Correspondent banking is how money crosses borders. A bank with no presence in a currency’s home country holds an account with one that does, and settles its customers’ payments through it. The system is essential and almost invisible to the people using it.
Its structural weakness is that the correspondent serves its respondent’s customers without knowing them. It sees a payment instruction, not a relationship. Every control in this area — due diligence on the respondent, restrictions on nesting, insistence on complete payment data — exists to compensate for that.
How it works
Nesting. A correspondent onboards a respondent bank and performs due diligence on it. That respondent then provides correspondent services to other banks, which use the original correspondent’s account without ever having been onboarded by it. Each additional layer removes another institution from the correspondent’s view. Nesting is not prohibited; undisclosed nesting is the problem, and it is a recurring finding in enforcement actions because it is the mechanism by which an institution in a restricted jurisdiction obtains clearing through two intermediaries that each believe they know their customer.
Payment data manipulation. Screening reads the structured fields in a payment message. Removing or altering the originator or beneficiary information defeats the screening without changing where the money goes. This is among the most heavily penalised sanctions violations on record, because it is unambiguous: the alteration is deliberate and is documented in the message itself.
Chain lengthening. Routing a payment through additional intermediary banks adds cost and delay. Where that is done without commercial justification, the effect is to increase the number of institutions each of which sees only a fragment.
Profile drift. A respondent describes its business at onboarding and the correspondent calibrates its monitoring to that description. Where the respondent’s customer base changes without notice, the monitoring is calibrated to a bank that no longer exists. The Wolfsberg Group’s guidance is built around keeping that picture current, and around payment transparency in the services a respondent offers onward1 .
What the correspondent can actually see
It is worth being exact about this, because the whole subject turns on it. A correspondent sees: the respondent, the payment messages it sends, the counterparties named in those messages, the currencies and amounts, and the pattern over time. It does not see the respondent’s customer files, the underlying contracts, or the identities behind names that appear correctly formed.
Detection therefore has to be built from what is visible: the aggregate shape of a respondent’s traffic, its consistency with the declared profile, and the completeness of the data in the messages.
How it is caught
Message field analysis. Incomplete or altered originator and beneficiary fields, recurring across many messages, is a pattern no single payment reveals and no reviewer can miss in aggregate.
Profile variance. A respondent’s actual traffic — corridors, counterparties, volumes, currencies — compared against what it described. Sustained divergence is the standard trigger for enhanced review and for requests for information.
Requests for information. The correspondent can ask, and the quality of the answer is itself diagnostic. A respondent that cannot identify the ultimate originator of payments it is passing on has answered the question.
Retrospective reconstruction. Most large enforcement actions in this area are built after the fact by comparing the instructions a bank received with the messages it sent. Where those differ systematically, the record proves itself, and this is why penalties in this area are among the largest ever imposed.
Why the correspondent model creates the exposure at all
It is worth being explicit about the structure, because the technique is a consequence of it rather than an attack on it.
A bank in one country cannot hold central bank money in another country’s currency. To settle in dollars, euros or sterling it holds an account with a bank that can, and instructs payments through that account. The correspondent executes those instructions for parties it has never onboarded, has no file on, and in many cases cannot identify beyond a name in a message field.
Every control in this area is compensation for that single fact. Due diligence on the respondent exists because the correspondent cannot do diligence on the respondent’s customers. Restrictions on nesting exist because each layer removes another institution from view. Payment data standards exist because the message is the only thing the correspondent sees.
What the message actually carries
Modern cross-border payment messages carry structured fields for the originating customer, the originating institution, intermediary institutions, the beneficiary institution and the beneficiary customer, along with remittance information.
Screening reads those fields. That is the entire basis of sanctions filtering in payments, and it means the integrity of the message is the integrity of the control.
Historic practice in this area — replacing a named originator with a generic reference, dropping a field, or routing a payment through an internal account so that the original instruction did not travel with it — attacked exactly that. It is the reason payment transparency standards were rewritten, and the reason those cases produced penalties unmatched in any other category.
Nesting is the modern version of the same problem
Message integrity is now heavily controlled at major institutions. Nesting is not, to the same degree, because it is not a falsification — it is an omission.
A correspondent onboards a respondent and forms a view of its business. That respondent provides correspondent services to other institutions, which reach the original correspondent’s account without ever having been assessed by it. Where that arrangement is disclosed it can be controlled: the correspondent can set expectations, require information, and monitor accordingly. Where it is not, the correspondent’s monitoring is calibrated to a customer base that no longer exists.
The Wolfsberg Group defines the arrangement directly: a downstream, or nested, relationship arises where a respondent provides correspondent banking services to other institutions, inside or outside its own country, on behalf of those institutions’ customers2 . Its guidance asks the correspondent to consider the degree to which the respondent examines those institutions’ financial crime controls, and to determine whether controls are in place to ensure payment transparency1 . The recurring finding in enforcement is not that nesting occurred but that it was not known about.
What a correspondent can realistically detect
Being concrete about this matters, because expectations of correspondent banks are frequently stated at a level no institution could meet.
A correspondent can see: the aggregate shape of a respondent’s traffic, its corridors, its currencies, its counterparties by name, its volumes over time, the completeness of its message data, and how the respondent answers questions.
It cannot see: the respondent’s customer files, the underlying contracts, the identity behind a correctly formed name, or anything at all about a customer of a customer it has not been told about.
Detection therefore has to be built from the first list. Profile variance — actual corridors and volumes against the described business — is the workhorse, because it uses only what the correspondent has and it surfaces exactly the drift that undisclosed nesting produces.
Why this category’s penalties are so large, and why they stopped
Two structural reasons.
Liability accrues per transaction against a statutory maximum, so conduct that ran for years across thousands of payments produces figures unrelated to any profit earned. And the evidence is the institution’s own archive: comparing the instruction received with the message sent is an exercise that proves itself, which is why the facts in these cases are so rarely contested.
The sequence of very large settlements running from 2009 to 2019 substantially ends after that, and the analysis of the full penalty record sets out what replaced it. The most likely reading is that the cases worked: payment message integrity became a board-level matter at every major correspondent bank, and the transparency standards adopted in response are the direct legacy of those penalties.