KYC

Customer Due Diligence: What It Is, What Regulators Expect, and What Gets You Cited

Published: Last updated: Also known as: CDD

Customer Due Diligence (CDD) is the process through which financial institutions verify customer identity, understand the purpose of business relationships, and assess money laundering and terrorist financing risk. It's required under FATF Recommendation 10, the EU's 6th Anti-Money Laundering Directive, and FinCEN's 2016 CDD Final Rule under the US Bank Secrecy Act.

What is Customer Due Diligence?

Customer Due Diligence (CDD) is the process of verifying who a customer is, understanding why they want access to a product or service, and assessing the money laundering and terrorist financing risk they present to the institution. It's a foundational control in any AML/CFT program, applied at onboarding and maintained throughout the customer lifecycle.

FATF's Recommendation 10 defines four core elements: identify the customer, verify that identity using reliable independent sources, identify beneficial owners of legal entity customers, and monitor the relationship on an ongoing basis. Those four elements are the shape of the control everywhere it appears, whatever the local statute calls it.

CDD operates at three levels. Standard CDD covers identity verification, collection of beneficial ownership information for legal entities, and an assessment of the intended nature and purpose of the business relationship. Simplified Due Diligence (SDD) is permitted for demonstrably lower-risk customer types, such as listed public companies or certain government bodies, where documentary requirements can be reduced proportionate to the risk. Enhanced Due Diligence (EDD) applies to higher-risk relationships: politically exposed persons, customers in high-risk jurisdictions, correspondent banking counterparties, and complex ownership structures that obscure the ultimate beneficial owner. A salaried employee opening a basic checking account and a foreign national establishing a private banking relationship through offshore structures do not get the same treatment, and they aren't meant to.

CDD sits within the broader Know Your Customer (KYC) framework. KYC is the overarching obligation to understand who customers are; CDD is the structured process that delivers that understanding. The two terms are often used interchangeably, but CDD is more specific. It's the documented procedure with defined tiers, clear triggers, and periodic review requirements. Know Your Business (KYB) is the corporate-specific extension, covering entity verification, ownership structure, and business activity screening for legal entity customers.

The obligation runs to the institution, not the customer. A customer who declines to provide the information required to complete CDD cannot proceed. Institutions can't waive this requirement, and regulators don't accept "customer refused" as a justification for incomplete files.

CDD doesn't end at account opening. Transaction monitoring continuously tests whether customer behavior matches their stated profile. A manufacturing company that starts receiving large cash deposits from shell entities should trigger a CDD refresh, going well beyond a standard transaction alert.


Why is Customer Due Diligence required?

The international standard is FATF Recommendation 10, which requires financial institutions to apply CDD measures when establishing business relationships, executing occasional transactions above €15,000 (or the applicable local threshold), when there's suspicion of money laundering or terrorist financing, or when the institution doubts the accuracy of previously collected identification data. All 39 FATF member jurisdictions are expected to transpose it into national law. The FATF Rec 1 risk-based approach governs how CDD is calibrated across customer segments: institutions must direct resources proportionate to risk, which means the depth of due diligence isn't uniform.

FATF Rec 12 extends Recommendation 10 specifically to politically exposed persons, requiring EDD for any customer identified as a PEP, their family members, and close associates. That obligation isn't discretionary or tiered by perceived seniority. PEP status triggers EDD, full stop.

FATF Rec 11 extends the requirement further: institutions must retain CDD records for at least five years from the end of the business relationship. Regulators don't just want evidence that CDD was completed; they want to see when it was done, by whom, and on what evidentiary basis.

In the United States, the legal obligation flows from the Bank Secrecy Act, implemented through FinCEN's Customer Due Diligence Rule, effective May 2018. Two provisions carry it. 31 CFR § 1010.230 sets the beneficial ownership requirement, mandating identity confirmation for any natural person who owns 25% or more of a legal entity customer plus one controlling person. 31 CFR § 1020.210 embeds ongoing monitoring in the AML program obligation itself, the addition usually described as the fifth pillar. Covered institutions include banks, credit unions, broker-dealers, mutual funds, and futures commission merchants. The beneficial ownership requirement significantly increased KYB workloads across the industry.

In the European Union, CDD is governed by successive Anti-Money Laundering Directives. The Fourth AMLD (2015) aligned EU requirements with FATF standards. The Fifth AMLD (2018) added public beneficial ownership registers and tightened due diligence for high-risk third country transactions. The Sixth AMLD (2020) expanded predicate offenses and introduced personal criminal liability for senior managers who fail to prevent money laundering.

