Customer Due Diligence
Customer Due Diligence (CDD) is the process a bank or business uses to verify who a customer is and to understand the risk of doing business with them. This is typically done by checking identity documents or data and by understanding the nature and purpose of the customer relationship. It also involves monitoring that risk over time rather than only at onboarding.
Customer Due Diligence (CDD) is a regulatory-mandated process by which a financial institution or obligated organization verifies a customer's identity, typically through documentation or data checks, and assesses the risk associated with that customer. Per FFIEC guidance, an objective of CDD is to enable the institution to understand the nature and purpose of customer relationships, and the process extends to ongoing monitoring of the assessed risk rather than a one-time check. CDD is a component of broader Know Your Customer (KYC) and anti-money-laundering obligations; specific requirements, thresholds, and applicable regulations vary by jurisdiction and should be confirmed against the governing regulatory framework.
Why it matters
Customer Due Diligence sits at the core of how obligated organizations manage financial crime risk. By verifying who a customer is and assessing the risk associated with them, CDD helps institutions decide whether and how to enter a relationship, and it establishes the baseline against which later activity can be judged. Per FFIEC guidance, an objective of CDD is to enable the institution to understand the nature and purpose of customer relationships, which supports downstream controls such as transaction monitoring and suspicious activity reporting. Without a sound CDD process, an institution has limited ability to distinguish expected customer behavior from anomalous activity that may warrant investigation.
Who it's relevant to
Inside CDD
Common questions
Answers to the questions practitioners most commonly ask about CDD.