Customer Due Diligence Guide: Main Requirements, Best Practices & Checklist (2024)

In 2022 alone, banks and other financial organizations were fined almost $5 billion for failing to conduct proper customer due diligence.

Customer due diligence (CDD) is what every financial institution must conduct. Together with Know Your Customer (KYC) and Anti-Money Laundering (AML) regulations, it is one of the three essential components in the fight against financial crimes. Failure to perform adequate CDD may result in reputational damage and significant fines.

In this article, we explore the steps for performing CDD, provide you with practical tips and best practices, and explain the importance of compliance with these regulations.

What is customer due diligence?

Customer due diligence (CDD) is a series of checks that helps organizations assess and verify the identity of their customers. It aims to mitigate risks associated with money laundering, terrorism financing, fraud, and sanctions busting.

The customer due diligence process typically includes the following stages:

  1. Establishing customer identities
  2. Performing a customer risk assessment
  3. Collecting additional information (if required)
  4. Reporting suspicious activity

To collect necessary information for CDD, organizations turn to different sources, including the customer, sanctions lists, and public and private data sources.

There are three types of customer due diligence, each tailored to specific customer risk levels: standard, simplified, and enhanced. By selecting the most appropriate CDD level, organizations maintain a robust yet flexible approach to customer verification.

Primarily, customer due diligence is applied to financial institutions, but it’s also a requirement for all non-financial businesses operating in countries that are members of the Financial Action Task Force (FATF). These businesses must adhere to the guidelines outlined in the FATF’s 40 Recommendations document.

When to apply CDD, and which type to use?

Let’s identify the cases when customer due diligence is required:

  1. New business relationship. When an individual or entity establishes a new business relationship with a financial institution, CDD is necessary. In this case, a potential customer should provide information on the origin of funds they will be using, financial statements, and details of the relationships between signatories and any underlying beneficial owners.
  2. Occasional transactions. This kind of transactions occurring outside of established business relationships and exceeding €10,000 require CDD (this figure has been reduced from €15,000). This requirement also extends to linked transactions, deliberately broken down into smaller parts to avoid CDD checks. Additionally, CDD applies for occasional transactions below €15,000 involving high-risk customers or regions.
  3. Unusual customer’s activity. When the customer’s activities are unusual, and a financial institution suspects money laundering or financing terrorism, CDD measures are essential.
  4. Doubtful customer’s identification information. When there are doubts about a customer’s identification information and the provided documentation seems unreliable, conducting customer due diligence is a must.

Each case may undergo a standard, simplified, or enhanced due diligence process, depending on the customer risk profiles:

Type of DDWhen to applyDescriptionCustomer’s risk profile*
1.Standard due diligenceApplied to determine and verify a new customer’s identity and gain initial insight into its risk profile.It aims to ensure that at least essential checks are performed before a customer onboarding process.Applied to all customers
2.Enhanced due diligenceWhen a customer isn’t physically present during identification checks.
When establishing a business relationship with a politically exposed person (PEP), i.e. an individual entrusted with a prominent public function. For example, a foreign or domestic member of parliament, a government minister, or their family members. A PEP typically presents a higher risk for potential involvement in bribery and corruption.
When engaging in financial transactions with an individual from a high-risk third country.
In any other situation where money laundering risks are high.
It involves obtaining and verifying additional customer information and conducting more thorough background checks.High-risk customers
3.Simplified due diligenceWhen the customer poses very low risks of money laundering, terrorist financing, or other financial crimes.It entails a less strict approach in certain check aspects.Low-risk customers

*Every financial institution, based on its location and area of focus, creates its own processes and procedures. Together with internal controls, they help organizations assign a risk level to each customer.

Simplify your due diligence with iDeals VDR

GET STARTED

Customer due diligence checklist

Now, let’s explore the customer due diligence checklist to learn what steps to take.

1. Establish customer identities

The first step is to conduct basic customer due diligence, which involves establishing the identity of potential customers by collecting and evaluating relevant information. This is important as it helps to identify fraud, ensure customers are indeed who they claim to be, and comply with AML regulations.

