CDD vs EDD is a question about extent, not about whether a measure happens. Under Regulation (EU) 2024/1624 every customer gets the full list of customer due diligence measures in Article 20; what risk changes is how far each one goes. Getting that distinction right is the difference between a defensible file and a gap that looks like a policy choice.
This is how the CDD vs EDD line is drawn in the Regulation, which triggers move a customer across it, and the two provisions that catch firms out because they apply regardless of which side you are on.
What this guide covers
- CDD vs EDD: the short answer
- What CDD requires before you reach the CDD vs EDD question
- CDD vs EDD: the triggers that make enhanced measures mandatory
- CDD vs EDD: the measures that actually differ
- Where simplified due diligence sits on the CDD vs EDD spectrum
- The transaction test that applies whatever side of CDD vs EDD you are on
- The high-value relationship trigger the CDD vs EDD debate usually misses
- Getting the CDD vs EDD decision recorded
- Frequently asked questions
- Documenting both sides

CDD vs EDD: the short answer
Customer due diligence is the baseline set in Article 20(1): identify and verify the customer, identify beneficial owners and take reasonable measures to verify them, understand the purpose and intended nature of the relationship, check targeted financial sanctions, understand the nature of the business, monitor on an ongoing basis, and determine whether anyone involved is a politically exposed person.
Enhanced due diligence, under Articles 34 to 46, adds measures on top. It never replaces the baseline. In a CDD vs EDD comparison the useful mental model is that enhanced measures are additive and simplified measures are reductive, and both operate inside the same list.
What CDD requires before you reach the CDD vs EDD question
Article 19 sets six circumstances that trigger due diligence at all: establishing a business relationship; an occasional transaction of at least EUR 10 000, single or through linked transactions; participating in the creation of a legal entity or the setting up of a legal arrangement, irrespective of value; suspicion, regardless of any derogation, exemption or threshold; doubts about previously obtained identification data; and doubts about whether the person you are dealing with is the customer or is authorised.
Four of those six have no monetary threshold at all. Credit institutions and financial institutions other than crypto-asset service providers carry an additional EUR 1 000 trigger for occasional transactions that are transfers of funds.
CDD vs EDD: the triggers that make enhanced measures mandatory
Article 34(1) is the gateway. Enhanced due diligence applies in the cases referred to in Articles 29, 30, 31 and 36 to 46, and in other cases of higher risk that the entity identifies itself. The mandatory list is worth memorising because it removes the judgement call.
| Trigger | Article | Who it reaches |
|---|---|---|
| Designated third country | 29, 30, 31 | All obliged entities |
| Cross-border correspondent relationship | 36 | Credit and financial institutions |
| Crypto-asset correspondent relationship | 37 | Crypto-asset service providers |
| Respondent named in an Authority recommendation | 38 | Credit and financial institutions |
| Correspondent relationship with a shell institution | 39 | Credit and financial institutions, and crypto-asset service providers under 39(2) — a prohibition, not a measure |
| Transfers to or from a self-hosted address | 40 | Crypto-asset service providers |
| Residence-by-investment applicant | 41 | All obliged entities |
| Politically exposed person, family member or close associate | 42–46 | All obliged entities |
| Higher risk the entity identifies | 34(1) | All obliged entities |
Note what a designated third country does to the CDD vs EDD analysis. Articles 34(3) and 34(4) both open “with the exception of the cases covered by Section 2 of this Chapter”, and Section 2 is the third-country section. So for a designated country the enhanced measures follow from the designation and from any countermeasures the Commission selects under Article 35, not from weighing Annex III.
CDD vs EDD: the measures that actually differ
Article 34(4) lists seven measures, applied proportionately to the higher risk identified. The Article says the measures “may include” them, so the list is available rather than cumulative — but the choice has to answer the specific risk, and the file has to show that link.
- Additional information on the customer and the beneficial owners
- Additional information on the intended nature of the relationship
- Additional information on the source of funds and source of wealth
- Information on the reasons for the transactions and their consistency with the relationship
- Senior management approval for establishing or continuing the relationship
- Enhanced monitoring — more controls, more often, with transaction patterns selected for examination
- Requiring the first payment through an account in the customer’s name at a credit institution subject to standards not less robust than the Regulation’s
Source of funds and source of wealth are two different questions and both are required where the measure is applied. A file that evidences where the money came from and nothing about how the wealth arose has answered only half of it.
Where simplified due diligence sits on the CDD vs EDD spectrum
Article 33 permits simplified measures where the relationship or transaction presents a low degree of risk, taking into account the factors in Annexes II and III. Reading only Annex II produces a one-sided assessment.
