Skip to main content
Category: AML and KYC

Recommendation 10 (CDD)

Also known as: R.10, FATF Recommendation 10, Customer Due Diligence (FATF R.10), R.10 Customer Due Diligence
Simply put

FATF Recommendation 10 is an international standard that sets out how financial institutions should identify and verify who their customers are, and understand who ultimately benefits from an account or transaction. It describes when this customer due diligence applies and requires that checks be adjusted to the level of risk involved. It also calls for ongoing attention to customer activity to spot anomalies over time.

Formal definition

FATF Recommendation 10 defines the customer due diligence (CDD) framework within the FATF Recommendations, the international standards countries are expected to implement to counter money laundering and terrorist financing. It sets out when CDD applies, the measures required, and how those measures should be calibrated to assessed risk (a risk-based approach). Core elements include identifying and verifying customer identity, identifying and verifying beneficial owners, understanding the purpose and intended nature of the business relationship, and conducting ongoing monitoring to challenge anomalies. Per the evidence, FATF expects the obligation to conduct CDD to be established in law, with implementation typically effected through national legislation (for example, in the UK via the Money Laundering Regulations as secondary legislation). Note that FATF Recommendation 10 is distinct from national CDD rules such as those administered by FinCEN, which may set their own scope for beneficial ownership identification and verification; practitioners should confirm requirements against the applicable jurisdiction's implementing law and the current FATF text.

Why it matters

Customer due diligence sits at the foundation of any anti-money laundering and counter-terrorist-financing program. FATF Recommendation 10 matters because it establishes the internationally agreed baseline for knowing who a customer is, understanding who ultimately benefits from an account or transaction, and forming a view of what normal activity looks like so that anomalies can be challenged over time. Without a common standard, identity and beneficial ownership checks would vary widely between institutions and jurisdictions, creating gaps that illicit actors can exploit.

The standard also matters because it is intended to be enforceable rather than aspirational. FATF expects the obligation to conduct CDD to be established in law, with countries implementing it through national legislation. In the UK, for example, this is effected through the Money Laundering Regulations, which are secondary legislation. This means that for regulated firms, CDD is not merely good practice but a legal requirement whose specific scope is defined by the implementing regime in each jurisdiction.

Because implementation is national, practitioners should not assume that FATF Recommendation 10 and local CDD rules are identical. National regimes such as those administered by FinCEN in the United States may set their own scope for beneficial ownership identification and verification, and that scope can change over time. Treating the FATF text and a specific national rule as interchangeable can lead to compliance gaps; requirements should be confirmed against the applicable jurisdiction's implementing law and the current FATF text.

Who it's relevant to

Compliance and AML officers
Those responsible for AML/CFT programs use Recommendation 10 as the reference point for designing CDD policies, but must implement against the specific national law that gives it effect, such as the UK Money Laundering Regulations or FinCEN rules in the US. They should confirm scope, beneficial ownership definitions, and verification thresholds against the current implementing legislation rather than the FATF text alone.
Financial institutions and other regulated firms
Firms subject to AML/CFT obligations must operationalize CDD across customer onboarding, beneficial ownership identification, risk assessment, and ongoing monitoring. Because the obligation is set out in law in most jurisdictions, failure to meet the applicable requirements carries legal and supervisory consequences, not just reputational risk.
Payment processors and acquirers
Organizations onboarding merchants or handling flows of funds apply CDD principles when assessing counterparties and understanding the purpose of a business relationship. The applicable scope of identification and verification depends on the jurisdiction's implementing regime, so cross-border operations may face differing requirements.
Fraud and risk analysts
The ongoing monitoring element of Recommendation 10 supports the detection of anomalous activity against an established understanding of expected customer behavior. Analysts should recognize that monitoring is intended to help identify anomalies for review and does not, by itself, confirm illicit activity; it works alongside other controls and requires investigation to reduce false positives and false negatives.
Policymakers and supervisors
National authorities transposing FATF standards into law and supervising compliance rely on Recommendation 10 to define the expected CDD framework, including the requirement that the CDD obligation be set out in law. Supervisors assess whether firms calibrate measures to assessed risk under a risk-based approach.

Inside R.10

Customer Identification and Verification
The process of identifying the customer and verifying that identity using reliable, independent source documents, data, or information before or during the establishment of a business relationship. Note that Recommendation 10 (CDD) is a FATF anti-money-laundering and counter-terrorist-financing standard and is distinct from PCI DSS cardholder identity or authentication requirements.
Beneficial Ownership Identification
Identifying the natural person(s) who ultimately own or control a customer that is a legal person or arrangement, and taking reasonable measures to verify that identity so the institution understands who is behind the account.
Understanding the Purpose and Nature of the Relationship
Obtaining information on the intended purpose and expected nature of the business relationship to establish a baseline against which activity can later be assessed.
Ongoing Due Diligence and Monitoring
Conducting continuous scrutiny of transactions throughout the relationship to ensure they are consistent with the institution's knowledge of the customer, their business, and risk profile, and keeping underlying documents and information current.
Risk-Based Application
Applying CDD measures on a risk-sensitive basis, allowing enhanced due diligence for higher-risk situations and, where permitted, simplified measures for lower-risk situations. The specific application depends on the applicable jurisdiction's implementation of the FATF standard.

