Introduction
Most AML compliance conversations focus on customer due diligence: the identity verification and screening process you run when onboarding a new client. But there is a second tier that matters just as much: enhanced due diligence, or EDD. EDD applies when a customer or transaction presents a level of risk that standard checks cannot adequately address.
Under Australia’s AML/CTF Act, EDD is not optional for high-risk scenarios. It is a legal requirement. From 1 July 2026, Tranche 2 entities (accountants, lawyers, real estate agents, and trust and company service providers) will face the same EDD obligations that financial institutions have operated under for years. For many of these businesses, EDD is new ground.
NameScan has supported compliance teams across 27,000 businesses in 195 countries with the screening tools that sit at the core of EDD. This guide explains when EDD is triggered, what it involves, and how to document it in a way that satisfies AUSTRAC’s expectations.
Standard CDD Versus Enhanced Due Diligence
Think of customer due diligence as a spectrum. At one end is simplified due diligence, a lighter process applied to customers who present minimal risk: typically straightforward, low-value services with transparent ownership. Standard CDD covers the middle ground: identity verification, sanctions and PEP screening, and an initial risk assessment for the majority of your customers.
EDD sits at the other end. It applies when the standard process is not sufficient, when a customer’s risk profile, the nature of the transaction, or other factors point to materially elevated exposure to money laundering or terrorism financing. The purpose of EDD is not to refuse the customer. It is to gather enough additional information to make an informed, documented decision about whether and how to proceed.
AUSTRAC’s AML/CTF Rules require that your Part B procedures specify the circumstances in which EDD applies and what additional measures it involves.
When Is EDD Triggered?
Under AUSTRAC’s framework, EDD is mandatory in several defined circumstances and risk-based in others.
Mandatory EDD Triggers
Foreign Politically Exposed Persons (foreign PEPs): A customer who is or has been entrusted with a prominent public function by a foreign country automatically requires EDD. This includes senior politicians, government ministers, senior military and judicial officers, senior executives of state-owned enterprises, and their immediate family members and known associates. Foreign PEPs attract mandatory EDD because the difficulty of verifying foreign political exposure increases the potential for undetected corruption.
Senior foreign political figures: Customers who hold or have held senior roles in foreign governments, intergovernmental organisations, or the senior management of foreign state-owned enterprises are subject to mandatory EDD under AUSTRAC’s Rules, consistent with FATF Recommendation 12.
Correspondent relationships: For financial institutions entering into correspondent banking or similar arrangements, EDD is required before the relationship commences.
Risk-Based EDD Triggers
Beyond the mandatory categories, your AML/CTF programme must specify the risk-based thresholds at which your business applies EDD. Common triggers include:
- Domestic PEPs where your risk assessment indicates a heightened level of exposure
- Customers or beneficial owners from FATF-listed high-risk or monitored jurisdictions, currently including Iran, North Korea, and Myanmar
- Complex corporate structures where the ultimate beneficial owner is difficult to identify
- Transactions that are unusually large, structured to avoid reporting thresholds, or inconsistent with the customer’s stated business
- Customers who are reluctant to provide information, or who have previously been the subject of a suspicious matter report
- Virtual asset users in higher-risk scenarios
What Does EDD Actually Involve?
EDD is not a single check. It is a process of gathering and evaluating additional information to build a more complete picture of the customer. The specific measures depend on the risk scenario, but typically include some combination of the following.
Source of Funds and Source of Wealth Verification
For high-risk customers, particularly PEPs, AUSTRAC expects you to verify not just who the customer is but where their money comes from. Source of funds refers to the origin of the money being used in the specific transaction. Source of wealth refers to the broader basis for the customer’s net worth. Verification can involve salary slips, tax returns, business financial statements, or property ownership records. The objective is to establish a coherent financial narrative that explains why the transaction makes sense for this customer.
Senior Management Approval
Under AUSTRAC’s Rules, establishing or continuing a business relationship with a foreign PEP requires approval from senior management. This is not a formality. Someone with oversight responsibility, not just the frontline compliance officer, must have reviewed the risk profile and authorised the relationship. Document the approval, the date, and the basis for the decision.
Additional Identity Verification
Where standard CDD identifies a customer using one source, EDD may require a second independent source. For beneficial owners of corporate structures, this might mean obtaining a certified copy of the entity’s register of members, a letter from a regulated legal practitioner confirming ownership, or direct verification through ASIC records.
