PEP Screening Explained: Categories, Risk Tiers, and When Someone Stops Being a PEP
PEP screening explained: position tiers, foreign vs domestic rules, how RCA risk is derived, and when PEP status can actually end under FATF, EU and UK rules.

A politically exposed person is someone entrusted with a prominent public function (a head of state, minister, senior judge, central bank governor, or the equivalent) plus their close family and associates. PEP screening identifies those people at onboarding and thereafter, so the relationship can be given enhanced scrutiny. It is not a prohibition list, and a PEP match is not a reason to refuse anyone.
That last point is where most programmes go wrong in one direction, and where the "once a PEP, always a PEP" reflex sends them wrong in the other. This guide covers position tiers, the domestic/foreign split, how relatives and close associates inherit risk, and the question the web answers badly: when PEP status ends. Current as of August 2026.
What is a politically exposed person?
A PEP is an individual entrusted with a prominent public function, and the status exists because such people have disproportionate access to public funds and disproportionate ability to launder the proceeds of corruption. The status attaches to the office, not to any allegation. FATF is explicit that it is not intended to cover middle-ranking or junior officials [FATF Recommendations, Glossary].
Three separate axes get collapsed into the single word "PEP", and confusing them is the root of almost every bad PEP workflow:
- Position seniority: a head of government and a municipal councillor are both technically covered in many frameworks, and they are not the same risk.
- Domestic vs foreign: foreign PEPs and domestic PEPs carry materially different regulatory treatment, in opposite directions depending on the jurisdiction you are in.
- Principal vs RCA: the office-holder themselves, versus a relative or close associate (RCA) whose exposure is entirely derived from a relationship.
A screening engine that returns "PEP: yes" without resolving all three has told you almost nothing. The rest of this guide takes them in order.
One structural fact worth stating early: there is no official global PEP list. Sanctions lists are published by the designating government that made the designation. PEP data is compiled, from public records of who holds which office. That means coverage, depth and freshness vary between datasets in a way they do not for sanctions, and no compiled dataset is complete. That difference explains most of what follows, including why office end dates matter as much as the names, and why a PEP dataset should be treated as one input to a risk assessment rather than an authoritative register.
How senior does someone have to be to count as a PEP?
Seniority is a spectrum, and useful PEP data grades it rather than flattening it. DeRisk Hub classifies every position into three tiers, and a person inherits the highest-risk tier across every office they have held.
| Tier | What it covers | Examples |
|---|---|---|
| Tier 1 | National executive power, control over public money, and the top of the judiciary | Heads of state and government, cabinet ministers, deputy ministers, central bank governors, supreme and constitutional court judges, heads of national audit and revenue bodies |
| Tier 2 | National-level office without direct executive control, and senior state functions | Members of parliament, ambassadors and heads of mission, senior military officers, senior political party officials, board members and senior executives of state-owned enterprises, senior officials of international organisations |
| Tier 3 | Sub-national and local office | Regional governors, mayors, provincial and municipal legislators, local judiciary, sub-national agency heads |
Two mechanics matter more than the tier boundaries themselves:
- Tier is the maximum, not the current job. A backbench MP who was once finance minister is Tier 1. Risk follows the most sensitive office ever held, because that is where the access (and any proceeds) originated.
- Tier assignment is a data problem, not a scoring problem. Position titles vary enormously across countries and languages, and "Minister of Finance" has hundreds of local renderings. DeRisk Hub resolves each office to a canonical position identifier and tiers that, rather than string-matching the job title, so the same role grades consistently regardless of how it was written down.
Frameworks differ on where obligations start. FATF's definition covers prominent public functions at the national level and does not extend down to junior officials. The EU requires each Member State to publish a list of the functions that qualify as prominent public functions in that country, with the Commission compiling them, so in the EU the boundary is answerable by reference to a published document [Directive (EU) 2015/849, Article 20a]. Elsewhere it is a judgement call your policy has to make and document.
What is the difference between a domestic and a foreign PEP?
