Syedur Rahman and Ulrich Schmidt outline the case and the key issues involved.
The Office of Financial Sanctions Implementation (OFSI) has fined Colorcon Limited £152,750 for payments that breached the UK’s Russia sanctions. This fine represents the fourth largest civil monetary penalty imposed by OFSI to date.
The payments that led to the financial penalty were made by Colorcon’s Moscow office to accounts held at designated Russian financial institutions. They were in breach of the sanctions imposed following Russia’s 2022 invasion of Ukraine.
Colorcon is a supplier to the pharmaceutical industry and a UK-registered subsidiary of Colorcon Inc, which has its global headquarters in North America. It had made funds totalling £191,290.57 available to four sanctioned Russian banks (Alfa Bank JSC, Promsvyazbank, Sberbank, and VTB Bank) through a series of 123 payments carried out between March and December 2022.
The payments covered costs such as employee salaries, book-keeping and insurance. While 44 of the payments (totalling £63,012.85), which were made between August 2022 and October 2022, were permitted as part of the company’s winding down of operations in Russia pursuant to a General Licence issued by OFSI, Colorcon admitted that it had not in fact recognised that the licence permitted it to make payments. The other 79 payments, totalling £128,277.72, were not permitted. Colorcon had also failed to meet its reporting requirements for the permitted payments, which was both an aggravating factor and a separate offence.
Suspect
OFSI found that Colorcon had knowledge or reasonable cause to suspect that those payments made before June 2022 (before strict civil liability for such sanctions compliance failings was introduced) were breaches. Colorcon voluntarily disclosed the breaches, but only four months after their discovery; which gained it a 35% discount on the £235,000 penalty. It could have obtained up to a 50% reduction for more prompt disclosure.
Colorcon cooperated with the investigation and did not contest the decision. It had operated a Moscow base for over 15 years, had sought legal advice on sanctions compliance before Russia invaded Ukraine and decided to close its Russian office in August 2022. OFSI began its investigation after Colorcon reported the breaches. The payments in question had been initiated by a Russian bookkeeper and authorised by UK signatories, who had not checked the sanctions status of the banks.
OFSI classed the case as serious, taking into account the total amount involved, that repeated direct payments were made to designated banks and that sanctions risks should have been better managed. It accepted as mitigating factors that some of the payments related to medical or humanitarian matters, as well as Colorcon’s disclosure, cooperation and decision to leave the Russian market.
Compliance
This penalty serves as a reminder that companies operating in high-risk jurisdictions such as Russia must maintain strong, regularly-updated compliance policies and carefully consider how they make payments to customers, suppliers and employees. Prompt disclosure is also paramount for all firms where they have reasonable grounds to believe that a breach of sanctions may have occurred.
When it comes to sanctions, relying on third parties’ compliance is dangerous. The UK Solicitors Regulation Authority guidance, for example, states “You cannot rely on other parties to assure you they are not designated persons. At the most basic level you should check the identities of clients (and for non-natural persons anyone with control over the entity or more than 50 per cent ownership) and counterparties against the UK consolidated sanctions list.”
Similarly, the Financial Conduct Authority has highlighted the over-reliance of companies on third parties. It has stated: “Ultimately, this resulted in firms not being able to show that they were adequately managing their risk of breaching sanctions appropriately. Like any outsourced service, firms need to ensure that they have appropriate control and oversight of their sanction screening controls. This could include regular testing and agreed internal service-level agreements (SLAs) for the time taken for lists to be updated following a designation.”
The UK having made sanctions breaches strict liability offences (meaning that an offending party is responsible for a breach regardless of whether they were aware of it or not) makes it imperative that companies are aware of the dangers of relying on third parties, and the penalties that can be imposed if problems arise as a result.
