Customer Due Diligence Guide: Main Requirements, Best Practices & Checklist (2024)

In 2022 alone, banks and other financial organizations were fined almost $5 billion for failing to conduct proper customer due diligence.

Customer due diligence (CDD) is what every financial institution must conduct. Together with Know Your Customer (KYC) and Anti-Money Laundering (AML) regulations, it is one of the three essential components in the fight against financial crimes. Failure to perform adequate CDD may result in reputational damage and significant fines.

In this article, we explore the steps for performing CDD, provide you with practical tips and best practices, and explain the importance of compliance with these regulations.

What is customer due diligence?

Customer due diligence (CDD) is a series of checks that helps organizations assess and verify the identity of their customers. It aims to mitigate risks associated with money laundering, terrorism financing, fraud, and sanctions busting.

The customer due diligence process typically includes the following stages:

  1. Establishing customer identities
  2. Performing a customer risk assessment
  3. Collecting additional information (if required)
  4. Reporting suspicious activity

To collect necessary information for CDD, organizations turn to different sources, including the customer, sanctions lists, and public and private data sources.

There are three types of customer due diligence, each tailored to specific customer risk levels: standard, simplified, and enhanced. By selecting the most appropriate CDD level, organizations maintain a robust yet flexible approach to customer verification.

Primarily, customer due diligence is applied to financial institutions, but it’s also a requirement for all non-financial businesses operating in countries that are members of the Financial Action Task Force (FATF). These businesses must adhere to the guidelines outlined in the FATF’s 40 Recommendations document.

When to apply CDD, and which type to use?

Let’s identify the cases when customer due diligence is required:

  1. New business relationship. When an individual or entity establishes a new business relationship with a financial institution, CDD is necessary. In this case, a potential customer should provide information on the origin of funds they will be using, financial statements, and details of the relationships between signatories and any underlying beneficial owners.
  2. Occasional transactions. This kind of transactions occurring outside of established business relationships and exceeding €10,000 require CDD (this figure has been reduced from €15,000). This requirement also extends to linked transactions, deliberately broken down into smaller parts to avoid CDD checks. Additionally, CDD applies for occasional transactions below €15,000 involving high-risk customers or regions.
  3. Unusual customer’s activity. When the customer’s activities are unusual, and a financial institution suspects money laundering or financing terrorism, CDD measures are essential.
  4. Doubtful customer’s identification information. When there are doubts about a customer’s identification information and the provided documentation seems unreliable, conducting customer due diligence is a must.

Each case may undergo a standard, simplified, or enhanced due diligence process, depending on the customer risk profiles:

Type of DDWhen to applyDescriptionCustomer’s risk profile*
1.Standard due diligenceApplied to determine and verify a new customer’s identity and gain initial insight into its risk profile.It aims to ensure that at least essential checks are performed before a customer onboarding process.Applied to all customers
2.Enhanced due diligenceWhen a customer isn’t physically present during identification checks.
When establishing a business relationship with a politically exposed person (PEP), i.e. an individual entrusted with a prominent public function. For example, a foreign or domestic member of parliament, a government minister, or their family members. A PEP typically presents a higher risk for potential involvement in bribery and corruption.
When engaging in financial transactions with an individual from a high-risk third country.
In any other situation where money laundering risks are high.
It involves obtaining and verifying additional customer information and conducting more thorough background checks.High-risk customers
3.Simplified due diligenceWhen the customer poses very low risks of money laundering, terrorist financing, or other financial crimes.It entails a less strict approach in certain check aspects.Low-risk customers

*Every financial institution, based on its location and area of focus, creates its own processes and procedures. Together with internal controls, they help organizations assign a risk level to each customer.

Simplify your due diligence with iDeals VDR

GET STARTED

Customer due diligence checklist

Now, let’s explore the customer due diligence checklist to learn what steps to take.

1. Establish customer identities

The first step is to conduct basic customer due diligence, which involves establishing the identity of potential customers by collecting and evaluating relevant information. This is important as it helps to identify fraud, ensure customers are indeed who they claim to be, and comply with AML regulations.

The following steps help to verify customer identities:

  1. Collect the customer’s information through an online form or KYC questionnaire. Gather essential data, including full name, date of birth, and residential address.
  2. Obtain copies of identity documents to verify the provided information.

At this step, it’s also recommended to review sanctions lists to ensure you’re not doing business with a sanctioned party. Failure to do so may result in substantial fines and legal proceedings.

2. Perform a customer risk assessment

Now, it’s time to assess a customer’s profile according to associated risks. This assessment further defines what type of due diligence a customer requires, simplified or enhanced.

