🇮🇳 Happy Independence Day — celebrating 78 years of freedom!

Customer Due Diligence (CDD/EDD): KYC, AML and CFT Guide

KYCAML By Ashish Jain · IIBF STORE Editorial · 02 July 2026 · Updated 14 Aug 2026 · 6 min read · 30 views
Customer Due Diligence (CDD/EDD): KYC, AML and CFT Guide

Every account a bank opens carries a promise and a risk, and customer due diligence is how the bank keeps that promise while managing the risk. For candidates preparing for the KYC, AML and CFT certification, due diligence is the beating heart of the syllabus: it is the process by which a bank identifies its customer, understands the purpose of the relationship, and decides how closely to monitor it. This guide explains the levels of due diligence, the risk-based approach that drives them, and how they connect to India's anti-money-laundering law.

Customer due diligence, universally abbreviated CDD, is the set of measures a regulated entity takes to verify who its customer really is and to assess the money-laundering and terrorist-financing risk that customer presents. It is not a one-time formality at account opening but an ongoing obligation that runs through the entire life of the relationship. Getting CDD right protects the bank from being used as a conduit for illicit funds — and protects the officer who signs off on the account.

The Risk-Based Approach to Due Diligence

Modern anti-money-laundering practice rests on a risk-based approach: banks apply more scrutiny where the risk is higher and less where it is lower, rather than treating every customer identically. This principle, promoted globally by the Financial Action Task Force and embedded in the RBI's Master Direction on KYC available at rbi.org.in, is what makes customer due diligence both effective and proportionate. A salaried individual opening a savings account and a cash-intensive business dealing across borders simply do not warrant the same intensity of checks.

Under this framework, banks classify customers into low, medium and high risk based on factors such as the customer's identity, geography, business activity and expected transaction pattern. That classification then dictates the depth of due diligence and the frequency of ongoing monitoring. Crucially, the risk rating is dynamic: a customer whose behaviour changes — sudden high-value transfers, links to a sanctioned jurisdiction, or a shift in business — should be re-rated and, if necessary, escalated. This is why examiners stress that CDD is a continuous cycle, not a box ticked at onboarding. Mastering the risk-based logic is essential, and it recurs throughout our certification course.

Simplified, Standard and Enhanced Due Diligence

The risk rating maps directly onto three levels of customer due diligence. Simplified due diligence applies to genuinely low-risk customers and permits lighter verification. Standard due diligence is the default for ordinary customers and involves full identity verification and understanding of the account's purpose. Enhanced due diligence (EDD) is reserved for high-risk relationships and demands additional steps: gathering more information on the source of funds, obtaining senior-management approval, and monitoring the relationship more intensively.

Certain categories almost always trigger enhanced due diligence. Politically Exposed Persons (PEPs) — senior public officials and their close associates — carry heightened corruption risk and require source-of-wealth checks and management sign-off. Complex ownership structures, non-face-to-face onboarding, and customers from higher-risk jurisdictions also warrant EDD. The identification of the beneficial owner — the natural person who ultimately owns or controls a customer — is a cornerstone of EDD, because criminals routinely hide behind layers of shell entities. Being able to distinguish these three tiers, and to recognise the red flags that push a customer up the scale, is a reliable exam winner and a genuine professional skill. Practise these scenarios with our mock tests.

Key Concepts — KYC, AML and CFT
Key Concepts — KYC, AML and CFT

From Due Diligence to Reporting Obligations

Diligence that never leads to action is pointless, so customer due diligence feeds directly into a bank's reporting duties under the Prevention of Money Laundering Act (PMLA), 2002. When ongoing monitoring flags a transaction that has no apparent lawful purpose or is inconsistent with the customer's known profile, the bank's principal officer must consider filing a Suspicious Transaction Report (STR) with the Financial Intelligence Unit-India. Banks also file Cash Transaction Reports for large cash movements and maintain records for the periods prescribed by law.

The chain is therefore continuous: identify the customer, assess the risk, apply proportionate due diligence, monitor the relationship, and report what looks suspicious — all while never tipping off the customer that a report has been made. This end-to-end view is exactly what the KYC, AML and CFT exam tests, because a bank that does excellent onboarding but poor monitoring, or good monitoring but no reporting, has still failed its regulatory duty. Keep your knowledge current through IIBF news updates, reinforce concepts with our match games, and browse more explainers on the blog.

Frequently Asked Questions

What is customer due diligence?

Customer due diligence is the set of measures a bank takes to verify a customer's identity, understand the purpose of the relationship, and assess the money-laundering risk. It is an ongoing obligation that continues throughout the life of the account, not a one-time check at onboarding.

When is enhanced due diligence required?

Enhanced due diligence is required for high-risk relationships such as Politically Exposed Persons, customers with complex ownership structures, non-face-to-face onboarding, and those from higher-risk jurisdictions. It involves source-of-funds checks, senior-management approval and closer monitoring.

Who is a beneficial owner?

The beneficial owner is the natural person who ultimately owns or controls a customer, or on whose behalf a transaction is conducted. Identifying the beneficial owner prevents criminals from hiding behind shell companies and is a core part of enhanced due diligence.

How does due diligence link to STR filing?

Ongoing monitoring under customer due diligence flags transactions with no apparent lawful purpose. The bank's principal officer then evaluates whether to file a Suspicious Transaction Report with FIU-India under the PMLA, without tipping off the customer.

Process & Framework — KYC, AML and CFT
Process & Framework — KYC, AML and CFT

Conclusion and Next Steps

Customer due diligence is the thread that ties the entire KYC, AML and CFT syllabus together — from the risk-based approach and its three intensity tiers, through the identification of beneficial owners and PEPs, to the reporting obligations under the PMLA. Treat it as a continuous cycle rather than a paperwork ritual, learn the red flags that escalate a customer, and you will handle both the exam and real-world compliance with confidence. Ready to check your understanding? Take a focused mock on our practice tests and explore the complete KYC and certification course.

In Practice — KYC, AML and CFT
In Practice — KYC, AML and CFT
Quick quiz

Quick quiz on this topic

5 exam-style questions from our free test bank — check yourself before you move on.

KYC, AML and CFT · 5 questions · instant result
Q1. A salaried individual's account receives over 5,700 small round-amount cheques (₹1,250, ₹2,000, ₹2,250 etc.) over 18 months, ~20% of which bounce, with cash withdrawn soon after credit and the holder untraceable at the declared address. Which typology BEST fits?
Q2. A branch officer, trying to be helpful, informs a customer that an STR has been filed against him. The customer promptly closes the account and disappears. What is the consequence under PMLA?
Q3. Which combination of red flags is MOST distinctive of Trade-Based Money Laundering (TBML) as opposed to generic AML alerts?
Q4. Mr. X deposits Rs. 7 lakh cash in his personal savings account and the same month deposits Rs. 5 lakh cash in his proprietary firm M/s. XX, plus Rs. 4 lakh cash in M/s. XYZ, a partnership firm in which he is a partner. For integrally connected CTR aggregation, which combination is counted together?
Q5. After an STR is filed on a customer's account, a junior officer suggests freezing the account and informing the customer to deter further laundering. As per the KYC Master Directions described in the chapter, what is the correct conduct?
Next step

Practice this topic

Ready to put this into practice?

Take a free mock test, download chapter PDFs, or watch a video class — all included on iibf.store.

Keep reading