Issue 004 · October 2026

ClearSanction Intelligence

Monthly compliance brief covering regulatory updates, enforcement actions and practical financial crime insights.

Concise monthly analysis for compliance officers, MLROs and financial crime teams.

ClearSanction Intelligence

Monthly Compliance Brief

Edition 004 · October 2026

October 2026 Compliance Brief

Controls that work: what enforcement, regulatory change and emerging financial-crime networks tell us about effective compliance.

  • When Sanctions Screening Fails
  • UK AML Strategy
  • Money Mule Networks
  • Iran Sanctions
Read the edition
Abstract compliance control network illustrating screening, investigation and evidence

ClearSanction Intelligence

Edition 004 · October 2026

October 2026 Compliance Brief

  • When Sanctions Screening Fails
  • UK AML Strategy
  • Money Mule Networks
  • Iran Sanctions

ClearSanction Intelligence

FEATURE 01

When Sanctions Screening Fails: Six Lessons from OFSI's £4.7m Citibank Penalty

On 2 September 2026, OFSI published details of a **£4,732,830.58 monetary penalty** imposed on Citibank, N.A., London Branch.

5 min read
Compliance
August 2026

When Sanctions Screening Fails: Six Lessons from OFSI's £4.7m Citibank Penalty

On 2 September 2026, OFSI published details of a £4,732,830.58 monetary penalty imposed on Citibank, N.A., London Branch.

The underlying conduct involved breaches of the Russia and Global Anti-Corruption sanctions regimes. OFSI's public notice is particularly useful because it goes beyond the headline penalty and describes weaknesses across an end-to-end sanctions control environment.

1. Alert Capacity Is Part of Screening Effectiveness

Following the significant increase in Russia-related designations, potential-match volumes increased and a backlog developed in third-level review.

The lesson is straightforward: screening effectiveness cannot be assessed only by whether technology generates an alert.

A control also depends on whether the organisation can investigate alerts quickly enough to prevent prohibited activity.

Compliance teams should therefore understand:

Normal alert volumes
Surge capacity
Ageing of unresolved alerts
Escalation thresholds
Whether higher-priority alerts can be separated from lower-value review work
What happens operationally when review capacity is exceeded

2. Matching Configuration Can Determine Whether an Alert Exists at All

OFSI's notice describes a screening issue involving the names Sovcomflot and PAO Sovcomflot.

The case demonstrates why seemingly minor differences in legal forms, prefixes, transliteration and naming conventions can materially affect screening outcomes.

The appropriate response is not simply to lower every matching threshold. Poorly calibrated screening can create excessive false positives and make genuine exposure harder to identify.

The objective should be a tested methodology capable of recognising meaningful identity correspondence while providing analysts with sufficient evidence to investigate the result.

3. Names Are Not the Only Useful Identifiers

OFSI identified circumstances in which designated banks appeared in payment information through BIC identifiers.

This raises a broader control-design question:

> Are relevant identifiers available to the screening process, or does the organisation depend too heavily on names?

Depending on the activity, useful identifiers may include BICs, company registration information, dates of birth, addresses, nationality, vessel identifiers or other structured data.

4. Ownership and Control Cannot Be Solved by Direct List Screening Alone

Some of the relevant exposure involved entities owned or controlled by designated persons.

A direct name-screening control can identify listed entities. It cannot, by itself, establish every relationship caught by applicable ownership and control rules.

Organisations therefore need a clear route from a screening result or ownership indicator to a legal and compliance assessment.

5. Screen the Transaction That Will Actually Be Executed

OFSI described a correspondent-banking process in which information could be added to a payment chain after an earlier screening stage.

That creates an important systems-design question:

At what point is the complete transaction screened?

If material information can be introduced after the screening decision, firms should determine whether the resulting transaction remains within the control.

6. Information Has to Reach the Control That Needs It

A firm may already possess information relevant to a sanctions decision and still fail to act on it.

Data availability, escalation and system integration therefore matter alongside the screening engine itself.

The practical test is whether relevant information can move from the point at which it is discovered to the people and controls responsible for making the decision.

Self-Reporting Is Also a Control

Citi received a 20% voluntary disclosure and co-operation discount. OFSI nevertheless identified delays, incomplete disclosures and inaccuracies during the reporting process.

That makes breach reporting another useful control to test.

Can the organisation:

Establish what happened?
Identify affected transactions?
Preserve evidence?
Explain the control failure?
Escalate internally?
Make a complete and accurate disclosure?
Demonstrate remediation?

What Should Organisations Do Next?

Run a sanctions-control stress test rather than another policy review.

