Chapter 3: Customer Due Diligence (CDD)

Chapter 3 of 8 • Estimated reading time: 35 minutes
Topics: Identity Verification, Beneficial Ownership, Risk Assessment, Documentation

3.1 The Foundation of CDD

Customer Due Diligence represents the cornerstone of any effective KYC/AML program. It is the process through which financial institutions verify the identity of their customers, understand the nature and purpose of business relationships, and assess the money laundering and terrorist financing risks associated with those relationships.

CDD is not a one-time event but an ongoing process that begins before account opening and continues throughout the customer relationship. The intensity and depth of CDD measures must be proportionate to the risks identified—a fundamental principle known as the risk-based approach.

3.2 Customer Identification Program (CIP)

The Customer Identification Program forms the first critical step in CDD. Financial institutions must obtain, verify, and record identifying information about each customer.

3.2.1 Individual Customers

For individual customers, institutions must collect minimum identifying information:

Verification of this information must occur through reliable, independent documents, data, or information sources. Acceptable documents typically include:

Best Practice: Multi-Factor Identity Verification

Leading institutions employ multiple verification methods:

3.2.2 Legal Entity Customers

For business entities, the CIP process is more complex, requiring collection and verification of:

Documentary verification for legal entities typically includes:

3.3 Beneficial Ownership Identification

One of the most critical and challenging aspects of CDD is identifying beneficial owners—the natural persons who ultimately own or control a legal entity customer. Shell companies and complex ownership structures have historically been exploited for money laundering, necessitating requirements to "look through" legal entities to identify the real people behind them.

3.3.1 Beneficial Ownership Definition

While definitions vary across jurisdictions, beneficial owners typically include:

If no person meets the ownership threshold, institutions must identify a controlling person (such as senior managing officials).

3.3.2 Beneficial Ownership Verification

Institutions must obtain identifying information for each beneficial owner and verify their identities. This presents challenges when dealing with:

Red Flags in Ownership Structures:

3.3.3 Beneficial Ownership Registers

Many jurisdictions have established centralized beneficial ownership registers to enhance transparency:

Jurisdiction Register Type Accessibility
United Kingdom Companies House PSC Register Public (with some restrictions for high-risk individuals)
European Union National Registers Varies (public access subject to recent ECJ ruling limiting access)
United States FinCEN BOI Database Limited to authorities and financial institutions (under Corporate Transparency Act)

3.4 Understanding the Customer's Business

Effective CDD requires understanding not just who the customer is, but what they do and why they need the financial relationship.

3.4.1 Purpose and Nature of Relationship

Institutions must understand and document:

3.4.2 Source of Funds vs. Source of Wealth

These related but distinct concepts are both important for CDD:

Source of Funds: The origin of particular funds involved in the business relationship or transactions. Example: salary, sale of property, business income, loan proceeds.

Source of Wealth: The origin of a customer's total net worth or assets. Example: inheritance, business ownership, investment returns, employment career earnings.

For higher-risk relationships, understanding both is crucial. Inconsistencies between claimed sources and observable facts can indicate money laundering.

3.5 Risk Assessment

The risk-based approach requires institutions to assess and categorize the money laundering and terrorist financing risk associated with each customer relationship.

3.5.1 Risk Factors

Risk assessment typically considers multiple dimensions:

Customer Risk Factors:

Geographic Risk Factors:

Product/Service Risk Factors:

Delivery Channel Risk Factors:

3.5.2 Risk Rating Methodology

Institutions develop risk rating methodologies to classify customers. A typical approach:

Risk Level Characteristics CDD Requirements
Low Domestic retail customer, standard products, no elevated risk factors Standard CDD, periodic reviews every 3-5 years
Medium Small business, moderate transaction volumes, some complexity Standard CDD with enhanced monitoring, reviews every 2-3 years
High PEP, high-risk jurisdiction, cash-intensive business, complex structure Enhanced Due Diligence, senior approval, continuous monitoring, annual reviews
Prohibited Sanctioned parties, shell banks, anonymous accounts Relationship not permitted

3.6 Ongoing Due Diligence

CDD is not static; it requires ongoing monitoring and periodic updates throughout the customer relationship.

3.6.1 Transaction Monitoring

Institutions must monitor transactions to ensure consistency with the understanding of the customer and to identify unusual or suspicious activities. This includes:

3.6.2 Periodic Reviews

Customer information and documentation must be reviewed and updated periodically, with frequency determined by risk level:

Reviews should update identifying information, beneficial ownership, risk assessments, and understanding of the business relationship.

