PEP Screening: A Complete Guide

PEP screening is the process of checking customers, beneficiaries, and business partners against structured databases to identify politically exposed persons who carry elevated financial-crime risk. The hardest part is rarely finding a match. It is managing false positives and applying due diligence that is proportionate to real risk, because names are not unique identifiers and a person’s PEP status can change at any time.

What Is a Politically Exposed Person?

A politically exposed person (PEP) is an individual who holds, or has recently held, a prominent public position, such as a senior government official, legislator, military leader, or judicial authority. Because these roles bring influence over public funds and decisions, PEPs are treated as carrying a higher risk of involvement in bribery, corruption, or money laundering.

The designation extends beyond the individual to their family members and close associates, since influence and access to state resources can flow through those relationships. For the full definition, see our dedicated entry on politically exposed persons.

Graphic showing the roles most commonly screened as PEPs

What Is PEP Screening?

PEP screening, often called a PEP check, is the process of identifying these individuals within your customer or partner base. It cross-references structured databases and clearly defined profiles of political exposure to flag elevated risk and keep your organization compliant with anti-money laundering (AML) regulations.

In practice, a PEP check does not decide whether you can do business with someone. A PEP is not a prohibited party. It signals that you must apply additional due diligence before and during the relationship.

Types of PEPs You Must Screen For

Not every PEP presents the same level of risk. A risk-based program starts by recognizing the main categories, because the category shapes how much due diligence you apply. Commercial PEP databases mirror these categories, tagging each entry as domestic, foreign, or international-organisation, so you can screen and re-rate accordingly.

Domestic vs. foreign PEPs

A domestic PEP holds a prominent public function within your own country. A foreign PEP holds one abroad. Foreign PEPs generally carry higher inherent risk, because you have less visibility into their background, local oversight, and political context.

International organisation PEPs

These are senior officials of international bodies, such as directors, board members, and equivalent roles at supranational organisations. They sit alongside domestic and foreign PEPs as a distinct category in most guidance.

Family members and close associates (RCAs)

Relatives and close associates, often abbreviated to RCAs, include spouses, children, parents, and known business partners. They are screened because a PEP’s influence and funds can move through people close to them, not only through the PEP directly.

Why PEP Checks Matter for Businesses

Conducting PEP checks helps stop a business from becoming a conduit for financial crime. By identifying individuals with political influence or close ties to power, companies can detect and mitigate the heightened risks of corruption, bribery, and money laundering, protect their reputation, and strengthen customer due diligence.

The requirement has spread well beyond banks. Depending on the jurisdiction, many sectors are now expected or legally required to run PEP checks as part of their AML and Know Your Customer (KYC) programs, including:

  • iGaming: platforms handling high-value, fast-moving transactions.
  • Fintech: digital wallets, lending, and peer-to-peer payments under close regulatory scrutiny.
  • Financial services: investment firms, hedge funds, and accountancy practices moving large sums.
  • Payments: PSPs and gateways processing cross-border flows.
  • eCommerce: retailers dealing in luxury or high-ticket items.

The consequences of getting it wrong are real. Regulators have issued substantial fines for inadequate PEP and sanctions screening, and non-compliance erodes trust with shareholders, customers, and partner banks. For smaller businesses, a single enforcement action can disrupt operations and stall growth.

“The compliance teams that thrive in 2026 won’t be the ones running the most rules or screening the most lists. They’ll be the ones who can configure their programs to match actual risk.”

Nauman Abuzar, VP of AML Compliance and Risk

PEP Screening Requirements by Jurisdiction

Most countries build on the standards set by the Financial Action Task Force (FATF), but the specifics differ. Always confirm your exact obligations with your local regulator.

  • United States: There is no single PEP statute in the US. The Financial Crimes Enforcement Network (FinCEN) directs institutions to take a risk-based approach to PEPs within their broader AML obligations under the Bank Secrecy Act (BSA), alongside sanctions screening against the Office of Foreign Assets Control (OFAC) lists.
  • United Kingdom: The Money Laundering Regulations 2017 (MLR 2017) and Financial Conduct Authority (FCA) guidance govern PEP screening in the UK. UK guidance allows firms to treat domestic PEPs as lower risk by default, escalating only where other risk factors are present, with the National Crime Agency (NCA) as the reporting body.
  • European Union: In the EU, requirements stem from the Sixth Anti-Money Laundering Directive (6AMLD), which defines PEP categories and mandates enhanced due diligence for higher-risk relationships.

How the PEP Screening Process Works

PEP screening is not a single check but a sequence, and each step feeds the next. Done well, it moves a customer from raw data to a defensible decision without drowning your team in false alarms.

  1. Collect and verify customer data. Start with clean inputs: full name, date of birth, nationality, and identification documents. This is the step that makes or breaks everything downstream, because a name with no date of birth is the single biggest source of false matches.
  2. Screen against PEP databases and lists. Cross-check that data against official and commercial PEP databases to surface any match with a known PEP or close associate. When the check runs can vary too. In some regimes a monetary threshold triggers it, so certain operators only screen once a customer’s aggregate deposits cross a set amount, such as roughly 2,000 dollars.
  3. Assess and categorise the risk. A match is a starting point, not a verdict. Weigh the person’s role, their geography, and any links to high-risk sectors to rate them low, medium, or high risk.
  4. Apply enhanced due diligence (EDD). For higher-risk individuals, go deeper: verify the source of funds, understand the purpose of the relationship, and secure senior management approval before onboarding or continuing.
  5. Make and document the decision. Decide whether to onboard, continue, or exit, and record the reasoning behind it. The written rationale is what protects you in an audit.
  6. Monitor on an ongoing basis. PEP status is not fixed. People enter and leave public office, so continuous monitoring keeps watching for the status and behavior changes that shift a customer’s risk after onboarding.

