Rethinking Correspondent Banking and Financial Integrity Risks
A Financial Integrity Ecosystem for Strengthening Correspondent Banking and Combating Illicit Finance
Vishnevich, A. (2026). Rethinking Correspondent Banking and Financial Integrity Risks. CENTEF. https://centef.org/research-publication/rethinking-correspondent-banking-and-financial-integrity-risks/
Table of Contents
Background
Correspondent banking constitutes the operational backbone of the international financial system. It enables cross-border payments, trade finance, foreign exchange transactions, securities settlement, and international investment flows. At the same time, it remains a major channel through which terrorist organizations, sanctions evaders, proliferation networks, transnational criminal organizations (TCOs), and corrupt state actors gain access to the global financial system.
Over the past two decades, countries have responded to these risks through increasingly sophisticated anti-money laundering (AML) and counter-terrorist financing (CFT) laws and regulations, sanctions and restrictive measures, and prudential regulatory frameworks. Despite substantial investment in compliance systems and significant control and enforcement activity, investigations and enforcement actions continue to demonstrate the persistence of structural vulnerabilities within correspondent banking networks.
The principal challenge is no longer the creation of new authorities, but rather the systematic deployment of existing tools and the development of complementary mechanisms that alter institutional incentives before violations occur. This article argues that the legal architecture required to address most correspondent banking risks already exists.
To address this challenge, the article proposes an integrated eight-pillar framework combining disclosure obligations, governance and market discipline mechanisms, external auditor accountability, prudential incentives, enhanced correspondent banking oversight, liability thresholds in sanctions implementation and ownership-transparency measures.
The importance of adopting this integrated eight-pillar framework is heightened by possible geopolitical developments and sanctions-relief arrangements – also such involving Iran – which may result in substantial increases in cross-border financial flows originating from a jurisdiction that has spent more than fifteen years developing sophisticated sanctions-evasion and illicit-finance infrastructures. Ensuring that correspondent banking networks can distinguish legitimate commercial activity from illicit financial flows should therefore be regarded as a strategic financial-integrity priority.
We believe that adopting this suggested framework might support financial institutions to better manage applying risks rather than totally avoiding also legitimate activity. We believe this should be in the interest of every participant in the control and compliance environment of the banking sector, and not only regulators and enforcement authorities.
Executive Summary
Integrity vulnerabilities of correspondent banking are well documented.
Terrorist organizations, sanctions-designated states, proliferators, narcotics traffickers, kleptocratic networks, and other illicit actors have repeatedly exploited correspondent banking relationships to move funds through the international financial system. These risks are not theoretical. They have been demonstrated through enforcement actions, intelligence assessments, legislative investigations, and supervisory findings across multiple jurisdictions and over several decades.
The following structural characteristics of correspondent banking explain its continued attractiveness to illicit actors: Transactions frequently pass through multiple intermediaries; nested correspondent relationships make it easier to obscure ultimate beneficiaries; transaction-processing volumes have brought extensive automation and less human monitoring; and regulatory visibility remains fragmented across jurisdictions.
Current regulatory approaches rely heavily and applied mainly via examinations, enforcement actions and compliance obligations imposed upon financial institutions. While these mechanisms remain essential, they are inherently reactive. In most cases, regulatory intervention occurs after deficiencies have already existed for extended periods or after illicit activity has already occurred.
This article advances a broader proposition that extends beyond the traditional regulatory paradigm. Rather than viewing the prevention of illicit financial activity as the sole responsibility of financial institutions and supervisory authorities, it designs a comprehensive financial-integrity framework that engages all participants in the governance and control environment surrounding correspondent banking. These participants include senior management, boards of directors, shareholders, external auditors, prudential supervisors, market regulators, business counterparts, rating agencies and other public authorities responsible for monitoring, assessing, and enforcing compliance with anti-money laundering, counter-terrorist financing, sanctions, and prudential regulatory requirements.
The objective is not to replace regulatory enforcement, but to reinforce it through a multidimensional framework that offers auxiliary and complementary tools and promotes continuous oversight, stronger governance, and earlier identification of emerging financial-integrity risks.
Accordingly, the improved methodology of correspondent banking controls should move beyond an enforcement-centric model and incorporate complementary mechanisms based on transparency, disclosure, market discipline, external auditor accountability, prudential incentives, and more systematic deployment of existing regulatory authorities.
Against this background, the article proposes eight complementary reform pillars designed to provide practical policy instruments that strengthen the implementation of risk-management frameworks governing correspondent banking. Collectively, these pillars seek to improve not only the effectiveness of banks’ internal compliance programs, but also the contribution of all participants in the broader financial governance ecosystem to the prevention of terrorism financing, sanctions evasion, proliferation financing, and other forms of illicit finance.
The eight reform pillars include:
- Financial reporting as a market-discipline mechanism.
- Expansion of the disclosure framework established under Section 219 of the Iran Threat Reduction and Syria Human Rights Act.
- Application of conflict-minerals and similar complex supply-chain due-diligence methodologies to correspondent banking.
- Expansion of external auditor responsibilities.
- Full implementation of CISADA §104(e) authorities and extension of their underlying logic to other high-risk jurisdictions, sanctions programs, and financial-integrity concerns.
- Reassessment of knowledge standards in secondary sanctions implementation.
- Terrorism-financing and sanctions-evasion capital buffers.
- Expansion of OFAC’s 50% Rule to address upstream ownership structures.
Together, these reforms seek to create a financial-integrity architecture capable of influencing behavior before violations occur rather than relying mainly on ex-post enforcement.
The objective is ultimately to move from a system in which financial integrity is principally something regulators enforce toward one in which financial integrity is also something that markets price, boards govern, auditors independently assess, supervisors evaluate, counterparties require and prudential frameworks recognize.
1. Introduction
Correspondent banking networks are dynamic systems through which economic activity, financial information, legal obligations, and risk exposures flow across jurisdictions and enable international trade and cross-border investment.
Unfortunately, the same characteristics that facilitate legitimate commerce can be exploited by different actors seeking to conceal ownership, disguise transaction origins, evade sanctions and restrictive measures, finance terrorist activity, support weapons-proliferation programs, launder criminal proceeds, or move public assets stolen through corruption.
These vulnerabilities arise not because correspondent banking is defective, but because it is designed to facilitate financial intermediation across multiple institutions and jurisdictions under different legal systems, regulatory frameworks, supervisory expectations, and risk environments. Complexity and scale are features of the system. They are also sources of risk.
Policymakers have responded to this risk through a combination of AML/CFT obligations, sanctions programs, beneficial-ownership requirements, prudential supervisory guidelines, enforcement actions, and international standards developed by the Financial Action Task Force (FATF), Basel Committee on Banking Supervision, the Financial Stability Board (FSB), and the United Nations Security Council.
