Customer due diligence best practices for fund managers

Customer due diligence best practices for fund managers

Author: 

The Carta Team

|

Read time: 

14 minutes

Published date: 

October 7, 2026

Learn how customer due diligence works, the different types of CDD, the regulatory requirements you need to follow, and practical steps for building a compliant program.

What is customer due diligence?

Customer due diligence (CDD) is the process fund managers use to verify an investor’s or a deal counterparty’s identity, assess their risk profile, and monitor their activities throughout the relationship. For fund managers and financial institutions, CDD is not an optional risk management exercise. In many jurisdictions, it is a legal requirement under anti-money laundering (AML) regulations, though in the U.S., AML program requirements for most private fund managers are not yet in effect. KYC is its core identification and verification component.

You must conduct CDD before onboarding a new customer or investor, and the obligation continues throughout the duration of the business relationship. The core information you collect includes legal name, address, identification documents, source of funds, business activity, and beneficial ownership.

At its core, CDD helps you answer three questions: Who is this customer? What risk do they present? And has that risk changed over time? If you manage a private fund, your CDD obligations extend to every limited partner (LP) you onboard and every entity you transact with.

How CDD relates to KYC and AML

AML is the overarching regulatory framework designed to prevent money laundering, terrorist financing, and other financial crimes. KYC is the identification and verification process that sits within AML. CDD is the broader set of obligations that includes KYC, adding risk assessment, and ongoing monitoring.

A simple way to understand the hierarchy:

  • AML: The regulatory framework—the legal obligation to prevent financial crime

  • CDD: The full compliance process—encompassing KYC, risk assessment, beneficial ownership, screening, and ongoing monitoring

  • KYC: The identity and verification component—establishing who the customer is

Think of it this way: KYC answers the question, "Who is this person?" CDD answers, "What risk does this person pose, and has that risk changed?" CDD is the broader obligation, beginning with KYC identity checks and goes further, requiring risk assessment, controls and monitoring of the relationship. 

The 2026 AML and KYC guide for asset managers
A clear, jurisdiction-by-jurisdiction view of where the rules sit today—and where LP expectations have already moved beyond them.
Free download

Why customer due diligence matters

CDD protects your fund from three categories of risk.

  • Regulatory risk: Failing to perform adequate CDD can result in significant fines and enforcement actions. In 2025 alone, global penalties for AML, KYC, and CDD violations totaled $3.8 billion. For fund managers, noncompliance can trigger regulatory investigations, restrict your ability to operate, and delay fundraising.

  • Financial crime risk: Without a structured verification and monitoring process, you are more likely to onboard bad actors or process illicit funds,  exposing the fund to civil liability, criminal investigation, and potential clawback of tainted capital. Private funds are increasingly a focus of regulatory scrutiny as enforcement expands beyond traditional banking. FinCEN's 2024 rule extends formal AML obligations to registered investment advisers for the first time, a signal that regulators view the sector as a meaningful vector for financial crime.

  • Reputational risk: A single AML compliance violation can damage your firm's reputation with LPs, regulators, and counterparties. Institutional investors conduct operational due diligence on fund managers, and a history of compliance failures makes fundraising significantly harder.

Types of customer due diligence

The Financial Action Task Force (FATF) requires a risk-based approach to CDD. This means the level of scrutiny you apply should match the risk each customer presents. Compliance frameworks codify this risk-based model across fund structures. There are three main tiers of customer due diligence:

Simplified due diligence

Simplified due diligence applies to low-risk customers where the likelihood of money laundering or terrorist financing is minimal. You still verify identity through background checks, but you can reduce the documentation and monitoring requirements. A publicly traded company listed on a regulated exchange in jurisdictions such as the U.S., UK, EU or other jurisdictions with equivalent AML frameworks is a typical example of a customer that qualifies for simplified due diligence.

Standard due diligence

Standard due diligence is the baseline you apply to most customer relationships. You collect and verify core identity information, confirm the customer's key details, verify its beneficial ownership, and understand the purpose of the business relationship. For fund managers, this is the minimum you perform for every LP at onboarding.

Enhanced due diligence (EDD)

Enhanced due diligence (EDD) applies to higher-risk customers. This includes politically exposed persons (PEP), customers based in jurisdictions subject to sanctions or with weak AML frameworks and entities with unusually complex ownership structures that make it difficult to verify beneficial ownership through standard documentation. Funds with exposure to offshore investors should also review jurisdiction-specific requirements—for example, Cayman Islands KYC/AML rules impose specific EDD obligations on regulated entities domiciled there.

