Chat with us, powered by LiveChat

Customer Due Diligence vs Enhanced Due Diligence

September 14, 2026

Customer due diligence is the baseline file an onboarding team must finish before a relationship, an account or an occasional transaction proceeds. Enhanced due diligence is the same file with extra identity, purpose, source of funds and source of wealth, tighter monitoring and, where the statute requires it, senior-management approval.

Nataly Medici
Nataly Medici
Managing Partner and CEO

FATF Recommendation 10 writes the baseline; Recommendation 12 writes the PEP overlay. Federal Decree by Law No. (10) of 2025 Article 19 requires CDD. Cabinet Resolution No. (134) of 2025 sets the operating rules: Articles 6 to 15 for CDD, Article 5(2) for the EDD toolkit, Article 16 for PEPs, Article 23 for high-risk countries.

A resident SME with a simple chart, a matching licence and no PEP hit stays on CDD if the Article 5 risk score supports it. A foreign PEP, a National Committee high-risk-country link, or a customer Article 1 already calls high risk moves the desk onto EDD. AML, CDD and EDD procedure work has to encode that fork. Digital asset legal support is the overlay conversation when the customer is a VASP.

Which instruments set the CDD and EDD split in 2026?

Write first to the federal instruments, then to the supervisor who will sample the file. Decree-Law 10 has been in force since 14 October 2025. Cabinet 134 has been in force since 14 December 2025, thirty days after Official Gazette Issue 811 dated 15 November 2025. They bind financial institutions, DNFBPs and VASPs. FATF Recommendations 10 to 13 are the international benchmark. They do not replace Cabinet article numbers.

CBUAE’s Guidance for Licensed Financial Institutions on Customer Due Diligence / Know Your Customer and Record-Keeping, dated 6 November 2025, creates no new statute. It tells CBUAE licensees how to show why the customer was onboarded, how the customer was risk-rated and how activity was monitored. Confirm the live Rulebook node: some PDF cross-references still point at repealed Cabinet 10/2019 numbering. Use Cabinet 134 numbers in the procedure.

Sector licences add a second layer. Dubai VASPs take VARA’s 4 March 2026 circular on Cabinet 134 plus the Compliance and Risk Management Rulebook. DIFC and ADGM firms still sit on the federal floor and on DFSA or FSRA modules. Crypto compliance in 2026 is the operating map for virtual-asset businesses inside that overlay. Confirm live pages before you freeze a board pack.

When does standard customer due diligence suffice?

Standard CDD is the lane after Article 5 has weighed customer, country, product, transaction and delivery-channel risk and the residual score is not high. FATF Recommendation 10 names four jobs: identify the customer, identify the beneficial owner, understand purpose and intended nature, and monitor against that picture. Cabinet Articles 6 to 11 and 13 to 15 turn those jobs into UAE rules. This lane fits a resident person or a legal person with a short chain, a matching licence, and no Article 16 foreign-PEP or Article 23 country hook. It fails when “standard” means skipping Article 8, ignoring Article 14 when papers stall, or skipping EDD on a customer Article 1 already calls high risk.

Identity and verification

Article 6 requires verification of the customer and the beneficial owner before or during establishment of a business relationship or account opening, or before an occasional transaction. Low-risk deferral is allowed only if verification follows as soon as possible, the deferral is needed so business is not disrupted, and you apply effective crime-risk controls. You still manage the risk if the customer can use the relationship before verification finishes. Article 21(1) requires the written programme to include those pre-verification procedures.

Article 9 sets identity content for natural persons (name, nationality, address, date and place of birth, employer where applicable, true copy of a valid identity card or travel document) and for legal persons or arrangements (name and form, memorandum, tax registration where corporate tax applies, registered office, articles, senior managers). Anyone acting for the customer must be authorised and identified to the same standard. Original documents or data from a reliable independent source are the medium.

Purpose, ownership and the 25 percent cascade

Article 9(3) and 9(4) require purpose and intended nature, plus the customer’s business and ownership and control structure. Article 10 is the beneficial-owner cascade for legal persons: the natural person who owns 25 percent or more, alone or with another; if that is in doubt or if no one controls through ownership, the natural person who exercises legal or actual control; if none, the senior manager. Legal arrangements have their own list: trustee, settlor, protector, beneficiaries or classes, and any other natural person with ultimate effective control. Article 11 relieves listed companies subject to sufficient disclosure, and qualifying subsidiaries. How a given corporate chain is evidenced is a KYB file step. Some correspondent questionnaires collect 10 percent; Article 10 remains 25 percent, then control, then senior manager.

