ACAMS CAMS: Customer Due Diligence Triggers

Customer due diligence is not a one-time file assembled at onboarding and left untouched until the next periodic review. A customer relationship can change materially after the account is opened: ownership shifts, expected activity expands, new geographies appear, products change, transactions no longer fit the stated purpose, or information previously relied on becomes questionable. Those events are triggers for reassessing what the institution understands about the customer and whether the existing risk profile still makes sense.

Current U.S. guidance reinforces this event-driven logic. FinCEN’s 2026 CDD updates allow covered institutions, if they choose to use the relief, to avoid re-identifying and verifying beneficial owners at every new account opening for an existing legal-entity customer. But the relief preserves the need to act when facts call prior information into question or when risk-based ongoing due diligence requires an update. The operational lesson is more important than the procedural detail: review should follow meaningful risk change, not paperwork frequency alone.

A well-designed trigger framework answers three questions: what changed, why does that change matter, and what level of customer review should follow?

Expected activity is the baseline that makes change visible

CDD should establish enough understanding of the relationship to recognize when actual activity no longer fits. That includes the nature and purpose of the relationship, expected products and services, likely transaction types, customer business, relevant geographies, and other factors appropriate to the institution. Without a baseline, “unusual activity” becomes a subjective judgment after the alert appears.

The baseline should be specific enough to support decisions but not so rigid that ordinary business variation produces constant review. A growing business may legitimately increase payment volume. A seasonal customer may have predictable peaks. The trigger should focus on changes that alter financial-crime exposure or confidence in the customer profile.

Ownership and control changes are material because identity risk changes

Changes in beneficial ownership, control persons, legal structure, or who is acting on behalf of the customer can alter the institution’s understanding of the relationship. The right response depends on the facts and applicable requirements, but the event should at least cause the program to ask whether existing information remains reliable and whether risk has changed.

This is not simply a form-maintenance exercise. Ownership opacity can change who benefits from the account, which jurisdictions matter, whether politically exposed persons or sanctions concerns are present, and whether source-of-funds analysis remains credible. The review should focus on the risk consequence of the ownership change, not just whether a corporate document was uploaded.

Product and channel changes can create a new risk profile

A customer that originally used a low-volume domestic product may later adopt international wires, remote deposit, instant payments, trade services, virtual assets, or another capability with different exposure. The customer may be unchanged in name while the risk of the relationship changes substantially.

Triggers should therefore include material product adoption, channel changes, and expansion into higher-risk services. The institution should compare the new activity with the original purpose and decide whether controls, monitoring scenarios, limits, or approval levels need to change. This is a practical example of moving compliance policy into operating controls.

Geographic change deserves context, not automatic conclusions

New counterparties, business locations, transaction corridors, or countries can increase or decrease risk depending on the customer and activity. A simple country flag can be useful as a prompt, but it should not replace analysis. FATF itself cautions against treating monitored jurisdictions as a reason for indiscriminate de-risking and emphasizes risk-based treatment.

The trigger should lead to questions: Is the geography expected for the customer’s business? Does it introduce sanctions, corruption, trafficking, tax, or money-laundering exposure? Is the volume material? Are counterparties transparent? Does the institution have enough information to understand the activity? The answer should determine the depth of review.

Monitoring alerts can be CDD events even when they do not become SARs

An alert may reveal a pattern inconsistent with the customer profile without reaching the threshold for suspicious-activity reporting. Repeated cash activity, unexpected counterparties, rapid movement of funds, sudden velocity, or behavior outside the stated business can still indicate that the existing CDD baseline is wrong or incomplete.

This is where evidence-led investigation becomes relevant beyond cybersecurity. The investigator should record what the activity shows about the customer, not merely whether the alert was closed. Useful case outcomes can include “no suspicion identified, but expected activity updated” or “risk rating increased pending enhanced review.”

