Correspondent banking and the nested relationship problem
A correspondent relationship means accepting payments from customers you will never onboard, never see and never interview. Nesting multiplies that by an unknown factor. This note is about what you can actually find out, where the answers live in the payment message, and what to do when you discover a downstream bank nobody approved.
What you are actually taking on
When a bank opens a correspondent account for another bank, it is not onboarding one customer. It is accepting payment flow generated by every customer of that respondent, in every branch, under whatever standards that respondent applies. I have sat in credit committees where a correspondent relationship was discussed in terms of the respondent's balance sheet and settlement volumes, and the phrase "their customer base" appeared exactly once, in passing. That is the wrong emphasis. The balance sheet is the counterparty risk. The customer base is the financial crime risk, and you will never meet a single one of them.
This is the structural oddity of correspondent banking and the reason it gets disproportionate attention from FATF and the supervisors. In almost every other part of a bank, the control model rests on knowing who you are dealing with. Here, you deliberately accept a relationship in which you do not, and substitute a judgement about the respondent's own controls for direct knowledge of the underlying parties. You are not doing due diligence on the payers. You are doing due diligence on someone else's due diligence.
That substitution works, more or less, when the respondent's customer base is what you were told it was. Nesting is what happens when it is not.
Nesting, and why it is different from volume growth
A nested relationship, sometimes called downstream correspondent clearing, is where your respondent provides correspondent services of its own to a third bank, and that third bank's payments come through your account. The message will often show your respondent as the sender. The economic reality is that a bank you have never assessed, in a jurisdiction you may not have considered, is using your clearing capability.
The important thing is what this does to the chain of substitution. You accepted the respondent's controls as a proxy for knowledge of its customers. In a nested arrangement, you are now implicitly accepting the respondent's assessment of the downstream bank's controls, which in turn stand as a proxy for knowledge of that bank's customers. Each link adds distance and loses information. By the third link you are not making a risk decision, you are making an assumption about somebody else's assumption.
Nesting is not inherently improper. Small institutions in emerging markets frequently cannot obtain direct correspondent relationships, and a regional bank providing clearing to them serves a real function. The Wolfsberg Group has been consistent that the answer to nesting is transparency and control, not blanket refusal. Wholesale de-risking of entire regions pushes flow into channels with less visibility, not more. What matters is whether the arrangement is one you approved or one you found.
Approved versus discovered
This distinction is the single most useful one I have taught to analysts new to correspondent work. They are the same fact pattern with completely different implications.
An approved downstream relationship is one your respondent declared, ideally at onboarding or at the next periodic review, where you know the name of the downstream institution, its jurisdiction, the products it can access through your account, and whether it is itself permitted to nest further. You can screen it. You can set expected volume. You can decide that it falls outside your appetite and require it to be excluded. Documentation exists. Somebody signed something.
A discovered relationship is one you identified from payment data, from a media hit, or from an investigation into an unrelated alert, and which nobody at your institution had ever assessed. The financial crime exposure of the two is broadly similar, but the second tells you something much more serious: your respondent's representations to you are incomplete. That is a relationship-level finding, not a transaction-level one, and it should escalate differently. I have seen analysts write up a discovered nested bank as a single suspicious activity report on the underlying payments and consider the matter closed. The payments may well warrant reporting. The gap in what you were told warrants a conversation with the respondent's compliance function and a note in the file for the next review.
Case note
A composite from work I have done on European clearing books. A respondent bank in a mid-sized Eastern European market had held a euro clearing account since 2016, with declared activity described as trade settlement for domestic corporate clients and remittance flow from its diaspora customer base. Declared annual throughput at the 2021 review was about forty million euros. By the second quarter of 2023 the account was running at just over eleven million euros a month.
Volume growth alone is not a finding, and the relationship manager had a plausible explanation involving a new trade finance desk. What surfaced the issue was a field-level review of about four thousand MT103 messages from January to June 2023. In roughly nine hundred of them, field 52 ordering institution carried a BIC belonging to a bank in a third country, one that did not appear anywhere in the respondent's declared downstream list. Those nine hundred messages accounted for about 2.4 million euros a month, with ordering customers concentrated in three commercial sectors that had nothing to do with the declared diaspora remittance business.
The respondent, when asked, confirmed the downstream relationship had been in place since late 2021. Nobody had told us. The eventual outcome was not termination but a restricted arrangement, with the downstream bank named, screened, volume-capped and reviewed quarterly. The more useful outcome was that we changed the periodic review template to require ordering-institution analysis as standard rather than on suspicion.
The questions a respondent should be able to answer
A correspondent due diligence conversation is not a compliance interview in the confrontational sense. It is an attempt to establish whether the respondent has the information you would need to have, if you were the one holding those customer relationships. A respondent that cannot answer these questions is not necessarily doing anything wrong, but it is telling you that your substitution of their controls for your knowledge is not well founded.
