KYC vs CDD Explained And The Compliance Mistakes To Avoid

KYC vs CDD

KYC and CDD are often used interchangeably which is why companies sometimes get compliance wrong.

To add to the confusion is the often-held assumption that if you have collected identity information such as a passport or drivers’ licence, you have done your due diligence. In reality you have only finished the very first step.

In this article we pick apart the difference between know your client (KYC) and customer due diligence (CDD), explain how it can go wrong, and provide a practical checklist so you can get it right.

What is the difference between KYC and CDD?

KYC is the process of understanding who your customer is by confirming their identity, their circumstances, and reasons for wanting to do business with you. Consider whether the information you have gathered makes sense, and whether it raises any areas of concern that might require more enhanced due diligence checks. This is often referred to as identification of red flags.

CDD is the broader compliance process that flows from your KYC. It includes the checks and verifications you carry out, understanding  the nature and purpose of the transaction, and any ongoing monitoring based on what your KYC has revealed.

The distinction may seem subtle but it matters more than some companies realise as without KYC and CDD both done correctly you’ll create serious gaps in your compliance process.

The common mistakes to avoid

The most common mistakes we tend to see fall into a couple of categories: 1) failure to consistently assess and identify risks; and 2) failure to treat compliance as an ongoing process.

1. Collecting KYC data without using it

Collecting the customer information required for KYC is a great start but it is a mistake not to take it a step further and use the data to assess:

  • Client risk ratings
  • Customer due diligence levels
  • Clear next steps

Without any form of assessment, KYC becomes an administrative task rather than a risk tool, and you will fail to build a genuine picture of your customer.

2. Incomplete identification of relevant parties

In many cases you will need to carry out checks on more than just your client to help verify the identity and relationships associated with your client.

This is extra effort but if you don’t do this and apply KYC too narrowly you could miss important information on:

  • Beneficial owners
  • Controlling individuals
  • Complex ownership structures

CDD depends on a complete view of who is involved. If KYC is incomplete, CDD will be too.

3. Applying a one-size-fits-all approach

Not all customers require the same level of due diligence. However, we have seen some cases where businesses apply the same process regardless of:

  • Customer type
  • Transaction complexity
  • Red flags presented
  • Geographical location of the customer

The information you collect on your customer should be robust enough to help you determine risk levels and what CDD approach to take.

Without correctly determining your risk you could either under-check or over-check clients. Either way you’ll be creating compliance gaps or inefficiencies in your business.

4. Forgetting that CDD is ongoing

One of the most consistent compliance gaps we see is businesses treating CDD as something that happens only when a client is being onboarded.

Under the AML/CFT Act, ongoing CDD is a legal requirement, and without it you’ll not be meeting your AML obligations.

Note, ongoing CDD may also be required if there is a material change in your customers’ circumstances. For example, CDD may need to reoccur if your customer’s corporate structure changes, or if they start carrying out different transactions to previous ones.

Your KYC and CDD checklist

Here are the key elements to include in your KYC and CDD processes.

KYC: Get to know your client

1. Identify who your client is in order to determine level of CDD required

Identify the parties involved and determine if there are trusts or companies involved.

  • Get the full picture: Why is the customer engaging with you, and does their activity makes sense
  • Determine the entity type: Understand whether they are an individual, a company, a trust, a partnership, or another type of entity, which could be used to promote anonymity of the beneficial owner

2. Obtain information to determine nature and purpose of proposed business relationship

Ensure you understand why your client wants to do business with you and how they plan to use your services. This will help you spot anything unusual early and ensure the relationship is for legitimate business purposes.

You should gather enough information to clarify things like:

  • What the customer intends to do
  • How they expect to use your products or services
  • Whether their activity and response to your questions is consistent with their age and stage

3. Assign a customer risk rating

Consider the information you have gathered on customers against your company’s risk methodology and assign an overall risk rating you feel is suitable for your customer. Validate and document the reasons for your risk rating.

Your risk rating will help determine whether simplified, standard, or enhanced CDD should be applied.

  • Factors to consider include the nature and purpose of transactions, delivery risk, where the client is based, the complexity of the product or service, and beneficial owner type

4. Gather identity documentation

After you have established the customers’ requirements it’s time to move into obtaining identity documents and if necessary, source of funds and/or source of wealth, depending on the level of risk identified.

  • Gather identity documents, such as passports or driver licences to verify your customer’s identity
  • If the customer is a trust or you consider them a higher risk you will need to obtain information to verify source of funds (SoF) and/or source of wealth (SoW). You need to refer to your AML/CFT Programme in which circumstances you will use SoF or SoW or both if the risk requires

Customer due diligence: Verify, monitor and review

1. Verify customers identity

According to the level of risk determined, verify the identity of your customer and other relevant persons such as the beneficial owner.

  • Use recommended photographic identification documents, or non photographic documents such as a birth certificate alongside other photographic identification such as a New Zealand driver’s licence.
  • If you are using electronic identity verification (EIV), verify your customer’s name and date of birth from one source, and the name on the second source.

2. Verify source of wealth (SoW) and/or source of funds (SoF)

Understand how the customer acquired their funds and confirm it is legitimate (e.g. salary, business income, investments, inheritance).

You must record this information and take reasonable steps, according to the level of risk involved to verify this information using reliable and independent sources.

3. Schedule regular reviews

Develop a process for ongoing CDD and account monitoring, and ensure you document this in your compliance programme. Develop this according to the level of risk identified for each of your clients.

Review ID documents to ensure they are still valid, and addresses are still accurate. Review trust documentation (if applicable) to ensure information is up-to-date.

4. Monitor material changes and red flags

Check and review any material changes to entity structures, such as whether new shareholders, beneficial owners, directors or effective controllers have been added.

If the nature or purpose of the relationship changes, re-assess the risk rating and complete CDD at the appropriate level.

Keep an eye out for any red flags, such as your client becoming secretive, appearing in adverse media checks, or conducting transactions that do not match their profile.

Discovering a red flag doesn’t mean you can no longer do business with your client but you must understand, assess, and record the risk, and carry out enhanced customer due diligence or submit a suspicious activity report where relevant. 

How KYC feeds CDD

KYC tells you who your customer is, and how much risk they represent. This feeds directly into CDD, determining which level of verification is required, and how deeply you need to investigate.

KYC and CDD compliance flow

Key takeaways

KYC is the foundation of customer due diligence and done effectively will help you build a clear picture of your customer; however, the broader compliance process that flows from your KYC is CDD.

Take a risk-based approach to both processes to help ensure you not only remain compliant, but are creating efficient methods that benefit your business and the fight against money laundering.

At tic company, we’ve built technology and expert processes specifically designed to make KYC and CDD easier. Contact us to find out how we can help you simplify compliance and create a more efficient customer onboarding process.

Joel Meiklejohn, Operational Excellence Lead, tic company
About the author

Joel Meiklejohn

Joel is a Compliance Officer at tic, specialising in AML/CFT operations, customer risk assessment, and practical compliance delivery.

He brings hands-on experience across onboarding, transaction monitoring, and case analysis, with a strong focus on applying regulatory requirements in real-world operational environments. Prior to joining tic, Joel worked in merchant services, making risk-based decisions on customer applications, which adds a valuable commercial lens to his compliance approach.

Follow Joel on LinkedIn

More articles from tic company

Get insights and news delivered to your inbox

Webite Developed by Logo