Enhanced Due Diligence (EDD): Compliance Guide
A risk-based guide to enhanced due diligence: triggers beyond standard CDD, source of funds and wealth, approvals, ongoing monitoring, evidence, review, and governance.

Enhanced Due Diligence (EDD), in anti-money-laundering compliance, is the additional investigation and control applied when standard Customer Due Diligence (CDD) does not sufficiently manage a higher-risk relationship or transaction. Here, EDD means Enhanced Due Diligence, not expected delivery date or estimated due date.
EDD is not a second identity check and not a fixed packet of documents. It starts with a defined risk, adds measures that address that risk, records who approved the outcome, and sets the closer monitoring needed afterward. The evidence may concern the customer, beneficial owner, purpose of the relationship, source of funds, source of wealth, transaction rationale, ownership structure, geography, or another risk factor.
This guide stays with the higher-risk branch of the wider AML compliance lifecycle: when EDD begins, how to investigate proportionately, and how to keep the decision current.
Key takeaways
- EDD is enhanced CDD, not a substitute for it. Complete the baseline customer, beneficial-owner, purpose, and risk work before deciding what additional evidence is necessary.
- Higher risk is the trigger; more paperwork is not the objective. Each added measure should answer a specific risk question and lead to a defined decision.
- Source of wealth and source of funds are different. Wealth concerns how the broader body of assets was acquired; funds concern the origin of the particular assets used in the relationship or transaction.
- EDD continues after onboarding. Approval should define review events, monitoring intensity, data-refresh conditions, and ownership of later escalations.
- A higher-risk relationship is not automatically suspicious. EDD manages risk; suspicion assessment and regulatory reporting are separate governed decisions under applicable law.
What is Enhanced Due Diligence?
Enhanced Due Diligence is a risk-based extension of normal CDD. Standard CDD establishes the customer and beneficial owner, understands the purpose and intended nature of the relationship, assesses risk, and provides for ongoing scrutiny. EDD increases the depth, reliability, approval level, or monitoring applied where the identified risk requires it.
The FATF Recommendations, updated June 2026, are an international standard that jurisdictions implement through their own laws. Recommendation 10 sets the CDD baseline. Its Interpretive Note gives risk-matched examples of enhanced measures, not one universal checklist.
CDD, EDD, simplified due diligence, and investigation
| Process | When it fits | Main question | Typical output |
|---|---|---|---|
| Standard CDD | Normal customer relationship or qualifying transaction | Who is the customer, who owns or controls it, what is the purpose, and what risk is present? | Verified customer record, risk rating, decision, and monitoring plan |
| Enhanced Due Diligence | Higher risk or a specifically prescribed scenario | Which additional evidence or control is needed to manage the identified risk? | Documented enhanced review, approval, restrictions, and closer monitoring |
| Simplified due diligence | Demonstrably lower risk where law and policy permit | Which CDD measures can be reduced without losing control of the lower risk? | Proportionate reduced measures with continuing review |
| Alert investigation | A screening, transaction, or customer event requires analysis | What happened, does it concern this customer, and does it create suspicion or another policy outcome? | Closed rationale, escalation, restriction, or reporting decision |
EDD should not repair incomplete standard CDD. If the beneficial owner or purpose remains unknown, complete the baseline requirement before deciding what to enhance.
Preserve the line between risk and suspicion. Complexity, political exposure, wealth, or geography can justify scrutiny without proving wrongdoing. Information discovered during EDD may separately create grounds for suspicion and trigger reporting and confidentiality duties.
What do FATF Recommendations 10, 12, and 22 expect?
Recommendation 10: risk-based CDD and ongoing scrutiny
FATF Recommendation 10 requires financial institutions to identify and verify the customer, identify and take reasonable measures to verify the beneficial owner, understand the purpose and intended nature of the relationship, and conduct ongoing due diligence and transaction scrutiny.
Its Interpretive Note describes enhanced measures for higher-risk relationships. Examples include:
- additional information about the customer and more frequent updates;
- more information about the intended nature of the relationship;
- information on source of funds or source of wealth;
- the reasons for intended or completed transactions;
- senior-management approval to begin or continue the relationship;
- enhanced monitoring through more or differently timed controls; and
- in an appropriate case, a first payment through an account in the customer’s name at a bank subject to similar CDD standards.