In the UK, the Money Laundering, Terrorist Financing and Transfer of Funds Regulations 2017 (MLR 2017) implement equivalent requirements, with the FCA expecting risk-proportionate CDD across the full customer book. The FCA fined NatWest £264.8 million in 2021 for AML failures that included deficient CDD on a cash-intensive customer who deposited £365 million in cash over five years. That remains the largest AML penalty in FCA history.

The Danske Bank 2018 enforcement action is the defining case study. Approximately €200 billion flowed through Danske's Estonian branch over nine years, with the bank's own post-mortem acknowledging that CDD on non-resident customers was fundamentally inadequate. The failure to verify beneficial ownership structures enabled layering at a scale that would have been visible with a functioning CDD program.

Inadequate CDD carries serious consequences: civil monetary penalties, regulator-imposed remediation programs, and in the most severe cases, consent orders that restrict business activity.


How is Customer Due Diligence (CDD) used in practice?

In a typical bank, CDD starts the moment a new customer application arrives. The compliance team, or an automated onboarding system, collects identity documents, runs them through an identity verification service, screens names against sanctions lists and PEP databases, and assigns a risk rating. All of that happens before the account opens.

For individual customers, the document set is straightforward: a passport or national ID, proof of address, and sometimes source-of-funds documentation for higher-value accounts. For business customers, the process is more involved. The onboarding team needs registration documents, an ownership chart, and verified identity for anyone who owns 25% or more. That's where Ultimate Beneficial Owner (UBO) verification becomes central to the CDD workflow.

Once the account is open, CDD is ongoing. Transaction monitoring flags activity that diverges from the customer's stated risk profile. A retail customer who said they'd move $3,000 per month and starts receiving $50,000 international wire transfers needs a CDD review. That review may result in a risk re-rating, a documentation request, or, if the activity can't be explained, a Suspicious Activity Report (SAR).

Periodic reviews complete the cycle. Most banks schedule these by risk tier: annually for high-risk accounts, every two to three years for standard ones. Trigger events, like sanctions screening hits or negative news, accelerate the schedule outside the normal cycle.

Teams using Identity Verification and KYC/AML Automation can automate document collection, screening, and review scheduling. Automation cuts time per case from hours to minutes. The final risk rating decision stays with the compliance officer.


What do regulators expect to see?

On an exam day, regulators look for evidence that the CDD program is documented, risk-calibrated, consistently applied, and independently tested. In concrete terms, this is what they want to find.

Documented CDD policies and procedures. A current policy that defines the three tiers, the criteria for each, who approves exceptions, how decisions are recorded, and what happens when a customer doesn't cooperate. Procedures should be detailed enough that a new analyst could apply them consistently without additional instruction.

Risk-based customer risk ratings. A written methodology showing how customer risk scores are calculated: what inputs drive them (jurisdiction, business type, product, channel, ownership structure, PEP status), how those inputs are weighted, and how the resulting score determines the CDD tier and review frequency.

Beneficial ownership records. For legal entities, documented collection and independent verification of UBO data at or above the applicable threshold. Regulators check both whether the data was collected and whether it was actually verified against a reliable, independent source.

Periodic refresh schedules. CDD isn't an onboarding exercise. Higher-risk customers need annual reviews; mid-risk customers every two to three years; low-risk customers every four to five years at minimum. Regulators want documented schedules and evidence of compliance with them.

Enhanced Due Diligence (EDD) documentation. For PEPs, correspondent relationships, and customers from higher-risk countries, examiners want to see what additional steps were taken, who approved the relationship, what source-of-wealth evidence was collected, and the rationale for the ongoing monitoring frequency.

Independent testing records. Results from compliance testing or internal audit, the specific findings from those reviews, management responses, and evidence that issues were tracked to resolution. The feedback loop between testing and program improvement is what regulators want to see working.

MI and escalation trails. Committee minutes or equivalent documentation showing that CDD exception volumes, backlogs, and policy breaches were reported to senior management. The absence of board-level MI on CDD backlogs is itself a finding in most exam frameworks.


What does good Customer Due Diligence look like?

The FATF Guidance on Customer Due Diligence and Beneficial Ownership and the Wolfsberg AML Principles describe consistent characteristics of well-run CDD programs. At a practical level, good CDD follows this sequence.

  1. Risk-based customer classification at onboarding. The institution assigns a risk rating before account opening, using a written methodology covering customer type, geography, product, channel, and ownership structure. That rating determines the due diligence tier applied before the relationship begins.

