Blog Login
AML

EDD in Banking: Definition, Process, and Real Examples

A

Anzar Dewani

1 day ago

Enhanced Due Diligence is a higher level of customer review required for higher-risk relationships. Here is what EDD means in banking and fintech, how the process works, and what it looks like in practice.

EDD in Banking: Definition, Process, and Real Examples

Enhanced Due Diligence — EDD — is the elevated level of customer review that financial institutions must apply to customers and relationships that present higher money laundering or financial crime risk. It requires collecting more information, conducting more thorough verification, and applying more frequent ongoing monitoring than standard Customer Due Diligence.

For fintechs, understanding when EDD is required and what it involves is essential — both to satisfy regulatory requirements and to avoid taking on unacceptable risk in higher-risk customer relationships.

What Makes EDD Different from Standard CDD

Standard Customer Due Diligence involves collecting and verifying the basic identity information for all customers — name, date of birth, address, identification number — and assigning an initial risk rating based on standard customer risk factors.

Enhanced Due Diligence goes further. It involves collecting additional information beyond the CDD baseline, conducting more thorough verification of that information, involving senior management in the decision to onboard and maintain the relationship, and monitoring the relationship more frequently and intensively than standard-risk relationships.

When EDD Is Required

EDD is required when a customer presents elevated risk indicators. The most common triggers include Politically Exposed Person status — where the customer or their immediate family or close associates hold or have held prominent public positions — customers in high-risk jurisdictions on the FATF or FinCEN high-risk jurisdiction lists, customers in high-risk business categories such as money services businesses, cryptocurrency businesses, cash-intensive businesses, and arms dealers, customers with unusual or complex ownership structures, customers whose transaction activity is inconsistent with their stated purpose or profile, and customers where the source of wealth or funds is unclear or raises concerns.

What EDD Involves

Additional Information Collection

EDD requires collecting information beyond the CDD baseline. Common additional information includes source of wealth — how the customer acquired their overall assets — source of funds — where the specific funds being moved through your platform originated — the purpose and nature of the business relationship — a more detailed description of why the customer needs your product — and beneficial ownership information for all individuals with any ownership or control interest, not just those above the standard 25% threshold.

Enhanced Verification

EDD requires more thorough verification of the information collected. This may include cross-referencing information against independent public sources, reviewing publicly available adverse media and litigation records, and for PEPs, reviewing news and government records about their activities and any allegations of corrupt conduct.

Senior Management Approval

Most EDD frameworks require senior management review and approval before accepting or continuing a high-risk customer relationship. This control serves as both a substantive check on the decision and an accountability mechanism — ensuring that higher-risk relationships are reviewed by someone with appropriate seniority and authority.

Enhanced Ongoing Monitoring

EDD customers require more frequent and intensive monitoring than standard-risk customers. This typically means more frequent re-verification of identity and profile information, more sensitive transaction monitoring thresholds that generate alerts at lower levels of activity, and more frequent formal relationship reviews.

Real Examples of EDD in Practice

PEP Onboarding

A fintech identifies at onboarding that a new customer is the adult child of a sitting senior cabinet minister in a foreign country. The customer is a PEP-by-association. EDD requires collecting detailed source of wealth documentation explaining the origins of the customer's assets, source of funds documentation for each significant transaction, and senior compliance officer review and approval before the account is opened.

High-Risk Jurisdiction Customer

A customer located in a jurisdiction on FATF's list of high-risk countries applies for account access. EDD requires enhanced verification of identity documents — which may be less standardized than documents from lower-risk jurisdictions — additional documentation of the purpose and nature of the relationship, and heightened monitoring thresholds once the account is active.

Frequently Asked Questions

Can a high-risk customer be accepted without EDD?

No. If a customer triggers EDD criteria, EDD must be completed before the account is accepted. Accepting a PEP or other high-risk customer without completing required EDD is a BSA compliance violation.

What EDD documentation must be retained?

All EDD documentation — the additional information collected, the verification steps taken, the senior management approval, and the rationale for the risk assessment — must be retained for five years following the end of the customer relationship, consistent with standard BSA recordkeeping requirements.

How ComplyOne Helps

ComplyOne helps fintechs design EDD programs and procedures that meet regulatory requirements — from EDD trigger criteria and documentation checklists through senior management review processes and ongoing monitoring calibration — through advisory services, compliance technology, or both.

 

 

Talk to the ComplyOne team to get started.

The information in this article is for general educational purposes and does not constitute legal or regulatory advice. Consult a qualified compliance professional for guidance specific to your situation.

Share this article:

Related Articles