What Is Customer Due Diligence? CDD Rules for Philippine KYC
Customer due diligence is the process of identifying a customer, verifying that identity against reliable evidence, understanding the purpose of the relationship, and monitoring it over time. In the Philippines it is governed by the 2018 Implementing Rules and Regulations of RA 9160 and by BSP Circulars 1022 and 1170. One detail separates Philippine practice from global summaries: the tiers are Reduced, Average, and Enhanced Due Diligence, and Average is the default. A covered person may only apply the reduced standard where documented risk profiling supports it.
What Is Customer Due Diligence (CDD)?
CDD is the set of measures a covered person applies to know who it is dealing with, before and throughout a business relationship. It is not a single document check at account opening. It runs from onboarding through the life of the relationship.
The 2018 IRR of RA 9160 breaks it into components that map to distinct obligations: the customer verification process, identification and verification of agents, beneficial ownership verification, determination of the purpose of the relationship, and the ongoing monitoring process.
Underneath sits the Customer Identification Process, or CIP, which the AMLC describes as the basic CDD measure. CIP covers obtaining the required identification information and identification documents to capture the customer’s profile. Everything else builds on what CIP collected, which is why weak identification quietly undermines every control downstream.
CDD vs KYC vs EDD: What’s the Difference
These three terms get used interchangeably in vendor material, and the imprecision causes real confusion when teams try to map obligations to controls.
| KYC | CDD | EDD | |
|---|---|---|---|
| What it is | The broad practice of knowing your customer | The regulated process that delivers it | The heightened tier of that process |
| Where it is defined | Industry usage, not a statutory term | 2018 IRR of RA 9160, BSP Circulars 1022 and 1170 | Section 10 of the 2018 IRR |
| Applies to | Everyone | Every customer | Higher-risk customers only |
| Triggered by | Business practice | Legal obligation | Risk profiling outcome |
Put simply: KYC is the goal, CDD is the mechanism, and EDD is CDD turned up for customers who warrant it.
The Four Steps of CDD
Step 1: Identify the customer
Collect the required identification information and documents. Where a customer presents the PhilID, the PhilSys Card Number, or a PSN derivative, BSP Circular 1170 states it shall be accepted as official and sufficient proof of identity subject to proper authentication, and no additional document may be required to verify identity. One handling rule attaches: only the front portion of the PhilID should be photocopied or scanned.
Step 2: Verify the identity
Confirm the claimed identity against reliable, independent evidence. Circular 1170 permits electronic KYC using a digital ID system, defining e-KYC as the process of electronically verifying a customer’s credentials. Where face-to-face contact is conducted using information and communications technology, the covered person must have measures in place to mitigate ML and TF risks and must document the key CDD processes.
Step 3: Understand the relationship and profile the risk
Determine the purpose and intended nature of the relationship, identify beneficial owners where the customer is a juridical person, and assign a risk profile. Under the Manual of Regulations for Banks, the covered person must document the risk profiling results, how the specific customer was profiled, and which standard of CDD was applied.
Step 4: Monitor on an ongoing basis
Keep transactions consistent with the profile, refresh customer records, and escalate where behaviour diverges. The IRR treats this as a distinct obligation, and it includes conducting EDD where the monitoring process surfaces higher risk after onboarding.
RDD, ADD, and EDD: The Philippine Tiers
Global guidance usually describes simplified, standard, and enhanced due diligence. Philippine regulation uses different names, and the difference is not cosmetic.
| Tier | When it applies | Status |
|---|---|---|
| Reduced Due Diligence (RDD) | Where lower ML and TF risk has been identified through adequate analysis | Must be earned with documented risk profiling |
| Average Due Diligence (ADD) | All other customers | The default |
| Enhanced Due Diligence (EDD) | Higher-risk customers and situations | Mandatory where triggered |
The 2018 IRR defines RDD as the lowest level of customer due diligence appropriate where there is low risk of money laundering or terrorism financing. The AMLC is explicit about what happens without that analysis: absent documented risk profiling supporting a finding that a customer or category of customers is low risk, the standards for ADD apply by default.
Two constraints follow, and both catch institutions out. RDD procedures must be commensurate with the lower risk factors identified, and they are not acceptable whenever there is suspicion of ML or TF, or in specific higher-risk scenarios. A blanket policy applying RDD to an entire product line because it feels low risk, without documented analysis, is non-compliant even if every customer in it turns out to be legitimate.
Risk Profiling: Documenting the Reasoning, Not Just the Score
Risk profiling assigns each customer a level based on customer type, product, channel, and geography. The obligation goes further than assigning a label.
What must be documented is the result, the reasoning behind it, and the CDD standard applied as a consequence. An examiner reading the file should be able to reconstruct why this customer carries the rating it does and why the corresponding tier followed. A risk score with no visible basis is a finding, because the risk-based approach is only defensible when the basis is inspectable.
