Services About Our Process Areas Expertise Blog Training AML Threat Intelligence Tool Let us help

Customer Due Diligence – More Than Collecting Documents

Passport and identification documents laid out for verification — customer due diligence beyond paperwork
Photo by Blake Guidry on Unsplash

For many businesses, customer due diligence (CDD) has long been treated as a procedural requirement—collect identification, complete forms, and move on. But for the Financial Action Task Force, that approach is no longer sufficient.

FATF repeatedly finds that businesses: Collect required documents, Complete onboarding forms and follow procedures rigidly. However, little may be done to analyse what the information means. CDD becomes a compliance exercise rather than a risk assessment tool.

Poor Customer Risk Differentiation

In some jurisdictions, high-risk and low-risk customers are treated similarly. Risk ratings exist but do not influence controls and businesses fail to identify genuinely higher-risk relationships

Inconsistent or Superficial Enhanced Due Diligence (EDD)

It was frequently observed that: EDD is not triggered when it should be. Source of wealth/funds is not properly verified, and checks are superficial or rely on customer declarations. As a result, high-risk customers are not subject to meaningful scrutiny.

Weak Identification of Beneficial Ownership

Businesses rely on information provided by customers. Complex ownership structures are not properly analysed and ultimate beneficial owners (UBOs) are not identified or verified. When a business does not know who controls the customer, risk cannot be properly assessed.

Lack of Ongoing Monitoring and Updating

CDD is often treated as a one-time onboarding exercise. Customer profiles are not updated. As a result, changes in behaviour are not reassessed and risk ratings remain static. Businesses that neglect ongoing monitoring fail to detect when a low-risk customer becomes high-risk.

Achieving effective Customer Due Diligence

Apply a Genuine Risk-Based Approach

  • Assess risk based on customer, geography, product, channel and behaviour
  • Clearly differentiate between low, medium, and high risk
  • Tailor controls accordingly

Effective Practice: directly determines the level of due diligence, monitoring intensity and frequency of review

Strengthen Customer Risk Profiling

  • Use structured risk scoring methodologies
  • Incorporate multiple risk factors
  • Regularly validate and refine risk models

Effective Practice: High-risk customers are clearly identified and actively managed, not just labelled.

Apply Robust Enhanced Due Diligence (EDD)

For higher-risk customers, FATF expects:

  • Verification of source of wealth and source of funds
  • Deeper background checks
  • Senior management approval for onboarding

Effective Practice: EDD provides credible insight into the legitimacy of funds and activities.

Ensure Accurate and Verified Beneficial Ownership

  • Identify the natural persons who ultimately own or control the customer
  • Understand ownership structures (including layered entities)
  • Verify information using independent sources

Effective Practice: Beneficial ownership is understood, documented, and explainable.

Implement Ongoing Monitoring and Periodic Reviews

CDD should be continuous:

  • Monitor transactions against customer profiles
  • Update customer information regularly
  • Reassess risk when unusual activity occurs

Effective Practice: Customer profiles are dynamic, reflecting real-time behaviour.

Effective CDD is not just collecting information—it is about understanding risk and acting on it.

Louis Parris is an Anti-money laundering Audit, Risk & Training Consultant.

Written by
Louis Parris
Compliance Consultant — AML/CFT/CPF Audits, Enterprise Risk Assessments, Internal Audits & Compliance Training
View profile, more articles & contact →