CDD vs. EDD: When to escalate

CDD vs. EDD: When to escalate

Author: 

Laurence Baker

|

Read time: 

9 minutes

Published date: 

29 September 2026

Learn how CDD and EDD work, the key differences between them, when to escalate from one to the other, and how to build a compliance workflow that keeps your fund protected without slowing down LP onboarding.

For fund compliance teams, having thorough due diligence procedures and risk management processes in place is critical. Not only to ensure risks are identified early, but also to meet increasingly stringent anti-money laundering (AML) and know your customer (KYC) regulations. Every investor you onboard and every counterparty you transact with carries some degree of risk. Customer due diligence (CDD) and enhanced due diligence (EDD) are the two processes that help you measure that risk, verify who your investors and counterparties are, and protect your fund from regulatory exposure. For legal and deal teams navigating complex transactions, understanding the difference between CDD and EDD, and when to use them, is essential—not just for compliance, but as strategic tools to inform smarter, safer investment decisions.

Understanding CDD and EDD

Customer due diligence (CDD) and enhanced due diligence (EDD) are the two core processes fund managers use to meet their anti-money laundering obligations—applied both when onboarding investors and when reviewing transactions. While limited partner (LP) onboarding is highly visible, nearly all jurisdictions outside the U.S. (and most large managers operating under a global AML policy) also require KYC/AML checks at the transaction level. For many managers, transaction-level compliance represents the greater operational burden given the volume of deals reviewed relative to the number of funds raised.

Customer due diligence

Customer due diligence (CDD) is the standard process fund managers use to verify an investor’s identity, assess their risk profile, and understand the nature of the business relationship. CDD is the baseline requirement under AML regulations. Every LP must go through CDD before onboarding.

Essential CDD steps include:

  • Identity verification: Collection of documents (for example, formation documents and government-issued IDs) and verification of provided information against trusted databases, corporate registries, etc.

  • Beneficial ownership checks: Identifying beneficial owners (UBO), reviewing corporate documents to understand the ownership and control structure, and verifying the identity of any UBOs

  • Screening checks: Ensuring the LP onboarding complies with anti-money laundering regulations by screening for sanctions or any legal or financial irregularities, as well as adverse media

  • Risk scoring: Evaluating a client’s risk based on factors such as jurisdiction, industry sector, PEP connections and screening results, business activity, and adverse media results

Enhanced due diligence

Enhanced due diligence (EDD) is a deeper level of investigation applied to investors who present a higher risk of money laundering, terrorism financing, or other financial crime. EDD builds on top of standard CDD. It does not replace it. This risk-based approach is often triggered by specific red flags, such as:

  • High-risk industries or locations: EDD is necessary for clients in sectors like money services businesses, cash-intensive businesses, cryptocurrency, gambling, arms dealers, real estate, and art/antiquities dealers, or in jurisdictions associated with high financial crime rates

  • Politically exposed persons (PEP): PEPs, or individuals in influential public roles, can pose heightened risks due to their visibility and vulnerability to corruption

  • Adverse media and sanctions lists: A history of negative press, connections to sanctioned entities, or associations with criminal activity can all prompt the need for EDD

EDD involves additional verification steps beyond those used in CDD. These might include source-of-funds (SOF) verifications, compliance due diligence including policy review, and deeper documentary or financial audits to uncover any hidden risks that could affect the transaction. For private firms, EDD is essential when potential investments could have a substantial impact on the firm’s reputation or regulatory compliance.

Comparing CDD vs. EDD

The following table summarizes how CDD and EDD compare across the dimensions that matter most to fund operations:

Customer due diligence

Enhanced due diligence

Purpose

Verify identity and assess baseline risk

Investigate elevated-risk relationships in depth

Applies to

All customers and investors

Higher-risk customers and investors only

Depth

Standard identity checks and screening

Source of funds, source of wealth, enhanced background

Approval

Standard onboarding process

Requires senior management sign-off

Monitoring

Periodic, event-driven reviews

More frequent, scheduled reviews with tighter thresholds

Documentation

Standard identity records and risk rating

Comprehensive investigation file with supporting evidence

CDD establishes the baseline for every investor relationship. EDD adds layers of scrutiny when the baseline assessment reveals elevated risk. The two processes are not alternatives. EDD includes everything in CDD plus additional investigation.

When to escalate from CDD to EDD

For firms and asset managers, the choice between CDD and EDD depends largely on the initial risk assessment and regulatory standards. Both types of triggers should be clearly documented in your AML policy. Here’s a simplified approach:

  • Apply CDD for all clients and deals as a minimum compliance standard. This ensures basic due diligence is met across all transactions, helping firms build a foundational risk profile and prevent basic compliance issues.

  • Apply EDD when heightened risk factors emerge, such as international transactions, clients with complex ownership structures, deals involving PEPs or any indicators of elevated financial or reputational risk.

