Compliance

What is Enhanced Due Diligence (EDD)?

Enhanced Due Diligence is the deeper set of checks a regulated business applies to customers presenting a higher financial-crime risk. It is not a punishment and not an accusation — it is the mechanism that makes it possible to serve higher-risk but entirely legitimate customers, such as licensed crypto and forex firms, instead of refusing the category outright.

Not every customer carries the same risk, so regulated businesses apply due diligence on a risk-based scale. Most customers receive standard Customer Due Diligence. Higher-risk customers receive Enhanced Due Diligence — additional scrutiny proportionate to the risk they actually present.

EDD is a core AML requirement, and its real function is often misread. It is what makes it possible to serve higher-risk sectors responsibly rather than refusing them. A firm with no EDD capability has only one available answer to a licensed crypto business, a forex broker or a money services business: no.

When EDD applies

Two distinct routes, and the difference matters.

Mandatory, regardless of your own assessment. Some triggers are set by law and are not yours to risk-rate away:

  • Politically-exposed persons, their family members and known close associates. FATF Recommendation 12 requires senior-management approval, source-of-wealth and source-of-funds establishment, and enhanced ongoing monitoring for foreign PEPs, with a risk-based approach to domestic ones.
  • Customers connected to jurisdictions subject to an international call for enhanced measures, including those on the FATF high-risk list.
  • Correspondent relationships and, in most regimes, transactions with no face-to-face element or with unusual complexity.

Discretionary, following your own risk assessment. Everything else — the categories your own documented assessment identifies as elevated:

  • higher-risk sectors: licensed crypto-asset businesses, forex and CFD brokers, money services businesses, precious metals, licensed gaming;
  • complex or opaque ownership, nominee arrangements, or structures with no evident commercial rationale;
  • activity inconsistent with the customer’s stated business — volumes, counterparties, corridors or patterns that do not match what they told you they do.

What EDD actually involves

Fully resolved ownership and control

The ownership chain is followed to natural persons through every layer, including trusts and jurisdictions whose registers are not publicly accessible. In standard KYB an unresolved layer is a finding. In EDD it is a stop.

Source of funds and source of wealth

These are two different questions and conflating them is among the most common EDD failures.

Source of funds is where this specific money came from — this payment, from that account, for that invoice or contract. Source of wealth is how the customer came to have money at all: the sale of a business, years of trading profit, inheritance, investment returns.

A customer can give a perfectly good account of source of funds while the source of wealth remains entirely unexplained, and that is precisely the shape laundering takes. Both need evidence — bank statements, audited accounts, sale agreements, contracts, tax filings — rather than a customer’s description. An EDD file resting on assertion is not an EDD file.

Senior-management approval

A named senior manager, not an analyst, approves entering or continuing the relationship and owns that decision. The requirement exists to place accountability where commercial pressure lands. Its practical test is whether that person is genuinely able to decline a lucrative relationship — if they are not, the control is decorative, and a supervisor will see that in the file.

Closer ongoing monitoring

More frequent review, tighter monitoring thresholds, and periodic re-verification rather than a one-time check. EDD is a standing posture toward a relationship, not an onboarding hurdle cleared once.

In practice an EDD review on a higher-risk business is the difference between a few automated identity checks and a file documenting every beneficial owner, the commercial logic of the expected flows, and the evidence behind both source of funds and source of wealth — proportionate to the risk, and revisited on a schedule.

Why de-risking is not the safe alternative

The intuitive response to a higher-risk category is to refuse all of it. That instinct is understandable and it is not straightforwardly safe.

Wholesale de-risking — declining every crypto firm, or every customer connected to a particular country, without individual assessment — has itself drawn supervisory criticism, from FATF among others. The objection is that it defeats the purpose of a risk-based approach: it pushes legitimate, regulated businesses toward less transparent channels, and it concentrates activity where visibility is worst. Refusing to assess risk is not the same as managing it.

For a provider, the practical consequence is that EDD capability is a commercial asset. A firm that can genuinely do EDD can serve licensed, regulated operators that competitors turn away — including authorised crypto-asset firms — without weakening its own defences, because the additional scrutiny is real.

The line worth being precise about: EDD is what allows a legitimate higher-risk customer to be served properly. It is not a route around the rules for a customer who should not be onboarded at all. Those cases are declined, and no amount of diligence changes that.

How KwiikPay applies it

KwiikPay is a trading name of KWP Finance Limited, registered in Canada as a Payment Service Provider under the Retail Payment Activities Act, supervised by the Bank of Canada, and as a FINTRAC-registered Money Services Business including dealing in virtual currency.

Enhanced due diligence is applied where the risk rating from KYB calls for it: ownership resolved in full, source of funds and source of wealth evidenced, sanctions and PEP screening across the ownership chain, approval by a named senior manager, and a tighter monitoring and review cycle thereafter. Our MLRO owns the framework.

That is what allows us to bank licensed crypto, forex and similar regulated businesses on a monitored rail. The categories we will not serve at any level of diligence are published in the risk appetite statement — if your sector is on that list, no amount of EDD changes the answer, and you should know that before you apply rather than after.

If you expect to be a higher-risk file and would rather find out early whether we can serve you, talk to us.

FAQs

When is EDD required?

In two situations. Some are mandatory by law regardless of your own assessment — notably politically-exposed persons and their close associates, and any customer connected to a jurisdiction subject to an international call for enhanced measures. The rest follow from your own risk assessment: higher-risk sectors, opaque ownership, unusual activity, or transactions inconsistent with the stated profile.

What does EDD involve beyond standard checks?

Fully resolving ownership and control; establishing both source of funds and source of wealth with evidence rather than assertion; obtaining senior-management approval to enter or continue the relationship; and applying closer ongoing monitoring with more frequent review.

What is the difference between source of funds and source of wealth?

Source of funds is the origin of the specific money in this transaction — this payment came from that account, for that invoice. Source of wealth is how the customer accumulated their overall wealth in the first place. They are commonly conflated, and evidencing only the first is one of the most frequent EDD failings.

What is the difference between CDD, SDD and EDD?

Simplified Due Diligence is the reduced level permitted for demonstrably low-risk cases; Customer Due Diligence is the standard; Enhanced Due Diligence is the heightened level for higher-risk cases. Your documented risk assessment decides which applies, and you must be able to justify the choice.

Does EDD mean a customer is suspicious?

No. EDD is a risk-based control, not an allegation. Many customers subject to it are entirely legitimate — an authorised CASP is higher-risk by sector and completely lawful. If a firm actually forms a suspicion, the response is a suspicious-activity report, which is a different obligation altogether.

Is refusing higher-risk customers the safer option?

Not automatically. Blanket de-risking of a whole category — declining every crypto firm, or every customer from a given country, without individual assessment — is itself a supervisory concern in several jurisdictions, because it pushes legitimate businesses toward less regulated channels and defeats the point of a risk-based approach. Refusing to assess is not the same as managing risk.

Related
RPAA end-user funds → Check your eligibility → MiCA CASP accounts → What is KYB? → AML compliance for payments → Crypto compliance for businesses → Compliance overview →

Open your first IBAN today.

Open a multi-currency account, subject to KYB, screening and our risk appetite.

Talk to sales