Enhanced Due Diligence & AML

Enhanced Due Diligence (EDD): Meaning, Requirements & Process

Enhanced Due Diligence (EDD) explained: definition, CDD vs EDD, when it's required in Canada and the U.S., a practical process, checklist, and questionnaire.

On this page
Get Expert Help

Key takeaways

  • Enhanced Due Diligence (EDD) is deeper customer review used when a relationship, transaction, or activity presents elevated financial-crime risk.
  • EDD requirements differ by jurisdiction: FINTRAC imposes enhanced measures for high-risk Canadian relationships, while U.S. BSA/FinCEN rules contain specific EDD obligations in defined contexts.
  • A practical EDD process should document the trigger, additional verification, ownership and source-of-funds review where applicable, escalation, and enhanced monitoring.
  • CDD and EDD are related but not identical: baseline CDD establishes the customer relationship and risk context, while EDD deepens the review when enhanced scrutiny is warranted.
  • Effective EDD procedures should be risk-based, supported by evidence, and connected to ongoing monitoring and independent testing.

Enhanced Due Diligence (EDD) is a deeper level of customer review used when a relationship or activity presents elevated money laundering, terrorist financing, sanctions, or other relevant financial-crime risk. EDD stands for Enhanced Due Diligence, and it builds on the standard customer due diligence every regulated business already performs β€” it doesn't replace it.

What Is Enhanced Due Diligence (EDD)?

A useful enhanced due diligence definition is additional scrutiny applied to a business relationship, customer, or transaction once standard due diligence indicates a level of risk that calls for closer review. The enhanced due diligence meaning is closely tied to depth: where routine customer due diligence confirms who a customer is, EDD goes further into understanding why they're transacting, where their funds come from, and whether their actual behaviour matches what was expected at onboarding.

What makes EDD different from routine review isn't a different set of forms β€” it's a different level of analysis. Baseline CDD establishes identity, verification, the nature and purpose of the relationship, and an initial understanding of risk. EDD deepens that analysis when additional scrutiny is warranted: more sources, more corroboration, and a more deliberate judgment about whether a relationship's actual risk is understood and manageable.

Why Enhanced Due Diligence Is Used in AML

EDD exists because a one-size-fits-all level of scrutiny doesn't match a one-size-fits-all level of risk. A business's inherent risk assessment identifies which customers, products, geographies, and transaction patterns carry more exposure before any controls are applied; EDD is one of the controls that responds when a specific relationship lands on the higher end of that assessment. The chain runs: risk assessment identifies a higher-risk relationship, which triggers additional scrutiny, which gets documented, and which then feeds into ongoing monitoring calibrated to what was found.

EDD is not simply "collect more documents." A file full of extra paperwork that nobody analyzed doesn't reduce risk β€” it just creates the appearance of diligence. The actual purpose of EDD is to understand and manage the specific risk identified in a relationship: to reach a reasoned view of whether the business relationship makes sense, whether the funds involved are plausible, and what ongoing scrutiny that relationship needs going forward.

Customer Due Diligence vs. Enhanced Due Diligence

CDD and EDD sit on the same spectrum rather than being two unrelated processes β€” EDD is what customer due diligence becomes once a relationship's risk profile calls for it. Enhanced customer due diligence is not a separate regime; it's standard CDD extended further in specific dimensions. Note that exactly how CDD and EDD operate, and what specifically counts as "enhanced," varies by jurisdiction and regulatory framework β€” the comparison below describes the general pattern, not a single global rule.

Factor Customer Due Diligence (CDD) Enhanced Due Diligence (EDD)
Purpose Confirm identity and establish a baseline understanding of the relationship Understand and manage a specific, elevated risk within the relationship
Depth of review Standard identification, verification, and basic risk categorization Deeper investigation into the customer, its ownership, and its activity
Risk level Baseline due diligence applied as required under the relevant customer-identification and CDD framework Additional scrutiny applied when the applicable framework or assessed risk calls for enhanced measures
Information collected Identity details, basic business or occupation information Additional detail on purpose, expected activity, ownership structure, and often source of funds
Verification depth Verify identity against a permitted source Independent, corroborating verification from multiple sources where warranted
Source of funds / wealth Not typically required as a matter of course Often reviewed where risk and applicable regulatory requirements call for it
Approval / escalation Handled through standard onboarding workflow May require escalation to a compliance officer or senior management, depending on the business and jurisdiction
Monitoring Standard, risk-based ongoing monitoring Enhanced ongoing monitoring calibrated to the specific risk identified
Review frequency / intensity Set by the business's general risk-based schedule Typically more frequent and more detailed than standard review cycles

When Is Enhanced Due Diligence Required?

There's no single global rule that determines when EDD applies. Enhanced due diligence requirements vary by jurisdiction, customer risk, activity, and the regulatory framework that applies to the business. What follows separates Canada and the United States deliberately, because the two frameworks are related in spirit but not identical in mechanics.

