Customer due diligence obligations require an institution to identify its customer, verify that identity, understand the relationship, and monitor it over time.
Customer identification. Name, date of birth or formation, address and an identification number, verified through documentary or non-documentary means, with records retained.
Beneficial ownership. For legal entity customers, the institution must identify individuals owning a stated percentage of equity and one individual with significant management responsibility, and verify their identities. Certification at account opening is the mechanism; refreshing it on trigger events is the practice examiners look for.
Understanding nature and purpose produces the expected activity profile against which monitoring works. Without it, transaction monitoring has no baseline and generates noise.
Risk rating. Customers should be rated on documented criteria, with the rating driving the intensity of ongoing review. Enhanced due diligence applies to higher-risk categories including certain foreign entities, cash-intensive businesses, politically exposed persons and correspondent relationships.
Ongoing monitoring includes updating information when the institution learns of a change — a bank that receives a wire to a new jurisdiction and does not revisit the profile has the information and has not used it.
Beneficial ownership reporting regimes for companies themselves have shifted repeatedly; institutions should track the current requirements rather than rely on the position from a prior year.