PEPs and Sanctions Lists in AML Compliance: Screening and Penalties

In anti-money laundering compliance, PEPs and sanctions lists are the two screening obligations that catch most enforcement actions. Politically exposed persons (PEPs) are individuals whose public roles create elevated corruption risk and who require enhanced scrutiny; sanctions lists are government-maintained rosters of people, companies, and countries you are legally prohibited from transacting with. Get either one wrong and civil penalties reach into the hundreds of thousands of dollars per violation, with willful sanctions violations carrying up to 20 years in prison.

Who Counts as a PEP

A PEP holds a prominent public role that creates an elevated risk of bribery or corruption. That covers heads of state, cabinet ministers, senior legislators, high-ranking judges, military commanders, and top executives of state-owned enterprises. People who control public funds or wield regulatory power have more opportunity than the average account holder to exploit the financial system, and screening frameworks are built around that reality.

The designation reaches past the officeholder. Immediate family, including spouses, parents, and children, carry PEP status because corrupt officials routinely move money through relatives. Close business associates and co-owners of legal entities tied to the PEP fall under the same umbrella. A program that screens only the official misses the most common laundering channels.

PEP status also doesn’t drop off the moment someone leaves office. Most compliance frameworks maintain the designation for several years afterward, since the relationships and influence built during a government career don’t vanish on the last day of a term. The exact duration varies, but treating a recently departed official as low-risk is a mistake regulators notice.

Foreign Versus Domestic PEPs

Not all PEPs carry the same risk weight. Under international standards, a foreign PEP is always treated as high-risk and always requires enhanced due diligence. A domestic PEP requires a risk-based assessment: if the relationship looks normal on review, standard due diligence may suffice.1Financial Action Task Force. Politically Exposed Persons (Recommendations 12 and 22)

The deciding factor is which country entrusted the person with their role, not where they live or hold citizenship. A foreign minister from a country with widespread corruption triggers automatic enhanced scrutiny. A city council member in a low-corruption jurisdiction may not. Factors that push a domestic PEP into higher-risk treatment include the corruption profile of their country, the source of their wealth, and the nature of the products or services they’re seeking.

PEP status alone should not automatically produce a high-risk determination for domestic officials. It is one factor among several. Failing to identify a PEP at all, foreign or domestic, is where institutions get into real trouble.

How Sanctions Lists Work

Sanctions lists are government-maintained databases identifying people, companies, and sometimes entire countries that are off-limits for financial transactions. In the United States, the primary authority is the Office of Foreign Assets Control (OFAC), which operates under 31 CFR Chapter V and publishes the Specially Designated Nationals (SDN) List.2eCFR. 31 CFR Chapter V – Office of Foreign Assets Control, Department of the Treasury People and entities on the SDN List have their assets blocked, and U.S. persons are broadly prohibited from doing business with them.3U.S. Department of the Treasury. Specially Designated Nationals (SDNs) and the SDN List

The United Nations Security Council maintains its own consolidated list, and member countries are obligated to implement sanctions against the individuals and entities it names.4United Nations. United Nations Security Council Consolidated List The European Union, the United Kingdom, and other jurisdictions publish separate lists. For organizations operating internationally, monitoring one list is not enough.

Some sanctions target specific individuals tied to terrorism, narcotics trafficking, or weapons proliferation. Others restrict entire sectors of a national economy or prohibit nearly all transactions with a designated country. OFAC updates its SDN List on an ongoing basis, sometimes multiple times per week. Institutions that screen only at account opening rather than continuously are exposed every time a new name appears.

The 50 Percent Rule

One of the most overlooked pieces of OFAC compliance is the 50 Percent Rule. An entity that is directly or indirectly owned 50 percent or more in the aggregate by one or more blocked persons is itself treated as blocked, even if that entity doesn’t appear on the SDN List by name.5U.S. Department of the Treasury. Entities Owned by Blocked Persons (50% Rule) Ownership stakes are added together. If two SDNs each own 25 percent of a company, that company is blocked.

The rule extends through layers of ownership. “Indirectly” means ownership held through another entity that is itself 50 percent or more owned by blocked persons. A company with no sanctions connection on its surface can still be blocked through its shareholders, so screening a name against a list is not enough on its own; you need visibility into the ownership structure.

The rule applies to ownership, not control. An entity controlled but not majority-owned by a blocked person is not automatically blocked, though OFAC can designate it separately on a case-by-case basis.5U.S. Department of the Treasury. Entities Owned by Blocked Persons (50% Rule)

OFAC Licenses

Not every transaction involving a sanctioned party is permanently off-limits. OFAC issues two types of authorization. A general license covers an entire category of transactions and applies automatically without any application. A specific license is a written authorization issued to a particular person or entity in response to a formal request.6U.S. Department of the Treasury. OFAC Licenses General licenses come with strict conditions, and failing to follow them converts a legal transaction into a violation.

Screening: What Data You Need

Accurate screening starts with the right inputs. At minimum, you need the individual’s full legal name and any known aliases. Date of birth and place of birth are critical for distinguishing between people who share common names, and nationality and current address further narrow the search and reduce false positives against databases that aggregate entries from multiple international authorities.

For entities, the data requirements shift toward corporate registration details, jurisdiction of incorporation, and beneficial ownership information. Under FinCEN’s Customer Due Diligence Rule, covered financial institutions must identify and verify the identity of any individual who owns 25 percent or more of a legal entity opening an account, along with an individual who controls the entity.7FinCEN. CDD Final Rule That beneficial ownership information feeds directly into both PEP screening and the 50 Percent Rule analysis.

