Few areas of anti-money laundering compliance generate as much operational friction, and as much regulatory attention, as politically exposed persons, commonly known as PEPs. The logic is straightforward: individuals entrusted with prominent public functions have greater opportunity to be involved in bribery, corruption, and the laundering of the proceeds. The execution is anything but straightforward. There is no single global list of PEPs, the category extends to family members and close associates, and the line between diligence and friction is easy to cross. For fintechs onboarding customers at scale, PEP screening is where regulatory expectation and customer experience collide most directly.

This guide is written for compliance professionals, founders, and product leaders at fintechs, payment firms, and digital asset businesses. It explains what a PEP is, what regulators expect you to do about it, how the rules are evolving in 2026, and where programs most often break down. It is general information, not legal advice; specific obligations depend on your jurisdiction, licence, and risk profile, and should be confirmed with qualified counsel or your regulator.

What is a politically exposed person?

The Financial Action Task Force (FATF), which sets the global AML standard, defines a PEP as an individual who is or has been entrusted with a prominent public function. The concept is not an accusation of wrongdoing. Being a PEP is a risk indicator, not a finding of guilt. It signals that a relationship may warrant closer scrutiny because of the position the person holds and the influence and access that come with it.

Prominent public functions typically include heads of state and government, senior politicians, senior government, judicial, or military officials, senior executives of state-owned enterprises, and important political party officials. The definition deliberately focuses on senior roles; it is not meant to capture middle-ranking or junior individuals.

The categories of PEP, and the people around them

Foreign PEPs

A foreign PEP holds a prominent public function in another country. Under FATF Recommendation 12, foreign PEPs always warrant enhanced due diligence; the requirement is mandatory rather than risk-based. This is the highest-scrutiny category because the combination of foreign jurisdiction and public power raises the corruption and laundering risk.

Domestic PEPs

A domestic PEP holds a prominent public function within your own country. FATF and, increasingly, national law require firms to identify domestic PEPs and to apply enhanced measures where the relationship is higher risk. The treatment is risk-based rather than automatically mandatory, but the expectation to identify and assess them is firm.

International organization PEPs

This category covers individuals who hold or have held a senior role in an international organization, such as directors, deputy directors, and members of a governing board. As with domestic PEPs, enhanced measures apply on a risk-sensitive basis.

Relatives and close associates (RCAs)

The obligation does not stop at the individual. Family members, such as spouses, partners, children, and parents, and known close associates who have business or other close ties, fall within scope because they can be used to hold or move assets on a PEP’s behalf. RCAs are frequently the hardest part of screening, because the relationships are not always disclosed or easy to establish. Identifying beneficial owners and connected parties is closely related to the customer diligence covered in our KYC verification guide.

Why PEP screening matters for fintechs

PEP status intersects with almost every other financial-crime control. A PEP relationship raises the baseline risk of the customer, which feeds the risk rating that drives the intensity of monitoring, a link we explore in our guide to AML customer risk assessment and risk-based scoring. It overlaps with sanctions exposure, since senior officials are more likely to appear on, or become subject to, restrictive measures, a dynamic we cover in our sanctions screening guide. And it shapes ongoing surveillance, because a PEP’s transactions may deserve a lower alerting threshold than a comparable non-PEP customer.

For fintechs specifically, the tension is scale. A firm onboarding thousands of customers a week cannot manually investigate every possible match, yet cannot afford to miss a genuine PEP either. Getting the balance wrong in one direction creates regulatory risk; getting it wrong in the other buries analysts in false positives and drives away legitimate customers.

What enhanced due diligence actually requires

When a customer is confirmed as a PEP who warrants enhanced due diligence, regulators generally expect three measures beyond standard onboarding.

The first is senior management approval to establish, or continue, the business relationship. The decision to take on PEP risk should be made deliberately and by someone with the authority and accountability to own it, not left to a front-line default.

The second is establishing the source of wealth and source of funds. The firm should take reasonable measures to understand how the customer accumulated their overall wealth and where the specific funds involved in the relationship come from. This is the control most directly aimed at detecting proceeds of corruption, and it is also the one examiners scrutinize most closely.

The third is enhanced ongoing monitoring. PEP relationships should be subject to more frequent and more sensitive review than standard customers, so that unusual activity is caught and the risk assessment stays current as circumstances change.

