Customer Due Diligence Checklist — 5 Steps to Improve CDD (2024)

What exactly is Customer Due Diligence (CDD)? And why is it so important? CDD is a critical element of effectively managing risk and protecting you (and your business) against potential association or involvement with bad actors and financial crimes. CDD processes are crucial for Know Your Customer (KYC), and while they vary around the world, in most cases, they involve identifying your customer and understanding their activities. This then allows you to assess their risk profile.

Sometimes, Enhanced Due Diligence (EDD) is needed. This involves collecting additional information on high-risk customers to provide a deeper understanding of customer activity and to mitigate risk. Customer assessments can be used to determine which level of due diligence is required, a crucial step in creating an effective risk-based approach as part of a robust compliance program.

To ensure that your business is following best practices, we have put together the following five-step checklist to help improve your CDD processes.

Step 1: Verify customer identities

Perform CDD measures before entering into business relationships with customers to detect potential bad actors early in the process. Creating barriers to prevent financial criminals from accessing accounts on your system helps avoid questionable activities before they can even begin.

How?Ascertain the identity and location of the potential customer, and gain a good understanding of their business activities. This can be as simple as verifying their name and address. However, with increases in online fraud, collecting more information or running additional identity checks might also be advisable. Some information sources that can help the identity process include:

  • Name
  • Address
  • Date of birth
  • Telephone number
  • National ID number
  • Identity documents
  • Mobile network data
  • Geolocation
  • Selfie
  • Live video
  • Third-party account verification

Business and other legal entity customers also require verification to ensure the legitimacy of the business and that the account holders have the proper authority to act on behalf of the business. The business verification process examines information like:

  • Business registration number
  • Company name
  • Address
  • Operational status
  • Key management personnel
  • Date of incorporation

Why?You have to first decide whether a client or customer fits your established risk profile, before entering into a business relationship with them. You can only do this by undertaking the appropriate CDD measures. This ensures that identity theft and any potential forgeries can be detected and dealt with early.

Step 2: Assess third-party information sources

Strengthen your processes when vettingthird parties.

How?You may rely on third parties — from banks, to lawyers, to auditors — to help you perform due diligence, however it’s important to choose these third parties wisely because the ultimate responsibility for CDD measures remains with you, not the third party.

Why?Sometimes, the only way to get the information required for CDD is through a trusted third party, so it’s important to ensure that their standards and best practices are aligned with your business. At the end of the day, you are liable and will be fined or penalized for non-compliance.

Systematically thinking about your business relationships, the potential exposures they could incur, what steps you need to implement, and then how you can operationalize and review those procedures makes good business sense — and helps ensure proper compliance.

Customer Due Diligence Checklist — 5 Steps to Improve CDD (1)

Step 3: Secure your information

Ensure that pertinent information has been collected and stored securely.

How?When authenticating or verifying a potential customer, classify their risk category and define what type of customer they are, before securely storing this information and any additional documentation digitally. While keeping personally identifiable information (PII data) might be necessary, there are often strict legal requirements regarding how that information is collected, stored and shared; beyond any legal necessity, protecting customer data is crucial to avoid any reputational damage.

Why?Having a meticulous and comprehensive process for documenting CDD-related information is highly effective and also mitigates any potential risk for you as a business.

Step 4: Take any necessary additional measures

Detect if there is a need for EDD.

How?Beyond basic CDD, it’s important that you carry out the correct processes to ascertain whether EDD might be necessary. This can be an ongoing process, as customers have the potential to transition into higher-risk categories over time so, conducting periodic due diligence assessments can be beneficial.

For example, most jurisdictions require politically exposed persons (PEPs) to go through the EDD process. Other factors that might trigger EDD are accounts with high transaction values, accounts that deal with high-risk activities and adverse media mentions. Factors to consider to determine whether EDD is required include, but are not limited to:

  • The person’s location
  • Their occupation
  • Transaction types
  • Expected activity patterns in terms of transaction types, dollar values and frequencies
  • Expected payment methods

If the account is for a business, additional EDD considerations include:

  • Identifying any connected entities and Ultimate Beneficial Owners (UBOs)
  • Performing AML/KYC checks on UBOs to verify their identities
  • Downloading official company records to act as a Record of Authority
  • Screening the company and its owners against global watchlists and sanctions lists

Why?Again, this protects you and your business against any involvement with nefarious activities and also ensures that you’re meeting various KYC and Anti-Money Laundering (AML) regulatory requirements.

Step 5: Ensure you’re audit ready

Keep historical records on hand.

How?Store records of instances of CDD and EDD securely, in a digital format.

Why?Keeping records of all the CDD and EDD performed on each customer, or potential customer, is necessary in case of future regulatory obligations (for example, an external audit).

With robust digital records in place, internal audit processes can account for deeper data sets, can re-run and re-analyze situations to decrease risk, improve performance and better guard against problematic accounts. These records are another line of defense to help protect the entire compliance process, as they can be used to double-check accounts that have passed onboarding checks. These checks also allow the auditing team to hone their strategy and tactics, test assumptions and otherwise optimize compliance procedures.

The digital audit trail is a cornerstone of creating a resilient, standardized, testable compliance program. Rising above the inconsistencies of individual people running and being responsible for account compliance, a systematic compliance program helps protect the company, besides being scalable and adaptable.

Ongoing CDD

The key to effective, ongoing CDD is to have set policies and processes for various contingencies. Anticipating scenarios helps to clarify which approaches are best and speeds up responses.

