The Office of Financial Sanctions Implementation (“OFSI”) has imposed a monetary penalty of more than £4.7m on Citibank, N.A., London Branch (“CBNA London”) for sanctions related breaches. The penalty, imposed on 11 August 2026 under section 146 of the Policing and Crime Act 2017, follows multiple transactions that OFSI assessed as breaches of UK financial sanctions prohibitions. This case study is a clear reminder for all financial services firms of the critical importance of robust, resilient sanctions systems and controls.
Background to case
CBNA London, the UK branch of Citibank, N.A., acts as a core wholesale and correspondent bank and facilitates cross-border payments and cash management. In February 2022, following Russia’s illegal invasion of Ukraine, the bank had significant exposure through its Russian client base, correspondent banking relationships involving Russian financial institutions, and payments linked to its then Russian affiliate, AO Citibank.
OFSI found that CBNA London processed 970 payments with a cumulative value of approximately £19.7 million that constituted breaches. These arose across multiple business areas, including payment processing, correspondent banking, and account restrictions. Many of the breaches occurred between February and November 2022, at a time of intense operational pressure caused by the rapid introduction of extensive new Russia-related sanctions packages.
Key Issues Identified
OFSI’s assessment highlighted a series of systems, controls and process weaknesses that contributed to the breaches:
- Significant delays in the review, escalation and adjudication of sanctions alerts.
- Failures to promptly identify and restrict accounts of entities owned or controlled by designated persons.
- Screening system calibration issues.
- Continued deduction of internal charges and fees from restricted accounts, and processing of certain correspondent banking payments to designated Russian banks.
- In one matter, a failure to report frozen assets to OFSI as soon as practicable.
OFSI recognised the unprecedented operational challenges created by the 2022 sanctions packages but concluded that the aggregate failings were material and significant.
For FCA-regulated firms, the case also reinforces the importance of effective financial crime systems and controls. FCA Financial Crime Guide (FCG) 7.1.1 states that all firms are required to comply with UK financial sanctions and explains that the FCA’s role is to ensure that firms it supervises have adequate systems and controls to do so. The guidance applies to firms subject to the financial crime rules in SYSC 3.2.6R or SYSC 6.1.1R and also applies to e-money institutions, payment institutions and the cryptoasset sector within the FCA’s supervisory scope.
The Penalty and Discounts Applied
The statutory maximum penalty was calculated at circa £9,8m, which was 50% of the estimated value of the funds involved. Further, CBNA London received a 20% discount for voluntary disclosure of the majority of the breaches and subsequent cooperation, plus an additional 20% settlement discount for reaching agreement within the 30-business-day settlement window. This resulted in a total 40% reduction and a final penalty of circa. £4,7m.
What Firms Should Consider
This enforcement action reinforces core obligations under UK financial sanctions legislation, including the Russia Regulations, the Global Anti-Corruption Sanctions Regulations, and the wider framework under the Sanctions and Anti-Money Laundering Act 2018 and the Policing and Crime Act 2017. OFSI’s enforcement action concerned breaches of regulations 11 and 12 of the Russia (Sanctions) (EU Exit) Regulations 2019 and regulation 13 of the Global Anti-Corruption Sanctions Regulations 2021.
It highlights the need for firms to review and, where necessary, enhance their sanctions compliance frameworks with particular focus on:
- Pre-emptive assessment of exposure to high-risk jurisdictions and clients, including scenario planning for rapid increases in designations.
- Capacity and resilience of alert-handling and investigation processes under stress.
- Accuracy and calibration of screening systems.
- Clear, tested procedures for prompt restriction of accounts and funds.
- Controls over internal charges, fees and automated payment routing once restrictions are in place.
- Timely, complete and accurate voluntary disclosure and ongoing cooperation with OFSI where potential breaches are identified.
Firms with elevated exposure should be able to demonstrate detailed prior analysis of vulnerabilities. The case also underlines the value of proactive self-reporting and full cooperation, which can materially reduce the level of any eventual penalty.
How Complyport Can Help
Complyport supports financial services firms, including banks, payment institutions and electronic money institutions in strengthening their financial sanctions compliance frameworks.
Our specialists can assist with:
- Sanctions Risk Assessments and Gap Analyses against current legal and regulatory expectations;
- Review and enhancement of screening systems, alert-handling capacity and escalation procedures;
- Testing of account restriction and internal charge controls under stress scenarios;
- Development of policies and procedures for general licence assessments and record-keeping;
- Anti-Financial Crime Training for staff and senior management including sanctions, anti-money laundering, counter terrorist financing, counter proliferation financing; and
- Support with voluntary disclosure considerations and engagement with OFSI where required.
Book a Meeting with a Complyport SME
To discuss how the lessons from this OFSI enforcement action apply to your firm and how Complyport can help strengthen your sanctions compliance framework, contact us today to book a meeting with one of our Subject Matter Experts.
Ask ViCA, your Virtual Compliance Assistant.
Access instant answers on regulatory changes.
Claim your complimentary 20 queries today! Register here: https://vica.chat





