AML/CTF customer due diligence (CDD) explained
Customer due diligence is how a reporting entity finds out who its customers are, assesses their financial crime risk and monitors that risk over time.
It is more than checking identification at onboarding. Customer due diligence starts before a designated service is provided and continues throughout the customer relationship.
This explainer covers initial and ongoing customer due diligence, customer risk ratings, simplified and enhanced measures, third-party arrangements, record keeping and post-implementation reviews.
What is customer due diligence?
Customer due diligence, or CDD, is the process of identifying customers and understanding the money laundering, terrorism financing and proliferation financing risks associated with providing services to them. These risks are referred to collectively as money laundering and terrorism financing risk, or ML/TF risk.
Customer due diligence is also commonly called “know your customer” or KYC.
CDD has three connected elements:
identifying the customer and other relevant people;
verifying information using reliable and independent data; and
monitoring the customer and their activity over time.
CDD is a core part of an anti-money laundering and counter-terrorism financing program, or AML/CTF program. A reporting entity’s AML/CTF policies must explain how it conducts both initial and ongoing CDD.
For more information about AML/CTF programs, see our AML/CTF programs explainer.
What is the difference between initial and ongoing CDD?
Initial CDD is generally completed before you begin providing a designated service. It establishes who the customer is, why they want the service and the ML/TF risk associated with providing it.
Ongoing CDD continues during the customer relationship. It tests whether the information held about the customer remains accurate and whether the customer’s transactions and behaviour are consistent with what you know about them.
Initial CDD gives you a starting point. Ongoing CDD tells you whether that starting point is still reliable.
What must you establish during initial CDD?
Before providing a designated service, a reporting entity generally needs reasonable grounds to establish:
the identity of the customer;
the identity of any person on whose behalf the customer is receiving the service;
the identity of anyone acting for the customer and that person’s authority to act;
the beneficial owners of a customer that is not an individual;
whether a relevant person is a politically exposed person;
whether a relevant person is subject to targeted financial sanctions; and
the nature and purpose of the business relationship or occasional transaction.
If an organisation has no identifiable beneficial owner, the reporting entity may need to identify its chief executive officer or equivalent senior individual.
The information required will depend on the type of customer. An individual, company, partnership, association, trust and government body will each require a different approach.
Who is a beneficial owner?
A beneficial owner is an individual who ultimately owns or controls a customer.
Ownership can be direct or indirect. Control may also exist without a straightforward ownership interest. Looking only at the name on a company register may therefore be insufficient.
A reporting entity may need to examine corporate ownership chains, trust arrangements, voting rights and other means of control. The aim is to identify the individuals who ultimately own or control the customer.
A complex structure is not automatically suspicious. It may, however, affect the information you need to collect, the steps required to verify it and the customer’s risk rating.
What are politically exposed persons?
A politically exposed person, or PEP, is a person who holds a specified public position or function. Certain family members and close associates are also treated as PEPs.
The AML/CTF regime recognises domestic PEPs, foreign PEPs and PEPs connected with international organisations.
PEP status does not mean that a person has done anything wrong. It indicates that their position or connections may expose them to a higher risk of bribery, corruption or misuse of public funds.
Reporting entities commonly use third-party screening services to identify PEPs and people subject to targeted financial sanctions. The screening result is only part of the process. Staff still need clear procedures for confirming possible matches, assessing risk and deciding what action to take.
What KYC information must be collected and verified?
KYC information helps a reporting entity establish the required facts about a customer and assess the customer’s ML/TF risk.
The reporting entity must collect information appropriate to that risk and verify relevant information using reliable and independent data.
The type and depth of verification should reflect:
the kind of customer;
the designated services being provided;
the customer’s ownership and control structure;
how the service will be delivered;
the countries connected with the relationship;
the nature and purpose of the relationship; and
any other relevant risk indicators.
CDD should not become a mechanical document-collection exercise. The information must allow the reporting entity to form a reasonable view of who the customer is and the risk involved in serving them.
What is a customer risk rating?
A customer risk rating records the reporting entity’s assessment of the ML/TF risk associated with an individual customer.
