In November 2023, FATF and the OECD published a joint report describing the criminal exploitation of citizenship and residency investment programmes as a multi-billion-dollar business used to launder the proceeds of fraud and corruption, evade justice, or gain access to third countries. The same report called on governments and programme operators to apply a variety of safeguards to ensure these programmes are administered in a risk-sensitive way, including stronger due diligence and transparency mechanisms.
That finding matters well beyond the governments that run Citizenship by Investment (CBI) programmes. It is a direct signal to every financial institution, legal firm, and advisory practice that touches a CBI application: the population of applicants carries risk characteristics that a standard identity check was never designed to catch.
What Makes CBI Applicant Risk Different
A typical retail or corporate customer has a domestic financial footprint: local employment history, a bank relationship, a credit file, and a residential address that can be independently corroborated. A CBI applicant frequently has none of this in the jurisdiction granting citizenship, by design. Their wealth, business interests, and personal connections often span several jurisdictions, and the depth of publicly available record-keeping on those interests varies enormously depending on where the applicant has lived, worked, and invested.
Separate academic research examining the FATF/OECD findings has noted that investigative journalists have exposed major cases of criminals in possession of citizenship gained through CBI programmes who have carried out billions of dollars in financial crimes. The pattern in these cases is rarely a failed identity check. It is a wealth narrative that was never independently corroborated, a source of funds that was never traced beyond the immediate transaction, or a corporate or family connection that never surfaced through applicant-level screening alone.
This is the core distinction that should inform how CBI due diligence is structured: identity verification confirms whom someone claims to be. It says nothing about how their wealth was built, whether the specific funds involved are legitimately sourced, or whom they are connected to.

A clean identity document and a clean database screening result can both be true at the same time as the file still missing the risk that actually matters, an unverified wealth story, or a fund path that was never traced beyond the initial transfer.
The Regulatory Signal on CRS and Tax Transparency
The FATF/OECD report addresses financial crime risk directly, but a related and separate concern has been building on the tax transparency side. The OECD has published an analysis of over 100 CBI/RBI schemes and identified a number of programmes it considers to potentially pose a high risk to the integrity of the OECD's Common Reporting Standard (CRS), the international framework financial institutions rely on to correctly identify a customer's tax residence. Identity cards and other documentation obtained through CBI/RBI schemes can potentially be misused to misrepresent an individual's jurisdiction of tax residence, undermining the due diligence procedures financial institutions are required to follow under the CRS.
The practical implication for anyone conducting CBI due diligence is that a clean identity document and a clean database screening result are not, on their own, sufficient evidence that an applicant's declared profile is accurate. Where an applicant's citizenship or residence documentation originates from a CBI/RBI scheme, that context is itself relevant to the wider risk assessment. Not because the programme is inherently improper, but because it is a documented avenue for misrepresentation that regulators have specifically flagged.
For financial institutions applying CRS due diligence, a CBI/RBI-issued identity document is not automatically a reliable indicator of tax residence. That context belongs in the risk assessment itself, not just the standard KYC file.
From Standard Checks to Enhanced Due Diligence
Customer due diligence (CDD); identity verification, basic screening, and a documented risk assessment- remains the correct starting points for every applicant. The question a compliance or risk team needs to answer is not whether to apply CDD, but whether the findings from that initial review indicate the file needs to move further.
Enhanced due diligence becomes appropriate where one or more of the following is present:
- Confirmed or unresolved exposure to a Politically Exposed Person (PEP), or potential sanctions exposure
- Links to higher-risk jurisdictions or ownership structures that are complex or opaque
- A Source of Wealth narrative that cannot be corroborated through independent evidence
- Source of Funds that cannot be clearly traced to the specific transaction
- Material adverse media, litigation, or regulatory enforcement history
- Involvement of third-party funders, agents, or intermediaries whose role and remuneration are not fully documented
- Inconsistencies in the application itself, or concerns about document authenticity
None of these, individually, means an applicant should be declined. A confirmed PEP match, for instance, does not automatically require refusal; it generally warrants a closer look at Source of Wealth, Source of Funds, and connected-party exposure. A confirmed sanctions match is a different matter entirely and needs to be escalated immediately and assessed against the applicable legal framework before the application proceeds any further. Treating these as the same finding, requiring the same response, is one of the more consequential mistakes a review process can make.

Source of Wealth and Source of Funds Are Not the Same Question
One of the most common gaps in CBI due diligence files is conflating two distinct lines of enquiry. Source of Wealth asks how an applicant's total net worth was accumulated over time through employment, business ownership, dividends, inheritance, or investment returns. Source of Funds asks something narrower: where did the specific money used for this transaction come from?
An applicant can have a well-documented, entirely legitimate Source of Wealth while the funds used for the CBI investment still raise questions — for example, if they were transferred from a third party, routed through an intermediary jurisdiction, or drawn from an account with limited transaction history. Verifying one does not verify the other, and a file that treats them interchangeably has not actually closed the underlying risk question.