The regulatory backdrop in 2026

The global baseline remains FATF Recommendations 12 and 22, which extend PEP obligations from banks to a wider set of financial institutions and to designated non-financial businesses and professions. Around that baseline, the European framework is consolidating. Regulation (EU) 2024/1624, the centrepiece of the EU’s new AML package, expands and clarifies the scope of PEP rules, including in relation to regional and local officials and to family members and associates, and aims to harmonize how these rules are applied across member states. The bulk of the regulation applies from July 2027, giving firms a defined runway to prepare.

Institutionally, the EU’s Anti-Money Laundering Authority (AMLA), based in Frankfurt, is standing up its operations and is expected to drive greater consistency in supervision and expectations over time. A practical detail worth tracking is that member states, and the Commission, publish lists of the specific prominent public functions that qualify within their jurisdiction, which helps firms translate a broad definition into concrete screening criteria. For a wider view of how regulatory technology is reshaping these obligations, see our overview of RegTech in financial services.

Where PEP programs break down

Even well-resourced firms struggle with a recurring set of operational problems.

There is no official global PEP list. Unlike sanctions, where authorities publish definitive lists, PEP status is inferred and maintained by commercial data providers with varying methodologies, coverage, and update frequencies. The quality of your screening is only as good as the quality and freshness of the data behind it.

False positives dominate. Common names, transliteration differences, and broad matching logic generate large volumes of possible matches, most of which are not the person in question. Poorly tuned matching turns PEP screening into an alert factory that exhausts analysts and slows onboarding.

Declassification is a judgement call. When a person leaves office, they do not automatically stop being a risk. Many firms apply a risk-based approach to how long enhanced measures continue after a person steps down, rather than treating status as switching off overnight. The “once a PEP, always a PEP” instinct is safer than an abrupt reset, but it must be balanced against proportionality.

RCAs are hard to find. Relationships to family members and close associates are often undisclosed, and establishing them reliably at scale is one of the genuine limits of automated screening.

Data ages quickly. Political roles change constantly. A screening result that was accurate at onboarding can be stale within months, which is why periodic rescreening against refreshed data matters as much as the initial check.

Building a defensible PEP screening program

A credible program is less about any single tool and more about a coherent set of decisions, documented and consistently applied. The checklist below captures the questions a compliance leader should be able to answer.

Element Question to resolve Why it matters
Definition Which functions do we treat as PEPs, using which lists? Turns a broad definition into consistent, testable criteria.
Data Whose PEP data do we rely on, and how fresh is it? Screening quality depends entirely on data quality.
Matching How is match logic tuned to balance coverage and false positives? Determines analyst workload and onboarding friction.
EDD What source-of-wealth and approval steps trigger, and when? The core control regulators examine.
Monitoring How often do we rescreen and re-review PEP relationships? Keeps the risk picture current as roles change.
Governance Who approves PEP relationships and owns the record? Demonstrates deliberate, accountable risk-taking.

Frequently asked questions

Is being a PEP illegal or a reason to refuse service? No. PEP status is a risk indicator, not a prohibition. Many PEPs are entirely legitimate customers. The obligation is to apply proportionate, enhanced scrutiny, not to de-risk automatically, and blanket refusal can itself attract regulatory criticism.

How is PEP screening different from sanctions screening? Sanctions screening checks against binding, published lists and a match generally requires action. PEP screening checks against inferred, commercially maintained data and a match triggers enhanced due diligence and a risk judgement, not an automatic block.

When does someone stop being a PEP? There is no universal switch-off. Firms typically apply a risk-based approach after a person leaves office, continuing enhanced measures for as long as the residual risk justifies it rather than resetting immediately.

Do we need to screen for relatives and close associates? Yes, within reason. RCAs are in scope because they can be used to hold or move assets for a PEP, though establishing these relationships reliably is one of the harder parts of the process.

Conclusion

PEP screening sits at the intersection of onboarding, sanctions, monitoring, and reputational risk, which is exactly why it is difficult and why regulators care about it. Done well, it is proportionate: it applies the heaviest scrutiny where the risk is highest, keeps its data current, and documents deliberate decisions about who the firm chooses to serve and why. Done poorly, it either lets genuine risk through or drowns the business in false positives. For fintechs, the goal is not to avoid PEPs but to manage them with a program that a regulator would recognize as thoughtful, consistent, and defensible.

If your team is building or reviewing its PEP and enhanced due diligence controls, the specialists at DanuSoft can help you align screening, source-of-wealth procedures, and ongoing monitoring with your risk profile and regulatory obligations.

This article is provided for general information only and does not constitute legal or compliance advice. Regulatory requirements vary by jurisdiction and change over time; confirm your specific obligations with qualified counsel or your regulator.