Customer Due Diligence (CDD)
Customer due diligence (CDD) is the set of checks a regulated institution performs to know who it is dealing with — verifying identity, identifying beneficial owners, understanding the purpose of the relationship, and monitoring it thereafter. It is the baseline every customer receives, and the foundation everything else in an AML program rests on.
| Also called | CDD, know your customer (KYC) in common usage |
| Governing standard | FATF Recommendation 10, implemented through national AML regimes |
| U.S. implementation | Customer Identification Program (CIP) rules under the Bank Secrecy Act |
| Four components | Identify and verify the customer; identify beneficial owners; understand the purpose and nature of the relationship; monitor on an ongoing basis |
| When performed | At onboarding, on trigger events, and periodically thereafter |
| Risk-based | Yes — depth scales with assessed risk |
| Lighter tier | Simplified due diligence, for demonstrably low-risk cases |
| Heavier tier | Enhanced due diligence, for higher-risk customers |
| Common failure | Treating it as a one-time gate rather than an ongoing obligation |
How it works
CDD has four components and programs tend to be strong on the first and weak on the rest.
Identify and verify the customer. Collect identifying information and confirm it against reliable, independent evidence — in practice a government-issued document, authenticated, and increasingly matched to a live face. This is the part most institutions do well because it is the most tractable.
Identify beneficial owners. For legal entities, establish who ultimately owns or controls the customer, typically at a 25% threshold. This is harder than it sounds once ownership runs through several layers or jurisdictions with no public register, and it is where deliberate opacity does its work.
Understand the purpose and nature of the relationship. What is this account for, what activity is expected, does the stated purpose fit the customer. This produces the profile that all later monitoring compares against — and it is the component most often reduced to a dropdown nobody reads.
Monitor on an ongoing basis. CDD does not end at onboarding. Activity is checked against the expected profile, and the customer information itself is refreshed periodically. A file accurate at account opening decays; addresses change, ownership changes, risk changes.
All four scale with risk. Demonstrably low-risk cases can receive simplified due diligence; higher-risk customers escalate to enhanced due diligence, which adds source of funds and source of wealth evidence and senior sign-off.
Why it matters for identity verification
The first component is identity verification, so the connection is direct — but the more interesting dependency is the third.
Ongoing monitoring compares activity against an expected profile. If the profile was built from self-reported information attached to an identity nobody authenticated, every later comparison is measured against a fiction. The institution appears to be monitoring and is in fact comparing noise to noise. That failure is invisible in an audit of process and obvious in an audit of outcomes.
Regulatory expectation has also shifted toward documented reasoning. Examiners assess whether verification was reasonable and whether the institution can evidence what it checked, what came back, and why a threshold sat where it did. Document authentication that records its own decision is worth more at examination than a marginally more accurate check with no audit trail — and Microblink’s KYC and AML workflow is built so decisions carry their evidence.
The three tiers of due diligence
| Simplified | Standard CDD | Enhanced | |
|---|---|---|---|
| Applies to | Demonstrably low-risk cases | Every customer by default | Higher-risk customers |
| Identity verification | Required, may be lighter | Full verification | Full, plus corroboration |
| Beneficial ownership | May be reduced | Identified and verified | Structure understood and evidenced |
| Source of wealth | Not required | Not required | Documented |
| Approval | Standard | Standard | Senior management |
| Monitoring | Reduced frequency | Ongoing | Closer and more frequent |
Simplified due diligence is a reduction in intensity, not an exemption. Institutions get into difficulty by treating it as permission to skip steps rather than as a documented risk judgment.
What it can’t do
It cannot verify claims the customer makes about themselves. CDD establishes who someone is. Whether their stated income, occupation or purpose is truthful requires independent data, and standard CDD does not reach it.
It cannot see through deliberate structuring. Ownership layered across jurisdictions without public registers can be documented to the limit of what is knowable and still conceal the ultimate owner. CDD records that limit rather than removing it.
It is not a one-time gate. The most common structural failure is treating CDD as an onboarding task. A customer verified three years ago whose file has never been refreshed is not a customer under ongoing due diligence, whatever the process documentation says.
It cannot compensate for a weak identity check. Every subsequent component inherits the quality of the first. Beneficial ownership research, profile-building and monitoring all assume the customer is who they claimed, and none of them detects that they were not.
Frequently asked questions
What is the difference between CDD and KYC?
In practice the terms are used interchangeably. Where a distinction is drawn, KYC refers to the identity-establishing steps and CDD to the broader ongoing obligation — identity, beneficial ownership, relationship purpose, and monitoring. FATF and most regimes use CDD as the umbrella term.
What are the four components of customer due diligence?
Identify and verify the customer; identify and verify beneficial owners; understand the purpose and intended nature of the relationship; and conduct ongoing monitoring. All four are required, and programs are typically strongest on the first.
When is simplified due diligence allowed?
Where the institution can demonstrate low risk based on the customer type, product, or jurisdiction. It reduces intensity rather than removing the obligation, and the risk judgment supporting it must be documented.
How often should customer due diligence be refreshed?
On a risk-based schedule — more frequently for higher-risk relationships — and on trigger events such as a change in ownership, a significant change in activity, or adverse information surfacing. A fixed periodic cycle with no trigger-based refresh is a common examination finding.
Related reading
- Enhanced due diligence — the escalation for higher-risk customers
- Know your customer — the term CDD is most often confused with
- Identity document verification — the first component, in practice
- AML red flags — what ongoing monitoring is looking for