Skip to main content
Category: Compliance Program Governance

Financial Crime Compliance Questionnaire

Also known as: FCCQ, Wolfsberg Financial Crime Compliance Questionnaire, Wolfsberg FCCQ
Simply put

The Financial Crime Compliance Questionnaire (FCCQ) is a standardized form developed by the Wolfsberg Group, an association of global banks, that financial institutions use to assess one another's financial crime compliance programs. It provides a common set of questions so that institutions can gather and share due diligence information about a counterparty's controls. It is intended as a broad tool supporting the evaluation of a financial institution's overall financial crime compliance framework.

Formal definition

The FCCQ is a due diligence questionnaire published by the Wolfsberg Group, an association of 12 global banks that develops frameworks and guidance for managing financial crime risks. Alongside the Correspondent Banking Due Diligence Questionnaire (CBDDQ), the FCCQ is presented by the Wolfsberg Group as part of the global standard for due diligence between financial institutions, with the FCCQ serving as a broader instrument supporting the assessment of a financial institution's financial crime compliance program. The FCCQ, together with supporting Guidance, Glossary, and FAQ documents, was published in an updated form by the Wolfsberg Group (updated documents released as noted in February 2023). As an industry-developed tool, the FCCQ is not itself binding regulation; it represents a voluntary market standard for information exchange, and its use and scope should be understood in the context of an institution's applicable regulatory obligations.

Why it matters

Financial institutions routinely need to assess the financial crime compliance programs of the counterparties they deal with, but doing so is difficult when every institution asks different questions in a different format. The FCCQ addresses this by offering a standardized set of questions developed by the Wolfsberg Group, an association of global banks. A common format helps institutions gather comparable due diligence information about a counterparty's controls, reducing the friction and duplication that arise when each party designs bespoke questionnaires. This standardization can support more consistent and efficient information exchange across the industry.

The FCCQ is positioned as a broader instrument than the Correspondent Banking Due Diligence Questionnaire (CBDDQ), supporting the assessment of a financial institution's overall financial crime compliance framework rather than being confined to correspondent banking relationships. Because it is intended to capture information about an institution's broader compliance program, it can serve as an input to a range of due diligence and relationship-management decisions. It should be understood as a tool that helps evaluate and manage counterparty risk, not one that eliminates it or guarantees the adequacy of any institution's controls.

It is important to recognize that the FCCQ is an industry-developed, voluntary market standard rather than binding regulation. Its use and the weight given to the information it collects should be understood in the context of each institution's applicable regulatory obligations, which vary by jurisdiction. Completing or receiving an FCCQ does not by itself satisfy any specific legal requirement, and institutions remain responsible for determining what due diligence is appropriate under the regimes that apply to them.

Who it's relevant to

Correspondent and relationship banking teams
Teams that establish and maintain relationships with other financial institutions can use the FCCQ, alongside the CBDDQ, to gather standardized information about a counterparty's financial crime compliance program. The FCCQ's broader scope makes it relevant where an assessment of an institution's overall compliance framework, rather than only its correspondent banking arrangements, is needed.
Financial crime and AML compliance officers
Compliance officers responsible for counterparty due diligence may rely on the FCCQ as a common-format tool to collect and compare information across institutions. They are also responsible for judging how the questionnaire fits within their institution's risk-based approach and applicable regulatory obligations, recognizing that the FCCQ is a voluntary industry standard rather than binding regulation.
Institutions completing the questionnaire
Financial institutions that are asked to complete an FCCQ use the standardized questions to describe their own financial crime compliance framework to counterparties. The Wolfsberg Group's supporting Guidance, Glossary, and FAQ documents are intended to help them respond consistently.
Risk and governance functions
Risk and governance professionals may use information gathered through the FCCQ as one input into decisions about counterparty relationships. It supports the assessment and management of financial crime risk but does not, on its own, guarantee the adequacy of a counterparty's controls or eliminate risk.

Inside FCCQ

Institutional and Ownership Information
Details identifying the respondent institution, including its legal name, jurisdiction of incorporation, licensing status, regulatory supervisor, and its beneficial ownership and group structure. This is distinct from legal ownership and typically seeks to identify natural persons who ultimately own or control the entity.
AML/CFT Program Governance
Questions covering the existence and scope of the institution's anti-money laundering and counter-terrorist-financing framework, including board and senior management oversight, the appointment of a designated compliance officer (such as an MLRO in the UK or a BSA Officer in the US), and the independence of the compliance function.
Customer Due Diligence (CDD) and Enhanced Due Diligence (EDD)
Inquiries into the institution's onboarding and ongoing due diligence practices. CDD and EDD are separate but related concepts: CDD is the baseline identification and verification process, while EDD represents heightened measures applied to higher-risk relationships. Questions may also address KYC procedures, which are generally a component of, rather than synonymous with, CDD.
Sanctions and PEP Screening
Coverage of the institution's screening controls, distinguishing sanctions screening (against designated persons and entities) from politically exposed person (PEP) screening. These are separate control types and a screening match is an alert for review, not evidence of wrongdoing.
Transaction Monitoring and Reporting
Questions on how the institution detects and escalates unusual or suspicious activity, and its processes for filing suspicious activity reports (SARs) or suspicious transaction reports (STRs). Terminology varies by jurisdiction; a filing reflects a suspicion for reporting purposes and does not establish criminal conduct.
Risk Assessment Methodology
Details of the institution's risk-based approach, including how it assesses and rates risk across customers, products, geographies, and delivery channels, and how identified risks are mitigated or managed.
Training and Independent Testing
Information on staff AML/CFT training programs and the frequency and scope of independent audit or testing of the compliance program.
Regulatory History and Attestation
Disclosures regarding relevant regulatory actions or enforcement matters, together with a signed attestation confirming the accuracy of the responses, typically executed by an authorized officer.