Enhanced Due Diligence Under FINTRAC in Canada

Under the Proceeds of Crime (Money Laundering) and Terrorist Financing Act (PCMLTFA) and its Regulations, a reporting entity that identifies a client as posing a high risk in its own risk assessment must take enhanced measures and conduct enhanced ongoing monitoring of that business relationship. This is a direct regulatory obligation, not merely a suggestion β€” but FINTRAC does not prescribe one fixed checklist of what "enhanced measures" must look like in every case; the specific steps are risk-based and business-specific.

FINTRAC's PEP/HIO requirements vary by reporting-entity sector and by whether the obligation arises from an account, business relationship, or prescribed transaction. For account-based sectors, foreign PEP determinations can trigger requirements such as establishing source of funds or virtual currency and source of wealth, senior-management approval to keep an account open, and enhanced measures. For non-account-based sectors such as MSBs, foreign PEP business relationships generally require source-of-wealth measures and enhanced measures, while additional source-of-funds and senior-management review requirements apply to certain prescribed transactions. Domestic PEP/HIO measures remain risk-assessment-driven where FINTRAC requires a high-risk determination.

Domestic PEPs, HIOs, and their family members or close associates are treated differently. A business must have a process to determine whether a client falls into one of these categories, but the additional measures β€” establishing source of funds and source of wealth, obtaining senior management review or approval, and applying enhanced measures including enhanced ongoing monitoring β€” only apply where the business's own risk assessment concludes there is a high risk of a money laundering or terrorist activity financing offence. If that risk assessment does not reach a high-risk conclusion, FINTRAC guidance does not require those additional PEP/HIO-specific measures. In short: foreign PEP treatment is largely prescribed; domestic PEP/HIO treatment is risk-assessment-driven.

For the fuller picture of how these obligations connect to registration, ongoing KYC, and reporting, see ComplyFactor's PCMLTFA requirements guide.

Enhanced Due Diligence in U.S. BSA/AML Compliance

In the United States, there is no single statutory "EDD rule" that applies identically across every type of financial business β€” but U.S. law does contain specific enhanced-diligence requirements in defined contexts under the Bank Secrecy Act (BSA), implementing Section 312 of the USA PATRIOT Act. Certain foreign correspondent accounts can trigger explicit enhanced due diligence requirements: covered financial institutions must apply a special, enhanced due diligence program to correspondent accounts they maintain for foreign banks operating under an offshore banking licence, a licence from a jurisdiction designated as non-cooperative with international AML standards, or a licence from a jurisdiction the Secretary of the Treasury has otherwise designated of concern. Separately, private banking accounts maintained in the United States for non-U.S. persons are subject to their own special due-diligence-program requirement β€” identifying nominal and beneficial owners and reasonably understanding the sources of funds involved β€” regardless of whether any particular red flag has been raised. A further, more targeted layer of enhanced scrutiny applies on top of that baseline specifically where a senior foreign political figure is a nominal or beneficial owner of the private banking account, requiring the institution to watch for transactions that may involve the proceeds of foreign corruption. Not every private banking account for a non-U.S. person triggers this heightened senior-foreign-political-figure scrutiny β€” it applies specifically where that person is involved.

For covered financial institutions subject to FinCEN's 2016 CDD Rule β€” including banks, federally insured credit unions, mutual funds, broker-dealers, futures commission merchants, and introducing brokers β€” the rule requires beneficial-owner identification and verification for legal-entity customers, an understanding of the nature and purpose of customer relationships, and risk-based ongoing monitoring. MSBs are not covered institutions under the 2016 CDD Rule. Their AML program obligations arise separately under 31 CFR 1022.210 and must be commensurate with the risks posed by the MSB's location, size, and the nature and volume of its financial services. FinCEN guidance also states that each MSB should identify and assess the money laundering risks associated with its unique products, services, customers, and geographic locations.

The CDD Rule itself has moved since 2016. In February 2026, FinCEN issued exceptive relief (FIN-2026-R001) narrowing when covered institutions must re-identify and re-verify the beneficial owners of an existing legal entity customer: rather than repeating that step at every new account opening, institutions may limit it to the customer's first account opening, situations where the institution has knowledge of facts calling the previously obtained information into question, and other points its own risk-based ongoing CDD procedures call for. This is a narrow, mechanical change to a specific re-verification trigger β€” it does not eliminate the broader CDD obligation, and the underlying requirements to identify and verify beneficial owners, understand the relationship, and conduct ongoing monitoring remain fully in force.

