Customer Due Diligence & KYC

Customer Due Diligence & KYC: banking drivers and controls

Understanding the relationship before providing services

Customer due diligence is the process of understanding who the customer is, who owns or controls the customer where relevant, what the relationship is for, what activity is expected and how the bank will manage the associated financial crime risk. KYC, or know your customer, is often used as a practical label for this work. The terminology should not obscure that due diligence continues after onboarding. A complete application is the beginning of an informed relationship, not the end of the bank's responsibility to understand it.

Sravanthi asks Malla Bank to open an account for her new design business. Ramesh wants to make the process clear and timely. He must establish whether the customer is Sravanthi trading personally or a separately incorporated entity, who is authorised to operate the account and what services the business needs. Asking for a company document when no company exists wastes time. Opening an individual account for a company can leave the bank with the wrong customer identity and contractual relationship.

The practical result of CDD is an assessed customer record and a defensible service decision. A folder of documents is not the result by itself. Staff should explain which facts the evidence establishes, what remains uncertain and what action the bank is authorised to take. That record should support later monitoring, customer service, investigation and review. It should also avoid collecting unrelated personal information merely because a form has space for it.

This chapter uses the fictional banks Malla Bank, Sravs Bank and Guna Bank and the fictional people Malla, Ramesh, Gunaditya and Sravanthi. Numerical examples use training currency units, written CU. Internal targets, review schedules and decision thresholds in examples are bank choices rather than regulatory minima. Cases examine identity evidence, expected activity, customer changes and control failures; unusual facts prompt assessment rather than an automatic accusation of crime.

Applicable standards and current scope

The FATF Recommendations consolidated in June 2026 provide the international CDD baseline in Recommendation 10. That baseline connects customer identification and verification, beneficial ownership, relationship purpose and ongoing scrutiny. National implementation determines binding requirements, permitted evidence and timing. This chapter does not assert one universal document list, ownership percentage, review interval or occasional-transaction rule for every bank.

[VERIFY: scope review completed 2 October 2026 against the linked official sources. FATF standards are distinguished from domestic rules and fictional bank procedure; United States examples are expressly scoped, and no unsupplied national requirement is certified.]

The FFIEC customer due diligence overview explains United States supervisory treatment of risk profiles and ongoing customer information. Its discussion does not impose a categorical periodic-update requirement; banks may establish risk-based review policies. Elsewhere, local rules can differ. A global procedure must identify those differences rather than tell every customer that an annual update is required by international law.

A current United States qualification matters for legal entity customers. FinCEN order FIN-2026-R001, issued 13 February 2026, permits covered institutions to limit repeated beneficial-owner identification and verification to initial account opening, reliability doubts and risk-based ongoing CDD circumstances, under its terms. It preserves other applicable BSA duties. Staff should therefore check the current order and applicable procedures rather than repeat an older universal claim that identification and verification must occur at every additional account opening.

The bank's legal inventory should name the relevant entity, authority, rule version, activity and requirement. Its procedure then explains how staff satisfy that requirement and what additional measures the bank chooses because of risk. A bank can adopt a stricter permissible procedure, but staff should describe it accurately as policy. An internal waiver may change a policy requirement within delegated authority; it cannot override binding law.

Identify the customer and the capacity in which they act

The first question is who will have the banking relationship. The person submitting the application can be the customer, a representative, an employee, an intermediary or someone assisting a customer who needs support. Those roles have different implications. A representative's identity does not replace the customer's identity, and possession of the customer's documents does not establish authority to act. The application should record the relevant parties and their capacities separately.

For an individual customer, staff collect the required identifying attributes and resolve material inconsistencies. Names can have several scripts or legitimate variations. A person can change a name after marriage or another lawful event. The record should preserve the necessary previous or alternative names and the evidence connecting them where relevant. Staff should not assume a different spelling proves a different person, nor merge two customers solely because their names match.

For an entity, the bank needs to establish its identity and legal existence under the relevant framework. Registered name, registration identifier, legal form and jurisdiction can help distinguish entities with similar trading names. A business's public-facing name may differ from the legal customer's name. The bank should record that relationship so invoices, website information and transaction references can be interpreted without changing the legal identity incorrectly.

A sole trader illustrates why capacity matters. The business may use a trading name without becoming a separate legal person. The bank's contractual and CDD treatment must follow the applicable legal position and product requirements. A partnership, company or other arrangement can require a different analysis. A standard business checklist should therefore branch on the customer's actual form rather than demand the same incorporation document from everyone.

Authority to act is another distinct question. An employee who knows the company's registration details is not automatically authorised to open or operate its account. Staff examine the applicable mandate, organisational authority or other permitted evidence. They should establish which activities the representative can perform and whether restrictions apply. A mandate to view information does not necessarily authorise payments or account closure.

The bank should also recognise when the applicant is acting on behalf of another person even though the requested account name looks ordinary. Explanations, documentation and the intended activity can reveal that funds or decisions belong to someone else. Staff should assess the applicable customer and beneficial-ownership requirements rather than use the applicant's identity as a shortcut. Legitimate agency arrangements exist; the objective is to understand them and apply the correct controls.

A customer identity record benefits from explicit role labels. The contractual customer, account operator, beneficial owner, controlling person and contact person should not all appear under a generic associated party field without a defined meaning. These distinctions affect screening, communications and permissions. If the same person occupies several roles, the system should preserve each relevant relationship rather than require several unrelated customer records that later become inconsistent.

Verification is an assessment of evidence

Identification records what identity is claimed. Verification assesses evidence supporting that claim. The bank should use the reliable and independent sources permitted by applicable rules and suitable for the circumstances. A document can establish some facts while leaving others unresolved. An incorporation certificate can support an entity's registration without demonstrating its current controllers or business activity. A personal identity document can support identity without proving authority to act for a company.

Staff need to assess authenticity, validity, relevance and connection to the applicant. A genuine document can be stolen or presented by another person. A valid document can contain an address that is no longer current. A document relevant to one person can be attached to another customer's file by mistake. The workflow should address those possibilities proportionately and preserve evidence of the checks that matter, not merely record a green verification flag.

Independent does not mean that every source is equally useful. A customer's own organisation chart can explain a claim, but it may need corroboration. A public registry can provide authoritative information within its scope, but its entries can be self-reported, delayed or limited. A commercial database can aggregate useful material while retaining the original source's limitations. Staff should distinguish a source's authority from the convenience of the interface through which it was obtained.