Ongoing monitoring

Article 8 requires you to scrutinise transactions throughout the relationship so they stay consistent with what you know about the customer, the activity and the risk, including source of funds where necessary, and to keep CDD data up to date, with particular emphasis on high-risk categories. Article 13 required CDD on existing relationships when Cabinet 134 entered into force, on a materiality and risk timetable.

CBUAE’s November 2025 guidance treats CDD as ongoing: onboarding, occasional transactions, suspicion, unreliable identification, periodic review and trigger events. A file complete at day one and never reviewed is already off Article 8. Standard CDD still produces a risk rating, an expected-activity profile and a review clock at ordinary intensity.

When must you apply enhanced due diligence?

EDD is CDD plus the Article 5(2)(c) toolkit when residual crime risk is high or another article names the customer. FATF Recommendation 1 requires enhanced measures where money-laundering or terrorist-financing risk is higher. The sections below match the CDD block: identity, purpose and funds, then monitoring and approval. Article 5(4) covers high proliferation-financing risk. This lane fits a foreign PEP, a National Committee high-risk-country person, a complex ownership vehicle, or a customer Article 1 already labels high risk. It fails when the seven examples are ticked with no reconstructable narrative. Building real rules for crypto argues that the operating file has to match the rulebook.

Extra identity and open sources

Article 5(2)(c)(1) adds identity, occupation, beneficial-owner facts, amount of funds, and information from public databases and open sources. That is adverse media, court and regulatory records, and a second pass on the names Article 9 already captured. You test whether the person the passport names matches the person open sources describe, and whether the occupation supports expected activity.

CBUAE’s EDD node (Rulebook 6.4 / 6.4.2) tells licensed financial institutions to judge the reasonableness of that extra information and to look for inconsistencies. A professional story that disagrees with the licence is an EDD finding. Confirm the live 6.4 page for your licence type. The federal list in Article 5(2)(c) is the floor for DNFBPs and VASPs as well.

Purpose, source of funds and source of wealth

Article 5(2)(c)(2) demands extra purpose: why this relationship, why these expected transactions, why transactions that already ran. Article 5(2)(c)(4) demands reasonable measures on source of funds and source of wealth for the customer and the beneficial owner. Source of funds is the origin of the monies in the relationship. Source of wealth is how overall net worth was built. A salary letter does not explain a property portfolio. A token-sale narrative does not explain cash from an unrelated third party.

VARA’s 4 March 2026 circular restates the same pair for Dubai VASPs where higher risks are identified, with additional scrutiny and, where appropriate, first-payment requirements and senior-management approval. First payment through an equivalent-CDD account is already Article 5(2)(c)(6). Put the trail in the file with statements, contracts or sale documents a stranger can follow.

Monitoring intensity and senior-management approval

Article 5(2)(c)(3) shortens the refresh cycle. Article 5(2)(c)(5) raises ongoing monitoring and names transaction patterns for extra review. Article 5(2)(c)(7) is the gate: senior-management approval to start or continue. CBUAE expects licensed financial institutions to record that approval against a stated risk appetite. Sales cannot be the signatory.

This intensity fits a relationship the board has accepted with a monitoring code operations can run. It fails when approval is a rubber stamp on an incomplete pack, or when monitoring still uses the standard-customer ruleset. Nataly Medici’s line on filings applies: a licence or banking file rejected for sloppy documentation is harder to recover from than one that was never filed.

How do politically exposed persons change the file?

Politically exposed persons are a statutory overlay on ordinary CDD. FATF Recommendation 12 requires systems to identify PEPs, senior-management approval, reasonable measures on source of wealth and funds, and enhanced ongoing monitoring, including family members and close associates. Cabinet Article 16 splits the UAE duty. Article 1 defines PEPs as natural persons entrusted, now or previously, with prominent public functions in the State or abroad: heads of state or government, senior politicians, senior government, judicial or military officials, senior executives of state-owned enterprises, senior party officials, and persons who manage international organisations.

