14.1 Customer Due Diligence (CDD) and Know-Your-Customer (KYC)
Key Takeaways
Under Republic Act No. 9160 (AMLA), as amended, and SEC Memorandum Circular No. 16 (Series of 2018), as amended, Customer Due Diligence (CDD) must follow a Risk-Based Approach (RBA) tiered into Simplified, Standard, and Enhanced Due Diligence.
Simplified Due Diligence (SDD) is permitted strictly for demonstrably low-risk clients—such as publicly listed companies, government agencies, and regulated financial institutions—and is strictly disqualified if money laundering suspicion arises.
Natural person identification mandates verifying full legal name, date and place of birth, nationality, residential address, TIN, and a valid government photo ID, with the Philippine National ID (PhilID/ePhilID) under RA 11055 holding statutory primacy as sufficient standalone proof of identity.
Beneficial ownership identification requires covered institutions to uncover the natural person(s) who ultimately own or control at least 20% of voting shares or capital stock, or who exercise ultimate effective control over a juridical entity.
SRC Rule 52.1.6.12 retains a face-to-face-meeting requirement for new broker-dealer accounts; technology may support identity capture and verification, but invented universal liveness, OCR, or geolocation mandates must not replace the controlling rule.
14.1 Customer Due Diligence (CDD) and Know-Your-Customer (KYC)
In the Philippine capital markets, Customer Due Diligence (CDD) and Know-Your-Customer (KYC) protocols serve as the foundational frontline defenses against financial crime, predicate criminal exploitation, and illicit capital flows. Governed primarily by Republic Act No. 9160, known as the Anti-Money Laundering Act of 2001 (AMLA)—as amended by Republic Act Nos. 9194, 10167, 10365, 10927, and 11521—and operationalized through the 2018 AMLA Implementing Rules and Regulations (2018 AMLA IRR) and Securities and Exchange Commission (SEC) Memorandum Circular No. 16, Series of 2018 (2018 AML/CFT Guidelines for SEC-Covered Institutions), as amended, registered market intermediaries are bound by rigorous statutory standards before establishing any business relationship or executing transactions.
Under Section 9(a) of AMLA, covered persons—including securities brokers, dealers, investment houses, mutual fund distributors, and transfer agents—are strictly prohibited from maintaining anonymous accounts, accounts opened under fictitious names, or numbered accounts. Every account maintained on the books of an SEC-registered entity must be tied to an authenticated, verified legal identity.
The Risk-Based Approach (RBA) to CDD: The Three-Tier System
Philippine anti-money laundering regulations mandate that covered persons adopt a Risk-Based Approach (RBA) in designing and implementing their CDD programs. Rather than applying a rigid, one-size-fits-all checklist, institutions must assess the specific money laundering, terrorist financing, and proliferation financing (ML/TF/PF) risks posed by customers, products, delivery channels, and geographic jurisdictions. Based on this risk assessment, institutions apply one of three distinct tiers of due diligence.
Customer Due Diligence (CDD) Tier Hierarchy
├── Simplified Due Diligence (SDD) [Low Risk: Reduced Verification; Zero ML Suspicion]
├── Standard Due Diligence (CDD) [Normal/Medium Risk: Standard ID, Proof of Address, TIN, UBO]
└── Enhanced Due Diligence (EDD) [High Risk: PEPs, Complex Trusts, SOW/SOF, Senior Mgmt Approval]
1. Simplified Due Diligence (SDD)
Simplified Due Diligence represents a streamlined onboarding protocol reserved exclusively for relationships presenting demonstrably low ML/TF risk.
- Eligible Entities: Publicly listed companies (PLCs) on the Philippine Stock Exchange (PSE) subject to regulatory disclosure regimes; Philippine government departments, bureaus, and local government units (LGUs); Government-Owned and Controlled Corporations (GOCCs); domestic banking institutions and financial entities supervised by the Bangko Sentral ng Pilipinas (BSP), the SEC, or the Insurance Commission (IC); and low-value retail investment products meeting strict financial inclusion caps.
- Permissible Concessions: Where the governing rules permit SDD, measures may be proportionate to the demonstrated low risk. The institution must still identify the customer, understand the relationship, screen relevant parties, and perform ongoing monitoring; SDD is not anonymous or verification-free onboarding.
