Bank of Scotland Sanctions Fine: Lessons for Law Firms

Updated October 2026: This article has been revised to reflect the official OFSI penalty notice, the SRA’s sanctions guidance and the replacement of the former OFSI Consolidated List by the UK Sanctions List.

A sanctions screening system returned no match. The customer presented a British passport. The account was opened.

But the individual was a designated person.

The Office of Financial Sanctions Implementation subsequently imposed a £160,000 monetary penalty on Bank of Scotland Plc. The case provides an important warning for solicitors: completing an electronic sanctions check is not the same as establishing that the check was effective.

The practical questions for law firms are whether their screening can cope with name variations, whether staff know how to escalate concerns and whether the firm can demonstrate that its controls work in practice.

What happened in the Bank of Scotland case?

OFSI imposed the penalty on 10 November 2025 and published the outcome in January 2026. The enforcement action concerned breaches of the Russia financial sanctions regime.

The designated person had been able to open an account using a British passport containing a spelling variation of their name. The variation was not identified as a potential match by the automated sanctions screening system.

As the SRA subsequently emphasised, the case demonstrates two important points:

  • sanctions matching must be capable of addressing relevant spelling and transliteration variations; and
  • nationality, residence or possession of a British passport must not be treated as evidence that sanctions risk is absent.

The official OFSI Bank of Scotland penalty notice should be consulted for the complete enforcement findings.

Why fuzzy matching matters

Names written originally in Cyrillic, Arabic or another script may be transliterated into the Latin alphabet in more than one way. Differences may also arise from spacing, punctuation, shortened names, aliases or the order in which names appear.

An exact-match system may therefore fail to return a result even where the person being checked is designated.

The SRA referred specifically to the importance of fuzzy matching following the Bank of Scotland case. This does not mean that there is one universally correct matching threshold. An excessively broad configuration can produce so many false positives that genuine alerts are obscured. A threshold that is too narrow may fail to identify relevant variations.

The firm should be able to explain:

  • what data source its screening system uses;
  • how the system handles spelling and transliteration differences;
  • whether known aliases and alternative identities are included;
  • how potential matches are presented to users;
  • who investigates and clears an alert;
  • what evidence is retained; and
  • when the provider last tested or changed its matching configuration.

Are law firms using the correct sanctions list?

Since 28 January 2026, the UK Sanctions List has been the single current source for UK sanctions designations.

The former OFSI Consolidated List is no longer updated. It remains available only for reference purposes.

Law firms should therefore check that:

  • policies and procedural documents refer to the UK Sanctions List;
  • bookmarked links and staff guidance no longer direct users to the former list for current screening;
  • training materials have been updated;
  • any external screening provider is using current UK designation data; and
  • the change has been communicated to the relevant staff.

A provider describing its product simply as an “OFSI check” should be asked to identify the precise source data it now uses.

Automation is not a complete control

An electronic verification result is evidence that a check was performed through a particular system at a particular time. It does not prove that every relevant person, name variation, ownership interest or control relationship was identified.

OFSI’s own analysis of the Bank of Scotland case stresses that automation is not a safety net. Firms need explicit contingency and escalation procedures for cases where:

  • the client’s name appears in different forms across documents;
  • a potential match is returned;
  • the available identifiers are incomplete;
  • the client is connected with an entity or person attracting sanctions concerns;
  • corporate ownership or control is unclear;
  • a payment is being made by or to a third party; or
  • new information emerges after the initial screening.

The appropriate checks depend upon the firm, the work undertaken and the particular matter. The important point is that the firm has considered its exposure and can explain why its controls are proportionate.

Do not screen on nationality stereotypes

The designated person in the Bank of Scotland case used a British passport. That fact is significant because it demonstrates why sanctions screening should not be driven solely by assumptions about nationality or residence.

The SRA’s guidance makes clear that UK sanctions may apply to UK nationals and people living in the United Kingdom. A low apparent geographic risk does not establish that a person is not designated.

This does not mean that every client presents the same level of risk. It means that nationality should not be used as a substitute for proper screening and identification.

PEP and sanctions screening are different

A politically exposed person is not necessarily subject to sanctions, and a designated person is not necessarily identified simply because a PEP check has been completed.