EDD requires additional steps beyond standard CDD:

  • Investigating the source of funds and source of wealth

  • Verifying beneficial ownership through multiple independent sources

  • Mandatory adverse media screening

  • Applying more frequent monitoring and review cycles

  • Obtaining senior management approval for the business relationship

→Learn more: CDD vs. EDD

Ongoing due diligence

CDD does not end at onboarding. All three tiers of CDD carry an ongoing monitoring obligation. Ongoing due diligence requires you to continuously monitor customer activity, update identity information, and reassess risk as circumstances change.

For example, a customer you initially classified as low-risk may begin receiving large transfers from a high-risk jurisdiction. Ongoing due diligence means you detect that change, reassess the customer's risk rating, and apply appropriate controls. Without it, your risk assessments become outdated and your compliance program loses effectiveness.

How the CDD process works

A structured CDD process follows four stages, from initial identification through ongoing monitoring. Fund administration teams typically own this process end to end, coordinating identity verification, risk assessment, screening, and ongoing monitoring across the LP base.

Identify and verify the customer

The first step is collecting and verifying identity information. For individual customers, this typically includes:

  • Full legal name

  • Date of birth

  • Residential address

  • Government-issued photo identification

For business entities, you also collect:

  • Business registration documents

  • Articles of incorporation or equivalent

  • Identification of beneficial owners (individuals who own and/or control the entity—the threshold is typically set at 25%, but this may vary by jurisdiction)

  • Information about the entity's business purpose and activities

Verification means confirming this information against independent, reliable sources rather than simply accepting it at face value. Understanding what qualifies an investor matters here too—the definition of accredited investors shapes the documentation you collect and how you verify eligibility during onboarding.

Electronic identity verification tools can automate document checks and cross-reference public databases, reducing the manual effort required for each new customer or investor. Many compliance solutions offer automated verification capabilities that integrate directly into your onboarding workflow.

Assess the customer's risk level

Once you have verified the customer's identity, you assess their risk level. Risk factors fall into several categories:

  • Geographic risk: Is the customer based in or connected to a jurisdiction with elevated AML risk, weak regulatory oversight, or active sanctions?

  • Industry risk: Does the customer operate in a sector associated with higher money laundering risk, such as cash-intensive businesses, cryptocurrency, or real estate?

  • Transaction risk: Do the customer’s stated investment objectives and expected transaction volumes make sense given their profile, source of funds, and business activity?

  • Sanctions and PEP exposure: Does the customer or any beneficial owner appear on sanctions lists or PEP databases?

Based on these factors, you assign the customer a risk tier: low, medium, or high. The risk tier determines the level of due diligence and monitoring you apply going forward. Your risk assessment framework should be documented and applied consistently across all customers. A well-structured due diligence process relies on the same rigor whether you are evaluating deals or investors.

Screen against sanctions and watchlists

You must screen every customer against relevant sanctions and watchlists before establishing a business relationship. In the U.S., this includes the Office of Foreign Assets Control (OFAC) Specially Designated Nationals (SDN) list and its sectoral sanctions lists. Internationally, you should also check United Nations and EU sanctions lists, as well as PEP databases and adverse media sources.

Sanctions screening is not a one-time event. You need to rescreen your customer base regularly and whenever sanctions lists are updated. A customer who was clean at onboarding may later be designated on a sanctions list, and you are responsible for detecting that change.

Monitor activity and report suspicious transactions

Ongoing transaction monitoring is the final stage of the CDD process. You monitor customer activity for patterns or anomalies that may indicate money laundering, terrorist financing, or other financial crimes (for example, proliferation financing).

When you identify suspicious activity, you are obligated to file a suspicious activity report (SAR) with the Financial Crimes Enforcement Network (FinCEN). In 2025, financial institutions filed more than 4.1 million SARs, a record high and an 8% increase over the prior year. SARs must be filed within 30 days of detecting the suspicious activity. Failing to file a SAR when required is itself a regulatory violation that can result in penalties.

Maintaining a clear audit trail of every monitoring decision and filing is essential for demonstrating compliance if a regulator examines your program.

Get Carta’s modern fund operations playbook
Swap disconnected data for greater clarity in fund operations.
Free download

CDD regulatory requirements

CDD obligations are shaped by both domestic and international regulatory frameworks. Understanding the rules that apply to your fund is the first step toward building a compliant program.

The FinCEN CDD rule

In the United States, the FinCEN CDD Rule establishes four core requirements that have long applied to banks and broker-dealers. Under FinCEN's 2024 rulemaking, private fund managers and registered investment advisers will be subject to equivalent AML/CFT obligations from January 2028. The four core requirements under the Rule are:

  1. Identify and verify customer identity: Collect and confirm personal or corporate details using official documents and independent sources.

