PEP and sanctions screening are two of the most consequential controls in any AML compliance program, and the ones most often mistaken for one another.
A sanctions match is a legal prohibition, whereas a PEP match is a risk signal that demands closer scrutiny, and that difference shapes every decision a compliance team makes when an alert fires.
According to OFAC, the SDN List is updated as necessary, with no advance notice, and names are added or removed as needed. OpenSanctions, which mirrors OFAC’s own published data feed, counts over 20,000 current targets on the list, with updates arriving sometimes several times in a single week.
Sanctions lists, however, do not capture politically exposed persons, and PEP-linked corruption moves through the financial system whether or not a name ever appears on a watchlist.
This guide explains what each control detects, where the two programs must work in coordination, and what separates a defensible joint program from one that only looks compliant on paper.
Key takeaways:
- Sanctions and PEP matches trigger different compliance responses
A sanctions match is a legal prohibition requiring immediate blocking. A PEP match triggers enhanced due diligence, but the relationship can continue.
- Relatives and close associates are the most commonly missed risk category
PEP databases often underrepresent RCA relationships, and illicit funds rarely move under the PEP’s own name.
- PEP obligations differ by jurisdiction
US rules apply enhanced due diligence to foreign PEPs only, while the EU AML Regulation extends those requirements to domestic officials from July 10, 2027.
- False positives in each program have different root causes
PEP false positives are an identity problem. Sanctions false positives are a configuration problem. The fix for one will not work for the other.
- Sigma360 runs both controls from a single shared entity record
With Sigma360, sanctions alerts and adverse media hits on the same counterparty appear together, helping compliance teams screen accurately and monitor continuously.
What is the difference between PEP and sanctions screening?
Both PEP and sanctions screening check individuals, entities, and associated parties against government sanctions lists and politically exposed person databases to identify legal restrictions and financial crime risk before or during a business relationship.
The two controls share the same infrastructure but produce fundamentally different obligations when a match is confirmed.
A sanctions match means the individual or entity appears on a list maintained by an authority such as OFAC, the UN Security Council, the EU, or the UK government. The institution must block or freeze all related transactions and report to the relevant authority. Under OFAC’s strict liability standard, a violation occurs regardless of whether the institution knew a designation had been made.
When screening returns a PEP match, it flags an individual who holds or has held a position of public trust. PEP status does not block the relationship, but it does require enhanced due diligence: source of wealth verification, senior management approval, and continuous monitoring.
Compliance teams that treat PEP and sanctions screening as interchangeable will miscalibrate both, because each control operates under a different legal framework and triggers a different compliance response.
The table below shows where they diverge.
| Dimension | PEP screening | Sanctions screening |
| Primary purpose | Identify elevated corruption and bribery risk | Identify legally restricted parties |
| Match consequence | Enhanced due diligence, ongoing monitoring | Blocking, freezing, or rejection |
| Can you onboard? | Yes, with controls in place | Not without a license or authorization |
| Key regulatory basis | FATF Recommendation 12, FinCEN CDD Rule, EU AMLR | FATF Recommendations 6 and 7, OFAC, OFSI, EU regulations |
| False positive profile | Name collisions, common surnames, transliteration errors | Misconfigured thresholds, incomplete entity data |
| Monitoring trigger | Role change, status change, new adverse media | List update, ownership change, new designation |
| EDD requirement | Source of wealth, senior sign-off, ongoing review | Risk-based review where relationship continues under license |
Understanding PEP tiers and RCA risk
PEP risk is not uniform across roles. FATF Recommendation 12 defines three categories (foreign, domestic, and international organization), but most screening programs operate with a four-tier model that treats relatives and close associates as a distinct category with its own risk profile.
| Tier | Category | Examples | Risk level |
| Tier 1 | International PEPs | Heads of state, prime ministers, heads of international organizations | Critical |
| Tier 2 | National PEPs | Members of parliament, senior judges, ambassadors, central bank governors | High |
| Tier 3 | Regional PEPs | Mayors, senior regional officials, state enterprise executives | Medium |
| Tier 4 | Relatives and close associates (RCAs) | Spouses, children, business partners of Tiers 1–3 | Variable |
Tier 4 is where most programs develop blind spots they cannot detect through structured data alone.
For instance, if a government minister is using illicit funds, the money might flow through a spouse’s account, a business partner’s company, or a family trust rather than under the minister’s own name.
