CDD Rule
The CDD Rule is a US regulation issued by FinCEN that amends Bank Secrecy Act rules to require certain financial institutions to understand who their customers are and, for many legal-entity customers, who ultimately owns or controls them. Its aim is to improve financial transparency and make it harder for criminals and terrorists to misuse companies to hide illicit activity. It is a compliance obligation for covered institutions, not a determination that any customer has done anything wrong.
The CDD Rule is a FinCEN regulation amending Bank Secrecy Act requirements that codifies customer due diligence obligations for covered financial institutions. According to the evidence, the objective of CDD is to enable an institution to understand the nature and purpose of the customer relationship so that it can comply with regulatory requirements, and the Rule requires covered institutions to identify and verify beneficial owners of legal-entity customers as well as to monitor and, on a risk basis, update customer information (including beneficial ownership information). The Rule is US-specific and applies to covered financial institutions as defined under the applicable BSA regulations; the precise scope of covered entities, applicable thresholds, and exemptions should be confirmed against the regulation itself. It should be distinguished from broader CDD/KYC processes and from enhanced due diligence, and it is regulatory in nature rather than a criminal-law standard; beneficial ownership under the Rule refers to identifying individuals who ultimately own or control a legal-entity customer and is distinct from legal ownership.
Why it matters
The CDD Rule addresses a longstanding vulnerability in the financial system: the misuse of legal entities to obscure who ultimately benefits from an account or transaction. By requiring covered financial institutions to identify and verify the beneficial owners of many legal-entity customers, the Rule aims to improve financial transparency and make it harder for criminals and terrorists to hide behind corporate structures. For compliance professionals, it formalizes beneficial ownership identification as a defined regulatory expectation under the Bank Secrecy Act rather than leaving it to institutional discretion.
Beyond the initial identification step, the Rule ties customer due diligence to ongoing monitoring. It requires covered institutions to understand the nature and purpose of customer relationships and, on a risk basis, to monitor for and update customer information, including beneficial ownership information. This connects onboarding to the broader AML program, supporting the institution's ability to detect activity that is inconsistent with what it knows about a customer and to comply with related regulatory requirements. It is important to understand these as measures to detect and manage risk, not guarantees that illicit activity will be prevented.
Compliance professionals should also be careful about what the Rule does and does not establish. It is a regulatory obligation for covered institutions, not a criminal-law standard, and collecting or verifying beneficial ownership information is not itself a determination that a customer has done anything wrong. The precise scope of covered entities, applicable thresholds, and exemptions should be confirmed against the regulation itself, as the definition here is drawn from FinCEN's framing and should not be treated as an exhaustive account of the Rule's requirements.
Who it's relevant to
Inside CDD Rule
Common questions
Answers to the questions practitioners most commonly ask about CDD Rule.