The Customer Due Diligence Rule, known as the CDD Rule, is a federal regulation from the Financial Crimes Enforcement Network (FinCEN) that requires certain financial institutions to verify who their customers are, identify the real people behind business accounts, build a risk profile for each customer, and monitor activity over time. Issued under the Bank Secrecy Act, it took effect on May 11, 2018. In practical terms, every time you open a bank account, a brokerage account, or a similar financial relationship, the institution is legally required to collect your information, size up the relationship, and keep watching.
The Four Core Requirements
Every covered institution must maintain written policies and procedures built around four obligations:
- Confirm the identity of every individual or entity opening an account.
- Identify and verify the natural persons who own or control any legal entity opening an account.
- Understand the nature and purpose of the customer relationship well enough to build a risk profile.
- Conduct ongoing monitoring to detect suspicious activity and keep customer information current on a risk basis.
The pieces work together. The first two gather identity data. The third turns that data into a prediction of what normal activity looks like for that customer. The fourth compares real transactions against the prediction as they happen. Miss any one of them and the framework fails.
For an individual customer, identification means collecting name, date of birth, address, and an identification number, typically a Social Security Number for U.S. persons or a passport number and country of issuance for foreign nationals. The institution then verifies that information, using a government-issued photo ID, checks against public databases or credit reporting agencies, or a combination of both. The depth of verification scales with the perceived risk of the relationship.
Identifying the Humans Behind a Legal Entity
When a business opens an account, the institution cannot simply accept the company name. The CDD Rule requires identifying the actual people who own or control the entity, through two prongs.
Ownership Prong
The institution must identify every individual who directly or indirectly owns 25 percent or more of the entity’s equity interests. That 25 percent figure is a regulatory ceiling on the threshold; institutions may set a lower one based on their own risk assessment, but they cannot go higher. If ownership runs through layers of intermediary entities, the chain gets traced until it reaches a natural person meeting the threshold. If a trust holds a qualifying stake, the trustee is identified as the beneficial owner for that interest.1eCFR. 31 CFR 1010.230 – Beneficial Ownership Requirements for Legal Entity Customers
Control Prong
Regardless of ownership, the institution must also identify one individual with significant responsibility to manage or direct the entity. The regulation points to roles like CEO, CFO, COO, managing member, general partner, president, vice president, treasurer, or anyone regularly performing similar functions.1eCFR. 31 CFR 1010.230 – Beneficial Ownership Requirements for Legal Entity Customers This person must be identified even if they hold no ownership interest at all.
A legal entity will have between one and five beneficial owners under the rule: always one under the control prong, plus up to four under the ownership prong, since at most four people can each hold 25 percent or more. The institution collects the same identifying information for each beneficial owner as it would for an individual customer. The person opening the account must certify that the beneficial ownership information is complete and accurate.2FinCEN.gov. Information on Complying with the Customer Due Diligence (CDD) Final Rule Each beneficial owner’s identity is then verified using the same methods applied to individual customers. The goal is to prevent criminals from hiding behind shell companies to move illicit money.
Which Financial Institutions Have to Comply
The CDD Rule applies to a specific set of “covered financial institutions”:
- Banks and credit unions.
- Broker-dealers registered with the SEC under the Securities Exchange Act.
- Mutual funds registered under the Investment Company Act.
- Futures commission merchants and introducing brokers in commodities registered under the Commodity Exchange Act.
These are the institutions FinCEN named when it finalized the rule.2FinCEN.gov. Information on Complying with the Customer Due Diligence (CDD) Final Rule The broader Bank Secrecy Act definition of “financial institution” reaches further, covering money services businesses, casinos, insurance companies, and others,3FFIEC BSA/AML InfoBase. Appendix D – Statutory Definition of Financial Institution but the CDD Rule’s beneficial ownership requirements apply only to the narrower group above. Other BSA-covered entities have their own anti-money laundering obligations without being subject to the CDD Rule’s four-pillar framework.
Each covered institution must maintain a written CDD program with internal controls and staff training, integrated into its broader anti-money laundering compliance. Falling short can trigger civil money penalties; for violations tied to due diligence obligations, fines can reach up to $1 million or twice the transaction amount.4Internal Revenue Service. 4.26.7 Bank Secrecy Act Penalties
Legal Entities Exempt From Beneficial Ownership Rules
Not every business account triggers the beneficial ownership analysis. The regulation exempts categories of entities already subject to robust regulatory oversight, including:
- Publicly traded companies with securities registered under the Securities Exchange Act.
- Banks, credit unions, broker-dealers, and other regulated financial institutions.
- Investment companies and advisers registered with the SEC.
- CFTC-registered entities such as commodity pool operators and swap dealers.
- Bank and savings holding companies.
- State-regulated insurance companies.
- Public accounting firms registered under the Sarbanes-Oxley Act.
- Certain foreign financial institutions in jurisdictions where the regulator already maintains beneficial ownership information.
