Pricing
Language

Guide · Updated 24 August 2026 · 26 min read

PEP Screening: A Practical Guide for Compliance Teams

A jurisdiction-aware guide to political exposure, potential-match investigation, proportionate controls and documented decisions.

Share

A screening result says that customer data resembles information associated with political exposure. It does not answer the questions that matter most: Is this the same person? Does the role or relationship fall within the applicable definition? What risk does the relationship present? Which measures are required? Can the firm explain the outcome later?

That is why PEP screening should be designed as a review process rather than a binary database check. The strongest control connects a candidate result to identity resolution, classification, customer-risk assessment, proportionate measures, a documented decision and later reassessment.

FATF Recommendation 12 provides the international baseline for politically exposed persons. FATF also makes an important point that should shape the whole process: PEP measures are preventive, not criminal, and PEP status must not be interpreted as meaning that a person is involved in criminal activity.1 Enforceable duties arise through the law applicable to the firm. This guide therefore distinguishes international standards, current EU and UK rules, and US banking guidance instead of presenting one global rule.

What is PEP screening?

PEP screening is a control used to identify possible political exposure among customers and, where relevant, beneficial owners or other people within the firm’s due-diligence scope. It compares available subject information with PEP-related data, returns potential matches for review and supports the next steps in the firm’s risk process.

The control is not complete when a name appears in a result. A competent process separates five layers:

Potential PEP match
Question: Is the subject sufficiently similar to a PEP-related profile to require review?
Limit: It does not prove identity or PEP status.
Confirmed PEP relationship
Question: Is the subject the relevant person, and does the role fall within the applicable PEP definition?
Limit: It does not imply criminal conduct or decide customer risk by itself.
Confirmed relative or close-associate relationship
Question: Is the subject a family member or known close associate within the relevant framework?
Limit: It does not mean the customer personally holds public office.
PEP-related risk indicator
Question: How does political exposure affect the wider risk assessment?
Limit: It is not automatically the final risk rating.
Firm decision
Question: What due diligence, approval, monitoring or customer treatment is appropriate?
Limit: It is not an automatic output from a match or classification.

This distinction prevents two opposite errors. The first is treating every alert as a confirmed PEP and burdening customers with unnecessary review. The second is clearing a true match because the screening record was not connected to the applicable role definition, relationship context and risk methodology.

External data can help firms find political exposure, but FATF says commercial and other external databases are neither mandated nor sufficient by themselves to satisfy PEP requirements.1 Data supports the control. The firm still needs a defensible process for scope, review, classification and decision-making.

PEP screening is not sanctions screening

PEP and sanctions checks can use similar identity data, but they answer different questions.

PEP screening
Identifies political exposure that may require specific risk-management and due-diligence measures.
Next: Confirm the match and category, then assess the relationship’s actual risk.
Sanctions screening
Identifies possible exposure to restrictive measures under an applicable sanctions regime.
Next: Determine whether a prohibition, restriction, reporting duty, licence or exception applies.
Adverse-media review
Finds contextual information that may affect risk or prompt investigation.
Next: Test whether the information is credible, relevant and material to the relationship.

A PEP is not automatically prohibited from becoming a customer. A person may separately be sanctioned, but that requires sanctions-specific analysis. See Sanctions Screening: A Practical Guide for Compliance Teams for the legal-perimeter, list, ownership/control and alert-investigation issues that belong to that control.

Who counts as a politically exposed person?

PEP classification starts with the definition that applies to the firm. FATF’s glossary and Recommendation 12 provide an influential baseline, but countries implement the standard through their own systems. A global policy can create a common operating framework; it should not erase jurisdictional differences.

