Fifth Pillar of BSA Compliance: Customer Due Diligence Rule

The fifth pillar of BSA compliance is customer due diligence, added to Bank Secrecy Act regulations by FinCEN’s 2016 Final Rule and enforceable since May 11, 2018.1Federal Register. Customer Due Diligence Requirements for Financial Institutions It sits alongside four older obligations and requires financial institutions to identify the real people behind their legal entity customers, understand what each customer relationship is supposed to look like, monitor activity against that baseline, and keep the underlying information current.

The Four Original Pillars

Federal law has long required every financial institution to maintain an anti-money laundering program with four components. Under 31 U.S.C. ยง 5318(h), those are internal policies and controls designed to ensure compliance, a designated compliance officer for day-to-day oversight, an ongoing employee training program, and an independent audit function that tests whether the program actually works.2Office of the Law Revision Counsel. 31 USC 5318 – Compliance, Exemptions, and Summons Authority

Customer due diligence was folded into that framework as a fifth, coequal obligation. Industry calls it the fifth pillar; FinCEN itself describes it as a set of four core requirements built into existing programs.3FinCEN. Information on Complying with the Customer Due Diligence Final Rule

What Customer Due Diligence Requires

The CDD rule has four working parts:

  • Identifying and verifying the beneficial owners of legal entity customers.
  • Understanding the nature and purpose of each customer relationship so the institution can build a risk profile.
  • Conducting ongoing monitoring to detect and report suspicious transactions.
  • Maintaining and updating customer information on a risk basis.

Each of these has to be reflected in the institution’s written program and available for examination.3FinCEN. Information on Complying with the Customer Due Diligence Final Rule

Identifying Beneficial Owners

The most concrete new obligation is beneficial ownership. When a corporation, LLC, partnership, or other legal entity opens an account, the institution must identify the real people behind it using two prongs.

The ownership prong reaches every individual who directly or indirectly holds 25 percent or more of the entity’s equity interests. The control prong reaches at least one individual with significant management responsibility, such as a CEO, president, or managing member.4eCFR. 31 CFR 1010.230 – Beneficial Ownership Requirements for Legal Entity Customers An entity may have no one at the 25 percent threshold, but it will always have someone under the control prong. Both prongs apply independently, so a single account opening can produce several named individuals.

The person opening the account certifies the accuracy of the information, either on the standard form in Appendix A of the regulation or through another method that includes a certification. The bank then verifies each identified beneficial owner using the same standards it applies to individual customers. If the entity refuses to provide the information, the bank can decline to open the account or terminate the relationship.4eCFR. 31 CFR 1010.230 – Beneficial Ownership Requirements for Legal Entity Customers

February 2026 Exceptive Relief

In February 2026, FinCEN issued an order granting exceptive relief from the requirement to identify and verify beneficial owners at each new account opening. Covered institutions are no longer required to repeat the full beneficial ownership process every time an existing legal entity customer opens an additional account. FinCEN is updating its CDD Rule FAQs to reflect the change, and institutions should consult the order directly for current guidance.3FinCEN. Information on Complying with the Customer Due Diligence Final Rule

Entities Exempt From the Beneficial Ownership Rule

Not every legal entity triggers beneficial ownership collection. Exempt categories include U.S. federal, state, and local government bodies; issuers of securities registered under Section 12 of the Securities Exchange Act and their majority-owned subsidiaries; banks, credit unions, and broker-dealers regulated by federal functional regulators or state banking regulators; SEC-registered investment companies, investment advisers, exchanges, and clearing agencies, along with CFTC-registered commodity entities; state-regulated insurance companies; bank and savings holding companies; pooled investment vehicles operated or advised by an otherwise-exempt financial institution; and public accounting firms registered under Section 102 of the Sarbanes-Oxley Act.4eCFR. 31 CFR 1010.230 – Beneficial Ownership Requirements for Legal Entity Customers Trusts are excluded from the definition of “legal entity customer” unless they are statutory trusts created by filing with a secretary of state.5FFIEC BSA/AML InfoBase. Appendix 1 – Beneficial Ownership

Building the Customer Risk Profile

Identification is only the starting point. The institution also needs to understand what the relationship is supposed to look like: expected transaction types, anticipated volumes, source of funds, and the geographic footprint of the customer’s activity. A local restaurant depositing cash receipts a few times a week reads very differently from an import-export company wiring funds across borders. The profile built from this information sets the baseline against which future activity is measured and determines how much scrutiny the account gets going forward.