To conduct a customer risk assessment, evaluate customers based on whether they come from a low or high-risk country, their industry, and their financial history. This information gives you an idea of whether a client requires a more rigorous CDD process.

If not, opt for simplified due diligence, which involves loosening several aspects of the checks. For example, you can:

  • Modify the timing of CDD
  • Adjust the quantity of obtained information
  • Review the frequency and intensity of transaction monitoring

3. Collect additional information (if required)

If, after risk assessment, you find it necessary to conduct enhanced due diligence, continue with the following steps:

  1. Obtain additional identifying information
  2. Conduct background checks by searching online databases or hiring a professional service
  3. Analyze the purpose of a transaction
  4. Analyze the origin of funds
  5. Check media to identify any adverse mentions
  6. Examine the customer’s social media accounts
  7. Request references from other companies that have had dealings with the customer
  8. Arrange on-site visits if necessary
  9. Perform ongoing monitoring, especially of higher-risk customers

Note: Pay close attention to the last point, as even after completing the due diligence, ongoing monitoring of customer profiles is crucial. It helps to ensure customer activities remain compliant and free from suspicious transactions. Employ the following steps to monitor customer activity:

  1. Regularly review the customer’s business account statements and transaction history.
  2. If anything unusual is observed, take appropriate steps, such as contacting the customer or reporting questionable activities to the relevant authorities.

4. Report suspicious activity

If you have reason to believe a customer is involved in money laundering or any other illicit activity, report it immediately. In this case, organizations don’t just follow the best practices, they fulfill their legal obligations.

The process of reporting suspicious activity varies depending on the country. The most common way is to file a Suspicious Activity Report (SAR) to a jurisdiction’s financial intelligence unit (FIU).

Note: It’s not allowed to disclose to customers that a SAR has been filed against them.

Tip: Consider employing a third-party
Certain data may only be accessible through third-party sources, such as banks, legal specialists, or auditors. These experts can provide guidance and verify the accurate execution of all CDD processes.

To hire a required specialist, search online or seek recommendations from a professional network. Once potential candidates are found, review their qualifications and conduct interviews to choose the best fit for this job.

Introducing the 4 main CDD requirements

In the UK alone, the Financial Conduct Authority (FCA) imposed fines of over £52 million in 2023. These fines are issued for a range of reasons, including non-compliance with anti-money laundering regulations and failure to conduct proper CDD checks. This not only leads to financial losses but also poses a considerable reputational risk for the entities involved.

That’s why it’s essential each institution adheres to a rigorous CDD process. Even though each country may have its specific AML regulations, there are four standard, core customer due diligence requirements:

  1. Customer identification and verification. The first core pillar of CDD involves thorough customer identity verification and investigation. This requires collecting and confirming personal details, such as name, date of birth, address, and identification numbers.
  2. Beneficial ownership identification and verification. Beyond individual customers, financial institutions must identify and verify the company’s beneficial owners, i.e. individuals who ultimately own or control the business.
  3. Defining the purpose of the business-customer relationships. This involves understanding and documenting the reasons for the relationships between financial institutions and their customers. This helps in creating risk profiles and ensures the business interactions align with their intended purposes.
  4. Ongoing monitoring. It involves regularly reviewing customer account activity to detect transactions that appear suspicious or unusual. When such transactions are identified, they must be reported to the relevant authorities.

Tip: Consider using automated customer due diligence solutions
Automated solutions streamline the CDD process, reduce manual errors, and provide more efficient risk assessment.

The importance of a customer due diligence process

To exemplify how expensive and harmful it is not to stick to customer due diligence requirements, let’s consider the following cases:

  • Danske Bank. In 2022, Danske Bank failed to implement effective CDD measures, which resulted in a fine of over $2 billion. “Danske Bank lied to U.S. banks about its deficient anti-money laundering systems, inadequate transaction monitoring capabilities, and its high-risk, offshore customer base in order to gain unlawful access to the U.S. financial system”, commented the Justice Department’s Criminal Division.
  • Equifax Limited. In October 2023, Equifax Limited faced a fine of over £11 million from the FCA as a result of one of the most significant cybersecurity breaches in history that exposed consumers to financial crime risks. The situation was described as “entirely preventable,” underlining the need for robust CDD practices.

Thus, the importance of customer due diligence can’t be overestimated as it helps banks and other financial institutions with:

  1. Legal compliance. Adhering to CDD requirements is essential for complying with anti-money laundering (AML) and counter-terrorism financing (CTF) regulations, avoiding heavy fines, and preventing legal consequences.
  2. Reputation protection. Proper due diligence protects a business’s reputation by ensuring ethical and transparent dealings and maintaining customer trust.
  3. Financial security. It also helps protect a company’s financial health by preventing losses resulting from fraudulent activities or regulatory penalties.

