Skip to main content
Category: Customer Due Diligence

CDD Rule

Also known as: CDD Rule, Customer Due Diligence Rule, CDD Final Rule, FinCEN CDD Rule
Simply put

The CDD Rule is a US regulation issued by FinCEN that amends Bank Secrecy Act rules to require certain financial institutions to understand who their customers are and, for many legal-entity customers, who ultimately owns or controls them. Its aim is to improve financial transparency and make it harder for criminals and terrorists to misuse companies to hide illicit activity. It is a compliance obligation for covered institutions, not a determination that any customer has done anything wrong.

Formal definition

The CDD Rule is a FinCEN regulation amending Bank Secrecy Act requirements that codifies customer due diligence obligations for covered financial institutions. According to the evidence, the objective of CDD is to enable an institution to understand the nature and purpose of the customer relationship so that it can comply with regulatory requirements, and the Rule requires covered institutions to identify and verify beneficial owners of legal-entity customers as well as to monitor and, on a risk basis, update customer information (including beneficial ownership information). The Rule is US-specific and applies to covered financial institutions as defined under the applicable BSA regulations; the precise scope of covered entities, applicable thresholds, and exemptions should be confirmed against the regulation itself. It should be distinguished from broader CDD/KYC processes and from enhanced due diligence, and it is regulatory in nature rather than a criminal-law standard; beneficial ownership under the Rule refers to identifying individuals who ultimately own or control a legal-entity customer and is distinct from legal ownership.

Why it matters

The CDD Rule addresses a longstanding vulnerability in the financial system: the misuse of legal entities to obscure who ultimately benefits from an account or transaction. By requiring covered financial institutions to identify and verify the beneficial owners of many legal-entity customers, the Rule aims to improve financial transparency and make it harder for criminals and terrorists to hide behind corporate structures. For compliance professionals, it formalizes beneficial ownership identification as a defined regulatory expectation under the Bank Secrecy Act rather than leaving it to institutional discretion.

Beyond the initial identification step, the Rule ties customer due diligence to ongoing monitoring. It requires covered institutions to understand the nature and purpose of customer relationships and, on a risk basis, to monitor for and update customer information, including beneficial ownership information. This connects onboarding to the broader AML program, supporting the institution's ability to detect activity that is inconsistent with what it knows about a customer and to comply with related regulatory requirements. It is important to understand these as measures to detect and manage risk, not guarantees that illicit activity will be prevented.

Compliance professionals should also be careful about what the Rule does and does not establish. It is a regulatory obligation for covered institutions, not a criminal-law standard, and collecting or verifying beneficial ownership information is not itself a determination that a customer has done anything wrong. The precise scope of covered entities, applicable thresholds, and exemptions should be confirmed against the regulation itself, as the definition here is drawn from FinCEN's framing and should not be treated as an exhaustive account of the Rule's requirements.

Who it's relevant to

Compliance Officers at Covered Financial Institutions
Compliance officers responsible for BSA/AML programs must operationalize the CDD Rule's requirements, including identifying and verifying beneficial owners of legal-entity customers and building risk-based processes to monitor and update customer information. They should confirm which of their institution's activities and customers fall within the Rule's scope and which exemptions may apply, referring to the regulation itself for definitive answers.
Financial Intelligence Analysts and Investigators
Analysts and investigators rely on the customer and beneficial ownership information gathered under the Rule to understand the nature and purpose of relationships and to assess whether activity is consistent with what the institution knows about a customer. This information supports detection efforts but does not by itself establish wrongdoing.
Onboarding and KYC Teams
Teams handling customer onboarding apply the Rule's identification and verification steps for legal-entity customers, distinguishing beneficial ownership from legal ownership. They also feed into the ongoing, risk-based updating of customer information, connecting onboarding data to the institution's continuing monitoring obligations.
Legal and Risk Professionals
Legal and risk professionals advising covered institutions need to understand that the CDD Rule is a US-specific regulatory obligation under the Bank Secrecy Act, not a criminal-law standard, and should be careful to confirm the precise scope of covered entities, thresholds, and exemptions against the regulation and applicable FinCEN guidance.

Inside CDD Rule

Customer Identification and Verification
The requirement to identify the customer and verify that identity using reliable, independent source documents, data, or information. This is a foundational element and is generally distinct from the broader ongoing customer due diligence obligations that follow.
Beneficial Ownership Identification
For legal entity customers, the obligation to identify and verify the natural persons who are beneficial owners, typically under an ownership prong (natural persons owning a specified equity threshold) and a control prong (an individual with significant managerial control). Beneficial ownership should not be conflated with legal ownership recorded on incorporation documents.
Understanding Nature and Purpose of the Relationship
Developing an understanding of the nature and purpose of the customer relationship in order to establish a customer risk profile against which activity can be assessed. This is an analytical expectation rather than a documentary formality.
Ongoing Monitoring
Conducting ongoing monitoring to identify and report suspicious transactions and, on a risk basis, to maintain and update customer information. This links the CDD Rule to suspicious activity reporting obligations and to the risk-based approach.
Applicable Obliged Entities and Scope
In the US context, the CDD Rule under FinCEN regulations applies to covered financial institutions as defined by that rule; scope, thresholds, and exemptions are set by the applicable regulation and should be confirmed against it. Terminology and specific requirements differ in other regimes such as the EU AML framework and the UK Money Laundering Regulations.

