Establishing secure connection…Loading editor…Preparing document…

Legal CDD Agreement

This template is fully customizable. Edit the text, fill out the fields, and send it for signature. Give it a try!

LEGAL CDD AGREEMENT

This Customer Due Diligence Agreement (the Agreement) is entered into on this day of , (Effective Date), by and between Client Name: Client Entity Type: , Client Address: ; and Service Provider Name: Provider Address: .

Recitals

WHEREAS, Client requires customer due diligence, identification and monitoring services in order to comply with applicable anti-money laundering, sanctions, and other regulatory obligations; and

WHEREAS, Provider represents that it has the technical capability, personnel, and procedures to perform identity verification, screening and ongoing monitoring services in accordance with industry standards; and

WHEREAS, the parties wish to set forth the terms and conditions under which Provider will perform Customer Due Diligence (CDD) services for Client.

NOW THEREFORE, in consideration of the mutual covenants and agreements contained herein, the parties agree as follows:

1. Definitions

Unless otherwise defined herein, the following terms shall have the meanings set forth below:

"Customer Due Diligence" or "CDD" means the identification, verification, screening, monitoring and record-keeping actions described in this Agreement performed to identify customers, beneficial owners, and risk indicators, including but not limited to identity verification, sanctions and watchlist screening, politically exposed persons (PEP) screening, adverse-media checks, and transaction monitoring.

"Beneficial Owner" means any natural person who ultimately owns or controls the customer or on whose behalf a transaction is being conducted, as determined under applicable law.

2. Scope of Services

Provider will perform the CDD services selected below and any additional services expressly agreed in writing by the parties. Provider's services shall include reasonable measures to verify identity and screen information against applicable sanction lists and databases.

Services selected:

Provider shall perform services in a commercially reasonable manner consistent with industry standards. Provider's services do not constitute legal advice; Client is responsible for determining the sufficiency of Provider's services to meet Client's legal or regulatory obligations.

3. Client Obligations and Representations

Client shall provide accurate, complete and timely information, documentation and authorizations necessary for Provider to perform the services, including copies of identity documents, corporate formation documents, ownership data and any information required to identify beneficial owners.

Client represents and warrants that all data and materials provided to Provider do not infringe third-party rights and that Client has authority to provide such data for processing under this Agreement.

4. Provider Obligations; Confidentiality; Data Handling

Provider shall implement reasonable administrative, technical and physical safeguards to protect Client data from unauthorized access, disclosure, alteration and destruction. Provider shall limit access to Client data to personnel and subcontractors who have a need to know for performance of the services and are bound by confidentiality obligations at least as protective as this Agreement.

Provider may engage subcontractors to perform portions of the services, provided Provider remains responsible for their performance and compliance with this Agreement. Provider shall notify Client in advance of material changes to subcontractor arrangements where feasible.

5. Fees and Payment

Client shall pay Provider the fees set forth below in consideration for the CDD services. Fees are exclusive of taxes; Client is responsible for all taxes imposed on payments under this Agreement, excluding taxes based on Provider's net income.

Overdue payments shall accrue interest at the lesser of 1.5% per month or the maximum rate permitted by applicable law. Provider may suspend services for Client's failure to timely pay, provided Provider gives at least ten (10) days' prior written notice.

6. Term and Termination

The term of this Agreement shall commence on the Effective Date and continue for months, after which it shall automatically renew for successive terms of equal length unless either party provides written notice of non-renewal at least days prior to the then-current term expiration.

Either party may terminate this Agreement for material breach by the other party that remains uncured for thirty (30) days after written notice specifying the breach. Termination shall not relieve Client of its obligation to pay fees for services performed through the effective date of termination.

7. Indemnification

Client shall defend, indemnify and hold harmless Provider and its officers, directors, employees and agents from and against any and all claims, liabilities, losses, damages and expenses (including reasonable attorneys' fees) arising out of or resulting from Client's breach of its representations, warranties, or obligations hereunder, or from Client's use of the CDD results in a manner inconsistent with applicable law.

8. Limitation of Liability

Except for liability arising from willful misconduct or gross negligence, Provider's aggregate liability to Client for any and all claims arising out of or relating to this Agreement shall not exceed the total fees paid by Client to Provider under this Agreement during the twelve (12) month period preceding the claim. In no event shall Provider be liable for special, consequential, incidental or punitive damages.

9. Audit Rights and Record Retention

Client shall maintain records necessary to demonstrate compliance with applicable laws and this Agreement for the retention period specified above. Provider shall permit Client, or Client's designated auditor, to audit Provider's performance under this Agreement subject to reasonable notice and confidentiality protections, provided that such audits shall not unreasonably interfere with Provider's business operations.

