In this article
Politically Exposed Persons (PEPs) come up in almost every mature AML and KYC program, but the term is often misunderstood.
A PEP is not "someone suspected of wrongdoing." The label is a risk indicator used in compliance. Because certain public roles can increase exposure to bribery, corruption, and misuse of public funds, regulated firms are expected to apply enhanced scrutiny when onboarding and monitoring PEPs and people closely connected to them.
This guide covers what a politically exposed person is, the main PEP categories, why the risk matters, and how to run PEP and sanctions screening in a practical, audit-ready way.
Key takeaways
PEP status is a risk indicator, not an accusation. Most programs treat PEPs as higher inherent risk, then apply Enhanced Due Diligence and a documented, risk-based decision.
PEP screening and sanctions screening are separate controls with different outcomes. A sanctions hit is usually a legal prohibition. A PEP hit usually triggers deeper checks.
Screening at onboarding is not enough. Roles change after elections and appointments, and sanctions lists change constantly, so re-screening and event-driven review are required.
Automation improves precision at scale. Good data inputs, sensible matching thresholds, and documented review notes reduce false positives more than raw list volume does.
What is a politically exposed person?
A politically exposed person (PEP) is someone who is, or has been, entrusted with a prominent public function. In most AML frameworks, the concept also includes close family members and close associates, because they may be used to hold or move funds on the PEP's behalf.
Global guidance from the Financial Action Task Force (FATF) underpins how many countries define and manage PEP risk. Local rules differ, for example across the UK, EU, and US, so firms typically implement a policy that can handle jurisdiction-by-jurisdiction nuance without losing consistency.
Who qualifies as a PEP? Core categories
Exact definitions vary by regulator, but most compliance programs work with these common categories.
Foreign PEPs
Individuals with prominent public functions in a foreign country. This often includes senior politicians, senior government officials, senior judicial or military officials, senior executives of state-owned enterprises, and senior political party officials.
Domestic PEPs
Individuals holding prominent public functions in the same country as the reporting firm. Some jurisdictions historically emphasized foreign PEPs, but many modern regimes apply robust controls to domestic PEPs as well.
International organization PEPs
Senior roles in international organizations, for example senior management or board-level positions. The core idea is the same: these roles can involve significant influence and access to funds.
Family members and close associates
Many AML regimes extend PEP treatment to people connected to a PEP, because corruption and money laundering risk can shift to proxies.
Common examples include:
Family members: spouse or partner, children, parents, and sometimes siblings, depending on the regime and your risk policy.
Close associates: known close business partners, people with joint beneficial ownership of entities, or individuals known to act on behalf of a PEP.
Why are PEPs considered higher risk?
PEP risk is about opportunity and influence, not presumption. Prominent public functions can create exposure to:
Bribery and corruption, for example payments linked to public contracts or licensing decisions
Misappropriation of state assets
Laundering of proceeds of corruption through accounts, corporate structures, or third parties
This is why many regulations require firms to apply Enhanced Due Diligence (EDD) to PEP relationships. The compliance expectation is simple: when inherent risk is higher, controls should be stronger and better documented.
PEPs, AML/KYC, and what regulators typically expect
Most AML frameworks follow a risk-based approach. You assess customer risk, apply proportionate checks, and keep evidence that your decisions are consistent and repeatable.
This is not legal advice, but PEP-related expectations often include:
Identifying PEPs at onboarding, and re-screening over time
Applying EDD where required
Obtaining senior management approval for higher-risk relationships, commonly required for onboarding or continuing PEP relationships
Taking reasonable steps to establish source of funds (SoF) and source of wealth (SoW)
Conducting ongoing monitoring, including event-driven reviews when risk changes
How PEP screening works in practice
A practical PEP program is more than a one-time list check. It is a repeatable workflow your team can operate and explain in an audit.
A typical flow looks like this:
Collect sufficient identity data. Good screening starts with good inputs: full name, date of birth where available, nationality, residence, and identifiers relevant to your product. Weak data increases false positives and missed matches.
Screen against PEP data sources. This may include commercial datasets, curated PEP lists, and adverse media signals. Quality and update frequency matter, because roles change and new appointments happen.
Triage potential matches. Decide whether an alert is a true match, a likely match needing more evidence, or a false positive. Document the rationale.
Risk-rate the relationship and apply EDD when required. The goal is to decide whether you can onboard or continue the relationship within your risk appetite, and under what conditions.
Approve, reject, or restrict with clear documentation. For accepted PEPs, define control measures such as limits, enhanced monitoring, and periodic reviews, and record senior sign-off where required.