These examples should be matched to risk, not applied to every case. The same text calls for examining the background and purpose of complex or unusually large transactions and unusual patterns with no apparent economic or lawful purpose.
Recommendation 12: politically exposed persons
FATF Recommendation 12 adds measures for politically exposed persons, or PEPs. For foreign PEPs, whether the PEP is the customer or beneficial owner, it calls for systems to determine PEP status, senior-management approval, reasonable measures to establish source of wealth and source of funds, and enhanced ongoing monitoring.
For domestic PEPs and people entrusted with a prominent function by an international organization, FATF applies those additional measures when the business relationship is higher risk. The requirements also extend to family members and close associates. FATF emphasizes that these are preventive measures: PEP status does not mean the person is involved in criminal activity.
Recommendation 22: relevant non-financial businesses
Recommendation 22 applies CDD, recordkeeping, PEP, new-technology, and third-party-reliance requirements to designated non-financial businesses and professions in specified activities, including parts of the casino, real-estate, precious-metals, legal, accounting, and trust or company-service sectors. EDD is therefore not only a banking workflow, but its trigger and scope still require local legal mapping.
The EU position: current directive and incoming regulation
At EU level, Directive (EU) 2015/849, as amended and implemented in Member State law, currently provides the common framework. Article 18 requires Member States to require enhanced customer due diligence in specified cases and other higher-risk situations identified by Member States or obliged entities. It also requires examination of the background and purpose of complex and unusually large transactions and unusual patterns without an apparent economic or lawful purpose.
The Directive’s Annex III provides non-exhaustive higher-risk factors across customers, products or delivery channels, and geography. Article 20 requires PEP risk-management systems, senior-management approval, adequate source-of-wealth and source-of-funds measures, and enhanced ongoing monitoring. National transposition and sector rules determine the operative duties for a particular organization.
Regulation (EU) 2024/1624 will generally apply directly from 10 July 2027, with a later date for limited categories. Article 34 lists proportionate EDD measures, and Article 42 addresses PEPs. Until then, teams should map current national requirements and separately prepare for the Regulation.
When does EDD trigger?
There is no reliable universal rule that “one red flag equals EDD.” A defensible trigger combines applicable mandatory cases with the organization’s documented risk assessment.
Customer and beneficial-owner risk
EDD may be appropriate where ownership or control is unusually complex for the stated business, customer or beneficial-owner information is inconsistent, the relationship involves a PEP under the applicable framework, or evidence cannot explain the profile. Complexity alone is not misconduct; establish its reason, owners, controllers, and decision-makers.
Product, service, and delivery-channel risk
Products that favor anonymity, unusually complex services, certain private-banking relationships, unrelated third-party payments, or remote delivery without suitable safeguards can increase risk. Remote onboarding is not automatically inadequate; assurance depends on its evidence, capture controls, fraud defenses, and exceptions.
Geography and cross-border exposure
Applicable lists, regulatory notices, sanctions, corruption exposure, terrorist-financing risk, weak AML controls, and the role of a geography can affect risk. Nationality is not a conclusion; residence, incorporation, operations, counterparties, and payment paths can mean different things.
Transaction and behavioral risk
Unusually large or complex activity, unusual patterns, unexplained third-party payments, or divergence from expected activity or known funds can trigger EDD or investigation. Interpret each event against customer context.
Legally specified scenarios
PEPs, certain correspondent relationships, designated higher-risk countries, and sector-specific situations can carry prescribed measures. The organization’s policy should distinguish:
- mandatory legal or regulatory cases;
- risk-model triggers that require EDD;
- event-driven triggers that reopen an existing record; and
- indicators that require immediate suspicion assessment rather than a routine document request.
