L-01 · Foundations

KYC, CDD and reading the red flags

How financial institutions and Designated Non-Financial Businesses and Professions (DNFBPs) are meant to identify their customers and detect suspicious behaviour, and where the process fails.

Module lecturer: Dr. Collen Lediga, Ruhr-Universität Bochum

Module progress
0 / 2 lessons55 min remaining

Visual overview

Interactive figure

Placement · Layering · Integration

The three-stage laundering cycle

Click any node · hover for tooltip

PlacementCash → systemLayeringMove · disguiseIntegrationClean re-entryClick each stage · red flags · example

Lessons

LESSON 0130 min read

Customer Due Diligence: the four elements

Figure 1.1 · Global flows

Where illicit money leaves — and where it lands

Estimated annual illicit financial outflows, in USD billions. OECD economies absorb more than the six largest source regions combined.

$0bn$55bn$110bn$165bn$220bnOECD (net inflow)$210 bnSub-Saharan Africa$88 bnLatin America$76 bnSouth-East Asia$62 bnMENA$54 bnEastern Europe$41 bnDestination markets absorb the outflows

Source · Composite of GFI (2020) and UNCTAD (2020) illustrative ranges

When I sit with bank compliance teams, the complaint is always the same: CDD has become a document-collection ritual. That is a failure of implementation rather than of the standard, and the difference matters when you are assessing whether an institution's file was adequate. Customer Due Diligence (CDD) is the operational core of every AML programme. It is the point at which the abstract obligation "know your customer" becomes a set of concrete tasks performed by a bank-account officer, a notary, a real-estate agent, a crypto exchange, or an accountant onboarding a new client. FATF Recommendation 10 sets out four elements which are then transposed, with minor variations, into national law across the FATF and FSRB memberships.

1. IDENTIFY THE CUSTOMER AND VERIFY IDENTITY from reliable, independent source documents, data or information. For a natural person this typically means a government-issued photographic identity document (passport, national ID card, driving licence) plus a proof of address (utility bill, tax notice, bank statement). Verification means checking that the document is authentic (chip-read, hologram inspection, database look-up) and that the person presenting it is its holder (increasingly done through liveness-detected selfies matched to the document photo). For a legal person, this means constitutional documents, evidence of incorporation and current status, registered address and business address, list of directors and senior officers, and identification of persons authorised to give instructions on the account.

2. IDENTIFY THE BENEFICIAL OWNERBeneficial OwnerThe natural person who ultimately owns or controls a customer or an asset (typically defined as ≥25% ownership or effective control). — the natural person(s) who ultimately owns or controls the customer, or on whose behalf a transaction is being conducted. FATF and virtually all national regimes set a rebuttable presumption at ≥25% direct or indirect ownership, or effective control by other means (voting rights, veto rights, protector rights over a trust, senior-management position where no equity owner is identified). BO identification must, wherever possible, be verified from independent sources — corporate registries, beneficial-ownership registers, court records, sworn declarations tested against third-party evidence, and not accepted purely on the client's own attestation. Where the ownership chain is layered across jurisdictions, BO identification requires the institution to look through each layer to the ultimate natural person(s), which in practice depends on cross-border information rights and, increasingly, on the emerging BO-register interconnection framework (in the EU) or on bilateral requests via FIU or tax channels.

3. UNDERSTAND THE INTENDED NATURE AND PURPOSE OF THE BUSINESS RELATIONSHIP. This is the qualitative pillar and, in practice, the most frequently short-cut. The account officer must understand the customer's business or personal circumstances to a level sufficient to construct a "customer profile" against which subsequent transactions can be judged normal or anomalous. That means source of funds (where does the money come from?), source of wealth (how did the customer accumulate their asset base?), expected transaction volumes and geographies, expected counterparties, and the underlying commercial rationale for the products chosen. A high-net-worth private-banking onboarding may generate a 30-page relationship memorandum; a retail current account may generate a five-line profile. Both must be internally consistent and testable.

