CDD, SDD and EDD Decisioning

Customer due diligence is not a choice between three universally defined packages called simplified, standard and enhanced. The safer mental model is a legal and policy baseline plus risk-sensitive calibration. Every bank first has to identify the obligations that apply to the customer, product, legal entity and jurisdiction. It then decides what additional or reduced measures are justified by the assessed money-laundering and terrorist-financing risk, subject to the limits in applicable law. That distinction matters because FATF sets global standards, while national and regional laws determine exactly when simplified measures are permitted, when enhanced measures are mandatory, which approvals are required and what a bank must do if it cannot complete due diligence.

FATF Recommendation 10 establishes core customer-due-diligence expectations: identify and verify the customer, identify the beneficial owner and take reasonable measures to verify beneficial ownership, understand the purpose and intended nature of the relationship, and conduct ongoing due diligence. FATF Recommendation 1 then provides the risk-based architecture. Higher risk calls for enhanced measures. Identified lower risk may permit simplified measures where the legal framework allows them. Simplified measures are not appropriate where there is suspicion of money laundering or terrorist financing. These are standards for national implementation, not a single worldwide operating procedure.

This chapter therefore uses SDD, baseline CDD and EDD as practical labels rather than pretending they mean identical things everywhere. The important question is not “Which box does this customer sit in?” but “What facts must the bank understand, what evidence is proportionate, what mandatory measures apply, what uncertainty remains, and who is authorised to accept the residual risk?”

Risk-based CDD calibration showing legal baseline, lower-risk simplification, higher-risk enhancement and the suspicion boundary.

Start with the legal baseline, not the tier label

A useful CDD decision begins by separating three layers that are often mixed together in operating procedures.

The first layer is mandatory law and regulation. Examples may include customer identification, beneficial-owner identification, PEP measures, correspondent-banking requirements, high-risk-country measures, sanctions controls, record keeping and suspicious-transaction reporting. Some requirements are triggered by a specific circumstance and cannot be removed simply because a scoring model produces a low customer-risk rating.

The second layer is the bank's risk-based control design. Here the institution decides what information, evidence, review depth and monitoring intensity are proportionate to the risk it has identified. A low-risk retail relationship may justify a lighter evidence burden where local rules allow it. A complex corporate structure, opaque ownership, unusual activity, higher-risk geography, correspondent exposure or another material risk factor may justify deeper work. The measures should answer the risk rather than simply add documents.

The third layer is institutional risk appetite and policy overlay. A bank may decide not to offer a product or accept a relationship that law would technically permit. It may also require stronger evidence or more senior approval than the legal minimum. That is a policy choice and should be described as such. Treating internal policy as if it were a universal legal rule creates poor training and weak requirements.

For a business analyst, this three-layer model is extremely useful. Requirements should identify the legal trigger, the policy rule, the risk rationale, the evidence required, the decision owner and the customer or transaction outcome separately. A single field such as eddRequired = true is usually too crude to explain why the requirement exists or what action follows.

Baseline CDD: know the customer well enough to make and maintain a decision

Baseline CDD is the normal foundation of the relationship. It should establish who the customer is, who owns or controls a legal entity where relevant, what the relationship is for, what activity is reasonably expected, and what information must be kept current. The exact verification method depends on the applicable regime, customer type, delivery channel and risk.

For an individual, the bank may need identity attributes, verification evidence, address or contact information, occupation or source-of-income context and the expected use of products. For a company, the bank may need legal existence, ownership and control, authorised persons, business activity, operating geographies, expected counterparties or corridors and product purpose. A trust or another legal arrangement may require a different set of parties and control relationships. The point is not to force every customer into the same evidence pack. The point is to obtain enough reliable information to meet legal obligations and support a defensible risk understanding.

Purpose and intended nature are especially important. “Payments” or “business use” is rarely a useful baseline. A good profile explains why the account exists, what products will be used, the broad sources and destinations of funds, expected scale and frequency where relevant, and the commercial or personal rationale. Those expectations then help the bank interpret later behaviour. They are not hard transaction limits unless the product or policy deliberately makes them so.

Ongoing CDD closes the loop. Customer information can become stale when ownership changes, a company enters new markets, account activity changes, a PEP connection emerges, adverse information becomes relevant or the relationship begins using a new product. Good control design combines periodic review where required with event-driven refresh. In the United States, for example, FFIEC material describes ongoing monitoring and risk-based updating of customer information; that framework should not be projected onto other jurisdictions as a universal timetable.

Simplified due diligence: reduced measures, not absence of due diligence

Simplified due diligence is frequently misunderstood as a “low-risk customer shortcut.” It is better understood as proportionate reduction of particular measures where lower risk has been identified and applicable law permits simplification. The customer still has to be understood sufficiently for the bank to know that simplified treatment remains appropriate.

FATF's risk-based framework supports simplified measures for identified lower-risk situations, subject to national implementation, and explicitly connects proportionality with financial inclusion. It does not say that an entire customer category is permanently low risk. A regulated financial institution, public body, low-value product or other category may receive different treatment under local law, but the bank still has to apply the actual eligibility conditions and remain alert to facts that contradict the lower-risk assessment.

SDD therefore should not be designed as a universal recipe such as “one document instead of two” or “database verification instead of biometrics.” Those are implementation choices that may be appropriate in one institution and inappropriate in another. The correct design question is: which measure can be simplified, why is the remaining control sufficient for the identified lower risk, and what would cause the simplification to stop?

A simplified relationship still needs meaningful monitoring and a mechanism for re-assessment. If activity changes materially, ownership becomes more complex, a new geography or product changes the risk, or information creates suspicion, the bank cannot rely on the old low-risk label. FATF also makes an important distinction between countries under increased monitoring and countries subject to a call for action: being on the “grey list” does not itself mean FATF calls for EDD or indiscriminate de-risking of all customers connected to that jurisdiction.

Enhanced due diligence: answer the specific higher risk

EDD means deeper or additional measures because the risk or a specific legal trigger requires them. It is not a global checklist. Different laws specify different EDD triggers and measures. PEPs, correspondent relationships, high-risk jurisdictions and particular unusual or complex situations may carry specific obligations depending on the jurisdiction. A bank's own risk assessment can also lead to enhanced measures where standard information does not provide enough confidence.

A strong EDD decision starts by naming the risk question. If ownership is opaque, the answer may be deeper ownership and control evidence. If the concern is wealth inconsistent with profile, source-of-funds or source-of-wealth work may be relevant. If a correspondent relationship creates nested exposure, the bank may need stronger understanding of the respondent's business, controls and underlying customer access. If digital impersonation is the problem, stronger identity assurance may matter more than collecting financial statements. Adding unrelated documents creates burden without reducing the risk.

