Home
/
Blog
/
Correspondent Banking AML Risk: A Framework for De-Risking Without Losing Relationships

Correspondent Banking AML Risk: A Framework for De-Risking Without Losing Relationships

#Banking #AMLCompliance #KYCC

date icon
July 2, 2026
3 Minutes

Introduction

For most of the last decade, the default response to correspondent banking risk has been to exit it. Faced with rising compliance costs and uncertain regulatory tolerance, large banks have shed correspondent relationships with smaller banks in emerging markets rather than manage the risk those relationships carry. Regulators now openly regard this as the wrong answer. Blanket de-risking doesn't reduce financial crime exposure; it pushes the same transactions into less regulated channels where nobody is watching them at all.

MemberCheck, an enterprise AML and KYC platform built for banks managing complex, multi-jurisdictional screening obligations, works with institutions that need to keep correspondent relationships open without carrying undue risk. This is the operational framework for doing that.

Why Regulators Have Turned Against Blanket De-Risking

The regulatory direction has shifted decisively. In the United States, Executive Order 14331 directed banking regulators to remove reputation risk as a factor in examination guidance and supervisory materials, and instructed financial institutions to identify and remediate past instances of debanking. A subsequent OCC review of the nine largest US banks in December 2025 found that most institutions had restricted banking services for entire industry sectors rather than assessing individual customer risk. FinCEN's own AML programme reform, proposed in April 2026, explicitly encourages institutions to manage correspondent relationships case by case, warning that broad de-risking pushes activity outside the regulated financial system and makes it harder, not easier, to detect illicit finance.

FATF has held this position since 2015, when it first clarified that the risk-based approach to correspondent banking does not require, or even support, wholesale exit from entire regions or categories of respondent bank. The message from every direction is the same: individual due diligence, not category-based exit, is the compliant response.

The Due Diligence Baseline: FATF Recommendation 13

FATF Recommendation 13 sets out what correspondent banks must do before and during a cross-border correspondent relationship: gather sufficient information on the respondent institution to understand the nature of its business, assess its reputation and the quality of its AML/CFT controls, confirm it has not been subject to a money laundering or terrorism financing investigation or regulatory action, and obtain senior management approval before establishing new relationships. Ongoing monitoring is required for the life of the relationship, not just at onboarding.

In practice, this means treating respondent bank due diligence as a continuing risk assessment rather than a one-off approval gate. A respondent bank's risk profile changes as its customer base, ownership, and jurisdiction risk change, and correspondent banks are expected to track that.

Know Your Customer's Customer (KYCC)

The structural problem in correspondent banking is visibility. A correspondent bank has a direct relationship with the respondent bank, but the transactions flowing through that relationship belong to the respondent's own customers, not the correspondent's. This is what Know Your Customer's Customer (KYCC) practices exist to address: understanding, at least at a risk-profile level, who is transacting through a respondent bank rather than treating the respondent as a black box.

Nested relationships make this harder still. When a smaller, second-tier bank accesses correspondent services indirectly through another respondent bank rather than directly, the identity of the ultimate originating institution can become obscured, and the correspondent bank's visibility drops another layer. Effective correspondent risk management requires respondent banks to disclose nested relationships as part of the due diligence process, not leave the correspondent to discover them after the fact.

A Practical Risk-Management Framework

Framework Element
What It Requires
Respondent due diligence at onboarding
Business nature, ownership structure, jurisdiction risk, regulatory history, AML/CFT programme quality
Ongoing monitoring
Periodic reassessment of respondent risk profile, not a one-time approval
Nested relationship disclosure
Respondent banks disclose downstream banking relationships using the correspondent account
Transaction-level screening
Sanctions, PEP, and adverse media screening applied to transaction parties, not just the respondent entity
Red-flag monitoring
Unusually large or frequent transactions, transfers to high-risk jurisdictions, sudden behavioural changes
Senior management sign-off
Documented approval for new and continuing higher-risk correspondent relationships
Individual risk-based exit
Relationship termination decided on documented, customer-specific risk grounds, not category or region

The last row is the one that separates a defensible risk-management programme from a de-risking policy dressed up as one. Regulators are explicit that exiting an entire category of respondent bank without considering individual risk is the practice they now expect institutions to have remediated, not the practice they expect to see going forward.

