What is customer due diligence (CDD)?

Customer due diligence (CDD) is the process that financial institutions, cryptocurrency exchanges, and other regulated entities use to verify a customer’s identity, understand the nature of their activity, and assess the financial crime risk they present before and throughout a business relationship. CDD is a foundational requirement of every anti-money laundering (AML) program, designed to prevent money laundering, terrorist financing, and other illicit activities.

At its core, customer due diligence answers a simple question: who is this customer, and what risk do they pose? To answer it, institutions collect identification documents, verify identity, identify beneficial owners, and build a customer risk profile that determines how the relationship will be monitored. CDD is closely tied to know your customer (KYC)—KYC is the identity-verification step, while CDD is the broader, risk-based process that surrounds it.

In the cryptocurrency industry, customer due diligence extends beyond traditional identity verification to on-chain analysis. Virtual asset service providers (VASPs) use blockchain analytics to screen wallet addresses, assess exposure to illicit sources, and evaluate the risk profile of customers and counterparties—evidence that traditional due diligence processes designed for bank accounts cannot produce.

Why does customer due diligence matter?

Customer due diligence is the first line of defense against financial crime. Without it, financial institutions cannot know who their customers are, whether their activity is legitimate, or whether they are facilitating money laundering, sanctions evasion, or terrorist financing.

The regulatory mandate is explicit. In the United States, the Bank Secrecy Act (BSA) and FinCEN’s CDD Final Rule require covered institutions to implement risk-based customer due diligence, including beneficial ownership identification. Internationally, the Financial Action Task Force (FATF) Recommendation 10 establishes CDD as a baseline obligation, implemented through national regimes such as the EU Anti-Money Laundering Directives. It is one of the five pillars of an effective AML compliance program.

The cost of weak CDD is severe. Inadequate customer due diligence has been at the center of major enforcement actions and billions of dollars in penalties, alongside reputational damage and loss of banking relationships. Beyond avoiding penalties, strong due diligence enables institutions to onboard customers confidently, enter new markets, and serve higher-risk segments under appropriate controls. It is both a compliance requirement and a business enabler.

How does customer due diligence work? Key components

An effective CDD process combines identity verification, risk assessment, and ongoing oversight into a single risk-based framework. The following components form the operational core of the process.

Identity verification and the customer identification program (CIP)

The process begins with verifying the identity of the customer. Under a customer identification program (CIP), institutions collect and verify identification documents—name, date of birth, address, and identification number—at onboarding. Digital onboarding and digital identity solutions increasingly automate this step, allowing fintech firms and crypto platforms to verify identity remotely while meeting regulatory standards.

Beneficial ownership

For corporate and legal-entity customers, CDD requires identifying the beneficial owners—the natural persons who ultimately own or control the entity. Mapping ownership structure and ultimate beneficial owners (UBOs) prevents bad actors from hiding behind shell companies, and collecting beneficial ownership information is a specific requirement of FinCEN’s CDD Final Rule.

Risk assessment and the customer risk profile

A central function of CDD is risk assessment: evaluating the money laundering and terrorist financing risk a customer presents based on their profile, geography, products used, and expected activity. The resulting customer risk profile drives every downstream decision—the level of due diligence applied, monitoring intensity, and review frequency. Customers in high-risk countries or matching politically exposed persons (PEP) and sanctions lists receive elevated scrutiny.

Ongoing monitoring

CDD is not a one-time onboarding event. Ongoing monitoring keeps the customer risk profile current by reviewing transactions for suspicious activity, detecting red flags, and updating risk ratings as behavior changes. Transaction monitoring systems flag activity inconsistent with a customer’s expected profile, generating alerts that compliance teams investigate and, where warranted, escalate to suspicious activity reports.

