# Wolfsberg Questionnaires: CBDDQ, FCCQ and the Standards Banks Use to Test Compliance

> Wolfsberg CBDDQ 1.4 and FCCQ 1.2: who publishes them, the 14 sections, signatures and 18-month refresh, the questions that trip up EMIs, PSPs and VASPs, and what must back an honest Yes.

Author: Alena Dunaeva — Lawyer, Family Office (https://wiki.private.law/en/authors/dunaeva)
Last modified: 2026-09-28T00:00:00.000Z
Canonical: https://wiki.private.law/en/wolfsberg-questionnaires
Publisher: wiki.private.law (https://wiki.private.law)
Version: 331bd38796719d3f5325b5538a5a57fc2c107054324bb474e1072d5affe709d2
Cite as: Wolfsberg Questionnaires: CBDDQ, FCCQ and the Standards Banks Use to Test Compliance. wiki.private.law. https://wiki.private.law/en/wolfsberg-questionnaires. Version 331bd38796719d3f5325b5538a5a57fc2c107054324bb474e1072d5affe709d2.
Topics: banking
Jurisdictions: global
Product tags: compliance, bank
Semantic tags: compliance, bank

---

When an EMI, payment firm, broker or bank opens an account with a large bank, the first document to arrive after the constitutional papers is almost always a Wolfsberg questionnaire: the CBDDQ for a correspondent relationship, or the shorter FCCQ for everything else. It runs to more than a hundred questions on how the counterparty's compliance programme is built, carries the signatures of accountable officers and a commitment to refresh the answers at least every eighteen months.

No statute introduces this questionnaire. It was written by a private association of the largest correspondent banks (twelve members today), yet over eight years it has become the common language in which financial institutions describe their AML, sanctions and anti-bribery controls to one another.

## Concept

A **Wolfsberg questionnaire** is a standardised self-disclosure by a financial institution about its financial crime compliance programme. It is completed by the institution seeking a banking service (the respondent) and read by the institution providing it (the correspondent). The point is to replace a hundred bank-specific questionnaires with one question set sharing the same wording, the same glossary and the same completion rules.

The need for such a set comes from law. [FATF Recommendation 13](https://www.fatf-gafi.org/en/publications/Fatfrecommendations/Fatf-recommendations.html) requires a correspondent to gather sufficient information about the respondent, assess its AML/CFT controls, obtain senior management approval and refuse to deal with shell banks. In the EU the same duties sit in [Article 19 of Directive 2015/849](https://eur-lex.europa.eu/eli/dir/2015/849/oj) and, from 10 July 2027, in the corresponding [Article 36 of Regulation (EU) 2024/1624](https://eur-lex.europa.eu/eli/reg/2024/1624/oj/eng), subject to that Regulation's scope and additional requirements. The law says "assess the controls" without saying how. The questionnaire is the how.

### Who the Wolfsberg Group is

The Group [first met in 2000 at Château Wolfsberg in north-eastern Switzerland](https://wolfsberg-group.org/about/) and only became a legal entity in October 2021. Today it is an association of twelve banks: Banco Santander, Bank of America, Barclays, Citi, Deutsche Bank, Goldman Sachs, HSBC, JPMorgan Chase, MUFG, Société Générale, Standard Chartered and UBS. The Group is headquartered in Basel, at the premises of the Basel Institute on Governance.

Wolfsberg is neither a regulator nor a standard-setting body: its documents bind nobody, including its own members. The Jersey Financial Services Commission describes them as an [“industry perspective on effective financial crime risk management”](https://www.jerseyfsc.org/industry/financial-crime/aml-cft-cpf-international-organisations/the-wolfsberg-group/). The market makes the questionnaire compulsory: the members are the world's largest dollar, euro and sterling correspondents, and when all of them ask the same questions, everyone has to answer.

