
CDD is four things, not one
Most businesses new to the regime equate customer due diligence with checking a photo ID. Identification is part of it, but on its own it satisfies very little. Initial CDD has four components, and a program that skips any of them has a gap.
- Identify the customer — and, where the customer is not an individual, the people who ultimately own or control it.
- Verify that identity using reliable and independent information.
- Understand the nature and purpose of the business relationship — what this client wants from you and why.
- Assess and record the money-laundering and terrorism-financing risk the customer presents.
Do it before you provide the service
The default position is that initial CDD happens before you provide a designated service, not alongside it and not afterwards. Practices that treat verification as something to tidy up before settlement are running the risk in the meantime.
Risk rating is where judgement lives
A risk rating is not a formality. It determines how much scrutiny the customer gets, both now and on an ongoing basis. Factors that typically raise a rating include complex or opaque ownership structures, a politically exposed person in the ownership or control chain, unusual geographic exposure, transactions that do not fit the customer's profile, and any reluctance to provide information.
Where risk is high, you apply enhanced due diligence: more information, more verification, and senior sign-off. Where risk is genuinely low, simplified measures may be available. The important thing is that the level of scrutiny is a decision you made for a reason you recorded.
CDD does not stop at onboarding
Ongoing CDD means monitoring the relationship for changes — in ownership, in behaviour, in sanctions or adverse-media status — and refreshing your information when something moves. A customer verified once in 2026 and never looked at again is not a monitored customer.
The record is the point
For each customer you should be able to produce: what you collected, what you verified it against and when, the beneficial ownership position, the screening results, the risk rating and the reasoning, who approved it, and what has changed since. Most obligations require records to be kept for seven years.

If that record only exists as scattered emails and PDFs in a matter folder, you technically have it and practically do not. Building CDD in a single system so the record assembles itself is the difference between compliance you assert and compliance you can prove. Start the conversation if you would like to see how that works.
Related insights
- Tranche 2 is here: what it means for Australian real estate agencies
Real estate · 5 min read
- Your AML/CTF obligations, in plain English
Getting compliant · 6 min read
- ‘Are we even captured?’ How AML/CTF scope really works
Scope · 4 min read