Customer Due Diligence: the four elements
Figure 1.1 · Global flows
Where illicit money leaves — and where it lands
Estimated annual illicit financial outflows, in USD billions. OECD economies absorb more than the six largest source regions combined.
Source · Composite of GFI (2020) and UNCTAD (2020) illustrative ranges
When I sit with bank compliance teams, the complaint is always the same: CDD has become a document-collection ritual. That is a failure of implementation rather than of the standard, and the difference matters when you are assessing whether an institution's file was adequate. Customer Due Diligence (CDD) is the operational core of every AML programme. It is the point at which the abstract obligation "know your customer" becomes a set of concrete tasks performed by a bank-account officer, a notary, a real-estate agent, a crypto exchange, or an accountant onboarding a new client. FATF Recommendation 10 sets out four elements which are then transposed, with minor variations, into national law across the FATF and FSRB memberships.
1. IDENTIFY THE CUSTOMER AND VERIFY IDENTITY from reliable, independent source documents, data or information. For a natural person this typically means a government-issued photographic identity document (passport, national ID card, driving licence) plus a proof of address (utility bill, tax notice, bank statement). Verification means checking that the document is authentic (chip-read, hologram inspection, database look-up) and that the person presenting it is its holder (increasingly done through liveness-detected selfies matched to the document photo). For a legal person, this means constitutional documents, evidence of incorporation and current status, registered address and business address, list of directors and senior officers, and identification of persons authorised to give instructions on the account.
2. IDENTIFY THE BENEFICIAL OWNERBeneficial OwnerThe natural person who ultimately owns or controls a customer or an asset (typically defined as ≥25% ownership or effective control). — the natural person(s) who ultimately owns or controls the customer, or on whose behalf a transaction is being conducted. FATF and virtually all national regimes set a rebuttable presumption at ≥25% direct or indirect ownership, or effective control by other means (voting rights, veto rights, protector rights over a trust, senior-management position where no equity owner is identified). BO identification must, wherever possible, be verified from independent sources — corporate registries, beneficial-ownership registers, court records, sworn declarations tested against third-party evidence, and not accepted purely on the client's own attestation. Where the ownership chain is layered across jurisdictions, BO identification requires the institution to look through each layer to the ultimate natural person(s), which in practice depends on cross-border information rights and, increasingly, on the emerging BO-register interconnection framework (in the EU) or on bilateral requests via FIU or tax channels.
3. UNDERSTAND THE INTENDED NATURE AND PURPOSE OF THE BUSINESS RELATIONSHIP. This is the qualitative pillar and, in practice, the most frequently short-cut. The account officer must understand the customer's business or personal circumstances to a level sufficient to construct a "customer profile" against which subsequent transactions can be judged normal or anomalous. That means source of funds (where does the money come from?), source of wealth (how did the customer accumulate their asset base?), expected transaction volumes and geographies, expected counterparties, and the underlying commercial rationale for the products chosen. A high-net-worth private-banking onboarding may generate a 30-page relationship memorandum; a retail current account may generate a five-line profile. Both must be internally consistent and testable.
4. CONDUCT ONGOING DUE DILIGENCE. Scrutinise transactions throughout the course of the relationship to ensure they are consistent with the institution's knowledge of the customer, their business and risk profile, and the intended nature of the relationship. Ongoing due diligence includes periodic refresh of KYC data (annually for high risk, every 3–5 years for standard risk), event-triggered review (unusual transaction, adverse media hit, change of beneficial ownerBeneficial OwnerThe natural person who ultimately owns or controls a customer or an asset (typically defined as ≥25% ownership or effective control)., sanctions listing, change of jurisdiction), and; the technical spine of modern AML, transaction monitoring, in which rule-based and increasingly machine-learning models score transactions against expected behaviour and generate alerts.
