OneID® | News and Events

Enhanced due diligence (EDD): when it applies and what it requires

Written by The OneID Team® | 22/07/26 06:59

The extra checks that kick in when a customer is higher risk, and what your firm still has to do

Enhanced due diligence is the extra scrutiny the Money Laundering Regulations 2017 require in higher-risk situations. Under Regulation 33 it applies to politically exposed persons, high-risk third countries, correspondent relationships, complex or unusually large transactions, and any case your risk assessment flags as high risk. It means gathering more information, checking source of funds, and monitoring more closely.

For most compliance teams the practical question is not what EDD means. It is which customers trigger it, how much extra work each trigger creates, and where a good identity check ends and the rest of the file begins. Getting that boundary right is the difference between a proportionate onboarding process and one that either waves risk through or drowns low-risk customers in paperwork.

What is enhanced due diligence (EDD)?

Enhanced due diligence is a heightened level of customer due diligence that regulated firms apply on top of their standard checks when a relationship or transaction carries a higher money-laundering or terrorist-financing risk. It is set out in Regulation 33 of the Money Laundering Regulations 2017. EDD is applied in addition to standard CDD under Regulation 28, not as a replacement for it.

When is enhanced due diligence required?

Regulation 33(1) lists the cases where a firm must apply EDD and enhanced ongoing monitoring. There are seven. Some are mandatory triggers written into the regulation; others depend on the firm's own risk assessment. The seven are set out below with the plain-English situation each one describes.

EDD trigger (Reg 33(1))

Plain-English situation

Key extra requirement

33(1)(a)

Your own risk assessment flags the case as high risk, or you are notified of high risk under regs 17(9)/47

Additional information plus enhanced monitoring

33(1)(b)

A party to the relationship or transaction is established in a high-risk third country (the live FATF call-for-action list)

Reg 33(3A) mandatory set: extra information, source of funds and wealth, senior sign-off, enhanced monitoring

33(1)(c)

A correspondent relationship with a credit or financial institution

Reg 34 measures

33(1)(d)

The customer or beneficial owner is a PEP, a family member or a known close associate

Reg 35(5) measures: senior management approval, source of wealth and funds, enhanced ongoing monitoring

33(1)(e)

The customer gave false or stolen ID and you still propose to deal with them

Heightened scrutiny

33(1)(f)

A complex, unusually large, unusual-pattern or no-clear-purpose transaction

Examine the background and purpose; increase monitoring

33(1)(g)

Any other case that by its nature presents a higher risk

Proportionate EDD

When assessing whether a case is high risk and how far to take EDD, Regulation 33(6) requires firms to weigh customer, product, transaction, delivery-channel and geographical risk factors. The trigger tells you EDD applies. The risk factors tell you how much.

What does enhanced due diligence require?

At a minimum, EDD means examining the background and purpose of the transaction or relationship as far as reasonably possible, and increasing the degree and nature of monitoring to judge whether activity is suspicious. Regulation 33(5) sets out measures a firm may apply: seeking additional independent, reliable sources to verify information; taking additional steps to understand the customer's background, ownership and financial situation; and increasing monitoring of the relationship.

Where the trigger is a high-risk third country under 33(1)(b), the requirements harden. Regulation 33(3A) makes a specific set of measures mandatory: additional information on the customer and beneficial owner, information on the source of funds and source of wealth, the reasons for the transaction, senior management approval to establish or continue the relationship, and enhanced monitoring.

What is a politically exposed person (PEP), and what does EDD require for one?

A politically exposed person is an individual entrusted with prominent public functions, above the level of a middle-ranking or junior official. The definition, along with "family member" and "known close associate", sits in Regulation 35(12). The substantive PEP requirements live in Regulation 35. Regulation 33(1)(d) is only the trigger that brings them into play.

Under Regulation 35(5), where a customer or beneficial owner is a PEP, family member or known close associate, the firm must obtain senior management approval to establish or continue the relationship, take adequate measures to establish the source of wealth and source of funds involved, and conduct enhanced ongoing monitoring. The firm must also run systems to identify whether a customer is a PEP in the first place, under Regulation 35(1).

Not every PEP sits at the top of the risk scale. Since 10 January 2024, and reflected in FCA finalised guidance FG17/6, the starting presumption is that domestic UK PEPs are treated as lower risk than non-domestic PEPs, on a risk-sensitive basis. EDD still applies, but proportionately.

What counts as a high-risk third country?

A high-risk third country is a jurisdiction identified as presenting a high money-laundering or terrorist-financing risk. The UK no longer maintains its own static schedule of these countries. Since SI 2022/860, Regulation 33 points to the Financial Action Task Force lists as they have effect from time to time, principally the FATF "high-risk jurisdictions subject to a call for action" list. That list is updated three times a year, at the February, June and October FATF plenaries.

