Section 01

Real-world case studies — lessons from failure

The most powerful way to understand what PEP compliance requires is to study where it has gone wrong. These cases — drawn from enforcement actions, regulatory findings, and publicly documented financial crime — illustrate the real consequences of PEP compliance failures.

Raiffeisen Bank — Russia PEP failures

Austria · 2022–2024 · Ongoing regulatory scrutiny

Compliance failure

Raiffeisen Bank International became one of the most scrutinised European banks following Russia's invasion of Ukraine in 2022, having maintained significant Russian operations and relationships with Russian oligarchs and state officials — many of whom were subsequently sanctioned.

The bank faced pressure from the ECB, US authorities (via correspondent banking), and multiple national regulators over its PEP and sanctions compliance. At issue: whether adequate EDD had been applied to Russian PEP customers before and after sanctioning, and whether the bank had robust processes to identify when existing customers became sanctioned.

Identified failures

  • PEP EDD not sufficiently robust for Russian state officials and oligarchs
  • Inadequate processes for identifying when existing customers became sanctioned
  • Source of wealth not adequately scrutinised for PEP customers with government connections
  • Insufficient adverse media monitoring — reputational risk not adequately assessed
Lesson: PEP EDD must anticipate the possibility of future sanctions designation. Robust SoW scrutiny at onboarding — and continuous adverse media monitoring — are the controls most likely to identify risk before a formal designation occurs.

Danske Bank — Estonia branch scandal

Denmark/Estonia · 2007–2015 · €200B+ suspicious transactions

Major failure

The Danske Bank Estonia scandal is one of the largest money laundering cases in European history. Between 2007 and 2015, approximately €200 billion in suspicious transactions — many from Russia and former Soviet states — flowed through Danske Bank's Estonian branch.

A significant proportion of the customers involved were PEPs, RCAs of PEPs, or companies connected to Russian and Ukrainian political figures. The bank's PEP identification and EDD processes were fundamentally inadequate — and the Estonia branch operated with minimal oversight from Copenhagen.

PEP-specific failures

  • PEP screening not applied systematically to the Estonia branch customer base
  • Beneficial ownership not adequately investigated — shell companies used by PEPs not identified
  • Source of wealth not established for customers with obvious public sector connections
  • No meaningful adverse media monitoring — documented corruption involvement of customers ignored
  • Internal whistleblower warnings about PEP-connected customers dismissed
Lesson: PEP compliance cannot be a head office exercise applied inconsistently to branches. Firms with international operations must ensure consistent PEP identification and EDD standards across all entities — and must act on internal warnings about PEP-connected customers.

Standard Chartered — FCA enforcement

UK · 2019 · £102.2 million fine

FCA enforcement

Standard Chartered was fined £102.2 million by the FCA in 2019 for AML failures including inadequate treatment of PEP customers. The FCA found that the bank had failed to apply adequate enhanced due diligence to a number of customers who were PEPs or connected to PEPs, particularly in its private banking and correspondent banking divisions.

PEP-specific failures

  • PEP status not identified for customers meeting the definition
  • EDD not applied where PEP status was identified
  • Source of wealth not established or not adequately documented
  • Senior management approval not obtained for some PEP relationships
  • Ongoing monitoring not enhanced for known PEP customers
Lesson: The FCA's enforcement approach to PEP failures focuses on the completeness of the EDD file — not just whether EDD was "done." Firms must be able to demonstrate, through documented evidence, that each of the four mandatory EDD measures was actually applied and is current.
🔍 Apply what you've learned
Search for PEPs connected to major enforcement cases
Try searching names from the case studies above in FinCrimeRadar — see how they appear in sanctions and PEP screening data.
Try PEP screening →
Section 02

FCA enforcement patterns — what triggers action

Analysis of FCA enforcement actions involving PEP compliance failures reveals consistent patterns. Understanding these patterns helps firms prioritise their compliance investment.

The FCA's top five PEP enforcement triggers

  1. No EDD file at all — PEP identified but no enhanced measures applied and no documentation of why not. This is the most basic failure and the hardest to defend.
  2. Inadequate SoW — EDD conducted but source of wealth not genuinely established. Accepting general statements ("successful businessman") without documentary evidence.
  3. Stale EDD — EDD completed at onboarding but not refreshed. A five-year-old EDD file for a PEP who has changed role, accumulated new wealth, or whose risk profile has changed significantly.
  4. Missing senior management approval — EDD conducted but approval not obtained or not documented. Verbal approvals without file notes are a common gap.
  5. Inadequate ongoing monitoring — PEP flagged but monitoring not enhanced. Standard transaction monitoring rules applied without adjustment for PEP risk.
💡
The FCA's file review test
When the FCA reviews PEP compliance, they pull individual customer files and ask: "Could I, reading this file, form a clear picture of who this customer is, where their wealth comes from, why we accepted this relationship, and what monitoring is in place?" If the answer is no — if the file is incomplete, inconsistent, or generic — enforcement risk is high. Good PEP compliance is as much about documentation quality as about the substance of the checks performed.
Section 03

Building an effective PEP screening programme

An effective PEP screening programme is more than a database subscription and a policy document. It is an integrated set of people, processes, systems, and governance that together ensure PEPs are identified, assessed, and managed appropriately throughout the customer lifecycle.

