{"id":1807,"date":"2026-09-29T05:14:25","date_gmt":"2026-09-29T05:14:25","guid":{"rendered":"https:\/\/trackwizz.com\/knowledge-hub\/?p=1807"},"modified":"2026-10-07T05:16:39","modified_gmt":"2026-10-07T05:16:39","slug":"enhanced-due-diligence-paper-vs-practice","status":"publish","type":"post","link":"https:\/\/trackwizz.com\/knowledge-hub\/enhanced-due-diligence-paper-vs-practice\/","title":{"rendered":"Enhanced Due Diligence: Paper Vs Practice"},"content":{"rendered":"<p>There is a sentence buried in every AML policy manual in the country that reads, in some form or another: <em>&#8220;Enhanced Due Diligence shall be applied to customers classified as high risk.&#8221;<\/em> It is one line. It sounds procedural, almost administrative. And it perhaps conceals one of the widest implementation gaps in Indian financial compliance.<\/p>\n<p>All regulatory Know Your Customer Guidelines\/Master Directions establishes a risk-based approach to customer due diligence, structured across three tiers:<\/p>\n<ul>\n<li><strong>Simplified Due Diligence (SDD)<\/strong> &#8211; for low-risk relationships such as small-value accounts, basic savings products, and government welfare scheme accounts, where documentation requirements are deliberately relaxed to support financial inclusion.<\/li>\n<li><strong>Standard Customer Due Diligence (CDD)<\/strong> &#8211; the baseline applied to the general customer base, covering identity verification, address proof, and PAN linkage for financial transactions above prescribed thresholds.<\/li>\n<li><strong>Enhanced Due Diligence (EDD)<\/strong> &#8211; usually reserved for customers the institution has classified as high risk: <em>inter-alia<\/em> politically exposed persons (PEPs), non-resident customers connected to high-risk jurisdictions, cash-intensive businesses, entities with complex or opaque ownership structures, and relationships where the source of funds is not immediately apparent from the customer&#8217;s declared profile.<\/li>\n<\/ul>\n<p>On paper, EDD is not meant to be an incremental step up from standard CDD &#8211; it&#8217;s meant to be a qualitatively different exercise. The written expectation typically includes at least four components:<\/p>\n<ol>\n<li><strong>Deeper identity and beneficial ownership verification<\/strong>, going beyond the documents accepted for standard onboarding.<\/li>\n<li><strong>Active inquiry into source of funds and source of wealth<\/strong> &#8211; not just a declaration, but a plausibility check against the customer&#8217;s known profile.<\/li>\n<li><strong>More frequent, ongoing monitoring<\/strong> &#8211; regulatory guidance sets periodic review cycles at least once every two years for high-risk customers, against eight years for medium risk and ten years for low risk.<\/li>\n<li><strong>Senior management approval<\/strong> before the relationship is onboarded or continued.<\/li>\n<\/ol>\n<p>That is the design, and it is a defensible one. It mirrors what FATF expects of a genuinely risk-based AML programme, and it gives an examiner a clean audit trail to test against. The branch-level reality, however, is often something else entirely.<\/p>\n<h3><strong>Where the Gap Begins: Risk Scoring at Onboarding<\/strong><\/h3>\n<p>The first crack appears before EDD even starts at the point of risk classification itself. Most institutions score customers using a rules engine that weighs a handful of static attributes: occupation code, geography, product type, declared income bracket. If the score crosses a threshold, the file is tagged high risk and routed into the EDD workflow.<\/p>\n<p>The problem is that this scoring model is only as good as the inputs feeding it, and those inputs are almost entirely self-declared at the point of onboarding. A customer who understates occupation risk, omits a PEP relationship, or simply isn&#8217;t caught by a sanctions or adverse-media screening tool due to a name-matching miss never enters the EDD pathway, the policy assumes will catch them. The written policy assumes detection precedes classification. In practice, detection is often the weakest link in the chain and it is where a large share of India&#8217;s screening failures actually originate, not at the EDD stage itself.<\/p>\n<h3><strong>Source-of-Funds Inquiry: Checkbox vs. Conversation<\/strong><\/h3>\n<p>Assuming a customer is correctly flagged, the next gap opens at the heart of what EDD is supposed to accomplish: understanding where the money comes from.