Header_3.2

AML/CFT Requirements

Breadcrumb

What is customer due diligence (CDD)?

Customer Due Diligence

What is customer due diligence (CDD)?


CDD is the process of identifying and verifying the identity of your customer.  A reporting institution must be satisfied that the customers are whom they say they are. This includes knowing:

  1. the identity of the customer*
  2. the identity of beneficial owner i.e. people behind the transaction
  3. the identity of person conducting transaction if the transaction is done on behalf of someone else or the person you dealing with is a representative appointed by a legal person
  4. the purpose i.e. why the transaction is undertaken
Please refer to AML/CFT and TFS for FIs and AML/CFT and TFS for DNFBPs and NBFIs Policy Documents for definition of ‘customer’.

A beneficial owner is someone who ultimately owns or controls a customer. It also includes someone who has ultimate control over a legal person; or trust. It is not to be confused with the term ‘beneficiary’. A beneficial owner must be an individual (natural person).

‘Owns’ in this context means ownership exercised through a chain of ownership. It can be direct (for example through percentage of shareholding) or indirect (such as through another company, entity or via proxy).

‘Controls’ in this context means direct control but also includes means of control other than direct control, for example, through trusts, agreements, arrangements, understandings, policies or practices.

To identify all the above, the RI must collect certain information from your customers. The information needed will depend on the type of customer on-boarded.

After identifying (collecting information on)  customers, the RI must also verify the person and the information provided through reliable and independent sources whether physical documents or electronic data, and keep records of such documents or process.

For more information on how to ascertain beneficial owner please refer to the Guidance on Beneficial Owner.

Why do CDD?

Why do CDD?


  • To confirm the identity of customers. Be certain who the RI is dealing with and ensure that the RI is not dealing with listed entities/ persons under the TFS regime (see ‘screening’ for more information on this).
  • To enable risk profiling of customers. CDD ensures the RI has the required information to profile customers and assess the money laundering/terrorism financing (ML/TF) risk the customer may pose to your business or organisation.
  • To prevent abuse by criminals. Criminals sometimes use proxies or appoint another person to conduct transactions on their behalf. This helps shield their own identity. Without proper CDD, the RI may unwittingly be helping a criminal launder money or financing terrorism
  • To assist law enforcement agencies. The CDD information that the RI collects may be vital for law enforcement agencies in undertaking an investigation, especially on persons-of-interest or anyone related to them.

When to conduct CDD?

When to conduct CDD?


If you are a reporting institution, you will need to conduct CDD when:

  • establishing business relationship with a new customer;
  • carrying out any transaction (including occasional or one-off transactions) involving the circumstances or an amount as specified;
  • having any suspicion of ML/TF, regardless of amount or thresholds;
  • there is doubt the accuracy and adequacy of information previously obtained from the customer; or
  • any other condition that the competent authority may specify

<i class="fas fa-bookmark"></i> What information is required?

What information is required?


The information to be collected varies, depending on the type of the customer, and the ML/TF risk posed by them.

For individual customers and beneficial owners, at a minimum you must identify and have on record the person’s:

  • Full name
  • National Registration Identity Card (NRIC) / passport number / reference number of any other official document
  • Residential and mailing address
  • Date of birth
  • Nationality
  • Purpose of transaction
  • Occupation type
  • Name of employer or nature of self-employment or nature of business
  • Contact number (home, office or mobile)

If your customer is a legal person i.e. company or business, the following are the minimum information needed:

  • Company / Business name
  • Business registration number
  • Powers that regulate and bind the customer, as well as person having senior management position
  • Business address / registered address
  • Nature of business
  • Directors & shareholders / beneficial owners details
  • Person authorised to represent the company or business

For other types of customers, please refer to the policy document applicable to your sector to find out the information you must obtain.

NOTE: Simplified CDD is allowed under very specific circumstances such as products and services assessed to be of lower ML/TF risk based on the reporting institutions’ institutional risk assessment.

For customers with low ML/TF risk, financial institutions, money services business (MSB) and Non-bank issuers of designated payment instruments and designated Islamic payment instruments (NBIs) may apply simplified CDD. Financial institutions, MSBs and NBIs must identify and have on record, at a minimum, the individual customer’s and beneficial owners’:

  • Full name
  • National Registration Identity Card (NRIC) / passport number / reference number of any other official document
  • Residential and  mailing address
  • Date of birth
  • Nationality

How to verify customers’ identity?

