A plain-English definition of a politically exposed person, the three PEP types, who counts as family or a close associate, and what enhanced due diligence actually involves.
A politically exposed person is someone who holds or has held a prominent public function, such as a head of state, senior politician, judge, or state-owned enterprise executive. Because those roles can be abused for corruption, regulated firms apply enhanced due diligence to the PEP and to family and close associates. PEP status is a risk marker, not an accusation.
A politically exposed person (PEP) is a natural person who is or has been entrusted with a prominent public function. Typical examples include heads of state and government, senior politicians, senior government, judicial, or military officials, senior executives of state-owned corporations, and important political party officials.
The definition comes from the Financial Action Task Force (FATF), the intergovernmental body that sets the global anti-money-laundering standards. Regulators single these roles out because holding public office gives access to public funds and to influence, and that access can be abused for bribery, corruption, or money laundering. So a firm that identifies a PEP has to look harder at the relationship than it would for an ordinary customer.
One point most pages miss: the categories are defined by the seniority of the function, not the individual. Middle-ranking and junior officials are not PEPs. And PEP status extends beyond the office-holder to their close family and business circle, which we cover below.
This is the single most important thing to understand, and the biggest source of real-world harm when firms get it wrong. Being a PEP does not mean a person has done anything wrong.
FATF splits PEPs into three categories, each defined by who conferred the prominent public function.
Individuals entrusted with a prominent public function by a foreign country, for example a head of state, a senior politician, a senior judicial or military official, or the chief executive of a state-owned corporation abroad. Under FATF, foreign PEPs are treated as higher risk by default.
The same categories of role, but conferred by the person's own country. FATF requires firms to assess the risk first and then apply enhanced measures where the relationship is higher risk. The UK now goes further and presumes domestic PEPs are lower risk than foreign PEPs unless other factors are present.
Individuals entrusted with a prominent function by an international organisation, meaning senior management such as directors, deputy directors, and board members at bodies like the IMF, the World Bank, the UN, or a development bank. As with domestic PEPs, treatment is risk-sensitive rather than automatically higher risk.
PEP controls do not stop at the office-holder. A corrupt official rarely holds tainted assets in their own name, so the requirements extend to the people around them, together known as relatives and close associates (RCAs).
The logic is simple: public office gives access to public money and to influence, and abuse of that access is one of the largest financial crimes in the world. The World Economic Forum, citing a UN estimate, puts the annual cost of corruption at roughly 3.6 trillion US dollars in bribes and stolen funds. Treat this as an order-of-magnitude figure rather than a current-year statistic.
The 1MDB scandal is the worked example PEP controls exist to catch. Malaysia's sovereign wealth fund was looted, with more than 700 million US dollars in 1MDB-linked funds reaching the personal accounts of a sitting prime minister. The failures reverberated through the financial system and contributed to the closure of the 140-year-old Swiss bank BSI. That is precisely the scenario enhanced due diligence on a PEP is designed to surface early.
Identifying a PEP triggers enhanced due diligence (EDD) on top of standard customer due diligence. FATF Recommendation 12 sets four required measures for foreign PEPs, and the same measures apply to domestic and international organisation PEPs where the relationship is assessed as higher risk.
These two terms are often used interchangeably, but they answer different questions and a PEP file needs both.
Everyone starts from the same FATF baseline, but the three major blocs have diverged. Firms operating cross-border now have to run jurisdiction-specific PEP policies. The table sets out the key differences.
The defining feature of the current moment is regulatory divergence on top of the common FATF baseline, alongside an active correction against over-classification.
United Kingdom. After the 2023 debanking controversy, the FCA concluded that firms were treating domestic politicians, public servants, and their families too harshly. Its review noted that UK firms closed roughly 343,000 accounts in the relevant period, about half because the firm could not satisfy itself the customer was not involved in financial crime, against just 1,083 money-laundering convictions in that window. From 10 January 2024 an amendment to the Money Laundering Regulations introduced a statutory presumption that domestic PEPs are lower risk. On 7 July 2025, revised 15 July 2025, the FCA published finalised guidance FG25/3, confirming that presumption, clarifying that non-executive board members of UK civil service departments are not PEPs, and requiring prompt removal of PEP status once a person no longer meets the definition.
European Union. The EU has passed its AML package: the Anti-Money Laundering Regulation (EU) 2024/1624 (AMLR), the sixth AML Directive, and a new supervisor, the Anti-Money Laundering Authority (AMLA). From 10 July 2027 the AMLR applies directly and identically across all 27 member states. It broadens the PEP definition, explicitly adds siblings as family members for the most senior functions, requires at least 12 months of continued EDD after a person leaves office, and tasks AMLA with issuing guidelines on identifying close associates.