Australian AUSTRAC guidance illustrates this targeted approach clearly in its own legal context: enhanced CDD measures should be targeted to the customer's ML/TF risk, proportionate and effective, and source-of-funds or source-of-wealth work is not relevant to every type of risk. That is a useful operating principle, but the Australian trigger set should remain labelled as Australian rather than taught as a global rule.

The United Kingdom provides a current example of why a country trigger needs an effective date. From 30 June 2026, regulation 19 of the Money Laundering and Terrorist Financing (Amendment) Regulations 2026 (SI 2026/621) changes the automatic country trigger in regulation 33(1)(b) of the 2017 Regulations to a FATF call-for-action country. This is the FATF list of High-Risk Jurisdictions subject to a Call for Action, as it changes over time. A grey-list connection alone is therefore not this UK automatic country trigger. The separate obligation to apply enhanced measures where the bank identifies higher risk remains; country exposure still contributes to that assessment. Preserve the country-list version, connection facts and legal or risk-based reason for enhancement instead of using one undated highRiskCountry flag.

EDD also does not mean the bank has already formed suspicion. Higher risk, complexity, a PEP connection, unusual behaviour and suspicion are different concepts. An unusual transaction may be legitimate once understood. A high-risk relationship may be acceptable with appropriate controls. Conversely, a customer can create reportable suspicion even if the relationship was originally assessed as ordinary risk. Systems and procedures should keep those decision types separate.

The suspicion boundary

The suspicion boundary is one of the most important controls in CDD decisioning. SDD cannot be used as a way to avoid investigating facts that create suspicion. If information reaches the applicable suspicious-reporting threshold, the bank must follow the reporting and confidentiality rules of the relevant jurisdiction. Whether the relationship is rejected, restricted, continued or exited is a separate decision that can depend on law, risk appetite, law-enforcement considerations and tipping-off restrictions.

This distinction prevents two common errors. The first is automatic escalation from “unusual” to “suspicious.” The second is automatic relationship exit once an STR or SAR is filed. Neither is a universal rule. The reporting decision and the customer-relationship decision should be independently reasoned, even though they may draw on the same evidence.

Decision authority model separating mandatory legal triggers, risk-based evidence, bank policy and final accountable approval.

Approval authority: consequence and legal trigger should drive the workflow

There is no universal rule that standard CDD must be approved by a team leader, EDD by an independent senior and the highest risk by an executive committee. Some jurisdictions impose senior-management approval for particular situations; banks may impose additional approval requirements through policy. The workflow should therefore be parameterised rather than hard-coded around a mythical global hierarchy.

A practical approval record should show the assessed risk, mandatory trigger if any, information reviewed, unresolved uncertainty, mitigating controls, policy exceptions and the person or forum authorised to decide. Where commercial teams own the relationship, risk and compliance challenge should be protected from inappropriate sales pressure. That does not always require a different reporting line for every EDD case, but it does require clear decision rights, escalation paths and auditable rationale.

For technology design, the approval engine should support jurisdiction, legal entity, customer type, product, risk trigger and policy version. It should also preserve effective dates. A decision made under policy version 7 must remain reconstructable after policy version 9 is introduced. This is essential for audit, investigations and regulatory review.

Evidence depth: corroborate propositions, not document counts

CDD quality is not the number of documents in the file. Evidence should test the propositions needed for the decision. If the proposition is that a company is actively trading, registry existence alone does not prove commercial substance. If the proposition is that a large incoming payment is proceeds from a property sale, a sale agreement may help but settlement evidence and ownership history may be more relevant. If the proposition is that an intermediary has effective AML controls, a policy manual alone does not establish operating effectiveness.

Evidence can also conflict. A reliable register may show one owner while the customer declares another because a recent transfer has not yet been reflected. A negative media article may contain allegations but little evidence. A source-of-wealth narrative may be plausible but only partially corroborated. Good decisioning records the conflict, seeks proportionate clarification and states the residual uncertainty rather than manufacturing false certainty.

This approach is particularly important for EDD. “More evidence” is not synonymous with “better evidence.” The bank should ask what additional information would materially change the decision. Where additional collection cannot reduce the relevant risk, another control or a risk-acceptance decision may be more appropriate.

Tier maintenance through the relationship lifecycle

A customer's CDD treatment can change in either direction. The trigger can come from the customer, an external source or observed behaviour. Ownership restructuring, a change in business, a new country connection, a sanctions or PEP update, a new product, an unexplained transaction pattern or improved transparency can all justify reassessment.

The change should not be automatic merely because one data point moved. A new country connection may be ordinary expansion. A PEP match may be a false positive. A complex ownership chain may have a legitimate commercial reason. Reassessment asks whether the information changes the risk and which control should change as a result.

Downgrading also needs a reason. Time alone does not prove that a risk has disappeared. But neither should EDD become a permanent label after its rationale has ceased to exist. The bank should record which risk factor changed, what evidence supports the change, and whether mandatory legal measures continue to apply.

Customer due-diligence lifecycle from onboarding through event triggers, reassessment, adjusted measures and ongoing monitoring.

Data and system touchpoints

CDD decisioning touches more systems than the KYC platform. Customer master data holds identity and legal-entity attributes. Beneficial-ownership services or registries supply ownership evidence. Screening platforms contribute sanctions, PEP and sometimes adverse-information results. Transaction-monitoring systems generate behavioural information. Case management preserves investigations and decisions. Product platforms know what services the customer actually uses. Payment data reveals counterparties, corridors and transaction context. Data warehouses and reporting layers support portfolio-level control testing.

A mature data model keeps facts, risk indicators, legal triggers, policy rules and outcomes separate. For example, countryOfIncorporation, fatfCallForActionConnection, customerRiskRating, eddLegalTrigger, eddPolicyTrigger, approvalRequirement, relationshipDecision and strFiled are not interchangeable. Combining them into one risk flag makes it difficult to explain why a customer was treated differently and creates dangerous side effects when one signal changes.

Every material input should have provenance and an effective date. The system should be able to answer: what information did the bank know on the decision date, which rule version evaluated it, what evidence supported the outcome, who approved it, and what later event changed the decision? That is the difference between a workflow that merely stores today's status and an auditable control system.

BA, architecture and testing considerations

Requirements should begin with decision tables rather than screen mock-ups. For each trigger, identify whether it comes from law, policy or risk appetite; which jurisdiction and legal entity it applies to; the required information; the permitted outcomes; the approval role; any customer-communication constraint; and the evidence that must be stored. Avoid a single global “EDD list.” A configurable rule set is safer where the bank operates across jurisdictions.

