Customer due diligence and beneficial ownership
Know the relationship, its purpose, and the people behind the entity.
The company has a neat logo and a complicated ownership chart. The job is to understand who is involved and why the account exists. A logo is optional. A coherent customer story is not.
Build a usable customer profile
Customer due diligence connects identity with the expected relationship. Record the nature and purpose of the account, relevant business activity, expected transaction behavior, and supporting evidence. Expected activity is a hypothesis to compare with later behavior, not a promise that every deviation is suspicious.
Keep customer-provided claims distinct from verified facts and analyst conclusions. A free-text business description alone is difficult to monitor. Translate it into useful fields while retaining context. For example, a seasonal ticket seller should not be compared blindly with a local repair shop. The profile needs enough detail to support meaningful review.
A usable profile contains enough context to interpret later activity. A monthly volume estimate alone says little about whether many small receipts and a few large supplier payments fit the customer’s business. Product, customer types, counterparties, geography, expected transaction patterns, and the source of relevant information can help distinguish ordinary variation from a meaningful change.
Expected activity should not become a rigid accusation threshold. A successful merchant may grow faster than forecast, and a legitimate business may enter a new market. A material difference prompts an evidence-based review of the current story. Record whether the difference reflects growth, a stale profile, a product change, or an unresolved concern. The outcome then informs the profile and the next control decision.
Inside the mechanism. A usable profile explains the customer’s activity in terms the monitoring system can compare with observed flows. Record expected counterparties, transaction types, geographic activity, scale, and the basis for the information. Expectations are hypotheses that can become outdated; they are not permanent proof of legitimacy. Preserve the source and uncertainty so an investigator can distinguish a supported business explanation from an unverified onboarding statement.
A concrete example. The profile describes how a merchant expects to receive and send money. Later activity must be interpreted against that story with room for legitimate growth and change. The daily source population is 5,200 items, but 104 are outside the completed monitoring run. The included population creates 331 hits and 271 unique cases. With 35 cases already open and capacity for 285, the queue closes at 21. Coverage, duplicate work, and staffing are separate causes; reducing one number does not prove that the overall control improved.
When the assumption fails. A monthly volume estimate is treated as the full customer profile. Use product, counterparties, timing, geography, and the source of each profile fact. The following worked sequence shows the reference condition, a stress condition, and a response condition with explicit synthetic data. These are comparative assumptions, not measured causal effects.
The profile describes how a merchant expects to receive and send money. Later activity must be interpreted against that story with room for legitimate growth and change.
- IdentifyEstablish customer facts
- UnderstandDocument purpose and expected activity
- CompareReview material changes over time
- Claim
- Information the customer supplied
- Verified fact
- Information supported by the stated check
Customer profile
Illustrative data; not a real customer record or a prescribed policy.
- Purposeseasonal ticket sales
Stated relationship
- Expected volumeseasonal peaks
Context for monitoring
- Verified evidencevenue agreement
Supports part of the story
Their evidentiary strength differs
Separate claims facts and conclusions. Their evidentiary strength differs.
- Failure mode 1avoid
- Treat every expected value as a hard legal limit. Profiles guide review rather than define every duty.
- Failure mode 2avoid
- Use only a broad industry label. It may miss the business pattern.
- Failure mode 3avoid
- Never update the profile. Relationships change.
Distinguish ownership from control
For covered financial institutions, FinCEN’s CDD framework includes identifying and verifying relevant beneficial owners. Its public summary describes a 25 percent ownership prong and a control prong, subject to scope and exceptions. These are not the same test as OFAC’s blocked-ownership rule.
Model ownership percentages and management authority as different relationship types. A chief executive may control a company without owning a quarter of it. An owner may hold a substantial stake without managing daily operations. Preserve the source and date of each relationship so changes can be assessed and the applicable rule can be applied accurately.
Ownership evidence needs a date and a clear unit of analysis. A person may own an intermediate company that owns the customer, while another person manages the customer without the same ownership interest. Represent those relationships separately. A diagram can explain a complex structure, but the underlying records should still identify the source for each edge, the percentage where relevant, and unresolved gaps. The collection duty depends on the applicable rule and relief; a convenient ownership graph should not silently replace that legal analysis.
Inside the mechanism. Ownership and control describe different relationships. A percentage interest can identify economic ownership, while management authority can exist without that percentage. Store the relationship type, relevant person or entity, effective dates, and source evidence. Do not reuse one regulatory ownership test as though it answered every beneficial-ownership or sanctions question. The applicable definition and purpose must travel with the conclusion.
