OFSI fined Citibank's London branch £4.73m for 970 payments that breached UK sanctions. What the notice says about screening, ownership tests and reporting.
Table of contents
The Office of Financial Sanctions Implementation imposed an OFSI penalty of £4,732,830.58 on Citibank, N.A., London Branch for 970 payments worth £19.72 million that breached UK sanctions. The notice, published on 2 September 2026, traces the breaches to screening gaps, alert backlogs and an unreasonable ownership determination.
- The OFSI penalty was imposed on 11 August 2026 under section 146 of the Policing and Crime Act 2017, and OFSI published the notice on 2 September 2026.
- OFSI rated the case Level 4, its highest seriousness tier, with High severity and Aggravating conduct.
- A screening system missed "PAO Sovcomflot" in KYC records because it did not account for the Russian corporate prefix, leaving 32 accounts unrestricted.
- An alert backlog and one ownership call OFSI found unreasonable left 24 accounts of companies owned by a designated individual unrestricted while 242 payments of about £5.9 million went through.
- CBNA London received a 20% disclosure and co-operation discount, not the maximum 30%, plus 20% for settling within 30 business days.
What did OFSI find against Citibank London?
The OFSI penalty on Citibank, N.A., London Branch rests on findings that it dealt with frozen funds or made funds available to designated persons across eight separate matters, mostly between February and November 2022. The breaches involved corporate accounts, correspondent banking, internal fees, a note interest payment and alert handling errors, with some running to July 2025.
The public penalty notice cites regulations 11 and 12 of the Russia (Sanctions) (EU Exit) Regulations 2019 and regulation 13 of the Global Anti-Corruption Sanctions Regulations 2021. OFSI accepted there was no intent to breach sanctions, but found that CBNA London should have known or suspected its actions would breach them. That finding mattered because some breaches predate the strict liability regime that began on 15 June 2022.
The most pointed finding concerns ownership. For one of 11 companies owned or controlled by a designated Russian individual, staff treated the stake as a minority one, and OFSI said "the conclusion of minority ownership was not a reasonable one to draw" from the information the bank held. A backlog at third level review delayed restrictions on the rest. Around £4.3 million of the 242 payments from those companies' accounts, worth about £5.9 million in total, went through within 24 hours of designation, which OFSI treated as strongly mitigating. The remainder ran on for weeks.
| Item | Detail |
|---|---|
| Penalty imposed | 11 August 2026 |
| Notice published | 2 September 2026 |
| Amount | £4,732,830.58 |
| Payments in breach | 970, worth £19,720,127.43 |
| Statutory maximum | £9,860,063.72 (50% of breach value) |
| Baseline penalty | £7,888,050.97, 80% of the maximum (Level 4 guidance: at or above 75%) |
| Discounts | 20% disclosure and co-operation, 20% settlement |
| Seriousness | Level 4 |
How did the screening controls fail?
The conduct behind the Citibank London OFSI penalty failed at the joins between systems rather than at a single list lookup. Names in KYC records did not match list entries, BIC codes were missing from internal lists, payment chains were screened before correspondent banks were added, and account restrictions did not stop internal debits.
A legal form prefix defeated name matching
The screening system perceived a material difference between "Sovcomflot" on OFSI's consolidated list and "PAO Sovcomflot" in the bank's own KYC records. It produced no alerts, so 32 accounts held by 29 entities owned or controlled by PJSC Sovcomflot stayed unrestricted while the bank processed 328 transactions worth about £5.4 million.
Correspondent banks were added after screening
An automated processor selected correspondent banks from an internal list that was not screened against sanctions lists at the time, and the full chain was not re-screened once banks were added. Nineteen payments reached Alfa-Bank, Gazprombank and Credit Bank of Moscow this way. A further 165 payments went through because internal list entries lacked the designated banks' BICs, the only identifier in the SWIFT messages. The largest share, 14 payments worth about £4 million, was screened before CBNA London itself was added to the chain, so staff missed the UK nexus.