For example, a firm looking to acquire a company with a presence in a high-risk jurisdiction should perform EDD to evaluate the potential risk exposure thoroughly, whereas for a company publicly listed in the U.S., CDD would typically suffice.

Mandatory EDD triggers

  • The investor is a politically exposed person (PEP) or a close associate or family member of a PEP

  • The investor is based in or connected to a high-risk country identified by the Financial Action Task Force (FATF) or other relevant bodies—as of September 2026, Iran, North Korea, and Myanmar are on the blacklist, plus 23 jurisdictions on the gray list—or subject to sanctions

  • The relationship involves correspondent banking with a foreign financial institution

  • The investor’s ownership structure is unusually complex (layered holding companies, trusts, or nominee arrangements) and beneficial ownership is difficult to verify

Risk-based EDD triggers

  • CDD screening returns adverse media results, such as news coverage of criminal investigations, regulatory enforcement, or fraud allegations

  • The investor’s source of funds cannot be clearly verified through standard documentation

  • Transaction monitoring uncovers patterns that deviate from the investor’s stated investment profile

  • The investor operates in a high-risk industry (cash-intensive businesses, cryptocurrency, arms, or gambling)

  • A previous suspicious activity report (SAR) has been filed in connection with the investor

For fund managers, the most common EDD trigger is onboarding an LP with complex ownership structures or connections to high-risk jurisdictions. Your fund’s AML and KYC policy should specify exactly which triggers require automatic escalation to EDD.

Keep your fund protected with KYC
Stay on top of compliance with automated tools for managing LP KYC checks.
Learn more

Regulatory requirements for CDD and EDD

CDD and EDD requirements vary by jurisdiction, but they share a common foundation in FATF recommendations. Staying current with private capital regulations is essential for any fund operating across borders.

Financial Action Task Force (FATF)

  • Recommendation 10 requires all member countries to implement CDD

  • Recommendation 19 mandates EDD for high-risk transactions and relationships involving FATF-identified countries

United States

  • The Financial Crimes Enforcement Network (FinCEN) CDD Final Rule requires financial institutions to identify and verify beneficial owners, maintain risk profiles, and monitor for suspicious activity

  • The USA PATRIOT Act (Section 312) mandates EDD for correspondent accounts with foreign banks, private banking for non-U.S. persons, and accounts involving senior foreign political figures

  • In 2024, FinCEN issued a final rule extending AML and countering the financing of terrorism (CFT) program and SAR filing obligations to registered investment advisers and exempt reporting advisers, including venture capital (VC) and smaller private equity (PE) fund advisors. The compliance deadline was postponed to January 1, 2028 to allow FinCEN to tailor the rule to diverse adviser business models.

United Kingdom and EU

  • The U.K.’s Money Laundering Regulations require EDD for PEPs, high-risk third-country transactions, and unusually complex ownership structures

  • EU Directive 2024/1640 strengthened EDD requirements for cross-border cases.

  • The EU's 6th Anti-Money Laundering Directive (Directive 2018/1673) separately imposed criminal liability for AML failures.

Regardless of jurisdiction, the principle is consistent. Standard CDD applies to every relationship. EDD applies when risk factors exceed the baseline threshold.

The 2026 AML and KYC guide for asset managers
A clear, jurisdiction-by-jurisdiction view of where the rules sit today—and where LP expectations have already moved beyond them.
Free download

The importance of sound due diligence in PE

Beyond ticking regulatory boxes, thorough due diligence is strategic and preventive. Integrating CDD and EDD processes enables legal and deal teams to proactively identify risks and opportunities, optimizing investment outcomes. Thorough due diligence mitigates financial and reputational risk, ensuring compliance excellence and enabling confident, informed investments in an evolving regulatory landscape.

In essence, by embedding a strong culture of compliance, PE professionals enhance their strategic capability, positioning their firms for long-term success.

Consequences of inadequate due diligence

Failing to perform adequate CDD or EDD creates exposure across three categories.

Regulatory penalties

  • Global AML fines exceeded $1 billion in the first half of 2025 alone, with cryptocurrency exchanges, banks, and payment firms bearing the largest penalties

  • License suspension or revocation for repeated or egregious failures

  • Personal liability for designated compliance officers and money laundering reporting officers (MLRO)

Financial exposure

  • Facilitating money laundering or terrorist financing, even unknowingly, exposes the fund to civil and criminal liability

  • Clawback risk if tainted capital is traced back through the fund’s accounts

  • Insurance and indemnity complications when AML failures are discovered during fund audits

Reputational damage

  • LP trust is difficult to rebuild once a fund is associated with a compliance failure

  • Adverse media coverage can affect fundraising for subsequent vehicles

  • Counterparty relationships with banks, custodians, and prime brokers may be terminated

Inadequate due diligence can also undermine investor reporting credibility and create complications during deal flow activities when counterparties question the fund’s compliance posture.

