Wiki / Banks & neobanks / Wolfsberg Questionnaires: CBDDQ, FCCQ and the Standards Banks Use to Test Compliance

Wolfsberg Questionnaires: CBDDQ, FCCQ and the Standards Banks Use to Test Compliance

mdCitemcp

When an EMI, payment firm, broker or bank opens an account with a large bank, the first document to arrive after the constitutional papers is almost always a Wolfsberg questionnaire: the CBDDQ for a correspondent relationship, or the shorter FCCQ for everything else. It runs to more than a hundred questions on how the counterparty's compliance programme is built, carries the signatures of accountable officers and a commitment to refresh the answers at least every eighteen months.

No statute introduces this questionnaire. It was written by a private association of the largest correspondent banks (twelve members today), yet over eight years it has become the common language in which financial institutions describe their AML, sanctions and anti-bribery controls to one another.

Concept

A Wolfsberg questionnaire is a standardised self-disclosure by a financial institution about its financial crime compliance programme. It is completed by the institution seeking a banking service (the respondent) and read by the institution providing it (the correspondent). The point is to replace a hundred bank-specific questionnaires with one question set sharing the same wording, the same glossary and the same completion rules.

The need for such a set comes from law. FATF Recommendation 13 requires a correspondent to gather sufficient information about the respondent, assess its AML/CFT controls, obtain senior management approval and refuse to deal with shell banks. In the EU the same duties sit in Article 19 of Directive 2015/849 and, from 10 July 2027, in the corresponding Article 36 of Regulation (EU) 2024/1624, subject to that Regulation's scope and additional requirements. The law says "assess the controls" without saying how. The questionnaire is the how.

Who the Wolfsberg Group is

The Group first met in 2000 at Château Wolfsberg in north-eastern Switzerland and only became a legal entity in October 2021. Today it is an association of twelve banks: Banco Santander, Bank of America, Barclays, Citi, Deutsche Bank, Goldman Sachs, HSBC, JPMorgan Chase, MUFG, Société Générale, Standard Chartered and UBS. The Group is headquartered in Basel, at the premises of the Basel Institute on Governance.

Wolfsberg is neither a regulator nor a standard-setting body: its documents bind nobody, including its own members. The Jersey Financial Services Commission describes them as an “industry perspective on effective financial crime risk management”. The market makes the questionnaire compulsory: the members are the world's largest dollar, euro and sterling correspondents, and when all of them ask the same questions, everyone has to answer.

Why this questionnaire became the standard

Three developments turned a private document into a de facto norm:

  1. In March 2018 the Basel Committee, CPMI, FATF and FSB publicly welcomed the CBDDQ as a tool that eases due diligence and helps halt the decline in correspondent banking relationships.
  2. Swift's KYC Registry lets members answer every CBDDQ question directly on the platform and share the completed questionnaire with their correspondents.
  3. The Group's own Financial Crime Principles for Correspondent Banking state that the CBDDQ “should be used to collect the related customer due diligence information”.

The key parameters of the questionnaires as at September 2026 are set out in one table.

ParameterValue
PublisherWolfsberg Group — private association of 12 banks, a legal entity since October 2021
Current CBDDQversion 1.4, published 10 February 2023
Current FCCQversion 1.2, published together with CBDDQ 1.4
CBDDQ answering levelone legal entity with its materially similar branches; not the group
CBDDQ structure14 sections, questions numbered up to 132, many with sub-questions
CBDDQ signatorieshead of correspondent banking and group head of AML or compliance
Refreshrecommended every 12–18 months; declaration — at least every 18 months
Supporting documentsGuidance v2.0, Glossary v3.0, FAQs v3.0 (2023)

The Group has issued no newer version since 2023: as at 24 September 2026 its news feed carries no revision of the questionnaires for 2024–2026, and its resources page still offers CBDDQ 1.4 and FCCQ 1.2 with Guidance v2.0, Glossary v3.0 and FAQs v3.0.

