top of page
Search

FinCEN Customer Due Diligence: Knowing Your Customer Is Only the Beginning

FinCEN's CDD Rule — September 21 and November 16, 2026

For years, financial institutions have been told to Know Your Customer.


FinCEN's Customer Due Diligence requirements push that concept considerably further.

It is not enough to know the name on the account. Financial institutions need to understand who owns or controls a legal entity, the nature and purpose of the customer relationship, the customer's risk profile, and whether subsequent activity makes sense in light of that profile.


That makes Customer Due Diligence—or CDD—much more than an account-opening exercise.


It is an ongoing AML internal-control process.


Corporate Compliance Seminars' FinCEN's CDD Rule is a two-hour, 2-CPE Auditing webinar designed for compliance professionals, Internal Auditors and financial executives who need to understand CDD requirements and evaluate whether their organization's controls actually satisfy them. The CCS program specifically addresses beneficial ownership, controlling persons, customer risk profiles, updating customer information and transaction monitoring.


Upcoming sessions are:

  • Monday, September 21, 2026

  • Monday, November 16, 2026



CDD Is the Fifth Prong of an AML Program

One of the central concepts covered in the CCS program is the relationship between traditional BSA/AML requirements and the addition of Customer Due Diligence as the fifth prong of an AML compliance program.


CDD substantially strengthens the idea that a financial institution should understand not simply the customer's identity, but the risk represented by the customer relationship.


Think about the progression:


Who are you?

What entity do you represent?

Who owns the entity?

Who controls it?

Why do you need this account?

What activity should we expect?

What activity actually occurs?

Does the activity make sense?


That last question is where CDD becomes particularly important to AML.


Customer Acceptance Is Only the Starting Point

An organization can perform excellent customer identification procedures when an account is opened and still have a weak CDD program.


Why?


Because risk changes.


A customer's ownership may change.


Business activities may change.


Transaction volumes may increase.


Geographic exposure may change.


New counterparties may appear.


An account originally established for relatively simple domestic transactions might later begin processing substantial international transfers.


That means CDD cannot be treated as:

“We checked the customer when the account was opened. Done.”

The CCS program specifically emphasizes updating risk profiles and monitoring baseline or normal customer transactions.


Establish a Customer Risk Profile

One of the most useful concepts in CDD is the customer risk profile.


The financial institution should understand what the relationship is expected to look like.


Depending upon the customer, relevant characteristics could include:

  • Business activities

  • Ownership

  • Geographic exposure

  • Expected transaction volume

  • Expected transaction types

  • Products and services used

  • Sources of funds

  • Expected counterparties


This gives transaction monitoring context.


Without a baseline, the institution may know that a transaction occurred but have little basis for deciding whether it is unusual.


Baseline Normal Activity

Suppose a small domestic business normally has:

  • $200,000 of monthly account activity.

  • Domestic customers.

  • No international wire transfers.

  • Relatively predictable vendor payments.


Then the account suddenly receives $2 million and sends multiple international wires.


Is that money laundering?


Not necessarily.


But it is inconsistent with the established baseline.


That should cause the institution to ask:

What changed?

The CCS program specifically includes monitoring baseline/"normal" transactions as a core CDD topic.


The process becomes:


Expected Activity

Actual Activity

Variance

Investigation

Risk Reassessment

Escalation if Necessary


That is a control system.


Beneficial Ownership Matters

Legal entities can make financial transparency difficult.


The person opening an account may not actually own the organization.


The named entity may itself be owned by another entity.


Ownership structures can become complicated.


That creates an obvious AML question:

Who ultimately owns or controls the customer?

CCS's CDD program therefore specifically addresses customer legal entities, beneficial owners, controlling persons and exclusions.


For Internal Audit, this should translate into testing.


Don't merely ask:

“Does our policy require beneficial-ownership information?”

Select accounts.


Inspect the evidence.


Determine whether required information was obtained.


Determine whether it was verified as required.


Determine how exceptions were handled.


Determine whether changes are appropriately incorporated into the customer risk profile.


CDD and Transaction Monitoring Belong Together

A sophisticated transaction-monitoring system is considerably more valuable when it understands what activity should be expected.


Consider two customers making the same $250,000 international transfer.


For Customer A, that transaction may be completely ordinary.


For Customer B, it may be highly unusual.


The transaction is identical.


The risk context is different.


That is why CDD and transaction monitoring should not operate as isolated compliance processes.


CDD establishes context.


Transaction monitoring evaluates activity against that context.


Internal Audit Should Test the Entire CDD Lifecycle

CDD should be audited as a process rather than as a collection of forms.


A useful audit trail is:


Customer Onboarding

Identity Verification

Legal Entity Identification

Beneficial Ownership

Controlling Person

Customer Risk Rating

Expected Activity

Ongoing Monitoring

Changes in Customer Information

Risk-Profile Update

Transaction Monitoring

Investigation

SAR Consideration


This allows Internal Audit to determine whether information gathered during onboarding actually influences downstream AML monitoring.


A Completed Form Is Not an Effective Control

This is a familiar Internal Audit problem.


The workpaper says: CDD completed.


The customer file contains the required form.


The boxes are checked.


Does that establish an effective CDD process?


Not necessarily.


Internal Audit should ask:

Was the information accurate?
Was it complete?
Was it appropriately verified?
Was the risk rating reasonable?
Was contradictory information investigated?
Did the information affect transaction monitoring?
Was the profile updated when circumstances changed?

A completed checklist proves that somebody completed a checklist.


It doesn't necessarily prove that the CDD control worked.


Data Quality Can Undermine the Entire AML System

Modern CDD and transaction-monitoring programs depend heavily upon technology.


That introduces an IT-control issue.