It's worth being precise about what's current law versus what's proposed. FinCEN has an active rulemaking process (a Notice of Proposed Rulemaking issued in April 2026, superseding an earlier 2024 proposal) that would formalize a documented risk-assessment process across a broader range of BSA-covered institutions. That proposal is not yet final and shouldn't be treated as a binding requirement for any specific institution type today. The FFIEC BSA/AML Examination Manual describes supervisory expectations for enhanced due diligence on higher-risk customers in detail, but it's written primarily for the examination of banks, savings associations, and credit unions β€” useful context for an MSB or fintech, but not the controlling standard for a business that isn't examined under that framework.

What Can Trigger Enhanced Due Diligence?

The following factors commonly prompt a business to consider EDD. None of them, on its own, should automatically produce a high-risk determination unless a specific law or regulation requires that treatment β€” each is an input a risk-based assessment weighs, not an automatic verdict.

Complex or opaque ownership structures β€” see ComplyFactor's beneficial ownership verification guide for how this is investigated in practice

  • Unusual customer activity relative to the expected profile
  • Higher-risk geographic exposure, including jurisdictions with weak AML/CFT frameworks
  • Cross-border activity, particularly through multiple intermediary jurisdictions
  • PEP or HIO status, where applicable under the governing framework

Activity conducted through, or apparently on behalf of, an undisclosed third party β€” see ComplyFactor's third-party determination guide for the underlying question set

  • Source-of-funds concerns that don't reconcile with the customer's stated profile
  • Material changes in customer behaviour over the life of a relationship
  • Higher-risk products, services, or delivery channels
  • Negative or adverse information, weighed for relevance rather than treated as automatic proof of wrongdoing
  • Sanctions exposure, including connections to sanctioned jurisdictions, persons, or entities

Enhanced Due Diligence Process

The sequence below reflects a practical approach used across regulated financial businesses. It should be adapted to the specific requirements that actually apply in a given jurisdiction β€” treating it as a rigid universal checklist would miss the point that EDD is meant to be risk-based.

1. Identify the specific reason EDD is required for this relationship or transaction

2. Review the customer's existing risk profile and what triggered the elevated rating

3. Collect additional customer information beyond what standard CDD already captured

4. Verify identity and beneficial ownership to the depth the risk warrants

5. Understand the purpose and intended nature of the relationship in concrete terms

6. Review source of funds and, where applicable, source of wealth

7. Investigate the relevant geographic, business, ownership, or transaction risks identified

8. Document findings and the reasoning behind the resulting risk decision

9. Obtain additional approval or escalation where the business's own procedures or applicable regulation require it

10. Establish enhanced ongoing monitoring calibrated to what was found

11. Set an appropriate review trigger or review cycle for the relationship going forward

Enhanced Due Diligence Checklist

This is a general operational checklist, not a substitute for jurisdiction-specific legal requirements β€” use it as a working reference, then confirm what actually applies under the regulation governing your business.

  • Customer identity is current and verified
  • Beneficial ownership has been reviewed and verified to the depth warranted
  • Purpose of the relationship is documented in concrete terms
  • Expected account or activity profile is documented
  • Customer risk factors have been assessed and recorded
  • Source of funds has been reviewed where applicable
  • Source of wealth has been reviewed where applicable
  • PEP/HIO status has been addressed where applicable
  • Geographic exposure has been reviewed
  • Relevant adverse information has been considered and weighed
  • Sanctions concerns have been addressed
  • The specific reason EDD was triggered is documented
  • Escalation or approval has been completed where required
  • Enhanced monitoring parameters have been documented
  • Follow-up or review triggers have been established
  • Evidence and rationale supporting the decision have been retained

What Should an Enhanced Due Diligence Questionnaire Cover?

An EDD questionnaire is a tool for structuring the conversation and the file, not a one-size-fits-all legal template β€” the right questions depend on the customer type, the product, and the jurisdiction. Practical example questions include:

  • What is the purpose of the relationship?
  • What products or services will the customer use?
  • What transaction volumes and values are expected?
  • What jurisdictions will funds move to or from?
  • Who owns or controls the customer?
  • What is the source of funds?
  • What is the source of wealth, where relevant?
  • What counterparties or customer types does the business itself serve?

Enhanced Ongoing Monitoring After EDD

EDD isn't a one-time event that ends at onboarding β€” a relationship rated higher risk needs monitoring that reflects that rating for as long as the relationship continues. Enhanced ongoing monitoring typically means closer attention to transaction activity relative to the expected profile, faster follow-up when a customer's information changes, and a lower tolerance for unexplained deviations from what was documented at onboarding.

Specific triggers for revisiting an EDD file include changes in expected activity, updates to customer information, ownership changes, new geographic exposure the original assessment didn't anticipate, and any change in the customer's overall risk rating. The intensity of monitoring should track the actual risk β€” a relationship that has settled into a stable, well-understood pattern doesn't need the same scrutiny as one still generating open questions.

