Learn more about the latest security and privacy threats
Back

Enhanced Due Diligence Workflows: From Trigger to Documented Decision

Michelangelo Frigo Michelangelo Frigo (Co-Founder at Zyphe) Published July 17, 2026 Updated July 17, 2026
Magnifying glass over a list with one flagged row representing enhanced due diligence workflows

Enhanced due diligence is a documented chain from trigger to decision. Here's the six-step EDD workflow regulators expect and how to make it audit-ready.

Table of contents
  • Enhanced due diligence is not a heavier version of onboarding, it is a documented chain from the trigger that fired it to the written decision that closes it.
  • The workflow has six steps: document the trigger, re-collect enhanced identity, re-screen for PEP, sanctions, and adverse media, evidence source of funds and wealth, write the risk memo, and feed ongoing monitoring.
  • It is triggered by risk factors, PEP status, high-risk jurisdictions, complex ownership, or unusual activity, under FATF Recommendation 10 and the FCA and EU frameworks.
  • The single most common failure is a missing or weak documented decision: the file shows checks ran but not why the customer was accepted or what residual risk was concluded.
  • Manual EDD can consume many hours per case in evidence assembly, which is exactly the work a reasoning agent compresses while a human owns the judgement.
  • Audit-readiness means each step is captured as a by-product of the workflow, not reconstructed after a regulator asks.

Enhanced due diligence is the deeper set of checks applied to higher-risk customers beyond standard KYC, including enhanced identity verification, PEP and sanctions re-screening, source-of-funds documentation, and a written risk decision. It is triggered by risk factors and documented end to end, from trigger to decision.

TL;DR

Enhanced due diligence is where compliance programmes are won or lost in an examination, and the reason is rarely that a check was skipped. It is that the file shows checks happened but never records why the customer was accepted or what residual risk the firm concluded. Enhanced due diligence is best understood not as more onboarding but as a documented chain from trigger to decision.

That chain has six steps: document what triggered EDD, re-collect enhanced identity and corroboration, re-screen for PEP, sanctions, and adverse media, evidence source of funds and wealth, write a risk memo with a clear decision, and feed the result into ongoing monitoring. It is triggered by risk factors under FATF Recommendation 10 and the FCA and EU frameworks. This guide walks each step and shows how to make the workflow audit-ready, with the heavy evidence-assembly compressed so humans spend their time on judgement.

!A six-step EDD workflow from trigger documentation through enhanced identity re-collection, re-screening, source-of-funds, a risk memo, and ongoing monitoring.

10 min read. Last updated 14 October 2026.

What is enhanced due diligence, and when is it triggered?

Enhanced due diligence is the heightened scrutiny applied to customers and relationships that present elevated money-laundering or terrorist-financing risk. It goes beyond standard customer due diligence with additional identity corroboration, deeper screening, source-of-funds and wealth establishment, senior sign-off where required, and enhanced ongoing monitoring. FATF Recommendation 10 requires it for higher-risk situations, and the FCA and EU frameworks codify the same expectation.

The triggers are the risk factors: a customer who is a politically exposed person, a high-risk jurisdiction, a complex or opaque ownership structure, an unusual or unexpectedly large transaction, or a red flag surfaced by monitoring or adverse media. Critically, a trigger can fire after onboarding, which is why EDD is a workflow that can start at any point in a relationship, not just a one-time gate. Knowing precisely what tripped it is the first step, because the whole file hangs off that trigger.

Step one: how do you document the trigger?

The workflow begins by recording why EDD is being performed at all, and this is the step most often skipped. Document the specific trigger: what fired it (a PEP match, a jurisdiction flag, a transaction threshold, an adverse-media hit), the threshold or rule involved, the source of the signal, and the date. This sounds administrative, but it is the spine of the audit trail, because every subsequent step is justified by the trigger.

A file that begins enhanced due diligence without a documented trigger looks, to an examiner, like either an arbitrary escalation or, worse, an unrecorded one. Capturing the trigger cleanly also lets you calibrate: if the same low-value trigger fires constantly and never yields real risk, that is a tuning signal, the same insight as in sanctions screening false positives. Start with why, and the rest of the workflow has a foundation.

Step two: what enhanced identity re-collection is needed?