Select scenarios involving:

A sudden increase in designations
A legal-form variation
A non-name identifier
An owned or controlled entity
Information added late in a payment flow
A potential breach requiring regulatory disclosure

Then test whether the control environment identifies, escalates, investigates and records each scenario as expected.

Primary source: OFSI, Imposition of Monetary Penalty – Citibank, N.A., London Branch, 2 September 2026.


FEATURE 02

The UK's New AML Strategy: From Compliance Activity to System Effectiveness

On 15 September 2026, the UK Government published its **Anti-Money Laundering and Asset Recovery Strategy 2026 to 2029**.

5 min read
Compliance
August 2026

The UK's New AML Strategy: From Compliance Activity to System Effectiveness

On 15 September 2026, the UK Government published its Anti-Money Laundering and Asset Recovery Strategy 2026 to 2029.

The strategy sets the direction for the UK's AML and asset-recovery system for the next three years.

For regulated organisations, the significance is not that an entirely new set of customer due-diligence rules appeared overnight. It is the direction of travel: greater focus on intelligence, disruption, asset recovery, coordination and the effectiveness of the overall response to money laundering.

Why It Matters

Financial-crime compliance can become dominated by process measures:

How many customers were reviewed?
How many alerts were closed?
Was the policy updated?
Was the training completed?

Those measures have value, but they do not necessarily show whether controls identify meaningful financial-crime risk.

What Compliance Leaders Should Consider

Boards, MLROs and financial-crime teams should ask:

Which money-laundering threats are most relevant to our business model?
Do our controls generate information that can be acted upon?
Are suspicious-activity decisions supported by usable evidence?
Can we connect customer, transaction, counterparty and geographic information?
Do governance metrics measure control effectiveness as well as operational throughput?
How quickly can emerging typologies be translated into controls?

What Should Organisations Do Next?

Use the strategy as a prompt to revisit the organisation's financial-crime risk assessment.

Do not simply add the document to the regulatory library. Identify which national priorities and threats intersect with your customers, products, channels and jurisdictions, and determine whether existing controls adequately address them.

Primary source: UK Home Office, Anti-money laundering and asset recovery strategy: 2026 to 2029, 15 September 2026.


FEATURE 03

Professional Money Laundering: What FATF's Hawala Report Means for Risk Teams

On 3 September 2026, FATF published new work examining professional money laundering, underground banking, hawala and other similar service providers.

5 min read
Compliance
August 2026

Professional Money Laundering: What FATF's Hawala Report Means for Risk Teams

On 3 September 2026, FATF published new work examining professional money laundering, underground banking, hawala and other similar service providers.

FATF reported that more than 80% of responding jurisdictions identified underground banking and similar systems among the principal channels or techniques used for professional money laundering.

Some case studies involved more than EUR 500 million being laundered within only a few months.

The Important Distinction

Hawala and other informal value-transfer mechanisms can have legitimate uses.

The compliance issue is not the label itself. It is understanding when networks or service providers are being exploited to move, settle or disguise criminal proceeds outside conventional financial channels.

Why It Matters to Regulated Firms

Professional money-laundering networks can separate the movement of value from the underlying predicate offence.

That means the regulated firm may encounter only one part of a much larger network.

Potential indicators may emerge through combinations of:

Customer behaviour
Counterparties
Cash activity
Geographic exposure
Unexplained third-party payments
Rapid movement of funds
Trade or settlement activity
Links to money or value transfer services

No single indicator necessarily establishes money laundering. The analytical value often comes from how those indicators interact.

What Should Organisations Do Next?

Review whether current transaction-monitoring scenarios and investigation procedures can identify activity consistent with professional money-laundering networks rather than focusing only on individual suspicious transactions.

Investigators should also understand what additional information would help distinguish legitimate remittance activity from potentially illicit settlement networks.

Primary source: FATF, Investigating Professional Money Laundering, Underground Banking, and the Use of HOSSPs, 3 September 2026.


FEATURE 04

Money Mules Are Becoming a Network Problem

On 23 September, the FCA published findings from its latest work on money mule activity.

5 min read
Compliance
August 2026

Money Mules Are Becoming a Network Problem

On 23 September, the FCA published findings from its latest work on money mule activity.

Its survey found that firms closed 238,396 suspected mule accounts in 2025, compared with 233,269 in 2024 and 184,935 in 2023.

The FCA cautions that increased closures may reflect customer growth and improvements in identifying and acting on suspected mule activity, rather than necessarily showing that mules make up a larger proportion of firms' business.

The more important finding is behavioural.

