When enhanced due diligence is required
In brief: Compulsory EDD factors, how risk points build up, and setting your firm's EDD threshold.
Every client risk assessment decides whether enhanced due diligence (EDD) is required. It happens in one of two ways.
1. A compulsory factor is present
EDD is always required when the assessment records any of these:
- the client, or a beneficial owner, director or person with significant control, is a politically exposed person (PEP), a family member of one, or a known close associate
- a sanctions match
- a connection to a FATF call-for-action country or a country under UK financial sanctions (such as Russia)
- false or stolen identity documents or information
- a transaction that is unusually complex or unusually large, or an unusual pattern, with no apparent economic or lawful purpose
- your own answer Yes to "is there a need for enhanced due diligence?"
These are marked Critical in your risk template. No threshold applies to them.
2. Risk factors build up to your threshold
Every other risk factor adds points. Most add 1 point. These add 2 points, because the AMLGAS guidance (Appendix D) or common red flags treat them as stronger signals:
- a cash-intensive business or income mostly in cash
- trading in high-risk goods (oil, arms, precious metals, tobacco, cultural artefacts, protected species, other high-value items)
- adverse media
- a client who has been evasive or uncooperative
- an ownership structure that is unusual or too complex for the business
- nominee shareholders or bearer shares
- a company used to hold someone's personal assets
- providing nominee directors or shareholders, forming companies abroad, or selling ready-made (off-the-shelf) companies
Other Appendix D factors add 1 point: payments from unknown or unconnected third parties, a service that favours anonymity, new products or technologies, a relationship conducted in unusual circumstances, and a client seeking residence or citizenship through investment.
HMRC accountancy sector risks
The assessment ends with a group of questions from HMRC's list of risks common to accountancy service providers: dormant companies, frequent changes of owner or director, unsupervised intermediaries, unexplained changes in activity, financial difficulty, frequent changes of accountant, pressure to reduce tax, audit combined with other services, and payroll anomalies. Individuals see the six that apply to a person.
Each Yes adds 1 point and raises the matching section to Normal. None requires EDD on its own. The questions are marked Optional: you can score without answering them. If HMRC supervises your firm for anti-money laundering, you must consider these risks, so answer them.
When the points reach your firm's EDD threshold, EDD is required. The default is 3: for example, cash plus one other factor, or three 1-point factors.
A single factor that is not compulsory raises its own section to Normal, not High, so on its own it gives a Medium rating rather than forcing EDD. If you judge a section High yourself, that still requires EDD. The rules never lower an answer you have given; when a rule would have suggested something lower, the assessment keeps your answer and records the rule's suggestion beside it.
Some answers are not scored but still count through the rules. For example, filings with HMRC or Companies House that are not up to date raise the identity section to Normal, and holding client money for the client raises the services section to Normal, as do company formation and a registered office service. None of these requires EDD on its own. Choosing nominee services or sale of ready-made companies in the services list answers the nominee and ready-made companies question Yes for you, so it scores 2 points. The one exception is a client you deal with remotely whose identity check failed: that raises the delivery channel section to High and requires EDD, because it points to false or stolen documents.
The assessment breakdown says which rule used each answer.
Recording enhanced due diligence
Record it on the Enhanced Due Diligence card in the client's risk assessment. Scoring the assessment no longer records it for you: it marks EDD as pending, and the card starts from the narrative you wrote on the assessment. Every record needs (AMLGAS 5.3.9):
- the background and purpose of the relationship and the measures you took, and
- the enhanced ongoing monitoring you will apply.
When the client, or one of its beneficial owners, is a politically exposed person, or the client is linked to a FATF call-for-action or sanctioned country, the record also needs source of wealth, source of funds and senior management approval with its date.
The approver is chosen from your firm: the owner, a manager or the appointed MLRO. You cannot approve a record you are recording yourself, unless you are the MLRO.
Simplified due diligence never applies alongside EDD
Simplified due diligence (SDD) is for clients who are low risk overall. The identity section asks which low-risk category a company falls into (a public body, a supervised credit or financial institution, or a company listed on a regulated market) and whether an individual lives in the UK or another lower-risk country. These answers are not scored. They feed a suggestion for the SDD question:
- Yes when a low-risk category applies and no risk factor is flagged
- No when no low-risk category applies, or a risk factor is flagged
- No whenever enhanced due diligence is required
If EDD is required, SDD must be set aside (AMLGAS 5.3.6). The form will not score the assessment while the SDD question says Yes and EDD is required: answer No first.
When the screening found a match
If the AML screening confirmed a PEP, sanctions or adverse media match and you answer No to that question, write the reason in the comment box. The assessment cannot be scored without it, whether you score it from the form or through a bulk re-score.
Setting your threshold
Settings → Risk → Firm-wide → When enhanced due diligence is required. Owners and managers can set any whole number from 1 to 10. A lower number means EDD more often.
The AMLGAS guidance (paragraph 5.3.8 and the Appendix D introduction) expects your policies to say what threshold you use, so record the number in your policies, controls and procedures.
Every change is written to your audit log with who made it, when, and the old and new values.
What each assessment records
Each scored assessment stores the threshold it was scored against, its risk points, and which factors counted. The threshold also appears on the risk assessment PDF. Changing your threshold does not change past results; re-score a client (or use Bulk re-score) to apply the new number.
The overall risk preview says Not scored yet until there is an answer to a scoring question. Informational answers alone do not create a risk band. After scoring answers are entered, the preview is available; use Save & Score to record the assessment.
Didn't find what you needed?
Contact support