AML/CFT — Customer Due Diligence (CDD)
Concept
Customer Due Diligence (CDD) is the process by which a financial adviser (FA) identifies who its customer really is, verifies that identity using reliable, independent sources, understands the purpose and intended nature of the business relationship, and looks through corporate/nominee layers to the beneficial owner — the natural person who ultimately owns or controls the customer. CDD is applied on a risk-based approach (RBA): the depth and intensity scale with the assessed ML/TF (money laundering / terrorism financing) risk. It is the foundational control in the MAS AML/CFT regime (for FAs, principally under MAS Notice FAA-N06 and its Guidelines — verify current notice reference).
Key rules & facts
- Four CDD triggers: (1) establishing business relations; (2) undertaking a transaction (including wire transfers) for a customer with whom no business relationship has been established; (3) suspicion of ML/TF; (4) doubt about the veracity or adequacy of previously obtained identification data.
- Identify AND verify the customer — verification is a separate step from identification. Collect: full name, unique identification number (e.g. NRIC/FIN/passport/UEN), residential/registered address, date of birth or date of incorporation, nationality or place of incorporation.
- Beneficial owner (BO): identify the BO and take reasonable measures to verify their identity; understand the ownership and control structure. FATF benchmark for ownership is ≥25% (verify current MAS threshold) — but control can also arise through voting rights, appointment of directors, or other means even below 25%.
- Persons acting on behalf (agents, authorised signatories, directors): verify their identity AND their authority to act.
- Purpose & nature: obtain information on the intended purpose of the relationship; use it as a baseline for ongoing monitoring.
- Risk-based approach: assess and document risk across customer, product/service, country/geography, and delivery channel; calibrate CDD intensity accordingly. Simplified CDD is permitted only for lower-risk situations — never where ML/TF is suspected.
- Timing: complete CDD before establishing business relations, with limited exceptions where verification is completed as soon as reasonably practicable and ML/TF risks are effectively managed.
- Ongoing CDD: monitor transactions for consistency with the customer's profile; periodically review and refresh CDD data — long-standing customers are not exempt.
Key data
| Element | Standard CDD requirement | Notes |
|---|---|---|
| Identify customer | Name, unique ID no., address, DOB/incorporation, nationality/place | Mandatory for all |
| Verify customer | From reliable, independent source documents/data | Separate from identify |
| Beneficial owner | Identify + reasonable measures to verify | ≥25% ownership benchmark (verify current MAS threshold) |
| Person acting on behalf | Verify identity + authority | Agents, signatories |
| Purpose of relationship | Obtain and record | Baseline for monitoring |
| Simplified CDD | Only for assessed lower risk | Never if ML/TF suspected |
| Enhanced CDD (EDD) | Required for higher risk / PEPs | See EDD topic |
| Risk level | CDD applied | When appropriate |
|---|---|---|
| Lower | Simplified CDD | Documented low-risk customer/product/country/channel; no suspicion |
| Standard | Full CDD | Default position |
| Higher | Enhanced CDD (EDD) | PEPs, complex/unusual transactions, higher-risk jurisdictions |
Exam angle
Situational — given a customer type (individual, company, trust, nominee/partnership), identify what CDD applies and when CDD is triggered. High-yield recall: the four trigger events, the identify-vs-verify distinction, and that simplified CDD is barred once suspicion exists.
⚠ The trap
Verifying only the natural person in front of you while forgetting the beneficial owner hidden behind a corporate, trust, or nominee structure; assuming a long-standing customer never needs CDD refreshed; or applying simplified CDD in a situation where ML/TF is actually suspected (never permitted).
Worked example
A private-limited company opens an account. Three shareholders each hold 20%; a fourth individual holds 40% and appoints the board. The FA must verify the company itself, identify the 40% holder as a beneficial owner, and — because control can exist below 25% — also assess whether any 20% holder exercises control through other means. Verifying only the director who walks in would be insufficient.
Takeaway
Identify, verify, and always look through to the real owner — risk-based approach sets the depth, and the four triggers set the moment.
Ready to test yourself on this?
Practise exam-style questions with the answer, explanation and the trap on every one.
Practise RES5 questions →