← Back to blog

Enhanced due diligence for compliance teams: UK guide

August 14, 2026
Enhanced due diligence for compliance teams: UK guide

Enhanced due diligence (EDD) is the heightened set of checks and monitoring you must apply where a customer or transaction presents a higher risk of money laundering or terrorist financing. Under Regulation 27 of the Money Laundering Regulations 2017, firms must apply enhanced measures proportionate to the risk identified. The moment you identify an EDD trigger, four actions are non-negotiable: record the trigger in the case file, gather corroborating source of funds (SoF) and source of wealth (SoW) evidence, require senior management approval before proceeding, and suspend or restrict activity if credible evidence cannot be obtained.

The HMRC Economic Crime Supervision Handbook at ECSH33335 sets out the specific triggers and measures regulators expect to see documented. The non-negotiable EDD elements are:

  • Identity verification beyond standard CDD — additional documents, independent corroboration, or in-person checks
  • Beneficial ownership — verified to the ultimate natural person, with corporate structure maps where relevant
  • Source of funds and source of wealth verification — corroborated, not merely declared
  • Enhanced ongoing monitoring — increased frequency and depth of transaction review
  • Senior management approval — obtained before or immediately upon onboarding, and re-confirmed at material changes

Key takeaways

Effective EDD requires a documented chain from trigger to monitoring plan, with senior approval and a narrative that explains why the evidence gathered mitigates the specific risk identified.

PointDetails
Record the trigger immediatelyName the specific indicator and cite MLR 2017 reg. 27 and HMRC ECSH33335 in every EDD case file.
Corroborate SoF and SoWA single self-certified document is not sufficient; regulators require independent, cross-referenced evidence.
Narrative before approvalWrite the analysis explaining how evidence mitigates the risk before submitting the file to the senior approver.
EDD is ongoing, not one-offRe-assess SoW and SoF after material changes in transaction behaviour or ownership structure.
Aithea accelerates vendor selectionAithea's Heliolus navigator matches EDD workflow requirements to explainable, audit-ready compliance technology.

This article is general information, not a substitute for advice from a qualified financial advisor. Consult a qualified financial professional about your own circumstances before acting on anything here.

Table of Contents

What is enhanced due diligence, and how does it differ from standard CDD?

EDD is not a separate category of customer. It is an increased intensity of the same customer due diligence (CDD) checks you already apply, triggered by risk rather than customer type. That distinction matters operationally: your CDD baseline stays in place, and EDD layers additional depth, corroboration, and governance on top of it.

The statutory foundation is Regulation 27 of the Money Laundering Regulations 2017, which sets the CDD obligations that underpin when enhanced measures must be applied. The HMRC anti-money laundering guidance at AMLG11600 goes further, requiring firms to document precisely how their EDD measures exceed standard CDD in their policies, controls and procedures (PCPs). That documentation requirement is what most firms underestimate: it is not enough to do more; you must show, in writing, why you did more and how each measure addressed the specific risk identified.

FATF's risk-based approach recommendations form the international baseline from which UK expectations are derived. FATF identifies politically exposed persons (PEPs), correspondent banking relationships, and high-risk jurisdictions as categories that typically require enhanced scrutiny, and the UK's MLR 2017 framework reflects those categories directly.

The practical difference between CDD and EDD is one of depth and corroboration:

DimensionStandard CDDEnhanced due diligence
Identity verificationPassport or driving licence, utility billAdditional documents plus independent corroboration (e.g. credit reference, professional attestation)
Beneficial ownershipIdentify and verify UBO thresholdVerify to ultimate natural person; map full corporate structure
Source of fundsDeclared and plausibleCorroborated with bank statements, transaction records, or third-party confirmation
Source of wealthNot always requiredRequired and verified against credible, independent evidence
MonitoringPeriodic, risk-basedIncreased frequency; defined triggers for escalation
ApprovalRelationship managerNamed senior manager with authority over risk appetite

Record the specific regulation and HMRC guidance reference that triggered EDD in every case file. Auditors reconstruct your decision by reading the file; if the legal rationale is absent, the decision looks arbitrary.