  2. Identify and verify beneficial owners: Determine the individuals who own 25% or more of a legal entity and at least one individual who  exercises significant control over it. These individuals are known as ultimate beneficial owners (UBO).

  3. Understand the nature and purpose of the relationship: Document the type of business, expected transaction patterns, and the reason for the account or investment.

  4. Conduct ongoing monitoring: Continuously review transactions, update customer information, and report suspicious activity to FinCEN.

In February 2026, FinCEN issued exceptive relief from the requirement to identify and verify beneficial owners at each new account opening, though institutions must still maintain risk-based procedures for updating beneficial ownership information.

International standards

Requirements vary by jurisdiction. Fund managers operating across borders meaning that they must comply with the all applicable regimes. The FATF 40 Recommendations serve as the global standard for AML and CDD compliance. Most national frameworks—including the EU's AML Directives, the UK's Money Laundering Regulations, and frameworks across Asia-Pacific—are built on these recommendations, though implementation and enforcement vary significantly by jurisdiction. Fund managers with LPs across multiple countries must identify and comply with the specific CDD requirements in each relevant jurisdiction; the most stringent applicable standard typically sets the floor.

Key international frameworks include:

  • EU Anti-Money Laundering Directives: The EU has enacted a series of AML rules (most recently, the directly applicable Anti-Money Laundering Regulation (AMLR 2024/1624)), that progressively strengthen CDD requirements across member states, including requirements for beneficial ownership registries and enhanced due diligence on high-risk third countries. The private fund adviser rules landscape continues to evolve in parallel, with regulators across jurisdictions tightening obligations on advisers managing assets for institutional LPs.

  • UK Money Laundering Regulations (MLR): The UK's MLR implements FATF standards and imposes CDD obligations on regulated firms, including private fund managers. Following Brexit, the UK maintains its AML framework independently of EU directives. The two regimes remain broadly aligned but are diverging incrementally, so fund managers with both UK and EU LPs should not assume the requirements are interchangeable.

  • Asia-Pacific frameworks: Jurisdictions across Asia-Pacific, including Singapore, Hong Kong, and Australia, have adopted FATF-aligned AML/CDD frameworks with varying levels of enforcement and scope. Singapore, Hong Kong, and Australia have mature, actively enforced FATF-aligned AML frameworks—administered by MAS, the SFC, and AUSTRAC respectively—that impose CDD obligations on fund managers operating in those jurisdictions. Compliance standards and enforcement intensity vary significantly across the broader Asia-Pacific region, and fund managers with LP exposure beyond these three jurisdictions should conduct jurisdiction-specific analysis before assuming FATF alignment.

If your fund operates across multiple jurisdictions or onboards LPs from different countries, you need to understand and comply with the CDD requirements in each relevant jurisdiction. Firms that prefer to outsource this work can engage fund services providers that specialize in compliance infrastructure for cross-border fund structures.

Stay ahead of Singapore's evolving private fund regulations
Our handbook is designed to help venture capital and private equity firms stay up to speed with Singapore’s current regulatory framework and compliance priorities.
Free download

Customer due diligence checklist

Use this checklist to verify your CDD process covers the essential elements.

Customer identification

  • Collect full legal name, date of birth, and address for individuals

  • Collect registration documents and articles of incorporation for entities

  • Verify identity against independent sources (government databases, credit bureaus, document verification)

  • Identify all beneficial owners at the 25% ownership and/or control thresholds (the beneficial ownership threshold and what constitutes “control”  varies depending on the jurisdiction whose AML rules the fund manager is subject to)

Risk assessment

  • Evaluate geographic, industry, transaction, and PEP/sanctions risk factors

  • Assign a risk tier (low, medium, or high) to each customer

  • Apply simplified, standard, or enhanced due diligence based on the assigned risk tier

  • Document your risk assessment methodology and each customer's risk determination

Screening

  • Screen all customers against OFAC, UN, EU, and other relevant jurisdictions’ sanctions lists

  • Check PEP databases for all beneficial owners and controlling persons

  • Conduct adverse media screening for all customers at onboarding; apply enhanced screening for high-risk customers

  • Establish a schedule for periodic rescreening

Ongoing monitoring

  • Monitor transactions for anomalies or patterns inconsistent with the customer's profile

  • Reassess risk when customer circumstances change (e.g., new jurisdiction, change in ownership)

  • Update customer information periodically and at trigger events (for example, adverse media hit, sanctions list update, change in beneficial ownership, unusual transaction pattern)

  • File SARs with FinCEN within 30 days from detection of a suspicious activity

Record keeping

  • Maintain CDD records for at least five years after the relationship ends

  • Document all due diligence steps, decisions, and risk assessments

  • Retain copies of all identity documents and verification results

  • Keep SAR filings and related documentation in a secure, auditable format. Fund audits rely on this documentation to verify that your CDD program operated as designed during the period under review.