For forward-looking organizations, compliance is a competitive advantage, not just a regulatory checkbox exercise. Effective ongoing compliance lessens risk, increases knowledge of customers and enables adaptable systems. Establishing values and procedures that promote constant vigilance and respect for regulatory obligations helps create a transparent organization with solid governance.

This post was originally published on February 22, 2018. It has been updated to reflect the latest industry developments and best practices.

Customer Due Diligence Checklist — 5 Steps to Improve CDD (2)

Compliance

Build Trust and Safety with Digital KYC

Meet global Know Your Customer requirements without burdening customers

Get the KYC White Paper

Customer Due Diligence Checklist — 5 Steps to Improve CDD (2024)

FAQs

Customer Due Diligence Checklist — 5 Steps to Improve CDD? ›

Customer Due Diligence (CDD) checks are systematic procedures employed by businesses, particularly in the financial sector, to confirm the identity, background, and risk profile of customers.

What is a CDD checklist? ›

Customer Due Diligence (CDD) checks are systematic procedures employed by businesses, particularly in the financial sector, to confirm the identity, background, and risk profile of customers.

What are the 5 stages of KYC? ›

The five stages of KYC – customer identification, customer due diligence, risk assessment, ongoing monitoring, and reporting suspicious activities – are essential to ensure compliance with regulatory requirements.

What is the CDD customer due diligence rule? ›

The CDD Rule has four core requirements. It requires covered financial institutions to establish and maintain written policies and procedures that are reasonably designed to: identify and verify the identity of customers. identify and verify the identity of the beneficial owners of companies opening accounts.

What is the basic requirement of CDD? ›

There are four components or requirements of CDD, which include: Customer identification and verification. Understanding the nature and purpose of the business-customer relationship. Beneficial ownership identification and verification.

How is CDD checked? ›

CDD consists of performing background checks, and screening potential and existing customers to ensure they're not involved in illegal activity. At a minimum, CDD checks include verifying a customer's name, address, date of birth and photo ID and screening them to ensure they're not on prohibited lists.

What is the 5th pillar of the CDD rule? ›

PILLAR #5

The CDD Rule has four main requirements. It requires financial institutions to establish and maintain written policies and procedures that are designed to: Identify and verify the identity of customers. Identify and verify the identity of the beneficial owners of companies opening accounts.

What is CDD strategy? ›

CDD involves analysing a wide range of commercially significant factors, including the target company's historic performance, benchmarking against peers and competitors, market share, customer and supplier relationships, competitive landscape, market conditions, and the long-term viability of the management strategy.

What best describes the CDD process? ›

In the world of Financial Crime Compliance (FCC), customer due diligence (CDD) is an important and complex field. Customer due diligence is the processes used by financial institutions to collect and evaluate relevant information about a customer or potential customer.

What is the first step of CDD? ›

Step 1: Verify Customer at Time of Onboarding

At this stage, the financial institution will collect customer identification documentation such as their name, address, and the purpose of the business relationship.

What are enhanced CDD measures? ›

Enhanced CDD measures must be applied where a firm's assessment is that there is a higher risk of money laundering or the financing of terrorism (i.e. a situation which by its nature can present a higher risk of money laundering or the financing of terrorism).

What is a KYC checklist? ›

Know Your Customer (KYC) compliance is a set of procedures and protocols implemented by businesses and financial institutions to verify and authenticate the identity of their clients. The objective is to prevent illicit activities such as money laundering, fraud, and financing illegal activity.

What are the 4 stages of customer due diligence? ›

The key stages of CDD are customer identification, risk assessment, and customer verification. Firms must document their CDD and be able to show regulators that appropriate processes were followed. Failure to perform proper CDD can lead to facilitating money laundering and reputational and regulatory issues for firms.

What is the CDD review process? ›

This process usually involves checking government-issued identity documents and verifying the provided information using methods such as biometric authentication and passive liveness detection. The purpose is to ensure that the customer is indeed who they claim to be.

What is simplified customer due diligence CDD? ›

Simplified due diligence is the lowest level of due diligence that can be completed on a customer. This is considered appropriate where there is little opportunity or risk of your services or customer becoming involved in money laundering or terrorist financing.

What is the 5th pillar customer due diligence? ›

Pillar #5: implement customer due diligence

Generally, the CDD rule has four main components: Proper verification of each customer's identity and risk level. Identifying the true owners of legal entities (namely, to detect shell corporations) Understanding the nature of customer relationships and how they affect risk.

What is the due diligence of a client? ›

Customer due diligence (CDD) is a series of checks to help you verify your customers' identities and assess their risk profiles. CDD is a regulatory requirement for companies entering into business relationships with a customer and is a big part of anti-money laundering (AML) and know your customer (KYC) directives.

What are the 4 pillars of customer due diligence? ›

Key customer due diligence requirements include customer identification and verification, beneficial ownership identification, defining the purpose of business-customer relationships, and conducting ongoing monitoring.

Top Articles
Latest Posts
Article information

Author: Barbera Armstrong

Last Updated:

Views: 6335

Rating: 4.9 / 5 (79 voted)

Reviews: 94% of readers found this page helpful

Author information

Name: Barbera Armstrong

Birthday: 1992-09-12

Address: Suite 993 99852 Daugherty Causeway, Ritchiehaven, VT 49630

Phone: +5026838435397

Job: National Engineer

Hobby: Listening to music, Board games, Photography, Ice skating, LARPing, Kite flying, Rugby

Introduction: My name is Barbera Armstrong, I am a lovely, delightful, cooperative, funny, enchanting, vivacious, tender person who loves writing and wants to share my knowledge and understanding with you.