Compliance practitioners know KYC (Know Your Customer), CDD (Customer Due Diligence) and EDD (Enhanced Due Diligence), but sometimes these terms are used interchangeably. Each plays a different role in helping businesses understand customers and manage financial crime risk.
KYC is all about who the customer is. CDD is a look at the overall risk of the customer and EDD is used when the risk is higher and needs to be looked at more closely.
Compliance teams can apply the right checks at the right time by understanding the difference between KYC, CDD and EDD. This also helps standardise onboarding and ongoing monitoring. Keep reading to explore more about KYC vs CDD vs EDD.
What is Know Your Customer (KYC)?
Know Your Customer, often shortened to KYC, is the process of verifying a customer’s identity. It helps businesses ensure that the person or the company is legit.
For individuals, it needs verification of his / her name, date of birth, address and identity documents. For a business, it can include company registration details, directors, shareholders and beneficial owners.
KYC answers who is the customer, and is generally done at the time of onboarding. But customer information may also need to be refreshed later when important details change.
Business KYC often requires more than just verifying a company name. Compliance teams may need to know who owns, controls or benefits from the company.
This is particularly so where ownership is split between a number of companies or jurisdictions. It is easier to correctly assess the customer when the ownership information is clear.
What is Customer Due Diligence (CDD)?
Customer Due Diligence (CDD) is more than checking a customer’s identity. It helps a business to understand the customer, their relationship and what risk is involved.
It reviews the customer’s business activity, occupation, ownership structure, expected transactions, and geographic exposure. The idea is to know what normal activity should look like.
The underlying question CDD answers is: How risky is this customer?
This is where KYC and CDD are different. KYC verifies the identity and CDD uses more data to build a customer risk profile.
CDD also helps a company to understand how the customer is likely to use its products or services. This provides a useful baseline for future monitoring.
For example, a small local business would be expected to have very different transaction patterns than an international trading company. Major deviations from expected activity may require further review.
What Is Enhanced Due Diligence (EDD)?
Enhanced Due Diligence or EDD is a more detailed review for higher risk customers when standard CDD doesn’t give enough information to understand or manage the risk. EDD might require additional documents, more independent checks, or a closer look at ownership and financial activity. The review should focus on the specific risks that led to the customer being treated as higher risk.
The main question EDD asks is: Is this increased risk understood and reduced?
EDD does not necessarily mean rejection of the customer. This gives the business more information before they make that decision.
It may also involve additional due diligence on the customer’s background, business activities, ownership, source of funds or source of wealth. Independent information may also be used to verify the information provided by the customer. Customers with a higher risk may need to be monitored more frequently. It helps businesses to detect changes or anomalies earlier. Monitoring should be related to the already identified risks. It is not a review of every minor activity which is not a need.
When is EDD Needed?
EDD may be necessary where the customer presents factors that are a higher level of financial crime risk. These factors should be defined in the risk framework and the internal procedures of the organisation.
Examples include complex ownership, unusual transaction activity, links to higher risk jurisdictions, politically exposed persons or information that is difficult to verify.
EDD may be required in cases where regular CDD has been a cause for concern. If the customer information doesn’t make sense or you can’t confirm important details, it may be appropriate to do a deeper review.
Just because there’s a higher risk factor doesn’t mean suspicious activity is happening. It simply means that the business needs more information to make a good decision.
KYC, CDD and EDD: What’s the difference?
| Aspect | KYC | CDD | EDD |
| Full Form | Know Your Customer | Customer Due Diligence | Enhanced Due Diligence |
| Main Purpose | Confirm who the customer is | Understand the customer and their risk | Look more closely at higher-risk customers |
| Level of Review | Basic checks | Standard checks | More detailed checks |
| When It Is Used | Mainly during onboarding | During onboarding and ongoing reviews | When higher-risk factors are found |
| Typical Checks | Name, address, date of birth, ID documents | Identity, ownership, business activity, expected transactions | Source of funds, source of wealth, ownership details, extra verification |
| Risk Focus | Confirms identity | Helps decide the customer’s risk level | Looks more closely at higher-risk areas |
| Information Needed | Basic identity details | More information about the customer | Additional details and proof |
| Monitoring | Mainly initial checks | Ongoing customer reviews | Closer or more frequent reviews |
| Key Question | Who is the customer? | What risk does this customer present? | Do we understand this higher risk well enough? |
| Role in Compliance | Confirms customer identity | Builds an understanding of customer risk | Helps investigate higher-risk customers |
The best way to understand KYC, CDD and EDD is to look at the purpose of each process. They are closely interconnected, but each performs a different degree of review.
The three processes should not be viewed as separate exercises. All of these are part of one customer risk management process.
How Does It Work?
The process starts with KYC. The business collects and verifies enough information to establish that the customer is who he says he is.
Then CDD helps the business understand why the customer needs the service, what activity is expected, and what risks might be present.
The information obtained can then be used to assign a risk rating to the customer. Lower risk customers can stay with standard controls and higher risk customers can move to EDD.
Onboarding is not the end of the process. Customer risk can be affected by changes such as to ownership, transaction behavior, business activity or location.
Common Mistakes of KYC, CDD and EDD
Avoid these mistakes to prevent bigger compliance gaps down the line:
Document-Only Checks
Some teams are of the perception that KYC is just collecting identity documents. That misses the bigger picture of knowing who the customer is and does this information make sense.
Uniform Checks
The same checks applied to every customer can be inefficient. Customers with lower risks may suffer unwarranted delays, and those with a real higher risk may not receive enough attention.
Weak Justification
You should not use EDD simply because a customer looks unusual. Any request for further information should be clearly justified on a risk basis.
Poor Documentation
Compliance teams should note why a customer received a particular risk rating. They should also record what checks were carried out and the reasons for the decision.
Outdated Information
Customer risk is time-dependent. If the ownership, business or transaction information becomes outdated, the original risk assessment may no longer be valid.
Missed Changes
A customer could appear to be low risk at onboarding but turn out to be higher risk later. Major changes in behavior or ownership should be reviewed.
Get KYC, CDD, and EDD Right
KYC, CDD and EDD are related but they are for different purposes. KYC is verifying the customer identity, CDD is knowing the customer and risk profiling and EDD is extra checks when there are high risk factors.
The best way is to not put the most checks on each customer. This means applying the right level of review based on the level of actual risk, keeping clear records and revising the assessment if customer circumstances change.
Frequently Asked Questions
1. When should a customer’s risk profile be reviewed?
Customer risk should be reviewed periodically and whenever there is a significant change in activity, ownership, location, transaction behaviour, or other relevant risk factors.
2. What can trigger additional customer verification?
Triggers may include unusual transactions, changes in beneficial ownership, links to high-risk jurisdictions, sanctions exposure, inconsistent information, or unexpected changes in customer behaviour.
3. What records should businesses keep during customer checks?
Businesses should maintain identification records, verification evidence, risk assessments, screening results, supporting documents, review notes, and records explaining important compliance decisions.
4. Can customer due diligence processes be automated?
Parts of the process can be automated using identity verification, screening, risk scoring, and monitoring tools. However, higher-risk cases may still require manual assessment and compliance judgement.
5. What happens if customer information becomes outdated?
Outdated information can affect the accuracy of a customer’s risk assessment. Businesses may need to obtain updated documents, repeat relevant checks, and reassess the relationship.
6. How often should businesses update customer information?
There is no single review frequency suitable for every customer. Review schedules are generally determined by the customer’s risk level, regulatory requirements, and changes identified during ongoing monitoring.