Foreign PEPs

FATF describes foreign PEPs as people who are or have been entrusted with prominent public functions by another country. Examples include heads of state or government, senior politicians, senior government, judicial or military officials, senior executives of state-owned corporations and important political-party officials. The definition is not intended to cover middle-ranking or more junior people.2

The word prominent matters. A policy that treats every public employee as a PEP creates avoidable false classifications and may be inconsistent with the relevant definition. Role seniority, actual function, authority and jurisdiction all matter more than a broad public-sector label.

FATF’s baseline for foreign PEP relationships includes systems to determine whether a customer or beneficial owner is a PEP, senior-management approval, reasonable measures concerning source of wealth and source of funds, and enhanced ongoing monitoring.2 These are standards addressed to countries for implementation. The firm must identify the binding rule that applies in its jurisdiction.

Domestic PEPs

A domestic PEP holds or has held a prominent public function in the country whose framework is being applied. FATF does not simply copy the foreign-PEP treatment across every domestic relationship. It calls for reasonable measures to determine whether a customer or beneficial owner is a domestic PEP, with the additional measures applying in higher-risk business relationships.2

National implementation may differ. The United Kingdom provides a particularly clear example: since January 2024, its rules require the starting point for a domestic PEP, or an associated family member or known close associate, to be lower risk than for a non-domestic PEP where no enhanced risk factors are present.3 That is a UK rule, not a universal statement that domestic PEPs are always low risk.

Local public functions can also be classified differently across Europe. See when a mayor is treated as a PEP in Europe for a country-by-country example.

The useful operational lesson is broader: PEP classification and customer-risk rating are separate judgments. Record both, and show which facts influenced the risk assessment.

International-organisation PEPs

FATF also covers people who are or have been entrusted with a prominent function by an international organisation. This category concerns senior roles such as directors, deputy directors, board members or equivalent functions; it is not intended to capture middle-ranking or junior staff.2

The review should identify the organisation, role, seniority, dates and relevant authority. A title alone may be ambiguous across organisations, so the evidence should show why the function meets—or does not meet—the applicable definition.

Family members and close associates

FATF extends its PEP requirements to family members and close associates.2 Current EU rules and UK Regulation 35 also address these relationships, with definitions and scope that must be read in their own legal context.45

An RCA is not the same person as the PEP. The record should distinguish:

  • the PEP and prominent function;
  • the family or associative relationship;
  • the evidence supporting that relationship;
  • dates or status information relevant to the relationship; and
  • the risk assessment and measures applied to the customer.

Avoid describing every social or professional contact as a close associate. The applicable definition, known relationship and available evidence should drive classification. Where a relationship is uncertain, preserve that uncertainty and the steps taken to resolve it rather than converting weak context into a definitive status.

Beneficial owners within the screening scope

FATF Recommendation 12 and current EU and UK frameworks refer to determining whether a customer or beneficial owner is a PEP.245 This guide assumes the beneficial owner has already been identified through the firm’s due-diligence process. It does not cover ownership thresholds, registry research or UBO discovery. For the handling of customer-provided ownership structures and related parties, see UBO and related parties.

From a PEP match to a compliance decision

The most useful way to design the control is to follow the life of one result. Each stage should have an owner, evidence standard and clear exit condition.

PEP review workflowFrom a candidate result to a documented decision
  1. 1
    Potential match

    Treat the screening result as a question to investigate.

  2. 2
    Resolve identity

    Compare identifiers, aliases and role context.

  3. 3
    Confirm PEP or RCA

    Establish the relevant status or relationship under the applicable framework.

  4. 4
    Determine category and jurisdiction

    Identify the applicable PEP category, legal perimeter and local requirements.

  5. 5
    Assess risk

    Consider the customer, role, geography, product and surrounding facts.

  6. 6
    Apply measures

    Use the approval, due-diligence and monitoring measures that apply.

  7. 7
    Record the decision

    Keep the rationale, evidence, approvals and final outcome together.

  8. 8
    Monitor and reassess

    Review relevant changes and reassess the relationship when required.

The required measures depend on the applicable jurisdiction, PEP category, relationship and assessed risk.

