Insights / Blog / Insights
Insights

Customer Due Diligence Explained: Why It's an Ongoing Process, Not a One-Time Check

CDD is not a form that has to be filled in once and for all. It is a question an organisation must be able to answer continuously: do we really know who this customer is, and does what they are doing still fit with who we know them to be?

Customer Due Diligence Explained: Why It's an Ongoing Process, Not a One-Time Check

Customer Due Diligence, as defined by the Financial Action Task Force, involves four elements: identifying the customer and verifying their identity through reliable, independent sources; identifying the beneficial owner and understanding the ownership and control structure; understanding the purpose and intended nature of the business relationship; and conducting ongoing monitoring of transactions to ensure they are consistent with what is known about the customer. The fourth element is the one most frequently treated as an afterthought. It is not a checklist point but a commitment to keep the answer up to date.

The Wolfsberg Group, an association of major global banks that has issued due diligence principles since 1999, makes the same point more directly: a bank must only accept clients whose source of wealth and funds can be reasonably established as legitimate, and it is the relationship manager who is responsible for that, not the compliance system that handled the paperwork at onboarding.

The majority of compliance teams treat Customer Due Diligence as a process of gathering documents, checking identity, and maintaining a file. That description is not incorrect, but it falls short in a significant way. CDD is not a form that has to be filled in once; it is a question an organisation must be able to answer continuously throughout the duration of the relationship.

This piece is structured around international standard-setting bodies, FATF and the Wolfsberg Group, rather than any single country's regulations. The principles described here apply across jurisdictions and are the baseline against which any national framework is measured.

Three levels, calibrated to risk

A uniform approach to due diligence introduces risk rather than reducing it. International standards describe three levels applied according to assessed risk, not merely customer category.

Simplified / Reduced Due Diligence
Applies only where lower risk has been genuinely established, for example where a customer’s identity and beneficial ownership details are already publicly available, or where the entity is subject to its own regulatory disclosure requirements. “Simplified” does not mean omitted; it means verification proportionate to a risk actually assessed as low.
Standard Due Diligence
The baseline: identify the customer and verify identity using reliable, independent sources; establish who the beneficial owner is and understand the ownership and control structure; understand the purpose and intended nature of the relationship; and conduct ongoing monitoring of transactions in light of what is known about the customer.
Enhanced Due Diligence
Required when risk is assessed as high. FATF standards specifically identify politically exposed persons, cross-border correspondent relationships, and customers linked to higher-risk jurisdictions as indicators. The Wolfsberg Group specifies what EDD actually requires in practice: senior management approval before the relationship starts, an established (not merely stated) source of wealth and funds, and ongoing monitoring frequent enough to detect changes.

No preference makes any of these three levels optional. Which applies depends on the assessed level of risk. Where there is any indication of high risk, simplified measures are explicitly unavailable even if the customer would otherwise fall into a reassuring-sounding category.

Beneficial ownership: the part most often done superficially

Identifying a natural-person customer is relatively straightforward. When the customer is a company, trust, partnership, or foundation, the quality of due diligence diverges sharply between institutions that treat it as a real analytical exercise and those that treat it as a form to be completed.

The Wolfsberg Group is specific about what genuine beneficial ownership understanding requires. For a company: who provides the funds, who is the beneficial owner of the assets, and who has the authority to direct the company's officers. For a trust: who provided the funds, who controls them, who has the power to remove a trustee, and who benefits. For a partnership or foundation: who provides the funds and how the entity is actually managed and directed.

The distinction that matters most is between control and signature authority. A firm that asks only who can sign for an account rather than who actually controls it has not carried out adequate beneficial ownership due diligence, regardless of what is recorded in its files. This is one of the most frequently misplaced aspects of CDD across institutions of all sizes.

Ongoing monitoring: where point-in-time due diligence fails

A customer accepted today on the basis of a risk assessment conducted today is not a fixed entity. Transaction patterns change, public profiles shift, and a person who was not politically exposed at onboarding can become one later. A declared source of funds can turn out not to match the funds actually moving through the account.

FATF's framework makes it explicit: transactions must be examined throughout the course of the relationship to ensure they are consistent with what the institution knows about the customer, their business, and their risk level. The Wolfsberg Group's principles specify that account activity must be continuously monitored, with frequency and depth determined by the customer's risk category, and that unusual or suspicious activity must trigger escalation: analyse the background, then either continue under enhanced monitoring, terminate the relationship, or report to the appropriate authority.

