In this article
On Monday morning, an onboarding analyst at a payments company opens a new application. The customer is ordinary at first glance. The name is common. The business is registered locally. Nothing obvious stands out. Then the screening tool returns a possible hit. The label is simple: PEP.
That moment is what most people mean by PEP screening. You screen a person against PEP data and you get a result. The real work starts immediately after. The analyst has to decide whether this is a true match, what kind of PEP it is, whether the customer is connected to a PEP as a relative or close associate, and what enhanced due diligence should follow. Those decisions must be risk-based and documented. FATF is the global baseline for this, and it defines key terms in its glossary and provides specific guidance on politically exposed persons under Recommendations 12 and 22. Sources: FATF Glossary (fatf-gafi.org); FATF PEP guidance (Rec 12/22) (fatf-gafi.org PDF).
The analyst’s first question is not “Is this customer bad?” FATF is clear that PEP status is a risk factor and not proof of wrongdoing. The question is “Do we have elevated corruption exposure, and can we show how we handled it?” If your process treats every PEP like a prohibited relationship, you can drift away from FATF’s risk-based intent. Source: FATF PEP guidance (fatf-gafi.org PDF).
What counts as a PEP in the real world
The analyst clicks into the match profile. The person is not a head of state. It is a senior official in a regional agency. There is also a note suggesting a family relationship to someone in government. This is where definitions stop being academic.
FATF defines politically exposed persons in its glossary and explains how firms should think about family members and close associates in the PEP context. That RCA concept becomes an operational problem immediately because a “relative” can mean different things in different frameworks, and the evidence for the relationship may be weak or incomplete. A deep-research way to handle this is to require your case record to capture three facts every time: which RCA category you are applying, what evidence supports the relationship, and which policy rule it triggers. Source: FATF Glossary (fatf-gafi.org).
Scope can also change over time. AML Intelligence reported on Europe’s updated PEP regime and highlighted that “PEP siblings” may require enhanced vigilance in the new framework. That kind of scope expansion has a direct operational consequence. If your internal taxonomy, vendor configuration, and analyst playbook were written for a narrower definition, you have a measurable gap. Source: AML Intelligence (Mar 2024) (amlintelligence.com).
Why PEP screening shows up in enforcement
The analyst escalates the match to a reviewer. The reviewer asks a simple question: “If a regulator asked next month, could we prove we handled this correctly?”
This is not hypothetical. AML Intelligence reported that Latvian gambling firm Laimz was fined 5% of turnover over customer screening issues. Sector and facts vary across cases, but the compliance lesson is stable and verifiable. Supervisors look at screening as a control environment. They look for coverage, governance, timeliness, and evidence. If you cannot show consistent operation, the control is treated as weak. Source: AML Intelligence (Jun 2025) (amlintelligence.com).
Industry stakeholders are also calling out the same problem from another angle. AML Intelligence reported that the DT4C Alliance called for more practical guidance on PEP screening. That signals persistent implementation ambiguity in the market. Ambiguity produces predictable outcomes: either teams over-escalate and create high false positives, or they under-scope and miss relevant political exposure. Both outcomes are measurable in backlog, review time, and missed triggers. Source: AML Intelligence (Feb 2026) (amlintelligence.com).
What risk-based PEP handling means in practice
The reviewer confirms the match is credible. Now the next part of the story is EDD.
FATF’s PEP guidance describes control actions that can be turned into case file requirements. It includes measures such as senior management approval for establishing or continuing certain PEP relationships, reasonable measures to establish source of wealth and source of funds where appropriate, and enhanced ongoing monitoring. In practice, the key is not that these steps exist somewhere in a policy. The key is that you can show exactly what was done for this customer, by whom, and based on what evidence. Source: FATF PEP guidance (fatf-gafi.org PDF).
In the EU, supervisory materials repeatedly emphasize proportionate, risk-based controls and governance. A concrete way to operationalize that principle is to ensure a confirmed PEP outcome changes the customer’s risk profile and review cadence, rather than being closed as an isolated alert. The European Banking Authority’s AML/CFT hub is a useful reference point for the EU supervisory posture and guidance landscape. Source: EBA AML/CFT hub (eba.europa.eu).
In the UK, the FCA Financial Crime Guide is often used as a practical reference for what “systems and controls” should look like in operation. For PEP screening, that translates into documented processes and evidence that decisions are consistent, reviewable, and proportionate. Source: FCA Financial Crime Guide (PDF) (handbook.fca.org.uk).
Wolfsberg guidance is not law, but it is a widely used industry benchmark for risk-based PEP governance. It reinforces the idea that PEP handling is a control design and governance discipline, not just a data purchase. A procurement-grade implication is testable: can the firm explain and defend its thresholds, escalation criteria, RCA handling rules, and change-control process? Source: Wolfsberg Group PEP guidance page (wolfsberg-group.org).
