DNFBPs should start with a risk-based customer due diligence framework that verifies identity, address, occupation, and business purpose before or at the point obligations trigger. For higher-risk customers, such as politically exposed persons or complex corporate structures, teams should add enhanced due diligence, beneficial ownership checks, and ongoing updates when circumstances change materially.
What practical customer due diligence should cover before a higher-risk transaction?
A practical CDD process is not just a form-filling exercise. It should create a repeatable decision path that confirms who the customer is, what they are trying to do, and whether the activity fits the stated profile. For higher-risk cases, the process needs stronger evidence, more frequent review, and clear escalation when the facts do not line up.
In practice, that means capturing identity data, verifying it against reliable sources, and recording the business rationale for the relationship or transaction. A process built this way makes it easier to distinguish routine activity from patterns that require enhanced due diligence, especially where ownership, control, or source of funds is harder to explain.
For cross-border and politically exposed cases, standards from FATF Recommendations — AML and KYC Framework and EBA AML/CFT Guidance both reinforce that the control is meant to be risk-based, not uniform.
How do you make due diligence usable for complex or higher-risk customers?
The process works best when it follows the customer’s real risk profile instead of forcing every case through the same checklist. For lower-risk customers, a standard file may be enough. For higher-risk customers, teams should collect additional corroboration, verify beneficial ownership, and ask whether the transaction purpose is consistent with what has already been established.
Complex corporate structures are where many processes fail. If the team cannot clearly identify the natural persons who ultimately own or control the customer, the file should move into escalation rather than being accepted on the basis of partial documentation. That applies equally when the transaction itself is unusual, the customer is newly formed, or the relationship depends on third-party intermediaries.
A practical way to strengthen this step is to use Identity Proofing and KYC Guide as the upstream verification layer for the identity checks that feed due diligence decisions.
What makes a higher-risk CDD process operationally effective?
It needs explicit triggers, clear ownership, and refresh rules. The team should know when enhanced due diligence is mandatory, who approves exceptions, what evidence must be retained, and which events force a review, such as a material change in ownership, address, business purpose, expected activity, or source of funds.
The other operational requirement is consistency. If different analysts treat the same risk indicators differently, the programme becomes unpredictable and hard to defend. A good process therefore combines structured intake, risk scoring, documented rationale, and periodic review so that the record reflects the customer as it is now, not just as it was at onboarding.
That discipline also aligns with NIST SP 800-53 Rev 5 Security and Privacy Controls, especially where organisations need documented identity, access, and audit controls to support evidence-based review.
Risk and Threat Considerations
Higher-risk CDD fails when organisations treat identity verification as a one-time step instead of an ongoing control. The main exposure is not only false onboarding, but also the later use of a legitimate customer file to obscure beneficial ownership, layer transactions, or move funds through a structure that no longer matches the original profile.
Failure mechanism: Weak source-of-funds review, shallow beneficial ownership checks, or stale customer records can let risky activity pass as ordinary business, especially when the transaction pattern is unusual but still superficially documented.
Impact: The organisation may process transactions it should have escalated, miss suspicious activity indicators, and leave itself with poor defensibility if regulators later ask why the customer was accepted or why the file was not refreshed after risk changed.
Standards & Framework Alignment
This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.
NIST SP 800-53 Rev 5 and CIS Controls v8 set the technical controls, while ISO/IEC 27001:2022 defines the regulatory obligations.
| Framework | Control / Reference | Relevance |
|---|---|---|
| NIST SP 800-53 Rev 5 | IA-2 — Identification and Authentication (Organizational Users) | CDD relies on verified identity evidence before risk decisions are made. |
| IA-8 — Identification and Authentication (Non-Organizational Users) | Customer due diligence depends on authenticating external parties and their claimed identity. | |
| AU-2 — Event Logging | CDD needs audit evidence for reviews, escalations, and material changes. | |
| Recommendation — Verify identity evidence before allowing higher-risk customer transactions. Apply stronger assurance to external customer identity verification. Log review decisions, exceptions, and material customer changes. | ||
| ISO/IEC 27001:2022 | A.5.15 — Access control | CDD supports controlled approval of higher-risk transactions and exceptions. |
| Recommendation — Enforce approval and exception handling for higher-risk cases. | ||
| CIS Controls v8 | CIS-5 — Account Management | CDD is a governance process for verifying and reviewing customer records. |
| Recommendation — Maintain and review customer records with risk-based governance. | ||
Practitioner Guidance
What to prioritise: Build the process around the highest-risk decision points first, beneficial ownership, source of funds, purpose of transaction, and review triggers. If those four are weak, the rest of the workflow will not materially improve the control outcome.
What to verify: Before trusting the file, confirm that the evidence actually supports the stated risk rating. The practical test is whether a reviewer could explain, from the record alone, why this customer was accepted, why the transaction was permitted, and what would force a refresh.
Practitioner takeaway: Good CDD is not defined by the number of fields collected, but by whether the process can justify a higher-risk decision, detect when the customer profile has changed, and force escalation when the evidence no longer fits.
Related resources from NHI Mgmt Group
- How should compliance teams implement customer due diligence under Kenya’s AML framework in higher-risk onboarding flows?
- When do service accounts become a higher risk than ordinary user accounts?
- Why do high-risk customers need more than standard customer due diligence?
- Why do standard due diligence checks fail for higher-risk relationships?