Recent UK regulatory findings reveal why financial-crime controls need to be tested for effectiveness, not simply documented in policies and procedures.
Most financial institutions have documented financial-crime controls, including AML screening, sanctions screening and transaction monitoring. The harder question is whether those controls continue to work under pressure. Complex payment flows, large alert volumes, new sanctions designations and evolving criminal behaviour all test whether controls hold up in practice.
Two UK regulatory developments in September 2026 illustrate the challenge from different angles. OFSI’s £4.7 million penalty against a major bank’s London branch identified failures involving sanctions screening, payment-chain controls, account restrictions and alert handling. Separately, an FCA multi-firm review of 35 firms found that 238,396 accounts were offboarded for suspected money mule activity in 2025. The review highlighted the importance of early detection and information sharing.
The common lesson is not that firms lack policies or technology. It is that teams need to test their financial-crime controls for effectiveness under real operating conditions. AML screening, sanctions screening and transaction monitoring all need testing against data variations, payment-routing changes, alert volumes, manual intervention and evolving criminal behaviour. This article breaks down what regulators found and what your compliance team can do about it.
| Regulatory source | What it demonstrates |
|---|---|
| FCA multi-firm review of money mule activity (September 2026) | Trends in suspected mule-account offboarding, account tenure, cash-out patterns and information-sharing opportunities across 35 firms |
| OFSI monetary penalty (August 2026) | Practical weaknesses in sanctions screening, payment-chain screening, ownership and control assessment, alert handling, account restrictions and frozen-asset reporting |
What a £4.7 million sanctions penalty reveals about control gaps
On 11 August 2026, the UK’s Office of Financial Sanctions Implementation (OFSI) imposed a penalty of £4,732,830.58 on the London branch of the global bank. The breach involved the Russia (Sanctions) (EU Exit) Regulations 2019 and the Global Anti-Corruption Sanctions Regulations 2021. The bank processed over 970 prohibited payments worth approximately £19.7 million between 2022 and 2025.
OFSI did not consider that the bank intended to breach sanctions or sought to circumvent them. Instead, OFSI identified eight matters involving sanctions controls, payment processing, correspondent banking and account restrictions. These ranged from name-matching deficiencies and unscreened correspondent banking routes to alert backlogs and improperly configured account restrictions.
The bank voluntarily disclosed many of the breaches and cooperated with the investigation. However, OFSI reduced the voluntary disclosure discount from 30% to 20%. The bank had not included approximately £6.9 million in breaches in its original disclosure. The final penalty reflected a combined 40% discount from a baseline of £7.9 million.
For compliance teams, this case matters because the failures were not unusual. They are the kind of AML screening and sanctions control gaps that can exist at any institution in any jurisdiction. Many of these gaps can be identified before they result in a regulatory breach through effective operational testing.
Where sanctions screening controls fail: name matching, routing and payment chains
The OFSI penalty exposed several technical and operational weaknesses that can undermine sanctions compliance effectiveness.
Name-matching gaps
The bank’s screening system did not recognise “PAO Sovcomflot” as a match for “Sovcomflot” on OFSI’s consolidated list. The prefix “PAO” is a Russian legal-form designator meaning “public joint-stock company.” The system failed to normalise these prefixes. That left 32 accounts across 29 entities unrestricted. As a result, 328 transactions worth approximately £5.4 million went through without triggering a single alert.
Russian corporate naming conventions use prefixes such as PAO, OOO and AO. If your AML screening configuration does not adequately account for legal-form prefixes and other naming variations, this type of blind spot can arise. The same principle applies to German (GmbH, AG), French (SA, SAS) and Southeast Asian (Sdn Bhd, PT) corporate forms.
Correspondent banking and payment-chain failures
OFSI identified several separate correspondent-banking failures. In one matter, the bank had not enriched its internal correspondent banking list with the Bank Identification Codes (BICs) of designated Russian banks. In the relevant payment messages, the BIC was the only identifying information available for the affected banks. This resulted in 165 payments worth approximately £729,000 passing through without generating alerts.