When does EDD apply? Recognising the triggers

EDD is required whenever the overall risk assessment of a customer or transaction crosses into high risk. The HMRC ECSH33335 guidance and FATF recommendations both identify the following as common triggers:

  • Politically exposed persons (PEPs) and their close associates or family members — mandatory EDD under MLR 2017
  • Customers or counterparties connected to FATF call-for-action or high-risk jurisdictions — including those on FATF's grey or black lists
  • Complex, opaque, or multi-layered ownership structures — where beneficial ownership cannot be readily established
  • Sanctions exposure — any match or potential match against HM Treasury, OFAC, or UN consolidated lists
  • Adverse media — credible reporting linking the customer to financial crime, corruption, or serious organised crime
  • Unusual or unexplained transaction activity — volumes, patterns, or counterparties inconsistent with the stated business profile
  • Correspondent banking or high-risk product relationships — where the firm cannot directly verify the end customer
  • Customers operating in high-risk sectors — such as cash-intensive businesses, virtual asset service providers, or arms dealers

Scenario: private client. A wealth management firm onboards a new client who declares income from a family business in a jurisdiction on FATF's grey list. The jurisdiction connection alone triggers EDD; the declared income source requires corroborated SoW verification before funds are accepted.

Scenario: corporate client. A corporate customer presents a holding structure with three layers of offshore entities before reaching the ultimate beneficial owner. Complex ownership is the trigger; the firm must map the full structure and verify the UBO's identity and wealth independently.

Scenario: correspondent banking. A bank establishes a correspondent relationship with a financial institution in a high-risk jurisdiction. The relationship itself is the trigger; the bank must apply EDD to the institution and obtain sufficient information about its AML controls before processing transactions.

Pro Tip: Add a mandatory "trigger rationale" field to every EDD case file. The analyst must name the specific trigger (e.g. "PEP — Tier 1, domestic") and cite the regulation or guidance that requires EDD. A file without this field is the first thing an auditor will flag.


What evidence do regulators accept? Core EDD measures in practice

LSEG's risk intelligence glossary describes EDD as a more detailed form of background check for high-risk customers, listing adverse-media screening, SoW/SoF checks, and enhanced monitoring as the practical measures firms should apply. The table below maps each core measure to the evidence regulators typically accept and the verification steps that support it.

Heliolus AI - The AI Powered RegTech Directory

EDD measureTypical evidence sourcesVerification steps
Enhanced identity verificationCertified passport copy, biometric check, professional attestation, credit reference agency reportCross-reference against two independent sources; flag discrepancies
Beneficial ownershipCorporate registry extracts, shareholder agreements, notarised UBO declarationsVerify each layer; obtain certified copies; map to natural person
Source of funds (SoF)Bank statements (3–12 months), audited accounts, sale or loan agreementsConfirm funds route from declared source; reconcile amounts
Source of wealth (SoW)Tax returns, inheritance documentation, property sale records, business valuation reportsCorroborate with independent evidence; assess plausibility against declared profession/history
Adverse media and sanctions screeningScreening against HM Treasury list, OFAC, UN lists; structured media searchDocument search methodology, date, and outcome; record false-positive rationale
Enhanced transaction monitoringAutomated alerts with defined thresholds; manual review of flagged transactionsSet thresholds calibrated to customer risk profile; document review outcomes
Senior management approvalSigned approval memo with named approver, date, and risk rationaleApprover must have authority over risk appetite; approval must precede or immediately follow onboarding

For SoW verification, the key test regulators apply is reasonableness: does the evidence credibly explain how the customer accumulated their wealth, given their stated profession, age, and history? A single bank statement showing a large balance does not pass this test. You need corroborating evidence that traces the origin of the wealth, not just its current location.

Certifications and third-party attestations should be stored in the case file with the date received, the certifying party's identity, and any caveats noted. Where you rely on a third party for verification, document the basis for relying on them and confirm they are subject to equivalent AML obligations.

Pro Tip: Regulators commonly accept evidence that is independently sourced, dated within a reasonable period (typically 3 months for identity documents, 12 months for financial records), and cross-referenced against at least one other source. A single self-certified document with no corroboration will ordinarily attract sceptical review.


How do you prove your EDD is appropriate? Governance, testing and records

Governance is what converts good EDD practice into a defensible position. The checklist below covers the minimum governance and testing steps compliance officers should have in place:

  • Policy alignment — EDD triggers, measures, and approval thresholds are defined in the firm's PCPs and reviewed at least annually
  • Defined triggers in PCPs — each trigger is named, with the regulation or guidance reference that requires EDD
  • Senior approval workflow — a named, senior approver is designated for each EDD category; the workflow is digitised with an immutable audit log
  • Four-eyes principle — all PEP approvals require sign-off from two senior individuals, at least one of whom is independent of the relationship
  • Sample audit tests — second-line compliance tests a random sample of EDD files quarterly, checking for trigger rationale, evidence completeness, analysis narrative, and approval
  • Periodic re-assessment — EDD files are reviewed at defined intervals (e.g. annually for PEPs, or on material change in transaction behaviour or ownership)
  • KPI tracking — the compliance function monitors the percentage of high-risk files with senior sign-off, average time to complete EDD, and the rate of files returned for remediation

Statistic callout: Tracking the percentage of high-risk files that carry a documented trigger rationale and a named senior approver is one of the most direct KPIs for second-line testing. If that figure is below 100%, the gap is an audit finding waiting to happen.