### Why this questionnaire became the standard

Three developments turned a private document into a de facto norm:

1. [In March 2018 the Basel Committee, CPMI, FATF and FSB publicly welcomed the CBDDQ](https://bis.org/press/p180306a.htm) as a tool that eases due diligence and helps halt the decline in correspondent banking relationships.
2. [Swift's KYC Registry lets members answer every CBDDQ question directly on the platform](https://www.swift.com/news-events/news/fostering-trust-and-transparency-global-correspondent-relationships-alongside-wolfsberg-group) and share the completed questionnaire with their correspondents.
3. The Group's own [Financial Crime Principles for Correspondent Banking](https://wolfsberg-group.org/resources/correspondent-banking/91) state that the CBDDQ “should be used to collect the related customer due diligence information”.
The key parameters of the questionnaires as at September 2026 are set out in one table.

| Parameter | Value |
| --- | --- |
| Publisher | Wolfsberg Group — private association of 12 banks, a legal entity since October 2021 |
| Current CBDDQ | version 1.4, published 10 February 2023 |
| Current FCCQ | version 1.2, published together with CBDDQ 1.4 |
| CBDDQ answering level | one legal entity with its materially similar branches; not the group |
| CBDDQ structure | 14 sections, questions numbered up to 132, many with sub-questions |
| CBDDQ signatories | head of correspondent banking and group head of AML or compliance |
| Refresh | recommended every 12–18 months; declaration — at least every 18 months |
| Supporting documents | Guidance v2.0, Glossary v3.0, FAQs v3.0 (2023) |

The Group has issued no newer version since 2023: as at 24 September 2026 its [news feed](https://wolfsberg-group.org/news) carries no revision of the questionnaires for 2024–2026, and its [resources page](https://wolfsberg-group.org/resources/correspondent-banking) still offers CBDDQ 1.4 and FCCQ 1.2 with Guidance v2.0, Glossary v3.0 and FAQs v3.0.

## Where the questionnaire came from

The Group's first document was the [AML Principles for Private Banking, published in October 2000](https://www.jerseyfsc.org/industry/financial-crime/aml-cft-cpf-international-organisations/the-wolfsberg-group/) and revised in 2002 and 2012. They set the logic that later passed into the questionnaire: a bank [accepts only clients whose source of wealth and funds can be reasonably established to be legitimate](https://wolfsberg-group.org/resources/202/45), and relationships with PEPs are opened only with senior management approval.

The correspondent questionnaire came later and has gone through several generations. The Group's FAQs record that the CBDDQ was first released to the banking community in October 2017, replacing the Group's previous questionnaire; the [Basel Committee, CPMI, FATF and FSB welcomed it on 6 March 2018](https://bis.org/press/p180306a.htm) as recently published, and the same [FAQs v3.0](https://wolfsberg-group.org/resources/correspondent-banking/129) confirm that it replaced the previous questionnaire and that all versions before 1.4 have been retired. A shorter FCCQ serves other relationships alongside it. Since then the questionnaire has evolved incrementally.

| Date | Event |
| --- | --- |
| October 2017 | CBDDQ released to the banking community, replacing the Group's previous questionnaire |
| 6 March 2018 | BCBS, CPMI, FATF and FSB welcome the CBDDQ |
| 27 June 2019 | capacity building materials: overview video, twelve section videos, question-by-question guidance |
| 17 April 2020 | version 1.3: one question removed, wording clarified |
| 10 February 2023 | CBDDQ 1.4 and FCCQ 1.2, new Guidance, Glossary and FAQs |

In the [2019 materials](https://wolfsberg-group.org/news/publication-of-the-cbddq-capacity-building-materials/) the Group called the CBDDQ “an enhanced and reasonable standard for cross-border and/or other higher risk Correspondent Banking Due Diligence”. [Version 1.3](https://wolfsberg-group.org/news/correspondent-banking-due-diligence-questionnaire-new-version-publication) was cosmetic. [Version 1.4](https://wolfsberg-group.org/news/36) added a Fraud section and questions on whistleblower policy, virtual bank licences and approval of the sanctions policy; the completion guidance and capacity building guidance were merged into one document, and the recommended refresh cycle was adjusted to 12–18 months.

### The questionnaire and de-risking

The questionnaire also has a policy function. [In October 2014 FATF defined de-risking](https://www.fatf-gafi.org/en/publications/Fatfgeneral/Rba-and-de-risking.html) as terminating or restricting business relationships with clients or categories of clients to avoid, rather than manage, risk, and called “the wholesale cutting loose of entire classes of customer” inconsistent with its standards. A standard questionnaire is the industry's response: it lowers the cost of assessing a respondent, making it easier for a bank to evaluate a specific institution than to cut off an entire country or sector.