The ones I return to, in rough order of how much they reveal:
- Do you provide correspondent or clearing services to other financial institutions, and if so, which ones? Ask for names and BICs, not a count.
- Can your downstream institutions themselves nest? This is the question that distinguishes a two-link chain from an open-ended one, and it is skipped far more often than it should be.
- What is your process for identifying originator and beneficiary information on payments you send us, and what do you do when it is incomplete?
- Which of your products can downstream institutions access — is it clearing only, or do they reach cash management, trade instruments, foreign exchange?
- Do you offer payable-through or similar arrangements in which a downstream customer can transact directly on the account? In several jurisdictions this attracts specific treatment; in the United States, FinCEN and the supervisors have long treated payable-through arrangements as a distinct category requiring particular scrutiny. Check what your own regime says rather than assuming the position transfers.
- How do you monitor the activity your downstream institutions generate, and can you show us what a review looks like? The quality of the answer here tells you more than the four preceding questions combined.
What the questionnaire is for
The Wolfsberg correspondent banking due diligence questionnaire is used badly more often than it is used well. I have watched teams treat it as a compliance artefact: collect it, file it, tick the review. That misses the point entirely.
The questionnaire exists to standardise the question set so that the answers become comparable and so that a respondent's own answers become comparable over time. Its value is in the delta. When a bank tells you in 2022 that it has two downstream institutions, and in 2024 that it has fourteen, no single answer is alarming but the trajectory is the whole story. When a respondent's answer on originator data quality softens between versions, that is worth a call. If nobody in your team has ever laid two years of the same respondent's completed questionnaire side by side, the document is doing no work. The Wolfsberg Group publishes the framework and guidance behind it, and I would encourage anyone running a correspondent book to read the reasoning and not just the form.
Payment message data is the visibility you actually have
Here is the practical position. You cannot interview the underlying customers. You get a questionnaire once a year, and it describes intent. What you have continuously, in volume, and generated by the actual behaviour rather than a description of it, is the payment messages.
For a cross-border credit transfer, the fields that carry the most investigative weight are the ordering customer, the ordering institution, the beneficiary, the beneficiary institution and any intermediary. FATF's recommendation on wire transfer information exists precisely so this data travels with the payment; the value to you is that it makes the chain partially visible from the inside. Concretely, in the teams I have run we look at three things:
Ordering institution population. Build a distinct list of every institution appearing as ordering institution on your respondent's inbound traffic over a rolling period, and compare it to the declared downstream list. New entrants are the finding. This is cheap to run and I have never seen it produce nothing.
Field completeness and quality. Payments with truncated, generic or repeating originator details tell you something about the respondent's own data discipline. A pattern of ordering customer fields reading "customer" or a single repeated address is not a suspicion about any individual payer, it is an observation about the respondent's controls, and that is the level at which you should raise it.
Corridor and counterparty geography. Compare the beneficiary jurisdictions actually appearing against the business description you were given. A respondent that described domestic trade settlement and is producing sustained flow to jurisdictions absent from that description has changed business without telling you, or has downstream activity it has not declared.
Where these reviews surface individual underlying entities worth understanding, the same techniques you would use elsewhere apply — reading an ownership chain to establish who the ultimate beneficial owner is, or distinguishing a genuinely dormant vehicle from an active one when you hit a shell or shelf company among the ordering customers. And when trade documentation is available behind the payment, the invoice red flags that apply to a direct trade finance customer apply equally here, with the caveat that you are usually working from fragments.
What to do with what you find
Findings from correspondent monitoring split along two axes, and keeping them separate will save you a great deal of muddle. There is transaction-level output, which follows your normal escalation route and, where the threshold in your jurisdiction is met, your normal reporting route — the mechanics of writing the narrative do not change because the subject is a bank rather than an individual, though you will need to be explicit about which party you are reporting and which are merely named. And there is relationship-level output: undeclared nesting, deteriorating data quality, an unexplained shift in corridor profile. That belongs in the respondent file and, if it recurs, in a restriction or an exit decision.
Exit is a real option and should not be treated as a failure of imagination, but it should be the outcome of a reasoned process. Restricting products, capping volumes, requiring named-downstream approval and shortening the review cycle are all available before termination. The supervisory position in the UK, articulated by the FCA, and the international position through the Basel Committee and Wolfsberg, has consistently discouraged reflexive wholesale withdrawal from correspondent relationships where risk can instead be managed. That is a position you can only hold if your monitoring is good enough to know what you are managing.
And if you are new to this, one piece of advice. Spend a day reading raw payment messages before you read a single policy document about correspondent banking. The policy will make far more sense once you have seen what field 52 actually looks like when somebody has filled it in properly, and what it looks like when they have not.
The point here: In a correspondent book, the questionnaire tells you what your respondent intends to do, and the payment messages tell you what it is actually doing — reconcile the two, or you are supervising a description rather than a relationship.
