What does customer due diligence involve?
The four CDD measures under Cyprus's AML/CFT Law, how risk sets their depth, and when a customer's identity counts as proven.
By the ExamPass CY editorial teamLast reviewed 5 min read
Topic 2 of 14 · all topics in this chapter
- 1When CDD is required
- 2What CDD involves
- 3When CDD must be completed
- 4Verifying individuals
- 5Verifying companies and organisations
- 6Customer economic profile
- 7Beneficial ownership registers
- 8Simplified due diligence
- 9Enhanced due diligence and PEPs
- 10CDD by sector
- 11Ongoing monitoring
- 12Reliance on third parties
- 13Group-wide AML policies
- 14Prohibited practices and data use
Short answer
Customer due diligence has four parts: identify the customer and verify their identity from a reliable, independent source; identify the beneficial owner and take reasonable steps to verify them; understand the purpose and intended nature of the relationship; and monitor the relationship on an ongoing basis. CDD applies to new and existing customers alike. Risk decides how far each measure goes, and the firm must be able to show CySEC that its choice is proportionate. The only exemption from the measures is for low-value electronic money.
The four CDD measures
| Measure | What it means in practice |
|---|---|
| 1. Identify and verify the customer | Documents, data or information from a reliable and independent source, including electronic identification, EU-recognised trust services or another secure remote process accepted by the competent Cypriot authority |
| 2. Identify and verify the beneficial owner | Reasonable measures to confirm who ultimately owns or controls the customer; for companies and trusts, understand the ownership and control structure |
| 3. Understand the relationship | Assess, and where appropriate obtain information on, its purpose and intended nature |
| 4. Monitor on an ongoing basis | Check that transactions match what the firm knows about the customer, their business and risk profile, including the source of funds where necessary, and keep records up to date |
Source: Law 188(I)/2007, Article 61(1).
How does risk change the depth of CDD?
The law does not let a firm skip CDD for customers it considers safe; it lets the firm scale it. When deciding how deep to go, the firm weighs at least three variables: the purpose of the account or relationship, the level of assets the customer will deposit or the size of the transactions, and how regular or long-lasting the relationship will be.
A firm that scales CDD this way must be able to show CySEC that the extent of its measures is proportionate to the risks of money laundering and terrorist financing it actually faces. Lighter measures for lower-risk customers are covered in When can simplified due diligence be used?, heavier ones in When is enhanced due diligence required?
Terms used in this note
- Beneficial owner
- The natural person who ultimately owns or controls the customer, or on whose behalf a transaction or activity is carried out. For a company, a shareholding of 25% plus one share, or an ownership interest above 25%, indicates ownership. Where a senior managing official is treated as the beneficial owner, the firm verifies that person and records what it did.
- Reliable and independent source
- Evidence the customer cannot easily alter or obtain illicitly, such as an official document or a regulated electronic identification scheme.
When is a customer's identity considered proven?
Certainty is not the standard. Proof of identity is sufficient when it is reasonable to accept that the customer is who they claim to be and the person checking the evidence is satisfied of it. The evidence must come from a reliable and independent source, which can include electronic identification, so customers can be onboarded remotely.
If someone else will act for the customer, the firm checks that they are duly authorised and identifies and verifies that person as well.
Are there any exemptions?
There is only one exemption from the measures themselves, for low-value electronic money, and only where a risk assessment shows the risk is low. The issuer may then leave out some of the first three measures if all of these conditions are met: the instrument cannot be reloaded, or has a low monthly payment limit and can be used only in Cyprus; no more than €150 is stored on it; it is used only to buy goods or services; it cannot be funded with anonymous e-money; and the issuer monitors enough to detect unusual transactions.
The exemption falls away when more than €50 is redeemed or withdrawn in cash, or when a remote payment exceeds €50. It never removes ongoing monitoring or the duty to identify and report suspicious transactions.
Separately, a firm may stop CDD part-way if completing it would tip the customer off about a suspicion, which is itself an offence; it must then inform MOKAS immediately. Cost or inconvenience is never a reason to stop.
What about insurance and trust beneficiaries?
For life and other investment-related insurance, CDD also covers the beneficiaries as soon as they are identified or designated. Named beneficiaries are recorded by name; beneficiaries described by class or characteristics must be identifiable at the latest when the policy pays out. Beneficiaries of trusts described by class follow the same logic: the firm must be able to identify them at payout or when they exercise their rights.
How to think about it
Picture CDD as four questions the firm must be able to answer about every customer: who are you, who is behind you, why are you here, and does what you do still match that? Risk decides how much evidence each answer needs, never whether the question gets asked. The only ways to skip questions are the tightly conditioned e-money exemption, which still keeps the fourth question, monitoring, and stopping to avoid tipping off a suspect.
Common mistakes
Believing low-risk customers can skip CDD. Risk changes the extent of the measures, not whether they apply.
Expecting absolute certainty about identity. The test is reasonable satisfaction based on reliable, independent evidence.
Mixing up the e-money figures. €150 is the most that can be stored on the instrument; cash redemptions or remote payments above €50 end the exemption.
Thinking the e-money exemption removes monitoring. Ongoing monitoring and suspicious transaction reporting still apply.
Listing reporting to the authorities as a CDD measure. The four measures are identification, beneficial ownership, purpose and ongoing monitoring; reporting suspicion is a separate duty.
Legal references
- The Prevention and Suppression of Money Laundering and Terrorist Financing Law of 2007 (Law 188(I)/2007), as amended (opens in a new tab)
Article 61 (CDD measures, risk-based extent, e-money, insurance beneficiaries) · Article 48 (tipping off) · Annex I (risk variables)
- CySEC Directive for the Prevention and Suppression of Money Laundering and Terrorist Financing, as amended (opens in a new tab)
- Directive (EU) 2015/849 (4th AML Directive), as amended by Directive (EU) 2018/843 (opens in a new tab)
Practise this topic
Test what you just read
The Chapter 6 pack has 152 exam-style questions, 17 of them on this topic. Every question has a hint before you answer and a full explanation after.
Or revise the numbers first with 18 free Chapter 6 flashcards →