← Industry Insights
Enhanced Due Diligence

KYC and CDD: What Is the Difference Between CDD and KYC?

Updated Jun 2026 · 7 min read
SHAREinXf
What is the Difference between CDD and KYC?

KYC and CDD are closely linked. They are not the same thing, though. Know Your Customer (KYC) is the broad framework regulated businesses use to verify who their customers are and keep watching them over time, and Customer Due Diligence (CDD) sits inside that framework as one component, focused on assessing and managing the risk each customer brings.

People use the two terms interchangeably. That habit blurs the line between them, and the blur is exactly what this guide sets out to clear up by breaking down what KYC and CDD each cover and how the two fit together. You will also find the global regulations that shape them, the challenges firms run into, and the practices that keep an Anti-Money Laundering (AML) program effective.

What Is Know Your Customer (KYC)?

Know Your Customer (KYC) is a process that financial institutions use to verify the identity of their customers, either during or before financial transactions. Real users, real engagement: that is what KYC promotes. Done well, it helps prevent fraud, money laundering, and the financing of terrorism.

Key Components of KYC

A KYC program rests on three working parts. The first is the Customer Identification Program (CIP), where companies obtain the customer's personal information: their name and date of birth, their address, and the identification documents that prove who they say they are. Customer Due Diligence (CDD) comes next, the process that assesses the risk associated with a customer. Then there is ongoing monitoring. Customers should be scrutinized periodically for suspicious behavior.

Banks, financial institutions, and other regulated organizations are required to use KYC to comply with Anti-Money Laundering (AML) laws. Compliance is only part of the benefit. Establishing trust with customers and building a secure financial ecosystem is the other, larger part.

What Is Customer Due Diligence (CDD)?

Customer Due Diligence (CDD) is a subset of the Know Your Customer (KYC) framework. It evaluates the risks associated with customers, then measures and mitigates those risks to gauge a company's exposure to potential fraud, corruption, or money laundering.

CDD is rooted in risk. How deep your due diligence goes depends on the risk a given client carries. A high-risk customer needs a more thorough level of due diligence before you operate with them, whereas a low-risk customer only calls for a basic check.

Types of CDD

To understand the difference between CDD and KYC, it helps to look at the types of due diligence and what each one means.

Simplified Due Diligence (SDD)

Reserved for customers at low risk of financial crime. Think individuals with an unblemished financial background, or institutions operating in a highly regulated environment.

Standard Due Diligence

Most customers fall here, the ones who show no signs of suspicious risk. The work amounts to basic identity checks and a risk evaluation.

Enhanced Due Diligence (EDD)

This applies to high-risk customers, a group that includes politically exposed persons (PEPs) and anyone engaging in significant transactions. It adds further verification, a check of the source of funds, and ongoing monitoring on top of the standard review.

How Are KYC and CDD Different?

KYC and CDD are closely related. Scope is where the key difference lives, in the range of activities each one covers: KYC is the wider framework, CDD is an integral part of it, and the cleanest way to hold the two apart is to remember that KYC is the overall program for knowing and monitoring a customer while CDD is the risk-assessment engine that runs inside it.

KYC sets out the full lifecycle: identifying the customer at onboarding, assessing their risk, and monitoring them on an ongoing basis. CDD concentrates on that middle step. It takes the information KYC gathers and turns it into a customer risk rating, deciding how much scrutiny a given customer warrants. Every KYC program relies on CDD. On its own, though, CDD does not cover the identification and continuous-monitoring duties that complete a KYC obligation.

CDD vs EDD

Within CDD, the level of scrutiny is not fixed. Standard CDD confirms who a customer is and gauges their baseline risk, whereas Enhanced Due Diligence (EDD) is the deeper investigation triggered by high-risk customers, the kind of review that calls for additional documentation, source-of-funds checks, and closer ongoing monitoring.

Getting this calibration right matters. Apply too little scrutiny and you miss real risk; push enhanced checks onto everyone and you burn resources while frustrating low-risk customers who never needed them in the first place. For a fuller breakdown, see the difference between CDD and EDD.

