Jurisdicción de Estados Unidos,
explicada con claridad.

U.S. jurisdiction,
explained clearly.

Customer Due Diligence (CDD): What U.S. Businesses Must Verify

customer due diligence requirements

Two very different people ask about customer due diligence requirements, and both get the same generic answer. One is a compliance lead at a bank who needs to know exactly what 31 CFR 1010.230 obliges the institution to collect. The other is a CFO or general counsel at an operating company that has just been told onboarding is frozen until certain ownership information is produced, and who cannot tell whether that demand comes from a statute, a contract, or the other side’s internal policy. Those are two separate legal worlds that share a vocabulary.

We run these files continuously on both sides of that line: for regulated institutions building customer files that survive an examination, and for operating businesses that have to satisfy someone else’s due diligence while protecting themselves from a counterparty they cannot see through. What follows is what is genuinely required, what «enough» means when nothing is formally required of you, and where these files actually fail.

What the customer due diligence requirements actually are

The term has a precise regulatory meaning and a loose commercial one, and almost every misunderstanding starts there. The precise meaning is the CDD Rule at 31 CFR 1010.230, adopted in 2016 with a compliance date of 11 May 2018. It binds covered financial institutions: banks, brokers or dealers in securities, mutual funds, and futures commission merchants and introducing brokers in commodities. If your company is not one of those, the CDD Rule imposes no obligations on you. That resolves most of the anxiety we encounter and sets the trap: not being covered is not the same as being unregulated.

For covered institutions, the rule defines four core elements the anti-money-laundering program must contain:

  1. Customer identification and verification — the long-standing CIP obligation.
  2. Identification and verification of the beneficial owners of legal entity customers.
  3. Understanding the nature and purpose of the customer relationship in order to develop a customer risk profile.
  4. Ongoing monitoring to identify and report suspicious transactions and, on a risk basis, to maintain and update customer information.

The fourth element changes the character of the other three: due diligence is a continuing duty, not an onboarding event, and identifying information is retained five years after the account closes.

This is also where the kyc vs cdd question resolves itself. KYC is an industry label for a program, not a rule you can cite. CDD is the content a regulator expects inside that program. A company can run an elaborate KYC process and still fail on due diligence, because collecting documents and understanding a customer are different activities. Screening is not verification either: it tells you whether a name matches a designation, not whether the entity is what it claims to be. Our breakdown of the FinCEN CDD Rule takes the text apart element by element.

The output is not a folder. It is a customer risk profile: a written view of who the customer is, what they say they will do with the relationship, and what would count as an anomaly. Without that baseline, ongoing monitoring has nothing to measure against. Examiners read the profile first, because that is where judgment is visible.

On ownership, the rule works in two prongs. The ownership prong reaches each individual who directly or indirectly owns 25 percent or more of the equity interests of a legal entity customer — up to four individuals, sometimes none. The control prong reaches a single individual with significant responsibility to control, manage or direct the entity: a chief executive, chief financial officer, managing member, general partner or president. There is always exactly one. Where a trust owns 25 percent or more, the trustee is the beneficial owner. Sole proprietorships and natural persons are not legal entity customers. Identifying who really controls a company is a separate discipline, and we treat it as one.

The most recent change is widely misreported. FinCEN’s exceptive relief of 13 February 2026, Order FIN-2026-R001, issued under Executive Order 14192, means covered institutions no longer have to verify beneficial owners at every new account opening by an existing legal entity customer. Verification can be limited to initial account opening, to facts calling prior information into question, and to what the institution’s risk-based procedures warrant. The conditions carry the weight: written procedures stay in place, the customer must certify or confirm that prior information is current, that confirmation must be documented, and full verification applies if the customer cannot. The 25 percent threshold and the control prong were untouched — this is relief from a trigger frequency, not from the obligation.

How much is enough when the CDD Rule does not bind you

Most companies searching this topic are not covered financial institutions. For them the CDD Rule is background, and four other forces do the real work: sanctions law, which applies to everyone; contractual representations already signed; their bank, which pushes its own obligations downstream as onboarding demands; and their own exposure to a counterparty that is not what it appeared to be.

ElementCovered financial institutionOrdinary U.S. operating business
Identity verification of the customerRequired under the CIP and CDD RuleNot required; driven by contract and commercial risk
Beneficial ownership verificationRequired for legal entity customersNot mandated; demanded by banks, insurers and large buyers
Written customer risk profileRequired element of the programNot mandated, but the only record of why you accepted
Ongoing monitoring and refreshRequired, on a risk basisGoverned by contract terms and renewal cycles
OFAC sanctions screeningRequiredRequired — strict liability, applies to every business

The bottom row is the one that costs companies money. OFAC administers a strict-liability regime, and intent is not a defense. The SDN list is the primary list, but the 50 Percent Rule catches unprepared businesses: an entity owned 50 percent or more, directly or indirectly and in the aggregate, by blocked persons is itself blocked though its name appears on no list. You cannot screen your way to that answer; you have to establish the ownership chain. That is why a structured corporate KYC program for suppliers and clients is worth building before a bank forces it.

What the official guidance does not tell you

A certification form is a starting point, not verification. The rule permits a certification form — appendix A to 1010.230, or equivalent certified information — and institutions read that as permission to treat the signed form as the answer. A certification proves the customer said something; it does not prove the statement is true. In our files the form is where the inquiry begins: it gives you names to test against formation documents, operating agreements and the reality of who signs and who benefits. When those sources disagree with the form, the disagreement is the finding.

