Skip to main content
Category: Customer Due Diligence

Correspondent Banking Due Diligence

Also known as: Correspondent Due Diligence, Correspondent Account Due Diligence
Simply put

Correspondent banking due diligence is the set of checks a bank performs before and during a relationship in which it provides banking services to another bank, often one located in a different country. Because one bank effectively relies on another to know its own customers, the reviewing bank assesses the other institution's ownership, location, and controls against money laundering and other financial crime risks. The goal is generally to manage and mitigate these risks rather than to avoid all such relationships entirely.

Formal definition

Correspondent banking due diligence refers to the risk-based measures an institution applies when establishing and maintaining a correspondent relationship, typically with a foreign financial institution (the respondent), to identify, assess, and manage associated money laundering and terrorist financing risks. Per FATF guidance, these measures are intended to manage rather than avoid such risks, and a foundational step, reflected in the FFIEC BSA/AML framework, is determining if and when a formal correspondent relationship has been established with a foreign financial institution. In practice, the due diligence assesses the respondent's risk profile, including its corporate structure, location, ownership, and AML standards, and may involve requesting and reviewing the respondent's own due diligence policies, procedures, and processes to gauge the adequacy of its controls; industry tools such as a Correspondent Banking Due Diligence Questionnaire (DDQ) are commonly used to gather this information. The specific obligations, scope, and any enhanced requirements vary by jurisdiction and applicable regime (for example, FATF Recommendations as standards versus the US BSA framework or individual national rulebooks), and exact requirements should be confirmed against the applicable regulation.

Why it matters

Correspondent banking relationships create a structural dependency that sits at the heart of the international payment system: a bank providing services to a respondent institution effectively relies on that respondent to know its own underlying customers and to apply adequate controls. This nested reliance means that weaknesses in one institution's AML framework can be transmitted through the correspondent relationship, exposing the reviewing bank to money laundering and terrorist financing risk it cannot directly observe. Correspondent banking due diligence is the primary mechanism for assessing and managing that indirect exposure before and throughout the relationship.

Because of this exposure, FATF guidance frames the objective as managing, rather than avoiding, these risks. Wholesale withdrawal from correspondent relationships, sometimes described as de-risking, can push activity toward less transparent channels and undermine financial inclusion in affected regions, so due diligence is generally intended to enable relationships to continue on an informed, risk-based basis rather than to terminate them by default. The reviewing institution's ability to understand a respondent's corporate structure, location, ownership, and AML standards is central to striking that balance.

The specific obligations attaching to correspondent due diligence vary by jurisdiction and regime, for example, the FATF Recommendations operate as standards rather than binding law, while the US BSA framework and individual national rulebooks impose their own requirements, so the scope and any enhanced measures should be confirmed against the applicable regulation. Firms should treat these measures as tools to detect, deter, and mitigate risk rather than as guarantees that a given relationship is free of financial crime exposure.

Who it's relevant to

Correspondent (reviewing) banks
Institutions that provide banking services to another bank must design and operate the due diligence program, including determining when a formal correspondent relationship exists with a foreign financial institution and assessing the respondent's risk profile. They typically issue and evaluate DDQ responses and decide, on a risk-based basis, whether and how to establish or maintain the relationship.
Respondent financial institutions
Banks receiving correspondent services are the subject of this due diligence. They are commonly asked to provide information on their corporate structure, ownership, location, and AML standards, and to share their own due diligence policies, procedures, and processes so the correspondent can assess the adequacy of their controls.
AML compliance officers and financial crime teams
These practitioners operationalize correspondent due diligence, collecting and reviewing DDQs, evaluating respondents' AML standards, and calibrating the risk-based measures applied. They must map the specific requirements to the applicable regime, as obligations differ between FATF standards, the US BSA framework, and national rulebooks.
Regulators and supervisory examiners
Supervisors assess whether institutions apply appropriate due diligence to correspondent relationships. Frameworks such as the FFIEC BSA/AML manual guide examination of whether banks correctly identify formal correspondent relationships with foreign financial institutions and manage the associated risks, while other jurisdictions apply their own rulebook requirements.

