Skip to main content
Category: AML and KYC

Politically Exposed Person

Also known as: PEP, Senior Foreign Political Figure
Simply put

A Politically Exposed Person (PEP) is someone who holds or has held a prominent public position, such as a role in government, a political party, or an international organization. Because these positions can be abused, PEPs are considered more susceptible to involvement in bribery or corruption. The label can also extend to close business associates and family members of such individuals.

Formal definition

A Politically Exposed Person (PEP) is an individual who is or has been entrusted with a prominent public function, whether in government, a political party, or an international organization; the term is commonly applied in the financial industry particularly to foreign individuals holding such functions. PEPs are treated as elevated money laundering and terrorist financing risk because their positions can be abused for bribery or corruption, and the designation may extend to close business associates and family members. Handling of PEPs is addressed under AML/BSA frameworks, including FATF Recommendations 12 and 22 and the FFIEC BSA/AML examination framework; these frameworks govern PEP identification and enhanced due diligence and are distinct from PCI DSS and related payment security standards.

Why it matters

Politically Exposed Persons present elevated money laundering and terrorist financing risk because the prominent public functions they hold or have held can be abused for bribery or corruption. Financial institutions that fail to identify PEPs and apply appropriate scrutiny may inadvertently process the proceeds of corruption, exposing themselves to regulatory, legal, and reputational consequences. Because the designation can extend to close business associates and family members, the risk is not always visible from a single name check, and institutions must consider relationships and beneficial ownership rather than relying on job titles alone.

The PEP concept is embedded in AML/BSA frameworks, including FATF Recommendations 12 and 22 and the FFIEC BSA/AML examination framework, which govern how institutions identify PEPs and apply enhanced due diligence. These frameworks are distinct from PCI DSS and related payment security standards; PEP handling is an anti-money-laundering obligation, not a payment card data protection control. Compliance teams should confirm specific obligations against the current published guidance, since interpretation, scope, and expectations can vary by jurisdiction and over time.

It is important to note that PEP status is a risk indicator, not an accusation of wrongdoing. The designation is intended to trigger additional scrutiny and ongoing monitoring rather than to categorically bar an individual from financial access. Screening approaches carry trade-offs: overly broad matching can generate false positives and unnecessary friction, while narrow criteria may miss associates or family members who fall within the intended scope.

Who it's relevant to

AML/BSA Compliance Officers
Compliance officers own the policies and procedures for identifying PEPs and applying enhanced due diligence. They map PEP handling to applicable frameworks such as the FFIEC BSA/AML examination framework and FATF Recommendations 12 and 22, calibrate screening to balance coverage against false positives, and document the rationale for risk decisions.
Financial Institution Onboarding and KYC Teams
Onboarding and Know Your Customer teams are typically the first line to detect PEP status, including the extension of the designation to close business associates and family members. They gather the information needed to assess relationships and beneficial ownership and escalate matches for enhanced review.
Fraud and Financial Crime Analysts
Analysts conducting ongoing monitoring use PEP status as one risk indicator among many. They investigate alerts, weigh false-positive and false-negative trade-offs in screening, and treat PEP designation as a trigger for additional scrutiny rather than as evidence of wrongdoing.
Regulatory and Examination Stakeholders
Examiners and regulatory liaisons assess whether an institution's PEP identification and enhanced due diligence practices align with applicable AML/BSA expectations. This work is distinct from payment security standards such as PCI DSS, and expectations may vary by jurisdiction and change over time.

Inside PEP

Definition and Scope
A Politically Exposed Person is an individual who holds or has held a prominent public function, along with their close family members and known close associates. The classification is used in anti-money laundering and sanctions-related due diligence rather than in PCI DSS, which governs the protection of cardholder data and sensitive authentication data. PEP screening is an out-of-scope concept for PCI DSS itself and belongs to AML/KYC compliance programs.
Categories of PEP
PEP frameworks commonly distinguish foreign PEPs, domestic PEPs, and persons entrusted with prominent functions by international organizations. Family members and close associates are treated as related exposure. The exact categories, thresholds, and definitions vary by jurisdiction and by the regulatory or card-brand rules that apply, so classification should be confirmed against the governing framework rather than assumed.
Risk Rationale
PEP status is treated as a risk indicator because the position may present a higher potential for involvement in bribery, corruption, or money laundering. PEP status is not in itself evidence of wrongdoing; it is intended to trigger enhanced scrutiny, not a presumption of guilt.
Enhanced Due Diligence (EDD)
When a customer is identified as a PEP, institutions typically apply enhanced due diligence, which may include senior management approval, source-of-funds and source-of-wealth inquiry, and closer ongoing monitoring. These measures are intended to help mitigate risk and do not guarantee detection of illicit activity.
Screening and Monitoring
PEP identification generally relies on screening against reference data sources at onboarding and on a periodic or event-driven basis thereafter. Screening carries known trade-offs, including false positives from name matching and false negatives from incomplete or outdated data; results depend on data quality and matching methodology.
Relationship to Payment Security Roles
PEP screening is most relevant to acquirers, payment processors, and merchant risk teams within their AML and merchant-onboarding obligations. It operates alongside, but is separate from, payment-data protection controls and fraud-detection controls, which address different risks.