Source of funds and source of wealth
Source of funds and source of wealth are related but answer different questions. FATF’s PEP guidance describes source of wealth as the origin of the person’s overall body of wealth and source of funds as the origin of the particular funds or assets involved in the relationship.
| Question | Source of funds | Source of wealth |
|---|---|---|
| Scope | The specific money or asset being deposited, invested, transferred, or used | The broader assets the customer or beneficial owner has accumulated |
| What to understand | How this asset was acquired and how it reached the transaction | How the person built or obtained the overall wealth |
| Possible evidence | Account history, sale completion, loan agreement, distribution, payroll, inheritance, or business receipt | Employment or business history, ownership records, financial statements, asset sale history, inheritance, or investment history |
| Consistency test | Does the amount, origin, route, timing, and purpose fit the explanation? | Does the scale and composition of wealth fit the person’s known history and credible sources? |
Evidence depends on the explanation. Salary, a company sale, inheritance, property disposal, investment return, loan, and business distribution create different chains. A bank statement may show the last transfer but not how funds were acquired.
A useful assessment separates five elements:
- Origin: what economic event created the money or asset?
- Ownership: who legally and beneficially owned it?
- Path: how did it move from origin to the current account or transaction?
- Purpose: why is it entering this relationship now?
- Consistency: does the explanation fit amounts, dates, customer history, business activity, and independent evidence?
Declarations can be necessary where public data is limited, but their weight depends on corroboration and consistency. The objective is a reasonable, documented understanding proportionate to risk.
A risk-based EDD workflow
1. Record the trigger
Capture the factor, source, date, and policy rule that opened EDD. “High risk” is not enough; name the ownership, geography, political, product, transaction, funds, wealth, or data concern.
2. Confirm baseline CDD
Verify that customer and beneficial-owner identification, purpose, expected activity, and screening are complete. Separate baseline gaps from enhanced questions.
3. Write the risk hypothesis
Translate the trigger into an answerable question. “Can the beneficial owner and commercial reason for this structure be established?” is more useful than “request corporate documents.”
4. Choose proportionate measures
Map each request, query, interview, approval, restriction, or monitoring change to the hypothesis. Define sufficient evidence, escalation conditions, and acceptable uncertainty.
5. Establish provenance and consistency
Check issuer, date, parties, ownership, completeness, and customer linkage. Compare declarations with reliable, lawful sources where available. A genuine document can still concern the wrong party.
6. Assess source of funds and wealth where relevant
Build the funds origin and path separately from the wealth narrative. Reconcile amounts, dates, counterparties, and profile; distinguish corroborated facts from declarations.
7. Decide through the correct authority
Use the approval level required by law and policy. Outcomes can include approval, restrictions, more evidence, monitoring, decline, exit, or suspicion review. Preserve reasons.
8. Set the ongoing review plan
Define monitoring intensity, review events, refresh conditions, owners, and the expected profile. A higher-risk approval without follow-up is incomplete.
9. Preserve an auditable record
Keep the trigger, policy version, evidence provenance, analysis, approvals, restrictions, monitoring plan, and changes. Record why evidence was accepted.
Ongoing EDD and event-driven review
EDD is not finished when onboarding is approved. FATF Recommendation 10 requires ongoing scrutiny and up-to-date, relevant CDD information, particularly for higher-risk categories. Closer monitoring should be defined by what risk is being watched.
An ongoing plan can combine:
- transaction patterns compared with stated purpose and expected activity;
- screening changes involving the customer, beneficial owner, controllers, or related parties;
- ownership, directorship, address, occupation, or business-model changes;
- document or evidence expiry;
- new products, counterparties, corridors, devices, or payment paths;
- material divergence from established source-of-funds or source-of-wealth information; and
- scheduled review where an event alone may not capture slow change.
There is no universal review interval. Cadence should follow applicable rules and risk; event-driven controls supplement required periodic review. Keep changed records, unusual transactions, alerts, cases, EDD refreshes, and suspicion decisions as separate states.
How to evaluate an EDD operating model
Trigger quality
Sample cases at each threshold. Check whether factors are explainable and linked to policy action. Review overrides and downstream findings.
Evidence quality
Test whether evidence answers the question, shows provenance, and distinguishes declaration from corroboration. More files do not necessarily strengthen the conclusion.