Common Enhanced Due Diligence Mistakes

  • Treating EDD as a one-time document-collection exercise β€” the value is in ongoing understanding, not a completed folder
  • Collecting source-of-funds documents without analyzing whether they actually make sense β€” unread documents provide no protection
  • Using the same procedure for every higher-risk customer regardless of why each one was flagged β€” different triggers call for different scrutiny
  • Failing to document why EDD was triggered in the first place β€” a file with no stated reason is difficult to defend later
  • Failing to document why the relationship was ultimately approved β€” the approval reasoning matters as much as the review itself
  • Performing EDD at onboarding but leaving ongoing monitoring unchanged β€” this defeats the purpose of the elevated rating
  • Treating adverse information as automatic proof of wrongdoing rather than one input to weigh against the full picture
  • Failing to update the customer's risk rating after EDD findings change the picture
  • Relying on generic templates without adapting them to the actual business relationship in front of the reviewer

How EDD Fits Into a Risk-Based AML Program

EDD isn't a standalone procedure β€” it's one link in a chain that starts with the business risk assessment and ends with independent testing: business risk assessment leads to a customer risk rating, which triggers EDD where warranted, which produces enhanced controls, which feed enhanced ongoing monitoring, which is in turn tested through independent review. A risk-based AML program is built so that each of these links actually connects to the next β€” a customer risk-rating framework that doesn't drive real EDD triggers, or EDD findings that never reach the monitoring team, breaks the chain regardless of how good any single piece looks on its own.

Written enhanced due diligence procedures should define the triggers, additional review steps, escalation requirements, documentation standards, and ongoing monitoring expected for higher-risk relationships. Leaving these undefined pushes the judgment call onto whichever staff member happens to handle a given file, which is exactly the inconsistency an examiner or auditor tends to find first.

Whether that chain is actually working in practice is exactly what an independent AML audit tests β€” sampling EDD files to confirm the reasoning is documented, the escalation happened where it should have, and the resulting monitoring reflects the risk that was found.

Enhanced Due Diligence FAQs

Is enhanced due diligence the same as enhanced monitoring?

No. EDD is the deeper review conducted at onboarding or when a risk trigger arises β€” a point-in-time or trigger-driven process. Enhanced monitoring is the ongoing surveillance that follows, calibrated to what the EDD review found. EDD without a corresponding change in monitoring intensity is incomplete.

Does EDD always require source of wealth verification?

No. Whether source of wealth needs to be established depends on the jurisdiction, the customer type, the assessed risk, and the specific regulatory requirement in play. In Canada, it's prescribed for foreign PEPs and their family members or close associates, and required for domestic PEPs/HIOs only where the reporting entity's own risk assessment concludes there is a high risk. In the U.S., it applies in defined contexts such as private banking accounts. It isn't a universal element of every EDD file in every jurisdiction.

Can EDD apply to a transaction even if the customer is not already rated high risk?

Yes, depending on the applicable framework and the facts. A specific transaction or a detected fact β€” an unusual pattern, a jurisdiction change, an adverse-information hit β€” can warrant additional review in its own right, even where the overall customer relationship hadn't previously been classified as high risk. The trigger can be transaction-specific rather than only relationship-wide.

What evidence should an EDD file retain?

A defensible EDD file documents the reason EDD was triggered, the information reviewed, any corroborating evidence obtained, the findings, the rationale behind the resulting decision, escalation or approval records where applicable, and any resulting changes to ongoing monitoring. A rating with no supporting file behind it is difficult to defend later, regardless of how sound the underlying judgment actually was.

Can EDD result in declining or exiting a customer relationship?

It can, but EDD informs a risk decision rather than automatically producing one outcome. Whether a relationship proceeds, continues with added conditions, or is declined or exited depends on the specific findings, the institution's own risk appetite, and any applicable legal or regulatory obligations β€” EDD is the analysis that supports that decision, not a verdict in itself.

Building EDD procedures that actually work under regulatory review starts with the risk framework behind them. ComplyFactor's AML advisory support helps MSBs, PSPs, fintechs, and other regulated businesses review their customer-risk frameworks, design or improve EDD procedures, align EDD with the rest of the AML program, and remediate weaknesses where they're found.

ComplyFactor Advisory Team

ComplyFactor specializes in FINTRAC MSB and PSP registration, independent AML effectiveness reviews, and compliance program design for Canadian and foreign money services businesses, payment service providers, fintechs, and virtual asset service providers.

Get started

Book a free Canada AML consultation

Tell us about your business and we'll confirm which services you need β€” free, no obligation, 30 minutes.

Free, no obligation, 30 minutes
Senior consultant on every engagement
Aligned with PCMLTFA & FINTRAC standards
+1 807 806 0444 Β· Suite 211, 320 Matheson Blvd West, Mississauga, ON

Talk to an AML expert

Thank you. Your message has been received β€” we'll be in touch within one business day.
Something went wrong while submitting the form. Please try again.