Lesson 1 of 5

What customer due diligence is for

Customer due diligence (CDD) is how a regulated business answers three questions about each customer: who are you, who is really behind you, and what will you use us for? The answers are the baseline against which everything the customer does later is judged. A transaction is only unusual if you know what usual looks like for that customer.

The international standard is set by the Financial Action Task Force (FATF). Its Recommendation 10 describes four CDD measures:

  • Identify the customer and verify that identity using reliable, independent documents, data or information.
  • Identify the beneficial owner, the person who ultimately owns or controls the customer, and take reasonable measures to verify who they are. For companies and trusts, this includes understanding their ownership and control structure.
  • Understand the purpose and intended nature of the business relationship, and obtain information on it where appropriate.
  • Conduct ongoing due diligence: keep watching the relationship and the transactions in it, and keep the information up to date.

Under the same Recommendation, CDD is required when a business relationship is established; for occasional transactions (one-off transactions for someone with no ongoing relationship with you) above a set threshold (USD/EUR 15,000 in the FATF standard) and for certain occasional wire transfers; whenever money laundering or terrorist financing is suspected; and when there are doubts about whether identification data obtained earlier is true or adequate.

In Kenya these duties sit in the Proceeds of Crime and Anti-Money Laundering Act, 2009 and the Proceeds of Crime and Anti-Money Laundering Regulations, 2023, alongside the rules of sector supervisors such as the Central Bank of Kenya. Kenya's Regulations go further than the FATF standard in places: they require CDD for occasional or one-off transactions without setting a threshold (regulation 14(5)).

If CDD cannot be completed, the FATF standard is not to open the account, start the relationship or carry out the transaction, or to end an existing relationship, and to consider a suspicious transaction report. Kenya's 2023 Regulations (regulation 25) go further. If a customer does not provide evidence of identity as soon as reasonably practicable, the institution must not open the account or carry out the transaction, must end any relationship already started, and must file a suspicious transaction report with the Financial Reporting Centre. And if carrying on with CDD would alert the customer to a suspicion, the Regulations allow the institution to stop and file the report instead.

Lesson 2 of 5

Finding the real owner

Criminals rarely open accounts in their own names when a company, trust or nominee will do it for them. That is why CDD looks through the customer to the beneficial owner: the natural person, always a human being, who ultimately owns or controls it, or on whose behalf a transaction is carried out.

For a company, the work usually runs in three steps:

  • Ownership: who holds shares or voting rights above the threshold that applies. Thresholds differ by country and by rule book, so use the one that binds you.
  • Control by other means: who can appoint the board, direct decisions or otherwise control the company without holding many shares.
  • Senior managing official: where no person qualifies under the first two steps, identify, and take reasonable steps to verify, the person who holds the position of senior managing official, such as the chief executive, and record why no owner was found. This person is a fallback; it does not mean they own the company.

Ownership can pass through several layers of companies, sometimes in different countries. Follow each layer until you reach people. Kenya's 2023 Regulations (regulation 22) require you to identify and verify the natural persons behind a company or trust and to understand its ownership and control. In practice that means obtaining documents such as the certificate of incorporation, details of directors and shareholders, and, for a trust, the trust deed. An official search from the Registrar of Companies is a common starting point.

Warning signs include structures that are more complex than the business needs, nominee shareholders or directors with no clear reason, bearer shares, and reluctance to explain who is behind the company.

Many countries now keep beneficial ownership registers. In Kenya, section 93A of the Companies Act, 2015 requires every company to keep a register of its beneficial owners and lodge a copy with the Registrar of Companies, with changes lodged within 14 days (30 days for listed companies). For the register, the Companies (Beneficial Ownership Information) Regulations, 2020 treat a person as a beneficial owner if, among other tests, they hold at least 10% of the shares or voting rights. Registers are a useful source, but they record what companies declared. They support your checks; they do not replace them.

Lesson 3 of 5

Rating customer risk

The risk-based approach comes from FATF Recommendation 1: countries, and the businesses they regulate, must identify, assess and understand their money laundering and terrorist financing risks, and apply measures in proportion to them. For each customer, it means working out where risk is higher and spending your effort there, rather than treating every customer the same.

FATF groups risk factors by customer, geography, and products, services, transactions or delivery channels. Many firms score delivery channel separately, so a customer risk rating usually combines four groups of factors:

  • The customer: their type (individual, company, trust, charity), occupation or business, whether they are a politically exposed person (a PEP: someone who holds or has held a prominent public function, such as a minister, senior judge or senior military officer, or a family member or close associate of such a person), and anything adverse known about them.
  • Geography: where they live, are incorporated and do business, and where their money comes from and goes, including countries the FATF lists as having strategic deficiencies (its "high-risk jurisdictions subject to a call for action" and "jurisdictions under increased monitoring"). Kenya itself has been under FATF increased monitoring since February 2024; check the FATF website for its current status.
  • Products and services: how easily each can be used to move value quickly, anonymously or across borders.
  • Delivery channel: whether the relationship was opened face to face, remotely or through an intermediary.

