The Wolfsberg Questionnaire is a standardized due diligence questionnaire published by the Wolfsberg Group, an association of 12 member banks. Its main form, the Correspondent Banking Due Diligence Questionnaire (CBDDQ v1.4), runs 132 numbered questions across 14 sections covering financial crime controls, and is the global standard for correspondent banking due diligence.
If your institution holds or wants a correspondent relationship, you will be asked for it, and the bank asking will not accept a bespoke narrative in its place. That rigidity is the point. Because every respondent answers the same numbered questions in the same order, a correspondent can compare institutions against identical data points instead of reading a hundred different compliance essays. The Wolfsberg Group publishes the questionnaire, along with its guidance, glossary and FAQs, on its correspondent banking resources page.
There are two questionnaires in the family, and picking the wrong one wastes weeks. Here is how they differ.
| DIMENSION | CBDDQ V1.4 | FCCQ V1.2 |
|---|---|---|
| Published by | The Wolfsberg Group | The Wolfsberg Group |
| Current version and date | Version 1.4, released February 2023 | Version 1.2, released February 2023 |
| Used for | Correspondent banking relationships | Non-correspondent banking relationships |
| Typical respondent | Banks offering or seeking correspondent services | Asset managers, insurers and other financial institutions |
| Length | 132 numbered questions across 14 sections | A shorter form covering the same control themes |
| Signatories on the declaration | Two, typically the Global Head of Correspondent Banking and the MLRO or equivalent | One senior compliance representative or equivalent |
| Formats available | PDF and Excel | PDF and Excel |
| Refresh expectation | No less frequently than every 18 months per the declaration | Every 12 to 18 months per the Wolfsberg FAQs |
Both are available as PDF and Excel. Most teams work in the Excel version because it can be routed, filtered and diffed against last year's answers, then produce the signed PDF at the end.

What the Wolfsberg Questionnaire actually asks
CBDDQ v1.4 is organised into 14 numbered sections followed by a declaration statement. Many of the 132 questions carry lettered sub-parts, so the real number of data points you have to supply is several times higher than the question count suggests. The sections are:
- Entity and ownership, products and services
- AML, CTF and sanctions programme, policies and procedures, and risk assessment
- Anti bribery and corruption
- KYC, CDD and EDD
- Monitoring and reporting, payment transparency, and sanctions
- Training and education, quality assurance and compliance testing, and audit
- Fraud, which was added in version 1.4
Version 1.4 was released on 10 February 2023 alongside FCCQ v1.2, Guidance v2.0, Glossary v3.0 and FAQs v3.0. The Wolfsberg Group’s publication note confirms what changed: a new Fraud section, plus new questions on whistleblower policy, virtual bank licences and the approval of the sanctions policy. If your last submission predates 2023, those are the answers that will not exist anywhere in your files.
Who signs it, and how often you have to refresh it
The CBDDQ declaration statement requires two signatures: the Global Head of Correspondent Banking or an equivalent position holder, and the MLRO, Global Head of AML, Chief Compliance Officer, Global Head of Financial Crimes Compliance or equivalent. Both certify that the answers are complete and correct to their honest belief. That is a personal attestation from two senior officers, which is why a CBDDQ cannot be treated as a routine form-fill delegated to a junior analyst.
The declaration also commits the institution to keeping the information current and updating it no less frequently than every eighteen months. The v3.0 FAQs set the recommended refresh window at 12 to 18 months, deliberately replacing the older idea of a hard expiry date, which used to cause delays whenever the expiry fell out of step with a correspondent’s own customer due diligence review cycle.
Why the Wolfsberg questionnaire is hard to keep current
The difficulty is not the questions. It is that no single person can answer them. A single CBDDQ pulls facts from legal, the business lines, financial crime compliance, sanctions, KYC operations, internal audit, training and fraud risk. Each of those owners has a different review cycle, and each answer has a shelf life. The date of your last enterprise wide risk assessment is true in March and stale in October.
Then multiply. A large bank does not fill in one CBDDQ. It fills in one per legal entity, and separate questionnaires for branches whose products, client base or control model differ materially from head office. Add the inbound side, where the same team is reviewing CBDDQs it receives from its own respondents, and the annual volume becomes a programme rather than a project.

Mapping sections to standing owners before the request arrives is the single highest-leverage change most teams make. A workable split looks like this.
| CBDDQ SECTION | WHAT IT ASKS FOR | USUAL OWNER |
|---|---|---|
| Entity and ownership | Legal name, registered address, LEI, regulator, ownership structure | Legal or corporate secretary |
| Products and services | Correspondent services, cash delivery, trade finance, virtual assets | Business line heads |
| AML, CTF and sanctions programme and policies | Programme components, prohibitions, record retention periods | Financial crime compliance |
| Anti bribery and corruption | ABC policy, mandatory training coverage, risk assessment currency | Ethics and compliance |
| Risk assessment | Enterprise wide risk assessment scope and completion dates | Risk management |
| KYC, CDD and EDD | Verification, beneficial ownership thresholds, restricted categories | KYC operations |
| Monitoring, payment transparency and sanctions | Tooling, screening lists, list update turnaround times | Sanctions and surveillance |
| Training, quality assurance and audit | Training coverage by line of defence, audit scope, findings tracking | Training and internal audit |
| Fraud | Fraud policy, dedicated team, real time monitoring, device signals | Fraud risk |
How to answer the Wolfsberg Questionnaire once and reuse it
Because the CBDDQ is standardized, almost every answer you give this cycle is an answer you will give again. The teams that handle it well stop treating each request as a writing exercise and start treating the answer set as institutional knowledge with an owner, a review date and a version history.
Build an approved answer library, not a folder of old files
Store each answer as a discrete, approved record tied to the question it answers, with a named subject matter expert and an expiry date, rather than burying it inside last year’s completed workbook. A structured content library lets you see at a glance which answers have gone stale before a correspondent does.
This is the same discipline that the Consortium for Service Innovation formalised as Knowledge-Centered Success, where knowledge is captured as a by-product of doing the work and improved every time it is reused, rather than written from scratch by whoever happens to be free. Applied to due diligence, it means the CBDDQ you complete in March makes the one you complete in October faster instead of starting the cycle over.
Route the questions that genuinely need an owner
Most of the questionnaire will match approved answers you already hold. The value of automation is not that it writes the whole thing, it is that it isolates the handful of questions that changed, and puts those in front of the right owner with a deadline. Everything else should arrive pre-filled and marked for confirmation rather than authorship.
Keep an audit trail, because two officers are signing
When the declaration is a personal attestation, the signatories need to know who supplied each answer, who approved it and when. Version history on every field turns that from an email archaeology exercise into a lookup, and it is the same record a regulator or an internal auditor will ask for later.

Before you submit
Confirm you are on v1.4 and not a copy of an older template. Check that every section-closing question about whether the answers represent all of the legal entity’s branches is answered honestly, and that any divergence is described where the questionnaire asks for it. Verify that dated answers, particularly risk assessment completion dates and list update turnaround times, are still true today. Then get both signatures, and diarise the refresh before the file leaves your hands.
RocketDocs helps financial institutions turn recurring questionnaires into reusable, approved, audit-ready content. See how teams handle DDQ completion and what the platform looks like for banking teams, or book a demo and bring your hardest questionnaire with you.
Looking for the platform behind this? See the RocketDocs platform or book a demo.