The following steps help to verify customer identities:

  1. Collect the customer’s information through an online form or KYC questionnaire. Gather essential data, including full name, date of birth, and residential address.
  2. Obtain copies of identity documents to verify the provided information.

At this step, it’s also recommended to review sanctions lists to ensure you’re not doing business with a sanctioned party. Failure to do so may result in substantial fines and legal proceedings.

2. Perform a customer risk assessment

Now, it’s time to assess a customer’s profile according to associated risks. This assessment further defines what type of due diligence a customer requires, simplified or enhanced.

To conduct a customer risk assessment, evaluate customers based on whether they come from a low or high-risk country, their industry, and their financial history. This information gives you an idea of whether a client requires a more rigorous CDD process.

If not, opt for simplified due diligence, which involves loosening several aspects of the checks. For example, you can:

  • Modify the timing of CDD
  • Adjust the quantity of obtained information
  • Review the frequency and intensity of transaction monitoring

3. Collect additional information (if required)

If, after risk assessment, you find it necessary to conduct enhanced due diligence, continue with the following steps:

  1. Obtain additional identifying information
  2. Conduct background checks by searching online databases or hiring a professional service
  3. Analyze the purpose of a transaction
  4. Analyze the origin of funds
  5. Check media to identify any adverse mentions
  6. Examine the customer’s social media accounts
  7. Request references from other companies that have had dealings with the customer
  8. Arrange on-site visits if necessary
  9. Perform ongoing monitoring, especially of higher-risk customers

Note: Pay close attention to the last point, as even after completing the due diligence, ongoing monitoring of customer profiles is crucial. It helps to ensure customer activities remain compliant and free from suspicious transactions. Employ the following steps to monitor customer activity:

  1. Regularly review the customer’s business account statements and transaction history.
  2. If anything unusual is observed, take appropriate steps, such as contacting the customer or reporting questionable activities to the relevant authorities.

4. Report suspicious activity

If you have reason to believe a customer is involved in money laundering or any other illicit activity, report it immediately. In this case, organizations don’t just follow the best practices, they fulfill their legal obligations.

The process of reporting suspicious activity varies depending on the country. The most common way is to file a Suspicious Activity Report (SAR) to a jurisdiction’s financial intelligence unit (FIU).

Note: It’s not allowed to disclose to customers that a SAR has been filed against them.

Tip: Consider employing a third-party
Certain data may only be accessible through third-party sources, such as banks, legal specialists, or auditors. These experts can provide guidance and verify the accurate execution of all CDD processes.

To hire a required specialist, search online or seek recommendations from a professional network. Once potential candidates are found, review their qualifications and conduct interviews to choose the best fit for this job.

Introducing the 4 main CDD requirements

In the UK alone, the Financial Conduct Authority (FCA) imposed fines of over £52 million in 2023. These fines are issued for a range of reasons, including non-compliance with anti-money laundering regulations and failure to conduct proper CDD checks. This not only leads to financial losses but also poses a considerable reputational risk for the entities involved.

That’s why it’s essential each institution adheres to a rigorous CDD process. Even though each country may have its specific AML regulations, there are four standard, core customer due diligence requirements:

  1. Customer identification and verification. The first core pillar of CDD involves thorough customer identity verification and investigation. This requires collecting and confirming personal details, such as name, date of birth, address, and identification numbers.
  2. Beneficial ownership identification and verification. Beyond individual customers, financial institutions must identify and verify the company’s beneficial owners, i.e. individuals who ultimately own or control the business.
  3. Defining the purpose of the business-customer relationships. This involves understanding and documenting the reasons for the relationships between financial institutions and their customers. This helps in creating risk profiles and ensures the business interactions align with their intended purposes.
  4. Ongoing monitoring. It involves regularly reviewing customer account activity to detect transactions that appear suspicious or unusual. When such transactions are identified, they must be reported to the relevant authorities.

Tip: Consider using automated customer due diligence solutions
Automated solutions streamline the CDD process, reduce manual errors, and provide more efficient risk assessment.

