Customer due diligence vs enhanced due diligence: SDD, CDD and EDD compared, what triggers EDD, what it collects, and how the rules apply to crypto exchanges.

Customer due diligence (CDD) is the standard set of checks a regulated business runs on every customer: verify who they are, identify who ultimately owns or controls them, understand what the relationship is for and keep monitoring it. Enhanced due diligence (EDD) is the heavier version applied when the risk is higher, for example for politically exposed persons, customers linked to high-risk countries or unusually large transactions. It adds source-of-funds and source-of-wealth checks, senior management sign-off and closer monitoring.
Between the two sits simplified due diligence (SDD) for low-risk cases. This guide explains all three levels, what triggers EDD and how the rules apply to crypto exchanges, for compliance teams and for users wondering why an exchange asked for more documents.
CDD is the legal core of "know your customer". The EU's Anti-Money Laundering Regulation, Regulation (EU) 2024/1624 (the AMLR), which applies from 10 July 2027 (Article 90), gives the clearest modern list. Under Article 20(1), CDD means:
Article 19 sets when CDD applies: when a business relationship starts, on occasional transactions of EUR 10,000 or more, whenever there is a suspicion of money laundering or terrorist financing, and when the firm doubts the data it already holds. Crypto-asset service providers (CASPs) get stricter thresholds, covered below.
For individuals, identification is the familiar KYC flow. For companies, the beneficial owner step does most of the work; see our guide to the ultimate beneficial owner (UBO) explains.
Under AMLR Article 20(2), firms set the extent of their checks on an individual analysis of risk: increased risk means they must apply EDD, lower risk means they may apply SDD.
| Simplified (SDD) | Standard (CDD) | Enhanced (EDD) | |
|---|---|---|---|
| When | Documented lower risk | Default for every customer | Higher risk, or a case the law names |
| Identity verification | Can be postponed, at most 60 days after the relationship starts | Before the relationship starts | Before, plus additional information on customer and owners |
| Source of funds / wealth | Not usually requested | Source of funds where necessary for monitoring | Source of funds and source of wealth |
| Approval | Normal process | Normal process | Often senior management sign-off (mandatory for PEPs) |
| Information updates | Less frequent | At least every 5 years | At least every year |
| EU legal basis | AMLR Article 33 | AMLR Articles 19 to 26 | AMLR Articles 34 to 46 |
SDD is not an exemption. Under Article 33 of the AMLR, a firm facing a genuinely low-risk relationship may:
The firm must still monitor enough to spot suspicious activity, and must stop applying SDD if it doubts the information, the low-risk factors disappear, or it suspects money laundering or sanctions evasion.
Article 34(1) of the AMLR requires EDD in the specific cases the regulation names and in any other higher-risk case the firm identifies itself. The main triggers are:
The Financial Action Task Force (FATF) publishes two lists after each of its plenary meetings in February, June and October: "high-risk jurisdictions subject to a call for action", for which FATF urges enhanced due diligence and in the most serious cases countermeasures, and "jurisdictions under increased monitoring". The most recent statements on the FATF high-risk jurisdictions page are dated 19 June 2026, and the June update added Bosnia and Herzegovina and Iraq to the increased-monitoring list. The EU keeps its own list in Delegated Regulation (EU) 2016/1675, last amended in January 2026 according to the European Commission. Under AMLR Article 29(4), business relationships or occasional transactions involving people from a listed country require EDD.
PEPs hold or held prominent public functions, such as heads of state, ministers, members of parliament, supreme court judges, central bank board members and board members of state-controlled companies (AMLR Article 2(1), point 34). FATF covers them in Recommendations 12 and 22. Under AMLR Article 42, a firm dealing with a PEP must get senior management approval, take adequate measures to establish source of wealth and source of funds, and apply enhanced ongoing monitoring. The same applies to family members and known close associates (Article 46). Being a PEP is a risk category, not an accusation, and the extra checks continue for at least 12 months after leaving office (Article 45). Our guide to watchlist and PEP screening covers how firms detect PEPs.
