When enhanced due diligence is required under the Money Laundering Regulations 2017, the measures it involves, and how it differs from standard CDD.

Enhanced due diligence, usually shortened to EDD, is the deeper level of customer scrutiny that firms must apply when a relationship or transaction presents a higher risk of money laundering or terrorist financing. It sits above standard customer due diligence (CDD), and it is not optional. Regulation 33 of the Money Laundering Regulations 2017 requires firms to apply enhanced customer due diligence measures and enhanced ongoing monitoring to manage and mitigate the risks arising in defined high-risk situations.
The difference between CDD and EDD is one of depth and certainty rather than of category. Standard CDD, set out in regulation 28, requires a firm to identify and verify the customer, identify the beneficial owner and take reasonable measures to verify their identity, and assess the purpose and intended nature of the relationship. EDD builds on that baseline. The FCA's Financial Crime Guide states that EDD should give firms a greater understanding of the customer and their associated risk than standard due diligence, and should provide more certainty that the customer or beneficial owner is who they say they are and that the purposes of the business relationship are legitimate.
This guide sets out when EDD is required under UK law, the specific measures it involves, and how firms can carry it out in a way that stands up to supervisory scrutiny. Every rule referenced here is drawn from the Money Laundering Regulations 2017 or the FCA's published guidance.
Standard customer due diligence is the floor. Under regulation 28, a firm must identify the customer and verify their identity from a reliable and independent source, identify the beneficial owner and take reasonable measures to verify who that person is, and assess and where appropriate obtain information on the purpose and intended nature of the relationship. The extent of those measures can be adjusted on a risk-sensitive basis, but the three core steps apply to almost every customer.
Enhanced due diligence does not replace these steps; it intensifies them. The FCA's Financial Crime Guide explains that the extent of EDD must be commensurate to the risk associated with the relationship or transaction, and that firms can decide in most cases which aspects of CDD they should enhance, depending on the reason the relationship was classified as high risk. In practice this means gathering more information, verifying it from more robust and independent sources, and monitoring the relationship more closely once it is live.
A recurring failure the FCA identified in its April 2026 review of firms' customer due diligence processes was firms not evidencing how their approach differed between low-risk and high-risk customers. If a firm cannot show what it did differently for a high-risk case, it has not applied EDD in a way it can defend.
Regulation 33(1) sets out the situations in which a firm must apply enhanced customer due diligence measures and enhanced ongoing monitoring. These are not matters of discretion. Where any of these circumstances applies, EDD is mandatory, and the firm must be able to demonstrate that the extent of the measures it applied was commensurate with the money laundering and terrorist financing risk.
The table below summarises the main statutory triggers and the corresponding measures. Alongside these specific scenarios, regulation 33(1)(g) provides a catch-all: any other case which by its nature can present a higher risk of money laundering or terrorist financing. This means the list of named triggers is a floor, not a ceiling, and a firm's own risk assessment under regulation 18 may surface further high-risk situations that warrant EDD. Building this logic into a documented, risk-based control framework is what turns the regulation into a repeatable process rather than a case-by-case judgement call.
