Enhanced Due Diligence (EDD)

Enhanced due diligence adds risk-based checks when ordinary customer due diligence does not adequately explain a higher-risk relationship or transaction.

Enhanced due diligence (EDD) is additional, risk-based review used when ordinary customer due diligence does not adequately explain or control a higher-risk customer, ownership structure, business relationship, or transaction. It can involve obtaining more information, corroborating it with reliable sources, securing additional approval, and applying closer ongoing monitoring.

EDD is not a universal document checklist or a finding that a customer has committed a crime. The required measures depend on the applicable law, institution, product, jurisdiction, and facts that created the higher risk.

Key Takeaways

  • EDD extends ordinary customer due diligence when identified risk is higher; it does not replace basic identity and ownership checks.
  • The purpose is to understand and manage a specific risk, not merely to collect more documents.
  • A politically exposed person (PEP), complex company, unusual payment, or geographic connection may require closer analysis, but no single label proves wrongdoing.
  • Source of funds and source of wealth answer different questions and should be verified only to the extent relevant to the risk and applicable requirements.
  • An EDD file should connect each risk factor to the evidence obtained, the conclusion reached, and any approval or monitoring response.
  • Requirements vary by jurisdiction. FATF standards influence national frameworks but are not a substitute for current local law and regulator guidance.
ControlMain questionTypical output
Know Your Customer (KYC)Who is the customer?Identity and verification records
Customer due diligence (CDD)Who owns or controls the relationship, why is it needed, and what activity is expected?Customer profile, ownership record, purpose, and risk assessment
Enhanced due diligence (EDD)What additional evidence or control is needed for the identified higher risk?Corroborated information, risk rationale, approval, and enhanced monitoring
Watch-list screeningDoes a person or entity potentially match a specified list record?Resolved match, false positive, or escalation
Transaction monitoringIs actual activity consistent with the known relationship, or does it require investigation?Alert disposition, case record, escalation, or report

These controls can overlap. For example, an ownership change discovered during ongoing monitoring may require refreshed CDD, sanctions screening, and EDD. Combining the work into one file does not make the underlying questions interchangeable.

When Enhanced Review May Be Appropriate

An institution should begin with the risk identified by its legal requirements and risk assessment. Relevant facts may include:

  • ownership that is unusually difficult to establish or explain;
  • transactions that differ materially from the stated business purpose or expected activity;
  • unexplained third-party payments, intermediaries, or rapid movement of funds;
  • products, delivery channels, or services that provide unusual anonymity or complexity;
  • connections to jurisdictions for which current official sources call for enhanced measures;
  • a foreign correspondent or private banking relationship subject to specific rules;
  • credible information that conflicts with the customer’s explanation; or
  • PEP status and associated risk factors under the applicable framework.

These are prompts for analysis, not automatic conclusions. A complex ownership structure may have a legitimate tax, financing, governance, or investment purpose. A large transaction may be ordinary for one customer and unexplained for another. EDD should test the facts that make the relationship different.

What an EDD Review Can Examine

Identity, Ownership, and Control

The reviewer may need to identify additional legal entities, beneficial owners, trustees, authorized signers, directors, intermediaries, or persons exercising control. Reliable company registries, constitutional documents, ownership charts, trust records, regulatory filings, and independently obtained information can help corroborate what the customer provides.

The goal is not simply to receive an ownership chart. The analyst should determine whether the chart is complete, internally consistent, current, and supported by evidence.

Purpose and Expected Activity

EDD can clarify why the account, investment, payment service, or other relationship is needed. Useful questions include:

  • What products or services does the customer provide?
  • Which countries and counterparties are normally involved?
  • What transaction sizes, currencies, and frequencies are expected?
  • Why are intermediaries or third parties involved?
  • How will the relationship be funded and used?

The resulting profile creates a basis for evaluating later activity. A vague statement such as “general business purposes” usually provides little monitoring value.

Source of Funds and Source of Wealth

Source of funds explains where the money used in a particular transaction or relationship came from, such as business revenue, sale proceeds, salary, or financing. Source of wealth explains how a person accumulated their broader economic resources over time.

Evidence may include audited statements, bank records, sale agreements, payroll records, tax documents, inheritance records, investment statements, or other reliable material appropriate to the facts. Possessing a document is not enough; amounts, dates, parties, and economic purpose should reconcile with the proposed activity.

Approval and Ongoing Monitoring

Higher-risk relationships may require approval at a specified level, more frequent review, narrower product access, transaction conditions, or monitoring calibrated to the expected activity. The file should state who approved the decision, what residual risk was accepted, which controls apply, and what change would trigger reassessment.

