Simplified Due Diligence: What It Is, What Regulators Expect, and What Gets You Cited
Simplified Due Diligence (SDD) is a risk-proportionate tier of customer due diligence that lets regulated financial institutions apply reduced verification and lighter ongoing monitoring to customers assessed as genuinely low risk. It's authorized under FATF Recommendation 10 and codified in the EU's Fourth Anti-Money Laundering Directive (AMLD4, Article 15) and the UK Money Laundering Regulations 2017 (Regulation 37).
What is Simplified Due Diligence?
Simplified Due Diligence (SDD) is a risk-proportionate tier of Customer Due Diligence (CDD) that allows regulated financial institutions to apply reduced identity verification, lower documentation thresholds, and less frequent ongoing monitoring to customer relationships assessed as presenting genuinely low money laundering or terrorist financing risk. It also appears as "reduced due diligence" or "simplified CDD" in supervisory guidance.
SDD sits within the broader Know Your Customer (KYC) framework. The logic is straightforward: if a relationship genuinely carries low risk, applying the same scrutiny as a high-risk correspondent banking relationship wastes compliance resources and creates friction for legitimate customers. SDD is the calibration mechanism that matches effort to actual risk.
SDD is not a blanket exemption from CDD, and the qualifying condition is documentation. Regulators don't accept intuition. A firm can apply simplified measures only where it holds evidence that the customer, product, or transaction type meets pre-defined low-risk criteria set out in national legislation. If that risk assessment changes, the firm must escalate to standard CDD or Enhanced Due Diligence (EDD). Getting that line wrong is one of the most common findings examiners raise in this space. The control requires active management, not a one-time classification at onboarding.
Categories that commonly qualify:
- Regulated financial institutions licensed in FATF-equivalent jurisdictions
- Publicly listed companies on recognized stock exchanges
- Central and local government bodies in low-risk jurisdictions
- Low-risk financial products: basic savings accounts, insurance policies with annual premiums below defined thresholds, occupational pension schemes with no early surrender options
What SDD actually reduces: the depth of initial identification, the volume of documents collected, and the frequency of periodic review. It doesn't eliminate the obligation to conduct due diligence. You still need to know who the customer is, what they do, and whether the relationship is consistent with your expectations. Firms must still collect enough information to detect suspicious behavior, and if a customer on an SDD path starts generating unusual transactions the obligation to file a Suspicious Activity Report (SAR) is unchanged. SDD doesn't suspend it.
The contrast with Enhanced Due Diligence (EDD) is direct. EDD adds documentation, senior management sign-off, and source-of-wealth verification. SDD removes process steps. They sit at opposite ends of the spectrum, with standard CDD in between. The simplification is real, but it's bounded by what the customer's risk profile actually supports.
Why is Simplified Due Diligence required?
The authorization for SDD flows from the risk-based approach at the core of modern AML/CTF regulation. FATF Recommendation 10 on Customer Due Diligence explicitly permits countries and regulated entities to apply simplified measures "where the risks of money laundering and terrorist financing are lower." It sits alongside FATF Recommendation 1, which establishes that compliance resources should be directed proportionately to actual risk rather than distributed uniformly.
One detail in the Forty Recommendations is frequently missed: national regulators, not individual firms, define which categories qualify for simplified measures. A firm decides whether a specific customer fits a pre-approved category. It can't invent new low-risk categories on its own.
In the European Union, the framework sits in Articles 15 to 17 of AMLD4 (Directive 2015/849), which set the conditions under which firms may apply SDD and require documented identification of the low-risk factors that justify it. Article 16 lists the indicators: geographic factors such as customers from EU member states or equivalent third countries, customer type such as regulated financial institutions, listed companies and public bodies, and product characteristics such as low transaction limits, no cash function, and purpose-limited use. AMLD5 (Directive 2018/843) tightened these provisions following supervisory failures at banks including those involved in the Danske Bank 2018 enforcement action, where inadequate risk differentiation between customer types contributed to one of the largest AML failures in European banking history. The incoming 6AMLD, to be transposed by 2027, tightens eligibility criteria further and introduces harmonized definitions across member states.
In the United States, the Bank Secrecy Act has no equivalent to the SDD label, and the distinction matters in practice. The Customer Identification Program rule for banks (31 CFR § 1020.220) sets a minimum standard of identity verification that applies to every customer and cannot be reduced on risk grounds. What can be calibrated is the depth of due diligence layered on top: FinCEN's Customer Due Diligence Rule permits firms to tailor procedures to each customer category's assessed risk, so lower-risk customers are handled with lighter procedures. The practical effect resembles SDD, but a US firm reaches it by scaling within the CDD obligation rather than by invoking a separate simplified tier.