Free year-end fund tax and audit guide
Our year-end checklist lists out the milestones to complete for a smooth tax and audit season.
Download the checklist

How to strengthen your CDD process

A compliant CDD program is a starting point, not a ceiling. Here are four ways to make your process more effective.

  • Allocate resources based on risk: Not every customer requires the same level of scrutiny. Focus your team's time and attention on higher-risk customers and complex ownership structures. Simplified due diligence for low-risk customers frees resources for the cases that matter most.

  • Use technology and automation: Manual CDD processes are slow, error-prone, and difficult to scale. Automated identity verification, sanctions screening, and transaction monitoring tools reduce processing time and improve accuracy.

  • Train your team regularly: CDD is only as strong as the people executing it. Regular training ensures your staff can identify red flags, apply risk-based procedures correctly, and stay current with regulatory changes. Training should cover both the regulatory requirements and your firm's specific policies and procedures.

  • Maintain thorough records: Good record keeping is both a regulatory requirement and a practical safeguard. If a regulator examines your CDD program, your records are the evidence that you followed your procedures. Document every step, decision, and rationale. Keep records for at least five years after the business relationship ends. Fund accounting systems that integrate with your compliance workflows make it easier to maintain a complete, time-stamped record of every transaction and due diligence action.

  • Periodic review: Review and test your program periodically against regulatory changes and your own risk profile.

Also consider choosing fund administration software that integrates AML/KYC compliance into LP onboarding workflows, so fund managers can handle due diligence alongside capital calls, reporting, and other operations in one place.

Broader fund management platforms extend this further by connecting compliance, accounting, reporting, and investor relations in a single system. Carta's purpose-built Carta KYC tool automates identity verification and sanctions screening across your LP base, reducing manual effort and compliance risk.

Keep your fund protected with KYC
Stay on top of compliance with automated tools for managing LP KYC checks.
Learn more

Common CDD challenges

Even well-designed CDD programs face operational hurdles. Understanding these challenges helps you build a more resilient compliance function.

False positives in sanctions screening

Automated screening tools flag potential matches against sanctions lists and PEP databases, but a significant portion of those flags are false positives. Reviewing and clearing false positives takes time and creates bottlenecks during onboarding. You can reduce the volume by tuning your screening parameters, using fuzzy-matching thresholds appropriate to your customer base, and maintaining a documented exemption process for recurring false positives.Each clearance decision should be documented with a written rationale and retained as part of your audit trail. Regulators will often scrutinize false positive clearance processes as closely as they scrutinize initial screening results.

Cross-jurisdictional complexity

If your fund onboards LPs from multiple countries, you must comply with the CDD requirements in each relevant jurisdiction. Rules vary on beneficial ownership thresholds, document retention periods, and what qualifies as acceptable identity verification. A process that satisfies FinCEN requirements in the U.S. may not meet the UK's Money Laundering Regulations or Singapore's AML framework. Building jurisdiction-specific workflows is essential for funds with a global LP base.

Keeping customer information current

CDD is not a point-in-time exercise. Customer circumstances change—ownership structures shift, business activities evolve, and new sanctions designations appear. Many compliance programs struggle with trigger-based reviews because they lack systematic processes for detecting changes in customer profiles between scheduled reviews. Automating change-detection alerts based on external data feeds can help close this gap.

Balancing thoroughness with onboarding speed

Extensive CDD checks can slow down the customer onboarding process, frustrating LPs who expect a smooth experience. The risk-based approach helps here: by applying simplified due diligence to low-risk customers, you can move them through onboarding faster while reserving intensive review for high-risk cases. The goal is right-sized scrutiny, not uniform scrutiny.

Risks of CDD non-compliance

Failing to implement proper CDD exposes your fund to serious consequences:

  • Financial penalties: Global AML, KYC, and CDD penalties totaled $3.8 billion in 2025, and enforcement actions have increased in both frequency and severity.

  • Criminal liability: Individual officers can face personal criminal charges for willful non-compliance with AML requirements.

  • Reputational damage: Loss of investor confidence, difficulty attracting new LPs, and potential exclusion from institutional allocator portfolios.

