Customer Due Diligence Process: KYC & AML Exam Guide
If you are studying for the IIBF KYC, AML and CFT certificate, the customer due diligence process is the single most important practical skill to master. The customer due diligence process is how a bank verifies who its customer really is, understands the nature of their dealings, and monitors transactions for signs of money laundering or terror financing. Built on the RBI Master Direction on KYC and the Prevention of Money Laundering Act, it is examined heavily and applied daily at every branch. This guide breaks the topic into clear, exam-ready sections.
Foundations of Customer Due Diligence
Customer due diligence, or CDD, is the set of checks a regulated entity performs to identify and verify a customer before and during a banking relationship. The customer due diligence process rests on the principle of "know your customer": establish identity using officially valid documents, verify the address, and understand the intended purpose of the account. Without satisfactory CDD, an account simply cannot be opened.
The legal backbone is the Prevention of Money Laundering Act, 2002 (PMLA) and the RBI's KYC Master Direction, which together require identification, verification, and ongoing monitoring. The objective is to prevent banks from being misused as conduits for illicit funds. These themes recur across the syllabus you will also encounter in the CAIIB programme, where compliance and risk are core.
For the exam, fix the three building blocks firmly: customer identification, beneficial-ownership identification, and the purpose-and-nature assessment of the relationship. Every later concept — enhanced diligence, risk categorisation, reporting — flows from this foundation, so a solid grasp here pays off across the whole paper.

Simplified, Standard and Enhanced Due Diligence
The customer due diligence process is risk-based, meaning the depth of checks scales with the risk a customer poses. Low-risk customers may qualify for simplified due diligence with lighter documentation. Most customers fall under standard CDD with full identity and address verification. High-risk customers attract enhanced due diligence (EDD), which adds source-of-funds checks, senior-management approval, and closer ongoing monitoring.
Politically exposed persons (PEPs), non-face-to-face customers, and those from high-risk jurisdictions flagged by the FATF typically trigger EDD. Banks must also identify the beneficial owner — the natural person who ultimately owns or controls a legal entity — to prevent shell companies masking illicit money. The global standards behind this risk-based approach are set by the Financial Action Task Force.
Examiners frequently test the thresholds and triggers for EDD, so memorise the PEP rule and the beneficial-ownership concept. A practical way to lock in these distinctions is timed revision on the IIBF practice tests, which mirror the format of the certificate exam and sharpen recall under pressure.

Ongoing Monitoring and FIU Reporting
The customer due diligence process does not end at onboarding; it continues for the life of the relationship through ongoing monitoring. Banks watch transactions against the expected profile and flag activity that is unusually large, complex, or lacking economic rationale. Periodic KYC updation keeps records current, with frequency tied to the customer's risk category.
When suspicion arises, the bank files a Suspicious Transaction Report (STR) with the Financial Intelligence Unit-India (FIU-IND). Banks also file Cash Transaction Reports for large cash dealings and Counterfeit Currency Reports as prescribed. These filings, mandated under PMLA, feed national efforts to trace and freeze illicit funds.
- Monitor transactions against the customer's expected profile.
- Update KYC periodically based on risk category.
- File STRs with FIU-IND on reasonable suspicion.
- Maintain prescribed records for the statutory retention period.
Understanding the reporting chain is essential, since scenario questions often ask which report applies. To keep these terms sharp between study sessions, the quick-recall activity on the match-the-concept game is a useful light-touch tool.

Common Pitfalls and Exam Tips
Candidates often confuse the customer due diligence process with a one-time formality, but ongoing monitoring is equally examinable. Another frequent error is mixing up the reports: an STR is suspicion-based, while a CTR is threshold-based on cash amounts. Be precise about which goes to FIU-IND and when.
Know the difference between simplified, standard, and enhanced due diligence, and the typical triggers for each. Remember that beneficial ownership must be established for non-individual customers, and that PEPs always warrant enhanced scrutiny with senior approval. Examiners also test record-retention periods and the consequences of non-compliance under PMLA.
Frame answers around identify, assess, monitor, and report, and you will cover most of what the paper asks. For grounding in the underlying banking-operations basics that first appear earlier in your studies, you can revise alongside the JAIIB course before returning to certificate-level depth.
Frequently Asked Questions
What is the difference between CDD and EDD?
Customer due diligence (CDD) is the standard set of identity, address, and purpose checks applied to most customers. Enhanced due diligence (EDD) is a deeper level for high-risk customers such as PEPs or those from high-risk jurisdictions, adding source-of-funds verification, senior-management approval, and intensified ongoing monitoring of the relationship.
When must a bank file a Suspicious Transaction Report?
A bank files a Suspicious Transaction Report with FIU-IND whenever it has reasonable grounds to suspect that a transaction involves proceeds of crime or terror financing, regardless of the amount. The suspicion may arise from unusual patterns, lack of economic rationale, or attempts to avoid reporting thresholds under the PMLA.
Who is a politically exposed person under KYC rules?
A politically exposed person, or PEP, is an individual entrusted with prominent public functions in India or abroad, such as senior politicians, judges, or military officials, along with close associates and family. Because of higher corruption risk, PEPs always require enhanced due diligence and senior-management approval before account opening.
Why is identifying beneficial ownership important?
Identifying the beneficial owner — the natural person who ultimately owns or controls a legal entity — prevents criminals from hiding behind shell companies or layered structures. The customer due diligence process requires banks to look through corporate veils so that illicit funds cannot be laundered anonymously through complex ownership arrangements.
Conclusion: Sharpen Your KYC and AML Edge
The customer due diligence process is the operational heart of the IIBF KYC, AML and CFT certificate and of real-world compliance. By mastering the foundations, the risk-based tiers, ongoing monitoring, and the FIU reporting chain, you can answer both conceptual and scenario questions with confidence. Reinforce this learning through structured mock tests and active revision. Start your focused preparation now on the IIBF mock test series and build the precision the compliance paper demands.
Quick quiz on this topic
5 exam-style questions from our free test bank — check yourself before you move on.
Practice this topic
Take a free mock test, download chapter PDFs, or watch a video class — all included on iibf.store.