Screen the customer and the beneficial owner under Article 16. A hit that nobody dispositions is a failed file in either lane.

Foreign PEPs

Article 16(1)(a) is mandatory for foreign PEPs: systems that can tell whether the customer or beneficial owner is a PEP; senior-management approval before establishing or continuing the relationship; reasonable measures on source of funds and wealth; enhanced ongoing monitoring.

This lane fits a non-UAE official, former official or beneficial owner who holds a foreign prominent function, where the firm has appetite and a monitoring code. It fails when a common-name hit is filed as “no match” without comparing date of birth, nationality and office, or when approval arrives after the account is live.

Domestic PEPs and international organisations

Article 16(1)(b) is a two-step. Take adequate measures to determine whether the customer or beneficial owner is a domestic PEP or a person with a prominent function in an international organisation. Apply the foreign-PEP extras where the relationship is high risk. A UAE minister’s sibling on a low-risk payroll account is not automatically on the full foreign-PEP pack. The same person wanting a personal asset-holding vehicle with cross-border wires is.

Article 16(2) adds a life-insurance limb: before payout or related rights, take reasonable measures on whether the beneficiary or that person’s beneficial owner is a PEP. Higher risk means inform senior management first, enhance scrutiny of the whole relationship, and consider an STR. Article 12 already treats a high-risk legal-person or legal-arrangement beneficiary as an EDD trigger at payout.

What documentation does each lane leave behind?

The reviewer samples a file, not a vendor dashboard. CBUAE’s November 2025 guidance asks licensed financial institutions to show why the customer was onboarded, how the customer was risk-rated and how activity was monitored. Cabinet Article 25 sets a federal clock of at least five years for transaction records and for CDD records, calculated from the latest of the listed events (relationship end, account closure, occasional transaction, inspection, investigation or final judgment). Organise the file so individual transactions can be reconstructed. VARA requires at least eight years for VASP books and AML records. Write both clocks if you hold a VARA permission. Commercial advisory fees sit outside any government tariff map; that work is not a Medici quote.

The standard CDD record

A reconstructable CDD file holds the Article 9 identity pack; agent authorisation; purpose in product language; ownership and control; the Article 10 cascade ending in a natural person, or an Article 11 listed-company note; an Article 5 risk rating; expected activity; screening dispositions with analyst name and date; Article 6 timing (or a documented low-risk deferral); and the Article 8 review clock. Suspicion or doubt about old data is itself an Article 7 trigger to refresh CDD.

This record fits a relationship operations can monitor against a simple expected-activity line. It fails when the rating says “medium” with no factors written down, or when screening is a green tick with no near-match disposition.

The EDD record

An EDD file holds everything in the CDD record plus the Article 5(2)(c) extras that applied: open-source and occupation pack; expanded purpose; shortened refresh cycle; source-of-funds documents; source-of-wealth documents; intensified monitoring code and selected patterns; first-payment evidence where used; and senior-management approval with date, name and residual-risk statement. Foreign PEP files add how you decided the person is a PEP under Article 16(1)(a).

This record fits a high-risk acceptance the board can defend. It fails when the extras are a second passport copy and a search screenshot with no analysis. EDD is depth plus a named decision.

Which statutory overlays force EDD even when the scorer hesitated?

Some triggers do not wait for a model score. Article 23 and Article 26 name country and correspondent cases that take enhanced measures even if the internal scorer preferred a medium rating. Article 15 bans shell banks and anonymous or fictitious-name accounts in every lane. Decree-Law Article 19(1)(c) repeats the anonymous-account ban and adds numbered names. A scorer who rates a correspondent file “medium” and skips Article 26 has not applied the statute. Targeted financial sanctions screening still runs on every customer; the freeze-and-notice process is a separate operating file. The two overlays below are the named statutory forks.

High-risk countries

Article 23(1) requires enhanced CDD proportionate to risk on relationships and transactions with a natural or legal person from countries the National Committee identifies as high-risk, or from countries with AML/CFT/CPF deficiencies. Article 23(2) requires countermeasures the supervisor or the Committee require. FATF Recommendation 19 is the international twin. Confirm the live National Committee list and the FATF high-risk and increased-monitoring lists on the day you rate the file. The UAE left FATF increased monitoring on 23 February 2024; that fact does not freeze your Article 23 procedure. This overlay fails when the team screens nationality only and ignores formation country, account use or fund origin.

