5.1 Customer Due Diligence (CDD) & KYC for Sanctions

Key Takeaways

  • While standard Anti-Money Laundering (AML) CDD identifies Ultimate Beneficial Owners (UBOs) at a statutory 25% threshold, sanctions compliance requires look-through to lower thresholds (often 10% or lower) to capture aggregated blocked ownership stakes.
  • Customer Identification Program (CIP) and CDD data—including full legal names, transliterations, primary addresses, registration/tax identifiers, and corporate registry documentation—constitute the foundational dataset for fuzzy-logic sanctions screening engines.
  • Establishing the commercial nature and purpose of a customer's business creates an expected behavioral baseline (counterparties, corridors, volumes) essential for detecting anomalous transactions indicative of sanctions evasion.
  • Control persons (executive officers, managing directors, authorized signatories) must be screened alongside equity owners, as operational control can freeze entities under EU and UK regimes and trigger US facilitation prohibitions.
  • Trigger events such as material ownership changes, board restructurings, cross-border jurisdictional expansions, and adverse media require immediate dynamic re-screening rather than waiting for periodic KYC refresh cycles.
Last updated: August 2026

5.1 Customer Due Diligence (CDD) & KYC for Sanctions

Core Principle: Customer Due Diligence (CDD) and Know Your Customer (KYC) procedures provide the primary intelligence layer for sanctions compliance. While AML frameworks focus on money laundering risk using statutory 25% ownership thresholds, sanctions due diligence operates under a strict liability mandate that requires identifying beneficial owners, control persons, and indirect nexus down to much lower thresholds to prevent transactions with designated targets.


1. The Intersection of AML/KYC and Sanctions Due Diligence

Financial institutions and multinational corporations maintain Know Your Customer (KYC) and Customer Due Diligence (CDD) programs primarily to satisfy Anti-Money Laundering (AML) and Counter-Financing of Terrorism (CFT) statutory obligations. However, sanctions compliance relies fundamentally on the identity data collected through these onboarding and lifecycle maintenance processes.

Despite their shared reliance on customer identity data, AML due diligence and sanctions due diligence differ substantially in their underlying legal standards, regulatory objectives, and risk tolerances:

+---------------------------------------------------------------------------------------------------+
|                     AML DUE DILIGENCE vs. SANCTIONS DUE DILIGENCE                                 |
+------------------------------------+-------------------------------+------------------------------+
| DIMENSION                          | AML / CFT DUE DILIGENCE       | SANCTIONS DUE DILIGENCE      |
+------------------------------------+-------------------------------+------------------------------+
| Legal Liability Standard           | Risk-Based Approach (RBA)     | Strict Liability (Civil)     |
| Primary Objective                  | Detect & Report Suspicion     | Prevent Prohibited Dealings  |
| Beneficial Ownership Threshold     | Statutory 25% (FATF / FinCEN) | Aggregation to 50% (OFAC/EU) |
| Look-Through Threshold Practice    | 25% (10% for High Risk)       | 10% or Lower / 0% Look-thru  |
| Target Identification Timing       | Transaction Monitoring (Post) | Real-Time / Pre-Execution    |
| Reporting Mechanism                | SAR / STR (Confidential)      | Blocking / Freezing Report   |
+------------------------------------+-------------------------------+------------------------------+

The Operational Tension

Under AML regulations (such as the Financial Action Task Force [FATF] Recommendations 10 and 24, and the US FinCEN CDD Rule at 31 CFR § 1010.230), institutions apply a Risk-Based Approach (RBA). Under an RBA, compliance resources are scaled proportionally to the identified risk of the customer, product, or geographic corridor.

In contrast, economic sanctions enforcement (such as OFAC civil penalties under 31 CFR Part 501, or UK OFSI penalties under the Sanctions and Anti-Money Laundering Act 2018) operates on a strict liability standard. A financial institution cannot defend an unlawful transaction with a designated entity by arguing that it applied a reasonable risk-based methodology. Consequently, sanctions compliance teams must leverage CDD files to perform precise, comprehensive look-through investigations regardless of customer risk tiering.


