September 2, 2026: OFSI penalizes Citibank £4.7 million for Russia sanctions breaches


Imposition of Monetary Penalty – Citibank, N.A., London Branch (“CBNA London”)

At a Glance

  • Subject: Citibank, N.A., London Branch (“CBNA London”)
  • Sector: UK branch of Citibank, N.A., operating as a core wholesale and correspondent bank and providing cross-border payments, cash management, multicurrency accounts, and market and securities settlement services
  • Authority: OFSI (HM Treasury), under section 146 of the Policing and Crime Act 2017
  • Date of Penalty: 11 August 2026
  • Penalty Amount: £4,732,830.58 (reduced from a baseline of £7,888,050.97)
  • Sanctions Regime: Russia (Sanctions) (EU Exit) Regulations 2019 and the Global Anti-Corruption Sanctions Regulations 2021
  • Provisions Breached:
    • Russia Regulations, regulation 11 — dealing with frozen funds
    • Russia Regulations, regulation 12 — making funds available
    • GAC Regulations, regulation 13 — making funds available for the benefit of a designated person
  • Designated Persons / Nexus: A designated Russian individual and companies that individual owned or controlled; PJSC Sovcomflot and entities it owned or controlled; the designated Russian financial institutions Alfa-Bank JSC, PJSC Gazprombank, Credit Bank of Moscow, Bank GPB International SA, Russian Agricultural Bank JSC, Amsterdam Trade Bank, Ural Bank for Reconstruction and Development, PJSC VTB Bank, Bank Otkritie Financial Corporation PJSC, Rosbank, Evraz PLC, and AFK Sistema (owner of East-West United Bank SA); a person who became designated after CBNA London’s appointment as Principal Paying Agent for loan participation notes issued by that person’s SPV; and an individual designated under the GAC Regulations. The notice does not give designation dates or unique IDs for these parties.
  • Guidance Applied: 9 February 2026 version of the Financial Sanctions Enforcement and Monetary Penalties Guidance
  • Resolution: Settlement

What Happened

CBNA London operates as the UK branch of Citibank, N.A., serving as a core wholesale and correspondent bank and as a key node in Citi’s global payments network. That footprint gave it particularly high exposure to Russia sanctions risk once the invasion of Ukraine began on 24 February 2022: a Russian client base, correspondent relationships with Russian financial institutions, and payments tied to its former Russian affiliate, AO Citibank.

The breaches surfaced across eight matters spanning payment processing, correspondent banking, and account administration. In total, CBNA London processed 970 payments worth approximately £19.72 million that OFSI considers were breaches of the Russia Regulations or the GAC Regulations.

The largest matter involved corporate clients majority owned by designated persons. CBNA London failed to promptly restrict 24 accounts held by 11 companies owned by a designated Russian individual, processing 242 payments worth roughly £5.9 million in breach of regulation 11. A backlog at the third-level alert review stage left some alerts unadjudicated for weeks. Staff missed internal warnings that the accounts remained unrestricted, and one entity’s ownership was incorrectly assessed as falling below the sanctions threshold. Roughly £4.3 million of the £5.9 million moved within 24 hours of designation. OFSI treated that timing as strongly mitigating, though the payments still counted toward the breach total because further breaches at the same entities followed weeks later. A separate £600,000 moved from an unrelated company to one the individual owned, in breach of regulation 12.

A related failure ran through 32 accounts held by 29 entities owned or controlled by PJSC Sovcomflot (“SCF”): 328 transactions worth about £5.4 million, also breaching regulation 11. Here the cause was more mechanical than procedural. CBNA London’s screening system treated OFSI’s consolidated-list entry, “Sovcomflot,” as a poor match against the bank’s own KYC record, “PAO Sovcomflot,” so the Russian corporate prefix suppressed the alert entirely.

CBNA London also deducted its own fees, taxes, and payment corrections from accounts already restricted pending a true-match determination on designated persons and SCF-linked entities: 177 transactions worth about £135,000, breaching regulation 11 on the debit side and regulation 12 on the credit side. The type of restriction applied to those accounts blocked customer and third-party debits but not the bank’s own internal charges – in substance, the bank kept helping itself to frozen funds while the accounts sat under review. A bulk interest-correction process compounded the problem, running without flagging that a sanctions hold was in place.

