loader image

What is standard due diligence?

Richard Simms
Richard Simms

Director and Founder of AMLCC and AMLCC Consult

What is standard due diligence?

The term standard due diligence isn’t used in FATF’s Recommendations. FATF asks countries to apply customer due diligence (CDD) on a risk-sensitive basis, rather than creating a separate legal category called ‘standard due diligence.’ Each country then writes that requirement into its own legislation, using its own terminology.

However, regulatory guidance in many countries uses ‘standard’ or ‘normal’ due diligence as shorthand for the level of customer due diligence (CDD) where the overall risk is neither clearly low (when simplified due diligence may be appropriate) nor clearly high (when enhanced due diligence is needed).

Deciding on the level of customer due diligence needed is part of taking a risk-based approach. You assess the client and the context first, then apply the level of due diligence that matches the risk.

When standard due diligence applies

For legal, accountancy and property businesses, and for dealers in precious metals and stones (also known as high-value dealers or HVDs), FATF’s Recommendation 10 sets out when you must apply CDD measures. 

Where the risk is assessed as normal, there are circumstances in which standard due diligence will usually apply. When you:

  • establish a business relationship;
  • carry out an occasional transaction of USD/EUR 15,000 or more, whether in a single operation or in several operations that appear linked;
  • carry out an occasional transaction that’s a wire transfer exceeding USD/EUR 1,000, under FATF’s Recommendation 16;
  • suspect money laundering (ML), terrorist financing (TF) or proliferation financing (PF); or
  • doubt the veracity or adequacy of documents or information previously obtained for the purposes of identification or verification.

An HVD must also apply CDD measures if they carry out an occasional cash transaction of USD/EUR 15,000 or more, whether in a single operation or in several linked operations, under FATF’s Recommendation 22. Some countries, including the UK, set their own threshold below FATF’s baseline.

Under FATF’s Recommendation 1, governments carry out national risk assessments to map their money laundering, terrorist financing and proliferation financing risks. These assessments consistently show that weak or incomplete due diligence is one of the most common compliance failings across all professional sectors. 

What standard due diligence involves

Standard due diligence has three core elements, which flow from the CDD requirements in FATF’s Recommendation 10. Even at the standard level, each element must be completed and recorded properly.

1. Identifying and verifying the client

You must establish who your client is and verify that identity using reliable and independent sources. The level of verification should be proportionate to the risks you have identified.

Individuals: photographic ID, proof of address and independent verification (for example electronic checks or corroborating information from trusted sources).

Companies: incorporation records, information about ownership and control (including directors and beneficial owners) and verification of the person who is actually instructing you.

Trusts or other structures: details of trustees, settlors, beneficiaries and anyone exercising control, supported by the trust deed or equivalent documentation.

The verification must be sufficient to give you confidence that the client is genuine and that the information you hold is consistent with the risks you have identified.

Technology can help, but national risk assessments warn that criminals increasingly use AI-generated fake IDs, synthetic identities and deepfake calls to bypass superficial checks. To manage these risks in practice, it is sensible to:

  • use more than one source of evidence, rather than relying on a single document or data provider;
  • build in a ‘genuine presence’ check for higher-risk or non-face-to-face clients (for example a live video call or liveness check);
  • sanity-check key details against open-source information and, where relevant, independent third-party records;
  • keep a short record of the steps taken and why they were sufficient in light of the risks.

2. Identifying beneficial owners

2. Identifying beneficial owners

If your client isn’t a natural person, you must identify beneficial ownership: the ultimate individuals (UBOs) who control or benefit from the entity. You must take reasonable steps to verify them.

Beneficial owners might include individuals who control a portion of the shares. FATF suggests 25% as this threshold but many countries set their own, so check what applies in your jurisdiction. However, UBOs might also have control over the client without holding any stake at all.

For most corporate clients, beneficial owners will include individuals who directly or indirectly own or control more than 25% of the shares or voting rights (or your country’s equivalent), as well as those who otherwise exercise significant influence or control. 

For example, this could be someone who can appoint or remove the majority of the board, who has veto rights over key decisions, or who otherwise exercises ultimate effective control of the business even with a smaller shareholding.

For partnerships and other unincorporated businesses, look at who is ultimately entitled to or controls a significant share of capital, profits or voting rights, and who in practice directs the business. 

For trusts and similar arrangements, the settlor, trustees, protector (if there is one), beneficiaries (or class of beneficiaries) and anyone who has control over how assets are used are normally treated as beneficial owners.

You must take reasonable steps to verify each beneficial owner and understand how they fit into the ownership and control structure. This might involve using corporate registries and beneficial ownership registers, reviewing structure charts and asking targeted questions about decision-making and voting arrangements.

Where no individual meets the ownership threshold that applies in your country, you should still identify and record the senior person or people who ultimately control the client and explain briefly why you reached that conclusion.

3. Understanding the purpose and nature of the relationship

To complete standard due diligence, you must understand the purpose and intended nature of the business relationship or transaction. In practice, that means understanding:

  • why the client is using your services;
  • how their business operates;
  • whether the relationship or transaction makes commercial and financial sense; and
  • how the client expects to fund the work or transaction.

This part of standard due diligence is where many businesses fall short. National risk assessments highlight that criminals exploit weak understanding of client activity, vague explanations of source of funds and inconsistencies that go unchallenged. 