See how Checklynx supports PEP screening and review across screening, casework and documented decisions.

1. Screen the right people at the right event

Define the screening population from applicable law, the firm’s customer model and policy. It may include an individual customer and, for a legal entity, a known beneficial owner within scope. Other people may be relevant under a particular regime or policy, but do not expand the population without a clear reason.

Common trigger points include onboarding, the addition of a person to an existing relationship, a change in known ownership or control, a customer-profile update, new information about a public role, or a change in the underlying PEP data. Scheduled review may provide a backstop, but there is no single global interval required by the principal sources used for this guide.

The input data should be good enough to support later disambiguation. Depending on what is lawfully available and proportionate, useful fields can include full name, aliases, date or year of birth, nationality, country of residence, role, organisation and relevant relationship information. Do not describe one universal minimum identifier set: requirements and available data differ.

2. Treat the result as a potential match

A screening engine may use exact matching, fuzzy matching, transliteration, aliases and other techniques. Thresholds and scores are implementation choices, not universal legal rules. Their purpose is to produce a manageable set of candidate results without hiding material exposure.

Label the initial result accurately. Potential match, candidate or requires review makes the status clear. Labels such as confirmed PEP, high-risk customer or reject are premature at this stage.

A useful alert record preserves:

  • the subject data sent for screening;
  • the returned profile and identifiers available at the time;
  • the source or dataset version and retrieval time;
  • the matching configuration or profile used;
  • the similarities and conflicts that matter; and
  • the person or queue responsible for review.

This creates a defensible starting point and avoids the common problem of an analyst seeing only a score with no explanation of what produced it.

3. Resolve identity

Identity resolution asks whether the customer and the person described in the returned profile are the same individual. Compare independent identifiers and contextual facts rather than relying on name similarity alone.

Start with the strongest information that is lawfully available. Look for consistency or conflict in dates of birth, nationality, residence, role, employer or public body, location, aliases and transliterations. A common name with no supporting identifiers should not be treated in the same way as a distinctive name plus matching birth and role information.

The conclusion should be reproducible:

  • False match: evidence shows the records concern different people.
  • Possible match: available information is not enough to resolve identity.
  • True identity match: evidence supports that the customer is the person in the profile.

An unresolved possible match is not a confirmed PEP. It may require more customer information, another reliable source, specialist review or a temporary workflow restriction depending on risk and policy. Case management should make the owner, requested evidence, deadline, rationale and escalation path visible rather than leaving the question in analyst notes or email.

4. Confirm the PEP or RCA relationship

A true identity match still needs a classification decision. Establish the public function or relationship, its seniority, jurisdiction, relevant dates and the definition being applied. For an RCA, establish the family or close-associate relationship separately.

This is where a data record and legal/policy analysis meet. A profile may contain a role that no longer applies, a role below the relevant threshold, or a relationship that falls outside the local definition. Conversely, reliable evidence may establish relevant exposure even where no single external source presents a perfect record.

Record the basis for the conclusion:

Role falls within the applicable definition
Retain: role, organisation, seniority, jurisdiction, source and dates.
Role does not fall within scope
Retain: the definition applied, limiting or conflicting facts and reviewer rationale.
Relative or close-associate relationship confirmed
Retain: the relevant PEP, relationship type, supporting source and dates.
Status remains uncertain
Retain: missing facts, attempts to resolve them, interim control and review owner.

This evidence prevents PEP status from becoming a permanent unexplained flag detached from the role or relationship that created it.

5. Assess the relationship’s actual risk

PEP status should feed the broader customer risk assessment; it should not replace it. Consider the applicable PEP category and legal requirements alongside the customer, product, geography, delivery channel, purpose, expected activity, source of wealth or funds where relevant, nature of the public function and other material facts.

