What Is PEP Screening?

PEP screening identifies politically exposed persons, their family members, and close associates to apply risk-based enhanced due diligence under FATF and AML regulations.
Alexandre Berkovic

TL;DR: PEP screening is the process of identifying whether a customer, beneficial owner, or counterparty is a politically exposed person — or a family member or close associate of one — and applying enhanced due diligence where the relationship warrants it. According to Alessa's 2026 Screening Trends Survey, data quality is the single biggest screening challenge reported by compliance teams at 26.85%, ahead of false positives, backlogs, and resource shortages. The process is required by FATF Recommendations 12 and 22, implemented across every major AML regime, and routinely examined by supervisors as a core component of risk-based compliance programs.

What PEP Screening Is and Why It Matters

Diagram showing three PEP categories: Direct PEP at top, branching down to Family Members and Close Associates
PEP screening covers three categories: the politically exposed person, their family members, and their known close associates.

PEP screening is the systematic process of checking customers, beneficial owners, and counterparties against databases of politically exposed persons to determine whether a business relationship requires enhanced due diligence. The FATF defines a PEP as an individual who is or has been entrusted with a prominent public function — heads of state, senior government officials, senior executives of state-owned enterprises, senior military officers, members of courts and central banks, and senior political party officials.

The definition extends beyond the individual holding office. FATF Recommendations and implementing legislation across jurisdictions treat three categories as subject to enhanced requirements: the PEP themselves, their family members, and their known close associates. Family members typically include spouses, children, parents, and siblings. Close associates encompass individuals with close business relationships, joint beneficial ownership of legal entities, or other professional or personal connections that could enable the misuse of the PEP's position.

The reason PEPs receive heightened scrutiny is specific: they hold positions that can be abused for laundering illicit funds or for predicate offences like corruption and bribery. FATF is explicit that the requirements are preventive, not criminal — PEP status is not an accusation of wrongdoing. But the risk profile of these relationships demands more than standard CDD. Source of wealth, source of funds, senior management approval for the relationship, and enhanced ongoing monitoring are baseline expectations across every major AML regime.

PEP screening also serves as a critical input to broader compliance processes. A PEP match on a beneficial owner identified through UBO identification may trigger entirely different risk treatment for the entity relationship. PEP connections surfaced during onboarding inform the scope of enhanced due diligence applied to the account. And PEP status interacts with adverse media screening — a customer who is both a close associate of a foreign PEP and the subject of corruption-related press coverage presents a compounded risk that neither check alone would fully characterize.

Risk Tiers and the Domestic-Foreign Distinction

Not all PEP relationships carry the same risk. The risk-based approach central to FATF guidance and national legislation requires firms to distinguish between risk levels rather than applying a blanket approach. The most significant distinction is between domestic and foreign PEPs. Since January 2024, UK legislation explicitly requires that domestic PEPs — those holding prominent public functions within the UK — be treated as lower risk unless other factors indicate otherwise. The FCA's updated guidance in FG25/3, published in July 2025, reinforced this position and clarified that firms should not treat non-executive board members of civil service departments as PEPs at all.

Foreign PEPs generally carry higher inherent risk because of reduced transparency in some jurisdictions, limited access to asset declaration data, and the potential for cross-border laundering. International organisation PEPs — senior officials at entities like the United Nations, World Bank, or International Monetary Fund — form a third category. The risk assessment for each category should be case-specific, documented, and revisited when circumstances change.

The Regulatory Framework Behind PEP Screening

PEP screening obligations derive from the global AML standards set by FATF and are implemented through national legislation across every major financial jurisdiction. The requirements are not optional, and supervisors examine them closely.

FATF Recommendation 12 requires financial institutions to have appropriate risk-management systems to determine whether a customer or beneficial owner is a PEP, a family member, or a known close associate. Where the relationship involves a PEP, the institution must obtain senior management approval to establish or continue the relationship, take reasonable measures to establish the source of wealth and funds, and conduct enhanced ongoing monitoring. Recommendation 22 extends equivalent requirements to designated non-financial businesses and professions.

