Skip to main content
Category: AML and KYC

Enhanced Due Diligence

Also known as:
Simply put

Enhanced Due Diligence (EDD) is a more detailed and rigorous form of background check applied to customers or transactions that are considered higher-risk. It goes beyond standard checks by adding extra investigation and procedures when the risk exceeds normal thresholds. The goal is to help identify and reduce risks such as money laundering associated with high-risk relationships.

Formal definition

Enhanced Due Diligence (EDD) is a heightened level of investigation and ongoing scrutiny applied to financial customers, entities, or transactions that meet defined high-risk criteria. It extends standard customer due diligence by requiring additional checks, more thorough background investigation, and intensified review procedures triggered when assessed risk exceeds established thresholds. EDD is intended to help mitigate risks such as money laundering in higher-risk business relationships, though the specific criteria, procedures, and thresholds depend on the applicable regulatory framework and the institution's risk-based approach.

Why it matters

Enhanced Due Diligence matters because standard customer due diligence is calibrated for typical, lower-risk relationships and may not surface the risks associated with higher-risk customers, entities, or transactions. When a relationship meets defined high-risk criteria, applying only baseline checks can leave an institution exposed to money laundering and related financial crime risks that more rigorous investigation is intended to help identify. EDD provides that additional layer of scrutiny, allowing institutions to gather deeper information and apply intensified review before and during a high-risk relationship.

EDD also supports a risk-based approach, in which resources are concentrated where potential exposure is greatest rather than applied uniformly across all customers. This helps institutions align their controls with the specific risk profile of each relationship and demonstrate that heightened attention was given where warranted. It is important to note that EDD is intended to help mitigate risk, not to eliminate it; the effectiveness of EDD depends on the applicable regulatory framework, the quality of information obtained, and how consistently procedures are applied.

The specific criteria, procedures, and thresholds that trigger EDD vary by regulatory framework and by an institution's own risk-based methodology. Because of this variation, EDD is not a single fixed checklist but a heightened standard of investigation whose exact requirements should be confirmed against the applicable rules and the institution's internal policies.

Who it's relevant to

AML and Compliance Officers
Compliance teams define the high-risk criteria and thresholds that trigger EDD and design the additional checks and review procedures applied to those relationships. They are responsible for ensuring EDD is consistent with the applicable regulatory framework and the institution's risk-based approach.
KYC and Onboarding Teams
Teams responsible for customer due diligence apply EDD during onboarding and throughout the relationship when a customer or entity meets high-risk criteria. They conduct the more thorough background investigation and gather the additional information that EDD requires beyond standard checks.
Fraud and Financial Crime Analysts
Analysts reviewing higher-risk customers and transactions rely on the intensified scrutiny EDD provides to help identify risks such as money laundering. They should recognize that EDD is intended to help mitigate risk rather than guarantee detection, and that its effectiveness depends on the quality of information and consistency of procedures.
Risk Management and Governance Functions
Risk leaders oversee how the risk-based approach allocates heightened scrutiny to high-risk relationships and confirm that EDD thresholds and procedures align with the applicable regulatory framework. They are positioned to review whether EDD is applied consistently where risk exceeds normal thresholds.

Inside EDD

Elevated Identity Verification
Additional steps to confirm the identity of a customer or merchant beyond standard onboarding checks, applied when a relationship presents higher risk. This may include collecting and independently corroborating additional documentation and identifying beneficial owners where applicable.
Source of Funds and Business Legitimacy Review
Assessment intended to understand the nature of the customer's business, expected transaction activity, and the origin of funds, so that observed activity can be compared against a documented expected profile. The rigor of this review scales with assessed risk.
Risk-Based Triggering Criteria
Defined conditions that move a relationship from standard due diligence into EDD, such as high-risk merchant categories, cross-border exposure, or activity inconsistent with the established profile. Criteria should be documented and periodically reviewed rather than assumed fixed.
Enhanced Ongoing Monitoring
More frequent or more granular monitoring of transactions and account behavior for higher-risk relationships, intended to detect deviations from expected activity. Monitoring is a detection control and carries false-positive and false-negative trade-offs; it helps identify anomalies but does not by itself confirm fraud or wrongdoing.
Documentation and Recordkeeping
Retention of the rationale for applying EDD, the evidence gathered, review outcomes, and approval decisions, so that the diligence performed can be demonstrated and re-examined over time.
Escalation and Approval Governance
Defined roles for reviewing EDD findings, escalating unresolved concerns, and approving or declining continuation of a relationship, typically involving senior or specialized risk personnel for higher-risk cases.

Common questions

Answers to the questions practitioners most commonly ask about EDD.

