Skip to main content
Category: AML and KYC

Wolfsberg Principles

Also known as: Wolfsberg Group frameworks and guidance, Wolfsberg Anti-Money Laundering Principles
Simply put

The Wolfsberg Principles are a set of frameworks and guidance developed by the Wolfsberg Group, an association of global banks, to help financial institutions manage financial crime risks. They address areas such as anti-money laundering, sanctions, counter-terrorist financing, corruption, and other financial crime concerns. They are industry guidance rather than a mandatory regulatory standard.

Formal definition

The Wolfsberg Principles refer to the body of frameworks, guidance, and standardized tools issued by the Wolfsberg Group, an association of 12 global member banks focused on the management of financial crime risks including anti-money laundering (AML), sanctions, counter-terrorist financing (CTF), anti-corruption, and broader financial crime. The Group's outputs include practitioner tools such as the Correspondent Banking Due Diligence Questionnaire (CBDDQ), the Financial Crime Compliance Questionnaire (FCCQ), accompanying guidance, glossary, and FAQs, with versioned releases (for example, CBDDQ version 1.4 announced February 10, 2023). These principles constitute voluntary industry guidance and are distinct from payment security standards such as PCI DSS; practitioners should confirm scope and applicability against the current published Wolfsberg materials.

Why it matters

Financial institutions face persistent pressure to manage money laundering, sanctions, counter-terrorist financing, corruption, and broader financial crime risks, particularly where cross-border relationships introduce exposure that a single institution cannot assess in isolation. The Wolfsberg Principles matter because they provide industry-developed frameworks and standardized tools that help institutions approach these risks in a more consistent way. Because they are produced by an association of global member banks rather than a regulator, they reflect practitioner experience and can serve as common reference points across institutions that must interact with one another.

Standardized tools such as the Correspondent Banking Due Diligence Questionnaire (CBDDQ) address a specific and long-standing challenge: gathering comparable due diligence information across correspondent banking relationships. When many institutions use the same questionnaire format, the effort of collecting and reviewing counterparty information can be reduced, and comparisons across counterparties can become more meaningful. This is intended to help institutions manage financial crime risk in relationships where they rely on information provided by other banks.

It is important to recognize what the Wolfsberg Principles are not. They are voluntary industry guidance, not a mandatory regulatory standard, and adoption of a Wolfsberg tool does not by itself satisfy any particular legal or regulatory obligation. They are also distinct from payment security standards such as PCI DSS, which governs the protection of cardholder data. Institutions should confirm scope and applicability against the current published Wolfsberg materials and against the regulatory requirements that apply to them.

Who it's relevant to

Financial Crime and AML Compliance Teams
Teams responsible for anti-money laundering, sanctions, and counter-terrorist financing programs use Wolfsberg frameworks and tools as reference points for structuring due diligence and risk assessment. They should treat the Principles as voluntary industry guidance that complements, rather than substitutes for, their institution's regulatory obligations.
Correspondent Banking and Onboarding Teams
Teams managing correspondent banking relationships may rely on standardized tools such as the CBDDQ to collect comparable due diligence information across counterparties. Because the questionnaire is versioned, these teams should confirm they are using the current published release.
Financial Crime Risk and Governance Functions
Risk and governance functions overseeing financial crime exposure, including corruption and broader financial crime, can use Wolfsberg guidance to inform consistent internal approaches. They should assess how these voluntary frameworks align with applicable legal and supervisory requirements in their jurisdictions.
Vendors and Practitioners Adjacent to Payment Security
Professionals working across payment security and financial crime should note that the Wolfsberg Principles govern financial crime risk management and are distinct from payment security standards such as PCI DSS. Applying the correct framework to the correct risk domain avoids conflating unrelated requirements.

Inside Wolfsberg Principles

Anti-Money Laundering (AML) Guidance
The Wolfsberg Principles are a set of non-binding guidelines developed by a group of global banks to help manage money laundering, terrorist financing, and related financial crime risks. They are advisory in nature rather than a regulatory standard, and they do not carry the enforcement mechanisms of law or of card brand rules.
Know Your Customer (KYC) and Customer Due Diligence
The principles emphasize identifying and verifying customer identity, understanding the nature of customer relationships, and applying risk-based due diligence. This is distinct from payment card authentication controls such as EMV chip authentication or 3-D Secure, which address transaction-level identity assurance rather than customer onboarding integrity.
Risk-Based Approach
Wolfsberg guidance promotes allocating monitoring and due diligence effort according to assessed risk of a customer, product, or geography. It is intended to help prioritize resources and may reduce exposure to illicit activity, but it does not guarantee detection of all suspicious behavior.
Transaction Monitoring and Suspicious Activity Reporting
The principles address ongoing monitoring of activity to identify patterns that may indicate money laundering or other financial crime. Such monitoring involves false-positive and false-negative trade-offs, and thresholds must be tuned; the guidance frames expectations rather than prescribing specific technical rules.
Correspondent Banking and Third-Party Risk
Certain Wolfsberg publications focus on risks arising from correspondent banking relationships and reliance on third parties, encouraging assessment of the counterparty's own controls. This is a financial-institution relationship concern separate from PCI DSS scope, which concerns the protection of cardholder data environments.

