- Customer due diligence best practices for fund managers
- What is customer due diligence?
- How CDD relates to KYC and AML
- Why customer due diligence matters
- Types of customer due diligence
- Simplified due diligence
- Standard due diligence
- Enhanced due diligence (EDD)
- Ongoing due diligence
- How the CDD process works
- Identify and verify the customer
- Assess the customer's risk level
- Screen against sanctions and watchlists
- Monitor activity and report suspicious transactions
- CDD regulatory requirements
- The FinCEN CDD rule
- International standards
- Customer due diligence checklist
- Customer identification
- Risk assessment
- Screening
- Ongoing monitoring
- Record keeping
- How to strengthen your CDD process
- Common CDD challenges
- False positives in sanctions screening
- Cross-jurisdictional complexity
- Keeping customer information current
- Balancing thoroughness with onboarding speed
- Risks of CDD non-compliance
- Streamlining CDD with an integrated platform
- Frequently asked questions about customer due diligence
What is customer due diligence?
Customer due diligence (CDD) is the process fund managers use to verify an investor’s or a deal counterparty’s identity, assess their risk profile, and monitor their activities throughout the relationship. For fund managers and financial institutions, CDD is not an optional risk management exercise. In many jurisdictions, it is a legal requirement under anti-money laundering (AML) regulations, though in the U.S., AML program requirements for most private fund managers are not yet in effect. KYC is its core identification and verification component.
You must conduct CDD before onboarding a new customer or investor, and the obligation continues throughout the duration of the business relationship. The core information you collect includes legal name, address, identification documents, source of funds, business activity, and beneficial ownership.
At its core, CDD helps you answer three questions: Who is this customer? What risk do they present? And has that risk changed over time? If you manage a private fund, your CDD obligations extend to every limited partner (LP) you onboard and every entity you transact with.
How CDD relates to KYC and AML
AML is the overarching regulatory framework designed to prevent money laundering, terrorist financing, and other financial crimes. KYC is the identification and verification process that sits within AML. CDD is the broader set of obligations that includes KYC, adding risk assessment, and ongoing monitoring.
A simple way to understand the hierarchy:
AML: The regulatory framework—the legal obligation to prevent financial crime
CDD: The full compliance process—encompassing KYC, risk assessment, beneficial ownership, screening, and ongoing monitoring
KYC: The identity and verification component—establishing who the customer is
Think of it this way: KYC answers the question, "Who is this person?" CDD answers, "What risk does this person pose, and has that risk changed?" CDD is the broader obligation, beginning with KYC identity checks and goes further, requiring risk assessment, controls and monitoring of the relationship.

Why customer due diligence matters
CDD protects your fund from three categories of risk.
Regulatory risk: Failing to perform adequate CDD can result in significant fines and enforcement actions. In 2025 alone, global penalties for AML, KYC, and CDD violations totaled $3.8 billion. For fund managers, noncompliance can trigger regulatory investigations, restrict your ability to operate, and delay fundraising.
Financial crime risk: Without a structured verification and monitoring process, you are more likely to onboard bad actors or process illicit funds, exposing the fund to civil liability, criminal investigation, and potential clawback of tainted capital. Private funds are increasingly a focus of regulatory scrutiny as enforcement expands beyond traditional banking. FinCEN's 2024 rule extends formal AML obligations to registered investment advisers for the first time, a signal that regulators view the sector as a meaningful vector for financial crime.
Reputational risk: A single AML compliance violation can damage your firm's reputation with LPs, regulators, and counterparties. Institutional investors conduct operational due diligence on fund managers, and a history of compliance failures makes fundraising significantly harder.
Types of customer due diligence
The Financial Action Task Force (FATF) requires a risk-based approach to CDD. This means the level of scrutiny you apply should match the risk each customer presents. Compliance frameworks codify this risk-based model across fund structures. There are three main tiers of customer due diligence:
Simplified due diligence
Simplified due diligence applies to low-risk customers where the likelihood of money laundering or terrorist financing is minimal. You still verify identity through background checks, but you can reduce the documentation and monitoring requirements. A publicly traded company listed on a regulated exchange in jurisdictions such as the U.S., UK, EU or other jurisdictions with equivalent AML frameworks is a typical example of a customer that qualifies for simplified due diligence.
Standard due diligence
Standard due diligence is the baseline you apply to most customer relationships. You collect and verify core identity information, confirm the customer's key details, verify its beneficial ownership, and understand the purpose of the business relationship. For fund managers, this is the minimum you perform for every LP at onboarding.
