Skip to main content
green gradient background, "The Future of Application Security Is Already Here." and a read the report button.
Six Myths About Sanctions Compliance That Cost Citibank £4.7 MillionRegulatory Compliance
5 min readFor GRC Leaders

Six Myths About Sanctions Compliance That Cost Citibank £4.7 Million

The £4.73 million penalty imposed by OFSI on Citibank N.A., London Branch in August 2026 didn't introduce new sanctions obligations. It highlighted a more uncomfortable truth: the gap between what compliance teams think they've built and what actually works under pressure.

This gap persists because myths about sanctions compliance continue to shape how institutions design and test their controls. These myths sound reasonable in boardroom discussions but collapse when faced with operational reality. Let's examine six of them.

Myth 1: Sanctions Screening Is a Technology Problem

Reality: Screening tools fail not because of weak algorithms but due to incomplete or incompatible data.

Citibank's systems couldn't match "PAO Sovcomflot" in KYC records to "Sovcomflot" on OFSI's consolidated list. The Russian corporate prefix created what the system saw as a material difference, so no alert triggered. In another case, payment messages used BIC codes while the internal sanctions list lacked those enrichments.

Your screening technology only works if it receives data in the format it expects and searches against records that include all identifiers your transactions use. If your KYC data includes corporate prefixes, legal suffixes, or transliterated names that don't appear in your sanctions list, you're screening against a partial dataset.

Test this: Pull a sample of actual payment messages from your correspondent banking queue. Check whether every entity identifier in those messages (BICs, registry numbers, transliterated names) appears in your screening database. If they don't match exactly, your system won't catch them.

Myth 2: Manual Review Catches What Automated Screening Misses

Reality: Manual review fails when volumes exceed your team's capacity to maintain quality and speed.

OFSI found that Citibank developed a backlog as large volumes of potential sanctions matches required manual review. In May 2022, the bank changed internal guidance so accounts under investigation didn't need restriction unless evidence showed 50% or greater ownership by a designated person. This increased both the risk of unrestricted accounts and the duration of exposure.

Manual processes work when you have time, clear procedures, and manageable volumes. During sanctions shocks, none of those conditions hold. The 970 payments Citibank processed in breach of sanctions between February and November 2022 occurred precisely when Russia-related sanctions created unprecedented review queues.

Your manual review process needs a defined capacity limit. When you hit that limit, the escalation protocol can't be "review faster" or "temporarily raise the threshold." It needs to be a documented procedure that maintains the control's effectiveness even when throughput slows.

Myth 3: Restricting Accounts Promptly Is Straightforward

Reality: Restriction timing depends on whether you can definitively establish ownership or control, and that often requires time-consuming investigation.

Some Citibank accounts belonging to companies owned or controlled by designated persons weren't restricted promptly. The complexity wasn't identifying the designated person but tracing ownership through corporate structures, especially when those structures involved jurisdictions with opaque beneficial ownership registries.

The Russia (Sanctions) (EU Exit) Regulations 2019 and the Global Anti-Bribery and Corruption Sanctions Regulations 2021 both require freezing assets of designated persons and entities they own or control. "Own or control" isn't always straightforward when dealing with shell companies, nominee arrangements, or holding structures.

Document your ownership investigation procedure with time limits for each stage. If you can't complete ownership tracing within your defined window, the account should be restricted pending completion, not left unrestricted pending certainty.

Myth 4: Process Sequencing Doesn't Matter If All Steps Eventually Happen

Reality: The order in which controls execute determines whether prohibited transactions can slip through gaps between steps.

Citibank's correspondent banking transactions underwent screening before the full payment chain had been constructed. Correspondent banks could be added to the chain after screening without triggering re-screening of the completed chain. This sequencing meant the control checked an incomplete picture.

Your control design must account for when information becomes available and whether changes after a control executes trigger re-execution. If you screen at step 3 but add critical data at step 5, you've created a window where prohibited transactions can proceed.

Map every point where transaction data changes or expands. Every addition of a party, beneficiary, or intermediary after initial screening should trigger automated re-screening of the complete chain.

Myth 5: Temporary Control Changes During Crises Are Self-Limiting

Reality: Crisis-driven control modifications become permanent unless you build expiration and review requirements into the change itself.

The May 2022 guidance change that raised Citibank's ownership threshold was introduced to manage volume during the sanctions shock following Russia's invasion of Ukraine. OFSI's decision doesn't specify when this guidance was rescinded, but the breaches it enabled continued through November 2022.

When you modify controls during operational stress, the modification needs a sunset date and a mandatory review. Otherwise, what you intended as a temporary accommodation becomes embedded in your procedures.

Every crisis-driven control change should include three elements: the specific trigger that justifies it, the date it expires regardless of conditions, and the title of the person authorized to extend it. Without all three, temporary becomes permanent.

Myth 6: Reporting Delays Are Administrative Issues, Not Compliance Failures

Reality: OFSI treated the 53 occasions where Citibank failed to submit frozen asset reports "as soon as practicable" as distinct breaches, including 11 cases with 518-day delays.

The requirement to report isn't a courtesy to regulators. It's how the sanctions regime confirms that the control operated. When you freeze assets but don't report it, the regulator has no confirmation that the prohibition functioned.

"As soon as practicable" isn't defined by your reporting team's schedule. It's defined by how quickly you can confirm the freeze and transmit the report. If your process takes 518 days, your process is the compliance failure.

Build reporting into the restriction workflow itself. The person who executes the freeze should trigger the report in the same session. If your reporting process is separate from your restriction process, you've created the gap where delays occur.

What to Do Instead

OFSI imposed this penalty not because Citibank lacked sanctions controls but because those controls didn't function effectively under operational pressure. The distinction matters.

Start with process mapping that includes failure modes. For each control, document what happens when volumes spike, when data is incomplete, when manual review queues exceed capacity, and when temporary changes are introduced. Those failure scenarios are where breaches occur.

Test your controls against actual transaction data, not sanitized test cases. If your screening works perfectly in UAT but fails when payment messages use BIC codes your sanctions list doesn't include, your UAT didn't test the right thing.

Review every control modification introduced during the last sanctions shock. If any temporary changes are still in effect, you've found your next audit finding before the regulator does.

The Citibank penalty represents 63% of all monetary fines OFSI imposed since 2022. That concentration signals a shift toward enforcement that treats operational effectiveness as the compliance standard, not just policy documentation. Your controls don't need to be perfect, but they do need to actually work when tested by real transactions under real pressure.

Promotional banner graphic asking if you are ready for PCI DSS 4.0 with a call-to-action to get the guide

You Might Also Like