Skip to main content
Category: Customer Due Diligence

Correspondent Banking Due Diligence Questionnaire

Also known as: CBDDQ, Wolfsberg CBDDQ, Wolfsberg Correspondent Banking Due Diligence Questionnaire, Wolfsberg Questionnaire
Simply put

The CBDDQ is a standardized questionnaire, developed by the Wolfsberg Group, that banks use to gather and share information when they enter into or maintain correspondent banking relationships with each other. It lets a bank offering correspondent services (and its counterpart) collect consistent details about a respondent bank's anti-money laundering controls. The goal is to make the due diligence process more transparent and consistent across the industry.

Formal definition

The CBDDQ is a standardized due diligence questionnaire developed by the Wolfsberg Group to support the assessment of correspondent banking relationships. It is generally completed at a legal entity (LE) level and is designed to promote transparency and consistency in the information exchanged between correspondent and respondent institutions, including with respect to the respondent's AML standards and controls. According to available guidance, the CBDDQ can be applied to financial institutions engaged in cross-border and/or other higher-risk correspondent banking relationships. As an industry standard rather than a binding legal instrument, the CBDDQ is a tool to inform an institution's own risk-based due diligence; completion or receipt of a questionnaire does not by itself satisfy any particular regulatory obligation, and applicable requirements should be confirmed against the relevant jurisdiction's rules governing correspondent relationships.

Why it matters

Correspondent banking relationships allow one financial institution to access services and settle transactions through another, often across borders. Because the correspondent institution may facilitate payments on behalf of a respondent's underlying customers it cannot directly see, these relationships are widely regarded as carrying elevated money laundering and sanctions risk. In many jurisdictions, rules governing correspondent relationships, for example those flowing from FATF Recommendation 13, the US Bank Secrecy Act and FinCEN rules, the EU AML framework, and the UK Money Laundering Regulations, require obliged entities to perform enhanced or additional scrutiny for certain cross-border correspondent arrangements. The CBDDQ emerged as an industry response to the practical challenge of gathering consistent information to inform that scrutiny.

Who it's relevant to

Correspondent banking teams and relationship managers
Staff at institutions that provide correspondent services use the CBDDQ to collect consistent information about a respondent's AML standards and controls, informing their own risk-based assessment of whether to enter into or maintain a relationship. The questionnaire supports, but does not replace, the institution's independent due diligence.
Respondent institutions
Financial institutions seeking or maintaining correspondent relationships generally complete the CBDDQ at a legal entity level to share standardized details about their AML programs. Accurate and current responses can facilitate the counterpart's review, though completion of the questionnaire does not by itself resolve the correspondent's obligations.
AML/financial crime compliance officers
Compliance professionals rely on the CBDDQ as a tool to promote transparency and consistency in due diligence across correspondent relationships, particularly for cross-border and other higher-risk arrangements. They should confirm how the questionnaire fits within the specific regulatory requirements applicable in their jurisdiction.
Onboarding, periodic review, and audit functions
Teams responsible for onboarding and ongoing review of correspondent relationships may use the CBDDQ to standardize the information collected and to support monitoring of trends in a respondent's AML standards over time. Auditors and reviewers may examine how questionnaire responses are assessed and used within the broader due diligence process.

Inside CBDDQ

Standardized Questionnaire Format
The CBDDQ is a standardized due diligence questionnaire developed under the auspices of the Wolfsberg Group to create a common baseline for information exchange between correspondent and respondent banks. It is an industry tool rather than a regulatory instrument, though its use supports compliance with correspondent banking obligations found in various regimes.
Institutional and Ownership Information
Sections typically capturing the respondent institution's legal name, licensing and regulatory status, ownership and control structure, and details relevant to identifying beneficial ownership as distinct from legal ownership. Exact fields should be confirmed against the current version of the questionnaire.
AML/CTF Programme Details
Questions generally addressing the respondent's anti-money laundering and counter-terrorist financing framework, including policies, governance, and the presence of a designated compliance function. Money laundering and terrorist financing controls may be addressed separately given they are distinct risks.
Customer Due Diligence and Screening Practices
Sections covering the respondent's CDD and, where applicable, EDD processes, as well as its approach to sanctions screening and PEP screening, which are treated as related but non-identical control functions.
Products, Services, and Risk Exposure
Information intended to help the correspondent assess inherent risk, such as the nature of the respondent's business, its client base, geographic footprint, and higher-risk activities. This supports a risk-based assessment rather than providing a definitive risk rating.
Transaction Monitoring and Reporting
Questions typically relating to the respondent's transaction monitoring arrangements and its processes for filing suspicious activity or suspicious transaction reports, with the applicable terminology and filing obligations varying by jurisdiction.

Common questions

Answers to the questions practitioners most commonly ask about CBDDQ.

