OFSI is reshaping sanctions enforcement — are firms moving fast enough?
The recent OFSI penalties against Deutsche Bank, Apple Distribution International (ADI), and Bank of Scotland should not be viewed as isolated enforcement actions.
Collectively, they reveal something much more important:
Recent enforcement actions suggest that many organisations still do not fully understand their sanctions exposure. Firms may have sophisticated sanctions frameworks, screening platforms, and governance structures, yet still fail to understand where their sanctions risk actually sits.
UK sanctions enforcement is becoming increasingly intelligence-led and focused on whether firms can identify and manage sanctions risk hidden within complex ownership structures, commercial relationships, and financial networks.
At the centre of the Deutsche Bank and ADI cases was Okko LLC, a Russian entity owned by sanctioned company JSC New Opportunities.
Different firms. Different operating models. Same core failure:
The firms identified the counterparty, but failed to properly identify the sanctions exposure sitting behind the ownership structure. The common thread running through these cases is not a failure to identify a sanctioned name. It is a failure to fully understand the sanctions exposure associated with a transaction, counterparty, ownership structure, or commercial relationship.
That distinction is becoming increasingly important. Modern sanctions enforcement is moving beyond list-based screening towards a broader assessment of whether firms can identify indirect exposure hidden within complex ownership structures, payment flows, commercial relationships, and wider business networks.
The recent OFSI cases suggest the gap between sanctions controls and sanctions understanding may be wider than many firms realise. Historically, many sanctions frameworks were built around direct-name screening and static list matching.
That is no longer enough.
Ownership and control is one of the ways sanctions exposure is hidden
Modern sanctions evasion rarely operates through straightforward direct exposure anymore.
It increasingly operates through:
• Intermediary entities
• Layered ownership structures
• Third-country facilitators
• Complex payment routing
• Nominee arrangements
• Shadow networks designed to obscure control and economic benefit
The Okko cases reinforce that regulators increasingly expect firms to understand not just who they are dealing with — but who ultimately sits behind the transaction, benefits from it, or controls the wider structure.
Many firms still operate sanctions frameworks heavily dependent on direct-name screening.
That creates significant vulnerability.
The regulatory expectation is increasingly shifting towards dynamic ownership intelligence, beneficial ownership analysis, and indirect exposure assessment.
Operational effectiveness is becoming critical
The Bank of Scotland case reinforces another major theme: operational effectiveness.
The issue was not the absence of controls on paper. It was whether those controls worked effectively in practice. Weak transliteration handling, ineffective escalation, screening limitations, and operational gaps prevented sanctions exposure from being identified early enough.
That is a significant regulatory signal.
Firms are increasingly being judged on whether they can operationalise sanctions intelligence effectively — not whether they can simply produce policies during a review.
The sanctions environment is evolving rapidly
The sanctions environment itself is becoming materially more complex.
In May 2026 alone, the UK issued at least five separate Russia sanctions notices, including a package containing 85 new designations linked to sanctions circumvention networks, intermediary entities, shipping structures, and Russia-linked operational support networks.
This is not simply an increase in names to screen against.
It represents an expansion in network complexity.
The UK and its allies are increasingly targeting:
• Shadow fleet operators
• Crypto-enabled payment channels
• Trade facilitators
• Intermediary jurisdictions
• Procurement networks
• Logistics and shipping structures
• Ownership and control arrangements designed to obscure exposure
Many sanctions frameworks currently operating across industry were designed for a much simpler pre-2022 risk environment.
That creates growing operational risk.
What firms should be doing now
Reassess screening effectiveness
Firms need to reassess whether their screening controls are genuinely capable of identifying modern sanctions exposure.
That means testing:
• Fuzzy matching logic
• Transliteration handling
• Alias management
• Threshold calibration
• False-negative risk
Many firms still rely too heavily on vendor defaults without independently validating screening effectiveness.
Strengthen ownership and control analysis
Point-in-time beneficial ownership checks are increasingly insufficient.
Firms should be implementing:
• Ongoing ownership monitoring
• Enhanced counterparty analysis
• Network and relationship mapping
• Escalation frameworks for indirect exposure risk
This is particularly important where high-risk jurisdictions, intermediary entities, or complex structures are involved.
Integrate intelligence across the organisation
Sanctions risk increasingly overlaps with AML, fraud, trade finance, cyber, and geopolitical risk. Firms operating siloed control environments are creating major visibility gaps. Intelligence-sharing between onboarding, AML, transaction monitoring, fraud, and sanctions functions is becoming critical.
Reassess governance and escalation frameworks
Senior management and boards increasingly need visibility over:
• Sanctions exposure trends
• Emerging typologies
• High-risk jurisdictions
• Material escalations
• Control-testing outcomes
Static annual reviews are no longer sufficient for a rapidly evolving sanctions environment.
Recent FCA findings reinforce this direction of travel. In its publication, Sanctions systems and controls: our findings, the FCA identified weaknesses across sanctions risk assessments, customer due diligence, screening controls, governance arrangements, escalation processes, and firms' understanding of sanctions exposure.
Taken together with recent OFSI enforcement actions, a clear pattern is emerging. Regulators are increasingly focused not simply on whether firms maintain sanctions controls, but whether those controls can identify sanctions exposure in practice.
The challenge is no longer whether firms can screen a sanctions list. It is whether organisations—from frontline teams through to senior management and boards—can identify, understand, and manage increasingly complex sanctions exposure across customers, counterparties, ownership structures, and wider commercial networks.
The consequence for firms that fail to adapt
The consequences are no longer limited to regulatory fines.
Weak sanctions controls increasingly create:
• Remediation costs
• Operational disruption
• Reputational damage
• Banking relationship pressure
• Increased supervisory scrutiny
• Personal accountability exposure for senior management
Perhaps most importantly, firms that fail to modernise sanctions capabilities risk becoming operationally unscalable.
The core regulatory expectation has fundamentally shifted.
Firms are no longer expected simply to screen sanctions lists.
They are increasingly expected to identify and manage sanctions exposure across the organisation.
The firms best positioned for this evolving environment will be those that can combine sanctions intelligence, ownership and control analysis, operational effectiveness, and governance into a coherent view of sanctions risk.
Ultimately, sanctions compliance is becoming less about screening names and more about ensuring that organisations can identify, assess, and respond to sanctions exposure wherever it exists.