Ask questions that change the control response:

  • What authority or access is associated with the role?
  • Is the relationship domestic, foreign or linked to an international organisation under the applicable framework?
  • Are there higher-risk geographies, products, ownership structures or transaction patterns?
  • Is the expected activity consistent with the known customer and source information?
  • Is there credible information that changes the risk assessment?
  • Which measures are required by law, and which are additional policy choices?

Do not write “PEP = high risk” into the methodology as a universal conclusion. FATF distinguishes categories, current UK law expressly requires a different starting point for domestic PEPs in specified circumstances, and US banking guidance takes a risk-based approach.236

6. Apply the measures required for the case

Once identity, status and risk are understood, determine the required treatment under the governing framework. That may involve enhanced due diligence, senior-management approval, reasonable measures concerning source of wealth and source of funds, enhanced ongoing monitoring or another proportionate response.

Keep the trigger and purpose of each measure explicit. Requesting more documents is not a control objective by itself. If the concern is source of wealth, gather evidence that addresses how the person accumulated wealth. If it is source of funds, focus on the origin of the funds used in the relationship or transaction. If the concern is the nature of the role, establish the authority, public resources or corruption exposure relevant to that role.

The final outcome belongs to the firm. Possible workflow states can include approve, approve subject to specified controls, request further evidence, escalate, restrict or decline. These labels are implementation choices and should not be presented as universal legal categories.

7. Record the decision and rationale

The file should let another qualified reviewer understand the decision without reconstructing it from disconnected systems. At minimum, connect:

  • the original screening event and returned profile;
  • identity-resolution evidence;
  • PEP or RCA classification and applicable definition;
  • risk factors, methodology and any override;
  • additional measures and approvals;
  • final outcome and reviewer rationale; and
  • the monitoring or reassessment plan.

An audit trail and evidence record should preserve meaningful changes, not just the latest status. If an alert was first unresolved, later confirmed and then reassessed after the person left office, the history matters.

What changes when a PEP is confirmed?

Confirmation moves the case from matching to the measures required by the applicable framework and assessed risk. It does not create one worldwide checklist.

Under FATF Recommendation 12, the international baseline for foreign PEP relationships includes senior-management approval, reasonable measures to establish source of wealth and source of funds, and enhanced ongoing monitoring. For domestic PEPs and people entrusted with prominent functions by international organisations, those additional measures apply in higher-risk relationships under the FATF standard.2

Current EU Article 20 requires obliged entities, through the existing directive framework and national implementation, to use risk-management systems to determine whether a customer or beneficial owner is a PEP. For PEP business relationships, it addresses senior-management approval, source-of-wealth/source-of-funds measures and enhanced ongoing monitoring.4

UK Regulation 35 contains its own requirements for relevant PEP relationships, including approval and enhanced ongoing monitoring, read with the current proportionality rules and FCA guidance.57

These measures serve different purposes:

Senior-management approval
Provides the oversight required by the applicable framework.
Evidence: who had authority, what they reviewed and what they approved.
Source of wealth
Explains how the person accumulated overall wealth where required.
Evidence: sources supporting the explanation and any uncertainty that remains.
Source of funds
Explains the origin of funds used in the relationship or activity where required.
Evidence: whether the records and transaction context support the stated origin.
Enhanced ongoing monitoring
Applies closer scrutiny appropriate to the relationship and risk.
Evidence: relevant events or activity, the reviewer and the effect on the customer record.
Additional due diligence
Resolves a defined risk question under law or policy.
Evidence: the question addressed and whether the answer changed the decision.

Avoid an indiscriminate “PEP evidence pack.” Ask for information because it answers a relevant question. Excess collection creates customer friction and can still fail to explain why the relationship was accepted, restricted or declined.

Ongoing PEP screening and former PEPs

Political exposure changes. A customer can enter a prominent function, change role, become a known family member or close associate, leave office, or present new facts that alter the risk assessment. The control should be able to detect and assess meaningful changes without assuming one global cadence.

