PEP screening is a risk-based compliance control required under FATF standards and enforced through U.S. examiner guidance rather than a single statutory checklist. In practice, that means every institution screens at onboarding and beyond, and any confirmed politically exposed person gets documented enhanced due diligence with dated senior management sign-off. Get the data quality and screening cadence wrong, and the EDD file behind it won’t hold up under review.
TL;DR:
- PEP screening must be risk-based, covering foreign PEPs with mandatory measures and domestic or international-organization PEPs with tailored policies.
- Accurate classification of family members, close associates, and former PEPs, including risk assessment and clear look-back periods, is essential for compliance.
- A consistent screening schedule includes onboarding, periodic reviews, and trigger events, with delta screening preferred if properly documented for efficiency.
- Documenting source of funds, wealth, and senior management approval is crucial for PEP-related enhanced due diligence files.
- Failing to enforce policy discipline, such as timely updates and thorough documentation, causes most PEP program deficiencies rather than policy design flaws.
Table of Contents
- Regulatory Baseline for PEP Screening Requirements
- Who Actually Counts as a PEP
- Building a Defensible Screening Schedule
- What Enhanced Due Diligence Actually Requires
- Tuning Your Screening Engine to Cut False Positives
- Program Governance Examiners Look For
- An Illustrative Screening-to-EDD Workflow
- Why Most PEP Programs Fail on Discipline, Not Design
- Sources
- FAQ
Regulatory Baseline for PEP Screening Requirements
There is no single U.S. statute that spells out PEP screening requirements the way, say, OFAC list-checking is mandated. Instead, expectations are stitched together from international standards and supervisory guidance, and examiners hold institutions to that combined standard whether or not it’s written into a single rule.
FATF sets the international floor: Recommendation 12 requires enhanced due diligence for foreign PEPs and a risk-based approach for domestic and international-organization PEPs, meaning not every domestic PEP automatically triggers the same intensity of review. U.S. guidance builds on that floor in a few key places:
- The FFIEC BSA/AML Manual frames PEP identification and EDD as an examiner expectation inside your broader customer due diligence program, not a bolt-on requirement.
- A joint statement from federal banking agencies and FinCEN confirms institutions may decide for themselves whether and how to flag PEP status at onboarding, as long as the underlying CDD/EDD obligations are met.
- FinCEN advisories, including the PEP facilitator advisory, push firms to document why someone was categorized as a PEP, not just flag the name and move on.
The upshot: your written policy, not a government list, is what examiners test against.
Who Actually Counts as a PEP
PEP eligibility criteria break into three broad categories, and confusing them is one of the more common program gaps. Foreign PEPs (heads of state, senior foreign officials, military brass) get mandatory enhanced measures under FATF. Domestic PEPs and international-organization PEPs get a risk-based approach instead, meaning your policy sets the intensity based on the individual’s actual risk profile, not a blanket rule.
Your definitions also need to reach beyond the individual:
- Family members: spouses, parents, children, and their spouses are the typical baseline, though your policy should state the exact scope.
- Known close associates: business partners or people with joint beneficial ownership tied to the PEP.
- Former PEPs: FATF and the FCA’s guidance both note that PEP status is preventive, not punitive, and that risk from a former official typically fades over time. Your policy should set a defined look-back period rather than treating “once a PEP, always a PEP” as permanent.
Building a Defensible Screening Schedule
Steps for PEP screening start well before onboarding closes and don’t stop once an account is open. A defensible cadence typically hits three touchpoints:
- Onboarding screening. Every new customer, plus beneficial owners and authorized signatories, gets checked before the relationship goes live.
- Periodic re-screening. Frequency should track the customer’s risk rating; higher-risk relationships get reviewed more often than a low-risk retail account.
- Trigger-based screening. A change in ownership, a new signatory, an adverse media hit, or a jurisdiction change should all kick off a fresh check outside the normal cycle.
One design decision matters more than people expect: batch versus delta screening. Batch screening re-runs your entire customer base against updated watchlists on a schedule. Delta (or continuous) screening checks only what’s changed since the last run, which is far lighter operationally but only defensible if you’ve written down exactly what counts as a “material change” that triggers it.
Pro Tip: Maintain a documented “no-match” registry for names your team has already investigated and cleared. Without one, the same false positive gets re-investigated every cycle, burning analyst hours on a decision you already made.
What Enhanced Due Diligence Actually Requires
Once a customer is confirmed as a PEP, the file needs to show more than a checked box. Document requirements for PEP screening at this stage typically include:
- Source of funds verification. Documentary proof tracing the specific funds moving through the account.
- Source of wealth narrative. A written explanation of how the person accumulated their overall wealth, not just this transaction.
- Calibrated transaction monitoring. Rules and thresholds tuned to the customer’s expected activity.
- Senior management approval. A named, dated sign-off, not a system-generated approval stamp.
