Identifying a politically exposed person is not a search for wrongdoing. It is a KYC control for recognising customers whose public functions may expose them to bribery, corruption or money-laundering risk.

A useful check confirms identity and public role, establishes relevant connections, assesses source of wealth and funds, and records why the relationship presents a lower or higher risk. The result should determine the depth of review—not create an automatic rejection.

What Is a Politically Exposed Person?

The Financial Action Task Force defines a PEP as an individual who is or has been entrusted with a prominent public function. Such influence can create opportunities for abuse of office or make the officeholder a target for corruption. PEP status does not imply a crime.

Under the UK Money Laundering Regulations, firms in scope need systems to identify whether a customer or beneficial owner is a PEP, family member or known close associate. Junior and middle-ranking officials are excluded, although evidence that one acts for a PEP may require closer review.

Who Falls Within the PEP Framework?

PEPs are commonly grouped into three categories:

  • Domestic PEPs are individuals who are or have been entrusted with prominent public functions by the United Kingdom. Under Regulation 35 and current FCA guidance, the starting point is that they, their family members and known close associates present a lower level of risk than non-domestic PEPs. If no enhanced risk factors are present, the EDD applied must be less extensive.
  • Non-domestic PEPs are PEPs who are not domestic PEPs. Regulation 35 still requires EDD, but the FCA expects an individual assessment rather than an automatic highest-risk rating. Consider the jurisdiction, actual authority, product and other case-specific facts.
  • International organisation PEPs include directors, deputies, board members or equivalent senior figures in public international organisations—not every employee.

Prominent functions can include heads of state or government, ministers, legislators, members of qualifying political-party governing bodies, senior judges, high-ranking military officers, central bank board members and members of the management or supervisory bodies of qualifying state-owned enterprises. Analysts should establish actual authority and access to public money, licences or procurement—not rely on title alone.

Family Members and Known Close Associates

UK rules include a spouse or person considered equivalent to a spouse, children and their spouses or equivalent partners, and parents. FCA guidance also treats siblings as included and permits a wider circle only where a documented higher-risk assessment justifies it.

A known close associate can include a joint beneficial owner, someone in another close business relationship with the PEP, or the sole owner of a structure known to have been created for the PEP’s benefit.

Family members and close associates are not themselves PEPs merely because of the connection. The relationship still triggers relevant scrutiny. Links through advisers, intermediaries or corporate vehicles may also require third-party due diligence.

Why PEP Identification Matters for KYC

PEP identification helps a regulated firm decide what evidence it needs before opening or continuing a relationship. It can reveal control of corporate structures, income linked to public office or exposure through cross-border products.

For UK-regulated firms, Regulation 35 requires a risk-sensitive assessment and enhanced measures when the customer or beneficial owner falls within the PEP framework. These controls sit within wider KYC compliance and customer due diligence and can support AML compliance and investigations where evidence raises separate concerns.

The FCA says firms should not decline a relationship merely because of PEP status. Refusal may be appropriate if the firm collects suitable information and concludes that it cannot manage the risk.

How to Identify a PEP

1. Define the Roles and Jurisdictions in Scope

Build the policy around applicable law. Record qualifying functions, treatment of domestic and foreign PEPs, covered connections and escalation triggers. A generic global definition may miss local differences.

2. Collect Reliable Identity Data

Screen the customer and beneficial owner using full name, aliases, original script, birth details, nationality, address, identifiers, public office and term dates. Corporate cases also require ownership, directors, registration numbers and the structure’s purpose.

3. Search Several Source Types

Commercial databases support scale but are not mandatory in the UK. Analysts should understand their sourcing and updates, then use official government or parliamentary pages, public registers, declarations of interest and reliable reporting.

No PEP list is complete or universally authoritative. A database result is a lead to reconcile with primary evidence.

4. Resolve the Identity and Public Function

Confirm the person, then verify the office, seniority, power and term dates. Record the classification evidence and reasons for including or excluding a borderline role.

5. Map Relevant Connections

Map relevant relatives, known associates, companies, trusts and beneficial ownership. Do not label every shareholder, colleague or acquaintance a close associate; the connection needs evidence.

6. Assign and Document the Risk

Consider the role, jurisdiction, product, expected activity, ownership, wealth, funds and credible adverse information. Document the rating, evidence, approval and monitoring plan.

PEP Risk Indicators

No single indicator proves misconduct. Consistent signals may justify deeper review:

  • authority over public budgets, procurement, licences or state assets;
  • personal wealth or spending inconsistent with known legitimate income;
  • unexplained dealings with government contractors or state-owned businesses;
  • transactions inconsistent with the relationship’s stated purpose;
  • frequent use of intermediaries, nominees, shell companies or opaque trusts;
  • links to jurisdictions affected by corruption, weak institutions, conflict or opaque ownership;
  • credible allegations, investigations, sanctions or findings involving bribery, embezzlement or financial misconduct;
  • contradictions about ownership, occupation, wealth or funds;
  • reluctance to provide information needed for a proportionate review.

Industry alone is not a source of wealth. Mining, defence, construction or privatisation may raise contextual risk because they involve public licences or procurement. The analyst must still establish how the person accumulated wealth and obtained the funds in question.

A PEP Match Is a Starting Point, Not a Verdict

PEP status, sanctions and adverse media answer different questions. A PEP match identifies a prominent public function. A sanctions designation may impose a legal restriction. Adverse media provides a potential risk signal, but an allegation is not an investigation, charge or court finding.

