ACAMS CAMS Customer Due Diligence Enhanced Due Diligence KYC

Customer Due Diligence vs EDD: A CAMS Study Guide

Understand customer due diligence vs EDD, when deeper checks are justified, what evidence matters and how to avoid treating higher risk as prohibited.

Updated
Table of Contents

ACAMS CAMS

Explore source-grounded summaries, flashcards, reference tools and realistic mock practice.

Customer Due Diligence vs EDD: A CAMS Study Guide

Quick answer: Customer due diligence (CDD) builds the baseline understanding of who the customer is, why the relationship exists, who owns or controls it, what activity is expected and what risk it presents. Enhanced due diligence (EDD) adds deeper, risk-responsive checks when that baseline is not sufficient.

The exam distinction in customer due diligence vs EDD is not “low-risk process versus high-risk process.” CDD applies to the customer relationship. EDD strengthens parts of that process when the customer, product, geography, channel, ownership or activity creates greater exposure or uncertainty.

What Should CDD Establish?

Effective CDD should help the organisation understand:

  • the customer’s identity and legal form;
  • beneficial ownership and control;
  • the purpose and intended nature of the relationship;
  • occupation, business model or source of activity;
  • expected products, channels, counterparties and transaction behaviour;
  • relevant source-of-funds or source-of-wealth information;
  • geographic and jurisdictional connections; and
  • the resulting risk classification and control needs.

The output is not merely a completed form. It is a usable profile against which later activity can be assessed.

What Does EDD Add?

EDD adds depth where risk or uncertainty requires it. Depending on the applicable regime and the facts, this may include:

  • more reliable or independent identity and ownership evidence;
  • deeper verification of beneficial owners and controllers;
  • additional source-of-funds or source-of-wealth work;
  • investigation of business purpose and counterparties;
  • senior-management approval;
  • closer or more frequent monitoring;
  • reduced limits or additional transaction controls; and
  • more frequent or event-driven review.

EDD should respond to the identified exposure. Collecting more documents without explaining what risk they address creates volume, not better due diligence.

CDD vs EDD Decision Table

QuestionCDD baselinePossible EDD response
Who is the customer?Identify and verifyCorroborate through additional reliable sources
Who owns or controls it?Establish beneficial ownership and controlTrace indirect layers, influence and conflicting records
Why is the account needed?Record purpose and expected useTest purpose against contracts, activity and counterparties
Where did value come from?Obtain relevant source informationVerify source through deeper financial and external evidence
How will activity be monitored?Compare activity with the expected profileApply closer review, tailored scenarios or additional approval

Interactive Playground

Explore our interactive learning tools below

Sample Question 1 of 10

Which CAMS knowledge point is defined or described by the following statement? Risk is dynamic and needs to be continuously managed, and the environment in which each organization operates is subject to continual change.

This is just a taste — the full course includes far more

Higher Risk Is Not Automatically Prohibited

A politically exposed person, private-banking customer, complex company, nonprofit, virtual-asset business or cross-border relationship can create elevated risk. None of those labels proves wrongdoing.

The risk-based response asks whether the organisation can understand the exposure and manage it lawfully. Strong controls may make a higher-risk relationship acceptable. Conversely, a relationship that appears ordinary may become unacceptable when identity cannot be established, ownership remains hidden, explanations conflict with evidence or mandatory restrictions apply.

This is why blanket de-risking can be a weak answer. It may exclude legitimate customers, reduce financial transparency and avoid the analysis required by a risk-based approach.

Source of Funds vs Source of Wealth

These questions are related but not interchangeable.

Source of funds asks where the specific money or assets used in the relationship or transaction came from. Relevant evidence may connect a payment to salary, sale proceeds, business income, investment activity, inheritance or another lawful source.

Source of wealth asks how the customer’s overall wealth was accumulated. The answer should fit the customer’s history, occupation, business interests, assets and known activity.

A bank statement can show where a transfer arrived from without proving how the underlying wealth was created. Equally, a plausible wealth narrative does not explain every particular transaction.

Customer Review Is a Lifecycle Control

CDD continues after onboarding. Periodic review reassesses customers according to the applicable risk-based schedule. Event-driven or perpetual KYC signals can identify material change between scheduled reviews.

Useful triggers include changes in ownership, control, products, geography, transaction behaviour, sanctions exposure or credible adverse information. A technology signal should route the change for proportionate validation; it should not silently change the customer’s risk or close the relationship without review.

Common CAMS Traps

  • Identity document equals full CDD: identity is one part of the customer picture.
  • EDD replaces CDD: EDD deepens the baseline; it does not discard it.
  • High risk equals reject: assess whether lawful controls can manage the exposure.
  • More documents equal better evidence: relevance, reliability and consistency matter.
  • Scheduled review is enough: material events can justify earlier reassessment.
  • Vendor reliance transfers accountability: the organisation remains responsible for the control and decision.

See PEP risk management for a practical higher-risk example, or use the CAMS exam guide to place CDD and EDD within the four-domain blueprint.

The strongest exam answer identifies the specific information gap, chooses the proportionate additional measure and keeps the final decision with the accountable function.

Frequently Asked Questions

1 What is the difference between CDD and EDD?

CDD establishes the customer's identity, purpose, ownership, control, expected activity and risk. EDD adds risk-responsive depth when the circumstances require more evidence, approval or monitoring; it does not replace the core CDD process.

2 Does every high-risk customer require rejection?

No. Higher risk may require deeper information, senior approval, tighter controls and enhanced monitoring. A relationship should be prohibited only when the applicable law or policy requires it, or when the risk cannot be managed within the organisation's lawful appetite.

3 Is document verification enough for CDD?

No. A document can support identity, but full CDD also considers ownership, control, purpose, expected activity and relevant source information. Digital identity tools answer specific questions rather than the entire CDD problem.

4 What is the difference between source of funds and source of wealth?

Source of funds concerns the origin of the money or assets used in a particular relationship or transaction. Source of wealth considers how the customer's overall wealth was accumulated.

5 When should customer information be refreshed?

Information may be reviewed periodically according to risk and when material events change ownership, behaviour, products, geography, sanctions exposure or other credible information. The exact requirement depends on the applicable regime and policy.

Keep learning

View all insights

Ready to Prepare for ACAMS CAMS?

Use source-grounded study tools and realistic practice to build accurate recall and exam-day confidence.

Explore Course Preparation

Exam Prep

ACAMS CAMS