A common model classifies customers as low, medium or high risk, although there is no prescribed classification system.
The rating should apply the factors in the reporting entity’s broader ML/TF risk assessment to the customer. These may include the customer type, services provided, ownership structure, delivery channel and countries involved.
The methodology should produce consistent and explainable results. It should also allow staff to apply judgement when unusual facts do not fit the standard scoring model.
A customer’s risk rating can change. New information, unusual activity, a change in ownership or a different use of the service may require the rating and related controls to be reviewed.
When can simplified CDD be used?
Simplified CDD may be available where the customer’s ML/TF risk is low and enhanced CDD is not required.
Simplified CDD does not mean no CDD. The reporting entity must still understand the customer and have a proper basis for concluding that the risk is low.
The AML/CTF policies should explain:
when simplified measures may be used;
what those measures involve;
who can approve their use;
how the low-risk conclusion is recorded; and
what would trigger standard or enhanced CDD.
Simplified measures should follow the risk assessment. They should not be used merely because the customer is well known, commercially important or keen to start quickly.
When is enhanced CDD required?
Enhanced CDD is required when specified higher-risk circumstances arise.
These include situations where:
the customer has been assessed as high risk;
a suspicious matter reporting obligation arises;
the customer is a PEP in circumstances requiring enhanced measures; or
a relevant transaction has a prescribed high-risk country connection.
Enhanced CDD involves obtaining or verifying further KYC information relevant to the identified risk. Its purpose is to give the reporting entity a deeper understanding of the customer and allow it to decide whether the risk can be managed.
Depending on the risk, enhanced CDD may include:
obtaining more information about ownership and control;
examining the customer’s source of funds or source of wealth;
obtaining more detail about the purpose of the relationship;
checking explanations against reliable information;
increasing the frequency or depth of monitoring; and
obtaining senior management approval.
Enhanced CDD should respond to the particular risk. Collecting more documents without considering what they show is not enough.
Can initial CDD be completed after the service starts?
Initial CDD must generally be completed before a reporting entity provides a designated service. Limited exceptions permit some steps to be completed later.
These exceptions are narrow. Depending on the exception, the reporting entity may need to establish that:
starting the service before CDD is complete is essential to avoid interrupting the ordinary course of business;
the additional risk created by the delay is low;
controls are in place to manage that risk; and
CDD will be completed as soon as practicable and within the applicable deadline.
Restrictions may prevent money, property or assets from being transferred or withdrawn until verification is complete.
Delayed CDD should be treated as an exception managed through clear controls, not as a routine response to onboarding delays.
How does the CDD transition period work?
Some reporting entities that were already enrolled before the reformed CDD requirements commenced can continue using their previous applicable customer identification procedures for specified customer classes during a transitional period.
The transitional period runs until 31 March 2029. A reporting entity relying on it must have transitional policies that identify the customer classes covered and state when the entity will stop using its previous procedures for each class.
The transitional arrangements affect initial CDD. They do not remove the need to conduct ongoing CDD.
A reporting entity should approach the transition as a planned migration. Treating 31 March 2029 as the implementation date may create operational pressure and increase the risk of inconsistent onboarding.
What does ongoing CDD require?
Ongoing CDD requires a reporting entity to monitor its customers so it can continue to identify, assess, manage and mitigate ML/TF risk.
This includes monitoring for unusual transactions and behaviour that may give rise to a suspicious matter reporting obligation.
A reporting entity may also need to:
review and update the customer’s risk rating;
review, update and reverify KYC information;
investigate doubts about the accuracy or reliability of existing information; and
identify significant changes in the nature and purpose of the relationship.
CDD therefore continues after onboarding. A verified identity is not enough if later information shows that the customer, ownership structure or use of the service has changed.
What transactions and behaviours may be unusual?
Unusual activity may include:
transactions that are unusually large or complex;
an unusual pattern of transactions or behaviour;
activity with no apparent economic or lawful purpose; or
activity inconsistent with what the reporting entity knows about the customer.
That comparison requires a reliable customer profile. If the reporting entity has not recorded the expected purpose and use of the service, it will be harder to identify activity that falls outside it.
