PEP risk assessment: Not quite a PEP. Definitely not low risk. So what now?
Here is a situation most compliance teams know well. You are onboarding someone who holds a senior public role. There is influence. There may be access to public funds or decision-making power. The risk indicators are there. But then comes the question: are they technically a politically exposed person (PEP)? And suddenly three compliance specialists, Legal and possibly someone from senior management are debating one sentence in the legislation.

This is where an internal Senior Public Figure (SPF), VIP or similarly named category can be useful. The name does not really matter. I use SPF to describe the grey zone of people who do not clearly meet the formal PEP definition but whose public influence means that treating them as ordinary customers does not make much sense. Think of municipal officials, such as a head of infrastructure (is this a middle-ranking position or a more senior one?), or other public figures whose PEP classification depends heavily on jurisdiction, seniority, powers or interpretation. The point is not to invent a new regulatory definition. The point is to follow the risk when the rulebook gives you an unclear answer.
Different label. Same risk conversation.
Suppose you classify someone as medium risk because you cannot establish that they meet the PEP definition. What exactly has been achieved? The person may still have similar influence, access and potential exposure to corruption. You have only changed the label. That is why an SPF category can be practical. Your internal AML/KYC policy might say: PEP → enhanced due diligence (EDD). SPF → high risk → enhanced due diligence. And if an auditor later says, “Actually, we think this person should have been classified as a PEP”, you have a much better conversation available: “Fair point. We classified them as an SPF, rated them high risk and applied equivalent controls.”
Different label. Similar risk mitigation outcome.
A small book interruption
If this is the kind of PEP due diligence problem you regularly encounter, I explore many more of them in my new book, Due Diligence Horizon.
There is an entire 70+ page chapter on PEPs, or “Politically Exposed Panic”, as I called it, covering the grey areas and practical problems that rarely fit neatly into a procedure. The book goes beyond PEPs into other areas of customer due diligence, including ultimate beneficial ownership (UBO), source of wealth (SoW) and source of funds (SoF).
Now, back to our almost-PEPs.
Why not just call them PEPs?
If these people look sufficiently similar to PEPs to justify enhanced controls, why not classify every borderline case as a PEP and move on? Because that creates another problem. Applying the PEP label when the legal definition is uncertain may itself be challenged by the person concerned. An internal high-risk classification can therefore be more appropriate than stretching the PEP definition to cover every uncomfortable case. The answer to possible under-classification does not have to be over-classification. At the same time, do not turn SPF into “PEP Plus”. Not every SPF presents the same risk, just as not every PEP presents the same risk.
Imagine the official in question is using relatively low-risk products, with no cash/crypto-intensive activity and limited transactional complexity. Do they automatically require the compliance equivalent of a forensic expedition involving twelve documents, three databases and someone investigating a flat purchased in 2004? Not necessarily. Enhanced due diligence can still be calibrated using a risk-based approach. A Source of Wealth / Source of Funds questionnaire with targeted verification may be sufficient in one case. A deeper investigation may be justified in another. High risk does not always mean maximum throttle. The controls should match the actual risk.
The practical benefit
Compliance teams can spend an impressive amount of time debating borderline PEP classifications. Emails, escalations, second opinions, legal interpretation, another meeting, and perhaps another meeting to discuss what was decided in the previous meeting. Six months later, someone reviews the file and starts the debate again. An SPF category does not necessarily mean creating a large new population of clients who suddenly require enhanced due diligence. It may simply help with that one problematic role where nobody is quite sure whether the person is a PEP. A documented SPF framework gives these cases somewhere to go. Define which characteristics may trigger SPF classification. Define the risk-based controls, establish the appropriate level of enhanced due diligence and document the reasoning. The conversation then becomes less “Can we prove this person is technically a PEP?” and more “What risk does this person actually present, and what controls are proportionate?”
SPF does not replace the PEP risk assessment, and it is not a new regulatory category. Local legislation still comes first. You still determine whether the person meets the applicable PEP definition and document that decision. SPF simply provides an internal way to manage the risk when the answer is unclear or the person falls outside the formal definition while retaining characteristics that justify additional scrutiny. When the same borderline roles trigger the same internal debate again and again, a documented internal category may be more sensible than repeatedly trying to force reality into a definition that does not quite fit.
Because risk, inconveniently, does not particularly care what label you give it.



Comments