Compliance teams often talk about CDD and EDD as if they’re two different tracks that they can run separately and switch whenever they want. That’s not how the law works. Enhanced due diligence isn’t an alternative to customer due diligence; it’s an extra layer applied on top of it, and there are set conditions that define when the layer can be or needs to be switched.
The distinction here matters because most regulatory issues arise when a file shows up exactly at the switch. The flow looks something like this:
- Standard checks run at the initial stage
- A condition is met
- The extra layer kicks in
Most of the time, the problem occurs at the third stage when a case gets stuck between two processes that were not designed to hand off to each other.
This article sets out what each level requires, what triggers the move between them, and where the US and UK rules differ.
What is the Difference Between CDD and EDD?
Customer due diligence (CDD) is the set of identity and risk checks a regulated firm runs on its customers. Enhanced due diligence (EDD) is a further set of checks applied when specific higher-risk conditions are present.
The UK Regulation 33(1) of the MLR 2017 requires enhanced measures and enhanced ongoing monitoring “in addition to” the customer due diligence measures in regulation 28, so EDD adds to CDD rather than replacing it.
| Criteria | Customer due diligence (CDD) | Enhanced due diligence (EDD) |
| Who it applies to | Every customer and business relationship the rules cover | Only customers and situations meeting defined higher-risk conditions |
| What starts it | A new business relationship, certain one-off transactions, suspicion of money laundering, or doubt about information already held | A condition listed in regulation 33(1), or a high risk the firm identifies through its own risk assessment |
| What it involves | Identifying the customer, verifying that identity, identifying who ultimately owns or controls a business customer, and understanding the purpose of the relationship | All of the above, plus further measures suited to the case. For politically exposed persons the rules specifically require senior management approval and steps to establish source of wealth and source of funds |
| Monitoring afterwards | Set in proportion to assessed risk | Enhanced, as regulation 33(1) requires |
Source of Funds and Source of Wealth are not the Same Thing
Two terms in that table are easy to confuse, and confusing them leaves a gap in the file.
- Source of Funds: It answers where the money originates from.
- Source of Wealth: It answers how the customer built up their overall assets.
A recent payslip can answer the first, but it says very little about the second. UK regulation 35 treats them as two separate things a firm must establish for a politically exposed person, which means someone holding a prominent public position, along with their family members and known close associates.
Why Running CDD and EDD as Two Separate Processes Causes Problems
Search results often frame this as CDD vs EDD, as though a firm picks one and sets the other aside. The regulations do not work that way, since enhanced measures are defined as additions to the standard ones. If these two are run in separate systems, then it will cause issues when the file is moved from one to another.
What are the Four Customer Due Diligence Requirements?
In the United States, the Financial Crimes Enforcement Network (FinCEN) sets four core requirements in its CDD Rule, which applies to covered financial institutions such as banks and broker-dealers. Written policies and procedures must be reasonably designed to do four things.
- Identify and verify the identity of customers. The basic identification is carried out when an account is opened.
- Identify and verify the identity of beneficial owners of companies opening accounts.
- Understand the nature and purpose of customer relationships in order to develop customer risk profiles.
- Conduct ongoing monitoring to identify and report suspicious transactions and, on a risk basis, keep customer information up to date.
Is Simplified Due Diligence the Same as CDD?
Simplified due diligence is customer due diligence carried out to a reduced extent, so it lowers the depth of the checks without removing the duty to run them. Under regulation 37 of the MLR 2017, a firm applying simplified measures must continue to comply with the requirements in regulation 28, and may adjust only the extent, timing or type of the measures it takes. Regulation 37 also sets out when simplified measures have to stop, which is where escalation begins.
In simpler words, the obligation stays, but the depth of it changes.
When does CDD escalate to EDD?
Escalation happens when a defined condition is met. Some of those conditions are written into the rules. The rest come from a firm’s own risk assessment.
The Conditions Written into the Rules
Regulation 33(1) lists the situations in which a firm must apply enhanced measures and enhanced ongoing monitoring. They include:
- A high risk the firm has identified itself, through its own risk assessment or through information supervisors have made available to it.
- A link to a high-risk third country, a term the regulations define by reference to the Financial Action Task Force (FATF) list of jurisdictions subject to a call for action.
