PEP, Sanctions & AML Screening: What Comes After KYC?

Posted by

–

Completing KYC does not necessarily mean a customer is safe to onboard.

KYC helps establish who the customer is and verifies information such as identity, address and other required details. But once the identity is established, financial institutions and businesses still need to understand who they are dealing with from a risk perspective.

This is where PEP, Sanctions & AML Screening becomes important.

A customer may have a valid identity document, a genuine address and a legitimate-looking profile, yet still present elevated financial crime or regulatory risk. They could be a politically exposed person (PEP), appear on a sanctions list, or have links to adverse media, money laundering or other financial crime concerns.

For banks, NBFCs, fintechs, payment companies and other regulated businesses, screening therefore needs to go beyond basic KYC.

KYC establishes identity. Screening adds context.

Think of KYC as the starting point of customer due diligence.

KYC answers questions such as:

  • Is this person who they claim to be?
  • Are their identity details valid?
  • Can the customer be verified against reliable records?
  • Who owns or controls a business?

Screening addresses a different set of questions:

  • Is the customer a PEP?
  • Is the customer or related entity listed under applicable sanctions?
  • Is there information suggesting involvement in financial crime?
  • Does the customer have links to higher-risk individuals, entities or jurisdictions?

The distinction matters because identity verification alone does not provide a complete view of customer risk.

FATF guidance specifically treats PEP identification as part of a broader risk-based approach. Being identified as a PEP does not mean that an individual is involved in criminal activity. Instead, it indicates that additional risk assessment and, where appropriate, enhanced due diligence may be required.

What is PEP screening?

A politically exposed person is an individual who is or has been entrusted with a prominent public function.

PEPs can include senior government officials, senior politicians, senior members of the judiciary, senior military officials and other individuals holding prominent public positions, depending on the applicable regulatory framework.

The concern is not the person’s political position itself. The concern is the potential exposure to risks such as bribery, corruption and misuse of public funds.

PEP screening can also extend to family members and close associates, depending on the applicable requirements and risk assessment.

This is why simply asking a customer whether they are a PEP may not always be sufficient. Screening against relevant data sources can help identify relationships that may not be disclosed during onboarding.

Importantly, a PEP match should not automatically result in rejection. FATF describes PEP controls as preventive measures and emphasises that identifying someone as a PEP does not mean that the person is a criminal.

The next step is to assess the risk and apply appropriate enhanced due diligence where required.

What does sanctions screening check?

Sanctions screening is different from PEP screening.

Sanctions are restrictions imposed by governments or international bodies on individuals, organisations, countries or other entities. Depending on the applicable sanctions regime, restrictions can relate to financial transactions, asset access, trade or other activities.

For a financial institution or fintech, a sanctions screening process may involve checking customers, beneficial owners, counterparties and sometimes transactions against relevant sanctions lists.

A potential match requires investigation because names can be similar. A genuine match and a false positive are not the same thing.

For example, a customer named “Mohammed Ali” appearing similar to an individual on a sanctions list does not by itself establish that the customer is the sanctioned person. Additional identifiers such as date of birth, nationality, location or other available information may be required to resolve the match.

This makes screening accuracy and match resolution just as important as the initial screening itself.

What is AML screening?

AML screening looks more broadly at potential money laundering and financial crime risks.

Depending on the organisation and its risk framework, this can involve screening for adverse media, criminal or regulatory information, suspicious associations and other risk indicators.

The objective is not simply to generate alerts. It is to help the organisation determine whether a customer requires further investigation or enhanced due diligence.

This distinction becomes particularly important as customer volumes increase.

A manual process may work for a limited number of customers. But for a digital lender, fintech, NBFC or payment platform onboarding thousands of customers, manually checking multiple sources can become slow, inconsistent and difficult to audit.

PEP, Sanctions & AML Screening: how are they different?

Screening typePrimary objectiveWhat it can identifyTypical next step
PEP ScreeningIdentify exposure to public-office-related riskPEPs, family members and close associatesRisk assessment / Enhanced Due Diligence
Sanctions ScreeningIdentify restricted individuals or entitiesSanctions-listed persons, organisations and other designated entitiesMatch investigation and action as required
AML ScreeningIdentify broader financial crime riskAdverse information, financial crime indicators and other risk signalsInvestigation / Risk-based due diligence

The three checks address different risk dimensions. In practice, they work better as part of a connected customer risk framework rather than as isolated checks.

Why screening should continue after onboarding

One of the biggest gaps in customer screening is treating it as a one-time activity.

A customer who clears screening during onboarding may not remain in the same risk position indefinitely.

A person could become a PEP after taking up a public position. A new sanctions designation could be issued. New adverse information could emerge. A business could also change its ownership structure or beneficial owners.

That is why ongoing monitoring matters.

FATF’s risk-based approach emphasises understanding and managing customer risk rather than relying on a one-time compliance check. Its current Recommendations, updated in June 2026, provide the international framework for countries to adapt AML/CFT controls to their own legal and regulatory environments.

For businesses, this means screening should be connected to the broader customer lifecycle.

What should a modern screening workflow look like?

A practical workflow can start with KYC and move through multiple layers of risk assessment.

1. Verify the identity

Establish that the customer is who they claim to be using appropriate identity verification methods.

2. Identify beneficial ownership

For businesses, understanding the individuals who ultimately own or control the entity can be critical. Screening only the legal entity may not provide the complete risk picture.

3. Run PEP screening

Check relevant individuals against reliable PEP data sources and assess whether additional due diligence is required.

4. Run sanctions screening

Screen relevant customers, entities and other applicable parties against the sanctions lists relevant to the organisation’s business and jurisdictions.

5. Conduct AML and adverse media screening

Look for information that may indicate financial crime, corruption, fraud or other relevant risks.

6. Resolve potential matches

Not every alert represents a genuine match. Organisations need processes to distinguish true matches from false positives and document the reasoning behind the decision.

7. Monitor continuously

Repeat screening and monitoring when required by the risk profile, regulatory obligations or changes in customer information.

Where technology makes a difference

The challenge is not simply having access to screening data. It is bringing different risk signals together quickly enough to support business decisions.

API-driven screening can allow financial institutions and fintechs to integrate PEP, sanctions and AML checks into onboarding or transaction workflows. Instead of moving between multiple systems, compliance teams can receive screening results within the existing customer journey.

Automation can also help with repetitive tasks such as list matching, alert generation, data enrichment and case routing. Human review remains important for interpreting potential matches and making risk-based decisions.

This becomes increasingly relevant as digital financial services expand and customer onboarding moves closer to real time.

KYC is the beginning, not the end

A verified identity tells a business who the customer is. It does not automatically explain what risk that customer may represent.

That is the gap that PEP, Sanctions & AML Screening helps address.

For BFSI and fintech businesses, the objective should not be to add more checks simply for the sake of compliance. The larger goal is to build a risk-based customer due diligence process that combines identity, ownership, screening and ongoing monitoring.

As financial crime risks evolve, the ability to connect these signals can become just as important as the ability to verify an identity in the first place.

KYC establishes identity. PEP, sanctions and AML screening help establish context. Together, they provide a more complete foundation for customer risk assessment.

Leave a Reply

Your email address will not be published. Required fields are marked *