← Blog · Compliance
PEP Screening: Classifying Political Exposure Without Over-Flagging

A politically exposed person (PEP) is not a criminal by definition. The FATF framework treats PEPs as a higher risk category because their position creates opportunity for bribery and corruption. The obligation is enhanced due diligence, not refusal of service. Teams that reject every match conflate a risk indicator with a verdict, and in doing so they lose customers while learning nothing about actual exposure.
Three Categories, Different Treatment
Most frameworks split exposure into three groups, and the distinction drives the depth of review:
- Domestic PEPs hold prominent public functions in your own jurisdiction — heads of state, senior politicians, senior judiciary, central bank officials, high-ranking military officers.
- Foreign PEPs hold equivalent functions abroad. FATF Recommendation 12 makes enhanced due diligence mandatory for foreign PEPs and risk-based for domestic ones.
- International organisation PEPs hold senior roles at bodies such as the UN, IMF, or regional development banks.
Beyond the individual sit relatives and close associates (RCAs) — spouses, children, parents, and business partners who can be used to move or hold assets. A screening program that checks the named customer but ignores RCA linkage leaves the most common evasion route open.
Why Name Matching Alone Produces Noise
PEP lists are built from public registers, government gazettes, and commercial data aggregators. They contain tens of thousands of names, many of them common. Screening on name strings alone generates false positives at a rate that overwhelms small compliance teams. Reducing that noise means adding corroborating attributes before an alert is raised:
- Date of birth or birth year to separate namesakes.
- Nationality and country of function to confirm the match aligns with a real jurisdiction of exposure.
- Secondary identifiers such as a known office, party affiliation, or tenure dates.
A chat-based onboarding flow can collect these attributes conversationally — asking for a birth date or nationality at the point of verification — so screening runs against structured fields rather than a free-text name. The goal is to confirm or dismiss a match on first contact, not to escalate every string collision to a human reviewer.
What Enhanced Due Diligence Actually Requires
Once a PEP relationship is confirmed, the controls are concrete. Senior management approval is typically required to open or continue the relationship. The firm must establish source of wealth and source of funds, and apply more frequent ongoing monitoring than for a standard customer. Transaction patterns that would pass without comment for a retail client warrant a second look when the account holder controls public funds.
Documentation matters as much as detection. A supervisor reviewing the file should see when the PEP status was identified, which category applied, who approved the relationship, and what source-of-wealth evidence was gathered. Record that rationale at the moment of decision; reconstructing it months later rarely holds up.
Declassification and the Retention Question
PEP status is not permanent. Many jurisdictions allow a person to be treated as no longer politically exposed once they have left the prominent function for a defined period — commonly 12 months, subject to a residual risk assessment. Hard-coding lifelong PEP status ignores this and keeps customers under enhanced monitoring they no longer warrant.
Declassification should be an event-driven review: when a tenure end date passes, re-evaluate rather than auto-clear. This connects directly to data minimization. The attributes you collected to confirm a match — birth date, affiliation, office — are sensitive. Retain only what supports an active obligation, define a deletion schedule for dismissed matches, and make retention windows configurable per jurisdiction. Screening the right people precisely is better compliance and less data to defend. For general reference, consult FATF guidance and your own supervisor's rules rather than treating any single list as definitive.
General information, not legal advice. Talk to your compliance counsel for guidance on your specific obligations.