A complete file also includes analyst disposition notes explaining why a decision was made, along with the underlying screening logs and alert history. Institutions that track EDD completion rate as a management metric tend to catch missing files before an examiner does, since incomplete EDD documentation is one of the most frequently cited findings in supervisory reviews. Retention matters too: keep these records retrievable, not archived somewhere nobody can pull them quickly, for the full period your recordkeeping policy requires, generally five years from account closure or the transaction date under standard BSA recordkeeping practice.
Tuning Your Screening Engine to Cut False Positives
Most of the operational pain in PEP screening guidelines comes down to noise. Common names generate matches against unrelated public figures constantly, and a program drowning in false positives eventually starts rubber-stamping alerts, which is worse than having no program at all.
Wolfsberg Group guidance recommends a minimum data set to fight this: name variants and known aliases, date or year of birth, nationality, country of political exposure, and the specific role with its appointment and, if applicable, departure dates. Screening on name alone against a watchlist entry with no other identifiers is close to guaranteed to over-flag.
- Test fuzzy-matching thresholds periodically against known PEP name sets, and log every threshold change along with its effect on alert volume.
- Use more than one PEP data vendor where risk warrants it, and document the due diligence behind vendor selection, including how frequently each source updates.
- Negotiate and record vendor SLAs on data refresh timing, since a stale PEP database is a gap examiners will ask about directly.
Pro Tip: Run your fuzzy-match threshold tests against transliterated names, not just English spellings. Cyrillic, Arabic, and Chinese name variants are where most matching engines quietly fail.
Program Governance Examiners Look For
A written PEP screening policy needs a delegated approval matrix (who can approve EDD at which risk tier), a defined annual review cycle, and a version history showing the policy has actually been updated as guidance shifts.
Management information should include EDD completion rates, the count of dispositions still open past your service-level target, total alert volume, and your false-positive ratio over time. Falling short on any of these is exactly where exams go sideways: missing EDD files and undocumented senior approvals remain among the most frequently cited PEP-related findings, and both are fixable with better recordkeeping discipline rather than a bigger budget. A clear role-based access control structure around who can view, approve, or override PEP dispositions also closes off a common audit gap around segregation of duties.
An Illustrative Screening-to-EDD Workflow
A workable version of this process typically runs: onboarding data capture, automated screening against watchlists, analyst disposition of any hits, EDD completion for confirmed matches, then senior management approval before the account activates fully.
Supporting documentation worth maintaining at each stage:
- A centralized PEP register tracking every confirmed match and its current risk tier.
- Screening logs and dated disposition records for every alert, cleared or escalated.
- An EDD checklist tied to each confirmed PEP file, showing exactly which documents are present and which are outstanding.
Institutions that run PEP and sanctions screening through the same underlying screening process tend to produce a single, coherent evidence package for exams instead of two disconnected trails an examiner has to reconcile by hand.
Why Most PEP Programs Fail on Discipline, Not Design
Most PEP screening programs don’t fail because the policy is wrong. They fail because nobody enforces the discipline the policy describes: dispositions logged three weeks late, EDD files missing the one document an examiner asks for first, thresholds nobody has retested since the vendor’s last database update.

The conventional advice treats PEP screening like a list-matching problem, but the harder work is judgment calls. FATF and the FCA are explicit that PEP status is preventive, not a presumption of guilt, which means a domestic PEP with a modest, well-documented source of wealth may warrant far less scrutiny than a foreign PEP with opaque fund flows. Institutions that apply the same heavy EDD template to every match regardless of actual risk are burning analyst time on low-risk relationships while genuinely risky ones wait in a backlog.
If you take one thing from this, prioritize data quality over software spend. A cheap screening tool fed with full names, dates of birth, and nationality will outperform an expensive one fed with names alone. Fix your intake fields before you fix your vendor contract.
— Harold
Sources
- FATF Guidance: Politically Exposed Persons (Recommendations 12 and 22)
- BSA/AML Manual — Risks Associated with Money Laundering and Terrorist Financing: Politically Exposed Persons
- Wolfsberg Group — PEP Screening guidance
FAQ
Who is not considered a PEP?
Ordinary customers with no current or past senior government, military, judicial, or state-enterprise role, and no close family or business ties to someone who holds one, fall outside PEP eligibility criteria. Junior or mid-level officials are also generally excluded unless your institution’s risk-based policy pulls them in.
Is a PEP automatically a high-risk customer?
Not automatically. FATF and FCA guidance both stress that PEP status is preventive rather than a presumption of wrongdoing, and each PEP’s actual risk should be assessed and documented individually rather than defaulted to high risk across the board.
How is PEP screening done?
Screening runs customer names, and typically beneficial owners and signatories, against PEP and watchlist databases at onboarding, on a periodic schedule, and after trigger events like ownership changes, with any match reviewed by an analyst and documented before it’s cleared or escalated to EDD.
Who is considered a foreign politically exposed person?
A foreign PEP is someone who holds or has held a prominent public function in another country, such as a head of state, senior politician, senior judicial or military official, or senior executive of a state-owned enterprise, and foreign PEPs require enhanced due diligence under FATF Recommendation 12 regardless of an institution’s own risk-based tiering.