Enhanced Due Diligence (EDD)

Enhanced Due Diligence (EDD)

Enhanced Due Diligence (EDD)

Enhanced due diligence (EDD) is the deeper level of customer checks applied when a business relationship carries a higher risk of money laundering or terrorist financing. It sits on top of standard customer due diligence, not in place of it. In the UK, Regulation 33 of the Money Laundering Regulations 2017 sets out specific mandatory situations where EDD applies, from politically exposed persons to correspondent banking relationships.

Key takeaways

  • EDD is the deeper level of due diligence applied when risk is genuinely higher; it adds to standard CDD, not replaces it.
  • UK Regulation 33 of the MLR 2017 lists specific mandatory triggers: high risk generally, correspondent banking, PEPs, false/stolen ID, high-risk third countries, and unusually complex or large transactions.
  • FATF spreads the same requirement across several recommendations (10, 12, 13, 19) rather than one consolidated provision.
  • Source of wealth (how someone built their overall net worth) and source of funds (where a specific transaction’s money came from) are related but distinct, and EDD expects both addressed.
  • PEP relationships require senior management sign-off and enhanced ongoing monitoring under Regulation 35.
  • Danske Bank’s Estonia branch was penalised roughly $2 billion after EDD failures on a higher-risk non-resident customer portfolio.
  • The most common EDD failure isn’t misclassifying risk; it’s correctly classifying a customer as high risk and then not actually escalating the checks to match.

7

Mandatory EDD triggers listed under UK MLR 2017, Regulation 33(1)

Source: UK Money Laundering Regulations 2017

$2bn

Penalty against Danske Bank after EDD failures on its Estonian non-resident portfolio

Source: US / Danish authorities

3x/year

FATF updates its high-risk jurisdictions list, at the February, June and October plenaries

Source: FATF, via UK MLR Reg 33(3)

What enhanced due diligence actually means

Enhanced due diligence, EDD, is the deeper level of customer checks a regulated firm applies once a relationship or transaction crosses into higher-risk territory. It doesn’t replace standard due diligence. It adds to it: more documentation, more verification, more frequent review, applied specifically because the ordinary level of checking isn’t enough to manage the risk in front of the firm.

There’s no single universal checklist that defines EDD precisely, because what counts as “enhanced” depends on what standard due diligence already covers in a given jurisdiction. What’s consistent across every framework is the underlying logic: match the depth of the check to the actual risk, and go further when the risk is genuinely higher.

EDD vs CDD: what actually changes

The practical difference between EDD and standard CDD isn’t a different set of activities so much as more of the same activities, done more rigorously, plus a few additions unique to EDD. Standard due diligence verifies identity and understands the relationship’s purpose. EDD adds independent verification from additional sources, a closer look at the customer’s background and financial situation, confirmation that transactions actually match the stated purpose of the relationship, and materially more frequent monitoring.

Under UK law specifically, Regulation 33(5) of the Money Laundering Regulations 2017 lists these enhanced measures directly: seeking additional independent, reliable sources to verify information; better understanding the customer’s background, ownership, and financial situation; taking further steps to confirm a transaction matches the relationship’s purpose; and increasing monitoring intensity.

The seven triggers under UK law

UK law is unusually specific about when EDD is mandatory. Regulation 33(1) of the Money Laundering Regulations 2017 lists the situations where a firm must apply enhanced measures, rather than leaving it entirely to internal judgement. The core mandatory triggers are: any case identified as high risk of money laundering or terrorist financing, correspondent relationships with a credit or financial institution, customers who are politically exposed persons or their family members and close associates, customers who have provided false or stolen identification and the firm proposes to continue dealing with them, business relationships or transactions involving a high-risk third country, and transactions that are unusually complex or unusually large given their nature.

Regulation 33(6) also requires firms to weigh a broader set of risk factors, customer, product, transaction, delivery channel, and geography, when deciding how far EDD needs to go even outside these specific triggers. Since a 2022 change (SI 2022/860), the UK’s list of high-risk third countries tracks FATF’s own list directly, rather than a separately maintained UK schedule, and that FATF list updates three times a year at the February, June, and October plenaries.

How FATF frames the same requirement internationally

FATF’s own standard doesn’t sit in a single dedicated EDD recommendation the way UK law does. Instead, the requirement is built into the interpretive notes of several recommendations at once: Recommendation 10 on customer due diligence requires a risk-based approach generally, Recommendation 12 addresses politically exposed persons specifically, Recommendation 13 covers correspondent banking, and Recommendation 19 addresses higher-risk countries. Taken together, these produce the same practical outcome as the UK’s Regulation 33, even without a single consolidated EDD provision.

