Enhanced Due Diligence (EDD) is where most AML/CFT programmes either prove their worth or quietly fail. Standard CDD is mechanical: a passport, a proof of address, a corporate structure. EDD is a judgement exercise. It asks the MLRO to understand the client — source of funds, source of wealth, commercial rationale — and document that understanding in a way the regulator can test.
This article is a practical walk-through for MLROs, compliance officers and senior management. It covers when EDD is triggered, what it must cover, what the evidence pack looks like, and the failures that show up most often in FIU and FSC findings.
When EDD is mandatory
Under the FIAML Regulations 2018, EDD is not optional when certain triggers are present. The most important:
- Politically Exposed Persons (PEPs) — foreign PEPs always; domestic PEPs and heads of international organisations on a risk-sensitive basis, per the latest FATF-aligned guidance.
- High-risk jurisdictions — FATF-listed countries, EU high-risk third countries, jurisdictions with strategic AML/CFT deficiencies.
- Non-face-to-face relationships where the risk of impersonation or identity fraud is elevated.
- Complex or unusually structured transactions without an apparent economic or lawful purpose.
- Private banking and wealth-management relationships above risk-sensitive thresholds.
- Any relationship or transaction assessed as higher risk under your business-wide risk assessment.
EDD is also strongly indicated — even where not strictly mandatory — whenever the client relationship involves opaque beneficial ownership, cross-border flows that do not match the apparent business, or sectors identified as high-risk in the Mauritius National Risk Assessment.
What EDD must cover
EDD is not just "more CDD". It is a qualitatively different exercise. At minimum it must address:
1. Source of funds (SoF)
The specific origin of the funds being used in the proposed transaction or relationship. "Salary" is not source of funds — the statement of account showing the salary being paid in, and the bank statement showing its onward movement to your firm, is. Evidence must be contemporaneous and corroborated.
2. Source of wealth (SoW)
How the client accumulated their total wealth. This is a biographical question: inheritance, entrepreneurial sale, long-term employment, investment returns. The evidence expected depends on the narrative — a sale-of-business SoW is evidenced by the SPA and completion account; an inheritance by the grant of probate and distribution schedule.
3. Purpose and intended nature of the relationship
Beyond "investment" or "banking services" — why this provider, this structure, this volume? The absence of a coherent answer is itself a red flag.
4. Beneficial ownership with corroboration
Ultimate natural person owners identified, with corroborating evidence — not a self-declaration alone. Where ownership is structured through trusts, nominees or complex corporate chains, the chain must be mapped and rationalised.
5. Ongoing monitoring uplift
EDD triggers an enhanced monitoring regime — higher-frequency review, tighter threshold alerts, and senior management sign-off for material changes. The intensity must match the risk.
6. Senior management approval
For higher-risk relationships, the onboarding decision and the EDD conclusions must have explicit senior management or MLRO sign-off. An unsigned EDD memo is, in the regulator’s eyes, an unmade decision.
The EDD evidence pack
A complete EDD file for a higher-risk client typically contains:
- The risk assessment that triggered EDD, with trigger reasons documented.
- The EDD memo — narrative setting out SoF, SoW, purpose, BO and assessed risk.
- Supporting evidence (bank statements, SPA, probate, tax returns, corporate filings).
- Screening results (sanctions, PEP, adverse media) with review notes.
- Senior management / MLRO approval, signed and dated.
- The ongoing monitoring plan for the relationship.
The failures regulators most often cite
Across our 60+ independent AML/CFT audits, the same EDD failures recur:
- "EDD applied" but no trigger documented. The file shows enhanced measures were taken, but not why. This makes the decision unreviewable.
- Source of funds confused with source of wealth. Files conflate the two or treat them as interchangeable. They are not.
- Evidence is self-declaration only. The client signed a form stating the source of wealth. No corroboration was obtained. This is not EDD — it is a questionnaire.
- Beneficial owner identified but not verified. Corporate chain mapped, but the natural-person BO’s identity is not evidenced to the standard of a direct client.
- No senior management approval. The file shows the EDD was done, but nobody signed off on the decision to proceed.
- Monitoring not uplifted. EDD was done at onboarding; the relationship reverted to standard monitoring thereafter.
How software supports EDD
A good onboarding platform does not do EDD for the MLRO — it removes the mechanical obstacles so the MLRO can focus on judgement.
Sherlock Onboarding supports EDD by:
- Triggering the EDD workflow automatically when rule-based or AI-based risk indicators fire.
- Pre-populating the EDD memo template with the triggering reasons.
- Requesting SoF/SoW evidence directly from the client in a structured, logged format.
- Capturing the senior management approval as part of the workflow — no unsigned files.
- Flagging EDD clients for enhanced ongoing monitoring in the monitoring engine.
- Producing an exportable EDD file on demand — mapped to the regulatory requirement.
The MLRO still makes the decision. The software ensures the decision is documented, evidenced and followed through.
Need an EDD health-check?
We can review a sample of your higher-risk client files against the FIAML Regulations 2018 and current regulator expectations — and flag the specific gaps before your next inspection.
Related
RegTech · KYC / Onboarding
Rethinking KYC onboarding: from paperwork to risk-based decisions in minutes
Digital ID, sanctions screening, hybrid AI risk scoring, beneficial ownership capture — and the audit trail regulators expect, by default.
Read article →AML/CFT · Governance
MLRO, DMLRO and Compliance Officer: roles, responsibilities and independence
The three compliance roles distinguished, the independence test regulators apply, and the board reporting standard they expect.
Read article →AML/CFT · Audit
Is your AML/CFT framework ready for an independent audit?
What regulators actually expect from an independent AML/CFT audit, how to scope it, and the common gaps we see across Mauritius licensees.
Read article →