Politically Exposed Persons (PEPs) in AML: A Complete Guide

A politically exposed person, or PEP, is someone who holds or has held an important public role, along with their close family members and close associates. In anti-money laundering (AML) work, PEPs matter because a public role can come with influence over public money, contracts, and decisions, and that influence can be misused.

Here is the part most people get wrong. Being a PEP is not a crime, not a sanction, and not a reason to refuse someone. It is a signal that you need to look more carefully before you say yes and keep looking afterwards.

This guide explains what PEPs are, how to find them, how to judge the risk they carry, and what you must do about it.

Quick Summary: What This Guide Covers

  • What a PEP is, in plain words, plus what PEP status does and does not mean for a customer.
  • The three main PEP types (domestic, foreign, and heads of international organisations) and why family members and close associates are included.
  • Who must screen for PEPs in the UAE, from banks and virtual asset firms to real estate agents, auditors, and law firms.
  • A step-by-step PEP identification process, from collecting the right details to making a documented decision.
  • PEP declaration forms: what to ask, and why a signed form on its own is never enough.
  • How to handle screening alerts, separate real matches from false ones, and write a clearing note that holds up.
  • PEP risk assessment, including a worked example of why one PEP is rated high and another is rated medium.
  • Enhanced due diligence in practice: source of funds, source of wealth, senior management approval, and ongoing monitoring.
  • When someone stops being a PEP, plus red flags, common mistakes, and a ready to use compliance checklist.

What Is a PEP in AML?

In AML, PEP stands for politically exposed person. It refers to a natural person who has been given an important public role, either in the UAE or in another country, together with their immediate family and known close associates.

The UAE rules describe PEPs as people entrusted, now or in the past, with prominent public functions. That includes heads of state and government, senior politicians, senior government officials such as judges and military officers, senior executives of state-owned companies, senior political party officials, and people running international organisations or holding a prominent role inside one (Cabinet Resolution No. 134 of 2025, Article 1).

PEP Full Form and Simple Meaning

PEP stands for politically exposed person. You will see both the short form and the full phrase used interchangeably in policies, onboarding forms, and screening software. Some firms also write “PEPs in AML” or “AML PEP” when they mean the same thing.

What Counts as a Prominent Public Function

A prominent public function is a role that carries real weight in public life. The test is not fame. It is influence.

Ask three simple questions:

  • Can this person influence how public money is spent?
  • Can this person influence policy, licences, permits, or contracts?
  • Can this person influence who gets appointed to other positions?
  • If the answer is yes to any of them, the role is likely a prominent public function. A little-known procurement director can matter more than a well-known figure with a ceremonial title.

A PEP Is Always a Person, never a Company

Companies are not PEPs. Only individuals are.

But a company can absolutely carry PEP exposure. That happens when a PEP sits behind it as an owner or controller. This is why beneficial ownership checks sit at the heart of PEP work, and why screening only the company name will miss the risk completely. More on this further down.

What PEP Status Does Not Mean

This is worth saying clearly, because it causes real confusion for customers filling in forms:

  • PEP status is not an accusation. It says nothing about whether the person has done anything wrong.
  • PEP status is not a sanction. Sanctions are a legal prohibition. PEP status is not.
  • PEP status is not an automatic refusal. It is a trigger for closer checks and a documented decision.

What it does mean is simple. The file needs more work, the approval needs to come from higher up, and the relationship needs closer watching.

Why PEPs Are Treated as Higher Risk in AML

The logic is not complicated. A person who controls public spending has something valuable to sell, and someone is usually willing to buy it.

Access, Influence, and Control Over Public Money

Public roles create opportunities that most customers simply do not have. Awarding a contract. Approving a licence. Signing off a payment. Where oversight is weak, those opportunities can turn into personal gain, and the proceeds must be moved, hidden, and made to look normal. That is exactly the process described in the stages of money laundering.

The Bribery and Corruption Link

Most PEP risk is really corruption risk. Bribery money does not stay in cash. It moves into property, jewellery, company shares, and investment accounts, which is why businesses far outside the banking sector end up handling it.

What It Costs Your Business to Get This Wrong

Three things are on the line.