Worked Example: An Importer With New Payment Flows

A privately held importer tells its bank that it buys household equipment from three established suppliers and receives payments from domestic retailers. Its ownership records show two individual owners, and its initial activity matches that description.

Several months later, the company begins receiving large transfers from unrelated individuals. Funds are quickly sent to newly formed overseas companies that do not appear on the original supplier list. The customer says it has expanded into online sales and uses purchasing agents.

The change does not prove money laundering. It does create questions that ordinary onboarding records do not answer. A focused EDD review could:

  1. refresh company ownership, control, and authorized-person records;
  2. obtain contracts, invoices, shipping records, and marketplace statements;
  3. identify why individuals are making payments and whether they are genuine customers;
  4. identify the purchasing agents, suppliers, and ultimate payment beneficiaries;
  5. compare goods, values, dates, currencies, and shipping routes with the payment flow;
  6. screen relevant parties and resolve any alerts using reliable identifiers;
  7. determine whether the explanation is corroborated, partly supported, or contradicted; and
  8. document approval, monitoring changes, restrictions, escalation, or reporting under current rules.

The evidence might confirm a legitimate direct-to-consumer sales channel. It might instead reveal fictitious invoices, undisclosed owners, or transactions unrelated to the stated business. EDD improves the decision by testing competing explanations.

Politically Exposed Persons

A PEP is a person entrusted with a prominent public function under the relevant framework. FATF guidance treats PEP measures as preventive, not criminal, and cautions against interpreting PEP status as evidence that a person is involved in crime.

The correct analysis depends on the type of PEP, jurisdiction, role, family or close-associate relationship where applicable, other risk factors, and current legal requirements. Additional measures may include senior-management approval, reasonable steps to establish source of wealth and source of funds, and enhanced monitoring. Commercial databases can assist identification, but they do not replace customer understanding or legal analysis.

U.S. Correspondent and Private Banking Context

In the United States, Section 312 of the USA PATRIOT Act and implementing rules establish specific due-diligence requirements for certain foreign correspondent accounts and private banking accounts for non-U.S. persons. Some relationships require enhanced scrutiny based on the account and foreign-bank facts defined by the rule.

This is one jurisdiction-specific use of enhanced due diligence. It should not be generalized into a claim that every customer with a foreign connection is automatically subject to the same procedures.

How to Evaluate an EDD File

A useful review should answer:

  • Trigger: Which facts or rule required additional review?
  • Scope: Which customer, owner, party, transaction, product, or jurisdiction is being assessed?
  • Evidence: What was obtained, from whom, as of what date, and how was it corroborated?
  • Reasoning: Does the evidence support the customer’s explanation and expected activity?
  • Decision: Was the relationship approved, declined, restricted, monitored differently, or escalated?
  • Ownership: Who made and approved the decision?
  • Follow-up: What event or review date requires reassessment?

An EDD process is weak when it accumulates documents without resolving the risk question or when the conclusion cannot be traced to the evidence.

Common Mistakes

  • Treating EDD as a fixed checklist for every higher-risk relationship.
  • Assuming a PEP, nationality, industry, or jurisdiction label proves suspicious or illegal conduct.
  • Collecting source-of-funds documents without reconciling the parties, values, dates, and purpose.
  • Screening only the named customer while ignoring relevant owners, controllers, counterparties, or intermediaries.
  • Relying on adverse media, database scores, or automated alerts without validating the underlying information.
  • Repeating the same customer questions without seeking independent corroboration.
  • Approving a relationship without documenting residual risk, conditions, and monitoring.
  • Applying current list or country statements retrospectively without checking the decision date.
  • Using FATF recommendations as if they were identical to the binding law in every country.

Authoritative Sources

This article provides general financial-crime compliance education. It is not legal advice, a customer-risk determination, or a substitute for current law, regulator guidance, and an institution’s approved procedures.

FAQs

What is the difference between CDD and EDD?

CDD establishes and maintains the basic understanding of a customer, relevant ownership, purpose, and expected activity. EDD adds measures proportionate to identified higher-risk facts when ordinary CDD is not enough.

Does a high-risk rating mean a customer must be rejected?

Not automatically. The institution must follow applicable law and policy, determine whether the risk can be understood and controlled, and document its decision. Some prohibitions or unresolved risks may prevent a relationship, while others can be managed with appropriate controls.

Is EDD a one-time onboarding task?

No. Higher-risk facts can arise or change after onboarding. Ownership changes, new products, unexpected activity, updated official information, and periodic review can require refreshed due diligence.
Browse Regulation