FinCEN Customer Due Diligence: Knowing Your Customer Is Only the Beginning
- John C. Blackshire, Jr.

- 1 hour ago
- 7 min read
FinCEN's CDD Rule — September 21 and November 16, 2026
For years, financial institutions have been told to Know Your Customer.
FinCEN's Customer Due Diligence requirements push that concept considerably further.
It is not enough to know the name on the account. Financial institutions need to understand who owns or controls a legal entity, the nature and purpose of the customer relationship, the customer's risk profile, and whether subsequent activity makes sense in light of that profile.
That makes Customer Due Diligence—or CDD—much more than an account-opening exercise.
It is an ongoing AML internal-control process.
Corporate Compliance Seminars' FinCEN's CDD Rule is a two-hour, 2-CPE Auditing webinar designed for compliance professionals, Internal Auditors and financial executives who need to understand CDD requirements and evaluate whether their organization's controls actually satisfy them. The CCS program specifically addresses beneficial ownership, controlling persons, customer risk profiles, updating customer information and transaction monitoring.
Upcoming sessions are:
Monday, September 21, 2026
Monday, November 16, 2026
CDD Is the Fifth Prong of an AML Program
One of the central concepts covered in the CCS program is the relationship between traditional BSA/AML requirements and the addition of Customer Due Diligence as the fifth prong of an AML compliance program.
CDD substantially strengthens the idea that a financial institution should understand not simply the customer's identity, but the risk represented by the customer relationship.
Think about the progression:
Who are you?
→ What entity do you represent?
→ Who owns the entity?
→ Who controls it?
→ Why do you need this account?
→ What activity should we expect?
→ What activity actually occurs?
→ Does the activity make sense?
That last question is where CDD becomes particularly important to AML.
Customer Acceptance Is Only the Starting Point
An organization can perform excellent customer identification procedures when an account is opened and still have a weak CDD program.
Why?
Because risk changes.
A customer's ownership may change.
Business activities may change.
Transaction volumes may increase.
Geographic exposure may change.
New counterparties may appear.
An account originally established for relatively simple domestic transactions might later begin processing substantial international transfers.
That means CDD cannot be treated as:
“We checked the customer when the account was opened. Done.”
The CCS program specifically emphasizes updating risk profiles and monitoring baseline or normal customer transactions.
Establish a Customer Risk Profile
One of the most useful concepts in CDD is the customer risk profile.
The financial institution should understand what the relationship is expected to look like.
Depending upon the customer, relevant characteristics could include:
Business activities
Ownership
Geographic exposure
Expected transaction volume
Expected transaction types
Products and services used
Sources of funds
Expected counterparties
This gives transaction monitoring context.
Without a baseline, the institution may know that a transaction occurred but have little basis for deciding whether it is unusual.
Baseline Normal Activity
Suppose a small domestic business normally has:
$200,000 of monthly account activity.
Domestic customers.
No international wire transfers.
Relatively predictable vendor payments.
Then the account suddenly receives $2 million and sends multiple international wires.
Is that money laundering?
Not necessarily.
But it is inconsistent with the established baseline.
That should cause the institution to ask:
What changed?
The CCS program specifically includes monitoring baseline/"normal" transactions as a core CDD topic.
The process becomes:
Expected Activity
→ Actual Activity
→ Variance
→ Investigation
→ Risk Reassessment
→ Escalation if Necessary
That is a control system.
Beneficial Ownership Matters
Legal entities can make financial transparency difficult.
The person opening an account may not actually own the organization.
The named entity may itself be owned by another entity.
Ownership structures can become complicated.
That creates an obvious AML question:
Who ultimately owns or controls the customer?
CCS's CDD program therefore specifically addresses customer legal entities, beneficial owners, controlling persons and exclusions.
For Internal Audit, this should translate into testing.
Don't merely ask:
“Does our policy require beneficial-ownership information?”
Select accounts.
Inspect the evidence.
Determine whether required information was obtained.
Determine whether it was verified as required.
Determine how exceptions were handled.
Determine whether changes are appropriately incorporated into the customer risk profile.
CDD and Transaction Monitoring Belong Together
A sophisticated transaction-monitoring system is considerably more valuable when it understands what activity should be expected.
Consider two customers making the same $250,000 international transfer.
For Customer A, that transaction may be completely ordinary.
For Customer B, it may be highly unusual.
The transaction is identical.
The risk context is different.
That is why CDD and transaction monitoring should not operate as isolated compliance processes.
CDD establishes context.
Transaction monitoring evaluates activity against that context.
Internal Audit Should Test the Entire CDD Lifecycle
CDD should be audited as a process rather than as a collection of forms.
A useful audit trail is:
Customer Onboarding
→ Identity Verification
→ Legal Entity Identification
→ Beneficial Ownership
→ Controlling Person
→ Customer Risk Rating
→ Expected Activity
→ Ongoing Monitoring
→ Changes in Customer Information
→ Risk-Profile Update
→ Transaction Monitoring
→ Investigation
→ SAR Consideration
This allows Internal Audit to determine whether information gathered during onboarding actually influences downstream AML monitoring.
A Completed Form Is Not an Effective Control
This is a familiar Internal Audit problem.
The workpaper says: CDD completed.
The customer file contains the required form.
The boxes are checked.
Does that establish an effective CDD process?