The same questionnaire works in the opposite direction too. If the answers show that the respondent's programme cannot carry its business profile, the correspondent gains a documented ground for exit. The 2022 Principles say plainly that relationships are avoided where due diligence produces “significant concerns that cannot be resolved”.

## How the CBDDQ is built

The questionnaire is an Excel file or PDF with an answer field for each question (usually Yes/No or a drop-down) and a field for clarifications. The completion rules sit in the header, and the most important of them is the level at which the institution answers.

### Legal entity level

The header requires the CBDDQ to be [completed at legal entity level](https://wolfsberg-group.org/resources/correspondent-banking): “The questionnaire is required to be answered on a Legal Entity (LE) Level”. Branches are included where their client base, products and control model are materially similar to the head office, but a single questionnaire “should not cover more than one LE”. Each section ends with two housekeeping questions: confirm that the answers are representative of all branches, and add clarifications if they are not.

For groups this is the main trap. A holding company with an EMI in Lithuania, an MSB in the United States and a VASP in Dubai cannot answer one questionnaire "for everyone": each entity has its own regulator, MLRO, risk assessment and audit. A bank that receives group answers from a subsidiary EMI sees at once that the licence, supervision and EWRA answers were given for someone other than its prospective client.

### Fourteen sections

The sections run from who the institution is to how it proves that its controls work. Question numbering in version 1.4 is [the same in every completed questionnaire](https://wolfsberg-group.org/resources/correspondent-banking), so banks refer to questions by number.

| Section | From question | What is asked |
| --- | --- | --- |
| 1. Entity & Ownership | 1 | legal entity, listing, beneficial owners, bearer shares, offshore banking licence, virtual bank licence, regulator, LEI |
| 2. Products & Services | 19 | correspondent services, downstream relationships, MSB/MVTS/PSP clients, cash, private banking, trade finance, virtual assets, walk-in |
| 3. AML, CTF & Sanctions Programme | 22 | programme components, compliance headcount, board approval of policy, outsourcing |
| 4. Anti Bribery & Corruption | 30 | documented ABC policy, minimum-standards programme, training for the board and staff |
| 5. Policies & Procedures | 46 | annual policy update, record retention; bans on anonymous accounts, shell banks, unlicensed banks and NBFIs |
| 6. Risk Assessment | 54 | AML/CTF EWRA and a separate sanctions EWRA, components, completed within the last 12 months |
| 7. KYC, CDD and EDD | 62 | customer and UBO verification, UBO threshold, PEP and adverse media screening, EDD categories, periodic review |
| 8. Monitoring & Reporting | 83 | monitoring method, vendor, SAR/STR, responses to correspondents' requests for information (RFIs) |
| 9. Payment Transparency | 92 | compliance with FATF R.16 and the Wolfsberg Payment Transparency Standards |
| 10. Sanctions | 98 | UN, OFAC, OFSI, EU lists; customer and payment screening; presence in comprehensively sanctioned countries |
| 11. Training & Education | 111 | mandatory training, coverage of the board and three lines of defence, frequency |
| 12. QA / Compliance Testing | 117 | risk-based quality assurance and compliance testing programmes |
| 13. Audit | 121 | internal and external audit of AML, CTF, ABC, fraud and sanctions policies, frequency |
| 14. Fraud | 127 | fraud policies, dedicated team, real-time monitoring |

The order mirrors the logic of a programme: first the business and its risks, then policies, then processes, then evidence that the processes work. A bank reads the questionnaire crosswise, checking the products in section 2 against the EWRA in section 6 and the monitoring in section 8.

### What the key blocks ask

Section 1 looks formal, yet it filters immediately. Question 9 reads: [“Does the Bank have a Virtual Bank License or provide services only through online channels?”](https://wolfsberg-group.org/resources/correspondent-banking). Alongside it sit the offshore banking licence, the share of bearer shares and the primary regulator. A "yes" to any of these leaves the relationship possible while moving the respondent into a higher risk category.

Section 2 lists products that a correspondent treats as risk indicators: cross-border bulk cash delivery, hold mail, payable-through accounts, private banking, remote deposit capture, sponsoring private ATMs, stored value instruments, trade finance, virtual assets. A separate block asks whether the institution allows downstream relationships — with domestic banks, foreign banks, MSBs, MVTSs and PSPs. This is the nested relationships question: will other people's customer flows pass through the respondent's account.

