A PEP result can be easy to misunderstand. It does not say that a customer has committed a crime. It says that their public position, influence or connection may require closer assessment.
The hard part is not finding a name in a database. It is confirming who the person is, understanding the relationship and deciding which controls are proportionate. That work needs evidence, ownership and a decision another reviewer can follow.
Quick answer: What is PEP screening?
PEP screening is the process of determining whether a customer, beneficial owner or relevant connected person is a politically exposed person, a family member or a close associate. It forms part of customer due diligence and ongoing risk management.
A possible match should trigger identity checks and a risk-based review. It is not evidence of corruption, money laundering or any other offence.
- Identifies possible PEP relationships
- Distinguishes a name match from a confirmed identity
- Supports proportionate due diligence
- Records review, approval and monitoring decisions
The Financial Action Task Force (FATF) describes PEP measures as preventive rather than criminal. FATF also makes clear that they should not be interpreted as meaning that every PEP is involved in criminal activity.
Who is considered a politically exposed person?
FATF defines a PEP as someone who is, or has been, entrusted with a prominent public function. Examples include heads of state or government, senior politicians, senior government, judicial or military officials, senior executives of state-owned corporations and important political party officials.
The definition is aimed at prominent functions. It does not generally cover middle-ranking or junior officials. Exact definitions still differ by jurisdiction, so organisations must apply the rules relevant to their operations.
| Category | What it generally means | Practical screening question |
|---|---|---|
| Foreign PEP | A person entrusted with a prominent public function by another country. | Does the customer or beneficial owner hold, or have they held, a qualifying foreign position? |
| Domestic PEP | A person entrusted domestically with a prominent public function. | Does the role qualify under local rules, and what risk does the relationship present? |
| International organisation PEP | A senior manager, director, deputy director, board member or equivalent within an international organisation. | Does the person exercise a sufficiently prominent function? |
| Family member | A person related to a PEP directly, through marriage or a comparable partnership. | Does the applicable framework bring this relationship into scope? |
| Close associate | A person closely connected to a PEP socially or professionally. | Is there a relationship, shared ownership or other connection that requires assessment? |
Family members and close associates matter because ownership, assets or transactions may be held through connected people. Their inclusion is a risk-control measure, not an allegation against them.
PEP screening and sanctions screening answer different questions
A PEP is not automatically sanctioned. Equally, a sanctioned person does not need to be a PEP. The controls may use similar matching technology, but the legal meaning and operational response are different.
| Control | Main question | What a match means | Typical next step |
|---|---|---|---|
| PEP screening | Does this person hold, or have they held, a prominent public function or relevant connection? | There may be elevated exposure requiring a risk-based review. | Confirm identity, assess risk and apply the required due-diligence measures. |
| Sanctions screening | Is this person, entity or activity exposed to applicable sanctions restrictions? | There may be a legal restriction or prohibition requiring urgent assessment. | Confirm the match, interpret the applicable regime and follow approved escalation procedures. |
| Adverse media screening | Is there credible reporting relevant to the subject's risk? | Published information may need verification and contextual assessment. | Evaluate source reliability, identity, relevance and materiality. |
Our sanctions screening guide explains the separate process for investigating possible sanctions exposure. Treating a PEP match like a sanctions prohibition can lead to unfair decisions and weak risk management.
Why PEP screening matters
Prominent public functions can involve influence over public funds, contracts, licences, policy or state-owned organisations. That access may create opportunities for bribery, corruption or the movement of illicit funds.
This does not mean every public official presents the same risk. The purpose of screening is to identify where further assessment may be needed, then understand the specific person and relationship.
FATF Recommendation 12 sets additional measures for foreign PEPs. For domestic and international-organisation PEPs, FATF uses a risk-based approach and calls for additional measures in higher-risk relationships. Local laws may set different or more detailed requirements.
The useful decision is not simply “PEP” or “not PEP”. Teams need to understand identity, role, influence, ownership, purpose of the relationship and the controls required under the applicable framework.
How does the PEP screening process work?
- Define the scopeDocument the customers, beneficial owners, connected parties, PEP categories and jurisdictions that fall within the organisation's process.
- Collect reliable customer dataObtain names, dates of birth, nationalities, addresses, occupations, ownership details and other identifiers through KYC or KYB.
- Run the screeningCompare relevant parties with appropriate PEP information using names, aliases and supporting identifiers.
- Investigate the possible matchConfirm whether the customer is the same person by comparing identity, role, country, age and other evidence.
- Classify the relationshipDetermine whether the subject is a foreign, domestic or international-organisation PEP, family member or close associate.
- Assess the riskConsider the public function, level of influence, geography, product, ownership, expected activity and source of wealth and funds.
- Apply appropriate measuresFollow applicable law and policy for approval, enhanced due diligence, monitoring, escalation or declining the relationship.
- Record the decisionKeep the match evidence, risk factors, rationale, approvals, controls and review schedule together.
- Monitor for changeRescreen and reassess when the person's role, relationships, customer information or risk context changes.
The process should separate identity resolution from risk assessment. First establish whether the match is genuine. Then decide what the confirmed relationship means.
