot" on the Treasury's consolidated list, decided they were different entities because it did not account for the Russian corporate prefix, and never raised an alert. What follows is what OFSI found, why it happened, the pitfalls every firm that touches cross-border payments shares, and how OFSI's rising enforcement fits the wider sanctions picture.
- Penalty
- £4.73mafter 20% discount
- Regimes
- Russia + GACs.146 PACA
- Nature
- Controlsno intent to evade
- Trigger
- 2022 surgepost-invasion
OFSI accepted that Citi did not set out to circumvent sanctions; the breaches came from systems-and-controls gaps and human error under extraordinary strain.
Source: RegLabs / OFSI penalty notice
Infringements
OFSI found breaches of both regimes under section 146 of the Policing and Crime Act 2017. Under the Russia regulations, Citi failed to promptly restrict the accounts of designated persons and then dealt with frozen funds and made funds available in breach of the prohibitions. The two largest tranches speak for themselves: 24 accounts held by 11 companies owned or controlled by a designated Russian individual were not restricted in time, and the bank processed 242 payments worth about £5.9 million through them; and 32 accounts held by 29 entities owned or controlled by the designated shipping group PJSC Sovcomflot were likewise left open, running 328 transactions worth about £5.4 million.
The breaches reached across correspondent banking and even the bank's own charges. Citi processed correspondent-bank payments to or for designated Russian financial institutions, including Alfa-Bank, Gazprombank, Credit Bank of Moscow, Rosbank and the Ural Bank for Reconstruction and Development, across several tranches, plus around £4 million of correspondent payments between companies owned by a designated individual. It also deducted its own fees and tax charges from the accounts of designated persons, roughly £135,000 across 177 internal-charge transactions. Separately, under the Global Anti-Corruption Sanctions Regulations, it processed about £300,000 of payments in 2025 for or between companies owned or controlled by a designated individual.
One episode shows the control chain failing from end to end. Acting as principal paying agent for loan participation notes issued by a special-purpose vehicle that became connected to a designated person, Citi received an interest payment through a correspondent bank and, months later, returned it, which OFSI determined indirectly made funds available to a designated person. An alert had actually fired on the notes; staff did not escalate it because they did not realise the vehicle was owned or controlled by a designated person; and an earlier escalation on the same exposure had been sent to the wrong team, was never redirected, and was closed with no action. The detection worked. Everything after it did not.
Value of payments OFSI assessed as breaches, by category (£m) · source: RegLabs / OFSI penalty notice
These are OFSI's assessed values by category and are not additive to the penalty. Further correspondent-bank payments to designated Russian banks (Alfa-Bank, Gazprombank, Rosbank, Ural Bank, Credit Bank of Moscow) across some 190 payments were also assessed as breaches.
Analysis
The root cause is screening that could not match names. OFSI's headline example is the Sovcomflot mismatch: the system treated the list entry "Sovcomflot" and the customer record "PAO Sovcomflot" as materially different because its calibration did not account for the Russian corporate prefix, so no alert was produced even though the bank's own records showed the exposure. Sanctions screening lives or dies on fuzzy matching across transliteration, aliases and corporate prefixes, the PAO, OAO, PJSC and OOO forms that pepper Russian entity names, and Citi's configuration had a gap exactly there.
The list behind the screen was also incomplete. An automated payment processor selected correspondent banks from an internal list that was not itself screened against sanctions lists, so payments routed to banks that had since become designated. And internal list entries had not been enriched with the designated banks' identifying codes; even after those codes were added in April 2022, a human error left one bank, the Ural Bank for Reconstruction and Development, off the list until later. A screening engine is only ever as good as the reference data feeding it, and here the data was stale, unscreened and incomplete.
Then sheer volume broke the manual processes. The post-invasion wave of designations produced enormous alert volumes; a backlog built at the third level of review, alerts sat unadjudicated for weeks, and the manual work of identifying, restricting and segregating accounts ran weeks or months beyond the bank's own targets. Processes that function in ordinary conditions collapse under a spike, and a sanctions spike arrives at precisely the moment the risk of a breach is highest. The strain was real, but strain is foreseeable, and OFSI pointedly concluded that several of the weaknesses could have been identified sooner through stress-testing in the run-up to February 2022.
The human layer failed in parallel. The loan-participation-notes alert was identified but not escalated because staff did not recognise the designated ownership; an initial escalation went to the wrong team and was quietly closed; and staff administering payments did not share information with colleagues who could have stopped a breach. Determining whether a remitter was owned or controlled by a designated person, the ownership-and-control question at the heart of sanctions, took months in one case while the payments kept flowing. Escalation routes that depend on an individual noticing the right thing and reaching the right desk are fragile, and under volume they fail.
One decision stands out as self-inflicted. In May 2022, under operational strain, Citi temporarily changed its guidance so that staff did not have to restrict an account under investigation unless there was evidence of 50 percent or greater ownership by a designated person. Loosening a control at the exact moment volume and risk were peaking is the opposite of what the situation demanded, and it lengthened the window in which accounts stayed open. The lesson OFSI draws is uncomfortable but clear: the surge did not create the breaches so much as expose control gaps that were already there, and in one case a control the bank chose to relax.
Practical Insights
Because sanctions compliance fails in such consistent ways, the fixes are well understood, and the control expectations RegLabs derives from this case read as a checklist any firm handling cross-border payments could run against itself. Four pitfalls recur, and each one appears in the Citi file.
