Due Diligence do Cliente (CDD)
-
Adicione-nos como sua fonte preferida.
- 01 What Does CDD Stand For? (CDD Full Form and Meaning)
- 02 O que é Due Diligence do Cliente?
- 03 CDD vs. KYC: Qual a diferença?
- 04 Por que o CDD é importante?
- 05 The 4 Customer Due Diligence Requirements (The CDD Rule)
- 06 Etapas principais no processo de CDD
- 07 Quando é necessário o CDD?
- 08 Levels of Customer Due Diligence: SDD, CDD, and EDD
- 09 Due Diligence Aprimorada (EDD) e Monitoramento Automatizado
- 10 Beneficial Ownership and the 25% Rule
- 11 Quem precisa de CDD?
- 12 Customer Due Diligence in Banking
- 13 Record Keeping and Retention Requirements
- 14 Tendências globais de CDD
- 15 Conclusão:
- 16 Perguntas frequentes
Com a expansão dos serviços financeiros e o aumento das transações digitais, as empresas, especialmente as dos setores financeiro, fintech e de comércio eletrônico, devem permanecer vigilantes contra crimes como lavagem de dinheiro e financiamento do terrorismo. Uma das estratégias fundamentais utilizadas globalmente para combater esses riscos é a Due Diligence do Cliente (CDD).
What Does CDD Stand For? (CDD Full Form and Meaning)
CDD stands for Customer Due Diligence. The full form of CDD is Customer Due Diligence, and the term is used across banking, finance, fintech, and other regulated industries. In banking, the full form of CDD is the same: Customer Due Diligence.
The abbreviation CDD is sometimes used with other meanings in unrelated fields. In the context of banking, KYC, and Conformidade com AML, however, CDD always means Customer Due Diligence.
O que é Due Diligence do Cliente?
A Due Diligence do Cliente é o processo de obter informações de identidade de um cliente, verificar sua identidade e avaliar o risco potencial que ele possa representar. Normalmente, envolve a coleta e verificação de informações pessoais como:
- Nome legal completo
- Endereço residencial
- E-mail e número de telefone
- Data de nascimento
- Documento de identificação emitido pelo governo (ex.: RG, CPF)
Para empresas, esses requisitos tendem a ser diferentes e geralmente incluem:
- Nome da empresa e dados de registro
- Informações de incorporação
- Informação sobre Ultimate Beneficial Ownership (UBOs)
- Detalhes sobre diretores, acionistas e principais executivos.
Esse processo estruturado constitui uma camada crucial de proteção contra a lavagem de dinheiro e o financiamento do terrorismo, permitindo que as empresas detectem e impeçam fraudes antes que elas comecem.
CDD vs. KYC: Qual a diferença?
Embora seja comum que sejam usados de forma intercambiável, Conheça seu cliente (KYC) and Customer Due Diligence are distinct but related elements of compliance. KYC usually refers to just the first steps of identifying a customer during onboarding. On the other hand, CDD goes further and assesses the risk associated with that customer throughout the relationship.
A Due Diligence do Cliente (CDD) é essencial para garantir os padrões de KYC (Conheça Seu Cliente) e ajuda as empresas a irem além do simples processo de verificação. Verificação de identificação permitindo-lhes monitorar mudanças de comportamento, padrões de transação ou outros indicadores de risco ao longo do tempo.
Por que o CDD é importante?
Um CDD eficaz é vital porque garante:
- Conformidade Regulatória: Global regulations from institutions like the Força-Tarefa de Ação Financeira (GAFI), the EU’s Anti-Money Laundering Authority (AMLA), and national regulators like the U.S.’s Rede de Execução de Crimes Financeiros (FinCEN) mandate CDD as part of Anti-Money Laundering frameworks.
- Mitigação de risco: CDD helps detect high-risk individuals or entities before they cause damage both within and outside of an organization. This includes pessoas politicamente expostas (PEPs), individuals with criminal backgrounds, or those involved in illicit finances.
- Confiança e Segurança: By understanding and verifying their customers properly, organizations can foster trust and deliver safer services with confidence.
The 4 Customer Due Diligence Requirements (The CDD Rule)
Regulatory frameworks worldwide, including the FinCEN CDD Rule in the United States, formalise customer due diligence into four core requirements, sometimes called the new customer due diligence rule. The four CDD requirements are:
- Identify and verify the customer: Collect identifying details and confirm them against reliable, independent sources such as official documents and trusted databases.
- Identify and verify beneficial owners: For legal-entity customers, identify and verify the individuals who ultimately own or control the business, so hidden risk cannot be masked behind a corporate structure.
- Understand the nature and purpose of the relationship: Determine why the customer wants the account or service, and their expected activity, to build an accurate risk profile.
- Conduct ongoing monitoring: Continuously monitor activity against the expected profile, keep information current, and report suspicious activity to the relevant authority.
