Blogs

Enhanced Due Diligence: A Key Step in CBI Applications

Written by Cedar Rose | Sep 1, 2026, 5:30:00 AM

 

 

In November 2023, FATF and the OECD published a joint report describing the criminal exploitation of citizenship and residency investment programmes as a multi-billion-dollar business used to launder the proceeds of fraud and corruption, evade justice, or gain access to third countries. The same report called on governments and programme operators to apply a variety of safeguards to ensure these programmes are administered in a risk-sensitive way, including stronger due diligence and transparency mechanisms.

That finding matters well beyond the governments that run Citizenship by Investment (CBI) programmes. It is a direct signal to every financial institution, legal firm, and advisory practice that touches a CBI application: the population of applicants carries risk characteristics that a standard identity check was never designed to catch.

What Makes CBI Applicant Risk Different

A typical retail or corporate customer has a domestic financial footprint: local employment history, a bank relationship, a credit file, and a residential address that can be independently corroborated. A CBI applicant frequently has none of this in the jurisdiction granting citizenship, by design. Their wealth, business interests, and personal connections often span several jurisdictions, and the depth of publicly available record-keeping on those interests varies enormously depending on where the applicant has lived, worked, and invested.

Separate academic research examining the FATF/OECD findings has noted that investigative journalists have exposed major cases of criminals in possession of citizenship gained through CBI programmes who have carried out billions of dollars in financial crimes. The pattern in these cases is rarely a failed identity check. It is a wealth narrative that was never independently corroborated, a source of funds that was never traced beyond the immediate transaction, or a corporate or family connection that never surfaced through applicant-level screening alone.

This is the core distinction that should inform how CBI due diligence is structured: identity verification confirms whom someone claims to be. It says nothing about how their wealth was built, whether the specific funds involved are legitimately sourced, or whom they are connected to.


 

The Regulatory Signal on CRS and Tax Transparency

The FATF/OECD report addresses financial crime risk directly, but a related and separate concern has been building on the tax transparency side. The OECD has published an analysis of over 100 CBI/RBI schemes and identified a number of programmes it considers to potentially pose a high risk to the integrity of the OECD's Common Reporting Standard (CRS), the international framework financial institutions rely on to correctly identify a customer's tax residence. Identity cards and other documentation obtained through CBI/RBI schemes can potentially be misused to misrepresent an individual's jurisdiction of tax residence, undermining the due diligence procedures financial institutions are required to follow under the CRS.

The practical implication for anyone conducting CBI due diligence is that a clean identity document and a clean database screening result are not, on their own, sufficient evidence that an applicant's declared profile is accurate. Where an applicant's citizenship or residence documentation originates from a CBI/RBI scheme, that context is itself relevant to the wider risk assessment. Not because the programme is inherently improper, but because it is a documented avenue for misrepresentation that regulators have specifically flagged.

 

From Standard Checks to Enhanced Due Diligence

Customer due diligence (CDD); identity verification, basic screening, and a documented risk assessment- remains the correct starting points for every applicant. The question a compliance or risk team needs to answer is not whether to apply CDD, but whether the findings from that initial review indicate the file needs to move further.

Enhanced due diligence becomes appropriate where one or more of the following is present:

  • Confirmed or unresolved exposure to a Politically Exposed Person (PEP), or potential sanctions exposure
  • Links to higher-risk jurisdictions or ownership structures that are complex or opaque
  • A Source of Wealth narrative that cannot be corroborated through independent evidence
  • Source of Funds that cannot be clearly traced to the specific transaction
  • Material adverse media, litigation, or regulatory enforcement history
  • Involvement of third-party funders, agents, or intermediaries whose role and remuneration are not fully documented
  • Inconsistencies in the application itself, or concerns about document authenticity

None of these, individually, means an applicant should be declined. A confirmed PEP match, for instance, does not automatically require refusal; it generally warrants a closer look at Source of Wealth, Source of Funds, and connected-party exposure. A confirmed sanctions match is a different matter entirely and needs to be escalated immediately and assessed against the applicable legal framework before the application proceeds any further. Treating these as the same finding, requiring the same response, is one of the more consequential mistakes a review process can make.


Source of Wealth and Source of Funds Are Not the Same Question

One of the most common gaps in CBI due diligence files is conflating two distinct lines of enquiry. Source of Wealth asks how an applicant's total net worth was accumulated over time through employment, business ownership, dividends, inheritance, or investment returns. Source of Funds asks something narrower: where did the specific money used for this transaction come from?

An applicant can have a well-documented, entirely legitimate Source of Wealth while the funds used for the CBI investment still raise questions — for example, if they were transferred from a third party, routed through an intermediary jurisdiction, or drawn from an account with limited transaction history. Verifying one does not verify the other, and a file that treats them interchangeably has not actually closed the underlying risk question.


Why This Extends Beyond the Applicant

Applicant-level checks, however thorough, only capture part of the picture. An applicant's personal profile can present no risk indicators at all while a company they control, a business partner, or a related entity carries a sanctions listing or adverse media history. Mapping beneficial ownership, directorships, and connected parties is not an optional enhancement to CBI due diligence; it is frequently where the risk that applicant-only screening misses actually surfaces, which is why risk intelligence providers such as Cedar Rose treat network mapping as a distinct stage of the review rather than a footnote to identity verification.

A Risk-Based Process, Not a One-Time Check

The FATF/OECD report's recommendation for risk-sensitive administration applies as much to ongoing monitoring as it does to initial onboarding. An applicant approved today is not guaranteed to remain low-risk indefinitely; sanctions lists change, adverse media emerges, and corporate structures evolve. A defensible due diligence process needs a mechanism for periodic rescreening and event-driven review, not just a point-in-time decision at approval. This is the logic behind Cedar Rose's six-stage due diligence framework: Identify, Verify, Screen, Investigate, Assess, Monitor. Which treats monitoring as a continuous stage rather than an afterthought to onboarding.


Taken together, these findings point to a consistent conclusion: identity verification is the starting point for CBI due diligence, not the endpoint. A structured, risk-based process, one that knows when to move from standard checks into enhanced due diligence, and why is what allows a programme operator, financial institution, or advisory firm to make a decision it can actually defend.

Conclusion

The regulatory record on Citizenship by Investment programmes is now well established. FATF and the OECD have both documented specific ways CBI and RBI schemes have been exploited, for money laundering and financial crime on one hand, and for circumventing international tax transparency standards on the other. Neither concern is resolved by identity verification and a clean database screening result. What closes the gap is a risk-based process that can distinguish a straightforward file from one that needs deeper review and that treats Source of Wealth, Source of Funds, PEP exposure, sanctions exposure, and beneficial ownership as distinct questions requiring distinct answers, not a single box to tick.

For a practical, six-stage framework covering applicant risk assessment, Source of Wealth and Source of Funds verification, and when to escalate to enhanced due diligence, see Cedar Rose's Citizenship by Investment Due Diligence Guide.

Sources & References