What is customer due diligence in banking and financial services?

Jonathan  Jensen

Jonathan Jensen

Regulatory Policy Advisor

Opening a new account should only take minutes. But for banks, verifying a customer's identity, assessing their risk and meeting Anti-Money Laundering (AML) and Know Your Customer (KYC) obligations is rarely that simple.

Customer due diligence (CDD) sits at the center of this challenge. While you must verify genuine customers quickly, you also have to screen for financial crime risk and comply with complex regulations. Yet many compliance processes still rely on disconnected systems and manual reviews that create friction for legitimate users while driving up operational costs.

To make matters more difficult, fraud tactics are becoming more sophisticated just as customers are demanding faster, smoother digital experiences. 

This article will explain what CDD is, when to apply it, how to build an effective program and how you can optimize your workflows with modern identity verification and risk intelligence. We’ll cover:

  • What is customer due diligence, and what role does it play in banking?
  • When does customer due diligence need to be applied?
  • The customer due diligence process explained
  • What banks often struggle with when it comes to customer due diligence
  • How GBG helps banks strengthen customer due diligence

Ready to strengthen your CDD process and start onboarding more customers quickly and securely? Book a demo to learn how our identity verification and risk intelligence solutions can help.

What is customer due diligence, and what role does it play in banking?

CDD is the process banks use to understand who their customers are and the level of financial crime risk they pose. By collecting and validating customer data, you can determine if a customer relationship aligns with your risk appetite and regulatory compliance obligations. It's the foundation of a bank's wider risk management framework, and it starts with a formal Customer Identification Program (CIP) that confirms a customer's identity before an account is opened.

Ultimately, effective due diligence acts as a protective shield. It prevents bad actors from exploiting your institution for illicit activities while building trust with genuine clients. CDD applies to both KYC processes for individuals and Know Your Business (KYB) processes for corporate entities.

A strong due diligence program protects banks from:

  • Money laundering schemes: Helps understand where a customer’s money comes from and whether their transactions match their known profile
  • Terrorist financing: Identifies individuals or organizations that may be using financial services to move money that supports terrorist activities
  • Sanctions evasion: Screens customers against sanctions lists and identifies attempts by restricted individuals or companies to access financial services or move funds
  • Fraudulent accounts: Verifies that customers are who they claim to be, helping prevent criminals from opening accounts with stolen or fake information
  • Mule accounts: Identifies accounts opened or controlled by individuals who allow criminals to move illicit funds through their accounts

Beyond defense, a risk-based CDD approach allows you to streamline onboarding by giving low-risk customers a fast-track experience while focusing heavier manual scrutiny only where risk is elevated.

When does customer due diligence need to be applied?

Customer due diligence is most commonly performed during onboarding before a bank opens a new checking account, savings account, credit product, business account or investment account. At this stage, banks verify a customer's identity, collect information needed for risk assessment and determine the appropriate level of due diligence. The same information often feeds directly into underwriting decisions for lending and credit products.

But CDD doesn't end after onboarding is complete. Banks are required to monitor customers throughout the relationship and may conduct additional reviews when transaction monitoring surfaces suspicious activity, such as large transactions, international fund transfers, interactions with high-risk jurisdictions or rapid movement of funds. These behaviors are common red flags for money laundering.

Customers presenting elevated risk may be subject to enhanced due diligence (EDD). While standard CDD is required for all customers, EDD involves deeper investigation and ongoing monitoring to better understand higher-risk individuals or organizations.

The customer due diligence process explained: 6 steps

Here is an overview of what the CDD process entails:

1. Collect customer information

Gather the information needed to establish customer identity and understand risk. For individuals, this means full legal name, date of birth, government-issued ID and contact details. 

For businesses, collect the registered business name, corporate address, registration number and identity details for all ultimate beneficial owners (UBOs). 

2. Verify customer identity 

Confirm that the submitted information belongs to a real person or active business. Use a combination of verification methods, such as:

  • Database verification: Checks customer information against trusted databases and data sources to confirm details such as name and date of birth
  • Document verification:Verifies a customer’s government-issued ID to confirm it’s authentic and belongs to the person applying
  • Biometric verification: Uses facial recognition to compare a customer’s live image with the photo on their identity document
  • Address verification: Confirms that a customer’s address is valid using sources like utility records, government databases, or credit reference data

3. Assess customer risk

Evaluate risk factors to assign a risk score. Consider geographic exposure (connections to sanctioned regions), product risk (for example, cash-intensive businesses) and customer characteristics (such as political exposure or complex corporate ownership webs).

4. Screen against watchlists 

Run customer names against sanctions lists, PEP lists, adverse media databases and regulatory enforcement databases, such as the US Securities and Exchange Commission enforcement actions database.

5. Apply EDD where necessary

If a customer is flagged as high-risk in steps three or four, escalate them to EDD. This usually requires collecting additional identity documents, verifying the source of wealth or funds (via tax returns or business ledgers) and establishing more frequent transaction review intervals.

6. Perform ongoing monitoring and investigate suspicious activity

CDD isn’t a one-time event. Continuously monitor transactions for anomalies, track changes in risk profiles and update sanctions databases in real time to catch emerging compliance issues.

When suspicious activity is detected, you may need to investigate further, escalate internally, file Suspicious Activities Reports (SARs) or update customer risk ratings.

What banks often struggle with when it comes to customer due diligence

While CDD is essential for managing risk and meeting regulatory obligations, many banks face operational challenges that make it difficult to deliver fast and accurate due diligence.

