The UK’s $6.4 Million Citibank Penalty: What Operational Sanctions Failures Actually Look Like Inside a Major Bank

The UK’s Office of Financial Sanctions Implementation fined Citibank’s London branch roughly 4.7 million pounds, about $6.4 million, for violating Russia sanctions, and this case deserves close attention from every financial institution compliance team, not because the violations were exotic or novel, but because they weren’t. This is a case study in ordinary operational failure at scale: screening systems that missed a name variant, alert backlogs that piled up faster than staff could clear them, a compliance guidance change that quietly loosened a control, and individual staff errors that, multiplied across hundreds of transactions, added up to more than $26 million in illegal payments processed.
How the Violations Happened
OFSI’s findings break down into several distinct failure categories, and each one illustrates a different kind of operational breakdown that can occur even inside a bank with a mature sanctions compliance program.
The first and largest category involved delayed account restrictions. Citibank London failed to promptly restrict 24 commercial accounts belonging to 11 companies owned by a single designated Russian individual, leading to 242 payments worth roughly $8 million being processed after those parties became subject to sanctions. OFSI found that a substantial share, about $5.8 million, moved within just 24 hours of designation, meaning the bank’s process for actioning new sanctions listings simply wasn’t fast enough to prevent immediate follow-on transactions from clearing. The remaining breaches stretched out over several weeks, reflecting a genuine backlog problem: the volume of new sanctions matches generated by the 2022 Russia designations overwhelmed Citibank London’s manual alert-adjudication process, leaving some alerts unresolved for weeks at a time.
Worth noting here is a specific decision Citibank London made in May 2022 that OFSI singled out as making the problem worse. Facing that alert volume, the bank revised its internal guidance so that staff only needed to request account restrictions when they had affirmative evidence that an entity was majority-owned by a sanctioned person, rather than restricting every account with a potential association to that person. OFSI’s assessment was direct: that change increased both the number of accounts left unrestricted and how long they stayed that way. It’s a useful illustration of how a well-intentioned effort to manage alert volume, tightening the evidentiary bar before acting, can itself become the source of additional violations if it isn’t calibrated carefully against the underlying sanctions risk.
The Sovcomflot Screening Gap
A second major category involved Russia’s largest shipping company, Sovcomflot, and its subsidiaries. Citibank London failed to restrict 32 commercial accounts held by 29 entities connected to Sovcomflot, resulting in 328 transactions worth about $7.2 million. The root cause here was a pure screening system defect: Citibank’s screening tools failed to match “Sovcomflot” as it appeared on the UK sanctions list against the company’s name as recorded in the bank’s own know-your-customer records, because the sanctions list entry included the Russian corporate prefix “PAO” and the bank’s screening logic didn’t account for that variant. This is exactly the kind of gap that sanctions screening calibration exercises are supposed to catch: foreign corporate prefixes, transliteration variants, and naming convention differences between how an entity appears on an official designation and how it’s recorded in a bank’s own customer records. When that calibration gap exists, it doesn’t just affect one account; it can silently fail to flag every account and transaction tied to that entity across the institution.

