Customer Due Diligence in the Digital Age: How to Stay Compliant and Manage Risks

Mažvydas Miliauskas
Author
Mažvydas Miliauskas, CAMS
Published
April 17, 2025
Magnifying glass inspecting a digital profile with an alert icon, representing identity verification.

In today’s complex financial landscape, Customer Due Diligence (CDD) plays a critical role in preventing financial crimes, ensuring regulatory compliance, and managing business risks. 

Despite its importance, businesses often face challenges by having to navigate evolving AML regulations. 

This article explores the key aspects of CDD, its significance, common obstacles, and provides a self-assessment for effective CDD program.

What is Customer Due Diligence (CDD)?

Customer Due Diligence (CDD) is the process that financial institutions, designated non-financial businesses and professions (DNFBPs) and other companies use to identify, verify and score the potential and existing customers.

During this process, they collect information, verify it and assess potential risks related to the presented factors. Without this process, the criminals might easily misuse other companies and sectors for their illicit purposes, therefore it is a key component of anti-money laundering (AML) program which helps organizations to ensure compliance with AML laws and regulations everywhere they do business.

In some resources, the CDD process is explained as being related only to Identification & Verification and Monitoring, however in reality it looks like this:

ProcessExplanation
Identification of the customerCollecting personal details about the person and/or the legal entity (e.g., name, date of birth, address, Legal entity identifier, Beneficial owners etc)
Verification of the provided documentationThis process ensures that customers are really who they say they are. For individuals, this may include the process of ID document collection, including selfie or biometric verification, collecting proof of address etc.

For businesses, it may include verifying the information against the information in the public legal entity register, cross-check the beneficial ownership information in independent sources etc.
Risk AssessmentThis process takes into account various factors (e.g., customer’s geographical location, expected transaction volumes, type of legal entities, sanctions and PEP screening results etc) to categorize customers as low, medium, or high risk.

Depending on the customer's risk profile and/or industry type, the organisation may need to collect and verify additional information about the customer.
Monitoring of the customerOnce the business relationship is established, companies must keep track of the customer’s transactional data and detect deviations from the information that was obtained. In addition, they need to periodically update the obtained information during the process that is called Ongoing Due Diligence (ODD).
Record KeepingThe companies need to keep thorough records of all customer interactions, documents, identification checks, and risk assessments for a certain period of time which is defined by the local legislation (e.g., 5 years after the business relationship was terminated).

Risk Based Approach in CDD

The company cannot avoid conducting CDD, but it can use a risk-based approach to profile the customers and determine how much information is required in such cases.  The CDD process can be classified in the following categories:

  1. Simplified Due Diligence (SDD)

    SDD can be applied in certain situations where the risk of money laundering or financial crime is low (it does not mean that all low risk customers can undergo SDD). This typically includes customers such as government agencies, or publicly listed companies with transparent financial records. SDD may also be applied to low-value accounts, pension funds, or customers conducting transactions below a specified risk threshold. The process can be adapted so the customers can be exempted from certain requirements (e.g., if the company has its shares listed on the publicly available stock exchange, they are subject to additional transparency requirements and usually beneficial ownership information is publicly available). However, it is important to note that SDD is only permissible when there are no red flags. If any suspicious activity arises, the institution must conduct the Standard or Enhanced Due Diligence procedures.

  2. Standard Due Diligence (SDD)

    SDD is applied in situations where the risk of financial crime is either low or medium, and the customer does not exhibit high-risk characteristics (otherwise the case may require escalation to Enhanced Due Diligence (EDD) for deeper investigation). SDD involves verifying the customer’s identity through official documents, assessing the nature of their transactions, and ensuring their activities align with expected financial behaviour.

  3. Enhanced Due Diligence (EDD)

    EDD is required in situations where a customer presents a higher risk of money laundering, terrorism financing, sanctions or such business relationship is simply outside of the company’s risk appetite (e.g., a situation can occur where company sells online pornography but the customer’s risk score results in a low or medium risk score, therefore it is important to determine which industries should be prohibited). This process can be applied to politically exposed persons (PEPs), high-net-worth individuals (HNWIs), customers from high-risk jurisdictions, businesses involved in cash-intensive or high-risk industries etc. EDD process typically involves collecting additional documentation, such as verifying the Source of Funds (SoF) and Source of Wealth (SoW) documents, conducting extensive background checks (e.g., conducting adverse media screening across all available watchlists), and/or applying additional transaction monitoring. In many countries after the EDD is completed, an additional senior management approval is needed for new or existing high-risk customers. 

The importance of CDD process

CDD is a fundamental process that can protect businesses and financial institutions (directly or indirectly) in the following ways:

Facilitates Better Decision-Making – by obtaining CDD information the company is in a better position to identify potential crimes when you know your client and understand the reasoning behind the information they provided. For example, by obtaining the information on the beneficial owner you are able to identify who are the Ultimate Beneficial Owners and conduct Sanctions and PEP Screening on them.  

Verifying the legitimacy of Source of Funds (SoF) and Source of Wealth (SoW) – by conducting thorough checks, businesses and financial institutions can ensure that customers’ money comes from legal and ethical sources.

Regulatory Compliance – by conducting these checks the company shows that it complies with laws such as the USA PATRIOT Act, the EU’s AML Directives, and other global regulations.

