01
First we define the product
- Account
- Nostro/vostro, settlement or safeguarding
- Currency
- OMR, USD, EUR, GBP, CNY and others
- Rail
- SWIFT, local payment system, cards or partner network
- Use
- Own payments, client payments, trade finance or treasury
- Customers
- Retail, SME, corporate, FI and geography
- Volume
- Transactions, average ticket, peak and expected balances
02
A bank card, not a promise of an account
The official CBO registry includes Bank Muscat, Bank Dhofar, National Bank of Oman, Oman Arab Bank, Sohar International, Ahli Bank, Islamic and foreign banks. Institutional appetite, available currency and direct clearing are to be confirmed with the relevant FI desk.
03
Who qualifies as a respondent institution
The bank verifies the current license, supervision, physical presence, management, ownership and authority to provide the relevant services. A shell bank, or an institution that permits its accounts to be used by a shell bank, is unacceptable.
A payment license is not a banking license. The applicant accurately describes its safeguarding arrangements, client money, settlement role and authorized services.
04
Institutional KYC package
License, register, constitution, regulator, permissions and legal opinion.
Controllers, UBO, group, source of capital and governance.
Audited statements, capital, liquidity and prudential ratios.
Products, customers, countries, channels, agents and projections.
- Management
- Board, CEO, compliance, MLRO, risk and audit
- Controls
- Policies, enterprise risk assessment and testing
- History
- Regulatory findings, enforcement, incidents and remediation
- Questionnaire
- CBDDQ/Wolfsberg-style questionnaire and supporting evidence
05
The bank evaluates the effectiveness of AML/CFT controls
CBO guidelines require sufficient information about the respondent institution and its controls, country risk, AML/CFT compliance, due diligence and record keeping. A policy without supporting evidence is insufficient.
- CDD/EDD
- Risk tiers, UBO, PEP, source and review
- Sanctions
- Screening customers, payments, vessels and ownership
- Monitoring
- Scenarios, thresholds, alerts, investigations and STRs
- Wire data
- Originator/beneficiary information and rejection/repair
- Independent test
- Internal audit or external assessment and remediation
- Training
- Role-based coverage and records
06
Payment traffic forecast
Correspondent wants to understand each corridor: country, currency, customer type, purpose, average ticket, sanctions exposure and underlying documents. High-risk industries and countries are highlighted rather than lost in the overall figure.
07
Nested and downstream relationships
If the respondent grants access to other banks, PSPs, agents or customers of customers, the correspondent receives a transparent map of downstream access and controls. An undeclared nested relationship may result in restriction or exit.
- Access
- Who actually uses correspondent rail
- Contracts
- Direct and downstream customer relationship
- Controls
- Onboarding, monitoring and right to audit
- Data
- Access to underlying payer/payee and purpose
- Prohibition
- Shell bank and unauthorized nested access
08
SWIFT, RMA and operational readiness
Account approval and RMA authorization are related but separate approvals. BIC, security controls, message types, sanctions filtering, reconciliation, cut-off times, investigations, returns, fees, business continuity and contacts are checked.
09
Opening process
- 01Readiness assessment
License, governance, AML gaps and commercial case.
- 02Target map
Currency, clearing access, appetite and service scope.
- 03Institutional file
Questionnaire, evidence, traffic and cover memorandum.
- 04Due diligence
Interviews, clarifications, regulator checks and approvals.
- 05Implementation
Agreement, limits, funding, RMA, testing and go-live.
10
The relationship is reviewed continuously
CBO guidance provides for periodic updates of due diligence commensurate with risk. Deterioration, adverse information, changes in ownership, license, products or geography, and material control failures are escalated to senior management.
- 01
Update license, ownership, audit and questionnaire annually.
- 02
Compare actual transaction flows with the declared profile.
- 03
Report material changes and regulatory findings.
- 04
Test sanctions, TM and payment data controls.
- 05
Maintain operational contacts and incident plan.
