← All lessonsPart I · Rules & Regulations

AML/CFT — Customer Due Diligence (CDD)

Concept

Customer Due Diligence (CDD) is the process by which a financial adviser (FA) identifies who its customer really is, verifies that identity using reliable, independent sources, understands the purpose and intended nature of the business relationship, and looks through corporate/nominee layers to the beneficial owner — the natural person who ultimately owns or controls the customer. CDD is applied on a risk-based approach (RBA): the depth and intensity scale with the assessed ML/TF (money laundering / terrorism financing) risk. It is the foundational control in the MAS AML/CFT regime (for FAs, principally under MAS Notice FAA-N06 and its Guidelines — verify current notice reference).

From onboarding to STRNew client / txnred flags?CDDID + verify + beneficial ownerSuspicious?NoProceedYesFile STR (STRO)never tip off
The AML reflex — CDD then, if still suspicious, an STR to the STRO (never tip off).

Key rules & facts

  • Four CDD triggers: (1) establishing business relations; (2) undertaking a transaction (including wire transfers) for a customer with whom no business relationship has been established; (3) suspicion of ML/TF; (4) doubt about the veracity or adequacy of previously obtained identification data.
  • Identify AND verify the customer — verification is a separate step from identification. Collect: full name, unique identification number (e.g. NRIC/FIN/passport/UEN), residential/registered address, date of birth or date of incorporation, nationality or place of incorporation.
  • Beneficial owner (BO): identify the BO and take reasonable measures to verify their identity; understand the ownership and control structure. FATF benchmark for ownership is ≥25% (verify current MAS threshold) — but control can also arise through voting rights, appointment of directors, or other means even below 25%.
  • Persons acting on behalf (agents, authorised signatories, directors): verify their identity AND their authority to act.
  • Purpose & nature: obtain information on the intended purpose of the relationship; use it as a baseline for ongoing monitoring.
  • Risk-based approach: assess and document risk across customer, product/service, country/geography, and delivery channel; calibrate CDD intensity accordingly. Simplified CDD is permitted only for lower-risk situations — never where ML/TF is suspected.
  • Timing: complete CDD before establishing business relations, with limited exceptions where verification is completed as soon as reasonably practicable and ML/TF risks are effectively managed.
  • Ongoing CDD: monitor transactions for consistency with the customer's profile; periodically review and refresh CDD data — long-standing customers are not exempt.

Key data

ElementStandard CDD requirementNotes
Identify customerName, unique ID no., address, DOB/incorporation, nationality/placeMandatory for all
Verify customerFrom reliable, independent source documents/dataSeparate from identify
Beneficial ownerIdentify + reasonable measures to verify≥25% ownership benchmark (verify current MAS threshold)
Person acting on behalfVerify identity + authorityAgents, signatories
Purpose of relationshipObtain and recordBaseline for monitoring
Simplified CDDOnly for assessed lower riskNever if ML/TF suspected
Enhanced CDD (EDD)Required for higher risk / PEPsSee EDD topic
Risk levelCDD appliedWhen appropriate
LowerSimplified CDDDocumented low-risk customer/product/country/channel; no suspicion
StandardFull CDDDefault position
HigherEnhanced CDD (EDD)PEPs, complex/unusual transactions, higher-risk jurisdictions

Exam angle

Situational — given a customer type (individual, company, trust, nominee/partnership), identify what CDD applies and when CDD is triggered. High-yield recall: the four trigger events, the identify-vs-verify distinction, and that simplified CDD is barred once suspicion exists.

⚠ The trap

Verifying only the natural person in front of you while forgetting the beneficial owner hidden behind a corporate, trust, or nominee structure; assuming a long-standing customer never needs CDD refreshed; or applying simplified CDD in a situation where ML/TF is actually suspected (never permitted).

Worked example

A private-limited company opens an account. Three shareholders each hold 20%; a fourth individual holds 40% and appoints the board. The FA must verify the company itself, identify the 40% holder as a beneficial owner, and — because control can exist below 25% — also assess whether any 20% holder exercises control through other means. Verifying only the director who walks in would be insufficient.

Takeaway

Identify, verify, and always look through to the real owner — risk-based approach sets the depth, and the four triggers set the moment.

Ready to test yourself on this?

Practise exam-style questions with the answer, explanation and the trap on every one.

Practise RES5 questions →