NISM Professor

Client Due Diligence

Also written Client Due Diligence (SEBI definition) · CDD · Customer due diligence · Client Due Diligence Programme

Screening and verifying a client using reliable, independent sources — identity, beneficial owner, purpose of the relationship — and then continuing to scrutinise it for as long as it lasts.

In plain language

Client due diligence is the whole of what an intermediary is expected to know about a client, not the paperwork it collects on day one.

It asks four questions: who is this person, who is really behind them, why are they here, and does what they do afterwards match the answers. The workbook calls CDD the heart of AML and KYC, and the ordering matters — CDD is the obligation, and the KYC documents are one of the means of discharging it.

The rule that ends most arguments about it is one sentence from the SEBI guidelines: no transaction or account-based relationship shall be undertaken without following the CDD procedure.

How it works

When it is triggered. Rule 9(1) of the PML Rules requires CDD at the commencement of an account-based relationship, on an occasional transaction of Rs 50,000 or more (whether a single transaction or several that appear to be connected), and on any international money transfer operation.

What it consists of. The SEBI guidelines list the measures: identify the client and verify identity using reliable and independent sources; obtain information on the purpose and intended nature of the relationship; verify the authority and identity of anyone purporting to act on the client's behalf; identify and verify the beneficial owner; understand the nature of the business and its ownership and control structure; conduct ongoing due diligence so that transactions stay consistent with the intermediary's knowledge of the client, its business and its risk profile; and periodically update the documents and data, particularly for high-risk clients.

No exemptions. The workbook is emphatic: irrespective of the amount of investment, no minimum threshold and no category-wise exemption from CDD is available to any registered intermediary, and non-compliance attracts sanctions.

Relying on a third party. Rule 9(2) permits it, subject to conditions — the records must be obtained immediately, copies must be available from the third party without delay, the third party must itself be regulated and supervised for CDD and record-keeping, and it must not be based in a jurisdiction assessed as high risk. Crucially, the intermediary remains ultimately responsible. FIU-IND's order against Paytm Payments Bank included precisely this charge: reliance on a non-compliant, unregulated entity for third-party KYC.

The tip-off exception. Where the intermediary suspects money laundering or terrorist financing and reasonably believes that performing the CDD process will tip off the client, it shall not pursue CDD, and shall instead file an STR with FIU-IND.

A worked example

Jalaram Broking Pvt Ltd onboards Sahyadri Trade LLP on 4 August.

CDD stepWhat it produced
Identity of the entityRegistration certificate, partnership deed, PAN of the firm
Purpose of relationshipDeclared: treasury deployment of surplus, cash segment only
Persons acting on its behalfTwo authorised signatories, POI, POA, PAN, and verification of the authority itself
Beneficial ownerTwo partners hold 44% and 38% of profits — both above the 10% partnership threshold, both identified as natural persons
Risk categoryMedium

The records go to the Central KYC Records Registry within ten days of the relationship commencing, as Rule 9(1A) requires.

Six weeks later, ongoing due diligence bites. The declared purpose was treasury deployment. Instead the firm is running Rs 3.4 crore a week through two illiquid scrips, funded by inward transfers from a Dubai entity that appears nowhere in the ownership structure. Rule 9(12) requires the intermediary to review its due diligence measures, including verifying the identity of the client again and re-obtaining information on the purpose of the relationship.

The compliance officer proposes writing to the client to ask about the Dubai transfers. The Principal Officer stops him: the intermediary already suspects laundering, and the questions would tip the client off. Under the guidelines the correct step is to stop pursuing CDD and file an STR with FIU-IND instead — within seven working days of being satisfied the transactions are suspicious — while keeping dealings with the client normal and putting no restriction on the account.

Why NISM asks about it

Chapter 6 (SEBI Guidelines for AML, CFT and PF), section 6.2.1, is the CDD chapter, and Chapter 3 supplies the statutory hooks in Rule 9. This is the single densest source of questions in the paper. Expect the Rs 50,000 occasional-transaction trigger, the "no threshold, no exemption" rule, the four conditions for relying on a third party, and — most often — the tip-off exception, where the correct answer is always to file the STR rather than ask the client.

Common exam traps

  • CDD is not KYC. KYC is the document-collection mechanism inside the wider obligation. An intermediary can have perfect KYC files and still have failed CDD, which is what the Raima Equities and SKSE Securities orders are about.
  • There is no minimum investment threshold for CDD, and no exempt category of client. The Rs 50,000 figure in Rule 9(1) is the trigger for an occasional transaction by a non-account holder, not a floor below which account-opening CDD can be skipped.
  • Third-party reliance does not transfer responsibility. The registered intermediary remains ultimately responsible for CDD and for enhanced due diligence.
  • Simplified measures are never available where there is suspicion, nor where a higher-risk scenario applies, nor where the identified risk is inconsistent with the national risk assessment.
  • When you suspect and questions would tip off — stop, do not ask. File the STR. Continuing to interrogate the client is the wrong answer even though it feels like more diligence.
  • Ongoing due diligence has no end date. It runs for the life of the relationship, and CDD must be applied to existing clients too, on the basis of materiality and risk.

Check yourself

  1. 1.Under the risk based approach, when may simplified client due diligence NOT be applied?

    1. a)When there are suspicions of ML or TF, or when other factors give rise to a belief that the customer does not in fact pose a low risk
    2. b)Only for corporate clients
    3. c)Only where the client invests above Rs. 10 lakh
    4. d)Simplified CDD is never permitted
    Show the answer

    Answer: (a) When there are suspicions of ML or TF, or when other factors give rise to a belief that the customer does not in fact pose a low risk

    It may be noted that low risk provisions shall not apply when there are suspicions of ML/FT or when other factors give rise to a belief that the customer does not in fact pose a low risk.