The importance of a customer due diligence process

To exemplify how expensive and harmful it is not to stick to customer due diligence requirements, let’s consider the following cases:

  • Danske Bank. In 2022, Danske Bank failed to implement effective CDD measures, which resulted in a fine of over $2 billion. “Danske Bank lied to U.S. banks about its deficient anti-money laundering systems, inadequate transaction monitoring capabilities, and its high-risk, offshore customer base in order to gain unlawful access to the U.S. financial system”, commented the Justice Department’s Criminal Division.
  • Equifax Limited. In October 2023, Equifax Limited faced a fine of over £11 million from the FCA as a result of one of the most significant cybersecurity breaches in history that exposed consumers to financial crime risks. The situation was described as “entirely preventable,” underlining the need for robust CDD practices.

Thus, the importance of customer due diligence can’t be overestimated as it helps banks and other financial institutions with:

  1. Legal compliance. Adhering to CDD requirements is essential for complying with anti-money laundering (AML) and counter-terrorism financing (CTF) regulations, avoiding heavy fines, and preventing legal consequences.
  2. Reputation protection. Proper due diligence protects a business’s reputation by ensuring ethical and transparent dealings and maintaining customer trust.
  3. Financial security. It also helps protect a company’s financial health by preventing losses resulting from fraudulent activities or regulatory penalties.

Risk-based approach in customer due diligence

A risk-based approach (RBA) is a strategic method that focuses on proactive risk management to combat financial crime. It’s widely recognized in AML compliance and includes the following aspects:

  1. Proactive risk management. Instead of reacting to financial crimes after they occur, a risk-based approach anticipates and addresses potential risks in advance, making it a preventive strategy.
  2. Customization within frameworks. Anti-money laundering compliance guidelines provide specific frameworks, but they offer flexibility for businesses to choose which measures best suit their needs. This customization is a crucial feature.
  3. Compliance with global standards. The RBA aligns with international AML standards and guidelines, including those set by the Financial Action Task Force (FATF). This ensures that businesses adhere to best practices recognized worldwide.
  4. Client-centric approach. It focuses on individual clients, recognizing that not all customers pose the same level of financial crime risk. This approach makes sure AML measures correspond to the risk associated with each client.

Key takeaways

  • Customer due diligence helps businesses verify customer identities and assess risks to prevent financial crimes like money laundering and terrorism financing.
  • The CDD process involves four stages, including establishing customer identities, performing risk assessments, collecting additional information, and reporting suspicious activities.
  • There are three types of CDD: standard and simplified CDD for low-risk customers and enhanced CDD for high-risk cases.
  • Key customer due diligence requirements include customer identification and verification, beneficial ownership identification, defining the purpose of business-customer relationships, and conducting ongoing monitoring.
Customer Due Diligence Guide: Main Requirements, Best Practices & Checklist (2024)

FAQs

What are the basic requirements of customer due diligence? ›

Basic customer due diligence involves collecting information about:
  • the identity of a customer – from their company address to the names of their individual executives.
  • the activities a customer is engaged in and markets in which they operate.
  • the other entities with which a customer does business.

What are the 4 stages of customer due diligence? ›

Customer Due Diligence (CDD) involves four key requirements:
  • Identifying and verifying the customer's identity using reliable sources.
  • Understanding the nature of the customer's business relationship to determine expected transactions.
  • Ensuring ongoing monitoring of the customer's transactions for suspicious activities.

What are the requirements for the customer due diligence rule? ›

However there are four core pillars that are similar the world over:
  • Identify and verify the identity of customers.
  • Identify and verify the identity of the beneficial owners of companies.
  • Understand the nature and purpose of customer relationships to develop risk profiles.
Mar 13, 2024

What are the basic requirements of due diligence? ›

Areas to target for scrutiny in the due diligence checklist should include:
  • Historical Financial Statements. ...
  • Revenue and Expense Analysis. ...
  • Assets and Liabilities Review. ...
  • Taxation and Tax Compliance. ...
  • Debt and Financing Agreements. ...
  • Working Capital Analysis. ...
  • Financial Projections and Assumptions. ...
  • Cash Flow Analysis.

