CDD, EDD, UBO, PEP — the compliance acronyms that show up in every onboarding flow, decoded in plain English.
The KYC/AML Glossary Every Fintech Founder Needs
A founder-friendly glossary of the core Know Your Customer and Anti-Money Laundering terms that shape how fintechs onboard and monitor users.
Every fintech that touches money movement inherits a stack of KYC/AML obligations, and the acronyms pile up fast. This glossary covers the terms that appear in almost every onboarding and compliance conversation.
Core identity terms
KYC (Know Your Customer) — The requirement that financial institutions verify the identity of individuals before letting them transact; formally known in some frameworks as the Customer Identification Program (CIP).
CDD (Customer Due Diligence) — The baseline process of verifying a customer's identity and beneficial owners, assessing their risk level, and monitoring their activity over time.
EDD (Enhanced Due Diligence) — A deeper layer of checks — source-of-wealth verification, in-person confirmation, senior management sign-off — triggered by elevated risk factors like PEP status or high-risk jurisdictions.
UBO (Ultimate Beneficial Owner) — The natural person who ultimately owns or controls a legal entity, commonly defined as anyone holding at least 25% of voting power, ownership, or economic benefit.
PEP (Politically Exposed Person) — An individual entrusted with a prominent public function (head of state, senior politician, senior government or judicial official) who carries elevated bribery/corruption risk and requires enhanced monitoring.
Program and monitoring terms
AML (Anti-Money Laundering) — The broader regulatory framework requiring financial institutions to detect, prevent, and report money laundering and terrorist financing.
Transaction monitoring — Ongoing automated screening of customer transactions for patterns that suggest fraud, laundering, or sanctions violations.
SAR (Suspicious Activity Report) — A filing financial institutions submit to regulators when transaction monitoring surfaces potentially suspicious behavior.
Sanctions screening — Checking customers and counterparties against government watchlists (e.g., OFAC) before and during the relationship.
Risk-based approach — The regulatory expectation that CDD/EDD intensity scales with the actual money-laundering risk a customer presents, rather than applying uniform checks to everyone.
How to use this glossary
Map each term to a control in your onboarding flow — identity verification (KYC), risk scoring (CDD/EDD), ownership checks (UBO), watchlist screening (PEP/sanctions), and ongoing monitoring — so nothing falls through the cracks during an audit.
Sources
Alloy: Glossary of AML Compliance Terms, Sanction Scanner: 50 AML & Compliance Terms.
Frequently asked questions
No — initial KYC happens at onboarding, but compliant programs also require ongoing monitoring and periodic re-verification, especially when a customer's risk profile or transaction pattern changes.
Common triggers include PEP status, operating in or transacting with a high-risk jurisdiction, complex or opaque ownership structures, and unusual transaction patterns flagged by monitoring systems.
It's the commonly used regulatory line for identifying who must be individually verified as an ultimate beneficial owner of a corporate customer, so compliance teams know exactly whose identity to check.