2. Customer Identification Program (CIP) & Verification Standards

A robust Customer Identification Program (CIP) establishes the baseline identity attributes required for automated and manual sanctions screening engines. Without verified, standardized, and cleansed CIP data, fuzzy-logic name matching and screening filters cannot function effectively.

+-----------------------------------------------------------------------------------+
|                         CIP TO SANCTIONS SCREENING PIPELINE                       |
+-----------------------------------------------------------------------------------+
|  [1. DOCUMENT COLLECTION]  -->  [2. DATA NORMALIZATION]  -->  [3. RESOLUTION]     |
|  - Legal Name / Trade Name       - Transliteration (Latin)     - Fuzzy Matching   |
|  - National Tax ID / Reg #       - Field Cleansing / UTF-8     - Alias Expansion  |
|  - Registered / Phys. Addr       - ISO 3166 Country Codes      - Geofence Filters |
|  - Articles of Association       - SWIFT / BIC Validation      - Secondary Review |
+-----------------------------------------------------------------------------------+

Required Data Elements for Natural Persons

  • Full Legal Name and Known Aliases: First, middle, and surnames, including patronymics, maiden names, and alternative spellings.
  • Date and Place of Birth: Essential for resolving common names (reducing false positives) and distinguishing target names from homonyms.
  • Nationalities and Dual Citizenships: Passports, national identity cards, and permanent residency statuses (critical for determining jurisdictional nexus and applicable sanctions prohibitions).
  • Residential and Mailing Addresses: Physical street address (P.O. Boxes alone are prohibited under CIP standards) and country of tax residence.
  • Government-Issued Identification Number: Tax identification number (TIN), Social Security number (SSN), or passport number with issuing country and expiration date.

Required Data Elements for Legal Entities

  • Full Registered Legal Name and Trading Names (DBA): Exact corporate title as registered with the official corporate registrar, including abbreviations (e.g., LLC, GmbH, PJSC, SA, Ltd.).
  • Principal Place of Business & Registered Address: Physical operational headquarters and jurisdiction of incorporation.
  • Corporate Registration / Tax Identifier: Commercial register extract, Unique Entity Identifier (UEI), LEI (Legal Entity Identifier), or VAT registration number.
  • Corporate Governance Documents: Certified Articles of Incorporation, Memorandum of Association, Certificates of Good Standing, and Shareholder Registers.
  • Identity of Authorized Signatories and Senior Executives: Board of directors, Chief Executive Officer (CEO), Chief Financial Officer (CFO), and persons authorized to bind the entity.

Identity Resolution & Script Transliteration

A common sanctions vulnerability arises from variations in name spelling across different alphabets (e.g., Cyrillic, Arabic, Chinese Hanzi, Persian Farsi). Compliance policies must enforce standardized transliteration algorithms (such as the BGN/PCGN or ISO standards) and mandate that customer records capture both local native script and Latin-character transliterations.


3. Determining the Nature and Purpose of Business

Understanding the commercial context of a customer's business is vital for distinguishing legitimate commercial operations from sanctions evasion conduits. Institutions must document the expected transactional baseline during onboarding:

  1. Core Economic Activity: Standard Industrial Classification (SIC) or North American Industry Classification System (NAICS) codes defining the industry sector (e.g., maritime logistics, crude oil refining, dual-use electronics manufacturing, aerospace maintenance).
  2. Geographic Corridors: Expected source and destination countries for cross-border wire transfers, supply chains, and distribution channels, paying specific attention to border countries contiguous to sanctioned jurisdictions (e.g., Central Asian states, UAE, Turkey).
  3. Customer Base and Key Counterparties: Major suppliers, primary commercial buyers, and correspondent banking relationships.
  4. Anticipated Transaction Volume & Frequency: Baseline estimates of monthly turnover, transaction values, and standard payment methods (e.g., open account, letters of credit, cash-against-documents).
+-----------------------------------------------------------------------------------+
|            NATURE & PURPOSE EVALUATION: RED FLAG PROFILE MATRIX                   |
+------------------------------------+----------------------------------------------+
| PROFILE ATTRIBUTE                  | SANCTIONS RED FLAG INDICATOR                 |
+------------------------------------+----------------------------------------------+
| Line of Business vs. Transactions  | Electronics exporter shipping oil equipment  |
| Geographic Operating Footprint     | High volume routing through border free zones|
| Corporate Age vs. Volume Turnover  | Newly formed entity executing $50M+ contracts|
| Counterparty Concentration         | 90%+ revenues derived from single opaque SPV |
| Delivery & Logistics Channels      | Ship-to-ship transfer zones, flag-of-convenience
+------------------------------------+----------------------------------------------+