Ramesh receives an identity document showing a name and date of birth that match the application, but its image is unreadable at the edges. He should identify which necessary elements cannot be assessed and obtain an acceptable clearer record or permitted alternative. He should not repeatedly ask for unrelated documents in the hope that volume compensates for the missing evidence. A focused request improves both customer experience and the quality of the assessment.

Where documents conflict, the bank should determine whether the difference is material and how it can be resolved. A minor formatting variation may have an understandable explanation. A conflicting registration identifier can indicate that the documents refer to different entities. The case record should explain what was compared and why the resolution was accepted. A note stating discrepancy cleared without evidence gives later reviewers little basis for challenge.

Verification outcomes should retain their meaning. Verified means that the applicable assessment was completed and satisfactory, not simply that an external provider returned a response. Pending means a relevant task remains, and failed can mean an adverse result or an inability to complete, which may require different action. A workflow that collapses all non-green responses into one status can send staff down the wrong escalation path and make management information unreliable.

Evidence alternatives and proportionate inclusion

A bank should avoid treating lack of a familiar document as proof of financial crime risk. People may lack conventional documentation because of displacement, rural residence, poverty, disability or the way local identity systems work. These circumstances call for an assessment of available permitted evidence and product design. They do not authorise the bank to ignore binding identity requirements, but neither do they justify inventing a legal requirement for a document that local rules do not demand.

The FATF financial inclusion guidance updated in 2025 supports proportionate approaches that improve formal access while managing illicit-finance risks. Its examples do not create a worldwide right to use any particular substitute document. The bank should translate the applicable local permissions into a clear route for staff, including who can assess alternatives and what evidence should be retained.

An alternative-evidence route should be operationally usable. If staff can approve an alternative only by contacting an unmonitored mailbox, the theoretical permission may not help customers. The route should explain the facts the bank needs to establish, acceptable source types in the relevant setting and the decision authority. It should preserve a consistent standard while allowing the evidence to vary according to lawful circumstances.

Product restrictions can sometimes support a proportionate service where permitted. A limited service might constrain channels or features until additional evidence is obtained. That design needs a legal basis, an assessed risk rationale and enforceable restrictions. Staff should not describe a restricted product as simplified CDD if mandatory steps remain unsatisfied or if the applicable framework does not permit the arrangement. The distinction between less extensive permitted measures and incomplete required measures is central.

Sravanthi helps a customer who cannot use a digital upload interface. The bank offers an accessible permitted route rather than interpreting failed uploads as unwillingness to cooperate. It still evaluates the evidence according to the applicable standard. Accessibility changes how the information is obtained; it need not weaken the identity conclusion. Requests should use understandable language and avoid exposing sensitive information to an unnecessary helper.

Customer refusal also needs context. A person may misunderstand a request, worry about security or lack the requested record. Staff can explain the purpose, authorised collection route and available alternatives. Persistent unexplained inconsistency or inability to complete required CDD then follows the proper escalation process. A bank should not use a broad suspicion label for every service difficulty, because that confuses access problems with facts relevant to reporting.

Digital identity and remote onboarding

Digital onboarding should establish the relevant identity facts and connect the claimed identity to the person using the service. It is not enough for a document image to look plausible if the process cannot assess who supplied it. Identity proofing, the handling of evidence and subsequent authentication perform related but different tasks. A successful login establishes use of an authentication method; it does not necessarily demonstrate that the original customer identification was sound.

The FATF guidance on digital identity, March 2020 asks users to assess the system's assurance and suitability for the risk. It does not treat every remote relationship as automatically higher risk, nor certify a named technology as universally sufficient. The bank should understand the provider's technology, governance and process, then assess whether its results are reliable and independent enough for the applicable use.

A service can use several checks, but the bank should understand what each establishes. Document validation can examine an image or source record. A face comparison can assess similarity to a reference image. A liveness or related presentation-attack check can address particular attempts to impersonate the applicant. Device and session information can inform fraud assessment. None should be described as proving every aspect of identity, beneficial ownership, source of funds and relationship purpose.

The bank needs controls for false rejection and false acceptance. False rejection can exclude legitimate customers, including people whose devices or circumstances are poorly supported. False acceptance can admit an impersonator or fabricated identity. Performance claims should be assessed against relevant customer populations and attack conditions rather than a single headline accuracy figure. Staff need a lawful, secure exception route that can resolve a genuine customer's difficulty without becoming an easy bypass for an attacker.

Provider results should retain sufficient context. The record should identify the relevant transaction or session, assessed attributes, result, material limitations and evidence accessible for later review. A provider reference that becomes unusable after a short contract period can leave the bank unable to reconstruct its decision. Contract and technical arrangements should support the applicable recordkeeping and access requirements. The bank should not assume it can retain unlimited sensitive data merely because the provider can supply it.

Gunaditya identifies a remote-onboarding configuration in which unsuccessful identity sessions can be restarted indefinitely without linking attempts. A legitimate customer may need retries, but unlimited disconnected attempts can conceal a pattern. The bank evaluates session linkage, proportionate retry handling, manual review and the ability to identify suspected misuse. It also ensures that an accessibility problem is not automatically coded as fraud. The result should address the demonstrated mechanism rather than simply increase the number of document requests.

Changes to the digital process need assessment. A provider can alter a model, supported document list or fallback route. The bank should identify changes that affect its evidence standard and test relevant cases before relying on the new result. A service still being online does not show that its new version meets the bank's requirements. Live quality monitoring and customer outcomes can reveal problems that pre-launch tests did not anticipate.

Beneficial ownership and control at the CDD boundary

For relevant customers, CDD extends beyond the legal entity's name to the natural persons who ultimately own or control it under the applicable definition. Ownership and control are connected but distinct. Equity interests can be held through several entities, while control can arise through other arrangements. The bank should understand the structure well enough to apply the relevant requirements. This chapter explains the CDD decision; the KYB chapter examines business structures and operations in greater detail.

The ownership record should show each material link, its source and the reason the bank accepts it. An organisation chart provides a useful starting map, but the bank should assess the supporting evidence and unresolved inconsistencies. Percentage interests, voting rights and other control arrangements should not be collapsed into one number where the distinction matters. Staff should also recognise when the structure involves an arrangement for which the applicable rules identify particular parties differently from an ordinary company.