Testing should include both positive and negative cases. A genuine lower-risk customer should not be forced through unnecessary enhanced checks. A customer with a mandatory EDD trigger should not be downgraded by a low model score. A false PEP match should not permanently raise the customer's tier after resolution. A material ownership change should trigger reassessment. A suspicious-activity decision should follow the correct reporting workflow without automatically forcing an exit unless policy or law separately requires that outcome.

Boundary testing is particularly valuable. Test customers just inside and outside policy thresholds, changes that occur after onboarding, missing or conflicting data, unavailable external services, policy-version changes and transfers between legal entities. Test for customer harm as well as missed financial crime: duplicate requests, inaccessible evidence demands, unjustified account restrictions, excessive review delays and inappropriate disclosure of confidential investigation activity are all control-quality issues.

Practical mini case: a growing import business

Consider a fictional domestic wholesaler that has banked for several years with a transparent ownership structure and predictable local supplier payments. It now begins importing industrial components, opens new foreign-currency facilities and adds suppliers in several jurisdictions. None of those facts proves higher risk. They do, however, make the original customer profile incomplete.

The bank reassesses the relationship. Registry records confirm that ownership is unchanged. Trade documentation supports the new business line. Expected payment corridors and volumes are updated. One supplier is in a jurisdiction with elevated corruption risk, so the bank asks for more context on the commercial relationship and applies the relevant screening and monitoring controls. The information supports a plausible expansion, and no reporting threshold is met.

The outcome might be continued baseline CDD with additional trade-related monitoring, or EDD if the institution's policy and local legal framework identify a higher-risk trigger. The important point is that the decision is evidence-led. The bank does not automatically label all cross-border trade as EDD, and it does not preserve the old low-risk profile after the business has materially changed.

Months later, a different event occurs: payments begin flowing through an unrelated intermediary with no obvious role in the supply chain. The bank investigates the change. If a legitimate logistics or procurement arrangement explains it, the profile can be updated. If the explanation and evidence do not resolve material concerns, the matter can move to investigation and, where the legal threshold is met, suspicious-transaction reporting. Relationship restriction or exit is then assessed separately.

What good looks like

A strong CDD-calibration framework can explain every material decision in plain language. It knows which parts of the process are mandatory, which are risk-based and which are bank policy. It uses simplified measures only where permitted and justified. It applies enhanced measures to the risk that actually needs mitigation. It separates unusual activity, higher risk and suspicion. It preserves evidence and rule versions. It allows justified movement in both directions through the lifecycle. And it measures quality through defensibility, timeliness, control coverage, overdue work, customer impact and the effectiveness of risk mitigation rather than treating SAR or STR volume as a production target.

That final point matters. A programme does not become better merely because an EDD population produces more reports. Reporting rates can be useful diagnostic information, but they are influenced by customer mix, products, typologies, thresholds and investigative practice. The better question is whether the bank identifies the risks it is required to manage, obtains proportionate evidence, makes timely and consistent decisions, escalates genuine suspicion correctly, and can reconstruct why it did so.

Operational deep dive: building a risk-based CDD decision engine

The base chapter separates mandatory obligations, risk-based measures and bank policy. This deep dive turns that distinction into a workable operating model for onboarding, review, monitoring and technology. The objective is not to manufacture a universal three-tier rulebook. It is to make every material CDD decision traceable to a legal or policy basis, an assessed risk and a proportionate response.

1. Build the rule model in layers

A bank operating across countries should avoid one global CDD_TIER table that silently assumes every legal entity follows the same rules. A safer rules model has at least four layers.

Layer one: mandatory triggers. These are obligations arising from applicable law or regulation, such as particular PEP measures, correspondent-banking requirements, high-risk-country measures or specified customer-identification requirements. Their implementation can vary materially by jurisdiction.

Layer two: customer and relationship risk. This combines relevant customer, ownership, product, channel, geography and behavioural factors. The model should not treat nationality or industry alone as proof of high risk. It should record the reason a factor matters and the information that supports it.

Layer three: proportionate controls. This determines which additional or simplified measures address the identified risk. Examples can include deeper ownership corroboration, additional purpose information, source-of-funds work, stronger identity assurance, a specialist review or a particular monitoring treatment. The measure should be connected to the risk it is intended to reduce.

Layer four: institutional policy and risk appetite. A bank may apply stricter requirements than the legal minimum, or decide not to offer a product in a particular risk combination. The system should label that clearly as policy rather than present it as universal law.

This layered design is especially useful when laws change. A policy team can change a rule for one legal entity or jurisdiction without rewriting the meaning of the customer's underlying risk data.

2. Treat SDD as a controlled exception to normal depth

Simplified treatment needs a positive basis. The bank should be able to answer which legal or policy provision permits the simplification, which risk assessment supports lower risk, what measure is being simplified and what information remains mandatory.

A useful decision record might capture:

Decision elementExample question
Eligibility basisWhat law, regulation or policy permits simplified treatment?
Lower-risk rationaleWhat facts support lower risk in this relationship?
Measure simplifiedWhich verification or review step is reduced, delayed or streamlined?
Controls retainedWhat CDD, screening and monitoring still apply?
DisqualifiersWhat facts would immediately end simplified treatment?
Review triggerWhat customer or behavioural change causes reassessment?

This prevents “SDD” from becoming shorthand for weak onboarding. It also supports financial inclusion: the institution can remove unnecessary burden where lower risk is genuinely established without abandoning the control framework.

3. Design EDD around a risk question

EDD works best when analysts are asked to resolve a specific uncertainty rather than collect a generic document pack. The case record should state the higher-risk factor or mandatory trigger and translate it into a question.

If a structure is unusually opaque, the question may be who ultimately owns or controls the customer and why the structure exists. If transaction behaviour is inconsistent with the known business, the question may be whether the change is commercially plausible. If a customer is a PEP, the applicable jurisdiction may require particular measures such as senior approval or source-of-wealth/source-of-funds work. If a correspondent bank provides indirect access to nested institutions or customers, the relevant question may be whether the respondent's control environment and transparency are adequate.

The evidence plan then follows the question. It can use registry information, customer explanations, contracts, independent databases, financial statements, transactional evidence, open sources or specialist analysis as appropriate. The analyst should record what each source proves and what it does not prove. A corporate registry can support legal existence and registered ownership; it does not by itself establish commercial substance or lawful source of funds.

4. Separate risk escalation from suspicious-activity reporting

Many weak workflows join these concepts too early. A customer can be higher risk without being suspicious. A transaction can be unusual without meeting a reporting threshold. A customer originally treated as ordinary risk can later generate suspicion.