For record retention, the MLR 2017 requires firms to keep CDD and EDD records for five years from the end of the business relationship or the date of the occasional transaction. Version your evidence files so that the state of the file at the point of approval can be reconstructed exactly. Auditors do not just want to see the current file; they want to see what the approver saw when they signed off.

Pro Tip: What auditors look for in a defensible EDD file is a logical chain: trigger identified → evidence gathered → analysis of how evidence mitigates the risk → decision reached → approval obtained → monitoring plan set. If any link in that chain is missing or implicit, the file is vulnerable.


Making EDD defensible: narrative files and the role of technology

A narrative-driven file, combined with explainable technology, is the most effective way to make EDD defensible to regulators. FTAdviser's practical commentary identifies the most common audit failure as firms collecting documents without demonstrating the analysis that links those documents to mitigating the specific risk. A folder of PDFs is not an EDD file. An EDD file is a reasoned argument.

Every EDD file should contain the following narrative structure, in this order:

  • Trigger — which specific indicator was identified, when, and by whom
  • Evidence — what was gathered, from which sources, and on what dates
  • Analysis — how each piece of evidence addresses the specific risk the trigger raised
  • Decision — the conclusion reached (proceed, proceed with conditions, or decline)
  • Approval — who approved, at what level, and on what date
  • Monitoring plan — what ongoing controls are in place, at what frequency, and what would trigger re-assessment

Technology can support every step of this structure, but only if it is selected and governed correctly. AI-driven tools can accelerate adverse-media screening and sanctions checks, surface patterns in transaction data, and automate alert generation. The risk is that automation produces outputs without the reasoning that makes them defensible. When procuring EDD tools, your RFP checklist should include:

  • Explainability — can the tool show why a match was flagged, not just that it was flagged?
  • Provenance — does the tool identify the source and date of the underlying data?
  • API access — can you retrieve raw source data to verify the tool's output independently?
  • Audit logs — are all actions, overrides, and decisions recorded with timestamps and user IDs?
  • Human-in-the-loop controls — is there a defined escalation path for edge cases that require analyst judgement?

Agentic AI systems are beginning to appear in compliance workflows, capable of executing multi-step research tasks autonomously. The governance question is not whether to use them, but how to constrain their scope and ensure every output carries a traceable rationale. For EDD specifically, any AI-generated finding must be reviewed by a human analyst before it enters the case file as evidence. For guidance on securing agentic AI deployments in enterprise environments, the Alectura Labs resource on agentic AI security offers a practical framework for teams evaluating these tools.

Pro Tip: Ask vendors three questions before signing: "How does your model explain a false positive to a compliance analyst?", "What happens when your data source is unavailable or outdated?", and "How do you handle a case where the model's output conflicts with the analyst's judgement?" Vendors who cannot answer these clearly are not ready for a regulated EDD environment.


EDD checklist and sample templates: from trigger to monitoring plan

The following numbered checklist takes a case from trigger identification through to the ongoing monitoring plan. It is designed to be embedded directly into your case management system or used as a standalone template.

  1. Identify and record the trigger — note the specific indicator (e.g. "PEP — Tier 2, foreign"), the date identified, and the analyst's name. Cite the relevant regulation (MLR 2017, reg. 27) and HMRC guidance (ECSH33335).
  2. Classify the risk band — assign a risk rating (high or very high) based on the trigger type and any aggravating factors (jurisdiction, transaction volume, ownership complexity).
  3. Gather identity evidence — collect and verify identity documents beyond the CDD baseline; cross-reference against at least two independent sources.
  4. Map beneficial ownership — obtain corporate registry extracts, shareholder agreements, or notarised declarations; map to the ultimate natural person.
  5. Verify source of funds — obtain bank statements, audited accounts, or transaction records covering the relevant period; reconcile amounts to the declared source.
  6. Verify source of wealth — obtain corroborating evidence (tax returns, property records, business valuations); apply the reasonableness test.
  7. Conduct adverse media and sanctions screening — run structured searches against HM Treasury, OFAC, and UN lists; document methodology, date, and outcome; record false-positive rationale.
  8. Prepare the analysis narrative — write a concise paragraph explaining how each piece of evidence addresses the specific risk the trigger raised.
  9. Obtain senior management approval — submit the file to the designated approver with a completed approval memo (see sample wording below).
  10. Set the monitoring plan — define the review frequency, the transaction thresholds that trigger escalation, and the date of the next scheduled re-assessment.
  11. Store and version the file — save all documents with version numbers and access controls; flag any confidential SoW documents as restricted.