What information supports a reliable PEP review?
A name alone is rarely enough. Reliable screening combines list or database results with customer due-diligence information and credible external sources.
- Identity: full name, aliases, date and place of birth, nationality and identity documents.
- Public function: official title, institution, seniority, country and dates in office.
- Business relationship: customer role, expected activity, products, services and transaction profile.
- Ownership and control: companies, trusts, beneficial ownership, directorships and shared interests.
- Connections: relevant family members, close associates and known professional relationships.
- Financial context: source of wealth, source of funds and whether available evidence is consistent.
- External information: official records, credible public information and relevant adverse media.
- Previous decisions: earlier matches, evidence, approval conditions and monitoring outcomes.
FATF notes that commercial databases can support PEP identification, but they are neither required nor sufficient on their own. The organisation still needs effective customer due diligence and risk-based judgement.
A possible PEP match requires context
Consider a hypothetical corporate customer whose shareholder has the same name as a former government minister.
The screening result alone cannot answer whether they are the same person. An analyst may compare date of birth, nationality, past positions, time in office, company ownership and other identifiers. If the identity is confirmed, the analyst then assesses the shareholder's influence, ownership level, source of wealth, purpose of the relationship and any relevant risk indicators.
The outcome may be approval with additional controls, a request for more evidence, escalation to an authorised reviewer or a decision not to proceed under the organisation's risk appetite. PEP status alone should not silently determine the result.
- Question one: Is the identity confirmed? Resolve the person using reliable identifiers and source evidence.
- Question two: What risk does the relationship present? Consider the role, influence, activity, geography and financial context.
- Question three: What controls are required? Apply the law, internal policy and approval authority relevant to the case.
- Question four: Can the decision be reconstructed? Retain the evidence, reasoning, conditions and review history.
How should teams assess PEP risk?
Risk varies between people and relationships. A senior official with control over public procurement presents a different profile from a former officeholder with limited continuing influence. A simple local product differs from a complex cross-border ownership structure.
| Risk area | Questions for the review |
|---|---|
| Public function | How senior is the role? What authority, budget, contracts or policy influence does it carry? |
| Jurisdiction | Which countries are connected to the person, funds and relationship? What risks and legal requirements apply? |
| Customer relationship | Why is the product or service needed? Is the expected activity reasonable for the customer? |
| Ownership and connections | Are companies, trusts, nominees, family members or associates involved? Is control transparent? |
| Wealth and funds | Can the origin of total wealth and the funds used in the relationship be understood and supported? |
| Activity and behaviour | Does actual activity match the stated purpose? Are there unexplained third parties, flows or changes? |
| Time and continuing influence | Has the person left office? Do they retain influence, networks, access or control that remains relevant? |
No single factor should become a hidden automatic decision. The assessment should show which factors mattered and how they affected the controls applied.
What additional measures may apply to a PEP relationship?
The precise requirements depend on the PEP category, jurisdiction and risk. Under the FATF framework, additional measures for relevant PEP relationships include:
- Appropriate senior management approval to establish or continue the relationship
- Reasonable measures to establish the source of wealth
- Reasonable measures to establish the source of funds involved
- Enhanced ongoing monitoring of the business relationship
- Risk-management systems for identifying relevant customers and beneficial owners
- Controls covering family members and close associates where applicable
Enhanced due diligence should add useful understanding. It should not become a larger document checklist with no connection to the risk. The reviewer needs to know what evidence resolves the concern, who can approve the relationship and which monitoring conditions should follow.
When should PEP screening and review happen?
PEP status and customer risk can change after onboarding. A customer may enter public office, leave a role, become linked to another PEP or change the ownership of a company. New information may also alter the assessment.
| Review point | What the team is checking |
|---|---|
| During onboarding | Whether the customer, beneficial owner or relevant connected person falls within the PEP framework. |
| Before approval | Whether required due diligence and approval are complete before the relationship begins. |
| After a role change | Whether a customer has entered, left or changed a prominent public function. |
| After ownership changes | Whether a new shareholder, controller or beneficial owner creates a PEP connection. |
| When risk events occur | Whether adverse information, unusual activity or new relationships change the assessment. |
| During scheduled review | Whether identity, role, source information, controls and risk classification remain appropriate. |
There is no single global period after which every former PEP stops presenting elevated risk. Organisations should follow applicable law and consider continuing influence, seniority, connections, time since office and other relevant factors.
Our guide to Know Your Customer compliance explains how screening and ongoing review fit within the wider customer lifecycle.
Why does PEP screening create false positives?
PEP datasets often contain common names, aliases, translated names, relatives, associates and historical positions. Customer records may contain only part of the information needed to separate one person from another.
- Common names create several possible identities.
- Transliteration produces different spellings of the same name.
- Dates of birth or nationalities are missing.
- Old roles remain without clear start and end dates.
- Family or associate relationships are unclear or outdated.
- Duplicate records generate repeated alerts.
- Junior roles are incorrectly treated as prominent functions.
- Earlier review evidence cannot be reused safely.
