Customer Due Diligence (CDD), what does it mean?
Reading time: 3 min.
In short
There are more and more vacancies on the internet with the request for a "CDD Analyst" or "compliance offer". But what does CDD actually mean? CDD stands for Customer Due Diligence. Customer Due Diligence is in fact part of a know-your-customer research. With a CDD investigation, for example, financial institutions investigate their clients and on that basis make a risk assessment. By properly conducting and applying the CDD investigation, a financial institution prevents them from being used for money laundering or fraud
CDD en KYC
CDD is often incorrectly referred to as a synonym for Know Your Customer (KYC) while CDD is a part of KYC. CDD is a legal obligation arising from the Anti Money Laundering Directive (hereinafter: AMLD). The AMLD is a fairly recent law that was introduced in the Netherlands in 2008. The AMLD has given certain professions and sectors a 'gatekeeper' function from the government to combat money laundering and fraud. They have an important role in this to pick up any signals as early as possible and to report any unusual transactions to FIU the Netherlands. Professions such as estate agents, notaries and lawyers are faced with this legal obligation. CDD is one of the first steps in the fight against money laundering and terrorist financing. Each institution determines its own CDD policy, but this policy must always be based on the AMLD.
How do you conduct a CDD research?
It is important to do a good CDD investigation so that companies know who they are doing business with and what risk the relationship entails. The first step is, of course, the identification and verification of a client. After this step, the risk inventory begins. Certain checks must be carried out to make a proper risk assessment, some of which are laid down by law. This includes finding out the Ultimate Benifical Owner (UBO) and checking the PEP and sanctions list. More extensive checks are also possible, such as taking country risk into account or checking the receivership and administration register. After all, the idea behind the Wwft is that you must make a risk assessment of your client. The more information companies have about the client, the better they can make a risk assessment.
Based on the risk assessment, companies can choose from three types of customer due diligence:
- Simplified
- Standard
- Enhanced

A simplified customer due diligence is not common. There are no longer any standard cases designated by law for which a simplified customer due diligence is sufficient. Companies themselves will have to provide evidence that research has been carried out and that the client poses a sufficiently proven low risk. To this end, the European Parliament and Council has drawn up an annex with indicators that a potentially lower risk. The appendix often refers to listed companies and government institutions.
Companies will almost always have to conduct a standard due diligence. In a standard customer due diligence, a standard number of points are always recorded and checked:
- The identity of the client must be established, checked and recorded;
- The identity of the ultimate beneficial owner (UBO) must be determined, verified and recorded;
- The purpose and nature of the transaction/order must be determined and recorded;
- Checking whether a client is acting for himself or for another person;
- If necessary: determine whether a natural person representing the client is authorized to do so;
- Constantly monitoring and controlling the client.
Finally, there is the enhanced due diligence. A company only carries out this in-depth investigation if the risk assessment reveals a high or increased risk. Increasing risk factors include:
- The client is a politically exposed person (PEP), a relative of a PEP, or an associate of a PEP;
- If the country where the client resides or is established has been designated as a risk country by the European Commission or FATF. Risk countries are countries with a higher risk of money laundering or terrorist financing;
- If it concerns a transaction or business relationship with a higher risk of money laundering or financing of terrorism. An example of this is a crypto transaction.
The type of customer due diligence therefore depends on the risk assessment. The process of making a risk assessment is time consuming and intensive. SCOPE FinTech Solutions has developed the CDD On Demand to support companies in making the risk assessment and identifying the UBO. In addition, it is also possible to put clients on a monitor list. The clients on the monitor list are checked at eleven different points every day.