Customer Due Diligence (CDD)

Customer Due Diligence (CDD)

Customer Due Diligence (CDD)

Customer due diligence (CDD) is the process of identifying a customer, verifying that identity, understanding the beneficial ownership behind any legal entity, and assessing the money laundering risk the relationship presents. In the US, it’s the fifth pillar of a Bank Secrecy Act programme under FinCEN’s 2016 CDD Rule, codified at 31 C.F.R. § 1010.230. In the UK and EU, the same core obligation sits in Regulation 28 of the MLR 2017 and FATF Recommendation 10.

Key takeaways

  • CDD means identifying a customer, verifying identity, identifying beneficial owners, and assessing risk, maintained for the life of the relationship.
  • In the US, FinCEN’s CDD Rule (81 Fed. Reg. 29398, codified at 31 C.F.R. § 1010.230) made CDD a formal fifth pillar of BSA/AML programmes, alongside internal controls, independent testing, a compliance officer, and training.
  • The beneficial ownership threshold is 25% under the ownership prong, or control regardless of percentage under the control prong.
  • Covered US institutions had until 11 May 2018 to comply, a two-year window extended from an original one-year proposal.
  • The UK applies the same substance through Regulation 28 of the MLR 2017, also using a 25% threshold.
  • FATF Recommendation 10 sets the global standard but doesn’t fix a specific ownership percentage, leaving that to national implementation.
  • CDD-related fines were part of $6.6 billion in global AML/KYC penalties in 2023, up 57% from 2022 (Fenergo).

25%

Beneficial ownership threshold under FinCEN’s CDD Rule’s ownership prong

Source: 31 C.F.R. § 1010.230

11 May 2018

Compliance deadline for FinCEN’s CDD Rule, two years after publication

Source: Federal Register, 81 Fed. Reg. 29398

$6.6bn

In global AML/KYC/CDD fines in 2023, up 57% from 2022

Source: Fenergo, January 2024

What customer due diligence actually means

Customer due diligence, CDD, is the process of identifying a customer, verifying that identity against reliable evidence, understanding who actually owns or controls the customer if it’s a legal entity, and assessing the money laundering or terrorist financing risk the relationship presents. It’s the operational core of what most people mean when they talk about KYC.

CDD isn’t a single check performed once. It’s a standard that has to be met at onboarding and maintained for as long as the relationship continues, which is why regulators increasingly examine not just whether a firm collected the right information, but whether it kept using that information correctly afterward.

The fifth pillar: how the US made CDD a formal AML requirement

In the US, CDD has a precise legal origin most compliance content glosses over. FinCEN’s Customer Due Diligence Requirements for Financial Institutions, published in the Federal Register on 11 May 2016 (81 Fed. Reg. 29398) and codified at 31 C.F.R. § 1010.230, formally added CDD as a fifth required pillar of every Bank Secrecy Act compliance programme.

Before this rule, BSA/AML programmes were built around four pillars: internal controls, independent testing, a designated compliance officer, and training. CDD, including identifying beneficial owners of legal entity customers, existed in practice at many institutions already, but wasn’t a codified, standalone requirement until this rule. Covered financial institutions had until 11 May 2018, two years from publication, to come into compliance, extended from an originally proposed one-year window after industry pushback over the operational complexity involved.

The four elements FinCEN’s CDD Rule actually requires

FinCEN’s rule sets out four specific elements that make up CDD in US law: identifying and verifying the identity of customers, identifying and verifying the identity of beneficial owners of legal entity customers, understanding the nature and purpose of customer relationships to develop a customer risk profile, and conducting ongoing monitoring to identify and report suspicious transactions and, on a risk basis, maintain and update customer information.

The third and fourth elements are the ones most often under-documented in practice. FinCEN’s own commentary noted that these two obligations existed implicitly through suspicious activity reporting requirements even before the rule, which is part of why the rule’s real effect was formalising and making auditable something many institutions were already doing informally, rather than inventing an entirely new obligation.

Worth knowing. FinCEN’s third and fourth CDD elements, understanding relationship purpose and ongoing monitoring, existed implicitly through suspicious activity reporting obligations even before the 2016 rule. The rule’s real effect was making these obligations explicit and auditable, not inventing something entirely new.

Beneficial ownership: the 25% threshold and the two prongs

Beneficial ownership identification is where CDD gets genuinely technical. FinCEN’s rule requires covered institutions to identify beneficial owners under two separate tests, and a legal entity customer can have beneficial owners under either one, or both. The ownership prong requires identifying any individual who owns 25% or more of the equity interests of the legal entity. The control prong requires identifying a single individual with significant responsibility to control, manage, or direct the entity, regardless of ownership percentage.