  • Balancing compliance and customer experience: Lengthy onboarding processes can increase abandonment rates and frustrate genuine customers. You need to satisfy regulatory requirements without creating unnecessary friction.
  • Fragmented data and disconnected systems: Many banks rely on multiple vendors and manual processes, which can lead to inconsistent risk assessments, data silos, operational inefficiencies and increased compliance costs.
  • AI-powered fraud: Fraud tactics are becoming increasingly sophisticated, and traditional verification methods often struggle to detect new threats, such as synthetic identity fraud and deepfakes.
  • Global complexity: Navigating varying regulatory standards and diverse global ID formats makes international expansion more challenging.
  • Ongoing monitoring at scale: Reviewing thousands or millions of transactions and customers manually is resource intensive and prone to delays.

How we help banks strengthen customer due diligence

A strong CDD program requires a single, unified view of customer data and risk intelligence across the entire lifecycle.

For more than 30 years, we’ve been helping banks like Santander, Metro Bank and HSBC solve their compliance challenges by combining identity verification, fraud prevention and risk management into a unified, scalable platform. 

Here are three reasons these banks and 20,000+ other companies across the globe choose to work with us: 

Verify identities in 195 countries with trusted data and layered verification workflows

Effective CDD starts with confidence in a customer's identity. But as fraudsters increasingly use synthetic identities and AI-generated documents, relying on a single verification check is no longer enough.

We help banks implement a layered defense by combining trusted data registries, biometric validation, document authentication, and multi-source checks into a single onboarding flow.

 

Through our end-to-end identity KYC orchestration platform, GBG Go, you gain instant access to more than 80 identity, fraud and risk modules across 195 countries, plus hundreds of trusted datasets and support for more than 8,500 identity document types.

Address verification adds another important layer of assurance. Validating that a customer's address is accurate and associated with the individual helps support KYC requirements and reduce onboarding friction caused by incomplete or inaccurate information.

Our multi-source verification is particularly valuable for CDD for underbanked or thin-file customers because it enables you to validate their information against alternative data sources when they can’t be matched using traditional options like a credit-based check. 

Identify higher-risk customers earlier with integrated risk intelligence

Due diligence doesn't end once you've verified an identity. You must also assess whether a customer presents a heightened risk of money laundering, sanctions violations, or another financial crime – and continue monitoring that risk over time.

 

We help embed risk intelligence directly into your CDD workflows by combining sanctions and PEP screening, adverse media monitoring, fraud intelligence, and email and mobile intelligence into our GBG Go platform. This provides a comprehensive view of risk and enables your team to identify potential risks earlier and make more consistent, risk-based decisions.

For KYB, you can automatically map out corporate structures and UBO data within the same system for KYB, GBG Detected.

And by adding GBG Trust (our cross-industry intelligence network that monitors millions of transactions across 28 sectors) into your flow, you can surface identity risk signals in real time. This gives your team immediate visibility into suspicious patterns and enables them to intervene sooner.

Automate ongoing monitoring and compliance workflows

Collecting customer and risk data is only half the challenge. You also need to investigate alerts, track changes in customer risk, maintain audit trails and demonstrate compliance to regulators – often across multiple systems and teams.

Instead of jumping between disconnected spreadsheets and databases, our GBG Go and GBG Detected platforms consolidate your post-onboarding compliance.

For example, our automated sanctions, PEP and adverse media monitoring helps identify customer changes that may require additional review, while intelligent alerts highlight higher-risk customers and cases. Built-in case management provides a clear audit trail of verification checks and risk decisions, which makes it easier to support regulatory reviews and internal audits.

Real-time dashboards give your team visibility into compliance performance, while A/B testing capabilities help optimize workflows and balance risk controls with customer experience.

How we helped a digital banking client achieved a 20% uplift onboarding new customers

A digital banking client was struggling with lower-than-desired onboarding rates and had limited visibility into customer risk during account opening. While the bank wanted to improve identity verification performance, it was concerned that adding more checks would create friction and reduce conversion rates.

The client implemented our identity data verification solution as the first step in its onboarding process. Customer details such as name, date of birth, and address were automatically checked against a broad network of trusted public and private data sources behind the scenes. This enables fast identity validation without adding friction to the customer experience.

Applicants identified as higher risk were then routed to an additional authentication step using dynamic knowledge-based questions. This risk-based approach helped genuine customers strengthen their identity assurance and continue through onboarding, while making it more difficult for fraudsters to proceed.

By combining identity verification and risk intelligence within a single workflow, the bank was able to improve its customer experience and achieve a 20% increase in successful new customer onboarding.

Read the full case study: GBG success story with digital banking brand

 

Strengthen customer due diligence with smarter identity and risk intelligence

CDD is about more than just meeting compliance requirements. It also plays an important role in building trust and creating a smooth customer experience from day one. 

The challenge is maintaining that smooth experience as fraud risks grow or regulatory obligations become more complex. By unifying identity verification, risk assessment and ongoing monitoring, you can better manage risk and deliver the onboarding experience customers expect without sacrificing compliance. 

Book a demo to discover how we can help you transform your CDD process and onboard more genuine banking customers. 

 

FAQs: Customer due diligence in banking

What is the difference between CDD and EDD?

CDD applies to standard-risk customers, while EDD involves additional verification and monitoring measures for higher-risk customers.

What information is collected during customer due diligence?

Typically, banks collect basic identity details (name, date of birth, address and government ID) for individuals and registration records, operating addresses and ownership structures for business accounts.

How can banks automate customer due diligence?

Banks can automate CDD by using a unified orchestration platform that automatically verifies IDs, runs PEP/sanctions checks, calculates risk scores and flags exceptions for human review.


Related Content