Customer Due Diligence: CDD, EDD and Simplified DD
Customer Due Diligence: CDD, EDD and Simplified DD

Introduction
Customer Due Diligence (CDD) turns KYC into a risk-based process. Not every customer needs the same level of checking. The central idea — from FATF downward — is that the intensity of your checks should match the risk the customer poses. This lesson explains the three tiers: SDD, CDD, and EDD.
The Risk-Based Approach
The risk-based approach is the organising principle of modern AML. It says: don't treat everyone the same. Spend your strongest resources on the people and activities that pose the highest risk, and keep genuinely low-risk relationships proportionate.
LOWER RISK HIGHER RISK
--------------------------------------------->
SDD CDD (standard) EDD
(fewer (normal checks) (enhanced checks)
checks)
Standard CDD
Standard Customer Due Diligence applies to most customers. Under FATF and most national laws, CDD must be performed:
- When establishing a business relationship
- When carrying out an occasional transaction above thresholds
- When money laundering or terrorist financing is suspected
- When there are doubts about previously obtained data
- Identifying and verifying the customer
- Identifying and verifying beneficial owners
- Understanding the purpose and intended nature of the relationship
- Conducting ongoing due diligence
Simplified Due Diligence (SDD)
SDD is allowed for low-risk situations where the risk of money laundering or terrorist financing is lower. Examples can include:
- Certain low-value, low-risk products
- Regulated financial institutions in low-risk jurisdictions
- Clearly transparent corporate structures
Enhanced Due Diligence (EDD)
EDD applies to higher-risk customers and situations. It means extra measures to understand the customer and the source of funds more deeply. EDD is typically required for:
- Politically Exposed Persons (PEPs)
- Customers in high-risk third countries / jurisdictions
- Complex or opaque ownership structures
- Unusual or complex transactions with no apparent economic purpose
- Certain cross-border correspondent relationships
- Obtaining additional information on the customer and beneficial owner
- Gathering more on the source of funds and wealth
- Requiring senior management approval to establish/continue the relationship
- Enhanced monitoring of the relationship
- More frequent review and updating of CDD
Applying the Tiers in Practice
A practical workflow:
Assess risk level of the customer
|
v
Low risk -> SDD
Normal -> standard CDD
High risk -> EDD (more info, senior approval, enhanced monitoring)
|
v
If risk rises later, upgrade the CDD level
Why Risk-Based CDD Matters
- Efficiency — resources go where risk is highest
- Fairness — low-risk customers aren't burdened unnecessarily
- Effectiveness — high-risk customers get the scrutiny they need
- Regulatory expectation — regulators audit whether CDD levels match assessed risk
Real-World Example
A bank has three customers. A small local pensioner buying a basic account is assessed as low risk and gets SDD. A standard small business gets regular CDD. A foreign official (PEP) with a complex corporate structure gets EDD: more source-of-funds documentation, senior approval, and enhanced monitoring of all activity.
Summary
- CDD is the risk-based process of knowing and checking your customer
- SDD applies to low-risk situations; EDD to high-risk ones
- The level of checks must match the money-laundering/terrorist-financing risk
- EDD adds documentation, senior approval, and enhanced monitoring
- Reassess and upgrade CDD when risk changes
Next Lesson
Two concepts drive higher-risk ratings: beneficial ownership and PEPs. Let's examine them.
Quiz - Quiz - Customer Due Diligence (CDD/EDD)
1. What is Enhanced Due Diligence (EDD)?
2. Simplified Due Diligence (SDD) is appropriate for...
3. When should you apply risk-based CDD?