These efforts have produced significant improvements: Compliance functions have expanded dramatically; Screening technologies have become more sophisticated; Suspicious activity reporting has increased, and Sanctions compliance has become embedded in institutional governance frameworks. Yet, recurring investigation findings and enforcement actions involving also major global financial institutions demonstrate that substantial vulnerabilities have remained and major weaknesses persist.
The main limitation of the current model is that it remains fundamentally reactive and usually suffers a time-lag problem so that even when enforcement is successful, the deterrent effect is frequently delayed: Most enforcement actions occur after misconduct has already occurred; Most examination findings identify weaknesses after those weaknesses have existed for extended periods and most penalties are imposed only after illicit activity has already passed through the financial system. Consequently, the system often responds to failures rather than preventing them.
This article argues that adjusted methodology should focus on creating continuous incentives for risk reduction rather than relying mainly on episodic regulatory intervention.
Financial institutions do respond to regulatory expectations, but they also respond to market forces, shareholder pressure, funding costs, reputational concerns, auditor scrutiny, and capital requirements.
These influences operate continuously rather than episodically, and this is the basis for the suggested analysis and the strategic focus of this article. To put it in one leading narrative, enforcement sets the floor – the minimum acceptable standard of conduct – but markets create continuous discipline.
2. The Emerging Iran Challenge
The urgency of strengthening correspondent banking controls is increasingly linked to the possibility that future geopolitical developments may substantially increase financial flows from jurisdictions that have been sanctioned for a long time and continuously have developed sophisticated sanctions-evasion infrastructures. The most significant example this article focuses on is Iran.
For more than fifteen years, Iran has operated under some of the most extensive sanctions regimes ever imposed on a sovereign state. During this period, Iranian state institutions, financial institutions, state-owned enterprises, and affiliated commercial actors developed extensive mechanisms designed to preserve access to international markets despite restrictions on financial transactions.
These mechanisms reportedly include front companies, alternative payment arrangements, commodity-based value transfer systems, trade-based money-laundering structures, complex beneficial ownership arrangements, cryptocurrency channels, and relationships with financial intermediaries willing to face elevated sanctions risks.
Whether future negotiations ultimately result in sanctions relief is beyond the scope of this article. In any case, meaningful relaxation of sanctions would almost certainly result in increased financial activity involving Iranian entities and counterparties. Much of that activity would necessarily pass through correspondent banking networks. This reality creates a challenge that requires adequate attention.
The debate surrounding sanctions relief focuses mainly on foreign-policy objectives, macro-economic consequences, or nuclear non-proliferation considerations. At this time it is required to devote attention to the financial-integrity architecture that would be required to accompany such possible sanctions relief.
The underlying issue is whether sufficient safeguards exist to distinguish legitimate commercial activity from activities involving terrorism financing, sanctions evasion, proliferation financing, or other illicit conduct.
This distinction is critically important because sanctions-evasion infrastructures will not automatically disappear when sanctions are relieved and will continue providing operational flexibility to illicit actors.
Networks built to facilitate sanctions evasion frequently possess capabilities that can be repurposed for other forms of illicit finance. The institutional knowledge, commercial relationships, beneficial ownership structures, and financial intermediaries that supported sanctions evasion will probably remain intact even after the underlying sanctions environment changes.
Consequently, any future increase in Iran-related financial flows would test the ability of correspondent banking controls to identify and mitigate elevated risks.
The broader lesson extends beyond Iran: Other sanctioned jurisdictions, state-sponsored illicit-finance networks, and transnational criminal organizations continue to develop increasingly sophisticated methods for accessing the international financial system. Strengthening correspondent banking controls therefore serves not only foreign sanctions policy but also broader financial stability and national-security objectives.
3. The Role of Market-Based Incentives
Financial institutions respond to regulatory expectations and to enforcement threats, but they also respond to market forces, shareholder pressure, funding costs, reputational concerns, auditor scrutiny, and capital requirements.
These influences operate continuously rather than episodically. They can also compensate for resource constraints of supervisory authorities which operate with finite resources. Even the most capable regulators cannot continuously monitor every correspondent relationship, transaction stream, ownership structure, or compliance program. The scale of global financial activity exceeds the capacity of any centralized monitoring framework and thus, enforcement necessarily becomes selective.
Enforcement establishes the minimum acceptable standard of conduct and Institutions understand that failure to comply may result in penalties, restrictions, or other enforcement actions. This deterrent effect remains indispensable, and it sets the floor for compliance. However, enforcement typically activates only after deficiencies have already emerged.
Continuous information-Based Market Discipline
Disclosure operates differently. When investors, creditors, counterparties, rating agencies, and analysts gain visibility into risk exposures, they begin pricing those risks into their decisions: Funding costs adjust; Credit spreads change; Counterparties modify exposure limit and boards and management become more attentive.
Unlike enforcement, market discipline functions continuously. It does not require a regulator to initiate an investigation. However, to become effective market discipline requires and depends upon information: Risks that remain invisible cannot be priced; Risks that become visible influence behavior.
This simple principle has ever been the basis for disclosure frameworks that were established across numerous areas of financial regulation, including the securities markets, corporate governance disclosures, conflict-minerals regulation, climate-risk reporting and of course traditional risks that are disclosed by financial institutions – credit risk, market risk, operational and legal risk etc.
The same logic can and should be applied to correspondent banking as will be demonstrated.
Expanding the Circle of Participants’ Accountability
A disclosure-based framework expands the number of actors participating in risk mitigation. Responsibility no longer rests solely with regulators but also with other participants: investors, correspondent counterparties, external auditors, credit-rating agencies, boards of directors etc.
This multiplication of oversight mechanisms creates a monitoring capacity that no regulatory agency can replicate.
Integrated Effects of the Eight-Pillar Framework on Correspondent Banking Integrity, structured by market-based incentives
Each pillar proposed in this article can be justified independently. The true value of the framework, however, emerges when the pillars are considered collectively and create multiple layers of oversight operating simultaneously.
Pillars One through Four focus on transparency, disclosure, governance and market discipline, and independent accountability.
Pillars Five through Eight focus on regulatory deployment, liability thresholds and deterrence, prudential incentives, and ownership transparency.
Together they catalyze market mechanisms where each participant in the financial integrity ecosystem acts and reacts according to its basic motivations and natural incentives:
Investors receive information to reshape or confirm investments decisions.
Auditors gain enhanced responsibilities what requires enhanced audit procedures to meet their legal and professional duties.
Correspondent banks receive stronger incentives to comply, to protect their correspondent agreements and maintain their financial access to other jurisdictions and other currencies.
Regulators obtain greater visibility, what not only enables but dictates thorough supervisory use of this information to ensure the quality of the supervisory process.
Supervisors acquire additional prudential tools which add business and financial incentives to compliance-related considerations.