Where the questionnaire came from

The Group's first document was the AML Principles for Private Banking, published in October 2000 and revised in 2002 and 2012. They set the logic that later passed into the questionnaire: a bank accepts only clients whose source of wealth and funds can be reasonably established to be legitimate, and relationships with PEPs are opened only with senior management approval.

The correspondent questionnaire came later and has gone through several generations. The Group's FAQs record that the CBDDQ was first released to the banking community in October 2017, replacing the Group's previous questionnaire; the Basel Committee, CPMI, FATF and FSB welcomed it on 6 March 2018 as recently published, and the same FAQs v3.0 confirm that it replaced the previous questionnaire and that all versions before 1.4 have been retired. A shorter FCCQ serves other relationships alongside it. Since then the questionnaire has evolved incrementally.

DateEvent
October 2017CBDDQ released to the banking community, replacing the Group's previous questionnaire
6 March 2018BCBS, CPMI, FATF and FSB welcome the CBDDQ
27 June 2019capacity building materials: overview video, twelve section videos, question-by-question guidance
17 April 2020version 1.3: one question removed, wording clarified
10 February 2023CBDDQ 1.4 and FCCQ 1.2, new Guidance, Glossary and FAQs

In the 2019 materials the Group called the CBDDQ “an enhanced and reasonable standard for cross-border and/or other higher risk Correspondent Banking Due Diligence”. Version 1.3 was cosmetic. Version 1.4 added a Fraud section and questions on whistleblower policy, virtual bank licences and approval of the sanctions policy; the completion guidance and capacity building guidance were merged into one document, and the recommended refresh cycle was adjusted to 12–18 months.

The questionnaire and de-risking

The questionnaire also has a policy function. In October 2014 FATF defined de-risking as terminating or restricting business relationships with clients or categories of clients to avoid, rather than manage, risk, and called “the wholesale cutting loose of entire classes of customer” inconsistent with its standards. A standard questionnaire is the industry's response: it lowers the cost of assessing a respondent, making it easier for a bank to evaluate a specific institution than to cut off an entire country or sector.

The same questionnaire works in the opposite direction too. If the answers show that the respondent's programme cannot carry its business profile, the correspondent gains a documented ground for exit. The 2022 Principles say plainly that relationships are avoided where due diligence produces “significant concerns that cannot be resolved”.

How the CBDDQ is built

The questionnaire is an Excel file or PDF with an answer field for each question (usually Yes/No or a drop-down) and a field for clarifications. The completion rules sit in the header, and the most important of them is the level at which the institution answers.

The header requires the CBDDQ to be completed at legal entity level: “The questionnaire is required to be answered on a Legal Entity (LE) Level”. Branches are included where their client base, products and control model are materially similar to the head office, but a single questionnaire “should not cover more than one LE”. Each section ends with two housekeeping questions: confirm that the answers are representative of all branches, and add clarifications if they are not.

For groups this is the main trap. A holding company with an EMI in Lithuania, an MSB in the United States and a VASP in Dubai cannot answer one questionnaire "for everyone": each entity has its own regulator, MLRO, risk assessment and audit. A bank that receives group answers from a subsidiary EMI sees at once that the licence, supervision and EWRA answers were given for someone other than its prospective client.

Fourteen sections

The sections run from who the institution is to how it proves that its controls work. Question numbering in version 1.4 is the same in every completed questionnaire, so banks refer to questions by number.

