The FCA’s Latest CDD Review Sends a Clear Message: Due Diligence Must Be Evidenced, Not Just Performed
The FCA’s 2026 review of customer due diligence controls highlights a recurring weakness across firms: due diligence may be taking place, but firms cannot always demonstrate what was done, why it was done, or how higher-risk customers were treated differently. The findings reinforce the need for structured, risk-based and evidence-backed CDD and EDD processes.
The FCA’s Latest CDD Review Sends a Clear Message: Due Diligence Must Be Evidenced, Not Just Performed
In April 2026, the UK Financial Conduct Authority (FCA) published the findings of a multi-firm review examining Customer Due Diligence (CDD), Enhanced Due Diligence (EDD) and ongoing due diligence controls.
The review assessed firms through questionnaires, policy and procedure reviews, customer file reviews and staff interviews. It covered asset managers, crowdfunding firms, wholesale banks, contracts-for-difference firms and non-bank lenders, although the FCA makes clear that its findings are relevant to firms undertaking CDD and EDD more broadly.
The findings are worth paying attention to.
Not because the FCA has introduced a fundamentally new concept of due diligence, but because the review exposes something more operational: having a CDD or EDD process is not enough if a firm cannot demonstrate how that process was applied to an individual customer.
That distinction matters.
For firms dealing with higher-risk customers, complex ownership structures, politically exposed persons (PEPs) or high-net-worth individuals, due diligence increasingly needs to produce not simply a conclusion, but an evidence trail supporting that conclusion.
The Gap Between Having a Policy and Executing It
One of the most striking themes in the FCA's findings is the gap between documented policies and practical execution.
Most firms reviewed had procedures for verifying customer identity. However, the FCA found that relatively few provided sufficient detail or practical guidance to staff. Some policies did not explain what alternative evidence should be obtained when conventional identification was unavailable. Others lacked clarity around periodic and event-driven reviews.
The FCA specifically identified poor practices including:
- Insufficient detail about the additional measures required for EDD
- Undefined customer review cycles
- Inadequate guidance on alternative identity verification
- Failure to follow firms' own CDD policies
This highlights an important distinction.
A policy might say that a high-risk customer requires enhanced due diligence. The harder operational questions are: What exactly should be investigated? Which sources should be considered? What evidence should be retained? What risks were identified? What information should be escalated? And how does the resulting file demonstrate that enhanced due diligence was actually enhanced?
Those are execution questions, rather than policy questions.
EDD Needs to Be Demonstrably Different From Standard CDD
Perhaps the most consequential observation in the FCA review concerns the treatment of higher-risk customers.
The FCA found that most firms tailored CDD according to customer risk and subjected higher-risk customers to enhanced checks and more frequent reviews. Stronger firms documented each stage of the EDD process and established clear requirements for senior management approval and oversight.
But this was not universal.
The FCA found instances where firms could not evidence the EDD measures taken for high-risk customers. In some cases, there was limited evidence showing how the firm's treatment of low-risk and high-risk customers actually differed.
That is an important supervisory signal.
Calling a process 'EDD' does not make it enhanced. The customer file needs to show what additional work was performed because of the additional risk.
The FCA's broader Financial Crime Guide reinforces this principle. It describes EDD as requiring firms to obtain additional information and apply additional measures where appropriate to gain a deeper understanding of higher-risk customers and relationships.
This is particularly relevant when dealing with individuals whose wealth, businesses, investments and relationships cannot be understood through conventional KYC databases alone.
Source of Wealth Is About Understanding the Story Behind the Wealth
For certain higher-risk relationships, including relevant PEP relationships, one of the demanding aspects of EDD can be establishing and assessing source of wealth and source of funds.
Source of wealth concerns how a customer or beneficial owner accumulated their overall wealth. Source of funds concerns the origin of the particular funds involved in a business relationship or transaction. Understanding these can help firms assess whether a customer's activities are consistent with what is known about them.
Establishing source of wealth therefore involves more than locating an estimated net-worth figure.
Consider an entrepreneur whose apparent wealth derives from several decades of company ownership.
A robust assessment might require understanding when the businesses were established, the individual's ownership interests, funding rounds, acquisitions, company valuations, dividends, business disposals, property holdings and other identifiable liquidity events where relevant evidence is available.
The objective is not simply to answer:
'How wealthy is this person?'
It is to address the more relevant due diligence question:
'Is there a credible, evidence-supported explanation for how this person accumulated their wealth?'
Open-source information, customer-provided information and documentary evidence can all contribute to that assessment, depending on the circumstances and the firm's risk-based procedures.
Reputation and Adverse Information Cannot Be Reduced to a Database Check
Another important aspect of EDD is understanding the customer's broader risk context.
The FCA Financial Crime Guide identifies gaining a better understanding of a customer's or beneficial owner's reputation and role in public life as an example of enhanced due diligence. Searches concerning directors and other controlling individuals may also be relevant where their activities or integrity affect the risks associated with the relationship.
This matters because material risk information can sit outside traditional screening databases.
Relevant information might appear in regulatory actions, litigation, corporate disclosures, court judgments, credible media reporting, political records or information about related businesses and individuals.
