Correspondent Banking Due Diligence: What Regulators Expect

How correspondent banks assess respondent institutions: FATF Rec 13, the Wolfsberg CBDDQ, nested accounts and Section 312 enhanced due diligence.
Alexandre Berkovic

TL;DR: Correspondent banking due diligence is the process a correspondent institution uses to assess and monitor the financial crime risk of a respondent bank it provides accounts and payment services to. FATF Recommendation 13 treats cross-border correspondent relationships as inherently higher risk and requires enhanced measures at onboarding and throughout the relationship. According to the Reserve Bank of Australia's June 2023 Bulletin, drawing on Bank for International Settlements data, correspondent banking relationships worldwide fell roughly 30% between 2011 and 2022 while transaction volume through the network rose 61% — de-risking concentrated the flows rather than removing the risk.

What Correspondent Banking Due Diligence Actually Requires

Five-step flow diagram of the FATF Recommendation 13 correspondent banking obligations: Gather, Assess, Approve, Document, and Confirm payable-through account CDD
FATF Recommendation 13 imposes five obligations on the correspondent institution, ending with confirmation that the respondent has performed CDD on payable-through account users.

Correspondent banking due diligence is the assessment a correspondent bank performs on a respondent institution before opening a correspondent account, and repeats on a risk-based cycle for as long as that account stays open. The correspondent is extending its own access to payment systems, clearing infrastructure and in many cases the U.S. dollar to an institution it does not supervise and whose customers it will never meet. That is the exposure the diligence exists to price.

FATF Recommendation 13 sets the baseline for cross-border relationships and imposes five obligations on the correspondent institution:

These obligations sit on top of, not instead of, the standard customer due diligence requirements that apply to every customer relationship under Recommendation 10. The distinction matters at exam time: a correspondent bank that has collected the respondent's licensing documents and policy manual has completed the intake, not the assessment.

The Basel Committee is direct about that gap. In its revised annex on correspondent banking, the Committee states that banks "should not treat the CDD process as a 'paper-gathering exercise' but as an essential step to support assessment of ML/FT risk," and expects the correspondent to test the respondent's controls on a risk-sensitive basis — reviewing sanctions screening coverage, checking whether internal audit examines those controls, and where appropriate speaking directly with the respondent's compliance officer. The same annex also draws a boundary compliance teams routinely over-read: a correspondent is not required to apply CDD measures to the respondent's customers, or to duplicate data the respondent already holds.

The Wolfsberg Questionnaire Is a Starting Point, Not the Answer

The Wolfsberg Group's Correspondent Banking Due Diligence Questionnaire is the industry-standard instrument for collecting respondent information, and version 1.4 has been the current release since February 2023. It covers ownership and licensing, products and services, AML program structure, sanctions policy and governance, transaction monitoring, testing and training — plus a dedicated fraud section added in version 1.4.

Two details in the CBDDQ carry more weight than their placement suggests. The Products and Services section asks whether the respondent offers payable-through accounts, whether it allows downstream relationships with domestic banks, foreign banks, money services businesses and payment service providers, and — separately — whether it has processes in place to identify those downstream relationships. A respondent that permits nesting but cannot identify it has answered honestly and disclosed a control failure in the same breath.

The questionnaire standardizes collection. It does not perform the assessment. The Wolfsberg Group's FAQ guidance sets the recommended refresh timeframe at 12 to 18 months, replacing a fixed expiry date so that renewal aligns with the correspondent's own CDD review cycle. Between refreshes, the correspondent still owes independent verification: corporate and beneficial ownership registries, regulator licensing databases, adverse media screening on the institution and its senior management, and reconciliation of the respondent's stated business against its actual payment traffic. A questionnaire that contradicts observed activity is a finding, not a file.

Nested Accounts and Payable-Through Accounts Carry the Real Exposure

Nested — or downstream — correspondent banking occurs when other financial institutions use a correspondent bank's services indirectly, through their relationship with that correspondent's direct respondent. The respondent becomes a conduit, and the correspondent is effectively banking institutions it never onboarded, never risk-rated, and in many cases cannot name. The FFIEC BSA/AML Examination Manual notes that indicators of nested activity include transactions to or from jurisdictions where the respondent has no known business, and volume or frequency that significantly exceeds expected activity for that respondent.

A payable-through account is a narrower and sharper version of the same problem: a correspondent account through which the respondent permits its own customers to engage directly, or through a subaccount, in banking activities in the United States. The respondent's customers are transacting on the correspondent's rails under the respondent's name.

Section 312 of the USA PATRIOT Act, implemented through 31 CFR 1010.610, makes both scenarios explicit obligations for U.S. institutions. Enhanced due diligence becomes mandatory — not risk-based, mandatory — when the foreign bank operates under an offshore banking licence, a licence from a jurisdiction designated non-cooperative with international AML principles, or a licence from a jurisdiction the Secretary of the Treasury has designated as warranting special measures. Where those triggers apply, the FFIEC Examination Manual requires the bank to obtain and consider the foreign bank's AML program, monitor transactions through the account, identify any person with authority to direct transactions through a payable-through account along with the source and beneficial owner of the funds, and determine whether the respondent in turn maintains nested accounts.

The ownership requirement is where files most often thin out. For any foreign bank subject to enhanced due diligence whose shares are not publicly traded, the correspondent must identify each owner holding 10% or more of any class of securities and document the extent of that interest, treating members of the same family as a single person. That is a beneficial ownership identification exercise against opaque cross-border structures, and a self-declared ownership chart does not satisfy it. When the required diligence cannot be completed, the regulation prescribes the response: refuse to open the account, suspend activity, file a SAR, or close the relationship.

