Rahman Ravelli
Syedur Rahman

Syedur Rahman | 16 February 2025
Share on:
Contact The Author >

OFSI’s first sector-specific threat assessment

Syed Rahman summarises its findings

The UK’s Office of Financial Sanctions Implementation (OFSI) has published its first of a series of assessments of threats to UK financial sanctions compliance.

The first assessment report relates to financial services, particularly retail and wholesale banks and non-bank payment service providers; including neo (digital-only) banks and challenger banks (which compete with the more traditional banks).

The report, “Financial Services Threat Assessment’’, provides information on suspected sanctions breaches and has been written in an attempt to help those in financial services manage their risk-based approach to compliance. While the report is not intended to be a complete detailing of ongoing OFSI investigations or enforcement activity, it can be viewed as an indicator of sanctions breaches that OFSI has either identified or believes are being carried out.

The report makes it clear that financial services firms have a role as gatekeepers of financial sanctions compliance. This is backed up by statistics: since February 2022 (when Russia invaded Ukraine), more than 65% of all suspected financial sanctions breach reports have come from financial services firms; 80% of which came from UK banks and non-bank service providers.

In the period covered by the assessment (January 2022 to March 2024), 87% of suspected breach reports involved Russia. Libya (8%) and Belarus (1%) are also cited, with the UK's other financial sanctions regimes, including Iran and DPRK, accounting for about 4% of reports. 

Judgements

At the heart of the assessment are six key judgements:

  • It is likely that some UK financial services firms have not self-disclosed all suspected breaches to OFSI.
  • It is highly likely that most non-compliance by the UK’s financial services firms has occurred due to several common issues.

    These issues include the improper maintenance of frozen assets (both intentional and unintentional) and licence conditions breaches, such as transactions occurring after a licence has expired, bank accounts being used for purposes other than those specified in OFSI licences and failures to follow licence reporting requirements.

    The report also cites inaccurate ownership assessments - particularly failures to identify entities which are directly owned by Russian designated persons (especially subsidiaries owned by Russian conglomerates) - inaccurate UK nexus assessments, and incorrect identification of differences between UK, European Union and US sanctions on Russia.
  • Russian designated persons are almost certain to have turned to new enablers in attempts to breach UK financial sanctions prohibitions. OFSI has recently seen increased activity by new groups of professional enablers and non-professional enablers such as friends, relatives and associates of designated persons.
  • There is a high likelihood that enablers have made payments through non-bank service providers to help Russian designated persons maintain their lifestyles and assets.

    The report includes a number of 'red flags' which firms should be alert to, with particular emphasis placed on new or unexplained payments to and from those associated with designated persons, payments related to maintenance of assets such as superyachts and UK residential property, and complex ownership and transaction structures. It is likely that a small number of enablers have attempted to act as fronts for Russian designated persons and claimed ownership of frozen assets.
  • Enablers have almost certainly used alternative payment methods, in particular crypto-assets, to breach UK financial sanctions prohibitions on Russia.

Circumvention

The fact that four of the six issues raised by OFSI relate to enablers indicates why the UK places an emphasis on circumvention of sanctions.

The assessment states that more than 25% of suspected breach reports from financial services firms have involved intermediary jurisdictions. The British Virgin Islands (BVI), Cyprus, Switzerland, United Arab Emirates (UAE), Guernsey, Luxembourg, Austria and Türkiye are the jurisdictions featuring in reports most often. The high-risk activities in each of these individual jurisdictions are listed in the assessment.

Useful

It could be argued that the assessment contains little that was previously unknown. But it paints a useful picture of the types of suspected breaches being reported to OFSI and how they have occurred. 

As a result, it can be used by those in the financial sector and compliance professionals to see if they should be doing more (or doing things differently) to ensure they are responding appropriately to current sanctions risks.

About The Author

Syedur Rahman
Partner

+44 (0)203 910 4566 vCard

Syedur Rahman is known for his in-depth experience of serious fraud, white-collar crime and serious crime cases, as well as his expertise in worldwide asset tracing and recovery, international arbitration, civil recovery, cryptocurrency and high-stakes commercial disputes.

View Author Profile >