AML Compliance: KYC, CDD, and Suspicious Activity Reporting
AML compliance rests on knowing your customer, conducting proportionate due diligence, and reporting suspicious transactions to the financial intelligence unit. This topic covers the operational mechanics from customer onboarding through enhanced PEP checks to SAR/STR filing obligations.
Last updated:
AML compliance operates through three interconnected mechanisms: customer due diligence (CDD) establishes who a financial institution is dealing with and why; enhanced due diligence (EDD) applies additional scrutiny to higher-risk relationships, particularly politically exposed persons; and suspicious activity reporting converts compliance observations into financial intelligence filed with a national Financial Intelligence Unit. Together, these obligations transform regulatory standards into operational decisions made at the institution level, where the FATF framework either produces usable intelligence or fails.
The global AML framework ultimately works, or fails, at the level of individual institutions deciding whether to accept a customer and whether to report a transaction. A compliance officer at a bank in Lagos, a trust company in Luxembourg, or a currency exchange in Mumbai is the front line. The standards they apply, the records they keep, and the reports they file are the data that flow into Financial Intelligence Units and from there into investigations. Failures at this layer mean that even a well-designed FATF framework produces no actionable intelligence.
This topic covers the operational core of AML compliance. Customer due diligence (CDD) is the structured process of identifying who you are dealing with and why. Enhanced due diligence (EDD) applies extra scrutiny to higher-risk relationships, especially politically exposed persons (PEPs) who control public funds or decisions. Beneficial ownership identification pierces the corporate veil to find the human beings who ultimately own or control a legal entity. Suspicious Transaction Reports (STRs) or Suspicious Activity Reports (SARs) are the intelligence product that gets filed when something looks wrong.
The topic also addresses two structural problems in the current system: correspondent banking risk, where a small bank with weak controls can push suspicious flows through a larger bank's infrastructure, and de-risking, where compliance pressure causes banks to exit entire markets rather than manage the risk, with counterproductive effects on financial inclusion and on law enforcement's ability to follow the money.
By the end of this topic you will be able to:
- Describe the four components of FATF Recommendation 10 CDD and explain when each is triggered.
- Distinguish between simplified CDD, standard CDD, and enhanced due diligence, identifying which customer types require each.
- Explain the beneficial ownership identification requirement, including the 25 percent ownership threshold and the senior-managing-official fallback.
- Outline the SAR/STR filing obligation, including the suspicion standard, the tipping-off prohibition, and the elements that make a filing actionable.
- Analyse how correspondent banking risk and de-risking each undermine AML effectiveness at the systemic level.
- Customer Due Diligence (CDD)
- The FATF-mandated set of measures requiring financial institutions to identify and verify customers and beneficial owners, understand the purpose and nature of the business relationship, and conduct ongoing monitoring of transactions.
- Enhanced Due Diligence (EDD)
- A heightened set of CDD measures applied to higher-risk customers or relationships, including PEPs, high-risk jurisdictions, and certain business types. EDD typically requires senior management approval, source-of-wealth verification, and more intensive monitoring.
- Politically Exposed Person (PEP)
- An individual who holds or has held a prominent public function, together with family members and known close associates, who presents a higher corruption and bribery risk because of their position and their ability to misuse public funds.
- Beneficial owner
- The natural person who ultimately owns or controls a legal entity or arrangement, or on whose behalf a transaction is conducted, even if a nominee or intermediary appears on the face of the transaction.
- Suspicious Activity Report (SAR) / STR
- A confidential report filed by a reporting entity to the national Financial Intelligence Unit when a transaction or pattern gives rise to a suspicion of money laundering or terrorist financing. Filing is mandatory; disclosing the report to the subject (tipping off) is a criminal offence.
- Correspondent banking
- A relationship in which one bank (the correspondent) provides services such as clearing and settlement to another bank (the respondent), allowing the respondent's customers to access markets and payment systems they cannot reach directly.
Customer due diligence: identifying who you are dealing with
CDD is triggered at account opening, at the formation of a business relationship, and when a one-time transaction exceeds a threshold (typically USD/EUR 15,000, or USD 3,000 for wire transfers in the United States). It has four components under FATF Recommendation 10: identify and verify the customer, identify and verify the beneficial owner, understand the purpose and intended nature of the relationship, and conduct ongoing monitoring.
- Customer identificationFor natural persons: full legal name, date of birth, nationality, and government-issued identity document number, verified against the original document. For legal entities: registered name, registration number, legal form, registered address, and identity of directors and authorized signatories.
- Beneficial ownership identificationIdentifying natural persons who own 25 percent or more of the entity (10 percent in some jurisdictions for PEP-connected entities), or who exercise effective control through other means. Where ownership is obscured by corporate layers, the institution must look through each layer. If no individual meets the threshold, the senior managing official is identified as a fallback.
- Purpose and nature of relationshipUnderstanding what the customer does, why they need this account or product, the expected transaction volumes and counterparties, and the source of funds. This builds the baseline against which future transactions are assessed for anomalies.
- Ongoing monitoringScreening transactions against the expected profile, updating CDD records when circumstances change, and re-performing CDD for existing customers periodically or when triggered by a suspicious event or change in risk rating.