Inside Correspondent Banking Due Diligence

Respondent Institution Identification and Verification
Gathering and verifying information about the respondent bank, including its ownership, control structure, and the nature of its business, before establishing a correspondent relationship. This forms the baseline understanding on which further due diligence is built.
Assessment of the Respondent's AML/CFT Controls
Evaluating whether the respondent institution maintains an adequate anti-money laundering and counter-terrorist financing program, and assessing the quality of that program relative to the risk it presents. This is generally a distinct requirement for cross-border correspondent relationships under standards such as the FATF Recommendations and is reflected in regimes including the US Bank Secrecy Act and FinCEN rules, the EU AML framework, and the UK Money Laundering Regulations.
Reputation and Supervisory History Review
Considering the reputation of the respondent institution and the quality of supervision to which it is subject in its home jurisdiction, including whether it has been subject to regulatory or enforcement action relevant to money laundering or terrorist financing.
Responsibility Documentation
Understanding and, in many jurisdictions, documenting the respective AML/CFT responsibilities of each institution in the correspondent relationship, so that expectations for monitoring and controls are clear between the parties.
Senior Management Approval
Obtaining approval from senior management before establishing new correspondent relationships, a control typically required for cross-border correspondent banking to ensure accountability for the risk accepted.
Payable-Through and Nested Account Considerations
For payable-through accounts, satisfying obligations regarding the respondent's customers who have direct access to the correspondent account. Nested relationships, where a respondent provides correspondent services to other institutions, may create indirect exposure that the correspondent generally needs to understand and manage.
Enhanced and Ongoing Measures for Higher-Risk Relationships
Applying enhanced due diligence and heightened ongoing monitoring where the relationship presents higher risk, for example due to jurisdiction, respondent profile, or transaction patterns, rather than treating due diligence as a one-time event at onboarding.

Common questions

Answers to the questions practitioners most commonly ask about Correspondent Banking Due Diligence.

Is correspondent banking due diligence the same as standard customer due diligence (CDD)?
No. While correspondent banking due diligence builds on standard CDD principles, it is generally treated as a distinct and enhanced category because of the elevated risks inherent in cross-border correspondent relationships. In many jurisdictions, reflecting FATF Recommendation 13 and instruments such as the US Bank Secrecy Act and FinCEN rules, the EU AML Directives, and the UK Money Laundering Regulations, correspondent relationships trigger additional measures beyond ordinary CDD. These typically include gathering information to understand the respondent institution's business, assessing its AML/CFT controls and reputation, and, in some regimes, obtaining senior management approval before establishing the relationship. Exact requirements vary by jurisdiction and should be confirmed against the applicable regulation.
Does performing correspondent banking due diligence mean the correspondent institution is responsible for monitoring the respondent's underlying customers?
Not in the sense of conducting direct CDD on each of the respondent's customers. In a traditional correspondent relationship, the correspondent typically does not have a direct relationship with, and is generally not expected to individually identify and verify, the respondent's underlying customers. Instead, the correspondent generally relies on assessing the adequacy of the respondent's own AML/CFT controls. A recognized exception in many frameworks concerns 'payable-through accounts' (sometimes referred to differently across jurisdictions), where the correspondent may need additional assurance that the respondent applies appropriate CDD to customers with direct access to those accounts. The precise expectations differ by regime and should be verified against the relevant rules.
What information should typically be gathered when onboarding a respondent institution?
Programs generally seek to understand the respondent's business, ownership and management structure, the nature and reputation of the institution, the quality of any regulatory oversight it is subject to, and the adequacy of its AML/CFT controls. In many jurisdictions this may also include understanding the purpose of the account, the products and services offered, and the respondent's own customer base at a portfolio level. The aim is to assess and manage risk rather than to guarantee prevention, and the specific data points collected should be calibrated to the assessed risk and to the requirements of the applicable regulation.
How should nested or downstream correspondent relationships be handled?
Nested relationships, where a respondent provides correspondent-type services to other financial institutions through the account it holds with the correspondent, can introduce visibility challenges and additional risk. Programs typically address this by seeking to understand whether the respondent offers such downstream services, assessing the associated risk, and considering whether enhanced measures or information-sharing arrangements are warranted. Because these arrangements can obscure the ultimate originators and beneficiaries of transactions, they are commonly treated as a higher-risk feature to be identified and managed rather than a control that eliminates risk. Specific expectations vary by jurisdiction.
When is senior management approval or periodic review typically required?
In many regimes, establishing a new cross-border correspondent relationship generally requires approval at a senior management level before the relationship goes live, reflecting the enhanced nature of these arrangements. Existing relationships are typically subject to periodic review on a risk-sensitive basis, with higher-risk respondents reviewed more frequently. Whether approval and review are mandated, and at what level and frequency, depends on the applicable instrument, such as FinCEN rules under the Bank Secrecy Act, the EU AML Directives, or the UK Money Laundering Regulations, and exact requirements should be confirmed against the relevant regulation.
What are the practical implications of prohibitions on shell bank relationships?
Many frameworks, consistent with FATF standards, prohibit obliged entities from entering into or maintaining correspondent relationships with shell banks, institutions with no physical presence and not affiliated with a regulated financial group. Operationally, this generally means confirming that a prospective respondent is not a shell bank and, in some jurisdictions, obtaining assurances that the respondent will not permit its accounts to be used by shell banks. These measures are intended to reduce exposure to institutions outside effective regulatory oversight; they mitigate rather than eliminate risk, and the precise prohibition and any related certification expectations should be verified against the applicable regulation.