That structural difference matters for firms operating across borders. A jurisdiction that implements FATF’s standard through several separate provisions might define EDD triggers slightly differently from one, like the UK, that consolidated them into a single regulation, even though both are implementing the same underlying FATF requirement.

What EDD measures actually involve

In practice, EDD work usually involves some combination of the following: verified source of wealth and source of funds, going beyond a stated explanation to independently corroborate where money has come from; adverse media and enhanced sanctions and PEP screening, going deeper than a basic name check; senior management approval before the relationship begins or continues; more frequent periodic review, often annually or more often rather than the multi-year cycle a lower-risk relationship might get; and closer transaction monitoring calibrated specifically to that customer’s expected activity rather than generic thresholds.

The exact combination depends on why the relationship triggered EDD in the first place. A PEP relationship and a correspondent banking relationship both require enhanced measures, but the specific checks that matter most differ meaningfully between the two.

Source of wealth and source of funds: the hardest part

Source of wealth and source of funds are related but distinct, and confusing them is a common practical mistake. Source of wealth explains how a customer accumulated their overall net worth, career history, business ownership, inheritance, investment gains. Source of funds explains where the specific money involved in a particular transaction or relationship came from.

A customer can have a source of wealth that’s entirely legitimate, decades in a successful business, and still raise questions about source of funds if a specific large transfer doesn’t obviously trace back to that business. EDD generally expects both to be addressed, not just one or the other, and expects the explanation to be corroborated against independent evidence rather than taken as given.

EDD for politically exposed persons specifically

Politically exposed persons are one of the clearest and most common EDD triggers, precisely because their access to public power and public funds creates the opportunity for exactly the kind of financial crime EDD exists to catch. Regulation 35 of the UK’s Money Laundering Regulations sets out specific duties for PEP relationships: senior management approval before establishing or continuing the relationship, adequate measures to establish source of wealth and source of funds, and enhanced ongoing monitoring for the life of the relationship.

Being a PEP isn’t an accusation of wrongdoing. It’s a risk classification based on position, not conduct. But that classification carries real, ongoing obligations for as long as the relationship lasts, and typically for a defined period after someone leaves the position that made them a PEP in the first place.

Worth knowing. Being classified as a politically exposed person isn’t an accusation of wrongdoing. It’s a risk classification based on position, not conduct, but it still triggers mandatory enhanced measures for as long as the relationship lasts, and typically for a defined period after someone leaves the position.

EDD for correspondent banking

Correspondent banking, where one bank provides services to another bank, sits inside UK Regulation 34 as its own EDD category, separate from the general high-risk trigger. The reasoning is structural: a correspondent bank often has limited direct visibility into the underlying customers and transactions moving through its correspondent’s own customer base, which creates a meaningful blind spot if the correspondent institution’s own controls are weak.

EDD for correspondent relationships typically includes gathering enough information about the respondent institution to understand its business and reputation, assessing the quality of its own AML controls, and getting senior management approval before establishing the relationship, on top of the general EDD measures that would apply anyway.

What happens when EDD fails (real cases)

The Danske Bank Estonia case remains one of the starkest illustrations of what happens when EDD doesn’t function as intended. Danske Bank’s Estonian branch processed a portfolio of non-resident customers, exactly the kind of higher-risk relationships that should have triggered rigorous enhanced due diligence, and was penalised roughly $2 billion by US and Danish authorities after investigators found significant deficiencies in customer due diligence, transaction monitoring, and risk assessment tied to that portfolio.

Closer to home for KYC failures generally, the UK’s Financial Conduct Authority fined Santander UK £107.7 million in 2023 for prolonged weaknesses in its KYC and CDD controls, including gaps in how business banking customers who should have warranted closer scrutiny were actually monitored. Neither case reflects a total absence of due diligence. Both reflect a gap between customers who were formally classified as higher risk and the depth of checking those customers actually received in practice.

