Leadership Series. PEP Screening

A PEP isn't just a foreign official. The definition is broader than most firms realize.

Politically Exposed Persons are one of the most commonly misunderstood categories in AML compliance. Here is who qualifies, why they carry elevated risk, and what a compliant screening program looks like in practice.

What this covers
The three PEP categories and where screening most commonly breaks down
Why periodic review cycles miss PEP status changes
What regulators look for in a PEP screening examination
How Sentinel ™ handles continuous PEP monitoring automatically
3 PEP categories every program must screen. foreign, domestic, and by association
12–18mo typical cooling-off period before a former PEP can be reclassified as standard risk
0.3% Sentinel ™ false positive rate. PEP alerts that reach your team are worth reviewing
FATF 12 the recommendation mandating PEP screening for banks, fintechs, and designated non-financial businesses
The Definition

What makes someone a Politically Exposed Person?

Most compliance teams have a working definition of a PEP. Fewer have a precise one. The gap between the two is exactly where regulatory findings originate.

A prominent public position, current or former

A PEP is an individual who holds or has recently held a prominent public function. heads of state, senior government officials, military officers, members of the judiciary, state-owned enterprise executives, and officials of international organizations. PEP status does not end the day someone leaves office.

Close family members and associates

PEP exposure extends to immediate family members. spouses, children, parents, and siblings. and to close associates who maintain a personal or business relationship with the PEP. These individuals carry the same indirect exposure to corruption and bribery risk as the PEP themselves.

Elevated risk, not automatic exclusion

Being a PEP does not disqualify someone from being a customer. It triggers a risk-based response. Enhanced Due Diligence, source of funds and wealth verification, and senior management approval. The obligation is proportionate scrutiny, not blanket rejection.

The Three Categories

Foreign, domestic, and by association

FATF and most national AML frameworks distinguish between three PEP categories, each carrying different risk weightings and due diligence requirements. Most firms screen correctly for one. The failures occur in the other two.

01
Foreign PEPs. highest risk under FATF guidelines

Individuals who hold or have held a prominent public function in a country other than the institution's home jurisdiction. Under FATF Recommendation 12, foreign PEPs must always be treated as higher risk and subjected to Enhanced Due Diligence regardless of the jurisdiction's perceived risk level. There is no threshold or exemption based on the seniority of the role.

Common mistake: screening for foreign government ministers but not for foreign state-owned enterprise executives or officials of international organizations such as the UN, IMF, or World Bank.
02
Domestic PEPs. risk-based approach required

Individuals who hold or have held a prominent public function within the institution's home country. Unlike foreign PEPs, most jurisdictions allow a risk-based approach for domestic PEPs. the level of EDD applied depends on the specific role, the nature of the relationship, and the institution's risk appetite. A risk-based approach still requires a documented decision. Treating a domestic PEP as standard risk without documentation is not defensible in an examination.

The EU's Anti-Money Laundering Directives require firms to treat both domestic and foreign PEPs as higher risk and apply EDD to both categories without differentiation.
03
PEPs by association. the most commonly missed category

Individuals who are not themselves PEPs but are closely connected to one. family members, business partners, or known associates. They carry indirect exposure to the same bribery and corruption risk as the PEP they are connected to. This category is the most commonly missed in screening programs, partly because it requires screening not just the customer but their network, and partly because the connection to a PEP may not be declared at onboarding.

A PEP's adult child opening a business account is not a PEP themselves. but they are a PEP by association and should trigger an EDD review and source of funds assessment.
Why It Matters

What happens when PEP screening breaks down

PEP screening failures do not announce themselves at onboarding. They surface gradually. through changes in customer risk profiles that a periodic review process cannot catch in time.

Onboarding
Low risk
Customer is screened and cleared at onboarding

The customer does not appear on any PEP database at the time of onboarding. They are assigned a standard risk rating, KYC documentation is collected and filed, and the relationship begins without any elevated due diligence requirements.

8 months
Elevated
Customer is appointed to a senior government role

The customer accepts a senior position in a government ministry. Their name is added to PEP databases within days of the announcement. Without continuous re-screening, this change is invisible to your compliance program. The relationship continues under a standard risk rating that no longer reflects reality.

14 months
High
Periodic review does not catch the change

The institution's annual KYC refresh runs a name screen against the customer record. Due to a data entry inconsistency between the name on file and the name on the PEP database, the match is not returned. The customer's risk rating is renewed as standard. The relationship continues unchanged.

22 months
Critical
Examiner identifies the unmonitored PEP relationship

During a regulatory examination, examiners pull customer records and cross-reference them against current PEP databases. The customer's current status is identified. The institution has no EDD documentation, no source of funds assessment, and no senior management sign-off for a relationship that has been a PEP exposure for fourteen months. The finding is cited as a material deficiency.

Sentinel ™
PEP status change detected within hours of appointment

Sentinel ™ re-screens your full customer portfolio continuously against live PEP databases. When the customer's name is added to a PEP list, the match is returned within hours. not at the next annual review cycle. The compliance team is alerted, EDD is triggered, and the documentation trail begins from the moment the risk materialises.

Continuous Monitoring
The Requirements

What a compliant PEP screening program actually requires

Regulators are not looking for perfection. They are looking for evidence that your program is structured, documented, and proportionate to risk.

Identification at onboarding. and all three categories

Screening must cover foreign PEPs, domestic PEPs, and PEPs by association. A program that screens the customer but not their close family members or business associates is incomplete. Most enforcement actions involving PEP failures cite the by-association category as the gap.

Enhanced Due Diligence with senior management sign-off

A PEP identification triggers an EDD process that must include verification of source of funds and source of wealth, an assessment of the purpose of the relationship, and documented senior management approval before the relationship is established or continued. Verbal sign-off is not sufficient for examination purposes.

Continuous monitoring, not periodic review

PEP status changes. A customer who is not a PEP today may be one in six months. A former PEP may remain in scope for 12 to 18 months after leaving office. Periodic review cycles cannot reliably detect these changes in time. Continuous re-screening against live PEP databases is the only approach that closes this gap systematically.

A complete, timestamped audit trail

Every PEP screening decision must be documented: the date of the screen, the database version used, the match result, the disposition decision, and who made it. When an examiner pulls a PEP record, they expect to see the full history of how the risk was identified, assessed, and managed. not a single onboarding entry and nothing since.

A PEP match is not the end of the process. It's the beginning of a documented decision.

Regulators do not expect compliance teams to reject every PEP. They expect a clear, documented, risk-proportionate response. Sentinel ™ surfaces the match, triggers the right workflow, and builds the audit trail automatically. so when an examiner asks how a PEP relationship was managed, the answer is already on record.

Foreign, domestic, and by-association categories
Continuous re-screening against live PEP databases
EDD workflow triggered automatically on match
Full timestamped audit trail per customer
0.3% false positive rate

Know exactly who your customers are. and who they're connected to.

See how Sentinel ™ handles PEP identification, EDD workflows, and continuous monitoring in a single platform.