What an EDD file should actually contain
Most enhanced due diligence files I inherit are not wrong so much as incomplete in ways nobody noticed until a reviewer arrived. The gap is almost always the same one: a file that explains where money came from last week but never establishes how the wealth was built in the first place. This note walks the components of a file that holds up.
The distinction that does most of the work
I have reviewed a great many enhanced due diligence files over about twenty years, and the single most common structural weakness is not a missing document. It is a conflation. The file treats source of wealth and source of funds as one question, answers the easier of the two, and calls the matter closed.
Source of funds is a transactional question. Where did this specific money, arriving on this date in this amount, come from immediately before it reached us? A property completion. A dividend payment. A transfer from an account at another institution. It is narrow, it is usually documentable, and it is often the only question a rushed file answers.
Source of wealth is a biographical question. How did this person or entity come to have money at all? Over what period? Through what activity? A customer can have an entirely clean source of funds for a given payment — the solicitor's client account really did send it — while the underlying wealth remains unexplained. The property was bought with cash of unknown origin nine years ago. The solicitor's letter tells you nothing about that.
When I train analysts I put it like this. Source of funds explains the last hop. Source of wealth explains the whole journey. A file that only does the former is a file that will not survive a reviewer who asks a second question.
The evidence standard
There is a temptation in EDD to collect paper for the sake of having collected paper. I have opened files with forty attachments and no discernible conclusion. The volume was doing the work that reasoning should have been doing.
The standard I hold teams to is this: every material assertion in the file should be traceable to something, and the file should say what that something is and how much weight it carries. Not all evidence is equal, and pretending otherwise is where files go soft.
I think of evidence in rough tiers. Independently verifiable documents from a source with no interest in the outcome sit at the top — audited accounts, land registry extracts, court filings, tax assessments issued by an authority. Below that, documents produced by a regulated third party who has their own duty of care: a solicitor's completion statement, an accountant's letter on headed paper with a practising certificate reference. Below that again, documents produced by the customer themselves — a self-prepared schedule of assets, a business plan, a CV. And at the bottom, the customer's oral explanation recorded by the relationship manager.
None of those tiers is worthless. The customer's own explanation is often the most useful thing in the file, because it gives you the shape of the story you then go and test. But a file that rests its conclusion entirely on the bottom two tiers has not done enhanced diligence. It has done an interview.
The other half of the standard is contemporaneity. I want to know when the evidence was obtained, by whom, and whether anything has changed since. A source of wealth narrative built on accounts filed six years ago, for a business that has since been sold, is a historical document rather than a current control. Guidance from JMLSG is useful here on the principle that the depth and currency of information should be proportionate to the risk presented, and I have found that framing lands better with commercial colleagues than a flat demand for more paper.
Walking the components
Verified identity, and what verified means
Identity verification is the part most firms do competently, so I will be brief. The thing I check is whether the file distinguishes between identity that has been verified and identity that has been asserted. A passport image sitting in a folder is not verification. Verification is the record of what was checked, against what source, on what date, with what result, and what the residual gaps were.
For entities, I want the equivalent for each individual in scope — not a list of names lifted from a corporate registry, but a record of who was actually verified and who was simply named.
The ownership chain, drawn as a chain
This is where I see the most avoidable failure. A file will state that Mr A holds sixty per cent of a holding company which holds all of an operating company, and stop. But there was a nominee arrangement two layers up, and a trust with a protector in a third jurisdiction, and nobody wrote it down because nobody drew the picture.
I insist on a structure diagram in every complex-entity file, with percentages, jurisdictions of incorporation, and the date the structure was as described. Where the chain breaks — a bearer instrument, an unverifiable nominee, a foundation with no published beneficiary — the file should say the chain breaks there and explain what compensating enquiry was made. A break that is documented and reasoned is a finding. A break that is silently smoothed over is a defect.
Expected activity, expressed in numbers
"Customer expects regular international payments" is not expected activity. It is a shrug. Expected activity is a set of parameters specific enough that a deviation from them is visible: approximate monthly credit and debit volumes, typical individual transaction size, the counterparty countries anticipated, the products expected to be used, and the seasonality if there is any.
The reason to be precise is downstream. Everything the monitoring team does depends on somebody having written down what normal was supposed to look like for this relationship. When I have sat with analysts working through a queue, the alerts that take longest to resolve are almost always the ones where the onboarding file gave them nothing to compare against. If you want a sense of what that feels like from the receiving end, the note on transaction monitoring alert triage covers how thin expected-activity records slow everything down.
