Correspondent Banking Due Diligence, Lifecycle and Exit

Correspondent banking lets one bank provide services to another, including payments, account services and other cross-border business. The correspondent's customer is the respondent institution; transactions can also expose it to the respondent's customers and downstream banks. A messaging relationship is not the same as an account relationship, and a SWIFT connection alone does not establish where funds settle.

FATF Recommendation 13 requires additional measures for cross-border correspondent and similar relationships: understand the respondent's business, reputation and supervision; assess AML/CFT controls; obtain senior-management approval for new relationships; and understand respective responsibilities. Payable-through accounts require attention to customers having direct access to the correspondent's accounts and the respondent's CDD and ability to provide relevant information.

FATF prohibits correspondent relationships with shell banks and requires institutions to satisfy themselves that respondents do not allow shell banks to use their accounts. A shell bank is not simply a small foreign bank or a bank in a higher-risk country; use the actual definition and applicable law.

FATF's correspondent-banking guidance rejects a blanket expectation that correspondents perform CDD on every customer of a respondent. Risk-based understanding, transaction monitoring and targeted requests remain necessary. A questionnaire is useful evidence, but not a substitute for assessing the actual services, customer populations and controls.

Correspondent Banking Due Diligence, Lifecycle and Exit — operating model

Correspondent Banking Due Diligence, Lifecycle and Exit — decision flow

Start with the service being purchased

A respondent asking for a euro account may need ordinary commercial payments, treasury settlement, securities-related payments, customer remittances or access for other financial institutions. The currency label explains very little of the exposure. Describe who can instruct a transaction, which balances fund it, what information accompanies it and who receives the resulting value. This service description becomes the boundary against which later activity is assessed.

Consider a fictional institution, Cedar Bank, seeking an account with Harbour Bank. Cedar has a banking licence, three domestic branches and an established small-business customer base. It requests euro supplier payments and dollar settlement for its own foreign-exchange trades. Harbour is considering two distinct services, with different counterparties and message patterns. Approval of supplier payments should not silently authorise Cedar to process remittances for money-transfer businesses, provide nested access to another bank or let customers instruct payments directly through Harbour's interface.

The relationship record should distinguish the legal entity from its brands and branches. A change from Cedar Bank plc to a group affiliate is not simply a change to a display name. It may change the contracting customer, supervisor, insolvency exposure, sanctions nexus and available CDD evidence. Similarly, an account operated by Cedar's foreign branch may be subject to host requirements as well as the home framework. Group ownership provides context; it does not establish that every affiliate has the same licence or controls.

Nostro and vostro describe the perspective on an account. Cedar's account held with Harbour is Cedar's nostro and Harbour's vostro. Those labels do not tell an investigator who originated the underlying customer payment. An internal transfer of liquidity between Cedar accounts can resemble a commercial payment if the event type is lost. Conversely, a customer payment may use Cedar's liquidity but still contain an underlying debtor and creditor whose identities matter for payment transparency and sanctions screening.

A useful initial walkthrough follows one representative transaction from customer instruction to final accounting. Ask operations to show the originating customer record, payment message, screening event, funds reservation, settlement entry, exception record and customer confirmation. If the proposed relationship involves cover payments, reconstruct the customer instruction and cover funding together. Do not conclude that customer data is absent merely because it is not present in the first message an analyst happens to open.

The walkthrough should include a failed or repaired transaction. A successful example shows the happy path; a repaired example shows whether original names and account details survive operator intervention. Where repair replaces a message, the bank needs the relationship between the original and replacement identifiers. A monitoring system receiving only the repaired version may miss repeated attempts to remove or alter a party's information.

Allocate exposure without transferring legal responsibility

The respondent generally knows its customer better than the correspondent. That fact supports a risk-based information model. It does not excuse the correspondent from understanding the institution it serves or from assessing suspicious activity visible in its own business. The practical question is what evidence Harbour needs to make its decisions, how Cedar can supply it and what happens when it cannot.

A responsibility matrix should use concrete activities: verify Cedar's identity; understand Cedar's ownership; perform CDD on Cedar's customers; screen the payment seen by Harbour; assess nested-bank exposure; answer an underlying-party information request; decide an external suspicious-activity report; maintain account access; and execute a legally authorised closure. A row reading “AML: respondent” is too vague. Several institutions may legitimately screen or report the same activity under their own frameworks.

Contract terms can set information formats, contacts, response expectations and service restrictions. They cannot create an exemption from a bank's own statutory duty. The matrix should therefore have separate columns for contractual allocation and the legal entity retaining accountability. When a relationship manager tells a customer that Cedar is responsible for all downstream AML, the statement should be challenged if Harbour continues to carry and monitor those payments.

Information requests should also have boundaries. Harbour may need an explanation of a particular payment, confirmation of an underlying customer's identity or details of a downstream financial institution. The request should identify the transaction, purpose, necessary fields and secure route. A standing demand for every customer file can create unnecessary data-transfer risk and delay useful responses. The depth of inquiry should follow the relationship's risk, the specific concern and applicable requirements.

Where the respondent claims that privacy or bank secrecy prevents a response, obtain a precise explanation. Determine whether the difficulty concerns a document, a data field, a recipient, a transfer route or disclosure of a protected report. A workable alternative might be locally reviewed underlying facts, a permitted confirmation or a lawful authority channel. The correspondent should not accept an unqualified “confidential” as an answer to every request, but should not direct unlawful disclosure either.

Three access patterns that change the control design

For ordinary respondent customer payments, Cedar sends instructions on behalf of customers for whom it performs CDD. Harbour sees messages, account activity and selected information. Its monitoring compares activity with Cedar's approved profile and investigates material anomalies. Harbour's customer remains Cedar; relevant underlying-party information can still be necessary for payment control and a particular investigation.