Common questions

Answers to the questions practitioners most commonly ask about CDD Rule.

Does the CDD Rule apply to all businesses that handle money?
No. The CDD Rule under the US Bank Secrecy Act framework, adopted by FinCEN, applies to covered financial institutions as defined in the rule, not to every business that handles funds. Entities outside the defined categories of obliged financial institutions generally fall outside its scope. The precise list of covered institutions should be confirmed against the applicable FinCEN regulation, and other obliged entities may be subject to different CDD-related obligations under separate rules.
Is completing CDD the same thing as verifying a customer's identity through KYC?
Not exactly. KYC (know your customer) is often used broadly and, in some usages, focuses on identifying and verifying the customer. CDD is a broader concept that typically encompasses identifying and verifying the customer, understanding the nature and purpose of the customer relationship to develop a risk profile, and conducting ongoing monitoring. Under the US CDD Rule, these components are treated as distinct pillars, so identity verification alone does not satisfy the full obligation. Terminology and emphasis vary by jurisdiction and institution.
What are the core components a covered institution must address under the CDD Rule?
The CDD Rule is generally described as resting on core pillars that include identifying and verifying the identity of customers, identifying and verifying the identity of beneficial owners of legal entity customers, understanding the nature and purpose of customer relationships to develop a customer risk profile, and conducting ongoing monitoring to identify and report suspicious activity and to maintain and update customer information. Institutions should confirm the exact requirements against the applicable FinCEN regulation and their own risk-based procedures.
How does the CDD Rule's approach to beneficial ownership work in practice?
For legal entity customers, the CDD Rule generally requires covered institutions to identify and verify beneficial owners at account opening, typically addressing both an ownership prong and a control prong. Beneficial ownership here refers to the natural persons behind a legal entity, which is distinct from the legal ownership recorded in formal documents. The specific ownership thresholds, exclusions, and verification methods should be confirmed against the applicable FinCEN rule and coordinated with any separate beneficial ownership reporting regimes that may apply.
How should ongoing monitoring under the CDD Rule be operationalized?
Ongoing monitoring is generally implemented on a risk basis and involves reviewing customer activity to identify and, where appropriate, report suspicious activity, as well as maintaining and updating customer information, including risk profiles, when relevant. This is an operational, risk-based measure intended to help detect and manage financial crime risk rather than a guarantee of prevention. The frequency and intensity of monitoring typically vary with the assessed risk of the customer relationship.
Does a customer's risk profile or a monitoring alert generated under CDD indicate wrongdoing?
No. A customer risk profile is a compliance tool used to calibrate the level of due diligence and monitoring applied to a relationship, and a monitoring alert flags activity for review. Neither establishes that a customer has engaged in criminal conduct. Any determination of wrongdoing is a matter for the appropriate authorities under criminal law, and CDD outputs should be treated as risk-management inputs rather than findings of guilt.

Common misconceptions

The CDD Rule and KYC are the same thing.
KYC is a broader, often operational umbrella term, while the CDD Rule refers to specific regulatory obligations. CDD itself is also distinct from enhanced due diligence (EDD), which applies additional scrutiny to higher-risk customers or relationships. These concepts are related but not interchangeable.
Identifying beneficial owners means identifying whoever legally owns the company on paper.
Beneficial ownership focuses on the natural persons who ultimately own or control the entity, typically assessed through ownership and control prongs. This can differ from the legal ownership shown in registration documents, particularly where nominee arrangements or layered structures are present.
Completing CDD requirements prevents money laundering.
CDD is a set of measures to detect, deter, and manage financial crime risk, not a guarantee of prevention. Meeting the requirements supports a risk-based program but does not eliminate risk or establish that any customer or transaction is lawful.

Best practices

Confirm the precise scope, thresholds, and exemptions applicable to your institution against the governing regulation rather than assuming a single global standard, as requirements diverge across the US CDD Rule, the EU AML framework, and the UK Money Laundering Regulations.
Treat identification and verification, beneficial ownership determination, understanding of relationship purpose, and ongoing monitoring as distinct components, and document how each is satisfied.
Apply both the ownership and control prongs when identifying beneficial owners of legal entity customers, and reconcile findings against legal ownership records to detect nominee or layered structures.
Use the customer risk profile established at onboarding as the baseline for ongoing monitoring, and update customer information on a risk-sensitive basis rather than only at fixed intervals.
Calibrate the depth of due diligence to assessed risk, reserving enhanced due diligence for higher-risk customers and relationships while avoiding treating standard CDD as a substitute for it.
Ensure monitoring outputs feed into suspicious activity reporting processes, and train staff that an alert, match, or filing reflects a risk signal and does not by itself establish wrongdoing.