Wolfsberg Non-Bank PSP Guidance: Banking the Sector Without De-Risking

On 15 July 2026 the Wolfsberg Group published its Guidance on the Provision of Banking Services to non-bank Payment Service Providers, and it lands on a problem most financial crime teams already know by feel: the bank holds the account, but it is several parties removed from the person actually sending the money. The new Wolfsberg non-bank PSP guidance is written for the banks that provide accounts, settlement and payment-system access to fintechs, remittance firms, e-money issuers and other non-bank PSPs, and it sets out how those banks should assess and manage the financial crime risk that comes with the relationship.

The Wolfsberg Group is an association of twelve global banks that writes practitioner frameworks for managing financial crime risk. Its output is voluntary industry guidance rather than law, so it does not create a new filing or a new reporting return. What it does is define a common baseline for due diligence, payment transparency and monitoring that supervisors increasingly expect banks to be able to evidence, and it does so at the exact point where correspondent-style intermediation makes visibility hardest.

For a bank weighing whether to onboard, keep or exit a non-bank PSP, the practical question is no longer whether the risk exists. It is whether the framework can see it. This article walks the guidance from a reporting officer’s chair: what the document actually asks banks to build, where the payment-transparency obligations really sit, and how to bank the sector without reaching for a blanket de-risking exit.

Related reading: our guide to the FATF Recommendation 16 travel rule reforms.

The dates that anchor the guidance

Non-bank PSP oversight is a moving target, and three reference points frame everything the guidance says about payment transparency. Keep them close when you map your obligations, because the Wolfsberg document interprets standards set elsewhere rather than replacing them.

  • 15 July 2026: the Wolfsberg Group publishes the non-bank PSP banking-services guidance.
  • June 2025: FATF agrees the updated version of Recommendation 16 on payment transparency at its plenary, tightening the information that must travel with a payment.
  • 30 December 2024: in the EU, Regulation (EU) 2023/1113, the recast Transfer of Funds Regulation, becomes fully applicable and replaces Regulation (EU) 2015/847.

The Wolfsberg guidance is voluntary. FATF Recommendation 16 is an international standard for countries, not a directly enforceable rule for firms; enforceable obligations arise under applicable local law and regulatory requirements. FATF has identified the end of 2030 as the target by which most or all of the June 2025 revisions should be in effect, so firms should distinguish the revised standard from requirements already implemented in each jurisdiction.

What the Wolfsberg non-bank PSP guidance changes for banks

The document expands existing Wolfsberg material by detailing the common relationship types between banks and non-bank PSPs, the risks attached to each, the compliance obligations that follow, and the risk management the Group expects banks to have in place. It rests on three stated principles: a risk-based approach, payment transparency, and comprehensive risk management. None of those phrases is new to anyone who has run a correspondent programme. The value is in applying them to a customer type that behaves like a mini-bank while sitting on the wrong side of the account relationship.

The guidance is a financial crime risk document. It covers how banks should size, monitor and document the risk of providing accounts and payment rails to a non-bank PSP; authorisation requirements, capital standards and safeguarding rules sit with the relevant licensing authorities and are outside its scope. If your firm already runs a correspondent banking due diligence programme, the guidance reads as an instruction to extend that discipline to a category many banks have historically onboarded as ordinary commercial customers.

Why non-bank PSPs are hard to bank

The core difficulty is intermediation. A non-bank PSP sits between the originator and the beneficiary, often bundling many underlying customers’ payments into net settlement or bulk transactions that reach the bank as a single flow. The Wolfsberg guidance flags that this many-to-many bundling reduces transparency for the institution providing the account, because the bank sees an aggregate movement rather than the individual payers and payees behind it. Layer a second PSP into the chain, and the originating customer can be two or three parties away from the bank that ultimately touches the payment system.

That opacity is what pushes banks toward the blunt instrument of de-risking, exiting the whole customer segment rather than carrying the monitoring cost. The guidance is explicit that its aim is to help banks support innovation in payments while managing the risk, which is the counterweight to a wholesale exit. Supervisors have made the same point for years: cutting off legitimate PSPs simply moves the flows to institutions with weaker controls. Our note on de-risking and ML/FT risk management covers how one supervisor frames the expectation that exit decisions be evidenced at the level of the individual relationship, not the sector.