Not necessarily.
Internal Audit should ask:
Was the information accurate?
Was it complete?
Was it appropriately verified?
Was the risk rating reasonable?
Was contradictory information investigated?
Did the information affect transaction monitoring?
Was the profile updated when circumstances changed?
A completed checklist proves that somebody completed a checklist.
It doesn't necessarily prove that the CDD control worked.
Data Quality Can Undermine the Entire AML System
Modern CDD and transaction-monitoring programs depend heavily upon technology.
That introduces an IT-control issue.
Consider the flow:
Customer Information
→ Core Banking System
→ CDD System
→ Customer Risk Rating
→ Transaction Monitoring
→ Alert
→ Investigation
→ SAR Process
What happens if customer information doesn't flow correctly between systems?
What happens if a risk-rating field is missing?
What happens if certain transactions never reach the monitoring platform?
The transaction-monitoring rules can operate exactly as programmed and the AML program can still fail.
Internal Audit should therefore ask:
How does management know the information feeding the AML system is complete and accurate?
Risk Ratings Need to Mean Something
Many financial institutions classify customers as:
Low Risk
Moderate Risk
High Risk
That creates another audit opportunity.
What actually determines the rating?
Is it based upon defined criteria?
Is the methodology consistently applied?
Can employees override the rating?
Who approves an override?
What evidence supports it?
Does a high-risk rating trigger additional procedures?
How often is the rating reconsidered?
If every customer receives a risk rating but the rating doesn't change what the organization does, the control may have little practical value.
CDD Should Connect With Fraud
There is another important consideration.
Fraud and AML frequently overlap.
A fraudulent entity may use:
Stolen identities
Synthetic identities
Shell companies
Nominee owners
Money mules
False business information
The CDD process can therefore provide valuable information not only to the AML department, but also to fraud investigators and other risk functions.
The organization should ask:
Are our fraud and AML functions sharing relevant customer-risk information—or are they operating in separate silos?
Internal Audit Should Challenge the High-Risk Customer Population
One particularly useful audit procedure is to examine customers classified as high risk.
Ask:
Why is the customer high risk?
What additional due diligence occurred?
What additional monitoring occurs?
Who reviews the relationship?
How frequently is customer information updated?
Have unusual transactions occurred?
Were alerts investigated?
Were SARs considered?
Then reverse the analysis.
Select customers with high-risk characteristics and ask:
Were they actually classified as high risk?
That can identify weaknesses in the risk-rating methodology itself.
CDD Is About Understanding Relationships
A strong CDD program ultimately tries to answer a relatively simple question:
Does what we are seeing make sense given what we know about this customer?
If the answer is yes, continue monitoring.
If the answer is no, investigate.
That does not mean every unusual transaction is suspicious activity.
It means unusual activity deserves enough analysis to determine whether there is a reasonable explanation.
Internal Audit Has an Important Role
CCS specifically identifies Internal Auditors as one of the intended audiences for its
FinCEN CDD training, alongside compliance professionals and financial executives.
Internal Audit can provide independent assurance over questions such as:
Is the CDD program properly designed?
Are beneficial owners appropriately identified?
Are customer risk profiles meaningful?
Are higher-risk relationships subject to appropriate controls?
Is customer information updated?
Does transaction monitoring reflect customer risk?
Are exceptions investigated?
Are technology and data reliable?
Does management monitor program effectiveness?
These are classic internal-control questions applied to AML.
CDD Should Be on the Audit Committee's Radar
For financial institutions with significant AML exposure, the Audit Committee should understand more than whether management says the organization is compliant.
Governance should ask:
What percentage of our customers are classified as high risk?
What are the principal reasons for those classifications?
Are customer reviews current?
How many significant CDD exceptions are outstanding?
Have regulators identified CDD weaknesses?
Are repeat findings occurring?
Does Internal Audit believe the CDD program is operating effectively?
That last question matters.
Compliance owns and operates the program.
Internal Audit provides independent assurance over it.
Two Opportunities to Attend in 2026
Corporate Compliance Seminars' FinCEN's CDD Rule is a Basic-level, Group Internet-Based program providing 2 NASBA-approved CPE credits in Auditing. The CCS program is offered on Mondays from 10:00 a.m. to noon Central Time, with no prerequisites or advance preparation.
Monday, September 21, 2026
The September program provides Internal Auditors and compliance professionals an opportunity to strengthen their understanding of CDD, beneficial ownership, customer risk profiles and ongoing transaction monitoring.
Monday, November 16, 2026
The November session is particularly well positioned for organizations developing their 2027 AML compliance plans, risk assessments and Internal Audit programs.
The Bottom Line: Know What Normal Looks Like
The real power of Customer Due Diligence isn't simply collecting more information about customers.
It is using that information to understand risk.
The progression should be:
Know the Customer
→ Understand the Legal Entity
→ Understand Ownership and Control
→ Understand the Relationship
→ Establish the Risk Profile
→ Establish Expected Activity
→ Monitor Actual Activity
→ Investigate Meaningful Deviations
→ Update the Risk Profile
→ Escalate Suspicious Activity
That is what turns CDD from a compliance exercise into an effective AML control.
CCS's FinCEN's CDD Rule webinar on September 21 and November 16, 2026 provides two focused CPE hours on developing that understanding and applying it to compliance and Internal Audit.
Comments