Politically exposed persons screening

A politically exposed person is a customer your institution may not treat like any other, and the test for who qualifies is written in German law, not in a vendor list. Section 1(12) of the Geldwäschegesetz names the public functions that create the status, section 1(13) and (14) extend it to family members and known close associates, and section 15(4) attaches the stricter duties that follow.

Getting the screening right saves two kinds of trouble: a missed PEP that a BaFin audit finds, and a compliance team that spends its week closing name matches on people who are not the customer at all.

A compliance analyst compares an identity document with a screening dashboard.

Which functions make a customer a PEP

Section 1(12) GwG lists the functions by name: heads of state and government, ministers and state secretaries, members of parliament and of comparable legislative bodies, members of the governing bodies of political parties, judges of supreme courts and constitutional courts, members of courts of auditors and of central bank boards, ambassadors and chargés d'affaires, high-ranking officers of the armed forces, members of the administrative, management or supervisory bodies of state-owned enterprises, and directors and board members of international organizations.

German law makes no distinction between a foreign office and a domestic one. A German state minister, a Bundesbank board member and a managing director of a municipal utility held by a city are PEPs on the same provision as a foreign minister. Institutions that imported a screening policy from a jurisdiction with a foreign-only definition carry a gap here. The BaFin interpretation and application guidance on the GwG states the duty for domestic and foreign holders of the listed functions alike.

Local offices sit outside the list. A mayor of a small municipality holds no function named in section 1(12), which is why the autocomplete question about mayors has a clear answer: the office qualifies when it belongs to a body at the level the provision names, and a risk-based assessment may still place a locally prominent customer in a higher class without the PEP label.

Family members and close associates

The status travels. Section 1(13) GwG covers the spouse or partner, the children and their spouses or partners, and the parents of a PEP. Section 1(14) adds the known close associate: a person who holds beneficial ownership of a legal entity jointly with a PEP, who maintains close business relations with one, or who is the sole beneficial owner of a structure set up for the benefit of a PEP.

"Known" does the work in that second category. The institution owes the duties it can discharge with the information available to it, which is why the customer questionnaire asks about the connection directly instead of leaving the answer to a database match. A screening tool finds the minister; the family and associate net around the minister comes from what the customer declares and what the institution can verify.

What the stricter duties actually require

Section 15(4) GwG sets three obligations on top of ordinary customer due diligence. A member of senior management has to approve the business relationship before it starts or, where the status arises later, before it continues. The institution has to establish the origin of the assets used in the relationship, which goes further than source of funds and asks where the wealth came from. And the relationship goes under intensified ongoing monitoring.

Senior management approval is the control supervisors read first, because it leaves a signature and a date. The source-of-wealth file is the one that decays: a salary statement, a company sale and an inheritance each explain a different part of a balance, and the file has to hold the explanation for the money that actually moves. Our page on source of funds in crypto transactions covers the same question where the assets arrive from a wallet.

How long the status lasts after the office ends

Twelve months, as the minimum. Section 15(4) GwG allows an institution to stop applying the stricter duties no earlier than one year after the PEP has left the function, and only when the institution has satisfied itself that the person no longer carries the risk the status assumed. The clock is a floor, not an expiry date.

In practice the second half of that sentence decides more cases than the first. A former finance minister who sits on the supervisory board of a state-held company has not left the risk behind, and a former ambassador whose family still holds the structures built during the posting has not either. The BaFin guidance asks for the assessment to be documented, so the file states why the stricter duties ended on a particular date.

Where the lists come from

No authority publishes a register of politically exposed persons. What exists instead is a list of functions: each member state reports the public offices on its territory that fall under the definition, and the European Commission compiles those reports into a single document plus a list of the functions at the EU institutions and at international organizations accredited in the Union. Commercial PEP databases build their person records on top of that function list, from public sources.

That is also why a database hit is a starting point and not a decision. The provider found a name and an office; whether the person in front of you is that person, and whether the office is still held, is the institution's call. A screening policy that treats the vendor record as the finding has outsourced the duty, which section 15(4) does not permit.