What Is Central KYC (CKYC)?

Central KYC, often shortened to CKYC, is a model in which customer KYC records are held in a single shared repository rather than collected separately by every institution. A customer provides their KYC data once. Participating institutions can then access it, which removes redundant paperwork and repeated checks across firms.

That stands in contrast to conventional KYC, where each institution carries out and stores its own verification independently. Central KYC does not replace a firm's due diligence obligations. What it does instead is simplify the identification step and cut the friction that builds up when a single customer ends up being onboarded by more than one regulated entity.

KYC and CDD Regulations Across Different Countries

Know Your Customer regulations and Customer Due Diligence laws vary across jurisdictions.

United States

The USA PATRIOT Act imposes stringent requirements regarding KYC and AML policies. Compliance is monitored by the Financial Crimes Enforcement Network (FinCEN).

United Kingdom

In the UK, KYC and CDD answer to the Money Laundering Regulations (MLR) 2017. Compliance is overseen by the Financial Conduct Authority (FCA).

European Union

AML Directives govern KYC and CDD across the EU. Oversight sits with the European Banking Authority (EBA).

Asia-Pacific

Countries such as India and Singapore adhere to the rules of the FATF. In India, KYC is established under the Prevention of Money Laundering Act (PMLA).

When Are KYC and CDD Required?

KYC and CDD obligations are triggered at defined points in the customer relationship rather than as a one-off task. In practice, regulated firms must apply them:

  • At onboarding, before establishing a new business relationship or opening an account.
  • For occasional transactions that run above regulatory thresholds.
  • Whenever money laundering or terrorist financing is suspected. No threshold applies here.
  • When existing customer information is doubtful, out of date, or has materially changed.

Risk is not static. CDD is not finished once a customer is onboarded either, because ongoing monitoring is what keeps the risk profile current as a customer's behavior, transactions, and circumstances change over the life of the relationship.

Importance of CDD and KYC in Fraud Prevention

KYC and CDD matter because they keep unlawful activity from exploiting businesses and financial organizations, and the payoff of getting them right shows up in several distinct places across a firm. Start with the obvious one. Verifying the identity of customers prevents money laundering. Meeting sanctions and AML obligations covers regulatory compliance. Avoiding involvement with criminal organizations secures business reputation. And building customer and shareholder confidence strengthens trust.

Challenges and Best Practices

Here are several common challenges and the practices that address them.

Challenges

  • Regulatory complexity. Different jurisdictions have varying laws, which makes it difficult to comply with all of them at once.
  • High implementation costs: building out thorough checks can prove very costly.
  • Customer friction. Long verification processes wear on the experience.
  • Data privacy concerns. Sensitive customer data has to be protected with strong security controls to be managed effectively.

Best Practices

  • Use AI-powered identity verification for accuracy.
  • Introduce automation for due diligence tasks.
  • Keep pace with evolving AML laws.
  • Train employees on fraud-prevention methods.

A practical KYC and CDD framework keeps these checks consistent across every customer, so the line between standard and enhanced scrutiny is applied the same way each time.

Book an AML Screening Demo to see how KYC Hub supports a consistent CDD framework: Book an AML Screening Demo.

How KYC Hub Supports KYC and CDD

KYC Hub's AML screening and monitoring solution is built for the risk side of KYC, which is exactly where CDD lives. Think of it as an end-to-end AML screening and ongoing monitoring platform. Exhaustive AML screening leads the way. Around that sit continuous monitoring and AML alerts, global adverse media intelligence, network intelligence, and global data coverage.

Exhaustive AML screening checks customers against the watchlists, sanctions, and PEP data that CDD and EDD depend on. Continuous monitoring and AML alerts keep that assessment live after onboarding, so a customer's risk profile is re-evaluated as their behavior shifts rather than going stale. Global adverse media intelligence surfaces negative news that a standard identity check would miss. Network intelligence maps the connections behind a customer, and global data coverage extends that reach across jurisdictions, which helps when KYC and CDD obligations span more than one regulatory regime.

