Anti Money Laundering

Cash Business CDD Requirements: 4 Rules & 2026 Updates

Cash business CDD requirements sound straightforward, but 2026 FinCEN changes reshaped beneficial ownership and account-opening obligations.

Compliance officer reviewing customer identity, beneficial ownership, and transaction activity for a cash-intensive business under CDD requirements.

What Are Cash Business CDD Requirements and Who Must Follow Them?

Cash business CDD requirements do not automatically apply to every company that handles large amounts of cash. FinCEN's Customer Due Diligence framework directly applies to specified covered financial institutions, including banks, broker-dealers, mutual funds, futures commission merchants, and introducing brokers in commodities. FinCEN's CDD Final Rule sets out four core requirements for those institutions.

A restaurant, convenience store, dealership, car wash, retailer, or similar cash-intensive business is therefore usually the customer being subjected to CDD by its financial institution, rather than a business that must implement FinCEN's four-part CDD Rule itself simply because it accepts cash.

This distinction matters because some cash-heavy businesses are also separately regulated under the Bank Secrecy Act. Money services businesses have obligations under 31 CFR Part 1022, while casinos and card clubs operate under Part 1021. An ordinary trade or business can also have separate cash-reporting obligations, such as Form 8300, without becoming subject to the financial-institution CDD Rule.

Infographic showing which business types are covered by the 2016 FinCEN CDD Rule, including banks, broker-dealers, ordinary cash-intensive merchants, money services businesses, and casinos, with related regulatory obligations.

Banks still need to assess cash-intensive customers on a risk-sensitive basis. FFIEC guidance notes that the nature and volume of currency activity can make unusual transactions harder to distinguish from legitimate business revenue, so banks should understand expected transaction volumes, business operations, geographic activity, and account use.

What Are the 4 Core CDD Requirements?

FinCEN identifies four core customer due diligence requirements for covered financial institutions:

  1. Identify and verify customers. The institution must have procedures for establishing a reasonable belief that it knows the customer's true identity.
  2. Identify and verify beneficial owners of legal entity customers. When the beneficial-ownership rule applies, the institution identifies individuals who own 25% or more of the legal entity and an individual with significant responsibility to control, manage, or direct it, subject to applicable exclusions, exemptions, and FinCEN's 2026 relief.
  3. Understand the nature and purpose of the customer relationship. The institution develops a customer risk profile by understanding how the relationship is expected to operate.
  4. Conduct ongoing monitoring. Institutions monitor for suspicious transactions and, on a risk basis, maintain and update customer information, including beneficial-ownership information when appropriate.

For a cash-intensive commercial account, that expected profile may include the purpose of the account, normal cash-deposit volume, frequency of deposits, geographic operating area, products and services used, and the nature of the customer's business.

Those expectations create a baseline. A deviation from that baseline does not automatically prove money laundering, but it can provide a reason for further review.

Customer Identification Program Requirements for Cash Business Accounts

A Customer Identification Program, or CIP, provides the identity-verification foundation for CDD.

For banks, 31 CFR § 1020.220 requires a written, risk-based CIP. At minimum, a bank generally obtains a customer's name, date of birth for an individual, address, and identification number and uses documentary, non-documentary, or combined verification methods.

The FFIEC Customer Identification Program guidance also requires procedures for situations in which the bank cannot form a reasonable belief that it knows the customer's true identity.

For a cash-intensive business customer, identity verification may involve both the legal entity and the individuals acting on its behalf. The bank's procedures should reflect the risks presented by the account rather than relying on an assumption that every cash-heavy customer requires identical treatment.

How Long Must CIP Records Be Kept?

For banks, identifying information obtained for CIP purposes is generally retained for five years after the account closes. Descriptions of documents relied upon, non-documentary verification methods, verification results, and resolutions of substantive discrepancies generally must be kept five years after the record is made.

The CIP rule does not generally require a bank to keep a photocopy of every identification document used for verification.

Beneficial Ownership in 2026: Do Not Confuse the CDD Rule With CTA Reporting

beneficial-ownership-cdd-vs-cta-reporting-2026

Beneficial ownership is one of the most important areas to update in a 2026 CDD program because two separate federal frameworks are frequently confused: the CDD beneficial-ownership requirement for financial institutions and the Corporate Transparency Act's BOI reporting system.

They are not the same obligation.

