PAYMENTS SIGNAL REFERENCE ARCHITECTURE · SYNTHETIC / TRAINING ONLY
Correspondent banking and CBPR+ serial, cover, nostro, screening, and tracking architecture
Connects payment information, bilateral account movement, serial and cover routes, screening holds, beneficiary posting, investigations, and nostro reconciliation.
Payments Signal reference architecture v1 · reviewed 2026-07-23
Reference architecture—not a scheme mandate. The diagram compresses a potentially long correspondent chain into one serial or cover component. Bilateral account terms, credit policies, screening obligations, charges, foreign exchange, cut-offs, and posting sequence differ by institution and currency. Current CBPR+ and authorised bilateral documentation remain controlling.
Components
Ordering customer and debtor agent
Creates and approves the cross-border payment instruction.
- Kind
- actor
- Owner
- Ordering customer and debtor-agent payments team
- Responsibilities
- Provide complete debtor, creditor, purpose, and remittance data
- Authorise the debit and charges arrangement
- Inputs
- Commercial obligation
- Beneficiary instructions
- Charge choice
- Outputs
- Approved customer transfer and interbank instruction
- Controls
- Customer due diligence
- Entitlement
- Sanctions and fraud controls
- Failure modes
- Incomplete party data
- Invalid account
- Unsupported charges or route
- Recovery
- Repair before release
- Reject with a precise customer status
- Non-functional requirements
- Durable correlation through stable business and technical identifiers
- Capacity and availability matched to the service-level objective
- Auditable state changes, configuration, and operator actions
Correspondent route and SSI service
Selects a reachable chain and the standing settlement instructions for the currency and accounts.
- Kind
- service
- Owner
- Payment product and reference-data operations
- Responsibilities
- Choose serial or cover treatment
- Resolve correspondents and account relationships
- Apply cut-offs and currency constraints
- Inputs
- Currency
- Agents
- BICs
- Standing settlement instructions
- Cut-offs
- Outputs
- Approved route and account chain
- Controls
- Maker-checker data
- Effective dates
- Reachability and account validation
- Failure modes
- Stale SSI
- Broken correspondent chain
- Unreachable agent
- Recovery
- Stop release
- Restore verified instructions
- Revalidate the route
- Non-functional requirements
- Durable correlation through stable business and technical identifiers
- Capacity and availability matched to the service-level objective
- Auditable state changes, configuration, and operator actions
Cross-border screening and hold control
Screens the parties and payment text at each institution that has a control obligation.
- Kind
- control
- Owner
- Financial crime operations
- Responsibilities
- Screen relevant parties, agents, addresses, and remittance
- Hold potential matches without losing payment state
- Inputs
- Payment data
- List data
- Customer and counterparty context
- Outputs
- Clear, hold, or stop decision with audit evidence
- Controls
- List freshness
- Match audit
- Four-eyes disposition
- Failure modes
- Unresolved alert
- Late list update
- Screening service outage
- Recovery
- Keep value movement controlled
- Investigate with authorised evidence
- Resume from the held state only
- Non-functional requirements
- Durable correlation through stable business and technical identifiers
- Capacity and availability matched to the service-level objective
- Auditable state changes, configuration, and operator actions
Sending bank customer and nostro books
Records the customer position, correspondent claim, charges, and expected settlement evidence.
- Kind
- ledger
- Owner
- Core banking, treasury operations, and finance
- Responsibilities
- Reserve or debit under the bank's posting policy
- Record the nostro-side accounting expectation
- Reconcile charges and value date
- Inputs
- Approved payment
- FX and charge details
- Correspondent account
- Outputs
- Customer and nostro ledger entries
- Controls
- Balanced entries
- Value-date control
- Posting idempotency
- Failure modes
- Posting mismatch
- Wrong account
- Unmatched correspondent debit
- Recovery
- Stop further release where possible
- Reconcile before reversal
- Post controlled adjustment with evidence
- Non-functional requirements
- Durable correlation through stable business and technical identifiers
- Capacity and availability matched to the service-level objective
- Auditable state changes, configuration, and operator actions
Serial correspondent chain
Passes the customer transfer through intermediaries while each link settles across its own bilateral accounts.
- Kind
- external-network
- Owner
- Correspondent banks in the selected chain
- Responsibilities
- Forward the payment instruction
- Apply each intermediary's controls and account posting
- Inputs
- pacs.008 or legacy MT103
- Bilateral account relationship
- Outputs
- Forwarded instruction
- Account debit or credit
- Status or return
- Controls
- Screening
- RMA and reachability
- Account and liquidity controls
- Failure modes
- Intermediary hold
- Deduction or charge dispute
- Broken onward route
- Recovery
- Investigate at the bank holding the last confirmed state
- Return through the applicable chain when required
- Non-functional requirements
- Durable correlation through stable business and technical identifiers
- Capacity and availability matched to the service-level objective
- Auditable state changes, configuration, and operator actions
Cover settlement chain
Carries the interbank cover separately while the customer-transfer instruction goes directly to the beneficiary agent.