4. CONDUCT ONGOING DUE DILIGENCE. Scrutinise transactions throughout the course of the relationship to ensure they are consistent with the institution's knowledge of the customer, their business and risk profile, and the intended nature of the relationship. Ongoing due diligence includes periodic refresh of KYC data (annually for high risk, every 3–5 years for standard risk), event-triggered review (unusual transaction, adverse media hit, change of beneficial ownerBeneficial OwnerThe natural person who ultimately owns or controls a customer or an asset (typically defined as ≥25% ownership or effective control)., sanctions listing, change of jurisdiction), and; the technical spine of modern AML, transaction monitoring, in which rule-based and increasingly machine-learning models score transactions against expected behaviour and generate alerts.

The regime is RISK-BASED. FATF's Recommendation 1 requires countries and institutions to identify, assess and understand their money-laundering and terrorist-financing risks, and to take mitigating action proportionate to those risks. This produces three intensities of CDD:

SIMPLIFIED CDD applies to demonstrably low-risk relationships. Typical examples include listed public companies subject to disclosure requirements, financial institutions supervised for AML, public-sector bodies, low-value or low-functionality products, and (in some regimes) small-balance basic accounts intended for financial inclusion. Simplified CDD is not "no CDD" — the four elements still apply, but the depth and evidentiary threshold is proportionately reduced.

STANDARD CDD is the default.

ENHANCED DUE DILIGENCE (EDDEDDEnhanced Due Diligence — heightened checks for higher-risk customers.) is mandatory for higher-risk categories: politically exposed persons (PEPs) — both foreign and, since the 2012 revision, domestic, their family members and close associates; correspondent banking relationships with respondent banks in higher-risk jurisdictions; customers from countries identified by FATF or the domestic regime as higher risk; complex or unusual ownership structures without an evident commercial or lawful purpose; certain products including private banking, correspondent banking, wealth-management vehicles, and (post-AMLD5) virtual-asset service providers, and situations flagged by the institution's own risk-scoring model.

EDDEDDEnhanced Due Diligence — heightened checks for higher-risk customers. requires additional information at onboarding (source of wealth and source of funds tested against independent evidence, senior-management approval to open the account, and enhanced ongoing monitoring), and periodic refresh at a heightened frequency. The FATF Guidance on PEPs (2013) sets out the classic EDDEDDEnhanced Due Diligence — heightened checks for higher-risk customers. architecture used worldwide.

WHERE CDD FAILS, IT TYPICALLY FAILS AT ELEMENT 2 (BENEFICIAL OWNERSHIP) OR ELEMENT 4 (ONGOING MONITORING). Element 2 fails because opaque foreign structures; nominee directors, trusts, foundations, bearer arrangements, cascaded holding companies across secrecy jurisdictions, defeat the institution's ability to look through, and the institution accepts a client-provided declaration in place of independent evidence. Element 4 fails because monitoring is rule-based and complex layering evades static rules, or because alert queues are so large that individual alerts are cleared perfunctorily. Both failure modes have been repeatedly documented in enforcement actions: the FinCEN Files (2020) showed alerts generated but transactions cleared; the Danske Bank Estonia matter (2018) exposed a monitoring architecture unable to see €200bn of non-resident throughput; the Wirecard matter (2020) exposed a payments group whose acquiring flows were understood by no one internally.

A well-designed CDD programme therefore does five things: it distinguishes risk tiers; it evidences BO with independent sources whenever the structure is cross-border; it captures source-of-funds and source-of-wealth substantively at onboarding; it feeds structured, machine-readable profile data into the monitoring engine so that alerts fire against expected — not just absolute — thresholds, and it forces senior-management sign-off, with an evidentiary record, at every EDDEDDEnhanced Due Diligence — heightened checks for higher-risk customers. escalation. Programmes that do these five things at scale are rare, expensive, and, when regulators inspect them; the difference between a clean supervisory report and a nine-figure penalty.