Beneficial Ownership Under the CDD Rule

Under the CDD Rule, covered financial institutions generally identify and verify applicable beneficial owners of legal entity customers. The ownership prong generally reaches each individual who directly or indirectly owns 25% or more of the entity, while the control prong identifies one individual with significant responsibility for controlling, managing, or directing the entity.

The same person can satisfy both prongs in an appropriate case.

What Changed in February 2026?

FinCEN issued major CDD account-opening exceptive relief in 2026.

A covered institution choosing to use that relief no longer has to identify and verify the same legal entity customer's beneficial owners every time that customer opens an additional account.

Instead, identification and verification may generally be limited to:

  • when the legal entity customer first opens an account with the institution;
  • when the institution learns facts that reasonably call previously obtained beneficial-ownership information into question; or
  • when the institution's risk-based ongoing CDD procedures indicate that another review is needed.

Use of the relief is discretionary. An institution can continue its existing account-opening process if it chooses.

What Changed Under the Corporate Transparency Act in August 2026?

The CTA changed even more dramatically.

FinCEN's current Beneficial Ownership Information reporting rule permanently exempts U.S.-created companies and U.S. persons from federal BOI reporting requirements.

As of August 2026, federal BOI reporting generally applies only to certain foreign entities registered to do business in the United States, and those reporting companies do not report U.S. persons as beneficial owners or company applicants.

A domestic LLC, therefore, should not rely on older guidance stating that it still has to file or update a CTA BOI report with FinCEN.

That CTA exemption does not eliminate a covered financial institution's separate CDD obligations when the institution establishes or maintains a legal entity customer relationship.

Do Cash-Intensive Businesses Automatically Require Enhanced Due Diligence?

No. Cash-intensive customers do not automatically require the same enhanced due diligence simply because they handle substantial physical currency.

Cash activity can create additional money-laundering risk, but federal regulators have emphasized that no customer category has one uniform risk profile. Banks should evaluate the specific facts and circumstances of the relationship. The interagency risk-based CDD statement specifically warns against treating entire customer categories as automatically presenting the same level of risk.

FFIEC's cash-intensive business guidance identifies factors banks can consider when evaluating these customers, including:

  • purpose of the account;
  • volume, frequency, and nature of currency transactions;
  • customer history;
  • principal business activity;
  • business structure;
  • geographic locations;
  • expected products and services; and
  • the availability and reliability of customer information.

Where a customer presents a higher risk profile, additional due diligence may be appropriate. That can include source-of-funds information, financial statements, information about suppliers or major customers, business locations, expected transaction volumes, ownership information, or closer review of transactional activity.

That additional review is commonly described as enhanced due diligence, or EDD.

However, there is no universal federal rule saying that every restaurant, car wash, dealership, pawn shop, cannabis business, MSB, or other cash-heavy customer must automatically receive identical EDD or senior-management approval.

Does CDD Require Annual Reviews or “Perpetual KYC”?

No universal federal CDD rule says that every customer must be refreshed once a year, nor does FinCEN require institutions to adopt a system marketed as “perpetual KYC.”

The regulatory requirement is ongoing monitoring and risk-based updating.

A bank should maintain customer information when facts emerge that are relevant to assessing or reassessing the customer's risk. This makes trigger-based reviews useful for cash-intensive accounts because meaningful changes can occur between scheduled review dates.

Potential review triggers can include:

  • a material change in normal cash-deposit volume;
  • a significant change in the customer's business model;
  • new geographic markets or locations;
  • changes in ownership or control;
  • account activity that no longer matches the stated business purpose;
  • unexplained movement of funds between related entities;
  • new negative information relevant to the risk assessment; or
  • activity suggesting possible reporting avoidance.

Institutions can use technology and automated monitoring to identify these changes, but FinCEN does not establish a universal percentage increase—such as 20%, 30%, or 50%—that automatically creates a CDD refresh requirement.

Thresholds should instead reflect the institution's products, customer base, risks, monitoring design, and documented procedures.

How Do CDD, CTR, Form 8300, and SAR Rules Interact?

CDD helps a covered institution understand a customer's expected activity. CTR, Form 8300, and SAR requirements address different reporting events.

They should not be treated as interchangeable.

Infographic comparing CDD, CTR, Form 8300, and SAR requirements by typical filer and main regulatory trigger for cash reporting and customer due diligence compliance.

For a detailed comparison of the two cash-reporting systems, the US Compliance Institute guide to Form 8300 vs. CTR explains the filer, transaction, aggregation, and reporting differences.