Nested banking adds another financial institution. Suppose Birch Bank uses Cedar's relationship to reach Harbour's euro service. Birch is not automatically Harbour's direct customer, yet its activity can materially change Harbour's exposure. The bank should understand whether Cedar offers this service, the countries and types of downstream institutions involved, the quality of data and Cedar's oversight. An approved nested arrangement should have sufficient visibility to distinguish Birch flows from Cedar's own retail business.

Payable-through access is different again. Direct access by the respondent's customers to the correspondent's accounts or services raises questions about who can initiate instructions and which controls apply before execution. The specific FATF standard addresses the respondent's CDD on such customers and its capacity to provide relevant information. Operational design must reflect the actual access mechanism; an account marketed as “ordinary correspondent” can still function differently if customer users receive credentials to instruct Harbour directly.

None of these patterns is classified adequately by a single tick in a questionnaire. Review entitlement design, customer agreements, sample messages, the respondent's customer segments and the operational demonstration. A product restriction stating “no payable-through access” is meaningful only if the systems and business process prevent the relevant direct access.

Separate institutional approval from payment disposition

A relationship can be approved while a specific transaction must be held, repaired, rejected or blocked under the applicable framework. Conversely, one payment anomaly does not automatically require immediate termination of the entire relationship. The decisions have different facts, owners and time horizons. Preserve the link between them without collapsing them into one status.

For example, Harbour approves Cedar subject to no nested activity outside a specified corridor. A payment arrives involving Birch from another region. Operations first determines the payment's actual status and any applicable legal restriction. Financial crime assesses the downstream exposure and asks targeted questions. The relationship owner evaluates the service breach. Senior management decides whether the relationship can continue under tighter conditions. A reporting officer separately assesses suspicion and reporting, preserving confidentiality.

If the account is legally blocked, ordinary service-exit instructions do not authorise returning the balance. If the problem is an unsupported new service without a legal restriction, a proportionate temporary restriction may be possible while the bank investigates. If the evidence demonstrates that the respondent cannot manage the exposure, relationship exit may follow. The written conclusion should show which of these situations applies and why.

The remaining sections develop this distinction through onboarding evidence, nested-service monitoring, control tests and a worked lifecycle. The examples illustrate bank design choices rather than universal numerical thresholds or legal deadlines. Applicable national rules, sanctions measures and contractual arrangements must be mapped for the booking entity before the workflow is used in production.

Relationship due diligence and lifecycle controls

Identify the respondent's legal entity, ownership, licence, supervisory authority, management, operating jurisdictions and services requested. Establish whether the relationship permits nested correspondent activity, direct customer access, cash services or unusual currencies. Review enforcement history and control weaknesses with context and evidence rather than accepting an unexplained adverse-media count.

Clarify which bank performs CDD, screens payments, monitors activity, handles information requests and makes its own reporting decisions. These responsibilities can overlap; contractual allocation does not waive statutory duties. Define response routes and escalation when required information is missing, late or inconsistent.

Monitoring should compare actual flows with the approved profile: corridors, currencies, volumes, counterparties and underlying payment information. Nested exposure can add banks and customers beyond the immediate respondent. Use risk-based inquiry to understand that exposure, while avoiding an unsupported demand for complete files on every downstream customer.

Periodic and event-driven reviews assess ownership changes, supervisory action, new services, unexplained flow changes and repeated information failures. For exit, distinguish a commercial decision from a legal restriction. Plan unsettled payments, balances, outstanding investigations, records and lawful communications. Do not return blocked assets or disclose protected reporting information as part of ordinary closure.

Correspondent Banking Due Diligence, Lifecycle and Exit — control architecture

Build a respondent assessment that can be challenged

Institutional identity is the first layer. Record the registered name, jurisdiction, relevant branches, licence number, supervisory authority, authorised activities and official verification source. Note whether the bank is a commercial bank, central bank, development institution or another entity permitted to carry the requested service. A public institution can have different governance and payment purposes, but public ownership alone does not remove the need to understand its activity.

Ownership and control form the second layer. Map controlling shareholders, relevant beneficial owners under applicable rules and material group links. Explain where a listed parent or state ownership changes the required evidence instead of copying a generic ownership chart. Record individuals' management roles separately from equity. When a new investor acquires influence through voting agreements or board appointment powers, a percentage-only field may fail to capture the change that matters.

Reputation and supervision form a third layer. Review official enforcement actions, licensing restrictions and credible adverse information. A historical penalty should be assessed for its cause, affected period, remediation and relevance to the proposed service. “Previously fined” is not an adequate acceptance or rejection rationale. Equally, a favourable reputation should not cancel an unresolved current regulatory restriction. The assessment should distinguish a completed action from a current limit on activity.

Control understanding is the fourth layer. Examine how Cedar identifies customers, assesses risk, handles beneficial ownership, screens names, monitors transactions, investigates alerts and submits reports. The purpose is not to reproduce every procedure in Harbour's format. It is to understand the effectiveness of the controls supporting the intended service and identify material gaps. A policy document may describe a sound design while staffing, data or execution remains inadequate.

A useful evidence meeting takes one risk scenario through the respondent's process. Cedar describes how it would identify a newly established intermediary sending many small payments to one overseas business. Harbour asks which customer attributes and transaction fields are used, who investigates, what evidence is retained and when a concern is escalated. The exercise reveals more than a general assertion that Cedar has automated monitoring.

The assessment should state its evidence limits. If Harbour has reviewed a policy and received an attestation but has not examined operational outcomes, record that distinction. If a local-law constraint prevents sharing customer-level material, explain what alternative evidence was examined. A defensible decision can rely on proportionate evidence; it should not claim a level of assurance that the work did not establish.

Questionnaire answers as hypotheses to test

A questionnaire is a structured way to collect information. Treat each important answer as a statement whose relevance and consistency can be assessed. “No nested relationships” should agree with the requested services and sample payment population. “No money-service-business customers” should agree with Cedar's customer segmentation. “All payments are screened” should identify which party fields, message types, channels and list versions are actually covered.