Keep these workstreams separate before combining them. Confirm the person and role, establish relevant connections and map the corporate network. Verify wealth and funds. Check applicable sanctions and assess adverse information by source, date, independence and corroboration.

This evidence chain avoids treating a namesake as a PEP or political exposure as proof of misconduct. When reporting may affect the decision, reputational due diligence helps separate documented facts from unsupported allegations.

Enhanced Due Diligence for PEPs

When a UK-regulated firm identifies a PEP, family member or known close associate, Regulation 35 requires it to:

  • obtain senior-management approval to establish or continue the relationship;
  • take adequate measures to establish the source of wealth and source of funds involved in the proposed relationship or transaction;
  • conduct enhanced ongoing monitoring proportionate to risk.

The firm should also retain an auditable record of the evidence, risk assessment, rationale and approval, in line with the MLR record-keeping framework and FCA expectations.

Source of wealth explains how the customer accumulated their net worth. Source of funds identifies the origin of money used in a particular transaction. A bank statement may show where funds arrived from without explaining how the underlying wealth was acquired.

PEP status alone does not require a suspicious activity report. Reporting depends on the legal threshold and facts found during review or monitoring. UK firms should align the process with applicable customer due diligence requirements.

How Long Does PEP Status Last?

In the UK, a former PEP remains subject to risk-based EDD for at least 12 months. Measures may continue longer where documented higher risk remains.

Family members should return to ordinary CDD when the PEP leaves office unless other risk justifies EDD. A known associate’s classification should reflect whether the qualifying relationship or risk continues. Firms should update rather than retain labels indefinitely.

How Technology Helps—and Where It Fails

Systems can compare aliases, transliterations and birth dates, monitor role changes and route matches for review. Automation helps rescreen large customer bases after elections or appointments.

Results still depend on data and settings. Outdated roles, missing connections or broad thresholds create false positives and missed matches. Machine learning can rank cases but cannot verify public authority, test an allegation or accept risk without accountable human review.

Conclusion

Effective identification combines accurate identity data, verified public roles, relationship mapping and documented risk assessment. It should detect exposure without treating every officeholder or connected person as a suspected criminal.

The question is whether the person’s role, connections, wealth and expected activity create risks the organisation can manage. If identity, ownership or influence remains unresolved, contact Molfar Intelligence.

Frequently Asked Questions

Is PEP Screening Mandatory in the UK?

Firms in scope of the UK Money Laundering Regulations must maintain systems to identify whether customers or beneficial owners fall within the PEP framework and apply the required measures.

Does PEP Status Mean a Customer Is High Risk?

Not automatically. UK domestic PEPs start from a lower relative risk position than non-domestic PEPs unless enhanced factors are present, but every case needs assessment.

Can a Company Be a PEP?

A PEP is an individual. A legal entity does not itself become a PEP merely because a PEP owns shares in it. However, Regulation 35 still applies where the beneficial owner of a customer is a PEP. Assess the person’s ownership, significant control and ability to use the entity, then apply measures proportionate to the risk.

Can a PEP Be Accepted as a Customer?

Yes. A firm may accept the relationship after completing the required checks and approval where it can manage the risk. Status alone is not a reason for rejection.

How Often Should PEP Screening Be Repeated?

There is no universal interval. Review frequency should reflect risk and events such as elections, appointments, ownership changes, unusual activity and new reliable information.

Author

Former British Army officer, trained in surveillance and target acquisition, and Bain and Company engagement manager, with more than a decade of experience working in consulting, private equity and venture capital across Western Europe.

Recent posts

View all
View all
White Plus Icon
View all
View all
White Plus Icon

Related posts

View all
View all
White Plus Icon
No items found.
View all
View all
White Plus Icon
Turn Intelligence Into Action
Order a service
Order a service
Black Plus Icon

Our cases

Behind every case is a client who needed clarity in uncertainty. Browse our work to see how we uncover what others miss — and what that means in practice for businesses and decision-makers.

View all cases
View all cases
White Plus Icon
Expanded Plus Icon

Investor Due Diligence: Mitigating Reputational Risks in Defence Tech

Revealed how a high-stakes Defence Tech investment was halted after OSINT-driven due diligence uncovered a co-founder’s links to Russian-origin money laundering and a seized 2.6 billion UAH gambling enterprise, protecting a global firm from severe reputational and regulatory fallout.

Investment

Learn more
Learn more
White Plus Icon
Expanded Plus Icon

Pre-Employment Screening for a Spacecraft Manufacturing Role

Conducted a full pre-employment background investigation for a high-security aerospace role, covering court registry checks, financial record verification, ideological risk assessment, and social media OSINT analysis across relevant jurisdictions.

Space

Learn more
Learn more
White Plus Icon
Expanded Plus Icon

Sanctions Gaps — Supercam Drone Production Continues

Revealed how Russian drone manufacturers circumvent international sanctions by exploiting a critical design flaw (sanctions applied to company names rather than underlying legal entity identifiers), enabling Supercam to increase production tenfold despite being designated.

Finance

Learn more
Learn more
White Plus Icon
Expanded Plus Icon

Cybersecurity Audit and Internal Data Exposure Mitigation

Conducted a comprehensive cybersecurity audit of a long-standing European IT infrastructure, identified critical internal data leaks involving financial plans and performance reviews, and implemented high-level security protocols to mitigate regulatory and operational risks.

Cybersecurity

Learn more
Learn more
White Plus Icon
Gain the Clarity You Need to Move with Confidence

Let’s connect to explore how tailored intelligence can strengthen your decisions, reveal opportunities, and minimise uncertainty.