Currency Transaction Reports

A covered financial institution generally evaluates whether currency transactions exceed $10,000 during one business day. Multiple currency transactions may need to be aggregated when the institution knows they were conducted by or on behalf of the same person.

Form 8300

A person engaged in a trade or business generally must file Form 8300 when it receives more than $10,000 in qualifying cash in one transaction or related transactions.

The IRS Form 8300 Reference Guide explains that the report is generally due within 15 days after the business receives the payment that causes the reportable amount to exceed $10,000. Related payments can also require aggregation under the applicable rules.

Suspicious Activity Reports

SAR rules are different because the applicable dollar threshold varies by institution type.

For example, the bank SAR provision commonly discussed in this context uses a $5,000 threshold for qualifying suspicious transactions, while certain MSB transactions can trigger mandatory SAR reporting at $2,000.

A transaction is also not suspicious merely because it falls close to $10,000.

FinCEN's 2025 SAR clarification on potential structuring activity states that activity at or near the CTR threshold, standing alone, is not sufficient to require an SAR. The financial institution must know, suspect, or have reason to suspect that the transactions were designed to evade reporting requirements or otherwise meet the applicable SAR standard.

For practical examples of behaviors that can warrant closer review, USCI's guide to cash business red flags covers structuring indicators, unusual deposit behavior, documentation problems, and other cash-account patterns.

CDD Training for Employees Handling Cash-Business Relationships

Training is an important component of an institution's broader BSA/AML compliance program.

For a bank serving cash-intensive customers, relevant personnel should understand not only the institution's policy but also what they are expected to do when the customer's activity changes.

Role-based CDD training can cover:

  • CIP information and identity-verification procedures;
  • beneficial-ownership requirements and the 2026 account-opening relief;
  • expected customer activity and risk profiling;
  • escalation of meaningful transaction changes;
  • CTR and SAR distinctions;
  • structuring indicators;
  • when additional customer information is appropriate; and
  • SAR confidentiality requirements.

Training documentation should demonstrate that training required by the institution's program actually occurred. Institutions may also retain assessments, scenarios, completion records, or other evidence of effectiveness as part of their internal training controls.

Those assessment methods can strengthen documentation, but a scored quiz is not itself a universal FinCEN requirement for every CDD training session.

How Do the Rules Differ for MSBs, Casinos, and Ordinary Cash Businesses?

CDD becomes easier to understand once the regulatory category is separated from the fact that a business handles cash.

Ordinary Cash-Intensive Businesses

Restaurants, retailers, convenience stores, parking businesses, car washes, dealerships, and other merchants do not become subject to the four-element CDD Rule merely because cash represents a large share of their revenue.

Their banks may nevertheless perform more detailed risk-based CDD when the account's activity, business model, geography, ownership, or expected cash volume warrants it.

The business itself may also have Form 8300 obligations when it receives more than $10,000 in qualifying cash in a transaction or related transactions.

Money Services Businesses

MSBs operate under separate BSA requirements in 31 CFR Part 1022.

Banks providing services to an MSB still perform risk-based CDD on that customer. The MSB itself may have registration, an AML program, transaction record-keeping, reporting, and agent-monitoring obligations depending on its activities.

For certain MSBs subject to mandatory SAR requirements, qualifying suspicious transactions of $2,000 or more may require reporting.

Casinos and Card Clubs

Casinos and card clubs operate under their own BSA rules in 31 CFR Part 1021 rather than the 2016 CDD Rule that applies to covered financial institutions.

Their obligations can include AML programs, currency transaction reporting, suspicious activity reporting, and specific transaction recordkeeping. Certain casino recordkeeping provisions use $3,000 thresholds, but that should not be described as a blanket rule requiring customer identification for every transaction above $3,000.

Cash Business CDD Checklist

A practical cash-business CDD review for a covered financial institution can follow this sequence:

  1. Confirm regulatory scope. Determine whether the institution and customer relationship fall within the applicable CDD and CIP rules.
  2. Identify and verify the customer. Follow the institution's CIP procedures.
  3. Apply beneficial-ownership requirements. Determine whether 31 CFR § 1010.230 applies and whether the 2026 account-opening relief affects the review.
  4. Understand the business. Document what the customer sells, how it generates revenue, where it operates, and how the account will be used.
  5. Establish expected activity. Record reasonable expectations for currency volume, transaction frequency, account products, counterparties, and geographic activity.
  6. Assess the relationship's specific risks. Do not assign risk solely because the customer belongs to a particular business category.
  7. Determine whether additional information is needed. Higher-risk facts may justify additional sources of funds, financial, ownership, licensing, operational, or transactional information.
  8. Monitor actual activity. Compare account behavior with the customer's known operations and expected profile.
  9. Update information when risk-relevant facts change. CDD maintenance should be risk-based rather than driven by an invented universal calendar or percentage threshold.
  10. Apply the correct reporting framework. CTR, SAR, and Form 8300 each have distinct triggers and filer requirements.