Correspondent banking and shell banks

Before a correspondent or similar relationship, Article 26 requires financial institutions to refuse shell banks and institutions that let shell banks use accounts; collect enough information to identify the respondent and understand its business, reputation and supervision; assess anti-crime controls; obtain senior-management approval; and understand each institution’s anti-crime responsibilities. For payable-through accounts, ensure the respondent applied CDD to customers with direct access and can provide that CDD on request. FATF Recommendation 13 is the same architecture. Article 15 is the customer-facing ban on shell banks and anonymous names. This overlay fits a bank that clears for another institution. It fails when a payments firm treats a nested VASP as “just another corporate” on standard CDD. UAE company formation and licensing is the permission layer that has to match the correspondent story.

What happens if CDD cannot be completed?

Article 14(1) prohibits establishing or continuing a business relationship, and prohibits executing a transaction, where you cannot apply CDD. Consider an STR to the Unit. CBUAE’s November 2025 guidance says the same: do not establish or maintain a customer who cannot or will not provide required CDD, including at review. A missing beneficial owner still blocks under Article 14 after open-source extras.

Article 14(2) is the narrow exception. If you suspect a crime and have reasonable grounds to believe CDD would tip off the customer, you may withhold those measures and must file an STR stating why. Decree-Law Article 18 and Cabinet Article 18 require that report without delay through the Unit’s electronic system. Cabinet Article 19 forbids tipping-off. The compliance officer owns the retain-or-file decision under Article 22. “Pending documents, account already funded” is a breach in progress.

When is simplified due diligence allowed?

Article 5(3) allows simplified due diligence only after the Article 5(1) risk assessment and Article 5(2) mitigation design, in coordination with the supervisory authority, where low risks are identified, and unless crime is suspected. Simplified measures must keep targeted financial sanctions instructions in full force. Examples include verifying identity after the relationship starts, longer update intervals, reduced monitoring, and inferring purpose from the type of transaction or relationship. FATF’s February 2025 update to Recommendation 1 encouraged simplified measures in lower-risk scenarios; UAE Article 5(3) still requires supervisor coordination and a documented low-risk finding.

This lane fits a tightly scoped low-risk product the supervisor has accepted as simplified, with TFS still running. It fails when a fintech applies “SDD” to a non-resident complex structure for volume reasons. Suspicion kills simplification: Article 7(1)(b) returns you to full CDD, and the risk may then be EDD.

At which moments must CDD or EDD run?

Article 7 lists the moments. Everyone in the perimeter applies CDD at the start of a business relationship, on suspicion of a crime, and on doubts about previously obtained identification data. Financial institutions also apply CDD to occasional transactions of AED 55,000 or more, including linked transactions, and to occasional wire transfers of AED 3,500 or more. VASPs apply CDD to occasional transactions of AED 3,500 or more, including linked transactions. Confirm Article 7 live for your activity. Do not import a US dollar currency-transaction figure and hope it maps.

EDD runs at those same moments when the customer or transaction is high risk, and again when a trigger changes the score: a PEP hit on refresh, a new country of operation, an unexpected product, a volume spike, or a beneficial-owner change. Article 24 requires a crime-risk assessment of new products, practices and technologies before launch; a new wallet flow can move a population from CDD to EDD before the marketing site updates.

Dealers in precious metals and stones sit on a separate Article 3 cash threshold of AED 55,000 for DNFBP perimeter. Gaming operators sit on Article 3(1) at AED 11,000. Keep the figures labelled by activity.

What extra does a Dubai VASP overlay add?

VARA’s 4 March 2026 circular tells Dubai VASPs to apply Cabinet 134 without delay. Occasional CDD at AED 3,500, linked transactions included, is restated. Where higher risks are identified, EDD must include source of funds and wealth, additional scrutiny, and strengthened safeguards including first-payment requirements and senior-management approval. Virtual-asset transfers still need originator and beneficiary information obtained, verified, retained and transmitted. Records follow the VARA eight-year floor. Proliferation financing is a distinct component of the business risk assessment.

