PAYMENTS SIGNAL REFERENCE ARCHITECTURE · SYNTHETIC / TRAINING ONLY

Correspondent banking and CBPR+ serial, cover, nostro, screening, and tracking architecture

Connects payment information, bilateral account movement, serial and cover routes, screening holds, beneficiary posting, investigations, and nostro reconciliation.

Payments Signal reference architecture v1 · reviewed 2026-07-23

Reference architecture—not a scheme mandate. The diagram compresses a potentially long correspondent chain into one serial or cover component. Bilateral account terms, credit policies, screening obligations, charges, foreign exchange, cut-offs, and posting sequence differ by institution and currency. Current CBPR+ and authorised bilateral documentation remain controlling.

Audience and purpose

Cross-border architects, correspondent-banking product teams, treasury operations, sanctions teams, and business analysts

Components

Ordering customer and debtor agent

Creates and approves the cross-border payment instruction.

Kind
actor
Owner
Ordering customer and debtor-agent payments team
Responsibilities
  • Provide complete debtor, creditor, purpose, and remittance data
  • Authorise the debit and charges arrangement
Inputs
  • Commercial obligation
  • Beneficiary instructions
  • Charge choice
Outputs
  • Approved customer transfer and interbank instruction
Controls
  • Customer due diligence
  • Entitlement
  • Sanctions and fraud controls
Failure modes
  • Incomplete party data
  • Invalid account
  • Unsupported charges or route
Recovery
  • Repair before release
  • Reject with a precise customer status
Non-functional requirements
  • Durable correlation through stable business and technical identifiers
  • Capacity and availability matched to the service-level objective
  • Auditable state changes, configuration, and operator actions

Correspondent route and SSI service

Selects a reachable chain and the standing settlement instructions for the currency and accounts.

Kind
service
Owner
Payment product and reference-data operations
Responsibilities
  • Choose serial or cover treatment
  • Resolve correspondents and account relationships
  • Apply cut-offs and currency constraints
Inputs
  • Currency
  • Agents
  • BICs
  • Standing settlement instructions
  • Cut-offs
Outputs
  • Approved route and account chain
Controls
  • Maker-checker data
  • Effective dates
  • Reachability and account validation
Failure modes
  • Stale SSI
  • Broken correspondent chain
  • Unreachable agent
Recovery
  • Stop release
  • Restore verified instructions
  • Revalidate the route
Non-functional requirements
  • Durable correlation through stable business and technical identifiers
  • Capacity and availability matched to the service-level objective
  • Auditable state changes, configuration, and operator actions

Cross-border screening and hold control

Screens the parties and payment text at each institution that has a control obligation.

Kind
control
Owner
Financial crime operations
Responsibilities
  • Screen relevant parties, agents, addresses, and remittance
  • Hold potential matches without losing payment state
Inputs
  • Payment data
  • List data
  • Customer and counterparty context
Outputs
  • Clear, hold, or stop decision with audit evidence
Controls
  • List freshness
  • Match audit
  • Four-eyes disposition
Failure modes
  • Unresolved alert
  • Late list update
  • Screening service outage
Recovery
  • Keep value movement controlled
  • Investigate with authorised evidence
  • Resume from the held state only
Non-functional requirements
  • Durable correlation through stable business and technical identifiers
  • Capacity and availability matched to the service-level objective
  • Auditable state changes, configuration, and operator actions

Sending bank customer and nostro books

Records the customer position, correspondent claim, charges, and expected settlement evidence.

Kind
ledger
Owner
Core banking, treasury operations, and finance
Responsibilities
  • Reserve or debit under the bank's posting policy
  • Record the nostro-side accounting expectation
  • Reconcile charges and value date
Inputs
  • Approved payment
  • FX and charge details
  • Correspondent account
Outputs
  • Customer and nostro ledger entries
Controls
  • Balanced entries
  • Value-date control
  • Posting idempotency
Failure modes
  • Posting mismatch
  • Wrong account
  • Unmatched correspondent debit
Recovery
  • Stop further release where possible
  • Reconcile before reversal
  • Post controlled adjustment with evidence
Non-functional requirements
  • Durable correlation through stable business and technical identifiers
  • Capacity and availability matched to the service-level objective
  • Auditable state changes, configuration, and operator actions

Serial correspondent chain

Passes the customer transfer through intermediaries while each link settles across its own bilateral accounts.

Kind
external-network
Owner
Correspondent banks in the selected chain
Responsibilities
  • Forward the payment instruction
  • Apply each intermediary's controls and account posting
Inputs
  • pacs.008 or legacy MT103
  • Bilateral account relationship
Outputs
  • Forwarded instruction
  • Account debit or credit
  • Status or return
Controls
  • Screening
  • RMA and reachability
  • Account and liquidity controls
Failure modes
  • Intermediary hold
  • Deduction or charge dispute
  • Broken onward route
Recovery
  • Investigate at the bank holding the last confirmed state
  • Return through the applicable chain when required
Non-functional requirements
  • Durable correlation through stable business and technical identifiers
  • Capacity and availability matched to the service-level objective
  • Auditable state changes, configuration, and operator actions

Cover settlement chain

Carries the interbank cover separately while the customer-transfer instruction goes directly to the beneficiary agent.

