PEP screening pitfalls that expose FinTech compliance teams

PEP

A politically exposed persons check (PEP check) sits among the most consequential controls in any AML compliance programme. Done well, it surfaces elevated risk before it becomes an institution’s problem.

According to RelyComply, done poorly – or treated as a one-off box-ticking exercise – it opens the door to regulatory censure, reputational harm and even the facilitation of corruption or money laundering.

RelyComply recently discussed PEP screening best practices and a guide for compliance teams.

While the stakes are widely understood, many institutions struggle to see where their own approach is falling short.

A PEP, or politically exposed person, is someone who holds or has held a prominent public function granting influence over public resources or policy. Typical examples include heads of state, senior ministers, members of parliament, high-ranking military officials, executives of state-owned enterprises, senior judges and central bank officials. Importantly, the definition also captures immediate family members and known close associates – individuals who carry elevated risk by proximity alone. Many institutions overlook this distinction.

Within AML and KYC frameworks, PEP screening is a mandatory risk management process. Individuals with access to public funds or policy influence present heightened bribery, corruption and money laundering risk. Under FATF recommendations, the EU’s 4AMLD and 5AMLD, and national regimes, firms must identify PEP customers and apply Enhanced Due Diligence (EDD) throughout the customer lifecycle, not merely at onboarding.

Effective screening rests on three pillars. First, data quality: screening is only as reliable as the lists behind it, so a reputable, frequently updated global PEP database with associate coverage and transliteration support is essential. Second, risk-based categorisation: a former local councillor and a serving foreign head of state demand very different scrutiny, so firms should tier PEP customers and calibrate controls proportionately. Third, ongoing monitoring: a customer who isn’t a PEP today may be one tomorrow, and FATF recommends at least a 12-month cool-down after leaving office, with many frameworks extending further.

Common failure points include siloed data, inconsistent thresholds between analysts, manual processes that buckle at scale, and neglecting close associates hidden behind shell companies and nominee structures. A robust KYB process mapping ownership and control is vital to closing that last gap.

Once a match is confirmed, EDD should cover independently corroborated source of wealth and funds checks, structured adverse media screening, risk-calibrated transaction monitoring, documented senior management sign-off and regular re-reviews. Regulators want to see the reasoning, not just the outcome.

At any meaningful scale, automation is unavoidable. Leading platforms aggregate multiple PEP sources, apply risk-weighted scoring, surface adverse media in context, generate audit-ready trails and cut false positives to combat alert fatigue. Configurability is critical – a rigid, one-size-fits-all system will either paralyse operations through over-flagging or create exposure by under-flagging.

PEP checks are no formality. They are among the most direct mechanisms institutions have for keeping corrupt funds out of the financial system. If your screening process was built around onboarding and hasn’t evolved since, it’s time to revisit it.

Read the full RelyComply post here. 

Read the daily FinTech news

Copyright © 2026 FinTech Global

Enjoying the stories?

Subscribe to our daily FinTech newsletter and get the latest industry news & research

Investors

The following investor(s) were tagged in this article.