10. Compliance with Laws

Each party shall comply with all applicable laws, regulations and governmental orders relating to anti-money laundering, counter-terrorist financing, economic sanctions and data protection. Client shall promptly notify Provider if Client becomes aware of any regulatory inquiries or investigations related to CDD matters arising from Provider's services.

11. Notices

All notices, requests, consents, claims, demands and other communications hereunder shall be in writing and addressed to the parties at their respective addresses set forth below or to such other address as a party may designate by notice in accordance with this section.

12. Amendments; Waiver; Counterparts

No amendment, modification or waiver of any provision of this Agreement shall be effective unless in writing and signed by authorized representatives of both parties. No failure or delay by either party in exercising any remedy shall operate as a waiver of that remedy. This Agreement may be executed in counterparts, each of which shall be deemed an original and all of which together shall constitute one instrument.

13. Governing Law; Severability; Entire Agreement

This Agreement shall be governed by and construed in accordance with the laws of without regard to conflict of law principles. If any provision of this Agreement is held invalid or unenforceable, such provision shall be reformed only to the extent necessary to make it enforceable, and the remaining provisions shall remain in full force and effect. This Agreement, together with any schedules and attachments expressly incorporated, constitutes the entire agreement between the parties with respect to the subject matter hereof and supersedes all prior agreements and understandings.

14. Miscellaneous Provisions

If either party is required to bring suit or arbitration to enforce this Agreement, the prevailing party shall be entitled to recover reasonable attorneys' fees and costs. The parties acknowledge that monetary damages may be insufficient to remedy certain breaches and that injunctive relief may be an appropriate remedy in addition to any other available remedies.

Client Printed Name:

By:

Date:

Provider Printed Name:

By:

Date:

Enter text✕

What a Legal CDD Agreement Is and when it’s used

A Legal CDD Agreement documents customer due diligence steps and the parties’ commitments to provide identity, ownership, and source-of-funds information required under anti-money laundering and risk-management policies. It typically sets out the obligations of the reporting party and the customer, the scope of information to be collected, representations about accuracy, data retention and privacy controls, and consent to verification checks. The agreement may be used by financial institutions, law firms, corporate legal teams, and regulated service providers to create an auditable record that supports compliance with federal and state AML, banking, and regulatory obligations.

Why a clear Legal CDD Agreement matters

A well-drafted Legal CDD Agreement reduces regulatory risk, clarifies responsibilities for data collection and verification, and creates an auditable record for exams or internal review. Precise terms improve onboarding speed and reduce follow-up requests that delay accounts or transactions.

Why a clear Legal CDD Agreement matters

Who commonly completes a Legal CDD Agreement

Organizations and roles that typically prepare or sign a Legal CDD Agreement include compliance officers, account onboarding teams, outside counsel, and covered financial institutions required to verify customer identity.

  • Compliance teams and AML officers responsible for KYC processes and regulatory filings, ensuring documentation meets program standards.
  • Relationship managers and account onboarding staff who collect customer data, coordinate verifications, and close onboarding checklists.
  • External counsel or corporate legal departments that draft or review the agreement language to align with corporate policies and local regulations.

The document’s users vary by industry and regulatory status; align signatory authority and data access with internal policies before circulation.

Core elements to include in a professional Legal CDD Agreement

A complete Legal CDD Agreement organizes identity verification, data sharing permissions, representations, retention rules, and dispute escalation to support compliance and audits.

Parties

Full legal names and entity types for each party, plus a designated compliance contact and mailing address to anchor obligations and notices.

Scope of Checks

Specify which verification steps apply (identity document review, beneficial ownership checks, sanctions screening, adverse media checks) and who performs them.

Customer Representations

Customer statements about accuracy of information, authority to act, and obligation to update material changes during the relationship term.

Data Use and Privacy

Describe permitted uses, third-party providers, cross-border transfers, and applicable privacy frameworks the parties rely on to protect personal data.

Retention and Audit

Retention schedules, audit rights, and the required documentation trail for verification steps to support regulatory examinations.

Governing Law & Remedies

Choice of law and dispute-resolution provisions plus remedies for false representations or material nondisclosure.

Step-by-step: completing a Legal CDD Agreement

Follow these sequential actions to prepare, verify, sign, and retain a complete CDD record that meets regulatory expectations.

  • 01
    Prepare: Assemble identity documents and beneficial ownership records before starting.
  • 02
    Populate: Enter accurate party details, dates, and contact information in each form field.
  • 03
    Verify: Run required screenings (sanctions, PEP, adverse media) and record results.
  • 04
    Sign & Store: Collect authorized signatures and preserve the audit trail with retention metadata.

Typical verification and signing workflow

A standardized workflow reduces friction and ensures each verification step is recorded and attributable.