A simple indirect-interest calculation helps test the map. In a fictional customer, Holding Entity A owns 60 percent of Operating Entity B, and Malla owns 50 percent of Holding Entity A. If these are ordinary equity interests with no other relevant arrangements, Malla's indirect economic interest through this chain is 50 percent multiplied by 60 percent, or 30 percent. That arithmetic does not by itself determine every legal beneficial-owner test or who controls B. The remaining ownership and relevant control facts still need assessment.

If Malla also owns 10 percent of B directly, the simple total economic interest across these two non-overlapping paths is 40 percent. Staff should verify that the paths are genuinely distinct and avoid double counting a holding already included elsewhere. Complex structures may require specialist analysis, particularly where interests overlap or rights differ. A spreadsheet can reproduce an arithmetic error consistently; it is not a substitute for understanding the legal and factual structure.

The United States CDD rule illustrates why scope matters. FinCEN describes an ownership prong covering individuals with 25 percent or more of relevant equity and a control prong covering a responsible individual, subject to definitions, exclusions and other provisions. These are not universal global percentages or a complete statement of all ownership-related controls. The bank should apply the current rule and February 2026 relief where relevant, without exporting them to customers governed by a different framework.

A person below a particular ownership threshold can still be relevant to control, sanctions or other risk analysis. Equally, a person identified for one regime is not automatically the same person required by every other regime. CDD ownership requirements, sanctions ownership rules and tax classifications can have different definitions. The bank should label the purpose of each assessment and preserve the necessary distinctions rather than reuse one beneficial owner flag without explanation.

Verification of a person's identity and verification of their ownership role are separate evidence questions. A valid identity document may establish who the person is but not whether the claimed interest is accurate. A registry entry may identify an owner while leaving the bank to assess the required identity evidence. Where the applicable framework permits reliance on particular information, the bank should understand that permission and its limits. Doubts about reliability need resolution through the proper process.

Purpose, intended activity and a usable customer profile

The bank needs to understand why the customer wants the relationship and what activity is reasonably expected. The answer should reflect the customer's actual circumstances and services rather than a generic statement such as business purposes. A salary account, collection account, investment holding account and operating account can produce different patterns. The purpose statement becomes useful when it gives later staff a basis for interpreting activity and recognising a material change.

For Sravanthi's design business, Ramesh records that the account will receive payments from domestic commercial clients and pay software costs, ordinary operating expenses and occasional subcontractors. The business expects uneven receipts because clients pay after project milestones. That explanation matters more than a misleading assumption that every month must look identical. Staff assess the plausibility of the profile using information appropriate to the customer and risk, avoiding a demand for a long history that a genuinely new business cannot provide.

Expected activity can include relevant amounts, frequency, counterparties, geographies, channels and cash use. The bank should collect attributes that its controls can actually use. A free-text narrative can preserve valuable context, while structured fields support segmentation and monitoring. The two should be consistent. If the narrative says no international payments but the structured field says worldwide, staff need to resolve the conflict before dependent controls rely on it.

Estimates are estimates. A new customer may not know precise turnover or monthly payment counts. The bank should record the basis and uncertainty of the expectation rather than treat an approximate forecast as a contractual limit or proof of suspicion. Materially different actual activity then prompts assessment of the explanation and risk. A successful new contract can increase turnover legitimately; an unexplained shift to unrelated third-party receipts may require different attention.

The bank should avoid circular profiles. If expected activity is continually updated to equal whatever happened, the baseline ceases to support challenge. A change should have a reason, assessed evidence and authorised review where required. Historical expectations should remain reconstructable so an investigator can determine what the bank knew at the time. Updating the current profile should not erase the earlier basis on which a material transaction was examined.

Customer profiles should support the actual services provided. A person can use several accounts or products with different purposes. The bank may maintain a relationship-level view alongside product-specific details. It should prevent one benign product from obscuring another product's distinct risk. A savings account profile does not automatically explain a new merchant settlement service or activity through an intermediary.

The profile also has limits. It does not prove that every payment consistent with the stated purpose is legitimate. Criminal activity can be structured to resemble ordinary business. Nor does every deviation establish illicit conduct. The bank should use the profile with other relevant information and control mechanisms, including pattern analysis and investigation. Its purpose is informed comparison rather than mechanical innocence or guilt.

Source of funds and source of wealth

Source of funds concerns where particular funds come from. Source of wealth concerns how a person's overall wealth was accumulated. The questions can overlap but are not interchangeable. A transfer from another bank describes the immediate payment route, not necessarily the economic origin of the funds. A person's substantial wealth does not explain the origin of every payment received from an unrelated third party.

The extent of assessment depends on applicable rules, risk and the particular question. The bank should not ask every ordinary customer for a lifetime wealth history without a reason. Where higher risk or specific requirements call for deeper understanding, the request should focus on the relevant facts and suitable evidence. A source-of-funds assessment might examine salary, business receipts, asset sale proceeds or another plausible origin according to the circumstances.

Sravanthi plans to fund a new business account with CU 80,000 from the sale of equipment. A statement showing CU 80,000 arriving from another institution supports the route but does not establish the claimed sale. Depending on the assessed risk and applicable requirements, the bank may examine relevant sale documentation and payment consistency. It should evaluate whether the evidence supports the amount, parties and timing, rather than collect an unrelated document that merely looks official.

An inheritance example requires a different evidence question from regular salary. Staff should understand what they need to establish and which records can reasonably support it. They should avoid assuming every customer can produce the same document. Where evidence is incomplete, the record should show the remaining uncertainty and permitted decision route. A commercial description such as wealthy client should not replace this assessment.

Source information can change the risk profile or create an investigation question. A payment described as a customer sale but received from an unrelated individual may have a legitimate explanation, such as an authorised payer arrangement. It may also indicate an inconsistency requiring examination. Staff should assess the connection, supporting evidence and wider pattern without accepting or rejecting the explanation automatically.

The bank should preserve the scope of its conclusion. Satisfactory evidence for one funding event does not mean every future source is verified. A credible wealth history can inform an assessment while leaving particular payment concerns unresolved. Records should distinguish the investigated event, relevant sources, limitations and authorised outcome. This prevents a broad approved source flag from becoming a permanent exemption from ongoing due diligence.

