Risk & Compliance

Enhanced due diligence (EDD): when and how

When enhanced due diligence is required under the Money Laundering Regulations 2017, the measures it involves, and how it differs from standard CDD.

Enhanced due diligence (EDD): when and how

Enhanced due diligence, usually shortened to EDD, is the deeper level of customer scrutiny that firms must apply when a relationship or transaction presents a higher risk of money laundering or terrorist financing. It sits above standard customer due diligence (CDD), and it is not optional. Regulation 33 of the Money Laundering Regulations 2017 requires firms to apply enhanced customer due diligence measures and enhanced ongoing monitoring to manage and mitigate the risks arising in defined high-risk situations.

The difference between CDD and EDD is one of depth and certainty rather than of category. Standard CDD, set out in regulation 28, requires a firm to identify and verify the customer, identify the beneficial owner and take reasonable measures to verify their identity, and assess the purpose and intended nature of the relationship. EDD builds on that baseline. The FCA's Financial Crime Guide states that EDD should give firms a greater understanding of the customer and their associated risk than standard due diligence, and should provide more certainty that the customer or beneficial owner is who they say they are and that the purposes of the business relationship are legitimate.

This guide sets out when EDD is required under UK law, the specific measures it involves, and how firms can carry it out in a way that stands up to supervisory scrutiny. Every rule referenced here is drawn from the Money Laundering Regulations 2017 or the FCA's published guidance.

Protect customersReduce risk and prevent harm
Meet obligationsStay aligned with laws and standards
Build trustStrengthen confidence with stakeholders
Improve decisionsUse insight to prioritise and act
Drive efficiencyStreamline audits and reporting

What EDD is and how it differs from standard CDD

Standard customer due diligence is the floor. Under regulation 28, a firm must identify the customer and verify their identity from a reliable and independent source, identify the beneficial owner and take reasonable measures to verify who that person is, and assess and where appropriate obtain information on the purpose and intended nature of the relationship. The extent of those measures can be adjusted on a risk-sensitive basis, but the three core steps apply to almost every customer.

Enhanced due diligence does not replace these steps; it intensifies them. The FCA's Financial Crime Guide explains that the extent of EDD must be commensurate to the risk associated with the relationship or transaction, and that firms can decide in most cases which aspects of CDD they should enhance, depending on the reason the relationship was classified as high risk. In practice this means gathering more information, verifying it from more robust and independent sources, and monitoring the relationship more closely once it is live.

A recurring failure the FCA identified in its April 2026 review of firms' customer due diligence processes was firms not evidencing how their approach differed between low-risk and high-risk customers. If a firm cannot show what it did differently for a high-risk case, it has not applied EDD in a way it can defend.

When EDD is required: the triggers in law

Regulation 33(1) sets out the situations in which a firm must apply enhanced customer due diligence measures and enhanced ongoing monitoring. These are not matters of discretion. Where any of these circumstances applies, EDD is mandatory, and the firm must be able to demonstrate that the extent of the measures it applied was commensurate with the money laundering and terrorist financing risk.

The table below summarises the main statutory triggers and the corresponding measures. Alongside these specific scenarios, regulation 33(1)(g) provides a catch-all: any other case which by its nature can present a higher risk of money laundering or terrorist financing. This means the list of named triggers is a floor, not a ceiling, and a firm's own risk assessment under regulation 18 may surface further high-risk situations that warrant EDD. Building this logic into a documented, risk-based control framework is what turns the regulation into a repeatable process rather than a case-by-case judgement call.

EDD triggerSourceCorresponding measures
Any case the firm has identified as high risk, or that regulations 17(9) and 47 flag as higher riskReg 33(1)(a)Additional information on the customer and business relationship; enhanced monitoring proportionate to the assessed risk
A business relationship or transaction where a party is established in a high-risk third country (a country named on the FATF lists)Reg 33(1)(b), 33(3A)Additional information on customer and beneficial owner, nature of the relationship, source of funds and wealth, reasons for the transaction, senior management approval, enhanced monitoring
A correspondent relationship with a credit or financial institution from a third countryReg 33(1)(c), Reg 34Regulation 33 EDD plus the additional correspondent measures in regulation 34, including senior management approval before establishing the relationship
The customer or beneficial owner is a PEP, family member or known close associateReg 33(1)(d), Reg 35Senior management approval; establish source of wealth and source of funds; enhanced ongoing monitoring
The customer has provided false or stolen documentation and the firm proposes to continue dealingReg 33(1)(e)Enhanced verification and scrutiny before continuing
Transactions that are unusually complex or large, follow an unusual pattern, or have no apparent economic or legal purposeReg 33(1)(f)Examine the background and purpose of the transaction; increase the degree and nature of monitoring to determine whether it appears suspicious
The main statutory EDD triggers under regulation 33 of the Money Laundering Regulations 2017 and the measures each requires.