How do you handle a false positive?

You close it with a documented reason, and the documentation is the part that matters. Name matching produces hits on a shared surname, a transliterated spelling, a date of birth the provider never had, and a homonym in another country. The BaFin guidance expects the institution to record the decision that discharged the alert, with the data points that distinguished the customer from the listed person: date and place of birth, nationality, address, the function and its period.

Teams that tune this well write the discriminating data into the customer record once, so the same alert closes itself on the next screening run. Teams that do not re-litigate the same hit every quarter. The tuning question belongs to the same discipline as rule tuning in transaction monitoring, where a threshold that produces alerts nobody can work is itself a finding.

Is PEP screening the same as sanctions screening?

No, and treating them as one system causes trouble in both. Sanctions screening tests a name against a legally binding list, and a match blocks the transaction or freezes the asset, with no risk appetite to apply. PEP screening tests a name against a risk category, and a match triggers due diligence, not a prohibition. A PEP may open an account; a sanctioned person may not.

The technical pipeline is often shared, because both run fuzzy name matching against reference data. The decision logic has to stay separate. Our page on sanctions compliance in Germany covers the list side, including the EU regulations that make a match binding.

What changes under the EU AML package?

The definition moves from German law into an EU regulation that applies directly. Regulation (EU) 2024/1624 carries the PEP definition, the family and associate categories and the stricter due-diligence duties for the whole Union, from July 10, 2027. The function lists member states report continue, and the Commission keeps publishing the consolidated version.

For a German institution the practical change is less in the substance than in the source: a policy that cites section 15(4) GwG today will cite the regulation then, and national interpretation guidance gives way to standards written by the new authority in Frankfurt. The EU AML package page sets out the three instruments and their dates, and AMLA in Frankfurt covers the authority itself.

Adverse media as the second half of the check

A list match tells you that a customer holds an office. It does not tell you that the same person is under investigation for procurement fraud in a country where the proceeding never reaches a sanctions list. Adverse media screening covers that second question, and the risk assessment under section 15(4) GwG is where its result belongs: a negative press finding raises the risk class and tightens the source-of-wealth demand, even when no list carries the name.

The discipline here is the same one that governs the list hit. A media article is a lead, and the file records what the institution did with it: whether the report concerns this person, whether the matter was resolved, and which decision followed. An unassessed clipping in a customer folder is worse than none, because an auditor reads it as knowledge the institution had and ignored.

Why one flat PEP treatment costs more than it buys

The GwG sets a floor for every PEP relationship, and above that floor the risk-based approach under section 10(2) GwG lets an institution differentiate. A sitting minister of a country with weak public procurement controls and a retired judge of a German regional court both carry the status; they do not carry the same risk, and the monitoring intensity may differ as long as the assessment behind the difference is written down.

Institutions that treat every PEP identically end up with a review backlog and a review that stops being read. The useful split works on the function, the country, the products used and the transaction pattern, with the strictest class reserved for relationships where the money and the office could plausibly meet. That is also the split a BaFin examiner asks to see, because it shows the institution thought about its own portfolio.

PEP screening and Finance Loop

Finance Loop is the meeting place for the people who run screening in German institutions: money laundering officers, KYC analysts, the data teams behind the matching engine, and the regtech firms that supply it. PEP screening comes up wherever onboarding automation meets a duty that a tool cannot discharge on its own.

Finance Loop is a professional network and has the goal of driving the adoption of emerging technologies in finance, such as AI, tokenization, stablecoins, and DeFi. Finance Loop helps its members build skills and personal networks in these fields: Investment & Digital Assets, Payments & Digital Money, Digital Infrastructure & Sovereignty, and Risk & Compliance.

Let's stay in touch

4,000+ members in finance and tech. Become a Network Member for free.

Get updates for free!

Exclusive event invitations, member perks and news from the network. Unsubscribe at any time.

By submitting you agree to the terms.