The London branch of Citibank has been fined £4.7m by the UK’s Office of Financial Sanctions Implementation (OFSI) after processing 970 payments worth £19.7m that breached UK financial sanctions relating primarily to Russia.

The majority of the breaches took place between February and November 2022, following Russia’s invasion of Ukraine and the rapid introduction of new sanctions.

This latest sanctions breach is a reminder that even sophisticated financial institutions can struggle when compliance controls rely on fragmented systems, manual processes and outdated assumptions. Here’s what compliance teams can learn from the case.

In its public penalty notice, OFSI acknowledged that the scale and speed of those sanctions created significant operational challenges for firms with Russian exposure but it also found that Citi’s issues went beyond the inevitable pressure of changing regulations.

What went wrong at Citi?

The scale of the Russia-related sanctions response put significant pressure on Citi’s alert handling and investigation processes.

One of the clearest examples involved 24 commercial bank accounts belonging to 11 companies controlled by a designated Russian individual. The accounts were not restricted promptly after the individual was designated.

Around £5.9m passed through those accounts, with approximately £4.3m processed within the first 24 hours of the designation. Then, in May 2022, Citi temporarily changed its guidance so accounts under investigation did not need to be restricted unless there was evidence that a designated person owned 50% or more of the company. OFSI found that this increased the risk that accounts would remain unrestricted for longer.

What’s more, Citi’s screening system did not generate an alert for Sovcomflot because there was a material difference between the name on the OFSI sanctions list and the name held in Citi’s records. The screening configuration did not account properly for the Russian corporate prefix “PAO” used in the company’s name. This contributed to 328 transactions involving 32 accounts and 29 entities, worth around £5.4m, being processed. OFSI also found that Citi had delayed frozen asset reporting by more than six weeks on 53 occasions. In the most extreme case, the delay was 518 days, while the average delay across those cases was 274 days.

What could have been done differently?

The OFSI findings point to several areas where Citi could have reduced the risk of these breaches.

Prepare for increased sanctions exposure: Citi had a significant Russia-related customer and payments exposure. That should have triggered a closer review of where its existing controls could come under pressure. When sanctions change quickly, firms need to look at more than the new names being added to a screening list. They need to understand which customers, accounts, payment routes and counterparties could be affected, and whether existing processes can handle the expected increase in activity. OFSI specifically highlighted the importance of firms assessing their sanctions exposure in advance and stress-testing systems and controls.

Test screening against real customer data: The Sovcomflot example shows why testing shouldn’t stop at confirming that a sanctions list is being screened. Firms should test how their screening works against the actual data held in their systems. That means looking at name variations, prefixes, identifiers, ownership information and other fields that could affect a match. The question should be simple: if a sanctioned party’s details look different in our system, will we still identify them?

Reduce reliance on manual queues: The alert backlog was a major factor in the account restriction failures at Citi. Firms can’t always avoid manual investigation, particularly for complex sanctions cases. But they can identify where manual queues are creating delays and set clear escalation points when cases aren’t reviewed within the expected timeframe. A sanctions alert sitting unresolved for weeks should not become normal operating practice.

Give teams clear ownership and escalation routes: Several findings involved information not reaching the right team or decisions being made using incorrect or conflicting guidance. Clear ownership matters as teams need to know who makes the final decision, where a case should be escalated and what happens when information from different parts of the business doesn’t agree. That becomes even more important when sanctions activity increases and multiple teams are handling related cases.

Test the process from start to finish: Perhaps the biggest change would have been to test the entire sanctions process rather than individual controls in isolation. Start with a customer or payment that presents a sanctions risk and follow it through the business. Does the screening system identify it? Does the alert reach the right person? Can they access the ownership and customer information they need? Is the account restricted quickly enough? Can the payment be stopped? Is the decision recorded? Are any required reports submitted on time?

Running those scenarios before a major sanctions event can expose gaps that routine control testing may miss. For compliance teams, that’s the real lesson from the Citi case. Don’t only test whether each control works. Test whether the controls work together when the business is under pressure.

Keep sanctions checks moving with ID-Pal

Screen customers and businesses against sanctions lists without the manual workload.