In a separate failure, an automated payment processor selected correspondent banks from an internal routing list that nobody had screened against sanctions lists. The system did not re-screen the full payment chain when new intermediary banks joined the route. This resulted in 19 payments worth approximately £26,000 reaching designated Russian banks. A further 14 payments worth approximately £4 million involved a different correspondent-chain configuration problem.
These are not theoretical sanctions compliance risks. They are the exact gaps that produced a multimillion-pound penalty. For a deeper look at how to structure sanctions and PEP screening programs, see our guide to sanctions and PEP screening requirements.
Money mule detection gaps the FCA identified across 35 firms
On 23 September 2026, the FCA published findings from a multi-firm review of money mule activity covering 35 regulated firms. The review included retail banks, building societies, challenger banks, payment institutions and electronic money institutions. The results highlight the challenge of keeping financial-crime detection and prevention controls ahead of evolving mule networks.
In 2025, firms offboarded 238,396 accounts for suspected money mule activity. That figure represented a 28.9% increase from 184,935 in 2023. The FCA also reported 233,269 offboarded accounts in 2024, suggesting the rate of increase slowed in the final year. The FCA cautions that increasing offboarding may partly reflect customer growth and improvements in identifying suspected mule activity, not solely an increase in mule volumes.
In 2025, 114,984 accounts were offboarded within the first year of opening, representing 47.1% of the FCA’s account-tenure data. More than 55,000 shut down within just three months.
The FCA found that account closures were highest among customers aged 26 to 39. The sharpest increase was among customers aged 40 to 49. Customers aged 21 and under also represented a significant proportion of closures. Electronic money institutions saw the sharpest spike, with a 164.6% year-on-year increase in mule-related offboarding.
Fraud proceeds typically moved through two to five mule accounts before reaching the cash-out stage. Card payments were the most common cash-out method. Crypto transfers had lower volume but higher individual values. International cash-outs frequently targeted South Asia, West Africa and the Middle East.
In 2025, firms also filed 15.3% of offboarded customers to the National Fraud Database (NFD). The FCA cautions that NFD filings and account closures operate at different evidentiary thresholds, so the figures should not be treated as directly equivalent. The NFD only introduced its dedicated money-mule filing category in January 2025. Without effective information sharing, firms may have less visibility of suspected mule activity. The same individuals or linked accounts can appear elsewhere in the financial system. The FCA urged firms to use the information-sharing provisions under the Economic Crime and Corporate Transparency Act 2023 to disrupt this pattern.
Why alert backlogs and delayed reporting weaken AML screening and sanctions controls
AML screening and sanctions control failures do not always originate at the point of detection. In many cases, the system generates the right alert but the organisation fails to act on it quickly enough.
In the OFSI case, alerts on accounts linked to a designated individual sat unadjudicated at third-level review for several weeks. This backlog began immediately after the February 2022 Russia designations. OFSI specifically noted that it expected greater stress-testing and analysis of vulnerabilities before the invasion. The bank’s elevated Russia exposure made this expectation especially important. During that window, the accounts continued processing payments.
The bank also temporarily raised its ownership threshold for requesting account restrictions to 50% or greater. OFSI considered this standard too permissive. Under UK sanctions regulations, firms must assess both ownership and control when deciding whether an entity connects to a designated person.
Frozen asset reporting compounded the problem. OFSI identified 53 occasions on which frozen assets were not reported as soon as practicable. The average time between the bank having reasonable cause to suspect it held frozen funds and submitting the corresponding report was 274 days. In 11 cases, the delay was 518 days.
The FCA’s money mule review revealed a parallel issue. Firms with slower detection and offboarding cycles allowed accounts to remain active for longer. Retail banks closed 45.4% of suspected mule accounts only after two or more years. In contrast, electronic money institutions and payment institutions closed 74.1% and 56.9% respectively within six months.
