Free EU compliance resource

Free CDD / KYC Policy Template (EU, 2026)

Copy a practical abridged customer due diligence policy for EU onboarding teams, then upgrade to the full €49 Starter Kit when you need the board-ready version, checklist, GDPR guide, vendor scorecard, and reusable-KYC explainer.

Target user

EU compliance, ops, and fintech founders

Best for

First written CDD/KYC operating standard

Use with

Local counsel, MLRO review, and risk assessment

Policy essentials

What a CDD/KYC policy must cover under EU AML rules

In 2026, most firms are still operating through national AML/CFT rules based on the EU AMLD framework while preparing for the newer EU AML package. A useful policy should translate those obligations into auditable onboarding decisions, not just cite regulations.

Scope, ownership, and approval

Name the legal entity, products, customer types, branches, outsourcing arrangements, policy owner, approval body, and review cycle.

Customer and beneficial-owner identification

Define what data you collect for individuals, companies, directors, authorised representatives, UBOs, trusts, and persons acting on behalf of a customer.

Verification standards

Set acceptable evidence sources, document checks, registry checks, remote onboarding controls, liveness or fraud controls, and when manual review is required.

Purpose and expected activity

Record why the customer wants the relationship, expected products, funding source, transaction types, countries, volume, and business rationale.

Risk-based CDD, SDD, and EDD

Define risk factors, scoring, low/medium/high bands, simplified due diligence eligibility, enhanced due diligence triggers, and senior approval rules.

PEP, sanctions, and adverse media screening

Specify who is screened, when screening happens, which lists are used, how false positives are cleared, and how true matches or PEPs are escalated.

Ongoing monitoring and periodic review

Set review cadence, event-driven refresh triggers, rescreening frequency, suspicious-activity escalation, and exit criteria for unacceptable risk.

Records, retention, and GDPR controls

Map each KYC data point to purpose, lawful basis, system owner, access role, retention period, deletion workflow, processor, and transfer safeguards.

Copy/paste abridged template

Free CDD policy template snippet

Markdown · editable

This is intentionally abridged so you can start quickly. Replace every bracketed placeholder, align it to your licence, member-state law, customer risk assessment, products, vendors, and approval process, then have counsel or your MLRO review it before relying on it.

# Customer Due Diligence (CDD) Policy — abridged template

Owner: [MLRO / Compliance Lead]
Approved by: [Board / Senior Management]
Effective date: [DD Month 2026]
Applies to: [Company legal name], products, branches, agents, and outsourced onboarding providers
Review cycle: At least annually and after material product, risk, vendor, regulatory, or geographic changes

1. Policy statement
[Company] operates a risk-based CDD programme to identify and verify customers, understand the purpose and intended nature of each relationship, identify and verify beneficial owners where applicable, screen relevant parties for sanctions and politically exposed person exposure, assign a documented risk rating, and monitor the relationship on an ongoing basis.

2. Customer acceptance
[Company] will not onboard or continue a relationship where identity cannot be verified, ownership/control cannot be understood, a sanctions true match remains unresolved, evidence is false or materially inconsistent, the customer refuses mandatory evidence without an approved exception, or the risk exceeds [Company]'s risk appetite.

3. Minimum standard CDD
Before activation, the onboarding team must:
- Collect required customer profile data and evidence for the customer type.
- Verify identity, legal existence, authority to act, and beneficial ownership/control where relevant.
- Understand expected product use, funding source, transaction profile, geography, and business rationale.
- Screen the customer and relevant connected parties for sanctions, PEP status, and adverse media according to policy.
- Record the risk rating, evidence reviewed, analyst decision, approvals, exceptions, and review cadence.

4. Enhanced due diligence triggers
EDD is required where policy-defined higher-risk factors are present, including PEP exposure, high-risk geography, complex or opaque ownership, credible adverse media, unusual source of funds or wealth, higher-risk products, weak non-face-to-face safeguards, unresolved identity mismatches, or other risk indicators approved by the MLRO.

5. GDPR and records
KYC data must be collected only for defined AML, fraud, legal, security, or operational purposes. Each data category must have a lawful basis, retention period, access rule, system owner, and deletion workflow. Copies outside the system of record must be avoided or deleted when no longer needed.

Who needs it

Use this before onboarding real customers

A written CDD policy helps turn regulatory expectations into repeatable product, compliance, and operations behaviour.

  • EU fintech, payments, lending, crypto, brokerage, e-money, or embedded-finance teams preparing for regulated onboarding.
  • Founders and operators buying their first KYC vendor who need an internal policy before launch or bank due diligence.
  • Compliance leads replacing scattered onboarding notes with one board-approved CDD operating standard.
  • Product and operations teams who need the compliance rules translated into buildable onboarding requirements.

Use it safely

A template is not a substitute for your risk assessment

Your policy should reflect what you actually sell, where customers are located, how funds move, what third parties touch the onboarding flow, and which risks your business accepts or prohibits.

Keep evidence practical: enough detail for audit, supervision, internal escalation, and repeatability, but not so much that analysts are pushed into hoarding unnecessary passport images, screenshots, or notes.

Upgrade when you need the full file

Get the complete EU KYC & GDPR Compliance Starter Kit

The €49 kit includes the full CDD policy template plus four more implementation assets, delivered instantly as editable Markdown and CSV files.

Buy the Starter Kit — €49

Secure checkout · Instant delivery · EU VAT may apply

  • Full editable CDD Policy Template
  • KYC Onboarding Checklist
  • GDPR / KYC Data-Handling Guide
  • KYC Vendor Evaluation Scorecard
  • Reusable-KYC Explainer