In the United States, FinCEN's CDD Rule and the BSA framework require institutions to identify and verify beneficial owners of legal entity customers. While FinCEN does not maintain a standalone PEP regulation, the risk-based approach mandated by the BSA makes PEP identification a practical requirement for any institution serving customers with political exposure. The FFIEC BSA/AML Examination Manual addresses PEPs within its risk assessment and EDD guidance, and examiners routinely evaluate whether institutions have adequate procedures to identify and manage PEP relationships.

The EU's Anti-Money Laundering Directives — most recently AMLD6 — require member states to implement PEP screening with enhanced due diligence. The forthcoming EU Anti-Money Laundering Regulation, directly applicable across member states, will further standardize PEP-related obligations under AMLA oversight. The FCA's FG25/3, finalised in July 2025, provides detailed guidance on how UK firms should apply a proportionate, risk-based approach to PEPs, their relatives, and close associates — reflecting changes to the Money Laundering Regulations 2017 that distinguish between domestic and non-domestic PEPs.

The common thread across these regimes is the risk-based approach. No regulator expects institutions to reject every PEP relationship. They expect institutions to identify PEP connections, assess the risk, apply proportionate enhanced measures, document their reasoning, and monitor the relationship on an ongoing basis. Enforcement actions consistently target firms that fail at one or more of these steps — typically identification failures or inadequate documentation of the risk assessment.

How to Build an Effective PEP Screening Program

Five pillars of an effective PEP screening program: Data Quality, Matching, Monitoring, Documentation, and Triage
Five capabilities separate effective PEP screening programs from those that draw supervisory criticism.

The difference between a PEP screening program that satisfies supervisors and one that draws enforcement attention comes down to five capabilities. Each addresses a specific failure mode that regulators have cited in public actions.

Data Quality and List Coverage

PEP databases are not standardized. They vary in completeness, update frequency, naming conventions, and the depth of relationship mapping they include. A screening program is only as good as the lists behind it. Coverage gaps — missing family members, outdated role information, incomplete coverage of lower-profile domestic PEPs — create blind spots that are difficult to detect until a supervisory examination or a missed match surfaces them. According to Alessa's 2026 Screening Trends Survey, data quality was cited as the single biggest challenge by 26.85% of respondents, outranking false positives, resource shortages, and cross-regime compliance.

Evaluating PEP data providers means asking specific questions: how many jurisdictions are covered, how frequently are lists updated, do the records include family members and close associates with relationship mapping, and how are names handled across scripts, transliterations, and aliases.

Fuzzy Matching and Name Resolution

PEP names present matching challenges that go beyond those in sanctions screening. Transliterations from non-Latin scripts produce multiple valid spellings of the same name. Cultural naming conventions vary — patronymic systems, compound surnames, titles used as names. A screening engine that relies on exact string matching will miss genuine PEPs. One configured with overly broad fuzzy matching will flood the alert queue with false positives on every common name in the customer base.

The balance between sensitivity and specificity requires ongoing calibration, not a one-time configuration. False positive rates in PEP screening commonly reach 95%, with some programmes reporting that reviewers clear 99% of alerts as non-matches. The operational cost is substantial: each false positive requires analyst time to investigate, document, and close. At scale, this creates the conditions for alert fatigue — the point where the volume of irrelevant matches makes it harder, not easier, to identify genuine PEPs. The secondary identifiers that reduce noise — date of birth, nationality, country of residence, position held — are the same data points that improve match quality.

Ongoing Monitoring and Lifecycle Management

PEP status is not static. Customers who were not PEPs at onboarding may acquire political exposure later. PEPs who leave office remain subject to enhanced measures for at least 12 months under most regulatory frameworks, and longer if the risk assessment warrants it. Family and associate relationships evolve — marriages, business partnerships, new corporate structures.

A screening program that checks customers only at onboarding misses these changes. Ongoing monitoring — rescreening the customer base against updated PEP lists at appropriate intervals, supplemented by event-driven triggers — is the supervisory expectation. The FCA's guidance is clear that the obligation to apply EDD to PEPs continues for 12 months after they leave office, or longer if appropriate. For family members and close associates, the obligation ceases when the PEP leaves office, but firms must have systems to track and implement these status changes.

Documentation and Audit Readiness

Every PEP screening decision — match, no match, escalation, clearance — must be documented with the reasoning, evidence reviewed, and disposition. When a PEP relationship is identified, the enhanced due diligence steps taken must be recorded: the source of wealth and funds assessment, senior management approval, the basis for the risk rating, and the enhanced monitoring plan applied.

