Your examiners won't ask if you perform Customer Due Diligence (CDD). They'll ask to see your written policy and compare it to your actual practices. If you can't produce a structured CDD policy that aligns with the Bank Secrecy Act and USA PATRIOT Act requirements, you're starting the exam behind.
This template provides a CDD policy framework you can adapt to your institution's risk profile and customer base. It addresses the four core requirements FinCEN expects: customer identification, beneficial ownership verification, risk assessment, and ongoing monitoring.
Purpose of This Template
Use this template to document your institution's CDD program in a way that meets regulatory expectations and supports your operations. The template structures your policy around the CDD Rule's requirements for covered financial institutions, which mandate identifying and verifying beneficial owners of legal entity customers when opening accounts.
This isn't just a compliance checkbox. Your policy needs to explain how your team makes decisions: when to escalate a customer to enhanced due diligence, what triggers ongoing review, and how you document your risk rationale. Examiners look for evidence that your policy drives actual behavior.
Prerequisites
Before customizing this template, gather:
- Your institution's risk appetite statement (if you don't have one, draft risk tolerance thresholds)
- Current customer segmentation criteria (geography, product type, transaction volume)
- Existing identification and verification procedures your staff already follow
- List of data sources for beneficial ownership verification
- Names and roles of staff responsible for CDD decisions at each risk tier
You'll also need to identify sign-off authority. Your policy should specify who approves exceptions, who escalates to enhanced due diligence, and who authorizes account opening for higher-risk customers.
The Policy Template
CUSTOMER DUE DILIGENCE POLICY
1. PURPOSE AND SCOPE
This policy establishes [Institution Name]'s approach to Customer Due Diligence (CDD)
in compliance with the Bank Secrecy Act, USA PATRIOT Act, and FinCEN's CDD Rule.
It applies to all account openings and customer relationships across [list business lines].
2. DEFINITIONS
Customer Due Diligence: The process of verifying customer identity, determining
beneficial ownership, assessing customer risk, and conducting ongoing monitoring.
Beneficial Owner: An individual who owns 25% or more of a legal entity customer,
or who exercises significant control over the entity.
Legal Entity Customer: A corporation, limited liability company, partnership,
or other entity created by filing a document with a government authority.
Risk-Based Approach: Applying CDD measures proportionate to the money laundering
or terrorist financing risk presented by the customer relationship.
3. CUSTOMER IDENTIFICATION PROCEDURES
At account opening, we collect and verify:
- Full legal name
- Date of birth (for individuals) or incorporation date (for entities)
- Physical address (not P.O. Box)
- Identification number (SSN, EIN, passport number, or government-issued ID)
Verification methods:
- Documentary verification: [specify accepted documents]
- Non-documentary verification: [specify database checks, third-party services]
- Retention: Copies of identification documents retained for [X] years after
account closure
4. BENEFICIAL OWNERSHIP REQUIREMENTS
For legal entity customers, we identify and verify:
- Each individual who owns 25% or more of the entity
- One individual with significant control (if no individual meets the 25% threshold)
Collection method:
- FinCEN Beneficial Ownership Certification Form or equivalent
- Supporting documentation: [specify: operating agreements, shareholder registers,
formation documents]
Verification standard:
- Name and date of birth verified through [specify method]
- Ownership percentages documented and retained
5. RISK ASSESSMENT FRAMEWORK
We assign each customer to a risk category using these factors:
Customer type:
- Individual consumer: [Low/Medium/High criteria]
- Small business: [Low/Medium/High criteria]
- Legal entity: [Low/Medium/High criteria]
Geographic risk:
- Low: [define jurisdictions]
- Medium: [define jurisdictions]
- High: [define FATF high-risk jurisdictions, sanctioned countries]
Product/service risk:
- Low: [list products]
- Medium: [list products]
- High: [list products, such as international wire transfers, cash-intensive services]
Transaction patterns:
- Expected volume thresholds by customer type
- Velocity triggers for review
Overall risk rating: [Document how you combine factors into Low/Medium/High rating]
6. RISK-BASED CONTROLS
Low Risk:
- Standard identification and verification
- Annual review of account activity
- [Transaction monitoring](/glossary/transaction-monitoring): [specify thresholds]
Medium Risk:
- Enhanced identification procedures: [specify additional steps]
- Semi-annual account review
- Lower transaction monitoring thresholds: [specify]
- Managerial approval required for account opening
High Risk:
- Enhanced Due Diligence required (see Section 7)
- Quarterly account review
- Senior management approval for account opening and ongoing relationship
- Continuous transaction monitoring
- Source of funds verification
7. ENHANCED DUE DILIGENCE (EDD)
Triggers for EDD:
- Customer or beneficial owner is a [Politically Exposed Person](/glossary/politically-exposed-person) (PEP)