The case workflow should therefore maintain separate fields for:

  • customer-risk assessment and rationale;
  • CDD or EDD measures required;
  • unusual-activity or investigation trigger;
  • suspicion decision under the relevant jurisdiction;
  • reporting status and confidentiality restrictions;
  • relationship decision such as continue, restrict, reject or exit.

This separation matters operationally. It prevents a risk score from automatically creating a SAR/STR and prevents a report from automatically causing account closure where law and policy do not require that outcome.

5. Approval workflow should be configurable, not mythical

Approval requirements vary. Some legal regimes require senior-management approval for particular circumstances, while others leave more detail to institutional policy. A global platform should therefore resolve the required authority from the combination of legal entity, jurisdiction, trigger, customer type, product and policy version.

Configurable approval workflow separating legal trigger, risk assessment, policy overlay and accountable decision.

The workflow should preserve the decisioner's role, the evidence considered, any dissent or exception, and the effective policy version. Where a relationship is commercially significant, conflict-management is important: risk and compliance challenge should not be diluted because revenue is high. However, the control should not invent a universal rule that every EDD case must be decided by a committee or by a person outside the business reporting line. The correct authority is the one required by applicable law and the bank's approved governance framework.

6. Migration: change the measures when the risk changes

Risk can increase or decrease. Migration should be driven by evidence, not by an arbitrary desire to keep customers permanently in one bucket.

Common reassessment triggers include material ownership change, new products, significant geographic expansion, business-model change, PEP status, material adverse information, unexplained transaction patterns, new correspondent or intermediary exposure, or a major control failure at a partner. Each trigger should open only the review needed to reassess the changed risk unless law requires a broader review.

A downgrade should be possible when the reason for enhanced treatment no longer applies and mandatory requirements allow it. For example, a complex ownership structure may be simplified and independently verified, or an adverse allegation may be resolved. The bank should document why the risk reduced and which enhanced measures can therefore be removed. Time elapsed on its own is weak evidence of risk reduction.

7. Monitoring intensity should follow risk without becoming a false-positive factory

Risk-based monitoring does not mean blindly lowering every monetary threshold for EDD customers. That can create large alert volumes with little additional detection value. Instead, monitoring should reflect the relevant risk: scenarios, peer groups, behavioural expectations, counterparties, corridors, products and event triggers may be more useful than a simple amount threshold.

The same principle applies to SDD. Lower-risk customers still need monitoring sufficient to identify behaviour inconsistent with the lower-risk assumption and to detect suspicious activity. Simplification at onboarding cannot remove the need to notice meaningful change.

Effectiveness measures should not reward SAR/STR volume. Reporting rates can be examined diagnostically, but higher conversion is not proof that a tier is better calibrated. Better measures include overdue reviews, time from trigger to reassessment, quality of rationale, evidence completeness, control coverage, false-positive burden, customer harm, quality-assurance findings, unresolved exceptions, data lineage and whether known risk indicators were actually addressed.

8. Data lineage and effective dating

Every material CDD decision should be reconstructable. Store the customer facts as they were known at the time, their sources and verification status, the rule set and policy version used, the risk factors evaluated, the measures applied, the approval, and later events that changed the outcome.

This creates an “as-at” view. If a customer is reviewed in 2028, investigators should still be able to reconstruct what the bank knew in 2026 rather than see only the latest overwritten profile. Effective dating is particularly important for ownership, PEP status, country risk, product use and policy rules.

Architecture teams should avoid deriving legal decisions from mutable reference data without versioning. If a country-risk table changes today, historical decisions should not silently appear to have been made under today's classification.

9. Testing the decision engine

Testing should prove both protection and proportionality.

Positive cases should include a mandatory EDD trigger, a genuine lower-risk SDD case where simplification is legally permitted, a customer whose behaviour materially changes after onboarding, a PEP false positive, a complex legal entity with transparent ownership, a genuinely opaque ownership structure, and an unusual transaction that is ultimately explained without suspicion.

Negative and boundary testing should prove that a low risk score cannot override a mandatory legal measure; that SDD is stopped when suspicion exists; that a resolved screening false positive does not leave an unexplained permanent risk uplift; that policy exceptions route to the correct authority; and that an STR/SAR workflow does not automatically disclose confidential reporting information to customer-facing systems.

Failure-mode tests should cover unavailable registries, stale data, external-screening outages, duplicate events, conflicting ownership information, rule-engine version changes and queue backlogs. Where a control cannot complete, the fallback must comply with local law and policy rather than improvising a universal response.

10. Practical design example

A corporate customer operates a domestic logistics business and has historically used local payments. It acquires a smaller company and begins cross-border freight activity. The change event opens a reassessment. The bank verifies the new ownership chain, updates the purpose and expected activity, assesses new geographies and products, and determines whether any mandatory legal trigger or policy EDD rule applies.

If the acquisition is transparent and the new activity is plausible, the bank may continue with baseline CDD plus specific monitoring for the new corridors. If the acquisition introduces opaque ownership through multiple entities and the customer cannot explain the structure, deeper beneficial-ownership work may be appropriate. If suspicious facts emerge, the matter moves to the relevant investigation and reporting process. Each transition is reasoned from evidence rather than from the label “international business.”

That is the standard a bank should aim for: not maximum friction, not minimum documentation, but the right measure for the right risk under the right legal framework, with an audit trail strong enough to explain the decision later.

Advanced practice: worked CDD calibration cases

These cases are fictional composites designed to practise judgement. They do not prescribe a universal tier or legal outcome. The correct decision in a live bank depends on the applicable legal entity and jurisdiction, the bank's policy, the product and the evidence available at the time.

Case 1: a regulated payment institution with nested customers

A licensed payment institution asks for settlement accounts. Its authorisation can be verified in the relevant regulator's public register and its direct corporate ownership is transparent. At first sight the relationship may appear suitable for streamlined treatment. During onboarding, however, the bank learns that a material part of the payment institution's activity comes from sub-merchants and other customers that will not be visible in ordinary settlement messages.

The correct question is not whether “regulated fintechs qualify for SDD.” The bank must first identify the legal and policy conditions for simplified treatment. It then asks whether the lower-risk rationale still holds when the business model creates nested exposure. The institution may have strong controls and transparent sub-merchant governance, in which case the bank can assess those facts. Or the institution may provide only aggregate information, leaving the bank unable to understand the risk it is accepting.

The outcome should follow the evidence. The bank could decide that ordinary CDD is sufficient, that targeted enhanced measures are needed around nested exposure, or that the relationship falls outside risk appetite. Licensing is relevant evidence, but it does not prove the operating effectiveness of the customer's controls and it does not create an automatic global SDD entitlement.