- The Absolute Exclusion Trap: Under the 2018 AMLA IRR, SDD is strictly prohibited whenever there is a suspicion of money laundering or terrorist financing, or where specific high-risk indicators are detected. The emergence of any red flag immediately invalidates SDD and mandates escalation to Standard or Enhanced Due Diligence.
2. Standard Due Diligence (Standard CDD)
Standard Due Diligence is the default baseline applied to commercial relationships with individuals and corporate entities carrying average or moderate risk profiles. It requires full identification and independent verification of the customer, identification of the ultimate beneficial owners (UBOs), acquisition of information regarding the purpose and intended nature of the business relationship, and ongoing monitoring of account activity.
3. Enhanced Due Diligence (EDD)
Enhanced Due Diligence is a heightened, comprehensive investigative protocol mandated whenever a customer, product, delivery channel, or geographic location poses high ML/TF risk. EDD requires deeper background inquiries, independent verification of the client's financial profile, establishment of both Source of Wealth (SOW) and Source of Funds (SOF), mandatory approval from Senior Management prior to account onboarding, and intensified ongoing transaction monitoring.
| CDD Tier | Eligible Risk Profile | Typical Client Categories | Source of Wealth / Funds Verification | Approval Authority | Ongoing Monitoring Frequency |
|---|---|---|---|---|---|
| Simplified (SDD) | Demonstrably low risk and rule-eligible | PLCs, government entities, and regulated financial institutions, subject to the rules | Proportionate identification and verification measures | Authority assigned by the approved program | Risk-based ongoing and event-driven review |
| Standard (CDD) | Normal / medium risk | Standard domestic corporations, retail investors, and professionals | Identity, purpose, beneficial ownership, and financial profile verified as applicable | Authority assigned by the approved program | Risk-based periodic and event-driven review |
| Enhanced (EDD) | High risk | Foreign PEPs, high-risk domestic PEPs, private banking, and complex structures | Additional verification, including source of wealth and source of funds as required | Senior management | Enhanced ongoing monitoring at a risk-based frequency |
Identification and Verification of Natural Persons
When onboarding individual customers, SEC-registered broker-dealers and intermediaries must gather mandatory identification information and independently verify those facts against reliable, independent source documents.
Minimum Customer Identification Data
Under the SEC 2018 AML/CFT Guidelines and the AMLA IRR, as amended, covered persons gather the applicable identification data before or during account opening or onboarding and verify it under the prescribed customer-identification process:
- Full legal name (including middle name and maternal surname);
- Date and place of birth;
- Nationality or citizenship (including dual citizenship details);
- Present residential address and permanent residential address;
- Contact details (mobile phone number, landline, and verified email address);
- Nature of work, name of employer, or nature of self-employment/business;
- Tax Identification Number (TIN) or other official government identification number (such as SSS, GSIS, or passport number);
- Specimen signatures or authenticated biometric identifiers.
Acceptable Official Government-Issued Photo IDs
Verification requires the presentation of valid, unexpired, government-issued photo identification. Acceptable primary documents include:
- Philippine Identification System (PhilID / ePhilID) issued under Republic Act No. 11055;
- Philippine Passport issued by the Department of Foreign Affairs (DFA);
- Driver's License issued by the Land Transportation Office (LTO);
- Unified Multi-Purpose ID (UMID) issued by SSS or GSIS;
- Professional Regulation Commission (PRC) ID;
- Voter's ID or Voter's Certification issued by COMELEC;
- Postal ID issued by the Philippine Postal Corporation (PhilPost).
Important
The PhilID Primacy Rule: Under Republic Act No. 11055 (Philippine Identification System Act) and AMLC Regulatory Issuances, the PhilID and printable ePhilID hold statutory primacy. Covered institutions are legally prohibited from demanding secondary identification cards when a customer presents a valid PhilID or ePhilID. Refusal to accept the PhilID constitutes a statutory violation carrying administrative penalties.
Identification and Verification of Juridical Entities
Juridical entities (corporations, partnerships, foundations, and trusts) present heightened vulnerability because legal shells can be constructed to conceal illicit beneficial owners. Covered persons must verify both the legal existence of the entity and the specific individuals authorized to commit corporate assets.