Enhanced due diligence (EDD)
Enhanced due diligence (EDD) applies to higher-risk customers. This includes politically exposed persons (PEP), customers based in jurisdictions subject to sanctions or with weak AML frameworks and entities with unusually complex ownership structures that make it difficult to verify beneficial ownership through standard documentation. Funds with exposure to offshore investors should also review jurisdiction-specific requirements—for example, Cayman Islands KYC/AML rules impose specific EDD obligations on regulated entities domiciled there.
EDD requires additional steps beyond standard CDD:
Investigating the source of funds and source of wealth
Verifying beneficial ownership through multiple independent sources
Mandatory adverse media screening
Applying more frequent monitoring and review cycles
Obtaining senior management approval for the business relationship
→Learn more: CDD vs. EDD
Ongoing due diligence
CDD does not end at onboarding. All three tiers of CDD carry an ongoing monitoring obligation. Ongoing due diligence requires you to continuously monitor customer activity, update identity information, and reassess risk as circumstances change.
For example, a customer you initially classified as low-risk may begin receiving large transfers from a high-risk jurisdiction. Ongoing due diligence means you detect that change, reassess the customer's risk rating, and apply appropriate controls. Without it, your risk assessments become outdated and your compliance program loses effectiveness.
How the CDD process works
A structured CDD process follows four stages, from initial identification through ongoing monitoring. Fund administration teams typically own this process end to end, coordinating identity verification, risk assessment, screening, and ongoing monitoring across the LP base.
Identify and verify the customer
The first step is collecting and verifying identity information. For individual customers, this typically includes:
Full legal name
Date of birth
Residential address
Government-issued photo identification
For business entities, you also collect:
Business registration documents
Articles of incorporation or equivalent
Identification of beneficial owners (individuals who own and/or control the entity—the threshold is typically set at 25%, but this may vary by jurisdiction)
Information about the entity's business purpose and activities
Verification means confirming this information against independent, reliable sources rather than simply accepting it at face value. Understanding what qualifies an investor matters here too—the definition of accredited investors shapes the documentation you collect and how you verify eligibility during onboarding.
Electronic identity verification tools can automate document checks and cross-reference public databases, reducing the manual effort required for each new customer or investor. Many compliance solutions offer automated verification capabilities that integrate directly into your onboarding workflow.
Assess the customer's risk level
Once you have verified the customer's identity, you assess their risk level. Risk factors fall into several categories:
Geographic risk: Is the customer based in or connected to a jurisdiction with elevated AML risk, weak regulatory oversight, or active sanctions?
Industry risk: Does the customer operate in a sector associated with higher money laundering risk, such as cash-intensive businesses, cryptocurrency, or real estate?
Transaction risk: Do the customer’s stated investment objectives and expected transaction volumes make sense given their profile, source of funds, and business activity?
Sanctions and PEP exposure: Does the customer or any beneficial owner appear on sanctions lists or PEP databases?
Based on these factors, you assign the customer a risk tier: low, medium, or high. The risk tier determines the level of due diligence and monitoring you apply going forward. Your risk assessment framework should be documented and applied consistently across all customers. A well-structured due diligence process relies on the same rigor whether you are evaluating deals or investors.
Screen against sanctions and watchlists
You must screen every customer against relevant sanctions and watchlists before establishing a business relationship. In the U.S., this includes the Office of Foreign Assets Control (OFAC) Specially Designated Nationals (SDN) list and its sectoral sanctions lists. Internationally, you should also check United Nations and EU sanctions lists, as well as PEP databases and adverse media sources.
Sanctions screening is not a one-time event. You need to rescreen your customer base regularly and whenever sanctions lists are updated. A customer who was clean at onboarding may later be designated on a sanctions list, and you are responsible for detecting that change.
Monitor activity and report suspicious transactions
Ongoing transaction monitoring is the final stage of the CDD process. You monitor customer activity for patterns or anomalies that may indicate money laundering, terrorist financing, or other financial crimes (for example, proliferation financing).
When you identify suspicious activity, you are obligated to file a suspicious activity report (SAR) with the Financial Crimes Enforcement Network (FinCEN). In 2025, financial institutions filed more than 4.1 million SARs, a record high and an 8% increase over the prior year. SARs must be filed within 30 days of detecting the suspicious activity. Failing to file a SAR when required is itself a regulatory violation that can result in penalties.
