An FT investigation revealed that Kremlin-controlled fintech A7 tricked international banks into handling billions of dollars in sanction-busting payments to Russian state companies. The operation succeeded because correspondent banks treated A7 as a legitimate financial institution, processing SWIFT messages without adequate scrutiny of the underlying beneficial owners or transaction purposes.
If you're responsible for transaction monitoring at a correspondent bank, this isn't just a geopolitical issue. It's a blueprint for how state-backed actors exploit the trust architecture of international payments. Your screening controls likely focus on sanctioned entity names and addresses, but they probably don't catch payments routed through compliant-looking fintech intermediaries that mask the true parties to a transaction.
Here's how to build detection capabilities that address this gap.
Essential Preparations
Before implementing enhanced fintech screening, ensure you have:
Access to beneficial ownership data. Your KYC files for fintech clients must include ultimate beneficial owner (UBO) information verified within the past 12 months. If you're relying on self-reported data from 2019, you're screening against outdated intelligence.
SWIFT message parsing capability. You need to extract and analyze fields beyond the ordering and beneficiary customer (fields 50 and 59 in MT103 messages). Specifically, access intermediary institution fields (52a, 53a, 54a, 56a) and remittance information (field 70).
A sanctions intelligence feed that includes indirect exposure. Standard OFAC and EU sanctions lists tell you who you can't pay. You also need intelligence on entities controlled by sanctioned parties, shell companies with shared directors, and fintechs operating as de facto correspondent banks for sanctioned jurisdictions.
Step-by-Step Implementation
1. Map Your Fintech Client Relationships
Start with your nostro account holders. Pull a list of every fintech that holds an account with you and processes cross-border payments. For each one, document:
- Date of most recent UBO verification
- Jurisdictions where the fintech holds licenses
- Volume of payments to/from high-risk jurisdictions in the past 90 days
- Whether the fintech offers correspondent banking services to other institutions
Flag any fintech processing more than $10M monthly to Russia, Belarus, Iran, or other comprehensively sanctioned jurisdictions. These require immediate UBO re-verification.
2. Build Fintech-Specific Transaction Rules
Your existing transaction monitoring system likely has rules for structuring, rapid movement, and round-dollar amounts. Add three fintech-specific rules:
Fintech intermediary masking. Alert when a SWIFT payment lists a fintech in field 52a (ordering institution) but the ultimate ordering customer (field 50) uses a generic description or matches your fintech client's own name. This pattern suggests the fintech is acting as a front for an undisclosed principal.
Jurisdiction mismatch. Alert when the ordering customer's address (field 50) is in a low-risk jurisdiction but intermediary banks (fields 53a, 56a) route through multiple high-risk jurisdictions before reaching the beneficiary. Legitimate payments don't take circuitous routes.
Remittance information vagueness. Alert when field 70 contains only generic terms like "payment for services" or "commercial invoice" without invoice numbers or contract references. Legitimate cross-border payments include specific transaction identifiers.
Configure these rules in your transaction monitoring system's rule engine. If you're using a platform like Actimize or SAS, create custom scenarios. If you're using an in-house system, implement these as SQL queries against your SWIFT message archive.
3. Enhance Watchlist Screening for Indirect Exposure
Standard watchlist screening checks the ordering and beneficiary customer names against sanctions lists. Extend your screening to check:
- All intermediary institution names (fields 52a, 53a, 54a, 56a) against sanctions lists
- UBOs of those intermediary institutions against Politically Exposed Person (PEP) databases
- Corporate registries for shared directors between your fintech clients and sanctioned entities
You can't do this manually at scale. If you're using Dow Jones Risk & Compliance or Refinitiv World-Check, configure your screening profiles to include intermediary parties and UBO lookups. Run these enhanced screens on all fintech-originated payments above $50,000.
4. Implement Enhanced Due Diligence Triggers
Create a policy requiring enhanced due diligence when a fintech client meets any of these criteria:
- Processes more than 30% of payment volume to sanctioned or high-risk jurisdictions
- Has UBOs who are PEPs or have been previously associated with sanctioned entities
- Provides correspondent banking services to institutions in comprehensively sanctioned jurisdictions
- Shows rapid growth in cross-border payment volume (more than 200% year-over-year increase)
Enhanced due diligence means annual UBO re-verification, transaction sampling (review at least 50 payments per quarter), and source of funds documentation for payments above $100,000.
Validation: How to Verify It Works
Test your new controls with these validation steps:
Create synthetic test cases. Work with your sanctions compliance team to create test SWIFT messages that mimic the A7 pattern: a fintech intermediary, generic remittance information, and routing through multiple jurisdictions. Run these through your transaction monitoring system. Your fintech-specific rules should alert.
Sample recent fintech transactions. Pull 100 random SWIFT payments from your three highest-volume fintech clients in the past 30 days. Manually review the intermediary institution fields and remittance information. If more than 10% lack specific transaction identifiers or route through unexpected jurisdictions, your baseline risk assessment for those clients was inadequate.
Measure your UBO data completeness. Query your KYC system for all fintech clients. What percentage have UBO information verified in the past 12 months? If it's below 80%, you have a data quality problem that undermines all downstream screening.
Document your validation results. When examiners from the OCC or your primary regulator ask how you're addressing fintech-intermediated sanctions risk, you need evidence that your controls are functioning.
Maintenance and Ongoing Tasks
This isn't a one-time implementation. Sanctions evasion tactics evolve, and your controls must keep pace.
Quarterly rule tuning. Review alerts generated by your fintech-specific transaction monitoring rules. Calculate your false positive rate. If it's above 90%, your rules are too broad. Work with your sanctions analysts to refine the thresholds and logic.
Annual UBO re-verification. Set calendar reminders to re-verify beneficial ownership for all fintech clients every 12 months. Don't wait for account review cycles. Ownership structures change, and yesterday's compliant fintech can become tomorrow's sanctions evasion vehicle.
Monthly intelligence review. Subscribe to sanctions intelligence feeds from your government's financial intelligence unit (FinCEN in the US, FIU in the UK). When new entities are designated or new evasion typologies are published, assess whether your existing controls would catch them. If not, update your rules.
The A7 case demonstrates that sophisticated sanctions evasion doesn't require technical exploits or system compromises. It requires only that correspondent banks treat fintech intermediaries as transparent pass-through entities. Your job is to make that assumption costly by building controls that look through the intermediary to the ultimate parties and purposes behind each payment.