Correspondent banking produced four further matters. Between February and June 2022, CBNA London processed 19 payments worth about £26,000 to designated Russian banks acting as correspondents, because an automated payment processor drew correspondent banks from an internal routing list that had never been screened against the sanctions list. Between March and May 2022, a further 165 payments worth about £729,000 breached regulation 12: correspondent banks were identified only by Bank Identification Code rather than name in the payment message, and those BICs had not been added to CBNA London’s screening lists in time. Between September and October 2022, 14 payments worth about £4 million breached regulation 12 after CBNA London itself was added to the correspondent chain post-screening, and staff missed the resulting UK nexus to a designated person. And between August and October 2022, CBNA London processed six return payments worth about £1.2 million to Rosbank and Gazprombank as ultimate beneficiary banks: the return instructions identified only the next bank in the chain, not the designated beneficiaries further along it.

A scattered set of alert-handling errors between March 2022 and February 2025 – nine payments worth about £500,000 – involved staff misreading sectoral guidance, issuing conflicting instructions to colleagues, or failing to follow a licence’s terms. In the highest-value case, an alert handler dispositioned a payment months after the fact and mistook the designated remitter bank for the beneficiary, releasing funds back to the designated person in error.

In November 2022, acting as Principal Paying Agent for loan participation notes issued by an SPV whose beneficial owner later became a designated person, CBNA London received an interest payment through a correspondent bank. It rejected and returned those funds in February 2023. OFSI determined this made funds available indirectly to a designated person – a breach of regulation 12 worth approximately £1.5 million – because staff had identified the relevant alert but failed to recognize the SPV’s ownership and escalate it.

Finally, between January and July 2025, CBNA London processed ten correspondent-banking payments worth about £300,000 connected to an individual designated under the GAC Regulations: nine for that individual’s benefit and one between two companies the individual owned, in breach of regulation 13. CBNA London first flagged the exposure through an unrelated money-laundering alert, but its initial sanctions escalation went to the wrong team, and the case was closed without further action.

CBNA London voluntarily disclosed the majority of these matters; OFSI identified the rest, principally the SCF breaches and the interest payment, through its own inquiries. OFSI issued a Notice of Intention to impose a monetary penalty on 15 June 2026. The parties agreed to enter settlement discussions on 29 June 2026, commencing 1 July 2026, and reached settlement on 11 August 2026, the same day OFSI imposed the penalty. As a condition of settlement, CBNA London agreed to pay the penalty as imposed and waived its rights to a ministerial review and to an appeal to the Upper Tribunal.

The Breaches

  • Russia Regulations, regulation 11 (dealing with frozen funds): Breached by failing to promptly restrict accounts held by companies owned or controlled by a designated Russian individual (242 payments, about £5.9 million) and by entities owned or controlled by PJSC Sovcomflot (328 transactions, about £5.4 million), and by debiting internal fees, taxes, and payment corrections from accounts that were restricted but not yet confirmed as a true sanctions match (part of the roughly £135,000 internal-charges matter).
  • Russia Regulations, regulation 12 (making funds available): Breached by a payment of over £600,000 from an unrelated company to one owned by the designated individual; by internal charges credited to restricted accounts (the remainder of the roughly £135,000 internal-charges matter); by 19 payments (about £26,000) and 165 payments (about £729,000) processed through designated Russian correspondent banks; by 14 payments (about £4 million) where CBNA London itself was added to a correspondent chain after screening; by 6 return payments (about £1.2 million) to Rosbank and Gazprombank as ultimate beneficiaries; and by an interest payment of about £1.5 million returned to a correspondent bank on behalf of a designated person’s SPV.
  • GAC Regulations, regulation 13 (making funds available for the benefit of a designated person): Breached by 10 correspondent-banking payments (about £300,000) connected to an individual designated under the Global Anti-Corruption Sanctions Regulations 2021.

The notice does not specify which regulation the nine alert-mishandling payments (about £500,000) breached, so they are addressed in the narrative and case assessment rather than in this list.