SectionFrom questionWhat is asked
1. Entity & Ownership1legal entity, listing, beneficial owners, bearer shares, offshore banking licence, virtual bank licence, regulator, LEI
2. Products & Services19correspondent services, downstream relationships, MSB/MVTS/PSP clients, cash, private banking, trade finance, virtual assets, walk-in
3. AML, CTF & Sanctions Programme22programme components, compliance headcount, board approval of policy, outsourcing
4. Anti Bribery & Corruption30documented ABC policy, minimum-standards programme, training for the board and staff
5. Policies & Procedures46annual policy update, record retention; bans on anonymous accounts, shell banks, unlicensed banks and NBFIs
6. Risk Assessment54AML/CTF EWRA and a separate sanctions EWRA, components, completed within the last 12 months
7. KYC, CDD and EDD62customer and UBO verification, UBO threshold, PEP and adverse media screening, EDD categories, periodic review
8. Monitoring & Reporting83monitoring method, vendor, SAR/STR, responses to correspondents' requests for information (RFIs)
9. Payment Transparency92compliance with FATF R.16 and the Wolfsberg Payment Transparency Standards
10. Sanctions98UN, OFAC, OFSI, EU lists; customer and payment screening; presence in comprehensively sanctioned countries
11. Training & Education111mandatory training, coverage of the board and three lines of defence, frequency
12. QA / Compliance Testing117risk-based quality assurance and compliance testing programmes
13. Audit121internal and external audit of AML, CTF, ABC, fraud and sanctions policies, frequency
14. Fraud127fraud policies, dedicated team, real-time monitoring

The order mirrors the logic of a programme: first the business and its risks, then policies, then processes, then evidence that the processes work. A bank reads the questionnaire crosswise, checking the products in section 2 against the EWRA in section 6 and the monitoring in section 8.

What the key blocks ask

Section 1 looks formal, yet it filters immediately. Question 9 reads: “Does the Bank have a Virtual Bank License or provide services only through online channels?”. Alongside it sit the offshore banking licence, the share of bearer shares and the primary regulator. A "yes" to any of these leaves the relationship possible while moving the respondent into a higher risk category.

Section 2 lists products that a correspondent treats as risk indicators: cross-border bulk cash delivery, hold mail, payable-through accounts, private banking, remote deposit capture, sponsoring private ATMs, stored value instruments, trade finance, virtual assets. A separate block asks whether the institution allows downstream relationships — with domestic banks, foreign banks, MSBs, MVTSs and PSPs. This is the nested relationships question: will other people's customer flows pass through the respondent's account.

Sections 3–7 are the programme itself. The questionnaire asks for its components (from appointed officer and adverse information screening to transaction monitoring), compliance headcount in full-time employees, whether the board approves the policy annually, and whether functions are outsourced. Section 6 asks two separate questions — whether the AML/CTF EWRA and the sanctions EWRA were completed within the last 12 months; the inherent-risk components are client, product, channel and geography, and on the controls side monitoring, CDD, PEP identification, screening, training, governance and management information. Section 7 asks for the lowest beneficial ownership threshold the institution applies.

Section 10 covers sanctions. The questionnaire asks which lists are screened: the UN Security Council consolidated list, OFAC, OFSI, the EU consolidated list and others. Sections 12–14 are the evidence part: second-line testing, audit, fraud. The Fraud section arrived only in 2023 and asks about policy, a dedicated team and real-time monitoring.

Declaration and signatures

The questionnaire closes with a declaration signed by two people: the Global Head of Correspondent Banking or equivalent, and the Group Money Laundering Prevention Officer, Global Head of AML, Chief Compliance Officer or equivalent. The signatories confirm that the institution complies, or is working to comply, with the Wolfsberg Correspondent Banking Principles and Trade Finance Principles, and undertake: “The information provided in this Wolfsberg CBDDQ will be kept current and will be updated no less frequently than every eighteen months”.

The signature turns the questionnaire from a marketing document into a representation. If a year later the "Yes" on the EWRA question turns out to lack a real assessment, the correspondent will take the matter up with the signatories.

Guidance, Glossary and FAQs

The questionnaire comes with a set of three supporting documents from 2023, listed on the Group's website and published in six languages:

  • Guidance v2.0 merged the former completion guidance and capacity building guidance and explains for each question which risk it addresses.
  • Glossary v3.0 supplies the definitions — what counts as an MSB, a nested relationship, a shell bank — so that there is no arguing over words.
  • FAQs v3.0 answer procedural questions on completing and refreshing the questionnaires.

