How Compliance Teams Should Handle PEP Screening Matches on Relatives, Close Associates and Residual Risk

Every compliance team that screens customers against politically exposed person (PEP) databases will, at some point, receive a match.

Compliance Guide  ·  August 2026  ·  Compliance Operations

Every compliance team that screens customers against politically exposed person (PEP) databases will, at some point, receive a match.

The First Step: Confirming Identity, Not Confirming the Match

The most common error when a PEP screening match is returned is to treat the match as a problem to be confirmed, rather than a question to be investigated. This inversion leads to confirmation bias, where the compliance team works backward from the assumption that the customer is a PEP in order to justify the match result.

The correct starting point is to treat the match as a data point requiring verification. The screening system has returned a potential association. It has not established one.

Identity confirmation is the first gate. Before any classification decision is made, the compliance team needs to establish whether the individual returned by the screening system is, in fact, the customer sitting in front of them. This requires moving beyond the name field alone.

Date of birth verification is the primary tool. A match on name and date of birth to the same individual, confirmed against a reliable identity document, resolves the majority of routine matches. Where date of birth is absent from the screening record or the customer’s records, additional evidence becomes necessary. This may include nationality, address history, corporate directorships, previous names or aliases, and documented relationship information.

Documentary evidence should be obtained and retained. Passports, national identity cards and government-issued records all carry weight. Where the customer is a corporate entity, the equivalent confirmation involves beneficial ownership records, incorporation documents and, critically, the relationship chain between the entity and any identified PEP.

MemberCheck supports configurable matching thresholds that allow compliance teams to set the sensitivity of their screening parameters. Lower thresholds return more matches, including a higher proportion of false positives. Higher thresholds reduce noise but increase the risk of missing genuine matches. The appropriate threshold for a given organisation will depend on its risk appetite, customer base and regulatory expectations in its jurisdiction. Configurable thresholds are not a substitute for proper match investigation, but they are a foundational control that shapes how much investigation workload the team will face.

The identity confirmation step should produce one of three outcomes: confirmed match (the customer is the PEP), excluded match (the customer is not the PEP), or unconfirmed (insufficient evidence to resolve either way, requiring further steps).

Classifying the Match: Customer, Relative, Close Associate or Residual Risk

Once identity is confirmed, the classification decision follows. Under FATF Recommendation 12 and the accompanying guidance, the relevant categories are:

Domestic PEP : an individual who is or has been entrusted with a prominent public function by a domestic government.

Foreign PEP : an individual who is or has been entrusted with a prominent public function by a foreign government.

International organisation PEP : an individual who is or has been entrusted with a prominent function by an international organisation, such as a senior official of a major multinational corporation or a senior diplomatic role.

Relative of a PEP : as defined under FATF guidance, this includes parents, siblings, spouses and children, and may extend to in-laws and step-relations depending on jurisdiction-specific definitions.

Close associate of a PEP : FATF defines close associates as natural persons who are known to have a close business relationship with a PEP or who share a beneficial ownership of a legal arrangement with a PEP. The key qualifier is “close” and the relationship must be meaningful in the context of money laundering risk, not merely coincidental.

It is at the RCA level that most operational complexity arises. The distinction between a relative and a close associate matters because different jurisdictions apply different obligations and because the risk profile of each category differs in practice.

A relative of a PEP is not automatically a high-risk customer. The relationship alone does not create money laundering risk. The risk arises from the potential for the relative to be used as a conduit for funds that originate from the PEP’s position, or to obscure the beneficial ownership of assets held by the PEP. Compliance teams must assess what the relationship actually means operationally, not merely whether it exists.

Close associate classification requires more careful assessment. The phrase “known to have a close business relationship” is deliberately broad. In practice, compliance teams should consider whether the customer holds joint business interests with the PEP, serves as a director or shareholder in the same corporate structures, acts as the PEP’s legal representative, or has other documented transactional patterns that suggest a meaningful financial connection. Being a customer of the same bank as a PEP, or having attended the same university, does not constitute a close associate relationship under any reasonable interpretation of the standard.

Residual risk is a category that often goes unacknowledged in screening workflows. After the match has been investigated and the customer has been confirmed as neither the PEP nor an RCA, a residual question may remain about whether the nature of the match itself indicates elevated risk. A customer who shares a name and partial biographical data with a serious financial crime subject, even without a confirmed PEP connection, may warrant a higher baseline risk rating in their overall customer due diligence profile. This is not a PEP classification, but it is a legitimate risk consideration that should be documented and reviewed periodically.

