AML/BSA Regulatory Expectations
Establishing a correspondent banking relationship in the U.S. requires adherence to AML and Bank Secrecy Act (BSA) regulations. U.S. regulators impose stringent standards and emphasize several key areas.
Risk Assessment
Conduct an AML and sanctions risk assessment to identify and evaluate risk across the bank’s customer base, products and services, transaction activity, and geographic exposure. The risk assessment should be refreshed at least annually and updated whenever there is a material change in the bank’s business or risk profile (e.g., entry into a new jurisdiction, launch of a new product, or a significant change in customer base or transaction activity).
Regulators and U.S. correspondent banks expect risk assessments for U.S. correspondent banking to explicitly address U.S. nexus exposure, including sanctions risk, cross-border transactions, nested account activity and higher-risk products (e.g., trade finance or payments involving multiple jurisdictions). Risk assessments should demonstrate how identified risks are mitigated through specific controls, not general descriptions.
Customer Due Diligence
Implement stringent customer due diligence (CDD) procedures to verify customer identities and assess banking activities by collecting and analyzing information to confirm customers are not involved in illicit activities. CDD is essential to an effective AML program because it allows banks to understand their customers and the nature of their relationships. Institutions should ensure customer risk ratings are applied consistently and supported by documented methods.
Transaction Monitoring
Implement a comprehensive transaction monitoring system to detect and report suspicious activities. The system should identify and flag unusual or potentially illegal transactions for further investigation. Advanced transaction monitoring systems allow banks to detect evolving money laundering methods and comply with regulatory requirements.
During regulatory reviews and correspondent bank due diligence, correspondent banks and regulators increasingly expect institutions to demonstrate that alerts are generated, that monitoring scenarios are aligned with risk and are periodically reviewed, and that clear governance is established. Documented model tuning, alert disposition rationales and audit trails are essential to demonstrate the effectiveness of transaction monitoring frameworks during reviews.