Government-issued identification, corporate registration documents, and similar records should be kept on file to support the data you’ve gathered. Clean, structured records make it easier to update profiles when individuals change roles, addresses, or affiliations.

Matching and Managing False Positives

Compliance software runs screening data against sanctions lists, PEP databases, and other watchlists using fuzzy matching algorithms. These catch spelling variations, transliteration differences (common with names originally written in non-Latin scripts), and typos. OFAC’s own Sanctions List Search tool uses approximate string matching and lets users set a confidence threshold for how close a potential match must be.8U.S. Department of the Treasury. OFAC Sanctions List Search Fuzzy matching inevitably produces false positives, and a compliance officer must review each flagged match against secondary identifiers like birth date, nationality, and unique identification numbers.

Organizations with significant screening volume maintain what OFAC calls “false hit lists,” records of individuals and entities whose characteristics trigger a match but who have been confirmed through review as not sanctioned.9U.S. Department of the Treasury. False Hit Lists Guidance These aren’t “set and forget.” OFAC guidance requires that when the SDN List is updated, new alerts should not be automatically suppressed simply because a similar entry sits on the false hit list. If a customer’s information changes meaningfully, the false hit entry should be re-reviewed.

Reporting Deadlines When You Get a Match

When screening surfaces a genuine match, reporting obligations kick in quickly.

For sanctions matches, OFAC requires that blocked property and rejected transactions be reported within 10 business days.10U.S. Department of the Treasury. Filing Reports with OFAC Rejected transactions are those that would violate sanctions but aren’t blocked because they don’t involve a blocked person’s property interest. Both types require separate reports under 31 CFR 501.603 and 501.604.11eCFR. 31 CFR 501.604 – Reports of Rejected Transactions Blocked property must also be reported annually by September 30.

Under the Bank Secrecy Act, financial institutions must file a Suspicious Activity Report (SAR) no later than 30 calendar days after detecting facts that may warrant filing. If no suspect has been identified at the time of detection, the institution gets an additional 30 days to identify one. Reporting cannot be delayed beyond 60 calendar days from initial detection under any circumstances.12Office of the Comptroller of the Currency. Suspicious Activity Reports (SAR)

Penalties for Noncompliance

Sanctions violations and BSA failures carry separate penalty regimes, and in serious cases both can apply at once.

Sanctions Penalties Under IEEPA

Most OFAC-administered programs draw their authority from the International Emergency Economic Powers Act. The statutory civil penalty for a single violation is the greater of $250,000 or twice the transaction amount.13Office of the Law Revision Counsel. 50 USC 1705 – Penalties After inflation adjustments, the per-violation cap is currently $377,700 or twice the transaction amount, whichever is larger.14eCFR. 31 CFR 560.701 – Penalties For large transactions, the “twice the amount” multiplier means civil penalties can easily run into the millions.

Criminal penalties for willful violations are harsher: up to $1,000,000 in fines and 20 years of imprisonment for individuals.13Office of the Law Revision Counsel. 50 USC 1705 – Penalties

BSA Penalties

Willfully failing to comply with BSA requirements, including SAR filing obligations, carries a criminal penalty of up to $250,000 and five years of imprisonment. If the violation is part of a pattern of illegal activity involving more than $100,000 within a 12-month period, the maximum climbs to $500,000 and 10 years.15Office of the Law Revision Counsel. 31 USC 5322 – Criminal Penalties A court can order forfeiture of any profits gained from the violation, and individuals who were officers or employees of a financial institution at the time must repay any bonus received during the calendar year of the violation or the year after.

Civil penalties for BSA violations run separately under 31 USC 5321, with caps that vary by violation type. Willful violations can reach $100,000 per incident; negligence by a financial institution carries a much lower ceiling.16Office of the Law Revision Counsel. 31 US Code 5321 – Civil Penalties A civil penalty can be imposed even when a criminal penalty is also assessed for the same violation.

Building the Compliance Program

OFAC expects organizations to maintain a formal sanctions compliance program built around five components: management commitment, risk assessment, internal controls, testing and auditing, and training. Checking all five boxes doesn’t guarantee immunity from enforcement, but OFAC treats a functioning program as a significant mitigating factor when violations occur.

Management commitment means more than a policy statement. Senior leadership must allocate adequate staffing, technology, and budget, and the compliance officer needs a direct reporting line to senior management rather than a chain filtered through operations. Risk assessment should be a living exercise that accounts for your specific customer base, product mix, geographies, and transaction types. Internal controls translate the assessment into day-to-day screening procedures, escalation chains, and recordkeeping protocols.

Recordkeeping and Testing

Under the BSA, institutions must retain most compliance records for at least five years. Customer identity records must be kept for five years after the account is closed.17FFIEC BSA/AML InfoBase. Appendix P – BSA Record Retention Requirements An institution may be ordered on a case-by-case basis, such as during a law enforcement investigation, to retain records longer.

There is no fixed regulatory requirement for how often independent BSA/AML testing must occur. The frequency should match the institution’s risk profile. Many banks test on a 12-to-18-month cycle, though more frequent testing is warranted after identified deficiencies or significant changes to the compliance program, systems, or staffing.18FFIEC BSA/AML InfoBase. BSA/AML Independent Testing

Training is the component that separates programs that work from programs that exist on paper. Front-line staff who open accounts need to understand what triggers escalation. Compliance officers need deeper knowledge of sanctions programs and PEP risk factors. Senior management needs enough understanding to ask the right questions when reviewing performance. A compliance program nobody understands is worse than no program at all, because it creates a false sense of security while the actual risks go unmanaged.