Common questions

Answers to the questions practitioners most commonly ask about PEP.

Is a Politically Exposed Person the same as a criminal or someone who has committed financial crime?
No. PEP status is not an accusation of wrongdoing and does not imply that the individual has committed a crime. The designation reflects that a person holds or has held a prominent public function, which may present a higher potential risk of exposure to bribery or corruption. It is a risk-classification concept used to determine the level of due diligence applied, not a finding of guilt. Many PEPs never engage in any illicit activity, and treating the label as an allegation misapplies the term.
Does PEP screening belong to PCI DSS or the payment security standards?
No. PEP screening is an anti-money-laundering and sanctions/compliance concept governed by AML and counter-terrorist-financing regulation and by the internal risk policies of the obligated entity, not by PCI DSS, PA-DSS, the PCI Software Security Framework, PCI PIN, PCI P2PE, or PCI 3DS. Those PCI standards address the protection of cardholder data and sensitive authentication data, not customer identity risk classification. PEP obligations arise from a separate regulatory framework and should be confirmed against the applicable AML rules in the relevant jurisdiction.
How should an organization determine what level of due diligence to apply to a PEP?
Due diligence is typically applied on a risk-based basis, meaning the intensity of review is scaled to the assessed risk rather than applied uniformly. Enhanced due diligence measures are generally associated with higher-risk relationships. The specific measures, thresholds, and approval steps depend on the organization's AML policy and the requirements of the applicable regulator, so teams should map their procedures to the current obligations in their jurisdiction rather than assume a single global standard.
How do PEP designations relate to family members and close associates?
Many regulatory frameworks extend PEP considerations beyond the individual holding the public function to certain family members and close associates, on the basis that risk may be channeled through connected parties. The precise definitions of who is covered, and for how long after a person leaves office, vary by jurisdiction and by the organization's policy. Implementation should reference the specific definitions in the applicable regulation rather than a fixed universal list.
What are the practical limitations of automated PEP screening tools?
Screening against PEP lists and reference data can produce both false positives, where a customer matches a similar name but is not the listed person, and false negatives, where a relevant individual is not matched due to name variations, transliteration, incomplete data, or gaps in the reference source. Because of these trade-offs, matches generally require human review and adjudication, and the quality of screening depends on the data source, its update frequency, and the matching methodology. No screening process should be treated as guaranteeing complete or error-free identification.
How is PEP status typically maintained over the life of a customer relationship?
PEP status is not usually a one-time check at onboarding. Because a customer may acquire or lose a relevant public function over time, organizations commonly incorporate ongoing monitoring and periodic re-screening so that the risk classification stays current. How long PEP-related handling continues after an individual leaves a public function is determined by the applicable regulation and the organization's policy, which should be confirmed against the current published requirements rather than assumed.

Common misconceptions

PEP screening is a PCI DSS requirement.
PCI DSS governs the protection of cardholder data and sensitive authentication data, not customer due diligence. PEP screening derives from AML/KYC regimes and applicable regulatory or network rules, which are separate from PCI DSS. Readers should confirm obligations against the specific governing framework rather than assuming PCI DSS coverage.
Being classified as a PEP means the person is a criminal or is engaged in money laundering.
PEP status is a risk indicator based on holding a prominent public function, not evidence of wrongdoing. It is intended to trigger enhanced scrutiny and closer monitoring, which may help reduce risk but does not establish guilt.
A one-time PEP check at onboarding is sufficient.
PEP status can change over time, and screening data can be incomplete or outdated. Effective programs generally combine onboarding screening with periodic or event-driven re-screening and ongoing monitoring, while acknowledging false-positive and false-negative trade-offs.

Best practices

Maintain a clear, documented PEP definition and classification methodology that reflects the specific jurisdiction and regulatory or network rules that apply, and confirm it against the current governing framework rather than a fixed assumption.
Treat PEP status as a risk trigger for enhanced due diligence, including source-of-funds and source-of-wealth inquiry and appropriate senior management approval, rather than as grounds for automatic denial or a presumption of wrongdoing.
Apply ongoing and event-driven re-screening in addition to onboarding checks, since PEP status and reference data change over time.
Tune screening and name-matching to manage false-positive and false-negative trade-offs, and document the review process for handling potential matches.
Keep PEP and AML/KYC processes organizationally and procedurally distinct from PCI DSS cardholder-data controls, while coordinating shared customer and merchant risk information where appropriate.
Retain audit-ready records of PEP determinations, EDD steps, approvals, and monitoring decisions to demonstrate compliance with the applicable regulatory obligations.