Skip to main content
Category: Money Laundering Typologies

Correspondent Banking Abuse

Also known as: Abuse of Correspondent Banking Relationships, Correspondent Banking Exploitation
Simply put

Correspondent banking abuse refers to the exploitation of arrangements in which one bank provides account and payment services to another bank, allowing illicit funds to move across borders. Because a correspondent bank often deals with its client bank rather than that bank's underlying customers, criminals may use these relationships to disguise the true origin of money or to move funds for illegal purposes. The reporting known as the FinCEN Files highlighted how such relationships can be exploited to facilitate financial crime.

Formal definition

Correspondent banking abuse describes the misuse of correspondent banking relationships (CBRs), arrangements whereby a correspondent institution provides banking services (such as payment processing, clearing, and account maintenance) to a respondent institution, to move or obscure the proceeds of crime or to finance terrorism. A core vulnerability arises because the correspondent typically applies due diligence to the respondent bank rather than directly to that respondent's underlying customers, which can allow illicit flows to be introduced further down the chain and used for layering across jurisdictions. Correspondent relationships are generally subject to enhanced AML/CTF measures; the FATF's guidance on correspondent banking services addresses these expectations at the standards level, while specific obligations for obliged entities derive from the applicable national or regional regime and should be confirmed against it. This is an operational and typological concept describing how the channel may be exploited; it does not itself constitute a legal test, and the existence of a correspondent relationship or an inadvertent facilitation of illicit funds does not by itself establish wrongdoing. Note also that heightened compliance concerns around CBRs have been associated with 'de-risking', the withdrawal or termination of correspondent relationships, which raises separate financial-inclusion and access considerations.

Why it matters

Correspondent banking is a foundational part of the global payment system, enabling banks to offer cross-border services in jurisdictions where they have no physical presence. This same reach is what makes the channel attractive to those seeking to move illicit funds. Because a correspondent institution generally conducts due diligence on its respondent bank rather than on that respondent's underlying customers, illicit flows can be introduced further down the chain and moved across borders in ways that obscure their true origin. This structural distance between the correspondent and the ultimate customer is central to why these relationships are treated as a heightened money laundering and terrorist financing vulnerability.

The reporting known as the FinCEN Files drew significant public attention to how correspondent banking relationships can be exploited to facilitate financial crime, illustrating the concern that correspondent banks may inadvertently facilitate the movement of funds for illegal purposes through their networks. It is important to keep the compliance and criminal-law dimensions separate: the existence of a correspondent relationship, or the inadvertent processing of illicit funds, does not by itself establish wrongdoing by any institution. The typology describes how a channel may be exploited, not a legal test of culpability.

Heightened compliance concern around correspondent relationships has also been associated with 'de-risking', the withdrawal or termination of these relationships by correspondent institutions. As reflected in work examining the post-global-financial-crisis withdrawal of correspondent banking relationships in some jurisdictions, de-risking raises separate financial-inclusion and access considerations, potentially cutting off certain regions or customer segments from the formal banking system. Firms therefore face the challenge of managing exploitation risk without indiscriminately severing relationships in ways that create downstream access problems.

Who it's relevant to

Correspondent (providing) institutions
Banks that provide account, clearing, and payment services to other institutions carry primary responsibility for applying enhanced due diligence to their respondent relationships. They must understand the respondent's business, its own AML/CTF controls, and the nature of the flows passing through the relationship, while recognising that they generally do not have direct visibility into the respondent's underlying customers. The scope and detail of these obligations derive from the applicable regime and should be confirmed against it.
Respondent institutions
Banks that rely on correspondent relationships to access cross-border services need to demonstrate the strength of their own AML/CTF programs to retain those relationships, and are also exposed to de-risking, where a correspondent may withdraw or terminate services over compliance concerns. This creates both a compliance and a business-continuity dimension for respondent institutions.
AML compliance officers and financial intelligence analysts
Professionals responsible for monitoring, screening, and investigating cross-border flows use the correspondent banking abuse typology to inform their assessment of layering and cross-jurisdictional movement risk. They should treat associated indicators as risk signals to be assessed rather than as proof of criminality, and calibrate controls to the specific relationships and jurisdictions involved.
Policymakers and financial-inclusion stakeholders
Regulators, standard-setters, and bodies concerned with financial access have an interest in the balance between managing correspondent banking exploitation risk and the effects of de-risking. As reflected in analysis of the withdrawal of correspondent banking relationships in some jurisdictions, these decisions can affect access to the formal financial system and raise financial-inclusion considerations distinct from the underlying crime risk.