<\/p>\n<p>On paper, this means the relationship manager or compliance officer engages with the customer to establish whether declared income, business activity, and transaction volumes are internally consistent. In practice, several things tend to happen instead:<\/p>\n<ul>\n<li>A <strong>self-declaration form<\/strong> is accepted as sufficient, with no independent corroboration against bank statements, ITRs, or business filings.<\/li>\n<li>Branch staff, measured on account-opening volumes and turnaround time rather than diligence depth, have a structural incentive to move the file forward rather than push back on inconsistencies.<\/li>\n<li>The &#8220;additional scrutiny&#8221; that policy demands collapses into &#8220;additional paperwork&#8221; and paperwork, once signed, satisfies the audit trail even when it hasn&#8217;t satisfied the actual purpose of EDD.<\/li>\n<\/ul>\n<p>The distinction matters because an examiner reviewing the file after the fact sees a completed form and infers due diligence occurred. What the form cannot show is whether anyone actually interrogated the answer.<\/p>\n<h3><strong>Risk Classification as a One-Time Event<\/strong><\/h3>\n<p>A second, quieter gap: risk classification is meant to be a living assessment, but is frequently treated as a one-time onboarding decision.<\/p>\n<p>A customer flagged high risk at account opening is, in many institutions, never meaningfully re-evaluated until the periodic review comes due &#8211; which, per say for example, in RBI&#8217;s own cadence, can be up to two years later for even the highest-risk tier. But risk in the real world moves faster than a two-year cycle:<\/p>\n<ul>\n<li>A customer&#8217;s <strong>transaction behaviour<\/strong> can shift materially within months of onboarding, well before any scheduled review.<\/li>\n<li>A customer&#8217;s <strong>business activity or ownership structure<\/strong> can change without the institution being proactively informed.<\/li>\n<li>A customer&#8217;s <strong>public profile<\/strong> &#8211; a new political appointment, an adverse media mention, a regulatory action can emerge at any point, but is only caught if adverse-media screening is run continuously rather than only at onboarding.<\/li>\n<\/ul>\n<p>Regulatory frameworks anticipate ongoing monitoring precisely because static, point-in-time risk tagging misses this drift. At the branch level, &#8220;ongoing monitoring&#8221; frequently means nothing more than the transaction monitoring system generating rule-based alerts with EDD customers otherwise treated no differently from standard customers once the onboarding file is closed.<\/p>\n<h3><strong>Senior Sign-Off: Genuine Oversight or Formality?<\/strong><\/h3>\n<p>The requirement that EDD relationships receive senior management approval exists for a specific reason: to inject independent judgment into a decision the frontline may be incentivized to wave through. In practice, this safeguard often weakens in one of three ways:<\/p>\n<ul>\n<li><strong>Sign-off happens after the fact<\/strong> &#8211; the relationship is functionally already live by the time it reaches the senior officer&#8217;s desk, turning approval into ratification rather than review.<\/li>\n<li><strong>The reviewing officer sees only summary fields<\/strong> &#8211; a risk score, a checkbox status rather than the underlying source-of-funds documentation or any other information that would let them meaningfully disagree.<\/li>\n<li><strong>Volume overwhelms scrutiny<\/strong> &#8211; at institutions with large EDD populations, senior officers approving dozens of files a day cannot realistically apply the depth of review the policy envisions for each one.<\/li>\n<\/ul>\n<h3><strong>Large Commercial Relationships and its impact on EDD<\/strong><\/h3>\n<p>A large business customer may require more extensive EDD because its ownership structure, geographic footprint, transaction volumes, funding arrangements and business activities can be more complex. However, size or commercial importance alone should not make a customer high risk. EDD must remain \u201crisk-based and proportionate\u201d, focusing on the actual ML\/TF risks presented.<\/p>\n<p>Importantly, a customer&#8217;s commercial value should never result in weaker AML scrutiny. Where a customer is strategically or financially important, institutions should ensure independent compliance oversight so that commercial considerations do not influence risk classification, EDD, escalation or ongoing monitoring.