OneID® | News and Events

Customer due diligence (CDD) explained: SDD, standard and enhanced

Written by The OneID Team® | 23/07/26 07:00

Know exactly who you are onboarding, at the right level of checking

Customer due diligence (CDD) is the set of checks a regulated firm must carry out to know who its customer is and monitor the relationship, under the Money Laundering Regulations 2017. At its core the firm identifies and verifies the customer from a reliable source independent of them, then applies simplified, standard or enhanced measures depending on risk.

Most of the commercial pain sits in that last part. Treat every customer as high risk and you slow good people down, add cost, and lose some of them at signup. Under-check where risk is real and you carry regulatory exposure. Getting the tier right, quickly, is where onboarding either helps the business or holds it back.

For the person on the other side, the difference is felt in seconds. A low-risk customer should be able to confirm who they are with a tap and get on with what they came to do. Someone in a higher-risk situation should expect a few more questions, and understand why. CDD is the framework that decides which of those experiences each customer gets.

What is customer due diligence (CDD)?

Customer due diligence is the process a regulated firm uses to identify its customer, verify that identity from a reliable independent source, understand the purpose of the relationship, and monitor it over time. It sits inside the wider anti-money laundering programme. Its job is to make sure the firm knows who it is dealing with before and during the relationship.

CDD is a legal duty for firms in regulated sectors, described in law as "relevant persons". Banks, payment and e-money firms, crypto businesses, lenders, gambling operators, accountants and property agents all carry it. The exact obligations come from the Money Laundering Regulations 2017.

When is customer due diligence required?

A relevant person must apply CDD when it establishes a business relationship, carries out an occasional transaction above the relevant threshold, suspects money laundering or terrorist financing, or doubts the accuracy of identity information it obtained earlier. These triggers sit in Regulation 27.

Regulation 27 sets the "when" and Regulation 28 sets the "what". Keeping the two apart matters in practice: the trigger tells the firm a check is due, and the measures tell it what that check has to cover. Most consumer onboarding falls under the first trigger, establishing a business relationship, which is why signup is where CDD is felt most.

What are the three levels of customer due diligence?

CDD runs on a risk-based scale with three levels. Simplified due diligence applies in lower-risk situations, standard CDD is the baseline for a normal-risk relationship, and enhanced due diligence applies in higher-risk situations. The firm decides which level fits using its own risk assessment and the risk factors set out in the regulations.

Standard CDD is the reference point. Simplified and enhanced adjust that baseline down or up. Each draws on the same Regulation 28 measures rather than a separate rulebook. The table below sets out each tier, the regulation behind it, when it applies and what it asks for.

Tier

Regulation

When it applies

What it requires (in brief)

Simplified due diligence (SDD)

MLRs 2017, Reg 37

Firm determines a low degree of ML/TF risk, judged against its risk assessment and the Reg 37 risk factors (customer, product, transaction, delivery channel, geography)

Standard CDD measures with the extent, timing or type adjusted down; ongoing monitoring still required; revert to fuller CDD if risk changes. Not an exemption.

Standard CDD

MLRs 2017, Reg 28

The default for a normal-risk business relationship or occasional transaction (triggered under Reg 27)

Identify and verify the customer from a reliable source independent of them; identify and verify beneficial owners and ownership structure; understand the purpose and nature of the relationship; ongoing monitoring (Reg 28(11)).

Enhanced due diligence (EDD)

MLRs 2017, Reg 33 (PEP specifics in Reg 35)

Higher-risk situations: PEPs and their family or close associates; high-risk third countries (FATF-identified); complex or unusually large transactions, unusual patterns or no apparent economic or legal purpose; false documentation; firm- or supervisor-assessed high risk; correspondent relationships (Reg 34)

Additional information on customer and beneficial owner and on the relationship's purpose; establish source of funds and source of wealth; senior-management approval (PEPs, Reg 35); enhanced ongoing monitoring.

What is simplified due diligence (SDD)?

Simplified due diligence applies where a firm decides a relationship or transaction carries a low degree of money laundering or terrorist financing risk, judged against its risk assessment and the risk factors in Regulation 37. It lets the firm adjust the extent, timing or type of the standard measures. It is not permission to skip customer due diligence.

The distinction is load-bearing. Under SDD the firm still identifies and verifies the customer and still conducts ongoing monitoring. It might, for example, verify identity later in the relationship or rely on fewer data points where the product and customer profile genuinely warrant it. If risk rises, or a higher-risk factor appears, the firm has to move back up to fuller checks.

What is standard customer due diligence?

Standard CDD is the ordinary set of measures in Regulation 28, applied in the normal, non-lower, non-higher risk case. The firm identifies and verifies the customer from a reliable source independent of them, identifies and verifies beneficial owners and the ownership structure of any legal entity, understands the purpose and intended nature of the relationship, and conducts ongoing monitoring.

