Skip to main content
Didit Raises $7.5M to Build the Infrastructure for Identity and Fraud
Didit
Back to blog
Blog · July 28, 2026

Enhanced Due Diligence (EDD): Compliance Guide

A risk-based guide to enhanced due diligence: triggers beyond standard CDD, source of funds and wealth, approvals, ongoing monitoring, evidence, review, and governance.

By DiditUpdated
enhanced-due-diligence-edd-compliance-guide.png

Enhanced Due Diligence (EDD), in anti-money-laundering compliance, is the additional investigation and control applied when standard Customer Due Diligence (CDD) does not sufficiently manage a higher-risk relationship or transaction. Here, EDD means Enhanced Due Diligence, not expected delivery date or estimated due date.

EDD is not a second identity check and not a fixed packet of documents. It starts with a defined risk, adds measures that address that risk, records who approved the outcome, and sets the closer monitoring needed afterward. The evidence may concern the customer, beneficial owner, purpose of the relationship, source of funds, source of wealth, transaction rationale, ownership structure, geography, or another risk factor.

This guide stays with the higher-risk branch of the wider AML compliance lifecycle: when EDD begins, how to investigate proportionately, and how to keep the decision current.

Key takeaways

  • EDD is enhanced CDD, not a substitute for it. Complete the baseline customer, beneficial-owner, purpose, and risk work before deciding what additional evidence is necessary.
  • Higher risk is the trigger; more paperwork is not the objective. Each added measure should answer a specific risk question and lead to a defined decision.
  • Source of wealth and source of funds are different. Wealth concerns how the broader body of assets was acquired; funds concern the origin of the particular assets used in the relationship or transaction.
  • EDD continues after onboarding. Approval should define review events, monitoring intensity, data-refresh conditions, and ownership of later escalations.
  • A higher-risk relationship is not automatically suspicious. EDD manages risk; suspicion assessment and regulatory reporting are separate governed decisions under applicable law.

What is Enhanced Due Diligence?

Enhanced Due Diligence is a risk-based extension of normal CDD. Standard CDD establishes the customer and beneficial owner, understands the purpose and intended nature of the relationship, assesses risk, and provides for ongoing scrutiny. EDD increases the depth, reliability, approval level, or monitoring applied where the identified risk requires it.

The FATF Recommendations, updated June 2026, are an international standard that jurisdictions implement through their own laws. Recommendation 10 sets the CDD baseline. Its Interpretive Note gives risk-matched examples of enhanced measures, not one universal checklist.

CDD, EDD, simplified due diligence, and investigation

ProcessWhen it fitsMain questionTypical output
Standard CDDNormal customer relationship or qualifying transactionWho is the customer, who owns or controls it, what is the purpose, and what risk is present?Verified customer record, risk rating, decision, and monitoring plan
Enhanced Due DiligenceHigher risk or a specifically prescribed scenarioWhich additional evidence or control is needed to manage the identified risk?Documented enhanced review, approval, restrictions, and closer monitoring
Simplified due diligenceDemonstrably lower risk where law and policy permitWhich CDD measures can be reduced without losing control of the lower risk?Proportionate reduced measures with continuing review
Alert investigationA screening, transaction, or customer event requires analysisWhat happened, does it concern this customer, and does it create suspicion or another policy outcome?Closed rationale, escalation, restriction, or reporting decision

EDD should not repair incomplete standard CDD. If the beneficial owner or purpose remains unknown, complete the baseline requirement before deciding what to enhance.

Preserve the line between risk and suspicion. Complexity, political exposure, wealth, or geography can justify scrutiny without proving wrongdoing. Information discovered during EDD may separately create grounds for suspicion and trigger reporting and confidentiality duties.

What do FATF Recommendations 10, 12, and 22 expect?

Recommendation 10: risk-based CDD and ongoing scrutiny

FATF Recommendation 10 requires financial institutions to identify and verify the customer, identify and take reasonable measures to verify the beneficial owner, understand the purpose and intended nature of the relationship, and conduct ongoing due diligence and transaction scrutiny.