Politically exposed persons: a distinct EDD regime

PEPs are treated as a category of their own under regulation 35 because their public function creates an inherent risk that they could abuse it for private gain. A PEP is defined in regulation 35(12) as an individual entrusted with prominent public functions, other than as a middle-ranking or more junior official. The regime extends to family members, defined to include a spouse or civil partner, children and their spouses or civil partners, and parents, and to known close associates.

Where a firm proposes to establish or continue a relationship with a PEP, a family member or a known close associate, regulation 35(5) requires three things: approval from senior management for establishing or continuing the relationship; adequate measures to establish the source of wealth and source of funds involved; and enhanced ongoing monitoring of the relationship. These apply even where an existing customer becomes a PEP after onboarding.

The measures are applied on a risk-sensitive basis. Regulation 35(3) requires the firm to assess the level of risk associated with the customer and calibrate the extent of the EDD accordingly, and regulation 35(4) allows firms to have regard to guidance issued by the FCA or another supervisory authority. When a person stops being entrusted with their public function, regulation 35(9) requires the firm to keep applying these measures for at least 12 months afterwards, on a risk-sensitive basis. Once that status ends, regulation 35(11) provides that the requirements no longer need to be applied to their family members or known close associates.

Source of funds and source of wealth

Two of the most commonly conflated concepts in EDD are source of funds and source of wealth. The FCA's Financial Crime Guide keeps them distinct. Source of wealth describes how a customer or beneficial owner acquired their total wealth. Source of funds refers to the origin of the funds involved in the specific business relationship or transaction, including the activity that generated them, such as salary payments or sale proceeds, and the means by which they were transferred.

Establishing both is a mandatory requirement where the customer is a PEP, under regulation 35(5), and it is a specified measure for high-risk third country situations under regulation 33(3A). The FCG lists two of the core examples of EDD as establishing how the customer or beneficial owner acquired their wealth to be satisfied that it is legitimate, and establishing the source of their funds to be satisfied that they do not constitute the proceeds of crime.

The FCA treats failure to distinguish the two as poor practice. Its guide gives, as an example of poor practice, a firm that does not distinguish between the customer's source of funds and their source of wealth, and separately, a firm that grants waivers from establishing source of funds or source of wealth without good reason. A firm that collects statements showing where money for one transaction came from has evidenced source of funds; it has not necessarily explained how the customer became wealthy in the first place.

Source of funds and source of wealth

How to carry out EDD in practice

EDD is a process, not a document. The FCA's guide frames it around a set of examples: obtaining more information about the customer's or beneficial owner's business; obtaining more robust verification of the beneficial owner's identity from a reliable and independent source; gaining a better understanding of the customer's reputation or role in public life; carrying out searches on a corporate customer's directors or controllers; establishing source of wealth; and establishing source of funds. The steps below turn those examples into an ordered workflow that maps onto the statutory measures.

The FCA also warns against thin evidence. Its guide flags, as poor practice, relying entirely on a single source of information for EDD, and treating annual reviews of high-risk customers as a tick-box exercise by copying information from previous reviews without thought. Good EDD complements staff knowledge with more objective information and documents the reasoning so it can be challenged later. Firms that link EDD to payment flows and transaction screening can surface the unusual activity that regulation 33(1)(f) is concerned with, and feeding enhanced alerts into a monitoring workflow is one way to do that.

1
Confirm the trigger
Record which regulation 33 or 35 situation applies and why the case is high risk.
2
Deepen verification
Verify customer and beneficial owner identity from additional reliable, independent sources.
3
Establish source of wealth
Understand and document how the customer acquired their overall wealth.
4
Establish source of funds
Trace the origin of the funds involved in the relationship or transaction.
5
Assess purpose and background
Examine the background and purpose of unusual, complex or large transactions.
6
Obtain senior approval
Get senior management sign-off before onboarding PEPs, correspondents and high-risk cases.
7
Enhance ongoing monitoring
Apply lower alert thresholds and independent, more frequent reviews of the relationship.

Core EDD measures required by law

The specified enhanced due diligence measures set out in regulations 33 and 35 for high-risk and PEP situations.

Core EDD measures required by law
100Total %
Additional information on customer and beneficial owner25%
Source of funds and source of wealth25%
Senior management approval25%
Enhanced ongoing monitoring25%

Correspondent relationships and high-risk third countries

Two triggers carry extra weight and deserve separate attention. Where a UK credit or financial institution enters a correspondent relationship with a respondent institution from a third country, regulation 34 layers additional measures on top of the regulation 33 EDD. The FCA's guide notes that these can include thoroughly understanding the correspondent's business, reputation and the quality of its defences against money laundering and terrorist financing, and that senior management must approve the relationship before it is established. The guide treats reliance on a single questionnaire, or inadequate due diligence on a respondent's parents and affiliates, as poor practice.

