Customer Due Diligence for Banks: A Complete CDD Guide
Customer due diligence at banks is the set of checks a financial institution runs on a new customer. Those checks confirm the customer's identity. They establish the purpose of the relationship. And they measure the money laundering risk that customer brings. Banks start this at onboarding and keep it going for as long as the account stays open. It is the backbone of every bank's anti-money laundering program.
The depth of those checks is not fixed. It scales with risk. That is why a risk-based approach sits underneath everything that follows. A retail saver does not get the same treatment as a foreign-owned holding company, and regulators expect a bank to explain why.
This guide walks through what customer due diligence means for banks specifically: the four pillars, how beneficial ownership rules work, the difference between simplified and enhanced checks, and what changed under the 2026 FinCEN relief order.
What is Customer Due Diligence?
Customer due diligence, or CDD, is the process of checking and screening prospective and existing customers. The point is to give a bank reasonable confidence that a customer is not involved in money laundering, sanctions evasion, or terrorist financing. It pairs identity verification with a risk assessment. One confirms who the customer is; the other decides how closely to watch them.
The term shows up across the whole financial sector. Banks run it. So do fintechs, insurers, and payment firms. At a minimum, CDD means verifying a customer's identity and screening them against PEP and sanctions lists before the relationship begins, then refreshing that picture over time.
What Does CDD Stand For?
CDD stands for Customer Due Diligence. You will also see it written as "client due diligence," and the two mean the same thing. In banking documents it often appears next to KYC (Know Your Customer) and EDD (Enhanced Due Diligence), which are related but not identical concepts covered further down.
Customer Due Diligence Requirements for Banks
Most banking CDD requirements trace back to a small number of laws and standards. In the United States, the Bank Secrecy Act and the USA PATRIOT Act set the baseline, and FinCEN's CDD Final Rule formalized it. Globally, the Financial Action Task Force (FATF) sets the template that national regulators adapt. FATF Recommendation 10 is the one that defines customer due diligence.
Under FATF Recommendation 10, a bank must apply CDD measures in four situations: when establishing a business relationship, when carrying out an occasional transaction above the USD/EUR 15,000 threshold, when there is a suspicion of money laundering or terrorist financing, and when it doubts the accuracy of information it collected earlier. Each measure is applied on a risk-sensitive basis.
The four core requirements themselves are consistent across most frameworks:
- Customer identification and verification. Collect and confirm identifying details using reliable, independent documents or data sources.
- Beneficial ownership. For legal entity customers, identify the people who ultimately own or control the company.
- Purpose of the relationship. Understand what the customer intends to do with the account, so unusual activity later stands out.
- Ongoing monitoring. Keep watching transactions and refresh customer records across the life of the relationship.
That fourth point matters. CDD is not a one-time gate at account opening. It runs continuously.
The Four Pillars of Customer Due Diligence
Banks often describe CDD as resting on four pillars. The first three predate the modern rules. The fourth, beneficial ownership verification, was added when FinCEN's CDD Final Rule took effect in May 2018, which is why older guides sometimes list only three.
Pillar one is customer identification. The bank gathers a customer's name, date of birth, address, and identification number, then verifies them. Many institutions use automated identity verification with document checks and selfie biometrics to make this step fast without weakening it.
Pillar two is beneficial ownership. When the customer is a company, trust, or partnership, the bank looks past the legal shell to the natural persons behind it. More on the 25% rule below.
Pillar three is understanding the relationship. A payroll account for a local bakery and a correspondent account for an overseas bank carry very different expected behavior. Capturing intent early gives the monitoring engine a baseline to compare against.
Pillar four is ongoing monitoring. Sometimes called perpetual KYC, this is the practice of reviewing activity and updating profiles over time rather than at fixed intervals only.
Beneficial Ownership Verification and the 25% Rule
For legal entity customers, a bank has to identify and verify any individual who owns 25% or more of the entity, plus at least one individual who controls it, such as a senior managing official. The idea is simple. Criminals hide behind corporate structures, so the bank needs to see the real humans underneath.
What changed recently is the timing. On February 13, 2026, FinCEN issued an exceptive relief order (FIN-2026-R001) that frees covered financial institutions from having to re-identify and re-verify a legal entity's beneficial owners every single time that customer opens a new account. The banking industry had pushed for this since the 2016 rule landed.
Under the order, a bank must still verify beneficial owners when the entity first opens an account, when it learns something that calls earlier information into question, and whenever its own risk-based procedures call for a refresh. Banks must keep written procedures for identifying and verifying beneficial owners inside their AML program either way. The relief is optional. An institution that prefers to collect ownership data at each new account can keep doing exactly that.
Simplified, Standard, and Enhanced Due Diligence
Not every customer warrants the same scrutiny. Banks generally work across three tiers, calibrated to risk.
Simplified Due Diligence (SDD) applies to demonstrably low-risk customers and products. The bank still identifies the customer but applies lighter verification and monitoring. A regulated domestic institution opening a low-value account is a typical candidate.
Standard CDD is the default for ordinary retail and business customers. It covers the four pillars above at a normal level of depth.
Enhanced Due Diligence (EDD) kicks in for higher-risk situations. A politically exposed person triggers it. So does a customer in a high-risk jurisdiction, a complex or opaque ownership structure, or an unusual transaction pattern. What EDD adds is depth. The bank verifies source of funds and source of wealth. It maps the full ownership chain, screens adverse media more deeply, requires senior management sign-off, and reviews the relationship more often.
