When Citibank's London branch processed nearly £20 million in illegal payments to sanctioned Russian individuals and organizations, the £4.7 million fine from the U.K.'s Office of Financial Sanctions Implementation wasn't just a penalty. It highlighted systematic failures that many global financial institutions haven't addressed.
You might be confident in your sanctions screening. Your vendor promises 99% accuracy, and your compliance team reviews alerts daily. Yet, the same mistakes that caught Citibank are common across the industry, often unnoticed until a regulator steps in.
Why These Mistakes Keep Happening
Sanctions compliance often fails because it sits at the intersection of technology, operations, and geopolitics, where no single team has the full picture. Your IT department maintains the screening system, your operations team processes transactions, your compliance team writes policies, and your legal team interprets regulations. When a sanctioned payment slips through, each group blames another's gap.
The regulatory environment complicates this further. Sanctions lists update constantly, and designations can appear without warning. A corporate entity restructures, and your screening logic can't connect the new subsidiary to the sanctioned parent. By the time you catch it, you've processed months of prohibited transactions.
Mistake 1: Treating Screening as a Binary Pass/Fail
Your screening system flags a transaction. The name matches three of four components of a sanctioned individual. Your operations analyst sees it's a common name in that region, clicks "false positive," and releases the payment.
This happens because screening tools present alerts as yes/no decisions, but sanctions compliance requires investigative judgment. A partial name match, combined with a matching birth year and a transaction from a sanctioned entity's known location, isn't a coincidence. It's a pattern that demands deeper review.
The consequence: You build a compliance record showing you "reviewed" the alert, but you didn't investigate the underlying relationship. When regulators audit your decisions, they see a pattern of superficial reviews missing obvious connections.
The fix: Implement a tiered review protocol. Partial matches with two or more corroborating factors (geography, transaction type, counterparty history, amount patterns) should escalate to a senior compliance analyst with access to commercial due diligence databases, not just the sanctions list. Document what you checked, not just what you decided.
Mistake 2: Screening Only Direct Counterparties
You screen the immediate sender and receiver. The transaction passes. What you didn't catch: the payment routes through three intermediary banks, and the ultimate beneficiary is a shell company 50% owned by a sanctioned oligarch's daughter.
This happens because your screening architecture mirrors your payment processing flow. You check the fields in the SWIFT message but don't reconstruct the full economic chain because that data doesn't populate automatically, and manual investigation doesn't scale to transaction volumes.
The consequence: You comply with the technical requirement to screen but miss the economic substance. Regulators increasingly focus on beneficial ownership and ultimate destination, not just the names in the payment instruction.
The fix: Build a secondary screening layer for high-risk corridors and transaction types. When payments exceed a threshold or involve jurisdictions with known sanctions evasion activity, require operations to document the ultimate beneficiary before release. For correspondent banking relationships, obtain and verify beneficial ownership data annually, then screen those entities even when they're not direct counterparties.
Mistake 3: Running Outdated Sanctions Lists
Your screening system checks transactions against last week's sanctions list. Yesterday, the Office of Financial Sanctions Implementation designated fifteen new entities. Your system won't see them until the next scheduled update runs tonight.
This happens because sanctions list management is treated as a data feed problem, not a compliance control. Your vendor pushes updates, and your system ingests them on a schedule. Nobody owns the gap between designation and implementation.
The consequence: You process prohibited transactions during the update lag. Regulators don't accept "we updated within 24 hours" as a defense when you had twelve hours to implement and didn't.
The fix: Subscribe to regulatory alert services that notify you of new designations in real time. Implement an emergency update protocol: when a major designation drops, particularly coordinated actions across the U.S., U.K., and EU, your compliance team can push a manual list update and pause high-risk transactions until screening incorporates the new entries. Test this protocol quarterly.
Mistake 4: Ignoring Screening System Configuration Drift
Your sanctions screening system went live three years ago. The implementation team configured matching thresholds, transliteration rules, and exception logic based on your transaction patterns at the time. Since then, you've expanded into new markets, your transaction volumes have tripled, and sanctions regimes have added new entity types.
Nobody has recalibrated the system. Your false positive rate has climbed from 8% to 34%. Operations analysts are fatigued. Real hits get lost in the noise.
The consequence: Your screening system degrades from a control into a compliance theater exercise. Analysts develop workarounds. Someone creates an undocumented "frequent false positive" list to auto-clear certain alerts. That list now contains a sanctioned entity's trading name.
The fix: Treat screening system configuration as a Key Control Indicator that requires quarterly review. Track your false positive rate, average investigation time, and escalation frequency. When these metrics drift beyond your baseline by more than 15%, conduct a tuning exercise. Engage your vendor to adjust matching algorithms based on your current transaction mix, not the original implementation profile.
Mistake 5: Separating Sanctions Compliance from Customer Due Diligence
Your customer onboarding team screens new clients against sanctions lists at account opening. Your transaction monitoring team screens payments. These systems don't share data. A customer passes initial screening, then their beneficial ownership changes six months later when a sanctioned individual acquires a controlling stake. Your payment screening doesn't catch it because you're screening the original entity name, not the updated ownership structure.
The consequence: You maintain compliant-looking processes in two separate functions while the actual risk slips between them. Your audit trail shows you screened both the customer and the transaction, but you never connected the two data points that would have revealed the violation.
The fix: Build a consolidated sanctions risk view that links customer due diligence, transaction screening, and ongoing monitoring. When your KYC system flags a beneficial ownership change, trigger an automatic re-screen of that customer's transaction history for the past 90 days. When transaction screening identifies a new risk pattern, push that intelligence back to customer due diligence for relationship review. This requires your GRC platform to maintain a unified entity record, not siloed compliance workstreams.
Prevention Checklist
Deploy these controls before your next regulatory examination:
- Real-time list management: Designate a compliance officer authorized to push emergency sanctions list updates outside the normal schedule.
- Tiered investigation protocols: Define escalation criteria that move alerts from operations to compliance based on risk factors, not just match scores.
- Beneficial ownership screening: Maintain and screen ultimate beneficiary data for customers in high-risk sectors and jurisdictions.
- Quarterly system tuning: Review false positive rates and recalibrate matching thresholds when metrics drift beyond baseline.
- Integrated entity records: Link customer due diligence, transaction screening, and ongoing monitoring in a single system that updates all three when any one identifies new risk.
- Scenario testing: Run known sanctioned entity patterns through your screening system monthly to verify detection, including transliterated names, partial matches, and corporate ownership chains.
- Cross-border coordination: When you operate in multiple jurisdictions, establish a protocol for implementing the strictest applicable sanctions regime across all entities, not just local requirements.
The £4.7 million fine Citibank paid wasn't for lacking a sanctions screening system. It was for operating one that didn't actually prevent violations. Your screening infrastructure probably contains the same structural gaps. The question is whether you'll find them before a regulator does.