An unusual transaction is not automatically suspicious. It is a prompt to review the activity, gather relevant information and decide whether there is a reasonable basis for suspicion.
Can another business conduct CDD for you?
A reporting entity may use an agent to collect and verify KYC information on its behalf. It may also be able to rely on CDD conducted by another reporting entity or an eligible overseas equivalent.
The reporting entity does not automatically transfer its compliance responsibility to the third party.
Before relying on another person, the entity should understand:
which CDD steps the person will perform;
the procedures and standards they use;
whether the entity can obtain complete KYC information and records promptly;
how errors and exceptions will be handled;
how the arrangement will be monitored; and
when reliance must stop.
Formal reliance arrangements require ongoing assessment. A contract alone does not show that the third party’s processes remain suitable.
What if a customer does not have standard identification?
A person may be unable to provide standard identification for reasons outside their control. That should not automatically exclude them from receiving services.
The reporting entity should assess the available KYC information, collect information appropriate to the person’s risk and take reasonable steps to verify it using alternative reliable sources.
Alternative evidence may include referee statements, government correspondence, community identification documents or evidence of membership of an Indigenous organisation.
The AML/CTF policies should explain how staff assess alternative evidence and manage any additional risk. The process should provide a genuine alternative without weakening the entity’s controls.
What CDD records must be kept?
A reporting entity must keep records showing how it complied with its CDD obligations.
These records should include:
the KYC information collected;
how and when information was verified;
customer risk assessments and ratings;
the reasons for material decisions;
screening results and the resolution of possible matches;
simplified or enhanced CDD measures;
reviews completed during the relationship; and
information obtained through third-party arrangements.
CDD records generally need to be retained for seven years after the customer relationship ends or an occasional transaction is completed.
Good records show more than the final result. They allow another person to understand what information was available, what decision was made and why that decision was reasonable.
What should you do?
Map each customer type. Identify the individuals, companies, trusts, partnerships, associations and other customers your business serves.
Define the required KYC information. Set out what must be collected and verified for each customer type and risk level.
Test your beneficial ownership process. Check that staff can identify ownership and control through layered companies and trusts.
Review your customer risk-rating method. Confirm that it reflects your ML/TF risk assessment and produces sensible outcomes.
Connect onboarding to ongoing monitoring. Make sure the information collected at onboarding creates a clear basis for identifying unusual activity later.
Set triggers for refreshed CDD. Changes in ownership, customer activity, risk information or the purpose of the relationship should prompt a review where appropriate.
Check third-party arrangements. Confirm that you can obtain the required KYC information and records promptly and that the provider’s procedures remain suitable.
Test customer files. Review a sample across different customer types and risk ratings to compare the written policies with actual practice.
Review your transition plan. If you are using previous customer identification procedures, document which customer classes are covered and when each will move to the new initial CDD process.
The bottom line
Customer due diligence is not a one-time identity check. It is the continuing process of knowing who your customer is, understanding why they use your services and recognising when their activity no longer matches that understanding.
Effective CDD connects customer identification, risk ratings, monitoring and escalation. If those processes operate separately, warning signs can fall between them.
Need help with AML/CTF customer due diligence?
Dwyer Harris assists reporting entities to develop, review, implement and update their AML/CTF customer due diligence frameworks.
We can help you:
identify the CDD requirements that apply to your customers and designated services;
draft or review initial and ongoing CDD policies;
design or review customer risk-rating methods;
develop procedures for beneficial owners, PEPs and higher-risk customers;
review simplified and enhanced CDD controls;
assess third-party KYC and reliance arrangements;
review transitional CDD policies and implementation plans;
test selected customer files and operational controls;
conduct a post-implementation review of new CDD processes; and
update your AML/CTF program following a business change, regulatory development or review finding.
Our focus is on CDD processes that meet the legal requirements, give staff clear instructions and work within the practical constraints of your business.
Get in touch with Dwyer Harris if you need help drafting, reviewing or implementing your customer due diligence framework.
This article provides general information only and is not legal advice.