  • Upload: Sender uploads the agreement and supporting documents.
  • Assign Fields: Place signature, date, and verification fields for required parties.
  • Authenticate: Signer verifies identity (email, SMS, or stronger methods).
  • Complete: Signed copy and audit trail are stored for retention.

Configuring an online Legal CDD Agreement workflow

Set these workflow parameters to control routing, signer authentication, and evidence capture for regulatory review.

Field Configuration
Signer Order Sequential or parallel routing per internal policy.
Authentication Email or SMS code; use KBA or multi-factor for higher risk.
Document Versioning Enable version control and append a certificate of completion.
Audit Trail Capture IP, timestamp, and signer actions for each step.

Digital signing and technical requirements

Choose a platform that preserves audit trails, supports conditional fields, and meets your compliance needs.

  • Document formats: PDF and DOCX support for templates.
  • Integrations: Connectors for CRMs and cloud storage.
  • Authentication: Support for email, SMS, and stronger KBA options.

Ensure the chosen provider offers TLS 1.2/1.3 transit encryption and AES-256 at rest, a BAA for HIPAA workflows, and audit logs for legal defense.

Typical timelines and regulatory timeframes to track

Track intake, verification, remediation, and retention deadlines to avoid regulatory gaps and fines.

Initial Onboarding:

Complete CDD before account activation; timing set by internal policy and risk tier.

Ongoing Monitoring:

Periodic reviews per risk category — often annually or on material changes.

Adverse Findings Remediation:

Address high-risk hits immediately and document actions taken.

Record Retention:

Maintain CDD records per retention policy and regulatory baseline.

Audit Availability:

Provide complete records promptly for examiners or law enforcement requests.

Key milestones from onboarding to audit readiness

Follow these numbered milestones to move from intake through documented verification and readiness for inspection.

01

1. Intake Submitted

Customer provides initial forms and ID documents.

02

2. Identity Verified

Documents and electronic checks produce verification results.

03

3. Risk Assessment

Assign risk tier and escalate if high or adverse.

04

4. Final Approval

Compliance signs off and account is enabled.

Security and compliance controls to include

Encryption: AES-256 at rest
Transport Security: TLS 1.2/1.3
Audit Trail: Timestamped logs
HIPAA BAA: Available when required
21 CFR Part 11: Supported for regulated records
SOC 2 Type II: Controls attested

Common mistakes that cause delays or compliance gaps

  • Mismatched names or missing entity details lead to TIN mismatches and potential withholding or reporting issues.
  • Insufficient beneficial ownership data leaves onboarding incomplete and increases regulatory scrutiny during exams.
  • Failing to capture an explicit consent for electronic verification can create admissibility or enforceability questions.
  • Not preserving an unalterable audit trail or failing to store verification artifacts exposes the organization during regulatory review.

Potential penalties and legal risks for incomplete or incorrect CDD

Regulatory fines: Civil penalties and enforcement actions
Operational risk: Account freezes or transaction blocking
Reputational harm: Adverse publicity and loss of trust
Criminal exposure: Willful blindness can trigger criminal charges
Reporting errors: Incorrect filings may lead to sanctions
Recordkeeping violations: Failure to retain evidence invites fines

Real-world examples of Legal CDD Agreement use

These case snapshots show how teams apply CDD Agreements to reduce onboarding friction while preserving evidence.

Optica Ventures

A venture fund standardized its CDD template to capture beneficial owners and KYC evidence before funding decisions.

  • The streamlined form reduced document back-and-forth by consolidating checks.
  • As a result, the fund shortened deal start times and preserved a consistent audit trail for investor and compliance reviews.

Fertility Centers

A healthcare provider added a privacy addendum and BAA to its CDD Agreement to support patient verification while protecting PHI.

  • The combined agreement enabled remote intake and identity proofing.
  • That allowed clinics to complete onboarding and retain HIPAA-compliant evidence without in-person visits, improving patient access and record completeness.

eSignature vendor comparison for CDD agreement workflows

Basic pricing and feature distinctions for common eSignature providers; signNow is listed first in accordance with platform comparisons.

signNow DocuSign Adobe Sign PandaDoc HelloSign
Starting Price $8/user/mo $15/user/mo $14/user/mo $19/user/mo $15/user/mo
Free Trial Yes, 7-day trial No No Yes, limited Yes, limited
Bulk Send Yes Yes Yes Yes No
Audit Trail Yes Yes Yes Yes Yes
HIPAA Compliant Yes Yes Yes No No

Frequently asked questions about Legal CDD Agreements

Answers to common questions when preparing, signing, or storing Legal CDD Agreements in regulated environments.


Need help? Contact support

be ready to get more
Join over 28 million airSlate SignNow users