Is Enhanced Due Diligence a PCI DSS requirement?
No. Enhanced Due Diligence is a risk-based customer due diligence concept associated with anti-money laundering (AML) and know-your-customer (KYC) programs, not with PCI DSS. PCI DSS governs the protection of cardholder data and sensitive authentication data within the cardholder data environment; it does not define EDD. EDD obligations typically arise from AML regulations, card brand or network rules, and acquirer or processor onboarding requirements, which vary by jurisdiction and program. Treat the two as separate frameworks and confirm each against its own governing source.
Does performing EDD guarantee that a merchant or customer relationship is free of fraud or money laundering?
No. EDD is intended to help identify and manage elevated risk associated with higher-risk relationships, but it does not eliminate fraud or money laundering. It provides additional information and monitoring to inform risk decisions and may reduce exposure, yet it carries inherent limitations, including reliance on the accuracy of submitted information and the possibility of both false positives and false negatives. EDD supports ongoing risk management rather than providing a one-time assurance.
When should an organization apply EDD instead of standard due diligence?
EDD is generally applied when a relationship or transaction pattern is assessed as higher risk under the organization's risk-based approach. Common triggers can include higher-risk business categories, unusual ownership structures, high-risk geographies, or transaction behavior that deviates from expected patterns. The specific triggers and thresholds should be defined in the organization's own policies and calibrated to applicable regulatory expectations and card brand or network rules, which vary by region and change over time.
What additional information does EDD typically collect beyond standard due diligence?
EDD generally seeks a deeper understanding of the customer or merchant, which may include beneficial ownership details, source of funds or wealth, expected transaction activity, and the nature of the underlying business. The exact data elements depend on the organization's policies and applicable regulations. Any payment-related data collected during onboarding should be handled according to applicable data protection and PCI DSS controls; note that sensitive authentication data must not be stored after authorization even when encrypted.
How does EDD relate to ongoing monitoring rather than one-time onboarding?
EDD is not solely an onboarding step. Higher-risk relationships identified through EDD typically warrant more frequent or intensive ongoing monitoring, periodic reviews, and re-assessment when circumstances change. The cadence and depth of ongoing monitoring should be defined by the organization's risk-based policies and adjusted as risk indicators or applicable requirements evolve.
Who is responsible for performing EDD in a payment ecosystem?
Responsibility depends on the relationship and applicable rules. Acquirers and payment processors commonly perform EDD on higher-risk merchants during onboarding and ongoing monitoring, while financial institutions apply it to customers under AML obligations. Roles and obligations can be allocated through contracts and program rules and vary by region and by card brand or network. Organizations should confirm their specific responsibilities against applicable regulations and their acquirer or processor agreements.

Common misconceptions

EDD is a PCI DSS requirement for protecting cardholder data.
EDD is a risk and due-diligence concept applied to customer or merchant relationships and is distinct from PCI DSS, which governs the protection of account data such as PAN and the prohibition on storing sensitive authentication data after authorization. The two address different objectives and should not be conflated; confirm any specific control obligations against the applicable standard, program, or regulatory source rather than assuming PCI DSS mandates EDD.
Completing EDD confirms a customer or merchant is legitimate and eliminates fraud risk.
EDD is intended to reduce and better understand risk, not to guarantee legitimacy. It may mitigate exposure to certain higher-risk relationships and support detection of anomalies, but it does not prevent fraud such as account takeover, synthetic identity, or first-party fraud, and monitoring outputs still involve false positives and false negatives.
EDD is a one-time step performed at onboarding.
EDD typically includes enhanced ongoing monitoring and periodic reassessment for as long as the relationship is classified as higher risk. Risk profiles and triggering criteria change over time, so diligence is intended to be a continuing process rather than a single checkpoint.

Best practices

Define and document objective, risk-based criteria that trigger EDD, and review those criteria periodically so triggers reflect current risk rather than a fixed, outdated list.
Establish an expected activity profile for each higher-risk relationship and compare observed transactions against it, treating monitoring alerts as indicators to investigate rather than confirmed findings given false-positive and false-negative trade-offs.
Independently corroborate identity, beneficial ownership where applicable, and source-of-funds information rather than relying solely on self-reported data.
Retain clear records of the rationale for applying EDD, the evidence gathered, review outcomes, and approval decisions so the diligence performed can be demonstrated and re-examined.
Implement defined escalation and senior-approval governance for unresolved or high-severity concerns, with authority to decline or exit a relationship.
Schedule periodic reassessment of higher-risk relationships and adjust monitoring intensity as risk changes, treating EDD as an ongoing process rather than a one-time onboarding task.