Completing the Wolfsberg CBDDQ starts with confirming that the Correspondent Banking Due Diligence Questionnaire is the right form for your institution, then gathering ownership, policy, screening, monitoring, and audit documentation before you open the file. From there, you work through the questionnaire section by section, answering every question with enough context that a correspondent bank reviewer does not have to come back with follow-ups, and share the finished document through the SWIFT KYC Registry or another channel your correspondent accepts. The current versions are CBDDQ v1.4 and FCCQ v1.2, both published by the Wolfsberg Group in PDF and Excel.
Choose the Right Questionnaire First
The CBDDQ is the longer form, built for correspondent banking relationships where one bank clears payments, executes wire transfers, or provides other transaction services on behalf of another bank across jurisdictions. Those relationships carry elevated risk because funds move through accounts the correspondent’s own customers never touch, which makes tracing harder. The Wolfsberg Group describes the CBDDQ and FCCQ together as “the global standard for due diligence between financial institutions in establishing a correspondent relationship.”1The Wolfsberg Group. Correspondent Banking and Payments
The FCCQ is the shorter alternative for lower-risk or less complex relationships. A regional bank that does not offer cross-border clearing, nested correspondent accounts, or payable-through accounts would typically complete the FCCQ. Both forms share the same underlying framework, and updates to the CBDDQ are mirrored in the FCCQ.2The Wolfsberg Group. Publication of the CBDDQ, FCCQ, Guidance, Glossary and FAQs
One structural rule matters before you begin: a separate CBDDQ must be completed for each legal entity. The responses cover all branches of that entity but exclude subsidiaries. If a branch runs a materially different business model or financial crime compliance program from head office, that branch needs its own questionnaire.3The Wolfsberg Group. CBDDQ Guidance v2.0
Where to Download the Forms and Guidance
Both questionnaires are on the Wolfsberg Group’s resources page in PDF and Excel. Use the Excel version to complete the form. Its drop-down menus and structured fields cut down on formatting errors that slow reviewers down. Alongside the questionnaires, the Group publishes a CBDDQ Guidance document (currently v2.0), a glossary, and a set of FAQs. Read the Guidance before answering anything. It explains what each question is looking for and flags where free-text explanations are expected rather than optional.4The Wolfsberg Group. Resources – Wolfsberg Group
Gather Your Documentation Before You Start
The CBDDQ pulls data from across the institution. Legal, compliance, operations, and senior management all contribute, and chasing missing pieces after the fact is where completion timelines blow up. Assemble the following before you open the form:
- Corporate structure and ownership records: legal name, registered address, date of incorporation, Legal Entity Identifier, and a full ownership chart. For privately owned entities, disclose all shareholders or Ultimate Beneficial Owners holding 10% or more. Report the percentage of bearer shares, if any, and whether the entity or any branch operates under an offshore banking license.
- Regulatory information: the primary financial regulator, jurisdiction of the licensing authority, and details of the ultimate parent entity where different from the respondent.
- AML and CTF policy documents: current written policies for customer due diligence, enhanced due diligence, suspicious activity reporting, and cash transaction reporting. These should be board-approved; if they are not, plan a free-text explanation.
- Sanctions screening documentation: which lists you screen against (OFAC, EU, UN, and others), the frequency of screening, and whether the screening is automated, manual, or both.
- Independent testing and audit results: the most recent dates and findings from independent testing of your financial crime compliance program, separate from internal audit.
- Anti-bribery and corruption policies: your ABC program documentation, including prohibitions on giving and receiving bribes, rules on interactions with public officials, and controls against falsification of books and records.
- Transaction monitoring details: the systems and processes you use to flag suspicious transactions, and whether monitoring is automated, manual, or a combination.
- Current employee headcount and total assets.
One trap to note early: the CBDDQ’s 10% UBO disclosure threshold is stricter than the 25% threshold in FinCEN’s Customer Due Diligence Rule for U.S. covered financial institutions.5eCFR. 31 CFR 1010.230 – Beneficial Ownership Requirements for Legal Entity Customers If your institution has only collected ownership data down to 25% for domestic purposes, you will need to go deeper before you can answer the ownership section.