Common questions

Answers to the questions practitioners most commonly ask about Wolfsberg Principles.

Are the Wolfsberg Principles a component of PCI DSS or a payment card security standard?
No. The Wolfsberg Principles are anti-money laundering (AML) and financial crime guidance developed by the Wolfsberg Group, an association of global banks. They are separate from PCI DSS and the other PCI standards such as PA-DSS, the PCI Software Security Framework, PCI PIN, PCI P2PE, and PCI 3DS. PCI DSS governs the protection of cardholder data and sensitive authentication data in payment card environments, while the Wolfsberg Principles address correspondent banking, AML, sanctions, and related financial crime risk. A term or expectation from one framework should not be assumed to apply to the other; confirm which framework governs a given control before relying on it.
Do the Wolfsberg Principles carry the force of regulation and guarantee AML compliance if followed?
No. The Wolfsberg Principles are industry guidance and are not themselves law or regulation. Adopting them is intended to help institutions structure financial crime risk controls, but it does not by itself satisfy any specific legal or regulatory obligation, which vary by jurisdiction. Following the Principles may support a control framework, but it does not guarantee AML compliance or prevent financial crime. Institutions remain responsible for meeting the applicable laws and regulatory expectations in each region where they operate, which change over time and should be confirmed against current sources.
How should an institution use the Wolfsberg Principles alongside its existing PCI DSS obligations?
Treat them as addressing different risk domains that may coexist in the same organization. PCI DSS scoping focuses on systems that store, process, or transmit cardholder data, with specific handling rules distinguishing cardholder data from sensitive authentication data. The Wolfsberg Principles inform AML and financial crime governance. Map each framework to the relevant teams and controls separately, and avoid assuming that satisfying one addresses the other. Where they touch shared systems, document how each set of requirements applies so that scope and accountability remain clear.
Which internal functions typically own responsibility for applying the Wolfsberg Principles?
Ownership generally sits with AML, financial crime, compliance, and correspondent banking risk functions rather than with payment card security or PCI DSS compliance teams. Because the Principles address customer due diligence, sanctions, and related financial crime concerns, the responsible teams differ from those handling cardholder data protection. Coordination across functions may be needed where data or systems overlap, but the primary accountability should be assigned to the functions that manage financial crime risk.
How can an institution keep its use of the Wolfsberg Principles current?
Because the Wolfsberg Group periodically publishes and revises guidance, institutions should confirm they are referencing the current published version rather than assuming a fixed edition. Regulatory expectations that intersect with the Principles also change and vary by region. A periodic review process that checks the latest published guidance against internal policies helps keep AML and financial crime controls aligned, but any specific version, date, or requirement should be verified against the original source rather than relied on from memory.
What are the limitations of relying on the Wolfsberg Principles as guidance?
The Principles are intended to support financial crime risk management, but they are non-binding guidance and do not replace applicable law, regulation, or an institution's own risk assessment. They do not eliminate financial crime risk, and their effectiveness depends on how an institution implements, tailors, and validates the underlying controls. They also do not address payment card data protection, which is governed by PCI DSS and related PCI standards. Institutions should treat the Principles as one input into a broader control framework rather than as a complete or self-sufficient solution.

Common misconceptions

The Wolfsberg Principles are a PCI standard or otherwise part of payment card security compliance such as PCI DSS.
The Wolfsberg Principles are AML and financial crime guidance produced by a banking group, and they are separate from PCI DSS, PA-DSS, the PCI Software Security Framework, PCI PIN, PCI P2PE, and PCI 3DS. They do not govern the protection of cardholder data or sensitive authentication data, and compliance with one does not imply compliance with the other.
Following the Wolfsberg Principles guarantees prevention of money laundering or fraud.
The principles are intended to help reduce and manage financial crime risk through a risk-based approach, but they do not guarantee prevention. Detection controls carry inherent false-positive and false-negative trade-offs, and no single framework eliminates money laundering, terrorist financing, or fraud.
The Wolfsberg Principles are legally binding regulations that firms must follow.
They are voluntary, non-binding guidance and industry good-practice statements rather than law or network rules. Actual legal obligations depend on applicable jurisdictional regulation, which varies by region and changes over time, and should be confirmed against the relevant authoritative source.

Best practices

Treat the Wolfsberg Principles as complementary AML guidance, and maintain your PCI DSS and card-data protection controls as a separate program governed by the current published PCI standards.
Apply a documented risk-based approach to customer due diligence and monitoring, prioritizing higher-risk customers, products, and geographies while acknowledging that no threshold eliminates all suspicious activity.
Tune transaction monitoring to balance false-positive and false-negative trade-offs, and periodically review alert thresholds against observed outcomes rather than assuming static rules remain effective.
Assess counterparty and third-party controls in correspondent or partner relationships, and keep this evaluation distinct from the technical scoping of your cardholder data environment.
Confirm any legal or regulatory obligation against the applicable jurisdiction's authoritative source, since the principles themselves are non-binding and requirements vary by region and change over time.
Coordinate AML, fraud, and payment security teams so that customer due diligence, financial crime monitoring, and cardholder data protection are aligned without conflating their differing scopes and standards.