Enhanced Due Diligence Obligations for PEPs and RCAs

When a customer is classified as a PEP, or as a relative or close associate of a PEP, enhanced due diligence (EDD) obligations apply. The word “enhanced” is often treated as a label. It is better understood as a set of specific operational requirements that increase the depth of the standard due diligence process.

Under FATF Recommendation 12, the core EDD obligations for PEP relationships include:

Approval from senior management before establishing or continuing the business relationship. This means the decision cannot sit entirely with a front-line compliance officer. The MLRO or an appropriately senior delegate must be involved.

Establishing the source of wealth and the source of funds. This is one of the most operationally demanding requirements. Source of wealth refers to the origin of the individual’s total assets. Source of funds refers to the specific funds involved in the transaction or relationship. For a PEP, this analysis must go beyond the standard questions applied to non-PEP customers. It must consider whether the individual’s public role creates opportunities for corrupt wealth accumulation, whether their business interests are consistent with their official position, and whether the funds in question originate from government contracts, regulatory approvals or other sources where a conflict of interest is plausible.

Enhanced ongoing monitoring. The business relationship must be subject to more frequent and more detailed transaction monitoring than would apply to a standard-risk customer. The monitoring scope should include the PEP’s known associates, beneficiaries and transaction counterparties where this information is available.

These obligations apply to foreign PEPs by default. For domestic PEPs, FATF Recommendation 12 requires that countries consider applying the same measures, reflecting the judgment that domestic public officials also present money laundering risk. Many jurisdictions, including Australia under the Anti-Money Laundering and Counter-Terrorism Financing Act 2006 and the United Kingdom under the Money Laundering Regulations 2017, apply PEP obligations to domestic and foreign PEPs alike. Organisations should confirm the specific scope of their domestic obligations with their legal counsel or the applicable regulator.

For relatives and close associates, the EDD obligations are broadly similar, but the risk assessment that precedes them requires additional judgment. A relative who has no financial relationship with the PEP, who earns a modest independent income and whose transactions are unremarkable presents a different risk profile to a close associate who holds a significant beneficial ownership stake in the same corporate group as the PEP. EDD is not applied uniformly. It is calibrated to the specific risk factors present in each case.

The Risk Acceptance Process

When EDD has been completed and the compliance team has sufficient information, a risk acceptance decision must be made. This decision determines whether the business relationship with the PEP or RCA customer can proceed, under what conditions, and with what ongoing obligations.

A risk acceptance decision is not simply a yes or no. It is a structured outcome document that records the assessment, the evidence examined, the risk factors identified, the mitigation measures applied, and the approval. It is a record that the MLRO will rely on if the relationship is later questioned by a regulator, an auditor or an internal compliance review.

The decision should be made at an appropriate seniority level. For higher-risk relationships, this means the MLRO personally. For lower-risk RCA relationships, a senior compliance manager may be appropriate, provided their authority to make the decision has been documented in the organisation’s compliance operating procedures.

The conditions attached to a risk acceptance may include:

Restrictions on transaction types or limits. Some organisations restrict large cash transactions, wire transfers to high-risk jurisdictions, or transactions involving corporate structures associated with the PEP’s home country.

Increased monitoring frequency. Transaction reviews may move from quarterly to monthly or from monthly to weekly, depending on the risk rating and the nature of the PEP’s role.

Periodic re-confirmation of source of wealth. For PEPs with significant wealth or complex corporate structures, annual re-assessment of source of wealth is a reasonable practice.

Enhanced relationship management. Some organisations assign dedicated relationship managers to PEP customers, not as a special privilege but as a control mechanism to ensure that account activity is reviewed by someone with awareness of the customer’s elevated risk profile.

Risk acceptance decisions should not be treated as permanent. They should be subject to periodic review, at minimum annually and more frequently where risk factors change. A PEP who leaves their government role remains a PEP for life under many regulatory frameworks, though some jurisdictions apply a reduced obligation period after the individual has left office. The compliance team should understand the applicable rules in their jurisdiction and apply them consistently.