Article 34(2) requires firms to examine the origin, destination and purpose of any transaction that is complex, unusually large, follows an unusual pattern, or has no apparent economic or lawful purpose. This is the trigger most retail crypto users meet: a deposit far larger than anything on the account before.
Cross-border correspondent relationships have their own EDD rules, including for CASPs dealing with crypto firms outside the EU (Article 37). And the list is not closed: Annex III of the AMLR names further higher-risk factors, such as complex ownership structures, nominee shareholders, cash-intensive businesses and products that favour anonymity.
Article 34(4) lists the measures a firm may apply, in proportion to the risk, including:
In practice, EDD files also usually include adverse media screening and a written rationale for the decision. Firms often use specialist tools for the screening and monitoring parts. iDenfy's AML screening, for example, checks customers against sanctions, PEP and watchlist data and re-screens them on an ongoing basis.
Article 26 of the AMLR requires firms to monitor transactions against what they know about the customer and keep customer information up to date, at least every year for customers under EDD and every five years for everyone else, and sooner if circumstances change.
This is why an exchange can ask for documents years after you signed up: a new PEP match, a newly listed country or a change in account use can move a customer from CDD to EDD. Our guide to AML transaction monitoring in crypto explains how it works, and AML red flags in crypto lists the patterns that tend to trigger reviews.
If a firm cannot complete due diligence, Article 21 says it must not carry out the transaction or start the relationship, end an existing one and consider filing a suspicious transaction report. That is why accounts get restricted when requested documents never arrive.
CASPs are obliged entities under the AMLR, and several rules are written specifically for them:
On timing: the AMLR applies from 10 July 2027. Until then, EU firms follow national laws implementing the current AML directives, which use the same three-level structure. The AMLR also required the new EU Anti-Money Laundering Authority (AMLA) to draft technical standards by 10 July 2026 on what information to collect at each level (Article 28), for the Commission to adopt. According to its own website, AMLA began operating in Frankfurt in summer 2025 and expects to start direct supervision of selected firms in 2028. For the licensing side of EU crypto rules, see what is MiCA.
In the United States, banks, broker-dealers, mutual funds and futures firms follow FinCEN's customer due diligence rule (31 CFR 1010.230), with the same risk-based logic.
If an exchange asks for payslips, a sale contract or tax returns, one of the triggers above has usually moved you into EDD, most often a large or unusual deposit. Answering fully and consistently is the fastest way through. Our ID verification tips cover the common mistakes.
JewelSwap's apps are non-custodial DeFi software and do not run customer due diligence themselves. Our explainer on KYC in DeFi covers why.
CDD is the standard set of checks applied to every customer: identity, beneficial owners, purpose of the relationship, sanctions and PEP status, and ongoing monitoring. EDD adds measures for higher-risk cases, such as source-of-funds and source-of-wealth evidence, senior management approval and more frequent monitoring.
The main triggers are a politically exposed person, a family member or close associate of one, a link to a high-risk third country, a complex or unusually large transaction with no clear purpose, certain correspondent relationships, and any other higher risk the firm identifies in its own assessment.
SDD is a lighter version of CDD for documented low-risk cases. Under the EU AMLR, a firm may postpone verification for up to 60 days, update information less often and monitor less intensively, but it can never skip due diligence entirely.
A PEP always triggers enhanced measures under EU rules: senior management approval, source-of-wealth and source-of-funds checks, and enhanced monitoring. That is a risk category, not an accusation, and the measures continue for at least 12 months after the person leaves office.
Under the EU AMLR, which applies from 10 July 2027, updates must happen at least once a year for customers under enhanced due diligence and at least every five years for all other customers, and sooner when circumstances change.
Under the EU AMLR, crypto-asset service providers apply CDD when a business relationship starts and on occasional transactions of EUR 1,000 or more. Below EUR 1,000 they must still identify and verify the customer.
This article is educational and is not legal or financial advice. Legal references are to Regulation (EU) 2024/1624, Regulation (EU) 2023/1113 and 31 CFR 1010.230 as published, checked on 8 October 2026. FATF list dates are from FATF's website and EU list details from the European Commission's website, both checked on 8 October 2026. Rules and lists change; check the current versions before relying on them.