Map the relationship before you price the risk

The guidance asks banks to identify what kind of non-bank PSP relationship they are actually in before calibrating due diligence, because the risk profile changes sharply with the structure. The document works through several recurring types. A direct customer relationship, where the PSP holds an account for its own operations and its customers. Nested or downstream activity, where the PSP is itself processing payments for other licensed PSPs and their underlying customers. Agency arrangements, where the PSP uses agents to deliver services on its behalf. And partnership models such as Banking-as-a-Service or sponsored-account structures, where a non-bank PSP reaches the payment system through a sponsoring bank’s licence and rails.

Treating all of these as one risk tier is the error the taxonomy is designed to prevent. A sponsored-account or Banking-as-a-Service arrangement can put the bank’s own licence and BINs behind a third party’s customer base, which is a materially different exposure from a PSP that simply banks its float. Nested activity is harder still, because the layer the bank cannot see directly is where the transparency gap opens. The onboarding file should record which structure applies and revisit it when the PSP changes its model, since a shift from direct servicing into downstream processing can change the risk without any change to the account itself.

Payment transparency and FATF Recommendation 16

This is where the guidance connects to a binding obligation. Payment transparency, its second principle, tracks FATF Recommendation 16, the standard often called the travel rule. Recommendation 16 requires that financial institutions include required and accurate originator information and required beneficiary information on wire transfers and related messages, and that the information stays with the transfer through the chain. FATF permits countries to set a de minimis threshold no higher than USD/EUR 1,000 for cross-border transfers. Below that threshold, the originator and beneficiary names and their account numbers, or a unique transaction reference where no account is used, must accompany the transfer. Those details need not be verified for accuracy unless there is suspicion of money laundering or terrorist financing, in which case the institution verifies the information relating to its customer. FATF agreed an updated Recommendation 16 at its June 2025 plenary to improve the consistency and quality of that information.

The guidance allocates the obligation along the chain. The debtor agent PSP, meaning the originating entity, carries the primary duty to ensure payment messages contain complete and accurate information under Recommendation 16 and local rules. Intermediary PSPs then have to preserve that transparency by transmitting the information without alteration and by monitoring for incomplete details. For the bank sitting behind a non-bank PSP, the operational consequence is concrete: your due diligence has to test whether the PSP can meet the message-quality standard its own role demands, because deficient originator or beneficiary data will surface as truncated or missing fields in the flows you screen.

The enforceable version of this standard depends on jurisdiction. In the EU, Directive (EU) 2015/2366 (PSD2), Directive 2009/110/EC and national implementing law remain the current authorisation framework for payment institutions and electronic money institutions. PSD3 and the accompanying Payment Services Regulation remain an ongoing legislative revision following political agreement. Regulation (EU) 2023/1113 carries the travel-rule data obligations for transfers of funds and crypto-asset transfers, supported by the EBA’s Travel Rule Guidelines. Message-integrity controls also connect to the payee-checking regimes now spreading across payment systems; our explainer on Verification of Payee checks shows how name-matching at the point of payment intersects with the transparency the guidance wants preserved.

Knowing the customer’s customer without owning the relationship

Comprehensive risk management, the third principle, is where the guidance asks the most of banks. It expects the institution to understand the non-bank PSP’s business model, its customer activities and the financial crime controls it operates, rather than treating the PSP as a sealed box. That is a know-your-customer’s-customer problem in all but name: the bank cannot onboard every underlying user, but it has to form a defensible view of who they are, where they sit, and how the PSP screens and monitors them.

In practice the assessment turns on the PSP’s own controls. The guidance points banks toward the funds-flow and corridor profile, the customer types the PSP serves and its stated risk appetite, and the maturity of its transaction monitoring, sanctions screening and suspicious activity processes. Enhanced due diligence is the expected response to a higher-risk profile or a material change in the business, and the review is meant to be ongoing rather than a point-in-time onboarding gate, because non-bank PSPs re-shape their models quickly. A useful discipline is to write the PSP’s controls into your own risk assessment as a dependency: if the PSP’s monitoring is weak, your residual risk rises even where your direct controls are strong.