Some differences arise from definitions rather than deception. Cedar might use “nested” only for accounts held by other banks, while Harbour also asks about downstream payment access provided through an intermediary arrangement. Resolve terminology before concluding that an answer is false. The assessment should contain the agreed operational meaning, not merely the yes/no response.

Repeated copied wording can indicate that a questionnaire is maintained centrally without local input. Ask whether the answers describe the specific contracting entity and service. A parent-bank response may be relevant, but a foreign subsidiary's systems and supervisory requirements can differ. Evidence should identify its entity scope, date, preparer, reviewer and material exclusions.

Where an answer is inconsistent with activity, open an issue with a fact-based statement. For example: “The approved profile excludes remittance-business payments; the last quarter's messages include recurring originators identified by Cedar as licensed remitters.” Request an explanation and supporting classification. Avoid writing “Cedar concealed remitters” before examining whether the discrepancy reflects a product change, a data issue or a deliberate omission.

The issue should reach the person authorised to reconsider the relationship. A relationship manager can collect documents and explain the business, but should not unilaterally resolve a material control concern because revenue is significant. Define who can accept a residual risk, which conditions are mandatory and what would make the decision expire.

Translate the assessment into an activity profile

An expected profile should describe payment purposes, customer segments, currencies, countries, representative counterparties, likely volumes and material seasonal variation. It should also identify approved nested services, cash-related business and any direct access. These attributes support comparison with actual activity. A narrative saying “international payments” provides almost no monitoring baseline.

For Cedar's supplier business, Harbour might expect recurring payments from domestic importers to established overseas vendors, with some seasonal purchases. Treasury flows may be larger and less frequent, involving recognised financial counterparties. The two populations should not be combined indiscriminately. A large liquidity transfer could be normal for treasury yet unusual for a small retailer. Attribution to service helps explain the difference.

Counts and values should be considered together. Rising payment value with stable customer count can mean larger legitimate invoices or concentration in a few new payers. Rising count with falling average value could reflect a new retail-remittance service. Neither pattern proves crime. The profile helps identify where explanation and updated approval are needed.

An analyst should compare corridor usage with declared purpose. A new beneficiary country may be expected after Cedar's customers expand their supply chains. A new intermediary bank can reflect routing changes rather than a new customer geography. Distinguish debtor residence, creditor residence, bank location, settlement currency and route. Country fields representing different roles should not be merged into one undifferentiated “high-risk country” signal.

Information requests that resolve the actual concern

An effective request begins with an answerable question. If a payment has an unexplained corporate beneficiary, ask for the business purpose, relationship, underlying invoice or equivalent evidence and the respondent's relevant customer understanding. If the concern is nested banking, ask which institution generated the flow, the service provided and Cedar's oversight. Do not request a random document collection because the workflow requires an attachment.

Use stable references and a secure route. Include the transaction identifier, date, amount, currency and relevant parties, while minimising unnecessary personal information. Record when the request was sent, acknowledged and answered. Harbour's internal response target is a design choice unless an applicable rule or authority request imposes a deadline. The case should distinguish these different clocks.

A late response needs operational interpretation. Did Cedar receive the request? Was it sent to a dormant mailbox? Did a national holiday or translation requirement create delay? Was required evidence genuinely unavailable? Did Cedar refuse to provide basic underlying facts despite an established arrangement? These explanations have different implications for relationship risk and remediation.

Assess response quality as well as timeliness. An answer “legitimate customer” does not explain an unusual payment. A complete document can still be irrelevant to the transaction. Responses should reconcile the specific parties, purpose and value path. Where facts remain contradictory, record the unresolved point and its significance rather than closing the case because a response arrived.

Monitoring nested exposure without universal customer-file collection

Suppose Cedar begins processing payments for Birch Bank. First determine whether this is an approved activity and whether Birch's identity can be reliably attributed in the payment population. Understand Birch's role, jurisdiction, supervisor and the types of customers or services generating the flows. Cedar's own due diligence on Birch and its ability to answer targeted questions are relevant evidence.

Monitoring can then assess concentration, new corridors, unusual party combinations, incomplete data and information-request outcomes associated with that exposure. Harbour may need deeper inquiry into a particular underlying party or transaction. This does not establish a blanket requirement for Harbour to obtain every Birch customer's full file. The assessment should explain why the selected evidence is enough for the identified exposure or why it is not.

The bank should also identify indirect shell-bank concerns. A licence claim and a website are not conclusive proof of physical presence and qualifying supervision. Where a legal shell-bank prohibition applies, evaluate the actual definition and any relevant regulated-affiliate provisions in the jurisdiction. Do not equate a digital business model or a small branch network with a shell bank without examining the legal criteria.

The US provides a jurisdiction-specific example. The FFIEC manual explains the prohibition and regulated-affiliate exception, certification records and required action when information cannot be obtained. That framework is separate from the general FATF guidance and must be mapped by the US bank to the relevant regulation. A global questionnaire should not turn a US certification requirement into an identical obligation for every foreign booking entity. See the linked FFIEC source in the references.

Review events and changing risk

Periodic review dates should follow applicable requirements and the bank's risk framework. Event-driven review is equally important. Trigger events can include a licence restriction, ownership change, new nested service, adverse control finding, material profile change or persistent information failures. A calendar schedule should not postpone action on a material event already known to the bank.

When Cedar changes its monitoring platform, assess whether the migration affects controls supporting Harbour's service. Ask about data coverage, open investigations, rule continuity and unresolved defects. A platform change is not inherently a reason to exit, but a prolonged monitoring outage may materially alter residual risk. Record whether compensating controls are actually staffed and operating.