A separate CBDDQ Publication Guidance from 2018 deals with publishing completed questionnaires.

FCCQ: the short questionnaire for other relationships

The FCCQ — Financial Crime Compliance Questionnaire — gives, in the words of the Group's FAQs v3.0, “high-level information about an FI's Financial Crime Compliance Programme” and “can be completed at the group level and encompass all the entities in the group”. It is not intended for institutions receiving cross-border or higher-risk correspondent banking services, which must be covered by the CBDDQ. In practice FCCQs are completed and published by banking groups and asset managers among others.

Structurally it is a cut-down CBDDQ. Completed version 1.2 FCCQs — for example HSBC Holdings' — have ten sections and 45 numbered questions: Entity Information, programme, ABC, policies, KYC/CDD/EDD, monitoring, payment transparency, sanctions, training, audit. There are no separate Products & Services, Risk Assessment, Quality Assurance or Fraud sections. The declaration is signed by one person, a second-line Senior Compliance Manager.

A comparison of the two questionnaires on the parameters that shape preparation:

ParameterCBDDQ 1.4FCCQ 1.2
Relationshipscorrespondent, cross-border and higher-riskother relationships between financial institutions
Size14 sections, up to question 13210 sections, around 45 questions
Products and EWRAseparate sectionsno separate sections
Fraud, QA testingincludednot included
Answering levelstrictly one legal entitygroup level permitted by the FAQs
Signatoriestwo, including the group head of AMLsecond-line Senior Compliance Manager

Group-level FCCQ answers are permitted and used in practice: BlackRock's FCCQ states that it “applies to BlackRock, Inc. and its subsidiaries”. For a fund manager or broker this is convenient, but the receiving bank may still ask for answers on the specific entity it contracts with.

The questionnaire in practice

The life of one request

The questionnaire's life cycle follows the correspondent relationship cycle set by FATF R.13 and Article 19 of the Directive:

  1. The correspondent bank sends the prospective respondent the CBDDQ or FCCQ together with its own supplementary questionnaire and document list.
  2. The respondent completes the questionnaire at legal entity level and attaches its policies, EWRA, independent review report, compliance organisation chart and MLRO details.
  3. The bank's due diligence team checks the answers against documents and public data: the regulator's register, sanctions and adverse media checks, the auditor's reputation.
  4. The bank raises follow-up questions on every "No", on the clarifications and on inconsistencies between sections.
  5. The relationship opens with senior management approval — for third-country respondents this is required by Article 19(c) of the Directive.
  6. After 12–18 months the questionnaire is requested again, earlier if the business changes materially.

A US bank will add a shell bank certification under 31 CFR 1010.630, renewed at least every three years. Without it a foreign bank's correspondent account must be closed.

Who receives which questionnaire

Wolfsberg does not allocate questionnaires by licence type; the bank decides. The starting point is whether third-party money will flow through the account.

RespondentWhat is usually requestedWhere it stumbles
Respondent bankCBDDQ plus a shell bank certification for US correspondentsnested clients, branches in other jurisdictions
EMI, payment firm, MSBCBDDQ or FCCQ plus the bank's own PSP questionnairedownstream clients, agents, compliance capacity, audit
VASP, CASPCBDDQ or FCCQ plus the bank's digital asset questionsvirtual assets in the products section, blockchain analytics, travel rule
Fund manager, brokerFCCQ, sometimes at group levelgroup answers instead of entity answers, investors' source of wealth

For payment firms the picture tightened in July 2026. The Guidance on the Provision of Banking Services to non-bank PSPs covers MSBs, third-party payment processors, fintechs and EMIs, notes that it may also be of value for AISPs and PISPs, and deals with proprietary, third-party and bundled flows, BaaS and sponsored (FBO) accounts. Entities that are solely VASPs or CASPs are excluded; banking for stablecoin issuers is covered by separate Group guidance of September 2025.