Risk assessment and the right level of due diligence

A customer risk assessment organises the information that affects the bank's exposure and the measures needed to manage it. It should consider the relevant customer, business, service, channel and geographic factors together. A category label alone can conceal significant differences. Two customers in the same industry can use different products, have different ownership transparency and conduct different activities. The assessment should explain the factors relevant to the particular relationship.

A risk rating is not a statement that the customer committed a crime. High risk indicates a need for appropriate attention and controls; low risk does not establish that misuse is impossible. Staff should avoid using the rating as a substitute for either mandatory CDD or a specific reporting decision. A mechanically low score cannot cure an unresolved legal requirement, and a high score does not automatically justify an accusation or blanket refusal.

The bank should distinguish risk factors from data uncertainty. Unknown ownership information may mean required work is incomplete, not that a completed assessment should simply receive a few extra points. A missing country field should not default silently to a low-risk value. A score can include an uncertainty dimension where the method permits it, but the underlying missing task still needs resolution. The customer record should show the actual state rather than hide it inside an aggregate number.

Weights, thresholds and overrides are bank-specific design choices unless an applicable requirement says otherwise. Their rationale should reflect the bank's activities and control capability. A score that combines ordinal categories should not be presented as a statistically validated probability of money laundering without evidence. Staff should be able to explain why a factor changes the assessment and what operational consequence follows.

Gunaditya tests a rating method that gives a customer a low overall result because transparent ownership offsets several other factors. The method does not separately flag a requested service that the bank cannot control adequately. The resulting number would permit a relationship the operational team cannot support safely. A better design preserves relevant mandatory restrictions and product limitations outside the averaging mechanism. Risk scoring helps prioritise work; it should not erase decisive constraints.

Overrides need a reason, authority and record. An override can correct a method's unsuitable treatment of a particular circumstance or apply a documented professional assessment. It should not be a convenient way to meet a sales target. The reviewer should identify the factor being changed, the evidence and resulting control requirements. Monitoring override patterns can reveal a weak model, unclear policy or pressure on decision makers.

Due diligence measures should respond to the assessed risk. Additional information or closer review should address a defined question, not simply enlarge the document folder. If the concern is an opaque controller, another utility bill from the operating entity may not help. If the concern is unexplained third-party receipts, the bank needs to understand those receipts. Proportionate design improves efficiency because the work is directed at the actual uncertainty.

Simplified measures, enhanced measures and mandatory boundaries

Simplified due diligence means less extensive measures where the applicable framework permits them for appropriately assessed lower risk. It does not mean no due diligence or an exemption created by a relationship manager. The bank should establish the conditions under which simplified measures are available and how it checks that those conditions continue. Suspicion or a material higher-risk circumstance can require reassessment under the relevant rules.

Examples of proportionate design can include using an inherent understanding of a straightforward product purpose or adapting the extent of information collected where permitted. The bank should distinguish such choices from mandatory identification or other requirements that still apply. A simple customer relationship can reduce the need for a detailed commercial questionnaire while leaving identity verification necessary. The exact permissible measures depend on local implementation and the customer concerned.

Enhanced due diligence responds to heightened risk or specific requirements. It may involve deeper inquiry into ownership, funds, wealth, activity or other relevant facts, additional approvals and closer monitoring. The measures should connect to the identified risk and applicable rules. A higher-risk label without changed procedures is not meaningful enhancement. Nor is requesting many additional documents useful if staff do not assess what those documents establish.

Politically exposed person requirements need careful scope. FATF Recommendation 12 distinguishes relevant categories and requires specified measures, including senior management approval and source-of-wealth and source-of-funds measures, in its defined circumstances. Domestic implementation determines the bank's binding duties. PEP status concerns exposure associated with a prominent public function; it is not proof of corruption. Family members and close associates require the treatment specified by the applicable framework rather than being described inaccurately as holding the public office themselves.

The CDD team should know when specialist requirements apply. Correspondent relationships, certain private banking arrangements, intermediary services or other activities can have additional duties under local law. A generic customer checklist may not capture them. The onboarding route should identify the relevant service and trigger specialist assessment early enough to inform the decision. Discovering the additional requirement after activation can leave the bank with an avoidable gap.

Ramesh reviews a customer requesting ordinary domestic collections and an additional service involving funds for other parties. The first service's CDD route cannot automatically approve the second. The team assesses the customer's role, relevant parties, visibility and applicable requirements. The bank may require different information or controls because the activity changes the risk mechanism. This is a substantive response to the service, not a generic high-risk questionnaire applied to every applicant.

Mandatory legal boundaries should be visible in the workflow. Where required CDD cannot be completed, staff must apply the applicable rule and consider the relevant reporting question. Any legally permitted delayed verification or limited arrangement needs its conditions checked and documented. A universal instruction that all accounts must be fully verified before any relationship is formed can be as misleading as a universal permission to verify later. The bank's procedure must state the actual rule for the activity and jurisdiction.

Onboarding decisions and enforced customer states

An onboarding workflow should distinguish collection, verification, assessment, approval and activation. These stages can occur partly in parallel, but their dependencies need to be understood. A completed data-entry task is not a completed legal assessment. A compliance opinion may advise a decision maker without itself authorising service activation. The system should reflect the authority and conditions of the actual decision rather than treating every green task as equivalent.

The decision record should identify the customer, services requested, relevant facts, assessed requirements, material exceptions and authorised outcome. If approval includes a restriction, it should describe the restriction precisely enough for operations and technology to enforce it. An approval stating proceed cautiously offers no usable instruction. A restriction to domestic collections has a clearer meaning, but the bank must establish how it applies to each channel and connected product.

States should be designed around real outcomes. Draft, awaiting information, under review, approved pending activation, active, restricted and exited can describe different positions. The bank can choose different labels, but it needs unambiguous definitions and permitted transitions. A customer should not bypass an unresolved task by applying through a second channel that creates an independent active record. Cross-channel identification and state checks help prevent that failure.

Malla authorises activation of Sravanthi's business account after the required CDD and product approval are completed. Gunaditya reconciles the approved customers with the active-account population. If 120 customers were authorised and 123 became active, the three additional records need explanation. They could be valid transfers, duplicates or unauthorised activations. A matching total alone is insufficient if the actual identifiers differ. The control should compare the relevant customer and account records, not only count them.