A change review should produce a specific outcome: retain the existing approval; amend the profile; impose a service limit; require remediation; increase scrutiny; or consider exit. The decision should identify the conditions, owner and evidence needed for closure. “Enhanced monitoring” without naming the monitored population, scenario, frequency and escalation is not a usable control.

The correspondent lifecycle remains dynamic. An institution can be acceptable for one bounded service while unsuitable for another. Decisions should follow the evidence and legal boundaries of the actual activity rather than permanently stamping the respondent “safe” or “unsafe” at onboarding.

Assurance and de-risking decisions

Test a nested payment, a payable-through customer, missing beneficiary data, a shell-bank concern and repeated respondent non-response. Check that cases reach an authorised owner and that the correspondence record supports the eventual action.

Avoid using country or industry labels as automatic substitutes for relationship assessment unless a binding prohibition applies. Consider whether a narrower service, stronger information arrangement or other proportionate control can manage the identified exposure. The bank may still choose to exit where risk cannot be managed, but should document why.

Review whether questionnaires are current and internally consistent with actual transactions. A well-completed questionnaire can coexist with a failed monitoring feed or uncontrolled nested service.

Correspondent Banking Due Diligence, Lifecycle and Exit — evidence map

Design tests around failures a questionnaire cannot reveal

The following acceptance tests are fictional control-design exercises. Set expected results before execution and preserve transaction identifiers, source records, system events and reviewer conclusions. A test that merely confirms a screen can be opened does not show that the service boundary or escalation works.

Test 1: Unapproved nested service

Create a payment from Birch routed through Cedar, whose approved service excludes downstream-bank activity. Preserve complete party data so the test concerns the service restriction rather than a missing-field error. The monitoring or operational process should identify the downstream exposure, open a review and route it to the authorised relationship owner. The payment disposition should follow its own legal and operational assessment. Failure is a silent pass because Cedar itself remains an approved customer.

Investigate the cause if the test is missed. Birch might be coded as an ordinary company, its identifier may be absent from the detection feed or the restriction may exist only in a PDF approval. These defects need different fixes. A new rule cannot compensate for an institution identifier that never reaches the control.

Test 2: Direct customer access despite a product prohibition

Attempt to create a user for a Cedar customer in Harbour's payment portal. The intended access policy should prevent unapproved direct instruction, not merely warn a relationship manager afterward. Test both ordinary user creation and bulk entitlement import. If an emergency administrator can create the user, verify a controlled approval and subsequent review. A restriction that applies only to the normal onboarding screen leaves a material alternative route.

Check whether the underlying instruction can be identified as customer-originated. If direct access is allowed under an approved payable-through model, test the relevant respondent CDD and information-availability arrangements. The expected result changes with the authorised product; the test should not accidentally forbid a service the bank deliberately approved.

Test 3: Missing and altered payment information

Send a payment with a missing debtor identifier, then a corrected message. The system should preserve the original defect, connect the versions and apply the relevant repair or restriction process. Repeat with a changed name rather than a harmless formatting correction. An analyst should be able to see who changed the data, why and whether screening used the corrected information.

Test the message type and channel separately. A control that works for one ISO 20022 instruction may not cover a proprietary bulk file or an older supported format. Establish the actual accepted population and any exclusions. Source-system totals should reconcile to the control population by meaningful event type, not only aggregate daily value.

Test 4: Respondent response that arrives but does not answer

Send a targeted request explaining an unusual beneficiary. Return an on-time response containing Cedar's general AML policy but no transaction explanation. The case should remain unresolved and indicate why the material question is unanswered. If timeliness metrics count this as a successful resolution, the management information should be changed to distinguish response receipt from response sufficiency.

Next provide a relevant response with a corroborating invoice and customer explanation. Test whether an authorised reviewer can resolve the concern while retaining the initial insufficiency and subsequent evidence. Good controls permit evidence-based closure; they should not leave every first-response defect permanently open.

Test 5: Current certification contradicted by an event

For a US relationship subject to the applicable foreign-bank certification regime, introduce credible new information inconsistent with a current certification. The process should route the concern for verification under the applicable rule rather than treating the recertification date as permission to wait. The regulatory source specifies particular clocks and closure conditions; the local procedure should identify them accurately. This test does not create the same deadline for other jurisdictions.

Preserve the date the bank learned of the contradiction and the verification request. Distinguish the service manager's internal target from the legal clock. Test escalation when the necessary information remains unavailable and confirm that closure controls implement the applicable restrictions on new positions or transactions.

Test 6: Monitoring feed interruption

Stop the transaction feed for Cedar while the payment platform continues operating. Reconciliation should detect a missing population, not merely a zero-alert day. The alert to operations should identify the affected account, service, period and event types. The incident owner should decide whether a controlled fallback or service restriction is needed.

Restore the feed and test replay. Duplicate suppression must not discard transactions that were absent from the original monitoring population. The recovery evidence should identify which records were reprocessed, what scenarios ran and whether resulting cases received appropriate review. “Feed restored” alone does not demonstrate that the exposure gap was assessed.

Test 7: A relationship limit without an operational effect

Reduce Cedar's approved service scope to supplier payments in specified corridors. Attempt a treasury payment and an out-of-scope corridor through every supported channel. Check whether the system blocks, routes or detects the event according to the chosen design. If the restriction is deliberately monitored after execution, senior management must understand that the exposure is not prevented beforehand.

Test the effective time. A scheduled restriction should not become effective accidentally at the next overnight batch if the approval requires immediate action. Preserve the approval timestamp, configuration deployment and first transaction evaluated under the new scope. If several systems use the restriction, assess consistency across them.

Test 8: Sanctions concern during commercial exit

Put a balance and an in-flight payment under a fictional legal restriction, then run ordinary relationship closure. The process should not return funds automatically or describe the legal restriction as a routine commercial cancellation. Route the asset treatment to the authorised sanctions and legal owners. Customer communications should follow lawful disclosure limits and retain their approval.

