Customer Due Diligence
Customer Due Diligence is the core legal obligation under MLR 2017 to identify clients, verify their identity using reliable independent sources, and understand the purpose and intended nature of the business relationship. Standard CDD applies to most clients. Where risk is elevated, Enhanced Due Diligence (EDD) is required instead.
a CDD file for a sole trader typically includes identity evidence (passport or driving licence), address evidence (utility bill or bank statement), and a note on the nature of services to be provided.
How different roles use Customer Due Diligence
A good definition should change the next action for the person reading it.
Partner or director
Check whether this term affects acceptance risk, fee scope, supervision exposure, or sign-off responsibility.
ContinueMLRO or compliance lead
Map the term to evidence, escalation, monitoring, training, and inspection readiness.
ContinueClient-facing team member
Use the plain-English explanation to ask better client questions and write clearer file notes.
ContinueOther terms that go with Customer Due Diligence
Enhanced Due Diligence is a more thorough level of client verification required when a relationship presents a higher risk of money laundering or terrorist financing. EDD steps typically include verifying the source of funds, establishing source of wealth, obtaining senior management approval before onboarding, and applying more frequent ongoing monitoring.
Simplified Due Diligence is a reduced level of KYC that may be applied where the money laundering risk is demonstrably low — for example, for certain regulated financial institutions, listed companies, or UK public authorities. SDD does not mean no checks at all; it means the checks can be less extensive if risk justifies it.
In AML, risk assessment operates at two levels. A firm-wide risk assessment identifies the overall money laundering risks facing a practice — covering client types, services offered, geographies, delivery channels, and funding sources. A client risk assessment scores an individual client as low, medium, or high risk and determines what level of due diligence to apply.
Before you treat Customer Due Diligence as handled
- Confirm which regulation, policy, or internal procedure the term maps to.
- Document the decision or evidence trail in the client file, not only in email or chat.
- Escalate where the term indicates higher risk, sanctions exposure, PEP status, suspicion, or missing evidence.
- Keep the wording consistent across onboarding, review notes, training material, and inspection packs.
Put Customer Due Diligence into practice with Certivus
Knowing the term is the first step. Certivus gives you the workflows — client intake, CDD, EDD, PEP and sanctions screening, audit-ready records — to apply it across every client.
Back to the full glossary