Supervisors review PEP files not just for outcomes but for the quality of the reasoning behind them. A file that says "cleared — no match" without documenting why the match was rejected is a finding waiting to happen. A file that identifies a PEP relationship but lacks evidence of source-of-wealth inquiry is equally problematic. The volume of screening alerts many institutions face makes documentation discipline harder to maintain — but it does not change the standard.

Screening Alert Triage and Workflow

The 52% of compliance teams that cite faster alert triage as their top priority for 2026, according to Alessa's survey, are responding to a structural problem. PEP screening generates high volumes of alerts, most of which are false positives. The workflow that processes those alerts determines whether genuine PEP matches receive the attention they require or get lost in the noise.

Effective triage separates the screening decision (is this person a PEP?) from the risk decision (what does the PEP relationship mean for this customer?). The first can be substantially automated through better matching, negative screening lists for previously cleared non-matches, and secondary identifier disambiguation. The second — assessing the risk of a confirmed PEP relationship, determining the appropriate level of EDD, and deciding whether to proceed with the relationship — requires human judgment, supported by structured data. Compressing both decisions into a single alert queue is how programmes end up with review times that make neither decision well.

Where Sphinx Fits

Sphinx automates the analyst work that follows a PEP screening alert. When a screening system generates a match, Sphinx's agents gather the evidence needed to confirm or clear the match, assess the risk context, document the disposition with full reasoning, and route confirmed PEP relationships for human review and senior management approval. Every recommendation is logged, explainable, and subject to analyst override — producing audit-ready outputs that satisfy the documentation standards supervisors expect.

Frequently Asked Questions

What is the difference between a PEP and a sanctioned person?

A sanctioned person is on an official sanctions list maintained by a government or international body — OFAC's SDN List, the EU Consolidated List, or the UN Security Council List. PEP status, by contrast, reflects a person's current or former political role. Being a PEP does not mean a person is sanctioned or suspected of wrongdoing. PEP screening requires enhanced due diligence on the relationship. Sanctions screening requires blocking or rejecting the transaction entirely. They are separate controls that complement each other within a compliance program.

How long does PEP status last after someone leaves office?

Most regulatory frameworks require enhanced due diligence to continue for at least 12 months after a PEP leaves their prominent public function. The FCA's FG25/3 guidance states the obligation continues for 12 months or longer if the firm's risk assessment warrants it. FATF guidance takes the same position — former PEPs should be assessed on a risk basis, considering the level of influence they retain, the jurisdiction, and the nature of the role they held. A blanket time-based cutoff without case-specific assessment is not consistent with the risk-based approach.

Should a firm reject every PEP relationship?

No. A blanket policy of refusing PEP relationships is not a substitute for a risk-based assessment and is not what regulators expect. The requirement is to identify the PEP connection, assess the risk, apply proportionate enhanced due diligence — including source-of-wealth and source-of-funds inquiry and senior management approval — and conduct enhanced ongoing monitoring. Many PEP relationships are legitimate and manageable with the right controls in place.

What is the biggest operational challenge in PEP screening?

False positive volume. PEP databases contain hundreds of thousands of records across dozens of jurisdictions, and common-name collisions generate alert volumes that overwhelm manual review capacity. Alessa's 2026 Screening Trends Survey found that data quality — the root cause of many false positives — is the number one challenge cited by compliance teams. Addressing it requires better data inputs, secondary identifier matching, negative screening lists, and workflow design that separates the matching decision from the risk assessment.

Does PEP screening apply to beneficial owners, not just direct customers?

Yes. FATF Recommendations and implementing legislation across jurisdictions require firms to determine whether a beneficial owner of a customer entity is a PEP, a family member, or a known close associate. This is why PEP screening and UBO identification are closely linked — a legal entity with a PEP as a beneficial owner requires the same enhanced due diligence as a direct PEP customer relationship.

Get Your Free AI Compliance Handbook

What compliance leaders need to know about AI-driven fraud, autonomous laundering, and how your team can
fight back.
Submit
Thank you! Your submission has been received!
Something went wrong while submitting the form. Please try again.