SardineCon SF/2026

Learn More

O que é Customer Due Diligence (CDD)?

SUBSCRIBE

CDD is the core process of identifying and verifying a customer, understanding the purpose of the relationship, and judging its money-laundering and terrorist-financing risk, with the depth scaled to that risk. It feeds the customer risk rating and sets the baseline for monitoring, so weak CDD undermines everything downstream.

What is CDD, in plain English?

Customer Due Diligence is the foundation of knowing your customer. It has three jobs: identify and verify who the customer is, understand what the relationship is actually for, and assess how much money-laundering and terrorist-financing risk it carries. The depth of the work is scaled to that risk, which is the risk-based approach in action.

CDD is not a standalone task; it is the engine that feeds the rest of the program. The risk it assesses drives the customer risk rating, and the picture it builds of expected activity becomes the baseline that transaction monitoring compares against. When CDD is thin, everything downstream inherits the weakness, because the controls are calibrated off a picture that was never properly drawn.

Two failures recur. The first is verifying identity but never establishing expected activity: the firm confirms who the customer is but never asks what they will do, so it has no definition of normal to detect abnormal against. The second is treating CDD as a one-time onboarding chore rather than a living record. Risk verified once decays as circumstances change, so a CDD file that is never refreshed slowly stops describing the customer it is supposed to cover.

The tiers of due diligence

Tier

When it applies

What it involves

Simplified (SDD)

Genuinely low-risk, evidenced customers.

Lighter verification and reduced ongoing checks.

Standard (CDD)

The typical customer.

Identity verification, purpose of relationship, risk rating, ongoing monitoring.

Enhanced (EDD)

Higher-risk customers, PEPs, complex ownership.

Source of funds and wealth, senior sign-off, tighter monitoring.

What it looks like in practice

In practice

A small business opens a merchant account. CDD confirms the company registration, the owner's identity, and the stated purpose: a local retailer expecting modest card takings. That expected-activity picture is recorded as the baseline, not filed and forgotten.

A year later the account starts receiving large international wires that have nothing to do with retail. Because CDD captured what normal looked like, monitoring flags the mismatch immediately, and a review asks the obvious question: what changed, and does the new activity fit the customer? Without that baseline, the wires would have looked like just more traffic, and the drift would have gone unnoticed.

Why it matters to operators

CDD is where a firm decides how much to trust a customer and how closely to watch them, and every later control leans on that decision. A strong CDD file gives monitoring a real baseline, gives reviewers a starting point, and gives the firm a defensible story about why it treated a customer the way it did. A weak one leaves all of those functions working from guesswork.

The two failure modes are worth committing to memory because they are so common. If you never define normal for a customer, you cannot tell when their behavior turns abnormal, and monitoring becomes noise. And because risk verified once decays as ownership, circumstances, and behavior change, the record has to stay current. CDD is not an onboarding gate you close behind the customer; it is a file you keep alive for the life of the relationship.

What to watch

  • Identity without activity. Verifying who a customer is but never capturing what they will do leaves monitoring with no baseline.
  • One-and-done files. CDD gathered at onboarding and never refreshed slowly stops matching the real customer.
  • Depth mismatch. Applying the same shallow diligence to a high-risk customer as to a low-risk one breaks the risk-based approach.
  • Unverified purpose. Accepting a stated purpose that does not fit the customer or the later activity without question.
  • Broken handoff. CDD data that never actually reaches the monitoring and rating systems it is meant to feed.

Quick questions

How is CDD different from KYC?

KYC is the broad concept of knowing your customer across the relationship. CDD is the specific, structured process that delivers it: identify, verify, understand the relationship, and assess risk. CDD is the working core of KYC.

What are the levels of CDD?

Simplified due diligence for evidenced low risk, standard CDD for typical customers, and enhanced due diligence for higher-risk customers, PEPs, and complex structures. The level is set by the risk-based approach.

Why capture expected activity, not just identity?

Because expected activity is the baseline monitoring uses to spot abnormal behavior. Verifying identity alone tells you who the customer is but gives you no way to tell when what they do stops making sense.

Is CDD a one-time task?

No. Risk verified once decays as circumstances change, so CDD has to be kept current through ongoing due diligence and trigger-based reviews. A file frozen at onboarding gradually stops describing the real customer.

How does CDD feed the risk rating?

The risk CDD assesses, covering who the customer is, where they operate, what they use, and how they transact, is what drives the customer risk rating, which in turn sets how much monitoring and review they receive.

What happens if CDD is weak?

Everything downstream inherits the weakness. Ratings are miscalibrated, monitoring has no real baseline, and reviews start from guesswork. Because so many controls depend on CDD, thin CDD quietly undermines the whole program.

Go deeper

  • FFIEC BSA/AML Examination Manual ↗ — The manual US examiners use to assess BSA and AML programs.
  • FATF ↗ — The global standard-setter for AML, counter-terrorist-financing, and counter-proliferation. Recommendations, guidance, and jurisdiction lists.

O que saber junto com Customer Due Diligence (CDD)