Adverse Media Screening
Adverse media checks are a core EDD tool. They involve systematic searches of news and public information sources for negative coverage linked to financial crime, corruption, fraud, or terrorism. They surface risk signals that do not appear on formal sanctions or PEP lists: court proceedings, regulatory enforcement actions, investigative journalism. NameScan includes adverse media screening alongside PEP and sanctions checks, with results stored for audit purposes.
Enhanced Ongoing Monitoring
EDD does not end at onboarding. High-risk customers require closer ongoing monitoring: more frequent re-screening, lower thresholds for transaction monitoring alerts, and closer scrutiny of any changes in the customer’s circumstances or behaviour.
Documenting EDD for AUSTRAC
The documentation requirements for EDD are more demanding than for standard CDD. AUSTRAC expects to see:
- A clear record of why EDD was triggered, including the specific risk factor or category that applied.
- Evidence of the additional information gathered: source of funds documents, extra identity verification, adverse media results.
- Evidence of senior management approval where required.
- A risk assessment decision: a documented conclusion that the relationship was accepted, accepted with conditions, or declined, and the reasoning behind that decision.
- Ongoing monitoring records showing that the elevated scrutiny continued after onboarding.
All EDD records must be retained for a minimum of seven years under the AML/CTF Rules. Your screening platform should maintain an exportable audit trail of all checks run.
Conclusion
Enhanced due diligence is the part of AML compliance that requires the most judgement. The triggers are specific in some cases and risk-based in others. What matters is that your Part B procedures define when EDD applies, that your staff know how to apply it, and that the outcomes are documented thoroughly.
For businesses entering the AML/CTF regime under Tranche 2, the practical approach is to start with the mandatory triggers (foreign PEPs and senior foreign political figures) and build your risk-based thresholds from there. Make sure your screening tools cover adverse media as well as sanctions and PEP lists, and that every check produces an auditable record.
Frequently Asked Questions
What is enhanced due diligence (EDD)?
Enhanced due diligence (EDD) is an elevated level of customer scrutiny applied under Australia’s AML/CTF Act when a customer or transaction presents a higher risk of money laundering or terrorism financing. It goes beyond standard identity verification and screening to include source of funds and wealth verification, additional identity evidence, senior management approval for PEPs, adverse media checks, and closer ongoing monitoring. AUSTRAC requires Tranche 2 entities to apply EDD in defined circumstances, including for foreign politically exposed persons.
Does EDD always mean refusing the customer?
No. EDD is a risk assessment process, not a rejection mechanism. The purpose is to gather sufficient information to make an informed, documented decision about whether the customer relationship presents an acceptable level of ML/TF risk. In many cases, EDD results in the relationship proceeding with appropriate controls and monitoring in place. AUSTRAC’s guidance makes clear that businesses should not automatically refuse customers because they are PEPs or from higher-risk jurisdictions. The obligation is to manage the risk, not to avoid it entirely.
How is EDD different from standard CDD?
Standard CDD verifies who a customer is: identity documents, beneficial ownership for entities, and sanctions and PEP screening. EDD adds depth. It typically requires evidence of the source of funds, verification of the broader source of wealth for high-risk scenarios, senior management sign-off for foreign PEP relationships, additional identity verification from a second independent source, and enhanced ongoing monitoring. The specific measures depend on the nature and level of the risk.
Which customers require mandatory EDD under AUSTRAC?
Under AUSTRAC’s AML/CTF Rules, mandatory EDD applies to foreign politically exposed persons: individuals who hold or have held a prominent public function in a foreign country, and to their immediate family members and known close associates. Senior foreign political figures and correspondent banking arrangements also require mandatory EDD. Beyond these categories, your AML/CTF programme must specify the risk-based thresholds at which EDD applies to other customers, which typically include customers from FATF-listed high-risk jurisdictions, complex corporate structures, and high-value or unusual transactions.
How do I document EDD for an AUSTRAC audit?
Documentation for EDD should include the specific trigger for elevated scrutiny, the additional information gathered (source of funds documents, extra identity verification, adverse media results), evidence of senior management approval where required, a written risk assessment decision explaining why the relationship was accepted or declined, and records of ongoing monitoring. All records must be retained for seven years. Using an auditable screening platform like NameScan ensures that PEP, sanctions, and adverse media check results are automatically stored with timestamps, reducing the manual documentation burden.
| NameScan provides PEP, sanctions, and adverse media screening with full audit trails. Pay per check, no subscription. Start free at namescan.io |
0 Comments