Skip to main content
Category: Customer Due Diligence

Standard Due Diligence

Also known as: SDD, Standard Customer Due Diligence, Standard CDD
Simply put

Standard Due Diligence is the usual level of checks a financial institution or other obliged entity carries out to identify and understand a customer whose risk is assessed as low-to-medium. It typically involves collecting and verifying basic information about who the customer is before and during a business relationship. It generally sits between simplified due diligence, applied to lower-risk situations, and enhanced due diligence, applied to higher-risk ones.

Formal definition

Standard Due Diligence refers to the baseline set of Customer Due Diligence (CDD) measures applied to customers assessed as presenting a low-to-medium money laundering or terrorist financing risk, and is generally the most commonly applied CDD level. It typically encompasses identifying the customer and verifying that identity, and, where applicable, understanding the nature and purpose of the business relationship and conducting ongoing monitoring, though the precise components and thresholds derive from the applicable regime rather than a single global standard (for example, the CDD Rule administered by FinCEN sets requirements for covered U.S. financial institutions such as banks, mutual funds, and brokers or dealers in securities). Standard Due Diligence should be distinguished from Enhanced Due Diligence (EDD), a deeper and more comprehensive review reserved for higher-risk customers or situations, and from Simplified Due Diligence, applied in lower-risk scenarios; the appropriate level is determined on a risk-based basis, and exact obligations, scope, and any exemptions should be confirmed against the relevant regulation in the applicable jurisdiction.

Why it matters

Standard Due Diligence sits at the operational core of most AML programs because it is generally the most commonly applied level of Customer Due Diligence. The vast majority of customer relationships are assessed as low-to-medium risk, meaning SDD represents the baseline through which obliged entities identify and understand the people and entities they do business with. Where this baseline is poorly designed or inconsistently executed, weaknesses cascade across the wider control framework, since risk-based decisions to escalate to Enhanced Due Diligence or to apply Simplified Due Diligence depend on the quality of the information gathered at the standard level in the first place.

Getting the calibration right matters because SDD is intended to detect, deter, and mitigate money laundering and terrorist financing risk rather than to guarantee its prevention. Applying too little scrutiny to a customer who warrants a deeper review, or over-applying resources to genuinely low-risk relationships, both undermine the risk-based approach that underpins modern AML regimes. The line between SDD and EDD is a judgment informed by risk assessment, not a mechanical test, and firms must be able to justify why a given customer was placed at the standard level.

The precise components and thresholds of Standard Due Diligence are not defined by a single global standard; they derive from the applicable regime, such as the CDD Rule administered by FinCEN for covered U.S. financial institutions. Because obligations, scope, and exemptions vary by jurisdiction and by type of obliged entity, firms operating across borders should confirm exact requirements against the relevant regulation rather than assume a uniform rule applies everywhere.

Who it's relevant to

Compliance officers and MLROs
Those responsible for designing and overseeing AML programs must define what Standard Due Diligence entails for their firm, calibrate the thresholds at which relationships escalate to Enhanced Due Diligence or qualify for Simplified Due Diligence, and be able to justify these decisions on a risk-based basis. Because SDD is generally the most commonly applied CDD level, its design has outsized influence on the effectiveness and efficiency of the wider control framework.
Onboarding and KYC operations teams
Front-line staff performing customer identification and verification apply Standard Due Diligence to the majority of relationships. They collect and verify basic information about who the customer is, and, where applicable, capture the nature and purpose of the business relationship, referring cases upward where risk indicators suggest a deeper review may be warranted.
U.S. financial institutions covered by the CDD Rule
Banks, mutual funds, and brokers or dealers in securities, among other covered institutions, are subject to customer due diligence requirements administered by FinCEN. For these entities, the specific components of their due diligence obligations should be confirmed against the CDD Rule and applicable Bank Secrecy Act requirements rather than assumed from general practice.
Obliged entities operating across multiple jurisdictions
Firms subject to more than one AML regime must recognize that the precise scope, thresholds, and exemptions for Standard Due Diligence are not defined by a single global standard and can differ meaningfully between jurisdictions. They should map their obligations to each applicable regulation to ensure consistent, defensible application of the risk-based approach.

Inside SDD

Customer Identification
The process of obtaining and recording identifying information about a customer, such as name, address, date of birth (for natural persons), or registered details (for legal entities). This typically forms the entry point of standard due diligence for obliged entities.
Identity Verification
Confirming the customer's identity using reliable, independent source documents, data, or information. Standard due diligence generally requires verification using credible sources rather than reliance on customer assertions alone.
Beneficial Ownership Identification
Identifying the natural person(s) who ultimately own or control a customer that is a legal entity or arrangement, and taking reasonable measures to verify that identity. This is distinct from legal ownership, which reflects the registered or titular holder rather than the ultimate controlling person.
Purpose and Intended Nature of the Relationship
Obtaining information on the purpose and intended nature of the business relationship, which supports the establishment of a customer risk profile and provides a baseline against which future activity can be assessed.
Ongoing Monitoring
Scrutinising transactions and activity throughout the relationship to ensure they remain consistent with the customer's profile, and keeping the underlying CDD information current. Ongoing monitoring is generally treated as an integral, continuing component rather than a one-off event at onboarding.
Risk-Based Application
Standard due diligence is generally the baseline set of measures applied where risk is assessed as normal, positioned between simplified due diligence (in lower-risk situations) and enhanced due diligence (in higher-risk situations). The intensity of measures is calibrated to the assessed risk.