Common questions

Answers to the questions practitioners most commonly ask about FCCQ.

Does completing an FCCQ confirm that a counterparty institution is compliant with all applicable AML requirements?
No. An FCCQ is a self-reported due diligence tool used to gather information about a respondent institution's financial crime compliance framework; it does not constitute an audit, certification, or independent verification of compliance. The responses reflect the respondent's own representations at a point in time and should be assessed alongside other information as part of a risk-based approach. Reliance on questionnaire responses generally does not discharge an obliged entity's own due diligence obligations, which vary by jurisdiction and applicable instrument.
Is the FCCQ a standardized document that is defined identically across all jurisdictions and institutions?
No. While industry-standard templates exist and are widely used to promote consistency, the FCCQ is generally an operational and industry-driven instrument rather than a form mandated in identical terms by a single regulatory body. Content, scope, and format may vary between institutions, banking groups, and correspondent relationships, and questions may be tailored to reflect the specific regimes to which the parties are subject. Terminology and expectations should be confirmed against the applicable framework and the requirements of the requesting institution.
When is an FCCQ typically requested during a business relationship?
An FCCQ is commonly requested at the onboarding stage of a relationship between financial institutions, such as when establishing a correspondent banking or other counterparty relationship, and again on a periodic basis as part of ongoing due diligence review. It may also be requested or refreshed when triggered by a material change in the relationship, the respondent's risk profile, or relevant external developments. The timing and frequency generally follow the requesting institution's risk-based policies rather than a single fixed schedule.
Who within a respondent institution is generally responsible for completing and approving the FCCQ?
Responses are typically prepared by the respondent institution's compliance or financial crime function, drawing on input from relevant business and control areas. Sign-off is often provided by a senior compliance officer or an individual with appropriate authority and accountability for the AML program. Because the responses represent formal institutional representations, many institutions apply internal review and approval controls before submission; specific approval requirements should be confirmed against the institution's own governance arrangements.
How should a requesting institution use FCCQ responses within its due diligence process?
FCCQ responses are generally used as one input into a broader risk assessment of the counterparty, helping to inform the level and nature of due diligence applied, which may range from standard measures to enhanced measures where higher risk is indicated. Responses may be corroborated against other sources, followed up with clarifying questions, or supplemented by additional documentation. The questionnaire is a measure to help identify and manage risk rather than a guarantee, and findings should feed into ongoing monitoring and periodic review.
What steps are commonly taken when FCCQ responses are incomplete, inconsistent, or indicate elevated risk?
Where responses are incomplete or appear inconsistent, requesting institutions typically seek clarification or additional information before reaching a conclusion. Indications of elevated risk may lead to enhanced due diligence, additional approvals, restrictions on the relationship, or escalation within governance structures, consistent with a risk-based approach. An elevated-risk indicator or an unresolved response does not, by itself, establish wrongdoing; it informs how the relationship is assessed and managed under the institution's own policies and applicable requirements.

Common misconceptions

Completing an FCCQ satisfies a firm's due diligence obligation on a counterparty.
An FCCQ is a self-reported information-gathering tool, typically one input into a broader due diligence process. It generally supports, but does not replace, the requesting institution's own risk assessment, verification, and ongoing monitoring. Responses are attestations by the respondent and are not independently verified by the questionnaire itself.
There is a single, universally mandated FCCQ format applicable across all jurisdictions.
No single global rule prescribes one standardized questionnaire. While industry templates exist and are widely used to promote consistency, the specific content and expectations are shaped by the applicable regime and the requesting institution's own risk-based policies, which diverge across jurisdictions such as the US, UK, and EU.
A favorable FCCQ response means the counterparty carries no financial crime risk.
An FCCQ helps detect, assess, and manage risk in a correspondent or third-party relationship; it does not eliminate risk or guarantee the absence of financial crime. Responses reflect the respondent's stated controls at a point in time and should be corroborated and periodically refreshed.

Best practices

Treat FCCQ responses as one input into a risk-based assessment, corroborating key answers (such as ownership and licensing) against independent sources rather than relying on self-attestation alone.
Apply enhanced scrutiny and follow-up questions where responses indicate higher-risk factors, and document how identified risks are being mitigated or managed.
Establish a defined refresh cycle so questionnaires are updated periodically and upon material changes, such as shifts in ownership, regulatory status, or risk profile.
Use recognized industry templates where appropriate to improve consistency, while tailoring additional questions to your own institution's policies and the applicable regulatory regime.
Ensure the questionnaire is completed and attested by an authorized officer, and retain completed FCCQs and supporting evidence in line with applicable record-keeping requirements.
Confirm any specific thresholds, definitions, or reporting terminology against the regulation applicable to each counterparty's jurisdiction, since these vary and should not be assumed to be uniform.