A foreign PEP is one holding office in a country other than the one you are screening them in; a domestic PEP holds office in your own. Every major framework treats foreign PEPs as inherently higher risk and domestic PEPs on a risk-sensitive basis, and since 2024 the UK and US positions have moved further apart than most people realise.
| Framework | Foreign PEPs | Domestic PEPs |
|---|---|---|
| FATF R.12 | Enhanced measures in all cases: senior management approval, source of wealth and source of funds, enhanced ongoing monitoring | Risk management systems to identify them; enhanced measures where the relationship is higher risk |
| EU (Directive 2015/849; AMLR 2024/1624 from 10 July 2027) | Enhanced due diligence required | Enhanced due diligence required: the EU applies the same measures to domestic PEPs |
| UK (MLR 2017 as amended, in force 10 January 2024) | Enhanced due diligence required | Starting point is that a UK PEP is lower risk than a non-UK PEP; where no enhanced risk factors are present, a proportionately reduced scope of EDD applies [FCA FG25/3] |
| US (BSA/CDD Rule) | Risk-based; no prescriptive PEP rule in regulation | The agencies do not interpret "PEP" to include US public officials, and there is no supervisory expectation of unique additional diligence for them [Joint Statement, 21 August 2020] |
Two practical consequences. First, "domestic" is relative to you, not to the PEP: a French minister is a foreign PEP to a UK bank and a domestic PEP to a French one, so the same record produces different obligations for different customers of the same screening vendor. Second, a global programme cannot run one PEP policy; the UK's lower-risk starting point and the EU's equal treatment of domestic PEPs are not reconcilable into a single rule.
DeRisk Hub resolves the foreign/domestic question per screening, by comparing the country attached to the PEP's office against the nationality or country of residence submitted for the entity being screened. Where either is unknown, the match is treated as foreign: the conservative reading, and the one that keeps a missing country field from quietly downgrading a risk.
That comparison feeds a ceiling on the risk level any PEP match can reach:
| Position tier | Foreign PEP | Domestic PEP |
|---|---|---|
| Tier 1 | Critical | High |
| Tier 2 | High | Medium |
| Tier 3 | Medium | Low |
The table is a cap, not a score. A weak name match against a Tier 1 foreign PEP does not become Critical because of the tier; it stays at whatever the name and identifier evidence supports, and the tier only limits how high it can go. The single exception is escalation in the other direction: an exact name match to a Tier 1 foreign PEP is raised to Critical, because that specific combination is the one no analyst should be able to miss in a queue.
What the cap governs is review urgency, not your legal obligation. It ranks a queue: which alerts an analyst opens first. It does not decide what due diligence the confirmed relationship then requires; that is set by your jurisdiction and your policy. An EU institution owes the same enhanced due diligence to a domestic PEP as to a foreign one whatever risk level the match carried into the queue. Any vendor whose risk score appears to reduce an obligation is describing prioritisation and labelling it compliance.
What is an RCA, and why does its risk come from someone else?
An RCA (relative or close associate) is a person whose PEP exposure exists solely because of their relationship to an office-holder. They hold no qualifying office. Screening them matters because assets and transactions are routinely routed through family members, which is precisely why every framework extends PEP measures to them.
Frameworks define the family perimeter differently, and the difference is not cosmetic:
| Relationship | EU Directive 2015/849 | EU AMLR 2024/1624 (from 2027) | DeRisk Hub data model |
|---|---|---|---|
| Spouse or equivalent partner | Yes | Yes | Yes |
| Children (and their spouses/partners) | Yes | Yes | Yes |
| Parents | Yes | Yes | Yes (father, mother) |
| Siblings | No | Yes, with Member States able to go broader where justified by social and cultural structures | Yes |
Close associates (business partners, beneficial owners of a PEP's vehicles, people with close business relationships) are handled by every framework in prose rather than by enumeration, because the category cannot be closed. No dataset will ever contain all of them. Treat compiled RCA data as a floor on the relationships you know about, not a complete map.
How RCA risk is derived
An RCA record carries no tier of its own. There is no office to tier. Risk is derived:
- Resolve every principal the RCA is linked to, with the relationship type.
- Compute each principal's PEP risk in full, including the tier cap and the foreign/domestic test, evaluated against the screened entity's country, not the principal's.
- Take the highest of those, then step one band down: Critical becomes High, High becomes Medium, Medium becomes Low, and Low stays Low.
The one-band step is the whole design argument. Flattening every RCA to a fixed level loses the difference between the spouse of a foreign head of state and the sibling of a municipal councillor, and those are not the same file. Deriving without a discount treats the relative as the office-holder, which over-alerts a category already prone to it. Where the link to a principal cannot be resolved at all, the match is capped at Medium rather than dropped: an unresolved relationship is a reason to look, not a reason to clear.
