Who counts as a PEP, and what follows

Who counts as a PEP, and what follows

Which PEP classes trigger mandatory enhanced due diligence, when ECDD is risk-based instead, and what a defensible PEP record actually contains.

AML/CTF Compliance 23 September 2026 14 min read AML Guard

Compliance officer reviewing PEP records

A politically exposed person (PEP) in Australia is an individual who holds, or has held, a prominent public position or function, classified under the AML/CTF Rules as a foreign PEP, a domestic PEP, or an international organisation PEP. Immediate family members and close associates fall into the same scope because of their relationship to that person, not any office of their own. The consequence differs sharply by class: foreign PEPs always trigger enhanced customer due diligence (ECDD), while domestic and international organisation PEPs only require it where the money laundering or terrorism financing (ML/TF) risk is assessed as high.


TL;DR:


AML Guard
Make PEP checks easier to document
AML Guard combines PEP screening, risk scoring, approval records and an 8-year tamper-evident audit trail for Australian reporting entities.
Book a demo

Table of Contents

The three classes of PEP: foreign, domestic and international organisation

AUSTRAC’s guidance sets out three distinct categories of PEP, and getting the classification right is the first job of any compliance officer, because it determines whether ECDD is mandatory or risk-based. Each category means an individual who holds, or has held, a prominent public position or function; the “has held” wording matters, because former officeholders don’t automatically fall outside scope.

A foreign PEP is an individual who holds or has held a prominent public position or function in a country other than Australia. This typically includes:

Importantly, a foreign PEP does not need to live overseas to count. A person who holds a prominent foreign public role but currently works or resides in Australia, for instance a foreign diplomat posted to Canberra, still meets the foreign PEP definition. Nationality and residency are irrelevant; the test is the role itself.

A domestic PEP covers the equivalent offices within Australia: members of federal, state or territory parliaments, senior executive government officials, senior judicial figures, senior military officers, and senior officials of a political party’s governing body at the state or federal level. AUSTRAC’s own worked examples describe scenarios such as an existing customer being elected as a mayor or a state MP, which converts them into a domestic PEP from the moment they take office, regardless of what their file said the week before.

An international organisation PEP is a person who holds or has held a prominent function in an international organisation, such as a director, board member, or senior executive of a body like the United Nations, the World Bank, or a comparable multilateral institution. The same officeholder logic applies: seniority is the threshold, not the mere fact of employment by the organisation.

A useful shorthand for classifying any individual is to ask which government or institution the role sits inside. Legislature, executive, judiciary, military, central bank, and political party leadership are the recurring categories across all three classes. Once you can place a customer or beneficial owner into one of those categories and one of the three classes, the classification exercise is largely done. The statutory anchor for these definitions sits within the AML/CTF Rules 2025, alongside the broader customer due diligence obligations set out under the AML/CTF Act 2006 (Cth).

Where the classification genuinely isn’t obvious, for example, a state-owned enterprise executive or a senior regulator who isn’t part of the judiciary or executive in the strict sense, AUSTRAC’s quick guide on politically exposed persons sets out further examples and indicators that reporting entities can use to reason through edge cases consistently.

Who else is covered: family members and close associates

The PEP definition doesn’t stop at the officeholder. Immediate family members and close associates of a PEP are captured by the same definition, and the reason is entirely relational: they are in scope because of who they are connected to, not because of anything they’ve done or any office they hold themselves.

Immediate family typically includes:

Close associates are harder to define with a tidy list, because the connection is about substance rather than a formal title. Indicators that someone is a close associate include:

Pro Tip: Document the specific fact that establishes the connection, not just the conclusion. “Joint director of [company] per ASIC records, sighted 14 March 2026” survives an audit; “known associate of a PEP” does not.

The relationship, not the individual’s personal risk profile, is what pulls immediate family members and close associates into the PEP definition. A retired schoolteacher married to a state minister is not personally exposed to political risk, but AUSTRAC’s guidance treats the marriage itself as the risk factor worth recording and monitoring.

PEP links to family and close associates

How do you establish reasonable grounds that someone is a PEP?

Establishing reasonable grounds means forming a defensible, evidence-based view, not a guess and not a formal certainty. AUSTRAC does not require reporting entities to prove PEP status beyond doubt; it requires a considered judgement built on credible public information.