Enumerated setVERITAS · Dr. Lediga
1
Identify + verify the customer
Government ID, proof of address, liveness-matched; for legal persons: constitutional docs, directors, authorised signatories.
2
Identify the beneficial owner
Look through to the natural person at ≥25% ownership OR effective control. Independent sources, not client attestation.
3
Understand purpose + nature
Source of funds, source of wealth, expected volumes, geographies, counterparties, commercial rationale.
4
Ongoing due diligence
Transaction monitoring, periodic refresh, event-triggered review, adverse-media screening.

The four elements of CDD under FATF Recommendation 10.

The operational core of every AML programme.

Key terms

PEP
Politically Exposed Person, an individual entrusted with prominent public functions, and their close associates and family.
EDD
Enhanced Due Diligence — heightened checks for higher-risk customers.
Beneficial Owner
The natural person who ultimately owns or controls a customer or an asset (typically defined as ≥25% ownership or effective control).

Exercise

Draft an EDD questionnaire (10 items maximum) tailored to onboarding a foreign PEP as a private-banking client.

Mark complete (sign-in) →

Sources

Last reviewed 2026-08-01

  1. 01FATF Recommendations 10, 11, 12 and 22 with Interpretive NotesFATF, 2025.CDD, record-keeping, PEPs and DNFBP scope.
  2. 02Regulation (EU) 2024/1624 (AMLR), obliged-entity scope and CDD chapterEuropean Union, 2024.
  3. 03Wolfsberg Group CBDDQ v1.5Wolfsberg Group, 2024.
Full bibliography →
LESSON 0225 min read

Red flags: the FATF and Egmont typologies

Figure 2.2 · Signal

Six axes of a suspicious transaction

Normalised red-flag intensity across the six compliance dimensions. The shaded polygon reveals a classic cash-and-geography profile.

0.250.500.751.00Cash intensity0.90Structuring0.70Geography0.85PEP linkage0.60Velocity0.78Documentation0.48

Source · Illustrative composite; scale 0 (nil) → 1 (severe)

The single most common mistake I see in trainee reports is treating one flag as a finding. Flags are priors. They tell you where to spend the next four hours. A red flag is not proof of laundering — it is a probability signal that, in combination with other flags, elevates the case above the ordinary noise of banking activity and requires investigation. The FATF and the Egmont GroupEgmont GroupGlobal body of Financial Intelligence Units facilitating cross-border information exchange. of Financial Intelligence Units publish periodic typologies studies that catalogue red flags by sector, product and predicate offence; national FIUs publish jurisdiction-specific supplements, and the Wolfsberg Group's guidance provides the private-banking industry perspective. A competent analyst treats these catalogues as living documents and updates their mental library as new typologies emerge (ransomware payments, deepfake-enabled CEO fraud, DeFi mixing, sanctions-evasion via commodity trade with third-country reinvoicing).

Red flags fall into three broad families.

TRANSACTIONAL RED FLAGS are anomalies visible in the pattern of movements through an account or product. The canonical list includes: transactions with no apparent economic or lawful purpose; repeated cash deposits just below the mandatory reporting threshold ("structuring" or "smurfing"); wire transfers to or from higher-risk jurisdictions where the customer has no evident connection; rapid movement of funds through an account with negligible ending balance ("pass-through" behaviour); receipt of a large lump-sum from an unrelated third party immediately followed by outward disbursement; sudden change in account behaviour without explanation (a dormant account that abruptly becomes active, or a low-activity account that suddenly transacts at multiples of prior volume); unusually complex ownership or transaction structures relative to the business's turnover or the customer's declared profile; use of intermediaries such as lawyers, accountants, or corporate service providers where direct dealing would be simpler and cheaper; multiple accounts held with the same institution and internal transfers between them that lack commercial logic; frequent use of round-figure amounts, and the receipt of funds from cryptocurrency exchanges immediately followed by conversion into a fiat asset with no evident source-of-wealth support.

BEHAVIOURAL RED FLAGS are signals from the customer's conduct rather than the transaction. These include: reluctance to provide standard identification or supporting documentation; hostility to routine due-diligence questions; the customer's demonstrated ignorance of, or evasion about, the source of funds; instructing counsel to communicate exclusively on the client's behalf without operational reason (legal privilege used defensively rather than in litigation); insistence on transacting in cash where non-cash alternatives are cheaper; requesting that documentation be issued in a name or entity other than the one funding the transaction; providing addresses that turn out to be service-of-process addresses of corporate service providers, and demanding accelerated onboarding without accepting standard timelines.

