Compliance

The Compliance Trail Every CFO Needs Before Trusting Cross-Border Rails

7 min read
The Compliance Trail Every CFO Needs Before Trusting Cross-Border Rails

When a CFO approves a cross-border payment infrastructure vendor, they are making a decision that has compliance consequences that extend well beyond the initial onboarding. Every cross-border payment touches at least two regulatory jurisdictions, involves counterparty institutions that each carry their own compliance posture, and creates documentation obligations that may be reviewed by auditors, regulators, or counterparties months or years after the transaction settles. The question is not whether the rails work operationally. The question is whether the compliance documentation the rails produce is adequate when it gets scrutinized.

This piece is aimed at CFOs and compliance officers evaluating cross-border payment infrastructure, not at payment operations teams optimizing throughput. The considerations are different at that level, and the failure modes are more consequential.

What an Audit-Ready Compliance Trail Requires

A compliance trail for a cross-border payment is more than a confirmation receipt. At minimum, a trail that holds up under audit should include: the original payment instruction with all counterparty fields populated per ISO 20022 or SWIFT MT field requirements; the route the payment actually took, including any intermediate institutions; timestamps at each processing stage; the outcome of sanctions and AML screening at the time of instruction; and the final settlement confirmation with correspondent reference. Each element serves a specific audit or regulatory purpose, and the absence of any one of them creates a gap that investigators or auditors will flag.

Sanctions screening documentation deserves specific attention. OFAC, EU restrictive measures, and UK financial sanctions regulations all require that payments do not benefit designated entities, and all impose obligations on the originating institution to screen counterparties and transaction details. For a corporate treasury team, the relevant question is not just whether your payment provider screens transactions but whether that screening is documented in a way that allows you to demonstrate compliance after the fact. A "we screened it" assertion is not the same as a retained record of what was screened, against which list, on what date, with what outcome.

The Correspondent Bank Compliance Problem

In a correspondent banking chain, compliance documentation is produced at each hop, but it is not automatically consolidated into a single record accessible to the originating company. Each bank in the chain performs its own KYC and AML screening based on the counterparty information it can see. The originating company's bank screens based on what the company disclosed at account opening. The correspondent bank one hop downstream screens based on the payment message it receives, which may contain different counterparty detail fields than the original instruction.

This creates a structural documentation gap. If a regulator asks the corporate treasury team to demonstrate that a specific payment from 18 months ago was screened for sanctions exposure, the answer depends on records held by two to four separate institutions. Retrieving consolidated documentation requires manual requests to each institution in the chain, response times measured in weeks, and the real possibility that some institutions retain records in formats that cannot be easily cross-referenced.

The practical implication is that a CFO relying on correspondent banking for compliance documentation is relying on a distributed record system that was not designed with consolidated retrieval in mind. That is acceptable for transactions that never attract scrutiny. It is a problem when a payment is associated with a counterparty that later appears on a sanctions list, a business relationship that comes under regulatory review, or a transaction that auditors sample as part of a broader compliance examination.

KYC Obligations on Both Sides

Cross-border payment compliance is not only an outbound screening exercise. It also includes knowing your own institution's obligations around know-your-customer (KYC) documentation for the counterparties your payment flows reach. FinCEN's due diligence requirements for correspondent accounts (31 CFR Part 1010.610) impose enhanced due diligence obligations on U.S. financial institutions maintaining accounts for foreign correspondent banks in certain jurisdictions. These rules flow through to corporate clients when the corporate's payment activity implicates those correspondent relationships.

For a corporate treasury team, the relevant question is whether their payment infrastructure provider maintains adequate correspondent KYC documentation and whether that documentation is available for review during a regulatory examination or audit. A provider that routes payments through correspondent relationships without maintaining accessible KYC files on those correspondents is creating compliance exposure for the corporate clients whose payments flow through those routes.

Documentation for Cross-Border Regulatory Filings

Beyond ongoing transaction screening, cross-border payments can trigger regulatory reporting obligations that require specific documentation. FinCEN Form 105 applies to cash payments above $10,000 crossing U.S. borders, but equivalent reporting regimes exist in many jurisdictions for electronic transfers above specified thresholds. The EU's Transfer of Funds Regulation (Regulation EU 2015/847) requires that full originator and beneficiary information accompany wire transfers throughout the payment chain. Similar payer information requirements exist under FATF Recommendation 16, implemented across FATF member jurisdictions.

Payment infrastructure that strips or truncates originator information to fit legacy message formats fails these requirements. SWIFT's gpi initiative includes commitments around full payment amount and originator information, but compliance is enforced at the member bank level and is not universal across all corridors and all intermediaries. A corporate treasury team that instructs full originator information at the point of payment has no guarantee that information survives intact through the correspondent chain unless the infrastructure it uses validates completeness at each leg.

What to Ask Before Approving Cross-Border Rails

The compliance due diligence process for cross-border payment infrastructure should address several specific questions that operational demonstrations and uptime SLAs do not answer.

  • Sanctions screening documentation. What does a retained sanctions screening record look like per transaction? Which lists are screened, and at what point in the payment lifecycle? Is the screening record accessible to the corporate for retrieval on demand?
  • Correspondent KYC. For each routing partner in the payment chain, does the provider maintain KYC documentation? What is the process when a routing correspondent's compliance posture changes?
  • Originator information persistence. How does the infrastructure ensure that ISO 20022 or SWIFT MT originator fields are transmitted intact to the beneficiary institution? What happens if an intermediate hop has a field truncation issue?
  • Audit trail retrieval. If an auditor requests consolidated documentation for a specific payment from 18 months ago, what does that retrieval process look like? Time to response, format, completeness.
  • Regulatory change monitoring. How does the provider monitor and adapt to regulatory changes in the jurisdictions of the corridors it operates? Who is responsible for maintaining compliance with new reporting requirements?

The Difference Between Compliance as Process and Compliance as Record

Many cross-border payment providers have solid compliance processes. They screen, they maintain KYC, they follow OFAC protocols. The gap is often between having a compliance process and producing a compliance record that is complete, consolidated, and retrievable on demand. For a CFO, the process is necessary but not sufficient. The record is what matters when something goes wrong or when a regulator asks.

At Birch Hill, our compliance trail is structured around per-transaction records from the point of instruction through settlement confirmation. Each record includes the screening outcome, the routing path, counterparty reference data, and the settlement reference at each leg. That record is the basis for answering an audit query without a multi-week manual retrieval exercise across correspondent institutions. We built it that way because the corporate treasury teams we work with told us their existing providers could produce compliance documentation, but only under significant operational strain and never in a format that matched what auditors actually asked for.

Ready to modernize your cross-border settlement?

Treasury teams using Birch Hill settle cross-border payments in minutes and receive complete compliance documentation automatically.