- Kind
- external-network
- Owner
- Reimbursement agents and correspondent banks
- Responsibilities
- Carry pacs.009 COV or MT202 COV through reimbursement agents
- Preserve the underlying customer-transfer references
- Inputs
- Cover instruction
- Underlying customer-transfer reference
- Outputs
- Interbank settlement movement and correlated status
- Controls
- Underlying-reference completeness
- Screening transparency
- Liquidity and account control
- Failure modes
- Customer leg arrives before cover
- Cover mismatch
- Unmatched reimbursement
- Recovery
- Hold beneficiary posting under policy
- Investigate both legs by shared references
- Do not duplicate cover
- Non-functional requirements
- Durable correlation through stable business and technical identifiers
- Capacity and availability matched to the service-level objective
- Auditable state changes, configuration, and operator actions
Beneficiary agent and customer books
Determines whether the beneficiary may be credited and records the final customer outcome.
- Kind
- ledger
- Owner
- Beneficiary-agent payment operations and core banking
- Responsibilities
- Validate the beneficiary account
- Confirm settlement or cover evidence under policy
- Credit or return
- Inputs
- Customer-transfer instruction
- Settlement or cover evidence
- Outputs
- Beneficiary credit
- Status
- Return
- Account reporting
- Controls
- Account validation
- Finality and cover policy
- Posting idempotency
- Failure modes
- Invalid account
- Missing cover
- Duplicate credit
- Recovery
- Keep the payment in a controlled pending state
- Return or investigate with complete references
- Non-functional requirements
- Durable correlation through stable business and technical identifiers
- Capacity and availability matched to the service-level objective
- Auditable state changes, configuration, and operator actions
Investigations, recalls, and reconciliation
Finds the last confirmed instruction, settlement, and ledger state across institutions.
- Kind
- operations
- Owner
- Cross-border payment operations and nostro reconciliation
- Responsibilities
- Correlate requests, responses, returns, and statements
- Distinguish cancellation before execution from recall after release
- Inputs
- camt.056, camt.029, camt.110/111, pacs.004, statements, gpi or network evidence
- Outputs
- Resolved case
- Return or no-action decision
- Reconciled nostro item
- Controls
- Original-reference integrity
- Four-eyes funds action
- Settlement-state check
- Failure modes
- Unmatched recall
- Return without original reference
- Statement break
- Recovery
- Trace the original and cover legs
- Act only after settlement and funds position are known
- Non-functional requirements
- Durable correlation through stable business and technical identifiers
- Capacity and availability matched to the service-level objective
- Auditable state changes, configuration, and operator actions
Interfaces
Approved cross-border intent
corr-originator → corr-routing
Carry the complete customer intent into route and profile selection.
- Contract
- message · asynchronous
- Controls
- Authentication and authorisation
- Integrity and replay protection
- Correlation and audit evidence
- Failure treatment
- Incomplete intent is rejected before route and value movement.
Routed payment for control
corr-routing → corr-screening
Screen the complete parties and selected agents before release.
- Contract
- control · synchronous
- Controls
- Authentication and authorisation
- Integrity and replay protection
- Correlation and audit evidence
- Failure treatment
- A hold preserves the selected route and prevents value movement.
Cleared posting instruction
corr-screening → corr-sender-nostro
Record customer and expected correspondent-account effects under the posting policy.
- Contract
- posting · synchronous
- Controls
- Authentication and authorisation
- Integrity and replay protection
- Correlation and audit evidence
- Failure treatment
- A posting failure stops network release until books and state agree.
Serial customer transfer
corr-sender-nostro → corr-serial
Move the instruction and bilateral settlement effect along the correspondent chain.
- Contract
- message · asynchronous
- Controls
- Authentication and authorisation
- Integrity and replay protection
- Correlation and audit evidence
- Failure treatment
- An ambiguous send is investigated before any replay.
Cover settlement instruction
corr-sender-nostro → corr-cover
Move the interbank cover separately from the customer-transfer information.
- Contract
- settlement · asynchronous
- Controls
- Authentication and authorisation
- Integrity and replay protection
- Correlation and audit evidence
- Failure treatment
- A missing or unmatched cover remains visible as a two-leg exception.
Serial payment and value
corr-serial → corr-beneficiary
Deliver the instruction and the final bilateral correspondent-account effect.
- Contract
- settlement · asynchronous
- Controls
- Authentication and authorisation
- Integrity and replay protection
- Correlation and audit evidence
- Failure treatment
- The beneficiary agent validates account and settlement state before final customer action.
Cover evidence
corr-cover → corr-beneficiary
Provide the settlement evidence required to pair with the direct customer leg.
- Contract
- settlement · asynchronous
- Controls
- Authentication and authorisation
- Integrity and replay protection
- Correlation and audit evidence
- Failure treatment
- An unmatched cover enters investigation and cannot silently credit the wrong payment.
Status, return, and reporting
corr-beneficiary → corr-investigations
Report credit, rejection, return, and account evidence using original references.
- Contract
- message · asynchronous
- Controls
- Authentication and authorisation
- Integrity and replay protection
- Correlation and audit evidence
- Failure treatment
- Unmatched reports enter reconciliation rather than changing the wrong payment.
Recall or investigation outcome
corr-investigations → corr-originator
Return an evidence-based outcome to the original payment owner.
- Contract
- message · asynchronous
- Controls
- Authentication and authorisation
- Integrity and replay protection
- Correlation and audit evidence
- Failure treatment
- No funds promise is made until the receiving chain confirms the outcome.