Mandatory Corporate Documentation
For domestic stock and non-stock corporations registered in the Philippines, covered intermediaries must inspect and maintain certified copies of:
- SEC Certificate of Incorporation / Registration: Proves legal personality and corporate existence under the Revised Corporation Code (RA 11232).
- Articles of Incorporation (AOI) and Corporate By-laws: Sets out the corporate purposes, capital structure, and governance mechanisms.
- Latest General Information Sheet (GIS): Must bear the official "Received" stamp of the SEC or electronic confirmation from the SEC eFAST portal. The GIS identifies the current directors, executive officers (President, Treasurer, Corporate Secretary), and recorded shareholders.
- Board Resolution or Corporate Secretary's Certificate: Explicitly authorizing the opening of the brokerage or investment account, designating the financial intermediary, and specifying the authorized corporate signatories along with their trading and withdrawal authorities.
- Government-Issued Photo IDs: Valid primary identification of all authorized signatories, the corporate secretary certifying the board resolution, and primary executive officers.
For partnerships, firms must obtain the SEC Articles of Partnership and a notarized Partners' Certificate designating authorized managing partners. For foreign corporations, institutions must obtain an SEC License to Transact Business in the Philippines, or apostilled/consularized charter documents along with a Certificate of Good Standing from the home jurisdiction.
Beneficial Ownership Identification: The 20% Rule
A critical requirement tested on the SEC licensing examination is the identification and unmasking of Ultimate Beneficial Owners (UBOs).
Ultimate Beneficial Owner (UBO): Any natural person who ultimately owns or controls the customer, or the natural person on whose behalf a transaction or activity is being conducted, or who exercises ultimate effective control over a legal person or arrangement.
The Cascading Three-Tier Test
Under SEC Memorandum Circular No. 15, Series of 2025 (the Beneficial Ownership Disclosure Rules of 2026, which lowered the former 25% ownership category under MC No. 15, Series of 2019 to 20%) and the 2018 AMLA IRR, covered institutions must apply a systematic, three-step cascading test to identify beneficial owners of corporate clients:
Cascading Beneficial Ownership Determination
├── Tier 1: 20% Ownership Test
│ └── Natural persons owning/controlling ≥ 20% of voting shares or capital stock
│ │ (If none identified, or if ownership control is in doubt)
│ ▼
├── Tier 2: Ultimate Effective Control Test
│ └── Natural persons controlling via voting trusts, debt covenants, or dominant influence
│ │ (If no natural person satisfies Tier 1 or Tier 2)
│ ▼
└── Tier 3: Senior Managing Official Test
└── Identify the natural person holding the position of CEO, President, or Managing Director
- Tier 1 (The 20% Equity/Voting Threshold): Identify all natural persons who ultimately own or control, whether directly or indirectly through corporate holding layers, at least twenty percent (20%) of the voting shares or capital stock of the juridical person.
- Tier 2 (Control through Other Means): If no natural person owns 20% or more, or if there is doubt as to whether the 20% equity owner exercises genuine control, the institution must identify the natural persons who exercise control over the corporation through other mechanisms—such as voting agreements, shareholder covenants, powers of attorney, debt agreements, or personal dominant influence.
- Tier 3 (Senior Managing Official): Where no natural person is identified under Tier 1 or Tier 2 after exhaustive measures, the institution must identify and verify the natural person who serves as the Senior Managing Official of the corporation (e.g., the Chief Executive Officer, President, or Managing Director).
Unmasking Nominee Arrangements
Under SEC Memorandum Circular No. 1, Series of 2021, nominee directors and nominee shareholders are legally required to disclose their nominee status and disclose the full identity of their true nominators and beneficial owners. Capital market intermediaries must ensure that nominee structures are never utilized to obscure the real natural persons controlling investment portfolios.
Broker-Dealer Account Opening and Technology-Assisted Verification
For this exam, apply the broker-dealer-specific rule first. SRC Rule 52.1.6.12 states that a broker-dealer cannot create a new account without a face-to-face meeting. The same rule family requires a CAIF, reliable identity records, prohibition of anonymous or fictitious accounts, and an electronic customer database whose material information is kept current.
Technology may support the customer-identification process. The AMLA IRR permits covered persons to scan or copy identification documents and to use information and communications technology to capture identification data, a customer photograph, or biometric information. Those provisions support reliable verification and recordkeeping; they do not themselves erase the separate SRC face-to-face-meeting requirement for a securities broker-dealer.
