Correspondent Banking Due Diligence and the Wolfsberg CBDDQ
Correspondent banking concentrates risk in a way few other products do. You are providing services to an institution whose customers you never see, whose controls you cannot directly test, and whose own correspondent relationships may extend the chain further than you know.
What makes it different
In ordinary customer due diligence you assess the customer. In correspondent banking you assess the respondent and its control environment, because the transactions flowing through the relationship originate with parties you have no direct relationship with. You are effectively relying on someone else's KYC.
That reliance is the central problem. It cannot be eliminated — correspondent banking would not function otherwise — so it must be assessed, bounded and monitored.
The Wolfsberg CBDDQ
The Wolfsberg Group's Correspondent Banking Due Diligence Questionnaire has become the de facto standard, replacing the bilateral questionnaires that once made every relationship a bespoke exercise. It covers ownership and management structure, licensing and regulatory status, the respondent's AML programme, sanctions compliance, its own KYC standards, and its correspondent and nested relationship policies.
Two things are worth saying plainly about it. First, a completed CBDDQ is a starting point, not a conclusion — it is a self-assessment by the respondent. Second, the value is disproportionately in the follow-up: the questions you ask about inconsistent, vague or surprising answers. A CBDDQ filed without being read is worse than none, because it creates a record suggesting diligence that did not occur.
Useful tests when reviewing one: does the ownership disclosed reconcile with independent registry data? Does the stated transaction volume reconcile with what you actually observe? Are sanctions screening arrangements described specifically, or in terms that could describe anything? Does the answer on nested relationships match the activity you see?
The nesting problem
Nested correspondent banking — where your respondent provides correspondent services to other institutions, which then access your services indirectly — is the highest-risk feature of the product.
The difficulty is detection. Nesting may be disclosed, but it may also be undisclosed, and undisclosed nesting is precisely what enforcement actions have repeatedly concerned. Indicators include payment volumes inconsistent with the respondent's stated customer base or home market size, originators and beneficiaries clustered in jurisdictions where the respondent has no apparent presence, payment message fields referencing institutions that are not your respondent, and transaction patterns that look institutional rather than retail.
Your position should be documented either way: nesting permitted with specified conditions and monitoring, or prohibited with testing to detect it. A policy silent on nesting is a gap an examiner will find.
Downstream clearing and payment transparency
Closely related is downstream clearing, where the respondent clears transactions for third-party institutions through your account. The same detection problem applies, and the same remedy: monitoring built around originator and beneficiary information rather than only around the respondent's own identity.
This depends on payment message data quality. Truncated or missing originator information defeats monitoring entirely, which is why transparency standards — and the ongoing migration to richer payment message formats — matter operationally rather than merely technically. Persistent incomplete information from a respondent is itself a due diligence finding.
Monitoring a respondent
Monitoring a correspondent relationship is not monitoring a customer. Four approaches carry most of the value.
- Expected-versus-actual volume. Establish expected activity at onboarding from the CBDDQ and business rationale, then monitor divergence. Material unexplained growth is the single most useful signal.
- Geographic profile. Monitor the jurisdictions appearing as originator and beneficiary, not merely the respondent's own location. Drift toward higher-risk corridors warrants enquiry.
- Counterparty concentration. A small number of originators or beneficiaries accounting for a large share of volume is worth understanding.
- Screening at payment level. Screen parties to the underlying payments, not just the respondent. See sanctions list screening.
Periodic review should be annual for higher-risk respondents, with a refreshed CBDDQ, updated ownership verification, and review of adverse media and any regulatory action against the respondent in the intervening period.
Making a de-risking decision defensible
Wholesale exit from a jurisdiction or a category of respondent has attracted sustained criticism from FATF and national supervisors for its financial-inclusion consequences. The expectation is that decisions be made case by case on assessed risk, not by category.
A defensible exit decision records the specific risk identified, what mitigation was considered and why it was inadequate, that the decision was made at an appropriate level, and how the exit was sequenced to limit disruption. A decision recorded only as "high risk jurisdiction" will not satisfy a supervisor asking why this respondent specifically.
Related: enhanced due diligence triggers covers the broader EDD framework this sits within.
Onboarding a Respondent: The Practical Sequence
Correspondent onboarding is a sequence of decisions, and taking them in the wrong order wastes effort on relationships that were never viable.
Establish the business rationale first
Why does this respondent need this relationship, what flows does it expect, in which corridors, and why you? A rationale that cannot be stated clearly at the outset will not become clearer once volumes start.
Verify status independently
Confirm licensing with the home regulator directly rather than relying on the questionnaire. Establish whether the home jurisdiction permits shell banks and whether the respondent maintains relationships with any.
Read the CBDDQ against independent data
Reconcile disclosed ownership with registry data, stated volumes with what you would expect for an institution of that size, and the sanctions programme description against how specific it is. Vague answers on screening arrangements are themselves informative.
Set expected activity in writing
Record expected volumes, corridors and counterparty types before the account opens, and configure monitoring against them. Without a baseline recorded at onboarding, later divergence is unmeasurable — which is the single most common reason correspondent monitoring produces nothing useful.
Payment Transparency and Message Quality
Correspondent monitoring depends entirely on the quality of the payment message. Where originator and beneficiary information is truncated or absent, no amount of analytics will recover it.
The migration to richer structured payment formats materially improves this, giving structured address data, clearer identification of parties and better separation of intermediary from ultimate counterparty. The compliance benefit is concrete: screening improves when parties are in discrete fields rather than concatenated free text, and volume monitoring improves when the true originating jurisdiction is visible.
Two obligations sit alongside the format change. A correspondent should monitor the completeness of information received, not merely screen what arrives — persistent truncation from one respondent is a due diligence finding about that respondent. And it should have a documented position on what to do about it: query, restrict, or exit. A firm that records incomplete information year after year without acting has identified a risk and accepted it silently, which is the weakest of the available positions.
Exiting a Relationship Properly
Exit decisions attract supervisory attention in both directions: for being made too readily, and for being made too slowly once risk is identified. The defence in either case is the record.
Decide at the right level
Correspondent exits should be taken by a committee with both compliance and business representation, minuted, with the specific risk stated. "High risk jurisdiction" is not a specific risk; undisclosed nesting identified through payment analysis is.
Consider mitigation before exit
Record what was considered and why it was inadequate — enhanced monitoring, transaction limits, corridor restrictions, additional information requirements. FATF and national supervisors have been consistent that wholesale de-risking should follow case-by-case assessment, and a file showing alternatives were weighed answers that concern directly.
Sequence the wind-down
Give reasonable notice, agree treatment of in-flight payments, and document the final settlement. Abrupt closure can strand legitimate underlying customers and creates its own conduct exposure.
Keep the analysis
Retain the due diligence and monitoring evidence after exit. If the respondent later features in enforcement action elsewhere, the question will be what you knew and when — and the answer needs to exist.
See Through the Correspondent Chain
One Constellation screens the parties to the underlying payment, monitors expected-versus-actual volume and surfaces the nesting patterns respondent-level checks miss.
