← All postsHow-to

Client due diligence: what to collect and what to keep

Client due diligence means knowing who you are dealing with, and being able to prove it later. The failures are almost always in the records, not in the judgement.

How-toC

Client due diligence — also called customer due diligence, or CDD — is the set of checks a regulated business performs to establish who its client is, who ultimately owns and controls them, and whether the relationship carries a money-laundering or sanctions risk. It applies well beyond banking: accountants, lawyers, estate agents, company formation agents, insolvency practitioners and others carry the obligation in most jurisdictions.

Firms rarely fail because they made a bad judgement about a client. They fail because they made a reasonable judgement and kept nothing that shows it: an identity document that expired and was never refreshed, a beneficial-owner check nobody wrote down, a risk rating that exists only in someone’s head.

What client due diligence collects

  • Identity of the client: for an individual, name and date of birth verified against a reliable document; for an entity, legal name, registered number, address and legal form.
  • Beneficial ownership: the individuals who ultimately own or control the entity, above the threshold your regime sets, verified rather than merely stated by the client.
  • The ownership and control structure where it is layered, so the chain from the client to the individuals is documented.
  • The purpose and intended nature of the relationship — why this client wants this service.
  • Source of funds, and for higher-risk relationships source of wealth, which is a different and harder question.
  • Screening against sanctions lists and, where applicable, politically exposed person status.
  • A documented risk rating, with the reasons for it.
  • The date of each check, who performed it and what evidence was relied on.

Risk-based means proportionate, not optional

A risk-based approach lets you apply simplified measures to demonstrably low-risk relationships and requires enhanced measures for higher-risk ones — unusual structures, high-risk jurisdictions, politically exposed persons, or a client you have never met. What it never permits is skipping the assessment. The record has to show that a risk decision was taken and on what basis, because an auditor reviewing a file cannot distinguish a considered low rating from an absent one unless you wrote the reason down.

Due diligence is not an event at onboarding. Relationships have to be monitored and the information refreshed on a cycle set by risk, and the trigger everyone misses is a change in ownership at an existing client — the entity is the same, the people behind it are not.

The file is the deliverable

What a supervisor examines is a file per client: identity evidence, the ownership chain, the screening results with dates, the risk rating and its reasoning, the review dates and anything escalated. Ettex Records holds that file with the documents attached and the review dates visible, Ettex Forms collects the onboarding information once rather than through an email thread, and the engagement letter and correspondence sit alongside it in Ettex Docs.

To be direct: this is record keeping, not a compliance product. There is no sanctions screening, no identity verification service, no PEP database and no regulatory sign-off. Those are separate, specialised and worth paying for. What obligations apply to you comes from your regulator and your jurisdiction, and the thresholds change.

Frequently asked

What is client due diligence?

The checks a regulated business performs to identify a client, verify who ultimately owns and controls them, understand the purpose of the relationship and assess money-laundering risk.

What is the difference between CDD and KYC?

Largely vocabulary. Know your customer usually refers to the identification and verification step; client due diligence covers that plus beneficial ownership, purpose, risk assessment and ongoing monitoring.

When is enhanced due diligence required?

For higher-risk relationships — politically exposed persons, high-risk jurisdictions, unusual or opaque structures, and non-face-to-face onboarding where your regime specifies it.

How long must due diligence records be kept?

Typically five years after the relationship ends, but the period is set by your jurisdiction and is worth confirming rather than assuming.

EP
Written by Elena P.

Part of the Ettex team — writing about product, engineering and the future of work.

More posts
Get the best of the Ettex blogProduct news, guides and tips — straight to your inbox, no spam.