The FCA found examples of accounts used multiple times and across different fraud types, suggesting established criminal infrastructure rather than purely isolated or opportunistic misuse. It also found organised criminal groups moving illicit funds through multiple accounts before cashing out.

Why It Matters

A mule account is not necessarily the end of an investigation.

The account may be one node in a wider movement-of-funds network involving:

Other mule accounts
Fraud victims
Cash-out accounts
Payment intermediaries
Merchants
Cryptoasset services
Overseas counterparties

This connects directly with FATF's work on professional money laundering: financial-crime controls increasingly need to understand relationships and movement of value, not simply identify one suspicious account.

Who Is Affected?

The findings are particularly relevant to:

Banks
Payment institutions
Electronic money institutions
FinTechs
Firms providing accounts capable of rapid receipt and onward transfer of funds

What Should Organisations Do Next?

Test whether mule controls can identify:

Rapid dispersal of incoming funds
Repeated use across different fraud types
Linked counterparties
Common cash-out destinations
Previously identified mule infrastructure
Patterns spanning more than one customer account

Intelligence from a confirmed mule account should also feed back into detection and investigation rather than ending when that individual account is closed.

Primary source: FCA, Money mules: mule activity and cashing out findings, 23 September 2026.


FEATURE 05

Group Structures Do Not Remove Sanctions Risk: Lessons from the £7.44m Illumina Settlement

On 8 September 2026, HMRC published details of a **£7,438,840.13 compound settlement** paid by Illumina Cambridge Limited in relation to Russia sanctions offences.

5 min read
Compliance
August 2026

Group Structures Do Not Remove Sanctions Risk: Lessons from the £7.44m Illumina Settlement

On 8 September 2026, HMRC published details of a £7,438,840.13 compound settlement paid by Illumina Cambridge Limited in relation to Russia sanctions offences.

According to HMRC, the conduct occurred between July 2022 and January 2023 and involved the supply of sanctioned goods from one overseas company within the corporate group to another overseas company within the group for export to Russia and other destinations.

A compound settlement is an alternative to criminal prosecution. HMRC states that it will only offer one where it believes there is sufficient evidence to prosecute.

Why This Matters

The case is a reminder that multinational structures can create sanctions exposure across:

Group companies
Internal supply chains
Overseas subsidiaries
Distribution arrangements
Export destinations
End users

An internal group transaction should not automatically be treated as low risk simply because both parties sit within the same corporate structure.

Questions for Multinational Businesses

Which group entities can create UK sanctions exposure?
Are intra-group transactions subject to appropriate sanctions controls?
Can systems identify the ultimate destination of goods?
Are overseas teams working from consistent restrictions and escalation rules?
How are sanctions changes communicated across the group?
Who owns the final decision where several jurisdictions are involved?

What Should Organisations Do Next?

Map sanctions controls across the whole transaction chain, not only the UK contracting entity.

For goods and trade-related activity, determine whether the organisation can evidence the parties, goods, destination, end use and relevant approvals throughout the transaction.

Primary source: HMRC, Agreed compound settlements for strategic export and sanction offences, 8 September 2026.


FEATURE 06

Iran Sanctions Tighten: What Firms Need to Review Before 29 September

September has brought significant changes to the UK's Iran sanctions framework.

5 min read
Compliance
August 2026

Iran Sanctions Tighten: What Firms Need to Review Before 29 September

September has brought significant changes to the UK's Iran sanctions framework.

UK statutory guidance was updated on 9 September to reflect the Iran (Sanctions) (Amendments) Regulations 2026, while further amendments are due to take effect on 29 September 2026.

The changes affect areas including energy, software, maritime activity and ship-related services.

A further development arrived on 23 September when OFSI introduced a presumption of denial for licence applications from five designated Iranian banks operating in the UK:

Bank Sepah
Melli Bank plc
Bank Saderat
Persia International Bank
Bank Tejarat

OFSI says each application will still be considered on its facts, but applications from these banks will ordinarily be denied unless strict criteria are met.

OFSI also states that General Licence INT/2025/7628424 will not be renewed when it expires on 22 October 2026.

Why It Matters

Sanctions change does not end when a legal team reads a new regulation.

Operational implementation can require changes to:

Restricted-goods controls
Customer and counterparty screening
Transaction controls
Geographic risk rules
Licensing processes
Trade-finance procedures
Internal guidance
Staff training

The new licensing position also demonstrates an important distinction: the existence of an applicable licensing purpose does not automatically mean OFSI will grant a licence.

Who Is Affected?

The developments are particularly relevant to:

Banks and payment institutions
Trade-finance teams
Exporters
Corporates with Iran exposure
Professional advisers
Organisations dealing with frozen funds connected with designated Iranian banks

What Should Organisations Do Next?