Picking the right tier is the hard part, and it is where many programs slow down. Treating it as a fresh judgment call for every customer creates inconsistency and audit gaps.
Rule-based risk rating takes the guesswork out of that tier decision and keeps it consistent across every customer. Book a Financial Crime Demo.
How the Customer Due Diligence Process Works at a Bank
In practice, a bank moves through a recognizable sequence. The exact tooling differs, but the shape holds.
Step 1: Establish identity
Before any business begins, the bank verifies the prospective customer's identity and, for entities, the nature of the business. This means collecting information and confirming it against reliable sources. Automated name and document checks make this quick rather than a multi-day wait.
Step 2: Assess and classify risk
Once identity is settled, the bank scores the customer's risk using factors like occupation, source of income, geography, and expected activity. That score drives which due diligence tier applies. The result needs to be stored somewhere auditable, because examiners will ask to see it.
Step 3: Apply the right level of diligence
With a risk score in hand, the bank chooses simplified, standard, or enhanced measures. High-risk customers move into EDD; low-risk ones may qualify for simplified due diligence.
Step 4: Monitor continuously
Onboarding is the start, not the finish. The bank screens transactions for patterns that do not fit the customer's profile. Records get refreshed when something material changes. Suspicious findings are escalated, and where warranted, reported through a Suspicious Activity Report.
When Should a Bank Apply Customer Due Diligence?
Banks run CDD at several defined moments rather than just once.
At account opening. A new customer triggers full identification and an initial risk assessment, including occupation, source of income, and expected turnover.
On significant or unusual transactions. A large transfer, a cross-border movement, or a counterparty in a high-risk country all call for one thing: confirmation that the funds are clean.
When the customer profile changes. A new address, a change in business ownership, or a shift in transaction patterns can move a customer into a different risk band and warrant a fresh look.
In high-risk scenarios. PEPs warrant enhanced review before transactions are approved. So do high-risk industries such as gambling or money services, along with high-risk jurisdictions.
CDD and KYC: What is the Difference?
People use the terms together so often that the line blurs. Here is the clean version. KYC, or Know Your Customer, is the identity piece: confirming a customer is who they claim to be. CDD is the wider discipline that wraps around it. On top of identification, it adds risk assessment, ongoing monitoring, and reporting.
Put another way, KYC is a component of CDD. A bank cannot do meaningful due diligence without first knowing the customer, but knowing the customer is only the opening move. This relationship also explains why KYB onboarding for business customers feeds directly into the CDD process.
Central KYC Registries
Some markets reduce duplicated effort with a central KYC registry, a shared utility that stores verified customer records financial institutions can draw on. India's CKYC system run by CERSAI is the best-known example. For banks, the appeal is obvious: pull an existing verified record instead of re-collecting documents a customer already supplied elsewhere.
Registries do not remove a bank's own obligations. The institution still owns its risk assessment, its monitoring, and its decision on what level of diligence applies. A registry speeds up the data-gathering step; it does not replace judgment.
CDD Checklist for Banks
While exact requirements vary by institution and jurisdiction, the identifying details a bank collects are broadly consistent. Customers typically provide personal information and supporting documents containing personally identifiable information (PII) so the bank can verify them.
A working CDD checklist usually captures:
- Full legal name
- Date of birth
- Residential and, where relevant, business address
- Government-issued ID such as a passport or driver's license
- Proof of address, such as a utility bill
- Source of funds and expected account activity
- For entities, beneficial ownership and control details
Best Practices for CDD in Banking
Build the program around risk
A risk-based design sends effort where it belongs. Low-risk customers clear quickly. High-risk ones get the scrutiny they warrant. The point is to stop spreading resources evenly across a population that is not evenly risky.
Collect accurate data and verify it independently
Garbage in, garbage out applies fully here. Verify identity documents and ownership details against independent, reliable sources. That is what separates real diligence from a paperwork exercise.
Automate the repetitive parts
Some tasks scale poorly by hand. Identity verification is one. Sanctions list screening and transaction monitoring are two more. Automating them frees analysts to focus on the genuinely ambiguous cases that need human judgment. That is where their time is worth most.
How KYC Hub Helps Banks Run CDD
KYC Hub built its banking compliance platform to handle customer due diligence end to end, with two priorities that map directly onto the pain points above: onboarding customers with ease and reducing false positives. Slow onboarding loses good customers; noisy alerts bury analysts. The platform is designed to ease both.
It pairs identity verification, ID checks, and digital signing with government database verification, so the identification pillar is covered without a patchwork of point tools. Screening against sanctions, PEP, and watchlist data runs at onboarding and continuously after it. Risk scoring drives the SDD, CDD, or EDD decision. That decision runs on rules you set rather than ad-hoc calls, which keeps outcomes consistent and auditable.
For the parts that need to flex, customizable risk assessments and ongoing transaction monitoring let a bank tune its CDD measures to its own risk appetite. The aim is straightforward. Stay compliant, onboard faster, and keep the audit trail clean.
Conclusion
Customer due diligence is how a bank turns "we don't really know this customer" into a documented, defensible view of who they are and what risk they carry. The four pillars give it structure. The risk-based approach decides how hard to push on each one. And the 2026 FinCEN relief is a reminder that the rules still move. That is exactly why programs need to be configurable rather than hard-coded.
Done well, CDD is not a box-ticking chore. It is what lets a bank grow its customer base with confidence instead of exposure.



