Customer Due Diligence Checklist: Key Steps for AML

07 October 2026 | Industry Intel

A customer due diligence checklist sets out the verification and risk assessment steps financial institutions must complete before and throughout a customer relationship to meet AML obligations.

CDD programs fail examination when individual controls run in isolation, without a coherent and auditable program behind them. For instance, when the FCA fined Starling Bank £29 million in 2024, the bank had opened more than 54,000 accounts for high-risk customers while under an explicit regulatory requirement not to do so. This indicated a CDD control failure that continued even after the bank’s own risk assessment had flagged the breach. 

The checklist below covers each required step and the evidence compliance teams need to identify where their program is examination-ready and where records are incomplete.

Key takeaways:

  • Risk classification must come before document collection

The tier assigned to a customer determines which documents to collect, which screens to run, and when senior approval is needed. Reversing that sequence means the program is scoped after the fact rather than designed for the risk.

  • Collecting a document and verifying it are two separate steps

Filing a passport copy satisfies the collection requirement. Cross-referencing it against an official registry satisfies the verification requirement. Regulators expect both, and enforcement records show the second step is where programs most often fall short.

  • PEP obligations aren’t uniform across all PEP categories

Senior management approval and source of wealth documentation are mandatory for foreign PEPs. For domestic PEPs and international organization PEPs, both apply only where the risk is assessed as high. Treating all PEPs identically either overburdens low-risk relationships or under-controls high-risk ones.

  • Fixed-calendar reviews miss risk that changes between review dates

A customer who clears every screen at onboarding can become a PEP, appear in adverse media, or restructure ownership with no alert until the next scheduled review. Event-triggered monitoring catches those changes when they happen, before the next scheduled review date.

  • Sigma360 connects identity verification, screening, beneficial ownership, and monitoring into one auditable workflow

Each CDD step produces its own evidence requirements. Sigma360 ensures every check, disposition, and analyst decision is logged automatically across all steps, so the audit trail holds up at examination without manual reconstruction.

What is a customer due diligence checklist for AML?

A customer due diligence checklist is the operational structure behind a CDD program. It’s a step-by-step record of what must be collected, assessed, and documented at each stage of the customer lifecycle, so the program can be reconstructed and defended under examination.

FinCEN’s CDD Rule identifies four core requirements: customer identification and verification, beneficial ownership identification and verification, understanding the nature and purpose of the relationship to develop a risk profile, and ongoing monitoring for suspicious activity.

FATF Recommendation 10 sets the international standard, requiring institutions to apply these measures using a risk-based approach and scale the depth of scrutiny to the risk each customer presents. The table below shows what that looks like in practice across the three standard due diligence tiers:

 

Risk tier Due diligence level Typical review frequency Senior sign-off required
Low Simplified (SDD) Every 3–5 years No
Medium Standard (CDD) Every 12–24 months No
High / PEP Enhanced (EDD) Every 6–12 months Yes

 

Review cadences reflect industry practice and examiner expectations, not explicit statutory deadlines in FATF or FinCEN text. Institutions set their own intervals based on their risk appetite and internal policy.

The customer due diligence checklist

Each step below covers one stage of the CDD lifecycle, focusing on what it involves and what evidence of it the program needs to provide.

1. Assign a risk tier before collecting documents

Risk classification sets the scope for what follows, including which documents to collect, which screens to run, how frequently to monitor, and when senior approval is required. Applying the wrong tier in either direction (too low for a high-risk entity or uniformly high across all customers) wastes analyst capacity and leaves the program either underscoped or buried in low-value alerts.

Five factors drive the initial classification:

  • Customer type: Individual, corporate entity, trust, PEP, or non-profit
  • Geographic risk: Placement on FATF’s high-risk jurisdiction list, the EU’s list of high-risk third countries, or the institution’s own country risk matrix
  • Sector risk: Involvement in cash-intensive businesses, real estate, cryptocurrency, or precious metals
  • Delivery channel: Non-face-to-face onboarding, which carries additional controls in most jurisdictions
  • Expected activity: The anticipated transaction volume, frequency, and counterparty profile relative to the customer’s stated business purpose

Every factor belongs in the written record, alongside the identity of the assessing officer. Examiners expect a reasoned, attributable determination: The logic behind the classification must be traceable to the evidence reviewed, not to a completed form alone.

Read more: Financial Crime Compliance Framework: How to Make It Work

How a single risk tier calibrates every downstream AML control

2. Collect and verify customer identity documents

The CDD Rule treats collection and verification as distinct obligations. A customer who submits a passport has satisfied the first obligation. An institution that files it without cross-referencing against reliable, independent source documents, data, or information hasn’t satisfied the second.

The table below covers the standard documentation set for individuals and legal entities:

 

Customer type Required documentation
Individual Government-issued photo ID (verified against a document database); proof of address, typically dated within 90 days; taxpayer identification number; source of funds declaration for elevated risk profiles
Legal entity Certificate of incorporation (verified against company registry); memorandum and articles of association; proof of registered address; full director and signatory list with individual CDD verification; corporate ownership chart; audited financial statements for higher-value relationships

 

Read more: What Is Financial Crime Compliance?

