By SanctionsAI team · Updated 2026-08-09

How to conduct customer due diligence (CDD) for sanctions

The FinCEN CDD Rule (31 CFR 1010.230) requires financial institutions to identify and verify beneficial owners, understand customer relationships, and monitor for suspicious activity.

The four pillars of CDD

PillarRequirementSanctions connection
Customer identification (CIP)Verify customer identityScreen against OFAC SDN at onboarding
Beneficial ownershipIdentify 25%+ ownersScreen each beneficial owner against SDN
Understand relationshipProfile expected activityIdentify sanctions risk factors
Ongoing monitoringMonitor transactionsRescreen against updated SDN list

Step-by-step process

Step 1: Collect customer identity documents.

Step 2: Screen customer name and all beneficial owners against OFAC SDN, EU, UN lists.

Step 3: Assign a risk rating based on customer type, geography, and business model.

Step 4: Set up ongoing monitoring: transaction screening, periodic rescreening, alert investigation.

For AI agents: Automate CDD by calling SanctionsAI at onboarding and before each transaction.

Screen your agent's next payment

Check any wallet, name, or entity against OFAC, EU, UN sanctions lists in real time.

Free wallet checker

Frequently Asked Questions

What is the FinCEN CDD Rule?
31 CFR 1010.230 requires identifying and verifying beneficial owners, understanding customer relationships, and conducting ongoing monitoring.
How often should I rescreen customers?
High-risk: quarterly. Medium: semi-annually. Low: annually. All after major SDN updates.
What is enhanced due diligence (EDD)?
EDD applies to high-risk customers: additional verification, source of funds, adverse media, senior approval.
Can CDD be automated?
Yes. Identity verification, sanctions screening, and risk rating can be automated via APIs.

← Back to how-to · SanctionsAI