Customer Due Diligence & Enhanced Due Diligence: Key Differences

18 September 2026 | Industry Intel

Customer due diligence (CDD) and enhanced due diligence (EDD) are the two core tiers of scrutiny that regulated institutions apply to customer relationships: one as the default, and the other as the obligation when risk crosses a defined threshold.

The FCA’s April 2026 multi-firm review of CDD and EDD controls found that across supervised firms, key weaknesses included failing to evidence what EDD measures had been taken and limited demonstration of how controls differed between low- and high-risk customers.

This guide covers what each process requires, what triggers the move from standard to enhanced scrutiny, and where programs most often get the boundary wrong.

Key takeaways:

  • CDD and EDD produce structurally different files
    A CDD file is a risk profile. An EDD file is an investigation record. Regulators assess them against different evidentiary standards, and the distinction matters at examination.
  • EDD triggers are set by regulation, not institutional judgment
    PEPs, high-risk jurisdictions, complex ownership structures, correspondent banking, and unusual transactions each carry mandatory escalation requirements across FATF, FinCEN, FCA, and the AMLR.
  • Most due diligence failures happen at the boundary between the two tiers
    The most common errors are misclassifying the risk level, documenting outcomes without documenting reasoning, and treating source of funds as equivalent to source of wealth.
  • A customer’s risk level can cross the EDD threshold after onboarding
    Mid-relationship changes can push a standard-CDD file into EDD territory. Programs built around periodic review cycles are structurally exposed to this.
  • Sigma360 handles the full CDD-to-EDD journey in a single environment
    From initial screening through to EDD investigation, Sigma360 removes the data-gathering and handoff problems that cause most programs to apply the two tiers inconsistently.

What customer due diligence and enhanced due diligence each require

CDD and EDD differ in what they are designed to produce, not just in how much work they involve.

Customer due diligence establishes who a customer is, what they do, and what level of risk they represent. Under FATF Recommendation 10 and the FinCEN Customer Due Diligence Rule, every regulated institution must collect and verify customer identity, identify the beneficial owners of legal entities, document the purpose and nature of the business relationship, and monitor transactions on an ongoing basis. CDD applies to every customer, regardless of risk level.

Enhanced due diligence applies when the risk profile of a customer or transaction demands evidence that standard checks cannot produce. 

Source of funds and source of wealth must each be verified with independent documentation, ownership structures must be traced to the natural persons who ultimately control the entity, and adverse media must be reviewed across languages and source types.

The monitoring that follows onboarding is more frequent and more tightly calibrated to the specific risk conditions that triggered EDD in the first place.

The differences are most concrete in what each process requires you to collect, verify, and document:

 

Customer due diligence Enhanced due diligence
Who it covers Every customer, regardless of risk level Customers meeting defined high-risk criteria
Identity verification Standard verification against reliable sources Enhanced verification across multiple independent sources
Beneficial ownership Identify and verify UBOs Full ownership mapping to the natural persons who ultimately control
Source of funds Required when risk warrants it Mandatory, with corroborating documentation
Source of wealth Not required for most customers Required, with separate evidentiary trail
Adverse media Standard screening Broader search across languages and source types, with materiality assessment
Monitoring Ongoing, risk-scaled Intensified, with triggers tied to specific risk conditions
Senior management approval Not required Required before relationship establishment
File standard Risk profile establishing identity and tier assignment Investigation record evidencing every finding, decision, and approval

When CDD escalates to EDD

EDD is a legal obligation, not a program option. FATF Recommendations 10 and 12, the FinCEN CDD Rule, the FCA Financial Crime Guide (FCG 3), and the EU’s Anti-Money Laundering Regulation each define specific conditions that trigger it:

  • Politically exposed persons (PEPs) and their associates: Foreign PEPs require EDD as a minimum under FATF Recommendation 12. Most jurisdictions extend this to domestic PEPs through their national frameworks. The risk perimeter extends to relatives and close associates beyond the named officeholder.
  • High-risk jurisdictions: Customers based in, transacting through, or connected to countries on the FATF grey or black list present elevated risk by regulatory definition. As of the June 2026 FATF plenary, 22 jurisdictions are under increased monitoring.
  • Complex or opaque ownership structures: Layered holding companies, offshore entities, nominee arrangements, and trusts that obscure beneficial ownership require EDD to establish who ultimately controls the entity.
  • Correspondent banking relationships: Cross-border correspondent banking carries its own EDD obligations under FATF Recommendation 13 and Section 312 of the USA PATRIOT Act, separate from standard customer onboarding requirements.
  • Large, unusual, or unexplained transactions: Activity that falls outside a customer’s expected profile and lacks a clear economic rationale triggers EDD regardless of the customer’s overall risk rating.
  • Non-face-to-face onboarding: Remote relationships where identity assurance methods do not meet a recognized standard require EDD to compensate for reduced verification confidence.

When EDD is triggered mid-relationship

A customer’s risk profile can change after onboarding. Corporate restructuring, a new beneficial owner, a jurisdiction update from the FATF, or adverse media emerging mid-relationship can each push a customer into EDD territory.

The same depth of investigation required at onboarding applies again when trigger conditions change. Programs built around fixed review cycles are exposed to undetected mid-relationship risk. By the time a quarterly or annual review runs, the elevated exposure has likely been present for months.

Perpetual KYC flags profile changes as they occur, without relying on a calendar cycle to catch them.

When a customer's risk crosses the EDD threshold

Read more: What Is Enhanced Due Diligence

Where programs get the boundary wrong

Most due diligence failures in regulatory findings trace back to the same root: The institution misread the trigger or applied the wrong tier, and could not demonstrate its reasoning or meet the file standard EDD demands.

Misclassifying the risk level

The most common version is a PEP relationship accepted under standard CDD because the political exposure was not identified at onboarding, or a corporate customer with a layered ownership structure treated as low-complexity without tracing the chain to its ultimate controllers.

Either way, the customer who should have triggered EDD was processed through standard CDD, leaving a documented deficiency that the next examination will identify.

Documenting the outcome without the reasoning

Recording the result of a risk decision without capturing the analysis behind it produces files that look complete but fail the evidentiary standard regulators apply to EDD. The written record must show what was checked, what was concluded, and who approved it. Verbal sign-off and informal notes do not satisfy this requirement.

Treating source of funds and source of wealth as the same thing

Enhanced due diligence requires separate documentation for each. The origin of money in a specific transaction and how a customer built their total assets over time are distinct questions requiring distinct evidence. Treating a bank statement as satisfying both is a frequently cited weakness in EDD examinations.

Treating EDD as a one-time exercise

The risk that triggered EDD can intensify after the relationship begins, or new triggers can emerge entirely. High-risk customer files require active maintenance. 

Four ways programs fail at the CDD EDD boundary

How the regulatory frameworks define the boundary

CDD and EDD obligations are not guidelines. Each of the four frameworks below sets binding conditions that determine which process applies.

FATF Recommendations 10 and 12

Recommendation 10 establishes CDD as the baseline for every customer relationship. Recommendation 12 requires enhanced measures specifically for PEPs, including senior management approval, source of wealth verification, and enhanced ongoing monitoring. 

The risk-based approach running through both means scrutiny must be calibrated to the assessed risk. 

FinCEN CDD Rule and USA PATRIOT Act Section 312

The FinCEN CDD Rule (31 CFR Part 1010) sets the US baseline across four pillars: 

  • Customer identification
  • Beneficial ownership
  • Purpose documentation
  • Ongoing monitoring

Section 312 of the USA PATRIOT Act adds EDD requirements for private banking and correspondent accounts involving foreign persons, including senior foreign political figures. The FFIEC BSA/AML Examination Manual translates both into the standards examiners apply in practice.

FCA Financial Crime Guide (FCG 3)

FCG 3 requires institutions to apply enhanced measures wherever higher risk is identified. Senior management sign-off is mandatory before establishing correspondent banking relationships and is a regulatory expectation for other high-risk customer decisions, with documented oversight at board or senior management level. 

The approval requirement extends beyond PEP cases to the full range of high-risk onboarding decisions.