The same caveat applies as to the tier cap: the step-down orders the review queue, it does not reduce what the frameworks require. FATF, the EU and the UK all extend PEP measures to family members and close associates, and a confirmed RCA is subject to those measures at whatever level your policy sets, not at whatever level the alert arrived with.
Where an RCA is linked to several principals, the highest-risk principal governs. And people can be both: an office-holder who is also the child of another office-holder is scored as a PEP on their own office, with the relationship surfaced alongside it.
When does someone stop being a PEP?
Under FATF's standard, never automatically: the handling of a person no longer entrusted with a prominent public function should be based on an assessment of risk, not on prescribed time limits [FATF Guidance on PEPs, June 2013]. The EU and UK both set a floor of at least 12 months, not a cut-off.
This is the most commonly mis-stated fact in PEP compliance. The rules:
| Framework | What it actually says |
|---|---|
| FATF R.12 / 2013 Guidance | No time limit. Risk-based assessment of the individual, considering the level of influence retained, seniority of the former office, and any link between the former position and current activity |
| EU (Directive 2015/849, Art. 22) | Take into account the continuing risk and apply risk-sensitive measures for at least 12 months, until the person is deemed to pose no further risk |
| EU (AMLR 2024/1624, Art. 45) | Same construction: mitigating measures until the risks no longer exist, and in any case not less than 12 months. AMLA is to issue guidance on assessing residual risk by 10 July 2027 |
| UK (MLR 2017, reg. 35(14)) | Continue EDD for at least 12 months, or longer where the risk requires it |
Read them together and the answer is: 12 months is the earliest you may stop, never the point at which you must. "Once a PEP, always a PEP" is a defensible institutional policy; it is not what the rules require, and applying it indiscriminately is a documented contributor to de-risking and unjustified account closures.
Applying the rule at all depends on data that carries office end dates, which many PEP datasets do not. Without them there is no "no longer entrusted" date to run the 12 months from, and no way to assess residual risk except by hand. DeRisk Hub carries the office history on the match itself, so a reviewer sees which state the person is in:
| Office status | Why it matters |
|---|---|
| Currently in office | Full PEP treatment; nothing to assess about residual risk yet |
| Recently left office | The population the ≥12-month EU and UK rules govern. The clock runs from the office end date, which is on the record |
| Left office some time ago | Still surfaced, with the dates. FATF sets no expiry, so neither does the platform: this is where the risk-based judgement actually happens |
| Office history incomplete | Surfaced and flagged as incomplete, not silently cleared |
Two deliberate choices sit behind that, and both point the same way as the rules rather than across them. The platform's own retention of former office-holders runs well past the 12-month statutory floor, because 12 months is the earliest a firm may stop applying measures, not a point at which the data should disappear from under it. And the platform never declassifies anyone automatically: it supplies the office dates and surfaces the match; whether residual risk has fallen away is a documented, risk-based decision for the firm, exactly where FATF, the EU and the UK put it.
Does a PEP match mean you have to refuse the customer?
No. A PEP match triggers enhanced due diligence, not refusal. Nothing in FATF, EU, or UK rules prohibits a business relationship with a PEP. What they require is senior management approval to establish or continue the relationship, reasonable measures to establish source of wealth and source of funds, and enhanced ongoing monitoring [FATF R.12].
The distinction matters commercially as well as ethically. Blanket refusal of PEPs and their families is a well-documented form of de-risking, and it is the behaviour the standard-setters are now actively pushing against: FATF revised Recommendation 1 and its Interpretive Note in February 2025 to strengthen proportionality and simplified measures, replacing "commensurate" with "proportionate" and explicitly framing over-application of controls as a harm [FATF, 25 February 2025]. The UK's 2024 domestic-PEP amendment came from the same direction. Refusing every PEP is not the safe option any more; it is a supervisory finding in waiting.
DeRisk Hub encodes the distinction in the workflow rather than leaving it to training:
| Match category | Available decisions | Effect on the entity |
|---|---|---|
| Sanctions | True Match, False Positive | A confirmed true match blocks the entity |
| PEP / RCA | Confirmed, Not a Match | Never blocks the entity: a confirmed PEP is recorded as exposure requiring EDD |
The two are also rolled up separately: a case carries a sanctions risk level and a PEP risk level as distinct fields, and an entity's PEP exposure is reported alongside (not merged into) its sanctions risk. A confirmed PEP and a confirmed sanctions hit are different facts with different consequences, and a system that averages them into one "risk score" has destroyed the information you need to act on either.