Legal ownership structures become more transparent what serves all of the above processes.
This multi-layered framework seeks to distribute responsibility across the broader financial ecosystem. The result is a more resilient model capable of influencing behavior before violations occur rather than relying exclusively upon enforcement after the fact.
The eight pillars that follow seek to operate those principles.
4. The Eight-Pillar Reform Framework
The eight pillars are not intended as independent policy initiatives. They are designed as mutually reinforcing components of broader financial-integrity architecture. Some focus on transparency. Others strengthen deterrence. Others improve accountability, supervision, or prudential incentives.
Pillar One: Financial Reporting as a Market Discipline Instrument
The core insight here is that mandatory public disclosure of correspondent banking relationships and their risk characteristics would activate market discipline mechanisms that enforcement alone cannot provide. When counterparties, investors, creditors, and depositors can see a bank’s correspondent exposure — including Concentration of correspondent banking activity by jurisdiction, relationships with institutions in FATF-monitored jurisdictions, relationships that have generated enforcement history, and relationships that carry elevated financial-integrity risk scores – they price that risk into funding costs, equity valuations, and counterparty credit assessments. This market discipline effect operates continuously and automatically, complementing the episodic deterrence of enforcement action.
The basic mechanism is simple: A risk that is visible can be priced. A risk that can be priced can influence behavior. A risk that influences behavior can reduce the likelihood of future misconduct.
Current financial reporting frameworks provide extensive disclosure regarding credit risk, market risk, liquidity risk, cybersecurity risk, climate risk, legal risk, and operational risk. By contrast, disclosure relating explicitly to correspondent banking exposures and financial-integrity risks remains relatively limited.
Material exposure to jurisdictions associated with elevated terrorism-financing, sanctions-evasion, proliferation-financing, or corruption risks can create significant financial consequences for institutions. These consequences may include enforcement actions, civil litigation, restrictions on business activities, reputational damage, increased compliance costs, and deterioration in shareholder value.
The financial significance of such risks is therefore beyond dispute. The experience of securities markets consistently demonstrates that disclosure influences behavior more effectively than many forms of direct intervention. Management teams also routinely devote substantial attention to risks that may affect earnings, valuations, or access to capital.
The objective would not be public naming and shaming. Rather, it would be to provide investors, counterparties, creditors, rating agencies, and auditors with sufficient information to assess risk.
The effectiveness of any enhanced financial reporting framework will ultimately depend upon a meaningful degree of international coordination.
Correspondent banking is, by its nature, a cross-border activity, and its integrity cannot be safeguarded through isolated national disclosure regimes alone. Significant asymmetries in reporting requirements would inevitably create transparency gaps, limiting the ability of investors, counterparties, regulators, and other stakeholders to develop a comprehensive understanding of institutions’ correspondent banking risk profiles.
Moreover, inconsistent disclosure standards could encourage regulatory arbitrage by creating incentives to channel higher-risk correspondent banking activities through jurisdictions with less demanding reporting obligations.
For these reasons, future changes in financial reporting guidelines should seek broad convergence of disclosure principles among major financial centers, supported by international standard-setting bodies such as the Basel Committee on Banking Supervision, the Financial Stability Board, the International Organization of Securities Commissions (IOSCO), and the International Accounting Standards Board (IASB).
While complete harmonization may not be immediately achievable, greater international consistency would substantially enhance transparency, improve comparability of disclosures, strengthen market discipline, and ultimately reinforce the effectiveness of correspondent banking risk management.
Correspondent banking is only as transparent as its least transparent major jurisdiction. National reforms, while valuable, are not sufficient. Since correspondent banking is a network, network transparency is constrained by its weakest disclosure link.
Pillar Two: Expanding Section 219 ITRSHRA Disclosure Framework
Sec. 219 of the Iran Threat Reduction and Syria Human Rights Act of 2012 Amends the Securities Exchange Act of 1934 to require securities issuers to disclose in detail in their mandatory annual or quarterly reports to the Securities and Exchange Commission (SEC) whether they or their affiliates have: (1) engaged in certain activities relating to Iran, terrorism, and the proliferation of weapons of mass destruction; (2) knowingly engaged in specified activities, or knowingly violated certain regulations prescribed under the Comprehensive Iran Sanctions, Accountability, and Divestment Act of 2010; (3) knowingly conducted any transaction or dealing with a person whose property and interests in property are blocked by certain Executive Orders; or (4) knowingly conducted a transaction or dealing with any person listed in the Iranian Transactions Regulations. Sec. 219 also requires: (1) an issuer to disclose in a separate SEC filing that any such activity has been included in an annual or quarterly report, (2) the SEC to transit the report to the President and Congress, and (3) the President to initiate an investigation into the possible imposition of sanctions. {Congress summary: H.R.1905 — 112th Congress (2011-2012) }
The mechanism established by Sec. 219 of ITRSHRA uses the existing securities disclosure infrastructure – with its legal liability regime, and public accessibility – to create a reporting obligation that sits outside the BSA/OFAC enforcement framework and activates a completely different set of consequences, including not only investor and market reactions but also SEC reporting to President and Congress and possible investigation and sanctions.
This mechanism could be extended beyond Iran to cover also other sanctions regimes and other varied integrity-related risks. It is applicable to correspondent relationships that expose the filer (the reporting entity) to illicit finance risk more broadly including to terror financing, proliferation financing, and other sanctions-evasion in general.
The proposed disclosure mechanism creates several layers of accountability simultaneously: Regulatory accountability through SEC reporting; Political accountability through notification to the Congress and president; Market accountability through public disclosure and Governance accountability through board and external auditor’s responsibility to the accuracy of this required reporting.
Importantly, these consequences arise regardless of whether a sanctions violation has occurred. Disclosure itself becomes a risk-management mechanism.
The resulting information would enable investors, counterparties, and regulators to better assess institutional exposure caused by correspondent relationships while simultaneously creating incentives for stronger risk-management practices.
This approach does not depend upon identifying misconduct. It seeks to shape behavior before problems emerge.
Pillar Three: Applying the Conflict Minerals and Other Complex Supply-Chains Due-Diligence and Disclosure Methodologies to Correspondent Banking
Pillar Three is built on a functional analogy between two different regulatory risk environments: conflict-minerals supply chains and correspondent banking networks. Although the underlying risks differ, both involve complex, multi-layered chains in which the reporting entity often lacks direct visibility into the ultimate source, intermediary actors, or final beneficiary. In each context, risk is transmitted through relationships that extend across jurisdictions, depend on third-party information, and may be deliberately structured to obscure problematic connections.
This analogy is therefore intended to identify a regulatory methodology suited to their shared characteristics. The conflict-minerals framework offers such a model, also because it does not demand perfect knowledge; instead, it requires reasonable inquiry, risk-based due diligence, documentation, risk mitigation, and disclosure calibrated to the institution’s position within the relevant chain.
