Skip to main content
Category: AML and KYC

Customer Due Diligence

Also known as:
Simply put

Customer Due Diligence (CDD) is the process a bank or business uses to verify who a customer is and to understand the risk of doing business with them. This is typically done by checking identity documents or data and by understanding the nature and purpose of the customer relationship. It also involves monitoring that risk over time rather than only at onboarding.

Formal definition

Customer Due Diligence (CDD) is a regulatory-mandated process by which a financial institution or obligated organization verifies a customer's identity, typically through documentation or data checks, and assesses the risk associated with that customer. Per FFIEC guidance, an objective of CDD is to enable the institution to understand the nature and purpose of customer relationships, and the process extends to ongoing monitoring of the assessed risk rather than a one-time check. CDD is a component of broader Know Your Customer (KYC) and anti-money-laundering obligations; specific requirements, thresholds, and applicable regulations vary by jurisdiction and should be confirmed against the governing regulatory framework.

Why it matters

Customer Due Diligence sits at the core of how obligated organizations manage financial crime risk. By verifying who a customer is and assessing the risk associated with them, CDD helps institutions decide whether and how to enter a relationship, and it establishes the baseline against which later activity can be judged. Per FFIEC guidance, an objective of CDD is to enable the institution to understand the nature and purpose of customer relationships, which supports downstream controls such as transaction monitoring and suspicious activity reporting. Without a sound CDD process, an institution has limited ability to distinguish expected customer behavior from anomalous activity that may warrant investigation.

Who it's relevant to

Compliance and AML officers
Compliance and anti-money-laundering teams own the CDD process as part of broader KYC obligations. They design identity verification and risk-assessment procedures, calibrate them to the governing regulatory framework, and maintain the ongoing monitoring that keeps a customer's risk profile current. Because requirements and thresholds vary by jurisdiction, these teams must confirm specifics against the applicable regulations rather than assuming a single standard applies everywhere.
Onboarding and customer-facing operations
Teams responsible for opening accounts or establishing customer relationships carry out the identity checks and information gathering that CDD depends on. Their work — verifying identity through documentation or data checks and capturing the nature and purpose of the relationship — produces the baseline risk profile that later monitoring relies on.
Financial institutions and obligated organizations
Banks and other organizations subject to CDD requirements must build the process into how they enter and maintain customer relationships. CDD is regulatory-mandated, so these institutions carry responsibility for verifying customers, assessing associated risk, and monitoring that risk over time, in line with the framework that governs them.
Risk and monitoring analysts
Analysts responsible for ongoing monitoring use the risk profile established at onboarding as a reference point for assessing later activity. Because CDD involves monitoring assessed risk rather than a one-time check, these teams reassess customers when behavior or circumstances change and escalate for further review as appropriate under the governing framework.

Inside CDD

Customer Identification and Verification
The process of collecting and verifying identifying information about a customer, such as legal name, address, and identification documents, to establish who the customer is before or during onboarding.
Beneficial Ownership Identification
For business or legal-entity customers, identifying the natural persons who ultimately own or control the entity, so that the real parties behind an account are understood rather than only the entity name.
Purpose and Nature of the Relationship
Understanding the expected activity, transaction types, and reasons a customer establishes a relationship, which provides a baseline against which later activity can be compared.
Risk Assessment and Customer Risk Rating
Assigning a risk level to a customer based on factors such as geography, product usage, and entity type, which helps determine the depth of due diligence applied.
Ongoing Monitoring
Continued review of customer activity over the life of the relationship to detect activity inconsistent with the established profile and to keep customer information current.
Enhanced Due Diligence (EDD)
Additional scrutiny applied to higher-risk customers, which may include gathering more information, closer monitoring, or senior approval, as distinct from standard CDD applied to lower-risk relationships.

Common questions

Answers to the questions practitioners most commonly ask about CDD.

