Recommendation 10 (CDD)
FATF Recommendation 10 is an international standard that sets out how financial institutions should identify and verify who their customers are, and understand who ultimately benefits from an account or transaction. It describes when this customer due diligence applies and requires that checks be adjusted to the level of risk involved. It also calls for ongoing attention to customer activity to spot anomalies over time.
FATF Recommendation 10 defines the customer due diligence (CDD) framework within the FATF Recommendations, the international standards countries are expected to implement to counter money laundering and terrorist financing. It sets out when CDD applies, the measures required, and how those measures should be calibrated to assessed risk (a risk-based approach). Core elements include identifying and verifying customer identity, identifying and verifying beneficial owners, understanding the purpose and intended nature of the business relationship, and conducting ongoing monitoring to challenge anomalies. Per the evidence, FATF expects the obligation to conduct CDD to be established in law, with implementation typically effected through national legislation (for example, in the UK via the Money Laundering Regulations as secondary legislation). Note that FATF Recommendation 10 is distinct from national CDD rules such as those administered by FinCEN, which may set their own scope for beneficial ownership identification and verification; practitioners should confirm requirements against the applicable jurisdiction's implementing law and the current FATF text.
Why it matters
Customer due diligence sits at the foundation of any anti-money laundering and counter-terrorist-financing program. FATF Recommendation 10 matters because it establishes the internationally agreed baseline for knowing who a customer is, understanding who ultimately benefits from an account or transaction, and forming a view of what normal activity looks like so that anomalies can be challenged over time. Without a common standard, identity and beneficial ownership checks would vary widely between institutions and jurisdictions, creating gaps that illicit actors can exploit.
The standard also matters because it is intended to be enforceable rather than aspirational. FATF expects the obligation to conduct CDD to be established in law, with countries implementing it through national legislation. In the UK, for example, this is effected through the Money Laundering Regulations, which are secondary legislation. This means that for regulated firms, CDD is not merely good practice but a legal requirement whose specific scope is defined by the implementing regime in each jurisdiction.
Because implementation is national, practitioners should not assume that FATF Recommendation 10 and local CDD rules are identical. National regimes such as those administered by FinCEN in the United States may set their own scope for beneficial ownership identification and verification, and that scope can change over time. Treating the FATF text and a specific national rule as interchangeable can lead to compliance gaps; requirements should be confirmed against the applicable jurisdiction's implementing law and the current FATF text.
Who it's relevant to
Inside R.10
Common questions
Answers to the questions practitioners most commonly ask about R.10.