Each factor is scored, and the scores combine into an overall rating such as low, medium or high. The method matters as much as the result:

  • Write it down: the factors, the weights and the reasons.
  • Allow a documented override, so an analyst can raise a rating when something does not fit the model.
  • Test it: check that high-risk customers really are rated high, and that the model is not quietly rating everyone as low.

A risk rating is not a verdict on the customer. It decides how much due diligence and monitoring the relationship needs.

Lesson 4 of 5

When to do less, and when to do more

The rating drives the depth of due diligence.

Simplified due diligence may be allowed where lower risk has been identified through an adequate analysis of risk, for example with financial institutions supervised under strong AML rules, or companies listed on a stock exchange with rules on disclosing their ownership, if the law where you operate permits it. It means lighter measures, not none. It is never allowed where there is a suspicion of money laundering, terrorist financing or proliferation financing (financing weapons of mass destruction), or where specific higher-risk scenarios apply. Kenya's 2023 Regulations (regulation 21) set the same limits.

Enhanced due diligence (EDD) applies where risk is higher. The FATF standards require it for foreign politically exposed persons (PEPs) and their family members and close associates. For domestic PEPs and people with prominent functions in international organisations, it is required where the relationship is higher risk. Kenya's 2023 Regulations (regulation 26) follow the same approach. EDD is also required for business relationships and transactions with people, companies and financial institutions from countries for which the FATF calls for it; in Kenya, section 45A of the Act sets this out. Typical EDD measures include:

  • establishing the source of funds (where the money in this relationship comes from) and the source of wealth (how the customer came to have their overall wealth);
  • obtaining more information about the customer and the intended relationship;
  • getting senior management approval before starting or continuing the relationship;
  • monitoring more often and more closely.

EDD should actually answer the question it raises. A payslip does not explain a deposit a hundred times the customer's salary; a sale agreement or an inheritance record might.

Higher risk does not mean automatic refusal. FATF has warned against de-risking, closing whole categories of customers without assessing each one, because it can push people and money out of the regulated system altogether. Decide customer by customer, and record why.

Lesson 5 of 5

Keeping it current

CDD is not a one-off check at onboarding. Customers change: a small trader grows into an exporter, a company changes owners, a customer becomes a politically exposed person. Ongoing due diligence keeps the picture accurate.

  • Periodic reviews, with frequency set by risk: for example high-risk customers reviewed more often than low-risk ones, under a schedule your policy defines.
  • Trigger events that prompt an immediate review: a change of ownership or control, a new country or product, transactions that do not fit the customer's profile, adverse media (negative news reports about the customer), or a new sanctions or PEP match.
  • Transaction monitoring that compares activity with what the customer said they would do. Unexplained differences are a reason to ask questions, and possibly to report.

Records matter as much as the checks. Keep what you obtained and why you decided what you did, for at least as long as the law requires. In Kenya, section 46 of the Proceeds of Crime and Anti-Money Laundering Act, 2009 requires records of customer identity and transactions to be kept for at least seven years from the date the transaction was completed or the relationship ended, or longer if the Financial Reporting Centre requires it. Good records let you show a supervisor or court that your decisions were reasonable at the time you made them.

When a review reveals something you cannot resolve, escalate it, normally to your Money Laundering Reporting Officer (MLRO). That may mean EDD, restricting the account, exiting the relationship or filing a suspicious transaction report. In Kenya, section 44 of the Act requires a suspicious transaction report to reach the Financial Reporting Centre within two days after the suspicion arose. Do not tell the customer that a report is being considered or made; tipping off is an offence under section 8 of the Act.

Knowledge check

Ten questions

Answer all ten questions, then check your answers. You need 9 out of 10 to pass and receive a certificate. If you score less, you will see which answers were right and wrong, and then go through the course again before you retake the check. Your answers, progress and times are kept only in this browser.

Sources

The official documents this course relies on. Laws and guidance change, so check the current version.

  1. The FATF Recommendations (International Standards on Combating Money Laundering and the Financing of Terrorism & Proliferation) · Financial Action Task Force
  2. Guidance for a Risk-Based Approach: The Banking Sector (2014) · Financial Action Task Force
  3. Proceeds of Crime and Anti-Money Laundering Act, 2009 (No. 9 of 2009) · Kenya Law
  4. Proceeds of Crime and Anti-Money Laundering Regulations, 2023 (L.N. 153 of 2023) · Kenya Law
  5. Companies Act, 2015 (section 93A, register of beneficial owners) · Kenya Law
  6. Companies (Beneficial Ownership Information) Regulations, 2020 · Kenya Law
  7. FATF clarifies risk-based approach: case-by-case, not wholesale de-risking (2014) · Financial Action Task Force
  8. Guidance: Politically Exposed Persons (Recommendations 12 and 22) · Financial Action Task Force
  9. Financial Reporting Centre, Kenya · Financial Reporting Centre