Is Customer Due Diligence a PCI DSS requirement?
No. Customer Due Diligence (CDD) is an anti-money-laundering and know-your-customer concept associated with financial regulatory regimes, not a control defined within PCI DSS. PCI DSS governs the protection of cardholder data and the security of the cardholder data environment; it does not define or mandate CDD. Payment organizations may need to perform CDD to satisfy separate legal and regulatory obligations, but those obligations sit outside the scope of PCI DSS and should be confirmed against the applicable laws, regulator guidance, and card brand rules that apply in your region.
Does performing CDD mean a merchant or account is free of fraud risk?
No. CDD is intended to help an organization understand who its customer is and assess associated risk; it does not eliminate fraud. It may help reduce certain risks, such as onboarding entities engaged in illicit activity, but it does not by itself detect or prevent transaction-level fraud, account takeover, synthetic identity fraud, or first-party (friendly) fraud. CDD is one input among many and carries its own limitations, including reliance on the accuracy and completeness of information provided at onboarding and over time.
At what points in the customer relationship should CDD be applied?
CDD is commonly applied at onboarding to establish and verify identity and assess risk, and then revisited on an ongoing basis, for example when risk indicators change, when there is unusual activity, or on a periodic schedule aligned to the assessed risk level. The specific triggers, frequency, and depth depend on the applicable regulatory framework and the organization's risk-based approach, which should be documented in internal policy and confirmed against current legal and regulator guidance.
How does a risk-based approach affect the depth of CDD applied?
A risk-based approach means the intensity of due diligence scales with assessed risk. Lower-risk relationships may warrant simplified measures where permitted, while higher-risk relationships may warrant enhanced due diligence with additional information gathering and closer ongoing monitoring. The criteria used to classify risk, and what measures are permitted at each level, are determined by the applicable regulatory regime and the organization's documented methodology rather than by any single fixed rule.
How does CDD relate to the data protection controls a payment organization already has in place?
CDD generates and relies on customer and identity information that must itself be protected under applicable data protection and privacy obligations. Where any of that information overlaps with cardholder data, the relevant PCI DSS controls apply to that data as defined by scope and validation. However, CDD records generally consist of identity and business information rather than the account data governed by PCI DSS, so organizations should map where CDD data resides, apply appropriate access controls and retention limits, and coordinate CDD processes with their broader security and privacy programs.
How should CDD outcomes be documented and retained?
CDD processes typically call for documenting the identity information collected, the verification steps performed, the risk classification assigned, and the rationale for decisions, along with records of ongoing review. Retention periods and required documentation are set by the applicable regulatory framework and should be confirmed against current requirements rather than assumed. Retained CDD records should be secured with appropriate access controls, and retention should be limited to what the governing obligations require, balancing regulatory record-keeping duties against data minimization principles.

Common misconceptions

CDD is a one-time check completed only at onboarding.
CDD is intended to be an ongoing process; onboarding verification is only the starting point, and ongoing monitoring and periodic refresh of customer information are part of the practice. Treating it as a single event may leave stale or inaccurate profiles.
CDD is the same thing as PCI DSS compliance or a payment security control.
CDD relates to knowing and risk-rating customers and is separate from PCI DSS, which governs the protection of cardholder data and sensitive authentication data. Meeting CDD expectations does not by itself address PCI DSS obligations, and vice versa. Practitioners should confirm which framework governs a given control.
Completing CDD prevents fraud and financial crime.
CDD is intended to help reduce and detect risk, not to guarantee prevention. It has limitations and can produce false positives and false negatives; it works alongside, and does not replace, other fraud and transaction-level controls.

Best practices

Apply a risk-based approach, calibrating the depth of due diligence to each customer's assessed risk and reserving enhanced due diligence for higher-risk relationships.
Verify identity and, for legal entities, beneficial ownership using reliable and independent sources rather than relying solely on customer-provided assertions.
Document the expected purpose and nature of each relationship to establish a baseline that supports meaningful ongoing monitoring.
Perform ongoing monitoring throughout the relationship and refresh customer information periodically so that risk ratings and profiles remain current.
Keep CDD processes distinct from, but coordinated with, payment security controls such as those governed by PCI DSS, confirming which framework applies to each obligation.
Tune monitoring thresholds with awareness of false-positive and false-negative trade-offs, and route higher-risk cases for additional review or senior approval.