What Does Customer Due Diligence Mean and Who Must Comply?

Customer due diligence is the process a financial institution uses to verify your identity, understand how you intend to use your account, and monitor your transactions for signs of illegal activity. Federal rules under the Bank Secrecy Act require banks and other covered businesses to build a profile of every customer before opening an account and to keep that profile current for as long as the relationship lasts. The purpose is direct: keep criminals from using the U.S. financial system to launder money or finance terrorism.

What the Institution Collects and Verifies

The first piece of CDD is the Customer Identification Program, or CIP. Every covered institution must have written CIP procedures suited to its size and business.1eCFR. 31 CFR 1020.220 – Customer Identification Program Requirements for Banks Before or at the time you open an account, four items have to be collected from you:

  • Your full legal name.
  • Your date of birth, for individual customers.
  • A residential or business street address, or a principal place of business for an entity.
  • An identification number. For U.S. persons, that means a taxpayer identification number such as a Social Security number. For non-U.S. persons, a passport number, alien identification card number, or another government-issued document number.

The institution then verifies what you gave it. Documentary verification means checking a government-issued ID such as a driver’s license or passport. Non-documentary verification means cross-referencing your information against credit bureaus, public databases, or other reliable third-party sources. Many institutions use both. Records of what was collected and how it was verified must be kept for five years after the account closes.2FFIEC BSA/AML InfoBase. Appendix P – BSA Record Retention Requirements

Why the Bank Asks What You’ll Do With the Account

Knowing who you are isn’t the whole picture. The institution also has to understand why you’re opening the account and what kind of activity to expect. That means asking about the types of transactions you plan to conduct, the expected volume and frequency, and where the money coming into the account will originate. For a personal checking account with direct deposit, the conversation is brief. For a business handling international wires or heavy cash, it goes deeper.

Your answers form a baseline. If an account opened as a small personal savings vehicle suddenly starts moving six-figure international transfers, the gap between the baseline and the actual activity is exactly what triggers further review. For high-net-worth customers or accounts opened with large initial deposits, institutions also ask about source of wealth, not just source of individual deposits. The point is to establish that money entering the system doesn’t come from illegal activity.

Beneficial Ownership for Business Accounts

When a legal entity opens an account, the institution has to look past the company name to identify the real people behind it. Shell companies, trusts, and layered corporate structures are among the most common tools used to hide the origin of illicit money. Federal rules define a “beneficial owner” using two separate tests, and the institution must apply both.3eCFR. 31 CFR 1010.230 – Beneficial Ownership Requirements for Legal Entity Customers

The ownership test requires identifying every individual who directly or indirectly owns 25 percent or more of the entity’s equity interests. That could be zero, one, or several people. The control test requires identifying a single individual with significant management responsibility, such as a CEO, CFO, president, or managing member. The same identifying information collected from individual customers has to be collected for these beneficial owners.4FFIEC BSA/AML InfoBase. Beneficial Ownership Requirements for Legal Entity Customers

Not every entity triggers beneficial ownership collection. The regulation exempts a long list of already-regulated or publicly transparent businesses, including federally regulated financial institutions, publicly traded companies registered under the Securities Exchange Act, registered investment companies and investment advisers, SEC-registered exchanges and clearing agencies, state-regulated insurance companies, public accounting firms registered under Sarbanes-Oxley, and bank holding companies.3eCFR. 31 CFR 1010.230 – Beneficial Ownership Requirements for Legal Entity Customers

A word on the Corporate Transparency Act, which some readers will have heard about: the CTA was originally designed to build a central FinCEN registry of beneficial ownership. In March 2025, FinCEN issued an interim final rule that exempted all entities created in the United States from reporting beneficial ownership to FinCEN.5Financial Crimes Enforcement Network. FinCEN Removes Beneficial Ownership Reporting Requirements for US Companies and US Persons Only entities formed under foreign law and registered to do business in a U.S. state or tribal jurisdiction still have to file with FinCEN.6Financial Crimes Enforcement Network. Beneficial Ownership Information Reporting That change concerns reporting to FinCEN’s central database. The separate obligation on financial institutions to collect and verify beneficial ownership when a legal entity opens an account is unchanged.

Risk-Based Scrutiny and Enhanced Due Diligence

Not every customer gets the same treatment. CDD programs must include risk-based procedures, so the depth of investigation scales with the risk a particular customer, product, or geography presents.7Financial Crimes Enforcement Network. Information on Complying with the Customer Due Diligence Final Rule In practice, institutions sort customers into tiers and adjust accordingly.

