Skip to main content
green gradient background, "The Future of Application Security Is Already Here." and a read the report button.
Building a Defensible PEP Due Diligence ProgramThird-Party Risk Management
6 min readFor Compliance Officers

Building a Defensible PEP Due Diligence Program

FinCEN's August 2020 guidance on politically exposed persons (PEPs) confirms what compliance officers already know: there's no checklist. You're expected to design a risk-based due diligence framework that you can defend under scrutiny, without specific procedural requirements to follow. For compliance officers at banks and covered financial institutions, this means you're building the plane while flying it.

The guidance states there's no Regulatory Obligation for banks to have unique, additional due diligence steps for PEPs. You don't even need to designate a customer as a PEP. But that doesn't mean you can skip enhanced due diligence for high-risk customers. It means you need a program you can explain and justify when regulators come asking.

Essential Preparations

Executive commitment, documented in writing. You can't build a defensible due diligence program if your C-suite treats compliance as overhead. Secure written acknowledgment from your board and executive committee that customer due diligence is a strategic priority. This isn't about getting permission; it's about establishing accountability if the program fails.

A current customer risk universe. You need an inventory of risk factors your institution actually faces, not a generic list copied from industry guidance. Document your customer segments, geographic exposure, product mix, and transaction patterns. If you serve correspondent banking relationships or private banking clients, those belong in your risk universe. If you don't, they shouldn't.

Access to automated screening and monitoring tools. Manual adverse media searches and periodic KYC refreshes don't scale. You need technology that can continuously monitor customer activity, screen against sanctions lists, and flag changes in risk profile without requiring analysts to manually review every account quarterly.

A compliance officer with real authority. If you're not on the executive committee where Impact Tolerance decisions get made, you don't have the autonomy FinCEN expects. The compliance function needs a seat at the table when leadership weighs customer profitability against due diligence costs.

Step-by-Step Implementation

Step 1: Define your risk rating methodology

Build a scoring model that assigns numerical risk ratings based on measurable factors. Start with these core components:

  • Customer type (individual, entity, trust structure)
  • Geographic risk (customer location, transaction counterparties, beneficial owner jurisdictions)
  • Product risk (account types, transaction volumes, cross-border activity)
  • Relationship risk (politically exposed status, adverse media, sanctions screening results)

Document the weighting for each factor. If you assign 30 points for high-risk geography and 20 points for PEP status, write down why those weights make sense for your institution's risk profile. You'll need to explain this later.

Step 2: Set due diligence triggers based on risk scores

Map your risk scores to specific due diligence procedures. Don't call them "PEP procedures"; call them enhanced due diligence for high-risk customers. Here's a working framework:

  • Low risk (0-30 points): Standard CDD at onboarding, automated transaction monitoring, annual KYC refresh
  • Medium risk (31-60 points): Enhanced CDD at onboarding, quarterly adverse media screening, semi-annual KYC refresh, manual review of transaction alerts
  • High risk (61-100 points): Senior management approval for onboarding, source of wealth verification, continuous adverse media monitoring, monthly transaction review, quarterly KYC refresh

Document what "enhanced CDD" means in practice. If it includes verifying source of funds for deposits over a certain threshold, specify that threshold and the acceptable forms of verification.

Step 3: Build your PEP identification process

Since FinCEN doesn't require you to designate customers as PEPs, you need to decide whether you will. Most banks should, because PEP status is a relevant risk factor even if it doesn't automatically trigger unique procedures.

Configure your screening tools to flag PEP matches during onboarding and on an ongoing basis. Use commercial databases that cover:

  • Current and former senior foreign political figures
  • Immediate family members and close associates
  • Senior executives at state-owned enterprises

When you get a PEP match, don't treat it as an automatic escalation. Feed it into your risk rating model as one factor among many. A mid-level official from a low-risk jurisdiction with transparent income sources might rate lower than a non-PEP with complex offshore structures and adverse media hits.

Step 4: Document your Impact Tolerance thresholds

Write down the risk score at which you'll decline to onboard a customer. This isn't a Regulatory Obligation, but it's a practical necessity. If your model can generate scores up to 100 points, at what number does the relationship become too risky regardless of profitability?

Get your executive committee to approve this threshold in writing. When a profitable customer relationship gets declined because it exceeded your Impact Tolerance, you need documentation showing this was a deliberate policy decision, not compliance being overly cautious.

Step 5: Create escalation procedures for ongoing monitoring

Your monitoring tools will generate alerts. Define who reviews them and what happens next:

  • Transaction alerts below a certain severity: First-line business unit reviews and documents disposition
  • Medium-severity alerts: Compliance team reviews within two business days
  • High-severity alerts: Immediate escalation to CCO, transaction hold pending review

Document the criteria for each severity level. "Unusual activity" isn't specific enough. "Transaction volume 300% above customer's historical pattern" is defensible.

Validation: How to Verify It Works

Test your risk rating model against your existing customer base. Run your entire portfolio through the scoring methodology. If 90% of customers score as low risk, your model might not be granular enough. If 40% score as high risk, your weights are probably too aggressive or your customer base actually is high risk and you need to address that strategically.

Conduct a lookback review on recent onboarding decisions. Pull a sample of 25 customers approved in the last quarter. For each one, verify:

  • Risk score was calculated correctly
  • Due diligence procedures matched the assigned risk tier
  • Required approvals were obtained and documented
  • Ongoing monitoring was configured appropriately

If you find gaps, they're process failures you can fix. If you find your team is consistently overriding the risk model without documentation, you have a control deficiency.

Run adverse media searches on your high-risk customer segment. If your continuous monitoring tools aren't flagging negative news that manual searches find, your automation isn't working. Either your search parameters are too narrow or you need different tools.

Review your exception registry. Every time you approve a customer who exceeds your Impact Tolerance threshold, that should be logged as a policy exception with executive approval. If you don't have any exceptions logged but you know you've onboarded high-risk customers, your escalation process isn't being followed.

Maintenance and Ongoing Tasks

Quarterly: Review your risk rating weights. If regulatory priorities shift or your institution's risk profile changes, your scoring model should reflect that. When FinCEN issues new guidance on sanctions evasion typologies, consider whether your geographic risk weights need adjustment.

Semi-annually: Audit your First Line of Defense. The business units conducting initial transaction monitoring need periodic quality assurance. Pull samples of their alert dispositions and verify they're applying consistent standards. If you find one business unit is dismissing alerts that another unit escalates, you have a training problem.

Annually: Validate your automation. Test your screening tools against known PEP matches and sanctions list entries. If you're not catching obvious hits, your tool configuration needs work. Test your transaction monitoring rules against known money laundering typologies. If your rules wouldn't flag structuring or trade-based laundering patterns, tune them.

Continuously: Document your decisions. Every time you make a judgment call about customer risk, write it down. When you decide a PEP match is a false positive, document why. When you approve an exception to your Impact Tolerance threshold, document the compensating controls. FinCEN's guidance gives you discretion, but discretion without documentation is just wishful thinking when the exam team shows up.

The lack of specific regulatory requirements isn't a gift; it's a test. You're expected to build a program that makes sense for your institution and that you can defend under scrutiny. That requires executive support, appropriate tools, and the authority to say no when risk exceeds tolerance. If you don't have those things, your due diligence program is a compliance theater, not a control.

Application Security Isn’t Optional Anymore.

You Might Also Like