Working Through the CBDDQ Section by Section
The Wolfsberg Guidance recommends transparency throughout. At the end of each section, add context wherever a yes/no answer alone would leave the reviewer guessing.
Entity and Ownership (Questions 1–18)
The opening questions capture legal identifiers and drill into ownership structure through mutually exclusive categories: publicly traded, member-owned or mutual, government-owned at 25% or more, or privately owned. Select the one that applies and attach an ownership chart where you can. For publicly traded entities, give the exchange and ticker. For privately owned entities, list every shareholder or UBO at 10% or above.3The Wolfsberg Group. CBDDQ Guidance v2.0
Question 7 asks for the percentage of bearer shares. Even a zero answer matters, because reviewers treat any bearer share exposure as a red flag. Question 8 covers offshore banking licenses, another place where a clear “no” is better than silence. Question 9 addresses whether you operate as a virtual bank or only through online channels. The section also asks whether 10% or more of your customer base or revenue comes from non-resident customers and, if so, requests the top five countries where those customers are located.
Products and Services (Question 19)
Question 19 is one of the longest parts of the form. It walks through a catalog of higher-risk products and services and asks whether your entity offers each one. The correspondent bank uses this section to see which risk categories it inherits by dealing with you.
The inventory covers correspondent banking (with sub-questions on downstream and nested relationships), cross-border remittances, bulk cash delivery, payable-through accounts, trade finance, private banking, virtual assets, and services to non-bank entities such as payment service providers and virtual asset service providers. Every “yes” opens follow-up questions about how you manage the associated risk. If you serve walk-in customers — check cashing, wire transfers, foreign currency conversion, or monetary instrument sales — the form asks what level of due diligence you apply to each.
This is where most compliance teams should expect to spend real time. Rushing this section, or marking items “not applicable” without explanation, produces exactly the follow-up inquiries that delay onboarding.
AML, CTF, and Sanctions Programme (Question 22)
Question 22 asks whether your entity has a program setting minimum standards across the pillars of financial crime compliance. The sub-questions cover:
- Whether you have a designated compliance officer with sufficient seniority and autonomy.
- Whether the program defines the levels of direct and underlying beneficial ownership to be identified for different customer types and risk levels.
- Whether you have documented standards for routine CDD and enhanced due diligence for higher-risk relationships.
- Whether the compliance program is tested independently of internal audit, with a defined approach, frequency, and reporting process.
- Whether your program defines both domestic and foreign politically exposed persons and includes a process for evaluating and approving PEP relationships.
- Whether your sanctions program defines applicable lists, screened data elements, and risk appetite for customers with a sanctions connection.
- Whether transaction monitoring standards cover detection patterns, the systems used, and alert-handling governance.
Answering “no” to board approval of policies does not automatically disqualify you, but it does require an explanation in the free-text field. Reviewers want to understand your control environment, not see a wall of “yes” responses with no substance behind them.3The Wolfsberg Group. CBDDQ Guidance v2.0
Anti-Bribery and Corruption (Questions 30–35)
The ABC section asks whether your documented policies prohibit both giving and receiving bribes, including promising, offering, soliciting, and receiving anything of value to improperly influence action. It asks specifically whether the program includes enhanced requirements for interactions with public officials and prohibits the falsification of books and records. A separate question addresses whether the ABC policy extends to agents, consultants, and other intermediaries acting on your behalf.3The Wolfsberg Group. CBDDQ Guidance v2.0
Transaction Monitoring and Suspicious Activity Reporting
Here the form asks how your institution detects and reports suspicious activity: whether monitoring is automated, manual, or a mix; how alerts are escalated; and what governance framework applies to suspicious activity report filings. Reviewers expect narrative here, not bare yes/no answers, particularly if you handle high volumes of cross-border payments.
