How to

How to run customer due diligence that stands up

True Comply · · 6 min read

← Back to Insights
A single closed passport lying on a plain dark grey surface.

CDD is four things, not one

Most businesses new to the regime equate customer due diligence with checking a photo ID. Identification is part of it, but on its own it satisfies very little. Initial CDD has four components, and a program that skips any of them has a gap.

  • Identify the customer — and, where the customer is not an individual, the people who ultimately own or control it.
  • Verify that identity using reliable and independent information.
  • Understand the nature and purpose of the business relationship — what this client wants from you and why.
  • Assess and record the money-laundering and terrorism-financing risk the customer presents.

Do it before you provide the service

The default position is that initial CDD happens before you provide a designated service, not alongside it and not afterwards. Practices that treat verification as something to tidy up before settlement are running the risk in the meantime.

Risk rating is where judgement lives

A risk rating is not a formality. It determines how much scrutiny the customer gets, both now and on an ongoing basis. Factors that typically raise a rating include complex or opaque ownership structures, a politically exposed person in the ownership or control chain, unusual geographic exposure, transactions that do not fit the customer's profile, and any reluctance to provide information.

Where risk is high, you apply enhanced due diligence: more information, more verification, and senior sign-off. Where risk is genuinely low, simplified measures may be available. The important thing is that the level of scrutiny is a decision you made for a reason you recorded.

CDD does not stop at onboarding

Ongoing CDD means monitoring the relationship for changes — in ownership, in behaviour, in sanctions or adverse-media status — and refreshing your information when something moves. A customer verified once in 2026 and never looked at again is not a monitored customer.

The record is the point

For each customer you should be able to produce: what you collected, what you verified it against and when, the beneficial ownership position, the screening results, the risk rating and the reasoning, who approved it, and what has changed since. Most obligations require records to be kept for seven years.

True Comply case detail for an individual client showing identity verification, screening results and risk rating in one record.
One record per customer: what was checked, what it returned, and who decided.

If that record only exists as scattered emails and PDFs in a matter folder, you technically have it and practically do not. Building CDD in a single system so the record assembles itself is the difference between compliance you assert and compliance you can prove. Start the conversation if you would like to see how that works.

Related insights

Compliance you can prove.

Tell us where you're at and we'll help you work out what applies to your business.

No jargon, no obligation.