Sections 3–7 are the programme itself. The questionnaire asks for its components (from appointed officer and adverse information screening to transaction monitoring), compliance headcount in full-time employees, whether the board approves the policy annually, and whether functions are outsourced. Section 6 asks two separate questions — whether the AML/CTF EWRA and the sanctions EWRA were completed within the last 12 months; the inherent-risk components are client, product, channel and geography, and on the controls side monitoring, CDD, PEP identification, screening, training, governance and management information. Section 7 asks for the lowest beneficial ownership threshold the institution applies.

Section 10 covers sanctions. The questionnaire asks [which lists are screened](https://wolfsberg-group.org/resources/correspondent-banking): the UN Security Council consolidated list, OFAC, OFSI, the EU consolidated list and others. Sections 12–14 are the evidence part: second-line testing, audit, fraud. The Fraud section arrived only in 2023 and asks about policy, a dedicated team and real-time monitoring.

### Declaration and signatures

The questionnaire closes with a declaration signed by two people: [the Global Head of Correspondent Banking or equivalent, and the Group Money Laundering Prevention Officer, Global Head of AML, Chief Compliance Officer or equivalent](https://wolfsberg-group.org/resources/correspondent-banking). The signatories confirm that the institution complies, or is working to comply, with the Wolfsberg Correspondent Banking Principles and Trade Finance Principles, and undertake: “The information provided in this Wolfsberg CBDDQ will be kept current and will be updated no less frequently than every eighteen months”.

The signature turns the questionnaire from a marketing document into a representation. If a year later the "Yes" on the EWRA question turns out to lack a real assessment, the correspondent will take the matter up with the signatories.

### Guidance, Glossary and FAQs

The questionnaire comes with a set of three supporting documents from 2023, [listed on the Group's website](https://wolfsberg-group.org/resources/correspondent-banking) and published in six languages:

- **Guidance v2.0** merged the former completion guidance and capacity building guidance and explains for each question which risk it addresses.
- **Glossary v3.0** supplies the definitions — what counts as an MSB, a nested relationship, a shell bank — so that there is no arguing over words.
- **FAQs v3.0** answer procedural questions on completing and refreshing the questionnaires.
A separate CBDDQ Publication Guidance from 2018 deals with publishing completed questionnaires.

## FCCQ: the short questionnaire for other relationships

The FCCQ — Financial Crime Compliance Questionnaire — gives, in the words of the Group's [FAQs v3.0](https://wolfsberg-group.org/resources/correspondent-banking/129), “high-level information about an FI's Financial Crime Compliance Programme” and “can be completed at the group level and encompass all the entities in the group”. It is not intended for institutions receiving cross-border or higher-risk correspondent banking services, which must be covered by the CBDDQ. In practice FCCQs are completed and published by banking groups and asset managers among others.

Structurally it is a cut-down CBDDQ. Completed version 1.2 FCCQs — for example [HSBC Holdings'](https://www.hsbc.com/-/files/hsbc/our-approach/risk-and-responsibility/pdfs/250704-hsbc-group-wolfsberg-questionnaire-2025.pdf?download=1) — have ten sections and 45 numbered questions: Entity Information, programme, ABC, policies, KYC/CDD/EDD, monitoring, payment transparency, sanctions, training, audit. There are no separate Products & Services, Risk Assessment, Quality Assurance or Fraud sections. The declaration is signed by one person, a second-line Senior Compliance Manager.

A comparison of the two questionnaires on the parameters that shape preparation:

| Parameter | CBDDQ 1.4 | FCCQ 1.2 |
| --- | --- | --- |
| Relationships | correspondent, cross-border and higher-risk | other relationships between financial institutions |
| Size | 14 sections, up to question 132 | 10 sections, around 45 questions |
| Products and EWRA | separate sections | no separate sections |
| Fraud, QA testing | included | not included |
| Answering level | strictly one legal entity | group level permitted by the FAQs |
| Signatories | two, including the group head of AML | second-line Senior Compliance Manager |

Group-level FCCQ answers are permitted and used in practice: [BlackRock's FCCQ](https://www.blackrock.com/corporate/literature/publication/wolfsberg-group-financial-crime-compliance-questionnaire.pdf) states that it “applies to BlackRock, Inc. and its subsidiaries”. For a fund manager or broker this is convenient, but the receiving bank may still ask for answers on the specific entity it contracts with.