When the Relationship Becomes Untenable: The Exit Decision

Most PEP relationships that are properly assessed and managed can proceed without unreasonable difficulty. However, there are circumstances under which a relationship should be exited.

Refusal to provide source of wealth or source of funds evidence is the clearest trigger. If a PEP or RCA customer cannot or will not explain the origins of their wealth or the funds in their account, the compliance team cannot complete the due diligence required to manage the risk. Continuing the relationship in this situation creates significant regulatory exposure and may constitute a failure of the compliance programme.

Evidence of unexplained wealth or unusual transaction patterns that are inconsistent with the customer’s declared profile is a second trigger. This does not require proof of criminal conduct. A compliance assessment that identifies unexplained assets, transactions with no apparent commercial rationale, or patterns consistent with layering or integration is sufficient to escalate the relationship toward exit.

The exit process for a PEP relationship requires particular care to avoid tipping off the customer. Telling a PEP that their account is being closed because of their political role creates obvious risks. The compliance team should manage the exit through commercial justification where possible and should involve the MLRO in planning the communication. In extreme cases, a suspicious matter report (or equivalent disclosure in the relevant jurisdiction) may be required before or alongside the exit.

Exit decisions should be documented with the same rigour as risk acceptance decisions. The rationale, the evidence considered, the alternatives evaluated and the decision made all form part of the compliance record.

Ongoing Monitoring Triggers After a PEP Match

A confirmed PEP or RCA classification changes the ongoing monitoring parameters for that customer. The question is not whether monitoring changes but by how much and on what triggers.

Transaction monitoring frequency increases for PEP and RCA customers. The specific frequency should be defined in the compliance operating procedures and calibrated to the risk rating assigned at the point of risk acceptance. Higher-risk PEPs, particularly those from jurisdictions with elevated perceived corruption levels or those associated with high-value transactions, warrant more intensive monitoring.

Jurisdiction changes are an important trigger. If a PEP customer is appointed to a new government role, particularly in a foreign jurisdiction, the risk profile of the relationship may shift materially. A domestic PEP who becomes a foreign minister in a high-risk jurisdiction requires re-assessment. A foreign PEP who transitions out of their government role may warrant a review of the monitoring intensity, subject to jurisdiction-specific rules on post-office PEP obligations.

Corporate structure changes are another trigger. If a PEP customer acquires a new corporate interest, establishes a new trust structure, or takes on a new beneficial ownership position, the compliance team should re-examine the relationship in light of these changes. New corporate connections may bring new RCAs into the scope of the relationship.

Adverse media alerts are particularly significant for PEP and RCA customers. A negative news item about a PEP customer or a known associate should trigger an immediate review of the relationship. Adverse media is not itself an indicator of criminal conduct, but it is a relevant risk factor that must be assessed and documented.

MemberCheck supports ongoing monitoring capabilities that can be configured to apply elevated review frequencies to PEP and RCA customers. The monitoring scope should encompass the customer, their known associates and their corporate interests where this information is within scope. Effective monitoring requires that the compliance team has access to current information about the PEP and their network, not just the snapshot taken at onboarding.

The Documentation Chain for the MLRO, Audit and Regulator

Every decision in the PEP match workflow should be capable of being reconstructed from the compliance record. This is not optional or aspirational. It is a core regulatory expectation.

The MLRO is personally accountable for the compliance programme. When a regulator reviews a business relationship with a PEP, they will want to understand what the compliance team knew, when they knew it, what they did about it, and who approved each decision. Gaps in the documentation chain undermine the compliance team’s ability to demonstrate that the obligations were met.

The documentation chain should include:

The initial screening result and the date it was returned.

The identity confirmation steps taken, including the evidence examined.

The classification decision and the rationale, including why the team concluded the customer was or was not a PEP, relative or close associate.

The EDD completed, including source of wealth and source of funds analysis.

The risk acceptance decision, including who made it, what conditions were applied, and what monitoring parameters were set.

Any subsequent reviews, including triggers for those reviews and outcomes.

Exit decisions, where applicable, including the rationale and process followed.

Each of these elements should be recorded in a way that is timestamped, attributable to an individual reviewer and retained for the period required by the applicable jurisdiction. Many regulators expect records to be kept for at least five years after the business relationship ends, but this varies by jurisdiction and the type of regulated entity.

