Enhanced due diligence (EDD) is the deeper investigation that follows when a customer’s risk profile exceeds what standard customer due diligence is built to handle. It covers source of funds and wealth verification, ownership network mapping, adverse media research, and the ongoing monitoring that runs for the life of the relationship.
The United Nations Office on Drugs and Crime puts the annual scale of money laundering at 2% and 5% of global GDP (up to $2 trillion). Much of it passes through institutions with functioning compliance programs, where the controls are present but not calibrated for the level of scrutiny high-risk relationships require. EDD is the layer that regulators expect institutions to apply when routine verification is no longer sufficient.
This guide covers what triggers EDD, how each step of the investigation should run, and what a completed file needs to contain to support the decision made about a high-risk customer.
Key takeaways:
- EDD applies where CDD is not enough
A customer’s risk profile can change after they are accepted, and the same depth of investigation applies when it does.
- Source of funds and source of wealth are not the same question
EDD must address both with separate evidence. Regulators treat them as distinct requirements and frequently cite programs that conflate them.
- The written record is what regulators assess
A completed EDD check is not enough on its own. The file must show the reasoning behind the decision, not just the outcome.
- How institutions run EDD depends on their type
Banks face volume and consistency challenges, fintechs face pressure to balance speed with depth, and payments firms apply EDD at the counterparty level, not only at customer onboarding.
- Sigma360‘s EDD Agent reduces manual review work
Instead of spending days gathering data across disconnected sources, analysts work from structured, AI-generated summaries covering 260+ jurisdictions, with every decision logged for audit readiness.
How enhanced due diligence differs from standard due diligence
The difference between EDD and CDD is one of depth, not kind:
- CDD verifies who a customer is and assigns them a risk rating.
- EDD investigates whether that customer’s funds, relationships, and activities are consistent with what they have disclosed, and it keeps watching after onboarding.
Here’s where they differ in practice:
| Customer due diligence | Enhanced due diligence | |
| Scope | Identity verification and risk rating | Identity, source of funds/wealth, ownership networks, adverse media |
| Documentation | Standard KYC file | Detailed investigation record with decision rationale |
| Monitoring | Periodic review | Continuous, risk-triggered monitoring |
| Applies to | All customers | High-risk customers, PEPs, complex structures, flagged transactions |
Source of funds vs. source of wealth
Source of funds identifies the origin of the money in a specific transaction: a property sale, an inheritance, or a business sale. Source of wealth is a broader question about how the customer built their total assets across the full span of their financial life.
Both require separate documentation. Supporting evidence includes tax records, financial statements, or sale contracts, and the explanation must be consistent with everything else the institution knows about the customer.
When a customer’s stated income does not square with their net worth, that is the inconsistency EDD is designed to catch. Treating the two as interchangeable is a frequent source of criticism in regulatory EDD examinations.

When is enhanced due diligence required?
Under FATF Recommendations 10 and 12, the FinCEN Customer Due Diligence Rule, the FCA Financial Crime Guide (FCG 5), and the EU’s Anti-Money Laundering Regulation, EDD is a legal obligation when defined risk conditions are present, not a a compliance option institutions can apply selectively.
The common thread across all four frameworks is the risk-based approach: Wherever increased exposure is present, deeper scrutiny is required. The situations that trigger that obligation are:
- Politically exposed persons (PEPs) and their associates: Public officials and those connected to them carry elevated corruption and bribery risk. FATF Recommendation 12 requires EDD for foreign PEPs at minimum, and many jurisdictions extend this to domestic PEPs.
- High-risk jurisdictions: Customers based in, or transacting through, countries on the FATF grey list or black list are strong grounds for EDD under most frameworks. As of the June 2026 FATF plenary, 22 jurisdictions are under increased monitoring, including Iraq and Bosnia and Herzegovina, which were added at that session.
- Complex or opaque ownership structures: Layered holding companies, offshore entities, nominee arrangements, and trusts that make beneficial ownership difficult to establish require EDD to identify who controls the entity.