Firms with Iran exposure should identify:

1Which activities are affected by the amended restrictions.
2Which customers, counterparties, products or transactions may fall within scope.
3Whether screening and transaction controls require adjustment.
4Whether pending licence applications involve one of the designated banks.
5Whether any activity relies on General Licence INT/2025/7628424.
6Whether activity previously permitted now requires a different assessment.

Publication note: This feature must be rechecked on 29–30 September after the amendments take effect.

Primary sources: UK Iran sanctions statutory guidance; Notice to Exporters 2026/18; OFSI, Presumption of Denial of Licence Applications for Designated Iranian banks, 23 September 2026.


FEATURE 07

Digital Assets and Sanctions Evasion: What OFAC's BitBank Action Tells Compliance Teams

On 17 September 2026, OFAC designated BitBank, its developer and associated individuals as part of an Iran-related action.

5 min read
Supply Chain
August 2026

Digital Assets and Sanctions Evasion: What OFAC's BitBank Action Tells Compliance Teams

On 17 September 2026, OFAC designated BitBank, its developer and associated individuals as part of an Iran-related action.

The US Treasury described the parties as components of digital-asset-based sanctions-evasion infrastructure.

The important compliance point is not that cryptocurrency is inherently suspicious. It is that digital assets can form one part of a broader network involving designated persons, companies, exchanges, wallets, counterparties and jurisdictions.

Move Beyond the Customer Name

A sanctions assessment involving digital assets may need to consider:

The customer
Relevant wallet addresses
Exchanges or VASPs
Transaction counterparties
Connected persons and entities
Jurisdictional exposure
Ownership and control
Transaction behaviour and purpose

A name-screening result and a wallet-screening result are therefore different pieces of evidence within a wider investigation.

What Should Organisations Do Next?

Firms exposed to digital assets should test whether their sanctions escalation process can combine customer identity, wallet information, counterparties and contextual risk information into one review.

The objective is not to label all digital-asset activity as high risk. It is to recognise sanctions exposure in the forms in which it can actually appear.

Primary source: US Department of the Treasury / OFAC, Iran-related action, 17 September 2026.


FEATURE 08

FCA AML Supervision Is Expanding: What Legal and Accountancy Firms Should Prepare For

The FCA is preparing to assume AML supervision of approximately **60,000 entities in the legal and accounting sectors**, with the change expected at the back end of 2028.

5 min read
Compliance
August 2026

FCA AML Supervision Is Expanding: What Legal and Accountancy Firms Should Prepare For

The FCA is preparing to assume AML supervision of approximately 60,000 entities in the legal and accounting sectors, with the change expected at the back end of 2028.

The regulator has described its intended approach as risk-based, intelligence-led and technology-enabled.

Importantly, the FCA's 22 September supervisory-reform guidance confirms that nothing changes immediately. Implementation depends on legislation, and affected businesses should continue following existing AML processes and dealing with their current supervisors.

Why It Matters Now

2028 may appear distant, but supervisory transition at this scale will require preparation by both the regulator and supervised populations.

Legal and accountancy firms should therefore watch how the future supervisory model develops rather than treating the announcement as either an immediate change or a distant issue that can be ignored.

What Firms Should Consider

Is the business-wide risk assessment specific to the firm's actual services and clients?
Can the firm demonstrate why its AML controls are proportionate to those risks?
Are CDD and EDD decisions evidenced?
Are suspicious-activity and escalation processes effective?
Can management information demonstrate control effectiveness?
Are group or parent-company controls being relied upon without sufficient local assessment?

What Should Organisations Do Next?

Treat the transition as a governance horizon rather than an immediate rule change.

Maintain compliance with current supervisory requirements while monitoring FCA communications about legislation, data, supervisory engagement and transition arrangements.

Primary sources: FCA, Financial crime: protecting the hive, 17 September 2026; FCA AML supervisory-reform guidance, 22 September 2026.


FEATURE 09

EU Russia Sanctions Keep Expanding: Why List Change Management Matters

Late September provides a useful reminder that sanctions-list management is not only about adding newly designated parties.

5 min read
Country Risk
August 2026

EU Russia Sanctions Keep Expanding: Why List Change Management Matters

Late September provides a useful reminder that sanctions-list management is not only about adding newly designated parties.

On 22 September, the Council of the European Union renewed its Ukraine territorial-integrity restrictive measures until 22 September 2029. The measures apply to more than 3,000 individuals and entities. The renewal also involved parties not being renewed and deceased individuals being removed.