The first is regulatory. Supervisory authorities can issue administrative fines from AED 10,000 up to AED 5,000,000 for each violation, along with restrictions on your activity and, in serious cases, action against your licence (Federal Decree-Law No. 10 of 2025, Article 17).

The second is reputational. Being the firm that moved a corrupt official’s money is not something a press release fix.

The third is operational. Once a PEP with real influence gets inside a business relationship, they can start pushing for exceptions, faster approvals, and fewer questions. Your own decision-making stops being your own.

Higher Risk Does Not Mean Automatic Rejection

Refusing every PEP feels safe. It is not good practice, and it is not what the risk-based approach asks of you.

Blanket refusal tells a supervisor that you do not have a working framework, only a blunt instrument. It also cuts off legitimate customers for no good reason. What supervisors want to see is a decision, with reasoning, written down.

Types of PEPs: Domestic, Foreign, and Heads of International Organisations

There are three core categories, and one broader group that sits alongside them.

Domestic PEPs

Domestic PEPs hold prominent public roles inside the UAE. Think federal and emirate level ministers, senior officials, judges, senior military officers, and senior executives at government owned entities.

Foreign PEPs

Foreign PEPs hold equivalent roles in another country. The role type is the same. What changes is the difficulty. You are usually working with less reliable information, an unfamiliar governance environment, and no easy way to verify what someone controls.

Heads of International Organisations

This group covers people running international bodies or holding a prominent function within one, such as directors, deputy directors, and board members at organisations like the World Bank or the IMF. An ordinary employee at such an organisation is not in this category. Seniority is the point.

Comparison Table: Domestic vs Foreign vs International Organisation PEPs

CategoryWho it coversExamplesUsual starting riskWhat you must do
Domestic PEPProminent public roles held in the UAEMinister, senior government official, judge, senior military officer, head of a state-owned companyMedium to high, depending on role and relationshipIdentify the status, then apply the enhanced measures where the relationship is high risk
Foreign PEPEquivalent roles held in another countryForeign minister, foreign head of state, senior foreign official, senior executive of a foreign state-owned entityUsually highApply the full set of enhanced measures in every case
Head of international organisationSenior management of an international bodyManaging director, secretary general, chairperson, board memberMedium to high, depending on role and relationshipIdentify the status, then apply the enhanced measures where the relationship is high risk

Does You’re Handling Actually Change by Category?

Slightly, and this is where a lot of guides confuse people.

Under the UAE rules, foreign PEPs attract the enhanced measures as standard. For domestic PEPs and heads of international organisations, you must first have a way to identify them and then apply the same enhanced measures where the relationship is high risk (Cabinet Resolution No. 134 of 2025, Article 16).

In practice, most firms apply one consistent process to all three and let the risk rating drive how deep they go. That is simpler to run, easier to train, and easier to defend.

Family Members and Close Associates of PEPs

This is where firms fail most often. The screening tool flags the minister, but the actual customer is the minister’s spouse, and nobody made the connection.

Which Family Members Are Covered

The UAE definition includes immediate family: spouses, children and their spouses, and parents.

Treat that as the floor, not the ceiling. A sibling or an adult stepchild is not on the list, but if the relationship is being used to hold or move the PEP’s money, the list is not the point. Your risk-based judgement is.

Who Counts as a Close Associate

The definition also covers people known to be close associates of a PEP. That includes:

  • People who jointly own a company or legal arrangement with a PEP
  • People with other close professional or social relationships with a PEP
  • People who solely own a company or legal arrangement set up for a PEP’s benefit

In everyday language: business partners, front holders, close advisers, and anyone transacting on the PEP’s behalf.

PEP by Association and the Term “RCA”

You will often see the abbreviation RCA, which stands for relative or close associate. It is shorthand for exactly this group. Some teams call it PEP by association.

The important idea is that RCAs inherit scrutiny, not guilt. A PEP’s daughter is not suspected of anything. Her file just needs to explain where her money comes from.

The Practical Problem: Relationships a Database Cannot See

Family links are sometimes in commercial databases. Close associate links usually are not.

You will rarely find “close business partner of a serving official” in a data feed. You will find it in three other places: the answers on a declaration form, the story that emerges when you ask about source of wealth, and adverse media. That is why the human part of customer due diligence still carries the weight here, no matter how good your software is.