A pending verification arrangement, where legally permitted, needs a real expiry and action route. Staff should understand what activity is allowed, what remains outstanding and what happens if the condition is not met. Extensions require the appropriate authority and legal assessment; repeated administrative extensions can undermine the intended control. The bank should not use a past-due status as a reason to continue unrestricted activity indefinitely.

Customer communications should match the state. Asking a customer to begin using an account while internal systems still prevent ordinary activity creates avoidable confusion. Conversely, telling a customer approval is pending while the service is already active can conceal a control failure. Staff should communicate permissible next steps, required information and available help clearly. They should avoid disclosing restricted reporting considerations or unsupported allegations in standard status messages.

Screening and adverse information

Customer screening can identify potential sanctions matches, relevant PEP exposure or adverse information requiring assessment. These tasks have different purposes and consequences. A sanctions match can raise a binding legal restriction. PEP status can trigger specified due diligence measures under the applicable framework. Adverse information can inform risk or an investigation. A single negative screening result should not be treated as proof that all three questions have been resolved.

The bank should identify the relevant customer and associated parties to screen, the applicable sources and the information needed to resolve potential matches. Identity attributes and role labels matter because a similar name may refer to someone else. The decision should preserve the evidence and applicable standard. A vendor's potential-match flag is an input to the bank's process rather than an automatic legal conclusion or accusation.

Adverse media needs assessment of identity, source credibility, allegation, date, context and later developments. A repeated article can reproduce the same original allegation without providing independent corroboration. An old allegation followed by an acquittal or correction should not be described as a current proven conviction. Equally, a lack of criminal conviction does not require the bank to ignore credible risk information. The record should distinguish allegation, established fact and the bank's risk inference.

Ramesh finds an article naming someone similar to an applicant. The applicant's available identifiers do not match the article's location and age information. He examines the evidence before deciding whether it concerns the same person. If identity remains uncertain, he records that uncertainty and follows the approved escalation route. He should not attach a sensational accusation to the customer record solely to make the search task appear complete.

A screening outcome should reach the appropriate workflow. A sanctions issue needs the legal and operational response required by the relevant regime, not a general high-risk approval. A relevant PEP finding needs the applicable measures rather than an automatic conclusion of corruption. Credible adverse information may require deeper CDD, investigation or an authorised relationship decision. The bank should preserve these boundaries while coordinating the information needed by each team.

Ongoing due diligence and changes in the relationship

Ongoing CDD connects the assessed profile to actual developments. The bank should identify material changes in information or activity, evaluate them and update relevant records and controls. This work is related to transaction monitoring but is broader. A ownership change can matter before an unusual payment occurs. A change in authorised users can affect account permissions. A new service can change the risk even if transaction amounts remain similar.

Periodic reviews can help detect stale information, while event-driven reviews respond when the bank learns of a material change. Applicable law and policy determine timing. The United States FFIEC discussion describes risk-based updating and does not create a categorical periodic-update requirement. Other jurisdictions can prescribe particular arrangements. A bank should avoid teaching one refresh frequency as a universal standard and should explain which events require action between scheduled reviews.

Events need a route to the people who can assess them. Relationship staff may learn that a business has been sold, credit staff may receive updated accounts, fraud staff may discover a change in account operation and investigators may identify an undisclosed party. Lawful internal sharing and clear workflow can connect these facts to CDD. A relevant fact buried in a separate system is unlikely to improve the customer profile automatically.

An event should be assessed for materiality rather than triggering every possible review. A corrected telephone formatting error has different implications from a new controller or unexplained cross-border payments. The procedure should identify decision authority and escalation where staff are uncertain. It should preserve the reason a change was considered immaterial when that conclusion matters, without producing unnecessary narrative for every minor correction.

Reviews should use the information appropriate to the decision date. When staff update an ownership record, they should preserve the effective date where known and the date the bank learned of the change. These can differ. Later assurance needs to distinguish a customer's change from a delay in the bank's awareness or action. A current correct record alone does not demonstrate that earlier controls used the right information.

The review outcome should reach dependent processes. A new beneficial owner may need screening under the applicable arrangement. A changed business purpose may affect monitoring segmentation. A new authorised operator may require permissions changes. A restricted product may need an operational block. The review is not complete merely because the CDD form was updated if required downstream actions remain outstanding.

From customer knowledge to transaction scrutiny

Customer information helps analysts assess whether activity is consistent with what the bank understands about the relationship. It should be accessible, current enough for the purpose and intelligible. A monitoring scenario can use structured attributes such as segment or expected channels; an investigator can use contextual narrative. The bank should recognise that a customer profile can be incomplete or wrong and avoid treating it as unquestionable ground truth.

Suppose Sravanthi's business expects domestic client receipts of approximately CU 40,000 per month. Actual receipts rise to CU 120,000 after a major project milestone. That is three times the approximate monthly expectation. The ratio describes a change in scale; it does not establish suspicion. The bank assesses the timing, client, supporting explanation and other relevant facts. A credible milestone can explain the increase, while unrelated payer patterns may require further inquiry.

If staff accept a new expectation of CU 120,000, they should document whether the increase is recurring or a one-off event. Otherwise the profile may become too broad to support future comparison. A one-time sale, settlement or project receipt should not necessarily redefine ordinary monthly activity. The record should preserve enough context for the monitoring and investigation teams to understand the difference.

Monitoring can also reveal information that CDD should assess. Repeated receipts from third parties inconsistent with the stated business might prompt inquiry into the customer's role. The CDD team and investigators should coordinate while retaining separate decisions and access restrictions. Updating a profile does not replace an investigation or required reporting assessment. Filing a report does not automatically establish that the CDD profile is complete.

The bank should avoid configuring monitoring to exclude customers merely because their CDD is incomplete. Missing information can require a controlled interim approach and prompt remediation. A system that assigns an unknown segment to an unmonitored default can make the weakest files least visible. Population testing should examine how pending, unknown and changed attributes affect scenario inclusion.

A lawful explanation should be evaluated and recorded, not ignored because an alert exists. An implausible explanation should not be accepted merely because a commercial relationship is valuable. The staff member's role is to assess the evidence and escalate through the appropriate process. The profile supports that judgement but does not automate the reporting test or determine every customer outcome.