Its Interpretive Note describes enhanced measures for higher-risk relationships. Examples include:

  • additional information about the customer and more frequent updates;
  • more information about the intended nature of the relationship;
  • information on source of funds or source of wealth;
  • the reasons for intended or completed transactions;
  • senior-management approval to begin or continue the relationship;
  • enhanced monitoring through more or differently timed controls; and
  • in an appropriate case, a first payment through an account in the customer’s name at a bank subject to similar CDD standards.

These examples should be matched to risk, not applied to every case. The same text calls for examining the background and purpose of complex or unusually large transactions and unusual patterns with no apparent economic or lawful purpose.

Recommendation 12: politically exposed persons

FATF Recommendation 12 adds measures for politically exposed persons, or PEPs. For foreign PEPs, whether the PEP is the customer or beneficial owner, it calls for systems to determine PEP status, senior-management approval, reasonable measures to establish source of wealth and source of funds, and enhanced ongoing monitoring.

For domestic PEPs and people entrusted with a prominent function by an international organization, FATF applies those additional measures when the business relationship is higher risk. The requirements also extend to family members and close associates. FATF emphasizes that these are preventive measures: PEP status does not mean the person is involved in criminal activity.

Recommendation 22: relevant non-financial businesses

Recommendation 22 applies CDD, recordkeeping, PEP, new-technology, and third-party-reliance requirements to designated non-financial businesses and professions in specified activities, including parts of the casino, real-estate, precious-metals, legal, accounting, and trust or company-service sectors. EDD is therefore not only a banking workflow, but its trigger and scope still require local legal mapping.

The EU position: current directive and incoming regulation

At EU level, Directive (EU) 2015/849, as amended and implemented in Member State law, currently provides the common framework. Article 18 requires Member States to require enhanced customer due diligence in specified cases and other higher-risk situations identified by Member States or obliged entities. It also requires examination of the background and purpose of complex and unusually large transactions and unusual patterns without an apparent economic or lawful purpose.

The Directive’s Annex III provides non-exhaustive higher-risk factors across customers, products or delivery channels, and geography. Article 20 requires PEP risk-management systems, senior-management approval, adequate source-of-wealth and source-of-funds measures, and enhanced ongoing monitoring. National transposition and sector rules determine the operative duties for a particular organization.

Regulation (EU) 2024/1624 will generally apply directly from 10 July 2027, with a later date for limited categories. Article 34 lists proportionate EDD measures, and Article 42 addresses PEPs. Until then, teams should map current national requirements and separately prepare for the Regulation.

When does EDD trigger?

There is no reliable universal rule that “one red flag equals EDD.” A defensible trigger combines applicable mandatory cases with the organization’s documented risk assessment.

Customer and beneficial-owner risk

EDD may be appropriate where ownership or control is unusually complex for the stated business, customer or beneficial-owner information is inconsistent, the relationship involves a PEP under the applicable framework, or evidence cannot explain the profile. Complexity alone is not misconduct; establish its reason, owners, controllers, and decision-makers.

Product, service, and delivery-channel risk

Products that favor anonymity, unusually complex services, certain private-banking relationships, unrelated third-party payments, or remote delivery without suitable safeguards can increase risk. Remote onboarding is not automatically inadequate; assurance depends on its evidence, capture controls, fraud defenses, and exceptions.

Geography and cross-border exposure

Applicable lists, regulatory notices, sanctions, corruption exposure, terrorist-financing risk, weak AML controls, and the role of a geography can affect risk. Nationality is not a conclusion; residence, incorporation, operations, counterparties, and payment paths can mean different things.

Transaction and behavioral risk

Unusually large or complex activity, unusual patterns, unexplained third-party payments, or divergence from expected activity or known funds can trigger EDD or investigation. Interpret each event against customer context.

Legally specified scenarios

PEPs, certain correspondent relationships, designated higher-risk countries, and sector-specific situations can carry prescribed measures. The organization’s policy should distinguish:

  1. mandatory legal or regulatory cases;
  2. risk-model triggers that require EDD;
  3. event-driven triggers that reopen an existing record; and
  4. indicators that require immediate suspicion assessment rather than a routine document request.