Where PEP Rules Come From

You do not need to memorise legislation to run PEP controls well. But you should know where the duties sit.

The UAE Position in Two Lines

The UAE’s AML framework is set by Federal Decree-Law No. 10 of 2025, with the operational detail in Cabinet Resolution No. 134 of 2025. PEP duties live in Article 16 of that resolution. You can read a fuller walkthrough in our guides to the new UAE AML law and Cabinet Resolution No. 134 of 2025.

Boiled down, the framework asks four things of you when a PEP is involved:

  1. Have a way to work out whether a customer or beneficial owner is a PEP.
  2. Get senior management approval before starting or continuing the relationship.
  3. Take reasonable steps to establish source of funds and source of wealth.
  4. Apply enhanced ongoing monitoring for as long as the relationship lasts.

That is the whole of it. Everything else in this guide is about doing those four things well.

If Your Policy Still Cites the Old Law

Worth a quick check. Federal Decree-Law No. 20 of 2018 and Cabinet Decision No. 10 of 2019 have both been replaced. If your AML manual, PEP procedure, or onboarding forms still reference them, the content may still be broadly right, but the citations are out of date and an inspector will notice. A short refresh of your AML policies and procedures usually sorts it out.

What FATF Asks For

Globally, PEP expectations come from FATF Recommendation 12, extended to non-financial businesses by Recommendation 22. FATF’s position matches the four duties above: identify, approve at senior level, establish source of funds and wealth, and monitor closely. Countries then write those expectations into their own law, which is what the UAE has done.

Which UAE Businesses Must Screen for PEPs

“We are too small to meet a PEP” is the most common reason firms skip this. It is also the weakest.

The duty follows your licence category, not your size, your customer numbers, or how likely you think it is that a PEP walks in.

Who supervises you Who this covers What is expected on PEPs
Central Bank of the UAE Banks, finance companies, exchange houses, insurance firms, payment providers Full PEP identification, senior approval, source of funds and wealth, enhanced monitoring
VARA Virtual asset service providers in Dubai Same duties, built into onboarding and wallet level monitoring. See our guide to AML laws for VASPs
DFSA and FSRA Firms licensed in DIFC and ADGM Same core duties under each authority’s own AML rulebook
Capital Market Authority Onshore capital markets and securities firms Same core duties. Relevant for asset managers and investment firms
Ministry of Economy and Tourism DNFBPs: real estate agents, dealers in precious metals and stones, accountants and auditors, lawyers and legal professionals, corporate service providers Same core duties, sized to the business. See our guide to AML laws for DNFBPs

One more group is easy to overlook. Life insurers must check whether the beneficiary of a policy is a PEP before paying out, tell senior management where the risk is higher, take a closer look at the whole relationship, and consider filing a report where needed (Cabinet Resolution No. 134 of 2025, Article 16). If you operate in the UAE insurance sector, the beneficiary is part of your PEP scope, not just the policyholder.

How to Identify a PEP: The Step-by-Step Process

There is no official checklist in the rules, so most firms build their own. Here is a version that works in practice, and that ends where it should, with a decision on record.

Step 1: Collect the Right Details

Screening quality is decided here, not in the software. Collect:

  • Full legal name, plus any other spellings or known variants
  • Date of birth
  • Nationality and country of residence
  • ID or passport number
  • Occupation, employer, and job title

Any public role held now or previously, and in which country

For the UAE market, name variants deserve special attention. The same person’s name can be transliterated from Arabic into English several different ways. Weak name data is the single biggest cause of both missed matches and alert overload.

Step 2: Ask the Customer Directly

Put the question in your onboarding pack. It costs nothing and it catches things databases miss, especially close associate relationships.

Step 3: Screen Against PEP Data

Run the details through your screening tool against PEP data, sanctions lists, and adverse media. This is also the moment to check the local terrorist list and applicable sanctions lists, since sanctions screening and PEP screening usually run through the same name screening process.

Step 4: Review the Alerts

Decide which hits are real. This gets its own section below, because it is where most of the daily work sits.

Step 5: Confirm the Category and Score the Risk

Once you have a real match, work out what type of PEP you are dealing with, then rate the risk. Not every PEP land in the same place.