Kind
external-network
Owner
Reimbursement agents and correspondent banks
Responsibilities
  • Carry pacs.009 COV or MT202 COV through reimbursement agents
  • Preserve the underlying customer-transfer references
Inputs
  • Cover instruction
  • Underlying customer-transfer reference
Outputs
  • Interbank settlement movement and correlated status
Controls
  • Underlying-reference completeness
  • Screening transparency
  • Liquidity and account control
Failure modes
  • Customer leg arrives before cover
  • Cover mismatch
  • Unmatched reimbursement
Recovery
  • Hold beneficiary posting under policy
  • Investigate both legs by shared references
  • Do not duplicate cover
Non-functional requirements
  • Durable correlation through stable business and technical identifiers
  • Capacity and availability matched to the service-level objective
  • Auditable state changes, configuration, and operator actions

Beneficiary agent and customer books

Determines whether the beneficiary may be credited and records the final customer outcome.

Kind
ledger
Owner
Beneficiary-agent payment operations and core banking
Responsibilities
  • Validate the beneficiary account
  • Confirm settlement or cover evidence under policy
  • Credit or return
Inputs
  • Customer-transfer instruction
  • Settlement or cover evidence
Outputs
  • Beneficiary credit
  • Status
  • Return
  • Account reporting
Controls
  • Account validation
  • Finality and cover policy
  • Posting idempotency
Failure modes
  • Invalid account
  • Missing cover
  • Duplicate credit
Recovery
  • Keep the payment in a controlled pending state
  • Return or investigate with complete references
Non-functional requirements
  • Durable correlation through stable business and technical identifiers
  • Capacity and availability matched to the service-level objective
  • Auditable state changes, configuration, and operator actions

Investigations, recalls, and reconciliation

Finds the last confirmed instruction, settlement, and ledger state across institutions.

Kind
operations
Owner
Cross-border payment operations and nostro reconciliation
Responsibilities
  • Correlate requests, responses, returns, and statements
  • Distinguish cancellation before execution from recall after release
Inputs
  • camt.056, camt.029, camt.110/111, pacs.004, statements, gpi or network evidence
Outputs
  • Resolved case
  • Return or no-action decision
  • Reconciled nostro item
Controls
  • Original-reference integrity
  • Four-eyes funds action
  • Settlement-state check
Failure modes
  • Unmatched recall
  • Return without original reference
  • Statement break
Recovery
  • Trace the original and cover legs
  • Act only after settlement and funds position are known
Non-functional requirements
  • Durable correlation through stable business and technical identifiers
  • Capacity and availability matched to the service-level objective
  • Auditable state changes, configuration, and operator actions

Interfaces

Approved cross-border intent

corr-originator → corr-routing

Carry the complete customer intent into route and profile selection.

Contract
message · asynchronous
Controls
  • Authentication and authorisation
  • Integrity and replay protection
  • Correlation and audit evidence
Failure treatment
Incomplete intent is rejected before route and value movement.

Routed payment for control

corr-routing → corr-screening

Screen the complete parties and selected agents before release.

Contract
control · synchronous
Controls
  • Authentication and authorisation
  • Integrity and replay protection
  • Correlation and audit evidence
Failure treatment
A hold preserves the selected route and prevents value movement.

Cleared posting instruction

corr-screening → corr-sender-nostro

Record customer and expected correspondent-account effects under the posting policy.

Contract
posting · synchronous
Controls
  • Authentication and authorisation
  • Integrity and replay protection
  • Correlation and audit evidence
Failure treatment
A posting failure stops network release until books and state agree.

Serial customer transfer

corr-sender-nostro → corr-serial

Move the instruction and bilateral settlement effect along the correspondent chain.

Contract
message · asynchronous
Controls
  • Authentication and authorisation
  • Integrity and replay protection
  • Correlation and audit evidence
Failure treatment
An ambiguous send is investigated before any replay.

Cover settlement instruction

corr-sender-nostro → corr-cover

Move the interbank cover separately from the customer-transfer information.

Contract
settlement · asynchronous
Controls
  • Authentication and authorisation
  • Integrity and replay protection
  • Correlation and audit evidence
Failure treatment
A missing or unmatched cover remains visible as a two-leg exception.

Serial payment and value

corr-serial → corr-beneficiary

Deliver the instruction and the final bilateral correspondent-account effect.

Contract
settlement · asynchronous
Controls
  • Authentication and authorisation
  • Integrity and replay protection
  • Correlation and audit evidence
Failure treatment
The beneficiary agent validates account and settlement state before final customer action.

