
Under the AML/CTF Act, establishing whether a customer is a politically exposed person is part of customer due diligence. Foreign PEPs require enhanced CDD automatically, while domestic and international organisation PEPs require it only where the customer’s money laundering or terrorism financing risk is high. Every decision to clear or escalate a match needs a recorded rationale, kept until seven years after the relationship ends or the occasional transaction is completed, and you must keep watching for a customer who becomes a PEP after onboarding.
TL;DR:
- Foreign PEPs always require enhanced due diligence without exception, regardless of the transaction size or customer relationship details.
- Domestic and international organisation PEPs need enhanced CDD where the customer’s ML/TF risk is high, or another section 32 trigger applies.
- All PEP matches should be adjudicated with supporting evidence, checked against primary sources where possible, and recorded with the reasoning, kept until seven years after the relationship ends or the occasional transaction is completed (section 111).
- Ongoing monitoring, including re-screening triggered by role changes, media alerts, or periodic reviews, is essential throughout the customer relationship.
- AML Guard runs PEP and sanctions screening with ongoing rescreening and records officer decisions in its audit trail, and senior manager approvals can be recorded against individual decisions.
Table of Contents
- What is PEP screening in Australia, and who counts as a PEP?
- When do you need enhanced due diligence and senior manager approval?
- How do you actually screen for PEPs in practice?
- Why ongoing monitoring matters more than the first screen
- What to do when a screening match comes back
- Building a PEP screening checklist
- How AML Guard supports PEP screening and record-keeping
- Where Tranche 2 firms trip up on PEP screening
- Put your PEP screening on record with AML Guard
- Sources
- FAQ
What is PEP screening in Australia, and who counts as a PEP?
The AML/CTF Act defines three kinds of politically exposed person (section 5): foreign, domestic and international organisation PEPs, with further domestic offices specified in the AML/CTF Rules (section 1-5). Each definition includes the office holder’s family members and close associates. Getting this right matters more than any technology decision, because a screening tool can only be as accurate as the criteria you give it. Our guide to who counts as a PEP covers the definitions in full; this article is about the screening workflow.
AUSTRAC’s PEP guidance sets out what must happen once a PEP is identified, and the class matters, because it decides whether enhanced CDD applies automatically:
- Foreign PEP: enhanced CDD always applies (section 32).
- Domestic PEP: enhanced CDD applies where the customer’s ML/TF risk is high.
- International organisation PEP: enhanced CDD applies where the customer’s ML/TF risk is high.
Foreign PEPs always require enhanced CDD, regardless of how the transaction looks or how long you have known the customer. Domestic and international organisation PEPs require it where the customer’s ML/TF risk is high, so two customers who hold the same state government office can be treated differently depending on the designated service and other risk factors. For foreign PEPs, the enhanced CDD trigger covers the customer, any beneficial owner, anyone acting on the customer’s behalf, and anyone on whose behalf the customer receives the service; senior manager approval and source of wealth and funds cover the same people except someone acting on the customer’s behalf. Your risk assessment method, not a blanket policy, decides the outcome for domestic and international organisation PEPs, and the file should show how.
When do you need enhanced due diligence and senior manager approval?
Enhanced CDD is not an optional upgrade you apply when a transaction feels unusual. Section 32 of the Act says when it is required, and your file should show which trigger applied and why.
- Foreign PEP identified: enhanced CDD applies automatically, with no risk-based carve-out available.
- Domestic or international organisation PEP identified, and your risk assessment rates the relationship as high ML/TF risk: enhanced CDD applies. If the risk assessment concludes standard risk, ordinary CDD measures remain appropriate unless another section 32 trigger applies, though you still need to document that assessment.
- Any PEP relationship where new information emerges (a change in role, an adverse media hit, a shift in transaction pattern): reassess and apply enhanced CDD if the updated picture warrants it.
Senior manager approval sits alongside these triggers as a separate, mandatory gate. Where the customer, a beneficial owner or a person on whose behalf the customer receives the service is a foreign PEP, or a domestic or international organisation PEP and the risk is high, your AML/CTF policies must require a senior manager’s approval before the service is provided (Rules section 5-5). Approval is also needed to continue a relationship when one of them becomes a PEP, and your policies must cover approval where one of them was previously a PEP. This is not a rubber stamp. The senior manager needs enough information in front of them to genuinely evaluate the risk, which means your escalation package should include the PEP classification, the source of the match, the risk rating, and the proposed enhanced measures.