- Non-U.S. government departments and agencies engaged only in governmental activities.
A pooled investment vehicle operated by an exempt financial institution also qualifies.1eCFR. 31 CFR 1010.230 – Beneficial Ownership Requirements for Legal Entity Customers If your entity falls into one of these buckets, the institution still runs standard customer identification but skips the beneficial ownership certification.
Enhanced Due Diligence for Higher-Risk Customers
Standard CDD sets the baseline. Some customers present elevated risk and warrant Enhanced Due Diligence: more extensive information, more rigorous oversight. Common triggers include complex international wire transfers involving jurisdictions with weak anti-money laundering controls, unusual transaction patterns, and connections to high-corruption industries or regions. Typical EDD steps include investigating the source of the customer’s wealth, verifying where specific funds originated, and requiring senior management approval to open or maintain the account.
One area worth clearing up: there is no BSA regulation requiring banks to screen for or identify politically exposed persons.5FFIEC BSA/AML InfoBase. Politically Exposed Persons Most large institutions do flag these individuals and apply EDD voluntarily as part of a risk-based program, but it is not a legal requirement of the CDD Rule.
Ongoing Monitoring and Suspicious Activity Reports
CDD does not stop at account opening. The fourth pillar demands continuous monitoring of transactions against the risk profile built during onboarding. If a customer whose profile suggests modest domestic activity starts receiving large international wires from high-risk regions, the institution has to investigate.
When a transaction looks suspicious, the institution files a Suspicious Activity Report with FinCEN. Banks must file a SAR for any transaction involving $5,000 or more where the bank knows, suspects, or has reason to suspect the transaction involves illegal activity, is designed to evade BSA requirements, or has no apparent lawful purpose the bank can identify after examining the facts.6GovInfo. 31 CFR 1020.320 – Reports by Banks of Suspicious Transactions For criminal violations involving insider abuse, there is no dollar threshold.
A bank must file a SAR within 30 calendar days of first detecting facts that suggest a reportable situation. If no suspect has been identified by then, the bank gets another 30 days to try, but filing cannot be delayed beyond 60 days after initial detection.6GovInfo. 31 CFR 1020.320 – Reports by Banks of Suspicious Transactions Urgent situations, like an active money laundering scheme, also require an immediate phone call to law enforcement.
When Beneficial Ownership Information Gets Updated
A covered institution does not need to re-collect and re-verify beneficial ownership every time an existing legal entity customer opens another account. Under current FinCEN guidance, beneficial ownership identification is required in three situations:
- When a legal entity customer first opens an account.
- When the institution learns facts that would reasonably call the accuracy of previously collected information into question.
- As needed under the institution’s own risk-based monitoring procedures, such as when unusual activity, negative media coverage, or known ownership changes appear.
For risk-based triggers, the institution can rely on existing records if the customer certifies, verbally or in writing, that the information remains accurate, and the institution documents that certification. If the customer cannot confirm or the institution has reason to doubt the information, full re-identification and re-verification are required.
Recordkeeping
The BSA requires institutions to retain most CDD records, including customer identity documentation and beneficial ownership certifications, for at least five years after the account is closed.7FFIEC BSA/AML InfoBase. Appendix P – BSA Record Retention Requirements This covers deposit accounts, loans, and trust relationships alike. The retention clock starts when the relationship ends, so an account open for decades means records are held for the full life of the account plus five more years. SAR filings and supporting documentation follow the same five-year retention rule and must stay accessible for examination by regulators and law enforcement throughout that period.
How the CDD Rule Relates to the Corporate Transparency Act
The Corporate Transparency Act, enacted in 2021, created a separate beneficial ownership reporting framework running alongside the CDD Rule. Under the CTA, certain companies were to report beneficial ownership information directly to FinCEN, which would maintain a central database for financial institutions and law enforcement to cross-reference.
The CTA’s path has been rocky. Multiple federal court challenges produced conflicting rulings and nationwide injunctions. In March 2025, FinCEN published an interim final rule that effectively exempted all U.S.-formed entities from CTA reporting. As of that rule, only entities formed under foreign law and registered to do business in a U.S. state or tribal jurisdiction must file beneficial ownership reports with FinCEN.8FinCEN.gov. Beneficial Ownership Information Reporting
For covered financial institutions, the practical impact is layered. FinCEN has authorized institutions to access the beneficial ownership database to support CDD compliance, provided they have the customer’s consent.9FinCEN.gov. Beneficial Ownership Information Access and Safeguards Final Rule Institutions are not required to use it, and there is no supervisory expectation that they do. The CDD Rule’s beneficial ownership requirements remain independently in force. Institutions must continue collecting and verifying beneficial ownership information through their own procedures whether or not they consult the FinCEN database. A future rulemaking is expected to align the CDD Rule more closely with the CTA framework, but as of 2026 the two systems run in parallel.