Join our Newsletter — 33% off our NHI Course

What is the difference between KYC and customer due diligence in 5AMLD compliance?

KYC is the process of verifying who a customer is, while customer due diligence is the broader control set used to understand the customer relationship and assess risk over time. Under 5AMLD, both matter because firms must identify customers, evaluate activity, and maintain enough evidence to support monitoring, reporting, and regulator review.

KYC identifies the customer, CDD manages the relationship

Under 5AMLD, KYC is the point-in-time process of establishing who the customer is, while customer due diligence is the broader control set that keeps testing whether the relationship still makes sense. That distinction matters because a firm can complete onboarding checks and still fail its ongoing obligations if it does not monitor behaviour, update risk, and retain evidence.

CDD is not just a thicker version of KYC. It also covers understanding the purpose and intended nature of the relationship, checking beneficial ownership where relevant, and applying ongoing scrutiny when activity, geography, product use, or transaction patterns change. That is why KYC is best treated as one input into CDD, not as a substitute for it.

Practitioners usually get into trouble when they reduce compliance to onboarding forms and identity documents. A stronger model is to think in layers: verify the customer, understand the relationship, then keep checking that the observed behaviour remains consistent with the stated profile.

How 5AMLD turns a one-time check into an ongoing control

5AMLD pushes firms toward lifecycle thinking. Once the customer is accepted, the control objective shifts from “is this person real?” to “is this customer still operating within the expected risk boundary?” That is why monitoring, periodic review, trigger events, and escalation paths are part of CDD even when the initial KYC file looked clean.

The regulatory value of that broader scope is that it helps firms catch risk drift. A customer may start as low risk and later become higher risk because of a changed ownership structure, new payment behaviour, unusual counterparties, or a material change in sanctions, geography, or business model. KYC alone will not surface that shift unless it is embedded in a CDD process with defined review criteria.

For readers who want the regulatory basis rather than a summary, the FATF Recommendations set the international AML/CFT baseline that underpins the KYC and CDD distinction, and the EBA AML/CFT guidance provides the EU supervisory lens that firms often map into operating procedures.

Risk and Threat Considerations

The practical risk is treating KYC as a documentation exercise and CDD as an occasional review, because that creates blind spots between onboarding and detection. In AML programmes, the weak point is often not whether a record exists, but whether the firm can explain why the customer remains acceptable as activity evolves.

Failure mechanism: A customer can pass initial verification, then change ownership, behaviour, or transaction profile in a way that should have triggered enhanced due diligence, but the firm misses it because monitoring thresholds, escalation rules, or ownership refresh are too weak.

Impact: The result can be regulatory breach, missed suspicious activity reporting, poor auditability, and exposure to higher-risk or illicit activity that should have been challenged earlier.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

NIST CSF 2.0, CIS Controls v8 and NIST SP 800-63 set the governance and control requirements practitioners need to meet.

Framework Control / Reference Relevance
NIST CSF 2.0 GV.RM-01 — Risk Management Strategy CDD requires ongoing risk-based review of customer relationships.
GV.OV-02 — Oversight of External Risk CDD includes oversight of counterparties, ownership changes, and third-party exposure.
Recommendation — Adopt a risk-based review process that updates customer risk when behaviour or ownership changes. Review external relationship changes that can alter customer risk.
CIS Controls v8 5.1 — Establish and Maintain an Inventory of Accounts KYC and CDD both depend on accurate account and customer records over time.
Recommendation — Maintain accurate customer and account inventories to support ongoing review and evidence retention.
NIST SP 800-63 IAL1 — Identity Proofing KYC hinges on establishing who the customer is before broader due diligence begins.
Recommendation — Use identity-proofing evidence as the baseline input to due diligence decisions.

Practitioner Guidance

What to verify: Check that your KYC record supports the CDD decision, not just the onboarding decision. The file should show the expected purpose of the relationship, risk rating rationale, beneficial ownership evidence where applicable, and the specific triggers that force a review.

Decision rule: If a control only proves identity at onboarding, treat it as KYC evidence, not full CDD. If the relationship can change in a way that alters risk, you need an ongoing review mechanism, not just a completed verification step.

Practitioner takeaway: In 5AMLD compliance, the real test is whether the firm can justify the customer’s risk position over time, not whether it can prove the customer’s name once.