Enhanced due diligence (EDD) is a more rigorous form of customer due diligence applied when a customer, transaction, product, or jurisdiction presents a higher risk of money laundering, terrorist financing, fraud, or other financial crime.
EDD goes beyond standard identity checks to build a deeper understanding of who the customer is, where their funds come from, why they are using the service, and whether their activity is consistent with their profile. It is a core requirement under global AML/CFT standards and local regulations for regulated financial and crypto services.
EDD vs standard due diligence
Most regimes distinguish between different levels of due diligence.
| Level | Typical use | What it involves |
| Simplified due diligence (SDD) | Demonstrably low-risk situations, where allowed by law | Minimal information, reduced verification, lighter ongoing monitoring |
| Customer due diligence (CDD) | Standard onboarding for most customers | Identity verification, basic background checks, risk profiling, ongoing monitoring |
| Enhanced due diligence (EDD) | Higher-risk customers, products, transactions, or jurisdictions | Additional information, deeper checks, senior approval, more frequent reviews, stronger monitoring |
EDD is not a separate process from CDD; it is CDD plus additional measures proportionate to the higher risk.
When EDD is triggered
EDD is typically required when one or more higher-risk factors are present.
Higher-risk customer types
Examples include:
- Politically exposed persons (PEPs) and their close associates or family members.
- Customers with complex ownership structures, such as certain trusts, foundations, family offices, or layered corporate vehicles.
- Customers in high-risk occupations or sectors (for example, certain cash-intensive businesses, high-value dealers, or sectors prone to corruption).
- Customers with adverse media or negative information suggesting possible involvement in financial crime.
Higher-risk geographic exposure
EDD may be required when there are links to:
- Jurisdictions identified as high-risk by bodies such as the FATF.
- Countries subject to sanctions or with weak AML/CFT regimes.
- Locations with elevated levels of corruption, organised crime, or terrorist financing.
A geographic connection alone does not prove wrongdoing; it is one factor that may require additional context.
Higher-risk products, channels, or transactions
EDD can be triggered by:
- Products that allow large, rapid, or cross-border transfers.
- Crypto services with higher inherent risk (for example, large external withdrawals, privacy-enhancing tools, or complex multi-chain activity).
- Unusual or complex transaction patterns, such as rapid layering of funds or activity inconsistent with the customer’s profile.
- High-value relationships or transactions above defined thresholds.
Other risk indicators
Additional triggers may include:
- Multiple failed verification attempts or inconsistencies in provided information.
- Use of third parties or intermediaries without a clear business rationale.
- Requests to obscure or complicate the transaction trail.
- Links to sanctioned entities, high-risk addresses, or flagged counterparties.
What EDD involves
The exact measures depend on the provider, product, and applicable law, but EDD typically includes some or all of the following.
Additional information collection
The provider may request more detailed information than for standard onboarding, such as:
- More comprehensive identity and background information.
- Detailed explanation of the purpose and intended nature of the relationship.
- Information about expected transaction volumes, counterparties, and use cases.
- For business customers, details on ownership and control structures, beneficial owners, and key managers.
Verification of source of funds and source of wealth
EDD often requires a deeper look at where the customer’s money comes from.
- Source of funds – the origin of the specific funds used in the relationship (for example, salary, business revenue, sale of an asset, inheritance, investment returns).
- Source of wealth – how the customer accumulated their overall wealth over time (for example, long-term business ownership, property portfolio, investments, inheritance).
Providers may ask for supporting documentation, such as:
- Employment contracts, pay slips, or tax returns.
- Business financial statements or audited accounts.
- Sale agreements for property or other significant assets.
- Investment statements or trust documents.
- Inheritance or gift documentation.
The aim is to confirm that the funds are consistent with the customer’s profile and declared activities.
Deeper background and adverse-information checks
EDD may include:
- More extensive sanctions, PEP, and watchlist screening.
- Broader adverse-media searches across multiple languages and sources.
- Deeper analysis of corporate registries and ownership chains for business customers.
- Review of prior relationships with other financial institutions, where permitted and relevant.