Step 6: Decide, Approve, and Record

Approve, decline, or approve with conditions. Then write down what you decided and why. This step is skipped constantly, and it is the one an inspector will ask to see.

When to Screen: Not Just at Onboarding

Screening once at onboarding and never again is one of the most common findings in AML inspections. Screen again when any of these happen:

  • The customer takes up a public role, or steps down from one
  • Ownership or control of a corporate customer change
  • Adverse media appears
  • A large or unusual transaction comes through
  • Your PEP or sanctions data is updated
  • The file reaches its periodic review date

Your ongoing monitoring framework should carry these triggers, not an analyst’s memory.

PEP Declaration Forms: What to Ask and What They Cannot Prove

A lot of people search for terms like “PEP declaration meaning” or “PEP details” because a form has just asked them something they do not understand. So let us deal with both sides of it.

What a PEP Declaration Is

A PEP declaration is a short statement in which a customer confirms whether they are a politically exposed person or are related to or closely associated with one. It is usually part of the onboarding paperwork, alongside standard know your customer information.

Questions a Good Declaration Should Include

Keep it to five:

  1. Do you currently hold, or have you previously held, a prominent public role?
  2. If yes, what was the role, in which country, and over which period?
  3. Are you an immediate family member of someone who holds or held such a role?
  4. Are you a close business or personal associate of such a person?
  5. Do you hold or control a company jointly with such a person?

If You Are the Customer Being Asked

You have not been singled out, and you are not under suspicion. The question is asked of everyone, because the business is required to ask.

Answering yes does not mean you will be refused. It usually means a few extra questions and some documents about where your funds and wealth come from. Answering inaccurately is the thing that causes real problems, because it surfaces later and it looks deliberate.

Why a Signed Declaration Is Not Enough on Its Own

This is the part firms get wrong.

A declaration is a source of information. It is not verification. Someone who wants to hide a PEP connection will simply tick “no”, and a signed form does not discharge your duty.

The declaration works alongside screening, and where relevant, alongside source of wealth evidence. One without the others leaves a gap.

PEP Meaning on Banking and Insurance Forms

If you have seen the term on a bank account application, it is the same question in a different setting. Banks screen new customers and existing customers, and a real match leads to enhanced checks and senior approval.

On insurance forms, the question can apply to more than one person. The policyholder, the person insured, and the beneficiary may each need checking, and for life policies the beneficiary check happens before payout.

Handling Screening Alerts: True Matches and False Positives

Every compliance team knows this feeling. Ninety alerts, eighty-five of which are noise, and the same amount of time to work through all of them.

Why Tools Produce So Many False Positives

Four usual causes: very common names, transliteration differences between Arabic and English, missing dates of birth in your own records, and matching thresholds tuned too loose.

None of this is a reason to lower your standards. It is a reason to fix your data and tune your system. If alert volumes are burying your team, our note on alert fatigue is worth a read.

How to Clear a False Positive Properly

Compare the identifiers you actually have, then write the reason. Compare it yourself:

Not good enough: “Not a match. Cleared.”

Good enough: “Alert on customer A. Matched profile is a former minister of country X, born 1961. Customer holds passport of country Y, born 1988, no public role declared, occupation confirmed as private sector. Different individual. Cleared by [name], [date].”

The second one takes forty extra seconds and survives an inspection. The first does not.

What to Do in the First Hours After a Real Match

  1. Pause the onboarding or the transaction. Do not proceed on the assumption it will be fine.
  2. Escalate to your compliance officer or MLRO.
  3. Collect the extra information: role, country, period, and the relationship to the customer.
  4. Start on source of funds and source of wealth.
  5. Prepare the approval submission for senior management.

Who Decides

Analysts can clear false positives. Real matches belong with the compliance officer and then with senior management. The person who owns the customer relationship should never be the person who approves the risk. That conflict is obvious to everyone except, sometimes, the firm itself.

Keep the Records

Alerts, clearing notes, escalations, and decisions all form part of your record keeping. Records must be kept for at least five years (Cabinet Resolution No. 134 of 2025, Article 25). Screenshots in a shared inbox are not a record keeping system.

PEP Risk Assessment: Are All PEPs High Risk?

