Sanctions News Desk · OFSI · Russia

    OFSI fined Citibank London £4.7 million. Its screening read “PAO Sovcomflot” and “Sovcomflot” as two different names

    On 2 September 2026 the UK's Office of Financial Sanctions Implementation published a penalty of £4,732,830.58 against the London branch of Citibank, for 970 payments worth £19,720,127.43 that it treats as breaches of UK sanctions, most of them made in 2022. One cause was a screening system that saw “PAO Sovcomflot” in the bank's own records and “Sovcomflot” on the sanctions list as materially different, and raised no alert. The other causes it lists are not about names at all. A list of correspondent banks was never screened, payments were screened before the payment chain was complete, and alerts waited weeks for a decision.

    By ScreenVeritAI Team, Sanctions News Desk

    Key facts

    • Penalty: £4,732,830.58
    • Payments treated as breaches: 970, worth £19,720,127.43
    • Sovcomflot group: 32 accounts, 29 companies, 328 transactions, about £5.4 million
    • Paid within 24 hours of a designation: About £4.3 million of £5.9 million
    • Late frozen-asset reports: 53, averaging 274 days
    • Discount from the baseline: 40%, from £7,888,050.97

    What changed

    OFSI published the notice on 2 September 2026, three weeks after the penalty was imposed. The 970 payments, worth £19,720,127.43, breached the Russia and Global Anti-Corruption sanctions regulations. Most were made between February and November 2022.

    The 16-page notice does not describe one failure. It describes screening that missed a name, a bank list that was never screened, alerts that waited weeks, and a rule change that told staff to wait for evidence of ownership before restricting an account.

    The name that did not match

    The name failure involves PJSC Sovcomflot, designated in the UK on 24 March 2022 (a date from the UK list, not from the notice). Citibank London did not promptly restrict 32 accounts held by 29 companies that Sovcomflot owned or controlled, and it processed 328 transactions worth about £5.4 million through them.

    OFSI's explanation is one sentence. Its screening system "perceived a material difference" between the name on OFSI's consolidated list, which the notice gives as "Sovcomflot", and the bank's own KYC records, which showed exposure to "PAO Sovcomflot". The calibration did not account for the Russian corporate prefix, so no alert was produced. Restricting the accounts was then a manual process, and it was slow.

    Two details are easy to get wrong. The account holders were not PAO Sovcomflot itself. OFSI says the bank told it in 2022 that PAO Sovcomflot was its customer, and that this was incorrect. And the bank did not report these breaches on its own: it reviewed them after OFSI wrote to it, and the full facts surfaced in August 2025, three years after the payments.

    PAO is publichnoye aktsionernoye obshchestvo, a public joint-stock company. English-language filings write it PJSC. The UK file we downloaded on 29 September 2026, report date 29 September, holds the company as entry RUS1097 under the primary name PUBLIC JOINT STOCK COMPANY SOVCOMFLOT, with PAO SOVCOMFLOT and PJSC SOVCOMFLOT among its name variations and a last-updated date of 9 April 2025. No name row reads simply SOVCOMFLOT. The notice quotes the 2022 list name only as "Sovcomflot" and does not reproduce the full entry or its aliases, so we cannot tell whether an exact match on "PAO Sovcomflot" would have hit then. Against today's file it would.

    Four gaps that a better name match would not have closed

    The rest of the correspondent-banking failures were about where screening sat in the payment, and what it was pointed at.

    GapWhat OFSI foundPayments
    A list nobody screenedThe payment processor chose correspondent banks from an internal list. The list held Russian banks that later became designated, and it was not itself screened against sanctions lists.19, about £26,000
    Screened too earlyPayment details were screened before correspondent banks were added automatically, and the full chain was not screened again. The 19 payments above went through this way. In 14 more, the bank itself was added after screening, and staff did not act on the UK link before release.14, about £4 million
    A code, not a nameSome internal list entries had no Bank Identification Codes (BICs). Payment messages carried only the code, as is normal in SWIFT. Codes were added on 5 April 2022; Ural Bank's was missed by human error.165, about £729,000
    Returned funds screened one hopReturn instructions named only the next bank, not the designated ultimate beneficiary. The bank held the outbound messages and did not use them.6, about £1.2 million

    Wind-down general licences for the designated Russian banks were in force during most of these payments. The bank made no assessment of whether they applied, because no alert fired. OFSI says that check belongs before the payment, with records kept.

    Accounts that stayed open

    None of the four reasons OFSI gives for the 242-payment group is a matching failure; the alerts fired, and then sat in a queue. After a designated Russian individual was listed, the bank did not promptly restrict 24 accounts held by 11 companies he owned or controlled. It processed 242 payments from them, about £5.9 million, and two more, over £600,000 together, from a company he did not own to a firm he did.

    Alerts backed up at the third level of review, and some sat undecided for several weeks. Staff did not act on internal messages saying the accounts were still open. One entity was judged minority-owned, which OFSI says was not a reasonable conclusion from the information the bank had, and some of his subsidiaries were not identified. And in May 2022 the bank temporarily changed its guidance: staff no longer had to request a restriction on an account still under investigation unless they had evidence that a designated person owned 50 percent or more. Until then every potentially linked account was restricted on escalation. OFSI says the change increased both the risk of accounts staying open and how long they stayed open.

    The notice also says what it counted in the bank's favour. About £4.3 million of the £5.9 million was paid within 24 hours of the listing. OFSI says it does not necessarily expect automated screening to stop payments made that close to a designation, and counts the timing as strongly mitigating. The payments stay in the total because, in OFSI's words, there were later breaches of the same or similar nature.