The analogy developed in this chapter is therefore methodological. It does not suggest that the underlying risks are equivalent; rather, it demonstrates that regulatory techniques developed to manage complex, opaque, and globally dispersed supply chains may provide a valuable conceptual starting point for managing comparable challenges within international correspondent banking networks.
Section 1502 of Dodd-Frank Act and the SEC’s implementing rules requires issuers to conduct reasonable country-of-origin inquiry and supply chain due diligence regarding tin, tantalum, tungsten, and gold sourced from certain countries, and to file an annual Conflict Minerals Report.
The methodology is transferable to correspondent banking for the following reasons:
It maps a complex, multi-tiered supply chain of relationships – Funds pass through multiple intermediaries, Relationships extend across numerous jurisdictions, Information that becomes increasingly fragmented as distance from the originating transaction increases;
It imposes a due diligence and disclosure standard calibrated to the filer’s position in the chain;
It distinguishes between different levels of inquiry obligation based on risk;
and it creates a public disclosure that activates market discipline.
We believe that The EU’s parallel Conflict Minerals Regulation {Regulation (EU) 2017/821 of the European Parliament and of the Council of 17 May 2017} and the broader EU corporate due diligence framework – including the Corporate Sustainability Due Diligence Directive (CS3D), could have provided a European methodological benchmark for shaping an adequate and internationally accepted Due Diligence Framework, modeled on the CS3D.
The Corporate Sustainability Due Diligence Directive (CSDDD) is one of the European Union’s most significant corporate governance initiatives. Unlike the Corporate Sustainability Reporting Directive (CSRD), which focuses primarily on reporting, CS3D imposes a legal duty to conduct a thorough due diligence on human rights and environmental risks throughout a company’s operations, subsidiaries, and chain of activities. It entered into force on 25 July 2024 and has subsequently been amended through the EU’s Omnibus simplification process, including on February 2026 via The Directive (EU) 2026/470 – the Omnibus I Directive.
Under the March 2026 Omnibus, Financial institutions remain in scope of the CSDDD for their own operations, subsidiaries, and the upstream part of their chain of activities — but the downstream financial activities (lending, investment) are not covered. The review of whether to extend obligations to downstream financial activities was removed entirely.
Without expressing an opinion on the exclusion that was found suitable for due diligence of financial institutions on human rights and environmental risks, we think it will be agreed that such an exclusion cannot stand should a financial institution be expected to avoid and mitigate terror financing and related integrity risks that are embedded in its correspondent banking activities.
In many respects, the CS3D implements principles originally developed in the United Nations Guiding Principles on Business and Human Rights, and in the OECD Due Diligence Guidance for Responsible Business Conduct.
The same as the Corporate Sustainability Due Diligence Directive (CS3D) focuses on environmental and human-rights risks, the framework for Correspondent Banking Due Diligence should focus on:
- terrorism financing;
- sanctions evasion;
- proliferation financing;
- and state-sponsored illicit finance.
Financial Institutions should be required to follow the six-step due-diligence methodology of CS3D and of course apply it on both upstream part as well as downstream part of their chain of correspondent activities:
- identify elevated correspondent-banking risks;
- map high-risk portions of their correspondent network;
- conduct enhanced due diligence;
- implement mitigation measures;
- periodically reassess effectiveness;
- provide periodic public disclosure/due-diligence statement.
A due-diligence model that the EU has already embraced in another regulatory domain could provide a basis for an agreed upon Correspondent Banking Due Diligence Framework as well as disclosure methodology and periodical public statements.
Executive Order 14415: A Contemporary U.S. National-Security Analogue for Network-Based Due Diligence
Executive Order 14415 of July 20, 2026, Securing America’s Defense Supply Chains and Ensuring Domestic Acquisition of Critical Materials.
A recent development provides additional support for the methodological approach proposed in this pillar. Executive Order 14415 of July 20, 2026, addressing risks in U.S. defense supply chains, adopts a regulatory methodology that is structurally similar to the conflict-minerals due-diligence model discussed in this chapter with the suggestion to apply it to correspondent banking.
Section 3 of the E.O. – “Critical Supply Chain Mapping and Illumination”, requires prime contractors and subcontractors at any tier to map and illuminate critical supply chains, trace components toward their source, establish written procedures for proactive supplier vetting, assess specified categories of risk, implement and track mitigation measures, and report significant risks and corrective actions to the government.
Although defense procurement and correspondent banking present materially different substantive risks, the regulatory logic is comparable: where national-security risk may be transmitted through complex and opaque multi-tiered networks, effective due diligence and risk management should require entities to develop visibility beyond their immediate contractual counterparty.
Once material risks have been identified, contractors are to implement mitigation measures, track those measures until closure, notify the government of significant risks, submit written corrective-action plans and, ultimately, submit closeout reports.
The framework therefore also links mapping, inquiry, risk identification, mitigation, monitoring and governmental reporting within a continuous due diligence process. It also contemplates consequences where contractors fail to remedy identified vulnerabilities, including requirements to qualify alternative sources and the possible suspension or termination of contractual arrangements.
The Executive Order’s explicit attention to foreign ownership, control or influence is also particularly notable because it recognizes that risks associated with an apparently acceptable first-tier counterparty may originate and be concealed through indirect control relationships several layers away from the regulated entity.
To conclude this discussion on Pillar Three, we believe that the conflict-minerals regime, the CSDDD and E.O. 14415, appear together as three mutually reinforcing methodological sources that strongly support our proposal to apply the Conflict Minerals Due-Diligence and Disclosure Methodologies to Correspondent Banking.
We also believe that these Supply-Chain Due-Diligence Methodologies could be applied not just to conflict minerals, defense supply chains and Correspondent Banking but also to other areas where the structural nature of risk justifies the methodological convergence we suggest here for correspondent banking.
Pillar Four: Expanding the Role of External Auditors
The auditor’s current role in AML/CFT compliance is largely indirect – auditors assess internal controls over financial reporting, which may include AML/CFT program controls, but there is no distinct, direct and explicit obligation to assess, opine on, or report to regulators about a client’s financial-integrity risk exposure or correspondent banking due diligence adequacy. This is a gap that could be bridged.
Auditors have unique access to the information required to assess correspondent banking risks – transaction data, relationship documentation, internal compliance assessments and management decisions.
Also, their independence, legal liability, and professional standards create accountability mechanisms that internal compliance functions lack. Expanding auditor duties to include specific attestation on correspondent banking risk management and mandatory reporting of material deficiencies would narrow a monitoring gap that currently allows systemic weaknesses to persist.
Existing professional responsibilities of the external auditor already include various obligations regarding illegal acts that have or may have occurred and came to the auditor’s attention.