For high-risk third countries, regulation 33(3)(a) defines the relevant list by reference to the countries named on the Financial Action Task Force's list of High-Risk Jurisdictions subject to a Call for Action, as that list has effect from time to time. Because the list changes, firms cannot hard-code it once and forget it; they must track FATF updates and adjust their EDD triggers accordingly. In these situations, regulation 33(3A) specifies the measures: additional information on the customer, the beneficial owner, the nature of the relationship, source of funds and wealth, and the reasons for the transaction, plus senior management approval and enhanced monitoring.

Conclusion

Enhanced due diligence is the mechanism the Money Laundering Regulations 2017 use to make sure the highest-risk relationships receive the deepest scrutiny. The triggers are set out clearly in regulation 33, with a separate and stricter regime for PEPs in regulation 35 and additional measures for correspondent banking in regulation 34. The measures themselves are consistent across the triggers: more information, verified from more robust sources; a proper understanding of source of funds and source of wealth; senior management approval; and enhanced ongoing monitoring calibrated to the assessed risk.

The difference between a firm that passes supervisory scrutiny and one that does not is rarely the absence of a policy. As the FCA's April 2026 review showed, it is usually the failure to evidence what was done differently for a high-risk case, or the failure to distinguish source of funds from source of wealth. Treating EDD as a documented, risk-sensitive process, rather than a form to complete, is what keeps a firm on the right side of the regulations. To see how a structured control and monitoring framework supports this in practice, request a demo.

Frequently asked questions

When is enhanced due diligence legally required?

Regulation 33(1) of the Money Laundering Regulations 2017 requires EDD in defined high-risk situations: any case the firm assesses as high risk, dealings involving high-risk third countries named on the FATF lists, correspondent relationships with third-country institutions, PEPs and their family members and close associates, cases involving false or stolen documentation, unusually complex or large transactions with no apparent purpose, and any other case that by its nature presents a higher risk.

How does EDD differ from standard CDD?

Standard CDD under regulation 28 requires identifying and verifying the customer, identifying and taking reasonable measures to verify the beneficial owner, and assessing the purpose of the relationship. EDD builds on that baseline. The FCA states that EDD should give firms a greater understanding of the customer and more certainty that they are who they say they are and that the relationship's purpose is legitimate, through additional information, more robust verification and closer monitoring.

What measures does EDD involve?

For high-risk third country and PEP situations, regulations 33(3A) and 35(5) specify measures including additional information on the customer and beneficial owner, establishing source of funds and source of wealth, obtaining senior management approval, and conducting enhanced ongoing monitoring. For unusual or complex transactions, regulation 33(4) requires examining the background and purpose of the transaction and increasing the degree of monitoring.

What is the difference between source of funds and source of wealth?

The FCA's Financial Crime Guide distinguishes them clearly. Source of wealth describes how a customer or beneficial owner acquired their total wealth. Source of funds refers to the origin of the funds involved in a specific relationship or transaction, including the activity that generated them and how they were transferred. Establishing both is mandatory for PEPs under regulation 35(5).

How long must EDD continue after a PEP leaves office?

Under regulation 35(9), a firm must continue applying the enhanced measures for at least 12 months after the person ceases to be entrusted with their prominent public function, on a risk-sensitive basis. After that, under regulation 35(11), the requirements no longer need to be applied to their family members or known close associates.

Does a firm need senior management approval for every EDD case?

Senior management approval is a specified requirement for PEPs under regulation 35(5)(a), for correspondent relationships under regulation 34, and for high-risk third country situations under regulation 33(3A). The FCA treats a failure to obtain senior management approval before taking on a PEP or a non-EEA correspondent as a breach of the Money Laundering Regulations.

Ready to move money with confidence?

Nasara Control helps UK firms send and control payments with lower fees, better rates and full visibility.

Talk to an expert
Secure by designBank-grade security and encryption
Built for UK firmsMade for FCA-regulated businesses
Data protectedYour data stays private and controlled
Global reachCross-border payments worldwide
Accepting enquiries

Tell us what you’re working on.

New firm, FCA authorisation, ongoing compliance or controlled payments, send a note and we’ll come back within one business day.

The business control layer for firms that start, get authorised, stay compliant and make controlled payments.

Nasara Connect is a trading name of Mema Financial Services Ltd, registered with the Financial Conduct Authority as a Small Payment Institution under the Payment Services Regulations 2017 (Firm Reference Number 1040933) and with HM Revenue & Customs for anti-money laundering supervision (registration number XFML00000205542). Registered in England & Wales, company number 15382445. View on the FCA Register.

© 2026 Nasara Connect. All rights reserved.

Cyber Essentials Certified