De-Risking Costs More Than It Saves

Wholesale exit is the most common response to correspondent risk and the least defensible one. FATF states plainly in its guidance on correspondent banking services that de-risking — terminating relationships with entire regions or classes of customer to avoid managing risk rather than to manage it — is not in line with the FATF Recommendations, and that it produces financial exclusion, less transparency, and greater money laundering and terrorist financing exposure, not less.

The measured effect is substantial. The Reserve Bank of Australia's June 2023 Bulletin, drawing on Bank for International Settlements CPMI data, reports that correspondent banking relationships declined about 30% between 2011 and 2022 and 4% in 2022 alone, while transaction volume and value across the network rose 61% and 37% over the same twelve years. Fewer institutions now carry more flow. In the South Pacific the retreat ran roughly twice as severe as the global average, with active correspondents falling around 60%.

Exiting a corridor does not retire the risk. Payments reroute through nested arrangements the correspondent can no longer see, or into unregulated channels where it has no visibility at all. Correspondents that keep the relationship and price the diligence properly retain the transaction data, and the transaction data is the control.

Building a Respondent Review That Survives an Exam

A defensible respondent review process is judged on whether an examiner can reconstruct the institution's reasoning from the file alone. Six dimensions determine whether that reconstruction succeeds.

Dimension What the file has to show
Risk tiering and review cadence A documented rating per respondent with the factors that produced it, and a review frequency tied to that rating rather than to a uniform annual calendar
Independent verification Licensing, ownership and enforcement claims corroborated against regulator registries and public sources, not accepted on the questionnaire alone
Activity reconciliation Observed payment behaviour compared against the type, purpose and anticipated activity recorded at onboarding, with variances investigated and documented
Nested and payable-through detection A method for identifying downstream institutions and subaccount users, plus evidence that the determination was made and refreshed
Senior management approval Evidence of deliberation by an empowered approver at onboarding and at material risk changes, with the information the approver relied on
Exit and escalation criteria Pre-defined thresholds for restricting, suspending or terminating a relationship, and documentation of every occasion they were applied or overridden

Activity reconciliation is the dimension most programs underinvest in and the one examiners test hardest. Section 312 requires a periodic review of correspondent account activity sufficient to determine consistency with what the correspondent was told about the account's purpose and expected use. That is not a request to scrutinize every transaction. It is a request to demonstrate that the institution knows the difference between expected and unexpected flow, which depends on transaction monitoring tuned to the respondent's stated business model rather than to generic typologies.

The practical constraint is capacity. A respondent review done properly generates a long evidence trail — registry cross-checks, adverse media on the institution and its principals, ownership traced through multiple jurisdictions, payment patterns compared against a stated profile, and a written rationale tying all of it to a rating. Done manually across several hundred respondents on a 12-to-18-month cycle, that work either consumes the team or gets compressed into a checklist. Compressed reviews produce the finding that a program existed on paper but was not applied.

Where Sphinx Fits

Sphinx operates at the investigation and documentation layer of periodic review workflows. For correspondent banking portfolios, its agents assemble the evidence a respondent review depends on — registry and licensing checks, adverse media on the institution and its principals, ownership tracing, and reconciliation of stated business activity against observed payment behaviour — then draft the written rationale and route material risk to an analyst for judgment. Every step is logged and source-linked, so the reasoning behind a rating is reconstructable rather than reconstructed after the fact.

Frequently Asked Questions

What is the difference between a correspondent bank and a respondent bank?

The correspondent bank provides the account, payment, clearing and settlement services. The respondent bank holds that account and uses those services to reach markets, currencies or infrastructure it cannot access directly. Due diligence obligations run from the correspondent toward the respondent, because the correspondent is the party extending access to its own payment rails.

Is the Wolfsberg CBDDQ legally required?

No. The Correspondent Banking Due Diligence Questionnaire is an industry standard published by the Wolfsberg Group, not a regulation. It has become the de facto baseline because it maps to FATF Recommendation 13 expectations, and declining to complete it is itself a risk signal to most correspondents. Completing it does not discharge the correspondent's obligation to verify and assess what the answers say.

Does a correspondent bank have to conduct due diligence on its respondent's customers?

Not as a general rule. The Basel Committee is explicit that a correspondent is not required to apply CDD measures to the respondent's customers or to duplicate data the respondent already holds. Two exceptions narrow that: payable-through accounts, where the correspondent must identify persons with authority to direct transactions and the beneficial owner of the funds, and cases where suspicious activity reporting or sanctions obligations require information about the underlying activity.

How often should correspondent banking due diligence be refreshed?

On a risk-based cycle, with higher-risk respondents reviewed more frequently. The Wolfsberg Group recommends refreshing the CBDDQ every 12 to 18 months, and several supervisors expect quarterly review for high-risk relationships. Review should also be event-driven: a change in ownership, licensing status, enforcement history or payment behaviour warrants reassessment regardless of the calendar.

What triggers mandatory enhanced due diligence under Section 312?

Three circumstances, set out in 31 CFR 1010.610(c). A correspondent account for a foreign bank operating under an offshore banking licence, under a licence from a jurisdiction designated non-cooperative with international AML principles, or under a licence from a jurisdiction the Secretary of the Treasury has designated as warranting special measures. Where any of the three applies, enhanced due diligence is a requirement rather than a risk-based option.

Get Your Free AI Compliance Handbook

What compliance leaders need to know about AI-driven fraud, autonomous laundering, and how your team can
fight back.
Submit
Thank you! Your submission has been received!
Something went wrong while submitting the form. Please try again.