Customer Due Diligence (CDD)
What Is Customer Due Diligence (CDD)?
How Does Customer Due Diligence (CDD) Work?
- Customer identification and verification. The organization collects identifying information and verifies it using reliable sources, such as identity documents, biometric checks, or official records. For legal entities, it also identifies beneficial owners and examines the ownership and control structure.
- Risk assessment. The customer is assessed based on factors such as location, occupation or industry, ownership structure, expected activity, transaction behavior, etc.
- Screening. Customer and beneficial-owner data may be checked against sanctions lists, Politically Exposed Person (PEP) databases, and relevant adverse-media sources. A match should be reviewed before action is taken, since automated screening can produce false positives.
- Ongoing monitoring. The organization monitors the business relationship and relevant transactions for activity that does not match the customer’s expected profile. Unusual patterns may trigger further investigation, updated CDD, or EDD.
- Record-keeping. Identity records, risk assessments, transaction information, screening results, and investigation records are retained for the period required by applicable law. These records support regulatory audits and future financial-crime investigations.
- Customer activity no longer matches the expected profile
- The ownership or control structure changes
- Existing customer information becomes outdated or unreliable
- Account activity suggests that a different person may be in control
Who Must Apply Customer Due Diligence (CDD)?
How Can Regula Help with Customer Due Diligence (CDD)?
FAQ
How does customer due diligence relate to Know Your Customer (KYC)?
CDD is commonly treated as a core component of the broader KYC framework. It covers measures such as customer identification and verification, understanding the purpose of the relationship, assessing risk, and conducting ongoing monitoring. However, terminology varies across jurisdictions: some regulators and organizations use KYC and CDD almost interchangeably, while others use KYC as the broader term and CDD for the specific measures within it.
When does customer due diligence move to enhanced due diligence (EDD)?
EDD is required when a customer or business relationship presents a higher risk of money laundering or other financial crime. Triggers may include links to high-risk jurisdictions, politically exposed persons, complex ownership structures, unusual activity, or concerns about the source of funds. The exact measures depend on applicable regulations and the organization’s risk-based policy.
Does customer due diligence end after account opening?
No. CDD continues throughout the business relationship through ongoing monitoring and periodic or event-driven reviews. A new review may be required when customer information becomes outdated, ownership changes, activity no longer matches the expected profile, or another person appears to control the account. The customer’s risk rating may also be updated when new information becomes available.
How does CDD support anti-money laundering (AML) compliance?
AML is the broader framework for preventing, detecting, and reporting money laundering. CDD supports that framework by helping organizations understand who their customers are, what activity to expect, and what level of risk they present. This information makes screening, transaction monitoring, and investigations more effective.
Why are beneficial owners identified during CDD?
A legal entity may be controlled by individuals whose names do not appear clearly in its public-facing records. Identifying beneficial owners helps an organization understand who ultimately owns or controls the customer. This can reveal hidden sanctions exposure, links to politically exposed persons, or ownership structures used to conceal financial crime.