Simplified Due Diligence (SDD)
Simplified due diligence, SDD, is a reduced but still real form of customer due diligence applied to relationships a documented risk assessment shows are genuinely low risk. It is not an exemption from CDD. In February 2025, FATF amended the Interpretive Notes to Recommendations 1, 10 and 15 specifically to push regulators and firms toward using SDD more deliberately, in response to evidence that 1.4 billion people worldwide remain unbanked.
Key takeaways
- SDD is a reduced but genuine form of CDD, applied only where a documented risk assessment supports lower risk; it’s not an exemption.
- FATF’s February 2025 amendment to the Interpretive Notes of Recommendations 1, 10 and 15 pushed regulators toward using simplified measures more deliberately, citing 1.4 billion unbanked people globally.
- PEP status, sanctions hits, and credible adverse media findings all disqualify a customer from SDD, with no exceptions.
- SDD reduces frequency, depth, and documentation intensity; it never removes the underlying requirement to identify a customer or escalate a genuine suspicion.
- The UK’s Regulation 37 and the EU’s AMLD4 Article 15 both require an actively documented low-risk rationale, not an automatic category-based exemption.
- SDD, CDD, and EDD sit on one continuous risk-based scale; every relationship gets classified somewhere on it.
- The most common SDD failure is applying it without a documented risk assessment, or failing to revisit the classification as a relationship evolves.
On this page
What simplified due diligence actually isWhy “simplified” doesn’t mean “skipped”FATF’s February 2025 amendment, and what it actually changedThe conditions that have to be met before SDD appliesWhat disqualifies a customer from SDD, no exceptionsWhat SDD measures actually look like in practiceHow UK and EU law implement the same standardSDD vs CDD vs EDD: where it sits on the scaleThe financial inclusion case for SDDWhere firms get SDD wrongDocumenting an SDD decision that holds upFAQsRead more
1.4bn
People worldwide who remain unbanked, cited by FATF as context for its February 2025 amendment
Source: FATF
Feb 2025
Date of the FATF Plenary that amended the Interpretive Notes to Recommendations 1, 10 and 15
Source: FATF
What simplified due diligence actually is
Simplified due diligence, SDD, is a reduced but still genuine form of customer due diligence, applied to relationships a documented risk assessment shows present low money laundering or terrorist financing risk. It’s a calibration of CDD’s intensity, not a separate category of check and not an exemption from the underlying obligation.
FATF Recommendation 10 permits it explicitly, provided the reduced risk is properly established first. The permission runs the other way from how it’s sometimes described: SDD isn’t a shortcut a firm reaches for to save time, it’s what a risk-based approach actually requires once genuine low risk has been demonstrated.
Why “simplified” doesn’t mean “skipped”
The word “simplified” causes real confusion, because it sounds like permission to skip steps. It isn’t. Identification and verification still happen under SDD; what changes is the depth, frequency, and intensity of the checks applied, not whether they happen at all.
A firm can reduce the documentation required, verify identity through fewer or less detailed sources, monitor less frequently, and take a lighter approach to ongoing review. What a firm can’t do under SDD is skip identifying the customer, skip verifying that identity through some reliable means, or ignore a suspicion of money laundering that arises regardless of the customer’s risk classification.
FATF’s February 2025 amendment, and what it actually changed
FATF’s February 2025 Plenary approved amendments to the Interpretive Note to Recommendation 1, with corresponding changes to the Interpretive Notes to Recommendations 10 and 15, specifically to better support financial inclusion. The stated context was direct: approximately 1.4 billion people worldwide remain without a bank account, and FATF’s own review found that frameworks applying uniform, maximum-intensity checks to every customer, regardless of actual risk, were part of the problem.
The amendment increased focus on proportionality and simplified measures under the risk-based approach, and provided further clarity on how simplified measures and exemptions should be applied in lower and low-risk scenarios. FATF followed up with updated guidance on AML/CFT measures and financial inclusion, published in June 2025, giving regulators and firms practical examples of how the calibration should work.
The conditions that have to be met before SDD applies
Applying SDD requires a specific sequence, not a default assumption. A firm first needs a documented risk assessment showing the relationship, product, or customer type genuinely presents lower risk, based on recognised low-risk indicators: publicly available ownership information, an already-regulated counterparty subject to equivalent AML obligations, or a product with restrictive limits on transaction size or account use.
Only once that risk determination is made and recorded can SDD measures actually apply. Treating every retail customer as automatically eligible for SDD without that underlying risk assessment is exactly the kind of shortcut FATF’s standard doesn’t permit, regardless of how low-risk a customer might seem informally.
What disqualifies a customer from SDD, no exceptions
Certain factors disqualify a customer from SDD outright, regardless of how the rest of their profile looks. A politically exposed person, or their family member or close associate, cannot receive SDD; PEP status requires enhanced due diligence under FATF Recommendation 12, full stop. A sanctions hit or a credible adverse media finding has the same effect: it triggers escalation toward standard or enhanced measures, not a continuation of simplified ones.
These aren’t judgment calls a firm weighs against other factors. They’re hard triggers that override whatever risk score a customer might otherwise have received.
What SDD measures actually look like in practice
In practice, SDD measures typically include some combination of: relying on identity verification already performed by another regulated entity subject to equivalent AML standards, rather than repeating it from scratch; reducing the frequency of ongoing monitoring and periodic file refreshes; applying lighter beneficial ownership verification where the entity type itself carries low inherent risk, such as a listed public company already subject to disclosure requirements; and verifying identity after establishing the relationship rather than requiring it fully complete beforehand, where the product’s own limits contain the risk in the meantime.
None of these measures remove the underlying requirement to identify the customer and to escalate immediately if suspicion arises. They reduce intensity, not obligation.