FinCEN has been explicit that 25% is a baseline regulatory benchmark, not a ceiling. Institutions can, and often do, apply a lower threshold based on their own risk assessment, particularly for higher-risk customer types. Institutions can rely on a legal entity customer’s own certification of beneficial ownership, using FinCEN’s own form or an equivalent, as long as there’s no reason to doubt its reliability, a deliberate response to industry concerns about the operational burden of independently verifying every layer of a complex ownership structure.

CDD requirements compared: US, UK, and FATF side by side

CDD requirements share a common FATF-driven foundation, but the way each jurisdiction implements it differs in ways that matter for a firm operating across borders. Here’s the same obligation, compared directly:

Jurisdiction Legal basis Beneficial ownership threshold Compliance milestone
United States FinCEN CDD Rule, 31 C.F.R. § 1010.230 (81 Fed. Reg. 29398) 25% ownership prong, or control prong regardless of percentage Applicability Date: 11 May 2018
United Kingdom Money Laundering Regulations 2017, Regulation 28 25% (aligned with the PSC register threshold) In force since 26 June 2017
European Union 4th / 5th / 6th Anti-Money Laundering Directives 25% baseline; member states may set lower Varies by member state transposition
FATF (global standard) Recommendation 10 and its Interpretive Note No fixed percentage; left to national implementation Standard first issued 1990, revised 2012

The pattern across all four is the same underlying logic: verify identity, find the real owner, understand the relationship, keep watching. But the US is the only one of the four with a single, precisely dated federal rule creating CDD as a standalone, numbered requirement. The UK and EU implement the same substance through broader money laundering regulations rather than a dedicated CDD-specific rule.

When CDD applies (and when it doesn’t)

CDD applies whenever a covered institution establishes a new customer relationship, and at several other trigger points: when carrying out occasional transactions above a set threshold (commonly $15,000 under FATF’s standard, though implementing jurisdictions set their own specific figures), whenever there’s a suspicion of money laundering or terrorist financing regardless of any exemption that would otherwise apply, and whenever there’s doubt about the veracity or adequacy of previously obtained customer identification data.

CDD generally doesn’t apply, or applies in reduced form, to certain low-risk, well-regulated counterparties, other regulated financial institutions in equivalent jurisdictions, for example, which is where simplified due diligence becomes relevant instead.

The CDD process step by step

  1. Identify the customer: collect name, address, date of birth (individuals) or registration details (entities).
  2. Verify identity against reliable, independent sources: government-issued ID, company registries, or equivalent documentation.
  3. Identify beneficial owners for legal entity customers, applying the ownership and control prongs.
  4. Verify beneficial owner identities using risk-based procedures.
  5. Understand the nature and purpose of the relationship, building a baseline risk profile.
  6. Screen against sanctions, PEP, and adverse media sources.
  7. Conduct ongoing monitoring against that baseline profile, flagging activity that doesn’t fit.
  8. Update customer and beneficial ownership information as circumstances change or new accounts are opened.

CDD vs EDD vs SDD

CDD, EDD, and SDD are tiers of the same obligation, not three separate processes. Simplified due diligence applies where a jurisdiction’s risk assessment supports a lighter check for genuinely low-risk relationships. Standard CDD, everything described above, is the default. Enhanced due diligence adds further measures, source of wealth verification, senior management approval, closer monitoring, for relationships a risk assessment flags as genuinely higher risk.

Every customer relationship gets assessed against this scale. None of the three tiers is optional to consider; a firm has to make an active, documented decision about which tier applies, rather than defaulting to standard CDD for everyone regardless of actual risk.

What incomplete beneficial ownership data actually costs

Incomplete beneficial ownership data is one of the more expensive gaps in CDD compliance specifically, separate from broader KYC failures. Because the FinCEN rule ties beneficial ownership so directly to a numbered federal requirement, examiners can point to a precise regulatory citation, not just a general AML weakness, when beneficial ownership records are missing or unverified.

KYC-wide enforcement data shows the scale of the exposure generally: Fenergo’s review found AML, KYC, and CDD-related fines totalled $6.6 billion globally in 2023, up 57% from 2022. Individual CDD-specific findings tend to concentrate on the same recurring gap: institutions collecting a beneficial ownership certification at onboarding, then never revisiting it as ownership structures change.

