Citibank’s £4.7m OFSI penalty: when the message matters more than the fine

Citibank’s £4.7m OFSI penalty: when the message matters more than the fine

An opinion piece by Anastasija Rackovska, IRM Financial Services Group Member OFSI’s £4.73 million penalty against Citibank N.A., London Branch does not introduce new sanctions obligations. Instead, it demonstrates the consequences when established requirements are not translated into effective systems, controls and operational practice. For financial institutions, the case may be less about changing the…

An opinion piece by Anastasija Rackovska, IRM Financial Services Group Member

OFSI’s £4.73 million penalty against Citibank N.A., London Branch does not introduce new sanctions obligations. Instead, it demonstrates the consequences when established requirements are not translated into effective systems, controls and operational practice. For financial institutions, the case may be less about changing the sanctions rulebook than about a maturing enforcement environment.

On 11 August 2026, the UK’s Office of Financial Sanctions Implementation (OFSI), part of HM Treasury, imposed a £4,732,830.58 penalty on Citibank N.A., London Branch (CBNA London) for breaches of the Russia (Sanctions) (EU Exit) Regulations 2019 and the Global Anti-Corruption Sanctions Regulations 2021.

The case covered eight groups of breaches across several areas of the bank’s operations. In total, CBNA London processed 970 payments with a cumulative value of approximately £19.72 million that OFSI considered to be in breach of UK financial sanctions.

Most of the breaches occurred between February and November 2022, following Russia’s invasion of Ukraine. OFSI acknowledged the context: the scale and pace of sanctions introduced by the UK and its allies created significant operational challenges for firms with exposure to Russia. CBNA London was particularly exposed because of its Russian client base, correspondent banking relationships involving Russian financial institutions, and payments connected with its then-Russian affiliate.

That context, however, did not excuse the breaches.

What went wrong?

There was no single failure.

The breaches resulted from a combination of weaknesses in systems and controls, operational backlogs, screening configuration, manual processes and human judgement.

Some accounts belonging to companies owned or controlled by designated persons were not restricted promptly. A backlog had developed as large volumes of potential sanctions matches required manual review. In May 2022, the bank temporarily changed its internal guidance so that accounts under investigation did not need to be restricted unless there was evidence of 50% or greater ownership by a designated person. OFSI concluded that the change increased both the risk of accounts remaining unrestricted and the length of time for which this could happen.

Screening weaknesses produced further breaches. In one case, the bank’s KYC records referred to “PAO Sovcomflot”, while OFSI’s consolidated list contained “Sovcomflot”. The system treated the Russian corporate prefix as a material difference and did not generate an alert. In another, payment messages identified banks using BICs, while the relevant internal sanctions-list entries had not been enriched with those BICs.

The sequencing of payment controls also mattered. In some correspondent banking transactions, screening took place before the full payment chain had been constructed. Correspondent banks could therefore be added after screening without the completed chain being re-screened.

Human errors added another layer. These included applying guidance relating to sectoral sanctions inappropriately, failing to follow licence conditions, incorrectly identifying a designated bank as a beneficiary rather than a remitter, and sending a sanctions escalation to the wrong team, where the mistake was not identified and the case was closed without further action.

The case also included 53 occasions where frozen asset reports were not submitted to OFSI as soon as practicable. In 11 cases, the delay was 518 days.

OFSI has published a detailed account of the Citibank case, including the breaches identified, the circumstances surrounding them and how the final penalty was calculated. The full decision is available

Is there anything fundamentally new here?

Not really – and that may be the most important point.

Financial institutions already know that designated persons’ assets must be frozen, that funds must not be made available to them where prohibited, that sanctions exposure must be identified, and that appropriate reporting and licensing requirements apply.

The Citibank case does not establish a different compliance standard. Nor does it suggest deliberate sanctions evasion. OFSI expressly concluded that CBNA London did not intend to breach sanctions and did not seek to circumvent them.

What it does show is a regulator increasingly willing to attach substantial financial consequences to failures in implementing those existing obligations.

How significant is the fine?

So, is £4.73 million really a significant sanctions penalty? By OFSI standards, yes.

The table below shows how OFSI’s monetary penalties have evolved since 2022.