Why This Extends Beyond the Applicant
Applicant-level checks, however thorough, only capture part of the picture. An applicant's personal profile can present no risk indicators at all while a company they control, a business partner, or a related entity carries a sanctions listing or adverse media history. Mapping beneficial ownership, directorships, and connected parties is not an optional enhancement to CBI due diligence; it is frequently where the risk that applicant-only screening misses actually surfaces, which is why risk intelligence providers such as Cedar Rose treat network mapping as a distinct stage of the review rather than a footnote to identity verification.
A Risk-Based Process, Not a One-Time Check
The FATF/OECD report's recommendation for risk-sensitive administration applies as much to ongoing monitoring as it does to initial onboarding. An applicant approved today is not guaranteed to remain low-risk indefinitely; sanctions lists change, adverse media emerges, and corporate structures evolve. A defensible due diligence process needs a mechanism for periodic rescreening and event-driven review, not just a point-in-time decision at approval. This is the logic behind Cedar Rose's six-stage due diligence framework: Identify, Verify, Screen, Investigate, Assess, Monitor. Which treats monitoring as a continuous stage rather than an afterthought to onboarding.

Taken together, these findings point to a consistent conclusion: identity verification is the starting point for CBI due diligence, not the endpoint. A structured, risk-based process, one that knows when to move from standard checks into enhanced due diligence, and why is what allows a programme operator, financial institution, or advisory firm to make a decision it can actually defend.
Escalating to EDD is not a verdict on the applicant. It is what turns a screening result into a decision a compliance team can actually stand behind, with the reasoning documented, not just the outcome.
Conclusion
The regulatory record on Citizenship by Investment programmes is now well established. FATF and the OECD have both documented specific ways CBI and RBI schemes have been exploited, for money laundering and financial crime on one hand, and for circumventing international tax transparency standards on the other. Neither concern is resolved by identity verification and a clean database screening result. What closes the gap is a risk-based process that can distinguish a straightforward file from one that needs deeper review and that treats Source of Wealth, Source of Funds, PEP exposure, sanctions exposure, and beneficial ownership as distinct questions requiring distinct answers, not a single box to tick.
For a practical, six-stage framework covering applicant risk assessment, Source of Wealth and Source of Funds verification, and when to escalate to enhanced due diligence, see Cedar Rose's Citizenship by Investment Due Diligence Guide.
Sources & References
- FATF/OECD – Misuse of Citizenship and Residency by Investment Programmes (Joint Report, November 2023)
- OECD – Residence/Citizenship by Investment Schemes (CRS risk analysis, ongoing update)
- Surak, K. – The Misuse of Citizenship and Residence by Investment: Going Beyond the FATF/OECD Report to Assess Key Risks, LSE Department of Social Policy Working Paper 02-24 (2024)
- Cedar Rose – Citizenship by Investment Due Diligence Guide (2026)
Find Useful
Question & Answer
Check our FAQs for quick answers to frequently asked questions we receive.If you have other questions write.
What is enhanced due diligence in the context of Citizenship by Investment?
Enhanced due diligence (EDD) is a deeper level of review applied to CBI applicants whose risk profile includes indicators such as PEP or sanctions exposure, complex ownership structures, unverified Source of Wealth or Source of Funds, or material adverse media. It typically involves additional independent verification, wider reputational research, and senior or risk-committee review before a decision is made.
Why do Citizenship by Investment applicants require more due diligence than typical customers?
CBI applicants often have wealth, business interests, and personal connections.
spanning multiple jurisdictions, frequently with no prior residence or financial history in the country granting citizenship. FATF and the OECD have documented cases of CBI programmes being used to launder proceeds of crime or conceal assets, which is why identity verification alone is not considered sufficient.
What triggers enhanced due diligence for a CBI applicant?
Common triggers include confirmed or unresolved PEP or sanctions exposure, links to higher-risk jurisdictions, opaque ownership structures, an uncorroborated Source of Wealth narrative, untraceable Source of Funds, material adverse media or litigation, and undocumented third-party funders or intermediaries.
Is a PEP match treated the same as a sanctions match?
No. A confirmed PEP match does not automatically require refusal, but it generally warrants enhanced assessment of Source of Wealth, Source of Funds, and connected-party exposure. A confirmed sanctions match is materially different, it must be escalated immediately and assessed against the applicable legal and regulatory framework before the application can proceed.
What is the difference between Source of Wealth and Source of Funds?
Source of Wealth refers to how an applicant's total net worth was built over time, through employment, business activity, inheritance, or investment. Source of Funds refers specifically to where the money used for the CBI transaction itself originated. Verifying one does not verify the other.
Can a CBI applicant with no personal risk indicators still present risk?
Yes. Risk frequently surfaces through connected parties rather than the applicant directly; a company they control, a business partner, or a related entity may carry a sanctions listing or adverse media history that would not appear in an applicant-only screening check.
Does OECD guidance on CBI/RBI schemes relate to money laundering risk or tax risk?
Both, but through different mechanisms. The FATF/OECD joint report addresses money laundering and financial crime risk. Separately, the OECD's CRS risk analysis addresses how CBI/RBI documentation can be used to misrepresent an individual's tax residence, which is a distinct compliance concern for financial institutions applying CRS due diligence procedures.
