Rethinking PEPs: Why the Old Playbook for High-Risk Customers No Longer Works
- TrustSphere Network

- Jun 10
- 3 min read
Updated: Jul 1

Politically exposed person (PEP) management is one of the oldest pillars of AML, and also one of the most poorly calibrated. Many institutions still treat PEP classification as a binary label, layered on top of an inflexible workflow that produces friction without producing insight. This blunt-instrument approach has persisted partly because the underlying data and governance have not caught up with the nuance that supervisors now expect, and partly because nobody wants to explain why a prominent PEP was offboarded without clear justification.
The consequences are visible in the data: large volumes of alerts, low productive SARs, and customer complaints driven by due-diligence burdens that do not translate into risk mitigation. Meanwhile, genuinely high-risk PEP exposures slip through because the model is too blunt. The result is a status quo that satisfies nobody: customers complain of unjustified friction, frontline staff manage unwieldy case queues, and genuinely high-risk exposures still occasionally slip through.
The current environment — with heightened geopolitical risk, fast-moving sanctions regimes, and publicised enforcement actions — demands a more intelligent approach. Rebuilding PEP management as an analytics-led discipline is overdue, and in the current environment, the cost of not doing so is rising fast.
Regulatory, Enforcement, and Market Context
FATF's guidance on PEPs, reinforced by the Wolfsberg Group, has long favoured a risk-based rather than a list-based approach. The European Banking Authority, FCA, MAS, and HKMA have all issued supervisory notices nudging banks in this direction. In several recent enforcement actions, supervisors have specifically criticised institutions for applying uniform PEP controls that combined customer-friendliness failures with missed high-risk exposures — the worst of both worlds.
Enforcement actions in multiple jurisdictions have focused on institutions that either over-applied PEP controls (causing financial exclusion) or failed to identify and manage genuinely high-risk political exposure. The balance is delicate and increasingly scrutinised. The consistent theme is proportionality: treating every PEP the same is no longer a defence, and the absence of differentiation is itself a finding.
OFAC and UK OFSI designations have repeatedly highlighted the overlap between PEP status and sanctions exposure, particularly in the current geopolitical environment. Institutions should also expect increased scrutiny on how quickly they refresh PEP status and how well they integrate geopolitical developments into ongoing monitoring.
What the Data Is Showing
Industry benchmarking data suggests that alert false-positive rates in PEP monitoring can exceed 95% in poorly tuned programmes. Sumsub and other data show a long tail of low-value PEP matches that consume the bulk of reviewer time. The tail of low-value PEP matches is effectively a tax on the programme, and the opportunity cost of that work is measurable in missed higher-risk cases elsewhere.
At the same time, Reuters and ACAMS investigations continue to report cases where clearly high-risk PEP exposures were missed for years. The cost of a blunt instrument is paid at both ends. Benchmarking shows that the best-performing institutions typically have much lower PEP alert volumes but significantly higher productive-SAR rates — evidence that smarter triage beats more triage.
Implications for Financial Institutions
PEP management should be driven by risk scoring that blends role, jurisdiction, sanctions adjacency, transactional behaviour, and adverse media signals. Static lists are a starting point, not a conclusion. Risk scoring should blend static factors (role, jurisdiction, sanctions adjacency) with dynamic inputs (transactional behaviour, adverse media, network signals) so that the same individual can move between tiers as their circumstances change.
Governance should ensure that high-risk PEPs receive dedicated senior review, while low-risk matches are processed efficiently. Uniform treatment is not equal treatment. Governance should ensure that the highest-tier PEPs receive genuine senior review, rather than being processed at the same pace as routine matches — a split that is often absent in practice.
Finally, PEP programmes must integrate tightly with sanctions screening and geopolitical risk monitoring. In 2026, the boundary between these disciplines is effectively gone. Technology is only part of the answer; institutions also need to invest in the analytical skills of the people reviewing PEP cases, because the judgement calls at the top of the tier are rarely simple.
Conclusion
PEP management has drifted from its original purpose. Institutions that rebuild their approach around risk-based scoring, tight integration with sanctions, and efficient workflows will simultaneously reduce friction and sharpen detection — a combination that is increasingly rare. The measure of a mature PEP programme is no longer alert volume — it is productive SARs, relationship retention, and the ability to evidence a genuine risk-based approach.
Suggested Next Steps
Replace binary PEP flags with a layered risk-scoring model.
Tighten integration between PEP, sanctions, and adverse-media screening.
Introduce senior-level review for the top tier of PEP exposures.
Measure PEP programme effectiveness, not just alert volume.
Sources: FATF PEP guidance, Wolfsberg Group statements, European Banking Authority guidelines, FCA, MAS, HKMA notices, Sumsub, Reuters, ACAMS, OFAC and UK OFSI designations.
TrustSphere helps financial institutions design and deploy intelligent fraud and financial crime detection solutions. Visit www.trustsphere.ai



Comments