How to verify customers’ identity?


Once you have the required information, you will need to verify the information against reliable and independent documentation, electronic data or any other measures that are necessary. You may verify the information through commercial or public databases.

The documents you need for the verification will depend on the type of customer. You also need to determine the extent of verification method that fits the customer’s ML/TF risk. Most importantly, you must be satisfied with the authenticity or accuracy of the information you use to verify the identity of the customer, the beneficial owner or the person conducting the transaction.

For customer types other than individuals, you may refer to the policy documents to find out the acceptable form of documents or methods you may use to verify your customer’s identity.

<i class="fas fa-bookmark"></i> Higher risk situations

Higher risk situations


CDD helps the RI to risk profile customers. Different customers pose different ML/TF risks to the RI and business. Below are examples of when a customer’s background may pose higher risks

  • customer or the transaction involves one or more PEP
  • customer or the transaction involves one or more parties from higher risk countries/ jurisdictions (HRJs)

A PEP is an individual who holds prominent public functions in a government body or international organisation, either in Malaysia or a foreign country. The family members and/or close associates of these individuals are also considered PEPs.

As PEPs, these individuals often have power and influence, for example:, procurement processes, granting approval for projects and development, and approving grants. Because of this, they can be a target for corruption and bribery, and by extension for money laundering activities.

Being a PEP does not automatically mean someone is involved in criminal activities. As such, dealings with PEPs are not prohibited, as long as the RI understand the risk they bring to the business and have put in place control measures to mitigate these risks.

Not all PEPs pose the same level of money laundering/terrorism financing (ML/TF) risk. All foreign PEPs must be treated as high risk customers and must be subject to enhanced CDD. For domestic PEPs or person entrusted with a prominent function by an international organisation, the RI will need to assess the ML/TF risk. If the RI have assessed them as higher risk, they must be subject to enhanced CDD.

Higher Risk Jurisdictions  are countries that have been identified by the FATF that pose risk to the international financial system and/or by the Government of Malaysia. This includes countries that have been assessed as having weak AML/CFT system or higher ML/TF risk, countries subject to sanctions or embargos, and also countries that are known to provide funding or support to terrorists or having terrorist organisations operating in the country.

If the reporting institutions deals with any customer from these higher risk countries, the RI must conduct enhanced CDD on the customer and any additional measures that are being imposed by the FATF or by the Government of Malaysia. These counter measures may include limiting business relationship with that particular customer and to maintain a summary of business exposure to customers from that particular country.

Note: risks are not static. The FATF issues periodic list of countries with strategic deficiencies in their AML/CFT regimes that are undergoing review by the FATF according to the agreed milestones and timelines.  If a jurisdiction fails to make sufficient or timely progress, the FATF can decide to publicly list these countries with weak AML/CFT regimes. If a jurisdiction is making sufficient progress, the FATF can delist a jurisdiction.

When to do enhanced CDD?

When to do enhanced CDD?


Enhanced CDD applies to customers who the RI have assessed as higher risk (from the ML/TF perspective) or when the customer (or the customer’s beneficial owner) is a foreign politically exposed person (PEP).

Enhanced CDD means that the RI will need to conduct extra measures due to the heightened ML/TF risk from that customer, including:

  • Finding out the customer’s and beneficial owners’ source of wealth or source of funds (if the customer is a PEP, both are required)
  • Finding out additional information on the customer
  • Getting the senior management’s approval before engaging further with that customer
  • On an on-going basis, monitoring the customer’s transaction. This should be done more frequently or in more detail than other customers who are lower risk

For a more detailed description of enhanced CDD, please refer to the policy documents.

What is on-going CDD?

What is on-going CDD?


On-going due diligence applies whenever the reporting institutions has on-going business relationship with the customer (customers maintaining an account, repeated customers, membership programme etc.). There are two main things that the RI needs to do for on-going due diligence:

  1. Scrutinise or monitor the customer transactions through-out the course of the relationship to ensure that the transactions conducted are consistent with the knowledge of the customer, their business and risk profile, including where necessary, the source of funds used for the transaction. The frequency of the transaction monitoring should be commensurate with the customer’s and transaction’s ML/TF risk level.
  2. to ensure all CDD information including CDD documents is kept up-to-date and relevant.

For a more detailed description of on-going CDD, please refer to the policy documents applicable to the respective sectors.