A sanctions or PEP screening result can therefore be an important component of due diligence without necessarily being the complete picture.
For complex customers, the analytical challenge is often connecting fragmented information and determining what is actually relevant to the risk assessment.
Documentation May Be as Important as Discovery
The FCA's 2026 review repeatedly returns to documentation.
Some firms failed to record the purpose and intended nature of the business relationship. Others could not produce evidence showing what EDD measures had been undertaken. The FCA also found cases where requirements for senior management approval were insufficiently specified.
This should change how firms think about due diligence technology.
The goal should not simply be to find information faster.
A useful EDD process should help create a structured record showing:
What was researched → what was found → where it came from → what risk it may indicate → what requires further investigation or human judgment.
That chain is particularly valuable when a case is subsequently reviewed by compliance, an MLRO, senior management, internal audit or an external reviewer.
The broader direction is clear: institutional knowledge is not a substitute for documented evidence.
Ongoing Due Diligence Cannot Be Treated as a Calendar Exercise
The FCA also identified weaknesses around periodic and event-driven reviews.
Some firms lacked sufficient detail about how frequently periodic reviews should occur or what should happen when an event-driven review was triggered. Others were not conducting periodic reviews in accordance with their own requirements.
This raises a broader technology opportunity.
Traditional due diligence is often performed as a snapshot: research the customer, approve the relationship, archive the report and revisit it at a predetermined date.
But risk does not operate on a predetermined schedule.
A customer could become a PEP. A company could become subject to regulatory action. New litigation could emerge. Ownership could change. A major business disposal could materially alter a person's source-of-wealth profile. Credible adverse information could surface months after onboarding.
For higher-risk relationships in particular, the future of due diligence is likely to involve combining periodic review with event-driven intelligence.
Where Diligencify Fits
This is where technology platforms such as Diligencify can support the EDD workflow.
Diligencify is designed to research complex individuals and relationships across multiple information sources and organise relevant findings into structured, source-backed intelligence.
For an EDD investigation, this can include areas such as:
Source of Wealth
Researching businesses, ownership interests, investments, transactions, liquidity events and other publicly identifiable indicators that can help analysts understand how wealth may have been accumulated.
Business Interests and Relationships
Identifying companies, directorships, ownership connections and relevant relationships that may warrant further investigation.
PEP and Political Exposure
Identifying political exposure and related information relevant to the customer's risk profile.
Litigation, Regulatory and Adverse Information
Bringing together potentially relevant court, regulatory and credible adverse-media information for analyst assessment.
Reputation and Background
Providing broader contextual research around an individual, their business activities and public profile.
Source-Backed Documentation
Connecting material findings to underlying sources so that analysts can review the evidence rather than relying solely on an opaque risk score.
Ongoing Intelligence
Supporting continued awareness of material developments that may warrant reassessment of an existing relationship.
The distinction is important: Diligencify does not replace a firm's CDD framework, MLRO, compliance judgment or regulatory responsibilities.
Instead, it can help solve one of the practical problems exposed by the FCA review: obtaining, organising and documenting the deeper intelligence required to make enhanced due diligence genuinely enhanced.
AI Can Accelerate EDD, But It Cannot Remove Accountability
There is another lesson here for firms adopting AI.
Speed alone is not enough.
An AI system capable of generating a customer profile in minutes has limited compliance value if the analyst cannot determine where material claims came from, distinguish fact from inference, investigate contradictory information or understand why a risk was surfaced.
For regulated due diligence, traceability should be a design requirement, not an optional feature.
AI can dramatically reduce the manual effort involved in searching fragmented sources, connecting entities, organising findings and identifying areas requiring further investigation.
But final risk assessment, escalation and decision-making remain matters for appropriately qualified people operating within the firm's policies and controls.
The better model is therefore not AI replacing the compliance analyst.
It is AI compressing the research burden so the analyst can spend more time evaluating evidence and exercising judgment.
The Bigger Message From the FCA
The FCA's review ultimately points toward a more mature definition of effective due diligence.
It is not enough to screen a name.
It is not enough to label somebody high risk.
And it is not enough to say that EDD was completed.
A strong process should enable a firm to demonstrate what it knew about the customer, what additional investigation the customer's risk warranted, what evidence supported the assessment, how material concerns were handled, who approved the relationship and how the firm's understanding of that customer remains current.
The FCA found stronger firms documenting EDD stages, tailoring CDD to individual customer risk, operating defined approval processes and independently testing their controls. It found weaker practices where evidence was missing, review cycles were unclear, EDD was insufficiently differentiated and independent assurance was lacking.
The FCA has encouraged firms to consider these findings in the context of their own businesses and says it will continue monitoring firms through its supervisory work.
For compliance teams, the implication is straightforward:
The standard is moving beyond 'Did we perform due diligence?' toward 'Can we demonstrate that the depth, evidence and oversight of our due diligence matched the risk?'
That is also where technology has the greatest opportunity to make a difference.
Not by automating judgment, but by making the intelligence behind that judgment faster to obtain, easier to interrogate and easier to evidence.