Common questions

Answers to the questions practitioners most commonly ask about R.10.

Is CDD the same as a one-time identity check performed only when onboarding a customer?
No. Treating CDD as a single onboarding event is a common misconception. Customer due diligence is intended to be an ongoing process that includes identifying and verifying the customer, understanding the nature and purpose of the relationship, and conducting ongoing monitoring of transactions throughout the relationship. The intensity of measures may vary with risk, but the obligation does not end once an account is opened. Note that specific requirements and terminology vary by jurisdiction and by the framework being applied, so confirm the applicable rules for your context.
Does completing CDD mean a transaction or customer is confirmed to be free of financial crime risk?
No. CDD is intended to help identify and manage risk, not to guarantee that a customer or transaction is legitimate. It supports risk-based decisions and monitoring but cannot eliminate the possibility of illicit activity. Effective CDD reduces exposure and improves the ability to detect and report suspicious activity, while acknowledging trade-offs such as false positives and the limits of available information.
How should CDD measures be scaled to different customer risk levels?
A risk-based approach is generally applied, so the depth of measures is intended to reflect assessed risk. Lower-risk relationships may warrant simplified measures where permitted, while higher-risk situations may call for enhanced due diligence, additional information, and closer monitoring. The specific triggers, permitted simplifications, and enhanced measures depend on the applicable framework and jurisdiction, so confirm against the current governing rules rather than assuming a fixed threshold.
What should ongoing monitoring under CDD actually involve in practice?
Ongoing monitoring is intended to keep the customer risk profile current and to scrutinize transactions to check they are consistent with what is known about the customer and their expected activity. In practice this can include reviewing transaction patterns, keeping identification and beneficial ownership information up to date, and escalating anomalies for review. The exact expectations and record-keeping requirements vary by framework, so align procedures with the applicable rules.
When should CDD be refreshed or re-performed for an existing customer?
CDD information is generally expected to be reviewed and updated when triggers occur, such as a significant change in the customer relationship, a change in risk, or when existing information appears outdated or insufficient. Periodic reviews may also be scheduled on a risk-sensitive basis. The precise triggers and timing depend on the governing framework and internal policy, so refer to the current applicable requirements rather than a fixed interval.
How does CDD relate to identifying beneficial ownership for legal entity customers?
For non-individual customers, CDD typically includes taking steps to identify beneficial owners and to understand the ownership and control structure so that the natural persons behind the entity are known. The measures applied are intended to be proportionate to risk. The specific thresholds, verification expectations, and documentation requirements vary by jurisdiction and framework, so confirm the applicable rules for the entity types you serve.

Common misconceptions

Recommendation 10 (CDD) is a PCI DSS requirement covering cardholder data controls.
Recommendation 10 (CDD) is a FATF anti-money-laundering and counter-terrorist-financing standard governing customer due diligence, and it is separate from PCI DSS, which governs the protection of cardholder data and sensitive authentication data. Confirm the source standard before mapping any control, and do not assume PCI DSS requirement numbering aligns with FATF recommendation numbering.
CDD is a one-time check performed only when opening an account.
CDD is intended to be an ongoing process. Beyond initial identification and verification, it includes continuous monitoring of the relationship and periodic updating of customer information, so it is not satisfied by a single onboarding step.
Completing CDD guarantees that money laundering or fraud will not occur.
CDD is intended to help reduce and detect illicit activity, not to eliminate it. Like other detection and control measures, it carries trade-offs and cannot guarantee outcomes; it may fail to catch sophisticated concealment and can produce false alerts depending on implementation and risk calibration.

Best practices

Verify customer and beneficial owner identities using reliable, independent source documents, data, or information rather than relying on customer-supplied assertions alone.
Apply a risk-based approach, reserving enhanced due diligence for higher-risk customers and situations and using simplified measures only where permitted by the applicable jurisdiction.
Document the intended purpose and expected nature of each business relationship to establish a baseline for later monitoring.
Perform ongoing monitoring of transactions against the customer's known profile and investigate activity that is inconsistent with expectations.
Keep customer, beneficial ownership, and supporting records current through periodic reviews rather than treating CDD as a one-time onboarding task.
Confirm requirements against the current published FATF standard and the relevant jurisdiction's implementing regulations, and keep CDD obligations distinct from separate standards such as PCI DSS.