Where Screening Technology Fits

None of this is manageable at scale without automated screening underneath it. Correspondent banks need sanctions, PEP, and adverse media screening that covers not just the respondent institution but the transaction parties flowing through the relationship, with fuzzy name matching robust enough to catch variant spellings across jurisdictions without generating so many false positives that genuine risk gets lost in alert volume. Ongoing monitoring of the respondent's own risk profile, rather than a static file reviewed once a year, is what makes individual, risk-based decisions defensible when a regulator asks why a relationship was kept open or closed.

Where MemberCheck Fits

MemberCheck's real-time sanctions, PEP, and adverse media screening, combined with fuzzy name matching and ongoing monitoring, gives correspondent banking teams the transaction-level and respondent-level visibility that individual, risk-based due diligence requires; without needing a separate system layered on top of core screening.

FAQs

What is de-risking in correspondent banking?

De-risking is the practice of terminating correspondent banking relationships with entire categories or regions of respondent banks to avoid money laundering or terrorism financing risk, rather than assessing and managing the risk of individual relationships. Regulators including FATF and FinCEN now regard blanket de-risking as counterproductive: it reduces financial access in affected regions and pushes transactions into less regulated, less visible channels.

What does FATF Recommendation 13 require of correspondent banks?

FATF Recommendation 13 requires correspondent banks to gather sufficient information about a respondent institution's business, ownership, reputation, and AML/CFT controls before establishing a relationship, confirm the respondent has not been subject to a money laundering or terrorism financing investigation, obtain senior management approval, and maintain ongoing monitoring of the relationship for its duration.

What is Know Your Customer's Customer (KYCC)?

KYCC refers to understanding, at a risk-profile level, the customers transacting through a respondent bank's correspondent account, rather than treating the respondent bank as a single opaque entity. It addresses the core visibility problem in correspondent banking: the correspondent bank's direct relationship is with the respondent, but the transaction risk actually sits with the respondent's own customers.

Are banks required to individually assess correspondent risk rather than de-risk by category?

Regulatory guidance increasingly requires it. In the US, Executive Order 14331 directed regulators to remove reputation risk from examination guidance and required institutions to remediate past debanking, and FinCEN's 2026 AML programme reform explicitly discourages broad de-risking in favour of case-by-case relationship management. FATF has held the same position on a risk-based approach since 2015.

What are common red flags in correspondent banking transactions?

Common red flags include unusually large or frequent transactions relative to the respondent's known business, transfers involving high-risk or sanctioned jurisdictions, sudden changes in transaction patterns or volume, undisclosed nested banking relationships, and opaque or frequently changing ownership structures at the respondent institution.

How does MemberCheck support correspondent banking due diligence?

MemberCheck provides real-time sanctions, PEP, and adverse media screening with fuzzy name matching suited to catching name variants across jurisdictions, combined with ongoing monitoring that flags changes in a respondent bank's risk profile rather than waiting for a scheduled annual review. This supports the individual, risk-based due diligence regulators now expect in place of category-based de-risking.

Managing Correspondent Risk Without Losing Relationships?

MemberCheck gives correspondent banking teams transaction-level and respondent-level screening in one platform. Request a demonstration

Related articles

Transaction Monitoring

FATF Mutual Evaluations: What They Mean for Financial Institutions

May 8, 2026
6 Minutes
#FATF #GreyList #BlackList #RiskAssessment

The Financial Action Task Force's mutual evaluation programme is the primary mechanism through which the...

Learn More
Transaction Monitoring

Designing an Enterprise AML Programme: A Framework for Compliance Officers

May 1, 2026
7 Minutes
#AMLProgramme #RiskBasedApproach #EnterpriseAML

For compliance officers in large financial institutions, designing an Anti-Money Laundering programme that is...

Learn More