Customer due diligence (CDD) form: compliance, components, and best practices

In 2019, Standard Chartered paid a combined $1.1 billion in penalties to U.S. and U.K. authorities, primarily over sanctions violations involving Iran. The U.K. Financial Conduct Authority imposed a separate £102 million fine — its second-largest AML penalty on record — and specifically cited ‘serious and sustained shortcomings’ in the bank’s customer due diligence processes. The fine remains one of the most cited examples in compliance training because it illustrates a straightforward point: a CDD failure is not a procedural technicality. It is a measurable financial and reputational event.
A customer due diligence (CDD) form is a document that regulated businesses use to collect, verify, and assess a customer’s identity, ownership structure, and risk profile before or during a business relationship. For banks, financial institutions, law firms, and other regulated entities, a CDD form supports AML customer due diligence obligations under applicable laws and FATF-aligned standards.
Key takeaways
- CDD form is required under AML/KYC rules across many regulated sectors, while the specific forms, fields, and documentation requirements vary by jurisdiction and customer type.
- A CDD form collects six core categories of information: customer identity, verification documents, business relationship details, beneficial ownership, risk assessment, and a signed declaration.
- FinCEN’s CDD framework includes four core CDD elements, while 31 CFR 1010.230 specifically sets beneficial ownership requirements for covered financial institutions
- The right CDD form level — standard, simplified, or enhanced — depends on a risk assessment of the customer, their jurisdiction, and the nature of the transaction.
- CDD form requirements vary by industry and jurisdiction, but usually cover identity, beneficial ownership, risk assessment, and ongoing monitoring.
- CDD records should be updated on a risk-based schedule, based on internal policy, local rules, customer risk, and trigger events.
What is a customer due diligence form?
A customer due diligence (CDD) form is a document businesses use to verify customer identities and assess risks related to fraud, money laundering, and terrorist financing. It is crucial for regulatory compliance, especially for banks, financial institutions, legal firms, and other high-risk industries.
These forms typically require personal details such as full name, address, date of birth, government-issued ID, and sometimes financial statements or proof of income. Businesses may also need to check if a customer is politically exposed or linked to high-risk entities.
CDD forms are required by global regulations such as the Financial Action Task Force (FATF) recommendations, Anti-Money Laundering (AML) laws, and Know Your Customer (KYC) requirements. Failure to comply can lead to penalties, fines, or reputational damage.
Covered U.S. financial institutions must follow FinCEN’s CDD Rule under the Bank Secrecy Act. This rule includes the following requirements:
- Verify customer identities
Businesses must confirm their customers’ identities. - Identify and verify beneficial owners
For legal entities, institutions must identify individuals who own or control 25% or more of the entity. - Understand the nature of customer relationships
This helps businesses develop customer risk profiles. - Ongoing monitoring
Financial institutions must continuously monitor transactions and update customer information as needed to detect and report suspicious activities.
CDD form vs. KYC form vs. EDD questionnaire
These terms are often conflated, but they refer to distinct instruments.
- A KYC due diligence form focuses on customer identity verification — confirming that the person or entity is who they claim to be.
- A CDD form is broader: it combines identity verification with a risk assessment of the customer relationship.
- An enhanced due diligence (EDD) questionnaire is a supplementary document used for high-risk customers that goes beyond the standard CDD form — requiring additional source-of-funds documentation, senior management approval, and more intensive ongoing monitoring.
All three are connected, but each has a distinct scope and trigger. Note that a CDD form is distinct from a broader due diligence questionnaire, which is typically used in M&A and vendor onboarding contexts to assess counterparty risk across operational, financial, legal, and ESG dimensions — not specifically AML/KYC.
Most regulated businesses now use digital CDD forms — either as PDF documents completed via secure portals, or as structured data inputs within compliance platforms. Paper-based CDD collection is still permitted in most jurisdictions, but it introduces manual-entry errors and makes audit-trail maintenance difficult. Integrated compliance platforms and regtech tools increasingly automate the form-population, document-request, and risk-scoring stages of the customer due diligence process.