## The questionnaire in practice

### The life of one request

The questionnaire's life cycle follows the correspondent relationship cycle set by FATF R.13 and Article 19 of the Directive:

1. The correspondent bank sends the prospective respondent the CBDDQ or FCCQ together with its own supplementary questionnaire and document list.
2. The respondent completes the questionnaire at legal entity level and attaches its policies, EWRA, independent review report, compliance organisation chart and MLRO details.
3. The bank's due diligence team checks the answers against documents and public data: the regulator's register, sanctions and adverse media checks, the auditor's reputation.
4. The bank raises follow-up questions on every "No", on the clarifications and on inconsistencies between sections.
5. The relationship opens with senior management approval — for third-country respondents this is required by [Article 19(c) of the Directive](https://eur-lex.europa.eu/eli/dir/2015/849/oj).
6. After 12–18 months the questionnaire is requested again, earlier if the business changes materially.
A US bank will add a [shell bank certification under 31 CFR 1010.630](https://www.ecfr.gov/current/title-31/subtitle-B/chapter-X/part-1010/subpart-F/section-1010.630), renewed at least every three years. Without it a foreign bank's correspondent account must be closed.

### Who receives which questionnaire

Wolfsberg does not allocate questionnaires by licence type; the bank decides. The starting point is whether third-party money will flow through the account.

| Respondent | What is usually requested | Where it stumbles |
| --- | --- | --- |
| Respondent bank | CBDDQ plus a shell bank certification for US correspondents | nested clients, branches in other jurisdictions |
| EMI, payment firm, MSB | CBDDQ or FCCQ plus the bank's own PSP questionnaire | downstream clients, agents, compliance capacity, audit |
| VASP, CASP | CBDDQ or FCCQ plus the bank's digital asset questions | virtual assets in the products section, blockchain analytics, travel rule |
| Fund manager, broker | FCCQ, sometimes at group level | group answers instead of entity answers, investors' source of wealth |

For payment firms the picture tightened in July 2026. The [Guidance on the Provision of Banking Services to non-bank PSPs](https://wolfsberg-group.org/resources/general/206) covers MSBs, third-party payment processors, fintechs and EMIs, notes that it may also be of value for AISPs and PISPs, and deals with proprietary, third-party and bundled flows, BaaS and sponsored (FBO) accounts. Entities that are solely VASPs or CASPs are excluded; banking for stablecoin issuers is covered by separate Group guidance of September 2025.

The 2026 guidance does not name the CBDDQ or FCCQ, but recommends that banks “use tailored questionnaires to facilitate the assessment of specific factors, including the customer's business model, funds flows, payment corridors, and financial crime risk controls”. In practice the standard questionnaire becomes the minimum for a payment firm, with a questionnaire on corridors, flows and business model on top.

### What the bank checks beyond the answers

The same document describes where the bank looks beyond the questionnaire. It asks about “backlogs in transaction monitoring, KYC renewal or other areas of operations”, about the scalability of the programme with business growth and, where an external auditor is used, about the reputation of the audit firm. Where risks cannot be sufficiently mitigated, “particularly given reduced end-to-end visibility”, the bank should choose an appropriate risk-control strategy, up to and including exit.

These questions hit the questionnaire's weak spot. The CBDDQ records that a control exists; it says nothing about the control's throughput. An honest "Yes" on monitoring does not reveal three thousand unreviewed alerts. The UK regulator has said so explicitly: the [FCA Financial Crime Guide](https://www.handbook.fca.org.uk/handbook/FCG/3/2.html) (FCG 3.2.8) lists as poor practice a correspondent bank that “relies exclusively on the Wolfsberg Group AML questionnaire”. That is why the bank checks the questionnaire against metrics, and the full stack on which those metrics are built is covered in the article on the [compliance stack of a licensed operator](https://wiki.private.law/en/compliance-stack).

### KYC utilities and published questionnaires

A completed questionnaire is reusable. Large banks publish their CBDDQs online: the questionnaires of [BACB](https://files.bacb.co.uk/production/files/BACB-Wolfsberg-CBDDQ-v1.4_0-16-Dec-2025-dated.pdf), [SIX SIS](https://www.six-group.com/dam/download/securities-services/clearing/regulatory/regulation-supervision/six-sis-wolfsbergs-questionnaire-cbddq.pdf), [NAB Europe](https://www.nabeurope.com/content/dam/nab-europe/CBDDQ_AF.pdf) and dozens of others are publicly available. The second channel is utilities: Swift KYC Registry members answer the CBDDQ on the platform and share their answers with correspondents there.