Answering Style That Avoids Follow-Up Delays
The single most common mistake is leaving fields blank. An empty field signals either evasiveness or carelessness, and both trigger clarification requests that push out account activation. If a question genuinely does not apply, mark it “N/A” and explain why. The Guidance is specific: use “not applicable” only for a regulatory reason (say, no cash reporting obligation exists in your jurisdiction) or an operational reason (your entity does not handle cash at all).3The Wolfsberg Group. CBDDQ Guidance v2.0
When a response differs for one of your branches, flag the discrepancy and explain it at the end of the relevant subsection. Do not average or generalize across branches. Correspondent banks need to see exactly where their exposure sits. If a full date is unavailable for something like your last independent test, provide the year and explain the gap.
Verify every response against actual operational practice before a senior officer signs off. Incorrect or misleading disclosures can end banking relationships and attract regulatory scrutiny. The Guidance frames the exercise as an opening for dialogue, noting that “open and direct communication between parties will assist to build a solid working relationship.”
Sharing the Completed Questionnaire
There is no single submission portal. You share the completed CBDDQ or FCCQ with each correspondent bank that requests it. Three distribution channels are common.
The SWIFT KYC Registry is the most widely used. Over 7,700 institutions participate. Members answer every Wolfsberg question directly on the registry, and the platform covers up to 90% of what correspondent banks typically need for due diligence. Respondent banks upload and share their data free of charge; correspondent banks pay per record to access it.6Swift. KYC Registry7Swift. Swift Aligns KYC Registry with Updated Wolfsberg Due Diligence Questionnaire
Some institutions share the completed PDF directly, either through a password-protected section of their website or through encrypted email. This works, but it puts version control and access management on you. Third-party compliance portals such as Bankers Almanac aggregate due diligence documentation for multiple institutions and offer a middle option.
Whichever channel you use, the correspondent bank decides whether your answers are sufficient. Expect follow-up questions if your entity operates in higher-risk jurisdictions, offers products like payable-through accounts or virtual assets, or has a complex ownership structure.
Keeping the Questionnaire Current
The CBDDQ is not a one-time filing. Industry practice and the Wolfsberg Guidance both contemplate periodic updates, and most correspondent banks require a refreshed questionnaire annually. If your risk profile shifts between cycles because of a new product launch, a change in ownership, or a regulatory action, update your responses on your own initiative rather than waiting for the next scheduled review.
Missing an update window can freeze correspondent banking services. At a minimum, the correspondent bank may restrict international wire capabilities until it receives a current questionnaire. Repeated late refreshes erode trust and can lead to termination.
What Weak or Misleading Responses Cost
The first consequence is commercial. A correspondent bank that reads an incomplete or misleading questionnaire declines to onboard you or ends an existing relationship. For institutions that rely on correspondent banking for cross-border payments, losing access can be operationally severe.
Regulatory exposure sits mainly with the correspondent bank that fails to conduct adequate due diligence, but respondents are not off the hook. If a respondent’s disclosures are materially false and the relationship facilitates money laundering, both parties face exposure under the Bank Secrecy Act. Section 313 of the USA PATRIOT Act prohibits U.S. banks from maintaining correspondent accounts for foreign shell banks — entities with no physical presence in any country. Section 319 requires banks providing correspondent accounts to foreign banks to keep records identifying those banks’ owners and to hold the name and address of a U.S.-based agent authorized to accept legal process.8Federal Financial Institutions Examination Council. FFIEC BSA/AML Manual – Prohibition on Correspondent Accounts for Foreign Shell Banks; Records of Owners and Agents The CBDDQ’s questions about ownership, shell bank status, and offshore licenses map directly to those requirements, which is one reason accurate answers matter beyond the commercial relationship.
Completing a Wolfsberg questionnaire does not by itself satisfy FinCEN’s Customer Due Diligence Rule for U.S. covered institutions, which requires written policies to identify and verify beneficial owners, develop customer risk profiles, and conduct ongoing monitoring.9FinCEN.gov. Information on Complying with the Customer Due Diligence (CDD) Final Rule It does produce the documentation regulators expect to see during examinations, which is why the quality of the answers you file today shapes what your next exam looks like.