Use a second balance without the legal restriction to prove that the workflow can complete ordinary lawful settlement. A safe closure process distinguishes states rather than freezing all balances indiscriminately. Treasury, operations and legal should agree how each category is treated and evidenced.

Test 9: Exit followed by accidental reopening

Close Cedar's account, then test a new account request under an alias, a different branch code and the same legal entity identifier. The bank's re-entry control should detect the previous relationship decision and route the request appropriately. Reopening can be lawful in some circumstances, but it should follow a new authorised assessment rather than arise from a duplicate customer record.

Separately test a genuinely distinct affiliate. The prior exit is relevant context, yet the legal entity and cause of exit should be examined. A group-wide restriction requires a defined policy or legal scope; an entity-only restriction should not accidentally block every affiliate without a decision.

Test 10: Reporting confidentiality in service communications

Generate a relationship-review letter from a case containing protected suspicious-reporting information. The customer-facing document should include only approved lawful information. Test attachment metadata, copied case notes, email templates and shared-folder permissions. A redacted narrative can still disclose a protected report through a file name or status field.

The reporting officer retains the external reporting decision; the relationship owner handles service decisions. Cases should show the necessary coordination without giving every commercial user access to protected reporting records. Test both normal-role access and the exceptions used for senior escalation.

Assurance that tests operational outcomes

Review a population of recent information requests. Sample unresolved, closed, overdue and apparently successful cases. Identify whether the evidence actually resolved the concern, whether service restrictions were applied and whether repeated failures reached a relationship review. A sample drawn only from well-documented closures cannot establish how the bank handles difficult cases.

Compare the approved nested-service population with actual institution identifiers in payments. Investigate unmatched identifiers and the reasons for classification. Some may be intermediaries used for routing, not downstream customers; others may indicate an unrecorded nested service. The analyst needs role-aware data to make the distinction.

Challenge residual-risk statements. If an approval says “risk mitigated by stronger monitoring,” ask for the specific coverage and outcome evidence. If it says “respondent has remediated,” inspect the issue scope, action, validation and any remaining limitation. Approval should communicate the risk still being accepted, not merely repeat that remediation occurred.

Finally, test examiner reconstruction. Give an independent reviewer one relationship and one material payment without narrating the intended conclusion. The reviewer should identify the service approved at that date, information available, control events, open questions and authorised decisions. Difficult reconstruction often exposes missing version history or fragmented evidence before a regulator has to ask.

Worked nested-service case

A fictional respondent initially requests ordinary commercial payments. Actual activity later includes large flows for another bank in an unfamiliar corridor. Determine whether nested services were approved, what the respondent knows about the downstream institution and whether the transaction information is adequate.

Explain the information needed for risk-based reassessment and why the correspondent should not either ignore the downstream exposure or assume it must obtain every customer's full CDD file.

Full lifecycle case: Cedar's new downstream business

This teaching case uses invented banks, amounts and dates. Harbour Bank holds Cedar Bank's euro account. Initial approval permits commercial customer payments and Cedar's own treasury settlement. No direct customer portal access is allowed. Nested services require separate approval. Cedar's original profile describes domestic manufacturers and importers, with a seasonal increase before the year-end shipping period.

During the first six months, monitoring broadly matches the profile. Information requests are answered with transaction explanations and relevant evidence. Harbour records some repairs for incomplete beneficiary addresses and asks Cedar to improve capture. The relationship remains open; the repairs are monitored as a data-quality issue rather than presented as proof of criminal activity.

Month seven: a new pattern

Payment count rises sharply while average value falls. Several messages identify Birch Bank as the originating institution. Beneficiaries include individuals and small merchants in corridors outside the original profile. The first analyst writes “possible remittance expansion or nested exposure” rather than “confirmed laundering.” The observation concerns a changed service population; its meaning depends on further facts.

Harbour asks Cedar whether it has begun providing payment access for Birch, what service is involved and which controls support it. Cedar replies that Birch is a licensed domestic bank and that the flows relate to Birch's customers. It provides a licence record and an agreement describing access to Cedar's international payment network. This confirms that the population differs from the approved ordinary Cedar-customer service.

The relationship team opens a service-change review. Operations identifies payments already settled, payments pending and instructions awaiting repair. Financial crime assesses the downstream exposure. Legal checks applicable correspondent obligations and the contractual restriction. The reporting officer considers whether facts support suspicion; the service breach alone is not treated as a report automatically.

The first decision meeting

Commercial management proposes accepting the change because revenue is growing. Compliance asks what Harbour can identify about Birch's activity, how Cedar oversees Birch and whether relevant information is available. Treasury asks about daily liquidity and rejected-payment effects. Operations explains that downstream-bank identifiers reach the message archive but are not yet mapped to the monitoring segmentation field.

This data gap matters. The bank cannot confidently compare Birch activity with the approved profile using its current segmentation. A licence document does not fix that weakness. The meeting therefore distinguishes institutional evidence from transaction coverage. It records both the potential acceptability of the respondent model and the current technical limitation.

A proportionate interim option is to restrict new Birch activity while retaining the originally approved service, if legally and operationally feasible. Another option is a carefully bounded temporary service with a manual review population. Whether either is acceptable depends on capacity, legal requirements and residual risk. “Manual review” is not a valid compensating control if daily volume exceeds the analysts' ability to review the relevant population.

An information request exposes a second problem

One Birch-related payment has an unusual corporate beneficiary and an inconsistent purpose. Cedar supplies a generic assurance but cannot obtain an explanation from Birch. Harbour specifies the outstanding question and asks for relevant underlying facts. Cedar explains that its agreement does not give it a reliable route to request those facts quickly.

This is different from a temporary mailbox error. Cedar accepted a downstream service without a sufficiently effective information arrangement for the exposure. Harbour considers whether the gap can be remedied through changed terms, named contacts, a tested request process and defined limitations. It does not demand all Birch customer files simply because one response failed.

