ISO 22000: what certification asks for beyond HACCP
ISO 22000 wraps HACCP in a management standard — leadership, objectives, internal audit, improvement. Deciding whether you need it is mostly a question about your customers, not your kitchen.
Client due diligence means knowing who you are dealing with, and being able to prove it later. The failures are almost always in the records, not in the judgement.
Client due diligence — also called customer due diligence, or CDD — is the set of checks a regulated business performs to establish who its client is, who ultimately owns and controls them, and whether the relationship carries a money-laundering or sanctions risk. It applies well beyond banking: accountants, lawyers, estate agents, company formation agents, insolvency practitioners and others carry the obligation in most jurisdictions.
Firms rarely fail because they made a bad judgement about a client. They fail because they made a reasonable judgement and kept nothing that shows it: an identity document that expired and was never refreshed, a beneficial-owner check nobody wrote down, a risk rating that exists only in someone’s head.
A risk-based approach lets you apply simplified measures to demonstrably low-risk relationships and requires enhanced measures for higher-risk ones — unusual structures, high-risk jurisdictions, politically exposed persons, or a client you have never met. What it never permits is skipping the assessment. The record has to show that a risk decision was taken and on what basis, because an auditor reviewing a file cannot distinguish a considered low rating from an absent one unless you wrote the reason down.
Due diligence is not an event at onboarding. Relationships have to be monitored and the information refreshed on a cycle set by risk, and the trigger everyone misses is a change in ownership at an existing client — the entity is the same, the people behind it are not.
What a supervisor examines is a file per client: identity evidence, the ownership chain, the screening results with dates, the risk rating and its reasoning, the review dates and anything escalated. Ettex Records holds that file with the documents attached and the review dates visible, Ettex Forms collects the onboarding information once rather than through an email thread, and the engagement letter and correspondence sit alongside it in Ettex Docs.
To be direct: this is record keeping, not a compliance product. There is no sanctions screening, no identity verification service, no PEP database and no regulatory sign-off. Those are separate, specialised and worth paying for. What obligations apply to you comes from your regulator and your jurisdiction, and the thresholds change.
The checks a regulated business performs to identify a client, verify who ultimately owns and controls them, understand the purpose of the relationship and assess money-laundering risk.
Largely vocabulary. Know your customer usually refers to the identification and verification step; client due diligence covers that plus beneficial ownership, purpose, risk assessment and ongoing monitoring.
For higher-risk relationships — politically exposed persons, high-risk jurisdictions, unusual or opaque structures, and non-face-to-face onboarding where your regime specifies it.
Typically five years after the relationship ends, but the period is set by your jurisdiction and is worth confirming rather than assuming.
ISO 22000 wraps HACCP in a management standard — leadership, objectives, internal audit, improvement. Deciding whether you need it is mostly a question about your customers, not your kitchen.
A variation order changes the contract scope, and with it the price and the programme. The money is lost in the gap between the instruction being given and it being written down.
A bill of lading does three jobs at once — receipt, contract and title document. Which is why an error on one costs far more than a typo usually does.