Sample approval memo wording:

For timeline expectations: a standard high-risk case with a cooperative customer typically takes several working days from trigger identification to approval. A very high-risk case involving complex ownership, multiple jurisdictions, or uncooperative counterparties may take a considerably longer period. Resource accordingly, and document delays with reasons.

Data privacy note: SoW and SoF documents often contain highly sensitive personal data. Store them in a restricted-access folder within your case management system, separate from the main client file. Flag them as confidential in the audit trail. Retention must comply with UK GDPR as well as the MLR 2017 five-year retention requirement; do not retain documents beyond the lawful retention period without a documented legal basis.

Pro Tip: For very high-risk cases, consider a pre-approval checklist that the analyst signs before submitting to the senior approver. This creates a second quality gate and reduces the number of files returned for remediation, which is one of the most common causes of timeline overrun.


When to refuse or exit a relationship, and what to do next

Some EDD processes end not with approval but with a decision to refuse or terminate. The following indicators typically justify exit or refusal:

  • Lack of credible SoF or SoW — the customer cannot provide, or refuses to provide, evidence that passes the reasonableness test
  • Sanctions hit — a confirmed match against HM Treasury, OFAC, or UN consolidated lists
  • Uncooperative counterparty — the customer fails to respond to information requests within a reasonable timeframe, or provides documents that appear altered or inconsistent
  • Unresolved adverse media — credible reporting of financial crime, corruption, or serious organised crime that the customer cannot credibly address
  • Ownership opacity — the ultimate beneficial owner cannot be identified after reasonable steps

Once exit is decided, act in this sequence: freeze or suspend transactions immediately; stop any onboarding activity; preserve all evidence in the case file with access controls; and assess whether a Suspicious Activity Report (SAR) must be filed with the National Crime Agency (NCA) under the Proceeds of Crime Act 2002. Filing a SAR is not optional where you have knowledge or suspicion of money laundering; it is a legal obligation.

Record the exit decision in the case file with the specific reasons, the evidence reviewed, and the date. If the relationship is being terminated rather than refused at onboarding, document the steps taken to wind down the relationship and the date on which it ended. This record is what regulators and law enforcement will request if the customer is subsequently investigated.

Pro Tip: When recording the SAR rationale, use a restricted-access section of the case file that is not visible to the relationship team or the customer. The tipping-off offence under the Proceeds of Crime Act 2002 applies to any disclosure that is likely to prejudice an investigation. Treat the SAR and its rationale as strictly confidential from the moment the decision to file is made.


What compliance teams consistently get wrong about EDD

The most persistent failure in EDD is not a lack of documents. It is a lack of analysis. FTAdviser's commentary captures this precisely: firms collect documents but fail to demonstrate the reasoning that connects those documents to mitigating the specific risk. An EDD file full of bank statements, passport copies, and screening results is not defensible if no one has written down why those documents, in that combination, are sufficient to address the risk the trigger raised.

The second failure is treating EDD as an onboarding event rather than an ongoing control. SoW and SoF checks must be revisited after material changes in the relationship or transaction behaviour. A customer whose wealth profile made sense at onboarding may look very different two years later if their transaction volumes have tripled or their business has expanded into a new jurisdiction. The monitoring plan is not a formality; it is the mechanism that keeps EDD current.

Technology is changing both of these failure modes, but not automatically. AI-driven screening tools can surface adverse media and sanctions matches faster and at greater scale than manual processes. The risk is that speed becomes a substitute for judgement. The analyst who accepts an AI-generated "clear" result without reviewing the underlying search methodology is not conducting EDD; they are conducting a checkbox exercise. The cybersecurity and AI dimensions of financial crime are evolving quickly, and the firms that will stay ahead are those that treat technology as a tool that supports analyst judgement, not one that replaces it.