The payment case remains unresolved pending the facts needed for its disposition. The relationship review records the repeated-information concern. If the reporting threshold is reached, the reporting officer follows the applicable reporting framework independently of the commercial decision. Any customer-facing communication must preserve reporting confidentiality.

Remediation proposal and evidence

Cedar proposes suspending Birch's new instructions, strengthening its own due diligence, obtaining a contractual information route and limiting the service to specified customer segments and corridors. Harbour asks for an implementation demonstration. Cedar sends revised documents, but Harbour also tests one actual permitted information request and examines the payment fields needed for downstream attribution.

The technology team adds a role-aware institution mapping to monitoring and reconciles the prior population. It checks that Birch is not confused with an intermediary used solely for settlement. Historical payments are replayed into the appropriate analysis after duplicate controls are configured. Analysts assess the resulting cases rather than treating successful replay as completed financial-crime review.

Independent challenge finds that one bulk-payment channel omits the downstream identifier. The remediation remains incomplete for that channel. Harbour can exclude the channel from an approved bounded service if the restriction is enforceable and acceptable, or require a repair before authorisation. The decision should not describe “all channels remediated” when one remains uncovered.

A defensible continuation decision

Assume Harbour finds Cedar's controls adequate for a limited nested service after the evidence and data issues are resolved. Senior management approves the specific scope, records the residual risk and identifies trigger events for reconsideration. The approval does not apply automatically to a different downstream bank or expanded corridors. Cedar's original customer service and the new nested population receive distinct profiles.

The first-month review assesses actual activity, request quality, exceptions and technical coverage. A low alert count is interpreted against transaction population and scenario design. If monitoring has no events because a feed failed, that outcome cannot be recorded as evidence of low risk. If activity is within profile and targeted inquiries are well supported, the relationship record should say so with the underlying evidence.

Alternative conclusion: controlled exit

Assume instead that Cedar repeatedly provides inconsistent information, cannot identify downstream activity and refuses a workable remediation. Harbour documents why the risk cannot be managed within its service. Legal assesses notice requirements and any current asset restrictions. Operations and treasury create a closure plan for unsettled payments, account balances, fees, investigations and records.

The plan distinguishes new instructions from existing obligations. It prevents unintended new activity, tracks the disposition of each in-flight item and records the lawful treatment of remaining balances. A blocked balance stays subject to the applicable legal restriction; ordinary closure does not release it. Communications explain the permissible service decision without revealing protected reporting information.

After closure, audit tests whether Cedar can regain access through a duplicate record or another channel. Records remain available for lawful authority requests and reconstruction. The bank also examines why its original approval boundary failed and whether similar unapproved nested exposure exists in other relationships. The lesson is operational and specific: a PDF condition needs data and process support to constrain activity.

Additional cases for independent judgement

A respondent changes its name after a merger. Determine whether the contracting entity survives, which licence and ownership records change, and whether accounts or services are being transferred. A simple brand update may need modest record maintenance; a new entity can require a different acceptance process. Preserve the basis for the classification and review downstream entitlements.

A small bank serves a remote region. Limited size and a higher-risk national environment do not establish that the bank is a shell bank or unacceptable customer. Assess actual physical presence, supervision, services and controls. Consider whether a bounded relationship can manage the exposure. If it cannot, explain the specific gap rather than using geography as a substitute for evidence.

An information request crosses a national secrecy restriction. Ask which information, recipient and legal rule create the restriction. Consider lawful alternatives and escalation. Do not write an instruction telling Cedar to disclose a suspicious report. Distinguish inability to share a protected report from inability to provide ordinary underlying transaction facts through a permitted route.

An intermediary identifier changes. A new intermediary bank can be a routing adjustment rather than a new downstream relationship. Review party roles, settlement instructions and the underlying customer population. If the system classifies every intermediary as a nested bank, the resulting false positives can obscure real downstream changes.

A correspondent wishes to stop a currency service. A strategic or economic decision can lead to exit without a finding of customer misconduct. Record that basis accurately. Assess customer notice, remaining payments, balances and legal restrictions. Do not invent an AML rationale simply to make a commercial decision appear more defensible.

Knowledge checks and model reasoning

  1. Why does a licence not complete respondent due diligence? It establishes a relevant legal permission but does not demonstrate the actual customer population, service scope, information arrangements or operating effectiveness of controls.
  2. Is Birch automatically Harbour's direct customer? No. A nested arrangement creates downstream exposure requiring risk-based understanding; the contractual and legal customer relationship must be established separately.
  3. Does a questionnaire create permission for a new service? No. Approval should identify the service and conditions; a response describing business activity is evidence to assess, not an authorisation by itself.
  4. Can a reporting decision be delegated through the service contract? The bank retains its own applicable duty. Institutions can coordinate lawful facts while each authorised officer applies the relevant reporting framework.
  5. What is lost when only repaired messages reach monitoring? The bank may lose the original defect, attempted alteration, operator action and sequence relevant to analysis and control assurance.
  6. Why distinguish receipt from sufficiency in information requests? An on-time irrelevant reply does not resolve the question. Timeliness and evidence quality measure different aspects of the control.
  7. When is a temporary manual control credible? When its population, staff capacity, decision process, evidence, duration and escalation are defined and demonstrably workable for the exposure.
  8. Can exit release a legally restricted balance? No. The legal asset restriction continues independently of the commercial relationship decision and requires authorised treatment.
  9. What makes an event-driven review meaningful? It evaluates the actual changed exposure and produces a documented decision or action, rather than merely moving the next calendar date.
  10. How should de-risking conclusions be documented? Explain the particular relationship and control gaps, alternatives considered and why the residual risk can or cannot be managed; do not substitute an entire country or sector label for that assessment.

