TL;DR
- EDD means enhanced due diligence, a deeper check triggered by risk.
- US law codifies EDD for only a handful of named account types.
- Everything else banks call EDD rests on examiner expectation.
- Examiners test the documented rationale, not the volume of documents.
- Under the BSA, ongoing EDD is event-driven rather than calendar-driven.
The Federal Financial Institutions Examination Council’s BSA/AML manual does not use the term EDD (Enhanced Due Diligence), instead, it describes it as “collecting additional information about customers that pose heightened risk”.
Enhanced due diligence is the deeper layer of customer scrutiny that’s used by banks where a relationship carries higher levels of money laundering or terrorist financing risks. Standard checks that establish who the customer is are not enough in these high-risk situations. EDD, on the other hand, establishes where these high-risk individual’s money comes from and whether the account’s behaviour matches the transactional history of that person.
This guide covers what EDD legally requires in the US, the UK and the EU, how the process runs in practice, and where programmes fail.
What is EDD in banking?
EDD in banking is the set of additional checks, evidence, and monitoring a bank applies to customers whose risk profile crosses its own escalation threshold. The EDD meaning is consistent across jurisdictions even where the legal force differs, so a bank in Ohio and a bank in Manchester are doing recognisably similar work under differently worded obligations. That consistency is not a coincidence. The risk-based principle behind EDD originates with Financial Action Task Force Recommendation 10, which requires the depth of due diligence to rise with the risk of the relationship, and the US, UK and EU regimes below are three different implementations of that same instruction.
Three features separate EDD from a routine check.
- It is triggered, not universal: EDD applies to a subset of customers identified by the bank’s risk assessment. Every customer gets due diligence, and a minority get the enhanced version.
- It reaches past identity into source and purpose: A standard check confirms a name and address. EDD asks where the wealth originated, what the account is for, and whether the expected activity is plausible.
- It continues after onboarding: EDD is a standing posture on a relationship rather than a gate at account opening, which means the monitoring intensity stays elevated for as long as the risk does.
Because the threshold is set by the bank rather than by a regulator, EDD is also a governance question before it is an operational one. Someone has to decide where the line sits, defend that choice, and own the escalations that cross it. Banks that leave the threshold undocumented tend to discover the gap during an examination rather than before it.
The acronym itself causes confusion in US search results, because “EDD” also refers to California’s Employment Development Department and its benefit payment card. In a banking compliance context, EDD always means enhanced due diligence.
CDD vs EDD in banking: what actually changes
The difference between CDD and EDD in banking is depth and evidence standard, not a different legal category. Customer due diligence is the baseline duty owed to every customer, and enhanced due diligence is that same duty performed to a higher standard where risk warrants it. Because EDD builds on CDD rather than replacing it, a weak CDD foundation makes EDD unreliable no matter how much extra paperwork sits on top.
| Dimension | Customer due diligence (CDD) | Enhanced due diligence (EDD) |
| Applies to | Every customer | Higher-risk customers and relationships only |
| Identity | Verify identity and, for legal entities, beneficial ownership | Same, plus corroboration from additional independent sources |
| Wealth and funds | Understand expected activity | Establish source of wealth and source of funds with evidence |
| Ownership | Beneficial owners at the applicable threshold | Full structure traced, including layered and offshore holdings |
| Screening | Sanctions, PEP and watchlist screening | Same, plus adverse media and closer analysis of near matches |
| Approval | Standard onboarding authorities | Senior or dual sign-off, with the rationale recorded |
| Monitoring | Ongoing, risk-based | Elevated scope and frequency for as long as risk persists |
| Documentation | Evidence of the checks performed | Evidence plus the written reasoning for the decision |
The last row is where most programmes underperform. Two banks can collect identical evidence packs on the same customer, and only one of them can show an examiner why it concluded the relationship was acceptable.
What are the enhanced due diligence requirements under the BSA?
