Enhanced due diligence (EDD) becomes necessary the moment a customer or transaction carries more risk than standard checks can capture.
According to Opoint, rather than being tied to a fixed checklist, the requirement follows a risk-based approach, meaning firms must judge for themselves when a relationship crosses the threshold into higher-risk territory, and be prepared to defend that judgement to regulators.
Several situations commonly trigger EDD. Politically exposed persons and their close associates carry elevated corruption risk simply by virtue of their public standing. Customers or transactions linked to jurisdictions with weak anti-money-laundering controls raise similar concerns, as do correspondent banking relationships, where one institution provides services to another in a way that can obscure who is really involved.
Complex or opaque ownership structures present another red flag, making it difficult to establish who ultimately controls a business. Finally, transactions that are unusually large, oddly structured, or inconsistent with a customer’s known profile all warrant closer inspection.
Although no single law names every customer requiring EDD, the obligation is effectively mandatory wherever risk is elevated. The Financial Action Task Force’s Recommendation 10 sets the international benchmark for customer due diligence and enhanced measures.
In the UK, Regulation 33 of the Money Laundering Regulations 2017 spells out when EDD must apply, while equivalent obligations sit within the EU’s Anti-Money Laundering Directives and US regulatory frameworks. The underlying principle is consistent across jurisdictions: greater risk demands greater scrutiny.
In practice, the customers most likely to trigger EDD are politically exposed persons and their associates, those based in or connected to high-risk countries, and businesses with complex or cross-border ownership structures. Any customer whose activity or profile raises red flags during onboarding, or afterwards, falls into this category too.
Crucially, EDD is not a decision made only at onboarding. A customer who initially presented standard risk can shift into EDD territory later, for instance if they become a politically exposed person, begin transacting with a high-risk jurisdiction, or become the subject of adverse media coverage.
This is where ongoing monitoring becomes essential: a compliance programme’s ability to catch a corruption case or regulatory action involving an existing customer depends heavily on the breadth and speed of the news data feeding its screening tools.
Once EDD is triggered, firms are expected to go beyond standard checks. That means verifying the source of funds and wealth, mapping out beneficial ownership in full, running closer adverse media screening, and maintaining enhanced ongoing monitoring for as long as the elevated risk persists.
Read the full Opoint post here.
Copyright © 2026 RegTech Analyst
Copyright © 2026 RegTech Analyst