The regime is RISK-BASED. FATF's Recommendation 1 requires countries and institutions to identify, assess and understand their money-laundering and terrorist-financing risks, and to take mitigating action proportionate to those risks. This produces three intensities of CDD:
SIMPLIFIED CDD applies to demonstrably low-risk relationships. Typical examples include listed public companies subject to disclosure requirements, financial institutions supervised for AML, public-sector bodies, low-value or low-functionality products, and (in some regimes) small-balance basic accounts intended for financial inclusion. Simplified CDD is not "no CDD" — the four elements still apply, but the depth and evidentiary threshold is proportionately reduced.
STANDARD CDD is the default.
ENHANCED DUE DILIGENCE (EDDEDDEnhanced Due Diligence — heightened checks for higher-risk customers.) is mandatory for higher-risk categories: politically exposed persons (PEPs) — both foreign and, since the 2012 revision, domestic, their family members and close associates; correspondent banking relationships with respondent banks in higher-risk jurisdictions; customers from countries identified by FATF or the domestic regime as higher risk; complex or unusual ownership structures without an evident commercial or lawful purpose; certain products including private banking, correspondent banking, wealth-management vehicles, and (post-AMLD5) virtual-asset service providers, and situations flagged by the institution's own risk-scoring model.
EDDEDDEnhanced Due Diligence — heightened checks for higher-risk customers. requires additional information at onboarding (source of wealth and source of funds tested against independent evidence, senior-management approval to open the account, and enhanced ongoing monitoring), and periodic refresh at a heightened frequency. The FATF Guidance on PEPs (2013) sets out the classic EDDEDDEnhanced Due Diligence — heightened checks for higher-risk customers. architecture used worldwide.
WHERE CDD FAILS, IT TYPICALLY FAILS AT ELEMENT 2 (BENEFICIAL OWNERSHIP) OR ELEMENT 4 (ONGOING MONITORING). Element 2 fails because opaque foreign structures; nominee directors, trusts, foundations, bearer arrangements, cascaded holding companies across secrecy jurisdictions, defeat the institution's ability to look through, and the institution accepts a client-provided declaration in place of independent evidence. Element 4 fails because monitoring is rule-based and complex layering evades static rules, or because alert queues are so large that individual alerts are cleared perfunctorily. Both failure modes have been repeatedly documented in enforcement actions: the FinCEN Files (2020) showed alerts generated but transactions cleared; the Danske Bank Estonia matter (2018) exposed a monitoring architecture unable to see €200bn of non-resident throughput; the Wirecard matter (2020) exposed a payments group whose acquiring flows were understood by no one internally.
A well-designed CDD programme therefore does five things: it distinguishes risk tiers; it evidences BO with independent sources whenever the structure is cross-border; it captures source-of-funds and source-of-wealth substantively at onboarding; it feeds structured, machine-readable profile data into the monitoring engine so that alerts fire against expected — not just absolute — thresholds, and it forces senior-management sign-off, with an evidentiary record, at every EDDEDDEnhanced Due Diligence — heightened checks for higher-risk customers. escalation. Programmes that do these five things at scale are rare, expensive, and, when regulators inspect them; the difference between a clean supervisory report and a nine-figure penalty.
The four elements of CDD under FATF Recommendation 10.
The operational core of every AML programme.
Key terms
- PEP
- Politically Exposed Person, an individual entrusted with prominent public functions, and their close associates and family.
- EDD
- Enhanced Due Diligence — heightened checks for higher-risk customers.
- Beneficial Owner
- The natural person who ultimately owns or controls a customer or an asset (typically defined as ≥25% ownership or effective control).
Exercise
Draft an EDD questionnaire (10 items maximum) tailored to onboarding a foreign PEP as a private-banking client.
Mark complete (sign-in) →Sources
Last reviewed 2026-08-01
- 01FATF Recommendations 10, 11, 12 and 22 with Interpretive Notes — FATF, 2025.CDD, record-keeping, PEPs and DNFBP scope.
- 02Regulation (EU) 2024/1624 (AMLR), obliged-entity scope and CDD chapter — European Union, 2024.
- 03Wolfsberg Group CBDDQ v1.5 — Wolfsberg Group, 2024.