- Correspondent banking relationships: Cross-border correspondent banking carries its own EDD obligations under FATF Recommendation 13, separate from standard customer onboarding.
- Large, unusual, or unexplained transactions: Activity that falls outside a customer’s expected profile and lacks a clear economic purpose triggers EDD regardless of the customer’s overall risk rating.
- Non-face-to-face onboarding: Relationships established remotely, where identity verification methods do not meet a recognized assurance standard, require EDD to compensate for the reduced identity assurance.
When EDD triggers mid-relationship
A customer’s risk profile does not stay static after onboarding. Corporate restructuring, a change in business activity, a new beneficial owner, or a jurisdiction update from the FATF can all alter the risk level in ways that standard CDD was not designed to detect. When a significant change occurs, the same depth of investigation required at onboarding applies again.
Programs built around fixed review cycles are structurally exposed to this. Periodic review catches changes on the schedule but by the time a quarterly or annual review runs, the exposure may have been present for months.
Continuous monitoring removes the lag. Perpetual KYC solutions flag profile changes that warrant a fresh EDD review without waiting for a scheduled cycle.
The enhanced due diligence process
A defensible EDD investigation leaves a clear record at every stage, from the rationale for classifying a customer as high-risk through to the monitoring plan that follows onboarding.
1. Classify the customer and document the rationale
Before the investigation begins, the customer must be formally classified as high-risk with the grounds for that decision recorded. Regulators examine not only that EDD was performed, but that the decision to apply it was justified and traceable. A risk score with no supporting rationale does not satisfy this requirement.
2. Collect enhanced identity and ownership documentation
For legal entities, this means tracing the ownership structure down to the natural persons who own or control the business, verifying each layer against corporate registry data, and confirming that the structure matches what the customer disclosed.
All of it must be verified against multiple independent sources rather than accepted at face value. Incomplete ownership mapping is frequently cited in regulatory criticism of EDD files.

3. Verify source of funds and source of wealth
Each line of inquiry requires its own documentation and its own evidentiary trail. The explanation a customer provides should be cross-referenced against their known assets, transaction history, and business profile. Inconsistencies are the point at which the investigation either deepens or the relationship is reconsidered.
4. Run adverse media and sanctions checks
At the EDD stage, adverse media screening requires a broader search across languages and source types than standard screening delivers. Materiality assessment is applied to determine whether findings are relevant to the specific risk in question. A name appearing in coverage is the starting point, not the conclusion.
Sanctions exposure involving the customer or any connected party must be resolved before onboarding continues.
5. Document findings and decision rationale
Regulators reviewing an EDD file look first at the written record. The reasoning that led to the decision carries as much weight as the decision itself. What was checked, what was found, what was concluded, and who signed off must all be documented.
The documentation must be detailed enough that an auditor could reconstruct the full investigation without additional explanation. Verbal sign-off and informal notes do not meet this standard.
6. Establish a monitoring plan and set review triggers
High-risk customers require a monitoring plan tied to the specific conditions that triggered EDD, with alerts set to fire when those conditions change. Risk can change independently of when the next review is due, and a generic periodic schedule does not keep pace.
Every alert, decision, and review action should be logged, producing the documented record regulators expect to find when they examine an ongoing EDD program.
Read more: AI in Financial Crime Compliance: Benefits and Use Cases
EDD in practice: Banks, fintechs, and payments firms
The regulatory requirements for EDD are consistent across institution types. Where they differ is in how each type of institution has to meet them operationally.
Banks
Banks run EDD at a scale most other institutions do not. Correspondent banking relationships fall under a separate EDD obligations framework (FATF Recommendation 13), and a large bank may maintain hundreds of respondent relationships requiring periodic review simultaneously.
The structural difficulty is applying EDD thresholds uniformly across retail, private banking, and corporate divisions, each with different risk appetites and relationship teams, without producing a patchwork of standards an examiner can exploit.
Senior management sign-off requirements, which most frameworks mandate for high-risk onboarding decisions, become an operational constraint when escalation queues are large enough to slow decisions.