Monitor on an ongoing basis. PEP status can change and risk can change. Monitoring should be continuous, or frequent and risk-based, rather than a single onboarding check.
What Enhanced Due Diligence (EDD) typically includes
EDD should be specific, evidence-based, and proportionate to risk. It often includes:
Source of Wealth (SoW): how the customer's overall wealth was generated, such as salary, business ownership, inheritance, or asset sale
Source of Funds (SoF): where the funds for a specific transaction or account funding come from
Senior management approval: documented decision-making at the right level
Ongoing monitoring and periodic reviews: calibrated to risk level, product type, and transactional behavior
Relationship mapping: confirming family members, close associates, and beneficial ownership links that pull others into scope
Regulated firms commonly run PEP checks and sanctions screening together at onboarding, then repeat both as part of periodic and event-driven review.
PEP screening vs sanctions screening: not the same thing
PEP screening is usually implemented alongside sanctions screening, but they are different controls with different outcomes.
Sanctions screening determines whether you are legally prohibited, or heavily restricted, from providing services to an individual or entity. A confirmed sanctions match generally means you cannot do business.
PEP screening flags higher risk that requires EDD and closer monitoring. It is not an automatic prohibition.
A person can be a PEP without being sanctioned. A sanctioned person may not be a PEP. Your controls should handle both, and your case notes should make clear which control produced which decision.
Sanctions screening | PEP screening | |
|---|---|---|
Purpose | Legal prohibition check | Risk indicator |
Typical outcome of a true match | Block, freeze, report | EDD, approval, enhanced monitoring |
Decision latitude | Very limited | Risk-based, policy-driven |
Data source | Official government and supranational lists | Commercial and curated datasets, adverse media |
Update pressure | Very high, lists change frequently | High, roles change with elections and appointments |
Financial sanctions and their impact
Financial sanctions are imposed by governments and international bodies to counter money laundering, terrorist financing, and other threats. Measures can include asset freezes, capital market restrictions, and trade limitations.
The operational impact is direct. Sanctions prohibit firms from transacting with designated individuals and entities, so a missed match is not just a control gap. It can be a breach. In the UK, the Office of Financial Sanctions Implementation (OFSI) oversees compliance with financial sanctions, and the UK Consolidated List sets out current designations that firms are legally obliged to screen against.
The sanctions screening process
Sanctions screening means checking customers, counterparties, and often payments against applicable sanctions lists. The steps are similar to PEP screening, with tighter tolerances:
Define scope: which parties, which lists, and which jurisdictions apply to your business
Screen at onboarding, then continuously as lists are updated
Triage alerts with secondary identifiers to separate true matches from name coincidences
Escalate and act on confirmed matches, including freezing and reporting obligations
Document every decision with the data that supported it
Manual list checks can work at very low volume, but they scale poorly and create audit gaps. Automated screening with real-time list updates gives you both faster detection and a cleaner evidence trail.
Where sanctions lists come from
Core sources include the United Nations and the European Union, both of which maintain consolidated financial sanctions lists used widely for international compliance. Many firms also screen against national lists such as the UK Consolidated List and the US OFAC Specially Designated Nationals list, depending on where they operate and which currencies and correspondents they touch.
Your list coverage should follow your actual risk exposure, not convenience. Under-scoping list coverage is one of the most common findings in screening reviews.
Integrating PEP and sanctions screening into your AML program
Screening only works when it is wired into the wider program rather than bolted on. That means:
Running due diligence that identifies and manages political exposure as part of the customer risk assessment, not as a separate task
Documenting controls and procedures so decisions are repeatable across analysts
Using real-time screening so high-risk matches surface while you can still act
Feeding screening outcomes into risk scoring, transaction monitoring thresholds, and review cycles
Training staff regularly and keeping compliance, operations, and product aligned on escalation paths
The role of technology in screening at scale
Technology improves screening in specific, measurable ways:
Automated matching reduces manual effort and human error at onboarding
Better matching logic and secondary identifiers cut false positives, which is usually the largest cost in a screening operation
Continuous list ingestion keeps checks current between periodic reviews
Structured case management preserves the audit trail that regulators ask for
Consolidated data sources give reviewers one view of the customer instead of five tabs
Customer due diligence software aggregates multiple data sources so analysts assess one consolidated profile. Adding adverse media screening to the same workflow surfaces new risk signals between scheduled reviews.