1
PEP policy
Written policy covering definition, categories, domestic vs foreign distinction, RCAs, EDD requirements, approval levels, and monitoring standards.
2
Screening technology
PEP database subscription (or free tools like FinCrimeRadar for learning). Automated screening at onboarding and ongoing. Alert management workflow.
3
EDD process
Documented SoF and SoW collection process. Questionnaire templates. Evidence standards. Escalation pathways. Senior management approval workflow.
4
Monitoring framework
Enhanced TM rules for PEP accounts. Adverse media monitoring schedule. Periodic review triggers. Sanctions rescreening frequency.
5
Governance & MI
MLRO oversight of all PEP relationships. Board/senior management reporting on PEP portfolio. Annual review of PEP policy against regulatory developments.
6
Staff training
PEP-specific training for onboarding, relationship management, and compliance teams. Updated training following FG25/3 and future regulatory changes.
Good practice — annual PEP programme review
Best practice firms conduct an annual review of their PEP programme against regulatory developments, enforcement trends, and the firm's own PEP portfolio composition. The July 2025 FG25/3 guidance should have triggered a review of domestic PEP policies and approval processes across the industry. Firms that haven't updated their PEP framework to reflect FG25/3 are operating on outdated guidance.
Interactive tool

The complete PEP EDD checklist

Use this interactive checklist to ensure your PEP EDD is complete. Tick each item as it is completed and documented in the customer file. This checklist reflects MLR 2017 requirements and FCA FG25/3 guidance.

🔍 PEP Identification
Customer screened against PEP database at onboarding
PEP status confirmed — category identified (head of state / minister / judiciary / military / SOE / international org)
Domestic vs foreign PEP determination made and documented
RCA screening conducted — family members and known close associates identified
PEP risk rating assigned (High / Medium / Lower) with documented rationale
💰 Source of Funds
Source of funds for the specific transaction/relationship established
Documentary evidence obtained and verified (bank statement, completion statement, payslip, etc.)
SoF is consistent with the customer's known profile and the nature of the relationship
🏦 Source of Wealth
Source of wealth established — full career/business history documented
SoW documentary evidence obtained (tax returns, company accounts, property records, inheritance documentation)
SoW tested for consistency with official salary history and publicly available information
Any inconsistencies between declared SoW and known information investigated and resolved
👔 Senior Management Approval
Senior management approval obtained before relationship commenced (or as soon as practicable for existing customers)
Approver's seniority is appropriate to the risk level of the PEP
Approval documented in writing with date and rationale (not a rubber stamp)
MLRO oversight confirmed (even where individual MLRO approval not required under FG25/3 for domestic PEPs)
📡 Ongoing Monitoring
Transaction monitoring rules enhanced for PEP account — lower thresholds, additional rules
Adverse media monitoring scheduled — frequency appropriate to risk (quarterly minimum for high-risk PEPs)
Sanctions rescreening frequency set — real-time or daily for active foreign PEPs
Periodic EDD review scheduled — annually for most PEPs, more frequently for high-risk
Annual senior management review of relationship continuance documented
📋 Documentation & Record Keeping
Complete EDD file maintained — all evidence, decisions, and approvals documented
File would satisfy FCA "file review test" — clear picture of who, what, why, and how monitored
Record retention set for 5 years from end of relationship
0 of 24 items completed
🔍 Complete your PEP EDD
Screen your PEP customer across sanctions, PEP databases and adverse media
FinCrimeRadar covers all three screening types required for PEP EDD — free, live data, no sign-up.
Screen now →
FAQ

Frequently asked questions

How do I handle a PEP who is also on a sanctions list? +
If a PEP is also on a sanctions list, the sanctions obligation takes precedence and is immediate — you must freeze assets, refuse transactions, and report to OFSI within 14 days of becoming aware. The PEP EDD obligations continue to apply alongside the sanctions obligations, but the sanctions measures are non-discretionary. If the customer was previously known as a PEP and has now been sanctioned, you should review your PEP EDD file to assess whether signs of the eventual designation were present earlier and whether a SAR should have been filed sooner.
Our PEP customer has now left office — what changes? +
For the first 12 months after leaving office, treat the individual the same as an active PEP — full EDD applies. After 12 months, conduct a risk-based assessment of whether enhanced measures should continue. Document your reasoning. Factors to consider: the nature of the role held, the jurisdiction, the level of corruption risk, whether the individual remains publicly active, and any adverse media since leaving office. Under FG25/3, this de-escalation assessment must be documented — a bare note that "12 months have passed" is insufficient.
What technology do firms typically use for PEP screening? +
Commercial PEP screening solutions include World-Check (Refinitiv/LSEG), Dow Jones Risk & Compliance, LexisNexis Bridger Insight, ComplyAdvantage, and Acuris Risk Intelligence. These provide regularly updated, comprehensive PEP databases with fuzzy name matching and integration capabilities. For educational purposes and smaller firms, open-source solutions like FinCrimeRadar provide access to PEP data from OpenSanctions. For regulated compliance decisions, commercial solutions with full audit trails and legal accountability are required. The FCA expects firms to use screening solutions appropriate to the size, complexity, and risk profile of their business.
Can we accept a PEP from a country on the FATF blacklist? +
There is no absolute prohibition on accepting PEPs from any jurisdiction — but the risk management burden is very high. Under the July 2025 MLR reforms, EDD for high-risk third countries is now limited to FATF "Call for Action" (blacklist) countries. For a PEP from a FATF blacklist country, EDD is mandatory and should be extremely robust — including the most intensive SoW scrutiny, real-time monitoring, board-level approval, and very careful consideration of reputational risk. Many firms' risk appetites do not extend to accepting PEPs from FATF blacklist countries, and there is no regulatory obligation to accept such relationships.
✓ Series complete
You've completed the PEP Screening Handbook
You now have a comprehensive understanding of PEP identification, EDD obligations, real-world case studies, and how to build an effective PEP screening programme.