MemberCheck provides audit trail functionality that can support the documentation requirements of the PEP match workflow. Compliance teams should ensure that the records created within MemberCheck are supplemented with any additional evidence or decision records held in other systems, and that the complete compliance file is maintained consistently.

PEP Matches and Sanctions Matches Are Not the Same Decision

A distinction that causes persistent confusion in compliance operations is the conflation of PEP screening matches and sanctions screening matches. While both involve screening a customer name against a database of risk-relevant individuals, the obligations, decision frameworks and consequences of each are meaningfully different.

Sanctions screening involves checking customer names against lists such as the United Nations Security Council sanctions lists, the US Office of Foreign Assets Control (OFAC) Specially Designated Nationals (SDN) list, the UK Treasury’s consolidated list, the European Union consolidated list and other national sanctions lists. Where a customer matches a sanctions list, the obligation is typically absolute. Permitted transactions are frozen, the relationship cannot proceed, and in many jurisdictions a reporting obligation arises. There is no risk acceptance process for a confirmed sanctions match.

PEP screening involves checking customer names against databases of individuals who hold or have held prominent public functions. The obligations are risk-based and graduated. Not every PEP match requires the termination of the relationship. Risk acceptance, with appropriate EDD and monitoring, is a legitimate and intended outcome of the PEP framework.

The practical implication for compliance operations is that the screening system must run both checks, but the decision workflow following each check is distinct. A customer who appears on a PEP database but not on a sanctions list is subject to a risk-based assessment. A customer who appears on a sanctions list requires immediate action under the applicable sanctions laws. Mixing these two workflows is a common source of both unnecessary escalation (treating PEP matches as sanctions matches) and insufficient response (treating sanctions matches as PEP matches requiring only enhanced monitoring).

MemberCheck supports both PEP screening and sanctions screening, with configurable matching and decision support that helps compliance teams apply the correct workflow to each match type.


Frequently Asked Questions

FATF Guidance on Politically Exposed Persons defines close associates as natural persons who are known to have a close business relationship with a PEP or who share beneficial ownership of a legal arrangement or other business relationship with a PEP. The relationship must be meaningful and close, not merely coincidental. Being a customer of the same institution or having a shared address history is not sufficient to meet this definition under the FATF standard.
Source of wealth refers to the origin of the individual’s total assets and accumulated wealth over time. Source of funds refers to the specific origin of the funds involved in a particular transaction or relationship. For PEP due diligence, both must typically be established, but they require different types of evidence and analysis.
Yes, provided the EDD obligations have been met, senior management approval has been obtained, and appropriate monitoring parameters have been established. A risk acceptance decision with documented rationale and conditions allows the relationship to proceed within defined parameters.
This varies by jurisdiction and by the specific role held. Under FATF Recommendation 12, the enhanced due diligence obligations continue to apply to existing relationships where the individual is already a customer. For former PEPs, many jurisdictions apply a reduced but still elevated monitoring obligation for a period following departure from public office. Organisations should confirm the applicable rules in their jurisdiction and document their approach.

Conclusion

PEP match decision-making is an operational discipline, not a screening output. The value of a compliance programme is measured not by whether it can identify a PEP match but by how it responds to one.

The framework set out here provides a structured path from initial match to documented outcome: confirming identity, classifying the relationship, applying enhanced due diligence, making a risk acceptance decision, maintaining ongoing monitoring, and keeping a complete documentation chain for the MLRO, for audit and for the regulator.

Each step requires judgment. The framework does not eliminate that judgment. It structures it so that the decisions made by compliance teams are consistent, defensible and proportionate to the actual risk presented.

MemberCheck supports this workflow through configurable matching thresholds, RCA relationship mapping, ongoing monitoring capabilities and audit trail functionality. Organisations looking to strengthen their PEP match decision-making process should evaluate how their screening platform supports each step of this framework, not just the screening step itself.

Explore how MemberCheck supports PEP screening decision workflows. [Request a demo]

PEP Match Decision-Making: A Framework for Compliance Teams

A structured decision framework for MLROs and compliance teams managing PEP screening matches, covering identity confirmation, RCA assessment, enhanced due diligence, risk acceptance and ongoing monitoring obligations.

Speak to our team

This article was accurate at the time of publication in August 2026 and is intended for general informational purposes only. It does not constitute legal, regulatory or compliance advice. Organisations should seek qualified professional guidance in relation to their specific obligations.