When sanctions against Russia began multiplying in 2022, the public images were hard to miss: Yachts seized in European ports, villas frozen, bank accounts linked to oligarchs blocked.
What I remember from the compliance side looked less visible and much more procedural. It was passports, residence permits, source-of-wealth documents, ownership charts, explanations of old bank transfers and increasingly detailed questions about where money had come from, which bank had touched it and through which institution an investment had been held. The questions kept changing because the rules kept changing. And gradually it became clear that the impact of sanctions was travelling much further than the people whose names appeared on sanctions lists.
By 2024, more than 3.5 million Russians had around RUB1.5 trillion ($17.8 billion) of foreign securities caught in asset freezes. According to Russia’s central bank, about 80 percent of those investors had less than RUB100,000 (approximately $1,200) in frozen foreign assets.
That statistic is important because it changes the picture. Many of the people caught up in the restrictions were ordinary retail investors. They had bought foreign shares, bonds and funds through regulated brokers. They were not sanctioned. They had not necessarily done business with sanctioned individuals. Some had very small portfolios. Yet they could no longer access their investments.
The reason is that by 2022 sanctions compliance had become a much bigger exercise than checking whether a client’s name appeared on a list.
There were several different ways into the sanctions net. Some restrictions were familiar. A person or company was designated, its assets were frozen and institutions had to determine whether entities connected to it were also caught through ownership or control. Then came rules that depended on other characteristics.
The EU, for example, introduced restrictions on accepting deposits above €100,000 ($115,600) from Russian nationals and Russian residents, subject to exemptions.
Russian nationality could matter even where somebody had been living outside Russia, unless the person also met one of the specified citizenship or residence exemptions. That changed the significance of a fairly ordinary field in a know your customer (KYC) file. A passport was no longer simply identification. It directly affected what a bank was legally permitted to do.
Once that happens, the questions multiply very quickly. The questions include:
- Where exactly does the client live?
- What is their tax residence?
- Do they have another citizenship?
- Where was their wealth earned?
- Does any part of it come from Russia?
- Through which banks has the money moved?
- Who owns the company holding the assets?
- Are there Russian shareholders?
- Has the client ever dealt with an entity that has since been sanctioned?
Before 2022, many of these questions already existed somewhere in anti-money laundering (AML) and KYC processes. What changed was their significance and the speed at which institutions had to connect them to new sanctions rules.
For compliance teams, answering the “Is this person sanctioned?” question was no longer enough. The whole financial chain mattered.
That became particularly obvious with securities.
In June 2022, the EU sanctioned Russia’s National Settlement Depository (NSD). That decision illustrates better than almost anything else how an ordinary investor could become trapped without being sanctioned personally.
A Russian investor might have bought shares in a U.S. company through a Russian broker. The shares themselves were perfectly ordinary. The company was not sanctioned. The investor was not sanctioned.
But securities do not travel directly from an issuer into an individual’s brokerage account. They sit inside layers of custody and settlement infrastructure. If one of those layers becomes blocked, everything above it can stop moving.
For large numbers of Russian investors, the relevant chain passed through NSD and international securities depositories. Once that infrastructure was caught by sanctions restrictions, investors discovered something rather unusual: They could still own an asset that they could no longer use in any meaningful sense. The security still existed. Its market price could move. The company could continue operating normally. But the investor might be unable to sell the position, transfer it to another custodian or receive cash through the normal settlement chain. Ownership had survived. Access had not.
Corporate actions made the situation even more complicated.
A dividend, coupon payment or other cash flow that would normally be completely routine could suddenly raise another sanctions question. European guidance had to deal with situations in which incoming money resulting from a securities transaction could itself fall within restrictions applying to deposits. This was the level at which sanctions became real for compliance departments: Not the political announcement, but the payment, the custody account, the dividend, the transfer instruction that could no longer be processed.
For those of us dealing with cross-border financial structures at the time, 2022 often felt like watching the compliance rulebook being rewritten while transactions were already in progress. EU, U.K. and U.S. sanctions did not always operate in the same way. New entities were being designated. Regulators were issuing guidance. Financial institutions were interpreting that guidance and, at the same time, setting their own internal policies.
Clients consequently found themselves answering increasingly detailed questions. Proof of residence might be followed by evidence of tax residence. Source of wealth could lead to source of funds for a specific transaction. A corporate structure might require explanations of every shareholder. An old transfer could generate questions about the sending bank. An investment could require an explanation of its custody history.
Much of this was justified. When the legal environment changes quickly, a compliance officer needs enough information to understand whether the transaction can legally proceed.
But another process was developing at the same time: De-risking. The distinction matters.