Control lesson: separate regulatory status, customer risk, transparency and the bank's own access to relevant information. Do not let a single label decide the whole relationship.

Case 2: a politically exposed person with a plausible wealth narrative

A senior public official seeks private-banking services and provides employment history, tax material and investment records that are broadly consistent with the stated wealth narrative. Open-source screening finds allegations of corruption, but the sources vary in credibility and no reliable evidence establishes wrongdoing.

PEP status is not proof of corruption. It is a risk factor to which specific measures may apply depending on the legal framework. FATF Recommendation 12 establishes global standards for PEP measures, but national implementation determines the exact obligations. The bank should therefore identify the applicable PEP requirements, assess source reliability, understand source of wealth and source of funds where required, and consider the customer's position, geography, business connections and transaction purpose without treating allegation as fact.

If the evidence supports the wealth narrative and mandatory measures are completed, the relationship may be acceptable with appropriate monitoring. If significant contradictions remain, the bank may seek further evidence, apply additional controls, decline the relationship under policy, or consider whether the reporting threshold is met. Those decisions are distinct.

Control lesson: EDD deepens understanding; it does not predetermine guilt, filing or exit.

Case 3: an MSB with a large agent network

A money-services business wants expanded settlement facilities. Its head office has formal AML policies, but the bank's due diligence shows uneven quality across the agent network. Some agents have stronger onboarding and oversight than others, and management information is heavily aggregated.

The risk question is operational effectiveness. The bank may ask how agents are selected, how high-risk agents are identified, what monitoring the principal performs, what happens after control breaches and what information the bank can obtain when investigating a payment. Sample testing may be more useful than demanding another policy document.

The bank should not automatically classify all MSBs as unacceptable or all licensed MSBs as standard risk. The relationship might require additional transparency, contractual information rights, targeted monitoring or a different product limit. If serious control weaknesses cannot be mitigated, acceptance may be outside risk appetite.

Control lesson: assess the actual delivery model and control environment, not only the licence or sector label.

Case 4: a long-standing retail customer whose activity changes

A customer originally opened a straightforward domestic account for salary and household payments. Years later, the account begins receiving large credits from unfamiliar third parties and sending funds to new overseas beneficiaries. The customer explains that the activity relates to a family inheritance and an investment project.

The old onboarding assessment is no longer enough. Event-driven review should update the profile and test the explanation with proportionate evidence. The bank should not jump directly from “different from expected” to “money laundering.” It should first establish what changed, whether the explanation is plausible and supported, whether any mandatory enhanced measures apply, and whether suspicion remains after reasonable inquiry.

If the inheritance and investment rationale are corroborated, the profile can be updated and monitoring adjusted. If important inconsistencies remain, further investigation may be required. Reporting depends on the relevant legal threshold, not on the customer having moved from a lower-risk to a higher-risk profile.

Control lesson: CDD is a lifecycle control. Risk labels must be allowed to change when facts change.

Case 5: a correspondent relationship with limited transparency

A respondent bank seeks an expanded clearing relationship. It has a long operating history and is supervised in its home jurisdiction, but it also provides services to other financial institutions and non-bank payment businesses. The prospective correspondent cannot initially explain how it identifies and controls nested relationships or what information it can supply on underlying activity.

Correspondent banking has specific standards and, in many jurisdictions, legal requirements that go beyond ordinary customer onboarding. The bank should identify those obligations directly rather than treating “EDD” as a generic document list. It may need to understand the respondent's business, reputation, supervision, AML controls, ownership and management, payable-through or nested access, and the responsibilities of each institution.

Limited transparency does not automatically prove illicit activity. It does, however, affect whether the bank can understand and manage the relationship. A bank may require additional information, contractual transparency, product restrictions or remediation before acceptance. If the residual risk cannot be managed, it may decide not to proceed.

Control lesson: opacity is a risk-management problem; it is not by itself a finding of criminal conduct.

Case 6: a charity moving into a conflict-affected region

A domestic charity with a clean history plans humanitarian work through local partners in a conflict-affected region. The new geography materially changes the relationship. The response should not be automatic de-risking. FATF has repeatedly stressed proportionality and the need to avoid unnecessarily disrupting legitimate humanitarian assistance and NPO activity.

The bank should understand the programme, partner selection, payment routes, governance and the specific sanctions and terrorist-financing risks that apply. If a high-risk jurisdiction is involved, FATF statements and national implementation must be read carefully: countries subject to a call for action and countries under increased monitoring do not carry identical FATF expectations. Sanctions obligations must also be analysed separately from AML customer-risk classification.

Targeted enhanced measures might include stronger partner understanding, payment-purpose information or monitoring adapted to the programme. Where humanitarian exemptions, licences or other legal provisions are relevant, sanctions specialists may need to be involved. The aim is to manage the real risk without assuming that charitable or conflict-region activity is inherently suspicious.

Control lesson: risk-based CDD should enable lawful activity where risks can be understood and mitigated; it should not become category-based exclusion.

Case 7: a legacy private-banking structure

A family has banked with the institution for many years. Over time, the original operating company has been sold, family members have moved to several jurisdictions and assets are now held through trusts and investment vehicles. The relationship manager argues that the history of clean conduct should allow the old CDD treatment to continue.

Longevity is useful context but not a substitute for current understanding. The bank should reassess ownership and control, purpose, source of wealth where applicable, the role of legal arrangements and the products now in use. That review can be proportionate: a long-standing transparent relationship does not need suspicion manufactured around it, but material structural change needs to be understood.

If the updated information remains coherent, the bank can document the new profile and continue. If opacity or unexplained wealth creates higher risk, targeted EDD may be appropriate. Commercial importance should not suppress a control requirement, but neither should wealth alone be equated with suspicion.

Control lesson: history informs risk; it does not freeze a customer profile permanently.

Case 8: digital onboarding with coordinated mule indicators

A bank sees a surge of new low-value accounts linked by shared devices, repeated beneficiary patterns and rapid pass-through behaviour. Individual accounts appear modest, but network analysis shows coordination.

This is a good example of why “low value” is not synonymous with “low risk.” The institution should assess whether its simplified or streamlined onboarding design remains appropriate for the observed abuse pattern. Device intelligence, beneficiary connections, onboarding velocity and transaction behaviour may provide more useful evidence than asking every customer for more identity documents.

Some customers may be victims or unwitting mules; others may be complicit. The response should combine fraud, AML and customer-protection processes. Cases should be investigated at network level, with suspicious reporting where the legal threshold is met and customer restrictions applied according to law and policy.