4. Beneficial Ownership (UBO) vs. Control Persons

International regulatory standards mandate the identification of two distinct categories of individuals within any legal entity:

Entity Governance Architecture=Equity Owners (UBOs)+Control Persons (Management)\text{Entity Governance Architecture} = \text{Equity Owners (UBOs)} + \text{Control Persons (Management)}

A. Ultimate Beneficial Owners (UBOs)

A UBO is any natural person who ultimately owns or controls a legal entity through direct or indirect equity shareholding, voting rights, or economic interest. Under standard corporate laws, an entity cannot be its own beneficial owner; compliance officers must peel back holding companies, trusts, and shell entities until a living natural person is identified.

B. Control Persons (The Control Prong)

A Control Person is an individual who possesses significant responsibility to control, manage, or direct a legal entity. Under FinCEN's CDD Rule and international equivalents, every corporate customer must identify at least one natural person under the control prong (e.g., CEO, Managing Director, General Partner), regardless of whether they own equity.

[!IMPORTANT] Why Control Persons Matter for Sanctions:

  • EU and UK Sanctions: An entity can be frozen based on control alone, even if a sanctioned individual owns 0% of the equity (e.g., an SDN serving as Managing Director or holding dominant board influence).
  • US OFAC Sanctions: While OFAC's 50% Rule applies to equity ownership, an SDN serving as CEO creates severe facilitation risks (31 CFR § 560.208), as US persons cannot execute contracts, approve payments, or deal with companies managed by blocked persons.

5. AML Risk Thresholds (25%) vs. Sanctions Exposure Thresholds

A critical compliance vulnerability occurs when institutions blindly apply the standard AML 25% UBO threshold to sanctions due diligence.

Compliance ParameterAML Regulatory StandardSanctions Due Diligence Standard
Statutory Threshold25% equity ownership per natural person50% aggregate ownership by blocked persons
Aggregation MandateIndividual stakes assessed separatelyStakes of all blocked persons summed together
Look-Through Best Practice25% for standard risk; 10% for high risk10% or 0% complete look-through
Legal Consequence of FailureRegulatory finding / AML deficiencyStrict liability civil penalty / asset block
+-----------------------------------------------------------------------------------+
|          THE 25% AML BLIND SPOT: WHY SANCTIONS REQUIRE DEEPER LOOK-THROUGH         |
+-----------------------------------------------------------------------------------+
|                                                                                   |
|                 +-----------------------------------------------+                 |
|                 |                  TARGET CORP                  |                 |
|                 +-----------------------+-----------------------+                 |
|                                         |                                         |
|         +-------------------------------+-------------------------------+         |
|         |                               |                               |         |
|         v                               v                               v         |
|  +-------------+                 +-------------+                 +-------------+  |
|  |   SDN A     |                 |   SDN B     |                 | Clean Owner |  |
|  | 20% Equity  |                 | 20% Equity  |                 | 60% Equity  |  |
|  +-------------+                 +-------------+                 +-------------+  |
|         |                               |                               |         |
|         +-------------------------------+-------------------------------+         |
|                                         |                                         |
|   * AML Review (25% Rule): Neither SDN exceeds 25%. UBOs NOT recorded!            |
|   * Aggregated Sanctions Stake: 20% + 20% = 40% Blocked Ownership.                |
|   * RESULT: Target Corp is 40% SDN owned. If a 3rd SDN acquires 10%, it is BLOCKED!|
+-----------------------------------------------------------------------------------+

If an institution only collects UBO data for shareholders owning $\ge 25%$, it will remain completely blind to situations where two sanctioned individuals each own 20% ($40%$ total) or three sanctioned individuals each own 17% ($51%$ total—automatically blocked under OFAC rules). Best-practice sanctions programs mandate unwrapping ownership chains down to 10% or 5% for all entity structures.


