Customer due diligence (in Dutch: cliëntenonderzoek) is the investigation the Wwft requires so that you know who you are doing business with. You establish who the customer is, who is ultimately behind them, what the customer wants from the relationship and whether the relationship behaves as you expect. The due diligence starts before you enter into the relationship and continues for as long as the relationship lasts.
It is often abbreviated to CDD. In practice people also speak of KYC. In What is KYC? you can read how these terms relate.
Why customer due diligence is mandatory
The Wwft makes banks, trust offices, accountants, civil-law notaries, estate agents and other institutions gatekeepers of the financial system. A gatekeeper can only pay attention if they know who is coming in. Without a clear picture of the customer, you will not recognise deviating behaviour either, and then you cannot report unusual transactions.
That is why customer due diligence underpins all other Wwft obligations. Read more about the Act itself in What is the Wwft?
What do you establish?
Article 3 of the Wwft describes what the due diligence must enable you to do:
- Identify the customer and verify their identity. You record who the customer is and check this against reliable documents, such as a valid identity document or an extract from the trade register.
- Establish the UBO. You identify the ultimate beneficial owner and take reasonable measures to verify their identity. For a legal entity you also map the ownership and control structure. See What is a UBO? and Requesting a UBO extract from the KvK.
- Establish the purpose and intended nature of the relationship. Why is the customer coming to you, and which services and transactions do you expect?
- Check the representative. You establish whether the person acting on behalf of the customer is authorised to do so, and you identify and verify that person.
- Find out on whose behalf the customer acts. You take reasonable measures to verify whether the customer acts for themselves or for a third party.
- Monitor the relationship on an ongoing basis. You check whether the transactions match what you know about the customer and their risk profile. Where necessary, you investigate the source of funds.
In addition, you establish whether the customer or the UBO is a PEP. In practice you also screen against sanctions lists. That obligation comes from sanctions legislation, but you usually carry it out as part of the same investigation.
When do you carry out customer due diligence?
The Wwft lists the moments at which due diligence is mandatory. The most important:
- when entering into a business relationship
- for an occasional transaction of € 15,000 or more, or for linked transactions that together reach that amount
- when there are indications that the customer is involved in money laundering or terrorist financing
- when you doubt the accuracy or completeness of data obtained earlier
- when the risk of an existing customer gives reason to do so
- when there is a higher risk because of the country in which the customer lives or is established
Separate thresholds apply to certain sectors and transactions, for example gambling and transfers of funds. You also keep the data up to date. If something relevant changes for the customer, you update the file.
Three levels: simplified, standard and enhanced
The Wwft is risk-based. You demonstrably tailor the due diligence to the risk of the customer, the relationship, the product or the transaction. In doing so, you take into account at least the risk variables from the European anti-money laundering directive.
This results in three levels:
- Simplified customer due diligence where the risk is demonstrably low. Read more in Simplified customer due diligence: when is it allowed?
- Standard customer due diligence for most customers.
- Enhanced customer due diligence where the risk is higher, such as for PEPs and high-risk countries. See enhanced due diligence.
Your own risk assessment and policy determine which level fits which customer.
Due diligence first, then the relationship
You complete the identification and verification of the customer and the UBO before you enter into the relationship or carry out the transaction. For a new corporate customer you must also have proof of registration in the trade register and check whether the UBOs are recorded in the UBO register.
There are limited exceptions. If the risk is low and a delay is necessary so as not to interrupt the service, you may complete the verification while entering into the relationship, as soon as possible after the first contact.
If you cannot complete the due diligence, you may not enter into the relationship. You terminate an existing relationship. If there are also indications of money laundering or terrorist financing, you report this to FIU-Nederland. See What is an unusual transaction?
Recording and retention
A supervisor assesses your due diligence on the basis of what is in the file. So record which documents and data you used, which risk you identified and how you reached your decision.
You keep those records in an accessible way for five years after the end of the business relationship, or five years after the occasional transaction. Read more in Record-keeping under the Wwft.
What changes with the AMLR?
From 10 July 2027 the European Anti-Money Laundering Regulation, the AMLR, applies. It sets out the customer due diligence rules directly for the whole EU. The core remains the same: establish the customer and the UBO, understand the purpose of the relationship and keep monitoring. Many details, however, become more precise and more uniform between Member States. Read more in AMLR 2027.
Doing it yourself or outsourcing
Good customer due diligence requires knowledge of the rules, reliable sources and time to ask follow-up questions. Many organisations do it themselves. Others outsource the execution, for example during peaks or a remediation project. You then remain responsible for the policy and for the decision on the customer. Read more about the work itself in What does a CDD analyst do?