KYC vs CDD vs EDD: Know Your Customer, Explained

Anyone working in payments or banking hears KYC, CDD, and EDD constantly, often used as if they were synonyms. They are not. They describe distinct layers of the same anti-money-laundering effort: knowing who your customer is, understanding the risk they pose, and doing more work when that risk is higher. Getting the vocabulary right helps you design compliance that regulators recognise.
KYC: the umbrella
Know Your Customer (KYC) is the broad principle and program: a regulated firm must know who it is doing business with. KYC is not a single step but the overall discipline of identifying and verifying customers and understanding their activity, so the firm can detect and prevent money laundering, terrorist financing, and fraud. It starts at onboarding and continues for the life of the relationship. When people say KYC, they usually mean the whole framework, of which the pieces below are components.
CDD: customer due diligence
Customer Due Diligence (CDD) is the core operational process inside KYC. It typically involves several standard steps:
- Customer identification. Collecting identifying information — name, date of birth, address, and for businesses, registration and ownership details.
- Identity verification. Confirming that the customer is who they claim to be, using documents, electronic verification, or biometrics.
- Beneficial ownership. For legal entities, identifying the natural persons who ultimately own or control the business — often those holding above a defined ownership threshold, commonly 25 percent.
- Understanding the relationship. Establishing the expected purpose and nature of the account, so unusual activity can later be spotted.
- Risk rating. Scoring the customer as low, medium, or high risk based on factors like geography, product, and customer type.
Standard CDD is the baseline applied to ordinary customers. It is proportionate — you do not want onboarding friction that drives away low-risk customers — but it must be thorough enough to establish identity and expected behaviour.
EDD: enhanced due diligence
Enhanced Due Diligence (EDD) is the extra scrutiny applied when a customer or transaction presents higher risk. It is not a different process so much as a deeper one. EDD is triggered by factors such as dealing with a politically exposed person (PEP), customers or transactions connected to high-risk jurisdictions, unusually complex ownership structures, or products prone to abuse. EDD measures typically include:
- Gathering additional information on the customer and the source of their funds and wealth.
- Obtaining senior management approval to establish or continue the relationship.
- More frequent and intensive ongoing monitoring of transactions.
- Deeper adverse-media and sanctions screening.
The logic is risk-based: apply more resources where the potential for harm is greatest, and keep friction proportionate where it is not.
Simplified due diligence
There is also a lighter tier, Simplified Due Diligence (SDD), permitted for demonstrably low-risk situations — certain regulated financial institutions or low-value, low-risk products. SDD reduces the intensity of checks but does not eliminate the obligation to monitor. It exists because a risk-based regime should not spend the same effort on a tiny prepaid product as on a private banking relationship.
Ongoing monitoring ties it together
None of this is a one-time gate. A defining feature of a real KYC program is ongoing monitoring: transactions are watched against the expected profile, and material changes trigger review. A customer rated low risk at onboarding can be re-rated if their behaviour changes, moving them from standard CDD into EDD. This lifecycle view — identify, risk-rate, apply proportionate diligence, monitor continuously, and re-rate — is what regulators expect.
How the pieces fit for builders
For anyone building a regulated financial product, the practical relationship is a hierarchy. KYC is the program you must run. CDD is the standard workflow you build for every customer: collect, verify, establish ownership, and score. EDD is a set of stronger controls you switch on when the risk score or specific triggers demand it. SDD is a lighter path you may take only where the risk is demonstrably low. And ongoing monitoring is the engine that keeps all of this current after onboarding.
Designing this well means treating the risk rating as the pivot. The rating decides which tier of diligence applies, how often you review the customer, and how much scrutiny each transaction gets. Because the rating can change, your systems must be able to move a customer between tiers over time rather than locking them into their onboarding category. Regulators care less about which label you use and more about whether your diligence is genuinely proportionate to risk and consistently applied.
Key takeaways
- KYC is the overall program and principle; CDD and EDD are processes within it.
- CDD is the core process: identify the customer, verify identity, establish beneficial ownership, understand the relationship, and assign a risk rating.
- EDD is deeper scrutiny for higher-risk cases such as PEPs, high-risk jurisdictions, and complex ownership, including source-of-funds checks and senior approval.
- SDD is a lighter tier for demonstrably low-risk situations but never removes the monitoring obligation.
- Ongoing monitoring and re-rating make KYC a continuous lifecycle, not a one-time onboarding gate.