You should avoid relying on generic statements such as ‘private funds’ or ‘family money’ without obtaining proportionate evidence. And you should resolve any inconsistencies between what the client tells you and what you see in documents or open sources.

When standard due diligence becomes enhanced

Under the risk-based approach, standard due diligence must be strengthened when the level of risk increases. FATF’s Recommendations require you to apply enhanced due diligence in situations where, for example:

  • you discover the client has provided false or stolen identification documentation or information;
  • there is a high risk of ML, TF or PF;
  • transactions with the client have no apparent economic or legal purpose;
  • transactions with, or made by, the client are complex, unusually large or show an unusual pattern;
  • the client or beneficial owner is a politically exposed person (PEP), a known close associate of a PEP or a family member of a PEP;
  • any of the parties is established in a high-risk jurisdiction; or
  • your client risk assessment or information from your AML supervisor indicates that the client is high risk.

You may start from standard due diligence and then move to enhanced due diligence if new information, behaviour or transaction patterns change the risk profile.

Consequences of weak standard due diligence

The consequences of poor standard due diligence can be serious for both businesses and individuals.

Regulatory and supervisory action – including fines, remedial directions, restrictions on activities and, in serious cases, loss of authorisation or registration.

Criminal liability – if you know or suspect that proceeds of crime are involved and fail to make a required report or tip off a client (known as tipping off)

Civil claims – from clients or others who suffer loss where your failure to carry out adequate due diligence contributed to the wrongdoing.

Reputational damage – including negative media coverage, loss of client and referrer confidence and increased scrutiny from supervisors and insurers.

In many enforcement cases, the problem is not an exotic high-risk structure but ordinary work where standard due diligence was incomplete, poorly evidenced or not kept up to date.

Common weaknesses in standard due diligence

Supervisors repeatedly flag the same issues across regulated businesses. These weaknesses almost always relate to standard due diligence rather than the more formal enhanced due diligence cases.

Relying on incomplete identity checks

Businesses often verify documents but fail to verify the person behind them, despite rising fake ID risks, such as synthetic identity fraud and AI-generated impersonation attempts highlighted in national risk assessments. 

Checks that stop at ‘passport on file’ without asking whether the document is genuine, current and is actually the person you’re acting for are unlikely to be sufficient.

Accepting vague or untested explanations

Generic statements about ‘private funds’, ‘consultancy income’ or ‘family money’ require verification. 

National risk assessments show that criminals rely on professionals accepting stories without evidence. You need to obtain proportionate documentation to back up what you are told and record what you have seen.

Treating templates as compliance

Risk assessments and standard due diligence records must reflect the actual client and matter. Templates and checklists are useful prompts but do not, on their own, demonstrate compliance if the content is thin, inconsistent or clearly not tailored to the engagement.

Not linking standard due diligence and ongoing monitoring

Standard due diligence must be refreshed if the client’s behaviour, ownership or transaction pattern changes. Many businesses complete onboarding but fail to update files later, which supervisors consistently view as a breach of the requirement to carry out ongoing monitoring of business relationships.

The role of the risk-based approach in standard due diligence

Standard due diligence is only meaningful when driven by a well-designed client risk assessment. You cannot apply standard due diligence safely if you do not understand the main risks your business faces, including:

  • the risks within your client base;
  • the jurisdictions involved;
  • the services you provide;
  • the delivery channels you use; and
  • your exposure to fraud, sanctions evasion, cryptoassets and other emerging technologies.

National risk assessments place significant weight on risk-based decision-making and highlight the need for businesses to update their business-wide risk assessment in line with emerging threats such as AI-enabled fraud, crypto-assets and cross-border risks. Your approach to standard due diligence should evolve alongside that assessment.

Final thoughts

Standard due diligence is the backbone of AML compliance. It is the everyday discipline that protects your business long before a high-risk client walks through the door.

Getting standard due diligence right means understanding your client, verifying information independently, documenting the rationale behind your decisions and updating your view as the relationship develops. 

Doing this well makes it easier to explain and defend your approach to supervisors and helps your business stay ahead of evolving risks.

Explore how AMLCC’s features can keep your business completely AML compliant

The one-stop AML solution

We know AML

We’re internationally recognised AML experts
We work with most accountancy supervisors and the Law Society
Bespoke AML consultancy available for all sectors

The one-stop AML solution

We know AML

We’re internationally recognised AML experts
We work with most accountancy supervisors and the Law Society
Bespoke AML consultancy available for all sectors

What others have said

“We had the man from the ICAEW here yesterday to carry out a QAD practice review. We got a clean bill of health – not a single action point…That is in no small measure due to AMLCC so I just wanted to say ‘thank you’”

“Thank you for such a perfect and informative [solution]. You have given me a clear direction for my AML training and CPD.”

“I just wanted to say ‘thank you’ to you, Richard, and all the team at AMLCC for providing a service that really does minimise the burden of AML compliance.”

“What a refreshing pleasure working with a company who actually listens to the feedback from their customers and communicates with them!”

“Your team they have been excellent from the moment Fiona did a demo for me with only 15 minutes notice, and thoroughly going through the AMLCC product, answering the many questions I had! It was at this point at which I made up my mind this is the sort of business I want to work with for my AML.”

Making compliance easier

AMLCC newsroom
Scroll to Top