Scope, ownership, and approval
Name the legal entity, products, customer types, branches, outsourcing arrangements, policy owner, approval body, and review cycle.
Copy a practical abridged customer due diligence policy for EU onboarding teams, then upgrade to the full €49 Starter Kit when you need the board-ready version, checklist, GDPR guide, vendor scorecard, and reusable-KYC explainer.
Target user
EU compliance, ops, and fintech founders
Best for
First written CDD/KYC operating standard
Use with
Local counsel, MLRO review, and risk assessment
Policy essentials
In 2026, most firms are still operating through national AML/CFT rules based on the EU AMLD framework while preparing for the newer EU AML package. A useful policy should translate those obligations into auditable onboarding decisions, not just cite regulations.
Name the legal entity, products, customer types, branches, outsourcing arrangements, policy owner, approval body, and review cycle.
Define what data you collect for individuals, companies, directors, authorised representatives, UBOs, trusts, and persons acting on behalf of a customer.
Set acceptable evidence sources, document checks, registry checks, remote onboarding controls, liveness or fraud controls, and when manual review is required.
Record why the customer wants the relationship, expected products, funding source, transaction types, countries, volume, and business rationale.
Define risk factors, scoring, low/medium/high bands, simplified due diligence eligibility, enhanced due diligence triggers, and senior approval rules.
Specify who is screened, when screening happens, which lists are used, how false positives are cleared, and how true matches or PEPs are escalated.
Set review cadence, event-driven refresh triggers, rescreening frequency, suspicious-activity escalation, and exit criteria for unacceptable risk.
Map each KYC data point to purpose, lawful basis, system owner, access role, retention period, deletion workflow, processor, and transfer safeguards.
Copy/paste abridged template
This is intentionally abridged so you can start quickly. Replace every bracketed placeholder, align it to your licence, member-state law, customer risk assessment, products, vendors, and approval process, then have counsel or your MLRO review it before relying on it.
# Customer Due Diligence (CDD) Policy — abridged template Owner: [MLRO / Compliance Lead] Approved by: [Board / Senior Management] Effective date: [DD Month 2026] Applies to: [Company legal name], products, branches, agents, and outsourced onboarding providers Review cycle: At least annually and after material product, risk, vendor, regulatory, or geographic changes 1. Policy statement [Company] operates a risk-based CDD programme to identify and verify customers, understand the purpose and intended nature of each relationship, identify and verify beneficial owners where applicable, screen relevant parties for sanctions and politically exposed person exposure, assign a documented risk rating, and monitor the relationship on an ongoing basis. 2. Customer acceptance [Company] will not onboard or continue a relationship where identity cannot be verified, ownership/control cannot be understood, a sanctions true match remains unresolved, evidence is false or materially inconsistent, the customer refuses mandatory evidence without an approved exception, or the risk exceeds [Company]'s risk appetite. 3. Minimum standard CDD Before activation, the onboarding team must: - Collect required customer profile data and evidence for the customer type. - Verify identity, legal existence, authority to act, and beneficial ownership/control where relevant. - Understand expected product use, funding source, transaction profile, geography, and business rationale. - Screen the customer and relevant connected parties for sanctions, PEP status, and adverse media according to policy. - Record the risk rating, evidence reviewed, analyst decision, approvals, exceptions, and review cadence. 4. Enhanced due diligence triggers EDD is required where policy-defined higher-risk factors are present, including PEP exposure, high-risk geography, complex or opaque ownership, credible adverse media, unusual source of funds or wealth, higher-risk products, weak non-face-to-face safeguards, unresolved identity mismatches, or other risk indicators approved by the MLRO. 5. GDPR and records KYC data must be collected only for defined AML, fraud, legal, security, or operational purposes. Each data category must have a lawful basis, retention period, access rule, system owner, and deletion workflow. Copies outside the system of record must be avoided or deleted when no longer needed.
Who needs it
A written CDD policy helps turn regulatory expectations into repeatable product, compliance, and operations behaviour.
Use it safely
Your policy should reflect what you actually sell, where customers are located, how funds move, what third parties touch the onboarding flow, and which risks your business accepts or prohibits.
Keep evidence practical: enough detail for audit, supervision, internal escalation, and repeatability, but not so much that analysts are pushed into hoarding unnecessary passport images, screenshots, or notes.
Upgrade when you need the full file
The €49 kit includes the full CDD policy template plus four more implementation assets, delivered instantly as editable Markdown and CSV files.
Buy the Starter Kit — €49Secure checkout · Instant delivery · EU VAT may apply