A plain-English definition of due diligence that covers both meanings people mix up: the commercial investigation before a deal and the legally mandated customer checks a regulated firm must run.
Due diligence is a reasonable, evidence-based investigation carried out before a decision, to confirm facts, quantify risk and satisfy a legal or fiduciary standard of care. It covers two families: the commercial investigation before a deal, such as a merger or acquisition, and the customer due diligence that banks and regulated firms must run to meet anti-money-laundering law.
Due diligence is a reasonable, evidence-based investigation carried out before a decision, to confirm facts, quantify risk and satisfy a legal or fiduciary standard of care. The term has legal roots in the level of care a prudent person is expected to exercise, and it entered mainstream finance through US securities law: the Securities Act of 1933 gave those selling securities a defence if they had conducted a reasonable investigation of an issuer before selling. Today the phrase is used across two broad families that searchers routinely confuse.
Family A: transactional and commercial due diligence. This is the investigation a party runs before a deal, most visibly in mergers, acquisitions, investments and major procurement. It confirms that what a buyer or investor is told matches what is actually there. Its recognised sub-types are financial (statements, quality of earnings, liabilities, working capital), legal (contracts, corporate structure, litigation, intellectual property, compliance), commercial and operational (market, customers, competitive position, supply chain), specialist strands for tax, technology and environmental or governance exposure, and reputational checks on the people and companies involved.
Family B: customer and regulatory due diligence, the anti-money-laundering meaning. In regulated financial services, due diligence most often means customer due diligence (CDD): the legal obligation to know who your customer is, understand the relationship, and monitor it. This is not optional or generic. The global standard is FATF Recommendation 10, which requires regulated firms to identify and verify the customer, identify and verify the beneficial owner, understand the nature and purpose of the relationship, and conduct ongoing monitoring. In the US, FinCEN codified these as the fifth pillar of anti-money-laundering programmes in its 2016 CDD Rule.
CDD operates in three risk-calibrated tiers, all governed by Recommendation 10: simplified due diligence (SDD) for demonstrably low-risk cases, standard CDD for the majority of customers, and enhanced due diligence (EDD) for higher-risk cases. The table below maps the main types you will meet.
Across both families the mechanism has the same shape, which is why one framework can teach both. Whether you are reviewing a company to acquire or a customer to onboard, the steps run in the same order.
A quick way to keep the tiers straight: simplified is lighter checks for genuinely low risk, standard is the default, and enhanced is deeper verification with source-of-funds analysis and senior sign-off. Enhanced due diligence is about depth, not a longer form. Collecting more documents without deeper analysis is not EDD.
Regulation is tightening and, in places, converging. Four shifts matter most for teams running due diligence right now.
FATF, February 2025. FATF amended Recommendation 1 and its Interpretive Note, with consequential changes to the Interpretive Notes for Recommendations 10 and 15, to better support financial inclusion and proportionality. The practical effect is that the guidance on simplified measures strengthened from merely permitting them toward directing firms to apply proportionate simplified due diligence where the risk evidence supports it. This is a meaningful change for teams managing low-risk segments.
EU single rulebook. The EU adopted the Anti-Money Laundering Regulation (EU) 2024/1624, which applies directly from 10 July 2027 and harmonises CDD, ongoing monitoring, politically exposed person checks and beneficial-ownership rules across member states without national transposition. The new Anti-Money Laundering Authority (AMLA), headquartered in Frankfurt, became operational on 1 July 2025. The EBA's revised guidelines on money-laundering risk factors (January 2024) also extended CDD guidance to crypto-asset service providers.
UK reform. HM Treasury published its response to the Money Laundering Regulations consultation in July 2025 and a draft statutory instrument in September 2025, aiming to make the enhanced due diligence trigger more proportionate. The changes are expected to take effect from the first half of 2026 at the earliest. Specific wording should be read from the statutory instrument itself once finalised.
US divergence on beneficial ownership. In a significant reversal, FinCEN's interim final rule of 26 March 2025 redefined which companies must report beneficial ownership under the Corporate Transparency Act to cover only foreign entities registered to do business in the US, exempting US-formed companies and US persons and removing the large majority of previously in-scope filers. This does not remove a firm's own CDD and beneficial-ownership obligations, but it shrinks the central registry data source they can lean on.
Why it matters. The scale of the problem due diligence exists to address remains stark. UNODC estimates that USD 800bn to USD 2tn is laundered globally each year, roughly 2% to 5% of GDP, while less than 1% of proceeds are seized or frozen. FATF's own mutual-evaluation data shows only about 9% of jurisdictions score high or substantial on investigating and prosecuting money laundering, and 19% on confiscation. In the US, FinCEN recorded 4.7 million suspicious activity reports and 20.5 million currency transaction reports in FY2024. An EY 2024 survey found almost 65% of institutions cite data quality as their top execution challenge. The RegTech market that supplies due-diligence, KYC and anti-money-laundering tooling was valued in the range of roughly USD 19bn to USD 25bn in 2025 depending on the analyst, driven explicitly by rising compliance complexity and the shift to digital onboarding.
