CDD and EDD sit at the heart of every regulated firm's defences, yet the distinction between the two is often misunderstood.

In short, CDD is the standard set of checks a firm performs on every customer to confirm identity and gauge risk, while EDD is the deeper investigation reserved for those customers whose risk profile demands it. CDD is the baseline that applies to everyone; EDD is the escalation for higher risk, detailed Opoint.

Opoint recently communicated with its readers what is the difference between CDD and EDD.

CDD acts as the front door of compliance. It confirms who the customer is, establishes the nature of the relationship and assesses the level of risk they present. For the vast majority of customers, this standard process is sufficient on its own, and no further scrutiny is required.

EDD, by contrast, is triggered when a customer or counterparty is assessed as carrying elevated risk. It layers on source-of-funds and source-of-wealth verification, mapping and verification of beneficial ownership, closer adverse media screening and tighter ongoing monitoring throughout the relationship. Where standard due diligence answers who a customer is, EDD is designed to build the full picture of the risk they carry.

The move from CDD to EDD is not arbitrary. Under a risk-based approach, escalation is driven by the assessed level of risk rather than a fixed category. Common triggers include politically exposed persons, customers based in high-risk jurisdictions, correspondent banking relationships, complex or opaque ownership structures, and unusual transaction patterns. Once any of these red flags appear, the standard checks are no longer enough.

The differences show up clearly in practice. Under CDD, source of funds is not usually required and beneficial ownership only needs basic identification, with periodic monitoring and standard adverse media screening. Under EDD, source of funds must be verified, ownership must be mapped in full, monitoring becomes more frequent, and adverse media screening becomes closer and continuous.

Adverse media is where the two regimes most visibly diverge. Both involve screening, but the intensity differs, and in both cases the screening is only as strong as the news coverage feeding it.

Risk on a high-risk counterparty frequently surfaces first in local-language reporting, meaning that for EDD in particular, the breadth and linguistic reach of the underlying data determine whether the deeper scrutiny actually catches what it should. For RegTech providers and compliance teams alike, that data question is fast becoming the real differentiator.

Read the full Opoint post here.