Inside Correspondent Banking Abuse

Correspondent Banking Relationship
An arrangement in which one financial institution (the correspondent) provides banking services to another financial institution (the respondent), often to facilitate cross-border payments, clearing, and settlement in a currency or market where the respondent lacks a direct presence. Abuse arises when this relationship is exploited to move illicit funds while obscuring the true originator or beneficiary.
Nested (Downstream) Relationships
A key vector of abuse in which the respondent's own customers, including other financial institutions, access the correspondent account indirectly. Because the correspondent may have limited visibility into these downstream parties, nesting can allow unknown or higher-risk entities to use the correspondent's services without direct due diligence, unless controls address this exposure.
Payable-Through Accounts
Arrangements where a respondent institution's customers are permitted to conduct transactions directly through the correspondent account. Several regimes, such as the US Bank Secrecy Act framework and the FATF Recommendations, treat these as elevated-risk and generally call for additional scrutiny, though specific obligations vary by jurisdiction.
Correspondent Due Diligence
The enhanced due diligence measures typically expected before establishing and throughout a cross-border correspondent relationship. In many jurisdictions this generally includes understanding the respondent's ownership, management, business, AML controls, and the quality of supervision in its home jurisdiction, though the precise requirements differ across the FATF standards, EU AML instruments, and national rules.
Shell Bank Prohibition
A control commonly emphasized across major regimes: correspondents are generally expected not to establish or maintain relationships with shell banks (institutions with no physical presence and not affiliated with a regulated financial group), and to obtain assurances that respondents do not permit their accounts to be used by shell banks. Exact wording and scope should be confirmed against the applicable regulation.
Transaction Monitoring and Visibility Limitations
Ongoing monitoring of correspondent flows to detect and manage risk, complicated by the correspondent's frequently limited line of sight into the underlying parties behind respondent-driven transactions. This visibility gap is a structural feature that abusers may seek to exploit.

Common questions

Answers to the questions practitioners most commonly ask about Correspondent Banking Abuse.