Control lesson: controls should be calibrated to the abuse mechanism. Adding friction that does not address the mechanism is not effective EDD.

Practitioner close

Across all eight cases, the discipline is the same:

  1. identify the applicable legal and policy trigger;
  2. state the risk question in plain language;
  3. collect evidence that can actually answer that question;
  4. distinguish higher risk, unusual activity and suspicion;
  5. choose a proportionate control or relationship outcome;
  6. record the rationale, approval and effective date; and
  7. keep the decision open to reassessment when facts change.

That is more defensible than forcing every customer into a rigid global SDD/CDD/EDD ladder. It is also more useful to architects, operations and testers because each decision can be expressed as traceable rules, data and outcomes rather than judgement hidden behind a label.

Practice close: the CDD analyst and delivery playbook

This section converts the chapter into a practical sequence for analysts, reviewers, business owners, BAs, architects and testers. The central discipline is simple: do not start by choosing a label. Start by identifying the applicable obligation, the risk question and the evidence needed to answer it.

The decision sequence

1. Resolve the legal and policy context. Identify the booking entity, jurisdiction, customer type, product and any mandatory trigger. Distinguish binding requirements from internal policy and risk appetite.

2. Establish the customer facts. Confirm identity, legal existence where relevant, beneficial ownership or control, purpose and intended nature of the relationship, products requested and meaningful geographic or channel exposure.

3. Assess risk. Consider the relevant customer, product, delivery, geography, ownership and behavioural factors. Avoid single-factor determinism. A country connection, occupation, sector or complex structure may be relevant without proving higher risk by itself.

4. Decide whether simplification is permitted. If lower risk is identified, determine whether the applicable framework permits simplified measures, which measure may be reduced, what remains mandatory and what facts would end the simplified treatment. Never use SDD where suspicion exists.

5. If higher risk or a specific trigger exists, define the EDD question. State what additional uncertainty or legal requirement must be addressed. Choose evidence and controls that are relevant to that question rather than applying a generic document pack.

6. Resolve contradictions. Conflicting registry data, customer explanations, media information or transaction evidence should be investigated proportionately. Record uncertainty honestly rather than forcing false certainty into the file.

7. Route approval correctly. Determine the required authority from the applicable legal and policy rule. Do not assume one global hierarchy. Preserve the rationale, evidence, rule version and effective date.

8. Separate suspicion and relationship outcomes. If the legal reporting threshold is met, follow the confidential SAR/STR process. Decide continuation, restriction, rejection or exit separately according to law and policy.

9. Set ongoing controls. Update the expected profile, monitoring treatment, review triggers and any follow-up conditions. The decision must remain capable of changing when the facts change.

What analysts should write

A high-quality CDD rationale is short enough to understand and detailed enough to reconstruct. It should explain:

  • what triggered the review;
  • which legal or policy requirement applies;
  • the customer's relevant facts and risk factors;
  • the evidence obtained and its limitations;
  • unresolved uncertainty;
  • why the selected measures are proportionate;
  • who approved the decision; and
  • what event would cause reassessment.

Avoid statements such as “EDD complete, documents satisfactory.” They say nothing about the risk being addressed. Prefer reasoning such as: “The ownership change introduced a new corporate shareholder in another jurisdiction. Registry and constitutional documents establish the new legal chain and natural-person controller. No mandatory high-risk-country measure applies. The business purpose remains consistent with observed activity. The relationship continues with an updated ownership record and event-driven review for further control changes.”

Customer communication

CDD communication should ask for information clearly and only to the extent needed. Explain the category of information required without revealing confidential monitoring logic or suspicious-reporting activity. Where a request is burdensome, analysts should consider whether the same fact can be established through information already held or a reliable independent source.

Higher-risk treatment should not be communicated as an accusation. A customer may face additional questions because of a legal requirement, the complexity of the relationship or a change in risk. Clear wording reduces unnecessary conflict and improves evidence quality.

Vulnerable customers, accessibility needs and legitimate difficulty obtaining documents should be considered within the legal framework. A control is not made stronger by demanding an impossible document where another reliable method can satisfy the same requirement.

Common failure modes

Tier by stereotype. Treating every customer in a sector, nationality or geography as identical creates both control gaps and unnecessary exclusion. Remedy: document the specific risk factors and applicable legal triggers.

SDD as no CDD. Removing essential understanding because a customer is considered low risk makes the low-risk conclusion impossible to defend. Remedy: record the basis for simplification and the controls that remain.

EDD as document accumulation. Asking for more documents without a risk question wastes effort and may still leave the real risk unresolved. Remedy: connect every additional measure to the uncertainty or obligation it addresses.

Automatic suspicion from high risk. Higher risk does not automatically meet a reporting threshold. Remedy: preserve a separate suspicion decision with jurisdiction-specific criteria.

Automatic exit after reporting. Filing a SAR/STR does not universally require relationship exit. Remedy: route the relationship decision separately and respect confidentiality and tipping-off rules.

Unversioned rules. When policy or country-risk data changes, historical decisions become impossible to reconstruct. Remedy: effective-date the inputs and decision logic.

Backlog hidden as business as usual. A long queue of overdue EDD reviews means the intended control is not operating on time. Remedy: age the backlog, triage by risk, record temporary risk acceptance where appropriate and escalate capacity needs.

BA and architecture acceptance criteria

A delivery team should be able to test the following statements:

  1. Mandatory legal triggers cannot be overridden by a low general risk score unless the applicable rule explicitly permits an exception.
  2. SDD eligibility records the legal or policy basis, lower-risk rationale and disqualifying conditions.
  3. EDD records the trigger or risk question and the additional measure chosen.
  4. The approval role is resolved from configurable jurisdiction/entity/policy logic rather than a global hard-coded hierarchy.
  5. Customer facts, risk factors, legal triggers, suspicion status and relationship outcomes are stored separately.
  6. Historical decisions retain the rule and data versions used at the time.
  7. Material events can create a reassessment without forcing unnecessary full re-onboarding.
  8. A resolved false-positive screening match does not leave an unexplained permanent risk uplift.
  9. A SAR/STR filing status is access-controlled and not exposed to ordinary customer-service views.
  10. Monitoring and review treatment can change when the customer's risk profile changes.

Testing scenarios

Test at least one ordinary retail customer, one legal entity with transparent ownership, one complex but legitimate ownership structure, one PEP false positive, one confirmed PEP requiring the applicable measures, one customer connected to a FATF increased-monitoring jurisdiction, one customer connected to a call-for-action jurisdiction, one genuine lower-risk SDD case, one EDD case driven by bank policy rather than law, and one unusual transaction that is fully explained without a suspicious report.

