Enhanced due diligence is increased due diligence for higher-risk situations: additional measures beyond the standard process, plus enhanced ongoing monitoring. In supervisory reviews the recurring failure is not the absence of EDD but the absence of evidence that the EDD performed was adequate, complete and concluded by someone accountable.
On this page
What EDD means
Enhanced due diligence is not a separate process bolted on to the side of onboarding. It is the standard process performed to a greater depth, with additional measures selected because of the specific risk identified, and with a higher standard of documentation and approval. The measures should respond to the reason for the elevated risk: source of wealth work answers a different question from corroborating a complex ownership structure.
Regulatory basis, stated carefully
HMRC guidance for supervised businesses describes enhanced due diligence as increased due diligence for higher-risk situations, including additional measures and enhanced ongoing monitoring. The Money Laundering Regulations 2017 set the statutory framework, and the FCA Financial Crime Guide sets out expectations for firms the FCA supervises.
In April 2026 the FCA published findings from its review of firms' customer due diligence processes and controls, covering CDD, EDD and ongoing due diligence. Weaknesses it observed included insufficient evidence of enhanced due diligence measures, failure to record the purpose and intended nature of relationships, insufficient detail on periodic and event-driven reviews, and weak independent assurance and version control. Stronger practice it described included risk-tailored due diligence, clearly documented EDD steps and regular independent testing.
These sources should be read together rather than interchangeably: statutory requirements, supervisory guidance and observed practice are different things, and the detail of what applies depends on the firm's sector, supervisor and risk profile. This page is general information, not legal or compliance advice.
Trigger design
A firm should be able to produce a single list of the circumstances in which EDD is engaged, showing for each whether it derives from the applicable regulations or from the firm's own risk assessment. Typical categories include:
- Situations specified in the applicable regulations for the firm's sector.
- Exposure to higher-risk jurisdictions under the firm's own country methodology.
- Politically exposed persons, their family members and known close associates.
- Complex, opaque or unusually structured ownership without an evident commercial rationale.
- Products, channels or activity patterns the business-wide risk assessment identifies as higher risk.
- Relationships that are unusual for the firm's stated customer base.
- Risk ratings reaching the firm's defined enhanced threshold.
Each trigger should state the measures it engages, so that the response is predictable and testable rather than left to the individual analyst.
Measures in practice
- Further information on the customer and its ownership. Deeper structure work, corroboration of control, and identification of parties not captured at standard depth. See beneficial ownership and KYB.
- Source of funds. The origin of the specific funds involved, evidenced rather than described.
- Source of wealth. How the overall wealth was accumulated, with corroboration proportionate to the amounts and risk.
- Purpose and intended nature, in more detail. Expected counterparties, jurisdictions, values and frequency, captured in a structured form so monitoring can use them. See purpose and intended nature.
- Independent corroboration. Documentary or third-party evidence rather than reliance on the customer's own statements alone.
- Senior management approval. Recorded at the appropriate level, with the basis for the decision, not just a name and a date.
- Enhanced ongoing monitoring. Defined and applied, not merely stated.
Agora practitioner interpretation
We would define, for each EDD trigger, the minimum evidence set that must be present before the case can be concluded, and enforce that as a checklist on the case record. It turns "we performed enhanced due diligence" into a set of artefacts a reviewer can test, which is precisely the gap the FCA's 2026 findings described.
Evidencing EDD
A defensible EDD record answers five questions without a conversation: why was EDD engaged, what specific measures were selected and why, what was obtained and from where, who concluded that the measures were sufficient, and what ongoing monitoring was set as a result. Attachments alone are not evidence; the reasoning that connects them to the risk is the evidence.
Enhanced ongoing monitoring
- Shorter review intervals or a broader trigger set for the relationship.
- Tighter transaction monitoring thresholds or additional scenarios.
- More frequent screening refresh, including on identified connected parties.
- Named ownership of the relationship with periodic senior review.
- A defined point at which continued elevated risk is escalated for a retention decision.
Common pitfalls
- EDD applied as a fixed checklist regardless of the reason for the elevated risk.
- Source of wealth described in a narrative with no corroborating evidence.
- Approval recorded without the basis for the decision.
- Enhanced monitoring stated in the file but never configured in the monitoring system.
- EDD performed at onboarding and never revisited despite trigger events.
- Policy changes to the EDD standard made without version control, so past cases cannot be judged against the standard then in force.
Where technology helps
Systems can enforce the evidence checklist, gather corroborating sources, route approvals, apply the enhanced monitoring configuration automatically and report on completeness. They should not conclude sufficiency. The Agora Due Diligence Platform supports this pattern with configurable rules, recorded overrides and a case report that assembles the EDD evidence in one place. See also CDD automation for the wider boundary between automation and judgement.
Primary sources
- HMRC AMLG11600, enhanced due diligence (updated 16 July 2026)
- FCA, Firms' customer due diligence processes and controls: our findings (8 April 2026)
- The Money Laundering, Terrorist Financing and Transfer of Funds Regulations 2017
- FCA Financial Crime Guide, chapter 3
Frequently asked questions
What is enhanced due diligence?
Enhanced due diligence is increased due diligence applied in higher-risk situations. HMRC guidance describes it as involving additional measures beyond standard customer due diligence together with enhanced ongoing monitoring, applied proportionately to the risk identified.
When does EDD apply?
Broadly, where the firm identifies a higher risk of money laundering or terrorist financing, including situations specified in the applicable regulations and those flagged by the firm's own risk assessment. The precise triggers depend on the firm's sector, supervisor and risk methodology, so firms should define and document their own EDD trigger set.
What additional measures count as EDD?
Common measures include obtaining further information on the customer, its ownership and the intended relationship, establishing source of funds and source of wealth, seeking independent corroboration, obtaining senior management approval, and applying more frequent or more intensive ongoing monitoring.
What did the FCA say about EDD evidence in 2026?
In its April 2026 findings on customer due diligence processes and controls, the FCA observed weaknesses including insufficient evidence of enhanced due diligence measures, and described stronger practice as including clearly documented EDD steps alongside risk-tailored due diligence and regular independent testing.
Can EDD be automated?
Parts of it can. Gathering additional data, retrieving corroborating sources, assembling evidence packs and tracking approvals automate well. Whether the measures taken are sufficient in the circumstances, and whether to proceed with the relationship, are accountable human decisions that automation should support rather than replace.
Related resources
CDD and onboarding
Customer Risk Assessment: A Practical CDD Framework
Ownership and KYB
Beneficial Ownership and KYB: A Practical UK Guide
Governance and assurance
Building a Regulator-Defensible CDD Audit Trail
Regulatory answer
When should existing customer due diligence be updated?
Where the technology fits
Agora is a technology provider: the platform supports the control described above, and your own teams operate it and hold the accountable decisions.
Next step
Making EDD evidence reconstructable
See how EDD steps, approvals and corroborating sources are captured against a case in the Agora platform.