Utilities are what BCBS, CPMI, FATF and FSB had in mind when they [wrote in 2018](https://bis.org/press/p180306a.htm) that their development would reduce the cost of correspondent relationships while keeping KYC effective. For a small licensed firm a utility is a matter of economics: one current questionnaire instead of twenty different ones.

## Questions that trip up new licensees

A new EMI, payment firm or VASP completes the CBDDQ at the worst possible moment: the licence is granted, clients are few and there is no control history. Several questions almost inevitably produce a "No" or "N/A", and it matters which of them a bank will forgive. The questions below are where this happens most.

| Question | Section | What the problem looks like |
| --- | --- | --- |
| EWRA within the last 12 months | 6 | written for the licence before the first client, or not separating AML/CTF from sanctions |
| QA testing and audit | 12–13 | no review history; what matters is whether a plan and a provider exist |
| Downstream relationships with MSBs, MVTSs, PSPs | 2 | agents, marketplaces and PSP clients in fact create a nested flow |
| Virtual assets | 2 | receiving funds from crypto exchanges or converting stablecoins without a crypto licence |
| Compliance headcount | 3 | headcount out of line with the scale of the business |
| Real-time fraud monitoring | 14 | absent in a card or P2P business |

### Evidence without history

Section 6 asks whether the EWRA was completed within the last 12 months. A newly licensed firm usually has one — the regulator typically requires it for the licence — but it was written before the first client. Banks understand this and expect a refresh after the first months of operation. It is worse when there is no EWRA at all or it does not separate AML/CTF from sanctions.

Sections 12 and 13 ask about second-line testing and audit. A new company has no first audit by definition, and an answer such as "scheduled for month X, auditor Y" is accepted. An answer of "not planned" reads as the absence of a third line of defence.

### A business model the bank treats as nested

Section 2 is the main filter for payment firms. If an EMI serves other PSPs, agents or marketplaces that collect their own customers' money, these are downstream relationships, and the bank will view them through the [Correspondent Banking Principles](https://wolfsberg-group.org/resources/correspondent-banking/91): understanding the types of downstream institutions, the scale of services, the geography and their customers. A "No" where nested flows really exist is the most dangerous error in the questionnaire, because it surfaces at the first review of payment messages.

The same applies to virtual assets: if the company receives payments from crypto exchanges or converts stablecoins, that is a section 2 product even if the word crypto appears nowhere in its licence.

### Resources and governance

The compliance headcount question looks harmless, but the bank compares it with the scale of the business it sees from the other answers and the accounts. Two people for a company with hundreds of thousands of clients is a signal the bank will read without any explanation. Next to it are the questions on annual board approval of the policy and on outsourcing: the "MLRO as a service" model needs an explanation of who takes decisions inside the company and how.

Section 14 asks about real-time fraud monitoring. For a card acquirer or a P2P wallet a negative answer here looks worse than for a custody bank.

## What has to sit behind an honest "Yes"

The questionnaire does not check documents, but every answer assumes that a document exists and can be produced on request. Below are the artefacts a bank may ask for to support the most sensitive answers.

| "Yes" in the questionnaire | What must exist |
| --- | --- |
| The programme includes all components (section 3) | board-approved AML/CTF, sanctions and ABC policies with dates and version history |
| An accountable officer is appointed | MLRO appointment, regulator approval where required, a deputy |
| EWRA within the last 12 months (section 6) | an assessment signed by the management body with an inherent → controls → residual methodology |
| UBO threshold (section 7) | a CDD procedure with the same threshold as the questionnaire, and client files that apply it |
| Periodic file review | a review calendar by risk category and a report on its execution |
| Automated monitoring (section 8) | scenario inventory, thresholds, tuning report, alert queue data |
| Screening against UN, OFAC, OFSI, EU (section 10) | screening system configuration, list update frequency, decision log |
| Independent audit (section 13) | a dated report with scope and a remediation log |

The logic of the table is simple: the questionnaire is the table of contents of the programme, and every line of that contents needs a chapter behind it. How to build a programme that can honestly answer "Yes" is covered in the [compliance stack](https://wiki.private.law/en/compliance-stack) article, and how the payment chain itself looks from the correspondent's side in the article on [correspondent banking and safeguarding](https://wiki.private.law/en/correspondent-banking-safeguarding).