On 24 September, the Council designated Xenia Fedorova, a former senior executive of RT France, under the EU regime addressing Russia's destabilising activities. The Council linked the designation to foreign information manipulation and interference.

The pace of change continued on 28 September.

The Council added a further 10 individuals and 17 entities under the Ukraine territorial-integrity regime in connection with the unlawful deportation, forcible transfer and assimilation of Ukrainian children. The entities include children's camps, sports centres and organisations operating in recreation, tourism and related activities.

Separately, the Council imposed restrictive measures on another 10 individuals under the EU regime addressing serious human-rights violations and repression in Russia. The listings include judicial and prosecutorial officials connected with proceedings involving members of the democratic opposition.

Why It Matters

Taken together, the September changes illustrate three operational requirements.

First, sanctions data must reflect removals, non-renewals and expiry decisions as reliably as new listings.

Second, designation risk cannot be inferred from sector alone. Organisations operating in areas such as tourism, recreation or education-related activity can become designated because of the conduct attributed to them.

Third, "Russia sanctions" are not one homogeneous regime. A Potential Match may arise under territorial-integrity, human-rights or hybrid-threat measures, and investigators need to understand the legal source and restrictions that apply.

Who Is Affected?

The developments are relevant to organisations with EU sanctions obligations and to global firms whose screening programmes include EU sanctions data.

They are particularly relevant to compliance teams responsible for:

Sanctions-list ingestion and change management
Ongoing monitoring
Potential Match investigation
Cross-border payments and customer due diligence
Recording the legal source and rationale for sanctions decisions

What Should Organisations Do Next?

Firms should confirm:

The 28 September additions have entered relevant screening and monitoring datasets
Renewals, removals and non-renewals are reflected promptly
Historic designations are not retained as if they remain legally active
Investigators can identify which sanctions regime generated a Potential Match
Procedures distinguish the restrictions and legal basis applicable to the relevant regime
Existing relationships are reviewed when a monitored person or entity becomes newly designated

The practical lesson is simple: sanctions change management is itself a compliance control. Accuracy depends not only on finding new names, but on maintaining a current representation of the legal position.

Primary sources: Council of the European Union, Russia sanctions timeline and press releases, 22, 24 and 28 September 2026.


FEATURE 10

AMLA's Emerging Rulebook: Risk-Based Supervision Becomes More Structured

September has provided another glimpse of how the EU's new AML architecture will operate in practice.

5 min read
Compliance
August 2026

AMLA's Emerging Rulebook: Risk-Based Supervision Becomes More Structured

September has provided another glimpse of how the EU's new AML architecture will operate in practice.

AMLA's consultation on ongoing monitoring closed on 3 September. Its consultation on the format of suspicion reports and transaction records closed on 20 September, and the consultation on draft technical standards for assessing the inherent and residual risk profile of non-financial obliged entities closed on 27 September.

The direction is towards greater consistency in how risk is assessed, relationships are monitored and information is reported.

Why It Matters

For firms operating across several EU jurisdictions, greater convergence could eventually reduce some differences in supervisory expectations.

But standardisation also increases the importance of structured, complete and usable compliance information.

This has implications for:

Customer data
Risk assessment
Transaction records
Case management
Investigation evidence
Suspicion reporting
Governance
Data quality

What Should Organisations Do Next?

EU-facing compliance teams should map AMLA's developing standards to existing processes now.

For non-financial firms in particular, consider whether the methodology used to assess inherent risk, mitigating controls and residual risk can be explained and evidenced consistently.

Primary source: AMLA public consultations, September 2026.


Practical Compliance Guide

12 Questions to Stress-Test Your Sanctions Controls

October's enforcement developments provide an opportunity to test sanctions controls against real failure modes rather than generic policy statements.

1Coverage — Can we demonstrate that all relevant customers, counterparties and other required parties enter the screening process?
2Data quality — What happens when names contain legal forms, transliterations, abbreviations or incomplete identifying information?
3Identifiers — Which non-name identifiers can our controls use, and where are they sourced?
4Thresholds — Have matching thresholds been tested against both false positives and realistic false-negative scenarios?
5Alert capacity — What volume of alerts can the review operation safely process before a backlog develops?
6Prioritisation — Can potentially higher-value alerts be identified when queues are under pressure?
7Ownership and control — What happens when the direct counterparty is not designated but an owner or controller may be?
8Transaction completeness — Can material information be added after screening has occurred?
9Escalation — Can information discovered in one team or system reach the person responsible for the sanctions decision?
10Evidence — Could an independent reviewer reconstruct why an alert was cleared or escalated?
11Breach response — Can we rapidly identify affected activity and prepare a complete, accurate regulatory disclosure?
12Stress testing — When did we last test the control against a designation surge or realistic sanctions scenario?