My practical observation after working across multiple compliance programmes is that the teams with the strongest EDD records share one habit: they write the analysis narrative before they seek approval, not after. When the narrative comes first, gaps in the evidence become visible before the approver sees the file. When it comes after, the narrative tends to justify the evidence already collected rather than test it.

Two actions you can implement this week:

  • Add a mandatory "trigger rationale" field and an "analysis narrative" field to your EDD case file template. Make both fields required before the file can be submitted for approval.
  • Require four-eyes sign-off on all PEP approvals, with both approvers named and dated in the file. If your current workflow does not support this, escalate it as a governance gap.

Aithea helps you build audit-ready EDD programmes faster

Selecting the right technology for EDD is one of the most consequential procurement decisions a compliance team makes, and it is also one of the least well-supported. Most vendor evaluations focus on feature lists rather than the explainability, provenance, and audit-log requirements that regulators actually test.

Aithea

Aithea works with compliance teams and risk functions to cut through that complexity. Using the Heliolus AI compliance technology navigator, Aithea maps your EDD workflow requirements to a shortlist of vendors whose tools are genuinely fit for a regulated environment, then supports the RFP design, explainability testing, and procurement cycle from scoping to contract. For teams that need to build or refresh EDD capability quickly, Aithea also provides compliance microlearning programmes that bring analysts and approvers up to speed on narrative-driven EDD practice. To start a scoping conversation, get in touch with the Aithea team and describe your current EDD challenge.


Sources

Every compliance team should have these documents bookmarked and cited in their PCPs:

HMRC ECSH33335 — the Economic Crime Supervision Handbook entry on EDD. This is the primary operational reference for HMRC-supervised businesses. It sets out triggers, required measures, and the expectation of senior management approval. Use this when designing your trigger list and approval workflow.

HMRC AMLG11600 — the anti-money laundering guidance for supervised businesses on EDD. This explains the requirement to document how EDD exceeds CDD in your PCPs. Use this when writing or reviewing your EDD policy.

Money Laundering Regulations 2017, Regulation 27 — the statutory basis for CDD and EDD obligations in the UK. This is the primary legal text; cite it in every EDD decision record and policy document. Consolidated legislative text is available at legislation.gov.uk, which also shows amendments made since the original 2017 instrument.

FATF Recommendations — the international standard. FATF's country listings (grey list, black list) directly inform which jurisdictions require EDD treatment under UK rules. Check the FATF website for current listings before finalising your high-risk jurisdiction list.

FCA guidance — the FCA's Financial Crime Guide and its thematic reviews on AML set out supervisory expectations for FCA-regulated firms. The FCA's approach to EDD aligns with MLR 2017 but adds sector-specific expectations for banks, wealth managers, and payment institutions. Access the FCA's financial crime guidance at the FCA website.

LSEG risk intelligence glossary — a practical reference for definitions and measure lists, useful for training materials and vendor briefings. Not a primary legal source, but a well-regarded industry reference.

For consolidated legislative text and HMRC internal manual extracts, legislation.gov.uk and GOV.UK are the authoritative sources. Always cite the specific regulation number and HMRC manual reference in your decision records, not just the title of the legislation.


FAQ

What is enhanced due diligence?

Enhanced due diligence is an increased level of customer checks applied where a customer or transaction presents a higher risk of money laundering or terrorist financing. Under the Money Laundering Regulations 2017, it requires additional identity verification, source of wealth and source of funds checks, enhanced monitoring, and senior management approval.

What is the difference between CDD and EDD?

Standard CDD establishes a customer's identity and the nature of the business relationship; EDD applies the same checks at greater depth and with independent corroboration, adds source of wealth verification, increases monitoring frequency, and requires senior approval before proceeding.

What is an example of EDD in practice?

A wealth manager onboarding a client connected to a FATF grey-list jurisdiction must apply EDD: this means verifying identity against two independent sources, obtaining tax returns and property records to corroborate declared wealth, running structured adverse-media and sanctions searches, and obtaining named senior management approval before accepting funds.

Who is required to conduct enhanced due diligence in the UK?

Any firm in scope of the Money Laundering Regulations 2017 must apply EDD when it identifies a high-risk customer or transaction. This includes banks, wealth managers, accountants, solicitors, estate agents, and other regulated businesses listed under the MLR 2017 regime.

How often should EDD be reviewed after onboarding?

EDD is not a one-time exercise. Firms should re-assess source of wealth and source of funds checks after any material change in transaction behaviour, ownership structure, or the customer's risk profile, and conduct a scheduled review at least annually for high-risk relationships.