EU Anti-Money Laundering Regulation (AMLR)

European institutions have a firm deadline. The AMLR (Regulation EU 2024/1624), applying from July 10, 2027, creates a single directly applicable rulebook across all member states. 

Its EDD provisions prescribe mandatory enhanced measures for high-risk third countries, standardized source-of-funds and source-of-wealth requirements, and heightened ongoing monitoring obligations. 

AMLA begins direct supervisory oversight of the highest-risk entities from January 2028.

One EDD obligation, four frameworks that enforce it

Read more: What is Financial Crime Compliance? [Complete Guide for 2026]

Sigma360: From screening to EDD investigation, without switching systems

When CDD and EDD run on fragmented data, such as sanctions screening in one tool, adverse media in another, corporate registries in a third, analysts spend their time consolidating sources rather than assessing risk. 

Deeper investigation requires deeper data, and pulling it manually across disconnected systems is where programs slow down and file quality drops.

Sigma360 consolidates the data problem at the source. The platform draws on 100B+ data points across 150+ corporate registries, global watchlist and sanctions coverage, and adverse media screening across 120+ languages, unified into a single entity view. 

Three capabilities cover the full CDD-to-EDD journey:

  • Match Agent clears identifiable false positives before they reach analyst queues, so review time concentrates on cases that genuinely require judgment
  • Entity Summary generates structured, AI-produced risk summaries covering KYC data, watchlist hits, adverse media, corporate registry detail, and network relationships, so analysts open every EDD investigation with a complete starting picture
  • EDD Agent cuts data-gathering time by 87% per the company, drawing on 260+ jurisdictions and 600K+ sources scanned daily, so analysts receive structured findings rather than raw data to sort

Each step is captured automatically. When a case moves from standard CDD to EDD, the system records what changed, what was reviewed, and what the analyst concluded, building the audit trail that regulators and internal governance require.

Banks, fintechs, payments firms, and regulated corporates running AML investigations alongside due diligence reviews draw on the same unified environment across both tiers.

Request a demo to see how Sigma360 handles the full CDD and EDD workflow.

FAQ

Does CDD apply to existing customers, or only at onboarding? 

CDD applies throughout the customer lifecycle. Risk indicators change after onboarding: A new jurisdiction designation, a change in business activity, or adverse media can each require a file review and updated risk assessment.

What is the difference between CDD and KYB? 

KYB (Know Your Business) describes the verification steps institutions apply to corporate customers as part of CDD, not a separate regulatory framework. It covers legal identity, ownership structure, and UBO identification. CDD uses that output to assign a risk rating and set the level of ongoing scrutiny.

How does simplified due diligence differ from standard CDD? 

SDD reduces the depth of verification required for demonstrably low-risk customers, such as listed companies, public authorities, and regulated financial institutions in equivalent jurisdictions. It does not remove the obligation to conduct due diligence.

Who is responsible for approving EDD decisions? 

Senior management, in most frameworks. FATF Recommendation 12 requires senior management approval for PEP relationships, and the FCA extends this expectation to other high-risk customer decisions. Analyst-level sign-off alone does not satisfy either.

Can CDD and EDD be outsourced to a third party? 

The activity can be, but the regulatory responsibility cannot. Institutions remain accountable for the quality of the file and the decision made, regardless of who gathered the underlying data.

What happens if EDD uncovers a problem after a customer has already been onboarded?

The institution must reassess the relationship, document the findings and their effect on the risk rating, and decide to continue, restrict, or exit. Regulators expect that decision and its reasoning to be recorded with the same rigor as the original onboarding file.

About Sigma360 | The Standard in KYC & Financial Crime Compliance

Sigma360 is an AI-powered, full-stack risk intelligence platform that consolidates operations into one enterprise-grade system, enabling point-in-time risk screening and perpetual client monitoring for financial crime prevention and compliance operations. Sigma360 unifies global risk data, proprietary intelligence, core screening technology and AI automation in a secure cloud environment to find direct and network-based risks at sub-second speed, reduce false positives and strengthen risk and compliance operations.

Sigma360.com / Schedule a Demo / Free Trial / Connect on LinkedIn

Engage with us

Our Risk Intelligence Specialists can get you the answers you need.