Etapas principais no processo de CDD
O processo de CDD geralmente envolve três fases principais:
1. Coleção de dados
As organizações começam por coletar informações de identificação do cliente no início do relacionamento. Isso geralmente inclui documentação, dados biométricos ou verificação de identidade digital, especialmente em cenários remotos ou internacionais.
2. Verificação e Triagem
Collected data is verified using databases, government records, or automated ID verification systems. The information is also screened against international listas de sanções, PEP lists, and mídia adversa reports to identify any red flags.
3. Monitoramento Contínuo
É aqui que a CDD (Due Diligence do Cliente) vai além das verificações iniciais de KYC (Conheça Seu Cliente). As organizações monitoram continuamente as transações e o comportamento para detectar anomalias como:
- Tamanhos ou frequências de transações incomuns
- Transferências para jurisdições de alto risco
- Utilização de métodos de pagamento anônimos
- Alterações repentinas e significativas nos perfis de usuário ou na documentação.
Quando é necessário o CDD?
O CDD não é um processo pontual: aplica-se em vários pontos ao longo do Ciclo de vida do cliente, incluindo:
- At Onboarding: To verify new customers and assess their risk to the organization before providing services.
- During High-Value or Suspicious Transactions: To ensure transparency and legality, particularly when the origin of the funds is unclear.
- Revisão periódica: To update out-of-date records, especially for long-term customers whose risk profile may have changed.
- Trigger-Based Reviews: Initiation when suspicious behavior is detected or when regulatory requirements change.
Levels of Customer Due Diligence: SDD, CDD, and EDD
Customer due diligence is not one-size-fits-all. It operates on a spectrum, with the depth of checks matched to the level of risk. A risk-based approach applies one of three levels (SDD, Standard CDD, and EDD) to each customer:
| Nível | Quando se aplica | O que envolve |
| Due Diligence Simplificada (SDD) | Low-risk customers and products | Reduced checks, often identification with limited verification |
| CDD padrão | The default for most customers | Full identity verification, risk assessment, and ongoing monitoring |
| Due Diligence aprimorada (EDD) | High-risk customers, such as PEPs or high-risk jurisdictions | Deeper information, source of funds and wealth checks, closer monitoring |
Due Diligence Aprimorada (EDD) e Monitoramento Automatizado
Quando um cliente ou transação apresenta um risco maior, seja devido à localização, histórico ou tipo de negócio, Due Diligence aprimorada (EDD) é acionado. A Due Diligence Aprofundada (EDD) investiga mais a fundo a identidade do cliente, muitas vezes exigindo documentos adicionais, entrevistas diretas ou investigações de terceiros.
Atualmente, as ferramentas automatizadas de conformidade podem sinalizar atividades suspeitas e permitir o monitoramento contínuo em tempo real. Essas tecnologias utilizam IA e aprendizado de máquina para rastrear padrões de comportamento em grandes conjuntos de dados e alertar as equipes de conformidade sobre inconsistências, possibilitando respostas rápidas e reduzindo erros humanos.
Beneficial Ownership and the 25% Rule
One of the hardest parts of CDD for business customers is seeing past the corporate structure to the real people in control. This is the job of beneficial ownership checks.
A beneficial owner, often called an ultimate beneficial owner (UBO), is the natural person who ultimately owns or controls a legal entity. Under common rules such as the FinCEN CDD Rule, a business must identify any individual who owns 25 percent or more of an entity, plus at least one individual who exercises significant control, for example, a senior manager or director.
Layered or cross-border ownership can hide risk behind shell companies and nominee arrangements. Verifying UBOs against official registries, then screening them against sanctions and PEP lists, closes that gap.
Quem precisa de CDD?
A Due Diligence do Cliente é vital para manter a conformidade em uma ampla gama de setores, especialmente aqueles que lidam com informações financeiras ou dados sensíveis. Os principais setores incluem:
- Serviços Bancários e Financeiros: CDD is a regulatory mandate for traditional banks, credit unions, neobanks, and investment firms.
- Trocas de criptomoedas: Regulators are tightening KYC/CDD requirements for crypto platforms to prevent misuse. The biggest piece of legislation comes from the EU with the Regulamentação de Mercados de Criptoativos (MiCA).
- Comércio eletrônico e marketplaces: Verifying the identities of buyers and sellers helps reduce fraud and protect consumers.
- Agências Imobiliárias: Property purchases are frequently used to launder illicit funds, making CDD critical to real estate transactions.
- Seguradoras: Ensuring that policyholders are legitimate minimizes the risk of claims fraud or insurance-based money laundering.
Customer Due Diligence in Banking
Banking is the most heavily regulated sector for customer due diligence. Banks and other financial institutions must apply full CDD at onboarding and monitor customers continuously across their accounts and transactions. CDD in banking is a legal requirement, not an optional control.
When should a bank apply customer due diligence?