  • Regulatory action: License revocation, enforcement orders, and mandatory remediation programs that divert resources from fund operations.

The cost of building and maintaining a strong CDD program is far lower than the cost of non-compliance. For fund managers, this is not an abstract risk—it directly affects your ability to raise capital and operate. Routine fund audits will scrutinize your CDD records, making thorough documentation a practical necessity.

Streamlining CDD with an integrated platform

Manual CDD processes slow your fund operations and increase compliance risk. Modern compliance platforms automate identity verification, sanctions screening, beneficial ownership verification, and ongoing monitoring in a single workflow. These platforms also simplify LP KYC checks by centralizing document collection and verification.

Carta's fund administration platform includes AML/KYC compliance services built directly into the fund operations workflow. Automated KYC checks, AML screening, and investor document collection happen alongside your other fund administration tasks rather than through separate tools and vendors. This integrated approach reduces the operational burden on lean fund teams and helps you maintain consistent regulatory compliance standards across every closing.

Teams looking to manage the full compliance lifecycle can also use Carta Law’s compliance solutions for investor onboarding, regulatory filings, and ongoing monitoring. For one firm, Carta Law cut onboarding time significantly by automating KYC and CDD workflows. Endowus is another example—the firm used Carta to scale its compliance operations across multiple regulatory jurisdictions without adding headcount.

Carta supports 9,000+ funds and SPVs representing $220 billion+ in assets under management. Request a demo to see how Carta Law can help your team manage CDD, AML/KYC compliance, and LP onboarding.

AI-Native Law Firm for Private Capital
Scale your legal and compliance operations through AI-native workflows with expert oversight built into every step.
Get started

Frequently asked questions about customer due diligence

What are the four elements of customer due diligence?

The four pillars under the FinCEN CDD Rule are identifying and verifying customer identity, identifying and verifying beneficial owners, understanding the nature and purpose of the relationship, and conducting ongoing monitoring with suspicious activity reporting.

What is the difference between CDD and KYC?

KYC focuses on identifying and verifying a customer's identity and ownership and control structure. CDD is broader. It includes KYC but adds risk assessment, ongoing monitoring, and the application of risk-based controls throughout the business relationship. KYC asks, "Who is this person?" CDD asks, "What risk does this person pose?"

What is an example of customer due diligence?

When a private fund onboards a new LP, the fund manager collects the LP's identity documents, verifies beneficial ownership, screens the LP against sanctions lists and PEP databases, assesses the LP's risk level, and establishes ongoing monitoring for suspicious activity. If the LP is a high-risk entity, such as a trust with complex ownership in a high-risk jurisdiction, the fund manager applies enhanced due diligence with additional source-of-funds verification and more frequent reviews. Fund formation decisions—including where to domicile the fund and how to structure LP admission—directly affect the CDD obligations you will carry throughout the fund's life.

When is enhanced due diligence required?

EDD is required in certain mandatory circumstances, including when a customer is a politically exposed person or is connected to a FATF-identified high-risk jurisdiction. It may also be required when a risk-based assessment identifies elevated risk factors such as complex ownership structures, unusual transaction patterns, or high-risk industries.

Does CDD apply to private fund managers?

In many jurisdictions, fund managers are subject to AML and CDD requirements when onboarding investors. In the U.S., registered investment advisers will be subject to federal AML/CFT obligations under FinCEN's 2024 Investment Adviser Rule, with compliance required by January 1, 2028. Fund managers operating in the EU or UK are already subject to CDD requirements under AIFMD and the Money Laundering Regulations respectively. Regardless of jurisdiction, conducting CDD on investors is widely regarded as best practice and is often required by fund administrators and prime brokers operating under their own regulatory obligations.

The Carta Team
Carta's best-in-class software, services, and resources are designed to promote clarity and connection in the private capital ecosystem. By combining industry experience with proprietary data and real customer stories, our content offers expert guidance and clear, actionable insights for companies and investors.

DISCLOSURE: This communication is on behalf of eShares, Inc. dba Carta, Inc. ("Carta"). This communication is for informational purposes only, and contains general information only. Carta is not, by means of this communication, rendering accounting, business, financial, investment, legal, tax, or other professional advice or services. This publication is not a substitute for such professional advice or services nor should it be used as a basis for any decision or action that may affect your business or interests. Before making any decision or taking any action that may affect your business or interests, you should consult a qualified professional advisor. This communication is not intended as a recommendation, offer or solicitation for the purchase or sale of any security. Carta does not assume any liability for reliance on the information provided herein. © 2026 Carta. All rights reserved. Reproduction prohibited.