
For compliance teams monitoring Chinese policy developments, decrees 834 and 835 offer a warning about what happens when an information environment narrows but expectations for risk understanding stay the same. Most commentary has focused on trade, sanctions, supply chains and geopolitics, which makes sense. Decree 834 emphasizes industrial and supply chain security, while Decree 835 expands China’s framework for responding to foreign measures it considers unjustified or extraterritorial. But for anti-money laundering (AML) and enhanced due diligence (EDD) teams, the more important lesson is that due diligence can become fragile long before a regulation changes.
Neither decree creates new AML obligations. Financial institutions are still expected to understand customer risk, identify beneficial ownership, assess sanctions exposure, evaluate source of wealth and source of funds, and conduct EDD where appropriate. That distinction matters because the due diligence issue is operational, not regulatory. The core issue is that Decrees 834 and 835 expose how vulnerable many due diligence programs become, and how quickly familiar investigative methods weaken, when the information environment becomes less open, less complete or harder to validate.
The practical lesson is straightforward: AML and EDD teams should treat Decrees 834 and 835 as a warning about due diligence models that rely too heavily on traditional sources. As official or commercial information becomes less complete, investigators must adapt by harnessing digital, relational, and behavioral context to understand risk.
In this way, the decrees surface a vulnerability that has existed within the financial crime industry for years. Due diligence programs have been built around information that is easy to source, validate and operationalize, such as corporate registries, commercial databases, adverse media providers, sanctions lists and public records. Those sources remain valuable and necessary. But risk does not reveal itself according to what is easiest to collect. Risk reveals itself where people behave.
Looking for Risk in the Wrong Places
One of the unintended consequences of modern compliance programs is that many institutions have become exceptionally good at collecting the same information as everyone else. Over the last twenty years, the industry has invested heavily in structured data sources because they support consistency, scalability and defensibility. Those investments have undoubtedly improved compliance programs, but they have also shaped how institutions think about risk. In many organizations, the sources that are easiest to collect and document have gradually become the sources that receive the greatest weight in the investigative process.
This point aligns with the direction of travel in AML supervision more broadly. Regulators increasingly emphasize efficacy in risk-based AML programs, which means institutions will not only judged on whether they performed expected checks, but whether those checks produced a reasonable understanding of customer and counterparty risk.
Consider a typical EDD investigation. An analyst reviews corporate records, beneficial ownership information, sanctions and watchlist results, adverse media, litigation records, and perhaps a commercial intelligence report. The review is documented, auditable and repeatable. From a compliance perspective, the institution may be able to show that it performed the expected checks. The harder question is whether those checks gave the investigator enough context to understand the risk, which is consistent with the broader direction of FinCEN’s recent rulemaking focus on risk-based, effective AML programs.
Most experienced investigators have worked cases where the information that ultimately changed the risk assessment wasn’t found in a registry, database or adverse media report. It was found in an undisclosed affiliation, a previously unknown relationship, a social media profile, an online business presence or a digital footprint that contradicted the narrative presented during onboarding. Corporate registries are excellent at documenting ownership structures, but they don’t always reveal influence. Adverse media is useful for identifying people who have already attracted public attention, but it is far less effective at identifying individuals who have successfully stayed out of the headlines. Sanctions and watchlist databases identify known risks, but they rarely explain the broader network surrounding an individual or organization.
This isn’t a criticism of traditional due diligence sources. The issue is not whether they are useful. The issue is whether the industry has become overly dependent on them. In many cases, investigators spend most of their time reviewing information that is easy to collect and document, while devoting comparatively little attention to the places where relationships, influence, behavior and undisclosed affiliations are more likely to surface.
The Problem Isn’t Data. It’s Information Sourcing.
This is where the industry has gotten due diligence information sourcing wrong.
The financial crime industry often frames challenges in terms of data: more data, better data, broader coverage, additional enrichment. While those conversations are important, they sometimes distract from the more fundamental issue. Most institutions already have access to enormous amounts of information. The harder question is whether investigators are sourcing information from the places where risk is actually observable.
That same issue appears in a basic beneficial ownership review. On paper, the ownership structure may appear straightforward: beneficial owners are identified, sanctions checks are clean, adverse media returns little of concern, and the customer appears low risk. But if an investigator later finds public online content linking a beneficial owner to a politically exposed individual, a sanctioned jurisdiction, an undisclosed business interest or a recurring network of high-risk associates, the risk picture changes. The registry did not change. The investigator’s visibility did.
An EDD analyst may be able to confirm that a customer’s ownership records are complete and that no formal sanctions hit exists but still miss risk if the beneficial owner maintains an active online relationship with a sanctioned intermediary, promotes business activity in a restricted jurisdiction or appears repeatedly in the digital network of a politically exposed associate. Those indicators may not change the registry record, but they can change the risk conclusion.
The same dynamic plays out across sanctions investigations, corruption/bribery investigations, fraud investigations and source-of-wealth reviews. Some of the most valuable context in these cases is often found outside the sources that have historically dominated due diligence programs. The challenge is that many AML and EDD analysts are not routinely collecting from these network-risk sources today. When they do, it is often ad hoc, dependent on individual investigator skill and difficult to standardize across teams. As a result, affiliations, relationships, behavioral indicators and digital footprints that could materially change the risk assessment may never appear in the file at all.
What Decrees 834 and 835 Actually Expose
Most commentary has focused on what these measures do. I think the more important question is what they reveal.
For years, the financial crime industry has operated under a largely unspoken assumption that investigators can access whatever information they need if they are willing to spend enough time and resources looking for it. Whether that information comes from a registry, a commercial database, a public filing, or an adverse media provider has almost been secondary to the assumption that it will ultimately be available somewhere.
