CDD (Customer Due Diligence): What It Is and When to Apply Each Level
CDD is basic continuous customer diligence: identification, risk profile, and monitoring throughout the relationship. It is the layer that sustains anti-money laundering obligations in daily operations. It is not a one-time onboarding event—it is a process that runs while the customer is active in your operation.
Why CDD Is Not Optional
Banks, fintechs, insurers, and exchanges operate under anti-money laundering regulation. BACEN, CVM, SUSEP, and COAF require you to know who is on the other side of the transaction, what their risk is, and whether they appear on restrictive lists. CDD is not compliance-box-ticking; it is the basis for every credit, investment, or coverage decision you make. Failing at CDD exposes the company to fines, regulatory blockade, and reputational damage.
The Three Levels of CDD
CDD is not one-size-fits-all. The depth of due diligence must vary according to customer risk. Regulation allows—and requires—you to use criteria to scale the investigation.
- Simplified CDD: for low-risk customers (individuals in routine operations, low value, low-surveillance sector). Collect basic data, document OCR, face match, and sanctions list screening.
- Standard CDD: for typical or medium-risk customers. Includes complete identification, source of funds profile, economic activity profile, verification on restrictive lists (OFAC, UN, Interpol), and continuous transaction monitoring.
- Enhanced CDD (EDD): for high-risk customers, PEPs (Politically Exposed Persons), individuals with complex source of funds, high-risk sectors, or high transaction volume. Requires beneficial owner analysis, shareholding structure investigation, OSINT, and continuous review.
How to Decide Which Level to Use
The level choice depends on risk factors. Ask: who is the customer? How much will they move? What is the source of the money? Which sector? Political involvement? Anomalous behavior signals? The more answers point to risk, the deeper the CDD should be. Financial institutions using risk scoring can automate this decision: an algorithm evaluates the customer profile and escalates to the appropriate due diligence level.
The CDD Cycle in Practice
CDD starts at onboarding. The customer enters through a digital portal with document OCR, liveness detection, KYC, and digital signature. At this point you capture identity, risk profile, and screen sanctions lists. Next, while the customer is active, you monitor the portfolio: changes in risk profile, new transactions, suspicious activity signals. If anything changes—risk increases, customer enters a list, transaction falls outside pattern—you review and may escalate to EDD. Continuous monitoring ensures you don't miss a change that requires attention.
Restrictive Lists and PEPs
Standard and enhanced CDD include screening against sanctions lists: OFAC (United States), UN and Interpol. You also need to identify PEPs — Politically Exposed Persons — who require heightened vigilance because of the position they hold. A PEP is not an unacceptable customer, but they require mandatory EDD and more frequent monitoring. And screening does not stop at the person: it also covers related parties (RCAs) — family members and close associates who may act on their behalf. That is why name-based lookups fall short: without tax-ID precision, namesakes and ties slip through.
Automating CDD Reduces Risk and Cost
Doing CDD manually is slow and error-prone. Institutions processing hundreds of customers per day need a decision engine: digital onboarding with OCR, face match, and KYC; due diligence scaled by risk level; automatic screening against OFAC, UN, and Interpol lists; continuous portfolio monitoring. GUÉP delivers the complete CDD cycle for banks, fintechs, insurers, and exchanges, serving BACEN, CVM, SUSEP, and COAF—ensuring every customer receives the right level of due diligence at the right time with complete audit trail.
CDD is continuity, not an event. The faster you escalate due diligence as risk changes, the less friction for low-risk customers and more protection for the company.
Frequently asked questions
Is CDD mandatory by law?
Yes. Financial institutions, fintechs, insurers, and exchanges operate under anti-money laundering regulation. BACEN, CVM, SUSEP, and COAF require you to perform CDD as part of your compliance program. CDD is not optional; it is the foundation of continuous vigilance the law requires.
What is the difference between CDD and EDD?
CDD is basic continuous due diligence: identification, risk profile, and routine monitoring. EDD (Enhanced Due Diligence) is in-depth analysis for high-risk customers, PEPs, complex source of funds, or sectors requiring intensive surveillance. CDD is for everyone; EDD is for those requiring deeper investigation. The decision to escalate to EDD comes from a high risk score.
How do I know if a customer is a PEP?
PEP stands for Politically Exposed Person—someone who holds or held high-ranking public office, or has intimate relationship with someone who does. This includes president, minister, judge, ambassador, and also spouse, minor children, and close associates. Identifying PEPs is technical and requires specialized databases and OSINT (open-source intelligence). A customer identified as a PEP requires mandatory EDD and enhanced monitoring.
What should I do if a customer appears on a sanctions list?
If a customer appears on a sanctions list (OFAC, UN, Interpol), you cannot proceed with the operation. You must block the transaction, report to the regulator (COAF), and terminate the relationship if confirmed. Automatic screening against restrictive lists during onboarding and continuous monitoring reduce the risk of missing a true positive. Lists are constantly updated; that is why monitoring must be automatic and real-time.