KibiPay
HomeBlog › AML

KYC vs CDD vs EDD: Know Your Customer, Explained

6 min read AML
KYCAMLCompliance
KYC vs CDD vs EDD: Know Your Customer, Explained

Anyone working in payments or banking hears KYC, CDD, and EDD constantly, often used as if they were synonyms. They are not. They describe distinct layers of the same anti-money-laundering effort: knowing who your customer is, understanding the risk they pose, and doing more work when that risk is higher. Getting the vocabulary right helps you design compliance that regulators recognise.

KYC: the umbrella

Know Your Customer (KYC) is the broad principle and program: a regulated firm must know who it is doing business with. KYC is not a single step but the overall discipline of identifying and verifying customers and understanding their activity, so the firm can detect and prevent money laundering, terrorist financing, and fraud. It starts at onboarding and continues for the life of the relationship. When people say KYC, they usually mean the whole framework, of which the pieces below are components.

CDD: customer due diligence

Customer Due Diligence (CDD) is the core operational process inside KYC. It typically involves several standard steps:

Standard CDD is the baseline applied to ordinary customers. It is proportionate — you do not want onboarding friction that drives away low-risk customers — but it must be thorough enough to establish identity and expected behaviour.

EDD: enhanced due diligence

Enhanced Due Diligence (EDD) is the extra scrutiny applied when a customer or transaction presents higher risk. It is not a different process so much as a deeper one. EDD is triggered by factors such as dealing with a politically exposed person (PEP), customers or transactions connected to high-risk jurisdictions, unusually complex ownership structures, or products prone to abuse. EDD measures typically include:

The logic is risk-based: apply more resources where the potential for harm is greatest, and keep friction proportionate where it is not.

Simplified due diligence

There is also a lighter tier, Simplified Due Diligence (SDD), permitted for demonstrably low-risk situations — certain regulated financial institutions or low-value, low-risk products. SDD reduces the intensity of checks but does not eliminate the obligation to monitor. It exists because a risk-based regime should not spend the same effort on a tiny prepaid product as on a private banking relationship.

Ongoing monitoring ties it together

None of this is a one-time gate. A defining feature of a real KYC program is ongoing monitoring: transactions are watched against the expected profile, and material changes trigger review. A customer rated low risk at onboarding can be re-rated if their behaviour changes, moving them from standard CDD into EDD. This lifecycle view — identify, risk-rate, apply proportionate diligence, monitor continuously, and re-rate — is what regulators expect.

How the pieces fit for builders

For anyone building a regulated financial product, the practical relationship is a hierarchy. KYC is the program you must run. CDD is the standard workflow you build for every customer: collect, verify, establish ownership, and score. EDD is a set of stronger controls you switch on when the risk score or specific triggers demand it. SDD is a lighter path you may take only where the risk is demonstrably low. And ongoing monitoring is the engine that keeps all of this current after onboarding.

Designing this well means treating the risk rating as the pivot. The rating decides which tier of diligence applies, how often you review the customer, and how much scrutiny each transaction gets. Because the rating can change, your systems must be able to move a customer between tiers over time rather than locking them into their onboarding category. Regulators care less about which label you use and more about whether your diligence is genuinely proportionate to risk and consistently applied.

Key takeaways

See these rails in motion

KibiPay connects UK Faster Payments, Bacs, CHAPS, Mojaloop mobile money and Solana behind one API, with ISO 20022 messaging and real-time fraud & AML screening.

Open the live console How it works