Due diligence is meant to be proportionate, and for most individuals a standard check is exactly that: enough to confirm who they are and clear them against the relevant lists, no more. The question this piece is about is what happens above that threshold, with the higher-risk minority for whom a standard check is not enough and both the rules and the risk call for more.
Politically exposed persons are the clearest example of that minority. They are also a group PEP screening frequently gets wrong, sometimes by treating the status as a mark against a person, sometimes by checking once and never revisiting it. The pages that follow look at who crosses into heightened scrutiny and why, what the enhanced due diligence workflow involves, and where screening tooling fits within it, which is a smaller part than the whole.
What a PEP is, and what it is not
A politically exposed person is someone entrusted with a prominent public function, senior figures in government, the judiciary, the military, central banks, and state-owned enterprises, along with their immediate family members and known close associates. The definition is set by international standards and implemented, with variations, in national rules.
The single most important thing to get right about PEP status is what it does not mean. It is not an accusation, and it is not a finding of wrongdoing. The great majority of PEPs are entirely legitimate people going about legitimate business. What the status reflects is elevated risk, specifically the higher risk of bribery, corruption, and money laundering that comes with holding a position of public influence and access. The status is a risk category, not a red flag.
That distinction has a direct practical consequence. Identifying someone as a PEP is not grounds to refuse the relationship; it is grounds to look more closely before and during it. A firm that reflexively blocks every PEP is not being cautious, it is misunderstanding the requirement, and it is turning away legitimate business for no good reason. The correct response to PEP status is enhanced scrutiny, applied on a risk-based footing. Many frameworks also distinguish between foreign and domestic PEPs, and apply tiers of risk within the category, so that the depth of scrutiny matches the specific level of risk rather than treating every PEP identically.
Beyond PEPs: other high-risk individuals
A PEP is the clearest reason to look more closely, though far from the only one. Sometimes the trigger is a control relationship, as with key personnel or the beneficial owners behind a high-risk entity. Sometimes it is where someone operates, in a high-risk jurisdiction or sector. Sometimes it is simply a news report when a person surfaces in serious adverse media, regardless of any formal status. Different as these are, they lead to the same place, because a standard check underweights the risk, and the enhanced workflow is what meets it.
What enhanced due diligence actually involves
Enhanced due diligence is often described as a deeper version of a standard check, which undersells it. It is a distinct workflow with several parts, and only some of them are screening. Understanding which parts are which is what makes it possible to see where tooling helps and where it does not.
Enhanced identification and screening
The workflow starts by confirming the individual’s status and screening them thoroughly, against sanctions, watchlists, and adverse media, more comprehensively than a standard check would. This is where an individual is correctly identified as a PEP or otherwise high-risk, and where the signals that shape the rest of the assessment are surfaced. This is the layer screening tooling addresses.
Source of funds and source of wealth
A defining feature of EDD is establishing where the individual’s money and wealth actually come from, both the funds involved in the relationship and the origin of their broader wealth. This is investigative work that goes well beyond screening, involving documentation, corroboration, and judgment, and it is not something a screening tool performs. It is a process the firm runs, and one of the parts of EDD that no monitoring product replaces.
Senior management approval
This is the step EDD keeps deliberately human. Accepting a high-risk relationship carries real consequences, so the workflow usually requires a senior person to sign off before it proceeds, putting an accountable name behind the decision to take the risk on. It is a judgment call, and it is meant to stay one.
Enhanced ongoing monitoring
EDD does not end at onboarding. A high-risk relationship calls for closer and more frequent scrutiny for as long as it lasts, which means monitoring the individual continuously rather than revisiting them at long intervals. This, like identification, is a layer screening tooling addresses directly, and it is the part that a one-time check cannot deliver.
Documentation
Underneath every part of the workflow is the need for a defensible record. That means capturing the rationale for the risk rating, the checks that were performed, and the approval that was given. An EDD decision that has not been documented and cannot be traced is one the firm will not be able to stand behind when it is questioned later, which is exactly why findings that link back to their source count for as much as the findings themselves.