A concrete example. An individual’s economic interest and management authority are different relationships. Due-diligence records should preserve each with its source and date. The case identifies 1,704 eligible records from a source population of 2,400. The required workflow completes for 1,653, but 25 completed records miss the illustrative internal target. Another 51 remain incomplete. Communication evidence covers 1,636 generated notices. Scope, completion, timeliness, and delivery are four separate properties of the customer outcome.
When the assumption fails. A manager’s name is stored as though it proves the full ownership structure. Represent ownership and control separately and apply the actual collection requirements and relief. The following worked sequence shows the reference condition, a stress condition, and a response condition with explicit synthetic data. These are comparative assumptions, not measured causal effects.
An individual’s economic interest and management authority are different relationships. Due-diligence records should preserve each with its source and date.
- OwnershipRecord economic stakes
- ControlRecord relevant management authority
- Apply scopeUse the applicable CDD rule and exceptions
- Ownership prong
- Specified equity interest
- Control prong
- Relevant responsibility for managing the entity
Entity relationship record
Illustrative data; not a real customer record or a prescribed policy.
- Person A30 percent owner
Ownership relationship
- Person Bchief executive
Control relationship
- RuleCDD scope
Separate from sanctions ownership
They answer different rule questions
Store ownership and control separately. They answer different rule questions.
- Failure mode 1avoid
- Use the OFAC threshold for all CDD. The frameworks have different tests.
- Failure mode 2avoid
- Assume a CEO must own shares. Control can exist without the stake.
- Failure mode 3avoid
- Ignore dated evidence. Ownership and authority can change.
Account for the 2026 relief
FinCEN’s February 2026 exceptive relief changes when covered institutions must identify and verify beneficial owners for additional accounts. The order permits an approach centered on the first account, facts that call prior information into question, and risk-based ongoing CDD needs. The exact conditions and scope remain in the order.
An engineering implementation should model the legal-entity relationship and prior verification evidence rather than treat every account as an unrelated customer. Reuse only evidence that remains eligible and reliable under the approved policy. A change in ownership still needs a route for review. Relief from repetition is not relief from understanding the customer.
Inside the mechanism. A change in collection requirements should alter the workflow at the correct scope rather than erase existing risk-based monitoring. Keep the reason a collection or refresh step was required, omitted, or repeated under the applicable framework. The system still needs to handle contradictory information and material changes in the customer’s activity. Preserve the effective date and policy version so historical treatment can be explained under the rule then in use.
A concrete example. The institution must distinguish beneficial-owner collection duties from other identity, monitoring, and risk-management work. The relief does not turn every old record into permanent sufficient evidence. The case identifies 1,827 eligible records from a source population of 3,150. The required workflow completes for 1,772, but 27 completed records miss the illustrative internal target. Another 55 remain incomplete. Communication evidence covers 1,754 generated notices. Scope, completion, timeliness, and delivery are four separate properties of the customer outcome.
When the assumption fails. A broad verified flag suppresses review after facts call earlier information into question. Keep the applicable trigger and source of authority explicit for each collection or refresh action. The following worked sequence shows the reference condition, a stress condition, and a response condition with explicit synthetic data. These are comparative assumptions, not measured causal effects.
The institution must distinguish beneficial-owner collection duties from other identity, monitoring, and risk-management work. The relief does not turn every old record into permanent sufficient evidence.
- First relationshipEstablish required ownership evidence
- Additional accountAssess eligible reuse under the order
- Changed factsRefresh when the relevant conditions arise
- Eligible reuse
- Prior evidence remains usable under policy
- Blind reuse
- Old information copied without checking conditions
Additional-account review
Illustrative data; not a real customer record or a prescribed policy.
- Prior verificationon file
Existing evidence
- Ownership changereported
Reliability trigger
- Actionrefresh relevant facts
Do not reuse blindly
The order changes repetition rather than removing CDD
Apply the relief with its conditions. The order changes repetition rather than removing CDD.
- Failure mode 1avoid
- Collect everything again without considering scope. That can add unnecessary duplication.
- Failure mode 2avoid
- Never refresh after the first account. Changed facts can require action.
- Failure mode 3avoid
- Confuse CDD with corporate BOI filing. They are separate frameworks.
Use enhanced review for the specific concern
Enhanced due diligence means obtaining and evaluating more evidence where the risk and applicable requirements call for it. The work should address the reason for concern: ownership opacity, unusual source of funds, a complex route, or another documented factor.
A large document request can be less useful than one well-chosen source. Distinguish source of funds for a transaction from source of wealth accumulated over time. Record how the evidence supports the explanation and what remains unresolved. Avoid treating a customer’s occupation, nationality, or a broad label as sufficient proof of misconduct.