One constraint on how far risk-based tiering may go is easy to miss. The Manual of Regulations requires covered persons to have policies and procedures ensuring non-discrimination against certain customer types when implementing AML and CFT regulations, and discriminatory acts are subject to sanctions. Risk-based does not license blanket exclusion of a category of people.
Enhanced Due Diligence in Brief
EDD applies to higher-risk customers and situations, including politically exposed persons, non-residents, and customers with complex ownership structures. Under the Manual of Regulations, EDD requires gathering additional customer information and identification documents beyond the minimum required for average due diligence, in addition to profiling and transaction monitoring.
Documentation of source of funds and source of wealth sits inside this tier. Our guide to enhanced due diligence covers the full trigger list and the additional measures required.
One rule about third parties is worth carrying: where a customer is assessed as high risk by a third party, the covered person must conduct its own separate EDD. Reliance does not transfer the obligation.
Beneficial Owners, Agents, and Nominee Arrangements
CDD does not stop at whoever is sitting across the counter.
Where an account is opened by, a relationship is established through, or a transaction is conducted by a trustee, nominee, agent, or intermediary, the covered person must establish and record the true and full identity of both parties: the trustee, nominee, agent, or intermediary, and the trustor, principal, beneficial owner, or person on whose behalf the arrangement operates. The true nature of the parties’ capacities and duties is determined by obtaining the written document evidencing the relationship.
For corporate customers this connects to beneficial ownership verification, which the 2018 IRR treats as a separate section of the CDD process. Our guide to KYB verification covers how that works for juridical persons.
What Happens When CDD Fails
The framework prescribes what happens when verification fails, and it is not a judgment call.
Under BSP Circular 1170, where a covered person is unable to comply with the CDD measures, it must either not open the account, commence business relations, or perform the transaction, or terminate an existing business relationship. In both cases the covered person must consider filing a suspicious transaction report in relation to that customer.
That last clause is the part most often missed. Failing CDD is not simply a declined application to close out quietly. It is a prompt to assess whether the circumstances warrant an STR, and the assessment should leave a record either way.
Tipping off applies here too. The 2018 IRR treats CDD and tipping-off as a linked concern, so a decline driven by suspicion cannot be explained to the customer in those terms.
Frequently Asked Questions About CDD in the Philippines
What does CDD mean?
- CDD stands for customer due diligence: the process of identifying a customer, verifying that identity against reliable evidence, understanding the purpose of the relationship, and monitoring it over time. In the Philippines it is governed by the 2018 Implementing Rules and Regulations of RA 9160 and by BSP Circulars 1022 and 1170.
What is the difference between CDD and KYC?
- KYC is the broad industry practice of knowing your customer and is not a statutory term. CDD is the regulated process that delivers it, with defined components and obligations under the 2018 IRR of RA 9160. In practice KYC is the goal and CDD is the mechanism.
What are RDD, ADD, and EDD?
- Reduced, Average, and Enhanced Due Diligence: the three CDD standards under the 2018 IRR of RA 9160. RDD is the lowest level, appropriate where low ML or TF risk has been identified through adequate analysis. EDD is the heightened level for higher-risk customers. ADD covers everything else and applies by default.
Can we apply reduced due diligence to low-risk customers?
- Only where documented risk profiling supports that finding. The AMLC states that without documented risk profiling supporting a low-risk determination, the standards for ADD apply by default. RDD is also unacceptable wherever there is suspicion of ML or TF, or in specific higher-risk scenarios.
Is the PhilID enough to satisfy customer identification?
- Yes. Under BSP Circular 1170, where the PhilID, PhilSys Card Number, or a PSN derivative is presented, it shall be accepted as official and sufficient proof of identity subject to proper authentication, and the covered person may not require an additional document to verify identity. Only the front portion of the PhilID should be photocopied or scanned.
What happens if we cannot complete CDD on a customer?
- Under BSP Circular 1170 the covered person must either decline to open the account, commence relations, or perform the transaction, or terminate an existing relationship. In both cases it must consider filing a suspicious transaction report. Document the decision and its basis either way.
The Default Is Average, Not Convenient
The most common CDD failure in Philippine onboarding is not a missing document. It is a product line quietly running on reduced due diligence because someone decided it was low risk, with no documented analysis behind that decision. Under the AMLC’s position, those customers should have been on average due diligence all along, and the gap only becomes visible during examination.
Getting the tier right depends on the quality of what CIP collected in the first place. Risk profiling compares a customer against a profile, monitoring compares transactions against that profile, and both inherit whatever reliability the identification step produced.
Verihubs eKYC API handles that first step for Philippine covered persons, with government ID verification across 15+ document types, PhilSys authentication, biometric liveness, and deepfake detection, built for the e-KYC conditions set out in BSP Circular 1170.
Talk to the Verihubs team about the identification layer underneath your CDD process.