Banks must apply CDD when:
- Onboarding a new customer or opening a new account
- Carrying out occasional or high-value transactions above regulatory thresholds
- There is any suspicion of money laundering or terrorist financing
- There are doubts about the accuracy of previously obtained identification data
Customer due diligence requirements for financial institutions include verifying identity, identifying beneficial owners, assessing risk, and keeping auditable records. Higher-risk banking customers, such as correspondent banks or clients in high-risk jurisdictions, require enhanced due diligence.
Record Keeping and Retention Requirements
Compliance does not end once a customer is verified. Regulations require businesses to document and securely store the evidence behind every CDD decision, so activity can be reconstructed for audits and investigations. Under most frameworks, CDD records must be retained for at least five years after the relationship ends.
Records that must be kept include:
- Customer identification and verification data
- Transaction records and account files
- Risk assessments and the rationale for decisions
- Any suspicious activity reports filed
- Business correspondence relating to the relationship
Because this information is sensitive, it must be stored securely and handled in line with data protection laws such as the GDPR.
Tendências globais de CDD
Nos últimos anos, a Due Diligence do Cliente passou por uma rápida transformação digital. As principais tendências incluem:
- KYC biométrico e por vídeo: Increasingly used for real-time, remote verification in a secure and scalable manner.
- Integrated AML/KYC Platforms: More businesses are adopting unified solutions to manage compliance more efficiently.
- Regulatory Convergence: Countries are aligning their AML/CTF frameworks to be more in line with Recomendações do GAFI, making CDD more standard around the globe.
- AI-Driven Risk Analysis: Artificial intelligence is enhancing risk scoring by analyzing user behavior, transaction history, and environmental factors in real time.
Conclusão:
Para se manter à frente dos crimes financeiros, é preciso mais do que apenas verificar a identidade de um cliente; é necessário um entendimento mais profundo e contínuo de quem ele é e como se comporta ao longo do tempo. A Due Diligence do Cliente oferece às organizações uma maneira estruturada e proativa de proteger suas operações, reduzindo a exposição a penalidades regulatórias e mantendo a integridade em um cenário digital cada vez mais complexo.
Com a evolução das tecnologias e o endurecimento das regulamentações, a Due Diligence do Cliente (CDD) continuará sendo um pilar central nos esforços de conformidade global. Seja uma startup fintech verificando usuários em diferentes países ou um banco tradicional monitorando clientes de longa data, incorporar medidas robustas de due diligence às operações diárias é essencial para o crescimento sustentável e para a segurança do relacionamento com o cliente.
Bring your entire CDD process into one workflow
From identity checks and beneficial ownership to risk scoring and enhanced due diligence, a unified due diligence form can handle every step in a single session, then keep monitoring customers long after onboarding.
Perguntas frequentes
What does CDD stand for?
CDD stands for Customer Due Diligence. Its full form is the same across banking, finance, and compliance: Customer Due Diligence.
What is CDD in banking?
In banking, CDD (Customer Due Diligence) is the set of checks a bank performs to verify a customer’s identity, understand the purpose of the account, and assess the risk of money laundering before and during the relationship.
What are the 4 customer due diligence requirements?
The four CDD requirements are: identify and verify the customer, identify and verify beneficial owners, understand the nature and purpose of the relationship, and conduct ongoing monitoring with suspicious activity reporting.
What is the CDD rule?
The CDD Rule is a regulation, introduced by FinCEN in the United States, that formalises customer due diligence into four core requirements, including the obligation to identify beneficial owners of legal-entity customers.
What is CDD in KYC?
Within a Know Your Customer (KYC) program, CDD is the due diligence layer that assesses how much risk a verified customer represents and how closely they should be monitored.
What is the difference between CDD and KYC?
KYC is the broader program of identifying and verifying customers. CDD is the risk-assessment layer inside KYC that evaluates and monitors customer risk.
What is client due diligence?
Client due diligence is another name for customer due diligence: the process of verifying a client’s identity and assessing the risk they present to the business.
When should a bank apply customer due diligence?
A bank should apply customer due diligence when onboarding a new customer, carrying out occasional or high-value transactions above thresholds, when it suspects money laundering, or when it doubts previously obtained identification data.
What documents are required for CDD?
Typical CDD documents include a government-issued identity document, proof of address, and, for businesses, incorporation documents, registration details, and beneficial ownership information.
How long must CDD records be kept?
Most frameworks require CDD records, including identification data, transaction records, and correspondence, to be retained for at least five years after the relationship ends.
What is the beneficial ownership threshold for CDD?
Under common rules such as the FinCEN CDD Rule, a business must identify any individual owning 25 percent or more of a legal entity, plus at least one individual with significant control.
O que é a due diligence contínua do cliente?
Ongoing customer due diligence is the continuous monitoring of a customer’s transactions and risk profile after onboarding, including re-screening against updated watchlists and reassessing risk when circumstances change.
