HomeBlogCompliance & AMLCustomer due diligence: a practical guide for 2026

Customer due diligence: a practical guide for 2026

With the AMLR taking effect in 2027 and the package of AMLA technical standards on the way, customer due diligence remains the operational core of anti-money laundering compliance for banks, fintechs, insurers and professionals. It is not a filing formality: it is the process that determines whether a company really knows who it is serving, and whether it can explain that to an inspector. Here is a practical guide to what it involves today and how to structure it efficiently.

What is customer due diligence (CDD)

Customer Due Diligence (CDD) is the set of activities through which an obliged entity identifies the customer, verifies their identity on the basis of reliable documents and sources, identifies the beneficial owner and gathers information on the purpose and nature of the relationship. In Italy, the reference legislation remains Legislative Decree 231/2007, which transposes the EU anti-money laundering directives, while at European level the new AMLR will harmonize the rules in a regulation directly applicable in all Member States.

The three levels of due diligence

The rules provide for three levels of intensity, to be calibrated to the actual risk of the relationship:

  • Simplified due diligence: for low-risk relationships, with reduced but still documented checks.
  • Standard due diligence: the baseline, with identification, verification of the beneficial owner and monitoring of the relationship.
  • Enhanced due diligence (EDD): mandatory for high-risk customers, PEPs, business involving high-risk countries or opaque corporate structures, with in-depth checks on source of funds and source of wealth.

The risk-based approach

The guiding principle is the risk-based approach: the intensity of due diligence is not the same for everyone, but proportionate to the actual risk of the customer, the product, the distribution channel and the geographic area involved. This means that every obliged entity must have its own risk assessment methodology, documented and kept up to date, capable of justifying why a customer was classified as low, medium or high risk. It is a choice that AMLA, in its direct and indirect supervisory role, will scrutinize ever more closely in the coming years.

KYC and KYB: the scope widens

While KYC (Know Your Customer) concerns natural persons, KYB (Know Your Business) is its extension to corporate entities: reconstructing the chain of control, identifying the real beneficial owner behind multi-layered structures and verifying that the corporate customer is not hiding sanctioned parties or parties with high reputational risk. With the rise of complex, multi-jurisdictional corporate structures, KYB has become an essential part of robust CDD, and it fits naturally with beneficial owner monitoring.

What to do: an operational checklist

  • Update the company’s risk assessment methodology and the classification of existing customers.
  • Check that processes clearly distinguish between simplified, standard and enhanced due diligence, with written and traceable criteria.
  • Automate document collection and screening against sanctions lists, PEP lists and adverse media to reduce manual errors and false positives.
  • Set up a complete audit trail of every decision made during due diligence, in view of AMLA supervision.
  • Train staff regularly on red flags and on the cases that require CDD to be updated over time (not just at onboarding).

How AegisX helps you

Monitus automates AML screening, risk assessment and ongoing customer monitoring, reducing false positives and keeping an audit trail that is always ready for supervisors. For reconstructing the chain of control and identifying the beneficial owner in the most complex corporate structures, Lensis supports the compliance team with fast, documented analysis. Want to find out how to make your customer due diligence more efficient and inspection-proof? Contact us for a demo.

This article is for informational purposes only and does not constitute legal or compliance advice.