Zenoo
Learn/What is due diligence? A clear guide to …
Glossary

What is due diligence? A clear guide to the types, process and rules

A plain-English definition of due diligence that covers both meanings people mix up: the commercial investigation before a deal and the legally mandated customer checks a regulated firm must run.

Last reviewed 12 February 202614 min read
In shortThe answer, first

Due diligence is a reasonable, evidence-based investigation carried out before a decision, to confirm facts, quantify risk and satisfy a legal or fiduciary standard of care. It covers two families: the commercial investigation before a deal, such as a merger or acquisition, and the customer due diligence that banks and regulated firms must run to meet anti-money-laundering law.

Key facts
  • Two meanings get mixed up: transactional due diligence before a deal, and regulatory customer due diligence (CDD) required under anti-money-laundering law.
  • The global standard for customer due diligence is FATF Recommendation 10: identify and verify the customer, identify the beneficial owner, understand the relationship, and monitor it over time.
  • CDD runs in three risk-calibrated tiers: simplified (SDD), standard, and enhanced (EDD) for higher-risk cases such as politically exposed persons.
  • It is not a one-off event. FATF and FinCEN both require ongoing monitoring, and the industry is moving toward continuous, perpetual review.
  • KYC is one part of CDD, which is itself one strand of due diligence: CDD adds beneficial ownership, purpose, risk-rating and monitoring on top of identity checks.

What due diligence is and how it works now

Due diligence is a reasonable, evidence-based investigation carried out before a decision, to confirm facts, quantify risk and satisfy a legal or fiduciary standard of care. The term has legal roots in the level of care a prudent person is expected to exercise, and it entered mainstream finance through US securities law: the Securities Act of 1933 gave those selling securities a defence if they had conducted a reasonable investigation of an issuer before selling. Today the phrase is used across two broad families that searchers routinely confuse.

Family A: transactional and commercial due diligence. This is the investigation a party runs before a deal, most visibly in mergers, acquisitions, investments and major procurement. It confirms that what a buyer or investor is told matches what is actually there. Its recognised sub-types are financial (statements, quality of earnings, liabilities, working capital), legal (contracts, corporate structure, litigation, intellectual property, compliance), commercial and operational (market, customers, competitive position, supply chain), specialist strands for tax, technology and environmental or governance exposure, and reputational checks on the people and companies involved.

Family B: customer and regulatory due diligence, the anti-money-laundering meaning. In regulated financial services, due diligence most often means customer due diligence (CDD): the legal obligation to know who your customer is, understand the relationship, and monitor it. This is not optional or generic. The global standard is FATF Recommendation 10, which requires regulated firms to identify and verify the customer, identify and verify the beneficial owner, understand the nature and purpose of the relationship, and conduct ongoing monitoring. In the US, FinCEN codified these as the fifth pillar of anti-money-laundering programmes in its 2016 CDD Rule.

CDD operates in three risk-calibrated tiers, all governed by Recommendation 10: simplified due diligence (SDD) for demonstrably low-risk cases, standard CDD for the majority of customers, and enhanced due diligence (EDD) for higher-risk cases. The table below maps the main types you will meet.

TypeWhat it is
Customer due diligence (CDD)The standard anti-money-laundering check: identify and verify the customer, identify the beneficial owner, understand the relationship, and monitor it over time. The default tier for most customers of a regulated firm.
Enhanced due diligence (EDD)A deeper investigation for higher-risk cases such as politically exposed persons, opaque ownership structures, cash-intensive businesses or high-risk jurisdictions. Adds source-of-funds and source-of-wealth checks, senior sign-off and tighter monitoring.
Simplified due diligence (SDD)Reduced measures for demonstrably low-risk customers or products, where full checks would be disproportionate. Still requires risk assessment and monitoring, just at a lighter level.
Know your business (KYB)Due diligence on a company rather than an individual: verifying the entity, its registration, and the ultimate beneficial owners behind it. The corporate counterpart to KYC within CDD.
Vendor and third-party due diligenceChecks on suppliers, partners and other third parties before and during a relationship, covering integrity, sanctions exposure, financial stability and operational risk across the supply chain.
Common misconception
The most common misconception
Due diligence and KYC are the same thing.
KYC, the identity check, is one component of customer due diligence, which is itself one strand of due diligence. CDD adds beneficial ownership, the purpose of the relationship, risk-rating and ongoing monitoring on top of identity verification. Treating them as identical leads teams to stop at an identity check when the law expects more.
The due diligence map
Select a type. CDD, SDD and EDD are tiers of one obligation, calibrated by risk. KYB and vendor DD are adjacent scopes.
RISK RISES
Enhanced (EDD)Source of funds, senior sign-off.
Standard (CDD)The default for most customers.
Simplified (SDD)Lighter checks, low risk.

