CDD, customer due diligence, and the one step of it we perform
Solidus does not provide customer due diligence. CDD is not-built in our
lexicon. What we do is one step inside it, identity verification, and this page is precise
about which step, because CDD is the term buyers most often use when they mean something much larger
than what any identity vendor supplies.
What CDD actually requires
It is a programme, not a check. A regulated firm generally has to:
- Identify the customer and verify that identity from reliable, independent sources.
- Identify beneficial owners where the customer is an entity, see UBO.
- Understand the purpose and intended nature of the relationship.
- Screen against sanctions, PEP and adverse-media sources.
- Risk-rate the relationship and calibrate everything else to that rating.
- Monitor on an ongoing basis, and refresh, see re-KYC and periodic review.
- Evidence all of it to a supervisor's satisfaction.
Where risk is higher, the standard escalates to enhanced due diligence, which adds source-of-funds and source-of-wealth work.
The one step we perform, stated exactly
Step 1, and only the verification half of it. Solidus verifies that a person is who they claim to be, using document capture, liveness and, where available, chip reading, and issues the result as a credential the person holds. See credential anatomy.
Steps 2 through 7 are not ours. No beneficial-ownership resolution, no screening, no risk rating, no monitoring, no case management, no supervisor-facing evidence pack. Those are the substance of a CDD programme and they are somebody else's product.
Where reuse changes something real
Step 1 is the step a customer experiences, and it is the one that repeats, at every institution, and again at every refresh. That is where a held credential does genuine work, and it is the same structural argument as re-KYC: the repetition is guaranteed by regulation rather than left to chance. The argument is good; what is unverified is our implementation, not the shape of the idea.
And the limit that a compliance officer will reach for immediately: accepting a credential issued by someone else does not discharge your CDD obligation. You remain answerable for having identified and verified the customer. Reuse changes the customer's experience and your cost; it does not move the duty. Any vendor telling you otherwise is describing a legal position that does not exist.