Continuous monitoring and risk assessment
Continuous monitoring exists because status changes. A customer who is not a PEP today may be appointed next quarter. A counterparty who is clear today may be designated tomorrow.
Effective ongoing monitoring:
Detects changes in political status and risk profile as they happen
Pulls automated updates from PEP and sanctions data sources
Triggers event-driven review when a role changes, a designation lands, or adverse media appears
Tracks transactional behavior against the expected profile, supporting effective risk control
Skipping ongoing assessment leaves you exposed on two fronts at once: undetected risk, and an audit trail that stops at onboarding.
Common PEP and sanctions screening challenges
Most compliance teams face the same operational issues. Addressing them upfront improves effectiveness and customer experience together.
Challenge | What it looks like | Practical mitigation |
|---|---|---|
False positives | Name matches with limited identifiers | Use secondary identifiers such as DOB and country, sensible matching thresholds, and structured review notes |
Data quality gaps | Incomplete records, inconsistent transliterations | Prioritize high-quality data sources; standardize customer data collection |
Relationship mapping | Missing close associates or family connections | Use workflows that capture relationships; trigger EDD when links are confirmed |
Static screening | Only screening at onboarding | Implement re-screening and event-driven alerts for role changes and new adverse media |
Stale sanctions lists | Screening against outdated designations | Automate list ingestion; verify update frequency and coverage per jurisdiction |
Name variation | Transliteration, aliases, and name order differences | Use fuzzy matching with tuned thresholds; test with known alias sets |
Inconsistent decisions | Two analysts, two outcomes on similar alerts | Codify decision rules, require rationale fields, and sample-review closed alerts |
What about former PEPs? Once a PEP, always a PEP?
Whether someone remains a PEP after leaving office depends on jurisdictional rules and your internal policy. FATF-aligned approaches are typically risk-based. Key considerations include:
How senior the prior role was
Whether the person still appears to have influence or access
Time since leaving office; some regimes specify a period, others leave it to risk assessment
Any adverse media or suspicious activity indicators
Many firms treat former PEPs as higher risk for a defined period, with the ability to extend enhanced controls if risk remains elevated.
Consequences of weak PEP and sanctions controls
Inadequate identification, screening, and EDD can lead to:
Regulatory findings, remediation programs, and fines
Breach exposure where sanctioned parties are onboarded or paid
Increased exposure to money laundering and corruption risk
Reputational damage and loss of partner and correspondent trust
Operational disruption from costly lookbacks, escalations, and audit burden
Documented screening is what converts a defensible process into demonstrable compliance. Strong controls do more than satisfy a checklist; they form part of a resilient financial crime program.
Frequently asked questions
Is a politically exposed person automatically high risk?
Not automatically. PEP status is a risk factor, not proof of wrongdoing. Many programs treat PEPs as higher inherent risk, then apply EDD and reach a risk-based decision.
Can we onboard a PEP?
Often yes, if your policy allows it and you complete the required EDD and approvals. Some firms choose stricter de-risking policies, but regulators generally expect a risk-based approach rather than blanket exclusions.
What is the difference between PEP screening and sanctions screening?
Sanctions screening checks whether you are legally prohibited from dealing with a person or entity. PEP screening flags elevated risk that calls for enhanced due diligence and closer monitoring. The first restricts what you may do; the second shapes how carefully you do it.
How often should we re-screen customers for PEP status?
Best practice is ongoing monitoring, or frequent re-screening based on risk. Someone who is not a PEP today may become one after an election or appointment.
Do family members and close associates need EDD too?
In many frameworks, yes, because they can be used as proxies to hold or move funds. The key is confirming the relationship and applying proportionate controls.
What documents are used to verify source of funds or source of wealth?
It depends on the scenario. Examples include payslips, financial statements, asset sale documentation, inheritance records, company ownership information, and banking evidence, always assessed for reasonableness and consistency.
Which sanctions lists should we screen against?
Screen against the lists that apply to your jurisdictions, currencies, and counterparties. Most firms start with the UN and EU consolidated lists, then add national lists such as the UK Consolidated List and the US OFAC SDN list based on their footprint.
What are the consequences of failing to comply with AML regulations?
Consequences range from supervisory findings and remediation orders to significant fines, and in serious cases criminal liability for firms or individuals. Penalties vary by jurisdiction and by the severity of the failure, so check the rules of your own regulator rather than assuming a single standard.
Ready to tighten your screening?
Pingwire combines screening, customer due diligence, and case management in one platform, so PEP hits, sanctions matches, and EDD evidence live in the same audit trail. Talk to us about your current screening setup.
.webp)