The bottom line on CDD and EDD

CDD and EDD are the operational foundation of your fund’s AML compliance program. CDD applies to every investor relationship, establishing baseline customer identity verification, risk assessment, and ongoing monitoring. EDD adds deeper investigation when risk factors exceed that baseline, requiring source of funds verification, enhanced background checks, and senior management approval.

The distinction between the two determines how you allocate compliance resources, how quickly you can onboard LPs, and how prepared you are for regulatory examinations. Getting the balance right protects your fund from penalties, financial exposure, and reputational harm while keeping investor onboarding efficient.

Start by documenting your fund’s CDD and EDD policies, defining clear escalation triggers, and ensuring your compliance infrastructure can support both levels of due diligence across every jurisdiction where you operate.

Streamlining CDD and EDD at your fund

CDD and EDD are non-negotiable, but the operational burden can be reduced with the right infrastructure. Good fund management practices start with building compliance into your operations from day one.

  • Automate screening and monitoring: Use compliance solutions that integrate sanctions, PEP, and adverse media checks into the onboarding workflow. Continuous monitoring catches changes in real time rather than relying on manual periodic reviews.

  • Centralize documentation: Maintain all CDD and EDD records in a single system with fund administration software that includes audit trail capabilities. This simplifies regulatory examinations and reduces the risk of incomplete records.

  • Define clear escalation policies: Document exactly which risk factors trigger EDD, who approves EDD decisions, and what documentation is required. Consistency protects the fund during regulatory reviews.

  • Leverage multi-jurisdictional expertise: When onboarding LPs across U.S., U.K., and EU regimes, work with a platform or service provider that understands the specific CDD/EDD requirements in each jurisdiction. A dedicated fund services partner can help navigate cross-border complexity.

Many firms that have centralized their investor due diligence workflows report significant time savings. One investor onboarding case study showed how automating KYC checks reduced onboarding time while improving compliance coverage. Firms like Endowus have also demonstrated how the right infrastructure supports compliance across multiple jurisdictions.

Carta Law integrates KYC compliance directly into your LP onboarding and deal workflows, automating screening, centralizing documentation, and supporting multi-jurisdictional AML requirements for funds of all sizes.

Request a demo to see how it works.

AI-Native Law Firm for Private Capital
Scale your legal and compliance operations through AI-native workflows with expert oversight built into every step.
Get started

Frequently asked questions about CDD and EDD

What is CIP vs. CDD vs. EDD?

These three terms are related but not parallel tiers. CIP (Customer Identification Program) is a U.S.-specific requirement under the Bank Secrecy Act that sets minimum standards for collecting and verifying customer identity. It functions as a component of CDD in the U.S. context, not a separate layer preceding it. CDD is the broader standard-level framework applied to all investors and counterparties, encompassing identity verification, beneficial ownership checks, screening, and risk scoring. EDD is the enhanced level applied to high-risk relationships, building on everything in CDD with deeper investigation. Outside the U.S., CIP as a distinct concept generally does not apply; the framework is CDD and EDD.

Is CDD and EDD part of KYC?

Yes. CDD and EDD are both components of the know your customer (KYC) framework. CDD is the standard due diligence applied to all customers, and EDD is the enhanced level applied to high-risk customer relationships.

What are the risks of not performing CDD?

Inadequate CDD exposes a fund to regulatory fines, criminal liability for facilitating money laundering, and reputational damage that can affect future fundraising and LP relationships.

What is simplified due diligence (SDD)?

Simplified due diligence is a reduced level of verification permitted for very low-risk relationships in some jurisdictions, such as publicly traded companies or regulated financial institutions. SDD is not widely available in the U.S. for Bank Secrecy Act (BSA) purposes.

Who is responsible for CDD and EDD at a fund?

The fund’s designated AML officer or money laundering reporting officer (MLRO) is typically responsible for overseeing CDD and EDD processes. In practice, fund administration teams and compliance staff execute the day-to-day checks, with senior management approving EDD escalations.

Laurence Baker
Laurence has over 15 years of B2B marketing experience, having worked with global brands including Universal Pictures, Toshiba, and Sky. Since 2016 he has focused on regulated industries, spanning fintech, regtech, and legal technology for private markets.

DISCLOSURE: This communication is on behalf of eShares, Inc. dba Carta, Inc. ("Carta"). This communication is for informational purposes only, and contains general information only. Carta is not, by means of this communication, rendering accounting, business, financial, investment, legal, tax, or other professional advice or services. This publication is not a substitute for such professional advice or services nor should it be used as a basis for any decision or action that may affect your business or interests. Before making any decision or taking any action that may affect your business or interests, you should consult a qualified professional advisor. This communication is not intended as a recommendation, offer or solicitation for the purchase or sale of any security. Carta does not assume any liability for reliance on the information provided herein. ©2026 Carta. All rights reserved. Reproduction prohibited.