Skip to main content
Commerce Security logo, "All 12 PCI DSS Requirements in Plain English," "Get it now for free," "Complete Survival Guide" and a button toclick to get it
Should You Treat Your Fintech Partner as a Correspondent Bank?Sanctions Lists & Screening
4 min readFor MLROs

Should You Treat Your Fintech Partner as a Correspondent Bank?

The decision you're facing isn't hypothetical anymore. Russian fintech A7 laundered billions through global banks using forged documents and front companies, according to Financial Times reporting on leaked internal data. The operation facilitated payments for war-related goods, including weapons, through an industrial-scale forgery operation producing fake stamps and invoices.

Your question: Do you apply correspondent banking due diligence standards to your fintech payment partners, or do you treat them as ordinary vendors?

This matters because sanctions-evasion-as-a-service models exploit a classification gap. Most institutions subject correspondent banks to enhanced due diligence under 31 CFR 1010.610 and FATF Recommendation 13. Fintechs processing cross-border payments often receive vendor risk assessments instead.

Key Factors That Affect Your Choice

Volume and jurisdiction reach. If your fintech partner processes payments across multiple jurisdictions, especially involving high-risk countries listed on FATF's Grey List or Black List, the risk profile resembles correspondent banking more than software-as-a-service.

Payment flow opacity. Can you trace beneficial ownership of entities receiving funds through your fintech partner? The A7 case involved a network of front companies. If your partner aggregates payments or uses pooled accounts, you're inheriting layered risk without layered controls.

Document verification responsibility. Who validates supporting documentation for transactions? A7's operation relied on forged invoices and stamps. If your fintech partner accepts documentation you never see, you're outsourcing Customer Due Diligence without outsourcing liability.

Regulatory classification. Does your jurisdiction's regulator classify the fintech as a payment institution, money services business, or technology provider? The U.K.'s FCA and EU's Payment Services Directive 2 impose specific obligations on payment institutions that trigger your enhanced due diligence requirements.

Path A: Apply Correspondent Banking Standards

Choose this path when your fintech partner meets two or more conditions:

They hold pooled client funds. If the fintech maintains omnibus accounts where your customers' funds mix with other institutions' customers, you're facing nested relationships. FinCEN's 2016 guidance on nested correspondent banking applies here, even if the word "bank" doesn't appear in your contract.

They process payments to sanctioned jurisdictions. Any fintech routing payments through Russia, Iran, North Korea, Syria, or other comprehensively sanctioned countries requires the same controls you'd apply to a correspondent bank in those regions. This means annual reviews minimum, transaction sampling, and independent validation of their sanctions screening program.

Your contract limits your visibility. If service terms prevent you from auditing transaction-level data or beneficial ownership records, you're accepting correspondent-level risk with vendor-level transparency.

Under this path, implement:

  • Annual on-site reviews of the fintech's AML/CFT framework, including their name screening systems, transaction monitoring rules, and Suspicious Activity Report history.
  • Quarterly transaction sampling covering at least 5% of payment volume, focusing on high-risk corridors.
  • Independent validation of their beneficial ownership identification processes.
  • Certification requirements under 31 CFR 1010.610(b) if you're a U.S. institution, adapted for non-bank payment processors.

The A7 case demonstrates why this matters. Global banks processed these payments because they treated A7 as a technology layer, not a financial intermediary. The forgery operation worked because no one verified documents at the source.

Path B: Enhanced Vendor Due Diligence

Choose this path when the fintech operates transparently but outside traditional banking channels:

They provide technology, not financial intermediation. The fintech offers payment infrastructure, but your institution maintains direct relationships with underlying beneficiaries. You see transaction-level data in real-time.

Payments stay within low-risk corridors. All transactions flow between FATF-compliant jurisdictions with strong AML/CFT frameworks. No exposure to Grey List or Black List countries.

You retain document custody. Supporting documentation for payments flows through your systems. You're not relying on the fintech's due diligence.

Under this path, implement:

  • Semi-annual risk assessments covering the fintech's sanctions screening capabilities, data security, and regulatory compliance history.
  • Contractual audit rights allowing you to review their controls on 30 days' notice.
  • Transaction monitoring coverage that includes payments processed through the fintech platform, using your own rules.
  • Incident reporting requirements obligating the fintech to notify you within 24 hours of any sanctions screening failures or suspicious activity.

You're still conducting enhanced due diligence beyond standard vendor management, but you're not replicating full correspondent banking protocols.

Path C: Reject the Relationship

Choose this path when:

The fintech refuses transparency. They won't provide transaction-level data, beneficial ownership information, or audit rights. A7 operated through opacity. Don't accept it.

Their jurisdiction lacks adequate supervision. If the fintech operates from a jurisdiction without a financial regulator applying FATF standards, you're inheriting supervision risk you can't mitigate.

Their business model depends on regulatory arbitrage. If the fintech's value proposition is "we can process payments your bank can't," you're looking at designed-in compliance risk.

Some relationships aren't worth the risk transfer. The A7 case involved industrial-scale forgery because the business model required it. When a fintech's economics depend on bypassing controls, enhanced due diligence won't fix structural problems.

Summary Matrix

Factor Correspondent Approach Enhanced Vendor Approach Reject
Payment visibility Pooled/aggregated Transaction-level access Refused transparency
Jurisdiction risk High-risk corridors FATF-compliant only Unsupervised jurisdiction
Document control Fintech validates You validate No validation possible
Audit rights On-site annually Remote semi-annually Contractually blocked
Regulatory status Payment institution Technology provider Unregulated/unclear
Your liability Full (nested risk) Shared (vendor risk) Unacceptable

The A7 leak revealed billions in sanctions evasion because financial institutions classified a payment processor as a technology vendor. Don't repeat that error. Your regulator won't accept "but they're a fintech" as an explanation for missed sanctions violations.

Match your due diligence intensity to the actual risk you're accepting, not the label in the contract.

Promotional banner for the Pentest Readiness checklist download

You Might Also Like