PEP Screening: How to Build a Defensible Politically Exposed Persons Program
The FATF definition, Tier-1 vs Tier-2 vs RCAs, where the data actually comes from, refresh cadence that holds up under audit, and the documentation pattern that has carried compliance teams through Mutual Evaluations.
PEP screening is the part of AML that most reliably exposes whether a compliance program is real or theatre. Sanctions screening is binary and well-tooled. KYC document collection is procedural. PEP screening, by contrast, requires a defensible definition, a data sourcing strategy, an enhanced-due-diligence workflow that actually triggers, and an audit trail that survives a Mutual Evaluation. Programs that paper over those four pieces are the ones that show up in FATF MER findings.
The FATF definition, precisely
FATF Recommendation 12 defines a Politically Exposed Person as "an individual who is or has been entrusted with a prominent public function." The recommendation distinguishes domestic PEPs (currently or formerly entrusted with prominent public functions in the country of the financial institution), foreign PEPs (the same in another country), and PEPs in international organisations. The 2012 revision elevated domestic PEPs to mandatory enhanced due diligence — pre-2012 they were a risk-based judgment call.
A "prominent public function" is illustrative, not exhaustive: heads of state and government, senior politicians, senior government, judicial, or military officials, senior executives of state-owned corporations, important political party officials. The list is intentionally non-exhaustive because national variation matters — a deputy minister in a country of 500,000 carries different exposure than the same title in a country of 80 million.
The Wolfsberg Group practical framework
In practice, most banks implement PEP screening using the Wolfsberg Group's tiered framework. Tier 1: heads of state, ministers, members of supreme courts, members of central bank boards, ambassadors, military flag officers, members of governing boards of international organisations. Tier 2: subnational politicians at the state/province level, senior officials of state-owned enterprises, ranking members of major political parties. Tier 3 (sometimes split out): municipal politicians, mid-tier judicial officials.
The tiering matters because it sets enhanced-due-diligence intensity. Tier 1 mandates senior-management approval before establishing the relationship, source-of-wealth and source-of-funds inquiry, and ongoing enhanced monitoring. Tier 2 typically gets the same EDD intensity for "high-risk" applications and risk-based monitoring otherwise. Tier 3 is where most "risk-based" judgment lives in a defensible program.
RCAs — Relatives and Close Associates
FATF Recommendation 12 explicitly extends the PEP regime to family members and close associates. "Family members" is broadly construed: spouses, children and their spouses, parents, siblings. "Close associates" is the harder definition — typically business partners, beneficial owners of jointly-held entities, and persons who hold influence over the PEP in a way that creates corruption exposure.
In FATF Mutual Evaluation Reports, missed RCA exposure is one of the most consistently cited Recommendation 12 deficiencies. The pattern is the same in 60%+ of MERs: the bank screened the named applicant, who was clean, and missed that the applicant was the adult child of a Tier-1 PEP. The defensible posture is to enumerate every UBO and director, screen each one as a potential PEP and as a potential RCA, and document the basis for both findings.
Where the PEP data actually comes from
Three sourcing strategies dominate the market. First: commercial PEP databases — Refinitiv WorldCheck, Dow Jones RDC, LexisNexis, the legacy enterprise vendors. Coverage is broad (5–10 million records including RCAs and historic entries) but with patchy freshness on subnational and SOE entries, and licensing terms that limit how the data can be cached or re-distributed.
Second: open-data graphs — Wikidata is the canonical example. Wikidata's structured person + position records cover the vast majority of Tier-1 PEPs globally with citation provenance for each claim, and the OpenSanctions PEP Index curates a deduplicated, normalized view. Coverage on Tier-2 drops outside OECD members but is improving rapidly.
Third: hybrid in-house — start with the open-data spine, augment with targeted commercial coverage where the open graph is thin (typically subnational officials in non-OECD jurisdictions and SOE executives), and maintain an internal "known PEP" register for repeated counterparties. This is the pattern most modern compliance teams converge on after two or three audit cycles.
Refresh cadence — the audit-defensible number
There is no FATF-prescribed refresh cadence. The defensible posture is: pick a cadence that matches risk, document the rationale, and adhere to it. The market consensus that survives audit is weekly screening for high-risk relationships (private banking, correspondent banking, MSBs servicing high-PEP-density corridors), monthly for standard retail and SME, and daily on any SDN delta event because OFAC and the PEP graphs are increasingly co-publishing changes.
The dangerous pattern is "screen at onboarding only" — a customer is Tier-1 clean in 2023 and becomes a designated PEP in 2025, and the bank never re-runs. Most MER findings under Recommendation 12 trace back to this gap.
False positives in PEP screening
PEP false-positive rates are typically lower than sanctions false positives because PEP records carry richer attributes (position, country, dates served, photo where available). The dominant FP source is name collision in common-name jurisdictions and historic-PEP-cleared accounts that match new entries. Cross-reference against the candidate's date of birth, nationality, and known business address, then route ambiguous matches to a documented disposition review.
The audit trail that holds
The single most consequential element of a defensible PEP program is documentation. Every onboarding decision should record: who was screened, against which dataset version, with what fuzzy parameters, what candidate matches were returned, who disposed each candidate, what rationale they recorded, and what enhanced measures were triggered. The artifact a regulator asks for in an exam is the audit trail, not the database.
“Financial institutions should be required, in relation to foreign politically exposed persons (PEPs), to put in place appropriate risk-management systems to determine whether a customer or beneficial owner is a politically exposed person.”