Treated as a whole, these steps turn PEP screening from a one-off box-tick into a living, risk-based process. The goal is not simply to catch a name on a list, but to apply the right level of scrutiny to the right people and to be able to show, at any point, why each decision was made.

PEP Lists and Data Sources

PEP data is compiled from a wide range of public sources, then consolidated. Sanctions and government lists come from bodies such as OFAC, the United Nations, HM Treasury, and the European Union. PEP and adverse-media data is aggregated from hundreds of open sources into structured databases.

Good sanctions and PEP data is more than a raw list. Reliable sources are cleaned and enriched with aliases, alternate spellings, and secondary identifiers, which is what makes accurate matching possible in the first place.

Providers differ in how they source this data. Some resell consolidated third-party databases; others, including SEON, build and maintain their own lists from primary sources and update them as the underlying data changes. This matters for coverage, freshness, and how much you can trust a given match.

The Challenges of PEP Screening

Ask any compliance team what makes PEP screening hard and the answer is rarely “finding matches.” It is everything around the match.

Reducing false positives

Names are not unique identifiers. Without a reliable date of birth or secondary identifier, common names generate large volumes of potential matches that a human then has to clear. At a minimum, screen an individual on name, date of birth, and country, and an entity on company name and country. The more identifiers you pass, the fewer false matches you review.

Blunt tuning backfires. Cranking a single fuzzy-match threshold up to something like 85 percent to quiet the noise is hard to defend to a regulator, because it silently hides real matches. The better approach is granular: weight name tokenization, date of birth, country, and how common the name is, so a “John Smith” clears more easily than a rare name, without loosening the whole system.

“A low-risk customer in the US doesn’t need the same screening intensity as a high-net-worth client in Germany. Sanctions lists differ by region. Your fuzzy matching logic should reflect these realities, not force every customer through the same filter.”

Nauman Abuzar, VP of AML Compliance and Risk

Keeping up with dynamic PEP status

A customer who is low risk today can become a foreign PEP next month, and a former official’s risk may fall over time. The widely used principle “once a PEP, always a PEP” means status is not simply switched off, but the associated risk should be re-rated. A clear declassification policy keeps due diligence proportionate.

Screening beyond the customer

Effective programs screen more than the account holder. That includes ultimate beneficial owners (UBOs) at typically 25% or more, directors, anyone with signing authority, and, in payments, the beneficiaries or counterparties on both sides of a transaction.

Balancing compliance cost against risk

Teams often question whether exhaustive PEP screening on every low-value transaction is proportionate, since PEP status alone does not prove wrongdoing. The answer is the risk-based approach: screen everyone, but concentrate enhanced due diligence and re-screening where the risk actually sits.

3 Ways to Perform PEP Screening

Regulators require you to perform customer due diligence (CDD) and enhanced due diligence, but they do not mandate a single method. Three approaches suit different scales and risk appetites.

Manual PEP screening

The simplest and most resource-intensive option: check the relevant lists by hand using official registers, public sources, and open-source intelligence (OSINT) tools. It works at low volume but is slow and error-prone, and the false-positive burden falls entirely on your team.

Manual checks with an AML solution

Input names into specialist software that aggregates results from many PEP lists worldwide and applies algorithms to estimate a match. It speeds up searches, but because names are weak identifiers, you still confirm results manually to verify the correct identity.

Fully automated PEP checks

Integrate AML software by API to verify large volumes of customers in near real time, aggregating global PEP data and running it through matching algorithms. The trade-off is the same one that runs through this whole topic: without strong identifiers and good relevancy tuning, similar names can surface as false positives.

What Effective PEP Screening Looks Like

The strongest PEP screening programs share a few traits. They bring screening, sanctions and watchlist checks, ongoing monitoring, and case management into one place, so analysts are not stitching together separate tools and losing the audit trail between them. They lean on quality, continuously updated data, and they tune matching granularly rather than with a single blunt threshold, which is what keeps false positives down without hiding real risk.

Increasingly, they also add context beyond the name. Signals such as digital footprint and device intelligence help teams judge whether a customer is who they claim to be, which sharpens decisions at onboarding and throughout the relationship. And they treat screening as continuous, re-checking customers as lists and circumstances change rather than only at the point of sign-up.

SEON brings these capabilities together in a single platform and maintains its own AML data rather than reselling third-party lists. You can read more about customer screening and AML compliance on our product pages.

FAQ

How do you check if someone is a politically exposed person?

Screen the person’s details against PEP databases, ideally with a name plus a secondary identifier such as date of birth or nationality to reduce false positives, then review any match to confirm identity and assess risk.

How do I run a PEP check?

Collect and verify the customer’s data, screen it against official and commercial PEP lists (manually or via an AML tool), categorise any match by risk, apply enhanced due diligence where needed, and set up ongoing monitoring.

What is the difference between PEP and sanctions screening?

A sanctions match generally means you cannot do business with that party. A PEP match does not: it means you must apply extra due diligence. Both are core to AML screening but carry very different consequences.

How often should you screen for PEPs?

Screen at onboarding, then run ongoing monitoring so status changes are caught. Re-screening cadence (daily, monthly, or per-transaction) should follow the customer’s risk level rather than a single blanket rule. Many teams screen against list updates as the data changes, rather than re-running the entire customer base each time.

Who needs to be PEP screened?

The customer, plus ultimate beneficial owners (typically 25% or more), directors, anyone with signing authority, and, in payments, the beneficiaries or counterparties involved in a transaction.

Take the First Step Toward Transformative Fraud Prevention