Reducing sensitivity until the queue becomes manageable is not a sound fix. Teams should improve customer data, use supporting identifiers, calibrate matching, prioritise intelligently and preserve well-evidenced previous decisions.
What should a defensible PEP review record contain?
A reviewer should be able to understand what matched, how identity was resolved and why the final controls were chosen without relying on the original analyst's memory.
- The customer, beneficial owner or connected person screened
- The source, date and details of the possible PEP match
- The identifiers and documents used to confirm or reject the match
- The PEP category, public function and relevant dates
- The relationship and ownership context considered
- The risk factors and mitigating information assessed
- Source-of-wealth and source-of-funds evidence where relevant
- The analyst's conclusion and supporting rationale
- Senior approval, conditions, escalation and any override
- The monitoring approach, review triggers and next review date
Retention and access should follow applicable law and organisational policy. Sensitive information should be available to authorised reviewers without being exposed more widely than necessary.
What should teams look for in PEP screening software?
Coverage matters, but a long record count says little about whether analysts can make good decisions. Evaluate the full review workflow.
| Evaluation area | Question to ask |
|---|---|
| Data and scope | Does the service support the PEP categories, jurisdictions, languages and connected parties relevant to the organisation? |
| Identity matching | Can it use aliases, dates, nationalities, roles and other identifiers without hiding how the match was produced? |
| Source transparency | Can analysts see where the PEP information came from and when it was updated? |
| Customer context | Can the reviewer access KYC, KYB, ownership, previous screening and relationship information? |
| Workflow | Can matches be assigned, investigated, escalated, approved and returned for more evidence? |
| Risk assessment | Can teams record explainable factors and apply policy without reducing every case to one score? |
| Ongoing screening | Can changes to PEP data or customer information trigger an appropriate review? |
| Auditability | Can the organisation reconstruct the data, evidence, reasoning, approvals and monitoring decision? |
Technology should support the organisation's policy and judgement. It should not decide that a customer is unacceptable simply because a name appears in a PEP dataset.
How WIDTH supports connected PEP screening workflows
WIDTH supports PEP screening within customer and business onboarding and ongoing compliance workflows. Screening results can remain connected with customer records, beneficial ownership information, risk reviews and investigations.
This gives analysts more of the context needed to resolve a possible match. Relevant identifiers, relationships, earlier decisions, supporting evidence and review actions can stay within one controlled process.
Where deeper investigation is needed, the result can move into case management with clear ownership, evidence, escalation, rationale and approval history. It can also sit alongside sanctions screening, adverse media and transaction monitoring rather than becoming an isolated customer flag.
WIDTH does not determine an organisation's legal obligations or guarantee compliance. It helps teams connect the information, workflow and decision record needed to manage PEP risk with greater control.
Good PEP screening protects judgement from shortcuts
A database can identify a possible connection. It cannot explain the customer, the public function or the risk on its own.
A defensible process confirms identity first. It then assesses the relationship, applies proportionate controls and records why the decision was made. This protects customers from automatic assumptions and gives compliance teams a clearer basis for approval, monitoring or escalation.
The result is not merely a PEP label. It is a reasoned decision that can be reviewed when the person's role, activity or wider risk context changes.
See the FATF Guidance on Politically Exposed Persons, the current FATF Recommendations and the Wolfsberg Group PEP Guidance. Definitions and required measures vary by jurisdiction and should be applied with the relevant local rules.
Frequently asked questions about PEP screening
PEP screening is the process of determining whether a customer, beneficial owner or connected person is a politically exposed person, family member or close associate. A possible match requires identity checks and a risk-based review; it is not evidence of wrongdoing.
No. PEP status reflects exposure associated with a prominent public function, while sanctions impose specific legal restrictions. A person may be a PEP without being sanctioned, sanctioned without being a PEP, or both.
No. PEP measures are preventive. FATF states that they should not be interpreted as meaning that every PEP is involved in criminal activity.
The appropriate scope can include customers, beneficial owners, directors and other connected persons, together with family members and close associates where required by the applicable framework.
The team should first confirm identity, then assess the relationship's risk and apply the measures required by its jurisdiction and policy. These may include senior approval, source-of-wealth and source-of-funds checks, enhanced monitoring and a documented decision.
A foreign PEP holds or held a prominent function for another country. A domestic PEP holds or held such a function in the institution's own country. FATF applies different baseline measures, but local law determines the exact treatment.
They may fall within the applicable PEP measures because funds or ownership can be held through connected people. The definitions and scope should follow local law and organisational policy.
There is no single global time limit. Organisations should follow applicable law and assess continuing influence, seniority, connections and other risks rather than removing the status automatically after a fixed period.
Technology can support data matching, alerts, rescreening and workflow routing. Human judgement remains important for identity resolution, contextual risk assessment, escalation and final decisions.
It should retain the subject data, source and date of the match, identifiers reviewed, relationship assessment, risk factors, source-of-wealth or source-of-funds evidence where relevant, approvals, monitoring decision and review history.
Connect PEP screening with the full customer risk workflow
Bring customer data, PEP results, ownership context, risk assessment, approvals and ongoing reviews into one controlled operating environment.