Decision consistency
Compare outcomes and reasons for equivalent cases. Use escalation, peer review, or quality assurance for material inconsistency.
Monitoring connection
Confirm that expected activity, ownership, restrictions, funds context, and review conditions reach screening and monitoring operations.
Governance
Assign owners for policy, sources, workflow, approval, monitoring, quality, reporting, retention, and redress. Test the full path from trigger to later event.
Common EDD mistakes
Treating EDD as a document pile
Collecting every available file increases privacy and review burden without guaranteeing that the identified risk was answered. Request evidence against a written hypothesis.
Using the same EDD for every risk
A PEP, opaque ownership chain, unusual payment, and higher-risk corridor raise different questions. They may share controls, but they should not automatically share one undifferentiated checklist.
Confusing the sending bank with source of funds
The account that sent money shows part of the path. It does not necessarily explain the economic event through which the customer acquired the money.
Auto-declining higher-risk customers
Higher risk justifies proportionate enhanced measures. It is not itself proof of criminality. Where risk cannot be understood or mitigated, document that reason and follow applicable law.
Approving without changing monitoring
If EDD identifies a meaningful risk but the relationship receives the same controls and review as a lower-risk customer, the enhanced analysis has not been operationalized.
Letting a provider make the legal conclusion
Technology can retrieve data, screen subjects, orchestrate requests, and surface alerts. The obliged organization remains responsible for triggers, sufficiency, approvals, suspicion, reporting, and records.
Using Didit in an EDD workflow
Didit lists AML Screening, Business Verification, and Transaction Monitoring alongside a free Workflow Orchestrator. Canonical rates are $0.20 per AML screening, from $2.00 per business verification, and $0.02 per transaction.
Current module rates are on the pricing page. Those canonical facts do not establish which evidence, triggers, sources, or review decisions a particular EDD policy requires. Confirm current product fields and behavior against product documentation; the obliged organization remains responsible for legal scope, evidence sufficiency, approvals, suspicion, reporting, and records.
Frequently asked questions
What does EDD mean in compliance?
EDD means Enhanced Due Diligence: additional evidence, approval, control, or monitoring applied when normal CDD is insufficient for a higher-risk relationship or transaction. In this context it does not mean expected delivery date or estimated due date.
What is the difference between CDD and EDD?
CDD is the baseline process for identifying the customer and beneficial owner, understanding the relationship, assessing risk, and monitoring it. EDD extends that process with measures proportionate to a specific higher risk.
What triggers Enhanced Due Diligence?
Triggers can include legally specified situations and higher risk identified through customer, ownership, product, delivery-channel, geography, transaction, or behavioral factors. The exact trigger and required measures depend on jurisdiction, sector, and policy.
Is a PEP always subject to EDD?
FATF requires additional measures for foreign PEPs and for higher-risk relationships with domestic or international-organization PEPs. EU rules prescribe additional PEP measures. Organizations must apply the relevant local definition and requirements, including the treatment of family members and close associates.
What is the difference between source of funds and source of wealth?
Source of funds concerns how the particular money or asset involved was acquired and reached the transaction. Source of wealth concerns how the customer or beneficial owner accumulated the broader body of wealth.
How often should an EDD customer be reviewed?
There is no universal interval. Review frequency and events should reflect applicable law, customer risk, product, ownership, activity, and the specific uncertainty or exposure identified during EDD.
Does EDD mean the customer is suspicious?
No. EDD is a preventive response to higher risk. If evidence creates suspicion or reasonable grounds for suspicion, the organization follows its separate investigation, reporting, and confidentiality duties.
Primary references
- FATF Recommendations, updated June 2026 — Recommendations 10, 12, and 22 and their Interpretive Notes
- FATF Guidance on Politically Exposed Persons — Recommendations 12 and 22
- Directive (EU) 2015/849 — current EU AML directive framework
- Regulation (EU) 2024/1624 — AML Regulation applying generally from 10 July 2027
EDD works when the organization can trace every additional measure to a risk, every conclusion to evidence, and every approval to an ongoing control. The goal is not maximum friction. It is a proportionate, reviewable understanding of a higher-risk relationship.