What is a due diligence checklist? ›

Legal Due Diligence Checklist

Legal due diligence involves the examination of the legal and compliance aspects of the target company. Its primary objectives are to understand any potential legal risks, obligations, and liabilities.

What are the core components of customer due diligence? ›

The CDD Rule has four core requirements. It requires covered financial institutions to establish and maintain written policies and procedures that are reasonably designed to: identify and verify the identity of customers. identify and verify the identity of the beneficial owners of companies opening accounts.

What are the 3 principles of due diligence? ›

Below, we take a closer look at the three elements that comprise human rights due diligence – identify and assess, prevent and mitigate and account –, quoting from the Guiding Principles.

What is the customer due diligence process? ›

What is the customer due diligence process? The customer due diligence (CDD) process involves gathering and verifying information about a customer and ongoing risk assessment and management to help organisations fulfil their legal and regulatory obligations and protect themselves from financial crime.

What are the 3 examples of due diligence? ›

Other examples of hard due diligence activities include: Reviewing and auditing financial statements. Scrutinizing projections for future performance. Analyzing the consumer market.

What is a CDD questionnaire? ›

Customer due diligence is part of the Know Your Customer (KYC) regulations. It requires that banks and financial institutions collect information about their customers and verify their customers' identities to assess the level of risk of doing business with them.

What is due diligence rule? ›

(a) A lawyer shall not intentionally, repeatedly, recklessly or with gross negligence fail to act with reasonable diligence in representing a client.

What are the know your customer requirements? ›

At the minimum, firms must pull four pieces of identifying information about a client, including name, date of birth, address, and identification number. Most firms take additional steps in their screening process.

What are the 4 P's of due diligence? ›

A few tangible principles can help guide the way, including people, performance, philosophy, and process.

What are the four due diligence requirements? ›

The Four Due Diligence Requirements
  • Complete and Submit Form 8867. (Treas. Reg. section 1.6695-2(b)(1)) ...
  • Compute the Credits. (Treas. Reg. section 1.6695-2(b)(2)) ...
  • Knowledge. (Treas. Reg. section 1.6695-2(b)(3)) ...
  • Keep Records for Three Years.
Jan 22, 2024

What is a simplified due diligence requirement? ›

Simplified due diligence is only meant to be used when there is a low risk of money laundering, tax evasion, criminal or terrorist financing, and other financial crimes. Scenarios can include, but are not limited to, when: The customer is a government entity. The customer is a publicly-known company.

What is the due diligence process for customers? ›

The customer due diligence (CDD) process involves gathering and verifying information about a customer and ongoing risk assessment and management to help organisations fulfil their legal and regulatory obligations and protect themselves from financial crime.

What are the basic requirements of KYC and Basic CDD? ›

KYC is a process that involves verifying current or prospective customers' identities, while CDD is a set of ongoing processes designed to assess customer risk. CDD is a key component of KYC. The biggest difference between KYC and CDD processes is when they occur during the customer interaction.

What are the requirements for ongoing due diligence? ›

Ongoing monitoring: Keeping customer information up-to-date and conducting periodic reviews of the customer's risk profile and transactions. Enhanced due diligence (EDD): Conducting additional scrutiny for higher-risk customers, which may involve obtaining additional information and monitoring risk profiles more ...

Top Articles
Latest Posts
Article information

Author: Aron Pacocha

Last Updated:

Views: 6038

Rating: 4.8 / 5 (68 voted)

Reviews: 91% of readers found this page helpful

Author information

Name: Aron Pacocha

Birthday: 1999-08-12

Address: 3808 Moen Corner, Gorczanyport, FL 67364-2074

Phone: +393457723392

Job: Retail Consultant

Hobby: Jewelry making, Cooking, Gaming, Reading, Juggling, Cabaret, Origami

Introduction: My name is Aron Pacocha, I am a happy, tasty, innocent, proud, talented, courageous, magnificent person who loves writing and wants to share my knowledge and understanding with you.