A salaried employee opening a personal checking account is low-risk, and the standard CIP process is usually enough. This is sometimes called simplified due diligence. Customers presenting elevated risk get enhanced due diligence, or EDD: additional information beyond the CIP minimum, more rigorous verification, and often senior compliance staff involved in the account decision. Common triggers include:

  • Cash-intensive businesses such as restaurants, convenience stores, and car washes, where cash volume makes fund origins harder to trace.
  • Customers or transactions tied to jurisdictions with weak anti-money laundering controls or known corruption problems.
  • Complex ownership structures with layered subsidiaries, trusts, or nominee arrangements that obscure who actually owns the entity.
  • Transaction patterns with no clear business rationale, such as frequent large transfers between unrelated parties.
  • Foreign financial institution relationships, particularly correspondent banking.

Politically Exposed Persons

Politically exposed persons — individuals who hold or have held prominent public office, together with their close family and associates — are widely treated as higher risk because government authority creates opportunity for bribery or misuse of public funds. Here’s a point that surprises people: no specific BSA regulation requires banks to screen for PEPs or apply a defined set of extra steps.8FFIEC BSA/AML InfoBase. Politically Exposed Persons The obligation is more general. A well-designed risk-based program flags PEPs for enhanced review as a matter of institutional practice, often with senior management approval before opening the relationship, but that practice comes from the institution’s own risk assessment rather than a rule that names PEPs.

Ongoing Monitoring After the Account Opens

CDD doesn’t end at account opening. An institution’s anti-money laundering program has to include risk-based procedures for ongoing monitoring of every customer.9FFIEC BSA/AML InfoBase. Assessing Compliance with BSA Regulatory Requirements – Customer Due Diligence There are two parts to it.

The first is keeping customer information current. This is where even compliance professionals sometimes get things wrong: the regulation is event-driven, not calendar-driven. The CDD rule does not require refreshing every customer file on a fixed schedule. When the institution becomes aware through normal monitoring that customer information has materially changed — a new beneficial owner, a different business model, a shift in expected activity — it must update the record. Many institutions run periodic reviews on their highest-risk customers anyway, but that’s an internal choice, not a regulatory mandate.

The second is transaction monitoring. Automated systems compare actual activity against the baseline built during initial CDD, watching for anomalies: large cash deposits in an account opened for payroll, sudden spikes in international wires, rapid movement of funds through multiple accounts with no evident purpose, or transactions structured just below reporting thresholds. When the system flags something, the institution investigates. If the activity fits the customer’s profile, the matter is documented and closed. If it doesn’t, the institution files a Suspicious Activity Report with FinCEN.10eCFR. 31 CFR 1020.320 – Reports by Banks of Suspicious Transactions

Which Businesses Have To Do CDD

CDD obligations reach further than traditional banks. Federal rules define “financial institution” broadly. Covered businesses include banks and credit unions, broker-dealers in securities, money services businesses (check cashers, money transmitters, currency dealers, and providers of prepaid access), casinos and card clubs, futures commission merchants, introducing brokers in commodities, and mutual funds.11FFIEC BSA/AML InfoBase. General Definitions Each must maintain an anti-money laundering program with, at a minimum, internal policies and controls, a designated compliance officer, ongoing employee training, and an independent audit function.12Office of the Law Revision Counsel. 31 USC 5318 – Compliance, Exemptions, and Summons Authority

One notable gap: SEC-registered investment advisers are not yet subject to these requirements. FinCEN finalized a rule in 2024 that would bring them in, but in early 2026 the agency formally pushed the effective date to January 1, 2028 for further review and tailoring.

What Happens When an Institution Fails

Institutions that treat CDD as paperwork tend to learn otherwise. For willful violations of BSA requirements, a financial institution faces a civil penalty of up to the greater of the amount involved in the transaction (capped at $100,000) or $25,000 per violation.13Office of the Law Revision Counsel. 31 USC 5321 – Civil Penalties “Per violation” is important, because each day a violation continues and each branch where it occurs counts separately. For violations of special due diligence requirements, the floor is twice the transaction amount, with a ceiling of $1 million. Criminal penalties under 31 USC 5322 also apply, especially where violations are willful.

Real-world numbers dwarf the statutory minimums. In the largest BSA enforcement action in Treasury history, FinCEN assessed a $3.4 billion civil penalty against a single institution for systemic failures in its anti-money laundering program. Beyond fines, institutions that fail BSA examinations face formal enforcement actions from their primary regulator, including cease-and-desist orders, removal of officers and directors, and restrictions on opening new accounts or expanding operations.14Internal Revenue Service. IRM 4.26.7 – Bank Secrecy Act Penalties For a bank, a broken CDD program is a business risk on the order of losing the charter itself.