The due diligence process, step by step

Across both families the mechanism has the same shape, which is why one framework can teach both. Whether you are reviewing a company to acquire or a customer to onboard, the steps run in the same order.

  • Scope and risk-rate. Decide what you are investigating and how much risk it carries. In anti-money-laundering work this is the customer risk assessment that sets simplified, standard or enhanced due diligence; in a deal it sets the depth of the data room review.
  • Collect. Gather documents and data: for a deal, financials, contracts, cap tables and filings; for a customer, identity documents, corporate registry data, ownership structure and expected activity.
  • Verify. Confirm identities, ownership and claims against independent, reliable sources rather than taking them at face value. In anti-money-laundering work this means identity verification, resolving the ultimate beneficial owner, and authenticating documents.
  • Screen and assess. Check against sanctions lists, politically exposed person lists and adverse media, then evaluate the red flags that surface. This is where risk becomes concrete.
  • Decide and record. Reach a documented conclusion: proceed, price differently, walk away, or in anti-money-laundering work, onboard, apply enhanced due diligence, or file a suspicious activity report.
  • Monitor. Due diligence does not end at onboarding. Regulators expect ongoing monitoring so the risk picture stays current as circumstances change.
Note

A quick way to keep the tiers straight: simplified is lighter checks for genuinely low risk, standard is the default, and enhanced is deeper verification with source-of-funds analysis and senior sign-off. Enhanced due diligence is about depth, not a longer form. Collecting more documents without deeper analysis is not EDD.

Where we are now (2025 to 2026)

Regulation is tightening and, in places, converging. Four shifts matter most for teams running due diligence right now.

FATF, February 2025. FATF amended Recommendation 1 and its Interpretive Note, with consequential changes to the Interpretive Notes for Recommendations 10 and 15, to better support financial inclusion and proportionality. The practical effect is that the guidance on simplified measures strengthened from merely permitting them toward directing firms to apply proportionate simplified due diligence where the risk evidence supports it. This is a meaningful change for teams managing low-risk segments.

EU single rulebook. The EU adopted the Anti-Money Laundering Regulation (EU) 2024/1624, which applies directly from 10 July 2027 and harmonises CDD, ongoing monitoring, politically exposed person checks and beneficial-ownership rules across member states without national transposition. The new Anti-Money Laundering Authority (AMLA), headquartered in Frankfurt, became operational on 1 July 2025. The EBA's revised guidelines on money-laundering risk factors (January 2024) also extended CDD guidance to crypto-asset service providers.

UK reform. HM Treasury published its response to the Money Laundering Regulations consultation in July 2025 and a draft statutory instrument in September 2025, aiming to make the enhanced due diligence trigger more proportionate. The changes are expected to take effect from the first half of 2026 at the earliest. Specific wording should be read from the statutory instrument itself once finalised.

US divergence on beneficial ownership. In a significant reversal, FinCEN's interim final rule of 26 March 2025 redefined which companies must report beneficial ownership under the Corporate Transparency Act to cover only foreign entities registered to do business in the US, exempting US-formed companies and US persons and removing the large majority of previously in-scope filers. This does not remove a firm's own CDD and beneficial-ownership obligations, but it shrinks the central registry data source they can lean on.

Why it matters. The scale of the problem due diligence exists to address remains stark. UNODC estimates that USD 800bn to USD 2tn is laundered globally each year, roughly 2% to 5% of GDP, while less than 1% of proceeds are seized or frozen. FATF's own mutual-evaluation data shows only about 9% of jurisdictions score high or substantial on investigating and prosecuting money laundering, and 19% on confiscation. In the US, FinCEN recorded 4.7 million suspicious activity reports and 20.5 million currency transaction reports in FY2024. An EY 2024 survey found almost 65% of institutions cite data quality as their top execution challenge. The RegTech market that supplies due-diligence, KYC and anti-money-laundering tooling was valued in the range of roughly USD 19bn to USD 25bn in 2025 depending on the analyst, driven explicitly by rising compliance complexity and the shift to digital onboarding.

The latest trends

Six directions are reshaping how due diligence is done in practice.

  • From periodic to perpetual. The clearest shift is away from calendar-based, point-in-time reviews toward continuous monitoring that re-runs screening and risk-rating whenever a material change occurs, such as a beneficial-ownership change or a spike in cross-border activity. ACAMS frames perpetual KYC as the end goal of ongoing monitoring.
  • Proportionality and financial inclusion. FATF's 2025 pivot toward simplified measures for genuinely low-risk customers is reorienting programmes away from blanket over-checking and de-risking, and toward defensible, evidence-led calibration.
  • Orchestration over single-vendor stacks. Firms are moving from one hard-wired verification vendor toward orchestrated stacks that route each check to the best source and fail over when one is down. The average financial institution already uses about 4.7 verification providers and stitches together 6 to 8 disconnected tools.
  • Continuous adverse media and beneficial-ownership monitoring. Best practice is now continuous screening of customers and their owners against sanctions, politically exposed person and adverse-media sources, rather than a one-time check at onboarding.
  • AI moving from pilot to production. Buyers are pushing AI beyond experiments into measurable results in KYC review, risk rating, ownership network modelling and alert triage.
  • Crypto and new sectors in scope. The EBA extended its risk-factor guidance to crypto-asset service providers, and the EU rulebook widens the population of firms that must run due diligence.

