Customer customer due diligence refers to the set of measures implemented by professionals subject to AML-CFT obligations AML-CFT identify their customers, understand the nature of their activities, and monitor their transactions over time. The intensity of these measures depends on the level of risk associated with each business relationship.
In practice, these systems are generally organized into three levels: simplified vigilance measures when the risk is low, the common baseline for vigilance applied to routine relationships, and enhanced due diligence measures when the risk is high. Certain situations provided for by regulations, particularly the status of a politically exposed person, also trigger specific additional due diligence measures.
At AP Solutions IO, we work daily with compliance teams that need to define these measures, integrate them into their procedures, and maintain the documentation needed to justify their decisions. The challenge lies less in the theoretical understanding of the different levels of vigilance than in their operational application, reassessment, and traceability in the event of an audit.
How can we tailor our vigilance to the level of risk?
The simplified due diligence measures may be implemented when a documented assessment concludes that there is a low risk of money laundering or terrorist financing. They allow for adjustments to the scope, frequency, or methods of controls, without interrupting customer monitoring.
The common due diligence framework, sometimes referred to as standard due diligence in internal procedures, includes identifying the customer and their beneficial owner, understanding the purpose of the business relationship, and monitoring the transactions carried out.
The enhanced due diligence measures apply when the business relationship, product, or transaction presents a high risk. The specific requirements depend on the identified factors and may include additional information, more frequent reviews, or closer monitoring of transactions.
The alert level is based on a documented risk classification. This classification must be updated whenever new information changes the exposure associated with the business relationship.
What is customer due diligence?
Customer due diligence is the operational implementation of the risk-based approach to AML-CFT. It begins before a business relationship is established and continues throughout the duration of that relationship.
It includes, in particular:
- customer identification and identity verification;
- identification of the beneficial owner, where applicable;
- an understanding of the purpose and nature of the business relationship;
- the collection of information consistent with the reported business activity;
- monitoring of completed operations;
- regularly updating the available information.
The KYC, or Know Your Customer, does not refer solely to the verification performed when a business relationship begins. It refers to an ongoing process of understanding the customer, updating their information, and monitoring the consistency of their transactions.
Organizations, institutions, and professionals subject to AML-CFT obligations AML-CFT tailor their systems to their business activities, their client base, the products they offer, the distribution channels they use, and the geographic areas to which they are exposed.
What is the connection between customer due diligence and a risk-based approach?
The level of vigilance is based primarily on the assessment of the risk associated with the business relationship. A reliable classification system allows for the most thorough controls to be focused on the most sensitive situations, while avoiding the imposition of excessive due diligence on relationships that pose a limited risk.
This approach is based on several categories of criteria:
- the customer's profile and activity;
- its legal form and ownership structure;
- the identity of its Beneficial Owners
- the products or services used;
- the amounts and nature of the transactions;
- the channel for establishing contact;
- geographic exposure;
- international sanctions;
- whether the individual is a PEP
- adverse information from open sources;
- the transactional behavior observed.
Our guide to the risk-based approach to AML-CFT explains how to classify a business relationship as low, standard, or high risk.
This classification must remain consistent with the organization’s AML-CFT risk map for the organization. A customer rating cannot be soundly justified if it is based on criteria that are disconnected from the risks specific to the business, products, or geographic areas in question.

Continuous vigilance throughout the business relationship
Vigilance efforts should not focus solely on the initiation of the relationship. The information gathered must be updated and cross-checked against actual operations.
Several events may trigger a reassessment of the risk:
- a change in business activity or legal form;
- a change in the shareholder structure or Beneficial Owners
- a new residence in a sensitive area;
- a significant change in financial flows;
- an unusual operation;
- an alert generated by transaction monitoring;
- the imposition of a sanction, the designation as PEP the disclosure of significant adverse information.
Each relevant event must trigger an appropriate analysis, without systematically waiting for the next scheduled review date. The decision made, the reasons for it, and the information used must be retained so that the decision-making process can be reconstructed.
Simplified Vigilance Measures: What Requirements Must Be Met?
The simplified due diligence measures may be applied when the risk of money laundering and terrorist financing is assessed as low or when the customer relationship falls into a regulatory category considered to be at low risk.
