OFSI’s largest published penalty against a bank operating in London, and the clearest public illustration yet of what “owned or controlled” costs a screening system that is built for name-matching rather than ownership-matching.
Two failure modes, not one
OFSI grouped the breaches into eight matters. Two account for most of the £19.7m: accounts belonging to companies majority-owned by a single designated Russian individual, and accounts belonging to subsidiaries of the designated shipping company PJSC Sovcomflot.
The two failures were different in kind. The individual’s structure was a screening-threshold problem: to manage a backlog of sanctions alerts after the invasion, the bank temporarily told staff in May 2022 not to request account restrictions unless they had evidence of 50 per cent or greater designated ownership — reintroducing, operationally, exactly the ownership threshold the underlying UK rule does not use. The Sovcomflot failure was a name-matching problem: the bank’s own KYC records read “PAO Sovcomflot,” its screening list read “Sovcomflot,” and the system’s calibration did not treat the Russian corporate prefix “PAO” as the same entity — so accounts the bank’s own records already linked to a designated person generated no alert at all.
What happened in the first 24 hours
£4.3m of the roughly £5.9m in payments connected to the designated individual’s companies moved within 24 hours of his designation. The rest moved over several weeks, while alerts sat unresolved in a third-level manual review queue. That split matters for anyone reading the maritime and correspondent-banking advisories on this site: same-day exposure is largely a pre-designation risk-appetite question, while weeks-long exposure is an alert-backlog and escalation-process question, and the fixes for the two are not the same.
The outcome
A single civil penalty covering all eight matters, discounted 20 per cent for voluntary disclosure and cooperation. OFSI explicitly weighed the operational strain of the 2022 designation wave in the bank’s favour and still found the breaches serious enough to penalise — consistent with the strict-liability standard that has applied to UK financial sanctions since June 2022, covering the breaches that occurred after that date.