How AI helps

AI is now the workhorse of modern due diligence, used defensively across the whole process. Machine-vision models authenticate identity documents and, with liveness detection, confirm a real person is present. AI can traverse corporate registries to map ownership networks and surface owners that manual review misses. Models turn customer, country, product and channel signals into dynamic risk scores that can be tuned to cut false positives. Natural-language models cluster and summarise adverse-media hits and pre-classify alerts so investigators see only what needs a human. Continuous monitoring, watching for material change and re-triggering due diligence automatically, is what makes perpetual review feasible at all.

The honest framing matters: AI accelerates and de-noises human due diligence, it does not replace the human decision. The analyst still decides; the machine removes the grunt work.

This is where orchestration earns its place. Zenoo runs 10 specialised AI agents across the due-diligence workflow: the KYB Researcher compiles a 50-plus-field company dossier in under 60 seconds against a manual 2 to 4 hours; the KYC Researcher completes individual due-diligence research in under 45 seconds against 1 to 3 hours; the Risk Assessor produces a FATF four-dimension assessment (customer, country, product or service, delivery channel) in under 30 seconds; and alert pre-classification can handle up to 80% of screening alerts, cutting per-alert disposition from 20 to 45 minutes down to 2 to 3 minutes.

AI on the defender’s side
The headline number

Across a full investigation, Zenoo cites a reduction from an industry-benchmark 22 hours to 12 minutes, with up to a 95% reduction in false positives within 90 days. The agents do the reading; the analyst keeps the decision.

How AI is abused

The same technology is being turned against due-diligence controls, and the escalation is documented. Deepfakes are appearing at onboarding and in the deal room. Sumsub's 2025 data, drawn from its own platform, shows deepfakes accounting for about 11% of first-party fraud cases, with a reported 2,100% year-on-year surge in the Maldives, the highest for any single country. Entrust recorded a deepfake attempt every five minutes in 2024, alongside a 244% year-on-year rise in digital document forgeries.

The archetype is the Arup case: in January 2024, a finance employee in Hong Kong was tricked by a deepfaked video call impersonating the CFO and colleagues into making 15 transfers totalling about USD 25.6m. No system was breached. It was pure synthetic-media social engineering built from publicly available footage, defeating exactly the relationship-level trust due diligence is meant to establish.

Generative AI is also industrialising synthetic identities that blend real and fabricated data to pass CDD. Sumsub reports synthetic identity document fraud up over 300% in the US, and the Federal Reserve Bank of Boston warns that generative AI is expanding the threat. Underground marketplaces now sell face-swap and liveness-bypass kits with tutorials and support, and prompt injection ranks number one on the OWASP Top 10 for LLM Applications 2025, so the AI systems used inside due diligence are themselves a target.

AI as the threat

The lesson is simple: no single detector holds, because attackers probe each one until it breaks. The honest defence is several independent checks, so one vendor's blind spot is covered by another. That is the case for orchestration rather than a single hard-wired vendor.

What the future looks like

Several directions look settled enough to plan around.

Perpetual by default. Expect regulators and buyers to treat continuous, event-driven due diligence as the baseline rather than a premium, with annual refresh cycles fading. The EU single rulebook lands. From 10 July 2027 the Anti-Money Laundering Regulation applies directly across the EU, with AMLA supervising the largest firms and driving convergence, so multi-jurisdiction firms will face a more uniform but more demanding CDD baseline. Proportionality becomes an expectation, not a favour. FATF's 2025 direction will push firms to justify calibration in both directions, making risk-based due diligence auditable up and down.

The AI arms race intensifies. As deepfake and synthetic-identity volumes climb, defensive AI, multi-signal verification and liveness detection will keep escalating against generative attack tooling. Regulatory data sources fragment. The US Corporate Transparency Act reversal shows central registries are not guaranteed, so firms will lean more on their own cross-source ownership discovery than on any single registry. AI governance enters the frame. Expect growing scrutiny of the AI used inside due diligence, covering explainability, bias, and the prompt-injection and adversarial risks flagged by OWASP.