Common CDD documentation mistakes

The documentation mistakes that come up repeatedly in CDD reviews include: accepting a beneficial ownership certification without any process for triggering re-verification when circumstances suggest it’s gone stale, applying the 25% ownership threshold mechanically without considering whether the control prong also applies to someone below that threshold, treating CDD as complete once a form is filed rather than as a profile that has to hold up against actual transaction activity, and inconsistent recordkeeping that can’t show an examiner, months or years later, exactly what was verified, when, and against what source.

None of these are exotic failures. They’re gaps in discipline around information a firm typically already collected once, correctly, at the start of the relationship.

Building CDD records that survive an audit

CDD records that survive an audit generally share a specific quality: they can answer, for any customer, exactly what was verified, against what independent source, on what date, and what triggered any subsequent update. That standard applies as much to beneficial ownership information as it does to the original identity verification.

Firms that treat the FinCEN CDD Rule’s four elements, and the equivalent UK and EU obligations, as a literal checklist tied to specific regulatory citations tend to produce records that hold up better under review than firms working from a general sense of what “good KYC” should look like. The precision is the point: a compliance file that cites Regulation 28 or 31 C.F.R. § 1010.230 directly is harder to dispute than one that just says the firm followed general AML best practices.

Run your CDD against the actual rule

Check identity, beneficial ownership and risk tier against the FinCEN and UK requirements side by side.

Try the CDD vs EDD Tool →

Frequently asked questions

What is customer due diligence (CDD)?

Customer due diligence is the process of identifying a customer, verifying that identity, identifying beneficial owners of any legal entity customer, and assessing the money laundering risk the relationship presents, maintained for the life of the relationship.

What is the FinCEN CDD Rule?

The FinCEN CDD Rule is the US regulation, Customer Due Diligence Requirements for Financial Institutions, published 11 May 2016 and codified at 31 C.F.R. § 1010.230, that formally made CDD, including beneficial ownership identification, a required fifth pillar of every Bank Secrecy Act compliance programme.

What is the beneficial ownership threshold under US law?

25% ownership under the ownership prong, or any individual with significant managerial control under the control prong regardless of ownership percentage. FinCEN treats 25% as a baseline that institutions may set lower based on risk.

What are the four pillars of a BSA/AML programme?

Internal controls, independent testing, a designated compliance officer, and training. FinCEN’s 2016 rule added CDD as a fifth pillar alongside these four.

How does UK CDD compare to the US rule?

The UK applies the same substance through Regulation 28 of the Money Laundering Regulations 2017, using a 25% beneficial ownership threshold aligned with its PSC register, rather than a single dedicated CDD rule like the US.

What triggers the requirement to perform CDD?

Establishing a new customer relationship, an occasional transaction above a set threshold, suspicion of money laundering or terrorist financing, or doubt about previously obtained customer information.

What is the difference between CDD and EDD?

CDD is the standard tier of due diligence applied to most customers. EDD adds further measures, verified source of wealth, senior management approval, closer monitoring, for relationships a risk assessment identifies as genuinely higher risk.

Can a firm rely on a customer’s own beneficial ownership certification?

Yes, under FinCEN’s rule, as long as there’s no reason to question the reliability of the information provided, using FinCEN’s own certification form or an equivalent.

How often should beneficial ownership information be updated?

FinCEN doesn’t require periodic updates for all customers at fixed intervals, but does require updating when the institution has knowledge of facts calling the existing information into question, and generally when a new account is opened.

Read more: our ultimate guides, whitepapers and templates

Related guides and resources to help you act on what you just read.

Last reviewed July 19, 2026 · 11 min read · Written for compliance and risk professionals · By the WhoWiki editorial team

Key takeaway: Customer due diligence (CDD) is the process of identifying a customer, verifying that identity, understanding the beneficial ownership behind any legal entity, and assessing the money laundering risk the relationship presents. In the US, it’s the fifth pillar of a Bank Secrecy Act programme under FinCEN’s 2016 CDD Rule, codified at 31 C.F.R. § 1010.230. In the UK and EU, the same core obligation sits in Regulation 28 of the MLR 2017 and FATF Recommendation 10.

Learn & stay current

A compliance reference that keeps up with the regulators

Plain-English explainers, country rules, and data you can cite, updated as the landscape moves.

Comparing tools before you commit?

See how WhoWiki lines up against the platforms you already know, and which free tools fit which job.

See how current your screening could be

Book a walkthrough with our team, or start with the tools today. No account needed to run your first check.