- Customer operates in or transacts with high-risk jurisdiction
- Customer profile matches [specify red flags]
- Unusual transaction patterns detected
Additional EDD measures:
- Obtain information on source of wealth and source of funds
- Conduct adverse media screening
- Obtain senior management approval
- Increase monitoring frequency
- Document rationale for continuing relationship
8. ONGOING MONITORING
Frequency by risk tier:
- Low: Annual
- Medium: Semi-annual
- High: Quarterly
Monitoring includes:
- Transaction pattern analysis against expected activity
- [Watchlist screening](/glossary/watchlist-screening) (updated upon list changes)
- Beneficial ownership verification (confirm no changes)
- Risk rating reassessment
Triggers for immediate review:
- [List transaction types, amounts, or patterns requiring immediate escalation]
- Adverse media hits
- Geographic risk changes
- Ownership structure changes
9. RECORDKEEPING
Retain for [5] years after account closure:
- Customer identification documents
- Beneficial ownership certifications
- Risk assessment documentation
- Account review records
- [Suspicious Activity Report](/glossary/suspicious-activity-report) (SAR) decision documentation
10. ROLES AND RESPONSIBILITIES
Account Opening Staff: Collect and verify customer information, complete initial
risk assessment, escalate medium and high-risk customers
[Title]: Approve medium-risk account openings, conduct ongoing reviews for
assigned portfolio
[Title]: Approve high-risk account openings and EDD determinations, review
escalations, approve exceptions
BSA/AML Officer: Oversee CDD program, review policy annually, coordinate examinations
11. TRAINING
All staff involved in account opening complete CDD training:
- Upon hire
- Annually thereafter
- When policy changes
Training covers: identification requirements, beneficial ownership procedures,
risk assessment factors, escalation protocols
12. POLICY REVIEW
This policy is reviewed annually and updated as needed to reflect:
- Regulatory changes
- Institutional risk profile changes
- Examination findings
- Operational lessons learned
Last Review Date: [Date]
Next Review Date: [Date]
Approved By: [Name, Title]
How to Customize It
Start with Section 5 (Risk Assessment Framework). Your risk factors must reflect your actual customer base. If you don't serve international customers, remove geographic risk or simplify it. If you operate only in one state with consumer deposit accounts, your risk tiers will look different than a commercial bank with trade finance services.
In Section 6 (Risk-Based Controls), align your thresholds with your transaction monitoring system's capabilities. Don't document a $5,000 wire transfer review threshold if your system alerts at $10,000. Your policy should describe what you do, not what you wish you could do.
For Section 7 (Enhanced Due Diligence), define your PEP screening process specifically. Do you screen beneficial owners? At what ownership threshold? Which PEP lists do you use? Your examiners will test whether your actual screening matches your documented approach.
Replace bracketed placeholders with your institution's specific criteria, titles, and thresholds. The retention period in Section 9 should match your overall BSA recordkeeping policy (typically five years after account closure, but verify your jurisdiction's requirements).
Validation Steps
Before you finalize this policy:
Map it to your procedures. For every "we will" statement in the policy, you should have a corresponding desk-level procedure that tells staff exactly how to execute it. If your policy says you verify beneficial ownership but you don't have a step-by-step procedure for your account opening team, you have a gap.
Test against recent account openings. Pull your last 20 account files. Can you find documented evidence of each policy requirement? If Section 5 requires a risk rating but half your files don't show one, either your policy is aspirational or your staff isn't following it.
Cross-reference your training materials. Your CDD training should teach staff to execute this policy. If your training mentions procedures that aren't in your policy, or your policy requires steps your training doesn't cover, you'll confuse your team and fail the exam consistency test.
Review with your BSA Officer and legal counsel. Your BSA Officer should confirm the policy aligns with your risk assessment and monitoring systems. Legal counsel should verify it meets the CDD Rule requirements for your institution type.
Conduct a tabletop exercise. Walk through three scenarios with your account opening team: a low-risk consumer, a medium-risk small business, and a high-risk legal entity with a complex ownership structure. If your team can't consistently apply the policy to these scenarios, revise the ambiguous sections before you deploy it.
Your CDD policy isn't static. Plan to update it after every exam, when you add new products, and when you expand to new customer segments or geographies. The Monetary Authority of Singapore's guidelines emphasize that CDD measures should match the money laundering or terrorism financing risks associated with each customer. That means your policy needs to evolve as your risk profile changes.
When your examiners ask to see your CDD policy, hand them a document that describes your actual operation. That's the policy that protects your institution.


