What we can Learn from Citibank's £4.7 million OFSI fine
What we can Learn from Citibank's £4.7 million OFSI fine

Hello dear readers, it has been a long time since my last article on this site. It turns out, moving to London and setting up a new life has been an all-consuming adventure. Though the US and the UK may share a common language, there are plenty of differences to sort through while setting up shop in a new country! But enough about my move across the pond, let's now turn to the wonderful world of sanctions, where the UK's Office of Financial Sanctions Implementation ("OFSI") has continued its banner year. This time, it was Citibank's London entity that was in the crosshairs.
What Happened?
OFSI fined Citibank N.A., London Branch ("Citibank") £4.73 million for breaches of UK financial sanctions. In short, Citibank processed 970 payments to sanctioned Russian entities, worth approximately £19.7 million, between February 2022 and July 2025. These payments were processed in the wake of Russia's invasion of Ukraine, and ran afoul of the deluge of sanctions designations that followed suit. From reading OFSI's release, Citibank seemed to have been overwhelmed by the sheer volume of designations. OFSI specifically called out Citibank for the following lapses:
- The screening software missed a match because of a three-letter Russian corporate prefix.
- Citibank's sanctions screening system treated two names for the same sanctioned entity as two materially different entities due to the inclusion of a common Russian prefix in the bank's KYC records. OFSI’s consolidated list showed the designated name as "Sovcomflot," while Citibank's internal records listed the same company as "PAO Sovcomflot." Because Citi's screening system lacked the flexibility to properly account for a common Russian corporate prefix (“PAO"), it did not produce the alerts it should have.
- Alerts that did materialize sat unresolved for weeks.
- The alerts that were triggered accumulated so quickly, and in such a large volume, that Citibank staffers could not keep up. A backlog of potential sanctions matches requiring manual review quickly developed, with OFSI noting that many alerts were not resolved for several weeks.
- Frozen assets were reported an average of 274 days late.
- Citbank failed to promptly report frozen assets to OFSI on 53 occasions, with a delay of over six weeks in all of those cases and, in 11 cases, a delay of a whopping 518 days. The average time between Citibank having "reasonable cause to suspect" that it held frozen funds and submitting the relevant report to OFSI was 274 days.
Compliance Lessons
Employees must understand reporting obligations
Freezing designated accounts only fulfills half of a bank's compliance obligations. Freezing must be followed by reporting, which OFSI expects will be done "as soon as practicable." Relevant employees should have been aware of this expectation and ensured timely reports were submitted. Reporting responsibility should be clearly assigned and employees that may become involved with account freezing should know if anyone else needs to be notified. Citibank's belated reporting of frozen accounts ultimatley compounded its penalty, as OFSI treated Citibank's 274-day average reporting delay as an aggravating factor when calculating its fine.
Screening Systems Need More Testing
The fact that the screening system in this case missed a designated entity's name due to the inclusion of a common corporate prefix indicates that the screening system probably would have benefitted from some additional testing. Though it's impossible to account for every name permutation, screening systems should be robust enough to account for prefixes or suffixes that may be included with corporate names. At the very least, the screening system should have flagged account names that contained "Sovcomflot" - even if those account names may have contained other words too. Here, it seems like the screening tool only flagged account names that exactly matched "Sovcomflot," and excluded any hits containing words beyond that name. This is where having someone test the screening system would have come in handy. This case also inadvertently highlights the benefits of employing a diverse team. Maybe a Russian speaker would have immediately recognized the "PAO" prefix while testing the bank's screening tool, and would have appreciated the frequency with which it would appear in account names and tweaked the tool accordingly.

Relaxing Controls should be Supported by Risk-Based Decisions
Most of the breaches in this case occurred between February and November 2022, when designations arrived faster than some firms could handle. The "fix" that Citibank implemented to clear the backlog of alerts ultimately became the breach. Specifically, to reduce alert volume, the bank relaxed its own rule by opting to restrict accounts only where there was evidence of designated ownership (as opposed to the original rule requiring restrictions of all escalations).
Controls aren't static. They can often change over time and under new circumstances, but every adjustment should be backed up by a risk-based analysis that is properly documented. In this case, OFSI clearly took the view that relaxing controls in order to deal with an increased alert volume at the height of the Russia sanctions frenzy was not the right call. I would tend to agree with this stance, but Citibank should have at least had a clearly documented explanation of why the controls were relaxed so that it could explain this decision and the thought process behind it when OFSI came knocking.
Final Thoughts
OFSI ultimately assigned this case its highest severity rating (level 4) when determining the penalty it would impose on Citibank - citing aggravating factors that caused severe damage to the goals of the UK's sanctions regime. OFSI conceded that there was no evidence that Citibank intended to breach or circumvent the Russia sanctions, but, at the end of the day, this lack of intent didn't carry much weight. Firms don't have to knowingly violate sanctions in order to be held responsible for doing so. This is why it is important to remain abreast of these regulations, which can evolve rapidly and increase substantially. The relevant employees should also be educated in accordance with their sanctions-related responsibilities and the general population of employees should at least have an elemtary grasp of what sanctions are and which countries are among the most heavily sanctioned. Organizations can only act through their employees, and, ultimately, a well-educated workforce is the best line of defense against violations.