3. Identify and verify beneficial ownership

Enforcement actions cite beneficial ownership failures more often than any other CDD deficiency. Multi-layered corporate arrangements are built to obscure who’s in control, and name-only checks at onboarding do nothing to penetrate them.

The CDD Rule requires institutions to identify all natural persons holding direct or indirect ownership of 25% or more of a legal entity customer, as well as one individual with significant responsibility to control, manage, or direct the entity. For higher-risk relationships, institutions may apply a lower threshold based on their own risk assessment.

The review covers six steps:

  • Identify all natural persons with direct or indirect ownership of 25% or more of the legal entity’s equity interests.
  • Apply the control test by identifying one individual with significant responsibility to control, manage, or direct the entity (typically a CEO, CFO, Managing Member, or General Partner).
  • Verify each beneficial owner’s identity to the same standard as individual customer CDD.
  • Cross-check against available beneficial ownership registers where accessible, including the UK PSC register, EU national registers, and the FinCEN Beneficial Ownership Information database for US entities (currently restricted to authorized users under the Corporate Transparency Act)
  • Identify the senior managing official where no natural person meets the ownership threshold: The CEO or equivalent becomes the default beneficial owner for FinCEN compliance.
  • Document the ownership determination in writing, including the analysis of any complex structure and the rationale for any judgment calls.

Where ownership chains involve offshore jurisdictions or multi-layer holding structures, escalate to enhanced due diligence and request a written explanation of the commercial rationale for each layer.

What a name-only check misses in a layered ownership structure

4. Screen for PEPs, sanctions, and adverse media

The table below shows what each screen type detects and what the record must contain:

 

Screen type What it detects Evidence required
Sanctions and watchlist Designated parties, blocked entities, restricted individuals Date, database version, match/no-match result, disposition
PEP screening Domestic and foreign PEPs, family members, close associates PEP category, source of wealth documentation, senior approval record
Adverse media Financial crime exposure in public sources before formal designation Materiality assessment, source credibility rating, impact on risk tier

 

PEP screening carries three obligations on top of standard CDD:

  • Screen the full legal name against databases covering domestic PEPs, foreign PEPs, international organization PEPs, and their family members and close associates.
  • Obtain senior management approval before establishing or continuing a relationship with a foreign PEP. For domestic and international organization PEPs, approval is required where the risk is assessed as high.
  • Establish source of wealth and source of funds; mandatory for foreign PEPs, risk-assessed for domestic and international organization PEPs.

Adverse media can’t be run through a manual approach. Manual searches are inconsistent, leave no audit trail, and produce nothing an examiner can assess. Every hit requires a documented materiality assessment covering the source’s credibility, its relevance to the relationship, and the impact on the customer’s risk rating.

Read more: Adverse Media Screening Guide: Definition & Importance

5. Establish ongoing monitoring and re-review triggers

The risk a customer presents at onboarding isn’t the same twelve months later. A customer who cleared every screen at account opening may become a PEP, appear in adverse media, or change their ownership structure with nothing to signal it until the next scheduled review. Fixed-calendar reviews catch these changes only if the review happens to follow the event.

Continuous monitoring triggers re-evaluation the moment risk changes, regardless of where the program sits in its review cycle.

Perpetual KYC replaces static review schedules with monitoring triggered by actual risk changes (new designations, adverse media hits, ownership shifts) rather than by calendar. Five areas must be covered:

  • Transaction patterns: Activity inconsistent with the customer’s stated business purpose, transaction history, or source of funds
  • Sanctions rescreening: Updated lists at intervals consistent with the institution’s risk profile, not the next scheduled full review
  • Adverse media monitoring: Scans for negative coverage that may not yet have triggered a formal designation
  • Change-of-circumstances triggers: Ownership changes, new adverse media hits, jurisdiction shifts, and PEP-trigger events
  • Periodic KYC refresh: Scheduled re-verification at the interval determined by the customer’s assigned risk tier

A log entry for every monitoring run should capture the database queried, the date, and the alert count produced. Without it, the control is a policy requirement, not a demonstrated one.

How fixed-calendar reviews create a monitoring gap when risk changes mid-cycle

6. Document every decision and maintain the audit trail

Regulators have cited record-keeping failures as standalone violations, independent of how well the underlying CDD was conducted. The documentation obligation is separate from the obligation to run the checks. Completing one without the other leaves a program exposed at examination.

Six elements make up a complete CDD record:

  • Identity documents: Certified copies of all ID and proof of address, stored in a tamper-evident format
  • Screening records: Date, database version, match/no-match result, and disposition for every PEP, sanctions, and adverse media check
  • Risk assessments: Written record of the risk tier assigned, the factors considered, any overrides applied, and the identity of the approving officer
  • False positive dispositions: Documented rationale for every alert closed as a non-match, including the evidence reviewed and the reasoning applied
  • SAR and STR records: Suspicious activity report filings retained separately and kept confidential from the subject of the report
  • Ongoing monitoring log: Evidence that monitoring was performed, with the specific databases queried and alert counts it produced

FATF Recommendation 11 and FinCEN regulations both require a minimum five-year retention period measured from the end of the business relationship. Records must be complete enough for a regulator to reconstruct the sequence of decisions without the institution supplying context that should’ve been captured at the time.

