How often to rescreen PEPs, by risk tier

How often to rescreen PEPs, by risk tier

AUSTRAC sets no fixed rescreening interval. How to set risk tiers, name the triggers that force an early rescreen, and record each decision you make.

AML/CTF Compliance 22 September 2026 10 min read AML Guard

Officer reviewing ongoing PEP rescreening results

PEP rescreening frequency isn’t a fixed number. It’s risk-based and event-triggered: continuous monitoring against priority lists, paired with periodic full reviews scaled to each customer’s risk rating. AUSTRAC doesn’t set an interval; the AML/CTF Act 2006 (Cth) requires ongoing customer due diligence instead. Get the triggers right and the record-keeping defensible, and the calendar date matters far less than most compliance teams assume.


TL;DR:


AML Guard
Make Rescreening Easier to Document
AML Guard supports ongoing screening, recorded risk reasoning, and an 8-year tamper-evident audit trail for Australian reporting entities.

Table of Contents

What is PEP rescreening frequency and how does it differ from screening?

Screening happens once, at onboarding. It’s a point-in-time check: you run the customer’s name against sanctions, PEP and adverse media sources, get a result, and make a decision. Monitoring is what happens after that. It’s the ongoing process of re-checking the same customer as external data changes, whether that’s a new sanctions listing, a ministerial appointment, or a fresh adverse media hit.

The distinction matters because a clean screen at onboarding tells you nothing about the customer’s status six months later. PEP status and sanctions listings are not static. Someone screened as a private citizen in January can become a state government minister by June, and nothing in a one-off screening process will catch that unless monitoring is running in the background.

The priority source is DFAT’s Consolidated List, which incorporates United Nations Security Council sanctions and carries immediate legal consequences in Australia if missed. Lower-priority sources, including some regional PEP databases and media aggregators, update on a slower, less predictable cycle.

The practical gap shows up when firms treat screening as a compliance box ticked once at file opening:

Ongoing monitoring is what closes that gap, and it’s the mechanism FATF’s guidance on PEPs points to when it talks about the level, frequency and extent of controls being proportionate to risk. That guidance carries no force in Australia, but it points the same way.

How should risk tiers set rescreening cadence and triggers?

There’s no AUSTRAC-mandated schedule, so the sensible move is to build your own defensible structure around risk tiers and named triggers rather than guessing at a number. Three tiers cover most reporting entities:

  1. High risk (confirmed PEPs, foreign PEPs, customers in higher-risk jurisdictions or with complex ownership structures): near-continuous monitoring against priority lists, with a full periodic review at the shortest interval your risk assessment supports.
  2. Standard risk (typical retail or commercial customers with no PEP or sanctions flags): regular monitoring against priority lists, with periodic full reviews on a longer, but still defined, cycle.
  3. Low risk (simple, low-value, well-understood relationships): monitoring continues, but periodic full reviews can sit at the longest interval your policy justifies.

The cadence numbers are yours to set and document. What isn’t optional is the list of triggers that should force an immediate rescreen regardless of tier:

Pro Tip: Write the rationale for each tier’s cadence into your risk assessment, not just your procedures manual. A supervisor reviewing your file wants to see why 90 days suits a high-risk PEP relationship, not just that it does.

This is exactly the proportionality FATF’s guidance describes; controls should track risk, and the reasoning behind each tier should be traceable back to your business-wide risk assessment.

Three risk tiers with different review cadences

How do you run rescreening at scale without drowning in alerts?

Two technical approaches sit underneath most rescreening programs, and mature setups run both. Delta (or continuous) rescreening checks only what’s changed, whether that’s a new list entry or an updated customer attribute, and can surface a match within hours of a list update. Full rescreens re-run every active customer against every source, and they’re the periodic backstop that catches anything a delta process might miss due to data quality issues or source lag.

Continuous rescreening is what actually closes the gap between a list publishing and a customer being checked. A mature program layers near-real-time delta screening for priority lists underneath periodic full CDD refreshes, with the real operational differences enforced through alert prioritisation rather than separate systems.

Alert triage needs its own rules. A reasonable starting structure:

Statistic Callout: Match volume alone tells you little; a program with high match counts but low completion rates is the real red flag. Track rescreen completion rate by tier, time-to-first-decision, and how often “resolved” false positives get reopened when customer attributes change. Slippage in any of these usually points to a resourcing or tooling gap, not a one-off blip.

One habit to avoid: permanently suppressing a match once it’s been marked a false positive. Attributes change, and a name that was cleared last year can become a genuine hit if the underlying customer details shift.

What records do supervisors expect for each rescreen?

Every rescreen needs a paper trail, not just a result. For each one, record the inputs used, the match outcome, the officer’s decision, and the reasoning behind it. That’s what turns a rescreen from an automated event into evidence.

The legal floor is seven years. Under the AML/CTF Act 2006 (Cth), reporting entities must retain records for a minimum of seven years, and rescreening records fall squarely within that requirement. Some platforms retain longer than the legal minimum, which gives extra buffer for long-running matters or historical reviews.

What matters most to a supervisor isn’t any single record. It’s whether:

Consistency across these documents is what a supervisor actually checks, far more than any individual rescreen record.

What does a practical rescreening checklist look like?