A Useful Exercise

Choose three recent cleared alerts and one simulated designation.

Attempt to reconstruct the complete decision using only the information retained in your systems.

Then introduce a sudden increase in alert volume.

The exercise should reveal whether the control works as an integrated process rather than simply whether the screening engine returns results.


Regulatory Watch

OFSI — Iranian Bank Licensing

OFSI introduced a presumption of denial for licence applications from five designated Iranian banks on 23 September.

Compliance takeaway: Review pending applications and activity relying on General Licence INT/2025/7628424 before its stated 22 October expiry.

FCA — Money Mules

The FCA's latest review identifies repeated use of mule accounts and movement through multiple accounts before cashing out.

Compliance takeaway: Test whether investigations identify linked behaviour and criminal infrastructure rather than ending at individual account closure.

EU — Russia Listings

The EU renewed territorial-integrity listings on 22 September, made a hybrid-threat designation on 24 September and added 10 individuals and 17 entities under the Ukraine territorial-integrity regime on 28 September. A separate 28 September decision listed another 10 individuals under the EU regime addressing serious human-rights violations and repression in Russia.

Compliance takeaway: Sanctions change management must process additions, removals, renewals and regime-specific legal changes accurately and promptly.

FCA — Cryptoasset Authorisation Gateway

The FCA's application period for the UK's future cryptoasset regulatory regime opens at 07:00 on 30 September 2026 and runs to 28 February 2027. The substantive regime is expected to take effect on 25 October 2027.

Compliance takeaway: Cryptoasset firms should determine which future regulated activities apply to them and prepare a timely, evidence-supported authorisation application. Existing MLR registration does not remove the need for FSMA authorisation where the new regulated activities are undertaken.

AMLA — Non-Financial Sector Risk

AMLA's consultation on risk assessment for non-financial obliged entities closed on 27 September.

Compliance takeaway: Legal, accountancy and other non-financial firms should watch how inherent and residual risk assessment becomes standardised under the EU framework.


Enforcement Watch

Citibank, N.A., London Branch

Authority: OFSI

Published: 2 September 2026

Penalty: £4,732,830.58

Issue: Breaches of Russia and Global Anti-Corruption financial sanctions.

Why it matters: The notice provides detailed lessons about alert backlogs, screening configuration, identifiers, ownership and control, payment architecture and disclosure.

Illumina Cambridge Limited

Authority: HMRC

Published: 8 September 2026

Compound settlement: £7,438,840.13

Issue: Russia sanctions offences relating to the supply of sanctioned goods within an overseas corporate group for export to Russia and other destinations.

Why it matters: Sanctions compliance needs to operate across group structures and international supply chains.


Country / Regime Focus

Iran: A Moving Sanctions Environment

Iran remains the regime to watch going into October.

September has included:

Updated UK statutory sanctions guidance
Further UK amendments due to take effect on 29 September
Changes affecting trade, energy, software, maritime activity and related services
OFSI's presumption of denial for licensing applications from five designated Iranian banks
The forthcoming expiry of General Licence INT/2025/7628424 on 22 October
Continued US action involving digital-asset sanctions-evasion infrastructure

For firms with Iran-related exposure, the practical requirement is disciplined change management.

A regulatory update should trigger a defined process:

CHANGE IDENTIFIED → LEGAL ANALYSIS → EXPOSURE MAPPED → CONTROLS UPDATED → AFFECTED ACTIVITY REVIEWED → EVIDENCE RETAINED

Editorial checkpoint: recheck this section on 29–30 September.


Emerging Risk

Financial Crime Is Increasingly a Network Problem

Several developments in this edition point towards the same operational challenge.

Professional money laundering can use networks of intermediaries. Money mule accounts can form established criminal infrastructure. Sanctions exposure can arise through ownership and control. Digital-asset activity can connect wallets, exchanges, counterparties and jurisdictions. Trade restrictions can involve several group companies and destinations.

The compliance unit of analysis therefore cannot always be a single customer or transaction.

That does not mean every investigation requires complex network analytics.

It means firms should know when the available evidence indicates that an investigation needs to move beyond the direct counterparty.

A useful escalation question is:

> What connected person, entity, wallet, account, jurisdiction or transaction would materially change this decision if we understood it better?


ClearSanction Product Update: Greater Control Over Screening Scope

During September, ClearSanction introduced additional screening-scope controls, giving compliance teams greater control over the checks performed for different screening workflows.

This includes the ability to run sanctions-only screening, excluding PEP screening where PEP checks are not required for the particular workflow. Screening-scope controls are available across individual and Bulk Screening workflows.

