These three acronyms appear on almost every compliance job description, and they are constantly used as if they mean the same thing. They do not.

Getting the distinction right is a quick way to sound like you actually know the subject rather than having memorised a glossary.

The short version

KYC is the overall practice of knowing who your customer is.

CDD is the specific set of steps you perform to achieve it.

EDD is the deeper version of those steps, applied when risk is higher.

A useful way to think about it: KYC is the goal, CDD is the process, and EDD is the process turned up.

KYC — Know Your Customer

KYC is the broad principle. It means understanding who your customer is, what they do, where their money comes from, and how much risk they present.

It is not a single task you complete at account opening. It runs for the entire relationship, because customers change — businesses expand, ownership changes hands, a director takes public office.

KYC underpins everything else in anti-money laundering. You cannot spot unusual behaviour unless you first know what normal looks like for that customer.

CDD — Customer Due Diligence

CDD is the concrete work. It has four core elements:

Identify the customer and verify their identity using reliable, independent documents or data.

Identify the beneficial owner — the real human being who ultimately owns or controls the customer — and take reasonable steps to verify them.

Understand the purpose and intended nature of the business relationship.

Conduct ongoing due diligence, which means monitoring transactions and keeping customer information current.

That fourth point is the one people forget. CDD is not finished when the account is opened.

What CDD looks like in practice

For an individual, you would typically collect a government-issued photo ID such as a passport, plus proof of address such as a recent utility bill.

For a company, you would collect the certificate of incorporation, constitutional documents, the register of directors and shareholding details — and then work through the ownership chain to identify the individuals behind it.

EDD — Enhanced Due Diligence

EDD applies when the assessed risk is higher than normal. It is not a different process; it is the same process done more deeply.

When EDD is required

The usual triggers are:

  • Politically exposed persons, their family members and close associates
  • Customers or transactions connected to high-risk jurisdictions
  • Complex or opaque ownership structures with no clear commercial rationale
  • Unusually large or unexplained transactions
  • Correspondent banking relationships
  • Any customer where adverse media raises credible concerns

What EDD adds

Beyond standard CDD, you would typically:

  • Obtain and verify information on source of funds and source of wealth
  • Seek senior management approval to establish or continue the relationship
  • Apply more frequent reviews and closer transaction monitoring
  • Gather additional information about the purpose of the relationship

And SDD — the fourth one

Simplified Due Diligence is worth knowing because interviewers sometimes add it to see if you overreach.

SDD is a lighter set of checks applied where the money laundering risk is genuinely low — for example, a small domestic salary account, or a regulated financial institution in a well-supervised jurisdiction.

SDD does not mean skipping due diligence. You still identify the customer and still monitor the relationship. You may simply verify fewer details or review less frequently. And SDD must never be applied where any red flag exists.

Source of funds vs source of wealth

Since EDD hinges on these, they are worth separating clearly.

Source of funds is where the money in this particular transaction came from — the sale of a property last month, or a salary credit.

Source of wealth is the bigger picture: how the customer accumulated their overall net worth over time, such as a family business they have run for twenty years.

A customer can have a perfectly clean source of funds for one transaction while their overall wealth still needs explaining. That is exactly why EDD looks at both.

How the risk-based approach ties it together

All of this rests on one principle: you focus effort where the risk is highest.

A salaried customer with a small savings account gets standard checks. A customer with layered offshore ownership and high-value international transfers gets far deeper scrutiny.

This is more effective than applying identical checks to everyone, and it is the approach regulators expect. Applying the same depth to every customer is not thoroughness — it is poor allocation of resources, and it usually means the genuinely risky cases get too little attention.

How to explain it in an interview

If asked, keep it structured and brief:

"KYC is the overall practice of knowing your customer. CDD is the specific set of steps — identify and verify the customer, identify beneficial owners, understand the purpose of the relationship, and monitor it on an ongoing basis. EDD is the enhanced version applied to higher-risk customers such as PEPs, and it typically adds source of wealth checks and senior management approval. SDD is the lighter version for genuinely low-risk cases, but it never means skipping due diligence entirely."

That answer takes about twenty seconds and covers all four terms with the distinction intact. Most candidates give a vaguer version of it, which is precisely why a clear one stands out.