Due diligence

The level of scrutiny each customer warrants. How it is graded by risk, what triggers the enhanced version, and why it does not end on sign-up day.

In short

Due diligence is the set of measures an organization applies to know a customer and keep that knowledge current for as long as the relationship lasts.

Its defining feature is grading: not every customer gets the same scrutiny. The level is set based on the risk each relationship represents, and that calibration is a decision the organization has to be able to justify.

That is why due diligence is not a requirement you fulfill, it is a criterion you apply. Two customers of the same organization can go through different processes without either one being wrong.

Due diligence has levels, and risk sets the level

The regimes in the region work with three intensities. The names vary a bit between standards; the logic does not.

  • Simplified — for relationships with demonstrated low risk. It reduces the depth of the information required, never the identification itself. There is no customer who does not need to be identified.
  • Standard — the norm for most of the portfolio. Customer identification, understanding the purpose of the relationship, and routine monitoring.
  • Enhanced — for high-risk relationships. It adds source of funds and wealth, approval from a higher hierarchical level to establish or maintain the relationship, and more frequent monitoring with lower thresholds.

Applying the highest level to the entire portfolio is not caution: it is a badly designed program. It uses up the team's time evenly and leaves it unable to look where the risk actually is, which is exactly what a risk-based approach is meant to avoid.

What sets the level, and what triggers the enhanced version

The classification is built on four factors, and all four are assessed together.

  • The customer — who they are, what they do, what structure stands behind them, and whether they qualify as a PEP.
  • The product — how exposed it is to the movement of funds and how easy it is to turn into cash.
  • The channel — how the relationship was established. A relationship formed with no physical presence has a different risk profile than an in-person one.
  • The jurisdiction — where the customer operates and which countries their activity relates to.

On that basis, the most frequent triggers of enhanced due diligence are PEP status, corporate structures that make it hard to identify the ultimate beneficial owner, transactions with no apparent economic justification, and exposure to jurisdictions flagged for deficiencies in their prevention regime, as explained under FATF and GAFILAT.

The digital channel deserves a note, because the classic reading has gotten old. Non-in-person onboarding was considered a risk factor in itself for years, back when the only solid way to check identity was having the person in front of you. Today a digital process with document verification, biometric comparison, and liveness detection produces more evidence, and more auditable evidence, than an employee glancing at a document across a counter. What adds or removes risk is not the channel, it is the quality of the check and the evidence it leaves behind.

Due diligence does not end at sign-up

The most expensive design mistake in this part of the program is treating it as an onboarding requirement.

The obligation is continuous. The organization has to know who its customer is on day one and keep knowing it the following year, which implies three different things.

  • Updating the information — data changes, and an outdated file stops supporting the risk classification it was built with.
  • Reviewing the classification — the level assigned at sign-up expires. A customer can take on a public role, change activity, or modify their corporate structure.
  • Monitoring activity against the profile — which is where due diligence connects with the rest of the AML program and stops being an onboarding formality.

Compliance due diligence is not M&A due diligence

The two uses of the term coexist and mean very different things, which explains much of the confusion when it comes up in a project conversation.

In a corporate transaction, due diligence is the review a buyer runs on the company they are about to acquire: contracts, liabilities, litigation, tax compliance. It is a time-bound, voluntary exercise aimed at settling a price.

In money-laundering prevention, due diligence is a regulatory obligation over each customer, continuous for as long as the relationship lasts, with a minimum content set by the standard and a supervisor who can review it.

The first happens once and ends in a report. The second never ends, and what it produces is a living file that has to be shown on demand.

Frequently asked questions

It is the set of measures an obliged organization applies to know each customer and keep that knowledge up to date for as long as the relationship lasts: identifying them, understanding the purpose of the relationship, classifying their risk, and monitoring their activity against that profile. It is graded in three levels, simplified, standard, and enhanced, based on the risk each relationship represents.

When the relationship presents a high risk. The most frequent triggers are that the customer is a politically exposed person or part of their circle, that their corporate structure makes it hard to identify the ultimate beneficial owner, that their activity has no apparent economic justification, or that they are exposed to jurisdictions flagged for deficiencies in their prevention regime. The measures it adds are source of funds and wealth, approval from a higher hierarchical level, and more frequent monitoring.

KYC is the identification part: checking who the person is and keeping the evidence of that check. Due diligence is broader. It includes that initial knowledge and adds the customer's risk classification, the decision about what level of scrutiny applies to them, and the obligation to sustain that knowledge over time. In practice, KYC is what gets done; due diligence is the criterion that defines how much gets done and for how long.

No. No level of due diligence removes the duty to identify. The simplified version reduces the depth of the additional information required and the frequency of its updates, for relationships whose low risk the organization can demonstrate. Identifying the customer and keeping evidence of it always stays in place.

One identity, one SDK

VU ONE brings identity verification, authentication and fraud protection together on a single identity graph.

The verification you run at signup stays available to authentication and to your fraud rules, with no repeated processes and no duplicated data.

Verify, Authenticate and Protect, consolidated in one place.

Request a demo