Blog Login
AML

CDD vs. EDD: What Is the Difference?

A

Anzar Dewani

1 day ago

CDD and EDD are both customer due diligence requirements under the BSA — but they apply to different customer risk levels and require different levels of review. Here is a clear breakdown of what separates them.

CDD vs. EDD: What Is the Difference?

Customer Due Diligence — CDD — and Enhanced Due Diligence — EDD — are both required elements of a compliant AML program under the Bank Secrecy Act. Both involve verifying who your customers are and understanding the nature of their relationships with your business. But they differ significantly in scope, depth, and when they apply.

Understanding the distinction matters for designing a compliant, risk-calibrated customer onboarding and monitoring program.

What CDD Is

Customer Due Diligence is the baseline set of know-your-customer procedures that applies to all customers. CDD requires collecting and verifying the minimum identifying information required under the BSA's Customer Identification Program rules — name, date of birth, address, and identification number — and assigning a risk rating to each customer relationship based on their profile and activities.

CDD also includes understanding the nature and purpose of the customer relationship — what product the customer is using, for what purpose, and what volume and type of activity are expected. This understanding is used to calibrate ongoing monitoring expectations.

CDD applies to every customer — no customer is exempted from the baseline due diligence process.

What EDD Is

Enhanced Due Diligence is the elevated level of due diligence required for customers who present heightened risk. EDD goes beyond the CDD baseline — collecting more information, verifying it more thoroughly, involving senior management, and applying more intensive ongoing monitoring.

EDD is not applied to all customers — it is specifically required for those who meet elevated risk criteria. The most common EDD triggers are Politically Exposed Person status, high-risk country exposure, high-risk business types, complex or opaque ownership structures, and situations where standard verification does not resolve questions about the customer's identity or the purpose of the relationship.

Key Differences: CDD vs. EDD

Scope of Information Collected

CDD requires the statutory minimum CIP data elements — name, date of birth, address, identification number — plus a general understanding of the customer relationship. EDD requires additional information — source of wealth, source of funds, more detailed beneficial ownership, the specific purpose of higher-value or unusual transactions, and independent corroboration of information provided by the customer.

Verification Depth

CDD verification confirms the customer is who they claim to be through standard document verification methods. EDD verification goes further — cross-referencing information against independent sources, reviewing adverse media and public records, and applying heightened skepticism when information is inconsistent.

Management Involvement

CDD decisions are typically made by front-line compliance staff following defined procedures. EDD decisions — whether to accept, continue, or terminate a high-risk relationship — typically require senior management or senior compliance officer review and approval. This governance layer exists to ensure that elevated-risk decisions receive appropriately senior oversight.

Ongoing Monitoring Intensity

CDD customers are monitored at standard risk calibration. EDD customers are monitored more intensively — with lower alert thresholds, more frequent formal relationship reviews, and more frequent updating of customer information. Ongoing EDD is not a one-time event at onboarding — it is a continuing, heightened oversight posture for the duration of the customer relationship.

When It Applies

CDD applies to all customers at onboarding. EDD applies when specific risk triggers are present. Applying EDD to all customers would be operationally impractical and is not required. Failing to apply EDD to customers who meet EDD criteria is a compliance violation.

Frequently Asked Questions

Can a customer start as CDD and be escalated to EDD later?

Yes. Customer risk ratings are not static. If a customer's risk profile changes — through PEP identification during ongoing screening, suspicious activity patterns, or changes in the customer's business or geographic exposure — the customer may be escalated from CDD to EDD at any point during the relationship.

What is Simplified Due Diligence?

Some AML frameworks recognize a third tier — Simplified Due Diligence — for customers assessed as particularly low risk. SDD involves a reduced level of information collection and verification. US BSA regulations do not formally define an SDD tier in the same way that some international frameworks do, so US fintechs generally operate with a CDD / EDD two-tier model.

How ComplyOne Helps

ComplyOne helps fintechs design risk-calibrated CDD and EDD programs that satisfy BSA requirements — from customer risk rating frameworks through tiered due diligence procedures and ongoing monitoring — through advisory services, compliance technology, or both.

 

 

Talk to the ComplyOne team to get started.

The information in this article is for general educational purposes and does not constitute legal or regulatory advice. Consult a qualified compliance professional for guidance specific to your situation.

Share this article:

Related Articles