Forteris
Enhanced Due Diligence · reviewed 2026-07-30

Enhanced due diligence, done so it survives the exam

Most programs can describe their EDD policy. Far fewer can produce a file that shows the policy was followed, the risk was understood, and someone made a documented decision. That gap is where examination findings come from.

Request the readiness review Free. A written readiness memo, and a straight answer on whether you need us.

/ What EDD is, and what it is not

Customer due diligence establishes who you are dealing with. Enhanced due diligence establishes whether you should be dealing with them at all, and on what terms. The distinction matters because programs frequently collect more documents and call it EDD, when what supervisors are looking for is more *understanding*.

EDD is risk-based. There is no universal list of triggers and no dollar threshold that switches it on. What your program must do is define, in writing, which relationships warrant it, apply that definition consistently, and be able to show why a given customer was or was not escalated.

The most common structural error is treating EDD as an onboarding event. For genuinely higher-risk relationships it is an ongoing obligation — the file should show refresh, not just origination.

/ What typically triggers it

Your risk assessment should drive this rather than a borrowed checklist, but relationships that commonly warrant enhanced treatment include:

  • Politically exposed persons, their family members and close associates
  • Customers with beneficial ownership that is layered, opaque, or spans secrecy jurisdictions
  • Correspondent and nested relationships, particularly cross-border
  • Money services businesses, and fintech programs sponsored by your institution
  • Cash-intensive businesses whose activity does not match their stated model
  • Customers with unresolved adverse media or a screening hit that could not be cleared
  • Digital-asset exposure, including customers whose counterparties are exchanges or mixers

/ What belongs in a defensible file

A file that holds up is one where a reviewer who was not there can reconstruct the decision. In practice that means:

  • The stated purpose of the relationship, and the expected activity that follows from it
  • Beneficial ownership established to a natural person, with the basis for each step recorded
  • Source of wealth and source of funds, evidenced rather than attested
  • Screening results with each hit either confirmed or excluded, and the reason stated
  • A written risk rationale — why this customer, at this rating, is acceptable
  • Named approval at the right level, dated
  • A defined review cadence, and evidence the reviews happened

/ The findings that surface most often

Across remediation work, the same handful recur — and almost none of them are about missing documents.

  • EDD performed but never documented as a conclusion, so the file shows activity without judgment
  • Beneficial ownership captured at the entity layer and never traced through to a person
  • Screening alerts closed with "no match" and no record of how that was determined
  • Source of wealth satisfied by the customer's own statement, uncorroborated
  • Periodic review dates passed with no evidence anything was reviewed
  • Risk ratings that never move, regardless of what the activity later shows

/ Where investigation becomes necessary

A large share of EDD is documentary and can be handled inside the compliance function. The remainder cannot: when ownership goes opaque, when adverse media cannot be resolved to a person, or when the stated source of wealth does not reconcile with the public record, you need someone to go and establish the facts.

That fieldwork runs through AM Forensics, our investigative practice — open-source intelligence, corporate registries, court and property records, with every finding cited to the record behind it, and written so it can be filed directly as the EDD record.

See how AM Forensics reports a subject

No-cost, no-obligation

AML Program Readiness Review

A 45-minute working session and a written one-page readiness memo scoring your program across the nine areas examiners open with. Delivered by the principal, not a sales engineer.

  • Nine-point scored readiness memo, in writing
  • Ranked list of the findings most likely to surface at exam
  • A straight answer on whether you need us at all

Business email required. We reply within one business day. We do not sell, share, or rent your details, and there is no mailing list attached to this form.

/ Questions we get asked

Is there a dollar threshold that triggers enhanced due diligence?
No. EDD is risk-based rather than threshold-based. What matters is that your risk assessment defines which relationships warrant it, that the definition is applied consistently, and that you can show why a given customer was or was not escalated. A program that applies EDD purely by transaction size usually has both over- and under-coverage.
How is EDD different from customer due diligence?
CDD establishes identity and expected activity for every customer. EDD applies additional scrutiny to higher-risk relationships — deeper beneficial-ownership work, corroborated source of wealth, closer ongoing monitoring, and senior approval. The practical difference is that EDD requires a documented judgment, not just additional collection.
Can we rely on the customer's own statement of source of wealth?
For lower-risk relationships, often yes. For the relationships that actually warrant EDD, an uncorroborated attestation is one of the most commonly criticised weaknesses. The expectation is that the stated source is tested against independent evidence in proportion to the risk.
How often should EDD customers be reviewed?
Your policy should set the cadence by risk rating and then the file should evidence that it happened. Annual is common for high-risk relationships, but the finding is rarely about the interval — it is that the review date passed and nothing in the file shows a review occurred.
Can Forteris perform EDD on our behalf?
We design the framework, test whether it is working, and remediate what is not. Where a specific subject needs investigating, AM Forensics performs that fieldwork and delivers a cited report you can file. We do not staff your ongoing queue — that is a different kind of firm, and we will say so.

/ Related

This page describes what supervisors generally expect and what a defensible file contains. It is general information, not legal advice, and it does not create an advisory relationship. Requirements are risk-based and vary by institution, charter, and jurisdiction — take advice on your own facts.