The cases illustrate that detection capability alone is not enough. Controls also need effective escalation, investigation and timely action. An alert that is not appropriately investigated or escalated can leave the underlying risk unresolved even when the detection system itself has identified it.
Six checks every compliance team should run today
Drawing on these findings, here are six practical checks compliance teams can use to test the effectiveness of their AML screening, sanctions screening and broader financial-crime controls before the next audit or supervisory review.
1. Test your name-matching logic against foreign corporate prefixes
Run a batch of test names through your AML screening system using common legal-form prefixes: PAO, OOO and AO (Russia), GmbH and AG (Germany), SA and SAS (France), Sdn Bhd (Malaysia) and PT (Indonesia). If your system does not generate matches when the prefix is added or removed, your AML screening configuration needs updating.
2. Verify that correspondent banking identifiers are screened
Cross-reference relevant BICs and other payment identifiers against the sanctions regimes applicable to your business and payment flows. Confirm that automated routing processes re-screen the full payment chain when intermediary banks are added or changed. A single unscreened identifier can create a systematic breach that affects hundreds of payments.
3. Audit your alert backlog and escalation timelines
Define risk-based service levels for alert review and escalation. Monitor actual performance against them. Investigate persistent backlogs or breaches of internal thresholds. Document your escalation process and confirm it reflects regulatory expectations rather than internal convenience.
4. Review your mule detection rules against FCA benchmarks
Check whether your AML screening and transaction monitoring rules identify the behavioural patterns highlighted by the FCA. Look for unexpected or high-velocity inbound funds followed by rapid dispersal, movement through linked accounts, international transfers and cash-out activity. Review whether your controls can identify activity early enough to disrupt the flow of funds. The FCA’s account-tenure findings can also help firms assess whether their own offboarding patterns indicate a need for earlier intervention, but account age should not be treated on its own as evidence of mule activity.
5. Test account restrictions and licence handling
Test whether account restrictions prevent prohibited transactions while appropriately handling any applicable licences or permitted transactions. In the OFSI case, 177 transactions worth £135,000 breached the freeze because the system did not block internal charges. Confirm that your team has identified relevant general licences, that staff assess licence applicability before processing and that your systems monitor conditions and expiry dates.
6. Stress-test controls under surge conditions
OFSI specifically expected the bank to have stress-tested its sanctions controls before the February 2022 Russia designations. Ask whether your controls can absorb a sudden surge in designations. Can newly designated entities be screened retrospectively? Will alert volumes overwhelm review teams? Can manual queues clear within defined risk-based timeframes? Test these scenarios before a real event forces the question.
Take action before the next regulatory review
Together, these findings highlight a gap. Having financial-crime controls is not the same as demonstrating that those controls can detect, disrupt and respond effectively to evolving risks. OFSI showed that sanctions control failures stem from misconfigured systems, unscreened data feeds and process gaps that allow prohibited payments through. The FCA showed that firms are identifying and offboarding increasing numbers of suspected mule accounts, while organised criminal groups continue to move fraud proceeds through multiple accounts before cashing out.
The common thread across both developments is operational effectiveness. The findings demonstrate why firms need to be able to evidence that their AML screening, sanctions and financial-crime controls are working as intended. Documented policies alone are not enough to demonstrate that those controls are operating effectively.
If your team has not stress-tested its AML screening and financial-crime controls recently, now is the time. Book a consultation with Compliance7 to review your sanctions screening, transaction monitoring and overall program effectiveness.
Related Compliance7 guides
- Core guide: Sanctions and PEP Screening: Requirements, Best Practices and Recent Developments
- Related: The 24-Hour Sync: Solving RBI’s Real-Time Sanctions Screening Mandate
This article is for informational purposes only and does not constitute legal or regulatory advice. For guidance specific to your business, consult a qualified compliance professional.