The broader trend reflected by Decrees 834 and 835 points to a more controlled and politically sensitive information environment. Decree 834 raises the stakes around supply chain and industrial security, which may make entities more cautious about what they disclose, how they document commercial relationships and how they share operational details across borders. Decree 835 reinforces China’s ability to respond to foreign measures it views as unjustified, creating additional uncertainty for organizations trying to collect information connected to sanctions, ownership, counterparties or supply chain exposure. For AML and EDD teams, the practical issue, in addition to legal complexity, is the possibility that some of the information needed to understand risk may become harder to obtain, less complete or more sensitive to verify.
For readers less familiar with the decrees, the important distinction is between the legal question and the operational one. Decrees 834 and 835 do not replace AML obligations or redefine EDD standards. They sit within a broader policy environment in which access to commercial, corporate, supply chain and sanctions-related information can become more sensitive, fragmented or difficult to verify across borders.
That is where the due diligence gap appears. The customer still needs to be reviewed. The risk assessment still needs to be completed. The institution still needs to be able to defend its decision. But if the program relies heavily on a relatively small number of traditional sources, and those sources become constrained, investigators may be left with a well-documented file that still lacks meaningful visibility into the relationships, affiliations and behaviors that matter most. In other words, the weakness is not simply that information may be harder to access. The weakness is that many due diligence models were never designed to compensate when familiar sources stop being enough.
Decrees 834 and 835 should serve as a bellwether, not because they represent a uniquely Chinese challenge, but because they show what happens when information sourcing becomes more complex while regulatory expectations remain unchanged. They force a practical question many institutions have not fully answered: if the usual sources become incomplete, restricted or harder to validate, where else will investigators look, how will they assess reliability and how will they document a defensible path from discovery to decision?
Why This Matters for EDD Teams
If one group should pay attention to Decrees 834 and 835, it is EDD teams. For them, the relevance is not the decrees’ direct legal effect on AML programs. It is the future they illustrate: one in which information access becomes less predictable, customers and counterparties become harder to verify through familiar channels and expectations for risk understanding remain high.
EDD exists because traditional sources and traditional controls are often insufficient to fully understand risk. Investigators are asked to go beyond what is obvious, beyond what is structured and screenable, and beyond what is already known. Their job is not simply to verify information. Their job is to discover information that materially changes the institution’s understanding of a customer, counterparty or beneficial owner.
The challenge is that many EDD programs are still built around sourcing models that prioritize traditional records over broader risk discovery. That approach worked reasonably well when information was abundant, accessible and relatively unconstrained. It may be less effective in an environment where information collection itself is becoming more complicated and where critical risk indicators increasingly exist within digital environments rather than traditional records.
This is precisely why social media, online content, digital footprints and broader open-source intelligence should become more important to EDD programs. These sources are not simply supplements to traditional due diligence when they are used well. In many cases, they provide the context necessary to understand relationships, affiliations, source of wealth indicators, business activities and risk signals that would otherwise remain hidden. The problem is that most programs have not yet made this kind of network-risk collection a routine, governed, repeatable part of the investigative workflow. This is particularly important in regions where businesses and individuals increasingly operate through digital platforms rather than traditional public-facing channels.
A More Resilient Due Diligence Model
The path forward is not to abandon traditional due diligence sources, but to build a more resilient sourcing model around them. Institutions should identify where current EDD workflows depend too heavily on a narrow set of registries, databases, and media sources, especially for higher-risk jurisdictions, complex ownership structures, and counterparties with supply chain or sanctions exposure. They should then define when broader open-source and online information is required, establish standards for reliability and corroboration, train investigators to document non-traditional findings and explain how those findings influenced the final risk conclusion. That approach gives investigators more ways to discover risk while giving compliance leaders a defensible process for explaining how those discoveries were sourced, tested and used.
That is where innovative data resources, including Fivecast Lunex, offer a practical path forward. If the gap is that AML and EDD teams are not routinely collecting from the places where network risk reveals itself, the answer cannot simply be to ask analysts to search more broadly on their own. Investigators need a way to bring online risk signals, digital footprints, affiliations and network-risk indicators into the workflow in a more consistent and defensible way. Lunex is designed to support that shift by helping institutions make network-risk discovery a structured part of EDD rather than an ad hoc extension of traditional research.
The Real Lesson
Most AML professionals are probably not thinking about PRC Decrees 834 and 835 today. I think they should be.
Not because the decrees represent a uniquely Chinese challenge, and not because they fundamentally alter AML obligations: they should pay attention because these decrees expose a weakness that already exists within many due diligence programs.
The financial crime industry has spent years treating registries, databases, and adverse media as primary sources while treating online and social intelligence as supplementary. At the same time, risk has increasingly migrated into digital environments where people communicate, influence, affiliate, transact and reveal behavior. Those two realities are beginning to collide.
The institutions that recognize this first will have an advantage, not because they have access to more data, but because they build investigative models that remain effective when familiar sources become incomplete. Ultimately, the most important lesson from Decrees 834 and 835 is not about China at all. It is that effective due diligence depends on knowing where risk actually reveals itself, validating what is found there and documenting a defensible path from discovery to decision.
About Fivecast
Fivecast delivers intelligence solutions built for clarity, powered by AI, and trusted to surface what matters. Engineered to solve complex intelligence challenges our platform cuts through digital noise to help those protecting nations, borders, businesses, and communities uncover critical insights – before risk becomes reality.
Trusted by agencies and enterprises across national security, law enforcement, defense, corporate security, and financial crime, Fivecast was born from collaboration between governments and research institutions. Headquartered in Australia with a global footprint, we support the world’s most critical missions.
Fivecast. Engineered for Intelligence.