Inside the mechanism. Enhanced review should resolve a defined concern with relevant evidence. A complex ownership chain may need ownership records; unusual trade flows may need commercial context. Repeatedly collecting unrelated documents adds cost without resolving uncertainty. Record the hypothesis, requested evidence, findings, unresolved gaps, and disposition authority. An incomplete response is a fact to evaluate, not automatic proof of a particular crime.
A concrete example. A reviewer identifies an uncertainty in the business explanation and seeks evidence relevant to it. More documents are useful only if they address that uncertainty. The case identifies 986 eligible records from a source population of 1,120. The required workflow completes for 956, but 14 completed records miss the illustrative internal target. Another 30 remain incomplete. Communication evidence covers 946 generated notices. Scope, completion, timeliness, and delivery are four separate properties of the customer outcome.
When the assumption fails. The same generic document bundle is requested from every customer regardless of the concern. Tie each evidence request to a factual gap, decision, owner, and proportionate handling. The following worked sequence shows the reference condition, a stress condition, and a response condition with explicit synthetic data. These are comparative assumptions, not measured causal effects.
A reviewer identifies an uncertainty in the business explanation and seeks evidence relevant to it. More documents are useful only if they address that uncertainty.
- ConcernName the unresolved risk factor
- EvidenceSeek information that tests it
- ConclusionDocument support and remaining gaps
- Source of funds
- Origin of money in a specific flow
- Source of wealth
- How broader wealth was accumulated
Enhanced review
Illustrative data; not a real customer record or a prescribed policy.
- Transactionlarge business sale proceeds
Claimed funds source
- Evidenceexecuted sale documents
Supports the transaction story
- Gapreceipt not reconciled
Still needs cash-flow evidence
Enhanced review should improve understanding
Match additional evidence to the concern. Enhanced review should improve understanding.
- Failure mode 1avoid
- Ask for every document available. Volume is not relevance.
- Failure mode 2avoid
- Treat source of wealth as the same as this transfer. The questions differ.
- Failure mode 3avoid
- Infer misconduct from nationality alone. That exceeds the evidence.
Refresh through events and risk
Customer information can be updated through scheduled reviews and event-driven triggers. The appropriate approach depends on the institution, customer, product, and applicable requirements. A material business change can matter before the next calendar review.
Define triggers such as new ownership, changed business activity, unusual transaction patterns, or evidence that contradicts prior records. Route the review to the right owner and preserve the previous profile. This history explains why earlier decisions differed. A current snapshot alone cannot show whether monitoring used the information available at the time.
Inside the mechanism. Refresh can follow a material event, changed activity, contradictory evidence, or an appropriate risk-based schedule. Define which event invalidates which part of the profile. A new address may not require the same work as a new controlling party or business model. Retain the prior profile and the change reason. The monitoring system should know whether a new expectation is verified, customer-asserted, or still under review.
A concrete example. A material change in activity or reliable ownership evidence can make an earlier profile stale. A periodic schedule alone may miss the relevant event. The daily source population is 9,300 items, but 186 are outside the completed monitoring run. The included population creates 292 hits and 239 unique cases. With 42 cases already open and capacity for 250, the queue closes at 31. Coverage, duplicate work, and staffing are separate causes; reducing one number does not prove that the overall control improved.
When the assumption fails. A new business line appears while the profile remains unchanged until the next annual review. Use defined event triggers and preserve the history of profile changes and supporting facts. The following worked sequence shows the reference condition, a stress condition, and a response condition with explicit synthetic data. These are comparative assumptions, not measured causal effects.
A material change in activity or reliable ownership evidence can make an earlier profile stale. A periodic schedule alone may miss the relevant event.
- TriggerDetect a relevant change
- ReviewUpdate the affected customer facts
- VersionPreserve prior and current profiles
- Current profile
- Best present view
- Profile history
- Evidence used in past decisions
Refresh event
Illustrative data; not a real customer record or a prescribed policy.
- Old activitylocal retail
Prior profile
- New activityinternational wholesale
Material change
- Reviewbusiness and route update
Targeted refresh scope
Calendar reviews alone can miss new exposure
Version profiles and act on material change. Calendar reviews alone can miss new exposure.
- Failure mode 1avoid
- Overwrite the old profile silently. Past decisions become hard to explain.
- Failure mode 2avoid
- Refresh unrelated fields only. The material change remains unresolved.
- Failure mode 3avoid
- Wait despite contradictory evidence. The prior information may no longer be reliable.
Chapter connections
This chapter builds on AML programs and the risk-based approach. Continue with Entity resolution and financial networks to follow the next part of the system. Use the glossary for terminology and risk mathematics for formulas and worked calculations.