We argue that possible integrity violations via correspondent banking activity that exposes the Financial Institutions to sanctions evasion, proliferation financing and terror financing, are also covered – even if not explicitly – under those responsibilities, and should be systematically applied.
This can be found on PCAOB SPOTLIGHT Auditor Responsibilities for Detecting, Evaluating, and Making Communications About Illegal Acts November 2024
The spotlight is not a new auditing standard; PCAOB expressly states that it represents staff views and is not a rule, policy, or Board statement. Rather, it consolidates and explains existing obligations, principally under Exchange Act §10A and PCAOB AS 2405 Illegal Acts by Clients:
First, The PCAOB describes a sequence of the auditor responsibilities:
1) detect → 2) evaluate → 3) determine whether an illegal act likely occurred → 4) communicate.
Under §10A, once information indicating a possible illegal act comes to the auditor’s attention, the evaluation obligation applies whether or not the act is initially perceived to have a material financial-statement effect.
Second – and particularly relevant to sanctions, terrorist financing and correspondent banking – the Spotlight distinguishes direct-effect illegal acts from illegal acts having an indirect effect on the financial statements. For the latter, if specific information comes to the auditor’s attention indicating a possible illegal act that could have a material indirect financial-statement effect, AS 2405 requires procedures specifically directed toward determining whether an illegal act occurred.
Third, the PCAOB gives considerable substance to what this can mean operationally. Auditors may obtain information from management, audit committees, legal counsel and internal audit, review regulatory filings, and examine regulatory correspondence, electronic payment support, contracts and other documentation
Fourth, materiality is not exclusively quantitative. Spotlight expressly says that auditors consider both quantitative and qualitative factors. It gives the example that an illegal payment that is itself financially immaterial can nevertheless become material because it may lead to a material contingent liability or material loss of revenue. An illegal act may also affect the reliability of management representations and the effectiveness of ICFR (Internal Control Over Financial Reporting).
This argument becomes stronger if the underlying violation would be either directly or indirectly related to sanctions evasion, proliferation financing and terror financing.
Fifth, once an illegal act has come to the auditor’s attention, AS 2405.17 requires the auditor to ensure that the audit committee is adequately informed as soon as practicable and before issuance of the audit report, except for matters that are clearly inconsequential.
Section 10A creates a further escalation mechanism if the act materially affects the financial statements, management/board fails to take timely appropriate remedial action, and that failure is expected to warrant a modified report, or even resignation.
The position adopted in this article might raise high criticism. Future discussion should therefore examine whether auditors should be explicitly required, as we recommend, to the following:
- Explicitly assess correspondent banking governance frameworks;
- Evaluate material financial-integrity risks and specifically those embedded in correspondent banking activities exposing the FI to sanctions evasion, terror financing and proliferation financing;
- Review sanctions-risk management controls and provide periodical attestation regarding key risk-management processes including those that should address the unique risks embedded in correspondent banking activity;
- Report significant deficiencies to regulators under defined circumstances.
Pillar Four should not be framed simply as creating an entirely new auditor responsibility. The objective is not to transform auditors into law-enforcement agencies. Rather, it is to leverage an existing key player that already possesses access, expertise, independence, and accountability mechanisms.
Pillar Five: Full Utilization of Existing CISADA Section 104(e) Authorities
Among the numerous authorities available to U.S. regulators, few illustrate the gap between legal capability and practical deployment more clearly than Section 104(e) of the Comprehensive Iran Sanctions, Accountability, and Divestment Act of 2010 (CISADA), that was designed as a proactive information-gathering and risk-management tool directed at correspondent banking relationships.
Section 104(e) was enacted against the backdrop of growing concerns that Iranian financial institutions were using correspondent banking relationships and third country intermediary financial networks to gain indirect access to the international financial system despite expanding sanctions, including via different executive orders.
The provision established a mechanism through which the U.S. Department of the Treasury, acting through FinCEN, could require U.S. financial institutions maintaining correspondent accounts for foreign banks to obtain information concerning those foreign institutions’ possible relationships with designated Iranian entities and related actors and if they have possibly processed transactions involving such entities.
Unlike traditional sanctions enforcement, Section 104(e) does not depend primarily on regulators detecting violations independently. Instead, it leverages the compliance infrastructure of correspondent banks themselves to generate information regarding high-risk relationships, as the most valuable information often resides not with regulators but with the financial institutions themselves.
By leveraging the compliance infrastructure of correspondent banks, regulators gain visibility into networks that would otherwise remain opaque.
In effect, Congress created a mechanism that transformed correspondent banks into force multipliers for financial intelligence collection. Yet, despite its potential reach, the provision has remained largely underutilized within broader sanctions-enforcement strategy.
The issue is not legal authority. The legal infrastructure remains intact. FinCEN’s implementing regulations exist. The reporting mechanism exists and remains available. The framework itself is operational.
The issue is deployment and sanctions policies. A more systematic implementation strategy could provide regulators with significantly greater visibility into correspondent relationships involving jurisdictions, institutions, and actors associated with elevated sanctions-evasion, terrorism-financing, and proliferation-financing risks.
The challenge moving forward is to ensure that these authorities become operational tools rather than dormant legal capabilities. It does require also fully implementing existing regulatory authorities and frameworks that were established to apply the core policy concept underlying Section 104(e) of CISADA:
In the summer of 2016, following the entry into force of the JCPOA, the U.S. Department of the Treasury and four major federal financial regulatory agencies issued a joint policy statement that specifically and comprehensively articulated federal policy regarding correspondent banking services in light of U.S. sanctions regimes and the need to enforce anti-money laundering (AML) and counter-terrorist financing (CFT) requirements.
In addition, the New York State financial regulator issued sector-specific correspondent banking regulations that became effective in January 2017. These regulations, among other things, require financial institutions to establish transaction monitoring and filtering compliance programs designed specifically to address vulnerabilities inherent in correspondent banking relationships, and to certify annually that such programs are reasonably designed to comply with applicable AML and sanctions requirements.
As Pillar 4 discussing the role and limits of responsibilities of the external auditor, it is important to notice the explicit requirement of the DFS for an independent audit that should periodically assess the transaction monitoring and filtering compliance programs, as mandated by the NY supervisory authority.
(U.S. Department of the Treasury and Federal Banking Agencies Joint Fact Sheet on Foreign Correspondent Banking: Approach to BSA/AML and OFAC Sanctions Supervision and Enforcement (June 2016)
(FDIC, Federal Reserve, OCC, NCUA, and Treasury Department)
(New York State Department of Financial Services (DFS), Superintendent’s Regulations, Part 504, Banking Division: Transaction Monitoring and Filtering Program Requirements and Annual Certification)
A broader approach to be considered:
The policy concept embedded in Section 104(e) has broader applicability: leveraging the information that could be held by correspondent institutions themselves to reduce risks that would otherwise remain obscured.
