Loading…
Loading…
OFSI's penalty enforces two regimes: the Russia (Sanctions) (EU Exit) Regulations 2019 (the majority of breaches) and the Global Anti-Corruption Sanctions Regulations 2021 (a smaller correspondent- banking category). The breaches were grouped into eight "Matters":
1. Corporate clients majority-owned by designated persons. CBNA London did not promptly restrict commercial bank accounts held by 11 companies owned/controlled by a designated Russian individual, processing payments worth ~£5.9m (reg. 11, dealing with frozen funds) plus two further payments over £600,000 to a firm owned by that individual (reg. 12, making funds available). ~£4.3m of the £5.9m occurred within 24 hours of designation (mitigating), but later related breaches kept the whole total in scope. 2. PJSC Sovcomflot ("SCF"). CBNA London did not promptly restrict 32 commercial accounts held by 29 entities owned/controlled by designated Russian shipping company Sovcomflot, processing transactions worth approximately £5.4m in breach of reg. 11. Root cause: the sanctions-screening system did not match "PAO Sovcomflot" (the KYC record) against "Sovcomflot" as it appeared on OFSI's consolidated list, so no screening alert fired despite documented exposure. 3. Internal charges. CBNA London deducted its own fees/tax charges from accounts of designated persons and corrected payment errors on frozen accounts — low-value individually (~£26,000 total) but a distinct breach category under both reg. 11 and reg. 12. 4. Russia-related correspondent banking. Between February and November 2022, CBNA London processed payments to/through designated Russian financial institutions acting as correspondent banks — AlfaBank, Gazprombank, Credit Bank of Moscow, Bank GPB International SA, Russian Agricultural Bank, Amsterdam Trade Bank, and the Ural Bank for Reconstruction and Development — arising from an automated payment processor that added correspondent banks to a payment chain without rescreening after initial screening, and from BIC-only payment messages that bypassed name-based sanctions screening. 5. Interest payment as Principal Paying Agent. In November 2022, acting as Principal Paying Agent for loan participation notes issued by an SPV owned by a person who later became designated, CBNA London received and (in February 2023) returned an interest payment worth ~£1.5m — which OFSI determined made funds available indirectly to a designated person (reg. 12). 6. GAC correspondent-banking payments. Between January and July 2025, CBNA London processed correspondent-banking payments worth ~£300,000 for the benefit of an individual designated under the Global Anti-Corruption Sanctions Regulations (reg. 13), continuing during an internal ownership investigation that was not escalated to the correct team. 7. Alert mishandles. Between March 2022 and February 2025, alert handlers made incorrect determinations on payments involving designated entities including VTB Bank, Bank Otkritie, Gazprombank (via Bank GPB International SA), Credit Bank of Moscow, Evraz PLC, and AFK Sistema (via EastWest United Bank SA) — total value ~£500,000. 8. Frozen-asset reporting failures. CBNA London failed to report frozen assets to OFSI as soon as practicable on 53 occasions (delay over six weeks in every case; up to 518 days in 11 cases; average 274 days) — an aggravating factor layered onto the substantive breaches.
OFSI assessed the case as Level 4 — its highest severity tier — with breach severity "High" and conduct "Aggravating." Aggravating factors included the very high aggregate breach value (£19,720,127.43), the strategic priority of the Russia sanctions regime, sustained material harm to the regime's objectives, and the repeated/persistent nature of most breach groups. Mitigating factors included the low individual value of the internal-charges breaches, the non-repeated nature of the interest-payment and alert-mishandle breaches, proximity to designation for some payments, CBNA London's remediation programme, and Citi's subsequent withdrawal from Russia.
the estimated breach value — here, 50% × £19,720,127.43 ≈ £9,860,063.72.
above 75% of the statutory maximum; the baseline applied was approximately £7,888,050.97.
self-disclosed most breach groups (though two categories, including the Sovcomflot matter, were not disclosed promptly — one delayed roughly seven months, another roughly ten months). The discount applied brought the baseline down to the final penalty of £4,732,830.58 — a reduction of roughly 40% from baseline.
"High" severity, "Aggravating" conduct — is OFSI's ceiling rating. Neither Deutsche Bank (severity 2, £165k) nor Sabre Global Technologies (severity 3, £1.0m) reached this classification.
At £4,732,830.58 this surpasses SGTL's £1,000,921 (May 2026), the prior record, by more than 4x.
processing, correspondent banking, Principal Paying Agent duties, and frozen-asset reporting — eight distinct failure categories across a global bank's UK branch, including a major designated shipping company (Sovcomflot) and a £19.7m aggregate breach value. Severity 5 is reserved for measures with register-wide structural effect (e.g., sectoral blocking orders, new designations regimes); this is a large enforcement action within an existing perimeter, not a new one — hence 4, not 5.
lesson.** The "PAO Sovcomflot" vs. "Sovcomflot" name-matching failure is a concrete, citable case study for sanctions-screening vendors and compliance teams handling Russian corporate-prefix conventions.
payment-processor gap — correspondent banks added post-screening without triggering a rescreen — is now a documented OFSI enforcement theme across at least two 2026 cases (CBNA London here; similar issues flagged in DBLB's post-listing ownership-chain case).
counsel now have a £4.73m/Level-4 reference point sitting well above the prior £1.0m/Level-3 SGTL record, sharpening the empirical range for board-level risk pricing of correspondent-banking Russia exposure.
confirm £4.73m as a genuine new ceiling or an outlier tied to CBNA London's unusually broad correspondent-banking footprint.
and-cooperation calculation or a stacked discount (disclosure + Settlement Scheme) — the notice's discount breakdown was not fully legible from the published PDF text extraction used for this filing; worth revisiting against the original PDF layout if OFSI's discount methodology becomes relevant to a future case comparison.