There is no separate "standard due diligence" regulation to cite. Standard CDD is simply the full Regulation 28 measures at their default extent. The statutory test for the identity step is precise: verification on the basis of documents or information "obtained from a reliable source which is independent of the person whose identity is being verified". Regulation 28 expressly allows an electronic identification process to meet this.

What is enhanced due diligence (EDD)?

Enhanced due diligence is the extra scrutiny required in higher-risk situations under Regulation 33. Triggers include politically exposed persons and their family or close associates, customers connected to countries identified by FATF, transactions that are complex or unusually large or follow an unusual pattern, cases involving false documentation, and any situation the firm or its supervisor assesses as higher risk.

EDD asks for more. The firm obtains additional information on the customer, the beneficial owner and the purpose of the relationship, establishes source of funds and source of wealth where relevant, and applies enhanced ongoing monitoring. For politically exposed persons, the specific requirements, including senior-management approval and source-of-wealth enquiry, sit in Regulation 35. Our separate guide on enhanced due diligence covers the triggers and requirements in full.

What does ongoing monitoring involve?

Ongoing monitoring means keeping the relationship under review after onboarding. Regulation 28(11) requires the firm to scrutinise transactions across the relationship to check they are consistent with what it knows about the customer, and to review existing records and keep the identity information it holds up to date.

This applies at every tier, including simplified due diligence. A one-off check at signup does not discharge the duty. As a customer's circumstances change, the firm is expected to keep its record of who they are current, which is where periodic and event-driven re-checks come in.

Where does electronic identity verification fit within CDD?

Electronic identity verification supports one specific limb of CDD: identifying and verifying the customer from a reliable source independent of them. In practice this is met through the industry "2+2" convention, matching at least two identity attributes against at least two independent, reliable data sources. The convention is a benchmark in guidance, not a term written into statute.

A strong electronic match settles the "who am I dealing with" question at the identity step. It does not, on its own, discharge the rest of CDD. Risk assessment, sanctions and PEP screening, source of funds and wealth where required, and ongoing monitoring stay with the firm. Government guidance on using digital identities with the Money Laundering Regulations, published on 26 February 2026, makes the same point: a certified provider is a reliable independent source for the identity step, and the firm remains responsible for everything else and ultimately liable.

This is the step where a specialist identity tool earns its place. OneID's KYC Match returns a configurable count of independent data-source matches across name, address and date of birth, drawn from banks, mobile networks, insurance data, public-sector data, finance applications and credit reference agencies. It meets and exceeds the 2+2 convention, and it recovers thin-file customers that a credit-reference-only check would fail. It handles the identity-matching step. Your firm keeps the wider CDD around it.

That matters commercially because thin-file customers are not fringe. A meaningful minority of UK adults leave little conventional footprint, concentrated among younger people, recent movers and newcomers to the country. In one Tier-1 gaming operator's data, a credit-reference-only check failed the 2+2 convention on almost a third of new customers, and a second pass across additional independent sources recovered enough of them to lift new-customer onboarding by around 15%.

FAQ

What are the 3 types of customer due diligence?

The three types are simplified due diligence (SDD), standard customer due diligence, and enhanced due diligence (EDD). SDD applies in lower-risk situations, standard CDD is the baseline for a normal-risk relationship, and EDD applies in higher-risk situations. The firm chooses the level using its own risk assessment.

What is the difference between CDD and EDD?

CDD is the overall duty to identify, verify and monitor a customer. Enhanced due diligence is the higher-intensity version of that duty, applied in higher-risk situations under Regulation 33. EDD adds requirements such as source of funds and wealth, additional information, and enhanced ongoing monitoring on top of the standard measures.

Is simplified due diligence the same as no due diligence?

No. Simplified due diligence adjusts the extent, timing or type of the standard measures where risk is low. The firm still identifies and verifies the customer and still carries out ongoing monitoring. If risk rises or a higher-risk factor appears, the firm must move back up to fuller checks.

What triggers enhanced due diligence?

Regulation 33 triggers include politically exposed persons and their family or close associates, customers connected to countries identified by FATF, complex or unusually large transactions or unusual patterns, cases involving false documentation, and any situation the firm or its supervisor assesses as higher risk.

What is the difference between KYC and CDD?

KYC, knowing your customer, is the identity and customer-knowledge component. CDD is the broader legal duty that contains it, including verification, understanding the relationship, and ongoing monitoring. KYC sits inside CDD, which sits inside the wider anti-money laundering programme.

Does electronic identity verification meet CDD requirements?

Electronic identity verification meets the identity-verification limb of CDD when it uses a reliable source independent of the customer, as Regulation 28 requires. It does not meet the whole duty on its own. Screening, risk assessment, source of funds and ongoing monitoring remain the firm's responsibility.

Compare your identity results for free

You can run 1,000 records through KYC Match at no cost and compare the results against your existing provider. It shows how many customers a multi-source match confirms that a credit-reference-only check misses, at the identity step of your CDD. To set up a comparison, contact OneID.