Some customers warrant enhanced due diligence from the start. That can include verifying source of wealth, reviewing financial statements, and taking a closer look at expected transaction volumes and trade areas.6FFIEC BSA/AML InfoBase. Assessing Compliance with BSA Regulatory Requirements – Customer Due Diligence Foreign correspondent accounts, payable-through accounts, and private banking accounts carry their own specific enhanced due diligence rules. Politically exposed persons are not singled out by BSA regulation and banks are not barred from serving them, but the potential for corruption proceeds makes them a common focus for risk-based scrutiny.7FFIEC BSA/AML InfoBase. Politically Exposed Persons

Ongoing Monitoring and Updating Information

Customer due diligence is not a one-time check at account opening. Monitoring systems compare actual account activity against the customer’s risk profile to catch anomalies, and unusual patterns feed into the institution’s suspicious activity reporting.

The duty to update customer information is risk-based, not calendar-based. For accounts opened before the May 2018 compliance date, there is no obligation to go back and retroactively collect beneficial ownership information. The obligation to update kicks in when the institution becomes aware of information relevant to reassessing the customer’s risk, rather than during routine periodic reviews absent risk-based concerns.8FinCEN. CDD Rule FAQs Triggers include a change in the entity’s ownership structure, a shift in business operations, or unusual transaction patterns.

Record Retention

Identifying information collected for beneficial ownership must be retained for at least five years after the account is closed. Verification records, including descriptions of documents reviewed, non-documentary methods used, and the resolution of any discrepancies, must be kept for five years after the record is made.9FFIEC BSA/AML InfoBase. Beneficial Ownership Requirements for Legal Entity Customers These periods can be extended in the context of law enforcement investigations.

Penalties for Getting It Wrong

Failures under BSA, including CDD failures, expose institutions and individuals to two tracks of penalties. Willful violations carry criminal fines of up to $250,000 and imprisonment of up to five years. When the violation occurs as part of a pattern of illegal activity involving more than $100,000 in a 12-month period, those maximums rise to $500,000 and ten years, and courts can order forfeiture of profits and repayment of bonuses received during the year of the violation.10Office of the Law Revision Counsel. 31 USC 5322 – Criminal Penalties

Civil penalties run on a separate track and can be imposed even alongside criminal charges. Willful violations cap at the greater of the transaction amount (up to $100,000) or $25,000 per violation. Negligent violations carry a $500-per-violation ceiling, rising to $50,000 for a pattern of negligent activity. Repeat violators face additional penalties of up to three times the profit gained or twice the maximum, whichever is greater.11Office of the Law Revision Counsel. 31 USC 5321 – Civil Penalties Enforcement actions against large institutions have produced totals well above these per-violation figures because regulators aggregate violations across thousands of accounts.

How the CDD Rule Differs From the Corporate Transparency Act

The CDD rule requires banks to collect beneficial ownership information for their own compliance files. The Corporate Transparency Act, enacted in 2021, is a separate obligation for companies themselves to report beneficial ownership directly to FinCEN’s national database. They are parallel systems with different rules, definitions, and exemptions.

As of March 2025, FinCEN narrowed CTA reporting sharply. All entities created in the United States, along with their U.S. beneficial owners, are exempt from CTA reporting. Only foreign entities registered to do business in a U.S. state or tribal jurisdiction remain subject to reporting, and even they are not required to report U.S. persons as beneficial owners.12FinCEN. Beneficial Ownership Information Reporting

Those CTA changes do not affect the CDD rule. Banks are still required to identify and verify beneficial owners of legal entity customers at account opening, whether or not that entity has any separate CTA filing obligation. The CDD rule operates at the institution level; the CTA operates at the entity level. FinCEN has indicated plans to align the two frameworks through future rulemaking, but as of 2026 they remain distinct obligations with different triggers, different ownership thresholds, and different enforcement mechanisms.