3.6.3 Event-Triggered Reviews

Certain events should trigger immediate review and update of CDD:

3.7 Simplified Due Diligence

While regulations focus heavily on enhanced measures for high-risk scenarios, many jurisdictions allow simplified due diligence for demonstrably low-risk situations, such as:

However, simplified due diligence still requires identification and basic verification; it cannot be used if there are suspicions of money laundering or terrorist financing.

3.8 Documentation and Record-Keeping

Comprehensive documentation is essential for demonstrating compliance and supporting investigations.

3.8.1 Required Records

Institutions must maintain records including:

3.8.2 Retention Requirements

Most jurisdictions require retention of CDD records for a minimum of five years after the end of the business relationship, though some require longer periods.

Records must be readily retrievable and available to regulators and law enforcement upon request.

3.9 Challenges in CDD Implementation

3.9.1 Customer Experience vs. Compliance

Balancing thorough CDD with customer experience presents ongoing challenges. Excessive documentation requests or lengthy verification processes can drive customers away, while inadequate CDD creates compliance and reputational risks.

Solutions include:

3.9.2 Data Quality and Availability

Obtaining accurate, current information can be challenging, particularly for:

3.9.3 Technology and Automation

While technology offers solutions, implementation challenges include:

3.10 Best Practices and Emerging Trends

3.10.1 Digital Identity

Digital identity solutions using blockchain, biometrics, and other technologies promise to streamline CDD while enhancing security and accuracy.

3.10.2 Utility Models

KYC utilities allow multiple institutions to share CDD information, reducing duplication and improving efficiency while maintaining compliance.

3.10.3 Perpetual KYC

Moving beyond periodic reviews, perpetual KYC uses continuous monitoring of multiple data sources to maintain real-time understanding of customers.

3.11 Conclusion

Customer Due Diligence forms the foundation upon which all other KYC/AML measures rest. Effective CDD requires thorough customer identification and verification, understanding of beneficial ownership, assessment of risks, and ongoing monitoring throughout the relationship.

As technology advances and regulations evolve, CDD processes continue to become more sophisticated, leveraging automation and data analytics while maintaining focus on the fundamental objective: knowing your customer.

Chapter Summary: This chapter examined the comprehensive requirements for Customer Due Diligence, including customer identification, beneficial ownership, risk assessment, ongoing monitoring, and documentation. These processes form the cornerstone of effective KYC/AML programs.

Korea Digital Transformation Detailed Mapping

Korea operates digital transformation through a comprehensive governance system. Digital Government: Digital Platform Government Committee (established September 2022, under the President)·Ministry of the Interior and Safety Digital Government Bureau·e-Government Support Center·Gov.kr·National Citizen Service·KDIS (Korea Digital Information Society)·NIA (National Information Society Agency)·MOIS (Ministry of the Interior and Safety). K-DNS Infrastructure: Korea Internet & Security Agency (KISA) Korea Internet Center·KISA DNS Root Server·KRNIC (Korea Network Information Center)·BGP Korea·National Cyber Security Center (NCSC)·KCC (Korea Communications Commission)·MSIT (Ministry of Science and ICT)·NIA·NIPA. Korean Cloud Infrastructure: KT Cloud·NAVER Cloud (NCloud)·Samsung SDS Cloud·LG U+ Cloud·NHN Cloud·Kakao Enterprise Cloud·SK Telecom Cloud·KISA Cloud Security Assurance Program (CSAP)·KCMVP-validated cloud·ISMS-P (Information Security & Personal Information Management System). Korean Security Certifications: KISA ISMS-P certification·KCMVP (Korean Cryptographic Module Validation Program)·NIS (National Intelligence Service) "National Cryptographic Technology Operation Standards"·NCSC "National Cyber Security Strategy 2024-2028"·CC (Common Criteria) Korean evaluation bodies·EAL4·EAL5·KS X ISO/IEC 15408·19790·24759 Korean Profile. Korean Data Standards: NIA AI Hub·National Data Standardization Committee·Statistics Korea (KOSTAT)·MyData 4 Designated Combination Specialists (Samsung SDS, KICI, KOSTAT, KFTC)·National Institute of Korean Language·National Law Information Center·National Spatial Information Platform·National Spatial Data Center·Korean Spatial Information Standards. Finance and Fintech Standards: FSC (Financial Services Commission)·FSS (Financial Supervisory Service)·FIU (Financial Intelligence Unit)·BOK (Bank of Korea)·FSEC (Financial Security Institute)·KFTC (Korea Financial Telecommunications)·KSD (Korea Securities Depository)·KRX (Korea Exchange) 8-agency cooperation. 5G/6G Communications Infrastructure: 5G subscribers 35 million (2024)·5G base stations 350,000·6G commercialization target 2028·5G dedicated networks 16 operators·6G Acceleration Council (MSIT, 2024). K-Content: KOCCA (Korea Creative Content Agency)·MCST (Ministry of Culture, Sports and Tourism)·KCA (Korea Communications Agency)·Korea Culture Information Service Agency·Korean Film Archive·Korea Publishing Industry Promotion Agency. Data 3 Acts (Personal Information Protection Act·Credit Information Act·Telecommunications Network Act, 2020 enforcement)·Data Industry Act (2021)·Public Data Act (2013)·AI Framework Act (2026)·Digital Platform Government Framework Act (2024 proposed) — Korea digital transformation core legislation.