### Companies that are not financial institutions

For a company that is not a financial institution, the Wolfsberg questionnaire matters indirectly. A family office, trading company or fund receives the bank's [corporate KYC](https://wiki.private.law/en/corporate-kyc) pack instead, but the questions cover the same ground: ownership, products, geography, source of funds. Source of funds within that pack is covered in the article on [source of funds](https://wiki.private.law/en/source-of-funds).

The questionnaire reaches the client directly through its payment provider. If the EMI through which a business collects revenue fails its bank's re-review, the EMI's accounts close, and the payment routes of its clients close with them. Provider resilience can therefore also be judged by whether a questionnaire is published, which version it is and when it was signed. What happens when a banking partner is lost is covered in the article on [account closures](https://wiki.private.law/en/bank-account-closure).

## Other Wolfsberg documents met in practice

Beyond the questionnaires, banks refer to a number of Group documents, above all in their own policies and supplementary questionnaires. All are in the [resources section](https://wolfsberg-group.org/resources/); only current editions are listed below.

| Document | Year | Where it applies |
| --- | --- | --- |
| Financial Crime Principles for Correspondent Banking | 2022 | correspondent due diligence logic, nested relationships, periodic review |
| Payment Transparency Standards | 2023 | completeness of payment message data, move to ISO 20022 |
| Payment Transparency — Roles and Responsibilities | 2024 | allocation of duties among payment chain participants |
| Swift RMA Guidance | 2024 | managing RMA authorisations between Swift users |
| Sanctions Screening Guidance | 2019 | design and management of sanctions screening |
| PEP Guidance | 2017 | defining and handling PEPs |
| Source of Wealth and Source of Funds FAQs | 2020 | corroborating SoW and SoF for private clients |
| Private Banking Principles | 2012 | core private banking rules |
| Statements on Effective Monitoring for Suspicious Activity | 2024, 2025 | moving from rules to risk-based monitoring |
| Guidance on the Risk-Based Approach | 2026 | updated guidance on the risk-based approach |
| Banking Services to Fiat-backed Stablecoin Issuers | 2025 | banking stablecoin issuers |
| Banking Services to non-bank PSPs | 2026 | banking EMIs, MSBs and other PSPs |

Whoever completes section 9 of the questionnaire needs the payment transparency standards above all. The [2023 Payment Transparency Standards](https://wolfsberg-group.org/resources/correspondent-banking/136) require that debtor and creditor information not be omitted, deleted or altered to avoid detection, and that structured formats such as ISO 20022 be adopted at the earliest opportunity. The standards apply equally to banks and non-bank PSPs. How these requirements relate to R.16 and the travel rule is covered in the article on the [travel rule](https://wiki.private.law/en/travel-rule), and the sanctions side in the article on [sanctions screening](https://wiki.private.law/en/sanctions-screening).

## Where the questionnaire breaks

Most problems with the questionnaire arise from a gap between what the questionnaire says and what actually exists in the company. The correspondent sees these gaps when it checks documents or, worse, at the first incident.

### Questionnaire versus policy

A typical picture: the questionnaire gives a 10% UBO threshold, the CDD procedure says 25%, and client files record none at all. Or the questionnaire says EDD applies to all PEPs, while the policy leaves it to a manager's discretion. The bank reads every such gap as a sign that the questionnaire was completed by someone who does not run the programme.

### Outdated version and outdated answers

A version 1.3 questionnaire in 2026 is a signal in itself: the respondent has no Fraud section and none of the 2023 questions. Another variant is a current-version questionnaire signed two years ago: since then the MLRO has changed, a new product has launched or a branch has opened. The declaration commits the signatories to refresh the answers at least every 18 months, and an expired questionnaire breaks their own undertaking.

> ⚠️ The most expensive error is a false "Yes". The answers are signed by the head of correspondent banking and the head of AML, which turns the questionnaire into a representation to the counterparty. A "Yes" on monitoring, EWRA, audit or the absence of nested clients without a supporting document is exposed at the first transaction review and usually ends with the bank exiting the relationship. For groups the second trap is answering for the holding company instead of the specific entity: the CBDDQ expressly bars one questionnaire from covering more than one legal entity.

