Fundamentals
KYC, CDD, and EDD Are Not the Same Thing — Here's the Actual Difference
The three terms get used interchangeably in job postings and casually in conversation. In practice they're a hierarchy, and knowing where one ends and the next begins is what separates a checklist analyst from a risk-based one.
June 12, 2026 · 8 min read
Ask five people in financial crime compliance to define KYC, CDD, and EDD, and you’ll often get five overlapping but slightly different answers — not because the terms are ambiguous, but because in daily practice people use them loosely. Getting the hierarchy precise matters, because it’s the hierarchy that a risk-based AML program is actually built on.
KYC is the umbrella, not a step
Know Your Customer is the overall obligation and program, not a single procedure. It’s the regulatory expectation that a financial institution understands who its customers are, what they’re likely to do with the relationship, and whether that matches what they actually do. Everything below it — identification, verification, risk rating, ongoing monitoring — is a component of KYC, not a separate parallel process.
CDD is the baseline procedure every customer gets
Customer Due Diligence is the specific, defined procedure applied to every customer at onboarding, scaled to risk. At its core, under the frameworks most institutions build to — FATF Recommendation 10 globally, implemented in the UK through Regulations 27 and 28 of the Money Laundering, Terrorist Financing and Transfer of Funds (Information on the Payer) Regulations 2017 (“the MLRs”) — baseline CDD requires four things:
- Identifying the customer and verifying that identity using documents or information from a reliable and independent source.
- Identifying the beneficial owner(s) of legal-entity customers — broadly, anyone holding more than 25% of the shares or voting rights, the same threshold Companies House uses for its People with Significant Control register — plus taking reasonable measures to verify who they are.
- Understanding the nature and purpose of the customer relationship well enough to develop a risk profile.
- Conducting ongoing monitoring to identify and report suspicious transactions, and to maintain and update customer information over time.
Crucially, CDD is not optional or reserved for “risky” customers — it’s the floor. Every customer gets it. What changes with risk is how much further you go, which is where EDD enters.
EDD is CDD’s escalation, triggered by risk — not a different process
Enhanced Due Diligence isn’t a separate framework; it’s additional depth applied to the same four CDD components when a customer’s risk profile crosses a threshold. Regulation 33 of the MLRs sets out when EDD is mandatory in the UK: business relationships or transactions involving a high-risk third country, politically exposed persons (PEPs) and their family members or known close associates, correspondent relationships, and any transaction that’s complex, unusually large, follows an unusual pattern, or has no apparent economic or legal purpose.
What EDD actually adds, practically:
- Source of wealth and source of funds analysis — not just “where did this specific deposit come from” but “how did this person or entity accumulate the wealth they now hold.”
- Senior management sign-off on establishing or continuing the relationship, rather than analyst-level approval alone.
- Shortened monitoring review cycles — a PEP relationship might be reviewed annually or more frequently rather than the standard cycle.
- Adverse media and sanctions research depth that goes beyond a single screening hit — checking for beneficial owners, close associates, and related entities, not just the named customer.
“High-risk third country” is not a fixed list — it changed its own definition in 2024
Most training treats “high-risk third country” as a stable category you just memorize the members of. It’s worth knowing it isn’t, because the definition itself has moved twice in four years and most people’s mental model hasn’t caught up. Before Brexit, the UK simply followed the EU’s own list. From 26 March 2021, the UK broke from the EU list entirely and maintained its own bespoke list in Schedule 3ZA of the MLRs, amended by HM Treasury statutory instrument each time it changed. Then, from 23 January 2024, the UK changed approach again — Schedule 3ZA was removed, and “high-risk third country” now means, by direct reference, whatever FATF itself currently lists on either its Call for Action list or its Increased Monitoring list.
The practical upshot: the UK no longer runs its own separate high-risk country list at all — it’s now contractually tied to FATF’s list, updated automatically whenever FATF’s plenary updates it, without a separate UK statutory instrument required each time. An analyst relying on a list they memorized even a year or two ago, or on a EU list from before 2021, is working from a framework that’s been replaced twice over. The correct habit, same as with beneficial ownership registries, is checking FATF’s current lists directly rather than trusting a remembered list of country names.
Why the distinction matters more than it looks
The practical failure mode I see most often — in training materials and in real programs — is treating EDD as a binary “flagged / not flagged” gate rather than a dial. A risk-based approach means EDD scales with the specific risk factors present: a foreign PEP with a transparent, well-documented business generating modest transaction volume warrants a different depth of review than a domestic PEP moving high volumes through a shell structure in a secrecy jurisdiction, even though both are technically “PEP, therefore EDD.”
An analyst who can articulate which specific risk factor triggered escalation, and what additional evidence that specific factor requires, is doing risk-based compliance. An analyst who applies a fixed EDD checklist to every flagged file regardless of why it was flagged is doing a compliance-shaped ritual — and it’s the difference regulators and hiring managers are both actually screening for.