Skip to main content
a promotional graphic telling you that PCI Compliance is no longer an annual exercise and that continuous monitory must be built in
Category: Due Diligence

Simplified Due Diligence

Also known as: SDD, Reduced Due Diligence
Simply put

Simplified Due Diligence is a lighter form of customer verification that a business may apply when a customer or situation is judged to present a low risk of money laundering or terrorist financing. Instead of the fuller checks used for typical customers, the business performs a more streamlined, lower-friction identity verification process. Whether it can be applied depends on the risk assessment and the applicable rules, so it is not available for every customer.

Formal definition

Simplified Due Diligence (SDD), also referred to as Reduced Due Diligence, is generally described as the lowest level of Customer Due Diligence (CDD) that a regulated entity may apply to eligible customers assessed as presenting a low risk of money laundering or terrorist financing. It typically involves a brief, lower-friction identity verification process rather than the standard or enhanced measures applied to higher-risk relationships. Eligibility for SDD depends on the outcome of a risk assessment; the specific criteria, permitted scope, and ongoing monitoring obligations vary by jurisdiction and governing AML regime and are subject to regulator interpretation. This entry is a simplified overview and does not set out the qualifying conditions or documentation requirements under any particular legal framework; application to a specific customer or product should be validated against the relevant local requirements and, where appropriate, professional advice.

Why it matters

Simplified Due Diligence sits at the low-risk end of the Customer Due Diligence (CDD) spectrum, and applying it correctly is a matter of both efficiency and regulatory exposure. When a regulated entity can justify that a customer or product presents a low risk of money laundering or terrorist financing, SDD lets it reduce onboarding friction and allocate verification resources toward higher-risk relationships. The critical point is that SDD is a risk-based concession, not a default: it can only be applied where the underlying risk assessment supports it, and the criteria for eligibility depend on the applicable AML regime and are subject to regulator interpretation.

Who it's relevant to

AML and Financial Crime Compliance Officers
Responsible for defining when SDD may be applied within the firm's risk-based approach, ensuring eligibility criteria align with the applicable AML regime, and documenting the rationale that supports a low-risk determination. They also need to ensure SDD is not applied where the risk assessment does not justify it.
Onboarding and Customer Verification Teams
Execute the lower-friction identity verification process for customers assessed as low risk. They rely on clear internal criteria to distinguish SDD-eligible cases from those requiring standard or enhanced measures, and should escalate where a customer's risk profile is unclear.
Risk and Assessment Functions
Own the risk assessment that determines whether a customer, product, or situation qualifies as low risk. Because SDD eligibility flows from this assessment, these teams shape when the simplified route is available and when circumstances warrant re-assessment.
Internal Audit and Assurance
Provide independent challenge on whether SDD decisions are properly evidenced, consistent with the applicable jurisdiction's requirements, and supported by a documented risk assessment rather than applied as a default. Their scope is testing controls, not making the eligibility determinations themselves.

Inside SDD

Risk-Based Rationale
SDD is applied only where the customer, product, service, or geographic relationship presents a demonstrably lower risk of money laundering or terrorist financing. The reduced measures must be justified and documented by reference to a supporting risk assessment rather than applied by default.
Reduced-Intensity CDD Measures
SDD does not eliminate customer due diligence obligations; it permits the extent, timing, or frequency of standard CDD measures to be adjusted. Identification and verification of the customer generally still occur, but the scope of information gathered or the intensity of ongoing monitoring may be reduced in proportion to the assessed risk.
Eligibility Criteria / Lower-Risk Factors
Circumstances that may support SDD typically include certain regulated financial entities, listed companies subject to disclosure requirements, or public authorities. The specific factors treated as lower risk are set by the applicable AML/CFT regime and supervisory guidance, and they vary by jurisdiction.
Ongoing Monitoring Component
Even under SDD, the relationship remains subject to ongoing monitoring appropriate to the risk level, so that changes in behaviour or circumstances that could elevate risk can be detected and the level of due diligence reconsidered.
Documentation and Auditability
The decision to apply SDD, the underlying risk assessment, and the reduced measures adopted are generally expected to be recorded so they can be evidenced to supervisors and internal or external auditors.

Common questions

Answers to the questions practitioners most commonly ask about SDD.

