Pricing
Language
Published 30-09-2024 · Updated 10-09-2026

KYC vs CDD vs EDD: What Is the Difference?

Compare customer due diligence and enhanced due diligence, see how KYC and simplified measures fit, and understand when additional measures may apply.

Share

Customer due diligence (CDD) is the process of understanding a customer and the risk of the relationship. Enhanced due diligence (EDD) means applying additional measures when the applicable law, an identified risk or the organisation's policy requires greater scrutiny. EDD is not a separate identity check, a fixed worldwide checklist or an automatic reason to reject a customer.

KYC, CDD, simplified due diligence and EDD are related terms, but their precise legal meaning depends on the framework that applies to the organisation and relationship.

CDD vs EDD: the difference in one view

QuestionCDDEDD
PurposeEstablish and maintain enough customer and relationship understanding to assess and manage relevant risk.Address a specified legal trigger, uncertainty or higher-risk feature with additional measures.
When usedAs required for the relevant customer, transaction or business relationship.When the governing regime requires it, or when a documented risk assessment or policy calls for added scrutiny.
DepthRisk-sensitive identity, ownership, purpose, expected-activity and ongoing-review measures, as applicable.Additional information, corroboration, approval or monitoring proportionate to the reason for enhancement.
DecisionSupports an informed relationship decision.Supports a more closely evidenced decision; it does not require automatic rejection.
EvidenceRecords the information obtained, checks performed, risk assessment and resulting treatment.Also records the trigger, additional question, extra measures, findings, approval and continuing treatment.

The difference is not simply “fewer documents versus more documents.” Baseline CDD measures establish the relationship understanding required by the applicable framework. EDD adds to or intensifies those measures for a defined reason.

How KYC, CDD and EDD fit together

TermPractical roleWhat it does not decide alone
KYCIdentifying a customer and verifying relevant identity information.The customer's complete risk or whether the relationship is acceptable.
CDDConnecting identity, beneficial ownership or control where relevant, purpose, expected activity, customer risk and ongoing review.Every separate sanctions, reporting or transaction-monitoring obligation.
EDDAdding measures that address a legal trigger, identified risk or unresolved question.A universal document list or final accept-or-reject result.

Organisations sometimes use “KYC” as an umbrella label for the whole onboarding process. The label matters less than ensuring that each required control has a clear purpose, evidence and owner. For the full lifecycle—including KYB, business ownership and relationship decisions—use the KYC, KYB and customer due diligence guide.

What customer due diligence covers

Depending on the customer, product and governing rules, CDD may include:

  • identifying the customer and verifying relevant information;
  • identifying beneficial owners or controllers and understanding the ownership structure where applicable;
  • understanding the purpose and intended nature of the relationship;
  • assessing relevant customer, product, channel and geographic risk;
  • determining the measures, approval and restrictions appropriate to that risk;
  • keeping relevant information current and reviewing activity over the relationship; and
  • retaining enough evidence to explain what was done and why.

CDD is therefore broader than collecting identification documents. It connects reliable customer information to a risk assessment and an authorised relationship decision.

What enhanced due diligence changes

EDD adds scrutiny that responds to a particular reason. Depending on the applicable framework and facts, additional measures might include:

  • obtaining more information about the customer, ownership or purpose of the relationship;
  • corroborating supplied information using reliable and independent sources;
  • establishing or examining source of funds or source of wealth where relevant;
  • seeking additional management approval;
  • examining the rationale for a transaction, structure, geography or delivery channel; or
  • applying more intensive or differently triggered ongoing review.

These are possible measures, not one global package. A defensible EDD record connects the trigger to the question being investigated, the additional work performed and the resulting decision.

When can enhanced due diligence be required?

There is no single worldwide trigger list. Separate three questions:

  1. Legal trigger: does the law applying to the organisation and relationship require enhanced measures for this circumstance?
  2. Risk indicator: does the evidence show a higher or less understood money-laundering or terrorist-financing risk that needs further work?
  3. Internal trigger: does the organisation's approved methodology or policy require escalation, evidence or approval beyond the legal minimum?

The UK's Money Laundering Regulations, for example, contain separate provisions for general CDD, enhanced CDD and PEPs for relevant persons within scope.1 This is a UK example, not a global trigger framework.

FATF's Recommendations provide an international standard implemented through national systems. FATF recognises that countries have different legal, administrative and operational frameworks, so its Recommendations are not a single directly binding worldwide checklist.2

FATF also states that inclusion on its list of jurisdictions under increased monitoring—the “grey list”—does not itself mean that enhanced due diligence should automatically be applied to all connected relationships.3

Where simplified due diligence fits

Some legal frameworks permit simplified due diligence (SDD) where the applicable conditions are met and lower risk has been established. Simplified does not mean no due diligence, and it should not be treated as a permanent customer label.

TreatmentControl question
Simplified measuresDoes the applicable framework permit reduced measures for this demonstrably lower-risk situation?
Normal or standard CDDWhat measures are required to understand and manage the relationship under its assessed risk?
EDDWhat additional measures address the relevant legal trigger, higher risk or uncertainty?