With the trigger documented, enhanced due diligence re-collects identity to a higher standard than standard onboarding. Depending on the risk, this can mean additional identity documents, stronger biometric verification, corroboration of address through independent sources, and verification of the customer's stated occupation or business. For a business customer, it means deeper verification of ownership and control, resolving the beneficial owners rather than accepting a declaration.

The goal is to remove ambiguity about who the customer actually is, because elevated risk means you cannot rely on the lighter onboarding check. This is where reusable, high-assurance identity helps: a customer verified to a strong standard can re-present that assurance without starting from scratch, and ownership can be resolved with tools like UBO mapping. The output of this step is a strengthened, corroborated identity picture that the rest of the EDD relies on.

Step three: how do you re-screen for PEP, sanctions and adverse media?

Higher-risk customers warrant deeper and fresher screening than the onboarding pass. Step three re-screens the customer, and for businesses their beneficial owners and key controllers, against sanctions lists, politically exposed person data, and adverse media, and it reads the results properly rather than clearing them on a score. A PEP hit is assessed for category and decay as covered in PEP screening; an adverse-media hit is read in context as in adverse media screening; a sanctions hit is confirmed or dismissed on the underlying identifiers.

The point of doing this within EDD, rather than relying on the onboarding screen, is that elevated risk justifies the extra effort to confirm there is no exposure the lighter pass missed, and to document the assessment. The screening output, what hit, how it was assessed, and the conclusion, becomes part of the EDD file.

Step four: how do you document source of funds and wealth?

For higher-risk customers, enhanced due diligence establishes both source of funds and source of wealth with corroborating evidence, as set out in our source of funds verification guide. Step four captures the customer's stated origin of the specific funds and of their overall wealth, obtains independent documentation proportionate to the risk and amount, and records how each was verified.

This is the step that most directly prevents the laundering EDD exists to catch, and it is the most common source of the largest fines when skipped. The output is a documented, evidenced understanding of where the money and the wealth came from, sufficient to defend the relationship. Getting this wrong, accepting an assertion, or a document that does not actually establish origin, undermines the entire EDD however thorough the other steps were.

Step five: what goes in the risk memo and decision?

This is the step that separates a defensible EDD from a pile of checks. Step five synthesises everything into a written risk memo: who the customer is, what triggered EDD, what the enhanced identity, screening, and source-of-funds work found, the residual risk after all of it, and the decision, accept, accept with conditions, escalate, or exit, with the name and authority of the decision-maker, including senior-management approval where required.

The memo answers the question an examiner always asks: knowing what you knew, why did you accept this customer and what risk did you conclude. A file with thorough checks but no documented decision and rationale is the classic failure, because the firm cannot show its judgement. Writing the memo, in the structured who-what-why form used for SAR narratives, is where reasoning support compresses hours of assembly while a human owns the conclusion and signs it.

Step six: how do you keep it audit-ready and monitored?

Enhanced due diligence does not end at the decision; the customer enters enhanced ongoing monitoring, and the file must stay current. Step six feeds the EDD outcome into monitoring at the heightened level the risk warrants, sets review triggers, and keeps the documentation as a living record rather than a one-time artifact. If the customer's risk changes, the EDD is revisited rather than left stale.

Audit-readiness is the property that ties the whole workflow together: each of the six steps captured as a by-product of doing the work, so that when a regulator asks, the trigger, the enhanced checks, the source-of-funds evidence, the risk memo, and the monitoring trail assemble on demand. A programme where this evidence is scattered across systems and reconstructed under pressure is the one that struggles in examination, which is why the AML compliance software layer should capture it natively.

When is standard due diligence enough?

Enhanced due diligence is for elevated risk, and applying it to everyone is both wasteful and a sign of a broken risk assessment. For customers who present standard or low risk, ordinary customer due diligence plus proportionate ongoing monitoring is appropriate, and forcing full EDD on them adds friction, collects sensitive data you must protect, and buries your team in work that does not reduce real risk.

The discipline is a sound risk assessment that reserves EDD for genuine triggers and applies standard measures elsewhere, with the rationale documented either way. The failure is not declining to run EDD on low-risk customers; it is failing to escalate when a trigger fires, or applying EDD indiscriminately so the genuinely high-risk cases get the same attention as everyone else. Match the depth to the risk, and the high-risk cases get the scrutiny they need. To streamline your EDD workflow, book a walk-through.