Maintaining a clear audit trail of every monitoring decision and filing is essential for demonstrating compliance if a regulator examines your program.

CDD regulatory requirements
CDD obligations are shaped by both domestic and international regulatory frameworks. Understanding the rules that apply to your fund is the first step toward building a compliant program.
The FinCEN CDD rule
In the United States, the FinCEN CDD Rule establishes four core requirements that have long applied to banks and broker-dealers. Under FinCEN's 2024 rulemaking, private fund managers and registered investment advisers will be subject to equivalent AML/CFT obligations from January 2028. The four core requirements under the Rule are:
Identify and verify customer identity: Collect and confirm personal or corporate details using official documents and independent sources.
Identify and verify beneficial owners: Determine the individuals who own 25% or more of a legal entity and at least one individual who exercises significant control over it. These individuals are known as ultimate beneficial owners (UBO).
Understand the nature and purpose of the relationship: Document the type of business, expected transaction patterns, and the reason for the account or investment.
Conduct ongoing monitoring: Continuously review transactions, update customer information, and report suspicious activity to FinCEN.
In February 2026, FinCEN issued exceptive relief from the requirement to identify and verify beneficial owners at each new account opening, though institutions must still maintain risk-based procedures for updating beneficial ownership information.
International standards
Requirements vary by jurisdiction. Fund managers operating across borders meaning that they must comply with the all applicable regimes. The FATF 40 Recommendations serve as the global standard for AML and CDD compliance. Most national frameworks—including the EU's AML Directives, the UK's Money Laundering Regulations, and frameworks across Asia-Pacific—are built on these recommendations, though implementation and enforcement vary significantly by jurisdiction. Fund managers with LPs across multiple countries must identify and comply with the specific CDD requirements in each relevant jurisdiction; the most stringent applicable standard typically sets the floor.
Key international frameworks include:
EU Anti-Money Laundering Directives: The EU has enacted a series of AML rules (most recently, the directly applicable Anti-Money Laundering Regulation (AMLR 2024/1624)), that progressively strengthen CDD requirements across member states, including requirements for beneficial ownership registries and enhanced due diligence on high-risk third countries. The private fund adviser rules landscape continues to evolve in parallel, with regulators across jurisdictions tightening obligations on advisers managing assets for institutional LPs.
UK Money Laundering Regulations (MLR): The UK's MLR implements FATF standards and imposes CDD obligations on regulated firms, including private fund managers. Following Brexit, the UK maintains its AML framework independently of EU directives. The two regimes remain broadly aligned but are diverging incrementally, so fund managers with both UK and EU LPs should not assume the requirements are interchangeable.
Asia-Pacific frameworks: Jurisdictions across Asia-Pacific, including Singapore, Hong Kong, and Australia, have adopted FATF-aligned AML/CDD frameworks with varying levels of enforcement and scope. Singapore, Hong Kong, and Australia have mature, actively enforced FATF-aligned AML frameworks—administered by MAS, the SFC, and AUSTRAC respectively—that impose CDD obligations on fund managers operating in those jurisdictions. Compliance standards and enforcement intensity vary significantly across the broader Asia-Pacific region, and fund managers with LP exposure beyond these three jurisdictions should conduct jurisdiction-specific analysis before assuming FATF alignment.
If your fund operates across multiple jurisdictions or onboards LPs from different countries, you need to understand and comply with the CDD requirements in each relevant jurisdiction. Firms that prefer to outsource this work can engage fund services providers that specialize in compliance infrastructure for cross-border fund structures.

Customer due diligence checklist
Use this checklist to verify your CDD process covers the essential elements.
Customer identification
Collect full legal name, date of birth, and address for individuals
Collect registration documents and articles of incorporation for entities
Verify identity against independent sources (government databases, credit bureaus, document verification)
Identify all beneficial owners at the 25% ownership and/or control thresholds (the beneficial ownership threshold and what constitutes “control” varies depending on the jurisdiction whose AML rules the fund manager is subject to)
Risk assessment
Evaluate geographic, industry, transaction, and PEP/sanctions risk factors
Assign a risk tier (low, medium, or high) to each customer
Apply simplified, standard, or enhanced due diligence based on the assigned risk tier
Document your risk assessment methodology and each customer's risk determination
Screening
Screen all customers against OFAC, UN, EU, and other relevant jurisdictions’ sanctions lists
Check PEP databases for all beneficial owners and controlling persons
Conduct adverse media screening for all customers at onboarding; apply enhanced screening for high-risk customers
Establish a schedule for periodic rescreening
Ongoing monitoring
Monitor transactions for anomalies or patterns inconsistent with the customer's profile
Reassess risk when customer circumstances change (e.g., new jurisdiction, change in ownership)
Update customer information periodically and at trigger events (for example, adverse media hit, sanctions list update, change in beneficial ownership, unusual transaction pattern)
File SARs with FinCEN within 30 days from detection of a suspicious activity
Record keeping
Maintain CDD records for at least five years after the relationship ends
Document all due diligence steps, decisions, and risk assessments
Retain copies of all identity documents and verification results
Keep SAR filings and related documentation in a secure, auditable format. Fund audits rely on this documentation to verify that your CDD program operated as designed during the period under review.