Monitoring, screening and where the reporting sits

The AML reporting obligations in this area sit in the local suspicious activity or suspicious transaction reporting regime and the travel-rule law that implements Recommendation 16. The Wolfsberg guidance adds the monitoring and screening framework a bank should run over those flows so that reportable activity is actually detected before it has to be reported.

The document treats transaction monitoring, sanctions screening and suspicious activity handling as areas the bank should assess in the PSP and, where the flows pass through the bank, operate itself. Screening free-text and connected-party fields, watching for unexpected shifts in volumes and corridors, and understanding the PSP’s own suspicious activity filing obligations across the jurisdictions it touches are all part of the picture. One recurring trap it calls out is a PSP describing third-party customer disbursements as its own liquidity management, which can mask the very payments the bank most needs to see. The cost of getting this wrong is not abstract: the FCA’s censure of CACEIS over financial crime controls, which our coverage of that case sets out, shows supervisors testing exactly whether monitoring kept pace with the business a firm actually processed.

The guidance also sketches the indicators that should raise attention on an ongoing basis. A PSP growing faster than its compliance function can scale, unresolved transaction-monitoring or customer-review backlogs, services offered in a market without the licence to support them, and limited visibility into the nested PSP networks a customer depends on are all signs that the residual risk has moved since onboarding. High-risk funding methods such as cash, money orders or prepaid instruments compound the traceability problem, because they weaken the audit trail before the flow ever reaches the bank. None of these is a mandatory exit trigger. Each is a prompt to re-test the assessment rather than let the file age, which is the discipline the ongoing-review expectation is meant to enforce.

Where this leaves de-risking decisions

The guidance does not tell a bank to keep any particular customer, and it does not promise that a well-documented framework makes a relationship safe. What it offers is a structure for deciding at the level of the individual PSP: identify the relationship type, test the PSP’s payment-transparency and control capability, size the residual risk, and monitor it on an ongoing basis. A bank that can show that chain of reasoning is in a stronger position whether it retains the customer or exits, because the decision is grounded in the relationship rather than in a category-wide reflex. That is the practical distance between managing non-bank PSP risk and simply refusing to hold it.

Frequently Asked Questions

Is the Wolfsberg non-bank PSP guidance legally binding?

No. The Wolfsberg Group is an industry association of twelve global banks, and its guidance is voluntary good practice. It creates no reporting obligation on its own. The binding obligations it references, chiefly payment-transparency duties under FATF Recommendation 16 as transposed locally and suspicious activity reporting, sit in law and supervisory rules, which is where enforcement risk actually attaches.

How does the guidance relate to correspondent banking due diligence?

It extends correspondent-style discipline to non-bank PSPs. Where a PSP performs banking-like activity, the Group’s existing correspondent banking financial crime principles remain the reference point, and the new guidance layers on the relationship types, risks and controls specific to non-bank PSPs so that banks apply the same rigour to a customer they may previously have onboarded as an ordinary commercial account.

Who holds the primary payment-transparency obligation in a PSP chain?

Under the framing the guidance uses, the debtor agent PSP, the originating entity, carries the primary duty to ensure the payment message is complete and accurate under FATF Recommendation 16. Intermediary PSPs must then transmit that information without alteration and monitor for missing detail. A bank behind the PSP should test that the PSP can meet the standard its role in the chain requires.

What is the de minimis threshold under FATF Recommendation 16?

FATF allows countries to set a de minimis threshold no higher than USD/EUR 1,000 for cross-border transfers. Below that threshold, the originator and beneficiary names and their account numbers, or a unique transaction reference where no account is used, must accompany the transfer. The information need not be verified for accuracy unless there is suspicion of money laundering or terrorist financing, in which case the institution verifies the information relating to its customer. National implementations set the operative requirements for firms in scope.