The two processes serve different purposes:

  • PEP controls concern the heightened corruption and bribery risks associated with particular public functions and relationships.
  • Sanctions controls concern restrictions imposed under applicable sanctions legislation, including asset freezes and prohibitions on making funds or economic resources available.

A screening product may check both datasets, but the firm should understand how the results are separated, investigated and recorded.

Should every law firm have a sanctions risk assessment?

The SRA states that a separate sanctions risk assessment is not compulsory, but recommends one as good practice, particularly for firms facing higher exposure.

Relevant risk factors may include:

  • high-value property transactions;
  • international clients or payments;
  • offshore structures;
  • complex or opaque beneficial ownership;
  • trust and company services;
  • high-net-worth or politically connected clients; and
  • the receipt or transmission of third-party funds.

A risk assessment is only useful if it reflects the firm’s actual work. Copying generic references to sanctioned countries into a policy will not demonstrate how the firm screens clients, investigates ownership and control, escalates potential matches or responds to a suspected breach.

What should firms ask their screening provider?

The Bank of Scotland case gives MLROs, MLCOs and compliance officers a practical reason to ask their provider the following questions:

  1. Does the system currently screen against the UK Sanctions List?
  2. How does it deal with spelling, alias and transliteration variations?
  3. Can the matching sensitivity be adjusted, and who controls it?
  4. What information is displayed when a potential match is found?
  5. Does the result distinguish sanctions, PEP and adverse-media checks?
  6. How are companies, beneficial owners and ownership or control risks addressed?
  7. How quickly is the underlying data updated after a new designation?
  8. What audit trail is retained when a user clears a possible match?
  9. How does the provider notify customers of material system or dataset changes?
  10. What testing has been conducted against alternative spellings and transliterations?

The answers should be assessed against the firm’s risk exposure. A provider’s contractual description of its service should not be treated as a complete substitute for the firm’s own understanding and controls.

What should happen when a possible breach is discovered?

A firm should not attempt to resolve a suspected sanctions breach informally or continue dealing with funds while the position remains unclear.

The appropriate response will depend upon the facts and applicable legislation, but may include:

  • stopping prohibited activity;
  • preventing funds or economic resources from being dealt with;
  • escalating the matter immediately to the responsible compliance personnel;
  • considering the firm’s statutory reporting obligations;
  • contacting OFSI where required;
  • considering whether a licence is required;
  • preserving a clear record of decisions and evidence; and
  • obtaining specialist legal advice.

Questions concerning legal professional privilege must be considered carefully. The SRA warns against taking a blanket approach that treats privilege as preventing any sanctions report.

Voluntary disclosure affected the penalty

Lloyds Banking Group disclosed the breaches on behalf of Bank of Scotland. OFSI applied the full 50% voluntary-disclosure discount that was available in the case, reducing the penalty from £320,000 to £160,000.

That should not be interpreted as a universal promise that every voluntary disclosure will receive the same reduction. The applicable enforcement guidance, timing, completeness of the disclosure, cooperation and circumstances of the breach all matter.

The practical lesson is narrower: a suspected breach should be escalated promptly, and firms should understand in advance who is responsible for considering notification to OFSI.

Sanctions compliance action plan for law firms

  1. Check the data source: confirm that internal and external systems use the current UK Sanctions List.
  2. Test name matching: use realistic spelling, alias and transliteration variations relevant to the firm’s client population.
  3. Review escalation: establish who receives an alert and who is authorised to clear it.
  4. Review ownership and control procedures: screening a company name alone may not identify a designated owner or controller.
  5. Update training: explain the difference between sanctions, PEP and AML checks.
  6. Review the risk assessment: ensure that it reflects the firm’s services, clients, transactions and geographical exposure.
  7. Check record keeping: retain evidence of the search, result, investigation and decision.
  8. Prepare for a breach: document the internal escalation, reporting and licensing process before it is needed.

Would your sanctions controls withstand scrutiny?

An independent review can test whether your firm’s policies, risk assessments, screening procedures, escalation controls and matter records are working as intended.

Independent AML audit Review your AML controls

Official resources

This article provides general compliance information and does not constitute legal advice on any sanctions designation, suspected breach, reporting obligation or licence application. Sanctions law and official guidance change, and the current legislation and official guidance should always be checked.