Enhanced due diligence for PEPs and high-risk relationships
Politically exposed persons receive enhanced scrutiny because their position gives them the opportunity to misuse public funds or exert influence over government processes, and because their wealth may be the product of bribery or corruption. FATF Recommendation 12 requires that for foreign PEPs (individuals from other countries), institutions must apply EDD automatically. For domestic PEPs and international organization PEPs, EDD is triggered by a risk-based assessment.
| EDD element | What it requires in practice |
|---|---|
| Senior management approval | A person at vice-president level or above must approve establishing or continuing the relationship |
| Source of wealth | Understanding how the PEP accumulated their overall wealth, not just the specific funds involved in this transaction |
| Source of funds | Identifying the specific origin of the funds in the transaction or account |
| Enhanced ongoing monitoring | More frequent and more detailed review of transactions than standard CDD, with lower thresholds for escalation |
The Riggs Bank case (2004) illustrates what happens when EDD fails. Riggs, a Washington DC bank with a niche in diplomatic accounts, maintained accounts for the government of Equatorial Guinea and for former Chilean dictator Augusto Pinochet. FinCEN and the OCC found that Riggs had failed to apply EDD to either relationship, had filed inadequate SARs, and had allowed tens of millions of dollars of suspect funds to move through the accounts without scrutiny. Riggs was fined USD 41 million, the largest US bank AML fine at the time, and was subsequently acquired and wound down.
Beneficial ownership registers
Beneficial ownership transparency is FATF Recommendation 24's core requirement. For years, satisfying it relied on financial institutions conducting their own CDD to look through corporate structures. Since 2015, the global policy direction has been toward central government-maintained registers recording who ultimately owns and controls each legal entity, accessible to competent authorities and, in many jurisdictions, to the public.
- UK: the People with Significant Control (PSC) register at Companies House, in force since 2016, requires UK companies to record any person owning more than 25 percent or exercising significant influence. The Register of Overseas Entities (2022) extended this to foreign companies owning UK property.
- EU: the 4th AMLD required member states to create central beneficial ownership registers accessible to competent authorities and obliged entities. The 5th AMLD made registers publicly accessible. The European Court of Justice's November 2022 ruling in Joined Cases C-37/20 and C-601/20 (Luxembourg Business Registers) found that unconditional public access breached the Charter of Fundamental Rights, prompting member states to restrict access to entities demonstrating a legitimate interest.
- US: the Corporate Transparency Act (2021, in effect from January 2024) requires most US entities to report beneficial owners to FinCEN's Beneficial Ownership Information system. Reports are accessible to law enforcement and, with customer consent, to financial institutions for CDD purposes, but not to the general public.
Suspicious activity reporting: the intelligence pipeline
The obligation to report suspicious transactions is the primary intelligence-generation mechanism of the AML system. A reporting entity, typically a bank, money service business, securities firm, or DNFBP, files a SAR (US) or STR (most other jurisdictions) when it has a suspicion of money laundering or terrorist financing. The suspicion standard is intentionally low: reasonable grounds to suspect, not proof. The institution is not required to investigate to certainty before filing.
In the United States, FinCEN received more than 4.3 million SARs in fiscal year 2022. The utility of the system depends on filing quality. A SAR with adequate detail about the transaction, the suspicious indicators, the parties, and the accounts is a usable intelligence product; a SAR that says only 'unusual transaction' provides almost nothing actionable. FinCEN guidance consistently identifies the narrative section as the most operationally important part of the filing.
Correspondent banking risk and de-risking
Correspondent banking presents a structural vulnerability in the AML system. A US or European correspondent bank providing dollar or euro clearing to a respondent bank in a smaller jurisdiction cannot apply its own CDD to the respondent's customers; it must rely on the respondent's AML program. Where the respondent has weak controls, the correspondent's infrastructure functions as an unmonitored conduit for suspect funds. The BIS reports that the number of active correspondent banking relationships has been declining since 2011.
- Nested correspondent accounts: a respondent bank allows its own respondents (sub-correspondents) to access the correspondent's infrastructure indirectly, creating additional layers the correspondent cannot see into. FATF Recommendation 13 prohibits entering correspondent relationships with shell banks and requires measures to prevent accounts being used by other undisclosed respondents.
- De-risking consequences: when major banks exit correspondent relationships with entire regions or categories of customer, including remittance companies, money service businesses, and small Pacific island or Caribbean jurisdictions, the flows do not stop. They migrate to informal value transfer channels, hawala networks, or cryptocurrency, which are harder for investigators to follow and carry no STR reporting obligations.
- The World Bank-CPMI survey: a 2015 survey by the World Bank and the Committee on Payments and Market Infrastructures found that 75 percent of large international banks had terminated some correspondent relationships in the prior five years, with Caribbean, Central Asian, and Pacific island banks most affected.
A customer opens an account at a bank. The bank identifies and verifies the customer's identity but does not ask about the source of funds or expected transaction volume. Which CDD component has been omitted?
Key Takeaways
- CDD has four components: customer identification, beneficial ownership identification, understanding the relationship's purpose, and ongoing monitoring. All four must be applied; omitting any one creates a compliance gap.
- PEPs require EDD automatically if they are foreign nationals; EDD includes senior management approval, source-of-wealth verification, and enhanced monitoring.
- Beneficial ownership registers in the UK, EU, and US are closing the gap created by anonymous shell company structures, though access rules differ by jurisdiction.
- SARs and STRs are the financial intelligence pipeline; the narrative quality of the filing determines whether law enforcement can use it, and tipping off the subject is a criminal offence.
- Correspondent banking risk and de-risking are structural weaknesses: the first allows weak respondent controls to compromise correspondent infrastructure; the second pushes high-risk flows into informal channels beyond the reporting system.
What is the difference between KYC and CDD?
Who is a politically exposed person (PEP) and what additional checks apply?
What is a Suspicious Activity Report and who must file one?
What is de-risking and why is it a problem?
What are the risks specific to correspondent banking?
Test yourself on Forensic Accounting and Financial Forensics with free, timed mocks.
Practice Forensic Accounting and Financial Forensics questionsSpotted an error in this page? Report a correction or read our editorial standards.