Korea Industrial, Research, Education Infrastructure Mapping

Korea operates its industrial ecosystem and standardization system through the following core infrastructure. Korea Top 5 Groups: Samsung, Hyundai Motor, LG, SK, Lotte. Each group operates standardization committees and ISO/IEC TC Korean secretariats. Samsung Electronics (semiconductors, displays, home appliances, telecom)·Hyundai Motor (automobiles, mobility)·LG Electronics (home appliances, displays, OLED)·SK hynix (memory)·LG Energy Solution·Samsung SDI (batteries)·POSCO Future M (materials)·Hyundai Mobis (parts). Korean IT Big Tech: NAVER (search, cloud, AI HyperCLOVA)·Kakao (messenger, payment, mobility, banking)·Coupang (e-commerce, logistics)·Karrot Market·Toss·Woowa Brothers. Korea Telcos: SK Telecom·KT·LG U+. 5G·5G dedicated networks·B2B cloud·AI businesses operating. Korea Top 7 Research Universities: Seoul National University·KAIST·POSTECH·Yonsei University·Korea University·UNIST·DGIST·GIST. All serve as standardization R&D bases and ISO/IEC/IEEE Korean chairs. Korea Government-affiliated National Research Institutes (26): KIST, KAERI, KIMM, KIER, KFRI, KRICT, KRIBB, KARI, KASI, KIGAM, KICT, KISTI, KETI, ETRI, NIMS, KIMS, KISDI, KOTRA, STEPI, KOEN, KICCE, KIET, KIPF, KIHASA, KICJ, KLRI. Korea Industrial Complexes / Tech Valleys: Pangyo Techno Valley·Dongtan·Gwanggyo·Songdo IBD·Yeouido·Gangnam·Sihwa·Banwol·Gumi·Ulsan·Changwon·Geoje·Yeosu·Onsan·Cheongju·Iksan·Gwangyang·POSCO Gwangyang Steel Mill·Asan Bay·Seosan·Songdo·Incheon Airport·Sejong·Cheongna·Geomdan. Korea Trade and Finance Infrastructure: Korea International Trade Association (KITA)·Korea Trade-Investment Promotion Agency (KOTRA)·Export-Import Bank of Korea (KEXIM)·Bank of Korea·Kookmin Bank·Shinhan·Hana·Woori·NH Nonghyup·IBK Industrial Bank·SC First Bank·Citi Bank Korea·HSBC Korea·DBS Korea — 14 Korean major banks and foreign banks. Korea K-POP / K-Content: HYBE·SM·YG·JYP 4 major entertainment companies·CJ ENM·tvN·MBC·KBS·SBS·EBS·YTN·Yonhap News TV·JTBC Korean broadcasting·NETFLIX Korea·Disney Plus·TVING·Wavve·Watcha·Coupang Play. Korea Gaming Industry: Nexon·NCsoft·Krafton·Netmarble·Kakao Games·Pearl Abyss·Com2uS·Gamevil·NHN·Smilegate·Webzen. Korea Automotive / Battery: Hyundai Motor·Kia·Genesis·LG Energy Solution·Samsung SDI·SK On·POSCO Future M·EcoPro·L&F battery cathode material suppliers. Korea Semiconductor: Samsung Electronics (HBM3E·HBM4)·SK hynix (HBM3E 12-Hi)·DB HiTek·SK siltron·SK Enpulse·Dongjin Semichem·Seoul Semiconductor·Simmtech·Samsung Display·LG Display.