Key takeaways
  • Two meanings get mixed up: transactional due diligence before a deal, and regulatory customer due diligence (CDD) required under anti-money-laundering law.
  • The global standard for customer due diligence is FATF Recommendation 10: identify and verify the customer, identify the beneficial owner, understand the relationship, and monitor it over time.
  • CDD runs in three risk-calibrated tiers: simplified (SDD), standard, and enhanced (EDD) for higher-risk cases such as politically exposed persons.
  • It is not a one-off event. FATF and FinCEN both require ongoing monitoring, and the industry is moving toward continuous, perpetual review.
  • KYC is one part of CDD, which is itself one strand of due diligence: CDD adds beneficial ownership, purpose, risk-rating and monitoring on top of identity checks.

Frequently asked questions

What is due diligence in simple terms?

Due diligence is doing your homework before you commit. It is a structured investigation to confirm facts and understand risk before a decision, whether that is buying a company, making an investment, or onboarding a customer at a regulated firm. The goal is to base the decision on evidence rather than assumption.

What are the main types of due diligence?

There are two broad families. Transactional due diligence covers financial, legal, commercial, operational, tax, technology, environmental and reputational checks before a deal. Regulatory due diligence covers customer due diligence (CDD) and its tiers, simplified (SDD), standard, and enhanced (EDD), plus company checks (KYB) and third-party or vendor checks.

What is the difference between due diligence and KYC?

KYC, know your customer, is the identity check: confirming who someone is. It is one component of customer due diligence, which is itself one strand of due diligence. CDD adds beneficial ownership, the purpose of the relationship, risk-rating and ongoing monitoring on top of the identity check.

What is enhanced due diligence, and when is it required?

Enhanced due diligence (EDD) is a deeper investigation for higher-risk cases, such as politically exposed persons, opaque or complex ownership structures, cash-intensive businesses, non-face-to-face onboarding, and customers connected to high-risk jurisdictions. It adds source-of-funds and source-of-wealth checks, senior-management sign-off, and closer ongoing monitoring. It is about deeper verification, not simply collecting more documents.

What is simplified due diligence?

Simplified due diligence (SDD) applies reduced measures to demonstrably low-risk customers or products, where full checks would be disproportionate. It still requires a risk assessment and monitoring, just at a lighter level. FATF's February 2025 update pushed firms toward applying proportionate simplified measures where the evidence supports genuinely low risk.

Is due diligence a legal requirement?

Customer due diligence is. Regulated firms must run it under FATF Recommendation 10 and its national implementations, such as FinCEN's 2016 CDD Rule in the US and the EU's Anti-Money Laundering Regulation. Getting it wrong is a fineable, licence-threatening compliance failure. Commercial due diligence before a deal is usually a matter of prudence and fiduciary care rather than a strict legal mandate.

How is AI changing due diligence?

AI sits on both sides. Defensively it authenticates documents, maps beneficial-ownership networks, scores risk, triages alerts and enables continuous monitoring, accelerating the human work rather than replacing the decision. Offensively, attackers use it to generate deepfakes and synthetic identities designed to pass checks, which is why running several independent detectors, rather than one, has become the honest defence.
ZenooWhere this fits, honestly

Due diligence spans many checks and many sources, which is exactly why it fragments across vendors. Zenoo is an orchestration layer: your vendors plus Zenoo, not instead of them. It routes each check to the right provider, fails over when one is down, and writes everything to one immutable audit trail so ongoing monitoring stays continuous rather than annual. The analyst keeps the decision; the 10 AI agents remove the grunt work.

Sources

Last reviewed 12 February 2026. Every statistic is traceable to a named source.
  1. 01FATF, updated Standards to promote financial inclusion (February 2025)
  2. 02Financial Services Perspectives, FinCEN's 2016 CDD Rule and the fifth pillar
  3. 03ComplyAdvantage, What is enhanced due diligence (EDD)?
  4. 04ShuftiPro, Simplified due diligence (SDD) and FATF rules
  5. 05Signicat, EU AMLR 2027 requirements explained
  6. 06EBA, revised Guidelines on ML/TF risk factors (January 2024)
  7. 07A&O Shearman, improving the effectiveness of the UK Money Laundering Regulations
  8. 08Miller Canfield, FinCEN interim final rule on the Corporate Transparency Act (March 2025)
  9. 09Moody's, AML in 2025: AI, real-time monitoring and global regulation
  10. 10Fraxtional, understanding ongoing monitoring in AML compliance (ACAMS perpetual KYC)
  11. 11Precedence Research, RegTech market size and forecast
  12. 12Sumsub, synthetic identity document fraud surges 300% in the US
  13. 13Entrust, deepfake attempt every five minutes amid 244% surge in digital document forgeries
  14. 14CNN Business, Arup revealed as victim of $25 million deepfake scam
  15. 15Federal Reserve Bank of Boston, generative AI and synthetic identity fraud (April 2025)
  16. 16OWASP Top 10 for LLM Applications 2025
  17. 17LexisNexis Risk Management, Due Diligence glossary
Was this helpful?
Share