The 2026 guidance does not name the CBDDQ or FCCQ, but recommends that banks “use tailored questionnaires to facilitate the assessment of specific factors, including the customer's business model, funds flows, payment corridors, and financial crime risk controls”. In practice the standard questionnaire becomes the minimum for a payment firm, with a questionnaire on corridors, flows and business model on top.

What the bank checks beyond the answers

The same document describes where the bank looks beyond the questionnaire. It asks about “backlogs in transaction monitoring, KYC renewal or other areas of operations”, about the scalability of the programme with business growth and, where an external auditor is used, about the reputation of the audit firm. Where risks cannot be sufficiently mitigated, “particularly given reduced end-to-end visibility”, the bank should choose an appropriate risk-control strategy, up to and including exit.

These questions hit the questionnaire's weak spot. The CBDDQ records that a control exists; it says nothing about the control's throughput. An honest "Yes" on monitoring does not reveal three thousand unreviewed alerts. The UK regulator has said so explicitly: the FCA Financial Crime Guide (FCG 3.2.8) lists as poor practice a correspondent bank that “relies exclusively on the Wolfsberg Group AML questionnaire”. That is why the bank checks the questionnaire against metrics, and the full stack on which those metrics are built is covered in the article on the compliance stack of a licensed operator.

KYC utilities and published questionnaires

A completed questionnaire is reusable. Large banks publish their CBDDQs online: the questionnaires of BACB, SIX SIS, NAB Europe and dozens of others are publicly available. The second channel is utilities: Swift KYC Registry members answer the CBDDQ on the platform and share their answers with correspondents there.

Utilities are what BCBS, CPMI, FATF and FSB had in mind when they wrote in 2018 that their development would reduce the cost of correspondent relationships while keeping KYC effective. For a small licensed firm a utility is a matter of economics: one current questionnaire instead of twenty different ones.

Questions that trip up new licensees

A new EMI, payment firm or VASP completes the CBDDQ at the worst possible moment: the licence is granted, clients are few and there is no control history. Several questions almost inevitably produce a "No" or "N/A", and it matters which of them a bank will forgive. The questions below are where this happens most.

QuestionSectionWhat the problem looks like
EWRA within the last 12 months6written for the licence before the first client, or not separating AML/CTF from sanctions
QA testing and audit12–13no review history; what matters is whether a plan and a provider exist
Downstream relationships with MSBs, MVTSs, PSPs2agents, marketplaces and PSP clients in fact create a nested flow
Virtual assets2receiving funds from crypto exchanges or converting stablecoins without a crypto licence
Compliance headcount3headcount out of line with the scale of the business
Real-time fraud monitoring14absent in a card or P2P business

Evidence without history

Section 6 asks whether the EWRA was completed within the last 12 months. A newly licensed firm usually has one — the regulator typically requires it for the licence — but it was written before the first client. Banks understand this and expect a refresh after the first months of operation. It is worse when there is no EWRA at all or it does not separate AML/CTF from sanctions.

Sections 12 and 13 ask about second-line testing and audit. A new company has no first audit by definition, and an answer such as "scheduled for month X, auditor Y" is accepted. An answer of "not planned" reads as the absence of a third line of defence.

A business model the bank treats as nested

Section 2 is the main filter for payment firms. If an EMI serves other PSPs, agents or marketplaces that collect their own customers' money, these are downstream relationships, and the bank will view them through the Correspondent Banking Principles: understanding the types of downstream institutions, the scale of services, the geography and their customers. A "No" where nested flows really exist is the most dangerous error in the questionnaire, because it surfaces at the first review of payment messages.

The same applies to virtual assets: if the company receives payments from crypto exchanges or converts stablecoins, that is a section 2 product even if the word crypto appears nowhere in its licence.