In the UK, Regulation 37 of the MLR 2017 grants firms discretion to apply simplified measures where, after conducting a risk assessment, they can demonstrate the relationship presents a lower degree of risk. The FCA's Financial Crime Guide, Section 5 is direct: if a firm can't explain why a customer qualified for SDD, the regulator treats it as a CDD failure, not a valid application of simplified measures. The Guide also makes SDD conditional on ongoing monitoring continuing at a frequency appropriate to the assessed risk. Monitoring doesn't stop; it's calibrated down.
The clearest recent enforcement example: the FCA fined Santander UK £107.7 million in December 2022 partly for correspondent banking due diligence failures, including cases where simplified measures were applied without documented justification. That case made the principle plain. SDD requires a paper trail, not just a risk score in a system field.
How is Simplified Due Diligence (SDD) used in practice?
The SDD workflow typically starts at onboarding. When a new customer is classified as low-risk and matches an approved SDD category, the compliance system routes them to the simplified path. That means collecting a single government-issued ID instead of multiple documents, skipping the source-of-funds questionnaire, omitting full Ultimate Beneficial Owner (UBO) verification for certain entity types, and setting the periodic review cycle to three to five years instead of the annual cadence applied to standard CDD customers.
The most common real-world scenario is correspondent banking. When a bank onboards another regulated institution, say a German savings bank supervised by BaFin and listed on a recognized exchange, it can apply SDD without collecting beneficial ownership documentation on that institution's underlying customers. That's a significant reduction in both onboarding time and documentation overhead.
On the consumer product side, basic prepaid accounts frequently qualify. A card capped at 150 EUR per transaction with no cash withdrawal function typically meets the criteria under Article 16 of 5AMLD. The same logic applies to certain low-premium life insurance policies and employer pension schemes where the funds are managed by a regulated entity.
For teams using automated onboarding platforms, SDD eligibility is encoded as a conditional branch. If a customer's risk score is below threshold AND their category matches an approved SDD type, the system triggers the simplified path automatically. That cuts analyst touchpoints and shortens the onboarding journey without reducing compliance coverage.
The risk that experienced MLROs flag most often is category drift. A customer who qualified for SDD at onboarding may not qualify 18 months later. Public companies get delisted. Correspondent banks lose their regulatory licenses. SDD is a snapshot classification, not a permanent status. Mature programs run a separate annual category validation, distinct from the periodic review cycle, to catch changes before an examiner finds them first.
Transaction monitoring for SDD customers runs with higher thresholds and fewer alert types. But the monitoring doesn't stop. If a customer on an SDD path starts generating high-volume cross-border transfers, a well-configured system escalates their risk rating and re-routes them to standard CDD or EDD automatically.
What do regulators expect to see?
On exam day, examiners aren't looking for a policy document that mentions SDD. They want evidence the control actually operates as documented. Here's what that means in practice.
A documented risk assessment per customer segment. Firms must demonstrate they evaluated the risk factors listed in applicable regulations (AMLD4 Annex II; JMLSG guidance) before applying SDD to any customer type. A generic "low-risk" label attached to a category without supporting analysis won't survive scrutiny.
A written, board-approved SDD policy with specific eligibility criteria. Which customer types qualify? Which products? When does the classification expire or require review? Examiners expect clear criteria, not ad hoc decisions made at the relationship manager level.
Calibrated ongoing monitoring. SDD doesn't mean no monitoring. Transaction Monitoring rules for SDD-classified customers should be documented separately, with alert thresholds and review frequencies justified by the risk rationale. Switching off monitoring for the SDD tier is a findings-generating error.
Evidence of trigger-based and periodic review. Customer risk classifications don't stay static. Regulators expect a formal review process that fires when transaction patterns change, adverse news appears, or on a scheduled cycle (at minimum annually for SDD portfolios).
Governance and escalation trails. Who approved the SDD framework? Who reviews outliers? Is there a documented escalation path to standard CDD or EDD? Examiners look for clear accountability at each decision point.
Board-level MI. Senior management and the board should receive regular reporting on the size of the SDD portfolio, the proportion that triggered reclassification, and any anomalies. Absence of board MI is a recurring finding in thematic reviews.
Records in line with FATF Recommendation 11. Documentation supporting the SDD determination must be retained for at least five years and available to regulators on request. This includes the risk assessment itself, not just the customer file.
What does good Simplified Due Diligence look like?
Best-practice SDD programs share characteristics that FATF's guidance on the Risk-Based Approach for the Banking Sector and the Wolfsberg Group's AML Principles both point toward. Where it can be expressed as steps, here is how well-run programs operate:
Risk categorization is specific, not generic. Good programs identify precise customer types eligible for SDD: domestic listed companies on regulated exchanges, domestic public authorities, subsidiaries of entities subject to equivalent AML/CTF requirements. Broad buckets like "corporate" or "domestic retail" aren't sufficient on their own.