No. And treating them all as identical is a weakness in both directions.

Rate everyone high and you drown in EDD work you cannot complete properly. Rate everyone low and you have no framework at all. The answer is a rating you can explain, which is what your customer risk assessment model exists to produce.

The Factors That Drive PEP Risk

The role. How much influence does it carry? Any control over public spending? How senior, and how independent are the decisions?

The country. What is the governance and corruption picture where the role sits? Are there asset disclosure rules? Are corruption cases prosecuted?

The relationship. Is this the PEP, a family member, a close associate, or a company they own? Direct relationships usually carry more risk than distant ones, but a front holder can carry more than either.

The business context. What product or service, what value, which delivery channel, and does the activity make sense for the profile?

Adverse media and history. Any credible reporting on corruption, investigations, or enforcement.

Worked Example: Two PEPs, Two Ratings

Profile A: rated high. A serving deputy minister in a jurisdiction with a weak corruption record, buying property through a holding company registered in a third country, with funds arriving from an account in a company name. Real influence, weak external controls, layered structure, third party funding. Everything points up.

Profile B: rated medium. A municipal council member in a well governed jurisdiction, opening a small savings account, funded by a salary that matches payslips and past account history. The role carries limited spending authority, the funding is consistent and verifiable, and the product is simple.

Both are PEPs. Both need identification, senior approval, and monitoring. But the depth of work and the frequency of review should not be the same, and your file should say why.

Testing PEP Risk Against Your Risk Appetite

Risk appetite is simply how much risk your business has decided it can live with. It belongs in your ML, TF, and PF risk assessment and it should be approved by senior management.

Then use it. If a PEP sits outside your stated appetite, the answer is no, and that no is defensible. If you have no stated appetite, every decision becomes an argument.

Document Why You Rated a PEP as Medium

A medium rating on a PEP is perfectly acceptable if the reasoning is written down and supported. The same rating with no reasoning is indefensible, even if the conclusion was right.

The rating is not the finding. The missing explanation is.

Enhanced Due Diligence for PEPs: What You Actually Have to Do

The rules list the enhanced measures, and they are practical rather than mysterious. They include getting extra information, updating customer data more often, establishing source of funds and wealth, increasing monitoring, taking the first payment from an account in the customer’s own name, and obtaining senior management approval (Cabinet Resolution No. 134 of 2025, Article 5).

Here is what each one means in practice.

Establish Source of Funds

Source of funds answers one narrow question: where did this money come from?

Useful evidence includes bank statements showing the origin, a sale agreement, a dividend notice, or a loan document. Our note on source of funds goes deeper.

Establish Source of Wealth

Source of wealth answers a bigger question: how was this person’s overall wealth built?

Useful evidence includes employment and salary history, business ownership records with financial statements, inheritance documents, property sale records, or investment statements.

The common failure is accepting “salary” for wealth that plainly exceeds any plausible salary. If the numbers do not add up, the file has not been completed, it has only been filled in.

Source of Funds vs Source of Wealth

Comparison pointSource of fundsSource of wealth
Question answeredWhere did this money come from?How was the total wealth built?
ScopeOne transaction or depositThe person’s whole financial history
Typical evidenceBank statement, sale contract, dividend noticeSalary history, business accounts, inheritance papers, property sales
Common mistakeAccepting “savings” with nothing behind itAccepting a salary that cannot explain the wealth

The Other Enhanced Measures

  • Verify identity more thoroughly, using independent sources rather than what the customer supplied alone.
  • Understand the purpose of the relationship, and check whether the activity matches it.
  • Increase monitoring, both relationship and of individual transactions.
  • Route the first payment through an account in the customer’s own name where that control fits your business.

EDD Evidence Checklist for a PEP File

Before you close a PEP file, confirm you have:

  • [ ] Verified identity documents, checked independently
  • [ ] The public role, country, and period recorded
  • [ ] The relationship type recorded: PEP, family member, close associate, or beneficial owner
  • [ ] Screening results and the clearing or confirmation note
  • [ ] Source of funds evidence for the expected activity
  • [ ] Source of wealth evidence that plausibly explains the whole picture
  • [ ] Adverse media search results, with dates
  • [ ] A documented risk rating with reasoning
  • [ ] Senior management approval, with reasoning
  • [ ] A monitoring plan and a review date

Senior Management Approval: Who Signs Off and What to Record

Approval for a PEP relationship must come from senior management, both to start a relationship and to continue an existing one.