Pitfall 1: the name your screen cannot match Transliteration, aliases and corporate prefixes are where screening quietly fails. The control is fuzzy matching tuned and tested against the real variants of designated names, including the versions sitting in your own KYC records, and an alias and prefix library that recognises that "PAO Sovcomflot" and "Sovcomflot" are the same entity. Test it with known designated names and their variants, and measure false negatives, not just false positives.
A second pitfall is the list behind the screen. A screening engine only checks what it is pointed at, so the reference data has to be current, complete and itself screened. That means daily list updates from official sources, enrichment of entries with identifying codes and known owned-or-controlled entities, and, critically, screening the internal and correspondent-bank lists that payment routers draw on. Citi's unscreened internal correspondent list and its missing bank code were not exotic failures; they are the routine gaps a reconciliation control is built to catch.
Third is capacity that collapses under a spike. Sanctions risk is not steady; it arrives in geopolitical shocks that flood the system with designations and alerts overnight. Alert-handling, ownership-and-control investigation and account-restriction capacity have to be built, and automated, for the surge rather than the average day, because a backlog at peak risk is the failure mode. And the instinct to relax a control under strain, as Citi did with its 50 percent guidance change, is exactly backwards: the moment to tighten is the moment volume spikes.
Fourth is ownership, control and escalation. Much of the Citi exposure ran through entities owned or controlled by designated persons rather than the designated persons themselves, which is where sanctions risk actually hides. Firms need a fast, defined process to resolve ownership and control, the 50 percent and control tests applied to real corporate structures, and an escalation route to sanctions specialists that cannot be defeated by a single person sending a case to the wrong team. The alert that fired on the loan participation notes shows detection is rarely the problem; acting on it is.
Thematic Review
The first thing the wider data shows is that Citi's failure is OFSI's signature finding. Across the regulator's book of sanctions cases, screening failures dominate: they appear in most of its penalised matters and account for essentially all of the penalty value it has levied. Every control that broke at Citi, the screening calibration, the escalation route, the alert-handling capacity, the underlying technology and reference data, is a repeat entry in OFSI's findings. A firm reading this penalty notice is not looking at a one-off; it is looking at the pattern the UK's sanctions enforcer keeps finding.
Control areas cited across OFSI's sanctions cases · source: RegLabs
Cases carry multiple tags, so these overlap. Sanctions-screening failures appear in the large majority of OFSI's sanctions cases and drive nearly all of the value it has penalised.
The second theme is that OFSI is a small enforcer that is now flexing. Measured globally, sanctions enforcement is a US story by a wide margin: the Department of Justice, New York's DFS, OFAC and FinCEN have levied billions, dwarfing everyone else. OFSI's total across all its cases is a rounding error against those figures. But two things changed the calculus. Russia's 2022 invasion created an enormous compliance surface almost overnight, and from June 2022 OFSI gained the power to impose penalties on a strict-liability basis, without having to prove the firm knew or suspected it was breaching sanctions. Citi's £4.73 million sits among OFSI's largest penalties, and the direction of travel is up.
Catalogued sanctions actions by regulator (case count) · source: RegLabs
By penalty value the gap is even wider: the DOJ has levied roughly $15.5bn and OFAC about $6.2bn across their catalogued sanctions cases, against OFSI's total of around $37m. Volume, not value, is where OFSI now shows up, and its post-2022 penalties are climbing.
The third theme is what the strict-liability era means in practice, and the Citi case is its template. OFSI accepted there was no intent to evade, and still imposed a multi-million-pound penalty, because strict liability makes the control itself the point. "We did not mean to" is no longer a defence; what matters is whether the screening matched the name, whether the list was complete, whether the capacity held under load, and whether the escalation reached the right desk. For any institution running cross-border payments or correspondent banking, that reframes sanctions compliance from a question of intent to a question of engineering.
And the direction of travel is unmistakable. Sanctions lists have become dynamic and fast-moving, and the next geopolitical shock will again designate at speed, flooding screening systems and alert queues overnight. The firms that come through the next wave will be the ones that have treated screening calibration, reference-data hygiene, surge capacity and ownership-and-control resolution as tested, evidenced, engineered controls rather than as policies in a binder. The ones relying on manual heroics under strain, or quietly relaxing a control when the volume spikes, will write the next penalty notice.
Find the mismatch before OFSI does
Engineer your sanctions controls for the next surge
A single unmatched prefix, an unscreened internal list, an alert sent to the wrong team: the failures behind a multi-million-pound penalty are specific, repeatable and visible across the enforcement record. In the strict-liability era, the control is the whole game, and it can be tested in advance. RegLabs turns the global sanctions record into a working assessment.
- Automate regulatory review across sanctions, screening, correspondent-banking, escalation and reporting obligations, mapping every designation wave and rule change to the controls it touches.
- Systematise risk assessment by benchmarking your screening calibration, list and reference-data hygiene, surge capacity and ownership-and-control process against the precise gaps regulators keep citing.
- Simulate an examination on sanctions controls for your own firm, using RegLabs models to surface the questions OFSI, OFAC or the FCA would ask next.
This article is an independent editorial summary for information only and is not legal or compliance advice. OFSI accepted that the firm did not seek to circumvent sanctions and applied a 20% discount for voluntary disclosure and cooperation.