The practical failure is rarely a complete absence of monitoring. It is more commonly that monitoring is a disconnected process from the original due diligence file. A transaction that should be evaluated against a customer's known profile is instead measured against general rules with no memory of what the institution established at onboarding.

What distinguishes a defensible CDD programme

Taken together, the international standards converge on five points that separate a CDD programme that holds up under examination from one that exists only on paper.

01
The risk assessment must be genuine

A customer classified as low risk because the classification is convenient rather than because of a real analysis becomes a liability as soon as anyone examines the file. A defensible programme classifies risk from evidence, not from the desire for a particular outcome.

02
Beneficial ownership must establish control, not just collect paperwork

Obtaining a signed ownership declaration is a different task from understanding who actually directs an entity’s funds and decisions. Only one of those tasks meets the standard. The distinction between signature authority and actual control is the most frequently misplaced aspect of beneficial ownership due diligence.

03
Enhanced due diligence must include the parts that are hardest to obtain

The source of wealth and source of funds must be established, not merely stated. Senior management approval must represent a genuine decision point, not a formality. These are the two aspects of EDD most frequently absent when time is pressing, and they are the two that matter most under examination.

04
Ongoing monitoring must be connected to what onboarding established

A transaction monitoring system that has no visibility into a customer’s stated purpose, risk classification, or beneficial ownership structure is only monitoring in name. It may identify anomalies by general rules, but it cannot determine whether an anomaly is consistent with what the institution already knows about that specific customer.

05
Records must allow for reconstruction, not just existence

The minimum five-year retention standard required by international frameworks exists for a reason: the real test of a CDD programme is whether someone reviewing the file later can reconstruct exactly what was known, when it was known, and what action was taken. A file that records outcomes but not the reasoning behind them does not meet this standard.

Closing the gap

All five points share the same root: due diligence quality depends on information gathered across the entire customer relationship — onboarding, risk classification, ongoing monitoring, investigation — and on those stages being genuinely connected rather than operating as separate systems that each appear adequate in isolation.

Fyscal Arcx's Name Screening module scores matches against sanctions, PEP, and adverse media data at onboarding with per-field explainability, and its Delta Screening capability continuously re-screens the existing customer base as new watchlist entries are added, so a customer's status is re-evaluated on an ongoing basis rather than fixed at the moment of acceptance.

Its Case Management module keeps beneficial ownership findings, risk classification history, and prior due diligence decisions in one persistent record tied to the customer, so a later transaction alert can be evaluated against what the institution already established rather than against a generic rule with no memory of the file. Its Transaction Monitoring module builds behavioral baselines specific to each customer, so ongoing monitoring reflects the individual relationship the standards describe rather than a uniform threshold applied regardless of what is actually known about who the customer is.

See how Fyscal Arcx connects onboarding, screening, monitoring, and case management in one record.
Book a demo

Frequently asked questions

Identifying the customer and verifying their identity through reliable, independent sources; identifying the beneficial owner and understanding the ownership and control structure; understanding the purpose of the business relationship; and conducting ongoing due diligence on transactions to ensure consistency with what is known about the customer.
Simplified due diligence applies to genuinely lower-risk situations and reduces verification extent without skipping it. Standard due diligence is the baseline applied to typical customers. Enhanced due diligence applies to higher-risk customers and requires established (not merely stated) source of wealth and funds, senior management approval, and more frequent ongoing monitoring.
Understanding who actually provides funds, who controls those funds, and who has the power to direct the entity’s decisions, not just identifying who can sign for an account. Signature authority alone does not establish control for due diligence purposes.
Because a customer’s risk profile is not fixed at onboarding. Transaction patterns can shift, a customer’s public profile can change, and a declared source of funds can turn out not to match actual account activity over time. International standards treat ongoing monitoring as a core requirement, not a supplementary one.
International standards call for a minimum of five years of record retention, so that a due diligence programme can be reconstructed by a later reviewer: what was known, when it was known, and what action was taken in response.
Stay in the loop

Insights on modern finance, monthly.

No noise — just the engineering and strategy behind banking that scales.

Keep reading

Related articles