NYDFS fined Nordea $35M in 2024 for correspondent-banking AML failures. See what FATF, FFIEC and Wolfsberg's CBDDQ require, and the gaps Nordea exposed.
Table of contents
- In August 2024, the New York Department of Financial Services fined Nordea Bank $35 million for failures in correspondent-banking AML controls exposed by the Panama Papers, including inadequate diligence over high-risk relationships.
- Correspondent banking due diligence is the enhanced scrutiny a bank applies to another bank it serves, covering the respondent's ownership, licensing, AML program, and the risk of its customers' customers.
- FATF Recommendation 13 and the FFIEC BSA/AML Examination Manual set the baseline, and the EU AML framework adds enhanced due diligence for cross-border relationships and a prohibition on dealing with shell banks.
- The Wolfsberg Correspondent Banking Due Diligence Questionnaire is the global standard, and its v1.4 update added a fraud section and questions on whistleblowing, virtual bank licences, and sanctions-policy approval.
- Nested correspondent relationships, where a respondent quietly provides downstream access to other institutions, are the enforcement vector regulators probe hardest.
- Nordea's failure was structural, weak diligence over high-risk correspondents, and it is exactly the kind of ownership and risk-chain gap a modern, evidence-led process is built to close.
Correspondent banking due diligence is the enhanced scrutiny a bank applies to another bank it serves, the respondent, covering the respondent's ownership, licensing, AML controls, and the risks posed by its customers. It is governed by FATF Recommendation 13, the FFIEC manual, and the EU AML framework, and standardised through the Wolfsberg CBDDQ.
TL;DR
Correspondent banking is where one bank provides services to another, and it is one of the highest money-laundering risks in finance, because you are exposed not just to the respondent bank but to its customers, and sometimes to their customers in turn. In August 2024, NYDFS fined Nordea Bank $35 million for correspondent-banking AML failures surfaced by the Panama Papers, citing inadequate diligence over high-risk relationships.
Correspondent banking due diligence is the enhanced process that manages this risk: verifying the respondent's ownership and licensing, assessing its AML program, understanding the risk of its customer base, and watching for nested relationships that hide downstream institutions. FATF Recommendation 13 and the FFIEC manual set the baseline, the EU framework adds enhanced due diligence and a shell-bank prohibition, and the Wolfsberg CBDDQ standardises the questionnaire. This guide covers each, the Nordea structural lesson, the nested-relationship problem, and how to operationalise the CBDDQ.
12 min read. Last updated 2 September 2026.
What is correspondent due diligence?
Correspondent banking due diligence is the enhanced scrutiny a correspondent bank applies to a respondent bank it provides services to, such as payments, clearing, or access to the correspondent's network. Because the correspondent does not directly know the respondent's customers, it inherits exposure to them, which is why ordinary customer due diligence is not enough and an enhanced process is required.
In practice that means verifying the respondent's legal ownership and beneficial owners, confirming its licensing and regulatory standing, assessing the quality and independence of its AML program, understanding the markets and customer types it serves, and screening for sanctions and adverse media. The deeper question is always the risk chain: who are the respondent's customers, and could the relationship be a conduit for illicit flows you cannot see. Resolving ownership at this depth is exactly where tools like UBO mapping earn their place.
What do FATF Recommendation 13 and the FFIEC manual require?
FATF Recommendation 13 is the international baseline for cross-border correspondent banking. It requires correspondent institutions to gather enough information to understand the respondent's business and reputation, assess its AML controls, obtain senior-management approval before establishing the relationship, document each party's responsibilities, and, critically, prohibits relationships with shell banks and with respondents that allow their accounts to be used by shell banks.
In the US, the FFIEC BSA/AML Examination Manual operationalises this, setting expectations for risk-rating correspondent accounts, conducting due diligence proportionate to risk, and applying enhanced measures to higher-risk relationships such as those involving foreign banks. The common thread between FATF and the FFIEC is that the diligence is risk-based and ongoing: a one-time questionnaire at onboarding does not satisfy either, because the respondent's risk profile and customer base change over time, which connects to the monitoring layer in our AML transaction monitoring guide.
How does the EU AML framework treat correspondent relationships?
The EU framework treats cross-border correspondent relationships as inherently higher risk and requires enhanced due diligence for them. Obliged institutions must gather sufficient information about the respondent, assess its AML and counter-terrorist-financing controls, obtain senior-management approval, and document responsibilities, mirroring the FATF baseline. The framework also prohibits entering into or continuing correspondent relationships with shell banks, and with respondents known to permit shell-bank use of their accounts.
What is changing in 2026 is consolidation. The EU's new AML package, including the single rulebook and the new Anti-Money Laundering Authority, harmonises these obligations across member states and raises the expectation of consistent, auditable diligence, reducing the room for jurisdiction-by-jurisdiction interpretation. For a correspondent bank operating across the EU, the practical effect is that enhanced due diligence for correspondent relationships becomes more uniform and more closely supervised, so the records you keep need to be consistent and examination-ready, a theme we cover in AML compliance software.
What did the Nordea case expose?