The change was informed by a real high-volume customer use case. Including PEP screening where it was not required was generating additional Potential Matches for analysts to review without supporting the purpose of that particular sanctions control.

The wider principle extends beyond ClearSanction: screening effectiveness should not be measured by how many alerts a system produces. Screening configuration should reflect the organisation's regulatory obligations, risk assessment and the purpose for carrying out the check.

Giving analysts appropriate control over screening scope can help reduce unnecessary review activity while maintaining the checks required for the relevant compliance process.

> Practical takeaway: Screening breadth should be deliberate. Compliance teams should be able to explain why particular screening checks are included in a workflow, what risks they address and how the resulting Potential Matches are reviewed.


The Intelligence Brief

October in 60 Seconds

ENFORCEMENT — OFSI's Citibank penalty shows how sanctions failures can emerge across the whole control chain, not only the screening engine.
UK AML — The Government's 2026–2029 strategy shifts attention towards the effectiveness of the wider AML and asset-recovery system.
PROFESSIONAL MONEY LAUNDERING — FATF is highlighting underground banking and hawala as important channels used by professional laundering networks.
MONEY MULES — FCA findings show how mule activity can form part of established criminal infrastructure spanning multiple accounts.
TRADE SANCTIONS — HMRC's Illumina settlement demonstrates the need to manage sanctions exposure across corporate groups and supply chains.
IRAN — UK restrictions and OFSI's licensing stance are tightening, with a key implementation date on 29 September.
DIGITAL ASSETS — OFAC action reinforces the need to consider wallets and digital-asset infrastructure within wider sanctions investigations, while the FCA's cryptoasset authorisation gateway opens on 30 September.
EU SANCTIONS — Further Russia-related listings on 28 September, alongside renewals, removals and hybrid-threat measures earlier in the month, reinforce the importance of sanctions-data change management.
SUPERVISION — The FCA is preparing to take on AML supervision of the legal and accountancy sectors, but current supervisory arrangements remain in force.
CONTROL TESTING — October's practical guide turns recent enforcement findings into a 12-question sanctions stress test.

What to Watch Before Publication

Final implementation guidance and licensing material relating to the UK Iran sanctions changes taking effect on 29 September
Confirmation of the FCA cryptoasset authorisation gateway opening on 30 September
Any further OFSI or OTSI enforcement action
Further OFAC Iran or Russia-related designations
Any post-consultation AMLA developments
FATF publications or announcements before month end
Material UK AML, sanctions or economic-crime announcements
Any late-September development strong enough to replace a lower-priority feature

Regulatory Updates
Regulatory Watch

Key regulatory and sanctions developments compliance teams should be aware of this month.

OFSI

Citibank Penalty Exposes End-to-End Sanctions Control Weaknesses

OFSI imposed a £4,732,830.58 monetary penalty on Citibank, N.A., London Branch in relation to breaches of the Russia and Global Anti-Corruption sanctions regimes.

Why it matters

The case provides detailed lessons on alert backlogs, matching configuration, identifiers, ownership and control, payment architecture and regulatory disclosure.

Recommended action: Stress-test sanctions controls against designation surges, naming variations, non-name identifiers, ownership and control scenarios and potential breach reporting.
UK AML

Government Publishes 2026–2029 AML and Asset Recovery Strategy

The UK Government published its Anti-Money Laundering and Asset Recovery Strategy 2026 to 2029 on 15 September.

Why it matters

The strategy reinforces an outcomes-focused approach built around intelligence, disruption, coordination and asset recovery rather than compliance activity alone.

Recommended action: Compare national priorities and threats with the organisation's financial-crime risk assessment, controls and management information.
FATF

Professional Money Laundering Networks Move Into Focus

FATF published new work on professional money laundering, underground banking, hawala and other similar service providers on 3 September.

Why it matters

The report reinforces that regulated firms may encounter only one part of a wider laundering and settlement network.

Recommended action: Review whether monitoring and investigation processes can identify linked behaviour, counterparties and movement of value rather than isolated suspicious transactions alone.
FCA

Money Mule Findings Point to Established Criminal Infrastructure

The FCA reported that 238,396 suspected mule accounts were closed in 2025 and found examples of accounts used repeatedly and across different fraud types.

Why it matters

Organised criminals can move proceeds through multiple accounts before cashing out, making linked-account and network behaviour increasingly important to financial-crime controls.