The quiet problem that breaks PEP screening: weak evidence
The reviewer writes: “false positive” or “confirmed PEP.” That line by itself is not enough.
A PEP database is an input. The control is the combination of identity data, matching logic, analyst adjudication, and escalation actions. This is easy to test. Sample closed alerts and ask whether a third party can reproduce the decision from the record alone. If the answer depends on personal memory or undocumented web searches, auditability is weak.
If you want a single operational metric that predicts pain, measure the percentage of alerts where the analyst had enough structured metadata to decide inside the case record. Missing date of birth, missing role details, and missing source links correlate strongly with longer disposition times and higher false positives. You can prove this by comparing average handling times for alerts with complete identifiers versus alerts without them.
The four checks that show whether PEP screening works
If you want to move from “we do PEP screening” to “our PEP screening is defensible,” you need checks that produce evidence and numbers. These are designed to be run in an audit, an internal QA cycle, or a vendor walkthrough.
Definition coverage check: Map your internal PEP and RCA taxonomy to FATF guidance and local rules; document which categories are in-scope, including less obvious family relationships, then confirm your screening configuration matches it. Sources: FATF Glossary (fatf-gafi.org); AML Intelligence (Mar 2024) (amlintelligence.com).
Evidence sufficiency check: For closed alerts, verify the record includes identifiers compared, match rationale, and source references; weak evidence trails are inconsistent with “demonstrable controls” expectations reflected in the FCA Financial Crime Guide. Source: FCA FCG (PDF) (handbook.fca.org.uk).
EDD application check: For confirmed PEPs, verify that senior approvals and source of wealth and source of funds measures were applied where required by policy and recorded in the case file. Source: FATF PEP guidance (fatf-gafi.org PDF).
Change-control latency check: Measure time from a policy or scope update to updated rules and updated analyst procedures in production; the DT4C Alliance call for more practical guidance is relevant context for why implementation lag remains a live risk. Source: AML Intelligence (Feb 2026) (amlintelligence.com).
Where Pingwire fits in the story
In most organizations, screening tools generate the alert, but the real control strength lives in what happens next. This is where case workflow matters.
Pingwire supports that post-match workflow by treating alerts as pings and routing them into a case workspace where investigators can capture match rationale, attach evidence, record RCA basis, and document approvals. Operational controls that can be verified in the platform include Case Deadline for time-bound handling, Case Snapshot for point-in-time evidence capture of what the analyst saw, and Case Reports for standardized investigation documentation. A Case AI Agent can summarize case data while keeping outputs anchored to the case record, and webhooks support event-driven integration so ownership changes or onboarding events can trigger a ping and open a case without manual re-entry.
What changes when you tell the story end to end
Back to the Monday morning case. If the team can show: who was screened, why the match was credible, what EDD steps were applied, who approved continuation, what monitoring plan followed, and how the case record supports the decision, then the program is doing what regulators expect. If the team cannot show those things, then even a “good” screening tool is not enough.
The easiest way to improve PEP screening is to stop treating it as a name-check and start treating it as a decision system. That shift is measurable in fewer unsupported escalations, fewer missed politically exposed relationships, faster handling time, and stronger audit trails.
FAQ
What is PEP screening in AML?
PEP screening is the process of identifying whether a customer, beneficial owner, or related party is a politically exposed person and then applying risk-based controls such as EDD and enhanced monitoring. Sources: FATF Glossary (fatf-gafi.org); FATF PEP guidance (fatf-gafi.org PDF).
Does a PEP match mean the customer is doing something illegal?
No. FATF treats PEP status as a risk factor requiring proportionate controls, not proof of criminality. Source: FATF PEP guidance (fatf-gafi.org PDF).
Who counts as a PEP family member or close associate?
Definitions vary by jurisdiction and internal policy. FATF provides baseline terminology and rationale in its glossary and PEP guidance, and firms should document their own RCA scope and evidence rules. Source: FATF Glossary (fatf-gafi.org).
Why is PEP screening getting harder in Europe?
Scope and supervisory expectations evolve, including attention to additional family relationships in certain contexts. AML Intelligence’s reporting on Europe’s updated PEP regime is one example that can require changes to screening rules and SOPs. Source: AML Intelligence (Mar 2024) (amlintelligence.com).
What evidence should be in a PEP case file?
At minimum: identifiers compared, match rationale, source references, RCA basis if applicable, EDD steps taken if required, approvals, and monitoring or review cadence updates so the decision can be reconstructed later. FCA’s Financial Crime Guide supports the expectation that firms can evidence how controls operate in practice. Source: FCA FCG (PDF) (handbook.fca.org.uk).
If you want to make PEP screening easier to run and easier to defend, focus on what happens after the hit. Pingwire helps teams turn pings into structured investigations with clear ownership, deadlines, evidence capture, and reporting.
Precise AML. Predictable Growth.