Ongoing monitoring can combine source-data changes, customer updates, relationship events and scheduled reviews. Useful triggers include:

  • a newly identified or changed public function;
  • a new or changed RCA relationship;
  • a change to a known beneficial owner within the firm’s CDD scope;
  • a material change in product, geography or expected activity;
  • new information that affects customer risk;
  • the end of a public function; and
  • the expiry of an approval, exception or review period set by policy.

Former PEPs require a continuing-risk decision

Leaving office does not always end the relevant risk on the same day. Current EU Article 22 requires obliged entities to consider the continuing risk for at least 12 months after a PEP leaves the prominent function and thereafter until the person is considered to pose no further PEP-specific risk.4 UK Regulation 35 similarly contains an at-least-12-month approach with continuing treatment where needed to address the remaining risk.5

Do not simplify this into “PEP status lasts exactly 12 months,” and do not export the EU or UK approach to every jurisdiction. A former-PEP review should consider the applicable rule, continuing influence, seniority and duration of the role, links retained after office, relationship context and any other facts relevant to residual risk.

Record the date and reason for any change in classification or treatment. A system status that changes from “active PEP” to “former PEP” or “no further PEP-specific treatment” without a rationale is difficult to defend and can hide inconsistent practice.

How to investigate false positives and ambiguous matches

False positives are not just an efficiency problem. Poorly resolved alerts can expose customers to unnecessary friction, while overly aggressive clearing can miss genuine exposure. The objective is not zero alerts; it is consistent, evidence-based resolution.

Work from discriminating identifiers

Names are a starting point. Reviewers should use the strongest available identifiers and context:

Full name and aliases
Connects variants, former names and known aliases. Common names can still produce many candidates.
Date or year of birth
Often separates similar names, although records may be incomplete, approximate or conflicting.
Nationality and residence
Adds geographic context. Nationality can change, and residence is not identity.
Public role and organisation
Tests relevance to the subject. Titles and translations may vary across sources.
Role dates
Distinguishes current, former and unrelated records. Start and end dates may be incomplete or updated late.
Relationship information
Supports relative or close-associate classification, but may require corroboration.

Aliases, transliterations and different naming conventions require care. A transliterated name can have several valid spellings; reversed name order and missing patronymics can also affect matching. Configuration should be tested against realistic names and languages in the firm’s customer population rather than tuned only on simple Latin-script examples.

Make the rationale concise and specific

Useful false-match rationale explains the decisive conflict: for example, a materially different date of birth combined with a different nationality and role history. “Not the same person” is a conclusion, not evidence.

For a true match, record the decisive similarities and the evidence used to confirm role or relationship. For an unresolved match, state what is missing and the next action. Quality assurance can then test both inappropriate clearing and unnecessary escalation.

Operational metrics can help find control weaknesses: alert volumes by screening profile, true-match rate, unresolved-case ageing, repeat false matches, override frequency, evidence requests and reviewer disagreement. These are management tools, not legal performance thresholds. Changes to matching configuration should be approved, tested and traceable.

How PEP requirements differ by jurisdiction

Use the source that applies to the firm and relationship:

FATF Recommendation 12
Status: international standard implemented through national systems.
Approach: foreign PEP measures include determination systems, senior approval, source-of-wealth and source-of-funds measures and enhanced monitoring. Domestic and international-organisation PEPs receive specified measures in higher-risk relationships. Family members and close associates are included.
European Union — current in August 2026
Status: Directive (EU) 2015/849, implemented through Member State law.
Approach: Article 20 covers customer or beneficial-owner PEP determination and measures for PEP relationships; Articles 22–23 address former PEPs, family members and close associates.
European Union — from 10 July 2027
Status: Regulation (EU) 2024/1624 is enacted but not yet generally applicable.
Approach: the directly applicable AML rulebook replaces the current framework on its application date. This section requires a substantive review before July 2027.
United Kingdom
Status: Money Laundering Regulations 2017 as amended, plus FCA guidance for firms within scope.
Approach: Regulation 35 governs relevant PEP relationships. Current rules require a lower relative-risk starting point for domestic PEPs and associated family members and close associates where no enhanced factors are present.
United States — banking context
Status: FinCEN and federal banking-agency statement, supported by FFIEC examination guidance.
Approach: PEP relationships present varying risk. The CDD Rule does not create a unique additional due-diligence requirement solely because a bank customer is considered a PEP.