Also test service failures. What happens if a registry is unavailable, an identity provider times out, a screening list is stale, a beneficial-ownership feed conflicts with customer information, or an approval queue exceeds its service target? The fallback should preserve legal requirements and expose unresolved risk; it should not silently mark a control complete.

Management information

Useful CDD management information should show whether the process works, not merely how many files were closed. Measures can include review timeliness, trigger-to-decision time, overdue cases by risk, policy exceptions, QA defects, evidence-request repetition, customer restrictions awaiting review, unresolved data-quality issues, rule-engine failures, model overrides and customer complaints linked to CDD.

SAR/STR volumes may be examined for context, but they should not be treated as a production target or proof of calibration quality. A strong CDD framework supports correct reporting decisions; it does not manufacture them.

Final practitioner test

Before closing a case, ask five questions:

  1. What exactly required or justified the level of due diligence used?
  2. Does the evidence answer the actual risk question?
  3. Have higher risk, unusual activity and suspicion been kept conceptually separate?
  4. Can another reviewer reconstruct the decision from the stored record and rule version?
  5. Is the ongoing profile clear enough that a future change will be recognised?

If those answers are defensible, the CDD decision is much stronger than one built around a label alone.

Masterclass: governing CDD calibration across a bank

CDD calibration is not only an onboarding problem. It is a governance problem spanning policy, customer operations, business ownership, compliance, financial-crime investigations, data, technology, model governance and assurance. A bank can have well-written SDD and EDD procedures and still fail if different businesses interpret the same trigger differently, if legal changes are not mapped to rules, or if the systems cannot explain why a particular measure was applied.

One control framework, multiple legal implementations

A global bank benefits from common principles: know the customer, understand beneficial ownership, understand the relationship, apply risk-sensitive controls and maintain the information through the lifecycle. But the implementation should retain jurisdictional specificity.

A central policy team can define the control objective and minimum design principles. Local legal and compliance teams identify mandatory triggers and national rules. Business and operations teams translate those requirements into procedures. Technology implements effective-dated rule logic. Assurance tests whether the control works in practice.

The key governance artefact is a requirement-to-control map. For every material CDD rule it should show:

  • the source of the obligation or policy requirement;
  • the affected legal entities and jurisdictions;
  • the trigger and scope;
  • the information and evidence required;
  • the approval authority;
  • the permitted or required outcomes;
  • the systems that implement the rule;
  • the control owner and testing approach; and
  • the effective date and version.

That map prevents a local rule from quietly becoming a global requirement and helps the bank explain deliberate differences between countries.

CDD governance model connecting legal interpretation, policy, operations, technology, data, assurance and accountable business decisions.

Governance should challenge both under-control and over-control

Financial-crime governance often focuses only on whether the bank did enough. Proportionality requires a second question: did the bank impose unnecessary or poorly targeted burden that did not reduce the relevant risk?

Over-control can create real harm. Repeated requests for the same evidence can delay access to accounts. Broad category-based EDD can exclude charities, migrants, small businesses or customers connected to higher-risk geographies even where risks are manageable. Unnecessary collection can also create privacy and data-retention exposure. FATF's recent work on proportionality and financial inclusion reinforces why a risk-based approach should not be interpreted as “more documentation is always safer.”

A governance forum should therefore review customer impact alongside control failures. Useful information includes unnecessary repeat requests, complaints about CDD, review delays, unworked trigger backlogs, policy exceptions, accounts restricted while reviews remain unresolved, false-positive escalation and evidence that a control is not addressing the risk for which it was designed.

Quality assurance: test reasoning, not just file completion

A completed checklist can hide a weak decision. Quality assurance should sample the reasoning chain: was the trigger identified correctly, was the legal or policy basis correct, was the customer information current, did the evidence answer the risk question, were contradictions resolved or explicitly accepted, and was the correct authority used?

Samples should include lower-risk cases as well as EDD. SDD deserves particular attention because an error can systematically reduce control depth across a large population. Boundary cases are useful: customers just inside and outside a policy condition, false-positive PEP matches, ownership changes, grey-list country connections and cases where enhanced treatment was later removed.

Do not set a target that EDD customers must generate more suspicious reports. SAR or STR rates can be reviewed as contextual data, but a reporting-rate target can distort investigator judgement and encourage unnecessary filing. The objective is correct risk identification, proportionate due diligence and correct reporting when the legal threshold is met.

Model governance for automated risk rating

Many banks use rules or models to generate customer-risk scores. The score can support CDD calibration, but it should not silently override mandatory obligations. A model that calls a PEP or another legally defined trigger “low risk” does not remove a measure that the applicable law requires.

Model governance should examine feature relevance, data quality, explainability, stability and unintended bias. A factor such as country, occupation, channel or product needs a documented reason for inclusion. Proxies that produce systematic disadvantage without a defensible financial-crime rationale should be challenged. Human overrides should be captured with reason codes and analysed for patterns; frequent overrides can indicate that the model or its inputs are wrong.

The model also needs versioning. When weightings change, the bank should know which customers were assessed under the old logic and whether re-assessment is needed. Historical investigations require the ability to reconstruct the decision that actually occurred, not the score the current model would produce today.

Change governance

Regulatory change can affect CDD rapidly. The change process should begin with legal interpretation and end with evidence that the operational control changed successfully. A practical sequence is: identify the change, determine applicability, assess policy impact, map affected rules and data, update procedure and training, configure systems, test positive and negative scenarios, deploy with an effective date, and monitor early outcomes.

Future-dated rules need particular care. For example, EU Regulation 2024/1624 is already law but generally applies from 10 July 2027. A September 2026 training chapter should not describe its future operating provisions as if they were already the general current rule. Requirements repositories should therefore record both publication and application dates.

Mergers, acquisitions and portfolio migrations

M&A exposes differences in customer-risk methodology, evidence standards and approval design. The acquiring bank should not assume that mapping “high to high, medium to medium, low to low” creates equivalent CDD. It should understand the underlying criteria and identify which legal or policy requirements change when customers move to a new entity or platform.

Portfolio migration should preserve evidence provenance and historical decisions. Where source records cannot be migrated cleanly, the bank should define a risk-based remediation plan rather than populate artificial “verified” flags simply to satisfy the new data model. High-risk or legally sensitive populations may need earlier remediation; low-risk records can be handled proportionately according to the applicable framework.

Crisis and capacity pressure

Large remediation programmes, sanctions events, acquisitions or system incidents can create CDD backlogs. Capacity pressure does not change the legal obligation, but the bank may need a risk-based triage model. That model should be approved, time-limited, transparent about what is deferred and supported by escalation where a control cannot be completed safely.