Common questions

Answers to the questions practitioners most commonly ask about SDD.

Is Standard Due Diligence the same as KYC?
No. KYC (Know Your Customer) and Standard Due Diligence are related but not interchangeable. KYC generally refers to the broader set of processes for identifying and understanding a customer, while Standard Due Diligence (often referred to as Customer Due Diligence, or CDD) is the specific set of measures obliged entities apply in typical, lower-to-normal risk situations. Standard Due Diligence sits within the wider KYC and CDD framework, and terminology varies by jurisdiction, so the applicable regime's definitions should always be confirmed.
Does applying Standard Due Diligence mean a customer poses no money laundering risk?
No. Standard Due Diligence is a set of measures to help detect, deter, and manage risk in situations assessed as normal or lower risk; it does not guarantee that a customer poses no risk, nor does it eliminate financial crime risk. Where risk factors are elevated, Enhanced Due Diligence (EDD) is typically required instead. Standard Due Diligence reflects a risk-based judgment about the level of scrutiny applied, not a conclusion that no risk exists.
When can an obliged entity apply Standard Due Diligence rather than Enhanced Due Diligence?
Standard Due Diligence is generally applied where a risk assessment does not identify factors warranting enhanced scrutiny. In many jurisdictions, higher-risk indicators, such as certain politically exposed person (PEP) relationships, higher-risk geographies, complex ownership structures, or specified higher-risk transaction types, trigger EDD instead. The determination should be documented and based on the entity's risk assessment and the criteria set out in the applicable regime, which should be confirmed against the relevant regulation.
What core measures does Standard Due Diligence typically involve?
In many regimes, Standard Due Diligence typically includes identifying the customer and verifying that identity on a reliable, independent basis; identifying beneficial owners and taking reasonable measures to verify their identity; understanding the nature and intended purpose of the business relationship; and conducting ongoing monitoring. The exact required elements and verification standards vary by jurisdiction and by the type of obliged entity, so the applicable instrument, such as the relevant AML directives or regulations, national money laundering regulations, or FinCEN rules, should be consulted.
How does ongoing monitoring fit within Standard Due Diligence?
Ongoing monitoring is generally treated as a continuing component of Standard Due Diligence rather than a one-time onboarding step. It typically involves scrutinising transactions to check consistency with what is known about the customer and keeping identification and other information up to date. The frequency and depth of monitoring are usually calibrated to assessed risk, and specific expectations should be confirmed against the applicable regulatory framework.
Can Standard Due Diligence be escalated to Enhanced Due Diligence during a relationship?
Yes. Because the level of due diligence is risk-based, a relationship initially subject to Standard Due Diligence may need to be escalated to Enhanced Due Diligence if new information or changes in circumstances raise the assessed risk, for example, changes in ownership, transaction patterns, or the customer's status. Firms generally maintain processes to reassess risk on a trigger or periodic basis, in line with the requirements of the applicable regime.

Common misconceptions

Standard due diligence (CDD) and KYC are the same thing.
KYC (Know Your Customer) is often used loosely to describe identification and onboarding activities, whereas customer due diligence is the broader, defined set of measures used in many AML regimes that includes identification, verification, beneficial ownership, understanding the purpose of the relationship, and ongoing monitoring. Terminology varies by jurisdiction, and the two should not be treated as interchangeable in a compliance context.
Standard due diligence is completed once at onboarding and does not need to be revisited.
In many jurisdictions, standard due diligence includes an ongoing obligation to monitor activity and keep information up to date over the life of the relationship. It is generally a continuing process, not a single point-in-time exercise.
There is one universal standard due diligence requirement that applies identically everywhere.
While the FATF Recommendations provide influential standards, the specific obligations, thresholds, and definitions are implemented through instruments such as the EU AML Directives and AML Regulation, the US Bank Secrecy Act and FinCEN rules, and the UK Money Laundering Regulations, which diverge in detail. Exact requirements should be confirmed against the applicable regime.

Best practices

Calibrate the depth of standard due diligence to the assessed customer risk, escalating to enhanced due diligence where higher-risk factors are present and reserving simplified measures for lower-risk situations that meet the applicable criteria.
Verify identity and, for legal entities, beneficial ownership using reliable, independent sources rather than relying solely on information provided by the customer.
Document the purpose and intended nature of the relationship at onboarding to establish a clear baseline profile against which future activity can be assessed.
Treat ongoing monitoring as a continuous obligation, refreshing CDD information on a risk-sensitive basis and reviewing whether activity remains consistent with the customer's profile.
Confirm the specific standard due diligence obligations, thresholds, and definitions against the applicable jurisdiction's instruments, since requirements diverge across regimes and should not be assumed to be uniform.
Maintain clear records of the due diligence measures taken and the rationale for the risk rating applied, so that decisions can be evidenced and reviewed.