The low level of risk must be established based on a prior, documented analysis. A simplified measure cannot, therefore, be chosen solely to reduce the administrative burden or speed up the establishment of a business relationship.
How can we streamline inspections without compromising vigilance?
When the conditions are met, the regulated entity may adjust certain aspects of its system, including:
- the amount of additional information collected;
- the frequency of updates;
- the time at which certain checks are performed;
- the extent of the resources allocated to oversight;
- the intensity of the relationship.
The measures selected must remain proportionate to the identified level of risk. The organization must also maintain sufficient capacity to detect unusual transactions or changes in a customer’s profile.
A low risk must remain subject to reassessment
A relationship classified as low risk may change. A change in business activity, the arrival of a new beneficial owner, or the emergence of cash flows that are inconsistent with the available information may call the initial classification into question.
The application of simplified measures must therefore remain reversible. When new factors arise, the level of vigilance must be reassessed and the controls adjusted accordingly.
Furthermore, even a suspicion of money laundering or terrorist financing precludes the continued application of simplified measures based on a low level of risk.
The Common Framework for Due Diligence Applicable to Business Relationships
The common framework, often referred to as “standard due diligence” in internal procedures, corresponds to the due diligence measures applied to the majority of business relationships that present neither a risk low enough to warrant simplified measures nor a high risk requiring specific enhancements.
It consists of three main dimensions:
- customer identification and identity verification;
- knowledge of the purpose and nature of the business relationship;
- monitoring the consistency of operations throughout the duration of the relationship.

Identification of the customer and the beneficial owner
The regulated entity must collect the information necessary for identify the customer, and then verify its accuracy using reliable documents or sources.
When the customer acts on behalf of a legal entity or has a holding structure, the identification of the beneficial owner allows for the identification of the natural person(s) who directly or indirectly control the entity.
Simply collecting a form of identification is therefore not enough to consider the process complete. The information must be analyzed as a whole and viewed in the context of the business relationship.
Understanding the Purpose and Nature of the Relationship
Before establishing a relationship, the organization must understand why the customer wants to use the product or service being offered.
This analysis may cover:
- professional or economic activity;
- the expected operations;
- the amounts typically considered;
- the foreseeable source and destination of the funds;
- the geographic areas concerned;
- the frequency of use of the service.
These elements constitute the framework of customer knowledge against which future transactions can be evaluated.
Monitoring and Updating Information
The frequency of reviews depends on the risk classification and internal procedures. A relationship with a higher risk level generally requires more frequent monitoring than a relationship with few aggravating factors.
However, the periodic review does not replace the reassessment triggered by a significant event. Any new inconsistency must be analyzed as soon as it is detected.
Enhanced Vigilance Measures: In What Situations Do They Apply?
The enhanced due diligence measures apply when the risk posed by a business relationship, a product, or a transaction is assessed as high.
This assessment may result, in particular, from a combination of several factors:
- a legal structure that is complex or difficult to understand;
- an activity that is particularly at risk;
- Beneficial Owners who are Beneficial Owners to identify;
- exposure to certain sensitive jurisdictions;
- unusual or complex international flows;
- persistent inconsistencies in the documentation;
- significant adverse information;
- transactional behavior that deviates from the expected profile.
A single factor does not always result in the same rating, depending on the context. The analysis must take into account the business relationship as a whole, while taking into account situations in which regulations require specific additional measures.
What measures should be implemented in the event of a high risk?
Depending on the risks identified, enhanced due diligence may include:
- collecting additional information about the customer;
- a more thorough review of the detention facility;
- an analysis of the origin of the assets or funds;
- a more detailed explanation of certain transactions;
- more frequent updates;
- closer monitoring of transactions;
- additional inspections by authorized individuals or agencies;
- greater emphasis on preserving the factors that led to the decision.
The measures selected must be tailored to the identified risk factors. An accumulation of controls unrelated to the client’s exposure complicates processes without necessarily improving the system’s effectiveness.
PEP Mandatory Supplementary Measures
When a customer, a beneficial owner, or, as the case may be, a closely related person is classified as a politically exposed person, specific additional measures must be applied.