United States. US anti-money-laundering rules do not define "PEP" at all. The 21 August 2020 FinCEN interagency Joint Statement confirmed there is no requirement to apply an automatic higher-risk designation, that the term is generally understood to mean senior foreign officials and their families and close associates rather than US officials, and that due diligence must be commensurate with the specific customer's risk.
You will often hear "once a PEP, always a PEP". As a statement of the standard, that is wrong.
PEP screening generates more false positives than almost any other part of customer due diligence. Screening tools match on partial and phonetic name equivalents, so a firm running fuzzy matching against a large PEP database will surface matches for anyone whose name loosely resembles a listed PEP, and common surnames produce match storms. Commercial lists are huge: LexisNexis maintains a global list of more than 3 million PEPs and foreign officials, and open-data project OpenSanctions publishes country files running into six figures. That scale is exactly why the false-positive load is so heavy.
This is where AI genuinely earns its place, by adding precision rather than replacing the underlying data or the human decision.
Entity resolution compares a customer against a candidate PEP using more than the name, weighing date of birth, nationality, location, occupation, and corporate links to decide whether they are truly the same person. That is where most false positives are killed. Natural language processing reads the surrounding adverse-media article and separates a genuine hit from a same-name coincidence, and continuous monitoring catches a status change or new adverse media in near real time rather than at the next annual review.
PEP controls sit inside the wider identity-verification funnel, and enhanced due diligence on a PEP is only as reliable as the certainty that the person onboarding is who they claim to be. Generative AI has made that certainty harder to obtain.
Sumsub's 2025 identity-fraud data reports deepfakes accounting for about 11 percent of all fraud globally, with attempts surging on some measures, and synthetic identity document fraud up over 300 percent in the US, with synthetic identities appearing in about 1 in 5 first-party frauds. Sumsub also finds AI-generated fake IDs available for as little as around 15 US dollars. A convincing deepfake or synthetic identity can defeat a liveness check that stands between a corrupt actor, or a PEP-linked proxy, and an account. The same name-matching weakness that causes false positives can be gamed in reverse, using transliteration variants and deliberate misspellings to slip a real PEP past a poorly tuned matcher. These are vendor findings from Sumsub, not regulator data.
2027 is the pivot. On 10 July 2027 the EU AMLR applies directly across all 27 member states, AMLA becomes fully operational, and AMLA issues binding guidelines on close associates and PEP risk levels. Expect the harmonised EU definition, siblings included and a 12-month floor, to become the reference point non-EU firms benchmark against.
Divergence continues. The UK will keep refining its proportionate, domestic-PEP-lighter model after FG25/3, and the US will keep its risk-based, definition-free stance, so cross-border firms will run jurisdiction-specific PEP policies indefinitely.
Monitoring becomes perpetual. Because PEP status is dynamic, an ordinary customer becomes a PEP the day they take office, periodic re-screening is giving way to event-driven, continuous monitoring, driven by both regulation and AI capability. This is the perpetual KYC pattern applied to PEP status changes. Analyst market forecasts, from MarketsandMarkets and Juniper Research, project the wider AML software market growing strongly to 2030, and expect continued tension between expensive commercial PEP lists and open-data alternatives.
Zenoo is a KYC, KYB, and AML orchestration platform. It is honest to be clear about what it does and does not do here. Zenoo does not publish or sell a PEP list, and it does not replace your screening provider such as LexisNexis, Dow Jones, ComplyAdvantage, Moody's, or an open source like OpenSanctions. If your underlying PEP data is thin, Zenoo will not fix that. What it does is coordinate the vendors you already use and apply AI to the workflow around the alert.
Zenoo does not decide whether someone is a PEP; that depends on the quality of the list you subscribe to. It does not remove the legal obligation to obtain senior-management approval or to document source of wealth and funds; a human still signs off. It cannot stop a deepfake or synthetic identity at the front door by itself; that is the job of the identity-verification and liveness vendors it orchestrates. And it does not set your jurisdiction policy; you still decide how you treat domestic versus foreign PEPs under UK, EU, and US rules.
A quick reference for the acronyms used on this page.
Zenoo does not sell a PEP list. It orchestrates the screening vendors you already use, routes PEP and sanctions checks with automatic failover, and puts 10 specialised AI agents on the alert so analysts start from a recommendation and a full audit trail, not a blank match.