The control prong is where files quietly fail. The ownership prong is arithmetic and people generally get it right. The control prong asks for judgment, and judgment can be gamed. We see it repeatedly: a nominal officer named because the title fits the form — a local director, a family member, an administrator with no real authority — while whoever actually directs the entity appears nowhere in the file. Nothing on the certification is false, and the file is still wrong. It will not survive the first serious question about who made a decision.

The risk profile has to be written at onboarding or it does not exist. Risk assessments reconstructed after something goes wrong are worth very little, and everyone reading the file can tell when that happened. A profile written at acceptance — what the customer does, what activity is expected, what would be out of pattern — is what lets you explain two years later why accepting this customer was reasonable then.

Refresh cycles fail silently. Nobody notices a refresh that did not happen. There is no alert and no missed deadline, only a file that ages until an ownership change or a new director makes it materially false. Since February 2026 that risk has grown, because relief from verifying at every new account opening removes the routine event many institutions relied on as their de facto refresh. The relief rewards programs that were genuinely risk-based and exposes those that were not.

There is no federal registry to check ownership against. This is the most commercially useful fact in the subject and the one generic content still gets wrong. Following the final rule FinCEN issued on 11 August 2026, U.S. companies and U.S. persons are permanently exempt from beneficial ownership reporting under the Corporate Transparency Act, and FinCEN is directed to delete information it reasonably believes relates to U.S. persons. Foreign reporting companies still report their foreign individual beneficial owners. The database was never public and will not contain U.S. persons at all, so «we will confirm it against FinCEN» is not a plan. Ownership of a U.S. company has to be established from state records, corporate documents and direct verification.

The most common mistakes and what they cost

The failures we are called in to fix are not exotic. They repeat, and each has a predictable price.

  • Treating collection as verification. The file is full and nothing has been tested. Cost: a deal signed on unverified information, with no answer when the real owner surfaces.
  • Screening only the entity. The company is clean, its owners are not, and the 50 Percent Rule blocks it anyway. Cost: a frozen payment and an exposure good faith does not cure.
  • Confusing an incorporation certificate with proof of control. State filings show formation and registered agent, rarely ownership. Cost: weeks of back-and-forth with a bank asking for something the company has not understood it must build.
  • Escalating nothing. Layered ownership, nominees and unexplained source of funds get the same treatment as a domestic customer with two shareholders. Cost: checks that resolve nothing, exactly where standard checks are not enough.
  • Stalling onboarding over one document. Cost: revenue delayed and the same work paid for twice.

The most expensive version combines two of these: a company signs, ships or lends against a file nobody verified, the counterparty turns out to be controlled by someone it would never have accepted, and remediation happens under pressure. Regulatory findings, blocked funds and unwound transactions all begin as a file nobody tested in time.

How Compliance Officers resolves it for you

Our clients do not chase Secretaries of State, request certified copies, decode ownership chains or argue with a bank about which document proves control. We run the verification end to end and deliver a file that answers the question actually being asked: who is this counterparty, who controls it, what does the record support, and what remains unresolved.

That means three things. Zero paperwork for you: we identify what has to be obtained, obtain it at source, and handle the requests and records. Zero errors: the ownership and control positions we report are reconciled against corporate documents and official records rather than accepted from a certification form, and where they cannot be reconciled we say so instead of filling the gap with an assumption. Zero unnecessary delays: we know which offices are slow and where a request will be refused before it is filed.

We work across both worlds: institutions that need customer files able to withstand examination, and operating companies facing a bank’s onboarding demands or a counterparty they have reason to question. Coverage is national, and the deliverable is written for whoever will have to defend the decision later. Contact us to evaluate your case.

Frequently Asked Questions

Is customer due diligence required by law for my business?

Only if you are a covered financial institution: a bank, broker-dealer, mutual fund, futures commission merchant or introducing broker. The CDD Rule does not bind ordinary operating businesses. Sanctions compliance is different — OFAC applies to every U.S. business on a strict-liability basis — and banks and counterparties impose demands that function like obligations. We assess which of these bind you.

Properly done, it proves the counterparty exists as claimed, that ownership and control were established against independent records rather than asserted, and that you documented your view of the risk before committing. It does not predict behaviour. It proves the decision was defensible on the information reasonably available — the standard a regulator, a court or an acquirer applies. We build files to it.

Yes. The February 2026 relief removed the requirement to verify beneficial owners at every new account opening by an existing legal entity customer. It did not touch the 25 percent threshold, the control prong or the obligation itself, and confirmation that prior information remains current must still be documented. The Corporate Transparency Act rollback removed reporting duties for U.S. companies, not verification duties. We keep clients aligned with both.

A domestic entity with straightforward ownership and a cooperative counterparty is usually a matter of days. Multi-layered structures, foreign entities, trusts, nominee arrangements or slow certified-copy processing take longer, and a counterparty that resists ownership questions is itself a finding. We give a realistic timeline once we see the structure, and say early when a file will not close quickly.

In almost all cases, yes. Records are requested from state offices, courts and registries, corporate documents are reviewed digitally, and confirmations are obtained and documented without anyone travelling. Certified originals occasionally have to move physically, and some jurisdictions still process on paper. We manage the requests, the certifications and the delivery from our side, so your involvement stays minimal.

It depends on the structure: how many entities and jurisdictions are involved, whether ownership is layered or foreign, whether certified records are needed, and how deep the risk analysis has to go. Government and state fees we pass through as charged. Contact us to evaluate your case and we will scope it precisely before you commit.

Need to know exactly what you are required to verify about a customer or counterparty?
Compliance Officers runs the verification end to end: zero paperwork for you, zero errors, zero unnecessary delays.
Phone and WhatsApp: +1 305 647 3000

Related News

Compliance Officers

Consulta sin ningún costo!

Request information with no commitment

QR-Compliance Officers

Do you want to talk with us?

Últimas publicaciones