Simplified customer due diligence is a lighter form of customer due diligence that the Wwft allows where a business relationship or transaction by its nature presents a low risk of money laundering or terrorist financing. You then adjust the measures to that low risk. You do less or do it later, but you never do nothing.
It is known as Simplified Due Diligence (SDD). It is the lightest of the three levels. Above it sit standard due diligence and enhanced due diligence.
What does the Wwft say?
Article 6 of the Wwft governs simplified customer due diligence. In short:
- You may carry out simplified due diligence where the relationship or transaction by its nature presents a low risk. In doing so, you take into account at least the factors of potentially lower risk in Annex II to the fourth European anti-money laundering directive.
- You demonstrably collect sufficient data to establish that simplified due diligence fits this customer.
- You keep that data and that conclusion up to date.
- You monitor the relationship and the transactions sufficiently to be able to report unusual transactions.
Until July 2018 the Wwft listed cases in which you could skip customer due diligence altogether. Those exemptions have been removed. Since then you assess case by case whether the risk is low.
When is the risk low?
Annex II to the anti-money laundering directive gives a non-exhaustive list of factors that may indicate a lower risk. For example:
- Customer: listed companies subject to disclosure requirements that ensure transparency about the UBOs, public administrations and public enterprises, and customers resident in lower-risk areas.
- Product or service: life insurance policies with a low premium, pension contracts without a surrender option that cannot be used as collateral, and products with spending limits or transparent ownership.
- Country: EU Member States and third countries with effective anti-money laundering systems and a low level of corruption.
These are indications, not a free pass. A listing on its own is not enough. De Nederlandsche Bank points out that it matters on which exchange a company is listed and what proportion of the shares is freely tradable. The product, the service and the country can also increase the risk.
When is it not allowed?
Simplified due diligence does not fit where the risk is higher. Think of:
- indications that the customer is involved in money laundering or terrorist financing
- a customer or UBO who is a PEP
- a link with a high-risk country
- complex or unusually large transactions without a clear purpose
- doubts about the accuracy of the data the customer has provided
In those cases you carry out standard or enhanced due diligence. If you see something unusual, read What is an unusual transaction?
What do you still do?
Simplified does not mean that the due diligence disappears. You still:
- collect enough data to support the low risk, for example an extract from the trade register or an entry in a public register
- reassess the low-risk classification regularly
- monitor the relationship and the transactions so that you can recognise and report unusual transactions
- screen against sanctions lists, as sanctions legislation applies in full
You record in your policy which measures you make lighter. European guidelines and the AMLR give examples: verifying identity later, updating customer data less often, collecting less information about the purpose of the relationship and monitoring transactions less intensively.
Recording your reasoning
The supervisor wants to see why you classified a customer as low risk. So record:
- which lower-risk factors you identified and on the basis of which sources
- which measures you made lighter
- when you will reassess the classification
You may determine in your policy in advance which types of customers qualify. You base that classification on a risk analysis. For each customer you then establish whether the low risk is actually present. If the risk increases later, you switch to a heavier level.
What changes with the AMLR?
From 10 July 2027 the European Anti-Money Laundering Regulation applies. Article 33 of the AMLR governs simplified measures for business relationships and transactions with a low risk. The Regulation lists the permitted measures. For instance, you may verify the identity of the customer and the UBO after entering into the relationship, but no later than 60 days. Under the AMLR, too, you must monitor the relationship sufficiently to detect unusual or suspicious transactions. Your internal procedures must contain the specific measures per type of customer. Read more in AMLR 2027.
Doing it yourself or outsourcing
Classifying customers correctly takes experience. A classification that is too light creates a risk with the supervisor; one that is too heavy costs unnecessary time and asks customers for documents that are not needed. It helps to set out the criteria for low risk concretely in your policy, with examples, so that every analyst makes the same assessment. Many organisations do this themselves. Others have the execution done by specialists and keep the policy and the decision on the customer in house.