Because the reference is live, firms should check the current position rather than rely on a saved list. HM Treasury and HMRC restate the current FATF position in a periodic Money Laundering Advisory Notice on high-risk third countries, which serves as the operational pointer.

What is the difference between CDD and EDD?

Customer due diligence is the standard set of checks every relevant person applies to know who they are dealing with: identifying the customer and verifying that identity from a reliable source independent of the customer, understanding the relationship, and monitoring it. Enhanced due diligence is what a firm layers on top in higher-risk cases. EDD does not replace CDD. It adds more information, closer scrutiny of source of funds and wealth, and tighter monitoring.

What is source of funds and source of wealth in EDD?

Source of funds is the origin of the specific money involved in a transaction or relationship, for example a property sale or a salary. Source of wealth is the origin of a person's overall assets, the story of how they came to hold what they hold. Establishing both is a core EDD obligation for PEPs under Regulation 35(5) and for high-risk-third-country cases under Regulation 33(3A). Neither is an identity check.

Where does identity verification fit in EDD, and what does it not cover?

Verifying who you are dealing with is the foundation every other EDD measure sits on. A strong identity check, matching a customer against several independent, reliable data sources, gives you defensible evidence for the identity and beneficial-owner information that Regulation 33(5) asks for. On a higher-risk file, that evidence base matters even more.

It does not discharge EDD. Screening a customer for PEP and sanctions status, establishing source of funds and source of wealth, running enhanced ongoing monitoring, and obtaining senior management sign-off all remain the firm's responsibility. The gov.uk position on digital identities and the Money Laundering Regulations makes the same point: a certified digital verification service is a reliable, independent source for the identity step, while the firm stays responsible for the rest of the programme and remains liable for it.

This is where a wider identity-matching layer helps a compliance team. For a higher-risk customer with a thin credit footprint, an overseas director or someone recently arrived in the UK, a single credit-reference check often returns nothing, and a good customer stalls at the very first step. Matching name, address and date of birth across banks, mobile networks, insurance data, public-sector data and credit reference agencies confirms that person exists and is who they claim to be, in seconds and with no document upload. The check clears the identity question so your analysts can spend their time on the parts of EDD that genuinely need judgement.

OneID's KYC Match returns a configurable count of independent data-source matches on name, address and date of birth, going beyond credit reference data alone. It handles the identity-matching step. Sanctions and PEP screening, source-of-funds analysis and transaction monitoring stay outside it, and it does not replace your firm's risk assessment or record-keeping. It gives you cleaner identity evidence to build the rest of the file on.

You can run 1,000 records through KYC Match for free and compare the results against your existing provider. To set that up, contact OneID.

FAQ

What does EDD stand for in AML? EDD stands for enhanced due diligence. It is the additional scrutiny that regulated firms apply, over and above standard customer due diligence, when a customer relationship or transaction carries a higher risk of money laundering or terrorist financing under the Money Laundering Regulations 2017.

When must enhanced due diligence be applied? EDD must be applied in the cases listed in Regulation 33(1): high-risk third countries, correspondent banking relationships, PEPs and their close connections, false or stolen identity, complex or unusually large or unusual-pattern transactions, and any case your own risk assessment flags as high risk.

Is EDD the same as CDD? No. Customer due diligence is the standard level of checks applied to every customer. Enhanced due diligence is an additional layer applied only in higher-risk cases. EDD is applied on top of standard CDD, not instead of it.

Do all PEPs require enhanced due diligence? All PEPs require EDD, but not at the same intensity. Since 10 January 2024 and under FCA guidance FG17/6, domestic UK PEPs start from a lower-risk presumption than non-domestic PEPs. Firms take a risk-based, proportionate approach rather than treating every PEP as maximum risk.

Is there a UK list of high-risk third countries? The UK does not keep its own static list. Regulation 33 points to the current FATF list of high-risk jurisdictions subject to a call for action, as it stands from time to time, updated three times a year. Firms should check the live position rather than a saved copy.

Who signs off enhanced due diligence for a PEP? Senior management. Under Regulation 35(5), a firm must obtain senior management approval before establishing or continuing a business relationship with a PEP, a family member or a known close associate.

Does electronic identity verification satisfy enhanced due diligence? No. Electronic identity verification strengthens the identity evidence within EDD, and a multi-source match supports the reliable-source element of Regulation 33(5). It does not discharge EDD. Screening, source of funds and wealth, enhanced monitoring and senior sign-off remain the firm's responsibility.