Future policymakers might therefore consider whether the underlying logic of Section 104(e) could analogically be adapted to other high-risk jurisdictions, sanctions programs, and financial-integrity concerns.
Such an approach would represent a desirable use of existing legal authority available to U.S. regulators. As long as it is regarding Iran, it would do so without requiring new legislation, major regulatory restructuring, or additional secondary sanctions. With respect to other jurisdictions, appropriate adjustments will be required in accordance with the applicable law.
Pillar Six: Reassessing The Role of the Knowledge Standard in Sanctions Frameworks
The “knowing liability standard” has long constituted one of the defining legal principles underpinning the implementation of U.S. sanctions policy. It is embedded in numerous statutory and regulatory authorities, including the Comprehensive Iran Sanctions, Accountability, and Divestment Act of 2010 (CISADA), the Countering America’s Adversaries Through Sanctions Act (CAATSA), and other sanctions legislation, and is reflected in several Executive Orders addressing terrorism, proliferation financing, and national security threats, including Executive Orders 13224 and 13382.
Collectively, these authorities have established a legal framework under which the imposition of secondary sanctions has, in many cases, depended upon a determination that a foreign financial institution or other non-U.S. person knowingly engaged in, facilitated, or provided significant support for prohibited activities.
Secondary sanctions have evolved over the years into one of the major deterrence instruments used by the United States to shape the conduct of foreign financial institutions operating beyond its territorial jurisdiction. Their effectiveness derives not only from the legal consequences they impose, but also from the central role of the U.S. dollar, the importance of correspondent banking relationships, and the indispensable access that foreign institutions seek to maintain to the U.S. financial system.
However the rapid evolution of sanctions-evasion methodologies has increasingly exposed the limitations of a legal framework that places substantial emphasis on demonstrating actual or constructive knowledge: Modern sanctions-evasion networks deliberately employ multi-layered ownership structures, shell companies, nominee shareholders, offshore jurisdictions, front companies, complex trade-finance arrangements, and nested correspondent banking relationships, specifically to obscure the identity of the ultimate parties involved. As these structures become more sophisticated, proving that a financial institution is possessing the requisite level of knowledge becomes progressively more difficult.
This challenge is particularly acute in correspondent banking. By its nature, correspondent banking requires institutions to process transactions originating from other regulated financial institutions, often several steps from the underlying customer or beneficial owner. The informational asymmetry inherent in these relationships makes the knowledge standard increasingly difficult to apply while simultaneously creating opportunities for sophisticated sanctions-evasion networks to exploit the resulting evidentiary burden.
Recent developments in U.S. sanctions policy suggest a gradual convergence toward a more risk-oriented approach. Executive Order 14114, addressing foreign financial institutions facilitating transactions connected to Russia’s military-industrial base, illustrates an increasing willingness to focus regulatory attention on the objective consequences of facilitating high-risk transactions rather than relying on concepts of actual knowledge.
While this evolution remains limited to a specific sanction program, it reflects that the legal and regulatory framework governing secondary sanctions can adapt to changing circumstances and emerging national-security priorities and apply a strict liability standard if suitable.
With this regard, and with a methodological linkage to our discussion under Pillar Eight on OFAC’s 50 percent rule, it should be noted that under existing OFAC’s rule, an entity owned 50 percent or more, directly or indirectly, by one or more SDN-listed persons is itself blocked, regardless of whether the entity appears on the SDN List. It will be without additional preconditions. In our understanding – an explicit strict liability.
The significance of the development introduced by EO 14114, extends beyond Russia and might reflect a broader policy principle. This principle appears particularly relevant in the context of terrorism financing, proliferation financing, and sanctions-evasion activities involving jurisdictions with extensive histories of deceptive financial practices.
Extending similar concepts to selected categories of Iran-related activity could significantly alter the incentives governing correspondent banking relationships.
Financial institutions would have stronger incentives to conduct enhanced due diligence, improve beneficial ownership analysis, strengthen transaction-monitoring and sanctions-screening systems, and reduce exposure to elevated-risk counterparties.
The objective is not to impose strict liability for innocent mistakes. The objective is to ensure that financial institutions cannot rely upon information gaps when operating in environments characterized by well-documented financial-integrity risks.
The suggested shift would not neglect knowledge standards entirely. Rather, it would recalibrate them for circumstances where the systemic risks are greatest.
Pillar Seven: Terrorism-Financing and Sanctions-Risk Capital Buffer
This strategic Pillar introduces our proposal to establish in the banking sector an explicit prudential capital framework for terrorism-financing and sanctions-risk.
The comprehensive analysis of this proposal includes legal, regulatory, methodological and financial aspects, as well as a technical demonstration for possible implementation.
The proposal is a prudential safety-and-soundness measure, grounded in existing supervisory authority and fully consistent with Basel III principles, the legal authorities of the Federal Reserve, FDIC (Federal Deposit Insurance Corporation), and OCC (the Comptroller of the Currency); and the increasing recognition by international financial institutions that AML/CFT failures can threaten systemic stability.
The proposal does not seek to transform prudential capital regulation into a foreign-policy or sanctions-enforcement instrument. Rather, it recognizes that severe financial-integrity failures, including sanctions violations, terrorism-financing exposure, proliferation financing and systemic AML/CFT deficiencies – generate material operational, legal, liquidity, funding, contagion, and systemic risks that may not be adequately captured under current capital methodologies.
We suggest that the Terrorism-Financing, Sanctions-Evasion and Illicit-Finance Risk Capital Buffer be generally designed in a tiered, at least two-layer architecture, that matches the level of analytical complexity to the scale of the institution and the materiality of the risk.
The framework should be no more complex than necessary to achieve its deterrence and loss-absorption objectives and should impose no burden on institutions whose financial-integrity risk exposure is genuinely low.
The tiered architecture we offer includes:
A standardized floor calculated from objective, observable exposure metrics. This formula measures for example: active correspondent connections in FATF-monitored regions, clearing links with past enforcement exposure, repeated enforcement history and trade-finance tranches crossing high-risk activities.
The full research paper on the suggested capital buffer discusses the details of the second layer – a dynamic supervisory add-on evaluated during the standard examination cycle where examiners would rate the transaction filtering systems, compliance infrastructure, internal governance metrics etc.
For the largest banks, a dedicated stress scenario overlay is discussed as well. We leave its specific design to regulatory authorities’ discretion to be fully integrated with supervisory methodological approaches that are being considered these very days and are referred to in the full analysis.
Methodological background:
The prudential supervision methodology governing modern banking recognizes that capital requirements shape business conduct more effectively than many forms of ex-post enforcement.
Financial Institutions respond strongly to capital requirements and devote enormous resources to managing capital because capital directly affects profitability, growth capacity, shareholder returns, and supervisory assessments. For these reasons, board of directors closely monitor regulatory capital requirements, senior management consider those requirements daily, Investors analyze and price them, and supervisors enforce them.