Cover evidence

corr-cover → corr-beneficiary

Provide the settlement evidence required to pair with the direct customer leg.

Contract
settlement · asynchronous
Controls
  • Authentication and authorisation
  • Integrity and replay protection
  • Correlation and audit evidence
Failure treatment
An unmatched cover enters investigation and cannot silently credit the wrong payment.

Status, return, and reporting

corr-beneficiary → corr-investigations

Report credit, rejection, return, and account evidence using original references.

Contract
message · asynchronous
Controls
  • Authentication and authorisation
  • Integrity and replay protection
  • Correlation and audit evidence
Failure treatment
Unmatched reports enter reconciliation rather than changing the wrong payment.

Recall or investigation outcome

corr-investigations → corr-originator

Return an evidence-based outcome to the original payment owner.

Contract
message · asynchronous
Controls
  • Authentication and authorisation
  • Integrity and replay protection
  • Correlation and audit evidence
Failure treatment
No funds promise is made until the receiving chain confirms the outcome.

Authored traces

CBPR+ customer transfer with cover

Follow the direct pacs.008 customer leg and its separately correlated pacs.009 COV settlement leg.

  1. Approve the cross-border payment — Customer authorised. The ordering side supplies complete party, account, purpose, amount, currency, and charge information.
  2. Choose the cover route — Route selected. The bank selects the beneficiary agent, reimbursement chain, standing settlement instructions, and current profiles.
  3. Clear the route and parties — Control cleared. Relevant parties, agents, addresses, and payment text pass the institution's controls.
  4. Record the sender-side position — Released for network. Customer and expected nostro effects are recorded under the bank's posting policy.
  5. Send interbank cover — Cover submitted. A pacs.009 COV moves through reimbursement agents with the underlying customer-transfer references.
  6. Match instruction and cover — Funds received. The beneficiary agent matches the customer-transfer information with settlement evidence.
  7. Credit the beneficiary — Beneficiary credited. The beneficiary account is credited once account, control, and funds conditions are satisfied.
  8. Report and reconcile — Reported and reconciled. Status and account reports close the business and nostro evidence.

Stress cases

Customer leg arrives before cover

The beneficiary agent receives the pacs.008 but cannot match settlement cover.

Last confirmed state
Customer-transfer information received; cover is not confirmed.
Settlement
Settlement remains unconfirmed for the beneficiary agent.
Funds and entries
Beneficiary credit follows the bank's controlled pending-cover policy; no duplicate cover is sent.
Next owner
Beneficiary payment operations and nostro investigations
Safe action
Hold or pend under policy, trace the pacs.009 COV by original references, and do not manufacture settlement evidence.
Evidence required
  • pacs.008 references
  • pacs.009 COV references
  • Reimbursement-agent status
  • Nostro entry
Recovery
  • Match late cover
  • Credit once conditions are met
  • Escalate or return under the applicable process if cover cannot be established

Intermediary screening hold

An intermediary identifies a potential sanctions match after the sending bank has released the payment.

Last confirmed state
Payment released by the debtor agent and held within the correspondent chain.
Settlement
Depends on the exact link at which the hold occurred; do not infer final settlement.
Funds and entries
Customer debit and correspondent entries may already exist; the held bank controls onward movement.
Next owner
Holding bank financial crime operations with correspondent investigations
Safe action
Preserve the hold, answer requests through authorised channels, and establish settlement and ledger state before any funds action.
Evidence required
  • Holding institution
  • Payment references
  • Alert disposition
  • Account entries
  • Request/response trail
Recovery
  • Resolve the alert
  • Continue or return according to lawful policy
  • Reconcile every affected bilateral account

Recall after settlement

The debtor side requests cancellation after the beneficiary agent has credited the payment.

Last confirmed state
Beneficiary credited.
Settlement
Settlement has occurred; a recall request does not reverse finality by itself.
Funds and entries
Funds are with the beneficiary unless recovered under the applicable process and consent or law.
Next owner
Cross-border investigations at both agents
Safe action
Send a correlated recall or investigation request, state the completed settlement, and never promise recovery before a confirmed response.
Evidence required
  • Original instruction
  • Settlement evidence
  • Beneficiary credit state
  • Recall reason and authority
Recovery
  • Request recovery
  • Record response
  • Return funds only through an authorised, reconciled transaction

Design decisions

When is serial or cover routing appropriate?

  • Serial — Payment information and settlement move link by link; each intermediary changes the bilateral account position.
  • Cover — Customer information reaches the beneficiary agent directly while a separate reimbursement chain carries settlement.

Choose from reachability, account relationships, currency, transparency, cost, and service rules. Preserve original references in either model.

What evidence permits beneficiary credit?

  • Confirmed funds or cover — Reduces credit exposure but can delay the customer outcome.
  • Credit under bilateral policy — Improves speed but creates explicit intraday or correspondent credit risk.

Document the exact posting and risk policy. A received payment instruction is not automatically settlement evidence.

Sources and disclosed synthesis