How UK and EU law implement the same standard
The UK codifies SDD in Regulation 37 of the Money Laundering Regulations 2017, which sets out the factors relevant to determining whether a lower-risk situation exists, factors a firm must actively assess and document rather than assume. The EU’s Fourth Anti-Money Laundering Directive, Article 15, took a similar approach and specifically removed the automatic, category-based SDD exemptions that existed under earlier EU AML directives, requiring firms to actively demonstrate and document a low-risk rationale for every case rather than relying on a customer simply falling into a pre-approved category.
That shift, from automatic category-based exemptions to actively demonstrated risk assessments, is the same underlying principle FATF’s February 2025 amendment reinforces at the international level: simplified measures have to be earned through evidence, not assumed by default.
SDD vs CDD vs EDD: where it sits on the scale
SDD, standard CDD, and EDD sit on one continuous scale of due diligence intensity, calibrated to risk. SDD applies to the lower end, where a documented risk assessment supports lighter measures. Standard CDD is the default for the great majority of relationships. Enhanced due diligence applies at the higher end, for PEPs, high-risk jurisdictions, complex ownership structures, and other elevated-risk situations.
No customer skips this assessment entirely. Every relationship gets classified somewhere on this scale, and the classification, along with the reasoning behind it, is exactly what a firm needs to be able to document and defend.
The financial inclusion case for SDD
FATF’s own reasoning for pushing SDD harder in 2025 was explicitly about financial inclusion, not just operational efficiency. Document-heavy, maximum-intensity checks applied uniformly tend to exclude exactly the low-income, informally-employed, or undocumented populations who present the least actual money laundering risk but the greatest difficulty producing standard verification documents.
SDD, applied correctly, is the mechanism that’s supposed to let firms serve these customers with proportionate friction rather than either excluding them entirely or applying disproportionate scrutiny that neither the risk nor the relationship value justifies.
Where firms get SDD wrong
The mistakes that come up most often with SDD are almost always about the underlying risk assessment, not the reduced measures themselves: applying SDD without a documented risk determination to point to, treating a customer type as low risk by category rather than actually assessing the specific relationship, failing to catch a PEP or sanctions hit that should have overridden the SDD classification, and never revisiting the SDD determination as a relationship evolves, continuing simplified treatment for a customer whose activity has genuinely changed.
Each of these turns a legitimate, permitted calibration into an unsupported shortcut, which is precisely the distinction a regulator will be checking for.
Documenting an SDD decision that holds up
Documenting an SDD decision that holds up means recording the specific low-risk factors relied on, not just a conclusion; confirming and recording that PEP, sanctions, and adverse media screening were still performed and came back clear; setting out what reduced measures are actually being applied and why they’re proportionate to the documented risk; and building in a trigger for re-assessment if the customer’s profile or activity changes. A file that shows this reasoning holds up under review. A file that just states “low risk, SDD applied” without the supporting analysis doesn’t.
Confirm a customer actually qualifies for SDD
Check the documented risk factors and disqualifying triggers before applying simplified measures.
Frequently asked questions
What is simplified due diligence?
Simplified due diligence (SDD) is a reduced but genuine form of customer due diligence applied to relationships a documented risk assessment shows present low money laundering or terrorist financing risk. It’s a calibration of CDD, not an exemption from it.
Does simplified due diligence mean skipping identity verification?
No. Identification and verification still happen under SDD. What changes is the depth, frequency, and intensity of checks, not whether the core CDD requirements are met at all.
What did FATF’s February 2025 amendment to Recommendation 10 actually change?
The February 2025 Plenary approved amendments to the Interpretive Notes to Recommendations 1, 10, and 15, increasing focus on proportionality and simplified measures and providing further clarity on applying simplified measures in lower-risk scenarios, specifically to support financial inclusion.
Can a politically exposed person receive simplified due diligence?
No. PEP status disqualifies a customer from SDD regardless of other factors; PEPs require enhanced due diligence under FATF Recommendation 12 instead.
What factors justify applying SDD to a customer?
Recognised low-risk indicators include publicly available ownership information, the customer being an already-regulated entity subject to equivalent AML standards, or a product with restrictive transaction or account limits, all backed by a documented risk assessment.
How does the UK regulate simplified due diligence?
Regulation 37 of the Money Laundering Regulations 2017 sets out the factors relevant to determining whether a lower-risk situation exists, which firms must actively assess and document.
What is the difference between SDD, CDD, and EDD?
They sit on one scale of due diligence intensity: SDD for documented low-risk relationships, standard CDD as the default, and EDD for higher-risk situations like PEPs or high-risk jurisdictions.
Why did FATF push for more use of simplified due diligence in 2025?
To support financial inclusion. FATF’s review found that uniform, maximum-intensity checks applied to every customer regardless of risk were contributing to financial exclusion, with roughly 1.4 billion people worldwide still unbanked.
What is the most common mistake firms make with SDD?
Applying it without a documented risk assessment to support the classification, or continuing simplified treatment after a customer’s risk profile has genuinely changed, rather than actively demonstrating and periodically revisiting the low-risk rationale.
Read more: our ultimate guides, whitepapers and templates
Related guides and resources to help you act on what you just read.
Last reviewed July 19, 2026 · 10 min read · Written for compliance and risk professionals · By the WhoWiki editorial team
Key takeaway: Simplified due diligence, SDD, is a reduced but still real form of customer due diligence applied to relationships a documented risk assessment shows are genuinely low risk. It is not an exemption from CDD. In February 2025, FATF amended the Interpretive Notes to Recommendations 1, 10 and 15 specifically to push regulators and firms toward using SDD more deliberately, in response to evidence that 1.4 billion people worldwide remain unbanked.