Customer due diligence is the set of obligations a covered institution carries out to know who its customer is, understand why the relationship exists, and keep watching it over time. Under FinCEN's CDD Rule it has four elements: a Customer Identification Program, beneficial ownership identification for legal-entity customers, a risk profile built on the nature and purpose of the relationship, and ongoing monitoring. Two of those are one-time verification tasks. Two never stop — and that asymmetry is where most lenders' documentation gets thin.
CDD Is a Program, Not an Onboarding Step
The most common misreading of customer due diligence is that it happens once, at account opening, and then the file is closed. That describes CIP, which is genuinely front-loaded. CDD is the wrapper around it.
The practical consequence is that a lender can be fully compliant at onboarding and still be exposed. If a borrower's beneficial ownership changes two years into a relationship and nothing on the record reflects that you noticed, the gap is not in your CIP — it is in element four. Examiners tend to find these gaps not by questioning your procedures but by pulling a sample of files and asking what happened between origination and today.
So what does this mean for your institution? The documentation burden is continuous, which means it has to be a byproduct of the workflow rather than a periodic clean-up project. A CDD program that depends on someone remembering to re-check is a program that will have holes in the sample the examiner picks.
CIP, CDD, and EDD — What Each One Actually Covers
These three get used interchangeably in conversation and they are not interchangeable in an examination.
CIP (31 C.F.R. § 1020.220) is the identity step: collect the required identifying information, verify it, keep records of how you verified, and check the customer against government lists where applicable. It is prescribed and reasonably mechanical.
CDD contains CIP and adds the parts that require judgment — beneficial ownership under 31 C.F.R. § 1010.230, the risk profile, and ongoing monitoring.
EDD is what you do on top of CDD when your own risk assessment places a customer in a higher-risk band. There is no schedule of mandatory EDD steps, which is precisely why it draws examiner attention: the standard you are held to is the standard you wrote for yourself.
For lenders, the sequencing question matters as much as the content. Verification that happens too late in the origination flow creates a different problem — one covered in KYC timing and FCRA compliance, where the permissible-purpose question interacts with when you pull data.
What a Customer Identification Program Must Collect and Verify
CIP is element one, and it is the part with the most prescriptive detail. Under 31 C.F.R. § 1020.220 a program has to be written, approved by the board or its delegate, and specify the procedures actually in use — not describe an intention.
At minimum, before or shortly after account opening, the program collects four items for each customer: name, date of birth for individuals, a physical address, and an identification number — a taxpayer identification number for U.S. persons, or one of the permitted alternatives for non-U.S. persons.
Collection is only half of it. The program then has to verify that information, and the rule allows two routes that most lenders use together:
Documentary verification — an unexpired government-issued identification for individuals, or formation documents such as articles of incorporation and partnership agreements for entities.
Non-documentary verification — comparing the information against independent sources. For lenders this is where credit bureau data earns its place: the file's address history, identity attributes, and name-and-SSN match results are independent corroboration, which is why the verification step and the credit pull tend to sit in the same part of the workflow.
Three requirements are easy to under-build. The program must include procedures for what happens when verification fails — not just the happy path. It must specify a records retention approach covering the identifying information and a description of how each item was verified. And it must include government-list screening against any list of known or suspected terrorists designated for CIP purposes.
The recurring examination finding here is not that institutions skip CIP — almost nobody does. It is that the written program describes procedures the operation has since drifted away from, or that the record shows an outcome without preserving how verification was achieved. Both are documentation gaps rather than control gaps, and both are avoidable if the verification artifact lands on the customer record automatically.
Beneficial Ownership: Two Prongs, and the Trap Between Them
The CDD Rule identifies beneficial owners of legal-entity customers through two tests applied together.
The ownership prong captures each individual who directly or indirectly holds 25 percent or more of the entity's equity. An entity may have as many as four such individuals, or none.
The control prong captures a single individual with significant responsibility to control or manage the entity — an executive officer, a managing member, someone in a comparable position.
The trap is treating these as alternatives. If no one clears the 25 percent threshold, the ownership prong yields nobody and the temptation is to record nothing. The control prong still applies. Every legal-entity customer has at least one beneficial owner on the record, and a file showing none is a file that will get questioned.
Layered ownership structures are the other recurring difficulty. "Indirectly" means you follow the chain through intermediate entities to the natural persons at the end of it, and the record needs to show that you did — not just the conclusion you reached.
Where CDD Documentation Breaks Down for Lenders
In practice the failures cluster in a few predictable places, and none of them are failures of intent:
The risk profile exists in someone's head. An underwriter understood exactly why the relationship made sense and why the transaction pattern was normal for this borrower. None of that reasoning is on the record, so at examination the profile looks like an unsupported rating.
Verification lives outside the system of record. Identity checks and watchlist screening are run in a separate portal, the results are read, the decision is made, and what lands in the CRM is an outcome without its evidence. The check happened; the audit trail did not.
Ongoing monitoring has no artifact. Someone reviews accounts. Nothing on the customer record distinguishes "reviewed and cleared" from "never looked at," and the two are indistinguishable in a file sample.
EDD is applied inconsistently. Higher-risk customers get more scrutiny, but which customers and how much varies by who handled them, because the written criteria are general and the application is discretionary.
Each of these is a records problem rather than a judgment problem. The institutions that hold up well under examination are usually not the ones making better risk calls — they are the ones whose risk calls leave a trace automatically.
A Working CDD Checklist
At onboarding, for every customer: identifying information collected and verified with the verification method recorded; watchlist and sanctions screening run with the result and timestamp retained; for legal entities, beneficial owners identified under both prongs, with the ownership chain documented where it is indirect; nature and purpose of the relationship recorded in enough detail to justify the risk rating; risk rating assigned against written criteria.
On an ongoing basis: monitoring calibrated to the risk rating rather than applied uniformly; trigger events defined in writing — ownership change, behaviour shift, adverse media, watchlist hit — with an escalation path for each; periodic review at a cadence tied to risk rating, leaving a dated artifact whether or not anything changed; EDD steps, where applied, evidenced on the record rather than implied by the rating.
The test to apply to your own program is narrow: pick a customer file at random and ask whether someone who has never spoken to the relationship owner could reconstruct what was checked, when, and why the rating is what it is.
Keeping the Record Where the Decision Happens
The structural reason CDD documentation drifts is that verification and decisioning usually live in different systems. Data is pulled in one place, the credit decision is made in another, and the compliance record is assembled from both afterwards — which is exactly when things go missing.
LASER Credit Access returns credit, identity, and watchlist results as structured Salesforce objects on the borrower record, so the evidence sits on the same record as the decision it informed. The built-in compliance workflow for lenders on Salesforce generates the FCRA audit trail, permissible-purpose documentation, and screening history as a byproduct of normal origination rather than as a separate reporting exercise. When an examiner asks what was checked and when, the answer is on the record instead of assembled from three systems under time pressure.
For the wider view of how customer due diligence sits inside the KYC obligations lenders are managing in 2026 — including where the regulatory direction is heading — see KYC for lenders: trends, challenges, and what 2026 demands. Note that FinCEN's AML/CFT modernization proposal would shift program expectations toward demonstrated effectiveness, which raises rather than lowers the value of a documentation trail you do not have to reconstruct.