    Two triggers — actual suspicion, or a belief that the low-risk classification was wrong.

    Option D overstates the position. The basic principle enshrined in this approach is that the registered intermediaries shall adopt an enhanced client due diligence process for higher risk categories of clients. Conversely, a simplified client due diligence process may be adopted for lower risk categories of clients.

    Simplified CDD is permitted — it is simply unavailable once suspicion arises.

    Options B and C invent classifications the guidelines do not use. Risk classification rests on the client's location (registered office, correspondence address, and any other relevant addresses), nature of business, trading turnover, and mode of payment for transactions, producing low, medium, or high-risk categories.

    And no client escapes CDD altogether: there shall be no minimum investment threshold/ category-wise exemption available for carrying out CDD measures by registered intermediaries.

    What the RBA requires structurally. Intermediaries shall apply a Risk Based Approach (RBA) for mitigation and management of the identified risk and should have policies approved by their senior management, controls and procedures in this regard. Further, the registered intermediaries shall monitor the implementation of the controls and enhance them if necessary.

    The documentation demanded also varies: the type and amount of identification information and documents that registered intermediaries shall obtain necessarily depend on the risk category of a particular client.

    And so does monitoring: the extent of monitoring shall be aligned with the risk category of the client.

    The underlying risk assessment covers clients, countries or geographical areas, nature and volume of transactions, payment methods used by clients, etc., and must be documented, updated regularly and made available to competent authorities and self-regulating bodies, as and when required.

  2. 2.An overseas branch of an Indian intermediary operates where the host regulator's AML standards are weaker than SEBI's. What applies?

    1. a)The more stringent of the two sets of requirements — and where the host country does not permit proper implementation, the group applies additional measures and informs SEBI
    2. b)The host country's standards, since local law governs
    3. c)SEBI standards only where the host country agrees
    4. d)Neither, since overseas branches are outside SEBI's remit
    Show the answer

    Answer: (a) The more stringent of the two sets of requirements — and where the host country does not permit proper implementation, the group applies additional measures and informs SEBI

    In case there is a variance in Client Due Diligence (CDD)/ Anti Money Laundering (AML) standards specified by SEBI and the regulators of the host country, branches/overseas subsidiaries of registered intermediaries are required to adopt the more stringent requirements of the two.

    The more stringent, whichever it is — so a host country with tougher rules would govern equally.

    And where compliance is impossible: if the host country does not permit the proper implementation of AML/CFT measures consistent with the home country requirements, financial groups shall be required to apply appropriate additional measures to manage the Money Laundering/Terror Financing (ML/TF) risks, and inform SEBI.

    Two obligations there — additional measures, and notification to SEBI. Silence is not an option.

    Option B treats local law as the ceiling; option C makes SEBI's standards optional; option D denies the extraterritorial reach the guidelines assert.

    The group dimension supports all of this. Financial groups shall be required to implement group wide programmes for dealing with ML/TF, which shall be applicable, and appropriate to, all branches and majority owned subsidiaries of the financial group — covering policies and procedures for sharing information required for the purposes of CDD and ML/TF risk management, the provision at group level of customer, account, and transaction information from branches and subsidiaries when necessary for AML/CFT purposes, and adequate safeguards on the confidentiality and use of information exchanged, including safeguards to prevent tipping-off.

    Note "majority owned subsidiaries" — the programme does not extend to minority holdings.

    And the group must communicate its policies: to all management and relevant staff that handle account information, securities transactions, money and client records etc. whether in branches, departments or subsidiaries.

    Country risk also feeds the assessment, which must take into account any country specific information that is circulated by the Government of India and SEBI from time to time, as well as, the updated list of individuals and entities who are subjected to sanction measures... under the various United Nations' Security Council Resolutions.

  3. 3.For the purpose of client due diligence, the KYC process requires every SEBI registered intermediary to obtain and verify which documents from clients?

    1. a)Both proof of identity and proof of address
    2. b)Proof of identity only
    3. c)Proof of address only
    4. d)Any one of the two
    Show the answer

    Answer: (a) Both proof of identity and proof of address

    The KYC process requires every SEBI registered intermediary to obtain and verify the Proof of Identity (PoI) and Proof of Address (PoA) from the client at the time of commencement of an account-based relationship.

    Both, and at the outset of the relationship.

    The learning objective for this chapter states the same: intermediaries must obtain and verify the Proof of Identity (PoI) and Proof of Address (PoA) from the client at the time of commencement of an account-based relationship.

    Why both matter. KYC and Client Due Diligence (CDD) policies as part of KYC are the foundation of an effective Anti-Money Laundering process — identity answers who the client is, address answers where he can be found and whether the two are consistent.

    And the names must line up: the name as mentioned in the KYC form shall match the name as mentioned in the Proof of Identity (PoI) submitted.

    The same seven documents serve both purposesthe passport · the driving licence · proof of possession of Aadhaar number · the Voter's Identity Card issued by Election Commission of India · job card issued by NREGA duly signed by an officer of the State Government · the letter issued by the National Population Register containing details of name address · any other document as notified by the Central Government in consultation with the Regulator.

    Where a client's OVD lacks a current address, four deemed documents fill the gap, replaced by a proper OVD within a period of three months.

    And the anonymity bar remains absolute: the registered intermediaries shall not open or keep any anonymous account or account in fictitious names or account on behalf of other persons whose identity has not been disclosed or cannot be verified.

    For foreign clients more is needed: copy of passport/Persons of Indian Origin (PIO) Card/Overseas Citizenship of India (OCI) Card and overseas address proof is mandatory, and if correspondence and permanent address is different, then proof for both shall be submitted.

Where this is taught

Free preparation for NISM Series XXIV

Related terms

← All terms
Something look wrong? Report it