Who Should Approve, and Who Should Not

Senior management means the people with authority to make strategic and executive decisions that materially affect risk management and compliance. In most firms that is a chief executive, general manager, or board member.

It should not be the relationship owner, the sales lead, or the person whose bonus depends on the customer saying yes.

What the Approval Record Should Contain

An approval is a decision, not a signature. Capture:

  • Who was assessed, and their PEP category
  • The risk rating and the reasoning behind it
  • The EDD evidence that was reviewed
  • Any conditions attached, such as transaction limits or a shortened review cycle
  • Who approved it, in what role
  • The date

Approval for Existing Customers Who Become PEPs

A customer you onboarded three years ago gets appointed to public office. Nothing about your file changes automatically, but your duties do.

The relationship now needs the enhanced measures and a senior management decision to continue. This is a very common gap, because most firms only think about approval at onboarding.

When Declining Is the Right Answer

Sometimes the risk sits outside your appetite, or the customer will not provide what you need. Where you cannot complete due diligence, you should not establish or continue the relationship, and you should consider whether a suspicious transaction report is needed.

Document declines too. A file showing why you said no is worth as much as one showing why you said yes.

Ongoing Monitoring and Reviewing PEP Customers

Approval is the start of the work, not the end of it.

How Often to Review

Tie the cycle to the rating rather than using one interval for everyone. Broadly, high risk PEP files deserve review at least annually, and often more frequently. Medium risk files can sit on a longer cycle. What matters is that the cycle is stated in your policy and happens.

What Should Trigger an Early Review

A change in role, adverse media, a change in ownership of a corporate customer, unusual activity, or a data update that changes the match picture.

Transaction Patterns Worth a Closer Look

  • Money coming in from government linked entities with no clear commercial reason
  • Payments from third parties with no explained connection to the customer
  • Activity that jumps well beyond the expected level agreed at onboarding
  • Funds arriving from, or heading to, jurisdictions with weak controls, including those on the FATF grey list
  • Large cash activity that does not match the stated profile

Your transaction monitoring rules should treat PEP files differently from standard ones. If the same thresholds apply to both, the PEP flag is decorative.

Keep Your Screening Data Fresh

Political roles change constantly. People are appointed, elected, and removed, and your existing customer book changes with them.

Rescreening only new customers means you will always be behind. Periodic rescreening of the whole book is what catches the customer who quietly became a PEP last year.

When Does Someone Stop Being a PEP?

You will hear the phrase “once a PEP, always a PEP”. It is a useful instinct and a poor rule.

There Is No Fixed Time Limit

UAE rules do not set a countdown after which a former official stops being a PEP. The definition itself covers people previously entrusted with prominent public functions.

So this is a risk decision, not a calendar calculation.

Criteria for Stepping Down a Former PEP

Consider all of these together:

  • How senior was the role? A former head of state is not comparable to a former mid-level official.
  • How much time has passed? More time usually means less residual influence, but not always.
  • Does influence remain? Networks, informal authority, and family members still in office all count.
  • Was wealth accumulated during office? If the money dates from the period of the role, the risk stays with the money.
  • Any adverse findings? Investigations or credible allegations should stop a step down.

Document the Step Down

Write the decision the same way you write an approval: the criteria you applied, what you found, who decided, and the date. An undocumented downgrade looks like an unnoticed one.

Some Former PEPs Should Stay High Risk

A former minister for public procurement in a high corruption jurisdiction whose wealth clearly dates from their years in office should stay high risk regardless of how long ago they left. The role ended. The exposure did not.

PEPs Behind Companies: Beneficial Owners and Controllers

Most PEP exposure enters a customer book through a company rather than through a person walking in the door.

Screen the People, Not Just the Entity

For every corporate customer, screen the beneficial owners, the directors, the authorised signatories, and anyone else with real control. A clean company name tells you almost nothing.

