Standard Due Diligence
Standard Due Diligence is the usual level of checks a financial institution or other obliged entity carries out to identify and understand a customer whose risk is assessed as low-to-medium. It typically involves collecting and verifying basic information about who the customer is before and during a business relationship. It generally sits between simplified due diligence, applied to lower-risk situations, and enhanced due diligence, applied to higher-risk ones.
Standard Due Diligence refers to the baseline set of Customer Due Diligence (CDD) measures applied to customers assessed as presenting a low-to-medium money laundering or terrorist financing risk, and is generally the most commonly applied CDD level. It typically encompasses identifying the customer and verifying that identity, and, where applicable, understanding the nature and purpose of the business relationship and conducting ongoing monitoring, though the precise components and thresholds derive from the applicable regime rather than a single global standard (for example, the CDD Rule administered by FinCEN sets requirements for covered U.S. financial institutions such as banks, mutual funds, and brokers or dealers in securities). Standard Due Diligence should be distinguished from Enhanced Due Diligence (EDD), a deeper and more comprehensive review reserved for higher-risk customers or situations, and from Simplified Due Diligence, applied in lower-risk scenarios; the appropriate level is determined on a risk-based basis, and exact obligations, scope, and any exemptions should be confirmed against the relevant regulation in the applicable jurisdiction.
Why it matters
Standard Due Diligence sits at the operational core of most AML programs because it is generally the most commonly applied level of Customer Due Diligence. The vast majority of customer relationships are assessed as low-to-medium risk, meaning SDD represents the baseline through which obliged entities identify and understand the people and entities they do business with. Where this baseline is poorly designed or inconsistently executed, weaknesses cascade across the wider control framework, since risk-based decisions to escalate to Enhanced Due Diligence or to apply Simplified Due Diligence depend on the quality of the information gathered at the standard level in the first place.
Getting the calibration right matters because SDD is intended to detect, deter, and mitigate money laundering and terrorist financing risk rather than to guarantee its prevention. Applying too little scrutiny to a customer who warrants a deeper review, or over-applying resources to genuinely low-risk relationships, both undermine the risk-based approach that underpins modern AML regimes. The line between SDD and EDD is a judgment informed by risk assessment, not a mechanical test, and firms must be able to justify why a given customer was placed at the standard level.
The precise components and thresholds of Standard Due Diligence are not defined by a single global standard; they derive from the applicable regime, such as the CDD Rule administered by FinCEN for covered U.S. financial institutions. Because obligations, scope, and exemptions vary by jurisdiction and by type of obliged entity, firms operating across borders should confirm exact requirements against the relevant regulation rather than assume a uniform rule applies everywhere.
Who it's relevant to
Inside SDD
Common questions
Answers to the questions practitioners most commonly ask about SDD.