The Nordea consent order is the cautionary case of the cycle. In August 2024, NYDFS required Nordea Bank to pay $35 million after finding that, in the wake of the Panama Papers, it had failed to conduct adequate due diligence on high-risk correspondent relationships and maintained inadequate AML controls, including, around 2015, a lack of formal agreements with correspondent banks on AML policies and weak KYC instructions.
The failure was structural rather than a single missed transaction: the bank did not adequately understand or document the risk in its correspondent relationships, so problematic activity could flow through unexamined. What a modern, evidence-led process would have caught is precisely that gap, who the respondents were, who their customers were, what AML controls they actually had, and whether the documented responsibilities existed at all. Correspondent banking due diligence done properly produces exactly those records, which is why Nordea reads less as bad luck and more as a missing system, the same lesson as our work on why your KYC vendor is your biggest data breach risk: the gap is architectural.
Why are nested correspondent relationships the top enforcement vector?
Nested correspondent banking, sometimes called downstream or nested accounts, is when a respondent bank uses its correspondent relationship to provide services to other financial institutions that the correspondent has not assessed. The correspondent thinks it is banking one institution; in reality it is indirectly serving several it has never diligenced, including possibly higher-risk ones it would never have onboarded directly.
This is the enforcement vector regulators probe hardest because it is where visibility breaks down and illicit flows hide. Managing it requires asking the respondent directly about downstream and nested relationships, the Wolfsberg questionnaire includes questions aimed at exactly this, monitoring transaction patterns for signs of unexpected third-party institutional activity, and treating undisclosed nesting as a serious red flag. The defensible posture is to know not just your respondent but whether your respondent is a doorway for institutions you cannot see, and to document that you asked and verified.
How do you operationalise the Wolfsberg CBDDQ?
The Wolfsberg Correspondent Banking Due Diligence Questionnaire, the CBDDQ, is the global standard for the information correspondents request from respondents, and using it is how most banks make this diligence consistent. Its v1.4 update broadened scope, adding a dedicated fraud section and questions on whistleblowing policy, virtual bank licences, and approval of sanctions policy, among refinements to usability.
Operationalising it well means more than collecting a completed questionnaire once. It means risk-rating each respondent from the answers, verifying the claims rather than taking them at face value, especially ownership and licensing, refreshing the CBDDQ on a risk-based cadence and on trigger events, and connecting the questionnaire to ongoing transaction monitoring so the static picture and the live behaviour are reconciled. A CBDDQ filed and forgotten is the Nordea failure waiting to repeat; a CBDDQ that is verified, risk-rated, refreshed, and tied to monitoring is correspondent due diligence that holds up. Underpinning all of it is reliable identity and ownership data, which is where decentralised KYC and KYB supports the process.
What audit pack does a correspondent-banking examiner want?
When an examiner reviews a correspondent banking program, the records they want are specific: the risk rating of each correspondent relationship and its basis, the due-diligence file including verified ownership and licensing, the completed and refreshed CBDDQ, evidence of senior-management approval, the documented division of AML responsibilities between correspondent and respondent, screening and monitoring records, and the handling of any nested-relationship inquiries.
The defensible posture is to keep that file current and reconstructable per relationship, so an examiner can see what you knew about each respondent, when, and what you did about it. The institutions that fail examinations, Nordea among them, are typically the ones whose files are stale, incomplete, or silent on who actually owned and controlled the respondent and its risk. Correspondent banking due diligence, in the end, is judged on whether that evidence exists and is alive, not on whether a policy document says the right things.
The bottom line
Correspondent banking is high-risk because you inherit exposure to a respondent's customers, and sometimes to institutions hidden behind it. Correspondent banking due diligence manages that by verifying ownership and licensing, assessing the respondent's AML program, understanding its customer risk, and watching for nested relationships, under FATF Recommendation 13, the FFIEC manual, the EU framework's enhanced-diligence and shell-bank rules, and the Wolfsberg CBDDQ.
Nordea's $35 million is the reminder that the failure is usually structural: a stale or incomplete picture of who the respondent is and what risk flows through it. Verify the CBDDQ rather than filing it, risk-rate and refresh on triggers, probe for nesting, and keep a living, examination-ready file per relationship. That is the difference between a policy and a defence.
Get a correspondent-banking compliance review, or see how it works.
Related resources
- AML compliance software in 2026
- AML transaction monitoring in 2026
- UBO mapping with AI
- Why your KYC vendor is your biggest data breach risk
- Decentralised KYC
- AML software
- How it works
Cited sources
- NYDFS, settlement with Nordea Bank Abp (August 2024): https://www.dfs.ny.gov/reports_and_publications/press_releases/pr20240827
- FATF Recommendations (Recommendation 13, correspondent banking): https://www.fatf-gafi.org/en/topics/fatf-recommendations.html
- Wolfsberg Group, Correspondent Banking Due Diligence Questionnaire (CBDDQ): https://wolfsberg-group.org/resources/correspondent-banking
- FFIEC BSA/AML Examination Manual: https://bsaaml.ffiec.gov/manual
- Anti-Money Laundering Authority (AMLA), EU AML framework: https://www.amla.europa.eu/about-amla_en
Michelangelo Frigo (Co-Founder at Zyphe) Michelangelo Frigo is a privacy and identity infrastructure expert and co-founder of Zyphe.