Systems and controlled exit evidence

Store respondent, account, service, corridor and downstream-exposure attributes with review dates and approval history. Preserve transaction references linking messages to accounting entries; message delivery does not by itself prove final settlement.

Acceptance tests cover service limits, information-request failures, changed profiles, reporting confidentiality and closure while payments are in flight. Operations, legal, compliance and treasury should agree the treatment of remaining assets and obligations before access is withdrawn.

An effective correspondent lifecycle combines institutional due diligence with visibility into the actual activity the relationship carries.

Correspondent Banking Due Diligence, Lifecycle and Exit — governance map

A service-aware data model

Begin with stable legal-entity identifiers and entity versions. Cedar's legal name, licence, owner and branch attributes should be linked to effective dates and evidence sources. Preserve the historic record when a name or ownership changes. An investigator reconstructing a payment from last year needs the entity state at that time, not only today's description.

Accounts should link to the contracting entity, booking location, currency, service permissions and status history. A single legal entity can hold several accounts with different allowed activity. A single service can use several accounts. The model should support both relationships without assuming that one account-level status describes every product.

Service records should identify customer segments, approved corridors, nested-access scope, direct-access permissions, operating channels and controls. Include the approval, owner, effective date and conditions. Store restrictions in a form that can be applied or reconciled to actual activity. A long free-text condition is still useful for rationale, but a system cannot reliably enforce it unless the relevant machine-readable attributes are defined.

Party roles belong to each transaction. A bank appearing as debtor agent, intermediary, creditor agent or downstream respondent performs different functions. Preserve the role, identifier, country and source field. A monitoring feature labelled simply “bank country” may confuse routing exposure with the respondent's customer geography. The data dictionary should identify the meaning of every derived country attribute.

Join the instruction, cover or funding message, accounting entry and settlement status. The transaction chain may have several identifiers. Keep the original references and the mapping to internal case identifiers. A message-delivery acknowledgement shows communication; an accounting or settlement event shows a different fact. Investigators should be able to state which point in the chain is evidenced.

Information requests should link to both the transaction and the relationship review when relevant. Record the question, requested fields, lawful transfer route, recipient, response status, sufficiency assessment and escalation. An overdue response is an operational state. A material unanswered question is an evidence state. A relationship restriction is a risk decision. A sound model does not represent all three through one generic red flag.

A fictional request-to-release trace

Harbour's case H-204 concerns a Cedar payment identifying Birch as a downstream institution. The instruction entered the payment system at 09:14, screening completed at 09:15 and an out-of-profile service control routed the instruction for review at 09:16. The accounting entry has not settled. These timestamps establish the actual operational position before the analyst contacts Cedar.

At 10:05 the analyst sends a secure request for the downstream-service explanation and relevant purpose information. Cedar acknowledges at 10:21. At 13:40 it supplies an explanation and confirms that the flow originated from Birch's customers. The bank records which statement is an attestation and which is supported by an agreement or transaction record. The response is not silently converted into independently verified fact.

At 14:10 compliance concludes that the service is outside the current approval and asks the relationship owner for a decision. Legal reviews the applicable restrictions; the sanctions owner confirms that no identified prohibition requires blocking in this fictional example. Operations explains the options for cancelling, returning or releasing the pending instruction under the applicable rail and contract. The reporting officer considers suspicion separately.

Senior management authorises a bounded outcome supported by the evidence and orders a broader service review. The system records who approved, which instruction was covered, any expiry and the policy version. A second instruction cannot reuse this transaction-specific approval automatically. When the relationship scope changes later, its new effective date does not rewrite H-204's original decision.

An examiner reconstructing H-204 should see the approved service at 09:14, transaction state, control trigger, request, evidence, decision owners and final execution. It should also see the service-change issue created by the case. A screenshot of a final green status would omit most of the facts needed to assess the decision.

Management information that exposes unresolved risk

Report the respondent population by material service and risk attributes. A count of active bank customers can hide how many provide nested access, use direct customer instructions or operate in a newly approved corridor. Show changes as well as the current stock, because a large unreviewed expansion can occur within an apparently stable customer count.

For due diligence, distinguish missing mandatory evidence, stale scheduled review, open remediation and an approved time-bound exception. Each state needs an owner and action. Aggregating them into “CDD incomplete” can prevent management from seeing which relationships cannot lawfully operate and which need ordinary evidence maintenance.

For information requests, measure receipt and sufficiency separately. Useful dimensions include service, respondent, downstream exposure, reason for request and unresolved material question. Review repeat non-response and vague-response patterns. A small number of high-value unanswered cases may matter more than a large number of harmless address clarifications.

For monitoring, report population reconciliation, channel exclusions, unavailable identifiers and control outages alongside alerts and cases. Fewer alerts can reflect better data and tuning, lower activity or failed coverage. Management needs enough context to distinguish these explanations. A false-positive reduction metric without detection assurance can reward a weakened control.

For service restrictions, report the condition, effective date, operational implementation and breaches. The business should know whether a limit is preventive, detective or manual. If an exception permits a bounded exposure temporarily, show the expiry and validation needed for continuation. Repeated extensions without evidence should be visible to the authorised risk committee.

For exits, separate commercial exits, unmanaged-risk exits and legally required restrictions. Show in-flight transactions, remaining assets and unresolved closure items. An account system marked closed can still have outstanding investigations or legal holds. Management should not treat the status as proof that every obligation has ended.

Exit as an operational programme

Start by establishing the cause and authority. A commercial service withdrawal, an evidence failure, an unacceptable residual risk and a legal prohibition can all lead to reduced access, but require different handling. The exit record should name the legal entity, accounts, services, countries and channels within scope. Avoid a vague group-name instruction that operations cannot implement consistently.

