KYC is the process of verifying who a customer is, while customer due diligence is the broader control set used to understand the customer relationship and assess risk over time. Under 5AMLD, both matter because firms must identify customers, evaluate activity, and maintain enough evidence to support monitoring, reporting, and regulator review.
KYC identifies the customer, CDD manages the relationship
Under 5AMLD, KYC is the point-in-time process of establishing who the customer is, while customer due diligence is the broader control set that keeps testing whether the relationship still makes sense. That distinction matters because a firm can complete onboarding checks and still fail its ongoing obligations if it does not monitor behaviour, update risk, and retain evidence.
CDD is not just a thicker version of KYC. It also covers understanding the purpose and intended nature of the relationship, checking beneficial ownership where relevant, and applying ongoing scrutiny when activity, geography, product use, or transaction patterns change. That is why KYC is best treated as one input into CDD, not as a substitute for it.
Practitioners usually get into trouble when they reduce compliance to onboarding forms and identity documents. A stronger model is to think in layers: verify the customer, understand the relationship, then keep checking that the observed behaviour remains consistent with the stated profile.
How 5AMLD turns a one-time check into an ongoing control
5AMLD pushes firms toward lifecycle thinking. Once the customer is accepted, the control objective shifts from “is this person real?” to “is this customer still operating within the expected risk boundary?” That is why monitoring, periodic review, trigger events, and escalation paths are part of CDD even when the initial KYC file looked clean.
The regulatory value of that broader scope is that it helps firms catch risk drift. A customer may start as low risk and later become higher risk because of a changed ownership structure, new payment behaviour, unusual counterparties, or a material change in sanctions, geography, or business model. KYC alone will not surface that shift unless it is embedded in a CDD process with defined review criteria.
For readers who want the regulatory basis rather than a summary, the FATF Recommendations set the international AML/CFT baseline that underpins the KYC and CDD distinction, and the EBA AML/CFT guidance provides the EU supervisory lens that firms often map into operating procedures.
Risk and Threat Considerations
The practical risk is treating KYC as a documentation exercise and CDD as an occasional review, because that creates blind spots between onboarding and detection. In AML programmes, the weak point is often not whether a record exists, but whether the firm can explain why the customer remains acceptable as activity evolves.
Failure mechanism: A customer can pass initial verification, then change ownership, behaviour, or transaction profile in a way that should have triggered enhanced due diligence, but the firm misses it because monitoring thresholds, escalation rules, or ownership refresh are too weak.
Impact: The result can be regulatory breach, missed suspicious activity reporting, poor auditability, and exposure to higher-risk or illicit activity that should have been challenged earlier.
Standards & Framework Alignment
This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.
NIST CSF 2.0, CIS Controls v8 and NIST SP 800-63 set the governance and control requirements practitioners need to meet.
| Framework | Control / Reference | Relevance |
|---|---|---|
| NIST CSF 2.0 | GV.RM-01 — Risk Management Strategy | CDD requires ongoing risk-based review of customer relationships. |
| GV.OV-02 — Oversight of External Risk | CDD includes oversight of counterparties, ownership changes, and third-party exposure. | |
| Recommendation — Adopt a risk-based review process that updates customer risk when behaviour or ownership changes. Review external relationship changes that can alter customer risk. | ||
| CIS Controls v8 | 5.1 — Establish and Maintain an Inventory of Accounts | KYC and CDD both depend on accurate account and customer records over time. |
| Recommendation — Maintain accurate customer and account inventories to support ongoing review and evidence retention. | ||
| NIST SP 800-63 | IAL1 — Identity Proofing | KYC hinges on establishing who the customer is before broader due diligence begins. |
| Recommendation — Use identity-proofing evidence as the baseline input to due diligence decisions. | ||
Practitioner Guidance
What to verify: Check that your KYC record supports the CDD decision, not just the onboarding decision. The file should show the expected purpose of the relationship, risk rating rationale, beneficial ownership evidence where applicable, and the specific triggers that force a review.
Decision rule: If a control only proves identity at onboarding, treat it as KYC evidence, not full CDD. If the relationship can change in a way that alters risk, you need an ongoing review mechanism, not just a completed verification step.
Practitioner takeaway: In 5AMLD compliance, the real test is whether the firm can justify the customer’s risk position over time, not whether it can prove the customer’s name once.
Related resources from NHI Mgmt Group
- What is the difference between customer identification and customer due diligence in Thailand compliance programmes?
- What is the difference between customer identification and customer due diligence in AML compliance?
- What is the difference between customer identification and customer due diligence in eCommerce KYC?
- What is the difference between standard KYC and enhanced due diligence for customer verification?
Deepen Your Knowledge
Free weekly newsletter
Subscribe to the NHI & AI Identity Journal
The latest on NHI and Agentic AI security – articles, research, breaches, news and events every week.
Bonus 33% off our NHI Course when you subscribe.
Reviewed and updated by the NHIMG editorial team on September 18, 2026.
NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org