
The Three CDD Tiers — SDD, Standard CDD, and EDD
Customer due diligence in regulated financial services is not a single fixed process but a risk-calibrated framework with three tiers. Simplified Due Diligence (SDD) applies to demonstrably low-risk customers — for example, listed companies in transparent jurisdictions, or crypto transactions below a de minimis threshold. SDD requires less documentation and verification than standard CDD and may allow automated processing without manual review.
Standard CDD is the baseline applied to all customers who do not qualify for SDD and do not exhibit elevated risk factors. It includes identity verification, confirmation of legal business existence, identification of UBOs, understanding of the business's purpose and expected transaction profile, and screening against sanctions and PEP lists. Enhanced Due Diligence applies to customers where risk factors elevate the potential for money laundering or terrorist financing — PEPs, high-risk jurisdictions, complex ownership structures, or unusual transaction profiles.
CDD for Business Customers vs. Individual Customers
The CDD process differs significantly depending on whether the customer is a natural person or a legal entity. For individual customers — a freelancer accepting crypto payments, or a private investor using a gateway — CDD focuses on identity verification (government ID), proof of address, and source of funds assessment. The process is typically automated through identity verification software that checks documents against national databases and performs liveness checks.
For business customers — which describes the majority of payment gateway merchant relationships — CDD expands to cover the legal entity itself (registration documents, articles of association, registered address verification) and the natural persons behind it (directors, UBOs). The business CDD process is qualitatively different from individual CDD in scope and complexity, which is why KYB (Know Your Business) is treated as a distinct process from KYC (Know Your Customer) even though both fall under the CDD umbrella.
Ongoing CDD vs. One-Time Verification
CDD is not a one-time gate at onboarding — it is an ongoing obligation. Financial regulations require regulated entities to maintain current knowledge of their customers' identities, ownership structures, business activities, and risk profiles. Material changes in any of these dimensions require re-verification. The practical implementation of ongoing CDD involves:
● Periodic refresh: Scheduled re-verification of customer information at intervals appropriate to the customer's risk tier — annually for high-risk customers, every 2–3 years for standard-risk, less frequently for low-risk with unchanged profiles.
● Event-triggered review: Changes in business ownership, significant transaction profile changes, adverse media alerts, or watchlist hits trigger immediate re-verification outside the scheduled cycle.
● Transaction-level monitoring: Ongoing CDD is supported by transaction monitoring systems that flag deviations from established customer patterns for compliance review.
Ongoing CDD is a resource-intensive function for high-volume gateways with large merchant bases. Regulatory technology platforms that automate document refresh reminders, watchlist re-screening, and risk tier reassessment significantly reduce the manual overhead while maintaining compliance quality.
Third-Party CDD Reliance
When a customer has been subject to CDD by another regulated entity — another payment institution, a bank, or a licensed exchange — the receiving regulated entity may, in certain circumstances, rely on that CDD rather than repeating the full verification process. Third-party reliance is permitted under the EU AML Directives and FATF standards, subject to conditions: the third party must be subject to AML regulation in an equivalent jurisdiction, the receiving entity must obtain the relevant CDD documentation from the third party, and the receiving entity retains ultimate responsibility for the adequacy of the CDD. Third-party reliance does not transfer compliance liability — the gateway that relies on another entity's CDD is accountable for any deficiencies in that CDD.
Compliance Note: This glossary entry is provided for general educational purposes only and does not constitute financial, investment, legal, or tax advice. Industry terminology may vary across jurisdictions and providers; definitions herein may not directly reflect the specific features, terms, or specifications of Finassets' services. For details on Finassets' offerings, please refer to official product documentation or contact our team directly.