Risk-based approach in customer due diligence

A risk-based approach (RBA) is a strategic method that focuses on proactive risk management to combat financial crime. It’s widely recognized in AML compliance and includes the following aspects:

  1. Proactive risk management. Instead of reacting to financial crimes after they occur, a risk-based approach anticipates and addresses potential risks in advance, making it a preventive strategy.
  2. Customization within frameworks. Anti-money laundering compliance guidelines provide specific frameworks, but they offer flexibility for businesses to choose which measures best suit their needs. This customization is a crucial feature.
  3. Compliance with global standards. The RBA aligns with international AML standards and guidelines, including those set by the Financial Action Task Force (FATF). This ensures that businesses adhere to best practices recognized worldwide.
  4. Client-centric approach. It focuses on individual clients, recognizing that not all customers pose the same level of financial crime risk. This approach makes sure AML measures correspond to the risk associated with each client.

Key takeaways

  • Customer due diligence helps businesses verify customer identities and assess risks to prevent financial crimes like money laundering and terrorism financing.
  • The CDD process involves four stages, including establishing customer identities, performing risk assessments, collecting additional information, and reporting suspicious activities.
  • There are three types of CDD: standard and simplified CDD for low-risk customers and enhanced CDD for high-risk cases.
  • Key customer due diligence requirements include customer identification and verification, beneficial ownership identification, defining the purpose of business-customer relationships, and conducting ongoing monitoring.
Customer Due Diligence Guide: Main Requirements, Best Practices & Checklist (2024)

FAQs

Customer Due Diligence Guide: Main Requirements, Best Practices & Checklist? ›

CDD consists of performing background checks, and screening potential and existing customers to ensure they're not involved in illegal activity. At a minimum, CDD checks include verifying a customer's name, address, date of birth and photo ID and screening them to ensure they're not on prohibited lists.

What are the basic requirements of customer due diligence? ›

CDD consists of performing background checks, and screening potential and existing customers to ensure they're not involved in illegal activity. At a minimum, CDD checks include verifying a customer's name, address, date of birth and photo ID and screening them to ensure they're not on prohibited lists.

What are the requirements for the customer due diligence rule? ›

What checks are carried out as part of customer due diligence (CDD)?
  • Electronic identity checks.
  • Geocoding checks.
  • ID and visa verification.
  • Trustee and charity details.
  • PEPs and sanctions screening.
  • Negative news or negative media screening.
  • Ultimate business ownership (UBO) detection and shareholder identification.
Mar 13, 2024

What are the basic requirements of due diligence? ›

Areas to target for scrutiny in the due diligence checklist should include:
  • Historical Financial Statements. ...
  • Revenue and Expense Analysis. ...
  • Assets and Liabilities Review. ...
  • Taxation and Tax Compliance. ...
  • Debt and Financing Agreements. ...
  • Working Capital Analysis. ...
  • Financial Projections and Assumptions. ...
  • Cash Flow Analysis.

What are the core components of customer due diligence? ›

Customer Due Diligence (CDD) involves four key requirements: Identifying and verifying the customer's identity using reliable sources. Understanding the nature of the customer's business relationship to determine expected transactions. Ensuring ongoing monitoring of the customer's transactions for suspicious activities.

What are the 4 pillars of customer due diligence? ›

Key customer due diligence requirements include customer identification and verification, beneficial ownership identification, defining the purpose of business-customer relationships, and conducting ongoing monitoring.

What should be included in a due diligence checklist? ›

20 Items That Should Be on Every M&A Due Diligence Checklist
  • Financial Matters. ...
  • Technology and Intellectual Property. ...
  • Sales and Customers. ...
  • Strategic Fit With Buyer. ...
  • Material Contracts. ...
  • Managerial or Employee Problems. ...
  • Litigation. ...
  • Tax Matters.
Dec 23, 2022

What are the three types of CDD? ›

There are three main types of CDD measures that organisations may use: standard CDD, enhanced CDD, and ongoing CDD. Standard Customer or Client Due Diligence refers to the basic level of information organisations must collect and verify about their customers.

What are the seven elements of customer due diligence program? ›

Customer due diligence records should include: Identification information of your customer and any beneficial owners. Copies of original documents used for verification of identity of your customer and any beneficial owners. Information on the nature and purpose of your business relationship with your customer.

What are the basics of due diligence? ›

Due diligence is a relatively common term. Used in business, it broadly refers to the process of investigating and verifying information about a company or investment opportunity. Specifically for compliance teams, it comes up when you consider relationships with new vendors and third parties.