Reliance, intermediaries and outsourced tasks

A bank may obtain information through an intermediary, a group service or an outsourced provider. Those arrangements need to be understood rather than treated as interchangeable. An intermediary may introduce the customer without performing the bank's CDD. A provider may perform specific verification tasks under the bank's instructions. A reliance arrangement may permit use of another regulated institution's work under defined conditions. The applicable legal framework determines what is permitted and who remains responsible.

The bank should identify exactly which task another party performs and what evidence it can obtain. A statement saying customer checked does not explain whether identity, beneficial ownership, relationship purpose or screening was examined. It should not be used as proof that every required task is complete. The arrangement should provide the information and records needed for the bank's own obligations and later review, according to the applicable rules.

FATF Recommendation 17 provides the international architecture for third-party reliance, including conditions and continuing ultimate responsibility. Domestic implementation can allow, limit or prohibit particular arrangements. It is separate from ordinary outsourcing under an agency relationship. The bank should classify its arrangement correctly before assuming that a vendor's work can satisfy a requirement. The customer remains entitled to clear information about the authorised collection route.

Malla Bank receives applications from a business association. The association checks membership but is not performing the bank's identity verification. Its familiarity with an applicant can provide context without satisfying the bank's required assessment. The bank should avoid telling staff that introduced customers are pre-verified unless the legal and factual basis supports that statement. A respected introducer can also be deceived or supply incomplete information.

For an outsourced verification service, the bank should test configuration, data completeness and exception handling. The provider may verify the document supplied while the bank accidentally sends the wrong customer's record. A positive provider result cannot correct that association error. The contract, operational controls and audit evidence should support the specific task, including how records are retained and how significant failures or changes are notified.

Where group information is reused, staff should confirm that it relates to the same customer, remains suitable and can lawfully be accessed. A subsidiary's customer assessment can use different rules, evidence or services. The bank may need additional local work. Shared data should preserve source and date so the receiving team can judge its relevance. A central customer number alone does not establish that the local decision requirements have been met.

Exceptions, unresolved information and escalation

An exception should describe the rule or policy concerned, the fact that differs from it, the risk and legal position, and the permitted decision route. Some exceptions can be resolved by correcting an administrative error. Others require further evidence or specialist advice. A legal requirement that cannot be satisfied is not an ordinary discretionary waiver. The workflow should make that boundary visible before a manager approves the relationship.

Staff should distinguish unwillingness, inability and uncertainty. A customer can be unwilling to provide necessary information, unable to obtain a requested document or unclear about the request. These situations can overlap but may call for different next steps. A proportionate explanation or permitted alternative can solve a service problem. Persistent material inconsistencies may require an investigation or reporting assessment. The bank should base those decisions on facts rather than the inconvenience of the case.

An escalation record should be usable by the decision maker. It should identify the customer, requested service, unresolved question, evidence already assessed and proposed options. Sending a large document folder without explaining the question can delay the answer. Conversely, a brief recommendation without the supporting facts can lead to an uninformed approval. Staff should communicate enough relevant information to enable a lawful and timely decision.

The decision maker should state what is authorised and why. If additional work is required, the record should identify the owner, due point and interim conditions where permitted. If the relationship cannot proceed, it should record the operational steps and any separate reporting assessment. Sensitive reporting information should remain appropriately restricted. A standard customer message should not expose the bank's confidential internal reasoning unnecessarily.

Escalation routes need to work during absence and urgency. A procedure naming one person without an alternate can create a practical blockage. Delegation should preserve competence, authority and conflicts safeguards. Commercial urgency can affect prioritisation but cannot change binding requirements. A documented urgent route is better than an informal bypass that leaves no reliable decision record.

The bank should examine exception patterns. Repeated missing evidence from one channel can indicate a confusing form, poor training or a weak provider process. Repeated overrides by one manager can indicate pressure or an unsuitable policy. Persistent customer difficulty can show that permitted alternatives are not accessible in practice. These patterns help improve the process while individual files still receive the necessary assessment.

Records, privacy and the customer experience

CDD involves personal and business information that can be sensitive. The bank should identify its lawful basis for collection, use and retention, apply access controls and communicate through secure authorised channels. Financial crime obligations do not automatically permit unrestricted collection or sharing. Privacy, confidentiality and other local requirements need to be assessed alongside CDD duties. A global workflow should explain relevant limits rather than assume every affiliate may inspect every document.

Records should support reconstruction without unnecessary duplication. A customer profile can reference authoritative evidence held in a controlled repository. The reference needs to remain available and interpretable for the applicable retention period. Staff should know which version was reviewed and which facts it supported. Copies scattered across email, personal drives and unrelated systems can increase security risk while making the actual decision harder to reconstruct.

The record should separate facts supplied by the customer, facts obtained independently and conclusions drawn by staff. It should preserve relevant effective dates and review dates. A later correction should not silently alter the evidence used for an earlier approval. The bank needs an appropriate history of changes, with access and retention consistent with law. This is particularly important where an investigation asks what the bank knew when activity occurred.

Customer requests should be targeted and understandable. A message asking for all ownership documents can be unclear where the customer does not know which structure the bank is trying to resolve. Staff can explain the relevant information needed and acceptable routes without disclosing confidential controls or reporting matters. Clear requests reduce repeated exchanges and help customers distinguish legitimate bank requests from phishing or fraudulent instructions.

The bank should avoid unnecessary repeated collection. If it already holds suitable current evidence that can lawfully be used, staff should assess whether another request adds value or is required. Current local rules and policy determine the answer. The February 2026 United States relief illustrates a specific change in repeated beneficial-owner work; it does not mean every customer in every jurisdiction is exempt from updates. The workflow should preserve justified reuse and required reassessment.

Customer complaints about CDD can reveal failures in communication, accessibility, consistency or delay. They do not automatically show the underlying control is inappropriate. The bank should examine both the customer outcome and the legal requirement, correcting avoidable process problems while maintaining necessary controls. Staff should provide the permissible complaint route and status information, with sensitive reporting matters kept appropriately protected.