How to strengthen your CDD process
A compliant CDD program is a starting point, not a ceiling. Here are four ways to make your process more effective.
Allocate resources based on risk: Not every customer requires the same level of scrutiny. Focus your team's time and attention on higher-risk customers and complex ownership structures. Simplified due diligence for low-risk customers frees resources for the cases that matter most.
Use technology and automation: Manual CDD processes are slow, error-prone, and difficult to scale. Automated identity verification, sanctions screening, and transaction monitoring tools reduce processing time and improve accuracy.
Train your team regularly: CDD is only as strong as the people executing it. Regular training ensures your staff can identify red flags, apply risk-based procedures correctly, and stay current with regulatory changes. Training should cover both the regulatory requirements and your firm's specific policies and procedures.
Maintain thorough records: Good record keeping is both a regulatory requirement and a practical safeguard. If a regulator examines your CDD program, your records are the evidence that you followed your procedures. Document every step, decision, and rationale. Keep records for at least five years after the business relationship ends. Fund accounting systems that integrate with your compliance workflows make it easier to maintain a complete, time-stamped record of every transaction and due diligence action.
Periodic review: Review and test your program periodically against regulatory changes and your own risk profile.
Also consider choosing fund administration software that integrates AML/KYC compliance into LP onboarding workflows, so fund managers can handle due diligence alongside capital calls, reporting, and other operations in one place.
Broader fund management platforms extend this further by connecting compliance, accounting, reporting, and investor relations in a single system. Carta's purpose-built Carta KYC tool automates identity verification and sanctions screening across your LP base, reducing manual effort and compliance risk.

Common CDD challenges
Even well-designed CDD programs face operational hurdles. Understanding these challenges helps you build a more resilient compliance function.
False positives in sanctions screening
Automated screening tools flag potential matches against sanctions lists and PEP databases, but a significant portion of those flags are false positives. Reviewing and clearing false positives takes time and creates bottlenecks during onboarding. You can reduce the volume by tuning your screening parameters, using fuzzy-matching thresholds appropriate to your customer base, and maintaining a documented exemption process for recurring false positives.Each clearance decision should be documented with a written rationale and retained as part of your audit trail. Regulators will often scrutinize false positive clearance processes as closely as they scrutinize initial screening results.
Cross-jurisdictional complexity
If your fund onboards LPs from multiple countries, you must comply with the CDD requirements in each relevant jurisdiction. Rules vary on beneficial ownership thresholds, document retention periods, and what qualifies as acceptable identity verification. A process that satisfies FinCEN requirements in the U.S. may not meet the UK's Money Laundering Regulations or Singapore's AML framework. Building jurisdiction-specific workflows is essential for funds with a global LP base.
Keeping customer information current
CDD is not a point-in-time exercise. Customer circumstances change—ownership structures shift, business activities evolve, and new sanctions designations appear. Many compliance programs struggle with trigger-based reviews because they lack systematic processes for detecting changes in customer profiles between scheduled reviews. Automating change-detection alerts based on external data feeds can help close this gap.
Balancing thoroughness with onboarding speed
Extensive CDD checks can slow down the customer onboarding process, frustrating LPs who expect a smooth experience. The risk-based approach helps here: by applying simplified due diligence to low-risk customers, you can move them through onboarding faster while reserving intensive review for high-risk cases. The goal is right-sized scrutiny, not uniform scrutiny.
Risks of CDD non-compliance
Failing to implement proper CDD exposes your fund to serious consequences:
Financial penalties: Global AML, KYC, and CDD penalties totaled $3.8 billion in 2025, and enforcement actions have increased in both frequency and severity.