    Smaller failures ran alongside. The bank debited its own fees and tax charges, and corrected some payment errors, in 177 transactions worth about £135,000, most of them on accounts restricted while a match was being confirmed. That type of restriction blocked customer and third-party debits but not the bank's own. A bulk process for correcting interest payments did not check for restrictions. And in the same matter, 53 frozen-asset reports were more than six weeks late; in eleven the gap was 518 days, and on average 274 days passed between the bank having reason to suspect it held frozen funds and filing.

    How the penalty was calculated

    OFSI put the statutory maximum at 50 percent of the £19,720,127.43 in breaches, £9,860,063.72, and set a baseline of £7,888,050.97. It then took off 20 percent for disclosure and co-operation and 20 percent for settling within 30 business days, and imposed £4,732,830.58.

    The baseline is 80 percent of the maximum; OFSI's guidance puts the floor for its most serious level at 75. The disclosure discount could have been 30 percent. OFSI gave 20 because about £6.9 million of the breaches, the Sovcomflot payments and an interest payment of about £1.5 million, came to light only after it wrote to the bank; because about £4 million was reported late; and because some early disclosures were incomplete or wrong.

    OFSI sent its notice of intention on 15 June 2026. Settlement talks began on 1 July and the settlement was agreed on 11 August.

    What to do this week

    1. Type the name both ways. Search "PAO Sovcomflot" and "Sovcomflot" in the tool you use, then PJSC, OAO, JSC and the Cyrillic. Note which lists return an entry for each and under what name. If the prefix changes the answer, that is a finding.
    2. Find where screening runs in the payment flow and what it reads from. Anything added after the screen, and any internal table the flow selects from, has to be screened too, including funds being returned, which are screened against the original payment.
    3. Check that bank entries carry identifier codes. If your messages carry only a BIC, a name-only list entry will not fire.
    4. Age your alert queue. Find the oldest undecided potential match and what the account was allowed to do while it waited.
    5. Read your written ownership guidance and your restriction types. Look for wording that asks for 50 percent before restricting, and check whether a restriction stops your own fees, interest and bulk corrections.
    6. Check that frozen-asset reports go out promptly. Find the gap between the day you had reason to suspect and the day you filed.

    How ScreenVeritAI handles this

    Test one takes a minute, and we would rather you ran it on us than took our word for it. Search the two spellings in our screening and read what comes back, list by list. Test four is about queues, which no tool fixes for you. Scheduled re-screens of a saved customer file put a new listing in front of an analyst on the next run, without waiting for a payment to trigger an alert.

    What this post does not say

    This is a report of what OFSI's public penalty notice says, and of what the UK Sanctions List file we downloaded on 29 September 2026 contained. It takes no position on whether OFSI's decision was right, and it does not say what any other bank's systems would have done.

    The notice's per-matter payment counts add to 973 against the 970 it penalises; it does not reconcile the difference, and neither do we. The notice does not name the designated Russian individual, and neither do we. We have no view on the bank's systems today.

    Frequently asked questions

    Did Citibank miss Sovcomflot because of the letters PAO, and would fuzzy matching have caught it?

    Partly, and the notice does not say. OFSI says the bank's screening system perceived a material difference between “Sovcomflot”, the name it gives for the listing, and “PAO Sovcomflot” in the bank's own customer records, and that the system's calibration did not account for the Russian prefix. It says nothing about thresholds or spelling tolerance, so whether another engine alerts on the pair depends on how that engine weights legal-form words. Restriction was also a manual process that ran late, so the name gap was one of two causes for the 328 payments. Run both spellings through your own system and record what comes back.

    Does OFSI expect screening to stop a payment made hours after a designation?

    Not necessarily. In its assessment of the 244 breaches on accounts of companies owned by one designated Russian individual, OFSI says it does not necessarily expect automated screening to stop payments made very close to designation, and it treats that as strongly mitigating. About £4.3 million of the £5.9 million was paid within 24 hours. The payments stay in the total because, in OFSI's words, there were later breaches of the same or similar nature.

    Do we have to re-screen a payment after a correspondent bank is added?

    OFSI treated the lack of that step as a cause of breaches. The bank's processor screened payment details before correspondent banks were added automatically, and did not screen the full chain afterwards. In 14 payments worth about £4 million the bank itself was added after screening, and staff did not act on the UK link before release. Screen the chain as it will actually travel.

    Can a wind-down general licence excuse a payment nobody assessed?

    Not by itself. Wind-down licences were in force for most of the correspondent-banking payments, but no alert fired, so nobody checked whether a licence applied before the money left. OFSI says firms should take reasonable steps in advance to satisfy themselves that a general licence covers a transaction, and keep records of that effort. The after-the-fact exercise helped OFSI's assessment and lengthened its investigation; the notice does not say which payments, if any, it took out of the total.

    How was the £4.7 million worked out?

    The statutory maximum is 50 percent of the £19,720,127.43 in breaches, or £9,860,063.72. OFSI set a baseline of £7,888,050.97, which is 80 percent of the maximum, took off 20 percent for disclosure and co-operation and a further 20 percent for settling within 30 business days, and imposed £4,732,830.58. The disclosure discount was 20 percent rather than the maximum 30 mainly because about £6.9 million of the breaches, the Sovcomflot payments and one interest payment, came to light only after OFSI wrote to the bank; late and incomplete early disclosures counted against it too.

    Sources

    1. Imposition of Monetary Penalty: Citibank, N.A., London Branch (public penalty notice, 16 pages) — Office of Financial Sanctions Implementation, HM Treasury, September 29, 2026
    2. Imposition of Monetary Penalty: Citibank, N.A., London Branch — GOV.UK, September 29, 2026
    3. The UK Sanctions List (CSV, report date 29 September 2026) — Foreign, Commonwealth and Development Office, September 29, 2026

    Run screening|All analyses

    Informational analysis of published regulatory sources. Not legal advice. Verify the primary sources before acting.