Does the guidance change how banks handle Banking-as-a-Service or sponsored accounts?

It treats them as a distinct, higher-attention relationship type rather than a standard account. Because a sponsored-account or Banking-as-a-Service model puts the bank’s licence and payment-system access behind a third party’s customer base, the guidance expects the bank to understand that underlying base and the PSP’s controls over it, and to revisit the assessment if the PSP changes its model.

How should a bank evidence that it is managing rather than avoiding non-bank PSP risk?

By documenting the relationship type, the PSP’s payment-transparency and control assessment, the resulting residual-risk rating and the ongoing monitoring applied to the flows. A file that records this chain supports either retention or an evidenced exit, and it answers the supervisory expectation that de-risking be a relationship-level decision rather than a blanket withdrawal from the sector.

Related Articles

Key Takeaways

  • The Wolfsberg non-bank PSP guidance, published 15 July 2026, is voluntary industry good practice, not a regulation or a new reporting return.
  • It rests on three principles: a risk-based approach, payment transparency, and comprehensive risk management applied to the bank-to-PSP relationship.
  • Banks should identify the relationship type first, since direct, nested, agency and sponsored-account or Banking-as-a-Service structures carry sharply different exposures.
  • Payment transparency tracks FATF Recommendation 16: the debtor agent PSP holds the primary message-quality duty, intermediary PSPs must transmit information without alteration, with a de minimis threshold no higher than USD/EUR 1,000.
  • The enforceable obligations live in local law, such as Regulation (EU) 2023/1113 in the EU and the applicable suspicious activity reporting regime, not in the Wolfsberg text.
  • The guidance frames comprehensive due diligence as a know-your-customer’s-customer exercise, with the PSP’s own controls treated as a dependency in the bank’s residual-risk assessment.
  • Its purpose is to help banks manage the sector rather than de-risk it wholesale, supporting relationship-level decisions that supervisors can test.

Sources and References

Bank the plumbing, but see the flow

The non-bank PSP sector will keep growing, and banks will keep being asked to provide its accounts, settlement and rails. The Wolfsberg guidance does not resolve the tension in that arrangement, but it gives financial crime teams a shared vocabulary for it: name the relationship, locate the transparency obligation, test the PSP’s controls, and decide on the individual case. For reporting officers, the payoff is a framework that can defend both the customers a bank keeps and the ones it lets go, on evidence rather than instinct.

Last updated: July 2026

Disclaimer: The information on RegReportingDesk.com is for educational and informational purposes only. It does not constitute legal, regulatory, tax, or compliance advice. Always consult your compliance officer, legal counsel, or the relevant supervisory authority for guidance specific to your institution.

Similar Posts

  • AMLR – What Changes for Luxembourg Firms Under the New EU AML Regulation

    Last updated: March 2026 Your compliance team has spent years building its AML framework around the Luxembourg Law of 12 November 2004, as amended, which transposes the EU Anti-Money Laundering Directives. That framework is about to be replaced. Not amended. Replaced. The AMLR (Regulation (EU) 2024/1624), published on 19 June 2024, is a directly applicable…

  • PSD2 Reporting Requirements for Payment Institutions: Complete Practitioner Guide

    Last updated: March 2026 Introduction PSD2 reporting is not optional – payment institutions face multiple overlapping reporting obligations including statistical, prudential, fraud, incident, and complaint reporting, each with distinct deadlines, data sources, and regulatory recipients. Payment Services Directive 2 (Directive (EU) 2015/2366) fundamentally reshaped how payment institutions, e-money institutions (EMIs), account information service providers (AISPs),…

  • MiCAR Reporting Obligations for CASPs: Complete Implementation Guide

    Last updated: March 2026 Introduction MiCAR (Markets in Crypto-Assets Regulation) creates the first comprehensive regulatory framework requiring crypto-asset service providers to implement authorization, prudential reporting, transaction monitoring, and incident notification systems. The Markets in Crypto-Assets Regulation (Regulation (EU) 2023/1114) represents the first unified rulebook for crypto-asset activities across the entire European Union. For reporting teams…