STRUCTURAL RED FLAGS are signals from the shape of the relationship or the entity involved: nominee directors on an entity whose real business is unclear; ultimate beneficial owners resident in jurisdictions with weak transparency; trust protectors whose identity is withheld; a corporate group with more legal entities than employees; a customer registered at the address of a corporate service provider and shared with dozens of unrelated entities; or a professional intermediary whose portfolio shows a disproportionate concentration of high-risk clients.

The critical analytical skill is COMBINATORIAL REASONING. A single red flag rarely justifies a filing; the concurrence of three or four across the transactional, behavioural and structural families almost always does. A pass-through pattern alone is uninformative; a pass-through pattern combined with unknown UBO, high-risk-jurisdiction counterparties and reluctance to answer source-of-funds questions is a filing. Investigators develop this skill by working portfolios of known typologies and reverse-engineering the flag combinations that would have identified them earlier. Modern transaction-monitoring systems partially automate the combinatorial step through composite alerts (scenario-based rules that fire only when multiple sub-conditions co-occur within a defined window), but the analyst's judgement remains decisive because false-positive rates on single-rule systems routinely exceed 95%.

RED FLAGS BY SECTOR

Different obliged entities see different signals. A retail bank sees teller behaviour and account patterns. A private bank sees discretionary-mandate divergence from the client profile and unusual capital-injection events. A correspondent bank sees respondent-bank throughput anomalies and country-of-payment surprises. A notary sees suspiciously round-number property prices, purchases immediately followed by re-mortgaging or resale, and buyers whose identity is presented through complex intermediary structures. A dealer in high-value goods (yachts, aircraft, jewellery, art) sees cash-adjacent payment (bank drafts, escrow releases, layered transfers). A crypto exchange sees deposit-then-immediate-withdrawal patterns to unhosted wallets, use of mixers, chain-hopping, and inconsistencies between declared and observed geolocation. A tax administration sees under-declared assets appearing in CRS returns, corporate structures inconsistent with the declared business, and transfer-pricing outcomes that consistently allocate profit to low-tax jurisdictions.

RED FLAGS BY PREDICATE

Different predicate offences leave different fingerprints. Drug proceeds present as high-volume small-cash placement, often in border regions or ports, followed by rapid layering. Corruption proceeds present as low-frequency, high-value payments from state-owned or state-connected counterparties to intermediary companies whose UBOs are traceable, on investigation, to public officials or their close associates. Trade-based laundering presents as invoice pricing outside the fair-market band, HS-code mismatches between origin and destination, and payments routed through third-country escrow. Tax evasion presents as under-reported income relative to observed lifestyle, undeclared foreign accounts, and use of nominee structures to hold assets. Terrorist financing presents differently from all of the above: often small amounts, mixed with genuine legitimate flows, moved via money-remittance operators and hawala, aimed at operational readiness rather than personal enrichment.

DOCUMENTATION DISCIPLINE

Every red-flag analysis must be documented contemporaneously with the reasoning that connected the flags. A well-drafted internal alert record answers four questions: (i) what did we observe? (ii) how does it deviate from the expected profile? (iii) what alternative innocent explanations did we consider and reject? (iv) what is the recommended action (clear, escalate, file STR/SAR, exit relationship)? This documentation record is what the supervisor inspects, what a subsequent prosecutor may rely on, and what the institution's own auditors test. A programme that generates alerts without disciplined dispositions is worse than a programme that generates no alerts at all, it creates the impression of monitoring without its substance, which is a specific supervisory failure repeatedly cited in enforcement actions.

