Join our Newsletter — 33% off our NHI Course

Standard Due Diligence

Standard due diligence is the normal control layer used for customers with ordinary risk. It requires mandatory identity authentication, collection of core documents, and verification of the person or entity being represented. The goal is to establish a reliable customer profile before the relationship and transactions progress further.

What Standard Due Diligence Covers

Standard due diligence is the baseline customer review used when the relationship presents ordinary risk. It sits above a simple intake check and focuses on knowing who or what is being represented before trust, transaction limits, or ongoing access expand.

In practice, that baseline usually includes identity authentication, core documentation, and verification that the stated person or entity is real and properly represented. The standard is meant to create a reliable customer profile, not to prove the highest possible assurance level.

Why Standard Due Diligence Exists

The purpose of standard due diligence is to reduce the chance that an organisation onboards a fabricated, misrepresented, or poorly understood customer. That matters because the first profile often becomes the reference point for later monitoring, transaction review, and escalation decisions.

It also establishes a defensible boundary between ordinary-risk customers and those that warrant deeper review. The quality of the initial due diligence directly affects how much confidence a team can place in downstream decisions, especially when the relationship later becomes more complex.

How It Differs From Enhanced Review

Standard due diligence is not the same as enhanced due diligence. Enhanced review is triggered when risk is higher, ownership is less transparent, the activity is unusual, or the customer profile raises additional concerns that require more evidence and scrutiny.

For ordinary-risk cases, the goal is completeness and reliability, not exhaustive investigation. When the facts do not fit the standard profile, the review should not be forced to remain standard simply because a workflow prefers speed.

That distinction is important because due diligence is a risk-based control, not a fixed paperwork exercise. The same customer may remain standard at onboarding but move into a more intensive review path if later facts change the risk picture.

What Good Standard Due Diligence Produces

Well-executed standard due diligence produces a trusted baseline: a verified identity, a documented relationship, and enough context to support appropriate screening, monitoring, and approval decisions. It should leave a reviewer able to explain who the customer is, why they are present, and what evidence supports that view.

Where the organisation depends on remote onboarding, the reliability of document checks and identity verification becomes especially important. Remote collection can be efficient, but it also increases the need for careful verification of documents, representations, and continuity between the claimed identity and the evidence provided.

When the process is weak, the result is often not an obvious failure but a thin profile that looks complete on paper. That creates future friction because later teams have to compensate for missing facts, inconsistent records, or unresolved identity questions.

Risk and Threat Considerations

Standard due diligence is exposed to misrepresentation, document fraud, synthetic identities, and weak verification processes. Those failures can allow a customer profile to appear legitimate while the underlying person, entity, or controlling relationship is false or incomplete.

Failure mechanism: Attackers or fraudsters exploit shallow document review, reused identity elements, or weak entity verification to pass as an ordinary-risk customer and move into a trusted workflow.

Impact: The organisation may onboard the wrong party, miss sanctions or fraud signals, weaken transaction monitoring, and build future decisions on an unreliable customer record.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

NIST SP 800-63, NIST SP 800-53 Rev 5 and CIS Controls v8 set the governance and control requirements practitioners need to meet.

Framework Control / Reference Relevance
NIST SP 800-63 IAL — Identity Assurance Levels Standard due diligence depends on verifying customer identity to an assurance level suitable for ordinary risk.
Recommendation — Set the identity assurance level to match the customer risk and verify the claimed identity before onboarding.
NIST SP 800-53 Rev 5 IA-8 — Identification and Authentication (Non-Organizational Users) Customer due diligence requires authenticating external persons or entities before trusting their profile.
IA-12 — Identity Proofing The term centers on proving the person or entity being represented before the relationship progresses.
AC-2 — Account Management Due diligence outcomes support whether a customer relationship and account should be created or maintained.
Recommendation — Require strong authentication for external users and tie the verified identity to the onboarding record. Use identity proofing controls to validate the claimed customer identity before account approval. Gate account creation and continuation on completion of the required due diligence checks.
CIS Controls v8 CIS-5 — Account Management Baseline customer review supports controlled account lifecycle and review of who receives access.
Recommendation — Align account onboarding and review steps to the verified customer profile before granting access.

Practitioner Guidance

Why practitioners should care: Standard due diligence is often treated as a routine intake step, but it is the point where customer trust is first established. If the baseline is weak, later monitoring and escalation logic inherit the error.

Common misunderstanding: “Standard” does not mean “minimal.” It means proportionate to ordinary risk, with enough verification to support a reliable profile and a defensible decision trail.

Practitioner takeaway: Treat the standard path as a quality control gate, not an administrative formality, because its output becomes the starting point for every later review.