<\/p>\n<h3><strong>Training and Institutional Memory<\/strong><\/h3>\n<p>A less discussed but equally significant gap sits in staff training. Branch-level turnover in Indian retail banking and NBFC networks is high, and AML\/CDD training is frequently delivered once, at induction, as a static compliance module rather than something refreshed against each new regulatory amendment.<\/p>\n<p>This creates a quiet drift: as an example, a staff member trained two RBI amendments ago &#8211; before the 2025 clarifications on PEP definitions and high-risk jurisdiction criteria, for instance, may be applying an understanding of &#8220;enhanced&#8221; scrutiny that no longer matches current expectations, without anyone flagging that the standard has moved beneath them.<\/p>\n<h3><strong>Why the Gap Persists<\/strong><\/h3>\n<p>None of this is a story of bad faith. It is a story of misaligned incentives and under-resourced execution. Compliance teams write policy to satisfy regulatory expectations, and those policies are, on their face, usually sound. But the people executing EDD day to day &#8211; branch staff, relationship managers, junior underwriters are rarely the people who wrote the policy, rarely trained to the same depth, and rarely evaluated on adherence to it with the rigor applied to their business targets.<\/p>\n<p>The result is a two-tier compliance reality: one version exists in the policy manual and satisfies an examiner reading documents; another exists at the counter and reflects what time, training, and incentive structures actually permit.<\/p>\n<h3><strong>Closing the Gap<\/strong><\/h3>\n<p>The fix is not another layer of documentation that has already been tried, and it is precisely how EDD became a checkbox exercise in the first place. Closing the gap requires making correct EDD operationally cheaper than superficial EDD:<\/p>\n<ul>\n<li><strong>Better risk scoring models<\/strong> that reduce false-high-risk noise, so EDD resources concentrate on genuinely elevated-risk relationships rather than being spread thin across over-flagged files.<\/li>\n<li><strong>Screening systems that catch PEP and adverse-media signals continuously<\/strong>, not just at onboarding, reducing reliance on customer self-declaration &#8211; which should never be relied upon.<\/li>\n<li><strong>Workflows that route EDD files to reviewers with both the time and the authority to push back<\/strong>, rather than volume-driven sign-off queues.<\/li>\n<li><strong>Refresher training tied to each regulatory amendment<\/strong>, rather than a one-time induction module that ages silently.<\/li>\n<\/ul>\n<p>Until execution is measured with the same seriousness as policy is written, the gap between what a regulator expects on paper and what happens at the branch will remain one of Indian AML&#8217;s most persistent and least discussed vulnerabilities.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>There is a sentence buried in every AML policy manual in the country that reads, in some form or another: &#8220;Enhanced Due Diligence shall be applied to customers classified as high risk.&#8221; It is one line. It sounds procedural, almost administrative. And it perhaps conceals one of the widest implementation gaps in Indian financial compliance. [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"inline_featured_image":false,"footnotes":"","_links_to":"","_links_to_target":""},"categories":[8],"tags":[],"class_list":["post-1807","post","type-post","status-publish","format-standard","hentry","category-anti-money-laundering"],"_links":{"self":[{"href":"https:\/\/trackwizz.com\/knowledge-hub\/wp-json\/wp\/v2\/posts\/1807","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/trackwizz.com\/knowledge-hub\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/trackwizz.com\/knowledge-hub\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/trackwizz.com\/knowledge-hub\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/trackwizz.com\/knowledge-hub\/wp-json\/wp\/v2\/comments?post=1807"}],"version-history":[{"count":1,"href":"https:\/\/trackwizz.com\/knowledge-hub\/wp-json\/wp\/v2\/posts\/1807\/revisions"}],"predecessor-version":[{"id":1808,"href":"https:\/\/trackwizz.com\/knowledge-hub\/wp-json\/wp\/v2\/posts\/1807\/revisions\/1808"}],"wp:attachment":[{"href":"https:\/\/trackwizz.com\/knowledge-hub\/wp-json\/wp\/v2\/media?parent=1807"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/trackwizz.com\/knowledge-hub\/wp-json\/wp\/v2\/categories?post=1807"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/trackwizz.com\/knowledge-hub\/wp-json\/wp\/v2\/tags?post=1807"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}