Map FATF standards to applicable law

FATF sets standards for countries and provides guidance. Its categories are useful for global policy design, but the firm needs to map them to the law and supervisory expectations that actually apply.21

Plan for the EU rulebook transition

As of 24 August 2026, Directive (EU) 2015/849 remains the current EU-level framework, implemented through national law. Regulation (EU) 2024/1624 has been enacted but generally applies from 10 July 2027; Directive 2015/849 is scheduled to be repealed from that date.89

This is not a cosmetic date issue. Any version of this guide published or maintained near July 2027 needs a substantive legal refresh. The current/future labels, article references and Member State discussion will change.

For an example of how Member State rules shape PEP classification and controls, see what counts as a PEP in Spain.

Apply UK proportionality

UK Regulation 35 and FCA FG25/3 put proportionate treatment at the centre of the control. The FCA’s multi-firm review also identified practical problems such as definitions wider than law or guidance, insufficient rationale for actual risk, failure to reassess after office ended, training weaknesses and outdated domestic-PEP policies.710

Those findings translate into concrete controls: maintain scoped definitions, distinguish classification from risk, review former-PEP status, train reviewers and keep a rationale that another person can understand.

Keep US banking treatment risk-based

FinCEN and the federal banking agencies state that PEP relationships present varying levels of money-laundering risk depending on facts and circumstances. Their 2020 statement also says the CDD Rule does not itself impose a unique additional due-diligence requirement solely because a bank customer is considered a PEP.6

The correct lesson is not that US banks should ignore political exposure. It is that the risk-based BSA framework should not be rewritten as if it were the EU or FATF text. The FFIEC manual provides the examination context for US banks.11

What should PEP screening software help teams do?

Start with a practical test: can the team move from a candidate result to a consistent, documented review while keeping the final customer decision with the firm?

A useful capability should help teams:

  • screen the people within the firm’s defined scope using the available identifiers;
  • present enough profile and source context to investigate a candidate;
  • distinguish potential, confirmed, false and unresolved matches;
  • route exceptions to an accountable reviewer;
  • connect PEP status with customer-risk assessment without treating them as the same thing;
  • retain notes, evidence, approvals, configuration and decision history;
  • trigger appropriate reassessment when relevant information changes; and
  • integrate screening with the actual customer workflow.

Ask vendors to demonstrate these steps using realistic false-positive and ambiguous-match cases, not only a clean demo record. Review source transparency, update handling, configuration governance, access control, case ownership, evidence export, change history and integration behaviour. Do not treat database size, a confidence score or an “AI” label as proof that the full control works.

For implementation into an existing customer journey, the real-time screening API can provide the technical handoff; the firm still owns its screening scope, risk method and final decisions.

Explore PEP screening with Checklynx →

PEP screening implementation checklist

Frequently asked questions

What is PEP screening?

PEP screening is a control for identifying possible political exposure among customers and other people within a firm’s applicable due-diligence scope. A candidate result must still be investigated, classified, assessed for risk and connected to the appropriate decision and monitoring process.

Does a PEP match mean the customer is a politically exposed person?

No. A match means the customer’s data is sufficiently similar to a PEP-related profile to require review under the firm’s configuration. The reviewer should resolve identity and then confirm whether the role or RCA relationship falls within the applicable definition.

Is every politically exposed person automatically high risk?