Korea Industrial Cluster, National Strategic Technologies, Workforce Development

Korea operates a comprehensive industrial cluster system. Korea Top 12 National Strategic Technologies (5th Science and Technology Master Plan 2023-2027): (1) Semiconductors and Displays (2) Secondary Batteries (3) Advanced Mobility (autonomous driving, UAM) (4) Next-Generation Nuclear (SMR) (5) Advanced Bio (6) Aerospace and Marine (7) Hydrogen (8) Cybersecurity (9) Artificial Intelligence (10) Next-Generation Communications (11) Advanced Robotics and Manufacturing (12) Quantum. 12 fields receive direct investment of 5 trillion KRW annually, cumulative 30 trillion KRW by 2030. Korea Major Industrial Clusters: Pangyo IT Cluster (1,300+ companies, 100 trillion KRW revenue), Gangnam Fintech (200+ companies), Songdo BT Bio Cluster, Daegu Medical Cluster, Ulsan Industry (shipbuilding, petrochemicals, automotive), Changwon Machinery, Changwon National Industrial Complex, Siheung and Banwol (SME manufacturing), Yeosu Petrochemicals, Pyeongtaek Semiconductor (Samsung Electronics Pyeongtaek Campus), Icheon and Cheongju Semiconductor (SK hynix Icheon and Cheongju Campuses), Asan Display (Samsung Display Asan Campus), Gumi Mobile (Samsung Gumi Campus), Pohang Steel (POSCO Pohang Steel Mill), Gwangyang Steel (POSCO Gwangyang Steel Mill), Dangjin Steel (Hyundai Steel Dangjin), Ulsan Automotive (Hyundai Motor Ulsan Plant), Asan Automotive (Hyundai Asan Plant), Kia Gwangju and Sohari, POSCO Gwangyang and Pohang Steel Mills, SK hynix Icheon and Cheongju, Samsung Electronics Hwaseong, Giheung, Pyeongtaek, Onyang, Cheonan, Asan Semiconductor Facilities. Major Industrial Complexes and Techno Valleys: Pangyo Techno Valley (1st 800 companies, 2nd 600 companies, 3rd 1,200 companies), Dongtan Techno Valley, Gwanggyo Techno Valley, Songdo IBD, Yeouido Financial District, Gangnam Teheran-ro Valley, Sihwa, Banwol, Gumi, Ulsan, Changwon, Geoje, Yeosu, Ulsan Mipo, Onsan, Cheongju, Iksan, Gwangyang, Yeosu, POSCO Gwangyang Steel Mill, Asan Bay, Seosan, Songdo, Incheon Airport, Sejong, Cheongna, Geomdan, Pyeongtaek Automotive Industrial Complex, Giheung Semiconductor Complex, Icheon Semiconductor Complex, Asan Display Complex, Gumi Mobile Complex, Changwon National Industrial Complex, Ulsan Mipo National Industrial Complex, Yeosu National Industrial Complex, Onsan National Industrial Complex. Korea Workforce Statistics: STEM undergraduate students 700,000 (26% of all university students), STEM graduate students 170,000, PhD researchers 140,000, STEM doctorates conferred 8,000 annually (Seoul National University 1,200, KAIST 800, POSTECH 400, Yonsei University 700, Korea University 600, UNIST 250, DGIST 100, GIST 200, KISTI 50, KIST and ETRI postdoctoral programs 1,000), information security experts 300,000 (KISA-trained and private), AI experts 50,000 (NIA, IITP, NIPA, Samsung, LG, SK, NAVER, Kakao trained), semiconductor experts 260,000 (Samsung Electronics 60,000, SK hynix 30,000, DB HiTek, SK siltron). National R&D Project Operation: National R&D projects 100,000+ annually (MSIT 35,000, MOTIE 25,000, MSS 20,000, MOE 15,000, others 5,000), R&D participating institutions 25,000+, R&D participating researchers 530,000, National R&D output (papers, patents) 540,000 annually. Korea Corporate R&D Investment Top 10 (2024): Samsung Electronics 28 trillion KRW, LG Electronics 9 trillion KRW, SK hynix 8 trillion KRW, Hyundai Motor 6 trillion KRW, Kia 4 trillion KRW, LG Chem 3.5 trillion KRW, LG Display 3.2 trillion KRW, POSCO 3 trillion KRW, Samsung SDI 2.7 trillion KRW, SK Innovation 2.5 trillion KRW.

