KYC due diligence, KYC CDD, CDD KYC and KYC/CDD are four ways of writing the same thing, and the energy spent distinguishing them is better spent on a boundary that does matter. This page explains the naming briefly and then draws the line that changes how you build a file: between a check that is performed and a record that is kept.
The naming, settled in a paragraph
Know your customer is the practice. Customer due diligence is what you do to a specific customer under that practice: identify, rate, evidence, review. When people write KYC/CDD they mean both, usually because their policy is called one thing and their regulator's language is the other. No firm has ever improved a file by resolving this, and the words appear together in job adverts more often than in obligations.
The boundary that does matter
On one side, checks: verifying an identity, searching a registry, screening a name. These are performed, they return a result, and they can be bought from someone else. On the other side, the record: what was run, when, by whom, what it returned, what your firm concluded, who approved that, and when it is revisited. Checks are a purchase. The record is a responsibility, and it is the one nobody can sell you out of.
Where firms put the boundary in the wrong place
The commonest mistake is treating the vendor's system as the record. It works until the day you change vendor, or your contract lapses, or you need a customer's history from four years ago in a form somebody outside the firm can read. Keep the checks wherever they are best done and keep the record where you control it. That is the whole argument for a customer file that is yours.
Questions people ask about kyc due diligence
Is CDD part of KYC or the other way round?
In ordinary usage, CDD is the work done on a customer within the KYC practice. Policies vary and it does not matter much, provided your own policy uses one convention consistently.
What does KYC/CDD mean on a job advert?
That the role covers both the front-end identification and the ongoing customer risk work, which is most of what a small firm's compliance function does.
Do we need both a KYC policy and a CDD policy?
Almost never. One policy, with sections for customer types and risk ratings, is easier to keep current than two documents that quietly diverge.