A workable, defensible process looks like this:

  1. Check official registers first. Parliamentary websites, government directories, and court appointment records are the primary source for domestic roles.
  2. Use DFAT resources for Australian officeholders posted overseas. The Department of Foreign Affairs and Trade’s lists of ambassadors and representatives cover Australian representatives, who are domestic PEPs. For foreign officeholders, the relevant country’s own government directories are the authoritative reference.
  3. Cross-check reputable media. Established news reporting can corroborate an office or a close associate connection where official registers are silent or out of date.
  4. Timestamp and record every check. Note the source, the date checked, and the officer who made the call.
  5. Escalate where your policy requires it. Many firms set a threshold where any positive PEP finding needs senior manager sign-off before onboarding proceeds.

Timing matters as much as method. PEP status should be checked at onboarding, revisited during ongoing customer due diligence, and re-checked when a trigger event occurs, an election result, a cabinet reshuffle, or a senior appointment, any of which can convert an existing customer into a PEP overnight.

AUSTRAC’s own examples make this concrete: a firm’s existing client who is later elected as a mayor becomes a domestic PEP from the point of election, and the documented worked example shows firms are expected to update the customer’s risk rating and apply ongoing CDD from that trigger, not wait for the next scheduled review.

If your firm handles CDD onboarding at any real volume, the process described here overlaps directly with broader Tranche 2 customer due diligence obligations. It is worth building PEP checks into that same workflow rather than treating them as a separate task.

What happens once someone is classified as a PEP?

The legal consequence is not uniform across the three classes, and this is the distinction that trips up firms building a one-size-fits-all policy. Foreign PEPs always require enhanced customer due diligence. There is no risk-based carve-out. Domestic PEPs and international organisation PEPs require ECDD only where the ML/TF risk associated with the business relationship is assessed as high.

Practical ECDD measures, once triggered, typically include:

What pushes a domestic or international organisation PEP into the “high risk” bracket that triggers ECDD? Common indicators include: unusually large or complex transactions inconsistent with known income; use of trusts, shell companies, or nominee arrangements to obscure ownership; dealings involving jurisdictions with weak AML controls; or a role with genuine discretion over public funds or procurement decisions. A backbench local councillor with a modest mortgage and a transparent salary looks very different, risk-wise, from a state minister overseeing multi-billion-dollar infrastructure contracts, even though both are technically domestic PEPs.

Pro Tip: Resist the urge to apply blanket ECDD to every domestic PEP “just in case.” AUSTRAC’s framework is explicitly risk-based for this class; over-applying ECDD wastes resourcing and can mask genuinely high-risk relationships in a sea of low-risk paperwork.

None of this should be read as an accusation. PEP status is a risk factor that justifies closer attention, not a finding of wrongdoing. The overwhelming majority of PEPs, in Australia and abroad, are exactly what they appear to be: public officials with no connection to illicit finance. The point of the classification is proportionate scrutiny, not suspicion by default.

How should former PEPs be treated?

A person doesn’t shed PEP status the moment they leave office. AUSTRAC’s guidance takes a risk-based approach to former PEPs, meaning firms can reduce the intensity of controls over time, but only where that reduction is genuinely justified and documented.

Before downgrading a former PEP’s risk rating, weigh up:

When you do lower controls, record the decision the same way you’d record the original PEP finding: who made the call, what evidence supported it, and the date. A downgrade without a documented rationale looks, on later review, exactly like a firm that simply stopped paying attention.

What records do you need to keep for a PEP customer?

The Act sets a legal minimum retention period of seven years for records connected to designated services, and that minimum applies fully to PEP-related customer due diligence evidence. Many firms choose to retain program-related records for longer as internal good practice, but seven years is the statutory floor under the AML/CTF Act 2006 (Cth), not a target to hit and then delete.

What belongs in the file:

This is where linked program artefacts earn their keep. A business-wide risk assessment, a set of AML/CTF policies, and a staff training record that all tell the same story make a supervisory review far less painful than a file where the risk assessment says one thing and the actual PEP decision says another.

A worked look at keeping PEP decisions consistent and auditable

The hardest part of PEP compliance usually isn’t the individual decision, it’s keeping hundreds of individual decisions consistent with each other over years of staff turnover. A PEP finding should show up identically in four places: the customer’s KYC record, the firm’s business-wide risk assessment, its AML/CTF policies, and its staff training material. If those four documents tell four slightly different stories about how PEPs are handled, an auditor will notice before you do.