Under the Bank Secrecy Act, enhanced due diligence is codified for a short list of named account types and otherwise derives from the general risk-based programme obligation. That two-tier structure is the answer most guidance skips, and it explains why no authoritative US source publishes a universal EDD checklist.
The codified tier
Specific EDD duties attach to particular relationships that Congress and Treasury singled out for named treatment. The FFIEC manual points to correspondent accounts for foreign financial institutions at 31 CFR 1010.610, payable-through accounts at 31 CFR 1010.610(b)(1)(iii), and private banking accounts for non-US persons at 31 CFR 1010.620. For these, the due diligence programme must include enhanced policies, procedures and controls, and the obligation does not bend to a bank’s own risk appetite.
The expectation tier
For every other higher-risk customer, EDD flows from the ongoing CDD requirement at 31 CFR 1020.210(b)(5), which obliges banks to understand the nature and purpose of each relationship and to monitor it. Politically exposed persons and money services businesses sit here too, carried by interagency guidance from 2001 and 2005 rather than by a rule that names EDD. The FFIEC manual is explicit that a bank’s procedures “must ensure compliance with these existing requirements and should meet these supervisory expectations,” which is a meaningful distinction because expectations are assessed against your own documented policy.
What this means for your policy
FinCEN‘s CDD rule took effect on 11 July 2016 with a compliance date of 11 May 2018, and it codified existing supervisory practice rather than raising the bar. One consequence surprises compliance teams. The manual states plainly that “there are no required risk profile categories,” so the familiar low, medium, and high tiering is a convention your bank chose, not a standard it inherited. Beneficial ownership is the exception that proves the pattern, because that information must be collected at the 25 percent threshold regardless of risk profile.
How does the EDD process work in banking?
The EDD process in banking runs in five stages, and each of the stages have to leave some sort of evidence behind. A file that contains information about what was collected without evidence or context about why it was selected is of no use.
Stage one: trigger and record the escalation
The first step is risk assessment. This is the step that determines, based on a customer’s geography, product, and expected activity, whether EDD applies at all or not. It gives a decision with a timestamp and a reason, so the logs show what triggered the escalation.
Stage two: gather the information the risk actually demands
Here the FFIEC manual is more useful than any vendor checklist, because it lists what a bank “may consider obtaining” for a higher-risk customer. That framing matters, since the manual describes information rather than a fixed set of documents.
- Source of funds and source of wealth: Where the money in the account came from and how the customer accumulated wealth overall.
- Occupation or type of business, including for anyone with ownership or control over the account.
- Financial statements for business customers.
- Location of organisation and principal place of business for corporate customers.
- Proximity of the customer’s residence, employment or business to the bank.
- Primary trade area and expected transaction profile, covering whether activity should be domestic or international and at what volumes.
- Business operations detail, such as total sales, currency transaction volumes, and major customers and suppliers.
Evidence follows from that list rather than driving it. Payslips, tax filings, audited accounts, share registers, trust deeds and sale contracts all appear in EDD files, and each one earns its place by answering a specific question about source or purpose.
Stage three: trace ownership and screen deeper
Layered ownership defeats surface checks, so business verification has to reach the natural persons behind the structure. The screening net widens at this stage to take in adverse media and closer handling of PEP and RCA matches, where the analyst has to record why a near match was cleared or confirmed.
Stage four: decide and name the approver
Someone has to own the outcome, and in UK-regulated groups that authority usually sits with, or is delegated by, the money laundering reporting officer. The FFIEC manual instructs that a bank’s procedures “should indicate who in the organisation is authorised to change a customer’s risk profile,” which turns approval authority into a documented control rather than an informal habit.
Stage five: monitor at elevated intensity
EDD relationships carry heavier ongoing monitoring than standard ones. Scope, frequency and escalation thresholds all tighten, and every subsequent review attaches to the same case record so the relationship reads as one continuous history.