Senior management approval
Many frameworks require that higher-risk relationships receive senior management or compliance approval before onboarding or continuing the relationship.
This ensures that:
- The risks are understood at an appropriate level.
- There is clear accountability for the decision.
- Any conditions or restrictions are documented and enforced.
Stronger ongoing monitoring
EDD usually comes with more intensive ongoing monitoring, such as:
- More frequent transaction reviews and risk-profile updates.
- Lower thresholds for generating alerts or triggering manual checks.
- Periodic re-verification of key information (for example, source of funds, beneficial owners).
- Shorter review cycles (for example, annual or semi-annual instead of multi-year).
Additional controls and restrictions
Depending on the risk, a provider may apply controls such as:
- Lower transaction or withdrawal limits.
- Restrictions on certain products, jurisdictions, or counterparties.
- Requirements for additional documentation before large or unusual transactions.
- In some cases, a decision not to proceed with or to terminate the relationship.
EDD in crypto and fintech services
Crypto and fintech providers apply EDD in similar ways to traditional financial institutions, but with some crypto-specific elements.
On-chain and wallet risk
EDD may include:
- Analysis of linked wallet addresses and their on-chain history.
- Screening for connections to high-risk addresses, such as those linked to scams, mixers, darknet markets, or sanctioned entities.
- Review of cross-chain activity, bridges, and use of privacy-enhancing tools where relevant.
Product and usage patterns
Higher-risk patterns in crypto might include:
- Rapid movement of large amounts between external wallets and exchanges.
- Use of multiple chains and protocols in a way that obscures fund origins.
- Sudden changes in behaviour, such as moving from small retail activity to large institutional-style flows without a clear explanation.
EDD helps the provider understand whether such activity has a legitimate business or personal rationale.
Cross-border and licensing considerations
Crypto services often operate across many jurisdictions. EDD helps ensure that:
- Customers in or linked to high-risk jurisdictions receive appropriate scrutiny.
- The service complies with local licensing and AML/CFT requirements.
- Risks from complex cross-border structures are understood and managed.
How EDD affects users
From a user’s perspective, EDD may be experienced as additional steps or requests during onboarding or ongoing use.
During onboarding
A user subject to EDD may be asked to:
- Provide more detailed information about their background, occupation, and intended use of the service.
- Submit additional documents to verify identity, address, source of funds, or source of wealth.
- Explain the purpose of the relationship and expected transaction patterns.
- Wait longer for approval while the provider completes deeper checks and obtains any required senior approvals.
This does not necessarily mean the provider believes the user has done anything wrong. It reflects the higher-risk profile of the customer, product, or situation.
During the relationship
Over time, a user may experience:
- More frequent requests to update information or confirm details.
- Additional questions about certain transactions or counterparties.
- Closer monitoring of activity and potentially lower limits for certain actions.
- In some cases, restrictions on products, jurisdictions, or transaction types.
If a user’s risk profile changes (for example, change of jurisdiction, occupation, or business model), the level of due diligence may be revisited.
Communication channels
Providers should contact users about EDD requests only through official, secure channels (for example, in-app messages, verified email addresses, or official support contacts).
Users should be cautious of anyone requesting sensitive information or documents through unofficial channels, social media, or messaging apps.
Why EDD matters
EDD serves several important purposes.
Protecting the financial system
By applying deeper scrutiny to higher-risk relationships, EDD helps:
- Reduce the risk that the service is used for money laundering or terrorist financing.
- Deter bad actors from targeting platforms with strong controls.
- Support broader efforts to protect the integrity of the financial system.
Meeting regulatory obligations
Regulators expect regulated firms to:
- Identify higher-risk customers and situations.
- Apply proportionate EDD measures.
- Document decisions and maintain records.
- Cooperate with investigations and reporting obligations.
Failure to apply appropriate EDD can lead to regulatory sanctions, fines, and reputational damage.
Protecting customers and the platform
EDD also helps:
- Detect and prevent fraud and account misuse.
- Protect legitimate customers from being associated with illicit activity.
- Maintain trust with partners, banks, payment networks, and other counterparties.