Source of funds and source of wealth

Source of funds and source of wealth are related but answer different questions. FATF’s PEP guidance describes source of wealth as the origin of the person’s overall body of wealth and source of funds as the origin of the particular funds or assets involved in the relationship.

QuestionSource of fundsSource of wealth
ScopeThe specific money or asset being deposited, invested, transferred, or usedThe broader assets the customer or beneficial owner has accumulated
What to understandHow this asset was acquired and how it reached the transactionHow the person built or obtained the overall wealth
Possible evidenceAccount history, sale completion, loan agreement, distribution, payroll, inheritance, or business receiptEmployment or business history, ownership records, financial statements, asset sale history, inheritance, or investment history
Consistency testDoes the amount, origin, route, timing, and purpose fit the explanation?Does the scale and composition of wealth fit the person’s known history and credible sources?

Evidence depends on the explanation. Salary, a company sale, inheritance, property disposal, investment return, loan, and business distribution create different chains. A bank statement may show the last transfer but not how funds were acquired.

A useful assessment separates five elements:

  1. Origin: what economic event created the money or asset?
  2. Ownership: who legally and beneficially owned it?
  3. Path: how did it move from origin to the current account or transaction?
  4. Purpose: why is it entering this relationship now?
  5. Consistency: does the explanation fit amounts, dates, customer history, business activity, and independent evidence?

Declarations can be necessary where public data is limited, but their weight depends on corroboration and consistency. The objective is a reasonable, documented understanding proportionate to risk.

A risk-based EDD workflow

1. Record the trigger

Capture the factor, source, date, and policy rule that opened EDD. “High risk” is not enough; name the ownership, geography, political, product, transaction, funds, wealth, or data concern.

2. Confirm baseline CDD

Verify that customer and beneficial-owner identification, purpose, expected activity, and screening are complete. Separate baseline gaps from enhanced questions.

3. Write the risk hypothesis

Translate the trigger into an answerable question. “Can the beneficial owner and commercial reason for this structure be established?” is more useful than “request corporate documents.”

4. Choose proportionate measures

Map each request, query, interview, approval, restriction, or monitoring change to the hypothesis. Define sufficient evidence, escalation conditions, and acceptable uncertainty.

5. Establish provenance and consistency

Check issuer, date, parties, ownership, completeness, and customer linkage. Compare declarations with reliable, lawful sources where available. A genuine document can still concern the wrong party.

6. Assess source of funds and wealth where relevant

Build the funds origin and path separately from the wealth narrative. Reconcile amounts, dates, counterparties, and profile; distinguish corroborated facts from declarations.

7. Decide through the correct authority

Use the approval level required by law and policy. Outcomes can include approval, restrictions, more evidence, monitoring, decline, exit, or suspicion review. Preserve reasons.

8. Set the ongoing review plan

Define monitoring intensity, review events, refresh conditions, owners, and the expected profile. A higher-risk approval without follow-up is incomplete.

9. Preserve an auditable record

Keep the trigger, policy version, evidence provenance, analysis, approvals, restrictions, monitoring plan, and changes. Record why evidence was accepted.

Ongoing EDD and event-driven review

EDD is not finished when onboarding is approved. FATF Recommendation 10 requires ongoing scrutiny and up-to-date, relevant CDD information, particularly for higher-risk categories. Closer monitoring should be defined by what risk is being watched.

An ongoing plan can combine:

  • transaction patterns compared with stated purpose and expected activity;
  • screening changes involving the customer, beneficial owner, controllers, or related parties;
  • ownership, directorship, address, occupation, or business-model changes;
  • document or evidence expiry;
  • new products, counterparties, corridors, devices, or payment paths;
  • material divergence from established source-of-funds or source-of-wealth information; and
  • scheduled review where an event alone may not capture slow change.

There is no universal review interval. Cadence should follow applicable rules and risk; event-driven controls supplement required periodic review. Keep changed records, unusual transactions, alerts, cases, EDD refreshes, and suspicion decisions as separate states.

How to evaluate an EDD operating model

Trigger quality

Sample cases at each threshold. Check whether factors are explainable and linked to policy action. Review overrides and downstream findings.

