ACAMS Customer Due Diligence (CDD) 2 — Questions and Answers
Question 1: Under FinCEN's Customer Due Diligence Rule (31 CFR 1010.230), what are the four core elements of CDD?
- Identification, verification, monitoring, and reporting
- Customer identification, beneficial ownership identification, understanding the customer's business, and ongoing monitoring (Correct answer)
- KYC, EDD, SAR filing, and CTR filing
- Account opening, transaction approval, risk scoring, and annual review
Correct answer: Customer identification, beneficial ownership identification, understanding the customer's business, and ongoing monitoring
FinCEN's 2016 CDD Rule established four core elements: (1) identifying and verifying the customer's identity; (2) identifying and verifying beneficial owners of legal entity customers; (3) understanding the nature and purpose of the relationship; and (4) conducting ongoing monitoring and updating customer information.
FinCEN's CDD Rule (effective May 2018) established four core requirements for covered financial institutions: (1) Customer identification and verification — applying CIP procedures to collect and verify identity information; (2) Beneficial ownership identification and verification — identifying and verifying the identity of beneficial owners of legal entity customers (those owning 25% or more, plus one control prong); (3) Understanding the relationship — determining the nature and purpose of the customer relationship to develop a risk profile; (4) Ongoing monitoring — conducting transaction monitoring to detect suspicious activity and updating customer information when triggered by certain events. These four elements form the foundation of a compliant CDD program.
Question 2: Under the FinCEN CDD Rule, who qualifies as a 'beneficial owner' of a legal entity customer?
- Any employee of the customer with signatory authority on the account
- Each individual who owns, directly or indirectly, 25% or more of the equity interests of a legal entity, plus one individual who controls or manages the entity (Correct answer)
- Only the CEO and CFO of the legal entity customer
- Any individual who has conducted a transaction through the account in the past 12 months
Correct answer: Each individual who owns, directly or indirectly, 25% or more of the equity interests of a legal entity, plus one individual who controls or manages the entity
The FinCEN CDD Rule defines beneficial owners using a two-prong test: the ownership prong (anyone owning 25% or more) and the control prong (one individual who controls or manages the entity, typically the CEO, COO, or equivalent).
The FinCEN Beneficial Ownership Rule requires covered financial institutions to identify and verify the beneficial owners of legal entity customers. The ownership prong requires identification of each individual owning, directly or indirectly, 25% or more of the equity interests. The control prong requires identification of one individual with significant responsibility to control or manage the entity (CEO, CFO, COO, Managing Member, General Partner, etc.). An institution may collect this information on a Certification Form completed by a representative of the legal entity. Certain entity types are exempt from the rule (publicly traded companies, government entities, regulated financial institutions, etc.). The information must be verified, and updated when triggered by account activity.
Question 3: What is 'simplified due diligence' (SDD) and when may it be applied?
- A shortened account opening process for customers referred by employees
- A reduced level of CDD measures that may be applied to lower-risk customers where the risk of money laundering is demonstrably low (Correct answer)
- An expedited CDD process for VIP or private banking customers
- CDD performed by a third party on behalf of the primary institution
Correct answer: A reduced level of CDD measures that may be applied to lower-risk customers where the risk of money laundering is demonstrably low
Simplified due diligence allows institutions to apply reduced CDD measures to clearly lower-risk customers — such as government entities, publicly listed companies, or low-value retail accounts — where the inherent ML/TF risk does not justify standard CDD requirements.
Under the FATF risk-based approach, SDD may be applied when the risk of ML/TF is lower. Eligible customers typically include: domestic government entities; publicly listed companies subject to disclosure requirements; regulated financial institutions in lower-risk jurisdictions; and retail customers with low-value, low-complexity products (e.g., basic savings accounts). SDD does not mean no due diligence — institutions still collect basic identifying information and monitor transactions. SDD cannot be applied in circumstances that inherently indicate higher risk (e.g., when a customer is known to be from a high-risk jurisdiction or is a PEP). Some jurisdictions do not permit SDD for certain product types regardless of customer risk profile.
Question 4: What is a 'trigger event' in the context of CDD ongoing monitoring, and can you provide three examples?