Backlogs and a looser escalation rule
After the 2022 designation wave, alerts sat unadjudicated at third level review for several weeks. In May 2022 the bank temporarily stopped requiring staff to request restrictions on accounts under investigation unless they had evidence of 50% or greater ownership by a designated person. OFSI said that change increased both the risk and the duration of unrestricted accounts.
| Breach group | Payments | Approximate value | Root cause named by OFSI |
|---|---|---|---|
| Companies owned by a designated individual | 244 | £5.9 million, plus two payments over £600,000 | Alert backlog, wrong ownership call |
| Sovcomflot-owned entities | 328 | £5.4 million | "PAO" prefix not matched |
| Internal charges and corrections | 177 | £135,000 | Restriction type allowed bank debits |
| Russian correspondent banking | 204 | £6 million | Unscreened routing lists, missing BICs, screening before the chain was complete, point to point returns |
| Alert mishandles | 9 | £500,000 | Handler errors |
| Note interest payment | 1 | £1.5 million | Escalation not followed |
| Global Anti-Corruption payments | 10 | £300,000 | Escalation sent to the wrong team |
Group figures are as described in the notice. Neither the payment counts nor the values reconcile exactly with OFSI's headline of 970 payments and £19.72 million, and the notice itself gives the first group as £5.3 million in its case assessment.
What does this OFSI penalty mean for your obligations?
This OFSI penalty maps onto five duties UK firms already hold: screening that matches how customers are recorded, an ownership and control test that goes beyond percentages, restrictions that stop bank-initiated debits unless a licence covers them, prompt and annual reporting of frozen funds, and evidenced checks before relying on a general licence.
Screening and KYC data quality
Screening only works on the data KYC captures. If customer records store legal names with a corporate form prefix such as PAO, OOO or AO, matching logic must normalise those forms before comparison. Internal routing tables, correspondent lists and BIC directories are screening objects too, and a payment chain needs screening again after any party is added. Our sanctions screening guide covers list and matching design.
Ownership and control versus the UBO test
UK customer due diligence and UK sanctions use different thresholds. Under regulation 5 of the Money Laundering Regulations 2017, a beneficial owner is an individual who holds more than 25% of shares or voting rights or otherwise controls the company. Under regulation 7 of the Russia Regulations, a company is owned or controlled by a designated person, which may itself be a company, holding more than 50% of shares or voting rights or the power to appoint a majority of the board, or where it is reasonable to expect that person could ensure its affairs follow their wishes. A CDD map that records only the individuals at the top can miss a designated company, such as PJSC Sovcomflot, in the middle of the chain. The US differs again: OFAC's FAQ 398 says entities controlled, but not 50% or more owned, are not automatically blocked.
Restrictions and frozen asset reporting
A restriction that blocks customer debits but lets the bank take its own fees or bulk-correct interest can still breach the freeze, as 177 transactions here did. A general licence for routine fees may cover some of those debits, subject to the prior checks described below. Regulation 70 requires relevant firms to tell the Treasury as soon as practicable when they know, or have reasonable cause to suspect, that a person is a designated person, and where that person is a customer, to state the funds they hold. OFSI found 53 reports delayed by more than six weeks, averaging 274 days. Separately, regulation 70(4A) requires anyone who knows, or has reasonable cause to suspect, that they hold funds of a designated person, including funds of a company the designated person owns or controls within regulation 7, to report holdings as of 30 September by 30 November, so the 30 September 2026 snapshot is imminent.
General licences and voluntary disclosure
OFSI expects firms to confirm a general licence applies before a payment and to keep records of that check. Because no alert fired, CBNA London made no prior assessment, and the after-the-fact reconstruction prolonged the investigation. On disclosure, OFSI's enforcement guidance offers up to 30% for prompt, complete reports. Two undisclosed breach groups worth about £6.9 million, late disclosures and materially incomplete reports cost CBNA London a third of that available discount.
What is still uncertain after the Citibank penalty?
The main uncertainty after this OFSI penalty is how the regulator will judge ownership calls that rely on incomplete information. The notice calls the branch's minority ownership conclusion on one entity unreasonable, but does not set out the evidence, so firms cannot yet see where a defensible judgment ends and an aggravating one begins.
Foreseeability sets a high bar
OFSI concluded the Sovcomflot matching gap and the unscreened correspondent list were reasonably foreseeable, and said stress testing before February 2022 might have exposed them. That standard asks firms to test their controls against a designation wave that has not happened yet. For any firm with concentrated exposure to one jurisdiction, the question is what evidence of prior analysis will satisfy OFSI next time.
Surge capacity as a control
OFSI accepted that the 2022 packages created serious operational strain, and said this context did not excuse the breaches. It also said it does not necessarily expect automated screening to stop payments made very close to designation. Where that tolerance ends is unclear. Here, payments within 24 hours of designation were strongly mitigated, while breaches that ran for weeks of backlog were not.