Quality assurance and management information

CDD quality assurance should assess whether files establish the required facts and support the decision. A completeness check can identify missing fields, but it cannot alone determine whether the evidence is credible or the reasoning sound. A file can have every box completed while confusing an operator with a beneficial owner. Reviewers need competence to examine the substantive conclusion as well as the workflow's formal completion.

The review scope should identify the population, selection method and questions tested. A sample of complex applications can reveal valuable issues but does not estimate the error rate for every customer automatically. A random sample can support particular conclusions if its design and population are appropriate. The bank can use both methods while explaining what each result establishes. Passing a few easy files does not demonstrate that exception handling works.

Gunaditya reviews 40 files from a defined population of 800 recently approved business customers. The sample deliberately includes 20 complex ownership cases and 20 ordinary cases. Six files have material weaknesses: four in the complex group and two in the ordinary group. The observed sample proportions are 20 percent and 10 percent respectively, but the judgemental selection does not justify projecting those rates across all 800 customers. The evidence supports targeted follow-up and assessment of the underlying cause.

A finding should connect the defect to its consequence. Missing assessed authority evidence can permit an unauthorised operator. An unclear source citation can make identity verification irreproducible. An outdated activity field can affect monitoring. An incomplete ownership chain can leave relevant parties unidentified. Describing all of these as documentation errors can understate materially different exposures and lead to unsuitable remediation.

Management information should distinguish pending applications, active customers with outstanding conditions, overdue reviews, material exceptions and quality defects. Counts need consistent definitions and reconciliation. A backlog falling because files were moved to an unreported queue is not an improvement. A high completion rate can coexist with poor decision quality. Management should receive the relevant limitations and dependencies as well as the headline number.

Useful action measures can include the age and significance of unresolved work, reasons for delay, effectiveness of interim restrictions and recurrence of material findings. These are internal management choices unless a specific rule requires them. They should support decisions about capacity, process repair and exposure. The bank should not replace necessary investigation with a target to close a fixed number of files each day.

Remediating a customer population

When a CDD weakness affects many customers, the bank should identify the affected population and the decisions that require correction. A new procedure improves future work but does not automatically repair existing files. The plan should distinguish the design change, staff competence, affected-file review and any downstream actions. It should also identify interim protection and the legal position of customers whose required information remains unresolved.

Population definition matters. If a defect concerns entity applicants processed through one provider between two dates, the bank needs a reliable source for those applications and their active status. A list of cases already noticed by reviewers can miss affected customers who have not yet been examined. Reconciliation should connect the source applications, approved relationships and relevant products, preserving exclusions and their reasons.

The bank should prioritise work based on legal requirements, exposure and available evidence rather than customer value alone. Higher-risk unresolved files may need prompt attention, but ordinary files can also contain a binding requirement failure. The plan should identify who can decide interim restrictions or relationship outcomes and how those decisions are implemented. Mass communications should be clear and appropriately scoped to what each customer needs to provide.

Remediation should avoid replacing one weak assessment with another. If the defect is failure to establish authority, collecting another identity document from the operator may not address it. If the defect is an incomplete ownership chain, a generic customer attestation may require additional assessment. The action should establish the missing fact under the applicable framework and preserve the evidence. Progress counts should describe completed assessed work, not merely requests sent.

Downstream effects should be examined. Corrected ownership may affect screening. Corrected customer classification may affect monitoring. An unauthorised user may affect access controls or disputed transactions. The remediation plan should identify these dependencies and allocate owners. A CDD file marked complete while these actions remain outstanding can present management with a false closure claim.

Independent closure review should test the repaired process and the affected population work. It should examine whether the evidence supports the new conclusions, whether exclusions are justified and whether required downstream actions occurred. Unresolved limitations should be visible in the authorised closure decision. A bank should not declare every customer remediated solely because the bulk processing job finished successfully.

Worked case: the new business with a changed payment purpose

Sravanthi opens a design-business account at Malla Bank. The legal customer is a company she owns directly, and she is authorised to operate it. The bank completes the applicable identity and ownership work, understands the business purpose and approves domestic collections and ordinary operating payments. Its assessed profile expects approximately CU 40,000 in monthly client receipts with variation around project milestones. The original approval does not include an intermediary collection service for unrelated businesses.

Three months later, receipts reach CU 160,000. Forty percent of that amount, CU 64,000, comes from payers whose references identify other small businesses. The remaining CU 96,000 is from the design company's established clients. The arithmetic separates the changed activity from the original activity. It does not establish that the CU 64,000 is criminal proceeds, nor that the CU 96,000 is automatically legitimate. It identifies the question requiring assessment.

Ramesh asks why the additional businesses' payments use this account. Sravanthi explains that she has begun helping local firms collect project payments and forward them to their suppliers. This is a material change in role and intended activity. The bank needs to assess the requested service, relevant customer relationships, legal requirements and control visibility. It should not simply increase expected turnover to CU 160,000 and conclude that the monitoring alert has been explained satisfactorily.

Malla's review distinguishes the existing design activity from the new collection activity. The bank considers whether the new service is within its permitted and supported offering, what information it needs about the parties and whether additional legal requirements apply. The chapter does not assume a licensing conclusion without the applicable jurisdiction and facts. The product specialist and relevant compliance decision makers examine that question through the bank's authorised route.

The bank separately examines payments already received and forwarded. A future service decision does not resolve the historical activity. Investigators assess available evidence and any reporting question under the applicable rules. Customer communications address the permissible operational outcome without disclosing restricted reporting information. If restrictions are imposed, they should be specific and enforced rather than merely asking Sravanthi to be careful.

The final customer record preserves the original purpose, when the bank learned of the change, the assessment and the authorised service decision. Monitoring fields are updated only to reflect an assessed permissible arrangement. If the bank cannot support the new service, the record distinguishes that capability decision from any conclusion about wrongdoing. This case demonstrates why a plausible explanation can be useful evidence while still requiring a substantive CDD and product reassessment.

Worked case: a document-association error

Guna Bank uses a verification provider for individual applicants. The provider returns a satisfactory identity result for the document it receives. A bank-side batching defect associates some returned results with the next application in the queue. The verification service is functioning as configured, but the customer record can receive another person's result. A dashboard showing provider success therefore does not establish correct verification for the bank's customer.