- A transaction that triggers an automatic SAR filing; examples: transactions over $10K, foreign wire transfers, cash deposits
- An event requiring a financial institution to review and potentially update a customer's CDD information; examples: significant changes in transaction patterns, adverse media, or customer-initiated changes to account information (Correct answer)
- A system alert requiring immediate account freeze; examples: OFAC match, court order, law enforcement request
- An indicator that a customer is about to close their account; examples: declining balance, reduced transaction frequency, competitor promotional offers
Correct answer: An event requiring a financial institution to review and potentially update a customer's CDD information; examples: significant changes in transaction patterns, adverse media, or customer-initiated changes to account information
Trigger events are circumstances that prompt a review and potential update of a customer's CDD file. Examples include significant changes in transaction activity, adverse media hits, changes to beneficial ownership, or requests for new high-risk products.
FinCEN's CDD Rule requires ongoing monitoring including updating customer information when the institution becomes aware of information that triggers a new review. Common trigger events include: significant deviations from established transaction patterns; adverse media or negative news hits; law enforcement inquiries about a customer; changes in beneficial ownership or control structure; customer requests for new products associated with higher ML risk; changes in country of operation or business activity; receipt of large, unexplained cash deposits or international wire transfers inconsistent with known business; and approaching or exceeding annual AML review thresholds. Trigger events require documentation, review of the full CDD file, and determination of whether updated information or enhanced measures are warranted.
Question 5: What is 'reliance on third parties' for CDD, and what conditions must be met for this reliance to be permissible?
- Using automated software to conduct CDD without human review; requires regulatory approval
- Allowing another regulated financial institution to conduct CDD on a customer and relying on those results, subject to specific conditions including written agreement, immediate access to records, and satisfaction that the third party is regulated and supervised (Correct answer)
- Outsourcing CDD to non-regulated service providers for cost savings; permitted without restrictions
- Requiring customers to self-certify their identity information; permissible for all customer types
Correct answer: Allowing another regulated financial institution to conduct CDD on a customer and relying on those results, subject to specific conditions including written agreement, immediate access to records, and satisfaction that the third party is regulated and supervised
Financial institutions may rely on third parties (other regulated institutions) to conduct elements of CDD, provided specific conditions are met: a written agreement, the ability to obtain CDD records upon request, and satisfaction that the third party is subject to AML regulation and supervision.
Under 31 CFR 1010.610, financial institutions may rely on another regulated financial institution to perform elements of the CDD process, provided: there is a written agreement in place; the relying institution can obtain the underlying CDD information upon request within a timeframe consistent with the institution's risk management practices; the relied-upon institution is subject to an AML program requirement and is supervised by a federal functional regulator. Critically, the relying institution remains legally responsible for AML compliance — the liability does not transfer to the third party. This provision is commonly used in correspondent banking, syndicated loan transactions, and institutional brokerage relationships where introducing brokers may conduct initial customer identification.
Question 6: What is the difference between Customer Identification Program (CIP) and Customer Due Diligence (CDD)?
- CIP and CDD are interchangeable terms for the same regulatory requirement
- CIP is the minimum identity verification process at account opening (name, address, DOB, ID number), while CDD is the broader ongoing program that includes risk profiling, beneficial ownership, and transaction monitoring (Correct answer)
- CIP applies to individuals while CDD applies to legal entities
- CIP is required by FinCEN while CDD is only a best practice recommendation
Correct answer: CIP is the minimum identity verification process at account opening (name, address, DOB, ID number), while CDD is the broader ongoing program that includes risk profiling, beneficial ownership, and transaction monitoring
CIP is the foundational identity verification requirement at account opening (collecting and verifying name, date of birth, address, and identification number). CDD is the broader, ongoing program that encompasses CIP plus risk profiling, beneficial ownership identification, understanding the business relationship, and ongoing monitoring.
Customer Identification Program (CIP) requirements under 31 CFR 1020.220: collect name, date of birth (individuals), address, identification number; verify identity using documentary (government ID) or non-documentary methods; compare against government lists (OFAC SDN); and retain records. CDD is the broader framework that includes CIP plus: risk classification of the customer; beneficial ownership identification for legal entities; understanding the nature and purpose of the relationship (expected account activity); ongoing transaction monitoring; periodic reviews and updates of customer information; and EDD for high-risk customers. CIP is the starting point — CDD encompasses the entire lifecycle of the customer relationship.
Under FinCEN's Customer Due Diligence Rule (31 CFR 1010.230), what are the four core elements of CDD?