Evidence quality

Test whether evidence answers the question, shows provenance, and distinguishes declaration from corroboration. More files do not necessarily strengthen the conclusion.

Decision consistency

Compare outcomes and reasons for equivalent cases. Use escalation, peer review, or quality assurance for material inconsistency.

Monitoring connection

Confirm that expected activity, ownership, restrictions, funds context, and review conditions reach screening and monitoring operations.

Governance

Assign owners for policy, sources, workflow, approval, monitoring, quality, reporting, retention, and redress. Test the full path from trigger to later event.

Common EDD mistakes

Treating EDD as a document pile

Collecting every available file increases privacy and review burden without guaranteeing that the identified risk was answered. Request evidence against a written hypothesis.

Using the same EDD for every risk

A PEP, opaque ownership chain, unusual payment, and higher-risk corridor raise different questions. They may share controls, but they should not automatically share one undifferentiated checklist.

Confusing the sending bank with source of funds

The account that sent money shows part of the path. It does not necessarily explain the economic event through which the customer acquired the money.

Auto-declining higher-risk customers

Higher risk justifies proportionate enhanced measures. It is not itself proof of criminality. Where risk cannot be understood or mitigated, document that reason and follow applicable law.

Approving without changing monitoring

If EDD identifies a meaningful risk but the relationship receives the same controls and review as a lower-risk customer, the enhanced analysis has not been operationalized.

Letting a provider make the legal conclusion

Technology can retrieve data, screen subjects, orchestrate requests, and surface alerts. The obliged organization remains responsible for triggers, sufficiency, approvals, suspicion, reporting, and records.

Using Didit in an EDD workflow

Didit lists AML Screening, Business Verification, and Transaction Monitoring alongside a free Workflow Orchestrator. Canonical rates are $0.20 per AML screening, from $2.00 per business verification, and $0.02 per transaction.

Current module rates are on the pricing page. Those canonical facts do not establish which evidence, triggers, sources, or review decisions a particular EDD policy requires. Confirm current product fields and behavior against product documentation; the obliged organization remains responsible for legal scope, evidence sufficiency, approvals, suspicion, reporting, and records.

Frequently asked questions

What does EDD mean in compliance?

EDD means Enhanced Due Diligence: additional evidence, approval, control, or monitoring applied when normal CDD is insufficient for a higher-risk relationship or transaction. In this context it does not mean expected delivery date or estimated due date.

What is the difference between CDD and EDD?

CDD is the baseline process for identifying the customer and beneficial owner, understanding the relationship, assessing risk, and monitoring it. EDD extends that process with measures proportionate to a specific higher risk.

What triggers Enhanced Due Diligence?

Triggers can include legally specified situations and higher risk identified through customer, ownership, product, delivery-channel, geography, transaction, or behavioral factors. The exact trigger and required measures depend on jurisdiction, sector, and policy.

Is a PEP always subject to EDD?

FATF requires additional measures for foreign PEPs and for higher-risk relationships with domestic or international-organization PEPs. EU rules prescribe additional PEP measures. Organizations must apply the relevant local definition and requirements, including the treatment of family members and close associates.

What is the difference between source of funds and source of wealth?

Source of funds concerns how the particular money or asset involved was acquired and reached the transaction. Source of wealth concerns how the customer or beneficial owner accumulated the broader body of wealth.

How often should an EDD customer be reviewed?

There is no universal interval. Review frequency and events should reflect applicable law, customer risk, product, ownership, activity, and the specific uncertainty or exposure identified during EDD.

Does EDD mean the customer is suspicious?

No. EDD is a preventive response to higher risk. If evidence creates suspicion or reasonable grounds for suspicion, the organization follows its separate investigation, reporting, and confidentiality duties.

Primary references

EDD works when the organization can trace every additional measure to a risk, every conclusion to evidence, and every approval to an ongoing control. The goal is not maximum friction. It is a proportionate, reviewable understanding of a higher-risk relationship.

Infrastructure for identity and fraud.

One API for KYC, KYB, Transaction Monitoring, and Wallet Screening. Integrate in 5 minutes.

Ask an AI to summarise this page