How EDD works in mobile banking
Mobile and other remote channels change the evidence problem rather than the obligation. An EDD mobile banking journey has to capture source-of-funds evidence, trace ownership, and route a case to a named approver without a branch visit, which is where programmes built around wet-ink documents stall.
Three constraints bite hardest in a remote channel.
- Evidence capture on a small screen: Source-of-wealth documents run to many pages, and a customer photographing a twelve-page trust deed on a phone will produce unusable images unless the flow guides the capture.
- Session continuity across days: EDD rarely completes in one sitting, because the customer has to find historic paperwork. A journey that discards partial progress forces a restart and loses the applicant.
- Approval away from the branch: The named approver has to see the same case the analyst saw, which means the decision surface has to travel to wherever that person is.
Remote onboarding is also where the elevated-risk customer is most likely to abandon. A high-value relationship lost at the source-of-wealth step is a commercial cost as well as a compliance one, and the customers most likely to walk are the ones whose accounts justify the scrutiny in the first place.
Why one global EDD policy breaks
A single global EDD policy will either over-apply controls where they are not required or under-document decisions where thorough documentation is required.
| Requirements | United States | United Kingdom | European Union, from 10 July 2027 |
| Legal form | Codified for named account types, otherwise supervisory expectation | Codified duty with a mandatory core | Directly applicable regulation with category-driven escalation |
| Key provisions | 31 CFR 1010.610, 1010.620, 1020.210(b)(5) | MLRs 2017 regs 33, 34, 35 | AMLR Section 4, Articles 34 to 46 |
| Mandatory measures | Programme must be risk-based, with specific measures largely undefined | Reg 33(4) requires examining background and purpose, plus increased monitoring | Named measures per category, including correspondent, crypto and PEP provisions |
| Discretionary measures | Manual lists information a bank “may consider obtaining” | Reg 33(5) sets out a menu including additional independent sources | Commission can mandate specific measures for listed third countries |
| High-risk countries | Risk-based, informed by geography | Points dynamically at the two FATF lists | Commission delegated acts per Articles 29 to 31 |
The UK regime is prescriptive in a way the US one is not. Regulation 33 of the Money Laundering Regulations 2017 requires enhanced due diligence and enhanced ongoing monitoring in defined high-risk cases, and regulation 33(4) makes two measures compulsory rather than advisory. Regulations 34 and 35 add specific duties for correspondent relationships and politically exposed persons.
One UK detail defeats a lot of global policies. Since SI 2024/69, made on 22 January 2024, a high-risk third country means a country on either the FATF list as they have effect from time to time, and the old Schedule 3ZA list was removed. A policy naming fixed countries is therefore already out of date, because the trigger now moves whenever FATF moves.
The EU is going with a different approach. Regulation (EU) 2024/1624 applies from 10 July 2027, and its Section 4 runs from Article 34 through Article 46 with separate articles for cross-border correspondent relationships, crypto-asset service providers, residence-by-investment applicants and politically exposed persons.
A workable group policy treats the strictest applicable regime as the floor and layers the local mandatory measures on top of it, rather than averaging across jurisdictions. The alternative, a single global standard applied uniformly, either imports UK-style prescriptions into US relationships that never needed it or exports US-style discretion into markets where discretion is not available.
The mistake banks make with EDD
Most EDD programmes are built as collection exercises. Because of that, teams measure the completeness of the file and count documents received, when what should be assessed is how effectively and easily an analyst could follow the reasoning to the conclusion.
Process quality is the thing under examination, which means a defensible decision that turned out wrong is survivable, whereas an undocumented decision that turned out fine is not.
The practical consequence runs against instinct. Another document request does little for defensibility once the pack already holds enough to reason from, whereas one paragraph explaining why the analyst accepted a source-of-wealth account changes the file materially. Effort spent on collection past the point of sufficiency is effort not spent on the part that gets tested.
