From identification to action — the EDD obligation
Identifying a customer as a PEP is only the beginning. The real compliance work lies in what happens next: the Enhanced Due Diligence process that transforms a PEP identification into a documented, risk-proportionate assessment of whether — and how — the firm should maintain the relationship.
MLR 2017 Regulation 35 sets out four mandatory EDD measures that must be applied to PEP relationships. These are not a checklist to complete and file away — they are ongoing obligations that must be actively maintained for the life of the relationship and beyond.
Obtain senior management approval
The business relationship must be approved by a senior manager before proceeding — or, for existing customers who become PEPs, as soon as reasonably practicable.
Establish source of wealth
Take adequate measures to establish the source of the PEP's wealth — how they accumulated their overall net worth.
Establish source of funds
Establish the source of funds involved in the specific business relationship or transaction.
Enhanced ongoing monitoring
Conduct enhanced ongoing monitoring of the business relationship — more frequent and more intensive than for standard customers.
When does EDD kick in?
EDD must be applied at the point a customer is identified as a PEP — and must continue for as long as the PEP obligation exists. The trigger points are:
| Trigger | EDD required by when? | Notes |
|---|---|---|
| New customer identified as PEP at onboarding | Before relationship commences | Senior management approval must be obtained before proceeding |
| Existing customer becomes a PEP (e.g. wins election) | As soon as reasonably practicable | Suspend or restrict activity until EDD completed if necessary |
| Existing customer identified as RCA of a PEP | As soon as reasonably practicable | Same EDD obligations as direct PEP apply |
| Periodic review triggers PEP identification | Within review cycle | Update CDD file and obtain fresh senior management approval |
| Transaction screening produces PEP match | Before transaction proceeds | Investigate and apply EDD measures before allowing transaction |
Source of funds vs source of wealth — understanding the difference
Source of funds (SoF) and source of wealth (SoW) are two distinct concepts that are frequently confused — even by experienced compliance professionals. Getting the distinction right is essential because they address different risks and require different evidence.
Why both matter for PEPs
For standard customers, SoF alone may be sufficient. For PEPs, both are required because the risk being mitigated is fundamentally different: the concern is not just where these specific funds came from, but whether the PEP's overall wealth may include proceeds of corruption or abuse of public office.
A PEP who can explain where a specific £500,000 wire transfer came from (SoF: sale of shares) but cannot explain how they accumulated £10 million on a public sector salary (SoW: unclear) presents a very different risk profile to one who can document both clearly.
What evidence is acceptable?
| Source | Acceptable SoF evidence | Acceptable SoW evidence |
|---|---|---|
| Employment/salary | Payslips, employment contract, bank statements showing salary credits | Career history, salary history, tax returns over time |
| Business ownership | Dividend payment records, company accounts, shareholder agreements | Business ownership history, company valuations, sale agreements |
| Property | Sale completion statement, solicitor confirmation | Property purchase history, mortgage records, rental income history |
| Inheritance | Grant of probate, solicitor confirmation of distribution | Estate valuation, relationship to deceased, timing |
| Investment returns | Broker statements, portfolio valuations, sale confirmations | Investment history, initial source of invested capital |
Senior management approval
MLR 2017 Regulation 35(5) requires that the establishment of a business relationship with a PEP must be approved by senior management. This is a mandatory control — not a best practice recommendation.
What does "senior management" mean?
The MLR 2017 does not define a specific seniority level for the approving manager. The FCA's expectation is that the seniority of the approver should be proportionate to the risk presented by the specific PEP relationship:
- Standard domestic PEP — a senior compliance manager or MLRO may be appropriate
- High-risk foreign PEP — MLRO plus a senior business line manager or board-level sign-off
- Very high-risk PEP (e.g. head of state from high-corruption country) — board-level approval may be required, with documented rationale for accepting the relationship at all
What the approval must consider
Senior management approval is not a rubber stamp. The approver must genuinely consider:
- The nature and purpose of the relationship
- The PEP's role and the associated risk of corruption
- The adequacy of the SoF and SoW evidence obtained
- Whether the proposed business relationship is consistent with the firm's risk appetite
- Whether adequate ongoing monitoring can be maintained
- The reputational risk to the firm of the association
All of this must be documented. A one-line approval note is unlikely to satisfy the FCA — the file should show that senior management genuinely engaged with the risk.
Enhanced ongoing monitoring of PEP relationships
PEP monitoring must be more intensive than standard customer monitoring. MLR 2017 Regulation 35(5)(d) requires "enhanced ongoing monitoring" — but does not prescribe exactly what this means, leaving it to the firm's risk-based judgement.
What enhanced monitoring looks like in practice
| Monitoring type | Standard customer | PEP customer |
|---|---|---|
| Periodic CDD review | Every 3–5 years (low risk) | Annually minimum — more frequent for high-risk PEPs |
| Transaction monitoring thresholds | Standard rule set | Lower thresholds — more alerts generated |
| Adverse media screening | At onboarding and periodic | Ongoing — quarterly or more frequent for high-risk |
| Sanctions rescreening | When lists update | Real-time or daily — PEPs are more likely to be sanctioned |
| Source of funds review | At onboarding | Per transaction for significant amounts |
| Senior management review | Not required routinely | Annual review of relationship continuance |
Ongoing adverse media monitoring
Adverse media monitoring is a critical component of PEP ongoing monitoring. A PEP who appears clean at onboarding may subsequently be implicated in a corruption investigation, sanctions designation, or criminal prosecution. Your monitoring must be capable of detecting this.
For high-risk PEPs, many firms now use automated adverse media monitoring tools that alert compliance staff when a monitored name appears in relevant news sources. FinCrimeRadar's adverse media engine — powered by BBC, OCCRP, AP and DW — demonstrates how this works in practice.
PEP red flags — when to escalate
Beyond the standard EDD measures, compliance teams must be alert to specific red flags that indicate a PEP relationship may involve financial crime. These should trigger immediate escalation to the MLRO and consideration of a SAR.
Exiting PEP relationships — doing it right
Sometimes the right decision is to exit a PEP relationship — because the risk cannot be adequately managed, the firm cannot obtain satisfactory EDD documentation, or the reputational risk is unacceptable. Exiting a PEP relationship correctly requires as much care as managing it.
The tipping-off risk on exit
If a SAR has been filed — or is being considered — the firm must not exit the relationship in a way that tips off the customer that they are under investigation. A sudden account closure following a SAR filing can constitute tipping off under Section 333A POCA. Exits must be managed carefully with legal advice where a SAR is involved.
Documenting the exit decision
The decision to exit a PEP relationship — like the decision to accept one — must be documented. The file should record:
- The reason for the exit decision
- Whether a SAR was considered or filed
- Senior management sign-off on the exit
- The manner and timeline of exit
- Ongoing record-keeping obligations (5 years from exit)