| EDD trigger | Source | Corresponding measures |
|---|---|---|
| Any case the firm has identified as high risk, or that regulations 17(9) and 47 flag as higher risk | Reg 33(1)(a) | Additional information on the customer and business relationship; enhanced monitoring proportionate to the assessed risk |
| A business relationship or transaction where a party is established in a high-risk third country (a country named on the FATF lists) | Reg 33(1)(b), 33(3A) | Additional information on customer and beneficial owner, nature of the relationship, source of funds and wealth, reasons for the transaction, senior management approval, enhanced monitoring |
| A correspondent relationship with a credit or financial institution from a third country | Reg 33(1)(c), Reg 34 | Regulation 33 EDD plus the additional correspondent measures in regulation 34, including senior management approval before establishing the relationship |
| The customer or beneficial owner is a PEP, family member or known close associate | Reg 33(1)(d), Reg 35 | Senior management approval; establish source of wealth and source of funds; enhanced ongoing monitoring |
| The customer has provided false or stolen documentation and the firm proposes to continue dealing | Reg 33(1)(e) | Enhanced verification and scrutiny before continuing |
| Transactions that are unusually complex or large, follow an unusual pattern, or have no apparent economic or legal purpose | Reg 33(1)(f) | Examine the background and purpose of the transaction; increase the degree and nature of monitoring to determine whether it appears suspicious |
PEPs are treated as a category of their own under regulation 35 because their public function creates an inherent risk that they could abuse it for private gain. A PEP is defined in regulation 35(12) as an individual entrusted with prominent public functions, other than as a middle-ranking or more junior official. The regime extends to family members, defined to include a spouse or civil partner, children and their spouses or civil partners, and parents, and to known close associates.
Where a firm proposes to establish or continue a relationship with a PEP, a family member or a known close associate, regulation 35(5) requires three things: approval from senior management for establishing or continuing the relationship; adequate measures to establish the source of wealth and source of funds involved; and enhanced ongoing monitoring of the relationship. These apply even where an existing customer becomes a PEP after onboarding.
The measures are applied on a risk-sensitive basis. Regulation 35(3) requires the firm to assess the level of risk associated with the customer and calibrate the extent of the EDD accordingly, and regulation 35(4) allows firms to have regard to guidance issued by the FCA or another supervisory authority. When a person stops being entrusted with their public function, regulation 35(9) requires the firm to keep applying these measures for at least 12 months afterwards, on a risk-sensitive basis. Once that status ends, regulation 35(11) provides that the requirements no longer need to be applied to their family members or known close associates.
Two of the most commonly conflated concepts in EDD are source of funds and source of wealth. The FCA's Financial Crime Guide keeps them distinct. Source of wealth describes how a customer or beneficial owner acquired their total wealth. Source of funds refers to the origin of the funds involved in the specific business relationship or transaction, including the activity that generated them, such as salary payments or sale proceeds, and the means by which they were transferred.
Establishing both is a mandatory requirement where the customer is a PEP, under regulation 35(5), and it is a specified measure for high-risk third country situations under regulation 33(3A). The FCG lists two of the core examples of EDD as establishing how the customer or beneficial owner acquired their wealth to be satisfied that it is legitimate, and establishing the source of their funds to be satisfied that they do not constitute the proceeds of crime.
The FCA treats failure to distinguish the two as poor practice. Its guide gives, as an example of poor practice, a firm that does not distinguish between the customer's source of funds and their source of wealth, and separately, a firm that grants waivers from establishing source of funds or source of wealth without good reason. A firm that collects statements showing where money for one transaction came from has evidenced source of funds; it has not necessarily explained how the customer became wealthy in the first place.

EDD is a process, not a document. The FCA's guide frames it around a set of examples: obtaining more information about the customer's or beneficial owner's business; obtaining more robust verification of the beneficial owner's identity from a reliable and independent source; gaining a better understanding of the customer's reputation or role in public life; carrying out searches on a corporate customer's directors or controllers; establishing source of wealth; and establishing source of funds. The steps below turn those examples into an ordered workflow that maps onto the statutory measures.
The FCA also warns against thin evidence. Its guide flags, as poor practice, relying entirely on a single source of information for EDD, and treating annual reviews of high-risk customers as a tick-box exercise by copying information from previous reviews without thought. Good EDD complements staff knowledge with more objective information and documents the reasoning so it can be challenged later. Firms that link EDD to payment flows and transaction screening can surface the unusual activity that regulation 33(1)(f) is concerned with, and feeding enhanced alerts into a monitoring workflow is one way to do that.
The specified enhanced due diligence measures set out in regulations 33 and 35 for high-risk and PEP situations.
