A correspondent banking relationship is an arrangement where one financial institution provides payment or settlement services for another. In sanctions contexts, it is a major control point because it can carry prohibited transfers or provide access to the financial system for designated persons and their related networks.
Expanded Definition
Correspondent banking relationship refers to a service arrangement in which one financial institution, often called the respondent bank, uses another institution to clear, settle, or move payments across jurisdictions. In sanctions compliance, the term matters because the correspondent can become an access layer for prohibited parties, indirect beneficial ownership, or concealed payment routes. Definitions vary across regulators and bank policies, but the operational core is consistent: one institution is extending financial infrastructure to another, and that extension creates exposure if the downstream institution’s customers, controls, or transaction patterns are weak. The concept overlaps with nested payment chains, nested accounts, and cross-border settlement, but it is not the same as general banking relationships or simple account servicing. A useful reference point for governance is the NIST Cybersecurity Framework 2.0, which helps organisations connect third-party exposure to risk treatment and monitoring obligations. The most common misapplication is treating every cross-border banking counterparty as low risk, which occurs when screening focuses only on the direct customer and ignores indirect transaction paths.
Examples and Use Cases
Implementing correspondent banking controls rigorously often introduces friction in payment processing, requiring organisations to weigh transaction speed against sanctions, AML, and reputational risk.
- A regional bank clears USD payments through a larger foreign institution because it lacks direct access to the clearing network.
- A sanctions review team investigates nested flows where a respondent bank’s customer sends funds through intermediaries before reaching the final beneficiary.
- A compliance function applies enhanced due diligence before opening a relationship with a bank operating in a high-risk jurisdiction, using guidance from the NIST Cybersecurity Framework 2.0 to structure monitoring and response ownership.
- An enterprise reviewing financial counterparties reads the Ultimate Guide to NHIs to compare how access delegation and third-party exposure create similar governance risks in non-human systems.
- A bank terminates a correspondent relationship after repeated alert overrides, weak KYC refreshes, and unresolved beneficial ownership questions.
In practice, the term is also used when investigating how trade finance, remittances, and nested correspondent chains can obscure true originators and beneficiaries. The risk is not limited to prohibited persons; it also includes weak visibility into who actually controls the respondent institution and how quickly transaction patterns can change.
Why It Matters in NHI Security
Correspondent banking relationships matter to NHI security because they resemble delegated access structures: one entity is trusted to act within another entity’s operational perimeter, often with limited real-time visibility. That is the same failure pattern that appears in service account sprawl, external API consumption, and third-party credential exposure. NHI Mgmt Group notes that 92% of organisations expose NHIs to third parties, and that risk is amplified when access is indirect, persistent, or poorly monitored. The parallel is important for governance teams because hidden dependency chains make it harder to prove who initiated an action, who benefited from it, and whether the access should still exist. The Ultimate Guide to NHIs also reports that only 5.7% of organisations have full visibility into their service accounts, a reminder that blind spots often persist until a review is forced by incident response or regulatory scrutiny. Organisations typically encounter the operational cost of correspondent banking controls only after a sanctions hit, payment investigation, or counterparty termination, at which point the relationship becomes impossible to manage without complete transaction visibility.
Standards & Framework Alignment
This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.
OWASP Non-Human Identity Top 10 address the attack and risk surface, while NIST CSF 2.0, NIST Zero Trust (SP 800-207), NIST SP 800-63 and NIST AI RMF set the governance and control requirements practitioners need to meet.
| Framework | Control / Reference | Relevance |
|---|---|---|
| NIST CSF 2.0 | GV.SC | Third-party exposure and counterpart risk map to supply chain governance expectations. |
| NIST Zero Trust (SP 800-207) | Zero Trust treats every delegated path as untrusted until verified and continuously evaluated. | |
| OWASP Non-Human Identity Top 10 | NHI-04 | Indirect access and third-party exposure are core NHI governance concerns. |
| NIST SP 800-63 | IAL2 | Relationship onboarding depends on adequate identity proofing and assurance for counterpart actors. |
| NIST AI RMF | MAP | Risk mapping should capture cross-boundary payment dependencies and misuse scenarios. |
Inventory delegated access paths and revoke any correspondent-like access that lacks current business justification.