How Layered Structures Hide Exposure

Holding companies in one jurisdiction, an operating company in another, nominee directors on the register, and the actual controller two layers back. Each layer is legal on its own. Together they put distance between the PEP and the transaction, which is often the point. Our note on beneficial ownership manipulation covers how this shows up in practice.

Shell and Shelf Companies

A company with no real activity, no staff, and no premises, owned by a PEP, is a much harder proposition than the same PEP as a direct customer. There is no business rationale to test, which means there is nothing to check the money against.

When One PEP Makes the Whole Relationship High Risk

Where several people control an entity and one of them is a high-risk PEP, the sensible default is to treat the whole relationship as high risk. Control rarely divides as neatly as an ownership chart suggests.

PEP Checks, Sanctions Checks, and Adverse Media: How They Differ

These three get bundled together in software and pulled apart by obligation. The difference matters.

Sanctions screening PEP screening Adverse media screening
What it finds People and entities subject to legal restrictions People in prominent public roles, plus their relatives and close associates Negative news, allegations, investigations
What it obliges you to do Stop. Freeze where required and report. You cannot proceed Apply enhanced checks, get senior approval, monitor closely. You may proceed Feed the finding into your risk assessment
Data source Official lists, published by authorities Commercial databases and public sources News, court records, registers
Is it a prohibition? Yes No No

The single most common mistake is treating a PEP hit as a prohibition. It is not. Sanctions are the prohibition.

Is There an Official Global PEP List?

No, and it is important to understand why.

Sanctions lists are published by authorities. There is no equivalent official global PEP list. What your software checks is a commercial database, built by a vendor from public records, government sites, media, and registries.

That has two consequences. Coverage varies between vendors, particularly for smaller jurisdictions and for close associates. And no vendor can honestly claim to be complete. This is exactly why data quality belongs in your AML software selection criteria rather than being assumed.

PEP Red Flags Worth Watching For

At Onboarding

  • Vague or evasive answers about occupation or public roles
  • Reluctance to explain source of wealth
  • A structure far more complex than the stated purpose needs
  • Funds arriving from an unexplained third party
  • Pressure to complete quickly, or hints about who the customer knows

During the Relationship

  • Activity that does not match declared income
  • Sudden inflows around procurement rounds, elections, or budget cycles
  • Transfers involving state linked entities with no commercial logic
  • Frequent requests for exceptions to normal process

Inside Your Own Firm

This one gets ignored, and it should not.

  • Staff being pressured to expedite a specific customer
  • Approvals sought after onboarding has already happened
  • Relationship owners pushing back on EDD requests as “too intrusive”
  • A pattern of one person clearing difficult alerts quickly

Most PEP failures do not begin with a clever criminal. They begin with an internal shortcut nobody wrote down.

Common PEP Compliance Mistakes and Inspection Findings

From what supervisors pick up:

  1. Screening only at onboarding. No rescreening of existing customers, so status changes are never caught.
  2. Treating the declaration as verification. A signed form filed as if it settled the question.
  3. Rating every PEP high, with no reasoning. Looks cautious, reads as no framework.
  4. Rating a PEP low, with no evidence. The mirror image, and harder to defend.
  5. Approval recorded as a signature with no rationale. A name and a date, nothing about what was considered.
  6. Source of wealth accepted at face value. “Family business” with no financials behind it.
  7. Screening tools never tested or tuned. Nobody has checked whether the system catches known cases, which is what name screening testing exists to establish.
  8. Policy and practice out of step. The manual describes a process the team does not follow, which a AML internal audit surface quickly.
  9. Policies still citing repealed law. A small thing that signals a bigger one.
  10. No training on PEPs. Front line staff who cannot recognise a prominent public function will not flag one. Targeted AML training fixes this faster than any system change.

