Skip to main content
Category: Politically Exposed Persons

PEP Screening

Also known as: PEP Check, Politically Exposed Person Screening, PEP Checks
Simply put

PEP screening is a due diligence process used to determine whether a customer or connected individual is a politically exposed person, meaning someone who holds or has held a prominent public position. Because such positions can increase a person's exposure to risks like bribery, being identified as a PEP generally signals that a financial institution should take a closer look. Being flagged as a PEP is an indicator of potential heightened risk, not a finding of any wrongdoing.

Formal definition

PEP screening is a control within the customer due diligence (CDD) process by which an obliged entity checks customers, and often their associated parties, against reference data to identify individuals who are or have been entrusted with a prominent public function, and to assess the associated financial crime risk. The term PEP is commonly applied in the financial industry to foreign individuals holding such prominent public functions, though the precise scope of who qualifies as a PEP, including domestic PEPs, family members, and close associates, varies by jurisdiction and should be confirmed against the applicable regulatory framework. A positive PEP identification typically informs the level of scrutiny applied and may trigger enhanced measures, but it is a risk indicator used to detect and manage heightened risk rather than a determination of criminal conduct; PEP screening is distinct from sanctions screening, which assesses exposure to designated persons and entities under applicable sanctions regimes.

Why it matters

PEP screening addresses a specific dimension of financial crime risk: individuals entrusted with prominent public functions can, by virtue of their position, have greater exposure to risks such as bribery and the misuse of public office. Identifying whether a customer or connected individual is a politically exposed person allows an obliged entity to calibrate the level of scrutiny it applies and to decide whether enhanced measures are warranted. It is important to stress that a PEP flag is a risk indicator, not a finding of wrongdoing; the vast majority of PEPs never engage in illicit conduct, and screening exists to detect and manage heightened risk rather than to presume criminality.

The operational significance of PEP screening lies in its role within the broader customer due diligence framework. A missed or mishandled PEP status can leave an institution unable to demonstrate that it understood and managed the risk profile of a relationship, which is a common area of supervisory focus. Conversely, the precise scope of who qualifies as a PEP, including whether domestic PEPs, family members, and close associates are captured, varies by jurisdiction and should be confirmed against the applicable regulatory framework. This variation means firms operating across borders cannot assume a single global standard applies, and must map their screening obligations to each relevant regime.

PEP screening should also be understood as distinct from sanctions screening, with which it is sometimes conflated. Sanctions screening assesses whether a party is a designated person or entity under an applicable sanctions regime, whereas PEP screening identifies exposure to prominent public functions and the risk that exposure may carry. Treating the two as interchangeable can lead to gaps in coverage, since a person may be a PEP without being sanctioned, and vice versa.

Who it's relevant to

Compliance officers and CDD teams
Those responsible for onboarding and ongoing due diligence use PEP screening to identify politically exposed persons and to determine whether the level of scrutiny should be raised or enhanced measures applied. They also need to ensure the scope of screening reflects the categories of PEPs and connected persons required under the applicable regime.
Financial intelligence analysts and investigators
Analysts treat a PEP identification as a heightened-risk indicator that may warrant closer review of a customer's activity, while being careful not to interpret a PEP flag as evidence of wrongdoing. It provides context for assessing risk alongside other factors.
Risk and control function leaders
Those overseeing AML programs rely on PEP screening as a core component of customer due diligence and must ensure it is distinguished from, and coordinated with, sanctions screening. They are also responsible for confirming that screening scope and thresholds align with the requirements of each jurisdiction in which the firm operates.
Legal and regulatory advisors
Because the definition of a PEP, including whether domestic PEPs, family members, and close associates are captured, varies by jurisdiction, legal advisors help map screening obligations to the correct source instruments and confirm scope against the applicable regulatory framework.

Inside PEP Screening

PEP Identification and Definition
The process of determining whether a customer or beneficial owner qualifies as a politically exposed person, meaning an individual entrusted with a prominent public function. Definitions vary by regime: the FATF Recommendations distinguish foreign PEPs, domestic PEPs, and persons entrusted with prominent functions by international organisations, while jurisdictions such as the EU (under its AML framework) and the US (under BSA/FinCEN guidance, which historically has not used an identical statutory 'PEP' term) may frame the category differently. Exact scope should be confirmed against the applicable regulation.
Associated Persons (RCAs and Family Members)
Screening typically extends beyond the PEP to close associates and immediate family members, often described as relatives and close associates (RCAs). The precise categories captured generally depend on the applicable regime and the entity's own risk assessment, and the boundaries of who counts are not defined identically everywhere.
Screening Against Reference Data
The operational matching of customer records against PEP reference lists or databases, frequently sourced from commercial data providers. A match is an indicator requiring review, not a determination that a person is a PEP or that any wrongdoing exists.
Risk-Based Classification and Tiering
Assessment of the risk posed by an identified PEP relationship, which in many jurisdictions may differentiate between foreign PEPs (often treated as inherently higher risk) and domestic or international-organisation PEPs (which may be handled on a risk-sensitive basis). This supports proportionate application of controls rather than a uniform treatment.
Enhanced Due Diligence Trigger
Identification of a PEP generally triggers enhanced due diligence (EDD) measures, which are additional to standard customer due diligence (CDD). These typically include senior management approval to establish or continue the relationship, establishing source of funds and source of wealth, and enhanced ongoing monitoring, subject to the applicable regime.
Ongoing Monitoring and Rescreening
PEP status can change over time, so screening is generally not a one-off event at onboarding but a continuing process, including periodic rescreening and monitoring of the relationship for as long as it persists, with some regimes contemplating continued application of measures for a period after a person ceases to hold the function.