Fintechs
Fintechs compete on fast onboarding, and manual EDD is structurally slow. The challenge is running it deeply enough on high-risk customers without creating a two-tier experience that delays legitimate applicants.
Fintechs onboard at higher velocity than traditional banks, which means EDD cases triggered by PEP matches, jurisdiction flags, or complex ownership structures accumulate faster. When manual review is the only tool, the quality of each file suffers as the queue grows.
Payments firms
Payments firms encounter EDD considerations at the counterparty level, a structural difference from banks and fintechs that apply EDD primarily at customer onboarding.
Higher-risk payment corridors, those touching high-risk jurisdictions or complex ownership chains, require enhanced scrutiny on the counterparty, not just the customer. The risk is concentrated in the transaction corridor rather than the ongoing customer relationship.
At the volume payments firms operate, manual counterparty EDD is economically unsustainable. Automation has to enter the workflow earlier than in banking, and the quality of the underlying data for cross-border counterparty verification determines how reliable the outcomes are.

EDD program readiness: A checklist for compliance teams
The questions below reflect the criteria regulators apply when determining whether the program functions as designed.
| Area | Key question |
| Risk triggers | Are the conditions that require EDD defined in policy, with a named owner for each? |
| Escalation thresholds | Is there a defined risk score or event that automatically escalates a customer to EDD? |
| Data collection | Are templates for source-of-funds and source-of-wealth documentation standardized across teams? |
| Beneficial ownership | Does the investigation process trace ownership to the natural person level in every case? |
| Documentation standard | Would the written record support a regulatory examination without supplementary explanation? |
| Mid-relationship triggers | Are there automated alerts for profile changes that should trigger a new EDD review? |
| Review cadence | Is the review schedule set by the identified risk conditions, not by a fixed calendar interval? |
What Sigma360’s EDD Agent delivers

A single high-risk EDD case can take days when analysts are pulling data from multiple systems across jurisdictions. The more cases in the queue, the harder it becomes to maintain the standard each file requires.
Sigma360’s EDD Agent reduces manual review work by 87%, per the company. Across 260+ jurisdictions and 600K+ sources scanned daily, it pulls together the data an analyst would otherwise gather across multiple systems and delivers it as a structured, AI-generated summary ready for review.
Every alert, decision, and review action is logged automatically, giving compliance teams a complete record of every investigation step. Analysts work from a prioritized queue of structured findings, which means their time goes to judgment calls, not data gathering.
For compliance teams at banks, fintechs, payments firms, and regulated corporates managing high-risk customer portfolios, Sigma360 makes it possible to run EDD to a consistent standard without the headcount it would otherwise require.
Request a demo to see how Sigma360’s EDD Agent works on your use case.
FAQ
How long does an EDD investigation take?
For a straightforward PEP case with clean documentation, it typically takes a few days. For a complex corporate structure spanning multiple jurisdictions or requiring additional documentation from the customer, it can take up to several weeks.
What is the difference between EDD and KYB?
KYB verifies a business customer’s identity, ownership, and legitimacy as part of standard CDD. EDD is the deeper layer applied when that business presents elevated risk, requiring source-of-funds verification, adverse media research across languages, and enhanced ownership tracing beyond what KYB covers.
Who approves EDD decisions?
Senior management, in most frameworks. FATF Recommendation 12 requires senior management approval for PEP relationships, and FCA FCG 5.3 extends this expectation to high-risk customer decisions more broadly. Analyst-level approval does not satisfy either requirement.
Can EDD be outsourced?
The activity can be. Many firms use third-party providers for adverse media research, beneficial ownership tracing, or source-of-wealth verification. The regulatory responsibility stays with the institution, though. The EDD file must meet the same standard whether the work was done internally or not.
How often does EDD need to be reviewed after onboarding?
As often as the risk conditions require, not on a fixed schedule. A PEP relationship in a stable jurisdiction might be reviewed annually. A correspondent banking relationship with exposure to high-risk corridors may need quarterly review or reassessment whenever the conditions change.