Together, these pillars let compliance teams run the risk-assessment engine inside KYC without stitching together separate tools for screening, monitoring, and adverse media.

Book an AML Screening Demo to see KYC Hub applied to your CDD and AML workflow: Book an AML Screening Demo.

Conclusion

Banks and other financial institutions should understand the distinction between Know Your Customer (KYC) and Customer Due Diligence (CDD) to ensure compliance and security. The distinction is simple once you hold the two side by side: KYC verifies that a customer's identity is accurate and keeps watching over time, while CDD, by contrast, is the method for assessing customer risk at varying levels. A practical KYC and CDD framework, kept current through ongoing monitoring, helps prevent fraud and uphold AML obligations.

[ FREQUENTLY ASKED QUESTIONS ]

Any questions? We got you.

What is CDD?

Customer Due Diligence (CDD) is the process regulated businesses use to identify a customer and assess the risk they pose for money laundering, fraud, or corruption. The depth of the checks scales with how risky the customer is.

What is meant by CDD in KYC?

Within KYC, CDD is the risk-assessment component. KYC covers the full process of identifying and monitoring a customer, and CDD is the step that turns the gathered information into a risk profile to decide how much scrutiny the customer needs.

What is CDD in banking?

In banking, CDD is the set of checks a bank runs to verify an account holder's identity and evaluate their risk before and during the relationship. It underpins the bank's wider KYC and AML obligations.

What is CDD and EDD?

CDD is the standard due diligence applied to customers based on their risk level. EDD (Enhanced Due Diligence) is the deeper layer reserved for high-risk customers, adding source-of-funds checks, extra documentation, and closer ongoing monitoring.

When are KYC and CDD required?

They are required at onboarding, for occasional transactions above regulatory thresholds, whenever money laundering or terrorist financing is suspected, and when existing customer information is doubtful or has materially changed.

What is the distinction between central KYC and KYC?

A centralized KYC (CKYC) system gives customers a single shared data repository, eliminating redundancy. Conventional KYC is carried out and stored individually by each institution.

Is KYC part of CDD?

It is the other way around. CDD is a subset of KYC, focused on quantifying the risk of clients based on their financial activity, while KYC is the broader framework around it.

What are the most essential aspects of KYC?

KYC comprises three core elements: customer identification, customer due diligence, and ongoing monitoring.

What are the regulations for KYC and CDD?

The major rules include the USA PATRIOT Act, the AML Directives (EU), the MLR 2017 and FCA rules (UK), and the recommendations provided by the FATF.

What happens if a company fails to implement proper KYC and CDD measures?

Non-compliance can result in heavy fines, reputational damage, and legal penalties imposed by regulatory bodies.

[ KYC HUB ]

Automate KYC from onboarding to ongoing review

KYC Hub verifies identities, screens against global watchlists and monitors risk continuously — in one platform.

Explore the KYC solutionBook a demo
[ RELATED READING ]
KYC vs eKYC: Which Method Should Your Institution Use in 2026?
[ KYC ]

KYC vs eKYC: Which Method Should Your Institution Use in 2026?

KYC vs eKYC isn't just a compliance choice, it's a cost and risk decision. Learn which method fits your product under RBI's 2025 guidelines.

Mar 2026 · 7 min read
KYC Requirements in Saudi Arabia: A Comprehensive Guide for Financial Institutions
[ KYC ]

KYC Requirements in Saudi Arabia: A Comprehensive Guide for Financial Institutions

Complete guide to KYC requirements in Saudi Arabia. Learn about SAMA regulations, compliance obligations, required documents, and penalties for financial institutions

Jan 2026 · 9 min read
Aadhar Card OCR API for KYC & Document Verification
[ KYC ]

Aadhar Card OCR API for KYC & Document Verification: A Buyer's Guide

An Aadhar card OCR API reads name, DOB, gender, and a masked Aadhaar number straight off the card so your KYC flow skips manual data entry. Here is how it works and how to evaluate one.

Dec 2025 · 10 min read