The three levels of due diligence

CDD is applied through a risk-based approach with three levels of intensity:

  • Simplified due diligence (SDD): The lightest level, applied to low-risk customers and certain occasional transactions where the risk of financial crime is minimal.
  • Standard customer due diligence (CDD): The default level for most customers—identity verification, beneficial ownership, risk profiling, and ongoing monitoring.
  • Enhanced due diligence (EDD): The deepest level, reserved for high-risk customers such as PEPs, customers in high-risk jurisdictions, and complex ownership structures. EDD adds source of funds verification, intensified monitoring, and additional screening.

Matching the level of due diligence to the level of risk is the essence of an effective, risk-based AML program—conserving resources for genuinely higher-risk relationships while not over-burdening low-risk customers.

When is customer due diligence required?

Regulated institutions must perform CDD at several points in a relationship:

  • At onboarding, before establishing a new business relationship or account.
  • For occasional transactions above regulatory thresholds, even where no ongoing relationship exists.
  • When suspicion arises, regardless of thresholds, if there is reason to suspect money laundering or terrorist financing.
  • When customer information changes, requiring the risk profile to be refreshed.
  • On an ongoing basis, through continuous monitoring throughout the relationship.

These obligations apply across banks, financial institutions, money services businesses, fintechs, and—critically—virtual asset service providers operating in regulated jurisdictions.

How is customer due diligence used in cryptocurrency compliance?

Cryptocurrency customer due diligence applies the same risk-based principles as traditional finance, but adds an on-chain dimension that traditional due diligence cannot reach. Crypto was once perceived as anonymous; in reality, public blockchains such as Bitcoin are pseudonymous, recording every transaction on an immutable ledger that blockchain analytics can trace and attribute.

Wallet screening and risk assessment. In crypto, CDD includes screening customer wallet addresses for exposure to sanctioned entities, darknet markets, mixers, scams, and stolen funds. Blockchain analytics provides this wallet-level risk assessment across 1,000+ assets and protocols—covering crypto assets and stablecoins that traditional CDD tools cannot interpret.

Source of funds and transaction history. Because on-chain activity is permanently recorded, compliance teams can review a customer’s transaction history directly, tracing the source of funds across chains to confirm activity is consistent with their stated profile.

VASP and counterparty obligations. Under FATF guidance and the Travel Rule, VASPs must perform CDD on customers and exchange originator and beneficiary information for qualifying transfers. This requires identifying counterparty VASPs and assessing their compliance posture.

Ongoing on-chain monitoring. Crypto due diligence pairs onboarding checks with continuous transaction monitoring, so that emerging risk—new exposure to a sanctioned address, an OFAC-listed entity, or a high-risk mixer—triggers review even after a customer is onboarded. Effective crypto compliance and regulatory compliance depend on this blockchain-native infrastructure.

Customer due diligence vs. KYC: what’s the difference?

Customer due diligence and KYC are closely related but not identical, and the terms are often used interchangeably.

KYC (Know Your Customer) refers specifically to verifying a customer’s identity—confirming they are who they claim to be using identification documents and identity verification.

Customer due diligence (CDD) is the broader, risk-based process that includes KYC but extends to beneficial ownership identification, risk profiling, and ongoing monitoring throughout the relationship.

In short: KYC is the identity check; CDD is the full risk-management process built around it. Both sit within the larger AML framework, which also encompasses sanctions screening, suspicious activity reporting, and transaction monitoring.

KYC Customer Due Diligence (CDD)
Focus Verifying customer identity Verifying identity + assessing and monitoring risk
Scope Identification documents, identity verification KYC + beneficial ownership + risk profile + ongoing monitoring
Timing Primarily at onboarding Onboarding and continuous
Regulatory basis BSA/CIP Rule, FATF Rec. 10 BSA CDD Final Rule, FATF Rec. 10

Risks and common misconceptions about customer due diligence

“CDD and KYC are the same thing.” KYC is the identity-verification component; CDD is the broader risk-based process that includes ongoing monitoring and beneficial ownership. Treating them as identical leads institutions to verify identity but neglect the monitoring that catches financial crime.