Next build a transaction inventory. Include pending instructions, unsettled payments, repair queues, returns, investigations, collateral, fees and liquidity arrangements where relevant. Identify whether an item can be cancelled, must be settled, requires a return process or remains legally restricted. Treasury should assess funding implications; operations should identify cut-off times and rail-specific constraints.

Prepare access changes across the entire service. Closing the core account while leaving portal credentials, payment file access or a linked account active can permit unintended new instructions. Inventory channels and entitlements rather than relying on one screen. Changes should be coordinated to avoid both accidental continuation and premature interruption of obligations that need controlled completion.

Communication needs its own review. State the lawful service action and practical steps without disclosing protected reporting information or unsupported allegations. Use an authorised contact and preserve the final approved wording. If a regulator or authority directs particular handling, identify that instruction and route any conflict with ordinary notice terms to legal.

Apply records controls. Retention depends on the applicable framework and record type; do not delete case evidence because the commercial account is closed. Keep a discoverable link between customer identity, account history, payments, due diligence, approvals and exit. Restrict protected reporting records appropriately while ensuring authorised reconstruction remains possible.

Finally, verify closure rather than assuming it. Attempt a new instruction through each channel, inspect residual balances and reconcile remaining items. Record the result of each closure task and unresolved exception. A senior sign-off should be supported by operational evidence, not a statement that all departments were notified.

Change management for correspondent controls

Regulatory changes, new message standards and respondent service expansions should enter a controlled impact process. Identify which booking entities, relationships, services and data fields are affected. Record whether a source is a binding enacted requirement, guidance, proposal or international standard awaiting implementation. A headline about a correspondent reform does not define the entire bank's obligation.

Translate each relevant change into a requirement and an owner. A payment transparency change may affect data capture, messaging, repair, screening and investigation evidence. A new local due-diligence requirement may affect institutional review and senior approval. Each requirement should have a test demonstrating the intended outcome, not simply a confirmation that a policy was updated.

Use representative and difficult populations. Include ordinary commercial flows, nested access, direct instructions if permitted, treasury activity, returns and legacy channels. Check whether the change alters false positives, operational queues or information requests. Business readiness includes the ability to handle the workload created by the control.

Prepare rollback and incident decisions. If a new mapping causes valid payments to be misclassified as nested, operations needs an authorised correction route. If rollback restores a known compliance gap, the release owner should understand the resulting exposure and required restriction. Technical reversibility does not automatically establish legal acceptability.

Post-release review should compare the implemented control with the approved design. Reconcile populations, examine exceptions and assess a sample of decisions. An implementation can pass unit tests while an upstream data feed omits a channel. The final evidence should describe what actually operated in the bank, including limitations requiring further action.

Decision-quality review questions

An independent reviewer can ask whether the bank identified the customer and service accurately, understood downstream exposure, challenged material contradictions, obtained the evidence necessary for the chosen outcome and preserved each decision's authority. These are connected questions, but none is answered solely by a completed questionnaire or an active account status.

Review language matters. “No risk identified” is stronger than the evidence usually warrants. “No material issue identified within the reviewed service and evidence, with the following limitations” is more precise when that is the actual conclusion. Similarly, “respondent failed AML” should be replaced by the demonstrated control or information failure unless the broader conclusion is supported.

The correspondent's commercial relationship, transaction decisions and external reporting are related parts of a lifecycle. Good design keeps their facts connected while preserving their different legal tests and owners. The bank should be able to explain both why it provided the service and why it took a particular action when the activity changed.

Messaging permissions, credit and financial-crime approval

Swift's Relationship Management Application controls permitted messaging relationships. Swift describes RMA as a filter for which counterparties can send relevant traffic. That technical permission should be inventoried and governed, but its existence does not establish an account, a credit facility or completed correspondent due diligence. The related Swift source is linked below. Review the service and supported messaging environment rather than assuming every permission carries the same business purpose.

For Harbour, an operations administrator may maintain messaging permissions while a separate committee approves Cedar's account service. Treasury may grant a settlement or overdraft limit under another process. Financial crime assesses institutional and activity exposure. These decisions should be connected through the legal entity and service records, with their respective owners and scope. An RMA entry should not be treated as evidence that the other approvals occurred.

Consider a non-customer messaging relationship used for a legitimate enquiry or trade-related communication. Harbour may have no Cedar account and no authority to settle a payment on its behalf. The appropriate due diligence and messaging restrictions need assessment under the applicable framework, but the bank should not invent an account relationship simply because authenticated communication is possible. Conversely, an account customer can continue to have other communication channels when a particular messaging permission is removed.

An exit plan therefore needs distinct actions for messaging, account access, credit exposure and outstanding contractual obligations. Removing a messaging authorisation may stop a relevant message route; it does not settle an outstanding payment or release collateral. Closing the account may leave a credit claim or a permitted communications requirement. Each closure task should state what it achieves and what obligations remain.

Credit controls and financial-crime controls also ask different questions. A payment can be within a sound credit limit yet involve an unacceptable service or legal restriction. A legitimate payment can fail for insufficient liquidity without being suspicious. Record these reasons separately so analysts do not interpret every financial rejection as an AML outcome or every credit approval as evidence of clean funds.

A useful combined test starts with an authorised message, adequate liquidity and an unapproved downstream service. The payment should reach the relevant service control despite passing communication and credit checks. Another test uses an approved service with a credit-limit breach; it should receive the credit disposition without an unsupported criminal allegation. Finally, remove the messaging permission while retaining the account temporarily for controlled closure, and verify that the operational team can complete lawful remaining obligations through an approved process.

This distinction improves both assurance and customer communication. Management can see which control caused a restriction, what evidence supported it and who can authorise the next action. The bank avoids a single ambiguous “relationship approved” flag that hides several independent approvals with different conditions and effective dates.

References and further reading

Reviewed 2 October 2026. FATF provides international standards; applicable national law determines binding duties. The operating examples are fictional teaching cases.