Key components of a customer due diligence form
The six-section structure below reflects the standard layout used across most regulated jurisdictions. CDD form fields may be adapted by individual institutions to reflect their risk appetite, customer base, or sector-specific regulatory requirements — but the core categories are aligned with FATF Recommendation 10 on FATF customer due diligence and the FinCEN CDD Final Rule for U.S.-regulated entities. A form that omits any of these sections creates a documentary gap that will be flagged during a BSA/AML examination or regulatory audit.
For a structured companion to the form, explore the due diligence checklist feature, which helps teams organize document requests and manage due diligence workflows more efficiently.
| Section | Details |
|---|---|
| 1. Customer information | Full legal name, date of birth, nationality, residential address, contact details, and taxpayer identification number or equivalent government identifier. For companies: registered name, registration number, jurisdiction of incorporation, and principal place of business. |
| 2. Identification & verification | Type of identity document provided (passport, national ID card, driving license), document number, issuing authority, and expiry date. Supporting evidence of address — utility bill, bank statement, or equivalent — dated within three months. For corporate customers: certificate of incorporation, register of directors, and shareholder register. |
| 3. Business relationship details | Purpose of the account or relationship, expected transaction types, anticipated frequency and volume of transactions, source of funds, and source of wealth. This section establishes the baseline against which future transaction monitoring alerts are assessed. |
| 4. Risk assessment | Assignment of a risk rating — low, medium, or high — based on customer type, country of residence or incorporation, business sector, transaction profile, and any PEP (Politically Exposed Person) or sanctions screening result. The risk rating determines the level of due diligence applied: simplified, standard, or enhanced. |
| 5. Enhanced due diligence (EDD) — if required | Additional documentation required for high-risk customers: certified source-of-funds evidence, beneficial ownership certification to the 25% UBO threshold (or lower for higher-risk contexts), senior management approval, and a defined enhanced monitoring schedule. EDD is triggered by a high-risk rating, PEP status, high-risk country of operation, or unusual transaction patterns. |
| 6. Declaration & customer signature | Customer attestation that the information provided is accurate and complete, consent to ongoing monitoring and record retention, and signature with date. For corporate customers: signature of an authorized signatory with evidence of authority (board resolution or power of attorney). |
A standard customer due diligence form — covering sections 1 through 4 and 6 — applies to the majority of customers who present a low or medium risk profile. Section 5, the enhanced due diligence component, is activated by a risk trigger: PEP status, beneficial ownership complexity, a high-risk jurisdiction, or suspicious activity. When triggered, this section effectively becomes a separate enhanced due diligence form layered on top of the standard CDD record — an escalation, not part of every completion.
CDD form for individuals vs. companies
An individual CDD form and a corporate CDD form share the same six-section structure, but the content of each section differs substantially. For an individual, identity verification relies on government-issued personal documents and proof of address. For a company, verification requires corporate registration documents, constitutional documents (articles of association or equivalent), and a register of directors and shareholders.
Beneficial ownership is the most operationally significant difference. Beneficial owner verification for a natural person simply confirms that the person is themselves the beneficial owner of the funds or relationship. For a corporate customer, the compliance officer must identify every natural person who ultimately owns or controls 25% or more of the entity — or, in some jurisdictions and risk contexts, 10% or more.
Where ownership is layered through holding companies, trusts, or nominee arrangements, the ownership chain must be traced until the natural-person UBOs are identified. This process can require multiple corporate registry extracts, shareholder declarations, and, in some cases, legal opinions.
Partnerships, trusts, and foundations each have their own documentation requirements under most AML regimes — the FFIEC BSA/AML examination procedures provide a detailed framework for U.S. financial institutions. Non-U.S. entities should cross-reference their national AML authority guidance for equivalent requirements.
When is a customer due diligence form required?
CDD form requirements apply in defined circumstances, not at a financial institution’s discretion. Most AML frameworks — including EU AML directives and the U.S. BSA framework — specify the trigger events that obligate a regulated entity to collect CDD. Failing to apply CDD at the right trigger point constitutes a compliance breach, regardless of whether a suspicious transaction subsequently occurs.