Resources and governance

The compliance headcount question looks harmless, but the bank compares it with the scale of the business it sees from the other answers and the accounts. Two people for a company with hundreds of thousands of clients is a signal the bank will read without any explanation. Next to it are the questions on annual board approval of the policy and on outsourcing: the "MLRO as a service" model needs an explanation of who takes decisions inside the company and how.

Section 14 asks about real-time fraud monitoring. For a card acquirer or a P2P wallet a negative answer here looks worse than for a custody bank.

What has to sit behind an honest "Yes"

The questionnaire does not check documents, but every answer assumes that a document exists and can be produced on request. Below are the artefacts a bank may ask for to support the most sensitive answers.

"Yes" in the questionnaireWhat must exist
The programme includes all components (section 3)board-approved AML/CTF, sanctions and ABC policies with dates and version history
An accountable officer is appointedMLRO appointment, regulator approval where required, a deputy
EWRA within the last 12 months (section 6)an assessment signed by the management body with an inherent → controls → residual methodology
UBO threshold (section 7)a CDD procedure with the same threshold as the questionnaire, and client files that apply it
Periodic file reviewa review calendar by risk category and a report on its execution
Automated monitoring (section 8)scenario inventory, thresholds, tuning report, alert queue data
Screening against UN, OFAC, OFSI, EU (section 10)screening system configuration, list update frequency, decision log
Independent audit (section 13)a dated report with scope and a remediation log

The logic of the table is simple: the questionnaire is the table of contents of the programme, and every line of that contents needs a chapter behind it. How to build a programme that can honestly answer "Yes" is covered in the compliance stack article, and how the payment chain itself looks from the correspondent's side in the article on correspondent banking and safeguarding.

Companies that are not financial institutions

For a company that is not a financial institution, the Wolfsberg questionnaire matters indirectly. A family office, trading company or fund receives the bank's corporate KYC pack instead, but the questions cover the same ground: ownership, products, geography, source of funds. Source of funds within that pack is covered in the article on source of funds.

The questionnaire reaches the client directly through its payment provider. If the EMI through which a business collects revenue fails its bank's re-review, the EMI's accounts close, and the payment routes of its clients close with them. Provider resilience can therefore also be judged by whether a questionnaire is published, which version it is and when it was signed. What happens when a banking partner is lost is covered in the article on account closures.

Other Wolfsberg documents met in practice

Beyond the questionnaires, banks refer to a number of Group documents, above all in their own policies and supplementary questionnaires. All are in the resources section; only current editions are listed below.

DocumentYearWhere it applies
Financial Crime Principles for Correspondent Banking2022correspondent due diligence logic, nested relationships, periodic review
Payment Transparency Standards2023completeness of payment message data, move to ISO 20022
Payment Transparency — Roles and Responsibilities2024allocation of duties among payment chain participants
Swift RMA Guidance2024managing RMA authorisations between Swift users
Sanctions Screening Guidance2019design and management of sanctions screening
PEP Guidance2017defining and handling PEPs
Source of Wealth and Source of Funds FAQs2020corroborating SoW and SoF for private clients
Private Banking Principles2012core private banking rules
Statements on Effective Monitoring for Suspicious Activity2024, 2025moving from rules to risk-based monitoring
Guidance on the Risk-Based Approach2026updated guidance on the risk-based approach
Banking Services to Fiat-backed Stablecoin Issuers2025banking stablecoin issuers
Banking Services to non-bank PSPs2026banking EMIs, MSBs and other PSPs

Whoever completes section 9 of the questionnaire needs the payment transparency standards above all. The 2023 Payment Transparency Standards require that debtor and creditor information not be omitted, deleted or altered to avoid detection, and that structured formats such as ISO 20022 be adopted at the earliest opportunity. The standards apply equally to banks and non-bank PSPs. How these requirements relate to R.16 and the travel rule is covered in the article on the travel rule, and the sanctions side in the article on sanctions screening.