Emergency shortcuts should not become permanent through inertia. Once the crisis ends, the bank should review deferred work, customer restrictions and temporary policy exceptions. Management information should distinguish “accepted temporary risk” from ordinary compliant processing so that the backlog is visible rather than hidden inside normal workflow statistics.

What senior management should be able to answer

A senior owner does not need to know every KYC document. They should be able to answer whether the bank knows where SDD is legally permitted, where specific EDD measures are mandatory, how risk-based EDD is targeted, how mandatory triggers are protected from model overrides, how customer impact is monitored, how stale reviews are controlled, how policy changes reach systems, and whether historical decisions can be reconstructed.

Those questions create a much stronger programme than a dashboard showing only numbers of high-risk customers and completed reviews. Good governance makes the reasoning visible: what risk was identified, what rule applied, what evidence was obtained, what decision was made, who accepted it, and what will cause it to change?

Knowledge checks with explained answers

1. Does FATF define one universal SDD, standard CDD and EDD package for every bank?

No. FATF sets global standards and a risk-based architecture. Recommendation 10 establishes core CDD expectations, while Recommendation 1 requires enhanced measures for higher risk and allows simplified measures for identified lower risk where the national framework permits them. National and regional implementation determines the detailed legal obligations. A bank may add stricter policy requirements, but those should not be taught as universal law.

2. Is SDD the absence of CDD?

No. Simplified due diligence means that particular measures may be reduced or streamlined where lower risk has been identified and the applicable framework permits it. The bank still needs sufficient understanding to justify the lower-risk treatment and must retain controls capable of detecting material change or suspicion. FATF does not permit simplified measures where there is suspicion of money laundering or terrorist financing.

3. Does higher customer risk automatically mean an STR or SAR must be filed?

No. Higher risk, unusual activity and suspicion are different concepts. Higher risk can require enhanced measures. Unusual activity can require inquiry. A suspicious report is made when the relevant legal threshold is met. The reporting decision should not be derived automatically from a customer-risk tier.

4. Does EDD always require source-of-funds and source-of-wealth evidence?

No. Those measures are important in some legal contexts and risk situations, including certain PEP requirements, but they are not universally relevant to every higher-risk customer. EDD should address the risk being assessed. AUSTRAC, for example, explicitly notes in its Australian guidance that source-of-funds and source-of-wealth measures are not relevant to every ML/TF risk.

5. Can a low customer-risk score override a mandatory legal trigger?

No. Risk models support decisioning; they do not repeal legal obligations. If a particular jurisdiction requires a specified measure for a PEP, correspondent relationship, high-risk-country exposure or another defined condition, the system should enforce that requirement even if the general score is low.

6. Should an EDD case always be approved by a committee or executive?

Not as a universal rule. Approval obligations depend on applicable law and bank policy. Some circumstances require senior-management approval in specific regimes; others do not. The workflow should resolve authority from the actual trigger, jurisdiction, legal entity and policy version.

7. A customer onboards as lower risk but later begins materially different cross-border activity. What should happen?

The change should trigger reassessment. The bank should understand the new activity, update the customer profile, identify any new legal or policy requirements and decide whether different controls are needed. Different activity is not automatically suspicious, but the old lower-risk rationale cannot simply be assumed to remain valid.

8. A country appears on FATF's list of jurisdictions under increased monitoring. Must every customer connected to that country receive EDD?

FATF itself says it does not call for enhanced due diligence merely because a jurisdiction is under increased monitoring and does not envisage indiscriminate de-risking. Institutions should incorporate the information into their risk analysis and follow applicable national requirements. FATF's “call for action” category is different and can carry stronger expectations.

9. Why should STR or SAR conversion not be a primary CDD-calibration target?

Because a reporting rate can be influenced by portfolio mix, typologies, investigative practice and legal thresholds. A target can distort judgement and encourage unnecessary filings. Better control-quality measures include timely review, sound rationale, appropriate evidence, correct legal-trigger handling, effective monitoring, overdue work, customer impact, exception management and whether genuine suspicion is escalated correctly.

10. What is the most important audit question for a CDD decision?

Can the bank reconstruct what it knew at the time, which legal and policy rules applied, which risk was being addressed, what evidence supported the decision, who approved it and what later event changed it? If the answer is yes, the decision is much easier to test and defend.

Glossary

Customer due diligence (CDD): measures used to identify and verify customers and beneficial owners, understand the purpose and intended nature of relationships and conduct ongoing due diligence, as implemented under the applicable legal framework.

Simplified due diligence (SDD): reduced or streamlined measures that may be permitted for identified lower-risk situations. SDD is not “no due diligence” and should not be applied where suspicion exists.

Enhanced due diligence (EDD): additional or more intensive measures required by a legal trigger or justified by higher risk. EDD should be targeted to the risk rather than treated as a universal document list.

Mandatory trigger: a circumstance in applicable law or regulation that requires a specified measure regardless of the general customer-risk score.

Policy trigger: an institutional rule that goes beyond or operationalises the legal minimum. It should be identifiable as bank policy rather than presented as universal law.

Risk-based approach: the process of identifying, assessing and understanding risk and applying measures proportionate to that risk within the applicable legal framework.

Event-driven review: reassessment prompted by a meaningful change such as ownership, business activity, geography, product use, PEP status, adverse information or transaction behaviour.

Suspicion boundary: the point at which facts meet the relevant legal threshold for suspicious-transaction or suspicious-activity reporting. It is distinct from a general high-risk classification.

Effective dating: preserving when facts, rules and decisions became valid so a historical CDD decision can be reconstructed accurately.

References and further reading

The sources below support the chapter's distinction between FATF global standards, jurisdiction-specific legal implementation and bank policy. They were reviewed on 17 September 2026. Live customer decisions must use the law and supervisory requirements applicable to the relevant legal entity and jurisdiction.

Global standards

United Kingdom

United States

The US CDD framework should not be converted into a universal global SDD/CDD/EDD ladder. It has its own statutory and regulatory architecture, customer-risk-profile requirements and ongoing-monitoring expectations.

Australia

AUSTRAC's current material is useful for understanding targeted, proportionate EDD and explicitly notes that particular measures such as source-of-funds and source-of-wealth work are not relevant to every ML/TF risk. These are Australian requirements and guidance, not universal rules.

European Union

Regulation (EU) 2024/1624 is in force but generally applies from 10 July 2027. This chapter therefore does not present its future general operating requirements as if they were already generally applicable on 17 September 2026.

Industry guidance

Wolfsberg material is useful industry guidance, not binding law. It should be read together with applicable legislation, regulation and supervisory guidance.