Skip to main content
Didit Raises $7.5M to Build the Infrastructure for Identity and Fraud
Didit
Back to blog
Blog · July 28, 2026

PEP Screening: Definitions, Scope, and Monitoring

An operational guide to politically exposed person screening: FATF definitions, foreign and domestic PEPs, family and close associates, tiering, match resolution, enhanced due diligence, ongoing monitoring, and governance.

By DiditUpdated
pep-screening-definitions-scope-monitoring.png

Politically exposed person (PEP) screening is the process of determining whether a customer, beneficial owner, or other in-scope party holds or has held a prominent public function, or falls within the relevant family-member or close-associate scope.

The result is preventive risk information, not evidence of wrongdoing. The Financial Action Task Force (FATF) is explicit that PEP requirements are preventive rather than criminal and must not imply that every PEP is involved in criminal activity. A useful PEP process does two jobs: it resolves whether the person matches a relevant profile, then applies measures proportionate to the relationship and risk.

This guide explains the international baseline and an operating model. Local definitions and measures vary, so firms must map the rules for each entity, product, and customer population.

Key takeaways

  • PEP status is a risk factor, not a verdict. A confirmed match should trigger the required assessment and controls, not an automatic accusation or rejection.
  • Scope extends beyond the named customer. Depending on the applicable regime, screening can include beneficial owners, family members, and persons known to be close associates.
  • Foreign, domestic, and international-organization PEPs do not always follow identical rules. FATF applies additional measures to foreign PEP relationships and a risk-based trigger to domestic and international-organization PEPs.
  • PEP tiers are operational conventions. Labels such as PEP 1–4 can help route work, but FATF does not define a universal four-tier legal hierarchy.
  • Matching and risk assessment are separate. First establish that the profile belongs to the customer; then assess the function, geography, influence, products, activity, and other risk.
  • Screening is ongoing. Appointments, resignations, family relationships, beneficial ownership, customer data, and source records can change after onboarding.

What is PEP screening?

PEP screening compares an in-scope person with reliable information about prominent public functions and relationships. Inputs commonly include:

  • full name and aliases;
  • date and place of birth;
  • nationality and residence;
  • public function and institution;
  • dates in office;
  • related countries;
  • family or close-associate relationship;
  • source provenance and last update.

The comparison produces a candidate, not a conclusion. A reviewer or governed matching process must decide whether the record concerns the same person, whether the function falls within the applicable definition, and what measures the relationship requires.

Names are not unique. Transliteration, reordered surnames, missing dates of birth, and stale office dates create false positives, while narrow spelling rules can miss a PEP recorded under another script, previous name, or alias.

The FATF definition and scope

The FATF glossary describes a PEP as an individual who is or has been entrusted with a prominent public function. Examples include heads of state or government, senior politicians, senior government, judicial or military officials, senior executives of state-owned corporations, and important political-party officials. The definition is not intended to cover middle-ranking or more junior individuals in those categories.

FATF separates three direct PEP categories:

CategoryBasic meaningFATF treatment at a high level
Foreign PEPEntrusted with a prominent public function by a foreign countrySystems to identify the relationship, senior-management approval, reasonable source-of-wealth and source-of-funds measures, and enhanced ongoing monitoring
Domestic PEPEntrusted domestically with a prominent public functionReasonable measures to identify; apply the additional measures where the relationship is higher risk
International-organization PEPEntrusted with a prominent function by an international organizationReasonable measures to identify; apply the additional measures where the relationship is higher risk

Recommendation 12 extends the relevant requirements to family members and close associates. Recommendation 22 applies the PEP requirements to designated non-financial businesses and professions when they conduct the activities covered by that recommendation.

These standards are implemented through national law. Countries can prescribe more specific functions, including roles at regional or local-government level.

Family members and close associates

Relatives and close associates are often grouped under the operational abbreviation RCA, but the governing legal categories are “family members” and “persons known to be close associates.” Their scope must come from applicable law rather than a vendor label.