Adverse information should be assessed for materiality and reliability

News, law-enforcement requests, regulatory actions, litigation, fraud allegations, or other adverse information can trigger customer review. The program should distinguish between credible information that changes risk and low-quality or ambiguous information that merely resembles the customer. Identity resolution, source credibility, recency, and relevance all matter.

An adverse-media trigger without a quality standard can flood teams with weak matches. A strong process records why the information belongs to the customer, what risk it creates, which facts need verification, and what decision follows. The same principle appears in decision-centered risk management: evidence matters because it changes treatment.

Periodic review should catch what event detection misses

Event-driven CDD does not eliminate periodic review where policy or regulation requires it. Events can be missed, customer data can drift quietly, and a relationship can become stale without one dramatic trigger. Periodic review is the backstop that tests whether the profile still reflects the relationship.

The cadence can be risk-based, with more frequent review for higher-risk relationships and a lighter process for lower-risk customers where permitted. The important point is that periodic review and event-driven review serve different purposes. One catches known changes as they happen; the other challenges the profile even when no trigger was recorded.

Trigger design needs ownership and service levels

A trigger that enters a queue with no owner is not a control. Each material event type should have a receiving team, required evidence, decision authority, target time, and escalation path. High-risk triggers may require immediate restriction or senior review, while lower-risk changes can be handled through routine refresh.

Programs should also monitor trigger aging, repeated triggers on the same customer, unresolved requests for information, and cases closed without updating customer records. These metrics reveal whether the CDD system actually changes when the relationship changes.

Document why the risk profile changed—or did not

Not every trigger should increase risk. A customer may provide a reasonable explanation, supporting documents may confirm the activity, or a data error may have produced the signal. The review should record the evidence and reasoning so a later investigator can understand why the profile stayed the same.

This is where the broader risk, evidence, and accountability model applies well. CDD governance is strongest when the institution can trace event → analysis → decision → profile update → control change. A trigger list is only the first step.

Trigger libraries should be calibrated to materiality. A minor address correction should not receive the same workflow as an unexplained ownership change or a sudden shift into high-risk cross-border activity. Tiering triggers by likely risk impact helps route simple data maintenance to operational teams while reserving investigative capacity for events that can materially alter the customer risk profile.

Systems should also prevent fragmented customer views from hiding triggers. A legal entity may use several products, business units, branches, or accounts. If each platform sees only its own activity, no single team may notice that the combined relationship has changed. Where permitted and practical, CDD governance should define how relevant information is aggregated or shared so the institution can evaluate the customer rather than a collection of disconnected accounts.

Quality assurance can test trigger effectiveness by looking backward from known customer changes. When an investigation, law-enforcement request, account exit, or material risk-rating change occurs, ask whether the event should have created an earlier CDD trigger. Missed-trigger analysis is valuable because it tests the detection design against real outcomes rather than only reviewing cases the system already surfaced.

Trigger testing should include both sensitivity and burden. If nearly every customer change launches a full review, the framework may be too broad to operate. If important ownership, activity, or geography changes routinely pass without review, it is too weak. Sampling closed events and known material changes helps calibrate where the institution should automate simple updates, where analysts should investigate, and where senior escalation is appropriate.

Trigger governance should also define evidence retention so later investigators can see what changed, what information was refreshed, and why the risk decision was made.

Customer due diligence stays useful when it behaves like a living model of the relationship. Material changes in ownership, products, geography, expected activity, adverse information, or monitoring evidence should challenge that model. Periodic review then tests the profile for changes the trigger system did not catch.

The quality of the program is visible in what happens after the trigger. If the institution can show what changed, how the evidence was evaluated, whether risk changed, and which controls were adjusted, ongoing CDD is doing more than refreshing forms. It is keeping the customer-risk decision aligned with reality.

Leave a Reply

How It Works

img
Step 1. Choose Exam
on ExamLabs
Download IT Exams Questions & Answers
img
Step 2. Open Exam with
Avanset Exam Simulator
Press here to download VCE Exam Simulator that simulates real exam environment
img
Step 3. Study
& Pass
IT Exams Anywhere, Anytime!