Valuation of the Breach

Total Assessed Value: £19,720,127.43 (970 payments)

  • Corporate clients – designated Russian individual: approximately £6.5 million (£5.9 million under regulation 11, plus a further £600,000+ under regulation 12)
  • Corporate clients – PJSC Sovcomflot-linked entities: approximately £5.4 million (regulation 11)
  • Internal charges on restricted accounts: approximately £135,000 (regulation 11 on debits, regulation 12 on credits)
  • Russia-related correspondent banking: approximately £26,000 (February–June 2022), £729,000 (March–May 2022), £4 million (September–October 2022), and £1.2 million (August–October 2022), all under regulation 12
  • Alert mishandles: approximately £500,000 (regulation not specified in the notice)
  • Interest payment / Principal Paying Agent role: approximately £1.5 million (regulation 12)
  • GAC correspondent banking payments: approximately £300,000 (regulation 13)

OFSI’s Case Assessment

Aggravating Factors:

  • The aggregate breach value was very high, at approximately £19.7 million, and the case involved a very high volume of payments, including repeated lower-value transactions reaching significant totals (Case Factor B).
  • The Russia sanctions regime is a strategic priority for UK foreign policy, particularly following the invasion of Ukraine (Case Factor C).
  • The breaches caused sustained, material harm to the sanctions regimes’ objectives, letting designated persons or their entities access funds, settle obligations, or continue operating, even though OFSI found no intent to undermine the regime (Case Factor D).
  • For breaches occurring after 15 June 2022, CBNA London’s own systems in some cases held information sufficient to catch the breach that was not properly disseminated or acted on; OFSI considered that the bank should have known or suspected its actions would result in a breach (Case Factor E).
  • The systems and controls issues behind many of the breaches, including the Sovcomflot screening gap and the unscreened correspondent-banking lists, were reasonably foreseeable given CBNA London’s known elevated exposure to Russia sanctions risk; OFSI expected more detailed UK-specific preparation than the bank could show (Case Factor F).
  • The incorrect ownership-and-control determination for one entity was not a reasonable conclusion from the information available to CBNA London (Case Factor G).
  • Most matters involved a repeated, persistent, or extended pattern of breaches sharing a common root cause, with the interest payment and alert mishandles as exceptions (Case Factor H).
  • CBNA London failed to report frozen assets to OFSI as soon as practicable on 53 occasions tied to the internal-charges matter, with delays exceeding six weeks in every instance, reaching 518 days in 11 cases, and averaging 274 days.

Mitigating Factors:

  • The internal-charges breaches were generally low in value (Case Factor B).
  • The internal-charges breaches caused comparatively little harm to the sanctions regimes’ aims: they did not make funds available to designated persons directly, involved a type of activity OFSI commonly licenses, and gave CBNA London no meaningful benefit (Case Factor D).
  • The interest payment and the alert-mishandling breaches were not repeated, persistent, or extended (Case Factor H).
  • Proximity to designation was strongly mitigating for the majority of the breaches involving corporate clients owned by the designated individual, where roughly £4.3 million of the £5.9 million total moved within 24 hours of designation.
  • CBNA London undertook a remediation programme addressing the root causes identified and was open in sharing its corrective action plans and progress updates with OFSI.
  • Citi’s decision to withdraw from Russia reduces the risk of future breaches and aligns with the sanctions regime’s aims, though OFSI noted it was not directly related to its investigation.

Neutral Factors:

  • OFSI does not consider that CBNA London sought to circumvent sanctions in any matter; consistent with its published guidance, OFSI does not treat the absence of circumvention as mitigating, so this factor was treated as not relevant (Case Factor A).
  • OFSI considered other case factors either not relevant to the case or, on balance, neither aggravating nor mitigating, without specifying which.

Overall Assessment: OFSI rated the severity of the case as High and CBNA London’s conduct as Aggravating, concluding the case met the criteria for Level 4, the highest rating in its four-tier seriousness framework. OFSI found no intent by CBNA London to breach sanctions, but characterized the errors and failings as material and significant across a wide range of business areas and systems, with the corporate-clients matter especially concerning given how long some accounts remained unrestricted after designation. OFSI also weighed the operational strain created by the unprecedented scale and complexity of the sanctions measures introduced after Russia’s 2022 invasion, without treating that context as an excuse for the breaches.