The EU’s Fourth Anti-Money Laundering Directive gives one concrete example. Its family-member definition includes a spouse or equivalent partner, children and their spouses or equivalent partners, and parents. Its close-associate definition includes certain joint beneficial owners, persons with close business relations, and a sole beneficial owner of an entity known to have been set up for the de facto benefit of a PEP.

Other jurisdictions can use different family degrees or relationship tests. An operating policy should therefore record:

  • which relationship types are in scope;
  • which evidence is sufficient to establish the relationship;
  • whether the person is screened because of their own function or their relationship;
  • how the direct PEP’s status and dates affect the related party;
  • what happens when the relationship is disputed or no longer current.

A shared surname is not evidence of family membership, and a corporate co-directorship is not automatically a close association.

PEP tiers: useful routing, not universal law

Many screening data sets divide PEPs into levels such as PEP 1, 2, 3, and 4. The labels can make review queues and policies easier to operate, but there is no FATF rule assigning every public function to a universal four-level scale.

A typical internal model might place national leaders and cabinet-level functions at the most senior end, then other national, regional, local, party, judicial, military, state-enterprise, or international-organization roles into lower categories. Another provider may map the same role differently. Treat the tier as a provider or policy attribute, not a legal conclusion.

QuestionWhy it matters more than the tier number
What exact function does the person hold?The legal definition attaches to the function, not the vendor’s label
Which country or organization entrusted the function?Foreign, domestic, and international-organization rules can differ
When did the function begin or end?Current and former status affect review and monitoring
What authority and access come with the role?Influence over funds, licenses, procurement, or appointments can change risk
Is the customer the direct PEP or a related party?Relationship type and evidence determine scope
What products, assets, and activity are involved?Customer and transaction context determine proportionate controls

If tiers drive workflow, keep the mapping versioned. Reviewers should be able to see the underlying function, source, dates, and relationship rather than only “PEP 2.”

A defensible PEP screening workflow

1. Define the screened population

Map the obligation before selecting a data source. The population may include customers, beneficial owners, controllers, authorized representatives, beneficiaries, settlors, trustees, directors, guarantors, or counterparties, depending on the relationship and law.

Document when each population is screened: onboarding, before a qualifying transaction, on a material data change, periodically, and when source data changes.

2. Collect enough identity data

A name-only comparison creates noise and misses. Collect identity attributes lawfully and proportionately, retain original-script names, and normalize separate fields without overwriting the source value.

Date of birth, nationality, residence, aliases, previous names, and occupation can materially improve resolution. Missing data should remain visible as uncertainty rather than being treated as a non-match.

3. Use multiple permitted sources

Sources include official function lists, government pages, appointment records, ownership information, customer declarations, public reporting, and commercial data.

FATF guidance says external databases can help but are not sufficient by themselves, and FATF does not require the purchase of a database. The accountable organization still needs a definition, a match process, a risk assessment, and continuing controls.

4. Generate candidate matches

Matching should account for aliases, token order, transliteration, diacritics, initials, and common-name frequency. It should also use negative evidence: an incompatible date of birth, different nationality, unrelated function, or impossible timeline can resolve a candidate.

Thresholds should reflect data quality and consequence. A lower threshold may improve recall but increase review work. Automatic clearance needs testing against known matches.

5. Resolve identity separately from exposure

The first decision is same person or not. The second is in-scope political exposure or not. Keep those states distinct:

StateMeaningNext action
CandidateSome identity features overlapCompare all available identifiers
False positiveEvidence shows a different personClose with a reason that supports safe suppression
Possible matchEvidence is incomplete or conflictingRequest information or escalate
Confirmed identity matchThe profile concerns the customer or related partyValidate function, relationship, dates, and legal scope
Confirmed in-scope PEPIdentity and scope are establishedApply the required risk assessment and controls

6. Assess risk and apply required measures

For relationships where the additional PEP measures apply, FATF Recommendation 12 identifies senior-management approval, reasonable measures to establish source of wealth and source of funds, and enhanced ongoing monitoring.