Two triggers carry extra weight and deserve separate attention. Where a UK credit or financial institution enters a correspondent relationship with a respondent institution from a third country, regulation 34 layers additional measures on top of the regulation 33 EDD. The FCA's guide notes that these can include thoroughly understanding the correspondent's business, reputation and the quality of its defences against money laundering and terrorist financing, and that senior management must approve the relationship before it is established. The guide treats reliance on a single questionnaire, or inadequate due diligence on a respondent's parents and affiliates, as poor practice.
For high-risk third countries, regulation 33(3)(a) defines the relevant list by reference to the countries named on the Financial Action Task Force's list of High-Risk Jurisdictions subject to a Call for Action, as that list has effect from time to time. Because the list changes, firms cannot hard-code it once and forget it; they must track FATF updates and adjust their EDD triggers accordingly. In these situations, regulation 33(3A) specifies the measures: additional information on the customer, the beneficial owner, the nature of the relationship, source of funds and wealth, and the reasons for the transaction, plus senior management approval and enhanced monitoring.
Enhanced due diligence is the mechanism the Money Laundering Regulations 2017 use to make sure the highest-risk relationships receive the deepest scrutiny. The triggers are set out clearly in regulation 33, with a separate and stricter regime for PEPs in regulation 35 and additional measures for correspondent banking in regulation 34. The measures themselves are consistent across the triggers: more information, verified from more robust sources; a proper understanding of source of funds and source of wealth; senior management approval; and enhanced ongoing monitoring calibrated to the assessed risk.
The difference between a firm that passes supervisory scrutiny and one that does not is rarely the absence of a policy. As the FCA's April 2026 review showed, it is usually the failure to evidence what was done differently for a high-risk case, or the failure to distinguish source of funds from source of wealth. Treating EDD as a documented, risk-sensitive process, rather than a form to complete, is what keeps a firm on the right side of the regulations. To see how a structured control and monitoring framework supports this in practice, request a demo.
Regulation 33(1) of the Money Laundering Regulations 2017 requires EDD in defined high-risk situations: any case the firm assesses as high risk, dealings involving high-risk third countries named on the FATF lists, correspondent relationships with third-country institutions, PEPs and their family members and close associates, cases involving false or stolen documentation, unusually complex or large transactions with no apparent purpose, and any other case that by its nature presents a higher risk.
Standard CDD under regulation 28 requires identifying and verifying the customer, identifying and taking reasonable measures to verify the beneficial owner, and assessing the purpose of the relationship. EDD builds on that baseline. The FCA states that EDD should give firms a greater understanding of the customer and more certainty that they are who they say they are and that the relationship's purpose is legitimate, through additional information, more robust verification and closer monitoring.
For high-risk third country and PEP situations, regulations 33(3A) and 35(5) specify measures including additional information on the customer and beneficial owner, establishing source of funds and source of wealth, obtaining senior management approval, and conducting enhanced ongoing monitoring. For unusual or complex transactions, regulation 33(4) requires examining the background and purpose of the transaction and increasing the degree of monitoring.
The FCA's Financial Crime Guide distinguishes them clearly. Source of wealth describes how a customer or beneficial owner acquired their total wealth. Source of funds refers to the origin of the funds involved in a specific relationship or transaction, including the activity that generated them and how they were transferred. Establishing both is mandatory for PEPs under regulation 35(5).
Under regulation 35(9), a firm must continue applying the enhanced measures for at least 12 months after the person ceases to be entrusted with their prominent public function, on a risk-sensitive basis. After that, under regulation 35(11), the requirements no longer need to be applied to their family members or known close associates.
Senior management approval is a specified requirement for PEPs under regulation 35(5)(a), for correspondent relationships under regulation 34, and for high-risk third country situations under regulation 33(3A). The FCA treats a failure to obtain senior management approval before taking on a PEP or a non-EEA correspondent as a breach of the Money Laundering Regulations.
Nasara Control helps UK firms send and control payments with lower fees, better rates and full visibility.
Practical guides and updates for UK firms, straight to your inbox.