How the Penalty Was Calculated

  • Total Breach Value: £19,720,127.43
  • Statutory Maximum: £9,860,063.72 (the greater of £1 million or 50% of the estimated breach value)
  • Baseline Penalty: £7,888,050.97 (80% of the statutory maximum; OFSI’s guidance sets a Level 4 baseline at or above 75%)
  • Discount(s) Applied:
    • Voluntary disclosure and co-operation discount: 20%, within a maximum available discount of 30%
    • Settlement discount: 20%, for reaching agreement within the 30-business-day settlement period
    • Combined discount: 40%
  • Final Penalty: £4,732,830.58

The statutory maximum here still uses the pre-existing formula, the greater of £1 million or 50% of the breach value. The Guidance’s proposed increase to the greater of £2 million or 100% of the breach value requires legislation that was not yet in force in this case.

Compliance Lessons

  • Study these failure patterns even outside financial services: firms using similar automated systems or manual escalation processes, not just banks, should examine whether their own controls could produce the same alert-handling delays, screening gaps, or internal-charge oversights identified in this case.
  • Map sanctions-risk exposure to a level of detail that survives real stress: firms with elevated exposure to a specific sanctions risk should carry out detailed prior analysis of where controls might fail once designations spike in volume, rather than relying on general preparedness.
  • General licences authorize exactly what they say, no more: a wind-down licence permits unwinding a relationship with a designated person; it does not cover every payment tied to that person indefinitely. Firms should confirm in advance that a licence applies to a given transaction, document that assessment, and take particular care where they operate accounts on a designated person’s behalf.
  • Voluntary disclosure pays, but only if it is timely and complete: firms can secure up to a 30% discount by self-reporting promptly, providing a full account of the breach, and cooperating throughout the investigation, including providing information beyond what OFSI explicitly requests. Where full disclosure is not immediately possible, an early partial disclosure followed by a fuller report is preferable to delay; in sufficiently complex cases, firms may also want to consider the Early Account Scheme, though CBNA London did not use it here.

Supplemental Information: At £4,732,830.58, this is one of OFSI’s larger civil monetary penalties, though it remains well below the £20.47 million OFSI imposed on Standard Chartered in 2020, still the largest penalty in OFSI’s history. It is larger than the roughly £1 million penalty OFSI imposed on Sabre Global Technologies Limited in June 2026, which press coverage at the time described as the largest OFSI penalty tied to Russia sanctions since the 2022 invasion of Ukraine. The case was decided under OFSI’s four-tier seriousness matrix introduced in its 9 February 2026 Enforcement Guidance, and a Level 4 rating, the framework’s top tier, carries significance beyond the size of the resulting penalty: practitioner commentary on the new framework notes that OFSI may refer Level 4 cases for criminal investigation in the first instance, turning to civil enforcement only if a prosecution does not follow. CBNA London’s case did not take that route; OFSI proceeded directly to a civil monetary penalty resolved by settlement.

Sources

Validation Note

  • All facts trace to the penalty notice itself; no press release or additional guidance PDF was attached to this run, and no unsupported claims were retained.
  • Extraction was done by meaning, not by paragraph position.
  • The penalty-calculation chain reconciles exactly: baseline (80% of the statutory maximum) less a combined 40% discount produces the final penalty to the penny. The component-level breach values across the eight matters, however, sum to roughly £20.3 million rather than the notice’s stated £19,720,127.43, and the notice’s own case-assessment paragraph cites still-different subtotals (approximately £5.3 million and £6 million) for the corporate-clients and correspondent-banking groups that don’t match the per-matter figures given elsewhere. All figures are reproduced as stated; this most likely reflects rounding across several “approximately” figures rather than an error to correct.
  • A minor count discrepancy exists in the notice itself: the corporate-clients/individual matter is described as 242 payments in one paragraph and “the majority of the 244 breaches” in another. Both figures are reproduced as stated.
  • The governing guidance is correctly identified as the 9 February 2026 four-tier framework, and the Level 4 label, discount caps, and calculation method match what the notice describes. The statutory maximum, however, still used the pre-existing formula rather than the higher cap floated for this framework, since that increase awaits legislation.
  • Regulation numbers and descriptors are reproduced exactly as stated. The nine alert-mishandling payments (about £500,000) are not tied to a specific regulation number in the notice and were therefore left out of the per-regulation breach list.
  • No conflation identified between CBNA London and the designated persons or entities named in the notice.
  • Supplemental content is confined to the block above and sourced in the Sources list.

Leave a Reply

Discover more from Mr. Sanctions

Subscribe now to keep reading and get access to the full archive.

Continue reading