- Opening a new business or personal account
Banks and financial institutions must follow CIP and risk-based CDD procedures when establishing a new customer relationship. Identity verification may be completed within a reasonable time after account opening, where permitted, while beneficial ownership and broader CDD requirements depend on customer type, risk profile, and applicable rules. Failure to complete required checks within permitted timeframes creates a serious compliance risk. - High-value transactions
Under the BSA, cash transactions over $10,000 generally trigger Currency Transaction Report obligations; CDD refresh or enhanced review depends on risk indicators, suspicious activity, or the institution’s risk-based procedures. Under the new EU AML Regulation, the occasional-transaction CDD threshold is reduced to EUR 10,000 from July 10, 2027; current thresholds may vary under national implementation. The transaction value alone does not determine the CDD requirement — the risk profile of the transaction and the customer’s established baseline must also be assessed. - Suspicious or unusual activity
CDD should be reviewed when customer activity appears inconsistent with the customer’s established profile, transaction history, risk rating, or expected behavior. Suspicious activity is not defined by value alone: smaller transactions can be reportable if they indicate potential money laundering, sanctions evasion, fraud, or terrorist financing risk. Compliance teams should assess behavioral anomalies, unusual counterparties, unexpected jurisdictions, changes in transaction patterns, and other red flags to determine whether enhanced review, CDD refresh, or suspicious activity reporting is required. - Regulatory compliance checks and sanctions screening updates
When a customer’s risk profile changes — they become a PEP, they are named on a sanctions list, or their country of operation is reclassified as high-risk — CDD must be reviewed and updated. Some regulated entities use automated screening tools that trigger a CDD review event upon a watchlist match. - Ongoing monitoring and customer updates.
CDD information should be reviewed and updated on a risk basis when monitoring identifies relevant changes in the customer profile, activity, or beneficial ownership. Many institutions also set internal periodic review cycles for higher-risk customers, but the exact schedule should follow internal policy, customer risk, trigger events, and applicable local rules.
Industries where CDD forms are mandatory
CDD obligations extend well beyond banks. Any entity classified as a ‘regulated business’ or ‘obliged entity’ under national AML legislation must collect CDD — a category that has expanded substantially under FATF-aligned national laws and the EU’s successive AML Directives. The AML due diligence requirements differ in specifics by jurisdiction, but the industries where mandatory CDD applies are broadly consistent:
- Banking and financial services
Retail banks, investment banks, credit unions, and payment institutions are the most heavily regulated sector. CDD obligations cover account opening, wire transfers above threshold, correspondent banking relationships, and private banking. - Real estate
Estate agents, property managers, and conveyancers are obliged entities in most developed jurisdictions. Cash-financed property transactions are a well-documented vehicle for money laundering, and CDD is required for both the buyer and the seller. - Legal services
Law firms and notaries handling client funds, company formations, real estate transactions, or trust arrangements must apply CDD before accepting instructions. The legal professional privilege exception does not override AML obligations. - Accountancy and auditing
Accountants providing tax advice, company secretarial services, or acting as a registered office are obliged entities and must apply CDD to clients at onboarding. - Insurance
Life insurance providers and insurance intermediaries are required to apply CDD, particularly for policies with a savings or investment component that can be used to launder money. - Cryptocurrency and virtual asset service providers (VASPs)
Under FATF standards, VASPs are subject to AML/CFT preventive measures, including CDD for business relationships and for occasional virtual-asset transactions above the USD/EUR 1,000 threshold. EU rules impose additional transfer-of-funds information requirements for crypto-asset transfers.
Best practices for completing a customer due diligence form
A well-completed due diligence form is not just a regulatory checkbox — it is the foundation of the customer risk record that will be reviewed in every future audit, examination, or investigation, and a key element of any sound due diligence process. The following practices reduce errors, strengthen defensibility, and align with the quality standards expected by regulators.