Common misconceptions

Correspondent banking due diligence requires the correspondent to identify and verify every underlying customer of the respondent institution.
In most cross-border correspondent relationships the correspondent is generally not expected to perform full customer due diligence on the respondent's underlying customers. The focus is typically on understanding and assessing the respondent institution and its AML/CFT controls. Payable-through accounts are a notable exception, where obligations may extend to the respondent's customers with direct account access. Exact scope should be confirmed against the applicable regulation.
Correspondent banking due diligence is a standardized global obligation that applies identically wherever it is performed.
While the FATF Recommendations set influential standards, they are standards rather than binding law. The specific obligations, scope, and documentation requirements differ across regimes such as the US Bank Secrecy Act and FinCEN rules, the EU AML framework, and the UK Money Laundering Regulations, and practitioners should apply the requirements of the relevant jurisdiction.
Completing correspondent due diligence at onboarding satisfies the obligation for the life of the relationship.
Correspondent banking due diligence is generally an ongoing process. Higher-risk relationships typically warrant enhanced and continuing monitoring, and information about the respondent may need to be refreshed and reassessed over time. Due diligence is a measure to detect, deter, and manage risk, not a one-time clearance that guarantees prevention.

Best practices

Assess the respondent institution's AML/CFT controls as a distinct step from basic identification, and document the basis for concluding those controls are adequate relative to the risk presented.
Obtain and evidence senior management approval before establishing new cross-border correspondent relationships, so accountability for the accepted risk is clearly assigned.
Clearly document the respective AML/CFT responsibilities of each institution in the relationship to avoid gaps in monitoring expectations between the parties.
Identify whether the relationship involves payable-through accounts or nested arrangements, and apply the additional or indirect-exposure considerations these create rather than treating all correspondent relationships uniformly.
Apply enhanced due diligence and heightened ongoing monitoring to higher-risk relationships, factoring in jurisdiction, respondent profile, supervisory quality, and transaction patterns.
Treat due diligence as an ongoing process by periodically refreshing and reassessing information on the respondent, and confirm specific scope, thresholds, and documentation requirements against the applicable regulation in each relevant jurisdiction.