Group operations and branch liability
Staff in the wider Citi group, acting for the London branch, made several of the errors. The UK branch still carried the OFSI penalty. The notice also shows a limit: OFSI did not treat 106 payments made before strict liability as breaches, on facts where a non-UK Citi entity rather than the branch selected the designated correspondent bank. After 15 June 2022 that distinction may carry less weight. Firms that run sanctions operations from shared service centres should expect OFSI to attribute failures by group staff acting for them locally, and should check that UK specific designations and guidance reach offshore teams.
Settlement and publication
CBNA London waived ministerial review and appeal as a condition of settlement, and could input into the published summary. The detail still became public, including the disclosure shortfalls. OFSI says settlement allows compliance messages to be published sooner, so a settled OFSI penalty should be treated as a public outcome.
How does the Citibank OFSI penalty compare with earlier cases?
The Citibank OFSI penalty is the largest on OFSI's enforcement list since Standard Chartered's £20.47 million penalty in February 2020, and far above every other 2026 action. It is also the only 2026 case with breaches spanning two sanctions regimes, Russia and global anti-corruption.
| Date listed | Firm | Sector | Penalty |
|---|---|---|---|
| 2 September 2026 | Citibank, N.A., London Branch | Banking | £4,732,830.58 |
| 17 June 2026 | Sabre Global Technologies Limited | Technology | £1,000,920.59 |
| 19 May 2026 | Deutsche Bank AG London Branch | Banking | £165,000 |
| 30 March 2026 | Apple Distribution International Limited | Technology | £390,000 |
| 26 January 2026 | Bank of Scotland PLC | Banking | £160,000 |
| 20 March 2025 | Herbert Smith Freehills CIS (Moscow) | Legal | £465,000 |
| 18 February 2020 | Standard Chartered Bank | Banking | £20.47 million |
Three of the five OFSI penalty notices from 2026 on OFSI's enforcement page target banks, and all five cite the Russia Regulations. The Citibank notice closes with guidance aimed at any firm using automated screening. Our note on OFAC's Rice Lake settlement shows US enforcers probing the same gap between group structures and local controls.
How should compliance teams respond?
Compliance teams should treat this OFSI penalty as a test script, starting with name matching against legal form prefixes and transliterations drawn from their own customer records. Then confirm that every routing table and correspondent list is screened, that payment chains are screened again after routing, and that BICs are populated on internal list entries.
Next, document how analysts reach ownership and control decisions, including the control limb of regulation 7, and require escalation where information is incomplete rather than a default to minority ownership. Check that account restrictions freeze bank-initiated debits and bulk corrections. Prepare this year's frozen asset report on 30 September holdings. Our pieces on sanctions screening false positives, alert triage and UBO mapping cover the backlog and ownership sides.
Ownership calls are only as good as the structure behind them. Zyphe resolves beneficial ownership recursively across 240+ corporate registries worldwide and keeps an exportable audit trail of how each result was reached. Our KYB software and AML software pages explain how. Book a demo.
The bottom line
The Citibank OFSI penalty shows that sanctions failures often begin before the list lookup: in customer records that store names differently from the list, in ownership judgments made without the full structure, and in controls nobody stress tested before volume arrived. KYC and KYB teams own much of that data, and its structure decides whether screening works.
Cited sources
- OFSI, Imposition of Monetary Penalty, Citibank, N.A., London Branch, public penalty notice
- OFSI, Enforcement of financial sanctions, list of penalties and disclosures
- The Russia (Sanctions) (EU Exit) Regulations 2019, regulation 7, meaning of owned or controlled directly or indirectly
- The Russia (Sanctions) (EU Exit) Regulations 2019, regulation 70, finance reporting obligations
- The Money Laundering, Terrorist Financing and Transfer of Funds Regulations 2017, regulation 5, meaning of beneficial owner
- OFSI, Financial Sanctions Enforcement and Monetary Penalties Guidance, version of 9 February 2026
- Policing and Crime Act 2017, section 146, power to impose monetary penalties
- OFAC, FAQ 398, entities controlled but not majority owned by blocked persons
Michelangelo Frigo (Co-Founder at Zyphe) Michelangelo Frigo is a privacy and identity infrastructure expert and co-founder of Zyphe.