Those measures are not a request for the same document from everyone. The evidence should be proportionate to what the customer says, the assets and activity involved, the public function, the relationship, and the uncertainty that must be resolved.

7. Preserve the decision

Record the input data, source record, source date, match features, conflicts, function, relationship, policy version, reviewer, evidence, decision, approval, and next review trigger. Preserve enough source context to explain the decision later, subject to retention and data-protection rules.

8. Monitor change

Rescreen when a source changes and when relevant customer data or behavior changes. Avoid reopening the same resolved article or profile without new information; equally, do not suppress a name forever when the earlier false positive depended on attributes that may change.

Source of wealth versus source of funds

The two terms answer different questions.

Source of wealth explains how the person accumulated their overall body of wealth—for example, business ownership, employment over time, investments, inheritance, or asset sales. It helps establish whether the scale and history of wealth are plausible.

Source of funds explains the origin of the particular money or assets used in the relationship or transaction. Naming the bank that transferred funds is not necessarily enough; the substantive economic origin may be salary, business revenue, a property sale, investment proceeds, a loan, or another activity.

Evidence can include accounts, tax records, payslips, contracts, sale or probate documents, investment statements, bank records, and reliable public information. The right evidence depends on risk and context.

Enhanced monitoring should compare later activity with the established explanation. A credible source-of-wealth narrative can still be inconsistent with a specific incoming payment, and a well-explained payment does not establish the origin of an unexplained wider fortune.

False-positive management

False positives are expected in name screening. Managing them well protects both control effectiveness and customer access.

Improve input quality

Separate given and family names, retain native script, capture aliases, and validate dates and country fields. Do not turn an unknown date into an assumed value.

Explain the mismatch

Use closure reasons such as incompatible birth date, different nationality with corroboration, unrelated public function, conflicting timeline, or verified different identity. “Reviewer knows it is false” is not a reusable control.

Suppress narrowly

A suppression should bind to the resolved customer, source profile, and decisive attributes. Broad name suppression can hide a future true match, especially for a customer whose role or identifiers change.

Test both misses and workload

Precision measures how many candidates are relevant; recall measures how many known relevant profiles are found. Candidate rate and review time measure workload. A threshold can look efficient while missing aliases or non-Latin names, so testing should be segmented by language, geography, name frequency, source, and data completeness.

Provide review and redress

PEP data can be wrong, late, or attached to the wrong person. Define a route to correct customer data, challenge a classification, update source records where possible, and reverse downstream decisions.

Ongoing monitoring and former PEPs

PEP screening cannot be an onboarding-only check. A customer can be appointed after the relationship begins; a beneficial owner can change; a relative or associate can enter scope; and an officeholder can leave a function while residual influence remains.

Resignation does not make a profile harmless, but “once a PEP, always a PEP” should not replace assessment. FATF supports a risk-based approach to former PEPs.

In the EU, Directive (EU) 2015/849 requires obliged entities to consider the continuing risk for at least 12 months after a person ceases to hold a prominent public function and until the person is deemed to pose no further PEP-specific risk. Regulation (EU) 2024/1624 retains a minimum 12-month concept when it applies from 10 July 2027.

An exit review can consider the seniority and duration of the function, continuing influence, links to successors, control over assets or entities, the nature of the customer relationship, activity since leaving office, and credible public information. Record why enhanced measures continue, change, or end.

How to evaluate PEP screening software

Ask vendors to demonstrate the operating evidence, not only the size of a list.

Scope and provenance

  • Which countries, public bodies, international organizations, family members, and associate relationships are covered?
  • Are underlying functions, dates, relationships, and sources visible?
  • How are corrections, conflicts, removals, and former status handled?
  • Are vendor tiers defined and versioned?