7. Define when and how to exit a customer relationship

Exiting a customer relationship is a compliance decision. When CDD can’t be completed, or the results reveal risk outside the institution’s risk appetite, the institution must terminate the relationship and consider making a suspicious activity report.

Four components must be documented for every exit:

  • Defined triggers: Inability to verify identity, incomplete beneficial ownership documentation, CDD revealing unacceptable risk, or sustained failure to provide requested information
  • Documented rationale: A written record of the grounds for exit, the evidence reviewed, and the decision-maker’s identity
  • SAR filing assessment: A formal consideration of the reporting obligation, with the outcome documented regardless of a filing being made
  • Notification handling: Procedures managing the exit without disclosing any related SAR filing to the customer

The table below shows how key CDD requirements vary by institution type, with the FFIEC BSA/AML Examination Manual providing the examiner-level detail for US-regulated institutions:

 

Institution type Key CDD variation Beneficial ownership threshold Primary regulatory framework
Bank Full CDD Rule obligations; CTR and SAR filing 25% (lower threshold at institution’s discretion) FinCEN CDD Rule, BSA, FFIEC
Fintech/payments Risk-based program; API-driven onboarding common 25% (lower threshold at institution’s discretion) FinCEN CDD Rule, state MTL requirements
Asset manager Greater exposure to PEPs and complex ownership structures 25% FinCEN CDD Rule, SEC
Regulated corporate Industry-specific regimes; may rely on third-party CDD Varies by jurisdiction FATF Rec 10, local AML law

Where Sigma360 fits in the CDD workflow

Sigma Homepage

CDD generates obligations across multiple control areas (identity verification, beneficial ownership, screening, monitoring, and documentation), each with its own data requirements and evidence standards. Running them in silos is what breaks the audit trail.

Based on internal data, Sigma360’s EDD Agent cuts data-gathering time by 87% and operates at the equivalent capacity of 90 analysts, pulling together watchlist records, corporate registry data, adverse media coverage, and proprietary derived intelligence (including shared addresses, shared directors, and nominee relationships) into a single structured review. Every analyst action and disposition is logged automatically, producing the audit trail each checklist step requires.

Sigma360’s Match Agent reduces manual match reviews by 90%, according to Sigma360 platform benchmarks, resolving false positives before they consume analyst capacity and recording each disposition with the evidence and reasoning an examiner would expect.

Perpetual KYC keeps every customer relationship under active review, triggering re-evaluation when ownership, sanctions exposure, or adverse media coverage changes rather than on a fixed calendar.

Speak to a compliance expert to walk through how Sigma360 addresses each step of this checklist, or watch the EDD Agent demo to see the platform in action.

FAQ

Which institutions are required to perform CDD?

Any financial institution subject to AML regulation, including banks, fintechs, payments companies, brokers, asset managers, and insurers. In the US, the FinCEN CDD Rule sets the specific obligations. Globally, FATF Recommendation 10 is the baseline most national frameworks are built from.

Can you rely on a third party to complete CDD on your behalf?

Yes, but the legal obligation stays with you. If the third party misses something, the institution is still liable, so any reliance arrangement needs to be documented, and the third party must operate under equivalent AML standards.

What triggers a CDD risk tier upgrade during an existing relationship?

The most common triggers are a new PEP designation, an adverse media hit, a change in ownership structure, or transaction behavior that no longer matches the customer’s stated purpose. Each should prompt a documented risk re-evaluation before the next scheduled review.

What is the difference between CDD and simplified due diligence?

Simplified due diligence (SDD) applies to customers with demonstrably low risk, such as listed companies or certain government entities. Rather than skipping checks, it means reduced frequency, depth, and documentation requirements. The institution still needs to show why SDD was appropriate.

How should a CDD program handle layered or complex ownership structures?

Look through every layer until natural persons with 25% or more ownership and one individual with significant control are identified. Offshore jurisdictions or nominee arrangements should escalate to enhanced due diligence, with the commercial rationale for each layer documented. Undocumented complexity is a risk signal in itself.

About Sigma360 | The Standard in KYC & Financial Crime Compliance

Sigma360 is an AI-powered, full-stack risk intelligence platform that consolidates operations into one enterprise-grade system, enabling point-in-time risk screening and perpetual client monitoring for financial crime prevention and compliance operations. Sigma360 unifies global risk data, proprietary intelligence, core screening technology and AI automation in a secure cloud environment to find direct and network-based risks at sub-second speed, reduce false positives and strengthen risk and compliance operations.

Sigma360.com / Schedule a Demo / Free Trial / Connect on LinkedIn

Engage with us

Our Risk Intelligence Specialists can get you the answers you need.