What are the 4 P's of due diligence? ›

The 4 P's of due diligence are People, Performance, Philosophy, and Process. These key elements form the foundation of a thorough due diligence process, covering aspects related to the team involved, performance metrics, investment philosophy, and the overall process followed.

What are the four due diligence requirements? ›

The Four Due Diligence Requirements
  • Complete and Submit Form 8867. (Treas. Reg. section 1.6695-2(b)(1)) ...
  • Compute the Credits. (Treas. Reg. section 1.6695-2(b)(2)) ...
  • Knowledge. (Treas. Reg. section 1.6695-2(b)(3)) ...
  • Keep Records for Three Years.
Jan 22, 2024

What is a simplified due diligence requirement? ›

Simplified due diligence is the lowest level of due diligence that can be completed on a customer. This is considered appropriate where there is little opportunity or risk of your services or customer becoming involved in money laundering or terrorist financing.

What is required for customer due diligence? ›

Basic customer due diligence involves collecting information about: the identity of a customer – from their company address to the names of their individual executives. the activities a customer is engaged in and markets in which they operate.

What are the 3 principles of due diligence? ›

Below, we take a closer look at the three elements that comprise human rights due diligence – identify and assess, prevent and mitigate and account –, quoting from the Guiding Principles.

Which are the five steps to client due diligence? ›

Customer Due Diligence Checklist — Five Steps to Improve Your CDD
  • Step 1: Verify customer identities. ...
  • Step 2: Assess third-party information sources. ...
  • Step 3: Secure your information. ...
  • Step 4: Take any necessary additional measures. ...
  • Step 5: Ensure you're audit ready.
Feb 22, 2018

What are the basic requirements of KYC and Basic CDD? ›

KYC is the initial step, where businesses verify the identity of their customers. CDD, on the other hand, is an ongoing process that involves continuously monitoring customer behavior and assessing risks associated with it. Both are pivotal in preventing financial crimes.

Top Articles
Millennials Lead The Charge In Solo Home Purchases | Bankrate
Can't unlock your Android device
#ridwork guides | fountainpenguin
123Movies Encanto
Craigslist Free En Dallas Tx
Quick Pickling 101
1970 Chevelle Ss For Sale Craigslist
Shs Games 1V1 Lol
1movierulzhd.fun Reviews | scam, legit or safe check | Scamadviser
Jonathan Freeman : "Double homicide in Rowan County leads to arrest" - Bgrnd Search
Free VIN Decoder Online | Decode any VIN
How To Get Free Credits On Smartjailmail
Samsung 9C8
Bustle Daily Horoscope
3656 Curlew St
Craigslist Dog Kennels For Sale
Detroit Lions 50 50
Scholarships | New Mexico State University
Cooking Fever Wiki
Busty Bruce Lee
Insidekp.kp.org Hrconnect
Most McDonald's by Country 2024
Tvtv.us Duluth Mn
使用 RHEL 8 时的注意事项 | Red Hat Product Documentation
Farmer's Almanac 2 Month Free Forecast
Lcwc 911 Live Incident List Live Status
Gayla Glenn Harris County Texas Update
Transactions (zipForm Edition) | Lone Wolf | Real Estate Forms Software
Fsga Golf
Isaidup
Ppm Claims Amynta
How to Grow and Care for Four O'Clock Plants
Engineering Beauties Chapter 1
University Of Michigan Paging System
Motorcycle Blue Book Value Honda
Weather October 15
Jailfunds Send Message
Town South Swim Club
Home Auctions - Real Estate Auctions
Gina's Pizza Port Charlotte Fl
Tas Restaurant Fall River Ma
Bones And All Showtimes Near Johnstown Movieplex
Express Employment Sign In
Tsbarbiespanishxxl
Lake Kingdom Moon 31
Below Five Store Near Me
Actor and beloved baritone James Earl Jones dies at 93
Mega Millions Lottery - Winning Numbers & Results
Unpleasant Realities Nyt
Cvs Minute Clinic Women's Services
Zom 100 Mbti
Https://Eaxcis.allstate.com
Latest Posts
Article information

Author: Lidia Grady

Last Updated:

Views: 6612

Rating: 4.4 / 5 (65 voted)

Reviews: 80% of readers found this page helpful

Author information

Name: Lidia Grady

Birthday: 1992-01-22

Address: Suite 493 356 Dale Fall, New Wanda, RI 52485

Phone: +29914464387516

Job: Customer Engineer

Hobby: Cryptography, Writing, Dowsing, Stand-up comedy, Calligraphy, Web surfing, Ghost hunting

Introduction: My name is Lidia Grady, I am a thankful, fine, glamorous, lucky, lively, pleasant, shiny person who loves writing and wants to share my knowledge and understanding with you.