When CDD is required
Customer due diligence applies whenever a reporting institution establishes a business relationship — and to occasional one-off transactions. The core requirement, set out in Section 16 of AMLA and the supervisory policy documents, is simple to state: know who your customer is, verify that identity from reliable sources, and understand the purpose and intended nature of the relationship.
The harder part is beneficial ownership. Where the customer is a company, trust, or other structure, the institution must identify the natural persons who ultimately own or control it — and take reasonable measures to verify them. Criminals rely on layered structures precisely because institutions stop at the legal-entity level.
The risk-based approach in practice
CDD is not one-size-fits-all. The depth of information collected and verified should scale with the risk of the customer, their geography, the product, and the delivery channel. A practical risk-based CDD programme means:
- A documented customer risk assessment at onboarding — who they are, where they operate, what they need
- Monitoring frequency and depth tied to the risk rating
- Graduated sign-off: higher-risk customers escalated to senior management
- Refreshing CDD for existing customers on materiality and risk — triggered by new products, unusual activity, or stale information
Enhanced due diligence: PEPs and non-face-to-face
Politically exposed persons
For PEPs, enhanced due diligence is mandatory: establish both source of wealth and source of funds, and obtain senior management approval — at head-office level — before establishing or continuing the relationship.
Non-face-to-face onboarding
Digital onboarding is permitted but Board-approved and subject to BNM's e-KYC policy document (updated April 2024). Institutions must demonstrate on a continuing basis that remote identification is secure and effective.
e-KYC controls
Robust e-KYC typically combines document verification (fraud-detection on government IDs), biometric matching against the ID, and liveness detection to defeat photos, videos, and synthetic masks — with multi-factor authentication proportionate to risk.
Sanctions screening is part of CDD
Every customer — regardless of any CDD threshold — must be screened against the Domestic List and the UN Security Council Resolutions List, both at onboarding and as part of ongoing due diligence. When a list is updated, the entire customer database, including dormant accounts, must be re-screened without delay.
Minimum data points to enable screening:
- Full name
- NRIC, passport, or other official reference number
- Date of birth
Lessons from enforcement
Frequently asked questions
In conclusion
Enforcement actions in Malaysia and the region keep pointing at the same weaknesses: beneficial ownership, source-of-wealth corroboration, and screening discipline. An independent review of your CDD framework — before the regulator's on-site examination finds the gap — is the cheapest fix available.
Get your CDD framework independently reviewed
We test onboarding files, beneficial-ownership verification, and screening controls against current requirements.