Skip to content
ProofVoltSend us a company

Customer due diligence (CDD)

Checked against the official texts on .

Customer due diligence (CDD) is the set of measures a regulated firm must apply to know its customer: identify and verify the customer and its beneficial owners, understand the purpose of the relationship, check sanctions and politically-exposed-person status, and monitor the relationship over time. The depth of CDD depends on risk: simplified where risk is demonstrably low, enhanced where it is higher.

Also called: KYC, customer due diligence measures.

Why it matters for PSPs and EMIs

CDD is the core onboarding obligation for payment and e-money institutions, and the first thing a supervisor tests. A firm must be able to show, customer by customer, not only that the checks were done but that their extent was appropriate to the risk.

What the law says

  • When CDD applies. AMLR Art. 19(1): when establishing a business relationship; for occasional transactions of EUR 10 000 or more; when participating in the creation of a legal entity or arrangement; on suspicion of money laundering or terrorist financing; when there are doubts about earlier identification data; and when there are doubts whether the person is the customer or is authorised to act for it. Art. 19(4) adds at least identification for occasional cash transactions of EUR 3 000 or more. Art. 19(2): credit and financial institutions (other than crypto-asset service providers) also apply CDD to occasional transfers of funds of EUR 1 000 or more.

  • What CDD consists of. AMLR Art. 20(1), points (a) to (i): identify and verify the customer; identify the beneficial owners and take reasonable measures to verify them; understand the purpose and intended nature of the relationship; verify targeted financial sanctions exposure; understand the customer's business; conduct ongoing monitoring; determine politically-exposed-person status; identify persons on whose behalf a transaction is conducted; and verify the authority of anyone acting for the customer.

  • How much. AMLR Art. 20(2): the extent is set by an individual analysis of risk, taking into account the firm's business-wide risk assessment and the risk variables and factors in Annexes I to III. Art. 20(4): the firm must be able to demonstrate to its supervisor that its measures are appropriate.

  • If CDD cannot be completed. AMLR Art. 21(1): refrain, terminate, and consider a suspicious transaction report. Art. 21(3): keep records of the actions and decisions taken, including refusals.

  • Detail to come. AMLR Art. 28(1): AMLA regulatory technical standards on the information to collect for standard, simplified and enhanced due diligence. AMLA consulted on a draft from 9 February to 8 May 2026; on AMLA's overview of 28 September 2026 the standards were not yet final. They apply once the Commission adopts them as a delegated regulation (Art. 28(4)).

  • Dates. The AMLR applies from 10 July 2027 (Art. 90). Until then: Directive (EU) 2015/849, Arts. 11 and 13, as transposed nationally.

  • International standard. FATF Recommendation 10.

How ProofVolt handles it

ProofVolt runs due diligence in a fixed order: investigate first (registers, sanctions and adverse media), then ask the customer only for what public sources cannot prove. Directors and beneficial owners are screened for sanctions and politically-exposed-person status, and the customer portal asks every customer for the source of funds and the source of wealth behind the relationship. The officer decides on one screen that shows what blocks a decision and the recommendation with its reasons. Every conclusion carries its source on the case's receipt, and every source, step and decision is kept in an append-only trail.

Sources

Informational only, not legal advice.