Terminology differs. Spain's Ley 10/2010, for example, uses medidas normales, medidas simplificadas and medidas reforzadas de diligencia debida and separately includes ongoing monitoring within normal due diligence.4 The Spanish wording should not be reduced to English acronyms.

PEPs and enhanced due diligence

A potential politically exposed person (PEP) result starts an identity and status review; it does not by itself establish that the customer is high risk, suspicious or unacceptable. Applicable PEP definitions and measures differ by jurisdiction and category.

PEP candidate → identity and role resolution → applicable PEP classification → customer-risk assessment → required approval and measures → relationship decision

FATF treats PEP measures as preventive and says PEP status should not be interpreted as implying criminal activity.5 For detailed operational and jurisdictional treatment, use the PEP screening guide.

Customer risk assessment and EDD

A customer risk assessment can help determine the intensity of due diligence, but a score should not become a legal verdict. The assessment should identify the factors driving the result and map them to proportionate treatment, qualified review and an authorised decision.

“High risk” should not automatically produce the same five documents for every customer. The extra work should answer the actual risk or legal question. The AML customer risk assessment methodology explains how to connect factors, rules, overrides and treatment while preserving decision ownership.

What happens after EDD?

EDD is not necessarily the end of the process. The organisation may need to keep customer information current, review whether the trigger or risk has changed, examine relevant activity and revisit the relationship under the applicable framework and its policy.

  • Ongoing CDD keeps customer and relationship understanding current.
  • Sanctions and PEP re-screening checks configured records against relevant data changes.
  • Transaction monitoring examines behavioural or transaction activity under a separate control design.

Checklynx ongoing monitoring supports configured sanctions, PEP and other watchlist re-screening. It is not behavioural transaction monitoring and does not decide whether EDD is legally required.

How technology can support CDD and EDD workflows

Technology can support individual controls without performing the whole CDD or EDD process.

Workflow needHow Checklynx can support itDecision that remains with the organisation
Customer-risk assessmentApply an approved, configured methodology and retain factors, results and review evidence.Risk methodology, legal interpretation, overrides and final treatment.
Sanctions and PEP screeningCompare supplied customer and related-party data with relevant sources and generate candidates for review.Identity resolution, legal status, EDD implications and relationship outcome.
Ongoing re-screeningRe-screen configured records when relevant source information changes and route new results for review.Population, trigger policy, investigation and response.
Case handlingAssign candidates and record notes, evidence, rationale and escalation.The substantive investigation and authorised decision.
Audit evidencePreserve screening and case activity so the process can be reconstructed.Whether the complete CDD file and legal conclusion are sufficient.

Checklynx does not independently verify identity documents, discover or verify every beneficial owner, verify source of funds or wealth, perform complete CDD or EDD, determine that EDD is legally required, approve a customer or guarantee compliance.

Frequently asked questions

What is the main difference between CDD and EDD?

CDD establishes and maintains the risk-based understanding needed for a customer relationship. EDD applies additional measures to address a legal trigger, higher risk or unresolved question. The measures depend on the framework and facts.

Is EDD required for every high-risk customer?

That cannot be answered globally. The organisation must distinguish binding legal triggers from risk indicators and its own policy triggers. Where EDD is required or selected, the measures should address the reason for enhancement.

Is EDD the same as ongoing monitoring?

No. Enhanced monitoring may be one EDD measure in some circumstances, but ongoing CDD can also apply outside EDD. Sanctions or PEP re-screening and behavioural transaction monitoring are separate controls.

Does a PEP match automatically require EDD?

A database match does not. First resolve identity, role and the applicable PEP definition. Then apply the measures required by the governing framework and the organisation's risk methodology. PEP status is not an automatic rejection rule.

Is sanctions screening part of EDD?

Sanctions screening may be used within a broader customer-control workflow, but it answers a separate legal question. A sanctions candidate is not proof of identity or legal effect. See the practical sanctions-screening guide.

Can software automate EDD?

Technology in a broader CDD stack can support data collection, configured risk assessment, screening, re-screening, case routing and evidence. It cannot safely be described as completing every investigation or making the organisation's legal and relationship decisions.

KYC, CDD and EDD comparison

Official sources

Footnotes

  1. UK legislation, Money Laundering Regulations 2017: Regulation 28, Regulation 33 and Regulation 35; binding UK law for relevant persons within scope, accessed 10 September 2026. ↩

  2. Financial Action Task Force, The FATF Recommendations, international standards implemented through national systems, amended June 2026, accessed 10 September 2026. ↩

  3. Financial Action Task Force, Jurisdictions under Increased Monitoring — 19 June 2026, FATF public statement explaining that increased monitoring does not itself call for EDD, accessed 10 September 2026. ↩

  4. Spain, Ley 10/2010, consolidated text, especially Chapter II and Articles 6 and 9–11; binding Spanish law for obliged entities within scope, accessed 10 September 2026. ↩

  5. Financial Action Task Force, Guidance: Politically Exposed Persons (Recommendations 12 and 22), international-standard guidance, June 2013, accessed 10 September 2026. ↩

Share
knowledge base

Footer

CDD vs EDD: KYC and Due Diligence Explained