FATF Recommendation 12 requires institutions to take reasonable measures to identify close family members and known associates of PEPs, but database coverage of RCAs is often incomplete, with relationships undocumented or changing over time.
Adverse media screening is the most reliable way to detect RCA-linked exposure that PEP databases do not yet reflect. A business associate named in a financial crime investigation, or a spouse connected to a state contract dispute, will appear in public reporting well before any structured database carries the update.
When PEP and sanctions screening must run
Neither control is a one-time check. Both must run at multiple points in the customer lifecycle, and the triggers for each are not identical. They should run:
- When onboarding a new customer. Screen all relevant parties before the relationship begins: the customer, directors, beneficial owners, authorized signatories, and any known associates. Incomplete data at this stage reduces matching accuracy for every subsequent check.
- When processing transactions. Sanctions screening must run at the point of payment for transactions involving cross-border transfers, correspondent banking, or high-risk corridors. A counterparty with a clean record at onboarding may carry new sanctions risk by the time a payment is initiated.
- When customer data changes. Changes in ownership structure, directors, geographic location, or beneficial ownership must trigger rescreening across both controls. A new ownership layer can bring a previously clean entity into PEP or sanctions scope without triggering a list update.
- When lists are updated. Sanctions lists change without advance notice and on no fixed schedule. OFAC’s SDN List is updated as necessary, with active periods delivering several new entries in a single week. Any institution running periodic batch screening rather than continuous monitoring leaves an interval between runs where a freshly designated party faces no check until the next cycle runs.
- When a PEP’s circumstances change. Someone who held no PEP designation at onboarding can acquire one overnight through election results or a government appointment. Perpetual monitoring catches status changes as they enter public reporting, often before any structured database has been updated.
Read more: What is Real-Time Sanctions Screening: Complete 2026 Guide

Domestic vs. foreign PEPs: A regulatory divergence with real consequences
PEP classification and the due diligence obligations it triggers are not uniform across jurisdictions, and the differences have direct operational consequences for institutions screening across multiple regulatory frameworks.
United States
BSA/AML regulations do not formally define PEPs. The USA PATRIOT Act Section 312 establishes enhanced due diligence for senior foreign political figures in private banking accounts, while the 2020 FinCEN Joint Statement clarified that US regulators do not interpret PEPs to include domestic public officials.
Risk-based CDD applies to all PEP relationships, but the formal EDD obligation under US law targets foreign individuals.
European Union
The EU AML Regulation requires enhanced measures for both domestic and foreign PEPs regardless of where they hold their position. AMLA, operational since July 2025, will directly supervise the highest-risk entities under that framework.
Institutions operating across both US and EU jurisdictions need separate calibration for each.
United Kingdom
The Money Laundering Regulations and OFSI guidance apply enhanced due diligence to PEPs regardless of origin, with a risk-based approach determining the depth of review required. The UK Sanctions List has been the sole authoritative source for UK designations since January 28, 2026, and must be screened independently of EU lists.
Public reporting follows none of these classifications. A domestic official excluded from formal US EDD obligations can still generate material adverse media, and those findings warrant the same investigative review as any other high-risk signal.
FATF and supervisory standards across both controls
The international standards that underpin jurisdictional rules above define what financial crime compliance programs must demonstrate when examined:
- FATF Recommendations 6 and 7 require countries to implement targeted financial sanctions without delay across terrorism financing and proliferation financing programs. Where countries have implemented these obligations into national law, institutions must screen against all applicable designations across every jurisdiction in which they operate.
- FATF Recommendation 12 requires enhanced ongoing monitoring for PEP relationships, extending that obligation to family members and close associates. The monitoring requirement does not end when a PEP leaves office, and residual influence and conduct risk from prior roles can persist long after a classification lapses.
- EBA Risk Factors Guidelines, applying from December 30, 2024, treat adverse media monitoring as a baseline expectation for PEP relationships, not an optional enhancement, and flag its absence as a program weakness during supervisory review.
Institutions that ran proper screening at relationship inception but failed to act on subsequent list changes, PEP status updates, or emerging adverse media have faced penalties on the same basis as those with no screening program at all.
How false positives differ between the two controls
Meeting these standards in practice depends on programs that generate accurate alerts. False positives undermine both controls, but the root cause and the fix differ between them.
