Customer due diligence (CDD) is the set of regulated procedures by which a financial institution or obliged entity identifies and verifies a customer, understands the nature and purpose of the business relationship, and assesses the money-laundering and terrorist-financing risk it poses. It encompasses identity verification, beneficial-ownership identification, screening against sanctions and politically exposed person lists, and ongoing monitoring of transactions and risk profile. CDD is a core obligation of anti-money-laundering regimes, calibrated through a risk-based approach that escalates to enhanced due diligence for higher-risk customers and permits simplified measures for lower-risk ones.
Overview
- CDD requirements derive from the FATF Recommendations, transposed into national law such as the EU Anti-Money Laundering Directives and the US Bank Secrecy Act regime.
- It applies not only to banks but to a broad set of obliged entities including payment firms, virtual-asset service providers, accountants, lawyers, and high-value dealers.
- The depth of due diligence scales with assessed risk: simplified for low-risk relationships, standard for ordinary customers, and Enhanced Due Diligence for high-risk customers, jurisdictions, or products.
- CDD is a lifecycle obligation, not a one-off check, requiring periodic review and event-driven re-verification throughout the relationship.
Key aspects
Identification and verification
- Collecting and independently verifying customer identity using reliable documents, data, or electronic Identity Verification sources.
- For legal entities, identifying the Beneficial Ownership structure to the natural persons who ultimately control the customer.
Risk assessment
- Applying a Risk-Based Approach that weighs customer type, geography, product, channel, and transaction patterns.
- Identifying Politically Exposed Person status and applying senior-management approval and source-of-wealth checks.
Screening
- Sanctions Screening against consolidated lists and adverse-media checks at onboarding and on an ongoing basis.
Mechanisms
Onboarding
- At account opening the institution gathers KYC information, verifies identity, and assigns an initial risk rating before activating the relationship.
Ongoing monitoring
- Transaction Monitoring systems flag activity inconsistent with the expected profile, triggering review and potential suspicious-activity reporting.
Periodic and trigger-based review
- Risk ratings and customer information are refreshed on a schedule and whenever material changes (ownership, behaviour, sanctions designation) occur.
Applications
- Account onboarding — banks and fintechs run CDD before granting access to payment and credit services, supporting Regulatory Compliance.
- Correspondent banking — enhanced CDD governs cross-border relationships with respondent banks.
- Virtual-asset onboarding — exchanges apply CDD and the FATF travel rule to crypto customers, often bridging to Digital Identity solutions.
- Trade and corporate finance — beneficial-ownership verification underpins lending to complex corporate structures.
- Periodic reviews — institutions re-run due diligence to keep risk ratings and customer data current across the portfolio.