Does Simplified Due Diligence mean no customer due diligence is required at all?
No. SDD is a reduced level of customer due diligence, not an exemption from it. It generally allows regulated firms to apply lighter-touch measures — such as reduced verification steps or adjusted timing — where a lower risk of money laundering or terrorist financing has been identified and justified. Core obligations, including identifying the customer and conducting ongoing monitoring, typically still apply. The specific measures that may be reduced depend on the applicable regime and the firm's risk assessment, and where doubt or a change in risk arises, standard or enhanced due diligence is usually expected instead.
Can a firm apply SDD automatically to any customer that falls into a low-risk category?
Not automatically. Even where a customer type or product is commonly associated with lower risk, most risk-based regimes require the firm to reach and document its own determination that the specific relationship presents a lower risk before applying SDD. Category membership is typically a starting point for assessment rather than a conclusive justification. Firms are generally expected to remain alert to factors that would displace the low-risk conclusion, at which point SDD would no longer be appropriate. This entry is a general description; the precise conditions vary by jurisdiction and firm, and specific application may require professional or legal advice.
How should a firm document its decision to apply SDD to a customer?
Firms generally maintain a record of the risk assessment supporting the SDD decision, including the factors relied upon and the rationale for concluding that a lower risk applies. The level of detail and retention expectations depend on the applicable regime and the firm's internal policies. Documentation typically needs to be sufficient to demonstrate to a regulator or auditor that the reduced measures were justified and consistent with the firm's risk-based approach. What constitutes adequate documentation may depend on the jurisdiction and the nature of the relationship.
What ongoing monitoring is expected once SDD has been applied?
Applying SDD does not typically remove the obligation to conduct ongoing monitoring, though the intensity or frequency may be adjusted to reflect the assessed lower risk. Monitoring is generally expected to identify changes in customer behaviour, transactions, or circumstances that could raise the risk level. Where such changes occur, firms are usually expected to reassess and, if warranted, move to standard or enhanced due diligence. The specific monitoring measures depend on the applicable regime and the firm's own policies.
What should trigger a firm to stop applying SDD and escalate to standard or enhanced due diligence?
Escalation is generally warranted where the basis for the low-risk determination no longer holds — for example, where new information, unusual or unexpected activity, doubts about previously obtained information, or a suspicion of money laundering or terrorist financing arises. Triggers may also include changes in the customer's profile, product use, or jurisdictional exposure. The specific escalation triggers and the resulting measures depend on the applicable regime and the firm's risk-based procedures, and should be defined in internal policy.
How should SDD provisions be reflected in a firm's policies and procedures?
Firms typically set out in their policies the circumstances in which SDD may be considered, the assessment required before it is applied, the reduced measures permitted, the documentation expected, and the triggers for escalation. These provisions are generally aligned to the firm's overall risk-based approach and the requirements of the applicable regime. Because thresholds and permitted measures vary by jurisdiction and may be amended over time, firms usually review these provisions periodically and may seek professional or legal advice when designing or updating them.

Common misconceptions

SDD means no due diligence is required for low-risk customers.
SDD is a reduction in the extent and intensity of measures, not an exemption. Core obligations such as customer identification and ongoing monitoring generally still apply; only the depth, timing, or frequency is adjusted based on assessed risk.
A customer type qualifies for SDD automatically and universally.
Eligibility for SDD depends on a documented risk assessment and on the specific lower-risk factors recognised under the applicable jurisdiction's AML/CFT framework and supervisory guidance. Factors accepted in one regime may not be accepted in another, and a category treated as lower risk generally cannot override contrary evidence in a specific case.
Once SDD is applied, the assessment is fixed for the life of the relationship.
SDD is not static. Ongoing monitoring may reveal changes that elevate the risk profile, in which case standard or enhanced measures may need to be applied. The lower-risk determination should be revisited when circumstances change.

Best practices

Base every SDD decision on a documented risk assessment that references the lower-risk factors recognised in your applicable jurisdiction, rather than applying SDD by default to a customer category.
Retain identification and verification of the customer as a baseline, adjusting only the extent, timing, or frequency of measures in proportion to the assessed lower risk.
Record the rationale, supporting evidence, and the specific reduced measures adopted so the SDD decision can be evidenced to supervisors and auditors.
Maintain ongoing monitoring calibrated to the risk level and define triggers that require the SDD status to be reassessed and potentially escalated to standard or enhanced due diligence.
Confirm eligibility criteria against current supervisory guidance for each relevant jurisdiction, since lower-risk factors and permissible reductions differ across regimes.
Seek qualified legal or compliance advice before applying SDD to novel or cross-border situations where the applicable requirements or lower-risk factors are unclear.
Promotional banner highlighting failures found in PCI audits and how to spot the gaps