Join our Newsletter — 33% off our NHI Course
Home› FAQ› Governance, Ownership & Risk› What is the difference between customer due diligence…
Governance, Ownership & Risk

What is the difference between customer due diligence and suitability checks in broker-dealer compliance?

← Back to all FAQ
By NHI Mgmt Group Editorial Team Updated September 29, 2026 Domain: Governance, Ownership & Risk

Customer due diligence establishes who the customer is, who can act for them, and what essential facts define the account. Suitability checks use that information to judge whether a recommended transaction or strategy fits the customer’s financial situation, objectives, and risk tolerance. In practice, due diligence is the foundation, while suitability is the recommendation decision built on top of it.

Why CDD and suitability checks solve different compliance problems

customer due diligence is an account-opening and ongoing-knowledge function: it establishes the customer’s identity, beneficial ownership or authority to act, and the essential facts the firm needs to understand the relationship. Suitability checks come later, at the recommendation stage, where the firm evaluates whether a proposed trade, strategy, or product fits the customer’s profile. The distinction matters because the second control depends on the quality of the first.

In broker-dealer practice, due diligence is about knowing the customer well enough to manage risk and meet onboarding and surveillance obligations. Suitability is about recommendation quality, not just account validity. A firm can know who the client is and still fail suitability if it recommends something inconsistent with the client’s objectives, experience, liquidity needs, or risk tolerance.

How the two controls work together across the client lifecycle

CDD is the foundation because it creates the factual record that later advice or order review relies on. If the firm misidentifies the customer, misses a beneficial owner, or fails to understand who is authorized to trade, every downstream assessment becomes less reliable. That is why customer onboarding, periodic refresh, and event-driven review are core to the control.

Suitability uses that customer record as input, then asks a narrower question: is this specific recommendation appropriate for this specific customer at this point in time? The check is transactional and contextual. A product may be suitable for one customer profile and unsuitable for another, even when both accounts passed due diligence.

The difference is easiest to see in failure cases. Weak due diligence can let the wrong person open or control an account, while weak suitability can let a valid customer receive an inappropriate recommendation. Firms need both, because one control does not substitute for the other.

What broker-dealers should treat as the practical boundary

CDD answers, “Who is this customer, who controls the account, and what facts define the relationship?” Suitability answers, “Given those facts, should we recommend this transaction or strategy?” The boundary is important for supervision, documentation, and escalation. If the account profile is incomplete or stale, the suitability review is already on shaky ground.

Good practice is to treat due diligence updates as triggers for suitability re-evaluation. A material change in income, investment objective, trading authority, or beneficial ownership may change the recommendation decision even if nothing else in the account has changed. Firms that separate the two too rigidly often miss that the same client facts feed both obligations.

Risk and Threat Considerations

The main risk is control drift, where customer facts are collected once but not maintained, and recommendation logic continues to rely on outdated information. That can produce mis-selling, unsuitable recommendations, and weak supervisory defensibility. It also creates room for account misuse if the firm has not correctly established who can act for the customer.

Failure mechanism: incomplete or stale due diligence feeds a suitability review that appears documented but is built on the wrong customer profile, so the firm cannot reliably prove that the recommendation matched the customer’s true situation.

Impact: the firm faces suitability exceptions, customer harm, remediation costs, and heightened regulatory exposure because the onboarding record and the recommendation decision no longer align.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

NIST SP 800-53 Rev 5 sets the technical controls, while ISO/IEC 27001:2022 defines the regulatory obligations.

FrameworkControl / ReferenceRelevance
NIST SP 800-53 Rev 5IA-8 — Identification and Authentication (Non-Organizational Users)Broker-dealer CDD establishes and verifies external customer identity.
IA-2 — Identification and Authentication (Organizational Users)Suitability decisions depend on authenticated supervised personnel making the recommendation.
AC-6 — Least PrivilegeCustomer records and recommendation authority should be limited to the minimum needed to prevent misuse.
Recommendation — Use IA-8 to verify external customer identity before relying on account data for suitability decisions. Use IA-2 to ensure only authorized staff can place or approve recommendations. Apply AC-6 to restrict who can change customer profiles or approve recommendations.
ISO/IEC 27001:2022A.5.15 — Access controlBroker-dealer review processes need controlled access to customer and suitability data.
A.5.16 — Identity managementThe question turns on knowing who the customer is and who can act for them.
Recommendation — Apply A.5.15 to limit access to customer due diligence and suitability records. Apply A.5.16 to manage customer and representative identities consistently across onboarding and review.

Practitioner Guidance

What to verify: Confirm that the customer profile used for suitability is the current profile, not just the original onboarding file. Pay special attention to beneficial ownership, trading authority, investment objective, and any account changes that should force a review.

Decision rule: If the firm cannot explain which customer facts were relied on for the recommendation, treat the suitability determination as weak even if the account passed due diligence. The better evidence is a clear linkage between the approved customer profile and the specific recommendation made.

Practitioner takeaway: Due diligence establishes the decision context, while suitability tests the decision itself; if the context is stale, the recommendation control is already compromised.

Deepen Your Knowledge

Sign up to our weekly newsletter — get 33% off our NHI Foundation Level Course

    NHIMG Editorial Note
    Reviewed and updated by the NHIMG editorial team on September 29, 2026.
    NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org