The circular does not replace Articles 6 to 16. It tells you which Cabinet sentences VARA will sample in 2026. Federal Article 36 still requires a VASP permission for virtual-asset activities conducted from the State. The CDD/EDD fork sits on that permission.

How will a bank or PSP desk read the fork you chose?

A bank or PSP onboarding the firm, or the firm’s customers through a nested flow, will replay the same fork: who stayed on CDD, who moved to EDD, who approved the high-risk book, and whether Article 14 is operable. Ksenia Babochkina’s line on the compliance service page applies: regulators move faster than founders expect, and what looked low-risk eighteen months ago can be a licensing requirement today.

The desk will sample one standard file and one enhanced file against identity, purpose and ownership, monitoring, then the extras. If the enhanced file shows source of wealth, a PEP or country rationale, a monitoring code and a named approver, the fork is visible. Confirm the live Cabinet text, the live CBUAE CDD guidance node and, for Dubai VASPs, the live VARA circular. Article numbers above are Cabinet 134 as hosted on the CBUAE Rulebook on 24 August 2026.

FAQ

What are the three types of due diligence in AML?

Simplified due diligence, customer due diligence and enhanced due diligence. In the UAE, simplified measures exist only under Cabinet 134 Article 5(3) after a documented low-risk finding, in coordination with the supervisor, and never where crime is suspected. TFS still applies in full. CDD is Articles 6 to 15. EDD is the Article 5(2)(c) toolkit plus overlays in Articles 12, 16, 23 and 26.

What are the four pillars of customer due diligence?

US search results often mean the FinCEN CDD rule (identify and verify the customer, beneficial owners, nature and purpose, ongoing monitoring). FATF Recommendation 10 uses the same four jobs. UAE procedures should cite Cabinet Articles 6, 8, 9 and 10 rather than “four pillars.” Article 21 lists six programme items, not five BSA pillars.

When must you do enhanced due diligence in the UAE?

When Article 5 residual risk is high; when the customer or beneficial owner is a foreign PEP (Article 16(1)(a)); when a domestic or international-organisation PEP relationship is high risk (Article 16(1)(b)); when the person is from a National Committee high-risk or deficient country (Article 23); when a life-insurance beneficiary is a high-risk legal person or arrangement (Article 12(2)); and, for financial institutions, before correspondent relationships (Article 26). Confirm the live Article 1 high-risk customer definition for your sector.

What is the difference between KYC and EDD?

Know-your-customer is the operational name for collecting and verifying identity. Customer due diligence is the legal set of measures, including purpose, beneficial ownership and ongoing monitoring. Enhanced due diligence is CDD plus extra depth where risk is high. A completed KYC checklist can still fail CDD if purpose and beneficial ownership are missing.

Does a PEP always require enhanced due diligence?

A foreign PEP does under Article 16(1)(a): systems, senior-management approval, source of funds and wealth, enhanced monitoring. A domestic PEP or a person with a prominent function in an international organisation takes those extras where the relationship is high risk. Low-risk domestic PEP retail accounts stay on CDD until the relationship scores high.

Can I onboard if the customer still owes documents?

No, except the narrow Article 14(2) tipping-off path, which requires an STR explaining why CDD was withheld. Article 14(1) otherwise forbids the relationship, its continuation and the transaction. Low-risk deferral under Article 6(2) is timed verification, not an open tab.

How long must CDD and EDD records be kept?

Cabinet Article 25: at least five years from the most recent of the listed events. VARA: at least eight years for VASP books and AML records. Keep both clocks if you hold a VARA permission. Reconstruction of individual transactions is the test.

Is source of wealth required for every customer?

Reasonable measures on source of funds and wealth are an EDD measure under Article 5(2)(c)(4) and a mandatory foreign-PEP measure under Article 16(1)(a)(3). Article 8 can still require source of funds on a standard relationship where monitoring needs it. A low-risk resident payroll customer on CDD does not automatically need a full source-of-wealth dossier.

Sources

Connect with our experts

Get full clarity on licensing, compliance and structuring before you spend time and budget on the wrong move.

Book a Free Call

Ready to build a structure that actually works?

Whether you are launching a fintech company, applying for a license, entering the UAE, issuing a token or preparing for regulatory review — we can help you choose the right path before costly mistakes happen.

Book a Free Call