Enhanced Due Diligence, or EDD, is a higher level of customer investigation applied when standard Customer Due Diligence does not sufficiently address the identified risk.
EDD is not intended for every applicant. Under the risk-based approach, businesses should apply stronger measures where money-laundering, terrorist-financing, identity-fraud, or sanctions risks are higher. FATF also emphasizes proportionality: enhanced measures for higher risk and simplified measures where lower risk is established. FATF Recommendations
For digital platforms, EDD combines compliance investigation with stronger identity assurance. Face++ face verification, liveness detection, and biometric search can support the identity layer, while screening, ownership, source-of-funds, and transaction checks are handled by the broader AML framework.
1. Politically Exposed Person Exposure
A customer identified as a politically exposed person, or closely connected to one, may require enhanced measures because their position can increase corruption or bribery exposure.
Depending on applicable regulations and the risk assessment, additional controls may include:
- Establishing source of wealth and source of funds
- Obtaining senior-management approval
- Understanding the intended account activity
- Applying enhanced ongoing monitoring
- Verifying beneficial owners and connected parties
PEP databases alone may not be sufficient. FATF guidance recommends effective CDD and consideration of additional information and risk indicators. FATF PEP Guidance
Face++ can strengthen identity verification by comparing the applicant’s live face with a trusted document portrait and confirming genuine presence through liveness detection.
2. High-Risk Geographic Exposure
EDD may be required when a customer, beneficial owner, transaction, or business relationship is connected to a jurisdiction presenting elevated AML/CFT risk.
FATF calls for enhanced due diligence for jurisdictions subject to a call for action. However, being placed under increased monitoring—the “grey list”—does not automatically mean that EDD must be applied to every customer from that jurisdiction. FATF instead calls for a proportionate, risk-based assessment. Platforms should always consult the latest FATF statements and local regulatory requirements. FATF High-Risk and Monitored Jurisdictions
Geographic risk should not be assessed in isolation. Residence, nationality, IP location, device location, transaction destination, and business activity may point to different jurisdictions.
3. Complex or Unclear Beneficial Ownership
Corporate customers may require EDD when their ownership structure is unusually complex, involves multiple jurisdictions, or makes it difficult to identify the person who ultimately owns or controls the entity.
Common triggers include:
- Multiple holding companies without a clear commercial purpose
- Nominee shareholders or directors
- Trusts or legal arrangements obscuring control
- Ownership information that conflicts across sources
- Frequent changes in directors or beneficial owners
- Reluctance to provide supporting documents
EDD should establish the ownership chain, verify relevant individuals, and document the purpose of the structure. Face++ face verification can help bind a remotely presented beneficial owner or authorized representative to their submitted identity evidence.

4. Unusual Source of Funds or Expected Activity
EDD may be triggered when the customer’s stated income, occupation, business model, or expected account activity does not reasonably explain the funds involved.
Examples include:
- High-value funding immediately after onboarding
- Transactions inconsistent with the customer profile
- Payments involving unrelated third parties
- Unexpected cross-border transfers
- Rapid movement of funds through a new account
- Unclear source of wealth or source of funds
Platforms may request bank statements, contracts, tax documents, corporate records, or other evidence. These documents should be checked for consistency rather than accepted solely because their text is readable.
5. Identity Evidence Is Inconsistent or Suspicious
EDD can also arise from identity risk. The applicant may submit valid-looking information while individual signals remain inconsistent.
Key warning signs include:
- Document details conflicting with user input
- Different names or dates across submitted evidence
- A document portrait that poorly matches the current user
- Signs of document manipulation or recapture
- Liveness or injection anomalies
- One face associated with multiple claimed identities
- Repeated onboarding attempts across linked devices
Face++ supports stronger identity assurance through 1:1 face comparison, liveness detection, and 1:N face search. These capabilities help determine whether the applicant matches the presented identity, is genuinely present, or may be linked to previous applications.
6. High-Risk Products, Channels, or Customer Profiles
The nature of the service may increase risk even when the customer’s identity appears normal. Relevant factors can include high transaction limits, cross-border payments, virtual assets, private banking, cash-intensive businesses, remote company formation, or products that allow rapid movement of value.
Non-face-to-face onboarding is not automatically suspicious, but weak remote controls can increase impersonation and document-fraud exposure. A digital EDD workflow should therefore combine compliance risk with document, biometric, device, and session evidence.
Face++ face verification and liveness detection can serve as step-up controls for applicants entering higher-risk products or requesting elevated account privileges.
7. Sanctions, Adverse Information, or Fraud Links
Potential sanctions exposure, material adverse information, internal blacklist matches, or links to known fraud networks can trigger EDD or prevent onboarding entirely.
The appropriate response depends on the type and reliability of the match. A name match may require disambiguation using date of birth, nationality, address, identification number, and other attributes.
Biometric evidence can add another identity-binding layer. For example, Face++ face search may help identify whether an applicant’s face is connected to previously flagged identities, subject to applicable law, consent, data governance, and configured thresholds.

8. What Enhanced Due Diligence Usually Includes
An EDD workflow may involve:
- Collecting additional identity or corporate documents
- Identifying and verifying beneficial owners
- Establishing source of wealth and source of funds
- Clarifying the purpose and expected nature of the relationship
- Obtaining internal approval before onboarding
- Applying stronger face verification and liveness controls
- Increasing the frequency and depth of ongoing monitoring
- Recording evidence, decisions, and reviewer rationale
Not every trigger should produce the same response. A risk engine can determine whether to request additional evidence, initiate Face++ identity reverification, route the case to manual review, or decline the relationship.
9. Frequently Asked Questions
Q1. Is EDD required for every PEP?
Requirements vary by jurisdiction and PEP category. Businesses should follow applicable regulations and assess the person’s role, geography, ownership structure, source of funds, and other risk factors.
Q2. Does a FATF grey-list connection automatically require EDD?
No. FATF does not call for automatic EDD solely because a jurisdiction is under increased monitoring. The relationship should be assessed proportionately using the complete risk context.
Q3. Can Face++ perform the entire EDD process?
Face++ supports the identity assurance component through face comparison, liveness detection, and face search. Complete EDD also requires AML screening, beneficial-ownership analysis, source-of-funds checks, risk assessment, approvals, and ongoing monitoring.
Q4. Should EDD end after onboarding?
No. Customer risk can change. New transactions, ownership changes, sanctions alerts, device anomalies, or account-recovery events may require renewed investigation and identity reverification.
10. Apply EDD Proportionately
EDD should provide deeper evidence where risk is genuinely elevated—not simply add friction to every digital customer.
A strong digital onboarding architecture combines compliance screening, ownership and financial evidence, document validation, Face++ face verification, liveness detection, and ongoing risk monitoring. This layered approach helps platforms investigate high-risk applicants more effectively while preserving a streamlined experience for lower-risk users.
This article provides general information and is not legal advice. EDD requirements depend on the applicable jurisdiction, sector, and regulatory framework.