The bottom line

Enhanced due diligence is judged not on whether checks happened but on whether you can show the chain from trigger to documented decision. The six-step workflow, document the trigger, re-collect enhanced identity, re-screen, evidence source of funds and wealth, write the risk memo, and feed monitoring, is what produces that defensibility, and the risk memo is the step that most often makes or breaks an examination.

Reserve EDD for genuine risk triggers, apply standard measures elsewhere, and capture each step as a by-product of the work so the file is audit-ready by default. Compress the evidence assembly so analysts spend their time on the judgement and the signature, which stay human. Done that way, EDD is a defence, not a liability.

Book an EDD workflow walk-through, or see how it works.

Cited sources

  • FATF Recommendations (Recommendation 10, customer due diligence and EDD): https://www.fatf-gafi.org/en/topics/fatf-recommendations.html
  • Financial Conduct Authority, financial crime and EDD: https://www.fca.org.uk/firms/financial-crime
  • FinCEN, customer due diligence requirements: https://www.fincen.gov/
  • EU Anti-Money Laundering framework (AMLA): https://www.amla.europa.eu/about-amla_en
Michelangelo Frigo Michelangelo Frigo (Co-Founder at Zyphe) Michelangelo Frigo is a privacy and identity infrastructure expert and co-founder of Zyphe.

Frequently Asked Questions

Enhanced due diligence is the heightened scrutiny applied to higher-risk customers beyond standard KYC, including additional identity corroboration, deeper PEP, sanctions, and adverse-media screening, source-of-funds and wealth establishment, senior sign-off where required, and enhanced ongoing monitoring. FATF Recommendation 10 and the FCA and EU frameworks require it for elevated-risk situations, and a defensible programme documents the whole chain from trigger to decision.

Risk factors trigger it: a politically exposed person, a high-risk jurisdiction, a complex or opaque ownership structure, an unusual or unexpectedly large transaction, or a red flag from monitoring or adverse media. Triggers can fire after onboarding, not just at the start, so EDD is a workflow that can begin at any point in a relationship when risk becomes elevated.

Six steps: document the trigger, re-collect enhanced identity and corroboration, re-screen for PEP, sanctions, and adverse media, evidence source of funds and wealth, write a risk memo with a clear decision and sign-off, and feed the outcome into enhanced ongoing monitoring. Each step is captured as part of the workflow so the file is audit-ready rather than reconstructed later.

Customer due diligence (CDD) is the standard verification and risk assessment applied to all customers. Enhanced due diligence (EDD) is the deeper scrutiny applied to higher-risk customers, with additional identity corroboration, deeper screening, source-of-funds establishment, senior approval, and enhanced monitoring. EDD is risk-based: it is reserved for elevated-risk situations rather than applied to every customer.

Most often because the documented decision is missing or weak. The file shows checks ran but does not record why the customer was accepted, what residual risk was concluded, or who approved it. Examiners want to see judgement, not just activity, so a thorough set of checks without a clear, signed risk memo is the classic failure point in EDD.

Manually, a complex EDD case can consume many hours over several days in evidence assembly, screening review, and documentation. The judgement, the risk decision, is a small part of that time; most of it is gathering and writing up. That is why reasoning support that compresses the assembly is valuable, freeing analysts to focus on the conclusion, which remains a human, signed decision.

For certain higher-risk relationships, yes, notably foreign politically exposed persons, where FATF and the EU framework expect senior-management approval to establish or continue the relationship. More broadly, your policy should define which EDD outcomes require sign-off and at what level, and the risk memo should record who approved the decision and on what authority, so accountability is documented.

Enhanced due diligence does not end at the accept decision; the customer enters enhanced ongoing monitoring at a level proportionate to the risk, with review triggers set. If the customer's behaviour or risk profile changes, the EDD is revisited rather than left stale. This keeps the file a living record and aligns with the perpetual, trigger-driven model regulators increasingly expect.

Compliance without the data honeypot

Zyphe verifies identity without holding your customers' PII. See it in action.

Book a demo