Risk Management – the company identifies and mitigates potential risks associated with customer transactions early in the process, allowing businesses to take necessary precautions. Without such checks, people could use fake identities and use them to take out loans that will never be paid back. 

Strengthens Financial System Integrity – when the country ensures that all market participants use the CDD process effectively, it contributes to a safer and more transparent global financial system that preventing illegal financial flows and decreases the need for additional checks.

Challenges in the CDD process

While the CDD process has its benefits, the businesses often face some challenges related to this process because the world and people are not stagnant, and their profiles constantly change. Some of the challenges can be related to:  

Difficulty in Verifying Identity 

Customers may not have official identification documents (e.g., in case of asylum seekers), or the ID documents can be fraudulent or forged. In addition, some jurisdictions (including many countries in the EU) lack publicly available or trusted financial databases for verification, therefore the company cannot check this information using independent sources.

Complex Ownership Structures

Large corporate structures can contain multiple layers of ownership, involve partnerships, trusts or offshore entities in high risk countries which complicates the due diligence process.

Increased Costs and Resource Demands

Implementing robust CDD systems requires investment in technology, personnel, and training. For example, the customer portfolio needs to be constantly screened against various sanctions and PEP lists, therefore small and medium-sized enterprises (SMEs) may struggle with the cost of compliance as they are less likely to deploy perpetual KYC processes or AI solutions in their daily work.

Data Protection

Laws like the GDPR and other national privacy regulations impose strict rules on data collection, storage, and processing, requiring organizations to implement strong security measures, consent management, and data access controls.

Inconsistent or Incomplete Customer Data

Customers may provide incorrect or incomplete information during onboarding. For example, some customers have dual citizenships and if one these countries is a high-risk jurisdiction, they might choose to provide documentation which raises less concerns. 

Passport comparison from multiple countries including USA, Poland, and Canada on a wooden surface.
An example of a post from a private Reddit group where people brag about the passports they have. Source: Reddit

 

Changing and Increasing Regulatory Requirements

AML and CDD regulations frequently change, requiring constant updates to compliance procedures. For example, the customer can receive a Low risk rating, but the next day the country where they reside is placed in the FATF’s greylist, therefore the regulation requires this customer to be rated High risk when in reality there was no real change in customer’s patterns or behaviour.

High False Positive Rates in Screening

Balancing accuracy and efficiency in screening is a challenge. Automated CDD and AML screening systems can generate a high number of false positives if they are not properly tuned, leading to unnecessary investigations and increased compliance costs.

Resistance from Customers 

Some customers (e.g., High net worth individuals) may be unwilling to share personal or financial details due to privacy concerns.

CDD program Self-Assessment

A well-structured CDD program is essential for financial institutions and businesses to mitigate risks, comply with regulatory requirements, and prevent financial crimes. Below there are questions that should help to self-assess your CDD program if it has the key elements:

  • Does the company have Know Your Customer (KYC) and Know Your Business (KYB) procedures in place? If yes, do these procedures establish red flag indicators for unusual transactions, how to properly investigate beneficial ownership, source of funds/wealth documents? Do these procedures define for how long the documents must be retained?
  • Does the company use Risk-Based Approach (RBA) in their procedures, like SDD and EDD? What additional procedures apply to high-risk customers? Have you defined what customers are outside of the company’s risk appetite? Does the customer risk scoring take into account the risks related to the customer’s profile, geographic locations, products they use and other elements? 
  • Does the company perform Ongoing Due Diligence and has implemented real-time transaction monitoring to detect suspicious activities?
  • Is the company conducting regular customer checks against sanctions lists, PEP lists, and adverse media databases?
  • Does the company maintain records of customer interactions, risk assessments, and due diligence reports for regulatory audits?
  • Does the program incorporate requirements from the relevant regulations such as FATF, 6AMLD, or the USA PATRIOT Act? How often are they updated and are they following the changes in the FATF greylist which occurs 3 times a year?
  • Are the employees provided with regular training programs on AML/CFT compliance, fraud detection, customer risk assessment? Can they recognize suspicious transactions and understand reporting obligations?

Conclusions and AMLYZE approach

CDD is crucial for safeguarding companies against fraud and financial risks, and it needs to be customized for specific institutional needs, properly documented and regularly updated if it wants to ensure that company resources are dedicated to customers that present the highest risk. In addition, this process needs to be streamlined, considering all key risk factors, such as customer, product, channel, and geographies.

To help financial institutions overcome the operational challenges of CDD, AMLYZE provides a robust Due Diligence form integrated directly into the customer profile.

AMLyze dashboard screenshot showing risk indicators and customer activity analysis.
The screen of the AMLYZE platform

This feature allows compliance teams to capture and manage critical risk indicators through a customizable interface aligned with their specific regulatory and business requirements. The system supports differentiated assessment logic based on whether a customer is subject to Simplified (SDD), Standard (FDD), or Enhanced Due Diligence (EDD), ensuring appropriate evaluation according to the customer’s risk profile.

These indicators can also be embedded into the customer risk scoring framework, enabling organizations to maintain a consistent, accurate, and context-driven approach to customer risk assessment.

Learn more about our Customer Risk Assessment product and request a demo today.

About the author

Mažvydas Miliauskas
Author
Mažvydas Miliauskas, CAMS
Mažvydas is AMLYZE contributing author. CAMS certified high achiever who is passionate about financial crime compliance, ML/TF typologies and enterprise risk management.

Related