There is no safe universal yes. FATF distinguishes foreign PEPs from domestic and international-organisation PEPs in higher-risk relationships. UK rules give domestic PEPs and associated RCAs a lower relative-risk starting point than non-domestic PEPs where no enhanced factors are present. Other jurisdictions can differ.23

Does being a PEP mean someone is suspected of criminal activity?

No. FATF expressly frames PEP requirements as preventive rather than criminal. Political exposure can increase vulnerability to corruption-related risks, but status alone is not evidence of misconduct.1

Should relatives and close associates be screened?

FATF Recommendation 12 extends PEP measures to family members and close associates. Current EU and UK frameworks also address these relationships, but the definitions and legal scope must be checked in the relevant jurisdiction.245

Do beneficial owners need to be checked for PEP status?

FATF Recommendation 12 and current EU and UK frameworks refer to determining whether a customer or beneficial owner is a PEP.245 The firm should first establish which beneficial owners are within its CDD scope. This screening question is separate from finding or verifying the ownership structure.

How often should PEP screening be repeated?

The principal sources do not create one global “every X days” rule. Set controls around applicable law, the risk of the relationship, source-data changes, customer events and any scheduled review required by policy or the relevant regime. Enhanced ongoing monitoring is a control objective; one technical cadence is not universal.

How long does someone remain a PEP after leaving office?

It depends on the jurisdiction and continuing risk. Current EU rules require consideration for at least 12 months and thereafter until no further PEP-specific risk is considered to remain. UK rules also use an at-least-12-month approach with longer treatment where continuing risk remains. Do not apply those periods as a worldwide rule.45

Is PEP screening the same as sanctions screening?

No. PEP screening identifies political exposure for AML risk management; sanctions screening identifies possible exposure to legal restrictions under the relevant sanctions regime. PEP status does not itself prohibit a relationship.

Who makes the final decision on a PEP relationship?

The firm does. Screening and workflow systems can surface candidates, organise evidence and route approvals, but the firm must apply its legal obligations, risk framework and policy to decide the appropriate treatment.

Build the review around evidence and risk

A strong PEP-screening control moves beyond the database result: resolve identity, confirm the role or relationship, assess risk, apply the relevant measures, record the decision and reassess when facts change.

Keeping those stages separate protects customers from automatic assumptions and gives compliance teams a clear record of why a relationship was cleared, escalated, accepted with controls or declined.

References

Footnotes

  1. FATF, Guidance: Politically Exposed Persons (Recommendations 12 and 22), June 2013, accessed 24 August 2026. 2 3 4

  2. FATF, The FATF Recommendations, Recommendation 12 and glossary, as amended June 2026 and accessed 24 August 2026. 2 3 4 5 6 7 8 9 10 11 12

  3. UK legislation, Money Laundering and Terrorist Financing (Amendment) Regulations 2023, effective 10 January 2024. 2 3

  4. EUR-Lex, Directive (EU) 2015/849, consolidated text, especially Articles 3 and 20–23, consolidated 30 December 2024. 2 3 4 5 6 7

  5. UK legislation, Money Laundering Regulations 2017, Regulation 35, current as amended and accessed 24 August 2026. 2 3 4 5 6 7

  6. FinCEN and federal banking agencies, Statement on BSA due diligence requirements for customers who may be considered politically exposed persons, 21 August 2020. 2

  7. FCA, FG25/3: Treatment of politically exposed persons, published 7 July 2025 and updated 16 July 2025. 2

  8. EUR-Lex, Regulation (EU) 2024/1624, adopted 31 May 2024 and generally applicable from 10 July 2027.

  9. EUR-Lex, Directive (EU) 2024/1640, Article 77, adopted 31 May 2024.

  10. FCA, The treatment of politically exposed persons, updated 3 December 2025.

  11. FFIEC, BSA/AML Manual — Politically Exposed Persons, accessed 24 August 2026.

Footer

PEP Screening Guide for Compliance Teams | Checklynx