CDD (Customer Due Diligence)

Definition

Customer due diligence (CDD) is the process AML-regulated firms use to identify a customer, verify their identity, identify beneficial owners, understand the purpose of the relationship and monitor it on an ongoing basis. Under the EU AMLR, CDD applies to occasional transactions of €10,000 or more, with limited CDD on occasional cash transactions from €3,000.

What is customer due diligence?

Customer due diligence is the backbone of AML compliance: before taking on a client (and periodically afterwards), a firm must identify the customer and verify their identity from reliable, independent sources; identify any beneficial owners and take reasonable measures to verify them; understand the purpose and intended nature of the business relationship; and keep monitoring the relationship and its transactions so activity stays consistent with what the firm knows about the client.

Irish designated persons apply CDD today under the Criminal Justice Act 2010. From 10 July 2027, the directly applicable AMLR harmonises the rules EU-wide.

When is CDD triggered?

CDD always applies when establishing a business relationship. For one-off dealings, the AMLR tightens the thresholds Irish firms are used to:

  • Occasional transactions of €10,000 or more (single or linked) — down from €15,000;
  • Occasional cash transactions of €3,000 or more — limited CDD applies;
  • Crypto-asset service providers — CDD from €1,000, aligned with MiCA;
  • Whenever money laundering or terrorist financing is suspected, or previous identification data is in doubt — regardless of amount.

Depending on risk, firms apply simplified, standard or enhanced due diligence; the level must be justified by the client's risk rating under the firm's business-wide risk assessment.

What changes under the AMLR?

Beyond the lower thresholds, the AMLR standardises what a CDD file must contain, harmonises the 25% beneficial-ownership test, and explicitly recognises eIDAS-aligned electronic identification — including the forthcoming EU Digital Identity Wallet — as a means of verifying identity. AMLA technical standards will pin down the operational detail, and records must be retained for five years and then deleted.

How should Irish firms prepare?

Review where your current CDD triggers, evidence standards and refresh cycles fall short of the AMLR, and make sure ongoing monitoring is actually happening, not just documented. CompliDesk runs digital CDD with electronic identity verification and audit-ready records — book a demo to see the workflow.

General information, not legal advice. This definition provides general information about EU and Irish anti-money-laundering requirements. Regulatory detail is still evolving through 2026–27 — verify against primary sources (EUR-Lex, AMLA, and your sector’s Irish supervisor) and seek qualified advice before acting.

Get AMLR-ready before 10 July 2027

CompliDesk turns these obligations into simple workflows for Irish designated persons.