6. Dynamic KYC Refresh Triggers vs. Periodic Review Cycles

Traditional AML programs schedule KYC reviews on fixed periodic cycles based on customer risk classification:

  • High-Risk Customers: Annual review (every 12 months).
  • Medium-Risk Customers: Biennial review (every 24 to 36 months).
  • Low-Risk Customers: Periodic review (every 36 to 60 months).

Because sanctions lists change daily and corporate structures can be reorganized overnight to evade imminent designations, relying solely on periodic review cycles creates unacceptable sanctions risk. Institutions must implement dynamic, event-driven trigger mechanisms.

+-----------------------------------------------------------------------------------+
|                       EVENT-DRIVEN KYC REFRESH TRIGGERS                           |
+-----------------------------------------------------------------------------------+
|  1. STRUCTURAL CHANGE  --> Change in UBO, board of directors, or parent entity    |
|  2. JURISDICTION SHIFT --> New operations in border countries or transshipment hubs|
|  3. ADVERSE MEDIA      --> Allegations of corruption, illicit trade, or SDN ties  |
|  4. TRANSACTION ANOMALY--> Sudden 500% surge in volume or circular trade routes   |
|  5. SCREENING NEAR-MISS--> Potential fuzzy match on new counterparty or director   |
+-----------------------------------------------------------------------------------+

High-Yield CDD Verification Checklist

[ ] Corporate registry documentation retrieved directly from official government portal.
[ ] Certificate of Good Standing verified within last 90 days.
[ ] All intermediate holding entities unwrapped to identify ultimate natural persons.
[ ] Beneficial ownership percentages documented down to 10% (or 0% for high risk).
[ ] Full legal names of all UBOs and Control Persons screened against SDN/Consolidated lists.
[ ] Native script and standardized Latin transliterations captured for all foreign names.
[ ] Business model and expected trade corridors validated against physical business address.
[ ] Source of Wealth (SoW) and Source of Funds (SoF) verified with independent documents.

7. Key Distinctions and Exam Traps

[!WARNING] Exam Trap 1: The 25% Ownership Fallacy An exam question may state that a customer has three shareholders: Person A (30%), Person B (20%), and Person C (20%). If Persons B and C are SDNs, the AML officer might only identify Person A as a UBO under the 25% AML rule. However, from a sanctions perspective, Persons B and C aggregate to 40% blocked ownership. If either acquires an additional 10%, the company is blocked by operation of law. Always aggregate all blocked stakes regardless of individual percentage!

[!WARNING] Exam Trap 2: Control Persons vs. Beneficial Owners Never assume that an individual who holds no equity cannot create sanctions liability. If a sanctioned person is appointed as Chief Executive Officer, General Director, or Chairman of the Board, US persons are prohibited from facilitating transactions signed or directed by that individual, and the entity may be considered frozen under UK OFSI and EU control rules.

Loading diagram...
Customer Due Diligence (CDD) to Sanctions Screening Architecture
Test Your Knowledge

A global compliance officer at an international bank is designing an onboarding beneficial ownership policy for corporate customers. The bank's standard AML onboarding procedure requires identifying and verifying beneficial owners holding a 25% or greater equity interest. Why is this 25% threshold insufficient for mitigating sanctions risk?

A
B
C
D
Test Your Knowledge

During a routine compliance review, an analyst discovers that a corporate customer operating in the renewable energy sector has made three significant changes over the past month: its registered address moved to a free trade zone near an embargoed border, a new Chief Executive Officer was appointed who is a known relative of a designated official, and monthly transaction volumes increased by 400%. The account is not due for its periodic KYC review for another 18 months. What action should the compliance department take?

A
B
C
D
Test Your Knowledge

An international bank is onboarding a multinational trading company incorporated in Singapore. The company provides a certified commercial register showing that 100% of the voting shares are held by an unlisted holding company in Cyprus. When the bank requests the identity of the natural persons behind the Cypriot holding company, the customer refuses, stating that standard local corporate law only requires disclosing the direct corporate shareholder. How should the bank proceed?

A
B
C
D
Test Your Knowledge

Which of the following data elements gathered during the Customer Identification Program (CIP) is MOST critical for resolving false positive name matches in automated sanctions screening systems?

A
B
C
D