Customer Due Diligence, as defined by the Financial Action Task Force, involves four elements: identifying the customer and verifying their identity through reliable, independent sources; identifying the beneficial owner and understanding the ownership and control structure; understanding the purpose and intended nature of the business relationship; and conducting ongoing monitoring of transactions to ensure they are consistent with what is known about the customer. The fourth element is the one most frequently treated as an afterthought. It is not a checklist point but a commitment to keep the answer up to date.
The Wolfsberg Group, an association of major global banks that has issued due diligence principles since 1999, makes the same point more directly: a bank must only accept clients whose source of wealth and funds can be reasonably established as legitimate, and it is the relationship manager who is responsible for that, not the compliance system that handled the paperwork at onboarding.
The majority of compliance teams treat Customer Due Diligence as a process of gathering documents, checking identity, and maintaining a file. That description is not incorrect, but it falls short in a significant way. CDD is not a form that has to be filled in once; it is a question an organisation must be able to answer continuously throughout the duration of the relationship.
This piece is structured around international standard-setting bodies, FATF and the Wolfsberg Group, rather than any single country's regulations. The principles described here apply across jurisdictions and are the baseline against which any national framework is measured.
Three levels, calibrated to risk
A uniform approach to due diligence introduces risk rather than reducing it. International standards describe three levels applied according to assessed risk, not merely customer category.
No preference makes any of these three levels optional. Which applies depends on the assessed level of risk. Where there is any indication of high risk, simplified measures are explicitly unavailable even if the customer would otherwise fall into a reassuring-sounding category.
Beneficial ownership: the part most often done superficially
Identifying a natural-person customer is relatively straightforward. When the customer is a company, trust, partnership, or foundation, the quality of due diligence diverges sharply between institutions that treat it as a real analytical exercise and those that treat it as a form to be completed.
The Wolfsberg Group is specific about what genuine beneficial ownership understanding requires. For a company: who provides the funds, who is the beneficial owner of the assets, and who has the authority to direct the company's officers. For a trust: who provided the funds, who controls them, who has the power to remove a trustee, and who benefits. For a partnership or foundation: who provides the funds and how the entity is actually managed and directed.
The distinction that matters most is between control and signature authority. A firm that asks only who can sign for an account rather than who actually controls it has not carried out adequate beneficial ownership due diligence, regardless of what is recorded in its files. This is one of the most frequently misplaced aspects of CDD across institutions of all sizes.
Ongoing monitoring: where point-in-time due diligence fails
A customer accepted today on the basis of a risk assessment conducted today is not a fixed entity. Transaction patterns change, public profiles shift, and a person who was not politically exposed at onboarding can become one later. A declared source of funds can turn out not to match the funds actually moving through the account.
FATF's framework makes it explicit: transactions must be examined throughout the course of the relationship to ensure they are consistent with what the institution knows about the customer, their business, and their risk level. The Wolfsberg Group's principles specify that account activity must be continuously monitored, with frequency and depth determined by the customer's risk category, and that unusual or suspicious activity must trigger escalation: analyse the background, then either continue under enhanced monitoring, terminate the relationship, or report to the appropriate authority.
The practical failure is rarely a complete absence of monitoring. It is more commonly that monitoring is a disconnected process from the original due diligence file. A transaction that should be evaluated against a customer's known profile is instead measured against general rules with no memory of what the institution established at onboarding.
What distinguishes a defensible CDD programme
Taken together, the international standards converge on five points that separate a CDD programme that holds up under examination from one that exists only on paper.
A customer classified as low risk because the classification is convenient rather than because of a real analysis becomes a liability as soon as anyone examines the file. A defensible programme classifies risk from evidence, not from the desire for a particular outcome.
Obtaining a signed ownership declaration is a different task from understanding who actually directs an entity’s funds and decisions. Only one of those tasks meets the standard. The distinction between signature authority and actual control is the most frequently misplaced aspect of beneficial ownership due diligence.
The source of wealth and source of funds must be established, not merely stated. Senior management approval must represent a genuine decision point, not a formality. These are the two aspects of EDD most frequently absent when time is pressing, and they are the two that matter most under examination.
A transaction monitoring system that has no visibility into a customer’s stated purpose, risk classification, or beneficial ownership structure is only monitoring in name. It may identify anomalies by general rules, but it cannot determine whether an anomaly is consistent with what the institution already knows about that specific customer.
The minimum five-year retention standard required by international frameworks exists for a reason: the real test of a CDD programme is whether someone reviewing the file later can reconstruct exactly what was known, when it was known, and what action was taken. A file that records outcomes but not the reasoning behind them does not meet this standard.
Closing the gap
All five points share the same root: due diligence quality depends on information gathered across the entire customer relationship — onboarding, risk classification, ongoing monitoring, investigation — and on those stages being genuinely connected rather than operating as separate systems that each appear adequate in isolation.
Fyscal Arcx's Name Screening module scores matches against sanctions, PEP, and adverse media data at onboarding with per-field explainability, and its Delta Screening capability continuously re-screens the existing customer base as new watchlist entries are added, so a customer's status is re-evaluated on an ongoing basis rather than fixed at the moment of acceptance.
Its Case Management module keeps beneficial ownership findings, risk classification history, and prior due diligence decisions in one persistent record tied to the customer, so a later transaction alert can be evaluated against what the institution already established rather than against a generic rule with no memory of the file. Its Transaction Monitoring module builds behavioral baselines specific to each customer, so ongoing monitoring reflects the individual relationship the standards describe rather than a uniform threshold applied regardless of what is actually known about who the customer is.