Six directions are reshaping how due diligence is done in practice.
AI is now the workhorse of modern due diligence, used defensively across the whole process. Machine-vision models authenticate identity documents and, with liveness detection, confirm a real person is present. AI can traverse corporate registries to map ownership networks and surface owners that manual review misses. Models turn customer, country, product and channel signals into dynamic risk scores that can be tuned to cut false positives. Natural-language models cluster and summarise adverse-media hits and pre-classify alerts so investigators see only what needs a human. Continuous monitoring, watching for material change and re-triggering due diligence automatically, is what makes perpetual review feasible at all.
The honest framing matters: AI accelerates and de-noises human due diligence, it does not replace the human decision. The analyst still decides; the machine removes the grunt work.
This is where orchestration earns its place. Zenoo runs 10 specialised AI agents across the due-diligence workflow: the KYB Researcher compiles a 50-plus-field company dossier in under 60 seconds against a manual 2 to 4 hours; the KYC Researcher completes individual due-diligence research in under 45 seconds against 1 to 3 hours; the Risk Assessor produces a FATF four-dimension assessment (customer, country, product or service, delivery channel) in under 30 seconds; and alert pre-classification can handle up to 80% of screening alerts, cutting per-alert disposition from 20 to 45 minutes down to 2 to 3 minutes.
Across a full investigation, Zenoo cites a reduction from an industry-benchmark 22 hours to 12 minutes, with up to a 95% reduction in false positives within 90 days. The agents do the reading; the analyst keeps the decision.
The same technology is being turned against due-diligence controls, and the escalation is documented. Deepfakes are appearing at onboarding and in the deal room. Sumsub's 2025 data, drawn from its own platform, shows deepfakes accounting for about 11% of first-party fraud cases, with a reported 2,100% year-on-year surge in the Maldives, the highest for any single country. Entrust recorded a deepfake attempt every five minutes in 2024, alongside a 244% year-on-year rise in digital document forgeries.
The archetype is the Arup case: in January 2024, a finance employee in Hong Kong was tricked by a deepfaked video call impersonating the CFO and colleagues into making 15 transfers totalling about USD 25.6m. No system was breached. It was pure synthetic-media social engineering built from publicly available footage, defeating exactly the relationship-level trust due diligence is meant to establish.
Generative AI is also industrialising synthetic identities that blend real and fabricated data to pass CDD. Sumsub reports synthetic identity document fraud up over 300% in the US, and the Federal Reserve Bank of Boston warns that generative AI is expanding the threat. Underground marketplaces now sell face-swap and liveness-bypass kits with tutorials and support, and prompt injection ranks number one on the OWASP Top 10 for LLM Applications 2025, so the AI systems used inside due diligence are themselves a target.
The lesson is simple: no single detector holds, because attackers probe each one until it breaks. The honest defence is several independent checks, so one vendor's blind spot is covered by another. That is the case for orchestration rather than a single hard-wired vendor.
Several directions look settled enough to plan around.
Perpetual by default. Expect regulators and buyers to treat continuous, event-driven due diligence as the baseline rather than a premium, with annual refresh cycles fading. The EU single rulebook lands. From 10 July 2027 the Anti-Money Laundering Regulation applies directly across the EU, with AMLA supervising the largest firms and driving convergence, so multi-jurisdiction firms will face a more uniform but more demanding CDD baseline. Proportionality becomes an expectation, not a favour. FATF's 2025 direction will push firms to justify calibration in both directions, making risk-based due diligence auditable up and down.
The AI arms race intensifies. As deepfake and synthetic-identity volumes climb, defensive AI, multi-signal verification and liveness detection will keep escalating against generative attack tooling. Regulatory data sources fragment. The US Corporate Transparency Act reversal shows central registries are not guaranteed, so firms will lean more on their own cross-source ownership discovery than on any single registry. AI governance enters the frame. Expect growing scrutiny of the AI used inside due diligence, covering explainability, bias, and the prompt-injection and adversarial risks flagged by OWASP.
Due diligence spans many checks and many sources, which is exactly why it fragments across vendors. Zenoo is an orchestration layer: your vendors plus Zenoo, not instead of them. It routes each check to the right provider, fails over when one is down, and writes everything to one immutable audit trail so ongoing monitoring stays continuous rather than annual. The analyst keeps the decision; the 10 AI agents remove the grunt work.