Common CDD Control Gaps in Cash-Business Accounts

Several weaknesses can undermine an otherwise well-designed CDD program.

Treating Every Cash Business as the Same Risk

A small local restaurant and a large multi-location cash business may have very different transaction patterns and risk factors. Category labels should not replace a customer-specific assessment.

Relying on Onboarding Information Indefinitely

A profile based on expected activity is useful only while it continues to reflect the customer's business. Material changes should be investigated and incorporated into the risk assessment when appropriate.

Failing to Revisit Beneficial Ownership When Triggered

The 2026 account-opening relief reduces repetitive collection, but it does not eliminate risk-based beneficial-ownership updates. New information that calls the existing data into question can still require review.

Collecting Identification Without Documenting Verification

CDD and CIP are not simply document-collection exercises. Policies should explain how the institution forms a reasonable belief that it knows the customer's identity and how material discrepancies are resolved.

Treating Threshold Activity as Automatically Suspicious

A $9,900 deposit is not automatically structuring, just as a $10,100 transaction is not automatically money laundering. Context, intent indicators, transaction patterns, and the applicable reporting rules matter.

What Changed for CDD Compliance in 2026?

Three developments are especially important.

First, FinCEN's February 2026 relief changed beneficial-ownership collection at subsequent account openings. Covered institutions using the relief do not have to re-identify and re-verify the same legal entity customer's beneficial owners every time another account is opened, subject to the conditions discussed above.

Second, FinCEN's August 2026 BOI final rule permanently removed CTA reporting requirements for U.S.-created companies and U.S. persons. Older articles telling domestic LLCs and corporations to file or update BOI reports are now outdated.

Third, FinCEN proposed broader AML/CFT program reforms in April 2026. As of September 2026, the agency continues to classify that action as a Notice of Proposed Rulemaking, not a final rule. Businesses should therefore distinguish the proposal from requirements already in effect.

Frequently Asked Questions

01 What are the 4 CDD requirements? +

FinCEN's four core CDD requirements are customer identification and verification, beneficial-ownership identification and verification for applicable legal entity customers, understanding the nature and purpose of customer relationships, and ongoing monitoring for suspicious activity and risk-based customer-information updates.

02 Is CDD required for all cash businesses? +

No. Handling significant cash does not by itself make an ordinary merchant subject to FinCEN's 2016 CDD Rule. Covered financial institutions perform CDD on their customers, while MSBs, casinos, and certain other regulated businesses can have separate BSA obligations.

03 Is CDD required for all customers of a bank? +

Banks must maintain risk-based CDD procedures for their customer relationships, but not every CDD component applies identically to every customer. For example, the beneficial-ownership rule specifically concerns applicable legal entity customers and contains exclusions, exemptions, and 2026 exceptive relief.

04 What should a cash-business CDD checklist include? +

A cash-business CDD checklist should cover customer identification, applicable beneficial ownership, business purpose, expected cash volume and transaction patterns, customer-specific risk factors, additional information where warranted, ongoing monitoring, risk-based updates, and the correct CTR or SAR escalation process.

05 Does every cash-intensive customer need enhanced due diligence? +

No. Cash intensity can be a relevant risk factor, but regulators do not treat every customer in a category as automatically presenting the same level of risk. Additional due diligence should be proportionate to the specific relationship and the risks the institution identifies.

06 What changed for beneficial ownership requirements in 2026? +

FinCEN made two major changes. February 2026 relief reduced repetitive beneficial-owner identification and verification when an existing legal entity customer opens additional accounts, and the August 2026 CTA final rule permanently exempted U.S.-created companies and U.S. persons from federal BOI reporting.

Precision Compliance Training Built for Your Business.
We’re constantly expanding our U.S. compliance courses to fit your exact needs. Whether that’s state-specific mandates, niche industry standards, or scalable training for your workforce. Reach out today to build your custom plan.
Request Custom Training
Ready to Write Your Success Story?
Join thousands of students who have already transformed their careers. Start your learning journey today and become our next success story.