Consider the flow:


Customer Information

Core Banking System

CDD System

Customer Risk Rating

Transaction Monitoring

Alert

Investigation

SAR Process


What happens if customer information doesn't flow correctly between systems?


What happens if a risk-rating field is missing?


What happens if certain transactions never reach the monitoring platform?


The transaction-monitoring rules can operate exactly as programmed and the AML program can still fail.


Internal Audit should therefore ask:

How does management know the information feeding the AML system is complete and accurate?

Risk Ratings Need to Mean Something

Many financial institutions classify customers as:

  • Low Risk

  • Moderate Risk

  • High Risk


That creates another audit opportunity.


What actually determines the rating?


Is it based upon defined criteria?


Is the methodology consistently applied?


Can employees override the rating?


Who approves an override?


What evidence supports it?


Does a high-risk rating trigger additional procedures?


How often is the rating reconsidered?


If every customer receives a risk rating but the rating doesn't change what the organization does, the control may have little practical value.


CDD Should Connect With Fraud

There is another important consideration.


Fraud and AML frequently overlap.


A fraudulent entity may use:

  • Stolen identities

  • Synthetic identities

  • Shell companies

  • Nominee owners

  • Money mules

  • False business information


The CDD process can therefore provide valuable information not only to the AML department, but also to fraud investigators and other risk functions.


The organization should ask:

Are our fraud and AML functions sharing relevant customer-risk information—or are they operating in separate silos?

Internal Audit Should Challenge the High-Risk Customer Population

One particularly useful audit procedure is to examine customers classified as high risk.


Ask:

Why is the customer high risk?
What additional due diligence occurred?
What additional monitoring occurs?
Who reviews the relationship?
How frequently is customer information updated?
Have unusual transactions occurred?
Were alerts investigated?
Were SARs considered?

Then reverse the analysis.


Select customers with high-risk characteristics and ask:

Were they actually classified as high risk?

That can identify weaknesses in the risk-rating methodology itself.


CDD Is About Understanding Relationships

A strong CDD program ultimately tries to answer a relatively simple question:

Does what we are seeing make sense given what we know about this customer?

If the answer is yes, continue monitoring.


If the answer is no, investigate.


That does not mean every unusual transaction is suspicious activity.


It means unusual activity deserves enough analysis to determine whether there is a reasonable explanation.


Internal Audit Has an Important Role

CCS specifically identifies Internal Auditors as one of the intended audiences for its


FinCEN CDD training, alongside compliance professionals and financial executives.


Internal Audit can provide independent assurance over questions such as:

  • Is the CDD program properly designed?

  • Are beneficial owners appropriately identified?

  • Are customer risk profiles meaningful?

  • Are higher-risk relationships subject to appropriate controls?

  • Is customer information updated?

  • Does transaction monitoring reflect customer risk?

  • Are exceptions investigated?

  • Are technology and data reliable?

  • Does management monitor program effectiveness?


These are classic internal-control questions applied to AML.


CDD Should Be on the Audit Committee's Radar

For financial institutions with significant AML exposure, the Audit Committee should understand more than whether management says the organization is compliant.


Governance should ask:

What percentage of our customers are classified as high risk?
What are the principal reasons for those classifications?
Are customer reviews current?
How many significant CDD exceptions are outstanding?
Have regulators identified CDD weaknesses?
Are repeat findings occurring?
Does Internal Audit believe the CDD program is operating effectively?

That last question matters.


Compliance owns and operates the program.


Internal Audit provides independent assurance over it.


Two Opportunities to Attend in 2026

Corporate Compliance Seminars' FinCEN's CDD Rule is a Basic-level, Group Internet-Based program providing 2 NASBA-approved CPE credits in Auditing. The CCS program is offered on Mondays from 10:00 a.m. to noon Central Time, with no prerequisites or advance preparation.


Monday, September 21, 2026

The September program provides Internal Auditors and compliance professionals an opportunity to strengthen their understanding of CDD, beneficial ownership, customer risk profiles and ongoing transaction monitoring.


Monday, November 16, 2026

The November session is particularly well positioned for organizations developing their 2027 AML compliance plans, risk assessments and Internal Audit programs.


The Bottom Line: Know What Normal Looks Like

The real power of Customer Due Diligence isn't simply collecting more information about customers.


It is using that information to understand risk.


The progression should be:


Know the Customer

Understand the Legal Entity

Understand Ownership and Control

Understand the Relationship

Establish the Risk Profile

Establish Expected Activity

Monitor Actual Activity

Investigate Meaningful Deviations

Update the Risk Profile

Escalate Suspicious Activity


That is what turns CDD from a compliance exercise into an effective AML control.


CCS's FinCEN's CDD Rule webinar on September 21 and November 16, 2026 provides two focused CPE hours on developing that understanding and applying it to compliance and Internal Audit.


 
 
 

Recent Posts

See All

Comments


Contact Us

Please white list the email address johnb@cseminars.com to allow for CCS emails to reach you effectively.

Thanks for submitting!

Corporate Compliance Seminars is registered with the National Association of State Boards of Accountancy (NASBA) as a sponsor of continuing professional education on the National Registry of CPE Sponsors. State boards of accountancy have final authority on the acceptance of individual courses for CPE credit. Complaints regarding registered sponsors may be submitted to the National Registry of CPE Sponsors through its website: www.nasbaregistry.org.

In accordance with the standards of the National Registry of CPE Sponsors, CPE credits are granted based on a 50-minute hour.

National Registry of CPE Sponsors ID #108983

Complaints may also be forwarded to the company principals, David S. Marshall (708-205-2366davem@cseminars.com) and/ or John Blackshire (479-200-4373johnb@cseminars.com)

 

bottom of page