Compliance
Oct 8, 2026

Customer Due Diligence vs Enhanced Due Diligence Explained

Customer due diligence vs enhanced due diligence: SDD, CDD and EDD compared, what triggers EDD, what it collects, and how the rules apply to crypto exchanges.

Customer Due Diligence vs Enhanced Due Diligence Explained

Customer due diligence (CDD) is the standard set of checks a regulated business runs on every customer: verify who they are, identify who ultimately owns or controls them, understand what the relationship is for and keep monitoring it. Enhanced due diligence (EDD) is the heavier version applied when the risk is higher, for example for politically exposed persons, customers linked to high-risk countries or unusually large transactions. It adds source-of-funds and source-of-wealth checks, senior management sign-off and closer monitoring.

Between the two sits simplified due diligence (SDD) for low-risk cases. This guide explains all three levels, what triggers EDD and how the rules apply to crypto exchanges, for compliance teams and for users wondering why an exchange asked for more documents.

What is customer due diligence?

CDD is the legal core of "know your customer". The EU's Anti-Money Laundering Regulation, Regulation (EU) 2024/1624 (the AMLR), which applies from 10 July 2027 (Article 90), gives the clearest modern list. Under Article 20(1), CDD means:

  • identifying the customer and verifying their identity;
  • identifying the beneficial owners and taking reasonable measures to verify them, so the firm understands the ownership and control structure;
  • understanding the purpose and intended nature of the relationship;
  • checking whether the customer or its beneficial owners are subject to targeted financial sanctions;
  • understanding the customer's business or occupation;
  • ongoing monitoring, including scrutiny of transactions and, where necessary, the source of funds;
  • determining whether the customer or beneficial owner is a politically exposed person (PEP), a family member or a close associate;
  • verifying anyone acting on the customer's behalf.

Article 19 sets when CDD applies: when a business relationship starts, on occasional transactions of EUR 10,000 or more, whenever there is a suspicion of money laundering or terrorist financing, and when the firm doubts the data it already holds. Crypto-asset service providers (CASPs) get stricter thresholds, covered below.

For individuals, identification is the familiar KYC flow. For companies, the beneficial owner step does most of the work; see our guide to the ultimate beneficial owner (UBO) explains.

SDD vs CDD vs EDD at a glance

Under AMLR Article 20(2), firms set the extent of their checks on an individual analysis of risk: increased risk means they must apply EDD, lower risk means they may apply SDD.

Simplified (SDD)Standard (CDD)Enhanced (EDD)
WhenDocumented lower riskDefault for every customerHigher risk, or a case the law names
Identity verificationCan be postponed, at most 60 days after the relationship startsBefore the relationship startsBefore, plus additional information on customer and owners
Source of funds / wealthNot usually requestedSource of funds where necessary for monitoringSource of funds and source of wealth
ApprovalNormal processNormal processOften senior management sign-off (mandatory for PEPs)
Information updatesLess frequentAt least every 5 yearsAt least every year
EU legal basisAMLR Article 33AMLR Articles 19 to 26AMLR Articles 34 to 46

Simplified due diligence: lighter, never zero

SDD is not an exemption. Under Article 33 of the AMLR, a firm facing a genuinely low-risk relationship may:

  • verify the customer and beneficial owner after the relationship is established, but no later than 60 days in;
  • update customer information less often;
  • collect less information about the purpose of the relationship, or infer it;
  • scrutinise transactions less often or less deeply.

The firm must still monitor enough to spot suspicious activity, and must stop applying SDD if it doubts the information, the low-risk factors disappear, or it suspects money laundering or sanctions evasion.

When enhanced due diligence is triggered

Article 34(1) of the AMLR requires EDD in the specific cases the regulation names and in any other higher-risk case the firm identifies itself. The main triggers are:

High-risk third countries

The Financial Action Task Force (FATF) publishes two lists after each of its plenary meetings in February, June and October: "high-risk jurisdictions subject to a call for action", for which FATF urges enhanced due diligence and in the most serious cases countermeasures, and "jurisdictions under increased monitoring". The most recent statements on the FATF high-risk jurisdictions page are dated 19 June 2026, and the June update added Bosnia and Herzegovina and Iraq to the increased-monitoring list. The EU keeps its own list in Delegated Regulation (EU) 2016/1675, last amended in January 2026 according to the European Commission. Under AMLR Article 29(4), business relationships or occasional transactions involving people from a listed country require EDD.

Politically exposed persons

PEPs hold or held prominent public functions, such as heads of state, ministers, members of parliament, supreme court judges, central bank board members and board members of state-controlled companies (AMLR Article 2(1), point 34). FATF covers them in Recommendations 12 and 22. Under AMLR Article 42, a firm dealing with a PEP must get senior management approval, take adequate measures to establish source of wealth and source of funds, and apply enhanced ongoing monitoring. The same applies to family members and known close associates (Article 46). Being a PEP is a risk category, not an accusation, and the extra checks continue for at least 12 months after leaving office (Article 45). Our guide to watchlist and PEP screening covers how firms detect PEPs.

Unusual transactions

Article 34(2) requires firms to examine the origin, destination and purpose of any transaction that is complex, unusually large, follows an unusual pattern, or has no apparent economic or lawful purpose. This is the trigger most retail crypto users meet: a deposit far larger than anything on the account before.

Other higher-risk cases

Cross-border correspondent relationships have their own EDD rules, including for CASPs dealing with crypto firms outside the EU (Article 37). And the list is not closed: Annex III of the AMLR names further higher-risk factors, such as complex ownership structures, nominee shareholders, cash-intensive businesses and products that favour anonymity.