Low-risk eligibility is documented at onboarding. The rationale for SDD classification is captured in the customer record at the time onboarding occurs, with specific risk factors cited by reference to regulatory criteria. This is the audit trail that survives examination.
Ongoing monitoring continues, calibrated down. A domestic government entity in the SDD tier might receive annual relationship reviews rather than quarterly, but transaction monitoring still runs continuously. Review frequency drops; monitoring doesn't stop.
Trigger-based reclassification operates automatically. Any change in transaction behavior, adverse media hit, or sanctions list match escalates the customer out of SDD to standard CDD or EDD review. This is an automated system function, not a manual process relying on analyst judgment.
Regular backtesting validates the SDD population. Firms test whether SDD-classified customers actually behave like low-risk customers. If 15% of the SDD portfolio is generating transaction monitoring alerts, the classification criteria need revisiting.
Policies are reviewed at least annually. Regulatory change, product changes, or shifts in the firm's risk appetite all require a formal review of which customers still qualify for simplified measures.
The Basel Committee's 2017 guidelines on sound management of ML/TF risks (BCBS 353) and the FCA's financial crime thematic reviews both reach the same conclusion: the quality of the underlying risk assessment determines whether SDD reduces unnecessary friction or conceals it.
Common challenges and how to address them
The most frequent mistake compliance teams make is treating SDD as a one-time classification. A customer gets approved for the SDD path at onboarding and isn't reviewed for five years. The FCA cited "set and forget" SDD classifications as a recurring deficiency in its 2022 supervisory findings on money laundering controls. Circumstances change. The classification has to keep pace.
Documentation gaps are the second problem. Applying SDD without a recorded rationale is functionally the same as not applying it at all. During an AML exam, examiners ask for the specific factor that justified reduced measures. "They're a regulated bank" doesn't pass muster. You need the jurisdiction's equivalence status, the entity's licensing details, and the date of the assessment recorded in the customer file.
Third: transaction monitoring calibration. SDD customers get higher alert thresholds. That's defensible when the risk profile justifies it, but static thresholds create a blind spot when behavior changes. Dynamic thresholding, where the system tightens monitoring automatically as a customer's activity deviates from their expected pattern, removes that blind spot. Several Regulatory Compliance Automation platforms now support behavioral baseline monitoring that adjusts thresholds at the individual customer level, not just the category level.
Fourth: correspondent banking scope errors. Applying SDD to a correspondent institution doesn't mean you accept that institution's underlying customers at SDD level. The SDD applies to the institution itself. Transactions flowing through the correspondent on behalf of high-risk underlying customers still need appropriate scrutiny. This distinction has been a direct contributor to enforcement action.
A practical annual review framework works like this: confirm the customer still meets the qualifying criteria; compare their recent transaction profile against the baseline established at onboarding; verify no changes in sanctions status, adverse media coverage, or regulatory standing. The FCA Financial Crime Guide Section 5.3 sets a workable baseline for what "adequate ongoing monitoring" looks like in SDD relationships. Automating these three checks removes the manual burden without creating coverage gaps.
Common audit findings and exam citations
SDD failures that lead to regulatory action fall into four recurring patterns.
Blanket SDD application without documented risk rationale. The FCA and EBA have cited firms that applied SDD to entire customer segments ("all SMEs," "all online accounts") without conducting segment-level risk assessments. The policy existed. The analysis underpinning it didn't.
No ongoing monitoring. The mistaken belief that SDD means no transaction monitoring is a persistent finding. The Danske Bank 2018 enforcement action illustrates the scale of damage when institutions fail to monitor non-resident portfolios regardless of their nominal risk classification. Danske Bank's Estonian branch processed approximately €200 billion in suspicious transactions over a decade, partly because adequate controls were never applied to what were treated as lower-scrutiny relationships. The branch's non-resident portfolio was a de facto SDD population with no meaningful transaction monitoring.
Failure to reclassify. Customers who trigger alerts or appear in adverse media remain in the SDD tier because there's no automated escalation mechanism. The FCA's 2021 Financial Crime Annual Report identified this as a systemic weakness across multiple mid-tier banks.
Weak documentation. When examiners ask for the rationale behind a specific customer's SDD classification, they receive either nothing or a generic template with no customer-specific analysis. This is particularly damaging for SAR filings: if a customer in the SDD tier later generates a suspicious activity report, the institution needs to show why SDD was appropriate at onboarding. Without that documentation, the firm's defence collapses.
Stale risk assessments. SDD classifications from 2019 or 2020 with no review since, applied to customers whose transaction profiles look nothing like the original assessment. This is a live exam finding in 2024 and 2025 across both the FCA and the European Banking Authority's AML supervisory peer reviews.