YearPenalty 
September 2026£ 4,732,830.58Citibank, N.A., London Branch (CBNA London)
June 2026 £1,000,920.59Sabre Global Technologies Limited (SGTL)
May 2026£165,000Deutsche Bank AG London Branch (DBLB)
Mar 2026£390,000Apple Distribution International Limited (ADI)
Jan 2026£160,000Bank of Scotland PLC
Sep 2025£152,750Colorcon Limited
Sep 2025DisclosureVanquis Bank Limited (VBL)
Jul 2025£300,000Markom Management Limited (MML)
May 2025£5,000Svarog Shipping & Trading Company Limited
Mar 2025£465,000Herbert Smith Freehills CIS LLPP (HSF Moscow) Date 
Mar 2025DisclosureCharities
Sep 2024£15,000Integral Concierge Services Limited
Aug 2023DisclosureWise Payments Limited
Sep 2022£30,000.00Hong Kong Wines and Spirits Competition Limited
19 May 2022£15,000.00Tracerco Limited

*Source and detailed information are available from OFSI’s enforcement collection.

A bit of statistics, as everyone loves it:

  • Total fines increased by 599% in 2026 compared with 2025.
  • The average fine increased by 458%, from approximately £231,000 to £1.29 million.
  • Citibank’s £4.73 million fine alone accounts for approximately 63% of all monetary fines imposed since 2022.

So, sanctions-wise, this is clearly significant. But is £4.73 million really that significant if we look at it from a different angle?

Put it alongside established financial crime enforcement, and the picture looks rather different. Multimillion-pound penalties have long been a feature of the UK AML regulatory environment, with individual FCA enforcement actions relating to financial crime controls running into tens and, in some cases, hundreds of millions of pounds.

One obvious example is NatWest. In 2021, National Westminster Bank Plc was fined £264.8 million following its conviction for failures to comply with the UK Money Laundering Regulations. More generally, multimillion-pound penalties for AML and financial crime control failures are hardly unusual.

So, was £4.73 million a big financial hit for Citi? I obviously do not have access to Citi’s internal numbers, but probably not.

In its letter to the shareholders, Citi reported $85.2 billion in revenue for 2025. Against that figure, a £4.73 million penalty represents only a tiny fraction of annual revenue – roughly equivalent to around four hours of revenue generation.

Its significance therefore lies less in the impact on Citi’s balance sheet and more in its regulatory and reputational effect.

And that distinction may be precisely the point.

Financial sanctions are intended to be more than another compliance requirement. They are a policy instrument. Their effectiveness depends on financial institutions actually preventing prohibited funds and economic resources from reaching designated persons.

In the Citibank case, OFSI concluded that the breaches enabled designated persons, or entities owned or controlled by them, to access funds, settle obligations or continue business operations, significantly undermining the effectiveness of the relevant sanctions regimes.

If sanctions exist in law but are not implemented effectively by the institutions through which money moves, the policy instrument itself becomes less effective. At some point, guidance and supervisory expectations therefore need to be reinforced by enforcement capable of changing behaviour.

Seen from that perspective, the Citibank penalty may be more significant as a message to the wider financial ecosystem than as a punishment of one institution.

So what should other firms take from it?

Probably not that everyone suddenly needs to redesign their sanctions compliance framework from scratch. The more practical question is whether the framework you already have actually works.

For boards and risk leaders, the question should therefore be less “Do we have sanctions controls?” and more “Do we know that they work?”

Would your screening work against the data you actually receive? If payment details change after initial screening, will the transaction be screened again? Can a manual escalation get lost between teams? Are temporary control changes introduced during a crisis still sitting somewhere in the process years later? And does everyone actually know who is responsible for reporting a potential breach?

These are operational questions rather than policy questions. But, as the Citibank case shows, operational weaknesses can ultimately become sanctions breaches.

And perhaps the most useful time to ask those questions is before the next sanctions shock, not after it.

The rules themselves have not fundamentally changed. What is changing is the enforcement environment around them. And for firms, that may be the most important takeaway from the Citibank case.





← Previous

The Human side of risk management
Why emotionally intelligent risk practice would help organisations by Thomas Clare, CFIRM We’re supposed to…


9 SEPTEMBER 2026

Owning your space: confidence, visibility & voice

This event marks the formal public launch of the IRM Women in Risk Special Interest Group. The session is themed around the most pressing personal and professional challenges identified by women in the risk profession today.

Find out more

10 SEPTEMBER 2026

Beyond compliance

Managing equity compensation risk through automation, governance and the unified equity compensation risk & automation framework (UECRAF).

Find out more

17 SEPTEMBER 2026

Building an effective risk culture in your organisation

The proactive cultivation of an effective risk culture can serve as a strategic differentiator, enhancing the organisation’s resilience, agility, and reputation in the eyes of customers, investors, and regulators alike.

Find out more

Advertisement