For a foreign PEP, and for a domestic or international organisation PEP where the risk is high, the Rules require you to establish the source of the PEP’s wealth and funds before providing the service (Rules section 6-23). Other enhanced measures are chosen by risk, and may include:
- More documentary evidence of the customer’s identity and ownership than standard CDD needed.
- A closer look at transactions against what you know of the customer’s wealth and income.
- Documentary evidence for the source of wealth and funds, rather than relying on a client’s verbal explanation alone.
- Increased transaction monitoring, with lower thresholds for review and shorter intervals between checks.
Pro Tip: Build your senior manager approval template so it forces a yes/no answer on each trigger condition individually, rather than a single blanket approval box. Anyone reading the file later should be able to see that the approver actually considered the classification, the risk rating, and the proposed measures as separate decisions, not one tick covering everything.
How do you actually screen for PEPs in practice?
Turning the Rules into a working process starts at onboarding, where you need to capture the right information before a match can even be assessed properly. Your intake form should ask directly whether the customer, or anyone with beneficial ownership or control, holds or has held a prominent public function, and should capture full legal names, any known aliases, date of birth, nationality, and current or former public roles.
From there, AUSTRAC’s guidance points to a mix of methods rather than a single source.
- Ask the customer directly as part of onboarding, and document the answer regardless of outcome.
- Check reputable databases and screening tools that maintain PEP records, understanding that these lists are a starting point, not a verdict.
- Run open-source and internet searches against the customer’s name, any known aliases, and close associates.
- Consult government records and directories, including the Australian Government Directory’s list of Commonwealth entities and companies, which helps confirm whether someone genuinely holds a Commonwealth office a database has flagged.
If you use a third-party screening provider, treat their output as an investigative lead rather than a legal determination. AUSTRAC tells firms using a provider to check that it searches for the positions and offices in the Act’s PEP definitions, and notes you may also need to check different spellings of names; a vendor’s label is not the test. This matters in two directions: a provider might flag someone whose actual role does not meet the statutory threshold, and equally, a provider’s list might miss a domestic official whose position genuinely qualifies. When instructing a provider or configuring a screening tool, specify the exact match parameters you want, including name variants, transliterations, and date-of-birth tolerances, so the search actually reflects the risk you are trying to catch.
Every match a screening process throws up is a candidate, never a finding. The adjudication workflow that follows the initial hit is where the real compliance work happens: verifying the customer’s identity against the flagged individual, checking whether the office or title matches the statutory description, cross-referencing primary sources like official government listings, and contacting the customer for clarification if the picture remains unclear. Whatever you conclude, clear or escalate, the reasoning behind that conclusion is what the record has to show, not the original alert itself.
Screening at onboarding is not the end of it. You must also take reasonable steps to find out whether a customer, a beneficial owner or a person on whose behalf the customer receives the service becomes a PEP during the relationship (section 30 of the Act and Rules section 6-24).
Why ongoing monitoring matters more than the first screen
PEP status is not fixed at the point you onboard a customer. Elections change governments and international organisations rotate their senior people. AUSTRAC suggests asking the customer when you reverify their KYC information, periodic open-source or database checks, and watching for transactions that suggest their circumstances have changed. The Act sets no fixed rescreening interval; our guide to PEP rescreening frequency covers how to set one by risk.
Monitoring does not sit in isolation from your broader transaction monitoring and reporting obligations. A newly detected PEP status change should feed directly into your transaction monitoring rules, potentially lowering thresholds for review, and should prompt reconsideration of whether a suspicious matter report is warranted under section 41 if the customer’s conduct alongside the new information raises concern. Treat the PEP re-screen and the transaction monitoring system as connected controls, not parallel processes that happen to sit on the same customer file.
What to do when a screening match comes back
A hit against a PEP database or an internet search is the start of an investigation, not the end of one. Treating it as an automatic finding goes wrong either way: it triggers unnecessary friction for customers who were never actually PEPs, or worse, it gets waved through without genuine scrutiny because the volume of alerts becomes unmanageable.
A disciplined adjudication runbook keeps both risks in check:
- Confirm identity first. Match the flagged name against the customer’s verified identity documents, checking date of birth, nationality, and any other identifying details before assuming the match is genuine.