### Group answers instead of entity answers

Groups create a separate problem of their own: a common questionnaire prepared by the parent is sent out in the name of each subsidiary. It carries the parent's licence and regulator, the parent's compliance headcount and the parent's audit. For the CBDDQ this is a direct breach of the completion rules; for the FCCQ it invites further questions. Each licensed entity needs its own questionnaire with its own EWRA and its own MLRO.

> 🍓 The Wolfsberg questionnaire is a private document of twelve banks that became compulsory by market force: the law requires a correspondent to assess the respondent's controls, and the questionnaire sets how. The current versions are CBDDQ 1.4 and FCCQ 1.2 of February 2023; the CBDDQ is completed for one legal entity, signed by two senior officers and refreshed at least every 18 months. The questionnaire is the programme's table of contents: every "Yes" must rest on a document, and for payment firms the Group's 2026 guidance recommends that banks add a tailored questionnaire on flows and corridors on top.

## Q/A

### Completing the questionnaire

### **Is a licensed firm obliged to complete the CBDDQ**

Not by law. The Wolfsberg Group is a private association with no regulatory powers. The duty to assess a respondent's AML controls falls on the correspondent bank under FATF R.13 and national law, and large banks discharge it through the CBDDQ or FCCQ. In practice, declining to complete the questionnaire means being declined an account.

### **Which version should be used in 2026**

CBDDQ 1.4 and FCCQ 1.2, published on 10 February 2023. The Group has issued no newer versions. A version 1.3 or older questionnaire lacks the Fraud section and the questions on whistleblower policy and virtual bank licences, so for the bank it is incomplete by definition.

### **Can one questionnaire cover the whole group**

Not for the CBDDQ: it is completed at legal entity level and should not cover more than one legal entity; branches are included only where their clients, products and controls are materially similar to the head office. The FCCQ, by contrast, may be completed at group level under the Group's FAQs, but a bank may ask for answers on its specific counterparty.

### **What if a question cannot honestly be answered "Yes"**

Answer "No" and use the clarification field: what has been done, what is planned and by when. From a new company a bank will usually accept "audit scheduled for the first quarter, auditor X"; a "Yes" without a supporting document costs far more.

### **How often should the questionnaire be refreshed**

The Group recommends a 12–18 month cycle, and the CBDDQ declaration commits the signatories to refresh the answers at least every 18 months. After a change of MLRO, a new product launch or a change of ownership it makes sense to refresh at once rather than wait for the deadline.

### Bank requests and counterparties

### **Why does a partner bank require a CBDDQ before opening an EMI's account**

Because in cross-border correspondent relationships the bank must, before opening them, gather information on the respondent's business, assess its controls and obtain senior management approval. The questionnaire is the standard way to collect this information, and for payment firms the 2026 Wolfsberg guidance recommends that banks add a tailored questionnaire on business model, flows and payment corridors.

### **How does the FCCQ differ from the CBDDQ**

The FCCQ is shorter: around 45 questions in ten sections against the CBDDQ's 14 sections. It has no separate blocks on products, risk assessment, testing or fraud, and the declaration is signed by a single Senior Compliance Manager. It is intended for relationships outside correspondent banking; the bank decides which questionnaire to request.

### **Where can a bank's or provider's questionnaire be found**

Many banks and large financial groups publish completed CBDDQs and FCCQs on their websites, and Swift KYC Registry members share theirs with correspondents through the platform. The signature date and version number on the first page show how current the questionnaire is.

---

## Factual claims

- The need for such a set comes from law.
- The key parameters of the questionnaires as at September 2026 are set out in one table.
- In the 2019 materials the Group called the CBDDQ “an enhanced and reasonable standard for cross-border and/or other higher risk Correspondent Banking Due Diligence”.
- Section 1 looks formal, yet it filters immediately.
- Sections 3–7 are the programme itself.
- Section 10 covers sanctions.
- The questionnaire comes with a set of three supporting documents from 2023, listed on the Group's website and published in six languages:
- A separate CBDDQ Publication Guidance from 2018 deals with publishing completed questionnaires.

---

Source: wiki.private.law — the private.law legal knowledge base. When quoting, cite the canonical page URL.
Consultation with a lawyer: https://t.me/private_law_bot