  2. Identity verification using independent sources. Documentary verification (passport, national ID) combined with non-documentary methods such as database checks and biometric verification. Multiple independent sources reduce the chance that fabricated or synthetic identities pass onboarding.

  3. Beneficial ownership collection and verification. For legal entities, UBO identification down to the applicable ownership threshold, with verification against independent sources. Complex structures including trusts and multi-layered corporate chains are documented in full, with source-of-funds and source-of-wealth collected for higher-risk entities.

  4. Ongoing monitoring tied to risk tier. CDD files are reviewed on a schedule proportionate to risk. High-risk customers annually; mid-risk customers every two to three years; low-risk every four to five years at minimum. PEP Screening results and adverse media alerts can trigger out-of-cycle reviews between those intervals.

  5. EDD for higher-risk relationships. PEPs, correspondent bank relationships, and customers from higher-risk jurisdictions receive additional scrutiny: senior management approval before account opening, source-of-wealth documentation, and tighter review cycles than standard CDD.

  6. Automated alerts when profiles diverge. When observed transaction behavior no longer matches the expected profile established at CDD, the monitoring system flags the account for review. This is the feedback loop that keeps CDD and transaction monitoring aligned.

The Basel Committee's Sound Management of Risks Related to Money Laundering and Financing of Terrorism provides the governance framework for embedding CDD within a bank's broader risk management architecture, including how CDD findings should flow to senior management and board-level oversight.


Common challenges and how to address them

CDD sounds straightforward on paper. In practice, it generates more operational headaches than almost any other AML control.

The first problem is outdated customer profiles. Many banks opened accounts before the 2018 FinCEN CDD Rule took effect, with no beneficial ownership information on file. Remediating that backlog takes years for any institution with a large business account portfolio. Manual periodic review cycles add enormous volume without proportional staff increases.

Document quality is a persistent issue. Customers submit expired IDs, documents in languages the compliance team can't process, or ownership structures designed to obscure the real Beneficial Owner. The ownership question gets especially complicated with multi-tier holding companies and nominee shareholders in secrecy jurisdictions. A bank onboarding a Cayman Islands shell owned by a BVI holding company requires due diligence at each layer, not just the entity in the contract.

Cross-border relationships create a risk rating problem. A customer who qualifies as standard risk in one jurisdiction may be high risk in another, depending on local PEP definitions, sanctions exposure, or predicate offense classifications. Material ties to a FATF-designated high-risk jurisdiction require heightened scrutiny regardless of actual transaction behavior.

Alert fatigue in ongoing monitoring compounds everything. Rule-based transaction monitoring systems produce high proportions of false positive alerts. Analysts who spend most of their day clearing non-events have less capacity to investigate real risk. Better calibration of AML transaction monitoring rules is a direct lever for improving CDD quality.

A few approaches have reliably helped: risk-based questionnaires at onboarding tied to automated document collection, AI-based screening to cut false positive rates, and automated review scheduling to keep profiles current. None of these replace compliance officer judgment. They reduce the manual burden so analysts can work on genuine cases.


Common audit findings and exam citations

CDD is one of the most frequently cited failures in AML enforcement actions. The patterns repeat.

Stale CDD files. High-risk customers whose files haven't been refreshed in three or more years. Regulators treat this as a controls failure regardless of whether any suspicious activity occurred in the interval.

Incomplete beneficial ownership records. Legal entity customers where UBO data was collected at onboarding but never verified against independent sources, or where subsequent ownership changes weren't captured on periodic refresh.

Weak EDD documentation. PEP relationships or high-risk-country accounts labeled "EDD" in the system with no documentation of what additional steps were taken, who approved the relationship, or what source-of-wealth evidence was collected.

Exception backlogs without governance escalation. Thousands of expired CDD reviews, with no formal escalation to senior management or the board. The Westpac 2020 enforcement action resulted in a A$1.3 billion penalty (the largest in Australian corporate history at the time) and included systemic failures in customer identification and ongoing due diligence across more than 23 million alleged breaches of AML/CTF law.

Profile mismatches with no follow-up. Customers whose stated business purpose didn't match their actual transaction patterns, with no system in place to detect or investigate the discrepancy.

CDD and transaction monitoring operating in silos. Programs where the two controls ran independently with no mechanism for a transaction alert to initiate a CDD review, and no process for updating CDD files when a SAR was filed.

The HSBC 2012 enforcement action, which resulted in a $1.9 billion penalty, included specific findings on inadequate CDD applied to Mexican customers and correspondent banking relationships. Regulators found that HSBC's compliance function was systematically unable to manage basic CDD review cycles. That consent order remains a standard reference in exam-preparation programs.