What enhanced due diligence collects

Article 34(4) lists the measures a firm may apply, in proportion to the risk, including:

  1. More information on the customer and beneficial owners, and on the intended nature of the relationship.
  2. Source of funds and source of wealth of the customer and beneficial owners. Source of funds is where the money for this transaction came from. Source of wealth is how the person built their overall wealth. Our guide to source of funds vs source of wealth lists the evidence that is usually accepted.
  3. Reasons for specific transactions and whether they fit the relationship.
  4. Senior management approval to start or continue the relationship.
  5. Enhanced monitoring: more frequent controls and closer review of transaction patterns.

In practice, EDD files also usually include adverse media screening and a written rationale for the decision. Firms often use specialist tools for the screening and monitoring parts. iDenfy's AML screening, for example, checks customers against sanctions, PEP and watchlist data and re-screens them on an ongoing basis.

Ongoing monitoring: due diligence doesn't stop at onboarding

Article 26 of the AMLR requires firms to monitor transactions against what they know about the customer and keep customer information up to date, at least every year for customers under EDD and every five years for everyone else, and sooner if circumstances change.

This is why an exchange can ask for documents years after you signed up: a new PEP match, a newly listed country or a change in account use can move a customer from CDD to EDD. Our guide to AML transaction monitoring in crypto explains how it works, and AML red flags in crypto lists the patterns that tend to trigger reviews.

If a firm cannot complete due diligence, Article 21 says it must not carry out the transaction or start the relationship, end an existing one and consider filing a suspicious transaction report. That is why accounts get restricted when requested documents never arrive.

How CDD and EDD apply to crypto firms

CASPs are obliged entities under the AMLR, and several rules are written specifically for them:

  • Lower thresholds. Under Article 19(3), CASPs must apply full CDD on occasional transactions of EUR 1,000 or more, and must at least identify and verify the customer below that amount. Other businesses use EUR 10,000.
  • Self-hosted wallets. Article 40 requires CASPs to assess the risk of transfers to and from self-hosted addresses and apply mitigating measures. These can include identifying the person behind the transfer, asking about the origin and destination of the crypto, or enhanced monitoring.
  • The Travel Rule. The EU Transfer of Funds Regulation has applied since 30 December 2024. It requires originator and beneficiary information to travel with crypto transfers between providers. See the crypto Travel Rule explained.
  • On-chain risk. Exchanges screen the wallets customers deposit from and withdraw to, and a deposit traced to a mixer or sanctioned address can push an ordinary customer into EDD. Our guide to blockchain analytics explains how that tracing works.

On timing: the AMLR applies from 10 July 2027. Until then, EU firms follow national laws implementing the current AML directives, which use the same three-level structure. The AMLR also required the new EU Anti-Money Laundering Authority (AMLA) to draft technical standards by 10 July 2026 on what information to collect at each level (Article 28), for the Commission to adopt. According to its own website, AMLA began operating in Frankfurt in summer 2025 and expects to start direct supervision of selected firms in 2028. For the licensing side of EU crypto rules, see what is MiCA.

In the United States, banks, broker-dealers, mutual funds and futures firms follow FinCEN's customer due diligence rule (31 CFR 1010.230), with the same risk-based logic.

For users: why the exchange asked for more

If an exchange asks for payslips, a sale contract or tax returns, one of the triggers above has usually moved you into EDD, most often a large or unusual deposit. Answering fully and consistently is the fastest way through. Our ID verification tips cover the common mistakes.

JewelSwap's apps are non-custodial DeFi software and do not run customer due diligence themselves. Our explainer on KYC in DeFi covers why.

Frequently asked questions

What is the difference between CDD and EDD?

CDD is the standard set of checks applied to every customer: identity, beneficial owners, purpose of the relationship, sanctions and PEP status, and ongoing monitoring. EDD adds measures for higher-risk cases, such as source-of-funds and source-of-wealth evidence, senior management approval and more frequent monitoring.

What triggers enhanced due diligence?

The main triggers are a politically exposed person, a family member or close associate of one, a link to a high-risk third country, a complex or unusually large transaction with no clear purpose, certain correspondent relationships, and any other higher risk the firm identifies in its own assessment.

What is simplified due diligence?

SDD is a lighter version of CDD for documented low-risk cases. Under the EU AMLR, a firm may postpone verification for up to 60 days, update information less often and monitor less intensively, but it can never skip due diligence entirely.

Is a PEP automatically high risk?

A PEP always triggers enhanced measures under EU rules: senior management approval, source-of-wealth and source-of-funds checks, and enhanced monitoring. That is a risk category, not an accusation, and the measures continue for at least 12 months after the person leaves office.

How often must customer information be updated?

Under the EU AMLR, which applies from 10 July 2027, updates must happen at least once a year for customers under enhanced due diligence and at least every five years for all other customers, and sooner when circumstances change.

When do crypto exchanges have to apply CDD?

Under the EU AMLR, crypto-asset service providers apply CDD when a business relationship starts and on occasional transactions of EUR 1,000 or more. Below EUR 1,000 they must still identify and verify the customer.

Keep reading

This article is educational and is not legal or financial advice. Legal references are to Regulation (EU) 2024/1624, Regulation (EU) 2023/1113 and 31 CFR 1010.230 as published, checked on 8 October 2026. FATF list dates are from FATF's website and EU list details from the European Commission's website, both checked on 8 October 2026. Rules and lists change; check the current versions before relying on them.

About the author.

Co-Founder at JewelSwap & Chief Strategy Officer at iDenfy. Viktor brings his successful track record of superb development & project management.