A Practical PEP Compliance Checklist

Policy and framework

  • [ ] PEP definition and categories written into your AML policy
  • [ ] The four core duties reflected in a documented PEP procedure
  • [ ] Risk appetite statement covering PEP relationships
  • [ ] Roles and approval authority clearly assigned

Onboarding

  • [ ] PEP declaration question in the onboarding pack
  • [ ] Identity and role details captured, including name variants
  • [ ] Screening run against PEP, sanctions, and adverse media data
  • [ ] Beneficial owners and controllers screened, not just the entity

Risk assessment and approval

  • [ ] Documented rating with reasoning
  • [ ] Source of funds and source of wealth evidenced
  • [ ] Senior management approval recorded with rationale
  • [ ] Any conditions attached and communicated

Ongoing monitoring

  • [ ] Review cycle set by risk rating
  • [ ] Trigger events defined and operational
  • [ ] Existing customer book rescreened periodically
  • [ ] Monitoring thresholds adjusted for PEP files

Governance, training, and records

  • [ ] Senior management receives PEP reporting
  • [ ] Staff trained to recognise PEPs and close associates
  • [ ] Records retained for at least five years
  • [ ] Independent testing of the PEP process built into audit planning

How GRC Advisors Helps with PEP and High-Risk Customer Management

PEP compliance rarely fails because a firm does not know the rules. It fails in the gaps: a screening tool nobody tuned, a rating nobody explained, an approval nobody documented, a customer nobody rescreened after they took public office.

GRC Advisors works with UAE regulated entities to close those gaps. We build and test PEP and high-risk customer management frameworks that hold up under supervision, covering PEP identification, enhanced due diligence, risk scoring, approval governance, and ongoing monitoring. Where the problem sits in the system rather than the policy, we tune and test name screening configurations, including transliteration handling and match thresholds, so your alerts reflect real risk instead of noise.

Our wider AML and CFT compliance work covers AML policies and procedures, KYC and CDD frameworks, customer risk assessment models, STR and goAML reporting, AML internal audit, and regulatory inspection readiness. We work across CBUAE licensed institutions, VARA regulated virtual asset firms, DIFC and ADGM entities, CMA regulated firms, and mainland DNFBPs, so the framework you get reflects your actual supervisor rather than a generic template.

Frequently Asked Questions About PEPs in AML

What is a PEP in AML?

A PEP, or politically exposed person, is someone entrusted with an important public role now or in the past, together with their immediate family and close associates. In AML terms, it is a category that triggers closer checks rather than a prohibition.

Politically exposed person.

PEP status means a business has identified that you hold, or are connected to someone who holds, a prominent public role. It is not an accusation and not a refusal. It usually means additional questions and documents about your funds and wealth.

Heads of state and government, senior politicians, senior government officials including judges and military officers, senior executives of state-owned companies, senior political party officials, and senior figures at international organisations, plus their immediate family and close associates.

A serving minister, a senior judge, a head of a state-owned utility, a senior political party official, a managing director at an international organisation, and the spouse or business partner of any of them.

A domestic PEP holds the role in the UAE. A foreign PEP holds it in another country. Foreign PEPs attract the enhanced measures as standard, while for domestic PEPs those measures apply where the relationship is high risk.

No. PEPs are a higher risk category, but the actual rating depends on the role, the country, the relationship, and the business context. What matters is that your rating is reasoned and documented.

A short statement in which a customer confirms whether they are a PEP or connected to one, usually collected at onboarding.

The information a business needs to assess political exposure: the role held, the country, the period, and the nature of any relationship to a person holding such a role.

Ask the customer, then screen their details against commercial PEP data, sanctions lists, and adverse media. Manual checking alone is unreliable because there is no single official global list.

No. Unlike sanctions lists, PEP data comes from commercial providers who build it from public sources. Coverage varies, especially for close associates.

Senior management, meaning people with authority over strategic and compliance decisions. Not the person who owns the customer relationship.

It is shorthand for the idea that political exposure does not simply expire. Treat it as a reminder to make a reasoned decision rather than as an absolute rule.

Financial institutions, virtual asset service providers, and DNFBPs including real estate agents, dealers in precious metals and stones, auditors, lawyers, and corporate service providers. The duty follows the licence category, not the size of the business.

Yes, particularly where the risk exceeds your appetite or you cannot complete due diligence. Refusing every PEP as a policy is a weakness rather than a safeguard.

The same thing as everywhere else. Banks screen new and existing customers, and a confirmed match leads to enhanced checks and senior approval.

You may face administrative penalties, restrictions on your activity, and licence consequences, alongside reputational damage and the risk of being used to move the proceeds of corruption.

Insights & Success Stories

Related Industry Trends & Real Results