Matching and resolution

  • How are aliases, native scripts, transliteration, compound names, and reordered tokens handled?
  • Can thresholds vary by population and risk?
  • Does the response separate match confidence from PEP risk?
  • Can reviewers see positive, negative, and missing attributes?

Ongoing operations

  • What event triggers a rescreen?
  • How are new and changed records distinguished from repeated records?
  • Can prior false positives be safely reused without broad suppression?
  • Are source time, ingestion time, rule version, and decision history retained?

Governance and integration

  • Can a business route possible and confirmed matches differently?
  • Are senior approval, evidence requests, reviews, and overrides recorded?
  • Can the system export an audit trail and support correction or deletion duties?
  • Does testing report recall, precision, unknowns, and performance by segment?

Common PEP screening mistakes

Treating every candidate as a confirmed PEP

A name match is only the beginning. Resolve identity and legal scope before applying the conclusion.

Treating every PEP as criminal

PEP controls address exposure to potential abuse of public function. Status alone is not suspicion, guilt, or a reason for blanket rejection.

Assuming PEP 1–4 is the law

Tiering can help operations, but the public function and applicable definition control the legal assessment.

Screening only the customer name

Relevant beneficial owners, representatives, family members, or close associates may be missed if the policy never defines and collects them.

Buying data without owning policy

No data source decides risk appetite, senior approval, evidence sufficiency, monitoring intensity, or the final customer decision.

Clearing a PEP automatically after a fixed date

Former status requires continuing-risk assessment. A minimum period is not automatically the end of risk.

Measuring only alert reduction

Fewer alerts can mean better matching or more missed PEPs. Pair workload measures with representative recall tests and quality sampling.

Where Didit fits

Didit lists AML Screening at $0.20 per check and Ongoing AML Monitoring at $0.07 per user per year. Transaction Monitoring is a separate product line, while the Workflow Orchestrator is listed as free. Current module rates are on the pricing page.

Those canonical facts do not establish a particular PEP source, tier model, matching threshold, update cadence, or automatic decision. Evaluate those details against the questions above and current product documentation. The organization using the system remains responsible for its screened population, match resolution, enhanced due diligence, approvals, customer decisions, records, and reporting duties.

Frequently asked questions

What is a politically exposed person?

A PEP is an individual who is or has been entrusted with a prominent public function. The precise functions and treatment come from applicable law; FATF examples exclude middle-ranking and more junior roles.

Is being a PEP evidence of a crime?

No. FATF says PEP requirements are preventive and should not be interpreted to mean that all PEPs are involved in criminal activity.

What does RCA mean in PEP screening?

RCA commonly means relatives and close associates. It is operational shorthand; the legally relevant family-member and close-associate definitions vary by jurisdiction.

Are PEP levels 1–4 defined by FATF?

No. Four-level models are provider or policy conventions. Review the underlying function, country, organization, relationship, and dates instead of relying on the number alone.

Does a PEP match require automatic rejection?

No. A candidate first needs identity and scope resolution. A confirmed PEP then receives the measures and risk assessment required by applicable law and policy. Status alone is not a criminal finding.

How often should PEP screening run?

There is no single frequency for every relationship. A defensible program screens at required lifecycle points and responds to source, customer, ownership, and activity changes.

How long does former PEP status last?

FATF supports a risk-based assessment rather than a universal lifetime label. Some laws set minimum periods; the EU framework uses at least 12 months and continues measures until the specific PEP-related risk no longer exists.

Primary references

PEP screening works when it preserves the distinction between identity, political exposure, and customer risk. Define the right population, resolve the person and relationship, make source evidence visible, apply proportionate enhanced measures, and keep monitoring changes without turning a preventive control into an accusation.

Infrastructure for identity and fraud.

One API for KYC, KYB, Transaction Monitoring, and Wallet Screening. Integrate in 5 minutes.

Ask an AI to summarise this page
PEP Screening: Definitions, Scope, and Monitoring