Put together, EDD is a workflow of several parts, and screening plus ongoing monitoring is one layer of it. That is the layer tooling contributes to. Investigating source of funds and deciding whether to accept the risk are process and judgment that run alongside it, not things a product does.
Why PEP screening has to be continuous
Of all the parts of EDD, ongoing monitoring is the one most often underdone, and for individuals specifically the case for it is strong, because a person’s status and risk are not fixed.
Someone can become a PEP during a relationship. A customer who was an ordinary individual at onboarding can be elected, appointed, or promoted into a prominent public function a year later, and a check performed only at onboarding will never see it. The same is true at one remove: a customer’s family member can enter public office, or a close associate can be implicated in something, changing the customer’s risk profile without anything about the customer themselves appearing to change. And adverse media arrives on its own schedule, so a high-risk individual can surface in reporting at any point long after the initial check.
The status can also diminish. Under a risk-based approach, a person who has left public office may, after an appropriate period and assessment, no longer warrant the same level of scrutiny, which is part of keeping the picture accurate rather than simply accumulating flags forever. What all of this means is that a PEP check performed once at onboarding is a snapshot of a moving subject. Keeping it current requires continuous monitoring, and the fuller argument for why this is true of risk screening in general is set out here.
Doing PEP screening properly: the common pitfalls
Doing this well is largely a matter of avoiding a handful of familiar mistakes, not mastering any single technique. The same pitfalls turn up across firms, and each has its own remedy:
- False positives. PEP screening is notorious for them, because names are shared and matching is imperfect, so a screen tuned too broadly flags large numbers of the wrong people. The fix is not to tune it down until it misses real matches, but to resolve hits fast, which needs good matching and the ability to check a hit against its source quickly rather than investigating each from scratch.
- Treating PEP status as a block. Refusing every PEP turns away legitimate business and misreads the requirement, and it is easy to slip into because blocking feels like the safe choice when it is not.
- One-time checking. Failing to monitor after onboarding leaves a firm blind to the status changes above.
- Weak matching and poor data. This produces both problems at once, missing the real matches and burying the team in false ones.
- No documentation. An EDD process whose decisions are not recorded and traceable cannot be defended when it is examined.
Where tooling helps is specific. Beady AI provides the screening-and-monitoring layer of the workflow: broad coverage across sanctions, watchlists, and adverse media, matches that trace back to their source so a false positive can be cleared quickly and a real one defended, and continuous monitoring of individuals so a change in status surfaces when it happens. The rest of the EDD workflow is out of its scope. It does not investigate source of funds, and it does not make the risk-acceptance decision, which stay the firm’s own process and judgment. How the continuous screening works for sanctions is covered on the sanctions monitoring page, and where EDD sits in the wider due-diligence spectrum is covered in the breakdown of KYC, KYB and ongoing monitoring.
Frequently Asked Questions
The short version
A standard check is proportionate for most people, but not for high-risk individuals, and politically exposed persons are the clearest case. The status is not an accusation and not a reason to refuse a relationship; it is a risk category that calls for enhanced due diligence and closer scrutiny. EDD is a workflow of several parts, enhanced screening, source of funds and wealth, senior sign-off, ongoing monitoring, and documentation, and only some of those parts are screening.
Screening and continuous monitoring is the layer tooling addresses, and doing it properly means resolving false positives rather than blocking on them, treating PEP status as a trigger rather than a bar, monitoring after onboarding rather than checking once, and keeping a defensible, traceable record. The parts EDD adds beyond screening, investigating source of funds and deciding whether to accept the risk, remain the firm’s own process and judgment, which is exactly why an honest account of the workflow keeps them distinct from what a tool does.
For the screening-and-monitoring layer, continuous and source-traceable across sanctions, watchlists, and adverse media on the individuals a firm is exposed to, Beady AI is built for the job, scoped to that layer rather than the source-of-funds investigation or the risk decision that sit alongside it. A session will show what it surfaces against a real set of individuals, and how quickly a change in status can reach the team.