Correspondent Banking Breakdowns
A third set of violations involved Citibank London’s role in correspondent banking chains, both as a bank routing payments through sanctioned Russian correspondent banks and as an intermediary correspondent for transactions involving sanctioned parties. In one instance, the bank processed 19 payments worth about $35,000 through an automated payment processor that selected correspondent banks from an internal list that simply hadn’t been screened against sanctions lists at the time those payments went out, a basic control gap in an automated system that should have had sanctions screening built into its routing logic from the start. In other cases, payment information had already been screened before the full correspondent banking chain was actually established, meaning staff didn’t catch that a UK nexus and a UK-designated person were involved in the payment before it was released. Citibank London also processed roughly 160 payments worth about $984,000 in March and April 2022 involving sanctioned Russian banks as beneficiary institutions, including Alfa-Bank, Gazprombank, and several others.
Human Error at the Individual Level
The remaining category is the one that will feel most familiar to any compliance officer who has ever managed an alert-handling team under pressure: individual staff mistakes. OFSI documented cases where an alert handler made an incorrect ownership and control determination for one entity, where staff failed to identify subsidiary companies connected to a designated person, and where alert handlers issued conflicting or incorrect instructions to colleagues. In the single highest-value transaction OFSI flagged, an alert handler reviewing a matter months after the fact mistakenly identified a sanctioned Russian bank as the payment’s beneficiary when the bank was actually the remitter, and as a result of that mix-up, rejected the payment back to the designated person, which itself violated sanctions.
Reporting Delays Compounded the Problem
Beyond the underlying payment violations, OFSI found that Citibank London failed to report frozen assets “as soon as practicable” on 53 separate occasions. Every one of those delays exceeded six weeks, and in 11 of those cases, the delay stretched to 518 days. Timely reporting of frozen assets is a distinct, independent obligation under UK sanctions law, and this pattern shows that operational strain doesn’t just cause transaction-level violations; it can also degrade an institution’s ongoing reporting compliance long after the initial crisis period has passed.
How OFSI Weighed the Case
OFSI rated the overall severity of this case as high, its most serious rating category, citing the substantial value and volume of breaches and what it described as sustained, material harm to the objectives of the underlying sanctions regime. Importantly, OFSI made clear that it did not believe Citibank London intended to breach sanctions, but it was equally clear that the absence of intent is not a mitigating factor. The agency’s core finding was that for at least some of these payments, Citibank London’s own systems held the information necessary to determine that a payment would violate sanctions, but that information simply wasn’t properly disseminated or identified at the critical moment, creating what OFSI called missed opportunities to prevent funds from reaching designated persons.
OFSI also pushed back on the idea that operational strain fully explains the case. While it acknowledged that Citibank London had done significant preparatory work ahead of the 2022 sanctions wave, it said it would have expected more institution-specific detail in the bank’s response to OFSI’s questions about how it prepared for the possibility of new Russia sanctions in the lead-up to the invasion. And OFSI flagged that most of the violations reflected a pattern of repeated or persistent breaches sharing similar root causes, rather than isolated one-off incidents, which weighed against the bank in its overall assessment.
Where Citibank Earned Credit

The penalty would likely have been considerably higher without meaningful mitigation. Citibank London self-disclosed most of the violations voluntarily, and OFSI awarded a 20 percent discount specifically for that voluntary disclosure combined with cooperation during the investigation. The bank also undertook a documented remediation program addressing the root causes OFSI identified, offered to share its remediation plans directly with the agency, and ultimately withdrew from the Russian market entirely. Beyond formal disclosure obligations, Citibank London made unprompted offers to hold technical briefings with OFSI on multiple themes related to the case, briefings OFSI specifically credited as materially contributing to its understanding of the breaches. That is a meaningful signal about what genuine cooperation looks like in the eyes of a sanctions regulator: not just responding to formal requests, but proactively offering context and technical explanation beyond what was asked.
There’s a pointed exception to this cooperation narrative worth flagging, though. Citibank London did not voluntarily disclose two groups of violations totaling roughly $9.3 million in value; OFSI only learned about those breaches because it proactively wrote to the bank asking about them. OFSI noted it remains unclear whether Citibank London would have discovered and reported those violations on its own, and said that gap in the bank’s self-monitoring is itself a cause for concern, a reminder that voluntary self-disclosure credit only extends as far as what a company actually catches through its own processes.
The Practical Lessons for Compliance Programs
A few takeaways from this case apply well beyond banking. Screening system calibration needs to specifically account for foreign corporate prefixes, transliteration variants, and naming conventions that differ between how an entity appears on a designation and how it’s recorded in internal customer records, because a single unmatched name variant can silently defeat screening across every account and transaction tied to that entity. Any internal policy change made to manage alert volume during a surge, like tightening the evidentiary threshold before restricting an account, needs its own risk assessment before implementation, because a change designed to reduce workload can directly increase violation exposure if it isn’t carefully calibrated. Automated payment routing systems need sanctions screening built into every list and lookup table they draw from, not just the primary transaction screening layer, since a stale or unscreened internal routing list is itself a control gap. Asset-freezing and reporting obligations are independent compliance requirements that deserve their own dedicated monitoring, separate from transaction screening, since this case shows reporting delays can persist and compound long after the acute operational crisis that caused the underlying violations has passed. And finally, genuine cooperation with a regulator, including proactive outreach and voluntary technical briefings beyond what’s formally requested, produces real, quantifiable credit, but only for what a company actually discloses on its own; violations a regulator has to surface itself receive no such benefit and can specifically undercut a company’s broader cooperation narrative.