Turning all of this into a working program comes down to five steps, applied in order:

  1. Define your risk tiers and write down what monitoring intensity and review cadence apply to each.
  2. Identify your priority screening sources (sanctions, PEP, adverse media) and confirm how often each updates.
  3. Set your trigger list and attach appropriate SLAs to each alert priority level based on your risk framework.
  4. Assign clear roles: who triages, who decides, who signs off on edge cases.
  5. Pilot with a small customer cohort, measure completion and slippage, then adjust before rolling out firm-wide.

A generic schedule matrix helps make the policy concrete:

Trigger Who acts Cadence / SLA Recordkeeping note
Sanctions list update Screening system, analyst review Same business day Match outcome and officer decision logged
High-risk periodic review Compliance officer Set per risk assessment Full rescreen result and rationale recorded
Ownership or director change Analyst, compliance officer Within days of notification Beneficial ownership update and decision logged
Adverse media hit Analyst triage Two to three business days Source, assessment and outcome recorded

Start the pilot small. A cohort of twenty to thirty files across your risk tiers is enough to expose whether your SLAs are realistic before you commit the whole book of business to them, and it mirrors the practical setup steps in a Tranche 2 compliance checklist.

How does AML Guard support a documented rescreening program?

AML Guard runs scheduled rescreening automatically, triggered by list updates as well as by calendar cadence, and records every result alongside the officer’s decision. That pairing, an automated check plus a human sign-off, is what turns rescreening from a background process into evidence.

The platform’s customer due diligence workflows link to the same risk assessment, AML/CTF policies, compliance action plan, and training manual, all generated from the same underlying inputs. That means your rescreening cadence in policy matches what your training manual teaches staff, and both match the risk assessment that justified them in the first place.

Every decision sits in an 8-year tamper-evident audit trail, above the Act’s seven-year minimum, giving supervisors a consistent record to review.

Why annual-only reviews and suppressed alerts quietly break compliance programs

Most rescreening failures aren’t dramatic. They’re an annual review cycle that misses a PEP appointment made in March, or a false positive suppressed permanently instead of left open to re-match if attributes change. Both feel efficient in the short term and both create exposure that only surfaces at the worst moment, usually during a transaction or a supervisor’s file review.

The fix isn’t more screening for its own sake. It’s watching completion rates by tier, adding automation where delta rescreening can catch what annual cycles miss, and tightening SLAs so alerts don’t sit unactioned. A program that measures its own slippage catches its own failures before a regulator does.

Turn rescreening policy into a documented, automated program

Most firms build rescreening policy in a document and then run it manually, checking spreadsheets, chasing analysts, and hoping the annual review catches what slipped through. AML Guard is the alternative: it schedules rescreening automatically against priority lists, records every officer decision as it happens, and keeps that record in an 8-year tamper-evident trail, well past the Act’s seven-year minimum.

Because the risk assessment, policies, compliance action plan, and training manual all come from the same set of inputs, your rescreening cadence matches what’s written in policy and trained, ensuring consistency that’s hard to maintain with disconnected templates. If you’re weighing whether your current approach would hold up to a supervisor’s review, book a demo to see how the automation and artefacts work together, or check current platform subscription pricing to see what a program-wide setup costs.

Sources

FAQ

What Are the Common Red Flags Associated With PEPs?

Red flags include unexplained wealth relative to a known salary, complex ownership structures that obscure the ultimate beneficial owner, transactions routed through high-risk jurisdictions, and adverse media linking the customer to corruption or misuse of public office. Any of these should trigger an immediate rescreen rather than waiting for the next scheduled review.

What Is PEP Screening?

PEP screening is the process of checking a customer’s name against politically exposed persons lists, sanctions lists, and adverse media sources to identify heightened money laundering or corruption risk. It’s typically run at onboarding and then repeated through ongoing monitoring, since the AML/CTF Act 2006 (Cth) requires customer information to stay current, not just accurate at the point of onboarding.

How Long Does a Person Remain a PEP?

There’s no single fixed period; many programs apply enhanced scrutiny for a defined time after someone leaves a prominent public role, since the risk from their former position and connections doesn’t disappear immediately. The appropriate length depends on the individual’s risk profile and should be set out in your risk-based policy rather than assumed.

What Are the Three Types of PEP?

The three commonly recognised categories are foreign PEPs (individuals who hold prominent public roles in another country), domestic PEPs (those holding equivalent roles within your own jurisdiction), and international organisation PEPs (senior figures in bodies such as the United Nations or World Bank). Family members and close associates of any of these are usually treated with the same elevated scrutiny.

Does AML Guard Set a Fixed Rescreening Schedule?

AML Guard doesn’t impose one universal interval, because AUSTRAC doesn’t prescribe one either. Instead, it runs scheduled and list-triggered rescreening mapped to each customer’s risk tier, with every result and officer decision recorded for review.

See How AML Guard Works

Tranche 2 obligations are now in force.
Book a 20-minute demo to see how AML Guard supports your compliance from the moment your designated service begins.

Book a Demo
This article is for general information purposes only and does not constitute legal advice. Firms should obtain independent professional advice on their specific AML/CTF obligations.
Last reviewed: 22 September 2026.