Gunaditya identifies the defect after a reviewer notices that one provider reference links to a different date of birth. The affected batch contains 500 applications. The bank reconstructs the association using source identifiers and finds 30 incorrect links, six percent of the batch. Of those 30 applications, 18 became active customers and 12 remain pending. These distinctions matter because the action required for an active relationship may differ from preventing activation of a pending application.

The bank's immediate plan addresses the 12 pending cases through the approved state controls and assesses the legal and operational position of the 18 active relationships. It does not assume all 30 identities are false. The defect concerns evidence association. Each customer's required verification must be completed correctly, and any facts suggesting impersonation or other misuse require their own assessment. The bank also evaluates whether the defect affected screening or other dependent controls.

Ramesh helps design a targeted customer communication where additional information is necessary. The bank first assesses what suitable information it already holds and what it can lawfully reuse. Customers should not receive an unexplained demand for an entire new application if the issue can be resolved more proportionately. The record should preserve the corrected evidence, previous error and date of resolution so assurance can reconstruct the impact.

The technical repair requires matching stable application identifiers and rejecting inconsistent associations rather than relying on batch order. Tests include out-of-order responses, retries and missing results. A live reconciliation compares source applications, provider requests, responses and assessed customer records. Passing a single ordered batch would not demonstrate that these failure conditions are controlled.

An independent reviewer checks the 30 affected cases and a relevant selection of later live applications. The closure evidence distinguishes the association repair, affected-file assessment, active-customer decisions and downstream checks. If a case remains unresolved, it stays visible with an owner and appropriate action. The bank should not close the entire issue merely because the provider continues to report high success rates.

Worked case: reuse of information with a reliability doubt

A United States example concerns a legal entity customer opening an additional account with a covered financial institution. The institution has identified and verified the relevant beneficial owners at the initial opening and applies its procedure under FinCEN's February 2026 relief. Staff should examine whether circumstances permit the contemplated reuse rather than automatically demand a new ownership package solely because another account is requested. They should also assess the new service's purpose and other applicable requirements.

Ramesh then notices a recently supplied document describing a new controlling person, while the stored record names the previous person. This is a fact that can call the reliability of the existing information into question. The relief does not provide a reason to disregard it. The institution follows the applicable rule and order, obtains and assesses the necessary information and records the result. Its ongoing CDD duties remain in place.

The customer says that ownership is unchanged but management has changed. Staff distinguish these concepts and assess the relevant control-prong information under the scoped United States framework. A form asking only whether shares changed can miss the issue. The bank's procedure should identify the information material to its actual requirement rather than interpret every update as an equity transaction.

If the customer cannot confirm that relevant previously obtained information remains accurate, staff follow the order's terms and applicable procedures. The decision record should preserve what triggered the doubt and how it was resolved. This example does not export the United States relief to another country or turn it into a general permission to ignore new information. It demonstrates current scope, justified reuse and the boundary created by a reliability concern.

Decision exercises with assessed answers

A customer submits a valid identity document but the account is requested for a company. The document can support the individual's identity. It does not establish the company's existence, the individual's authority or the relevant ownership and control. Staff should identify the actual customer and capacities, then complete the applicable tasks. Treating one valid document as complete CDD would confuse distinct facts.

A registry and customer chart disagree about a controller. Staff should examine source scope, dates and supporting evidence to determine whether the difference reflects a recent change, a registry limitation or an unresolved inconsistency. The registry should not be dismissed automatically, and the customer chart should not be accepted simply because it is newer. The conclusion should identify the evidence and remaining uncertainty, with escalation where required.

A low-risk customer fails a remote onboarding check because the interface cannot process their document type. Staff should assess a permitted accessible alternative and distinguish a technical rejection from an adverse identity finding. The customer risk rating does not excuse required verification, but the failed upload does not prove impersonation. The bank needs an evidence route that meets its actual requirements.

An analyst proposes updating expected activity after every alert to match actual payments. That approach would erase the comparison baseline. Updates should follow an assessed change in the relationship with a documented reason and appropriate authority. Historical profiles should remain reconstructable. The analyst should separately examine the activity and any reporting question rather than use a profile change to close an alert automatically.

A review programme reports 95 percent complete because 950 of 1,000 request letters were sent. That figure measures communication, not completed assessed reviews. Management needs the number with necessary information received, assessed decisions completed and downstream actions finished, according to the programme's defined states. The original communication count remains useful for tracking effort but should not be labelled CDD completion.

An urgent applicant asks a senior manager to approve a policy exception. The manager should identify whether the requirement is binding law, permissible bank policy or a task that has already been satisfied by suitable evidence. Only then can the proper authority determine the available decision. Commercial urgency can justify prompt attention; it cannot convert an unmet legal requirement into a discretionary waiver.

A defensible customer record

Good CDD leaves the bank with an assessed understanding that can support actual decisions. The record identifies the customer and relevant capacities, connects the required facts to suitable evidence, explains relationship purpose and activity, and states the authorised services and conditions. It preserves material uncertainties and the way they were resolved. It also ensures that necessary information reaches ongoing controls without unrestricted disclosure of sensitive records.

The bank should keep that understanding current through the applicable event-driven and periodic arrangements, evaluate material changes and repair demonstrated weaknesses. It should make the customer process clear and proportionate while respecting mandatory boundaries. Evidence quality, accurate states and appropriate authority matter more than the number of documents collected. A complete file should be one whose conclusion the bank can explain and whose operating consequences it can demonstrate.

Malla can then make a supported service decision, Ramesh can explain what the customer needs to provide, Gunaditya can trace the data used by dependent controls and Sravanthi can receive a process suited to her actual business. Later reviewers can see what the bank knew, when it knew it and what it did. That is the practical value of customer due diligence continuing through the relationship.

Official references and interpretation boundaries

The FATF June 2026 Recommendations supply the international standards referred to in this chapter, including Recommendations 10, 12 and 17. National implementation and the bank's activities determine binding duties. The FATF 2025 financial inclusion guidance and 2020 digital identity guidance inform proportionate access and assessment of digital identity systems; they do not certify a universal evidence substitute or named technology.

The FFIEC CDD overview and FinCEN CDD resource page are expressly United States references. Staff applying the beneficial-ownership requirements should also consult FIN-2026-R001, including its conditions and preserved obligations. The chapter's worked calculations and operating examples are fictional teaching cases, not legal thresholds or statistical estimates of crime.