CDD (Customer Due Diligence)

Ayrıca şöyle anılır Customer Due Diligence, due diligence, DD

Bir araya getirildiİnşa edilmedi

Customer Due Diligence is the regulatory obligation a bank, payment provider, exchange, or other regulated business runs to know who it's dealing with and stay comfortable with that relationship for as long as it lasts. It has four parts, done in sequence and then repeated: identify the customer (collect who they claim to be), verify that identity against reliable, independent evidence, understand the purpose and intended nature of the relationship (why is this person opening this account, what will they use it for), and monitor the relationship on an ongoing basis to confirm what actually happens matches what was expected at onboarding. A one-time identity check that's never revisited isn't CDD: the ongoing-monitoring leg is what makes it a program rather than a gate.

Regulation doesn't apply the same depth of check to every customer. FATF's risk-based approach calls for three tiers: Simplified Due Diligence for genuinely low-risk relationships (a low-value, restricted-purpose account, say), standard CDD as the baseline for everyone else, and Enhanced Due Diligence (see EDD) for relationships a risk assessment flags as higher-risk, a Politically Exposed Person, a high-risk jurisdiction, an unusually large or opaque transaction. Applying the same fixed check to every customer regardless of risk is itself a compliance failure under this framework, not a safe default.

One source of everyday confusion worth naming plainly: "KYC" is often used, informally, as a synonym for CDD, but the term this Lexicon defines separately under KYC is narrower in practice: the identification-and-verification step specifically. CDD is the fuller obligation that step sits inside, alongside the purpose-of-relationship and ongoing-monitoring pieces. The two terms blur in casual usage because FATF's own Recommendation 10 is literally titled "Customer due diligence" and describes what most people mean when they say KYC, but a compliance program that only ever does the identification step and never revisits it has not actually done CDD.

Who actually built this

FATF Recommendation 10 and its interpretive note are the reference text nearly every country's CDD rule traces back to. The EU's Anti-Money Laundering Directive series (and the newer, directly-applicable AMLR) is the regional implementation; Türkiye's MASAK runs its own customer-identification and risk-based-approach regulation covering the same ground for TR-regulated entities. None of this is a Solidus design, it's decades of AML policy Solidus builds against.

Solidus today

Solidus has not built a CDD program. Solidus Verify performs the identification-and- verification leg, document authenticity, liveness, face match, which is a real input to CDD but not CDD itself. The risk-rating, purpose-of-relationship, and ongoing-monitoring pieces don't exist in any Solidus product, and there's no committed date to build them; this tracks the same deliberate sequencing already documented under AML.

See also

KYC and IDV are the identification-and-verification input CDD needs. EDD is the escalated tier CDD steps up to for higher-risk relationships. PEP and UBO are two of the specific risk factors a CDD risk assessment has to catch. AML is the umbrella compliance program CDD sits inside.

Nereden geliyor

Bunu başkası belirtti. Solidus bir araya getiriyor.

CDD is the core obligation of FATF's Recommendation 10, "Customer due diligence", identify the customer, verify that identity, understand the purpose and intended nature of the relationship, and monitor it on an ongoing basis. The EU codifies the same obligation through its Anti-Money Laundering Directives (AMLD) and the newer AMLR; Türkiye's equivalent runs through MASAK's own customer-identification and risk-based-approach rules. The three-tier model, Simplified DD, standard CDD, Enhanced DD, is FATF's own tiering by risk, not something Solidus designed.

Bunu nasıl doğrularsınız

Solidus bunu inşa etmedi. Girdi kavramı açıklıyor.

verify.solidus.network is live and performs the identification leg (see KYC's proof for the exact check). No risk-rating engine, purpose-of-relationship workflow, or ongoing-monitoring dashboard exists to link to, none is invented here.

İlgili

CDD (Customer Due Diligence) · Solidus Lexicon