
15 June 2026
Swarmer and Molfar Partner to Integrate Verified Intelligence Data for Autonomous Systems
Partnership connects combat-proven drone autonomy software with verified intelligence data sets to improve AI decision-making.
A customer can pass an identity check and still present a material risk. The document may be genuine, but the company behind the application may have opaque ownership. A screening tool may return no direct sanctions match while connected parties, the source of funds or the purpose of the relationship remain unclear.
Customer due diligence (CDD) is designed to close those gaps. It gives a regulated organisation a reasoned basis to approve, escalate, restrict or decline a relationship. It is not a single database search, and it does not end when an account is opened.
This guide explains the UK framework. Organisations operating elsewhere should apply the rules of each relevant jurisdiction and obtain legal advice where the position is unclear.
Customer due diligence is the process of establishing who a customer is, who ultimately owns or controls a legal entity, why the relationship is being formed and whether the activity fits the risk profile.
Under the UK Money Laundering Regulations 2017, a relevant person must identify the customer and verify that identity using reliable, independent evidence. For a company, trust or similar arrangement, the review must also identify and take reasonable measures to verify the beneficial owner, understand ownership and control, and assess the purpose and intended nature of the relationship.
Recommendation 10 from the Financial Action Task Force sets a similar international baseline. FATF standards inform national AML regimes but do not replace local law. CDD therefore combines verification with judgement: a passport or registry extract is a starting point, not the decision.
Regulation 27 sets the main triggers for businesses within scope of the UK regime. CDD is required when a relevant person:
The regulations include monetary thresholds for certain occasional transactions. Since 30 June 2026, the general threshold for most sectors has been £12,000, while a transfer of funds by a money service business can trigger CDD when it exceeds £800. Different thresholds apply to some activities: for example, high-value dealers and art market participants use £10,000, while certain estate agency and letting agency transactions have their own rules. A threshold should never be used without checking the current provision for the activity concerned.
Existing customers are not exempt. CDD must be refreshed at appropriate times on a risk-sensitive basis, including when relevant circumstances change. Scope depends on the sector, activity and supervisory regime: companies outside the regulated sector may use CDD as a commercial control, but should not present a voluntary check as a statutory duty.
The evidence should match the customer and the proposed relationship. A low-value domestic account for an individual does not create the same questions as a cross-border relationship with a privately held company and layered ownership.
The organisation normally records the person’s full legal name, date of birth and other identifying details required by its policy and applicable rules. It then verifies identity using reliable, independent evidence. Depending on the risk and service, that may include a passport, national identity document, driving licence, address evidence or a suitable electronic identity process.
The review should also establish whether the person is acting for someone else and has authority to do so. The stated purpose, expected activity, relevant jurisdictions and source of funds may require examination. Collecting more personal data does not automatically produce a better risk decision.
For a business customer, CDD should establish the entity’s legal name, registration details, status, registered office, principal activity, directors and authorised representatives. The next task is to trace ownership and control to the relevant natural persons.
A shareholder register, confirmation statement or Companies House record can provide useful evidence, but not the complete answer. Companies House warns that its public service is not a complete source of company information. Registry data may be outdated or fail to show control exercised through nominees, agreements or connected companies.
Beneficial ownership thresholds depend on applicable law, and ownership is not the only form of control. Voting rights, appointment powers, trusts and partnership arrangements may matter. Contradictions between filings, customer declarations and independent sources need to be resolved.
Identity answers “who”. CDD must also answer “why” and “what should normal activity look like”. Relevant questions can include:
Sanctions, politically exposed person (PEP) and adverse-media screening inform the assessment. An alert is not a confirmed match, and PEP status is not evidence of wrongdoing. A confirmed sanctions match can create separate legal restrictions or reporting duties.
The UK framework is risk-based. This affects the extent and timing of measures, but it does not allow a firm to disregard inconvenient information.
Simplified due diligence (SDD) may be appropriate where the organisation has established a lower risk and the law permits a reduced approach. The firm should document why the relationship is lower risk and adjust its measures accordingly. It must still monitor the relationship and apply ordinary or enhanced measures if suspicion arises or the risk changes.
SDD is not “no due diligence”. A familiar company name, UK registration or referral from an existing customer is not enough on its own to justify a lower-risk rating.
Standard CDD applies the core measures: identify and verify the customer, establish beneficial ownership, understand the purpose and intended nature of the relationship, assess risk and monitor the relationship. The exact evidence depends on the customer, product, geography and delivery channel.
EDD is required in cases specified by the regulations and in other situations assessed as high risk. Triggers may include a PEP, a party in a FATF Call-for-Action jurisdiction, a transaction that is unusually complex or large for its context, opaque ownership, false identity evidence, unclear funds, sanctions concerns or credible adverse information. FATF’s separate increased-monitoring list remains a risk factor, but does not now create an automatic UK EDD duty on geography alone.
Measures can include further evidence, deeper ownership tracing, source-of-funds or source-of-wealth checks, senior approval and closer monitoring. Each measure should address the identified risk, not simply add documents.
A useful process produces a decision trail, not only a folder of documents.
Standard tools can collect records and generate alerts. When sources conflict or ownership remains unclear, analyst-led KYC and customer due diligence services can provide the context needed for a defensible decision.
Electronic identity systems can improve speed and consistency, but no method is always the most reliable. FATF’s digital identity guidance recommends assessing a system’s assurance level, technology and governance before using it for CDD.
