Oscilar Team

PEP Screening Explained: What US Rules Require

Posted

Posted

Oscilar Team
Contents

Share this article

Last updated: September 2026

Search for PEP screening and you will find a lot of pages telling you it is mandatory. The clearest US source on the subject says something different, and the difference matters — it changes how you scope the control, how much noise you generate, and what you can tell an examiner about why your programme looks the way it does.

TL;DR

  • PEP screening checks whether a customer, or someone close to them, is a politically exposed person, so you can build an accurate picture of that customer's risk.

  • "PEP" is an industry term, not a regulatory one. US BSA/AML regulations do not define it, and the FFIEC examination manual states there are no BSA regulations specific to customers a bank designates as PEPs.

  • The CDD rule does not require you to screen for PEPs. Customer identification, customer due diligence, beneficial ownership and suspicious activity reporting all still apply in full.

  • Being a PEP does not make someone high risk by default, and banks are "neither prohibited nor discouraged" from serving them.

  • PEP screening, sanctions screening and adverse media screening are three different controls with three different consequences when they hit.

  • Most of the pain in a PEP programme comes from match quality, not alert volume.

What PEP screening is

PEP screening is the process of checking whether a customer, or someone connected to them, is a politically exposed person — a foreign individual entrusted with a prominent public function — so the institution can build an accurate customer risk profile. It sits inside customer due diligence, alongside the identity and ownership checks that make up KYC compliance.

One piece of housekeeping first. In financial crime, PEP means politically exposed person.

The more useful thing to know is that PEP is industry vocabulary rather than regulatory vocabulary. The FFIEC BSA/AML Examination Manual is direct about it: BSA/AML regulations do not define the term, and it should not be confused with "senior foreign political figure", which is a defined subset and carries its own obligations under a different part of the rules.

That distinction sounds academic. It is not. It is the reason two institutions can both say they "screen for PEPs" and mean substantially different things.

Who counts as a politically exposed person

The manual describes the common industry usage: foreign individuals who are or have been entrusted with a prominent public function, along with their immediate family members and close associates.

Note what is missing from that sentence. There is no official master list. Commercial PEP databases are constructed by their vendors from public records, media and government sources, which means two providers screening the same customer can return different answers — and neither is authoritative in the way a sanctions list is.

The manual is also explicit that PEP status is not a risk verdict:

"Not all bank-identified PEP customers pose the same risk, and not all bank-identified PEP customers are automatically higher risk."

Some PEPs do present elevated risk, because their position gives them access to funds that may be proceeds of corruption. Others do not. Banks that manage the risk properly are "neither prohibited nor discouraged" from providing services to them.

How long does someone stay a PEP?

There is no fixed answer in US guidance, and any vendor that gives you a specific number of years is telling you about their product rather than about the rules. For someone no longer in active government service, the manual says banks may consider how long they have been out of office and how much influence they may still hold. That is a judgment, and it should be a documented one.

Is PEP screening actually required in the United States?

Here is the part that many get wrong.

"The CDD rule does not require a bank to screen for or otherwise determine whether a customer or beneficial owner of a legal entity customer may be considered a PEP."

And:

"Examiners are reminded that there are no Bank Secrecy Act (BSA) regulations specific to foreign individual customers who the bank has designated as PEPs."

Both sentences are from the FFIEC BSA/AML Examination Manual. Read them carefully, though, because the conclusion is not "you can skip this."

Everything else still applies, in full. Accounts held by customers a bank identifies as PEPs are subject to the same BSA/AML requirements as any other account: customer identification, customer due diligence, beneficial ownership of legal entity customers, and suspicious activity reporting. The manual is equally clear that a bank may determine PEP status at account opening if it decides that information is needed to develop the customer risk profile — and most institutions do, for good reason.

So the obligation is not "run this screen." The obligation is to hold a defensible, risk-based understanding of your customers, and PEP status is one input into it.

That reframing has practical consequences:

  • You are accountable for the quality of the risk profile, not for the existence of a screening tool.

  • You can scope screening to where it changes your assessment, rather than everywhere.

  • When an examiner asks why your programme is designed the way it is, "our vendor said it was required" is not an answer. "Here is the risk rationale, and here is the documentation" is.

PEP screening, sanctions screening and adverse media are three different things

This one shows up constantly in real conversations. A compliance leader at a commercial bank, going through a vendor's screening capability, stopped to ask the obvious question: the screen was described as "sanctions" — did that include PEPs and adverse media, or not?

It is a fair question, and getting the answer wrong has operational consequences, because a hit on each of the three means something different.


Sanctions screening

PEP screening

Adverse media screening

What it is

A check against government-published prohibition lists, such as those administered by OFAC

A check for political exposure, feeding the customer risk profile

A search of news and public reporting for negative information

What obliges it

Legal prohibition. Dealing with a listed party is unlawful

No standalone US requirement. It supports the CDD obligations that do apply

No standalone requirement. Supports due diligence and SAR decisions

What a hit means

Potentially a blocking event, once the match is confirmed

A signal to look more closely. Not a reason to decline

Evidence to weigh, of highly variable quality

What you do next

Confirm the match, then act on it — the answer is prescribed

Assess and document. The answer is yours to reason to

Assess relevance and credibility, then decide whether it changes the profile

The failure mode is treating a PEP hit like a sanctions hit. That produces reflexive de-risking, exits customers you had no obligation to exit, and generates work nobody needed.

How PEP screening works, step by step

  1. Decide the scope. Which customers, which products, which points in the lifecycle. This decision does more for your programme's cost and quality than any other.

  2. Screen at onboarding, then on an ongoing basis at a frequency proportionate to risk. Political exposure is not a static attribute.