Current capital frameworks recognize credit risk, market risk, operational risk, liquidity risk, and systemic risk. Yet, financial-integrity risk remains largely absent as an independent, distinct, prudential category, though major sanctions violation, terrorism-financing enforcement action, or correspondent banking compliance failure can generate losses measured in billions of dollars, trigger severe reputational damage, restrict business activities, and impair economic value.
The proposal is not the creation of an entirely new capital regime but builds upon existing prudential concepts and the greater use of existing supervisory authorities under Basel frameworks to currently assess whether an institution’s exposure to elevated terrorism-financing and sanctions-evasion risks warrant additional capital requirements.
The objective is incentive alignment and not punishment. When financial-integrity risk carries a capital cost, institutions begin managing that risk through the same rigorous processes used for credit, market, liquidity, and operational risks:
Compliance would become a capital-management issue rather than solely a regulatory obligation. In other words, compliance would cease to function solely as a cost center and could become a component of capital optimization.
Internal capital adequacy assessments would require explicit formal consideration of financial-integrity risks and thus, would add a substantial layer to the internal control processes.
Institutions would gain a direct financial incentive to reduce exposure to higher-risk correspondent relationships. Most importantly, deterrence would become continuous, as capital requirements shape institutional decision-making and influence business conduct every day.
This proposed Terrorism-Financing and Sanctions-Risk Capital Buffer should not remain solely a domestic prudential initiative within the United States. Given the inherently cross-border nature of terrorism financing, sanctions-evasion networks, illicit trade finance, correspondent banking activity, offshore settlement structures, and alternative payment systems, the effectiveness of any enhanced prudential framework will depend significantly on broader international adoption and supervisory convergence.
Pillar Eight: Expanding OFAC’s 50 Percent Rule and Ownership Transparency
The final pillar addresses a significant structural weakness in sanctions implementation.
OFAC’s 50 Percent Rule provides that any entity owned 50 percent or more, directly or indirectly, by one or more SDN-listed persons is itself blocked, regardless of whether the entity appears on the SDN List. For correspondent banks, this rule requires not merely SDN list screening but beneficial ownership analysis of counterparties – an obligation that extends through nested correspondent chains and creates significant operational complexity for institutions processing large volumes of cross-border transactions.
The current 50 Percent Rule successfully addresses downstream sanctions circumvention but leaves a significant upstream ownership gap. Extending sanctions scrutiny to entities that own 50 percent or more of an SDN-listed entity would better align sanctions policy with economic reality, require enhanced and more comprehensive due-diligence, reduce opportunities for regulatory arbitrage, strengthen deterrence, and enhance the effectiveness of U.S. sanctions programs.
The basic rationale to this recommendation is that Ownership interests are designed to generate economic returns. A parent company holding a majority interest in a sanctioned subsidiary typically benefits from dividends, capital appreciation, management fees, intra-group financing arrangements, or other forms of value transfer. Even where such transfers are suspended, the parent retains a residual economic interest in the sanctioned enterprise.
The current framework creates incentives for sanctioned actors to preserve access to international markets through non-designated parent companies. A sanctioned subsidiary can be isolated while its parent company continues to obtain financing, insurance, trade credit, investment, and correspondent banking services. This may undermine the intended economic pressure of sanctions and expose a financial institution providing correspondent services to indirect sanctions violation.
Majority ownership generally conveys significant governance rights, including board appointments, strategic direction, approval of budgets, and oversight of management. Even where a parent company claims no involvement in sanctionable conduct, its ownership position creates the possibility of influence over the sanctioned subsidiary’s operations.
Financial institutions frequently face difficulty determining whether a non-designated parent is genuinely independent from a sanctioned subsidiary. Complex corporate structures, nominee arrangements, offshore holding companies, and opaque ownership chains can conceal continuing relationships. Extending sanctions scrutiny to majority owners would reduce opportunities for exploitation of such opacity.
Ownership opacity remains central to terrorism financing, sanctions evasion, proliferation financing, corruption, and transnational money laundering. Any comprehensive effort to strengthen correspondent banking integrity must therefore address ownership transparency as a fundamental requirement.
International Perspective
The proposed expansion of OFAC’s 50 Percent Rule would also move the U.S. sanctions framework closer to the broader ownership-and-control approach adopted by the European Union. Unlike the U.S. regime, which generally applies an objective ownership threshold whereby entities owned 50 percent or more by one or more designated persons, the EU sanctions framework places greater emphasis on the broader concept and characteristics of “control”.
Under EU guidance, an entity may be regarded as subject to sanctions where a designated person exercises decisive influence over his activities, even in the absence of majority ownership, based on factors such as governance rights, the ability to appoint management, or other forms of effective control.
We believe that modern sanctions enforcement should indeed evolve from a formal ownership paradigm toward an economic reality paradigm. That is, becoming less concerned with the legal form of ownership and increasingly concerned with who ultimately exercises economic influence, control, or receives the economic benefit while remaining outside the sanction’s perimeter.
The proposal advanced in this article does not seek at this stage to replace the U.S. ownership threshold with the EU control model. It focuses on extending scrutiny to majority owners of designated entities, thereby complementing the existing downstream ownership rule and reducing opportunities for regulatory arbitrage through upstream ownership structures.
Yet, we believe that such a methodological gap could be bridged to avoid regulatory arbitrage. It does require a thorough discussion we hope will be possible to achieve that important coordination.
European Commission, Consolidated FAQs on EU Restrictive Measures (Sanctions) (ownership and control guidance)
5. Conclusion: Toward a New Financial-Integrity Architecture for Protecting Correspondent Banking Against Illicit Finance
This article introduces an integrated financial-integrity framework designed to strengthen correspondent banking resilience against terrorism financing, sanctions evasion, proliferation financing, and other forms of illicit finance.
Collectively, the eight pillars seek to complement the existing enforcement architecture with additional mechanisms based on transparency, market discipline, independent oversight, prudential incentives, and more systematic deployment of existing legal authorities.
These measures are intended to distribute responsibility for financial integrity across the broader governance ecosystem, engaging regulators, financial institutions, boards of directors, external auditors, shareholders, investors, and other market participants in a continuous process of risk identification and mitigation.
The need for such a multidimensional framework becomes relevant considering the possibility that future sanctions-relief arrangements involving Iran as example, may substantially increase financial flows through the international correspondent banking system.
Any meaningful relaxation of sanctions should therefore be accompanied by a corresponding strengthening of the financial-integrity safeguards governing the channels through which those funds will move. The effectiveness of sanctions relief should not be measured solely by its economic or diplomatic objectives, but also by the ability of the international financial system to distinguish legitimate commercial activity from transactions involving terrorism financing, sanctions evasion, proliferation financing, and other illicit conduct.
