A7 alert and doubled OFSI fines: the new sanctions perimeter for UK finance
The UK has issued its first industry-wide alert against Russia's A7 sanctions evasion network and doubled the maximum OFSI penalty to 100% of breach value. Senior leaders in banking, payments and asset management now face a materially higher enforcement bar and explicit expectations to screen for third-country conduits.
The Treasury has moved the UK's sanctions regime onto a more aggressive footing. On 31 August, the Chancellor announced the first ever nationwide alert against the A7 network and doubled the maximum fine available to the Office for Financial Sanctions Implementation from 50% to 100% of the value of a sanctions breach (HM Treasury). For boards and executive committees in regulated firms, this is a step change in both intelligence-sharing and financial exposure.
Key Executive Takeaways
- The UK has issued its first ever nationwide alert against Russia's A7 sanctions evasion network, giving firms named typologies to screen against and removing the defence of ignorance.
- OFSI's maximum civil penalty has doubled to 100% of the value of a sanctions breach, meaning enforcement risk now matches transaction size rather than a capped proportion of it.
- A7 claims to have settled more than $86 billion of transactions in its first year using third-country financial institutions, so correspondent banking, trade finance and payments intermediaries carry the highest residual risk.
The alert itself, issued jointly by the National Crime Agency and government, is designed to expose the methods A7 uses to move value through third-country financial institutions and cross-border payment chains (HM Treasury). The scale claim is striking: A7 says it has settled more than $86 billion in its first year of operating, and the network has been linked to Iranian state-associated actors as well as Russia (HM Treasury). Once a public alert exists, supervisors and prosecutors will treat firms that fail to reflect its typologies in transaction monitoring as having accepted a known risk. The evidentiary burden shifts.
The fine change is the more consequential lever. Moving the OFSI ceiling from 50% to 100% of breach value means the civil penalty can, in principle, exceed the commercial margin on almost any transaction a bank or payments firm might process. Combined with OFSI's existing power to impose penalties on a strict civil basis, this recalibrates the internal economics of sanctions compliance: the cost of a single missed screening hit can now match the notional of the payment itself. Finance and risk committees that have been sizing sanctions provisions against historical fine distributions will need to rebuild those assumptions.
The operational implications concentrate in three places. Correspondent banks and payment service providers sit closest to the A7 typology, because the network's model relies on third-country institutions to intermediate cross-border flows (HM Treasury). Trade finance and commodity-linked lending face parallel exposure where documentation obscures ultimate counterparties. And private banking and wealth teams should read this alongside the FCA's parallel signalling on integrity failures, where the regulator recently banned three former Dolfin executives over a scheme that generated at least £35.5m in fees while bypassing UK visa rules (FCA). The common thread is that UK authorities are willing to publish detailed conduct findings and pursue individuals, not just firms.
For senior leaders, the near-term action is unglamorous but specific: confirm the A7 alert has been ingested into financial crime frameworks, revisit third-country correspondent exposures, and re-price sanctions risk in capital and provisioning models against the new 100% ceiling. Boards that treat this as a compliance memo rather than a change in the enforcement contract will be exposed on the next inspection cycle.
Sources
What this reveals
The A7 alert and doubled OFSI ceiling expose a common failure mode: sanctions provisioning and screening calibration are usually anchored to historical enforcement patterns rather than to current supervisory intent. Firms that treat published typologies as reference material rather than as a live update to their risk model are running on an assumption, that ignorance remains a partial defence, which regulators have now explicitly removed. Other leadership teams may wrongly believe their existing correspondent banking and payments controls are proportionate because they have never been tested against a 100% penalty economics or a named typology they failed to screen for. This matters beyond any single firm because it signals a broader shift where the cost of a missed signal now scales with transaction notional, not with historical fine averages.
Questions accountable leaders should ask
- 01When did your transaction monitoring last incorporate a named public alert as a specific typology, and can you evidence the change control that followed?
- 02If OFSI imposed a penalty at 100% of breach value on your largest plausible missed hit, would your current sanctions provision and capital planning absorb it without a going-concern conversation?
- 03How confident are you that your correspondent banking, trade finance, and payments intermediary relationships are being screened for third-country conduit risk, rather than only for directly designated parties?
- 04Who on your executive committee owns the assumption that historical fine distributions are a valid basis for sizing sanctions risk, and when was that assumption last challenged?
- 05If a supervisor asked you to demonstrate how the 31 August alert changed your controls, monitoring thresholds, or board reporting within 30 days, what would you show them?
What accountable leaders should do now
- 1Commission an immediate gap assessment mapping the A7 typologies published in the NCA alert against current transaction monitoring rules, screening logic, and correspondent banking due diligence, with a documented change log.
- 2Re-baseline sanctions risk provisioning and capital planning against the new 100% penalty ceiling, and put the revised assumptions in front of the risk committee before the next reporting cycle.
- 3Identify the three or four business lines closest to third-country conduit risk (correspondent banking, cross-border payments, trade finance) and require line-one leaders to attest to controls specifically against A7-style typologies.
- 4Update board and executive committee reporting so that public alerts, supervisory statements, and enforcement pattern shifts are treated as live inputs to risk appetite, not as background reading.
- 5Rehearse a supervisory conversation on what the firm has done since 31 August, and use the gaps that surface in the rehearsal to prioritise remediation before an actual examination.
Explore the practical guide
This guide sets out how senior leaders at FCA regulated firms should identify, assess, and manage stakeholder risk in a way that stands up to supervisory scrutiny. After reading it, you will know how to structure a stakeholder risk framework that aligns with Consumer Duty, SM&CR, and Threshold Conditions, and where firms typically fail.
Read the guideWhere the operating environment may be moving faster than internal reporting reflects
Polar Insight's Signal Briefings translate emerging regulatory, stakeholder, and market developments into a clear implication for accountable leaders.
Explore Signal BriefingsRelated insights
The FCA's bid for legal and accounting AML supervision: what changes for regulated firms
Steve Smart used the Law Society Economic Crime Conference to signal the FCA is ready to take on anti-money laundering supervision of the legal and accounting sectors. For financial services leaders, the move reshapes the intelligence-sharing perimeter and raises the bar on what 'partnership' with the regulator now requires.
Customs reference documents on a two-month cycle: the compliance load nobody budgeted for
HM Treasury and HMRC have issued another round of updates to the UK's authorised use, tariff suspension and import duty relief reference documents, with new versions taking effect on 1 October 2026. For regulated firms with trade finance, supply chain and treasury exposure, the cadence itself is now the governance issue.
Crypto authorisation opens 30 September: the gateway is now the strategy
The FCA has published perimeter guidance for the UK's cryptoasset regime, with the authorisation gateway opening on 30 September 2026 and the regime taking effect on 25 October 2027. For senior leaders at crypto firms and the banks, custodians and asset managers adjacent to them, the thirteen-month window between gateway opening and regime commencement is now the defining planning horizon.
Stakeholder Signals
Consequential developments in financial services and other regulated markets, with one implication for accountable leaders.