These include, in particular:
- a decision to establish or maintain the relationship made by an authorized person or body;
- investigating the origin of the assets and the funds involved;
- enhanced monitoring of the business relationship.
The intensity of this monitoring must be tailored to the risk profile. The operational arrangements are determined based on the position held, the country in question, the products and services used, the ownership structure, and the nature of the operations.
The PEP status must therefore be distinguished from a simple optional factor included in an overall score. It triggers a set of additional measures, to which further due diligence may be added if the overall assessment concludes that there is a high risk.
Unusual Procedures: When Should an In-Depth Evaluation Be Conducted?
A transaction that is particularly complex, involves an unusually large amount, or lacks an economic justification or apparent lawful purpose must be subject to an enhanced review.
This review is intended, in particular, to gather information on:
- the source of the funds;
- their destination;
- the purpose of the transaction;
- the identity of the beneficiary;
- the consistency of the transaction with the customer's profile.
The enhanced review focuses first on the transaction in question. Its findings may then lead to a change in the customer’s classification and to increased monitoring of the entire business relationship.
This distinction prevents a one-time atypical transaction from being mistakenly classified as high risk for the entire relationship.
Enhanced Due Diligence: How Can We Strengthen Our Checks?
The term EDD, which stands for Enhanced Due Diligence, refers to the in-depth due diligence procedures carried out in response to high exposure. The scope of these procedures depends on the client’s profile, the third parties involved, and the nature of the transactions.
In a relationship involving suppliers, intermediaries, or a chain of partners, controls must also provide insight into the relationships between the various parties. Our article on due diligence and KYS outlines the key mechanisms for ensuring reliable knowledge of third parties and suppliers.
Effective enhanced due diligence is closely linked to risk mapping, internal procedures, and the validation processes defined by governance. It must also produce information that is sufficiently detailed to explain the controls implemented and the decisions made.
How can the level of vigilance applied be justified?
The effectiveness of a monitoring system depends as much on the quality of the checks as on the ability to demonstrate it.
In the event of an inspection, the organization must be able to present:
- the date the relationship was classified;
- the risk factors taken into account;
- the weighting rules used;
- the alert level selected;
- any internal approvals;
- the measures implemented;
- events that led to a revaluation;
- a history of the changes and the reasons behind them.
The competent authority varies depending on the sector in question. It may include the ACPR, the AMF, the DGCCRF, or a professional regulatory body. Tracfin acts as France’s financial intelligence unit, particularly in receiving and analyzing reports of suspicious activity.
An organization based on scattered files, implicit rules, or poorly documented decisions makes it more difficult to provide justification. Teams are then forced to reconstruct decisions—some of which may be old—after the fact, with the risk of inconsistencies between the theoretical procedure and the controls actually carried out.
Structuring Risk Scoring with AP Scoring
This need for traceability guided the development ofAP Scoring, the risk scoring solution offered by AP Solutions IO.
AP Scoring enables the evaluation of business relationships based on more than 90 configurable criteria. The solution can incorporate data from KYC and KYB processes, as well as signals related to sanctions, PEP, adverse information, geographic exposure, the product sold, and its acquisition channel…
His approach Glass Box aims to make the scoring process transparent and traceable. Teams can identify the criteria applied, understand their impact on the result, and retain the information needed to justify the decision.
The tool provides a rating method and information to aid decision-making. Responsibility for classification remains with the subject entity, in accordance with the governance rules, procedures, and delegations of authority it has established.
The founders of AP Solutions IO AML-CFT drawn AML-CFT their more than fifteen years of experience in the fields of compliance and AML-CFT to help shape this approach. The solutions are developed by a French RegTech company and the processed data is hosted in France.
Objectify, document, and review customer monitoring
An effective monitoring system relies on a clear classification system, proportionate measures, and sufficient traceability to reconstruct each decision.
Simplified measures apply to relationships that are demonstrated to be low-risk. The common framework governs customer identification, due diligence, and ongoing monitoring. Enhanced measures involve more thorough controls when exposure is high, while certain regulatory situations require specific additional due diligence procedures.
When pricing is still based on scattered files or insufficiently formalized decisions, consulting with a compliance expert can help identify the most critical vulnerabilities and assess how AP Scoring can structure the classification, review, and justification of vigilance levels.