- Check the office or title against the statutory description. A database entry calling someone a “senior official” tells you nothing until you have confirmed the actual role sits within the Act’s definition of a foreign, domestic, or international organisation PEP.
- Cross-reference primary sources. Government directories, official gazettes, and organisational websites carry more evidentiary weight than a vendor’s internal categorisation.
- Contact the customer if ambiguity remains. A direct question about a role or former position is a legitimate and often the fastest way to resolve an unclear match.
- Decide and record, either way. If you clear the match, write down why. If you escalate, document the classification, the risk rating, and the enhanced measures applied.
Whether enhanced measures apply follows the trigger rules already covered: automatic for foreign PEPs, risk-based for domestic and international organisation PEPs. Senior manager approval is mandatory where the customer, a beneficial owner or a person on whose behalf the customer receives the service is a foreign PEP, or a domestic or international organisation PEP and the customer’s risk is high, and the senior manager’s decision, whether to proceed, proceed with conditions, or decline the relationship, needs its own documented rationale sitting alongside the original adjudication.
Termination or refusal of service is a legitimate outcome where the risk cannot be adequately mitigated, but it should never be the default response to a match. A rushed exit, taken without proper adjudication, is poor risk management, because it suggests the entity never actually understood the risk it was managing.
What you retain matters as much as what you decide. Section 111 of the Act requires your CDD records to include any analysis, risk assessment or decision making about the customer, kept until seven years after the relationship ends or the occasional transaction is completed. For a PEP check, AUSTRAC suggests keeping extracts of the pages that suggested the person is a PEP, the names and phrases you searched for, and why you decided they are or are not a PEP. A file that shows only the outcome, without the reasoning, is incomplete.

Building a PEP screening checklist
Your AML/CTF policies must set out how you establish whether a person is a PEP, so the checklist starts there.
Your written policy should address:
- How your entity determines whether a customer is a foreign, domestic, or international organisation PEP, including family members and close associates.
- The risk factors you use to decide whether a customer with a domestic or international organisation PEP is high ML/TF risk, which triggers enhanced CDD.
- The escalation pathway to senior manager approval, including what information the approver must review.
- Your re-screening cadence and the triggers that prompt an out-of-cycle check.
On the systems side, three things matter more than any single feature: screening frequency that matches your documented cadence, an adjudication workflow that forces a recorded decision on every match rather than allowing silent dismissal, and a tamper-evident audit trail that retains PEP screening decisions and their reasoning until seven years after the relationship ends or the occasional transaction is completed. A structured risk scoring approach that records the reasoning behind each rating gives your senior managers something concrete to review rather than a bare number.
Staff training and governance round out the picture. Front-line staff need to understand what questions to ask at onboarding and when to flag ambiguity upward, while senior managers need clarity on exactly which approvals are theirs to give and what a defensible file looks like before they sign it. Building this into your broader staff training program rather than treating PEP screening as a standalone module keeps the obligation connected to your wider AML/CTF framework.
Pro Tip: Run a quarterly file review on a small sample of cleared PEP matches, not just escalated ones. Reviewing why a match was dismissed is often more revealing about the quality of your adjudication process than reviewing the escalations, because dismissals rarely get a second look once the file is closed.
How AML Guard supports PEP screening and record-keeping
The obligations above sound straightforward in summary and become considerably more demanding the moment you try to run them at volume across a live customer book. AML Guard’s platform runs sanctions, PEP, and adverse media screening as a connected process, with the officer’s decision and reasoning recorded against each match in an 8-year tamper-evident audit trail, above the Act’s seven-year minimum.
The platform automates the repetitive parts of the workflow: running the initial searches, surfacing candidate matches, and maintaining the customer due diligence record set that ties identity verification to the screening outcome. Senior manager approvals can be recorded against individual decisions, so the approval sits in the same file as the screening result rather than in an email chain. Beneficial ownership determination runs on a company’s ACN, with trusts and SMSFs reached through their corporate trustee’s own ACN-based determination, keeping that process anchored to a verifiable identifier rather than a manual lookup.
