What is a Wolfsberg questionnaire?

A Wolfsberg questionnaire is a standard Wolfsberg Group questionnaire (the CBDDQ or the FCCQ) in which a financial institution sets out its financial crime controls. A correspondent bank asks for it as part of its due diligence, and your team prepares the answers for senior officers to sign off on.

Each completed CBDDQ covers one legal entity and its branches, and the answers become the basis of the correspondent’s due diligence discussion with that entity. In correspondent banking, the Wolfsberg Group describes its questionnaires as the global standard for due diligence between financial institutions setting up a correspondent relationship. The term covers the CBDDQ and the FCCQ, together with the guidance, glossary and FAQs the Group publishes alongside them.

What do the CBDDQ and FCCQ ask?

The Wolfsberg correspondent banking due diligence questionnaire (CBDDQ)

The CBDDQ is the form for cross-border and other higher-risk correspondent banking relationships. Any financial institution that receives, or may receive, correspondent banking services should complete it.

The CBDDQ groups its questions by subject:

  • entity and ownership
  • products and services
  • the AML, CTF, and sanctions programme
  • anti-bribery and corruption
  • AML, CTF, and sanctions policies and procedures
  • AML, CTF, and sanctions risk assessment
  • KYC, CDD, and EDD
  • monitoring and reporting
  • payment transparency
  • sanctions
  • training and education
  • quality assurance and compliance testing
  • audit
  • fraud

The questions run from 1 to 132, many with lettered sub-questions. Each section closes by asking the institution to confirm that its answers apply to all of the legal entity’s branches and to explain any differences.

Complete a separate CBDDQ for each legal entity, and ensure the answers cover every branch of that entity. A subsidiary has its own questionnaire as a separate legal entity, and so does a branch whose business or financial crime compliance programme differs significantly from head office.

Take a bank that receives cross-border payment services from a correspondent and offers no correspondent banking of its own. When the correspondent asks for an updated CBDDQ, the bank’s DDQ manager prepares one for the legal entity and a second for the bank’s branch abroad, whose business differs significantly from head office. Financial crime compliance colleagues supply the answers to both as subject matter experts.

The Wolfsberg FCCQ questionnaire

The FCCQ, the Financial Crime Compliance Questionnaire, gives high-level information about an institution’s financial crime compliance programme. A group may complete one FCCQ for all of its entities.

An institution that receives cross-border or other higher-risk correspondent banking services must use the CBDDQ, and the FCCQ is not meant for such an institution.

The FCCQ’s questions run from 1 to 45. They fall under subjects the CBDDQ also covers: entity and ownership; the AML, CTF, and sanctions programme; anti-bribery and corruption; policies and procedures; KYC, CDD, and EDD; monitoring and reporting; payment transparency; sanctions; training and education; and audit.

The latest Wolfsberg questionnaire versions

The current versions are CBDDQ v1.4 and FCCQ v1.2, each in PDF and Excel on the Wolfsberg Group’s correspondent banking resources page, which lists no later version of either form.

All CBDDQ versions before v1.4 are retired. The same page carries CBDDQ Guidance v2.0, the CBDDQ Glossary v3.0, and the CBDDQ and FCCQ FAQs v3.0.

Who signs the declaration?

The CBDDQ declaration statement

The CBDDQ ends with a declaration statement signed by two people, whether the completed questionnaire is shared through a utility or bilaterally. The first is the head of the institution’s correspondent banking business (or equivalent), and the second is the group money laundering reporting officer (MLRO) or head of financial crime compliance.

An institution with no correspondent banking business takes its first signature from the most senior person in the unit that handles the transactions or manages the account. At the bank, that is the head of the unit that manages its account with the correspondent, and the group head of financial crime compliance provides the second signature.

Each signatory certifies that the answers are complete and correct to their honest belief, and that they are authorised to sign for the institution, so an answer that departs from the bank’s actual financial crime programme goes out under both certifications. Keeping every answer traceable to an auditable library of approved content lets the DDQ manager show each signatory where an answer came from.

The declaration also commits the institution to keep the information current, update it at least every 18 months, and file any supplemental information accurately and on time. In the same statement, the institution certifies that it complies, or is working to comply, with the Wolfsberg Correspondent Banking Principles and Trade Finance Principles.

At the end of each CBDDQ section, a free field takes any context that helps the correspondent understand the answers, and the respondent is expected to be transparent there.

The FCCQ signature page

The FCCQ needs one signature from the MLRO or a senior financial crime compliance manager in an equivalent role who represents the second line. That signatory certifies the answers as complete and correct to their honest belief.