A second habit compounds the first. Many banks run EDD refresh on a calendar, and the BSA does not require that. The manual states that the ongoing monitoring element “does not impose a categorical requirement that the bank must update customer information on a continuous or periodic basis,” and it lists the events that should prompt review instead, among them unexplained changes in account activity, changes in business ownership, law enforcement enquiries, and adverse media results. Those listed events have a stronger claim on analyst hours than an annual review of a customer whose circumstances have not changed.
Cross-border exposure adds a third failure mode. Andrei Sribny of the AML Certification Center puts it directly, observing that criminals rarely challenge the technology and instead exploit inconsistencies between jurisdictions, because the weakest point in a verification chain is very often a country rather than a tool. An EDD standard applied unevenly across a banking group creates exactly that gap.
There is also a commercial argument that compliance teams rarely make out loud. As Tom Gadsden, VP of Product at Shufti, frames it, your best customers are often your EDD customers, so the question is how to automate those processes well enough that a high-net-worth client is approved rather than interrupted. A programme that treats EDD purely as a cost centre puts its heaviest friction on its most valuable relationships.
What to fix now
Five checks will tell you whether your EDD programme would survive examination.
- Pick a live EDD case and trace the reasoning: If the file shows what was collected but not why it satisfied the reviewer, the documentation gap is your priority.
- Name the approver for each risk tier: Confirm your procedures state who may change a customer risk profile, and confirm the system enforces it rather than relying on convention.
- Audit your triggers against your calendar: Count how much review effort is spent on scheduled refreshes versus event-driven escalations, then rebalance toward the events the manual actually lists.
- Check your high-risk country list is dynamic: Any hard-coded jurisdiction list should be replaced with a live reference to the relevant FATF lists.
- Map your policy to each regime you operate under: One global standard is fine as a floor, provided the mandatory measures of each jurisdiction sit on top of it.
Stephen Geerman of Axioma, a Shufti partner, argues that decision confidence rests on better data, better workflows and better documentation and describes static screening as the still photograph that preceded moving pictures. The EDD equivalent is a file frozen at onboarding while the relationship keeps changing.
Where Shufti fits in the EDD process
If your EDD work lives in spreadsheets and email threads, the reasoning behind each decision is the first thing to go missing, and it is the first thing an examiner requests. Audit preparation quietly consumes weeks when nobody can reconstruct why a PEP was approved eighteen months ago.
Shufti’s due diligence forms run standard and enhanced due diligence inside one case record. Weighted answers produce a risk score against thresholds you configure, and cases route to straight-through CDD, open EDD sections automatically, or escalate for four-eyes approval before verifications fire. Every submission, action, approval, and rationale writes to an immutable log with reason codes, and re-verification triggers when a risk signal changes rather than when a calendar date arrives. The record you export for a regulator is the same record your reviewer used.
Frequently Asked Questions
What are CDD and EDD in banking?
CDD is customer due diligence, the baseline check every customer receives to verify identity and understand expected activity. EDD is enhanced due diligence, a deeper examination of source of wealth, ownership and purpose, applied only to higher-risk customers.
What does EDD stand for in banking?
EDD stands for enhanced due diligence. In US consumer search results the same acronym often refers to California's Employment Development Department, but in banking compliance it always means enhanced due diligence.
What are the enhanced due diligence requirements under the BSA?
The BSA codifies EDD for foreign correspondent accounts, payable-through accounts and private banking accounts for non-US persons. For other higher-risk customers, EDD derives from the risk-based ongoing CDD obligation at 31 CFR 1020.210(b)(5) plus supervisory guidance.
What documents does an EDD check involve?
The FFIEC manual lists information rather than documents, including source of funds and wealth, occupation, financial statements, and expected transaction volumes. Payslips, tax filings, audited accounts, and share registers are common evidence, chosen to answer a specific risk question.
How does EDD work in mobile banking?
The obligation is identical, but evidence capture happens remotely. Source-of-funds documents are uploaded and parsed, ownership is traced against registries, and the case routes to a named approver in-app, with the full decision trail retained.