Recommended action: Test whether mule controls identify rapid onward movement, repeated use, linked counterparties and intelligence generated by previously confirmed mule accounts.
HMRC

Illumina Pays £7.44m Russia Sanctions Compound Settlement

HMRC published a £7,438,840.13 compound settlement with Illumina Cambridge Limited relating to Russia sanctions offences involving intra-group supply of sanctioned goods.

Why it matters

Sanctions exposure can arise across overseas subsidiaries, group transactions, supply chains and end destinations.

Recommended action: Map sanctions controls across the complete corporate and transaction chain, including group companies, goods, destination and end use.
OFSI

Licensing Presumption Tightens for Designated Iranian Banks

On 23 September, OFSI introduced a presumption of denial for licence applications from five designated Iranian banks operating in the UK.

Why it matters

The existence of an applicable licensing purpose does not mean a licence will be granted, and OFSI says applications will ordinarily be denied unless strict criteria are met.

Recommended action: Review Iran-related licensing assumptions, pending applications and transactions previously relying on General Licence INT/2025/7628424, which OFSI says will not be renewed when it expires on 22 October 2026.
FCA

UK Crypto Regulation Moves Into Implementation

The FCA's application gateway for the UK's future cryptoasset regulatory regime opens at 07:00 on 30 September 2026, with the substantive regime expected to come into force on 25 October 2027.

Why it matters

The UK crypto framework is moving from rulemaking towards implementation, and existing MLR registration is not equivalent to authorisation under the future FSMA regime.

Recommended action: Cryptoasset firms should assess which regulated activities apply to their business and ensure governance, financial-crime controls and supporting evidence are ready for the authorisation process.
EU

EU Russia Listings Expand Again in Late September

The Council renewed its Ukraine territorial-integrity listings on 22 September, made a hybrid-threat designation on 24 September and on 28 September added 10 individuals and 17 entities over the unlawful deportation of Ukrainian children, alongside a separate 10 individual human-rights listing decision.

Why it matters

Sanctions change management needs to capture additions, removals and renewals across several legal regimes, while designation risk increasingly extends beyond traditional military and commercial actors.

Recommended action: Confirm list updates flow promptly into screening and monitoring and that obsolete designations are removed when the legal position changes.
AMLA

EU Non-Financial Sector Risk Methodology Consultation Closes

AMLA's consultation on draft technical standards for assessing inherent and residual risk profiles of non-financial obliged entities closes on 27 September.

Why it matters

The work supports a more consistent and proportionate EU framework for risk-based supervision of non-financial sectors.

Recommended action: EU-facing legal, accountancy and other non-financial firms should monitor the final standards and map emerging expectations to their risk assessment methodology.
Compliance Tip

Select a realistic sanctions scenario and follow it end to end. Test the data, screening result, investigation, escalation, decision, evidence and breach response rather than reviewing the written procedure alone.

Compliance Insight

A Control That Exists Is Not Necessarily a Control That Works

Recent enforcement and supervisory findings point towards the need to test controls as connected operational systems rather than isolated policies, alerts or technologies.

“Effective financial-crime compliance depends on whether controls identify the right risk, at the right point, and whether the organisation can act on the information they produce.”
1Identify
2Screen
3Investigate
4Act
5Evidence
6Stress-test
Key Takeaway

Recent enforcement and supervisory findings point towards the need to test controls as connected operational systems rather than isolated policies, alerts or technologies.

Product Intelligence

New in ClearSanction

ReleasedIn ProgressComing Soon
Canonical screening and entity resolution — released to production in September 2026.Released
Potential Matches — screening results are presented for analyst review rather than as customer-risk outcomes.Released
Match Score — represents the strength of identity correspondence and is not a customer-risk score or compliance decision.Released
API improvements for ERP integrationIn Progress
Enhanced reporting suiteIn Progress
Team managementIn Progress
Beneficial ownership screening (OFAC 50 Percent Rule)Coming Soon
Trade & export control datasetsComing Soon
Iran country intelligenceComing Soon
North Korea country intelligenceComing Soon
Myanmar country intelligenceComing Soon
Belarus intelligence moduleComing Soon
Venezuela sanctions spotlightComing Soon

On the roadmap

  • Beneficial ownership screening (OFAC 50 Percent Rule)
  • Trade & export control datasets
  • Iran country intelligence
  • North Korea country intelligence
  • Myanmar country intelligence
  • Belarus intelligence module
  • Venezuela sanctions spotlight

Stay ahead of sanctions, PEP and financial crime risk.

Book a demo or start screening with ClearSanction.

ClearSanction Intelligence

Stay Ahead of Financial Crime

Receive the monthly ClearSanction Intelligence Brief with regulatory updates, enforcement actions and practical compliance guidance.

No spam. Unsubscribe at any time.