Common questions

Answers to the questions practitioners most commonly ask about PEP Screening.

Does identifying someone as a PEP mean they are a criminal or involved in money laundering?
No. A PEP match does not establish wrongdoing of any kind. PEP status is a risk indicator, not an accusation. It reflects that an individual holds or has held a prominent public function, and, in many regimes, extends to their family members and known close associates, which may expose them to a higher risk of bribery, corruption, or misuse of position. The designation triggers enhanced scrutiny and, in many jurisdictions, enhanced due diligence measures; it does not imply the person has committed an offence or should automatically be refused service. Treating a PEP match as proof of criminality misapplies the concept.
Is PEP screening the same thing as sanctions screening?
No, though the two are often run through overlapping technology and are sometimes conflated. Sanctions screening checks whether a party appears on sanctions lists maintained by bodies such as national authorities, the EU, or the UN, and a true match generally carries hard legal consequences such as asset freezes or prohibitions on dealing. PEP screening identifies individuals holding prominent public functions to determine whether enhanced due diligence measures may apply; a PEP identification does not by itself prohibit a relationship. The obligations, the source instruments, and the required responses differ, so the two processes should be treated as distinct even where systems are shared.
How should a firm decide whether family members and close associates of a PEP fall within scope of screening?
In many jurisdictions the definition of a PEP is extended by regulation to include certain family members and known close associates, but the precise categories and how far they reach can vary between regimes. Firms typically define these categories in policy by reference to the applicable regulation, for example the relevant EU AML instruments, the UK Money Laundering Regulations, or local rules, and calibrate their screening data and matching logic accordingly. The exact scope of who qualifies should be confirmed against the applicable regulation rather than assumed to be uniform.
What is a practical approach to handling the high volume of potential matches PEP screening can generate?
PEP screening frequently produces potential matches that require human review, particularly for common names, so many firms establish a risk-based alert adjudication process. This typically involves configuring matching thresholds and fuzzy-logic settings, using additional identifiers to confirm or discount a match, documenting the rationale for each disposition, and escalating confirmed PEPs for the enhanced measures the applicable regime may require. The aim is to manage and prioritise review capacity; no screening configuration eliminates the need for judgement or guarantees that all relevant relationships are captured.
How often should PEP status be re-screened after onboarding?
PEP status can change over time, as individuals take up or leave public functions, so screening is generally treated as an ongoing rather than one-time obligation. Many firms apply periodic re-screening and event-driven reviews as part of ongoing monitoring, with the frequency calibrated to the assessed risk of the relationship. The specific expectations around ongoing monitoring and re-screening should be confirmed against the applicable regulation and the firm's own risk-based policies.
What steps typically follow once a customer is confirmed to be a PEP?
Once PEP status is confirmed, many jurisdictions require obliged entities to apply enhanced due diligence measures. These commonly include obtaining senior management approval to establish or continue the relationship, taking reasonable measures to establish the source of wealth and source of funds, and applying enhanced ongoing monitoring. The precise measures required depend on the applicable regime, so firms should map their procedures to the specific obligations set out in the regulation governing their operations.

Common misconceptions

Being a PEP, or generating a PEP match, means the person is involved in corruption or money laundering.
PEP status is a risk indicator reflecting potential exposure to bribery and corruption risk due to a public position; it is not an allegation or finding of wrongdoing. Screening classifies risk and triggers additional scrutiny under a risk-based approach, and a match must be reviewed and confirmed rather than treated as evidence of a crime.
There is a single global list of PEPs and one universal definition that all firms must apply.
No authoritative global PEP list exists, and definitions differ across the FATF Recommendations (which are standards, not binding law), EU AML instruments, and US BSA/FinCEN expectations. Commercial databases compile candidate records but are reference tools, not definitive registers, and the categories of PEPs and associated persons captured vary by jurisdiction and by an entity's own risk assessment.
PEP screening and sanctions screening are essentially the same control.
They are distinct. Sanctions screening tests whether a party appears on binding sanctions lists, where a true match generally carries direct legal prohibitions such as asset freezes or transaction bars. PEP screening identifies exposure to a higher-risk category to inform risk-based enhanced due diligence, and identifying a PEP does not by itself prohibit dealing with that person.

Best practices

Base the PEP category and associated-persons scope you screen for on the definitions in the regime(s) that apply to your entity, and confirm the exact boundaries of foreign, domestic, and international-organisation PEPs against the applicable regulation rather than assuming a uniform standard.
Treat PEP database matches as review triggers, not conclusions: build a disposition workflow that verifies matches against underlying information and documents the rationale for confirming, tiering, or discounting each result.
Apply a risk-based approach that differentiates the intensity of enhanced due diligence according to the type of PEP and the specific relationship, rather than applying identical measures to every match.
Where a relationship is confirmed as involving a PEP, ensure the enhanced measures your regime contemplates are carried out and evidenced, such as senior management approval, establishing source of funds and source of wealth, and enhanced ongoing monitoring.
Perform screening on a continuing basis, not only at onboarding, including periodic rescreening to capture individuals who become PEPs during the relationship and to reflect status changes over time.
Maintain records of screening decisions, data sources, and the basis for classification so that the risk rationale is auditable and can be demonstrated to regulators, while recognising that no screening control eliminates financial crime risk.