The proposals presented in this article are intended to serve as the basis for a broader research agenda. Each of the eight pillars raises important legal, supervisory, financial, operational, and international policy questions that warrant detailed examination. Collectively, these future studies would contribute to the development of a more resilient correspondent banking framework capable of supporting legitimate international commerce while significantly reducing the opportunities for abuse by illicit financial networks.
Notes
Fundamental Correspondent Banking Authorities
- Financial Action Task Force (FATF), Recommendation 13 (Correspondent Banking).
- FATF, International Standards on Combating Money Laundering and the Financing of Terrorism and Proliferation.
- FATF Guidance on Correspondent Banking Services (2016). The 2016 FATF Guidance clarifies the application of the risk-based approach to Anti-Money Laundering and Counter-Terrorist Financing (AML/CFT). It explicitly states that correspondent banks are not required to perform Customer Due Diligence (CDD) on the individual customers of their respondent institutions, curbing the practice of indiscriminate “de-risking”.
- Basel Committee on Banking Supervision, Sound Management of Risks Related to Money Laundering and Financing of Terrorism (2020).
- Basel Core Principles for Effective Banking Supervision (2024 revision).
Terrorism Financing and Proliferation Financing
- United Nations Security Council Resolution 1373 (2001).
- United Nations Security Council Resolution 2462 (2019).
- FATF Guidance on Terrorist Financing Risk Assessment.
- FATF Guidance on Counter-Proliferation Financing.
Iran and Sanctions Framework
- Comprehensive Iran Sanctions, Accountability, and Divestment Act of 2010 (CISADA).
- Iran Threat Reduction and Syria Human Rights Act of 2012 (ITRA).
- Countering America’s Adversaries Through Sanctions Act (CAATSA).
- International Emergency Economic Powers Act (IEEPA).
- Executive Order 13224 (terrorism sanctions).
- Executive Order 13902 (Iranian economy sanctions).
- Executive Order 14114 (Russia-related secondary sanctions framework).
- Executive Order 13382 (“Blocking Property of Weapons of Mass Destruction Proliferators and Their Supporters”).
Disclosure and Market Discipline / ITRA Disclosure Expansion
- Securities Exchange Act of 1934.
- Exchange Act Section 13(r).
- ITRA Section 219.
- SEC Final Rule implementing Section 219 of ITRA.
- Financial Stability Board, Enhancing Market Discipline and Risk Transparency.
Conflict Minerals Framework
- Dodd-Frank Wall Street Reform and Consumer Protection Act, Section 1502.
- SEC Conflict Minerals Rule.
- OECD Due Diligence Guidance for Responsible Supply Chains of Minerals from Conflict-Affected and High-Risk Areas.
- Regulation (EU) 2017/821 (EU Conflict Minerals Regulation).
- Directive (EU) 2026/470 of the European Parliament and of the Council of 24 February 2026 amending Directives 2006/43/EC, 2013/34/EU, (EU) 2022/2464 and (EU) 2024/1760 as regards certain corporate sustainability reporting requirements and certain corporate sustainability due diligence requirements (OJ L, 2026/470, 26.2.2026).
Auditor Accountability
- PCAOB AS 2110 (Identifying and Assessing Risks of Material Misstatement).
- PCAOB AS 2405 (Illegal Acts by Clients).
- PCAOB Release No. 2023-003.
- International Standard on Auditing (ISA) 250.
- International Standard on Auditing (ISA) 315.
- International Standard on Assurance Engagements (ISAE) 3000.
(ISAE 3000 (International Standard on Assurance Engagements 3000) is the globally recognized standard for independent audits of non-financial information. Issued by the IAASB)
CISADA Section 104(e)
- CISADA Section 104(e).
- FinCEN Final Rule Implementing CISADA Section 104(e).
CISADA; 31 CFR §1060.300; FinCEN (U.S. reporting obligations regarding foreign bank relationships with Iranian-linked financial institutions and IRGC-linked persons designated under IEEPA. US banks that maintain correspondent accounts for specified foreign banks must collect and report specific information, such as fund transfers and account ownership, within 45 days of a written FinCEN request.) - FinCEN Information Collection Renewal Notices (2022 and subsequent renewals).
- U.S. Department of the Treasury and Federal Banking Agencies Joint Fact Sheet on Foreign Correspondent Banking: Approach to BSA/AML and OFAC Sanctions Supervision and Enforcement (June 2016) (FDIC, Federal Reserve, OCC, NCUA, and Treasury Department)
- New York State Department of Financial Services (DFS), Superintendent’s Regulations, Part 504, Banking Division: Transaction
Prudential Capital Framework
- Basel III Framework.
- Basel Pillar 2 Supervisory Review Process.
- Federal Deposit Insurance Act Safety-and-Soundness Authorities.
- Dodd-Frank Act Section 165.
Ownership Transparency
- OFAC Revised Guidance on Entities Owned by Persons Whose Property and Interests in Property are Blocked (50 Percent Rule).
- “Expansion of End-User Controls to Cover Affiliates of Certain Listed Entities,” Department of Commerce September 29, 2025
- FATF Recommendation 24 (Beneficial Ownership).
- FinCEN Beneficial Ownership Reporting Framework.
Reassessing Knowledge Standards in Secondary Sanctions enforcement
- IEEPA; CISADA; CAATSA; EO 14114
Appendix A
Institutions Relevant to Future Development of the Eight Pillars
United States
- U.S. Department of the Treasury
- Financial Crimes Enforcement Network (FinCEN)
- Office of Foreign Assets Control (OFAC)
- Federal Reserve Board
- Office of the Comptroller of the Currency (OCC)
- Federal Deposit Insurance Corporation (FDIC)
- Securities and Exchange Commission (SEC)
- Public Company Accounting Oversight Board (PCAOB)
- Congressional Banking and Financial Services Committees
International Bodies
- Financial Action Task Force (FATF)
- Basel Committee on Banking Supervision (BCBS)
- Financial Stability Board (FSB)
- International Monetary Fund (IMF)
- World Bank
- Organization for Economic Co-operation and Development (OECD)
- International Organization of Securities Commissions (IOSCO)
- International Auditing and Assurance Standards Board (IAASB)
Private-Sector Stakeholders
- Global Correspondent Banks
- Regional Correspondent Banking Networks
- External Audit Firms
- Credit Rating Agencies
- Export Credit Agencies
- Trade-Finance Providers
- Institutional Investors
- Securities Exchanges
Footnotes
Avi Vishnevich is a former Deputy Supervisor of Banks at the Bank of Israel, and currently a Senior Research Fellow at CENTEF, the Center for Research of Terror Financing (www.centef.org). CENTEF is a global research institute dedicated to advancing the understanding of terror financing and its impact worldwide. Mr. Vishnevich can be reached at avi@centef.org.