Five simplifications are permitted and nothing else is: verifying identity after the relationship is established where the specific lower risk justifies postponement and in any case within 60 days; reducing the frequency of identification updates; reducing or inferring the information on purpose and intended nature; reducing the frequency or degree of transaction scrutiny; and any further measure the Authority identifies.
The 60-day limit is the most useful number in the CDD vs EDD debate because it is absolute. And Article 33 preserves a floor regardless: the entity must still carry out sufficient monitoring to enable detection of unusual or suspicious transactions. Reducing scrutiny operates inside that floor, not through it.
The transaction test that applies whatever side of CDD vs EDD you are on
Where such an examination becomes a reportable suspicion is covered in suspicious transaction report deadline. Article 34(2) is independent of the customer’s risk band, and it is the provision firms most often discover late. The entity must examine the origin and destination of the funds involved in, and the purpose of, all transactions meeting at least one of four conditions: the transaction is complex, unusually large, conducted in an unusual pattern, or has no apparent economic or lawful purpose.
“At least one” — not a combination. A low-risk customer making a single unusually large transaction engages the duty. Whether your monitoring can detect each of those four conditions is a design question worth testing before the application date set out in our AMLR 2027 timeline.
The high-value relationship trigger the CDD vs EDD debate usually misses
Article 34(5) adds three further measures, and it turns on two thresholds that must both be met. It applies to credit institutions, financial institutions and trust or company service providers where a relationship already identified as higher risk involves handling assets of at least EUR 5 000 000 through personalised services, for a customer holding total assets of at least EUR 50 000 000 — financial, investable or real estate, or a combination, excluding that customer’s private residence.
Where it bites, the entity must adopt specific measures for the risks of personalised services, obtain additional information on source of funds, and prevent and manage conflicts of interest between the customer and senior management or the employees serving them. That last one turns a relationship-management conflict into an AML control.
Getting the CDD vs EDD decision recorded
Whichever side of the CDD vs EDD line a customer falls, the defensible position is the same: the file shows which route was taken, on what basis, and who decided. Three records carry most of that weight.
The customer risk assessment produces the band, drawing on the Annex I risk variables and the Annex II and Annex III factors alongside the entity’s own business-wide risk assessment under Article 10. Article 34(3) also requires notifications issued by the Financial Intelligence Unit to be taken into account, which means there has to be a route by which those reach the risk model.
The enhanced case file records which of the eight triggers brought the customer in — more than one can apply and the measures are cumulative — which Article 34(4) measures were applied, and which specific risk each one answers. A measure applied with no stated risk cannot be shown to be proportionate, which is what Article 34(4) requires.
The low-risk determination does the opposite job. It records the Annex II factors present, the Annex III factors considered and set aside, and the mandatory exclusions checked. Recording only the lower-risk factors shows what the entity looked for, not what it found and discounted — and that gap is exactly what a supervisor probes when testing whether simplified measures were properly available.
None of this is bureaucracy for its own sake. In a CDD vs EDD review the reviewer is not asking whether you had a policy; they are asking why this customer got this treatment on this date.
Frequently asked questions
Does simplified due diligence mean fewer documents?
No. It reduces the extent of measures that are still all performed. Article 33 lists exactly five permitted reductions, and the internal procedures under Article 9 must contain the specific provisions governing their use.
How often must a higher-risk customer be updated?
Article 26(2) caps the interval at one year for higher-risk customers to whom Section 4 measures apply, and five years for everyone else. Those are maxima, and the Regulation also requires the interval to vary with risk below the ceiling, so one standard interval for all customers does not satisfy it.
Can we rely on another firm’s CDD instead of doing our own?
Only partly. Articles 48 and 49 permit reliance for Article 20(1) points (a), (b) and (c) only. Ongoing monitoring, the sanctions check and the politically exposed person determination can never be relied on, and ultimate responsibility stays with the relying entity.
Who decides the customer’s risk profile?
Someone inside your firm. Article 18(3) makes both the risk-profile decision and the decision to enter into the relationship non-delegable. A provider may compute a score; a named person must adopt it.
Documenting both sides
The CDD vs EDD distinction only holds up if the file shows which route was taken and why. Our EU AMLR Toolkit carries a customer due diligence policy, a simplified-measures determination record, an enhanced case file and an Annex III checklist, so a reviewer can see the reasoning rather than infer it. The full Article 34 text is on EUR-Lex, and the wider changes are set out in AMLR vs AMLD.