Enhanced Due Diligence
Also written EDD · Enhanced Customer Due Diligence · Enhanced CDD
The additional customer due diligence a Regulated Entity must perform where ML/TF risk is high — including source of wealth, Senior Management approval and enhanced ongoing monitoring.
In plain language
Customer due diligence is not one procedure applied identically to everyone. The IFSCA Guidelines run three settings off a single risk rating:
- rated low → simplified CDD
- rated medium → standard CDD
- rated high → standard CDD plus enhanced CDD
Enhanced Due Diligence is that top setting. It is never a substitute for ordinary CDD — the Guidelines say the enhanced measures are undertaken in addition to the measures under clause 5.4, not instead of them.
And the risk rating has to be assigned before due diligence begins, not discovered during it.
How it works
Where the risks of ML/TF are high, a Regulated Entity shall conduct enhanced CDD measures consistent with the risks identified. There are six:
- Obtain additional information on the customer — occupation, volume of assets, information from public databases — and update the identification data of customer and beneficial owner more regularly.
- Take additional steps to examine the ownership and financial position, including source of wealth and source of funds of the customer or the beneficial owner.
- Record the purpose behind the specified transaction and the intended nature of the relationship between the transaction parties.
- Obtain the approval of Senior Management to commence or continue the business relationship.
- Conduct enhanced monitoring — increasing the number and timing of controls and selecting patterns of transactions needing further examination.
- Require the first payment to be carried out through an account in the customer's own name with a bank subject to similar CDD standards.
That first-payment account must be with a Bank; or a regulated financial institution whose entire operations are supervised for AML/CFT in a jurisdiction equivalent to FATF standards; or a subsidiary of such an institution where the parent's law ensures the subsidiary observes the same standards.
EDD is mandatory for PEPs, where the additional measures include collecting the source of wealth and income of family members, beneficial owners and close relatives, verifying identity before accepting the PEP as a customer, and obtaining Senior Management approval before opening the account or making any payout. If an existing customer subsequently becomes a PEP, Senior Management approval is needed to continue the relationship. EDD is also required, proportionate to the risks, for persons from countries for which FATF calls for it.
Risk rating also drives how often the file is refreshed. Periodic updation runs annually for high risk, once in three years for medium, once in five years for low — or, for a resident Indian customer with an existing relationship with the Financial Group in India, two, eight and ten years respectively. Where the Financial Group's rating differs from the Regulated Entity's, the stricter of the two periodicities applies.
A worked example
On 9 January 2026 a GIFT IFSC banking unit is approached by Mr Dalmar Osei, a former deputy energy minister of a foreign state who stepped down in 2023, to open an account and place USD 12 million.
He is a PEP who has stepped down — and the Guidelines expressly let the Regulated Entity take a risk-based view of such a person, considering the level of influence he may continue to exercise. The unit rates him high, so the file runs:
| Step | What is done |
|---|---|
| Identity verified before acceptance | Passport, unique identification number, date of birth, nationality, legal domicile, current residential address |
| Source of wealth and income | Of Mr Osei and of his spouse, his beneficial owners and close relatives |
| Senior Management approval | Obtained before the account is opened, minuted |
| First payment | Routed from an account in his own name with a FATF-equivalent regulated bank — not from the family trust, and not from a third party |
| Ongoing monitoring | Enhanced; alerts tuned tighter than the standard book |
| Periodic updation | Annually, not the three- or five-year cycle |
Eighteen months later the monitoring throws an alert: USD 2.3 million arrives from an unassociated third party in a grey-listed jurisdiction. Because he is high risk, that alert is escalated, the purpose is documented, and the Principal Officer decides on the STR — due within seven working days of concluding that the transaction is suspicious.
Had the unit instead rated Mr Osei low and applied simplified CDD, it would have broken an explicit rule: SCDD shall not be conducted where there is a suspicion of ML/TF, and simplified measures are unacceptable wherever specific higher-risk scenarios apply.
Why NISM asks about it
Chapter 6 (section 6.5) lists the six enhanced measures, and the Chapter 5 sample question — "obtaining the approval of Senior Management to commence or continue the business relationship is a measure specified under which process?" — has Enhanced Due Diligence as its answer. Chapter 6's own sample question asks when EDD must be performed, with "all of the above" covering high risk, PEPs and PEPs who have stepped down. The periodic updation cycles in section 6.10 are a separate, very examinable set of numbers.
Common exam traps
- EDD is in addition to CDD, never instead of it. Six extra measures on top of the four standard ones.
- Senior Management approval is the signature measure of EDD — it is the distractor-proof answer when a question describes it without naming the process.
- Simplified CDD is forbidden wherever there is a suspicion of ML/TF, regardless of how low the customer's rating was.
- The risk rating comes first. Customer risk assessment is completed before due diligence for a new customer, and the rating and its reasons must be kept confidential from the customer to avoid tipping off.
- Periodic updation: 1 / 3 / 5 years normally, 2 / 8 / 10 years for a resident Indian customer with an existing Financial Group relationship in India, and the stricter cycle wins if the two ratings disagree.
- The first payment must come from an account in the customer's own name. A payment from a spouse, a group company or a nominee defeats the measure.
- A PEP who has stepped down is not automatically out of scope — the Guidelines require a risk-based judgement on residual influence.
Where this is taught
Free preparation for NISM Series IFSCA-01Related terms
- ControlIn the beneficial-ownership tests, the right to appoint a majority of directors or to control management or policy decisions — the limb that catches an owner holding no shares at all.
- Customer risk assessmentA risk-based assessment of every customer, completed before customer due diligence for new customers, using risks identified in the business risk assessment, and producing a rating of high, medium or low proportionate…
- Ongoing due diligenceThe continuing obligation to examine transactions for consistency with the client, his business and risk profile and where necessary the source of funds; to review due diligence including re-verifying identity where…
- Simplified Customer Due DiligencePermitted where risks are low — verifying identity after the relationship is established, reducing the frequency of identification updates, reducing ongoing monitoring based on a reasonable monetary threshold, and…
- Politically exposed personsA higher-risk class of client that SEBI treats as a client of special category: the intermediary must detect them, obtain senior management approval to deal with them, and verify their source of funds and wealth.
- Suspicious Transaction ReportA report a SEBI intermediary must file with FIU-IND within 7 days of concluding that a transaction or connected series of transactions is suspicious — and must never disclose to the client.
- Know Your CustomerThe identity and address check every investor must clear before a bank, broker or depository participant will open an account — mandatory under the Prevention of Money Laundering Act, 2002.
- Risk Based ApproachApplying each due diligence measure in proportion to the money-laundering risk a client poses — enhanced diligence for higher-risk clients, simplified for lower-risk, never simplified where suspicion exists.
- Regulated EntityIFSCA's term for a unit that holds its licence, recognition, registration or authorisation — the entity the IFSCA (AML, CFT and KYC) Guidelines, 2022 place their duties on.
- Specified transactionThe class of transactions under section 12AA of the PMLA that a reporting entity may not begin until it has completed enhanced due diligence on the client undertaking them.