  3. Match against list data. Understand that match quality is where most of the cost lands — see below.

  4. Triage the hit. Before you treat anything as a PEP relationship, establish whether it is even the same person. Most alerts die here.

  5. Where the match is real, gather what the profile needs. The manual names what is useful, and it is more specific than "collect more information."

  6. Document the reasoning. Not the outcome — the reasoning. Decision reconstruction is what gets asked for later.

Scoping the control: the six factors that should drive it

For understanding the nature and purpose of a PEP relationship, the FFIEC manual names these:

  • The type of products and services used.

  • The volume and nature of transactions.

  • Geographies associated with the customer's activity and domicile.

  • The customer's official government responsibilities.

  • The level and nature of their authority or influence over government activities or officials.

  • Their access to significant government assets or funds.

That last pair is the substance. A minister with budget authority and a retired local official are both technically PEPs and are not remotely the same risk.

The manual also describes what a lower-risk PEP relationship can look like: limited transaction volume, a low-dollar deposit account, known legitimate sources of funds, products subject to specific terms and payment schedules, a small number of associated accounts. Those relationships can reasonably sit in a lower-risk profile.

Buyers arrive at the same place independently. A risk lead at a cross-border payments company, working through an expansion, pushed back on routing every transaction through PEP screening and asked how to distinguish the flows that genuinely needed it. That instinct is right, and it is what a risk-based approach actually looks like in practice.

Why PEP screening generates so many false positives

Ask a compliance team about their screening pain and they rarely lead with volume. They lead with relevance.

A compliance lead at a European bank put it plainly during a review of their sanctions and PEP alerts: many of them were completely irrelevant, and the matching logic would fire on a shared first name with an entirely different surname.

There are three usual causes.

Name matching. Fuzzy logic tuned for recall produces matches on partial names, common names in large populations, and transliteration variants. Tune it the other way and you miss real hits. This is a genuine trade-off, not a bug to be fixed once.

List construction. Because PEP lists are built rather than published, coverage and granularity differ between providers. The same customer can generate a hit against one dataset and nothing against another.

Over-scoping. Screening everything produces more alerts without producing more signal. Broad scope is often chosen because it feels defensible, and it is the most expensive form of caution available.

The fix for all three is upstream. Better identity resolution and better customer context before the alert is generated will always beat adding reviewers after it — the same principle that governs alert quality across AI-driven AML programmes generally.

What to look for in a screening system

  • Match explainability. A reviewer should be able to see why the system matched — which fields, at what confidence — not just that it did. Unexplained matches take longer to clear and are harder to defend.

  • Thresholds your compliance team can adjust. Screening is tuned continuously. If a threshold change is an engineering ticket, it will not happen at the pace the work requires.

  • Data coverage that matches your footprint. A provider strong in one region can be thin in another. Test against your actual customer geographies, not a demo dataset.

  • Ongoing monitoring, not just onboarding. People enter public life after they open accounts.

  • A full audit trail per decision, with the reasoning stored. This is what makes decision reconstruction possible months later, when the question is not what you decided but why.

  • A queue design you have actually thought about. One team standing up PEP screening for the first time found their first real decision was whether watchlist hits and PEP hits belonged in one queue or two. Different hit types need different handling, and merging them by default costs you either speed or care.

Where screening fits in the wider risk picture

Screening produces one input. The customer risk profile — the thing you are actually accountable for — is assembled from that input alongside transaction behaviour, geography, product usage and everything else you know.

Our view is that this is a data problem before it is a tooling problem. A screening result that arrives without the context needed to interpret it is how a review queue becomes a backlog. The value comes from a unified view over richer data, not from another point tool running alongside the ones you already have — which is the approach behind how we build AML controls for banks and for fintechs.

If you are designing a screening control now, the sanctions and PEP screening capability in our agent lineup is worth a look once it is published — it is built around the explainability and audit-trail requirements above.

Frequently asked questions

Is PEP screening required by law in the United States? Not as a standalone requirement. The FFIEC BSA/AML Examination Manual states that the CDD rule does not require a bank to screen for or determine whether a customer may be considered a PEP, and that no BSA regulations are specific to PEPs. Customer identification, customer due diligence, beneficial ownership and suspicious activity reporting obligations all still apply, and most institutions screen because political exposure is genuinely useful for building a risk profile.

What is PEP screening in AML and KYC? It is the step in customer due diligence where you check whether a customer, or a family member or close associate, holds or has held a prominent public function abroad. The result feeds the customer risk profile, which then drives how much diligence and monitoring that relationship gets.

How is PEP screening different from sanctions screening? Sanctions screening enforces a legal prohibition — a confirmed match means you cannot transact. PEP screening is a risk-profiling input — a confirmed match means you should look more closely and document what you conclude. Treating a PEP hit as a blocking event is the most common and most costly confusion in this area.

How long does someone remain a PEP after leaving office? US guidance sets no fixed period. The FFIEC manual says banks may consider the time the customer has been out of office and the level of influence they may still hold. Whatever period you apply should be a documented risk decision rather than a vendor default.

Who counts as a close associate of a PEP? The industry definition covers immediate family members and close associates of a person entrusted with a prominent public function. Precisely who falls inside that boundary is a judgment for your institution, and it should be written down — this is one of the most common places two programmes diverge without either being wrong.

What does enhanced due diligence on a PEP involve? There is no prescribed US checklist. In practice it means collecting more of what the manual names as useful: the products and services used, transaction volume and nature, geographies, the customer's official responsibilities, their authority or influence, and their access to government assets or funds. The level of diligence should be commensurate with the risk the relationship actually presents.

Oscilar Team

The Oscilar Team is comprised of experts from many domains of risk operations. These articles express viewpoints and knowledge from a variety of sources and contributors across the organization.