Frequently asked questions
Are PEPs illegal to serve? No. PEP status is not a sanction, a designation, or an allegation. It requires enhanced due diligence (senior management approval, source of wealth and funds, enhanced monitoring) and permits the relationship on that basis. Refusing PEPs as a class is de-risking, and standard-setters are pushing against it, not for it.
Is a mayor a PEP? Usually yes, at the lowest tier. Mayors and sub-national officials fall into Tier 3 in most gradings: covered, but at the level of risk their actual access justifies. FATF's definition targets prominent public functions and is not intended to reach junior officials; where the line sits for local office is a policy call you should document.
Do PEP lists include family members? Yes, and they must: every framework extends PEP measures to family members and close associates. But the family perimeter differs by regime: siblings are outside the EU's current statutory definition and inside the incoming AMLR one. Close associates can never be exhaustively listed, so treat RCA data as a floor rather than a complete map.
How long does someone stay a PEP after leaving office? At least 12 months under EU and UK rules, and for as long as the risk persists under FATF's; there is no automatic expiry. Assess the influence retained, the seniority of the former office, and whether current activity connects to it. Twelve months is the earliest you may stop, not the point at which you must.
Is a US senator a PEP? Not for US banks. The US federal banking agencies and FinCEN stated in August 2020 that they do not interpret "politically exposed persons" to include US public officials, and there is no supervisory expectation of unique additional diligence for them. A non-US institution screening the same senator is looking at a foreign PEP with full EDD obligations.
What is the difference between PEP screening and sanctions screening? Sanctions screening tests a binary legal prohibition: the party is designated or is not. PEP screening identifies a risk category that changes how you conduct the relationship, not whether you may. See our guide to sanctions screening for the prohibition side.
Citations
- FATF, International Standards on Combating Money Laundering and the Financing of Terrorism & Proliferation, Recommendation 12 and its Interpretive Note, and the Glossary definitions of PEP, family members and close associates, https://www.fatf-gafi.org/en/publications/Fatfrecommendations/Fatf-recommendations.html
- FATF, Guidance: Politically Exposed Persons (Recommendations 12 and 22), June 2013, https://www.fatf-gafi.org/content/dam/fatf-gafi/guidance/Guidance-PEP-Rec12-22.pdf
- FATF, FATF updates Standards to better promote financial inclusion (revisions to Recommendation 1 and its Interpretive Note), 25 February 2025, https://www.fatf-gafi.org/en/publications/Fatfrecommendations/update-standards-promote-financial-conclusion-feb-2025.html
- Directive (EU) 2015/849, Articles 3(9), 20a, 22 and 23, https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=celex%3A32015L0849
- Regulation (EU) 2024/1624 (AMLR), Article 2(1)(35) and Article 45 (applies from 10 July 2027), https://eur-lex.europa.eu/eli/reg/2024/1624/oj/eng
- The Money Laundering, Terrorist Financing and Transfer of Funds (Information on the Payer) Regulations 2017, regulation 35, as amended by the Money Laundering and Terrorist Financing (Amendment) Regulations 2023 (in force 10 January 2024), https://www.legislation.gov.uk/uksi/2017/692
- FCA, FG25/3: The treatment of politically exposed persons for anti-money laundering purposes, 7 July 2025 (revised 15 July 2025), https://www.fca.org.uk/publications/finalised-guidance/fg25-3-treatment-politically-exposed-persons
- FinCEN, Federal Reserve, FDIC, NCUA and OCC, Joint Statement on Bank Secrecy Act Due Diligence Requirements for Customers Who May Be Considered Politically Exposed Persons, 21 August 2020, https://www.fincen.gov/sites/default/files/shared/PEP%20Statement_FINAL%20508.pdf
PEP screening that grades risk instead of flattening it
Most PEP screening returns a yes. The work is in everything after that: which office, how senior, foreign or domestic to this customer, principal or relative, still in post or eight years out, and whether any of it is recorded well enough to defend the decision two years later.
DeRisk Hub screens against global sanctions, export-control, law-enforcement and PEP data in a single pass, resolves tier, foreign/domestic status and RCA relationships automatically, keeps PEP exposure separate from sanctions risk, and writes every decision to an audit trail. See the screening platform, the compliance glossary, or how the sanctions lists compare. Start your free trial, or go to DeRiskHub.com.
This article is informational and does not constitute legal advice. Regulatory positions described here were verified against the issuing bodies' published material in August 2026 and change frequently: confirm against the primary source before relying on any of it.