Is the CBDDQ a regulatory form that respondent banks are legally required to complete?
No. The CBDDQ is a standardized industry questionnaire developed by the Wolfsberg Group, an association of international banks, rather than a regulatory instrument issued by a legislator or supervisor. Completing it is not, in itself, a statutory obligation. However, correspondent banking due diligence is a regulatory expectation in many jurisdictions, for example, obligations addressing cross-border correspondent relationships appear in instruments such as the FATF Recommendations, the EU AML framework, the US Bank Secrecy Act and FinCEN rules, and the UK Money Laundering Regulations. Institutions often adopt the CBDDQ as a practical tool to help meet those underlying obligations, but the questionnaire and the legal duty are distinct. The exact requirements applicable to any relationship should be confirmed against the relevant regulation.
Does receiving a completed CBDDQ satisfy a correspondent bank's due diligence obligations on its own?
Generally, no. The CBDDQ is one input into a due diligence process, not a substitute for it. It supports the collection of information in a consistent format, but the correspondent institution typically remains responsible for assessing, verifying where appropriate, and forming its own risk-based view of the respondent and the relationship. A completed questionnaire is a self-disclosure by the respondent; it does not by itself confirm the accuracy of the responses, resolve identified risks, or constitute enhanced due diligence where that is warranted. It should be treated as part of a broader set of measures to manage and mitigate correspondent banking risk rather than as a conclusive control.
At what point in the correspondent relationship should the CBDDQ be requested and reviewed?
The questionnaire is commonly requested during onboarding of a correspondent relationship, before services are established, so that the information can inform the initial risk assessment and any decision to proceed. Many institutions also refresh the CBDDQ periodically thereafter, with the frequency typically driven by the assessed risk of the relationship, and may seek an updated version following material changes to the respondent's profile, ownership, or business. The precise timing and refresh cadence should align with an institution's own risk-based policies and any applicable supervisory expectations.
How should responses in a CBDDQ be handled when answers appear incomplete, inconsistent, or raise concerns?
Responses that are incomplete, internally inconsistent, or that surface potential risk factors generally warrant follow-up rather than acceptance at face value. In practice this may involve requesting clarification or supporting documentation, escalating within the institution's governance framework, and considering whether enhanced due diligence measures are appropriate. The questionnaire is designed to prompt further inquiry where needed; unresolved concerns may feed into decisions about whether to establish, continue, or restrict the relationship. Such handling should follow the institution's documented procedures.
How does the CBDDQ relate to other information an institution collects on a respondent bank?
The CBDDQ is typically used alongside, not instead of, other information sources gathered as part of due diligence on a respondent. Institutions commonly consider it together with corporate and licensing information, ownership and control details, screening outputs, and their own understanding of the respondent's jurisdiction and business. The questionnaire's value lies in standardizing self-reported information across counterparties; corroborating and contextualizing that information against independent sources generally remains part of a risk-based approach.
Should the CBDDQ be retained as part of a correspondent banking file, and how is it maintained over time?
The CBDDQ is generally retained as part of the due diligence record supporting a correspondent relationship, so that the basis for onboarding and ongoing decisions can be evidenced. Institutions typically maintain the completed questionnaire alongside the analysis and any follow-up, and update it in line with their periodic review cycles or upon material changes. Applicable record-keeping requirements vary by jurisdiction, so retention periods and documentation standards should be confirmed against the relevant regulatory framework.

Common misconceptions

The CBDDQ is a legally mandated form that all banks are required to use.
The CBDDQ is an industry-developed tool produced by the Wolfsberg Group. It is not itself binding law. Correspondent banking due diligence obligations derive from applicable regimes such as the FATF Recommendations (which are standards, not law), the EU AML framework, the US Bank Secrecy Act and FinCEN rules, and the UK Money Laundering Regulations, and use of the CBDDQ is one means of supporting those obligations rather than a substitute for them.
A completed CBDDQ satisfies a correspondent bank's due diligence obligations on its own.
The questionnaire is a starting point that gathers self-reported information from the respondent. It generally does not replace independent verification, ongoing monitoring, or, where warranted, enhanced due diligence. It is a measure to help assess and manage risk, not a guarantee that risk has been eliminated.
The CBDDQ produces a definitive assessment of whether a respondent is engaged in financial crime.
The questionnaire supports a risk-based evaluation of a correspondent relationship. Responses, alerts, or identified risk factors indicate areas for further review and do not establish wrongdoing on the part of the respondent institution or its customers.

Best practices

Treat the completed CBDDQ as one input into a broader, risk-based correspondent banking due diligence process rather than as a standalone compliance deliverable.
Independently verify material self-reported information where practicable, and apply enhanced due diligence measures to higher-risk respondent relationships.
Confirm which regulatory obligations actually apply to the relationship, since correspondent banking requirements differ across the FATF Recommendations, EU, US, UK, and other regimes, and align the review accordingly.
Use the most current version of the questionnaire and confirm any specific thresholds, fields, or expectations against the applicable regulation rather than assuming they are uniform across jurisdictions.
Refresh CBDDQ information periodically and on a risk-sensitive basis, integrating it with ongoing monitoring rather than treating due diligence as a one-time event.
Document how questionnaire responses informed the risk assessment and any decision to establish, maintain, restrict, or exit a correspondent relationship.