Where the questionnaire breaks

Most problems with the questionnaire arise from a gap between what the questionnaire says and what actually exists in the company. The correspondent sees these gaps when it checks documents or, worse, at the first incident.

Questionnaire versus policy

A typical picture: the questionnaire gives a 10% UBO threshold, the CDD procedure says 25%, and client files record none at all. Or the questionnaire says EDD applies to all PEPs, while the policy leaves it to a manager's discretion. The bank reads every such gap as a sign that the questionnaire was completed by someone who does not run the programme.

Outdated version and outdated answers

A version 1.3 questionnaire in 2026 is a signal in itself: the respondent has no Fraud section and none of the 2023 questions. Another variant is a current-version questionnaire signed two years ago: since then the MLRO has changed, a new product has launched or a branch has opened. The declaration commits the signatories to refresh the answers at least every 18 months, and an expired questionnaire breaks their own undertaking.

Group answers instead of entity answers

Groups create a separate problem of their own: a common questionnaire prepared by the parent is sent out in the name of each subsidiary. It carries the parent's licence and regulator, the parent's compliance headcount and the parent's audit. For the CBDDQ this is a direct breach of the completion rules; for the FCCQ it invites further questions. Each licensed entity needs its own questionnaire with its own EWRA and its own MLRO.

Q/A

Completing the questionnaire

Is a licensed firm obliged to complete the CBDDQ

Not by law. The Wolfsberg Group is a private association with no regulatory powers. The duty to assess a respondent's AML controls falls on the correspondent bank under FATF R.13 and national law, and large banks discharge it through the CBDDQ or FCCQ. In practice, declining to complete the questionnaire means being declined an account.

Which version should be used in 2026

CBDDQ 1.4 and FCCQ 1.2, published on 10 February 2023. The Group has issued no newer versions. A version 1.3 or older questionnaire lacks the Fraud section and the questions on whistleblower policy and virtual bank licences, so for the bank it is incomplete by definition.

Can one questionnaire cover the whole group

Not for the CBDDQ: it is completed at legal entity level and should not cover more than one legal entity; branches are included only where their clients, products and controls are materially similar to the head office. The FCCQ, by contrast, may be completed at group level under the Group's FAQs, but a bank may ask for answers on its specific counterparty.

What if a question cannot honestly be answered "Yes"

Answer "No" and use the clarification field: what has been done, what is planned and by when. From a new company a bank will usually accept "audit scheduled for the first quarter, auditor X"; a "Yes" without a supporting document costs far more.

How often should the questionnaire be refreshed

The Group recommends a 12–18 month cycle, and the CBDDQ declaration commits the signatories to refresh the answers at least every 18 months. After a change of MLRO, a new product launch or a change of ownership it makes sense to refresh at once rather than wait for the deadline.

Bank requests and counterparties

Why does a partner bank require a CBDDQ before opening an EMI's account

Because in cross-border correspondent relationships the bank must, before opening them, gather information on the respondent's business, assess its controls and obtain senior management approval. The questionnaire is the standard way to collect this information, and for payment firms the 2026 Wolfsberg guidance recommends that banks add a tailored questionnaire on business model, flows and payment corridors.

How does the FCCQ differ from the CBDDQ

The FCCQ is shorter: around 45 questions in ten sections against the CBDDQ's 14 sections. It has no separate blocks on products, risk assessment, testing or fraud, and the declaration is signed by a single Senior Compliance Manager. It is intended for relationships outside correspondent banking; the bank decides which questionnaire to request.

Where can a bank's or provider's questionnaire be found

Many banks and large financial groups publish completed CBDDQs and FCCQs on their websites, and Swift KYC Registry members share theirs with correspondents through the platform. The signature date and version number on the first page show how current the questionnaire is.

Download the offer «Wolfsberg Questionnaires»

How we approach such matters, the stages, the team and the contacts in one short document.

If you have questions or need a consultation, our experts will be glad to help.

Request a callback

Your contacts are used to answer this request. No mailing lists.