| Best Practice | Details |
|---|---|
| Collect information accurately and consistently. | Use standardized form templates across all teams and channels. Inconsistency in how fields are completed — different formats for dates, abbreviated names, missing middle names — creates matching problems during sanctions screening and makes periodic review difficult. |
| Verify identification using official government documents. | Passports, national identity cards, and government-issued driving licenses are the accepted forms of verification in most jurisdictions. Verify that documents are current and that details match across all fields. Where digital identity verification is used, ensure the tool is recognized by your regulator. |
| Screen against sanctions and PEP lists at point of collection. | Do not wait until the form is complete before screening. Real-time screening during the onboarding process prevents the bank or business from inadvertently establishing a relationship with a sanctioned entity or politically exposed person. Screening must also cover connected parties: beneficial owners, directors, and authorized signatories. |
| Assess risk before assigning a CDD level. | Apply a risk-based approach CDD to determine whether the customer requires simplified, standard, or enhanced due diligence. Simplified CDD is available for genuinely low-risk customers — certain government entities, publicly traded companies — but must be documented. Applying simplified CDD by default, without a documented risk assessment, is a breach of the risk-based approach and will be challenged in examination. |
| Document the source of funds for high-value or complex customers. | For customers presenting a medium or high risk profile, collecting a self-declaration of source of funds is insufficient. Require documentary evidence: audited accounts, tax returns, property sale agreements, or other corroborating material. Source-of-funds documentation is one of the most common deficiency findings in BSA/AML examinations. |
| Apply enhanced due diligence where triggered. | EDD is not optional when the risk rating triggers it. Any compliance officer who applies standard CDD to a high-risk customer — and documents that decision without adequate justification — creates a material compliance exposure. EDD must include a documented rationale for any risk acceptance, senior management sign-off, and a defined enhanced monitoring schedule. |
| Retain compliance records according to applicable rules. | Under FinCEN’s CDD Rule, beneficial ownership identification records must be kept for five years after account closure, while verification records must be kept for five years after the record is made. EU AML rules generally require CDD records to be retained for five years after the business relationship ends or an occasional transaction is completed, subject to national implementation and permitted extensions. |
| Establish a re-verification schedule. | Build periodic CDD review triggers into your compliance program. A high-risk customer file that has not been reviewed in three years is a compliance vulnerability, even if no triggering event has occurred. Automated reminders or workflow tasks in your CRM or compliance system ensure reviews are completed on schedule. |
| Apply a risk-based approach to form depth. | Not every customer requires the same level of detail on every field. A low-risk retail banking customer and a high-risk corporate client in a high-risk jurisdiction should have materially different CDD file depths. The customer due diligence process is most effective when form content scales proportionately with risk. |
| Leverage digital tools and automation to reduce manual errors. | Manual CDD form completion introduces transcription errors, missed fields, and inconsistencies, creating audit risks. Digital CDD workflows — whether within a compliance platform or supported by a virtual data room — enforce field completion, time-stamp submissions, and generate an audit record that is reviewable without manual reconstruction. |
Well-completed CDD forms contain sensitive personally identifiable information (PII) and corporate confidential data that must be stored and shared with appropriate controls in place. Emailing scanned forms to reviewers or storing them on shared drives without access logging creates both a data protection risk and an AML compliance vulnerability. Secure, access-controlled document environments address this gap directly.
Using virtual data rooms for customer due diligence
Customer due diligence forms contain some of the most sensitive information a regulated business handles: passport copies, tax identification numbers, corporate ownership structures, and financial statements.
Sharing client due diligence forms with regulators, counterparties, or external compliance advisers via unencrypted email or consumer-grade file-sharing tools creates two overlapping risks: a data protection breach under GDPR or equivalent privacy regulation, and an audit trail failure that regulators will flag when examining whether CDD records are adequately protected and retrievable.
A virtual data room provides the infrastructure to share, store, and manage CDD documentation with the level of control required by compliance environments. For teams handling regulated customer records, data room compliance helps connect document security, access control, audit trails, and retention practices with AML, privacy, and internal governance requirements.
Key capabilities include:
- Secure document sharing with granular access permissions — restricting access to specific files by user, role, or reviewer group.
- Encryption for documents in transit and at rest, supporting secure handling of sensitive PII.
- Audit trails that log every document view, download, and access event — providing a reviewable record that can be produced to regulators on request.
- Multi-factor authentication for all users, preventing unauthorized access to CDD files even if login credentials are compromised.
- Version control, ensuring that updated CDD records replace earlier versions in a traceable sequence — critical during periodic re-verification.