“CDD is a one-time onboarding step.” Effective CDD requires ongoing monitoring throughout the relationship. A customer’s risk profile changes over time, and static checks miss the very activity CDD exists to detect.

“Crypto is too anonymous for meaningful CDD.” Public blockchains are pseudonymous, not anonymous. Blockchain analytics can trace fund flows, establish wallet exposure, and verify on-chain source of funds—often providing more granular evidence than traditional CDD on cash or wire transfers.

“More documents mean better CDD.” Collecting identification documents is necessary but not sufficient. The challenge is converting customer data into an accurate risk profile and effective ongoing monitoring—particularly across crypto exposure that traditional systems cannot evaluate.

The central operational risk is inconsistency: applying due diligence unevenly, or failing to refresh risk profiles as customer behavior evolves. Both create gaps that sophisticated actors exploit.

How Chainalysis helps strengthen customer due diligence

Chainalysis provides the blockchain intelligence that powers CDD for crypto—giving compliance teams the on-chain evidence to verify customers, assess risk, and monitor relationships continuously.

Chainalysis KYT (Know Your Transaction): Delivers real-time transaction monitoring and dynamic risk profiling across 1,000+ assets and protocols, supporting the ongoing monitoring component of this process and reducing false positives by up to 90%.

Chainalysis Address Screening: Screens customer wallet addresses against sanctions lists, known illicit entities, and risk categories—the wallet-level layer of crypto due diligence that traditional name screening cannot provide.

Chainalysis VASP Risking: Assesses the compliance posture and risk exposure of counterparty crypto platforms, supporting checks on VASP relationships and Travel Rule obligations.

Chainalysis Reactor: Enables compliance teams to trace on-chain source of funds and investigate flagged activity. Reactor’s analysis has been validated under the Daubert standard in U.S. courts—a structural advantage unmatched by other blockchain analytics providers.

Chainalysis Academy: Has certified over 50,000 professionals in blockchain analytics and crypto compliance, helping AML teams apply due diligence effectively in digital assets.

Frequently asked questions about customer due diligence

Q: What is customer due diligence (CDD)?

A: Customer due diligence (CDD) is the risk-based process that regulated institutions use to verify a customer’s identity, identify beneficial owners, assess the financial crime risk they present, and monitor the relationship over time. CDD is a core component of anti-money laundering (AML) compliance, required under the Bank Secrecy Act, FinCEN’s CDD Final Rule, and FATF standards.

Q: What is the difference between CDD and KYC?

A: KYC (Know Your Customer) is the process of verifying a customer’s identity. Customer due diligence (CDD) is the broader, risk-based process that includes KYC plus beneficial ownership identification, risk profiling, and ongoing monitoring. KYC is the identity check; CDD is the full risk-management process built around it.

Q: What are the levels of customer due diligence?

A: There are three levels: simplified due diligence (SDD) for low-risk customers, standard customer due diligence (CDD) for most customers, and enhanced due diligence (EDD) for high-risk customers such as politically exposed persons (PEPs) and those in high-risk jurisdictions. Institutions apply the level that matches the customer’s risk under a risk-based approach.

Q: How does customer due diligence work for cryptocurrency?

A: Cryptocurrency customer due diligence adds on-chain analysis to traditional checks. Beyond verifying identity, VASPs use blockchain analytics to screen wallet addresses for exposure to sanctioned and illicit entities, review on-chain transaction history and source of funds, assess counterparty risk, and monitor customers continuously for emerging red flags.

Q: Who is required to perform customer due diligence?

A: Banks, financial institutions, money services businesses, fintechs, and virtual asset service providers (VASPs) are required to perform customer due diligence in regulated jurisdictions. Obligations apply at onboarding, for certain occasional transactions, when suspicion arises, and on an ongoing basis throughout the relationship.

Chainalysis enables cryptocurrency customer due diligence by giving compliance teams on-chain evidence to verify a customer’s source of funds, screen wallet exposure against sanctioned and illicit entities, and continuously monitor risk profiles across 1,000+ assets and protocols.

Request a demo.