CySEC AML · Chapter 6 · Topic 8 of 14

When can simplified due diligence be used?

The conditions for lighter CDD, what a firm may scale back, the factors that point to lower risk, and the cases that rule it out.

By the ExamPass CY editorial teamLast reviewed 5 min read

Short answer

Simplified due diligence (SDD) lets a firm apply lighter CDD once it has established that a relationship or transaction carries lower risk and there is no suspicion of money laundering or terrorist financing. It is not an exemption: every CDD measure still applies, but the firm may adjust how much it collects, when it verifies, which sources it accepts and how often it reviews. Monitoring must still catch unusual activity. Suspicion, doubts about the information obtained or any case that requires enhanced due diligence rule SDD out.

SDD at a glance

Before SDD can applyThe firm has established that the risk is lower, and there is no suspicion of money laundering or terrorist financing
What may changeHow much, when and in what form each CDD measure is applied, never whether it is carried out
TimingVerification can be completed during onboarding. EU guidance also mentions waiting until activity passes a set amount, but only where national law allows; Cyprus law requires verification before or during onboarding
EvidenceA single reliable and independent source may be enough to verify identity
Reviews and monitoringReviews can follow trigger events instead of a fixed cycle; monitoring can focus on transactions above a threshold
What never changesEnough monitoring to spot unusual transactions, and reporting of suspicions to MOKAS
SDD is ruled outSuspicion of money laundering or terrorist financing, doubts about whether information is true, or any case where enhanced due diligence is mandatory

Source: Law 188(I)/2007, Article 63 and Annex II; EBA ML/TF Risk Factors Guidelines.

What can a firm scale back under SDD?

SDD adjustments include the following. The firm can change the timing, for example completing verification during onboarding. EU guidance also lists waiting until account activity reaches a defined amount, but only where national law does not require verification at the outset, and in Cyprus Article 62 does. It can reduce the quantity of evidence, verifying identity from a single reliable, independent source. It can accept a different quality or source of evidence, such as verifying the beneficial owner's identity from information the customer supplies instead of an independent source, or, where the overall risk is very low, treating funds arriving from an account held in the customer's own name at a regulated EEA firm as meeting part of its CDD. And it can review the relationship less often, for instance only when the customer asks for a new product.

Transaction monitoring can be scaled too, for example by concentrating on payments above a set amount. What the firm may not do is drop any of the four CDD measures altogether.

Terms used in this note

Simplified due diligence (SDD)
A lighter application of the CDD measures, permitted only where lower risk has been established. It adjusts the measures; it does not remove them.
Trigger event
Something that prompts a CDD review outside the normal cycle, such as a customer asking for a new product or a transaction passing a set amount.
FATF Recommendations
The international standards against money laundering and terrorist financing issued by the Financial Action Task Force.

What still applies when SDD is used?

The information gathered must still be enough for the firm to be reasonably satisfied that its low-risk rating is justified, and to understand the relationship well enough to notice when something unusual happens. Monitoring continues, and suspicious transactions are still reported to MOKAS; SDD changes none of that.

Which factors point to lower risk?

The law lists factors a firm must at least consider, grouped by customer, product and geography. Customer factors: companies listed on a stock exchange whose disclosure rules make their beneficial ownership transparent, public administrations and public enterprises, and residents of lower-risk areas.

Product and service factors: life insurance with a low premium; pension insurance that cannot be surrendered early or used as collateral; employee retirement schemes funded from wages whose rules do not let members assign their interest; narrowly defined products designed to widen access to financial services; and products whose risk is contained by other features, such as limits on amounts or stored value, or transparent ownership, as with some electronic money.

Geographic factors: EU member states, and third countries that credible sources, such as mutual evaluations, show to have effective AML/CFT systems, low levels of corruption and crime, or requirements consistent with the FATF Recommendations that they apply effectively. The list is not exhaustive, and a single lower-risk factor does not make a relationship low risk on its own; the firm weighs everything it knows.

When is SDD not allowed?

SDD stops as soon as the grounds for low risk are in doubt. It cannot be used where the firm suspects money laundering or terrorist financing, where it doubts that information it has received is true, or where a situation calls for enhanced due diligence, such as a politically exposed person or a high-risk third country.

Some sectors do not suit it at all: SDD is not appropriate in wealth management, and national rules may exclude it for particular products or services. See How does CDD differ by sector?

How to think about it

Treat SDD as turning CDD down, never off. First establish that the risk really is lower. Then decide which setting to lower: when verification finishes, how much evidence is taken, which sources are accepted, how often the file is reviewed. Before lowering anything, check for the three blockers: suspicion, doubtful information and a case that demands enhanced due diligence.

Common mistakes

  1. Calling SDD an exemption from CDD. Every measure still applies; only its extent, timing or type changes.

  2. Applying SDD before assessing risk. Lower risk has to be established first.

  3. Dropping monitoring or reporting. Monitoring must still detect unusual transactions, and suspicions still go to MOKAS.

  4. Using SDD for a politically exposed person. Any case that requires enhanced due diligence rules SDD out.

  5. Treating every company as low risk. Being a company, or a professional client, is not a lower-risk factor in itself. The customer factors name listed companies whose disclosure rules make ownership transparent, and public administrations or enterprises; geographic factors, such as being established in the EU, apply to any customer.

Practise this topic

Test what you just read

The Chapter 6 pack has 152 exam-style questions, 10 of them on this topic. Every question has a hint before you answer and a full explanation after.

Try the free demo

Or revise the numbers first with 18 free Chapter 6 flashcards →

Last reviewed on by the ExamPass CY editorial team against the law in force on that date. Study notes help you prepare for the CySEC exams; they are not legal advice. ExamPass CY is not affiliated with CySEC.

How we write study notesReport an error