Guide · Customer due diligence

What belongs in a CDD file: a checklist for Irish firms

When a supervisor opens one of your client files, seven things should be there. This checklist sets out each one, what “evidence” actually means, and how to audit your own files before someone else does.

In brief

A complete CDD file for an Irish firm contains seven things: verified identity evidence, beneficial-ownership evidence including the RBO extract obtained before the relationship began, a stored screening record, a reasoned risk rating, any EDD triggers and the enhanced measures taken, review dates showing ongoing monitoring, and a retention record supporting the AMLR’s five-year retain-then-delete rule.

The checklist

What are the seven things every CDD file needs?

The test for each item is the same: could a stranger open the file and see not just that a check happened, but what it found and what you decided?

1

Identity evidence

Who the client is, verified from reliable sources: passport or other identity documents, or eIDAS-aligned electronic identification, which the AMLR explicitly recognises for identity verification. For companies, the incorporation details — pulled from the CRO rather than retyped. Record what was checked, when, and by whom.

2

Beneficial-ownership evidence, including the RBO extract

Who ultimately owns or controls the client, applying the AMLR’s harmonised 25%-or-more ownership test. For a new corporate client this means the client’s own account of its beneficial owners plus the RBO extract you must obtain before entering the business relationship (a flat €2.50 per extract), the comparison between the two, and your discrepancy decision — including any report to the Registrar.

3

Screening record

Evidence that the client and beneficial owners were screened against the EU consolidated financial sanctions list, UN lists and PEP data — at onboarding and on an ongoing basis. Keep the result, the date, and how any potential match was resolved. “We screened” without a stored result is not evidence.

4

Risk rating and rationale

The client’s risk rating and, crucially, why. A number with no reasoning will not survive an inspection. The rating should trace to your Business-Wide Risk Assessment and drive the level of due diligence applied.

5

EDD triggers and enhanced measures

Where enhanced due diligence applies — for example a politically exposed person, or a high-net-worth relationship — record the trigger and the extra measures taken. The AMLR’s high-net-worth test is cumulative: it applies where you handle assets of €5 million or more for a client whose total wealth is €50 million or more.

6

Review dates and ongoing monitoring

When the file was last reviewed, when it is next due, and what changed. CDD is not a one-off event: the file should show the relationship being monitored at a frequency matching its risk rating.

7

Retention and deletion record

The AMLR requires records to be retained for five years — and then deleted. Your file structure should record when the relationship ended, when the five years expire, and how deletion will happen. Indefinite retention is itself a compliance failure under the new framework.

Thresholds worth knowing

Which AMLR thresholds shape the file?

CDD at €10,000 — cash at €3,000

CDD for occasional transactions applies from €10,000, down from €15,000 today. Occasional cash transactions of €3,000 or more trigger limited CDD, so even a one-off cash customer can need a file.

Beneficial ownership at 25%

The harmonised test is ownership or control of 25% or more, direct or indirect. Following a review due by 2029, the Commission may set a lower threshold of 15% or lower for high-risk sectors by delegated act — build files so the threshold is a setting, not a rebuild.

High-net-worth EDD: €5m and €50m

The test is cumulative: enhanced due diligence applies where you handle assets of €5 million or more for a client whose total wealth is €50 million or more. AMLA guidance on the €50 million test is due by 10 July 2027.

Self-audit

How do you audit your existing files?

1

Pick ten live client files at random

Not your best ten. A supervisor will not choose your best ten either.

2

Score each against the seven items above

Present, partial or missing. Be honest about “partial” — an unsigned checklist is not a screening record.

3

Fix the systemic gaps first

If nine files lack an RBO extract, the fix is a workflow, not nine uploads. Change how files are built, then remediate.

4

Set review dates for every file

A file with no next-review date will drift. Risk-rate the book and diarise reviews accordingly.

CompliDesk builds files this way by default: structured onboarding with KYC and KYB verification, a guided RBO extract workflow, stored screening results, risk ratings with rationale, diarised reviews and a retention clock on every record. Related guides: the €10,000 cash cap and STR dual reporting.

Inspection-ready files

Every file complete, every time

See how CompliDesk assembles all seven items into every client file automatically — or join the waitlist for free early access.