Metrics and KPIs

A CDD program without measurement is a program that can't demonstrate effectiveness to regulators or its own board.

CDD file currency rate. The percentage of customer files reviewed within their required refresh cycle. A healthy program runs above 95%. Below 90%, most examiners treat it as a finding.

EDD refresh timeliness. Average days between scheduled and actual EDD review completion for high-risk customers. Systematic delays here are a governance indicator regulators test for specifically, not a secondary concern.

Beneficial ownership completion rate. The percentage of legal entity customers with fully documented and verified UBO data. Gaps in this number almost always trace to process failures at onboarding or weak exception management.

CDD exception volume and aging. How many accounts are in exception status and how long they've been there. Exceptions aged over 90 days without documented escalation are a consistent exam finding across jurisdictions.

Risk classification accuracy. If a disproportionate number of customers are classified as high-risk at onboarding and immediately downgraded after EDD, the initial methodology is over-sensitive. If virtually no customers in high-risk business lines are ever escalated to EDD, it's under-sensitive. Both patterns attract examiner attention.

Triggered review volume. How many out-of-cycle CDD reviews were initiated in the period, and what triggered them: SAR filings, PEP screening matches, adverse media alerts, or transaction pattern changes. A program generating near-zero triggered reviews in a high-risk business book almost certainly has a broken connection between monitoring and CDD functions.

FinCEN's Customer Due Diligence Final Rule FAQ provides additional measurement context for US-regulated institutions.


How Customer Due Diligence connects to other controls

CDD is the foundation other controls depend on.

Transaction Monitoring uses the customer risk profile to calibrate alert thresholds. If the CDD profile is stale or inaccurate, the calibration is wrong. An account reclassified as low-risk two years ago, with no refresh since, generates fewer alerts than current behavior may warrant. The two controls must share data bidirectionally to function correctly.

PEP Screening and sanctions screening are both inputs into CDD. A positive PEP match during onboarding or a routine refresh triggers EDD. A sanctions match triggers immediate account review and potential reporting obligations. These controls don't operate independently of CDD; they feed into it.

Adverse Media Screening provides an ongoing monitoring layer between scheduled CDD refresh cycles. A negative news alert about a customer can initiate an out-of-cycle review before the next scheduled date, often catching material risk changes before they escalate to a SAR or regulatory inquiry.

At the typology level, CDD is the primary defense against Synthetic Identity Fraud, where fabricated combinations of real and invented data are used to open accounts and generate a clean transaction history. Robust identity verification at the CDD stage catches synthetic identities before they enter the transaction monitoring layer.

CDD documentation also feeds SAR quality. A well-maintained CDD file gives the investigator the verified identity, the stated business purpose, and the expected transaction profile, which together produce a more accurate and defensible SAR narrative. Regulators expect CDD files to be updated when a SAR is filed; a file unchanged after a filing indicates a broken feedback loop between the SAR and CDD functions.

Enhanced Due Diligence (EDD) and Simplified Due Diligence (SDD) sit at either end of the same spectrum. EDD adds source-of-wealth verification, senior management approval, more frequent review cycles, and enhanced transaction monitoring, and it's mandatory for politically exposed persons, customers from high-risk jurisdictions, and certain correspondent banking relationships. SDD reduces verification requirements for demonstrably low-risk customers such as some government entities, listed companies, and regulated financial institutions, subject to regulatory approval.

When CDD monitoring identifies activity that can't be explained, the output is typically a Suspicious Activity Report (SAR) in the US or a Suspicious Transaction Report (STR) in many other jurisdictions. The SAR or STR is the direct regulatory output of effective CDD and transaction monitoring working together. Institutions that automate the chain from identity checks through to case escalation reduce time from alert to filing from days to hours.


How FluxForce supports Customer Due Diligence

FluxForce's AI agents automate the evidence collection and risk scoring that CDD programs require at scale. Aiden Flux continuously monitors customer profiles against observed transaction behavior and flags mismatches that indicate a stale or inaccurate risk classification. Nova Sentinel processes real-time PEP and adverse media signals and routes EDD triggers directly into case queues. Every decision produces a timestamped audit trail, so examiners see the full review history alongside the data inputs and analyst actions at each point. Request a demo to see the CDD workflow in practice.

How FluxForce strengthens Customer Due Diligence

FluxForce AI agents operate Customer Due Diligence in real time, capture audit-ready evidence automatically, and surface the gaps examiners cite before they become findings.

← Back to Controls