- A correspondent relationship, meaning an arrangement where one financial institution provides services to another institution rather than to an end customer.
- A politically exposed person, or a family member or known close associate of one.
- False or stolen identification, where the firm has discovered the customer supplied it and still intends to continue the relationship.
Regulation 37(8) reaches the same point from the other direction. A firm applying simplified measures must stop doing so if it doubts the truthfulness or accuracy of documents or information it already holds, if its risk assessment changes so the relationship is no longer low risk, if it suspects money laundering or terrorist financing, or if any condition in regulation 33(1) applies.
Taken together, these read as switches rather than judgement calls. The judgement lies in noticing that a condition has been met, which is a systems question more than a policy one.
The conditions You Set Yourself
Those listed conditions are the starting point. Above that starting point, it’s your responsibility to assess your firm’s own risks, and set and review your own thresholds based on that. Two questions tend to expose that. When was the risk model last reviewed, and against what evidence.
From a Shufti AML Roundtable“The biggest issue with traditional risk scoring is that it’s largely static, while financial crime is anything but. A genuinely adaptive framework works like a living system. It continuously absorbs new information, it learns from outcomes, and it separates policy from execution, so the institution sets its risk appetite and the system applies it dynamically.”
Umair Hameed, Regional Vice President, Sales, Shufti
What a reviewer looks for afterwards is the link between the trigger and the action. Which condition applied, what changed in the risk profile as a result, and what the additional checks produced. AML screening that runs continuously rather than once at onboarding is what keeps that link current, because a condition met months into a relationship only counts if something is still watching.

How CDD and EDD Compliance Differs in the US and the UK
Both countries reach similar outcomes by different routes, so CDD and EDD compliance work does not transfer cleanly between them.
| Criteria | United States | United Kingdom |
| Where the duty sits | Four core CDD requirements in the FinCEN CDD Rule, applied on a risk basis | Standard measures in regulation 28, enhanced measures in regulation 33 |
| How EDD is set out | Mainly through supervisory expectation rather than one standalone EDD rule | Codified, with a list of conditions that make enhanced measures mandatory |
| A recent change | FinCEN granted exception relief in February 2026 from identifying and verifying beneficial owners at each account opening | The 2026 amendment regulations revise regulations 27, 33 and 37. |
| A dated change ahead | None identified in this review | From 1 February 2027, new regulation 34A applies extra measures, on top of regulation 33, where a cryptoasset exchange provider or custodian wallet provider has or plans a correspondent relationship with a similar provider from a third country |
Firms operating in both countries face a harder version of the same problem. A single global due diligence policy will either apply the UK’s listed conditions to US customers who do not fall under them, or fail to apply them to UK customers who do. The workable answer is one risk framework with country-specific escalation rules layered on it.
How Shufti Helps you Apply the Right Level of Due Diligence
If your escalation rule lives in a policy document while the verification flow that enforces it sits in a development backlog, the two fall out of step. A threshold changes in the policy, the flow catches up several releases later, and real customers pass through the gap.
Shufti’s Journey Builder is a no-code, drag-and-drop tool in the Shufti back office where verification workflows are built and changed. Policies can be set by geography, product, and transaction type. Step-up rules, meaning the extra checks applied once a customer meets a higher-risk condition, can be adjusted without waiting for a release cycle. A changed risk weighting and the flow that applies it therefore move together, and customers meeting the new condition are routed into the deeper checks immediately.
Frequently Asked Questions
Is EDD a separate process from CDD?
No. Under UK regulation 33(1), enhanced measures apply in addition to the standard customer due diligence measures. A firm runs one due diligence process whose depth changes with assessed risk, rather than two processes side by side.
Who decides when a customer moves from CDD to EDD?
The rules decide it wherever a listed condition applies, such as a politically exposed person or a link to a high-risk third country. Above that floor the firm's own risk assessment sets the thresholds, so those thresholds and their review schedule belong to the firm.
Does simplified due diligence remove the need for monitoring?
No. A firm applying simplified measures must still carry out monitoring sufficient to detect unusual or suspicious transactions, and must stop applying those measures if its risk assessment changes or it suspects money laundering.