Metrics and KPIs
Measuring SDD control health requires visibility into three areas: the accuracy of the risk classification, the behavior of the SDD population, and the responsiveness of the reclassification mechanism.
SDD population size and trend. What percentage of the customer base is classified SDD? A ratio above 60-70% in a retail bank warrants internal challenge. If that percentage rises sharply quarter-on-quarter without a corresponding explanation in the business, either risk assessment criteria have loosened or the customer base has shifted in profile.
Reclassification rate. How many SDD customers were escalated to standard CDD or EDD in the period? Zero is a red flag. A well-calibrated program shows a small but non-zero reclassification rate, typically 1-3% quarterly in a stable retail portfolio.
Alert rate for SDD customers. What proportion of transaction monitoring alerts originate from SDD-classified customers? If SDD customers generate alerts at a rate approaching standard-risk customers, the classification criteria are wrong, not the customers.
Time to reclassify. When a trigger fires (adverse media, an alert above threshold, a sanctions hit), how long does it take to reclassify and review the customer? Best-practice programs achieve under 24 hours for automated triggers.
Policy review frequency. Is the SDD policy reviewed at least annually, with documented sign-off from the MLRO and the relevant governance body? This should appear in committee minutes, not just on a checklist.
Documentation completeness rate. What percentage of SDD-classified customers have a complete, current risk rationale on file? This should be 100%. Below 95% is an exam risk.
These metrics belong in regular board MI and MLRO reporting, not just internal audit packs. Gaps in any of these measures are precisely what examiners focus on in thematic reviews.
How Simplified Due Diligence connects to other controls
SDD is a calibration point within the broader KYC lifecycle. It doesn't stand alone.
Customer Due Diligence is the parent control, and SDD is one tier within it alongside standard CDD and EDD. The risk assessment that determines SDD eligibility also feeds into Sanctions Screening and PEP Screening frequencies. A customer in the SDD tier still goes through sanctions and PEP checks at onboarding and on a scheduled basis thereafter. The difference is the frequency and depth of ongoing review, not whether the checks happen at all.
Transaction Monitoring is the runtime control that validates the SDD classification over time. When monitoring produces alerts inconsistent with the SDD tier, that's the signal to reclassify. The two controls need to be connected operationally: a spike in alerts from the SDD population should trigger a review of the classification criteria, not just the individual customer file.
On the typology side, SDD weaknesses most commonly surface in Smurfing and Structuring schemes, where criminals deliberately target lower-monitoring tiers. Structured deposits can stay below alert thresholds calibrated for low-risk customers while moving significant volumes. Money Mule Networks exploit SDD classifications when mule accounts are established using customer profiles that initially qualify for simplified measures, such as students or low-income domestic workers whose early transaction behavior appears low-risk.
The escalation pathway from SDD through standard CDD to EDD is what holds the customer risk profile together across the relationship lifecycle. A firm that can't trace that path in its system documentation has a governance gap examiners will find.
For entity customers, SDD intersects with Know Your Business (KYB) obligations. Even under SDD, firms need to understand what the business does and where it operates. SDD typically exempts firms from full Ultimate Beneficial Owner (UBO) verification for certain entity types, such as regulated financial institutions where ownership disclosure is already a regulatory requirement. That exemption has limits. If the firm has any reason to question the entity's legitimacy, the SDD path is closed.
From a reporting perspective, SDD affects trigger thresholds for Suspicious Transaction Reports (STR). Higher thresholds mean fewer alerts, which is the intended efficiency gain. But the underlying reporting obligation doesn't change. A suspicious transaction on an SDD account still requires a report.
For firms managing large customer volumes, AML Transaction Monitoring Rules Tuning is where SDD classifications translate directly into monitoring rule parameters. Thresholds set too high miss genuine alerts. Thresholds set too low generate noise that overwhelms analysts. Getting that calibration right is where the SDD tier makes its biggest practical difference, and where poorly governed SDD programs tend to break down first.
How FluxForce supports Simplified Due Diligence
FluxForce AI agents continuously monitor SDD-classified customer behavior. When patterns are inconsistent with the assessed risk tier, the system flags them and triggers reclassification workflows automatically. Nova Sentinel's behavioral analytics detect structured activity and mule network patterns in populations that standard controls may underweight. Every SDD classification decision, threshold adjustment, and reclassification event is captured with full audit evidence. Exam preparation becomes straightforward. For teams managing large SDD portfolios across multiple jurisdictions, FluxForce's Regulatory Compliance Automation capabilities reduce manual review burden and keep documentation audit-ready. Book a demo to see it in action.
How FluxForce strengthens Simplified Due Diligence
FluxForce AI agents operate Simplified Due Diligence in real time, capture audit-ready evidence automatically, and surface the gaps examiners cite before they become findings.