PEP false positives: An identity problem
Common names, shared surnames across large populations, and transliteration variations between scripts generate matches that require secondary identifiers to resolve. Date of birth, nationality, and known addresses are the filters that separate a genuine PEP match from a coincidental name collision.
Sanctions false positives: A configuration problem
The matching threshold determines what the engine flags and what passes through unchallenged. A threshold calibrated too broadly floods the queue with low-confidence hits that obscure genuine matches. However, if you tighten it too far, near-matches pass through without review.
As the FFIEC BSA/AML Examination Manual notes, a high volume of false hits indicates a need to review the interdiction program, and threshold settings must be documented and defensible. Risk-based calibration, applying tighter settings for high-risk segments and payment corridors with AI-assisted scoring for volume flows, reduces alert volume without reducing genuine detection.
Running both controls on the same platform does not eliminate the need for separate calibration. The sources of error are distinct, and a configuration designed for one will systematically underserve the other.

Common mistakes in PEP and sanctions screening programs
Most compliance failures in this area trace back to a handful of recurring program design errors, each creating liability that regulators and examiners consistently identify. The OFAC Framework for Compliance Commitments identifies internal controls as one of five essential program components:
- Screening the customer name only, leaving beneficial owners, directors, and RCAs outside the check entirely
- Relying on a single sanctions list, so EU, UN, or UK designations go undetected when OFAC alone is screened
- Treating PEP and sanctions alerts through the same escalation path, despite their different legal consequences and resolution requirements
- Running screening only at onboarding, so new designations, political appointments, and ownership changes create unchecked exposure mid-relationship
- Applying a single global matching threshold across all customer segments, when high-risk corridors and routine onboarding flows require different calibration
All five are well-documented in enforcement actions, and all five are avoidable with program design that reflects how the two controls actually differ.
Read more: The Only Sanctions Screening Checklist You Need in 2026

How Sigma360 runs PEP and sanctions screening
The three failure patterns this article traces each require a different technical response. Running them through separate tools means calibrating each in isolation, without visibility into how a sanctions alert and a PEP match on the same entity relate to each other.
Sigma360 runs PEP screening, sanctions and watchlist screening, adverse media monitoring, and perpetual KYC from a single shared entity record. When a watchlist hit and an adverse media development appear on the same counterparty, analysts see both in one place rather than reconciling findings across disconnected systems.
Each capability maps to a specific failure mode:
- Match Agent applies entity resolution across name variations, transliterations, date-of-birth fields, and ownership structures, targeting the identity disambiguation problem that drives PEP false positives at their source rather than after the alert is generated.
- Adverse Media Agent consolidates open-source coverage of a PEP or their associates into a single risk narrative, giving analysts the conduct context and RCA-linked exposure that structured databases cannot carry.
- Perpetual KYC rescreens relationships continuously as sanctions lists update and PEP status changes enter public reporting, so the monitoring cadence runs on the data’s schedule rather than on a review cycle.
In 2026, Chartis Research independently assessed Sigma360 as the top-ranked solution on technical capability and a Category Leader across both Name and Transaction Screening and Adverse Media Monitoring, a position reinforced by back-to-back #1 rankings in Adverse Media Solution and Adverse Media Data in the FCC50. The platform covers 100B+ data points and 150+ corporate registries, with SOC 2 Type II and ISO/IEC 27001:2022 certification, and 99.9% uptime.
To speak with a compliance expert about how Sigma360 handles PEP and sanctions screening, or to explore how AI in financial crime compliance applies across your program, get in touch with the team today.
FAQ
Can you do business with a PEP?
Yes, but the relationship requires senior management approval, source of wealth verification, and ongoing monitoring before it can proceed. PEP status is a risk classification, not a legal prohibition.
How long does PEP status apply after someone leaves office?
Most frameworks require at least 12 months of continued elevated scrutiny after departure. A risk-based assessment determines how long PEP status applies beyond that.
Do relatives and close associates of a PEP need to be screened?
Yes. RCAs of an active PEP carry the same EDD obligations as the named PEP and are subject to the same ongoing monitoring requirements.
What triggers a fresh sanctions screen for an existing customer?
A list update, an ownership change, a new correspondent banking relationship, or a payment through a high-risk corridor should each prompt immediate rescreening.
How does AI change PEP and sanctions screening in practice?
AI clears low-confidence false positives before they reach the analyst queue, reducing the manual workload without removing human judgment from escalation and final decisions.