A compliant technology-assisted process should therefore be evaluated against the applicable SEC rule, the institution's approved risk-based policies, and reliable independent-source verification. Live video, biometric comparison, document authentication, device controls, sanctions screening, and audit logs may be useful controls depending on the design and risk. They are not a universal statutory checklist requiring every system to use “liveness detection,” OCR, GPS coordinates, and eye tracking.
Citation trap: AMLC Regulatory Issuance No. 4, Series of 2020 concerns targeted financial sanctions and freeze obligations. It is not the authority for broker-dealer e-KYC onboarding.
Third-Party Reliance Rules
Under Section 9 of AMLA and the 2018 IRR, covered persons are permitted to rely on a third party (such as a universal or commercial bank, or another regulated broker-dealer) to perform specific CDD measures, subject to strict conditions:
- Regulated Third Party: The third party must be an AML-regulated entity supervised by the BSP, SEC, or an equivalent foreign regulator;
- Immediate Data Access: The covered person must immediately obtain the customer identification data from the third party;
- Immediate Document Production: A written contractual agreement must ensure that the third party will provide certified copies of all underlying KYC identification documents without delay upon request;
- Non-Delegable Liability: Ultimate legal responsibility for customer due diligence remains strictly with the covered person. If the third party conducts defective CDD, the covered person cannot assert third-party reliance as a legal defense to avoid regulatory sanctions.
Practical Exam Traps and Regulatory Pitfalls
- Trap 1: Demanding Secondary Identification when PhilID is Presented. Exam items frequently test whether an onboarding officer can demand a utility bill or second government ID from a customer holding an ePhilID. By law (RA 11055), the PhilID is sufficient standalone proof of identity; refusing it or demanding secondary IDs violates national policy.
- Trap 2: Believing Simplified Due Diligence is an Absolute Safe Harbor. Candidates often assume that if a customer is a publicly listed company, SDD applies under all circumstances. If the transaction triggers an ML red flag or STR indicator, SDD is immediately prohibited, and the firm must execute Enhanced Due Diligence.
- Trap 3: Confusing the 20% Beneficial Ownership Threshold with Majority Control. Exam questions often tempt candidates with 50% or 51% majority options. In Philippine AML jurisprudence, beneficial ownership identification begins at 20% voting or equity interest.
- Trap 4: Transferring Regulatory Liability to a Third Party. Under third-party reliance agreements, firms often assume that legal liability transfers to the originating bank. Remember: The relying covered person retains 100% of the ultimate legal and administrative responsibility.
Under SEC Memorandum Circular No. 16 (Series of 2018), as amended and AMLC regulations, what is the statutory ownership threshold for identifying a natural person as an Ultimate Beneficial Owner (UBO) of a corporate client?
Natural persons who ultimately own or control at least 20% of the voting shares or capital stock, or who exercise ultimate effective control
Natural persons who hold at least 50% plus one share of the voting common stock
Any shareholder holding at least 10% of total assets regardless of voting rights
Only directors who hold at least 33.3% of the outstanding preferred shares
Under what circumstance is an SEC-registered broker-dealer legally prohibited from applying Simplified Due Diligence (SDD) to an otherwise eligible institutional or retail customer?
When the customer conducts transactions using Philippine Peso currency rather than US Dollars
Whenever there is a suspicion of money laundering or terrorist financing, or where high-risk indicators are present
When the institutional client is an enterprise fully owned by the National Government of the Philippines
When the customer presents an electronic Philippine Identification Card (ePhilID) as their primary document
A registered securities broker enters into a formal third-party reliance agreement with a commercial bank to perform customer identification procedures for mutual clients. If the bank fails to verify a client's identity properly, what is the legal liability of the broker under the AMLA 2018 IRR?
The broker is fully exonerated from all regulatory liability because the written reliance agreement transfers fiduciary duty to the bank.
The broker is liable only for civil damages brought by private third parties, while administrative penalties are absorbed by the bank.
The broker retains ultimate legal responsibility for CDD compliance and remains directly subject to SEC and AMLC regulatory sanctions.
The broker is subject only to a private reprimand from the Philippine Stock Exchange while the bank faces license revocation.
Sections you finish are checked off in the contents.