Adverse media, including the absence of it
A file that contains no adverse media results is ambiguous. Did the analyst search and find nothing, or did nobody search? I have inherited hundreds of files where that question could not be answered, and it is the easiest defect in this entire note to fix.
Record the search: the tool or database used, the exact search strings including transliterations and known aliases, the date and time, the date range covered, the languages searched, and the outcome. A negative finding, properly recorded, is evidence. An unrecorded negative finding is nothing at all.
Where there are hits, I want the discounting logic written out. "Different date of birth, different city, subject of article is a chef in Lyon" takes twelve seconds to type and saves the next reviewer forty minutes.
The sign-off trail
Enhanced due diligence usually requires approval above the level of the person who compiled it, and the specific approval requirements vary by jurisdiction and by firm policy — for politically exposed persons in particular, you should be working from your own local rules rather than a general assumption. What does not vary is that the trail should show who approved what, on the basis of what version of the file, and with what conditions attached.
Conditions matter and are usually omitted. If approval was granted subject to obtaining the 2023 accounts within ninety days, the file needs to show that condition and its subsequent discharge or breach. I have seen conditional approvals treated as unconditional simply because nobody diarised the condition.
Case note
A composite from several remediation programmes. We picked up a corporate relationship onboarded in March 2019 — a commodities trading company incorporated in one jurisdiction, banking with us in another, with a beneficial owner resident in a third. The file rated the relationship high risk and contained twenty-two attachments. Turnover through the account across 2021 and 2022 ran at about £14m a year against an expected-activity figure recorded at onboarding as "significant trade flows".
The source of funds work was competent. Every large credit we sampled — eleven payments between £180,000 and £2.3m — traced to a named commercial counterparty with an invoice on file. But the source of wealth section was a single paragraph stating that the owner had built the business over twenty years in agricultural commodities. There was no evidence of the earlier businesses, no accounts predating 2018, and no explanation of the $4.1m equity injection recorded in the 2018 balance sheet as "shareholder loan". Adverse media had been run once, in 2019, in English only, on the anglicised spelling of a name with two other common transliterations.
The remediation took about seven weeks. Two of the three transliterations returned nothing of substance. The third returned a 2016 regulatory action in the owner's home jurisdiction against a company he had directed, which did not in itself change our conclusion but which the file should have contained from the start. The relationship continued, on a revised risk rating, with an expected-activity record that actually had numbers in it.
The four gaps I find in almost every inherited file
These recur across banks, payment firms and crypto businesses alike, and they are not sophisticated failures. They are the consequence of files being built under time pressure by people who were never shown a good one.
- Source of wealth asserted, never evidenced. A sentence of biography where a documented history should be. This is the big one and it accounts for more remediation hours than the other three combined.
- Adverse media with no negative-findings record, so a reviewer cannot distinguish a clean search from an absent one.
- Expected activity written in adjectives rather than figures, which quietly degrades every downstream monitoring decision for the life of the relationship.
- No refresh trigger. The file is a photograph of one afternoon in 2019. Nobody recorded what event or date should cause someone to look again, so nobody did.
I would add a half-gap: files that record conclusions without recording the reasoning that produced them. The conclusion "we are satisfied as to source of wealth" is not portable. The reasoning behind it is. When the analyst who wrote it has moved on and a reviewer arrives eighteen months later, only the reasoning survives.
Writing it so somebody else can use it
The discipline that makes a good EDD file is the same discipline that makes a good suspicious activity report: write for a reader who has none of your context and cannot ask you questions. If you find that hard, the worked example of a SAR narrative is a useful drill, because the constraint is identical and the feedback loop is shorter.
Structurally, I ask for a one-page summary at the front of every complex file: who the customer is, what they do, where the wealth came from, what we expect to see, what we found and discounted, and what we are relying on. Everything else is annex. A reviewer who reads only that page should reach roughly the conclusion the file reached. If they cannot, the file is not finished, however many attachments it holds.
Two habits I would press on anyone building these. Date every assertion, because an undated statement about a customer's business is unfalsifiable and therefore useless. And write down what you could not establish. The FATF standards are built on a risk-based approach, and a risk-based approach depends on knowing where your knowledge stops. A file that admits its own limits is more defensible than one that pretends to completeness, and the FCA has been consistent over the years that documented reasoning under uncertainty is treated more sympathetically than confident silence.
None of this is about volume. Some of the strongest files I have read ran to nine pages. They were strong because someone had thought about what they were trying to establish, established it, said what they had failed to establish, and signed their name to the whole thing.
Worth remembering: Source of funds explains the last hop; source of wealth explains the journey, and a file that only does the first has answered the easier question.