Document authentication, biometric comparison and liveness checks can detect some impersonation or tampering, yet they can also produce false positives and say little about ownership or purpose. Manual review can be inconsistent. A risk-based process combines appropriate technology, escalation rules and human judgement.
There is no universal sequence in which KYC happens first and CDD follows. In some policies, “Know Your Customer” is the wider onboarding and monitoring framework, while CDD describes the specific AML measures used within it. Other organisations and guidance use the terms almost interchangeably.
What matters is not the label but whether the policy covers identity, beneficial ownership, relationship purpose, risk assessment, escalation and monitoring.
Customer due diligence should also be distinguished from broader corporate due diligence, which may support an acquisition or investment, and third-party due diligence, which focuses on vendors, agents, contractors and other external relationships. The checks may overlap, but the decision and legal context differ.
CDD continues throughout the relationship. Under Regulation 28, ongoing monitoring includes scrutinising transactions to check whether they fit the organisation’s knowledge of the customer, its business and risk profile. It also requires relevant documents, data and information to remain current.
Monitoring intensity should reflect risk; every customer does not need the same daily review. Higher-risk relationships may require more frequent screening, closer transaction analysis and shorter intervals. Lower-risk files may be reviewed less often if material changes can still be detected.
Events that can trigger a new review include:
Under UK rules, CDD records are generally kept for five years after the relationship ends or an occasional transaction completes, then deleted unless another lawful basis applies.
An unresolved discrepancy does not prove criminal conduct, but it changes the decision the organisation can responsibly make. The team may request more evidence, move the file to EDD or escalate it to the money laundering reporting officer or legal team. Where required CDD cannot be completed, the regulations may prevent the relationship or transaction from proceeding.
Where suspicion meets the reporting threshold, the responsible team should follow its legal process. The National Crime Agency states that UK Suspicious Activity Reports should be submitted through the SAR Portal. Staff must observe confidentiality and tipping-off rules. A business should seek advice rather than infer a reporting duty from a generic checklist.
Complex ownership, financial crime indicators or connected-party activity may require separate AML investigations and compliance support to establish what sits behind the alert.
CDD obligations are jurisdiction-specific. The FATF Recommendations provide a shared policy baseline, but local legislation determines who is regulated, when checks are required and what reporting follows.
EU firms currently follow applicable national AML rules. The new EU Anti-Money Laundering Regulation 2024/1624 introduces directly applicable CDD rules, mostly from 10 July 2027. Directive 2018/1673, sometimes called 6AMLD, concerns money laundering through criminal law; it is not a complete CDD code.
In the United States, the FinCEN CDD Rule applies to specified covered financial institutions, not every business. It covers customer and beneficial-owner identification, relationship purpose and ongoing monitoring. Since February 2026, covered institutions need not repeat beneficial-owner identification at every new account opening in all cases. UK, EU and US requirements should be implemented separately.
CDD cannot guarantee that a customer is legitimate or that no future risk will emerge. It reduces uncertainty and creates an evidence trail for action.
Molfar Intelligence supports teams when routine checks leave material questions unresolved. Analysts verify records, map ownership and affiliations, examine sanctions and PEP links, and place local-language adverse information in context. Findings separate what is confirmed, what remains unclear and what may require escalation. This work supports internal decisions; it does not replace legal advice, regulatory ownership or transaction-monitoring controls.
There is no single interval. Reviews should be risk-based, with material changes, inconsistent activity, new ownership, sanctions or PEP results and credible adverse information prompting an earlier review.
No. PEP status is not proof of misconduct. The organisation should confirm the match, assess the exposure and apply measures required by law and policy. The evidence may support approval with controls, escalation or rejection.
External providers can support verification and investigation, but outsourcing does not automatically transfer regulatory responsibility. The regulated organisation should understand the work, assess the evidence and retain ownership of the decision.
Author

15 June 2026
Partnership connects combat-proven drone autonomy software with verified intelligence data sets to improve AI decision-making.

2 March 2026
A €900M EU real estate deal under investigation shows why institutional reputation cannot replace structured due diligence.
Behind every case is a client who needed clarity in uncertainty. Browse our work to see how we uncover what others miss — and what that means in practice for businesses and decision-makers.
Revealed how a high-stakes Defence Tech investment was halted after OSINT-driven due diligence uncovered a co-founder’s links to Russian-origin money laundering and a seized 2.6 billion UAH gambling enterprise, protecting a global firm from severe reputational and regulatory fallout.
Investment
Conducted a full pre-employment background investigation for a high-security aerospace role, covering court registry checks, financial record verification, ideological risk assessment, and social media OSINT analysis across relevant jurisdictions.
Space
Revealed how Russian drone manufacturers circumvent international sanctions by exploiting a critical design flaw (sanctions applied to company names rather than underlying legal entity identifiers), enabling Supercam to increase production tenfold despite being designated.
Finance
Conducted a comprehensive cybersecurity audit of a long-standing European IT infrastructure, identified critical internal data leaks involving financial plans and performance reviews, and implemented high-level security protocols to mitigate regulatory and operational risks.
Cybersecurity
Let’s connect to explore how tailored intelligence can strengthen your decisions, reveal opportunities, and minimise uncertainty.
Let’s connect to explore how tailored intelligence can strengthen your decisions, reveal opportunities, and minimise uncertainty.