Korea Global Standards Cooperation — Quantum, Bio, Aerospace, AI

Korea leads global standardization cooperation in 4th industrial revolution technologies. Korea Quantum Technology Standards: "Quantum Science and Technology Comprehensive Development Plan 2024-2030" (8 trillion KRW R&D), National Quantum Science and Technology Committee, MSIT Quantum Technology Bureau, KIST Quantum Information Research Division, KAIST Quantum Graduate School, POSTECH Quantum Science and Technology Division, KAIST IQC, Seoul National University Quantum Information Center, Korea Institute for Advanced Study Quantum Computing Division, KRISS Quantum Measurement Standards Center, SK Telecom QKD, KT QKD, LG U+ QKD, Samsung SDS PQC, Easy Security, CryptoLab Quantum-Resistant Cryptography, KS X ISO/IEC 18033-3, NIST PQC ML-KEM/ML-DSA/SLH-DSA Korean adoption, QKD ETSI GS QKD series Korean Profile. Korea Next-Generation Communications (5G/6G) Standards: 5G subscribers 35 million, 5G base stations 350,000, 5G dedicated networks 16 operators, 6G Acceleration Council (MSIT 2024), 6G commercialization target 2028, 3GPP Release 18/19/20 Korean participation, KS X 3GPP, Samsung Research 6G, LG Electronics 6G, KT 6G, SK Telecom 6G, LG U+ 6G, NIA, ETRI, KAIST, POSTECH, Seoul National University 6G Research Division, O-RAN ALLIANCE Korean Chair Company, M-CORD, OpenRAN Korean Cooperation. Korea AI Standards: KS X ISO/IEC 22989 (AI Concepts and Terminology), KS X ISO/IEC 23053 (AI System Framework), KS X ISO/IEC 5338 (AI System Lifecycle), KS X ISO/IEC 24029 (AI Trustworthiness and Robustness), KS X ISO/IEC 24028 (AI Trustworthiness), KS X ISO/IEC 23894 (AI Risk Management), KS X ISO/IEC 38507 (AI Governance), KS X ISO/IEC 42001 (AIMS Operations System), KS X ISO/IEC 42005 (AI Impact Assessment), AI Framework Act (effective July 2026) Enforcement Decree, Mandatory ex-ante impact assessment for high-impact AI, Samsung Research HyperCLOVA X, LG AI Research EXAONE, SK Telecom A., KT Media AI, NAVER Clova, Kakao i Korean foundation models. Korea Bio Standards: KS X ISO 20387 (Biobanking), KS X ISO 21709, KS X HL7 FHIR R5, SNOMED CT, LOINC, KCD-8, ICD-11, OMOP CDM v5.4, CDISC SDTM, DICOM, HL7 V2, HL7 CDA, MFDS GMP, MFDS Good Tissue Practice, MFDS AI Medical Device Guidelines (50+ approvals), KRIBB, KRICT, KFRI, KIST, KAIST, POSTECH Bio R&D Centers, Samsung Biologics, Celltrion, SK Bioscience, GC Biopharma, LG Chem, Chong Kun Dang, Yuhan Korean Bio Pharmaceuticals, 6 Major Hospitals (Seoul National University, Samsung, Asan, Severance, Bundang Seoul National University, Korea University) Clinical Trial Infrastructure. Korea Aerospace Standards: Korea AeroSpace Administration (KASA, established May 27 2024), MSIT, Ministry of National Defense, KARI, KASI, KIGAM, ETRI, KAI, Hanwha Aerospace, Hanwha Systems, LIG Nex1, CCSDS, ITU, NORAD, IADC, NASA, ESA, JAXA, CNSA, ISRO Korean Cooperation, KS W ISO 14620, KS W ISO 11227, KS W ISO 27026, Nuri Rocket KSLV-II, KSLV-III, Danuri KPLO, Next-Generation Reconnaissance Satellite 425 Project, Arirang, Cheollian, KOMPSAT, CAS500 series. Korea Secondary Battery Standards: "3rd Secondary Battery Industry Development Strategy 2024-2030", MOTIE Secondary Battery Bureau, LG Energy Solution, Samsung SDI, SK On, POSCO Future M, EcoPro BM, L&F, DI Dongil, Samsung SDI Korean Secondary Battery 6 Companies, KS C IEC 62660, KS C IEC 62619, KS C IEC 62133, UN ECE R100, UN/ECE R136 Korean Adoption. Korea Semiconductor Standards: Samsung Electronics (HBM3E, HBM4, DDR5, LPDDR5X), SK hynix (HBM3E 12-Hi, HBM4), DB HiTek, SK siltron, SK Enpulse, Dongjin Semichem, Seoul Semiconductor, Simmtech, Samsung Display, LG Display, JEDEC, SEMI, IEEE, KS C IEC 60068, UCIe 1.1/2.0, CXL 3.0/3.1, HBM4 Standardization, DDR6 Standardization, LPDDR6 Standardization, MRAM, ReRAM, PCRAM Korean Standards Adoption.

📐 시뮬레이터 패널 2