Customer risk and EDD briefing · 2026
Enhanced Due Diligence is the additional investigation applied when a customer, beneficial owner, transaction or geography presents elevated money-laundering, terrorist-financing, sanctions or reputational risk. EDD is not a punishment and it is not a generic request for every document available: it is a proportionate response to identified risk.
1. Standard KYC versus EDD
| Question | Standard customer due diligence | Enhanced due diligence |
|---|---|---|
| Identity | Verify the customer, representatives and beneficial owners. | Obtain additional independent evidence and resolve inconsistencies or complex ownership. |
| Purpose | Understand the expected product use and relationship. | Test the commercial rationale, counterparties, flows, jurisdictions and risk appetite in more detail. |
| Funds and wealth | Collect information proportionate to the profile and service. | Trace source of funds and source of wealth using tax, corporate, financial, sale, investment or other reliable evidence. |
| Monitoring | Apply routine transaction monitoring and periodic refresh. | Use tighter thresholds, more frequent reviews, transaction pre-clearance or senior approval where justified. |
| Governance | Follow ordinary approval and escalation routes. | Record the rationale, designate an accountable decision-maker and review whether the relationship remains acceptable. |
2. Common EDD triggers
Triggers differ by business and jurisdiction, but frequently include a politically exposed person or close associate, a high-risk country, sanctions exposure, opaque or multi-layered ownership, unusual source of wealth, cash-intensive or high-risk industries, non-face-to-face onboarding with weak evidence, adverse media, complex crypto flows, nominee arrangements, unexplained third-party payments or activity inconsistent with the customer's profile.
A trigger does not automatically mean the customer must be rejected. It means the risk assessment should change and the business should collect enough evidence to make a defensible decision. The reason for applying EDD, the information requested and the final decision should be recorded.
3. What an EDD file should contain
Ownership
Group chart, control rights, directors, UBO evidence, nominee explanation and independent verification.
Wealth and funds
Financial statements, sale agreements, tax evidence, investment records or other credible provenance documents.
Activity
Expected flows, counterparties, wallet addresses, markets, products, source countries and transaction rationale.
Documents should be assessed, not simply collected. A bank statement may show a balance but not explain how wealth was created. A corporate chart may show ownership but not who exercises control. A blockchain address may be identifiable but still require screening and a reason for the transfer. EDD is the analysis connecting the evidence to the risk decision.
4. PEPs and high-risk countries
PEP controls should be risk-based and aligned with the applicable law. A PEP status is not proof of wrongdoing, but it generally requires senior management approval, reasonable measures to establish source of wealth and source of funds, and enhanced ongoing monitoring. The relationship should be reviewed when the person leaves office because risk may not end immediately.
Country risk should also be specific. Consider sanctions, corruption, conflict, weak AML controls, tax transparency, regulatory restrictions, customer location, counterparties and the service being provided. Do not rely on a single public “high-risk country” list without checking the lists and rules relevant to the business.
5. When EDD should become ongoing
EDD is not completed once the first set of documents is uploaded. The business should define review frequency, event-driven triggers, transaction thresholds, expiring documents, ownership changes, adverse-media alerts, unusual wallet exposure and changes in the customer's business. If the customer cannot provide a reasonable explanation or the risk exceeds the firm's appetite, the options may include restricting services, filing a suspicious activity report where required, exiting the relationship or refusing the transaction.
- Identify the trigger and document the initial risk assessment.
- Request targeted evidence with a clear explanation of what is needed.
- Verify the evidence independently and resolve contradictions.
- Obtain senior approval where required by law or internal policy.
- Set monitoring, refresh and escalation conditions before activation.
- Record the outcome and review it when the facts change.
EDD should be proportional, not endless
Requesting irrelevant documents can reduce customer fairness without improving risk understanding. A strong EDD procedure explains why each item is needed, what would satisfy the request and who decides whether the evidence is sufficient.
Conclusion: EDD is disciplined curiosity
Enhanced Due Diligence gives a business a structured way to understand higher-risk relationships. It protects the firm when the evidence is credible, the relationship fits the risk appetite and monitoring is active. It also provides a clear basis for declining a relationship when the customer cannot explain ownership, wealth, funds or activity.
Licensium can build an EDD procedure and risk methodology, review customer files, prepare source-of-funds controls and support a bank or regulator readiness exercise. Start a confidential discussion about your risk profile.
Research and legal sources
- FATF — Customer due diligence and risk-based approach
- FATF — Politically exposed persons
- EU AML framework
Risk classifications and EDD duties vary by activity and jurisdiction. This article is general information, not legal advice.