None of this replaces the compliance officer’s judgement. AML Guard records the decision and the reasoning behind it; the determination itself, whether a match genuinely reflects a statutory PEP role, still belongs to the person reviewing the file. If your firm is working through what a Tranche 2 program needs to look like end to end, book a demo to see how the screening and recordkeeping workflow fits your specific designated services.
Where Tranche 2 firms trip up on PEP screening
A common mistake in newly regulated firms is treating PEP screening as a box to tick during onboarding and then forgetting it exists. That approach misreads what AUSTRAC is actually asking for. A PEP relationship formed today can look completely different in eighteen months once an election reshuffles a state cabinet or a customer takes on a new board appointment, and a program with no re-screening cadence is likely to miss that change.
The second mistake sits right behind the first: outsourcing the definition of a PEP to whatever a vendor’s database happens to label. A screening tool is a search mechanism, not a legal authority. If your adjudication process stops at “the database flagged them” without checking the actual office against the Act’s definitions, you have not really adjudicated anything.
Fix both by building lifecycle monitoring into your CDD program from day one, and by insisting every adjudication, cleared or escalated, carries a written rationale and, where the triggers require it, a senior manager’s signature. That discipline is what lets the file show why each decision was made.
Put your PEP screening on record with AML Guard
Manual PEP checks run through spreadsheets and inbox approvals tend to break down exactly when volume increases. The platform is designed for entities that require ongoing sanctions, PEP, and adverse media screening, with all officer decisions and reasoning recorded in an 8-year tamper-evident audit trail rather than scattered across email threads and shared drives.
The system brings together screening, recorded senior manager approvals, and beneficial ownership determination based on company identifiers to help align risk assessment, policies, and training consistently. AML Guard is not a self-service sign-up: firms begin with a demo, after which the platform is configured to their designated services, risk profile, and workflow. If your PEP screening process currently depends on someone remembering to run a periodic check, book a demo with AML Guard and see how an ongoing, recorded workflow replaces that risk.
Sources
The obligations in this guide are drawn from the Act, the Rules and AUSTRAC’s published guidance; the practice tips are our own. Keep the primary sources to hand when building or reviewing a PEP screening program.
- Politically exposed persons (PEP) | AUSTRAC
- Commonwealth entities and companies | Australian Government Directory
- Anti-Money Laundering and Counter-Terrorism Financing Act 2006 (Cth)
- Anti-Money Laundering and Counter-Terrorism Financing Rules 2025
FAQ
How is PEP screening done in Australia?
Entities ask the customer directly about public office at onboarding, check reputable databases and government directories, and run open-source searches on the customer’s name and known associates. Every resulting match is then adjudicated against the PEP definitions in the AML/CTF Act, with the decision and reasoning recorded regardless of outcome.
What are the common red flags associated with PEPs?
Commonly cited red flags include unexplained wealth relative to a publicly known salary, complex ownership structures involving family members or close associates, transactions inconsistent with the customer’s stated occupation, and reluctance to explain source of funds or source of wealth. None of these alone confirms PEP status; they inform the risk assessment once a role has been identified.
Who is considered a PEP by AUSTRAC?
AUSTRAC recognises three classes: foreign PEPs, domestic PEPs, and international organisation PEPs, plus their family members and close associates. Foreign PEPs require enhanced due diligence automatically, while domestic and international organisation PEPs require it only when the assessed ML/TF risk is high.
How do you check if someone is a PEP?
Combine a direct question at onboarding with checks against government directories, reputable screening databases, and open-source media searches, then verify any match against the customer’s confirmed identity and the actual office held. A database flag is a starting point for investigation, never a final determination on its own.
What records must be kept for PEP screening decisions?
Section 111 requires records of any analysis, risk assessment or decision making, kept until seven years after the relationship ends or the occasional transaction is completed. For a PEP check, AUSTRAC suggests keeping what you searched, what you found and why you decided the person is or is not a PEP, along with any senior manager approval, whether the match was cleared or escalated. AML Guard’s platform maintains this as a tamper-evident audit trail tied to each screening decision.
Recommended
- Tranche 2 customer due diligence in Australia
- Tranche 2 AML Australia: your compliance obligations explained
- AML/CTF Program Documents for Tranche 2
- Acceptable ID documents for Tranche 2 firms
See How AML Guard Works
Tranche 2 obligations are now in force.
Book a 20-minute demo to see how AML Guard supports your compliance from the moment your designated service begins.