The FCCQ’s signature page creates no obligation to refresh the answers, and keeping an FCCQ current depends on the institution’s review cycle.

What happens after you submit it?

Sharing one completed questionnaire

Because the CBDDQ holds extensive information, banks may choose not to post it on their websites. A correspondent then obtains the questionnaire from a KYC utility or directly from the respondent.

Some institutions publish their FCCQ on their website and hand over the CBDDQ only where the relationship warrants it. Either way, one approved CBDDQ per legal entity serves every correspondent that asks, and a questionnaire response process that answers once and reuses the approved answers keeps each copy the same.

Questions beyond the form

Each correspondent may ask its own additional questions, but they stay off the CBDDQ and FCCQ template, which the Wolfsberg Group endorses only as published.

The bank’s correspondent sends its additional questions with the request as its own set. The DDQ manager answers that set alongside the CBDDQ and returns the questionnaire itself unchanged, with financial crime compliance colleagues supplying the substance of both.

The CBDDQ is enough in most cases and should be the basis of the bilateral due diligence discussion between respondent and correspondent. The relationship, its products or its geographies can still call for a broader conversation.

Which rules does it serve?

FATF Recommendation 13

FATF Recommendation 13 requires a correspondent to apply additional due diligence to cross-border correspondent banking relationships, including higher-risk ones, and the Wolfsberg Group expects a completed CBDDQ to be a baseline that helps the correspondent meet Recommendation 13.

For your team, the CBDDQ’s answers are the material that due diligence draws on, from ownership to the sanctions programme.

In themselves, FATF Recommendations are not regulatory requirements. A correspondent may still want to see controls in place, and your team can expect questions on how the institution’s programme addresses the Recommendations.

EU rules on correspondent relationships

EU rules, for example, require a correspondent with a cross-border relationship with a respondent in a non-EU country to take these measures besides standard customer due diligence:

  • gather enough information to understand the respondent’s business, and judge its reputation and supervision from public information
  • assess the respondent’s AML/CFT controls
  • get senior management approval before opening the relationship
  • document the responsibilities of each institution
  • for payable-through accounts, be satisfied that the respondent has done due diligence on customers with direct access and can supply that data on request

The measures apply where your institution, as respondent, sits outside the EU. Your team supplies the facts the first two rest on: the institution’s business, ownership, and AML/CFT controls, as the CBDDQ records them.

The EU rules name no questionnaire, form or Wolfsberg Group; they require the due diligence measures. When a correspondent asks for more than the CBDDQ provides, or treats the completed form as its entire due diligence, your team can point to the measures themselves.

How does it differ from similar forms?

The Wolfsberg AML questionnaire

The CBDDQ replaced the Wolfsberg Group’s earlier questionnaire, yet the AML name survives on published responses. Clearstream, for one, describes the Wolfsberg questionnaire as the Group’s template AML questionnaire and labels the responses it publishes “Anti-money laundering declaration and questionnaire”.

A request under the old name is therefore answered with a current form, chosen for the relationship as for any other request.

A due diligence questionnaire (DDQ)

The CBDDQ is itself a DDQ: its question 12 calls the completing institution “the Entity completing the DDQ”. What sets the Wolfsberg forms apart from a due diligence questionnaire in general is that each is one template, used as published, that the Wolfsberg Group sets as its standard for due diligence between financial institutions in a correspondent relationship.

The supplier-side DDQ your team may also answer comes from an institutional investor, bank, insurer, or corporate buyer that assesses a supplier as a third party. The Wolfsberg forms instead assess a financial institution’s financial crime controls for a correspondent relationship.

Wolfsberg questionnaires in SEQUESTO

Answering a CBDDQ or FCCQ means your team must keep every answer aligned with the institution’s approved programme and traceable for the officers who sign, and SEQUESTO aOS brings auditability to that work. On each questionnaire, auditability means every response cited to a source with a full audit trail, down to the policy document and clause behind each answer.

When the institution revises a policy, SEQUESTO flags every answer drawn from that policy for review. Each answer’s record also keeps the policy version it came from, so the DDQ manager can show what had been approved on the day a questionnaire went out.

Reviewers, approvers, and financial crime compliance experts work in the workflow, and each question can have its own reviewer and approver. The team sees what James and Agent Force did and accepts, rejects, or adjusts it. The bid manager signs off, and the final wording stays in human hands.

SEQUESTO logs every action, who took it, and when, and exports the log for compliance review. For banks, payment processors, and insurers, that log is the chain of custody behind every answer a regulator or an institutional client asks about.

Frequently Asked Questions

Put the terminology to work

Now you know the language, see how SEQUESTO automates the process. Book a demo and experience AI-powered bid management first-hand.