The FinCEN Customer Due Diligence rule and the Corporate Transparency Act's Beneficial Ownership Information framework now coexist in a way that creates genuine operational complexity for covered financial institutions. Both involve beneficial ownership data, both reference FinCEN as the administering agency, and both impose obligations on legal entity customers. But they are distinct regulatory instruments with distinct legal bases, and understanding which obligation is whose responsibility matters considerably for how a compliance program is structured.
This post is a practitioner-focused breakdown of the CDD rule at 31 CFR 1010.230, how its five standard control components work in practice, and where the CTA/BOI framework intersects without replacing the institution's independent obligations. We are not covering BOI reporting requirements for reporting companies themselves, which is a separate topic for corporate counsel.
The CDD Rule: What It Requires and Why It Persists
The CDD rule, codified at 31 CFR 1010.230, requires covered institutions to identify and verify the beneficial owners of legal entity customers and to understand the nature and purpose of customer relationships in order to develop customer risk profiles. It applies to banks, savings associations, credit unions, mutual savings banks, and bank holding companies, as well as certain other covered financial institutions under the BSA's definition.
The CDD rule has a foundational logic that distinguishes it from a simple data collection requirement. The rule is structured around the premise that a financial institution cannot manage anti-money laundering risk for a legal entity customer unless it knows who ultimately controls or benefits from that entity. The 25% ownership threshold for beneficial ownership identification reflects a judgment that control significant enough to create money laundering exposure shows up at that equity level, though institutions are expected to look through to the actual controlling person even when the ownership structure is layered.
The five standard CDD control components, in the order they most often appear in examination findings, are: customer identification and verification, beneficial ownership identification and verification, customer risk profiling, ongoing monitoring, and record retention. Each has a distinct evidence requirement, and each interacts with the others in ways that mean a weakness in one component creates cascading gaps elsewhere.
How the Five CDD Control Components Work in Practice
Control Component 1: Customer Identification and Verification
For legal entity customers, CIP requires the institution to collect name, address, EIN, and formation jurisdiction, and to verify the information through documentary or non-documentary methods. The persistent examination finding in this area is not about data collection failure; it is about documentation linkage. The CIP record and the beneficial ownership collection need to sit in the same customer file as a single onboarding package, not in separate systems maintained by separate teams with no demonstrated connection between them.
Institutions where CIP is handled by one team and beneficial ownership collection is handled by a separate CDD or KYC team are at documentation risk if the examination file review cannot show that both steps were completed as part of a unified process and that the beneficial ownership information was actually used in developing the initial customer risk profile.
Control Component 2: Beneficial Ownership Identification and Verification
The 25% ownership threshold is established and has not changed. The examination findings that cluster around this component usually involve one of three patterns: the institution did not apply the control at all to customers that qualified, the institution documented an exemption without sufficient basis, or the institution collected a beneficial ownership certification without verifying the information against any independent source.
The documentation standard for claimed exemptions from the beneficial ownership requirement deserves specific attention. A checkbox or a brief note that the customer was exempt is not sufficient. The file needs to document the specific basis for the exemption and, where the basis is the customer's status under an exemption category, the evidence used to confirm that status. This is an area where the CTA/BOI framework intersects: for customers that are registered with FinCEN as reporting companies under the CTA, the institution may under certain conditions treat the information reported to FinCEN's BOI registry as one evidentiary source. But the reliance conditions are specific, must be documented, and do not eliminate the institution's obligation to maintain its own customer file with the relevant information.
Control Component 3: Customer Risk Profiling
The customer risk profile is what connects the CIP and beneficial ownership data to the institution's AML controls. A risk profile that was built at onboarding but never updated is a control gap because beneficial ownership structures change and customer business activities change. The CDD rule's expectation around ongoing due diligence requires the risk profile to reflect a current assessment of who the customer is and what the relationship is for, not just the original onboarding snapshot.
The practical question for institutions using risk scoring models is whether the model is re-run periodically against current data or only triggered by incoming alerts. Alert-triggered reviews are necessary but not sufficient if the customer's underlying data has changed in ways that would not generate an alert under the current monitoring parameters.
Control Component 4: Ongoing Monitoring
Ongoing monitoring under the CDD rule has always encompassed two distinct sub-obligations that examination findings suggest institutions frequently conflate: transaction monitoring and information refresh. These are different controls with different evidence requirements. Transaction monitoring is alert-driven and produces SAR filing decisions. Information refresh is review-driven and produces updated customer files with current beneficial ownership data and risk assessments.
Institutions whose ongoing monitoring program consists entirely of transaction monitoring infrastructure, with no structured process for periodically reviewing whether a customer's beneficial ownership and business purpose information remains current, are treating a two-part obligation as a single control. That gap is visible in examination when the customer file shows years of clean transaction alerts alongside a beneficial ownership certification that has never been reviewed since onboarding.
Control Component 5: Record Retention
The retention period for CDD records is five years from the date the account is closed or the customer relationship ends, consistent with the BSA general retention standard. The examination gap in this component is typically not about the length of retention; it is about scope. Retention needs to cover the full documentation trail, including any periodic review records, not just the original onboarding certification. A file that contains the original beneficial ownership form but no documentation of subsequent reviews, even if those reviews concluded the information was still current, has a retention gap for the periods not covered by the original onboarding record.
The CTA Intersection: What It Means and What It Does Not Mean
We want to be careful about overstating the relationship between the CTA BOI reporting framework and the CDD rule. Companies have their own direct reporting obligations to FinCEN under the CTA. Financial institutions have their own independent CDD obligations under the BSA. The existence of a FinCEN BOI registry does not eliminate or replace the institution's CDD obligation; it creates an evidentiary source that institutions may use under specified conditions for certain components of their CDD process.
The risk of conflating the two frameworks is that institutions may incorrectly assume that a customer's CTA compliance means the institution's CDD obligation is satisfied. It does not. An institution that relies on a customer's BOI filing as its primary CDD evidence, without independently verifying the information and maintaining its own compliant documentation, is exposed in examination regardless of whether the customer has accurately filed with FinCEN. The regulatory obligations are parallel, not sequential.
Mapping CDD Obligations in a Control Library
When we built Regloom's FinCEN CDD obligation set, the decision that shaped everything else was whether to treat the CDD rule as a single control block or to decompose it into the five components with distinct control owners and evidence requirements for each. We chose decomposition, and the reason is practical: a single CDD control block makes it impossible to tell which component is implicated when a supervisory notice or examination finding touches the rule.
If your control library maps the CDD rule as a single entry, the next time FinCEN publishes guidance or examination findings that affect beneficial ownership documentation standards, you will face a whole-program review to determine what the impact is. If you have the five components mapped as distinct obligations, you can identify in minutes which component is affected and whether your current controls for that component need updating. That is the operational difference between a compliance program that responds to regulatory developments and one that simply observes them.