A risk-based process identifies an elevated risk, asks additional questions and then reaches a decision based on the answers. De-risking reaches a different conclusion: Examining every case individually has become too expensive, difficult or uncertain, so the institution reduces or eliminates exposure to the whole category.
Russian clients created an unusually difficult version of that choice. Take a Russian national who has lived abroad for many years, pays taxes abroad, accumulated wealth outside Russia and has no relationship with a sanctioned individual or company.
A financial institution can investigate all of those facts. Or it can conclude that servicing Russian nationals now consumes too much compliance capacity and creates too much regulatory or reputational uncertainty.
At scale, the attraction of the second approach is obvious. It is simple, it is consistent and it dramatically reduces the number of difficult decisions a compliance team has to make. It is also very blunt.
The pressure has not disappeared four years later. Similar cases involving non-sanctioned Russian clients have been reported across Europe since 2022.
Most recently, Swiss financial outlet Inside Paradeplatz reported that Russian nationals living in Switzerland, including holders of permanent residence permits, had received account-closure notices from Swissquote and its Yuh subsidiary.
Swissquote CEO Marc Bürki confirmed that some accounts were being closed, while stressing that Russian residents were not being exited systematically and pointing to sanctions exposure and strong economic links to Russia as examples of situations requiring action.
The episode illustrates how, even years after the initial sanctions shock, the boundary between legal restrictions, enhanced monitoring and an institution’s own risk appetite can remain difficult for clients to see.
As the above shows, a cross-border financial transaction rarely depends on one institution. A portfolio manager can approve a client. The fund administrator can approve the subscription. The custodian can accept the account. Then the correspondent bank rejects the payment. Or the payment bank accepts it and the receiving bank refuses it. Or everybody accepts the client, but a securities depository will not process the underlying asset. A transaction involving several institutions therefore tends to inherit the risk tolerance of the most conservative participant in the chain.
From the client’s perspective, the distinction can be almost invisible. The result is simply: No.
But there are several very different kinds of “No.” The law can prohibit the transaction. The transaction can be legally permissible but impossible because a sanctioned institution sits somewhere in the financial infrastructure. Or every relevant sanctions rule can permit the transaction while one institution decides that it falls outside its own risk appetite.
Those differences matter. A legal prohibition cannot simply be waived by a compliance department. An infrastructure problem may eventually have a technical solution. An internal risk decision is a choice made by the institution.
In the first months after the Russian invasion of Ukraine, those categories often blurred together. Clients would be told that something could not proceed “because of sanctions,” even when the actual reason lay partly or entirely in an institution’s internal policy.
I understand why that happened. Compliance departments were operating under enormous pressure. The consequences of getting a sanctions decision wrong could be severe, while the commercial benefit of making a difficult borderline transaction work might be small.
Faced with asymmetric risk, institutions naturally became conservative. But four years on, the distinction deserves more attention. Emergency controls have a tendency to become permanent processes. A rule introduced because a team did not have enough information in March 2022 can still be sitting in a compliance manual years later, long after systems, guidance and client information have improved.
That is where the Russian experience offers a lesson beyond Russia. Modern sanctions operate through a highly intermediated financial system. A government can draft a measure targeted at a particular bank, company or individual. Once that measure enters the financial infrastructure, however, every institution in the chain has to interpret it, implement it and decide how much additional risk it is willing to accept.
The legal perimeter is therefore only the beginning. There is also an infrastructure perimeter created by the banks, custodians, depositaries and payment systems through which assets move. And beyond that sits the institution’s own risk perimeter. For the ordinary investor at the end of the chain, all three can feel exactly the same.
This is why the compliance lesson from the Russian sanctions wave is less about whether firms should have been stricter or more permissive. It is about precision. Firms should know whether they are stopping a transaction because the law requires it, because the financial infrastructure cannot process it, or because their own risk appetite says no. Clients should ideally know that too.
The next major geopolitical sanctions event will again force institutions to make decisions quickly and with imperfect information. Compliance teams will again have to determine where the legal boundary sits, how much due diligence is enough and how much uncertainty the institution is prepared to accept. Some cautious decisions will inevitably affect people whom policymakers never intended to target.
The experience since 2022 shows how easily targeted sanctions can have consequences far beyond the individuals and entities they were designed to restrict.
Sanctions begin with laws, lists and designated entities. But their practical reach is ultimately determined by the financial plumbing through which money and securities have to move — and by the compliance decisions made at every point along the way.
Zezag Kaimova is a finance executive with extensive experience at the intersection of finance, operations, and compliance in asset management and investment businesses. Her work has included overseeing KYC and due diligence processes, supporting regulatory compliance, managing banking and broker relationships, and navigating cross-border financial and operational requirements across multiple jurisdictions.
