Citi fined £4.7m for UK sanctions breaches involving Russia

Citibank’s London branch was fined £4.7 million by the UK’s sanctions regulator on Wednesday after processing 970 payments worth £19.7 million in breach of restrictions imposed on Russia following its invasion of Ukraine.

The Office of Financial Sanctions Implementation (OFSI) found the breaches occurred mainly between February and November 2022, involving payments linked to designated Russian banks and companies. These included Alfa-Bank, Gazprombank, Credit Bank of Moscow and state-owned shipping company Sovcomflot.

OFSI found that Citi failed to freeze as many as 24 commercial bank accounts belonging to 11 companies controlled by a designated Russian individual. Of the £5.9 million in funds passed through by the client, around £4.3 million was processed within the first 24 hours after the individual was added to the UK sanctions list.

The regulator said the introduction of sanctions following Russia’s invasion placed “significant strain on the bank’s alert handling and investigation processes”. To manage a backlog, Citi temporarily changed its compliance guidance in May 2022 so accounts were not restricted unless there was evidence that a sanctioned individual held more than 50 per cent ownership.

OFSI said Citi’s screening software failed to generate alerts for PJSC Sovcomflot because it did not recognise the Russian corporate prefix “PAO” in the company’s name. An automated payment processor also selected Russian correspondent banks from an internal list that had not been screened against sanctions lists before being added to transactions.

The regulator rated the case as high severity, citing aggravating factors including sustained and material harm to UK foreign policy objectives. It said there was no evidence that Citi’s London branch intended to breach sanctions, but the errors and failings were material, significant and spread across multiple business areas and systems.

Citi received a settlement discount after cooperating with the investigation and voluntarily disclosing the majority of the breaches. The bank’s spokesperson said: “Citi takes sanctions compliance extremely seriously and continues to invest significantly in its global sanctions compliance framework.”

OFSI said Citi had delayed reporting frozen assets to the regulator by more than six weeks on 53 occasions, with the longest delay reaching 518 days. More than 20 companies have faced enforcement action for sanctions breaches since 2019.

Citi announced in August 2022 that it would wind down its exposure to Russia, while its board approved the sale of its Russian banking subsidiary to Renaissance Capital in late 2025.



Share Story:

Recent Stories


Creating value together: Strategic partnerships in the age of GCCs
As Global Capability Centres reshape the financial services landscape, one question stands out: how do leading banks balance in-house innovation with strategic partnerships to drive real transformation?

Data trust in the AI era: Building customer confidence through responsible banking
In the second episode of FStech’s three-part video podcast series sponsored by HCLTech, Sudip Lahiri, Executive Vice President & Head of Financial Services for Europe & UKI at HCLTech examines the critical relationship between data trust, transparency, and responsible AI implementation in financial services.

Banking's GenAI evolution: Beyond the hype, building the future
In the first episode of a three-part video podcast series sponsored by HCLTech, Sudip Lahiri, Executive Vice President & Head of Financial Services for Europe & UKI at HCLTech explores how financial institutions can navigate the transformative potential of Generative AI while building lasting foundations for innovation.

Beyond compliance: Building unshakeable operational resilience in financial services
In today's rapidly evolving financial landscape, operational resilience has become a critical focus for institutions worldwide. As regulatory requirements grow more complex and cyber threats, particularly ransomware, become increasingly sophisticated, financial services providers must adapt and strengthen their defences. The intersection of compliance, technology, and security presents both challenges and opportunities.