FROM ALERT TO STR

The STR (Suspicious Transaction Report) or SAR (Suspicious Activity Report) is the FIU-facing product of red-flag analysis. It should be timely, specific, and evidenced. National regimes differ on the trigger (suspicion, knowledge, reasonable grounds), the timeframe, and the safe-harbour protection for the reporter. The reporting duty is disapplied only in narrow cases and, notably, is NOT displaced by legal professional privilege where the lawyer is engaged in transactional (not litigation) work in most FATF-member jurisdictions. Filing an STR does not require the reporter to prove laundering; it requires only articulable suspicion, documented as above.

Four-part typologyVERITAS · Dr. Lediga
1CATEGORY 01Transactional
Structuring, pass-through, no economic purpose, high-risk-jurisdiction counterparties, unusual complexity.
2CATEGORY 02Behavioural
Evasion of CDD questions, cash preference, defensive use of counsel, accelerated-onboarding demands.
3CATEGORY 03Structural
Nominee directors, CSP-only address, UBO in secrecy jurisdiction, more entities than employees.
4CATEGORY 04Sectoral
Notary: round-number property + fast re-mortgage. Crypto: deposit-then-withdraw to unhosted wallet, mixers, chain-hop.

Red-flag families; pattern, conduct, structure, sector.

Combinatorial reasoning across families is the decisive analytical skill.

Key terms

Egmont Group
Global body of Financial Intelligence Units facilitating cross-border information exchange.
Pass-through account
Account whose sole function is to receive and immediately forward funds, holding no meaningful balance.

Exercise

Given a fictional statement showing 15 deposits over 3 months, all between USD 9,200 and USD 9,850, followed by a single outgoing wire to a shell in the BVI, list five distinct red flags and rank them by severity.

Mark complete (sign-in) →

Sources

Last reviewed 2026-08-01

  1. 01FATF, Money Laundering and Terrorist Financing Typologies reportsFATF, 2024.
  2. 02Egmont Group, Principles for Information Exchange Between FIUsEgmont Group of FIUs, 2013.Use limits on FIU-sourced material.
  3. 03Financial Intelligence Centre Act 38 of 2001 (South Africa), as amended 2022Republic of South Africa, 2022.
Full bibliography →

Case study

The lawyer's client account

Jurisdiction: Common-law jurisdiction, based on public FATF typology

A solicitor's pooled client account receives USD 4.1 million from a client described only as 'a family trust based in Liechtenstein'. Funds are used to buy three residential properties over four months. No CDD file exists for the beneficial owner.

Facts

  • The solicitor is a sole practitioner in a mid-sized city.
  • The trust's protector is a Cayman-based company; the trustee is a Liechtenstein fiduciary.
  • Two of the three properties are re-mortgaged within six months of purchase; net cash back to the trust is USD 2.3 million.

Investigative questions

  1. Which FATF Recommendation and which DNFBP obligations are engaged?
  2. What EDD steps should the solicitor have performed at instruction?
  3. How would you approach a mutual legal assistance request to Liechtenstein for the trust documentation?

Learning points

  • Legal professionals sit at the top of the AML risk hierarchy for real-estate transactions.
  • Chain re-mortgaging is a textbook integration technique.
  • Trust structures across two jurisdictions defeat single-jurisdiction beneficial-ownership registries.

Where the field disagrees

Does customer due diligence catch anyone?

There is a persistent finding, most sharply put by Peter Reuter and Ronald Pol, that the compliance industry costs more than the criminal proceeds it interdicts and that conviction rates are a rounding error. The counter-argument from FIUs is that CDD produces the intelligence base without which nothing else works, and that convictions are the wrong metric. Both sides are arguing from thin data. Form a view before an interview panel forces you to.

Lecturer's note · not examinable, but argue it in your essay

Assessment

Module quiz

10 multiple-choice questions. Pass at 70%. Scores are saved to your dashboard.

Begin quiz →

Written work

Essay prompts

  • Q1Discuss the strengths and weaknesses of the risk-based approach to AML compliance as compared with a rules-based approach.
  • Q2Assess the role of legal professional privilege as an obstacle to effective AML supervision of lawyers.
Submit essay →

Assignment

"Design a one-page CDD triage checklist your bank branch could use during onboarding of small-business customers. Justify every field."