Language

Customer Due Diligence (CDD)

What Is Customer Due Diligence (CDD)?

Customer due diligence (CDD) is the process organizations use to identify customers, verify their identities, understand the purpose and intended nature of the business relationship, assess their risk profiles, and monitor the relationship over time. It supports anti-money laundering (AML) compliance by helping organizations understand expected customer activity and determine whether additional checks are required.
CDD is commonly treated as a core component of Know Your Customer (KYC), although the terminology varies across jurisdictions. Some regulators and organizations use KYC and CDD almost interchangeably, while others use KYC for the broader compliance framework and CDD for the specific measures applied within it.

How Does Customer Due Diligence (CDD) Work?

A typical CDD process includes the following steps:
  • Customer identification and verification. The organization collects identifying information and verifies it using reliable sources, such as identity documents, biometric checks, or official records. For legal entities, it also identifies beneficial owners and examines the ownership and control structure.
  • Risk assessment. The customer is assessed based on factors such as location, occupation or industry, ownership structure, expected activity, transaction behavior, etc.
  • Screening. Customer and beneficial-owner data may be checked against sanctions lists, Politically Exposed Person (PEP) databases, and relevant adverse-media sources. A match should be reviewed before action is taken, since automated screening can produce false positives.
  • Ongoing monitoring. The organization monitors the business relationship and relevant transactions for activity that does not match the customer’s expected profile. Unusual patterns may trigger further investigation, updated CDD, or EDD.
  • Record-keeping. Identity records, risk assessments, transaction information, screening results, and investigation records are retained for the period required by applicable law. These records support regulatory audits and future financial-crime investigations.
CDD continues throughout the business relationship. A review may be triggered when:
  • Customer activity no longer matches the expected profile
  • The ownership or control structure changes
  • Existing customer information becomes outdated or unreliable
  • Account activity suggests that a different person may be in control

Who Must Apply Customer Due Diligence (CDD)?

CDD requirements apply to organizations covered by AML and other financial-crime regulations. These commonly include banks, payment providers, fintech companies, cryptocurrency exchanges, remittance services, gambling operators, and certain non-financial businesses and professions. The exact scope depends on national law and the activities the organization performs.
The level of CDD is determined by risk. Where permitted by law, lower-risk relationships may be subject to simplified due diligence, moderate-risk relationships to standard CDD, and higher-risk relationships to enhanced due diligence (EDD).

How Can Regula Help with Customer Due Diligence (CDD)?

CDD begins with reliable identity information. Regula provides document and biometric checks that help confirm that an applicant presents a genuine identity document and matches its portrait.
Regula Document Reader SDK verifies identity documents and extracts personal data for use in CDD records. It processes information from the visual zone using OCR, the machine-readable zone (MRZ), and NFC/RFID chips. The SDK supports more than 16,500 document templates from 254 countries and territories.
Regula Face SDK performs a 1:1 comparison between the applicant’s current facial image and the document portrait. Active liveness asks the user to follow an on-screen instruction, while passive liveness analyzes the captured image or video without requiring an additional action. Face matching and liveness detection help confirm that the applicant is present and matches the document holder. The results can support later screening, monitoring, and investigations as part of the customer’s CDD record.

FAQ

How does customer due diligence relate to Know Your Customer (KYC)?

CDD is commonly treated as a core component of the broader KYC framework. It covers measures such as customer identification and verification, understanding the purpose of the relationship, assessing risk, and conducting ongoing monitoring. However, terminology varies across jurisdictions: some regulators and organizations use KYC and CDD almost interchangeably, while others use KYC as the broader term and CDD for the specific measures within it.

When does customer due diligence move to enhanced due diligence (EDD)?

EDD is required when a customer or business relationship presents a higher risk of money laundering or other financial crime. Triggers may include links to high-risk jurisdictions, politically exposed persons, complex ownership structures, unusual activity, or concerns about the source of funds. The exact measures depend on applicable regulations and the organization’s risk-based policy.

Does customer due diligence end after account opening?

No. CDD continues throughout the business relationship through ongoing monitoring and periodic or event-driven reviews. A new review may be required when customer information becomes outdated, ownership changes, activity no longer matches the expected profile, or another person appears to control the account. The customer’s risk rating may also be updated when new information becomes available.

How does CDD support anti-money laundering (AML) compliance?

AML is the broader framework for preventing, detecting, and reporting money laundering. CDD supports that framework by helping organizations understand who their customers are, what activity to expect, and what level of risk they present. This information makes screening, transaction monitoring, and investigations more effective.

Why are beneficial owners identified during CDD?

A legal entity may be controlled by individuals whose names do not appear clearly in its public-facing records. Identifying beneficial owners helps an organization understand who ultimately owns or controls the customer. This can reveal hidden sanctions exposure, links to politically exposed persons, or ownership structures used to conceal financial crime.

On our website, we use cookies to collect technical information. In particular, we process the IP address of your location to personalize the content of the site

Cookie Policy rules