Criminal liability: Individual officers can face personal criminal charges for willful non-compliance with AML requirements.
Reputational damage: Loss of investor confidence, difficulty attracting new LPs, and potential exclusion from institutional allocator portfolios.
Regulatory action: License revocation, enforcement orders, and mandatory remediation programs that divert resources from fund operations.
The cost of building and maintaining a strong CDD program is far lower than the cost of non-compliance. For fund managers, this is not an abstract risk—it directly affects your ability to raise capital and operate. Routine fund audits will scrutinize your CDD records, making thorough documentation a practical necessity.
Streamlining CDD with an integrated platform
Manual CDD processes slow your fund operations and increase compliance risk. Modern compliance platforms automate identity verification, sanctions screening, beneficial ownership verification, and ongoing monitoring in a single workflow. These platforms also simplify LP KYC checks by centralizing document collection and verification.
Carta's fund administration platform includes AML/KYC compliance services built directly into the fund operations workflow. Automated KYC checks, AML screening, and investor document collection happen alongside your other fund administration tasks rather than through separate tools and vendors. This integrated approach reduces the operational burden on lean fund teams and helps you maintain consistent regulatory compliance standards across every closing.
Teams looking to manage the full compliance lifecycle can also use Carta Law’s compliance solutions for investor onboarding, regulatory filings, and ongoing monitoring. For one firm, Carta Law cut onboarding time significantly by automating KYC and CDD workflows. Endowus is another example—the firm used Carta to scale its compliance operations across multiple regulatory jurisdictions without adding headcount.
Carta supports 9,000+ funds and SPVs representing $220 billion+ in assets under management. Request a demo to see how Carta Law can help your team manage CDD, AML/KYC compliance, and LP onboarding.

Frequently asked questions about customer due diligence
What are the four elements of customer due diligence?
The four pillars under the FinCEN CDD Rule are identifying and verifying customer identity, identifying and verifying beneficial owners, understanding the nature and purpose of the relationship, and conducting ongoing monitoring with suspicious activity reporting.
What is the difference between CDD and KYC?
KYC focuses on identifying and verifying a customer's identity and ownership and control structure. CDD is broader. It includes KYC but adds risk assessment, ongoing monitoring, and the application of risk-based controls throughout the business relationship. KYC asks, "Who is this person?" CDD asks, "What risk does this person pose?"
What is an example of customer due diligence?
When a private fund onboards a new LP, the fund manager collects the LP's identity documents, verifies beneficial ownership, screens the LP against sanctions lists and PEP databases, assesses the LP's risk level, and establishes ongoing monitoring for suspicious activity. If the LP is a high-risk entity, such as a trust with complex ownership in a high-risk jurisdiction, the fund manager applies enhanced due diligence with additional source-of-funds verification and more frequent reviews. Fund formation decisions—including where to domicile the fund and how to structure LP admission—directly affect the CDD obligations you will carry throughout the fund's life.
When is enhanced due diligence required?
EDD is required in certain mandatory circumstances, including when a customer is a politically exposed person or is connected to a FATF-identified high-risk jurisdiction. It may also be required when a risk-based assessment identifies elevated risk factors such as complex ownership structures, unusual transaction patterns, or high-risk industries.
Does CDD apply to private fund managers?
In many jurisdictions, fund managers are subject to AML and CDD requirements when onboarding investors. In the U.S., registered investment advisers will be subject to federal AML/CFT obligations under FinCEN's 2024 Investment Adviser Rule, with compliance required by January 1, 2028. Fund managers operating in the EU or UK are already subject to CDD requirements under AIFMD and the Money Laundering Regulations respectively. Regardless of jurisdiction, conducting CDD on investors is widely regarded as best practice and is often required by fund administrators and prime brokers operating under their own regulatory obligations.
DISCLOSURE: This communication is on behalf of eShares, Inc. dba Carta, Inc. ("Carta"). This communication is for informational purposes only, and contains general information only. Carta is not, by means of this communication, rendering accounting, business, financial, investment, legal, tax, or other professional advice or services. This publication is not a substitute for such professional advice or services nor should it be used as a basis for any decision or action that may affect your business or interests. Before making any decision or taking any action that may affect your business or interests, you should consult a qualified professional advisor. This communication is not intended as a recommendation, offer or solicitation for the purchase or sale of any security. Carta does not assume any liability for reliance on the information provided herein. ©2026 Carta. All rights reserved. Reproduction prohibited.




