Screening for Politically Exposed Persons is a required element of AML compliance for fintechs. Here is how to build a PEP screening program that satisfies regulatory requirements and manages the risk PEPs present.
PEP Screening: How to Build a Compliant Program
PEP screening — the process of identifying whether customers or their close associates hold or have held prominent public positions — is a required element of AML compliance for fintechs. Customers who qualify as Politically Exposed Persons present elevated money laundering risk and must be subject to Enhanced Due Diligence.
This article covers how to build a PEP screening program — what to screen, when to screen, how to manage matches, and what a compliant ongoing monitoring posture looks like for PEP relationships.
What PEP Screening Is
PEP screening involves checking customer identity information against databases of known Politically Exposed Persons — databases that compile information about individuals who hold or have held senior government, military, judicial, and political party positions globally, as well as their family members and close associates.
Unlike sanctions screening — where a match requires mandatory blocking — a PEP match triggers Enhanced Due Diligence, not automatic rejection. The regulatory requirement is to know that you have a PEP customer and to manage that relationship with heightened scrutiny. Most PEP relationships can be accepted and maintained — but they require more thorough review and more intensive ongoing oversight than standard-risk customer relationships.
When PEP Screening Must Occur
PEP screening must occur at customer onboarding — before the customer relationship is established. It should also occur on an ongoing basis, because customers who were not PEPs at onboarding may become PEPs later through appointment to a public position, and the status of existing PEP customers changes over time — they may leave office, their risk profile may evolve, or the time period warranting elevated scrutiny following their departure from public life may expire.
Ongoing PEP screening is typically accomplished through periodic re-screening against updated PEP databases and through integration of PEP status into your broader customer risk monitoring program.
What PEP Databases Cover
Commercial PEP databases aggregate information from government records, news sources, and official rosters of public officials globally. Coverage varies by database provider — the depth of coverage of senior officials in smaller countries, the recency of updates, and the inclusion of family members and close associates differ significantly across vendors.
Key factors for evaluating PEP database coverage include global coverage breadth, update frequency, inclusion of family and close associate relationships, and the definition of "PEP" used by the database — some databases apply broader or narrower criteria than your program may require.
How to Manage a PEP Match
When screening produces a PEP match, the match must be reviewed to confirm it is a true positive — that the customer is actually the PEP in the database, not a different person with a similar name. This is the false positive review step, and it is important because PEP names may be common names that match multiple people.
If the match is confirmed as a true positive, Enhanced Due Diligence must be initiated before onboarding proceeds. EDD for PEPs includes collecting source of wealth and source of funds documentation, conducting more thorough identity verification and background research, obtaining senior management approval for the relationship, and implementing enhanced ongoing monitoring.
Building Your PEP Screening Policy
A compliant PEP screening policy should define which PEP categories are in scope for your program, the PEP database or data sources used, the screening process at onboarding and on an ongoing basis, the process for false positive review and clearing, the EDD requirements triggered by a confirmed PEP match, senior management approval requirements, the frequency of periodic re-screening, and the process for managing PEPs who exit public office.
Frequently Asked Questions
Do I need to screen for domestic PEPs or only foreign PEPs?
Both. US AML regulations require screening for foreign PEPs and, under a risk-based approach, domestic PEPs as well. For fintechs serving a US customer base, domestic PEP screening is increasingly expected — particularly for senior federal and state officials. For an international customer base, both domestic and foreign PEP screening is standard practice.
What if a customer discloses their own PEP status?
Customer self-disclosure of PEP status is a useful data point but does not substitute for screening. Self-disclosure must be noted in the customer's file and should trigger EDD procedures, but screening should occur regardless of whether the customer disclosed their status. Relying solely on customer disclosure creates gaps when customers fail to disclose.
How long does EDD apply after a PEP leaves office?
Most AML frameworks require continued elevated scrutiny for a period after the PEP leaves their public position — commonly 12 to 24 months, though longer periods may be appropriate for very senior positions or where other risk factors remain. Your PEP program policy should specify the off-boarding criteria for EDD and how the transition back to standard monitoring is documented and approved.
How ComplyOne Helps
ComplyOne helps fintechs design and implement PEP screening programs — from database selection and policy development through EDD procedures and ongoing monitoring — through advisory services, compliance technology, or both.
Talk to the ComplyOne team to get started.
The information in this article is for general educational purposes and does not constitute legal or regulatory advice. Consult a qualified compliance professional for guidance specific to your situation.