Does correspondent banking abuse mean the correspondent bank itself is laundering money?
Not necessarily. Correspondent banking abuse typically refers to the misuse of a correspondent relationship to move illicit funds, often driven by activity originating with the respondent bank's underlying customers rather than by the correspondent institution itself. Because the correspondent generally does not have a direct relationship with, or visibility into, the respondent's customers, it can be exposed to abuse without being a knowing participant. The presence of suspicious flows through a correspondent account does not, by itself, establish wrongdoing by either institution; it is an indicator that may warrant further scrutiny under a risk-based approach.
Is due diligence on a correspondent relationship the same as the CDD a bank performs on a normal customer?
The two are related but not identical. Standard customer due diligence focuses on identifying and verifying a customer and understanding the nature of their activity. Correspondent banking due diligence generally goes further, because the respondent's customers are effectively transacting through the correspondent's systems. In many jurisdictions, cross-border correspondent relationships, particularly with respondents in higher-risk locations, are treated as warranting enhanced measures, which may include assessing the respondent's own AML/CFT controls, reputation, ownership, supervision, and the purpose of the relationship. Terminology and the precise triggers for enhanced measures vary by regime, so requirements should be confirmed against the applicable rules.
What steps are typically involved in performing due diligence on a respondent bank?
In many frameworks, correspondent due diligence generally involves gathering information to understand the respondent's business, ownership and management, the quality and supervision of its AML/CFT controls, its regulatory and reputational standing, and the intended purpose of the relationship. Where a respondent permits other institutions to use its correspondent account (nested or downstream relationships), additional inquiry may be warranted. Many regimes also expect senior management approval before establishing certain correspondent relationships. The specific documentation, thresholds, and approval requirements differ by jurisdiction and should be confirmed against the applicable regulation and each institution's own risk-based policies.
How should an institution handle nested or downstream correspondent relationships?
Nesting arises when a respondent uses its correspondent account to provide services to its own customers or to other financial institutions, which can obscure the ultimate originators and beneficiaries of transactions. As a practical matter, institutions generally seek to understand whether and to what extent nesting occurs, and to assess the associated risk. Managing this may involve inquiring about the respondent's downstream client base, monitoring for unexpected third-party institution activity, and, where warranted, applying enhanced measures or restricting or exiting the relationship. Expectations vary by jurisdiction and by the institution's own risk appetite.
What role does transaction monitoring play given the limited visibility into a respondent's customers?
Because the correspondent typically lacks direct information on the respondent's underlying customers, transaction monitoring is often used to detect patterns that appear inconsistent with the expected purpose and profile of the relationship. This can include watching for unexpected volumes, jurisdictions, transaction types, or third-party activity. Monitoring is a measure to help detect and manage risk rather than a guarantee against abuse, and an alert or an anomaly indicates activity that may warrant review, not proof of illicit conduct. Where activity cannot be adequately explained, institutions may consider further inquiry, escalation, or a suspicious activity or transaction report under the applicable regime.
How are prohibitions on shell banks relevant to correspondent banking controls?
A recurring correspondent banking risk arises where a respondent maintains relationships with, or is itself, a shell bank, an institution with no physical presence and no affiliation with a regulated financial group. Many regimes prohibit establishing or continuing correspondent relationships with shell banks and expect institutions to satisfy themselves that a respondent does not permit its accounts to be used by shell banks. As part of onboarding and ongoing review, institutions generally seek assurances on this point. The exact wording and scope of these prohibitions differ across regimes and should be confirmed against the applicable rules.

Common misconceptions

Performing due diligence on the respondent institution means the correspondent has effectively vetted all the parties transacting through the account.
Correspondent due diligence typically focuses on the respondent institution itself, not on each of the respondent's underlying customers. Where nested relationships or payable-through arrangements exist, the correspondent may have limited visibility into downstream parties, which is precisely why these structures are treated as higher-risk and may warrant additional measures.
A single global rulebook governs correspondent banking obligations.
The FATF Recommendations set influential standards but are not binding law. Actual obligations flow from regime-specific instruments such as the US Bank Secrecy Act and FinCEN rules, EU AML instruments, and the UK Money Laundering Regulations, and these diverge on scope, defined terms, and specific requirements. Practitioners should apply the rules of the relevant jurisdiction rather than assume uniformity.
Enhanced due diligence and monitoring guarantee that a correspondent relationship cannot be abused.
These are measures to detect, deter, and mitigate risk, not guarantees of prevention. Structural visibility limitations mean residual risk generally remains, and identifying a suspicious transaction supports risk management and any applicable reporting rather than establishing that a crime has occurred.

Best practices

Apply enhanced due diligence to cross-border correspondent relationships, including understanding the respondent's ownership, management, business activities, AML controls, and the quality of supervision in its home jurisdiction, consistent with the requirements of the applicable regime.
Assess and document exposure to nested and downstream relationships, and take measures to understand which third parties may access the correspondent account indirectly rather than relying solely on due diligence of the direct respondent.
Treat payable-through accounts as elevated-risk and apply additional scrutiny where they are permitted, confirming the specific obligations against the applicable jurisdiction's rules.
Confirm that respondents are not shell banks and obtain assurances that respondent accounts are not used by shell banks, verifying the precise wording of this obligation in the relevant regime.
Implement ongoing transaction monitoring calibrated to the visibility limitations of correspondent flows, and escalate or report unusual activity in line with the applicable reporting framework without treating an alert as proof of wrongdoing.
Periodically review and refresh correspondent due diligence throughout the life of the relationship, and confirm any thresholds, defined terms, and specific requirements against the applicable regulation rather than assuming a single global standard.