A platform built specifically for this obligation can help hold that consistency together. Useful features include:

Pro Tip: If your firm handles property settlements or company formations regularly, check whether your existing checklist already prompts a PEP check at the right trigger points; a Tranche 2 readiness checklist built for real estate professionals is a fast way to spot gaps before 1 July 2026 obligations catch you out.

None of this replaces the officer’s judgement. Automation can run the lookups, flag the re-screen date, and keep the audit trail intact, but the decision about whether reasonable grounds exist, and whether a domestic PEP’s risk is genuinely high, still sits with a human compliance officer who understands the specific relationship.

Why documentation discipline matters more than the classification itself

Getting the classification right matters, but in practice, most PEP disputes during a supervisory review aren’t about whether someone was correctly labelled a foreign or domestic PEP. They’re about whether the firm can show its working: what was checked, when, by whom, and why the resulting decision followed logically from the risk assessment already on file.

Firms that treat PEP identification as a one-off tick box tend to struggle when a customer’s circumstances change quietly, an election, a promotion, a change in business ties, and nobody re-checks the file for years. Building re-screen triggers and senior manager sign-off into the process, rather than relying on someone remembering to look again, is the difference between a defensible file and a lucky one.

It’s also worth resisting the instinct to treat every PEP flag as a red flag. The Rules deliberately separate foreign PEPs, who always require ECDD, from domestic and international organisation PEPs, who only require it where risk is genuinely high. Collapsing that distinction either wastes compliance resourcing on low-risk customers or, worse, trains staff to see PEP status as inherently suspicious when it usually isn’t.

How AML Guard supports PEP identification and record-keeping

AML Guard is built specifically for Australian Tranche 2 reporting entities, not adapted from banking software with local labels bolted on. The platform runs sanctions, PEP, and adverse media screening with ongoing re-screening, helping ensure PEP classifications remain up to date beyond initial onboarding.

Guided wizards help produce your risk assessment, AML/CTF policies, compliance action plan, and staff training manual as a linked set, so a PEP finding in a customer file aligns with associated compliance documents. Senior manager approvals can be recorded against individual decisions, and a tamper-evident audit trail maintains that history. Beneficial ownership lookups can run on a company’s ACN, with trusts and SMSFs reached through their corporate trustee’s own ACN-based checks. An officer approves every determination before CDD proceeds; the platform assists with lookups and record-keeping, not the judgement call.

Firms begin with a demo rather than a self-service sign-up, so your tenant gets configured to your designated services and workflow from day one. Full plan and per-check pricing details, including the Platform subscription and per-service fees, are available on the AML Guard site if you want to see how it fits your firm’s volume before booking that first conversation.

Sources

FAQ

Who is considered a PEP by AUSTRAC?

AUSTRAC treats a PEP as an individual who holds, or has held, a prominent public position or function within one of three classes: foreign, domestic, or international organisation. Immediate family members and close associates of that person are also captured, and the full definition sits within AUSTRAC’s PEP guidance.

Is a local councillor a PEP?

It depends on seniority and the specific role, not the title alone. A councillor holding a senior executive government function, such as a mayor with executive authority, generally falls within the domestic PEP definition, while more junior or purely advisory local roles may not meet the threshold; AUSTRAC’s worked mayoral example is the clearest reference point.

How long is a person considered a PEP?

There is no fixed cut-off period in the Rules; a former PEP can retain elevated risk indefinitely if circumstances warrant it, or be downgraded sooner where the risk genuinely has reduced. Firms should assess factors like time since leaving office, continuing influence, and unexplained wealth before lowering controls, and document that decision the same way they’d document the original finding.

Does PEP status mean the person has done something wrong?

No. PEP status is a risk factor that justifies proportionate scrutiny, not an allegation or a presumption of misconduct. The vast majority of individuals classified as PEPs, in Australia and internationally, have no connection to illicit finance whatsoever.

Do domestic PEPs always require enhanced due diligence?

No, and this is the detail firms most often get wrong. Foreign PEPs always require ECDD under the Rules, but domestic and international organisation PEPs only require it where the ML/TF risk is assessed as high for that specific relationship.

See How AML Guard Works

Tranche 2 obligations are now in force.
Book a 20-minute demo to see how AML Guard supports your compliance from the moment your designated service begins.

Book a Demo
This article is for general information purposes only and does not constitute legal advice. Firms should obtain independent professional advice on their specific AML/CTF obligations.
Last reviewed: 23 September 2026.