SardineCon SF/2026

Learn More

O que é Simplified Due Diligence (SDD)?

SUBSCRIBE

Simplified due diligence is a reduced level of diligence allowed for customers or products assessed as demonstrably low risk. It applies lighter verification and monitoring than standard due diligence, letting a firm focus effort where risk is higher, but only when low risk is genuinely evidenced.

What is SDD, in plain English?

Simplified due diligence is the lightest tier in a risk-based diligence model. When a customer or product is assessed as low risk, a firm can apply lighter verification and less intensive monitoring than it would for a standard customer. The idea is proportionality: not every relationship needs the same depth of scrutiny, so effort can be concentrated where the risk actually is.

The critical word is demonstrably. SDD is permitted where low risk can be shown, not assumed. That usually means a specific, evidenced basis: a regulated counterparty, a low-value and low-functionality product, or a customer type that a risk assessment has established as low risk. A vague sense that a customer seems fine is not a basis for SDD.

SDD also never means no diligence and no monitoring. It is a reduction, not an exemption. Identity is still confirmed, screening still applies, and activity is still watched, just at a level calibrated to genuinely low risk. The moment the low-risk basis stops holding, the customer should move back to standard diligence.

SDD versus standard and enhanced diligence

What changes

Standard / enhanced

Simplified (SDD)

When it applies

Normal or higher risk customers and products.

Only where low risk is demonstrably evidenced.

Verification depth

Full checks, deeper for high risk.

Lighter checks proportionate to low risk.

Monitoring

Standard to intensive.

Reduced, but never switched off.

Re-assessment

Ongoing, with tighter triggers.

Must re-check that the low-risk basis still holds.

What it looks like in practice

In practice

A firm offers a low-value stored-value product with tight caps and no ability to transfer funds externally. A risk assessment establishes the product as low risk, so it applies simplified due diligence: basic identity confirmation and lighter monitoring rather than the full standard flow.

Months later, a customer on that product starts hitting the caps repeatedly and requests an upgrade that would allow external transfers. The activity has outgrown the low-risk basis that justified SDD, but because the firm treats SDD as permanent rather than conditional, nobody re-assesses. The right move is to recognize that the low-risk assumption no longer holds and step the customer up to standard diligence before the new functionality goes live.

Why SDD matters to operators

Diligence resources are finite. SDD is the mechanism that lets a firm spend its scrutiny where it counts, applying lighter checks to genuinely low-risk relationships so analysts and reviewers can focus on the higher-risk ones. Used correctly, it makes a risk-based program efficient rather than uniformly heavy.

The common pitfall is applying SDD too broadly or too permanently. Firms stretch it to customers whose low-risk status was never really evidenced, or they fail to re-assess when a customer's activity outgrows the basis that justified it. A customer who qualified for SDD at signup can quietly become one who no longer should, and the discipline is to keep checking that the low-risk assumption still holds rather than treating it as a permanent label.

What to watch for

  • Unevidenced low risk. SDD applied on a hunch rather than a documented, specific basis is a control gap waiting to be found.
  • Outgrown basis. Activity that has moved beyond the low-risk profile that justified SDD in the first place.
  • Over-broad application. Stretching SDD across customer types that a real risk assessment would not support.
  • Monitoring switched off. Treating SDD as no monitoring rather than reduced monitoring leaves activity unwatched.
  • No re-assessment triggers. Nothing in place to catch when a low-risk customer stops qualifying and should step up.

Quick questions

Does SDD mean no due diligence?

No. It is reduced diligence, not none. Identity is still confirmed, screening still applies, and activity is still monitored, just at a level proportionate to genuinely low risk.

When is SDD allowed?

Only where low risk can be demonstrably shown, such as a regulated counterparty or a low-value, low-functionality product assessed as low risk. It cannot be applied on assumption alone.

How is SDD different from EDD?

They are opposite ends of the risk-based scale. SDD applies lighter checks to low-risk cases, while enhanced due diligence applies deeper checks to high-risk ones. Standard diligence sits in between.

What is the most common mistake with SDD?

Applying it too broadly, or failing to re-assess when a customer outgrows the low-risk basis. A customer who qualified at signup can become one who no longer should, and treating SDD as permanent misses that shift.

Can a customer move off SDD?

Yes, and they should when their risk changes. If activity, product use, or circumstances outgrow the low-risk basis, the customer moves up to standard or enhanced diligence.

Who decides what qualifies for SDD?

The firm's risk-based approach and risk assessment, within the bounds regulators allow. The criteria should be documented so that each application of SDD can be justified and reviewed.

Go deeper

  • FFIEC BSA/AML Examination Manual ↗ — The manual US examiners use to assess BSA and AML programs.
  • FATF ↗ — The global standard-setter for AML, counter-terrorist-financing, and counter-proliferation. Recommendations, guidance, and jurisdiction lists.

O que saber junto com Simplified Due Diligence (SDD)