Common EDD mistakes

The mistakes that show up repeatedly in EDD failures aren’t usually about not knowing the rules. They’re about the gap between classification and execution: correctly identifying a customer as high risk, but not actually escalating the depth of checking to match; collecting source of wealth information once at onboarding and never revisiting it as circumstances change; treating EDD as a one-time gate to pass rather than an ongoing standard of monitoring that has to be sustained for the life of the relationship; and applying EDD inconsistently across similar customers, which undermines a firm’s ability to defend its risk-based approach if a regulator asks why one high-risk customer got closer scrutiny than another.

The common thread is that EDD, done properly, isn’t a heavier version of onboarding. It’s a heavier, sustained version of the entire relationship.

Building an EDD process that holds up

An EDD process that holds up under scrutiny generally has a few consistent features: clearly documented criteria for what triggers EDD, tied directly to the regulatory triggers rather than left to ad hoc judgement; a defined, consistent set of enhanced measures applied whenever those triggers fire, not a different approach every time; genuine independent verification of source of wealth and funds, not just a customer’s own explanation recorded and filed; and a review cycle that’s actually followed, not just specified in policy.

Firms that get this right tend to treat EDD triggers as an operational checklist tied to specific regulatory citations, Regulation 33, Recommendation 12, Recommendation 13, rather than a vague internal sense of what “higher risk” should mean.

Run a structured EDD assessment

Work through the CDD-to-EDD escalation triggers and see exactly what deeper checks a relationship needs.

Try the CDD vs EDD Tool →

Frequently asked questions

What is enhanced due diligence?

Enhanced due diligence (EDD) is a deeper level of customer checks applied when a relationship or transaction carries a higher risk of money laundering or terrorist financing. It adds to standard customer due diligence rather than replacing it.

When is enhanced due diligence required?

Under UK Regulation 33 of the Money Laundering Regulations 2017, EDD is mandatory for cases identified as high risk, correspondent banking relationships, politically exposed persons, customers who provided false or stolen ID, high-risk third countries, and unusually complex or large transactions.

What is the difference between EDD and CDD?

CDD (customer due diligence) is the standard level of checking applied to most customers. EDD applies the same core activities more rigorously, plus additional measures such as independent source verification and closer monitoring, when risk is genuinely higher.

What does an enhanced due diligence checklist typically include?

Common elements include verified source of wealth and source of funds, enhanced adverse media and PEP screening, senior management approval, and more frequent periodic review than a standard relationship would receive.

What is the difference between source of wealth and source of funds?

Source of wealth explains how a customer built their overall net worth over time. Source of funds explains where the specific money in a particular transaction or relationship came from. EDD generally expects both to be addressed.

Does every politically exposed person require enhanced due diligence?

Yes. Under UK Regulation 35, any customer identified as a PEP, or their family member or close associate, triggers mandatory EDD, including senior management sign-off and enhanced ongoing monitoring.

How does FATF address enhanced due diligence internationally?

FATF doesn’t have one dedicated EDD recommendation. The requirement is built across several recommendations: Recommendation 10 on customer due diligence generally, Recommendation 12 on PEPs, Recommendation 13 on correspondent banking, and Recommendation 19 on higher-risk countries.

What happens if a firm fails to apply proper EDD?

Penalties can be severe. Danske Bank was fined roughly $2 billion after EDD failures on a higher-risk customer portfolio at its Estonian branch, and UK regulators have issued fines exceeding £100 million for related KYC and CDD weaknesses at other firms.

Is enhanced due diligence a one-time check?

No. EDD includes enhanced ongoing monitoring for the life of the relationship, not just a deeper check at onboarding. Treating it as a one-time gate rather than a sustained standard is one of the most common EDD failures regulators flag.

Read more: our ultimate guides, whitepapers and templates

Related guides and resources to help you act on what you just read.

Last reviewed July 19, 2026 · 11 min read · Written for compliance and risk professionals · By the WhoWiki editorial team

Key takeaway: Enhanced due diligence (EDD) is the deeper level of customer checks applied when a business relationship carries a higher risk of money laundering or terrorist financing. It sits on top of standard customer due diligence, not in place of it. In the UK, Regulation 33 of the Money Laundering Regulations 2017 sets out specific mandatory situations where EDD applies, from politically exposed persons to correspondent banking relationships.

Learn & stay current

A compliance reference that keeps up with the regulators

Plain-English explainers, country rules, and data you can cite, updated as the landscape moves.

Comparing tools before you commit?

See how WhoWiki lines up against the platforms you already know, and which free tools fit which job.

See how current your screening could be

Book a walkthrough with our team, or start with the tools today. No account needed to run your first check.