A compliance officer screens a depositing address. The standard check clears it. Two hours later a sanctions designation lands on an address three hops upstream. The funds that arrived were already contaminated at the source. Standard customer due diligence asked who the customer is. It never asked what the money touched. That question belongs to Enhanced Due Diligence, the heightened check a VASP runs when a customer, address, or transaction carries risk signals above the baseline.
What Is EDD and How It Differs from CDD
Enhanced Due Diligence is the heightened level of customer due diligence that a VASP applies when standard CDD leaves residual risk unresolved. Where CDD confirms identity and records a baseline risk profile, EDD collects additional evidence on the source of funds, the purpose of the relationship, and the risk of the counterparty. For a crypto address, the new evidence EDD demands is on-chain risk proof, not another identity document.

Think of CDD as a standard physical and EDD as a specialist referral. CDD answers who the customer is and what the baseline risk looks like. EDD answers why this specific flow of funds carries elevated risk, and what evidence supports that judgment. The split matters in crypto because identity verification sits with the VASP, while the address and transaction risk evidence comes from on-chain screening. The two feeds must be combined inside the EDD file, not substituted for each other.
The FATF Risk-Based Approach makes EDD mandatory whenever a VASP identifies higher risk. The specific obligation is set by FATF Recommendation 10 and its Interpretive Note paragraph 20, which requires enhanced measures where higher risks are identified. The rule is proportionality. The higher the risk, the deeper the diligence. For the regulatory baseline, see FATF's Risk-Based Approach guidance for virtual assets.
What Triggers EDD for a Crypto Address
EDD is not a routine refresh. It is triggered by specific risk signals that push an address or a transaction above the standard CDD threshold. The triggers most compliance teams recognize, aligned with the FATF risk-based approach, fall into five families.

-
The address itself carries a high-risk label. Sanctioned, terrorist financing, human trafficking, drug trafficking, mixing, dark market, scam, ransomware, and laundering indicators all qualify. A labeled address is the strongest trigger because the risk is externally attested.
-
The flow of funds shows abnormal behavior. Large-value transfers above a defined threshold (the Phalcon Compliance default engine uses $50,000), high-frequency small payments that look like smurfing, and rapid transit through intermediary addresses are the standard signals of layering. Each pattern tells the team that the money is being moved to obscure its source.
-
The address or its counterparty sits in a sanctioned or FATF grey-list jurisdiction. Geography alone does not prove illicit intent, but under the risk-based approach it raises the diligence bar.
-
The address has direct interaction with a blacklisted counterparty. A single confirmed touch with a sanctioned address is enough to escalate.
-
The relationship involves a politically exposed person or another high-risk entity, such as an unregulated gambling service, an exchange with insufficient identity controls, or an address previously frozen by a stablecoin issuer.
These signals are not abstract. They map directly to the FATF-derived default risk engine set. The set includes Wallet Owned by Illicit Entities, Wallet Owned by High-Risk Entities, Unknown address with Large Transfers, High-Frequency Trading Address, Potential Intermediary Address, and Wallet Owned by Entity in FATF Grey-List Jurisdiction. When the trigger fires, the next step is not another screen. It is a deeper assessment, which is where crypto address risk assessment methodology takes over.
EDD Process and Document Checklist
Once EDD is triggered, the workflow runs through five stages: trigger confirmation, heightened risk assessment, document collection, decision and archiving, and continuous review. Phalcon Compliance fits inside stage two and stage five. It supplies the on-chain risk evidence that the EDD file requires. It does not perform the identity verification or file collection that the VASP owns.
Stage one confirms the trigger. The compliance team reviews the alert, the risk label, and the exposure path that produced it.

Stage two runs the heightened risk assessment. KYA screening produces the address-level risk labels across the seventeen risk indicators, from Sanctioned and Terrorist Financing through Mixing, Scam, and FATF Grey List Jurisdiction. The interaction path is traced across multiple hops to find where funds originated and where they are going. Two quantitative outputs feed the EDD file. Exposure Value is the total USD value of assets that originated from or touched a risk source. Exposure Percentage is the contaminated share of total inflow or outflow. For the transaction side, KYT screening evaluates each transfer individually, with direction set to Deposit for inflow tracing or Withdrawal for outflow tracing.
Stage three collects the documents the heightened risk case requires. Source-of-funds evidence, a statement of business purpose, counterparty identity information, and the risk assessment record itself. This stage is the VASP's responsibility, including the identity verification step, and Phalcon Compliance does not perform it.
Stage four records the decision. The case is accepted, rejected, or escalated into a suspicious transaction report. The KYA report and the per-transfer STR export are archived as the compliance artifact.
Stage five is continuous review. EDD is not a one-time file. Under the risk-based approach, an address cleared on Monday can be linked to illicit activity by Thursday. Monitor runs on a dynamic schedule, re-analyzing the address and firing on four event types: Risk Level Increased, Risk Level Decreased, Alert Triggered, and Alert Expired. That continuous loop is what turns EDD from a snapshot into an ongoing risk position.
Take EDD From Concept to Closed Loop
EDD is the entry concept. The deeper question is how an address is actually scored, how the seventeen indicators combine into a risk level, and how interaction paths are traced hop by hop. That methodology lives in the assessment layer, not the diligence definition. For the full AML compliance architecture that wraps CDD, EDD, and continuous monitoring into one platform, see AML compliance for crypto.
→ Book a Phalcon Compliance demo and run on-chain risk proof for your EDD cases: Book a demo
Frequently Asked Questions
Is EDD the same as KYC?
No. KYC verifies customer identity at onboarding. EDD is the heightened level of customer due diligence that a VASP runs when risk signals exceed the standard threshold. EDD builds on top of KYC, it does not replace it.
When should a crypto address be moved from CDD to EDD?
When one of the trigger signals fires: a high-risk label, abnormal fund flow, sanctions or FATF grey-list exposure, direct blacklist interaction, or a high-risk entity relationship such as a politically exposed person.
Does Phalcon Compliance perform the full EDD process?
No. EDD includes identity verification and document collection, which are the VASP's responsibility. Phalcon Compliance supplies the on-chain address and transaction risk evidence that feeds into the EDD file, plus continuous monitoring for ongoing review.
What documents does an EDD file typically contain?
Source-of-funds evidence, a statement of business purpose, counterparty identity information, the risk assessment record, and the exported KYA and STR reports that serve as the compliance artifact.
Is EDD a one-time check?
No. Under the risk-based approach, EDD is a continuous obligation. An address cleared at screening can acquire new risk later, so continuous monitoring re-runs on a dynamic schedule and alerts the team when the risk level changes.