- Time-limited access settings, allowing compliance teams to grant a regulator or external auditor time-bounded access to a defined set of CDD files without permanent access to the full document repository.
Ideals VDR is ISO 27001-certified and has SOC 2 assurance reporting — the two primary internationally recognized standards for information security management and operational controls. Its audit trail functionality helps record document activity, such as access and review events, supporting internal accountability and regulatory recordkeeping.
For compliance officers managing a periodic CDD review cycle or responding to a regulatory examination, the ability to produce a timestamped access record without manual reconstruction significantly reduces the operational burden of a regulatory request.
Conclusion
A CDD form is a core AML/KYC document that helps regulated businesses collect data on customer identity, beneficial ownership, relationship purpose, and risk assessment. Its depth should match the customer’s risk level: simplified for low-risk customers, standard for most relationships, and enhanced for higher-risk cases.
For banks, the FinCEN CDD framework requires customer verification, beneficial owner identification, understanding the nature and purpose of the relationship, and ongoing monitoring. Corporate CDD is especially complex because ownership must be traced to the natural-person level across holding structures.
CDD records should be updated on a risk-based schedule and supported by clear documentation, source-of-funds evidence, and audit-ready monitoring records. Digital CDD workflows help reduce manual errors, enforce required fields, and create the records regulators expect during examinations.
FAQ
Customer due diligence is required under AML/KYC rules across many regulated sectors, while the specific forms, fields, and documentation requirements vary by jurisdiction and customer type. It is required under AML frameworks, including the U.S. Bank Secrecy Act, EU AML Directives, and FATF Recommendations, and must be completed before establishing a customer relationship and updated on a risk-based schedule thereafter.
The four core elements of the customer due diligence process — as defined by FinCEN’s CDD Rule and aligned with FATF Recommendation 10 — are: (1) identifying and verifying the customer’s identity, (2) identifying and verifying the identity of beneficial owners of legal entity customers, (3) understanding the nature and purpose of the customer relationship, and (4) conducting ongoing monitoring to maintain up-to-date customer information and identify suspicious activity. All four elements must be documented to meet CDD form requirements.
CDD must be applied when establishing a new customer relationship, when a customer conducts a high-value occasional transaction (typically $10,000 / EUR 10,000 or above), when there is suspicion of money laundering or terrorist financing, regardless of transaction size, when there is doubt about the accuracy of existing identification data, and on a periodic risk-based schedule during ongoing customer relationships. The enhanced due diligence threshold is triggered by a high-risk rating, PEP status, or high-risk jurisdiction of operation.
CDD requirements apply to any entity classified as an ‘obliged entity’ or ‘covered financial institution’ under applicable AML law. This includes banks and credit unions, investment firms, payment service providers, money transfer operators, insurance companies, accountants, law firms handling client funds, real estate agents, notaries, trust and company service providers, and virtual asset service providers (VASPs), including cryptocurrency exchanges. The exact scope of obliged entities varies by jurisdiction, but broadly follows FATF’s Recommendations on which sectors are subject to AML obligations.
Failure to complete CDD — or completing it inadequately — exposes a regulated business to regulatory fines, license suspension, and, in serious cases, criminal prosecution of responsible officers. Standard Chartered’s $1.1 billion fine for AML failures, including deficiencies in its customer due diligence processes, is among the most cited examples. Regulatory authorities, including FinCEN, the FCA, and the ECB’s supervisory arm, have demonstrated consistent willingness to impose material penalties for CDD failures across the banking sector.
A KYC form focuses specifically on who the customer is — collecting identity information and verification documents to confirm the customer’s claimed identity. A CDD form is broader: it combines identity verification with a risk assessment of the customer relationship, including source of funds, beneficial ownership, and the expected nature and purpose of the business relationship. KYC is a component of CDD, not a substitute for it. Completing a KYC form without the broader CDD elements does not satisfy the full AML obligation under most regulatory frameworks.
A CDD form banking version follows the FinCEN CDD Final Rule’s four requirements: customer identity fields, beneficial ownership certification (collecting the identity of all natural persons owning 25% or more of a legal entity, and at least one control person), a section establishing the nature and purpose of the account relationship, and an ongoing monitoring acknowledgment.