Obligations
PEP and targeted financial sanctions screening in Australia
Politically exposed person screening and targeted financial sanctions screening are related controls with different consequences. A PEP relationship is not prohibited and a PEP is not presumed criminal; the status informs risk and can trigger additional CDD, source enquiries, approval and monitoring. A true sanctions match can engage legal prohibitions on making assets available or dealing with controlled assets and needs urgent specialist handling. A reporting entity should therefore avoid a single opaque pass-or-fail screen. This guide explains who to screen, when to screen, how to resolve name matches and how to preserve a reasoned decision. The DFAT Consolidated List and legal settings change, so screening must use current data and the response to an apparent match should follow current AUSTRAC and DFAT guidance.
Step-by-step process
Build the population
Identify customers, beneficial owners, representatives and other relevant connected parties.
Run current screening
Use verified identifiers, aliases and current PEP and Australian sanctions data.
Resolve and respond
Separate false positives, PEP risk measures and urgent sanctions action with evidence.
Monitor change
Rescreen on list updates and customer events, and quality-test alert decisions.
Screen the right people and entities
AUSTRAC requires a reporting entity to establish on reasonable grounds whether relevant people are PEPs before providing a designated service. Depending on the customer and service, the screening population can include the customer, beneficial owners, representatives and a person on whose behalf the service is received. For sanctions, assess the customer and relevant connected parties, including ownership and control, because prohibitions are not limited to an exact customer-name match.
Create screening rules for individuals and entities, aliases, former names, transliteration, date of birth, nationality, address, office, ownership and control. A company search and individual screen perform different functions. Identify and verify the person sufficiently before relying on a no-match result; incomplete names or unknown birth dates can make screening ineffective. Document who was screened, against which data, at what time, using which parameters and with what result.
Treat PEP status as a risk factor, not an accusation
AUSTRAC distinguishes foreign PEPs, domestic PEPs and PEPs of international organisations, together with relevant family members and close associates under current definitions. PEP status can change during a relationship, so monitoring is necessary. A match should be resolved using reliable attributes and, if confirmed, reflected in the customer risk assessment. Explain the risk without discriminatory assumptions: public function, access, jurisdiction, recency, relationship purpose and controls are relevant.
Foreign PEPs and higher-risk domestic or international-organisation PEPs can require additional measures under current law and policy, including senior-management approval, establishing source of funds and source of wealth, enhanced due diligence and monitoring. Apply the precise current requirements to the PEP type and risk. Do not automatically decline every PEP, and do not automatically downgrade a former PEP without assessing the continuing influence, exposure and applicable definition.
Escalate possible sanctions matches before proceeding
DFAT's Consolidated List records persons and entities subject to Australian targeted financial sanctions and is updated as designations change. Screening should use a current, complete source and consider aliases and identifying details. If a potential match cannot be confidently ruled out, stop the affected service, payment or asset dealing where necessary to avoid a prohibited action, preserve confidentiality and escalate immediately to someone authorised and competent to apply sanctions law.
Resolve the alert by comparing identifiers, ownership and control rather than clearing on name difference alone. A confirmed match can require freezing or preventing dealing with an asset and notification or engagement with relevant authorities under current requirements. Obtain sanctions advice for ownership, control, indirect benefit and permit questions. Do not tell the customer that an SMR has been or may be lodged, and coordinate sanctions action with AML reporting without assuming one report satisfies every legal duty.
Design screening for change and quality
Screen before service at the point required by the CDD framework, and rescreen throughout the relationship. Event triggers include ownership or representative change, new instructions, higher-risk services, jurisdiction change, new PEP information, sanctions-list updates and a material adverse information result. Batch or continuous screening frequency should reflect risk and list-update capability. A one-time onboarding screen cannot identify a customer designated later.
Tune matching to manage false positives without creating dangerous blind spots. Quality assurance should sample cleared alerts, overrides and no-match populations, test data completeness and assess time from list update to action. Vendor use does not transfer responsibility. Contracts should address list sources, update frequency, matching logic, audit evidence, availability, data protection and exit. Maintain a manual contingency for outages and an urgent process for retroactive list matches.
Document a two-track decision process
Keep PEP reasoning and sanctions-match evidence distinct even if one system generates both alerts. The outcome record should allow a reviewer to reproduce the decision without exposing SMR information to staff who do not need it. A trigger can justify review without proving suspicion; any SMR decision should use the separate statutory test and protected process.
- Identify and verify the customer and relevant connected parties before interpreting screening output.
- Screen against current PEP and Australian targeted-sanctions data with sufficient identifiers and alias handling.
- Resolve each alert using evidence, a trained reviewer, documented rationale and controlled override authority.
- For a confirmed PEP, classify type and risk, then apply approvals, source enquiries, enhanced measures and monitoring as required.
- For an unresolved or confirmed sanctions concern, stop affected action, obtain specialist advice and follow current DFAT, AUSTRAC and reporting requirements.
- Rescreen on list updates and customer-change triggers, and test vendor data and alert quality.
Official sources
Use these primary AUSTRAC pages to confirm the current rules and apply them to your circumstances.
Frequently asked questions
Must a reporting entity reject every PEP?
No. PEP status is not proof of wrongdoing or an automatic prohibition. Establish the PEP type and customer risk, then apply the enhanced measures, source enquiries, approvals and monitoring required by current law and policy. A decision to accept or decline should be reasoned and non-discriminatory.
Is a PEP match the same as a sanctions match?
No. PEP controls manage heightened corruption and financial-crime risk. Australian targeted financial sanctions can prohibit dealing with assets or making assets available. Keep separate decision paths, even where one screening provider returns both types of alert.
How often should customers be screened?
Screen at the required onboarding point and on a risk-sensitive ongoing basis. Include list updates and changes in ownership, representation, PEP status, jurisdiction or service risk. The interval should not allow a newly designated person to continue unnoticed simply because an annual review is months away.
What should staff do with a possible DFAT match?
Do not casually clear it or proceed with the affected dealing. Preserve the evidence, restrict disclosure, compare reliable identifiers and escalate urgently under the sanctions procedure. Obtain specialist advice and follow current DFAT and AUSTRAC reporting or asset-control requirements if the match remains possible or is confirmed.
Put it into practice
Cassandra AML turns these obligations into a working system: designated-service decisions, customer due diligence, screening, monitoring and reporting records — hosted in Sydney, free to start.
This guide is general information for Australian professionals. It is not legal advice and does not replace the AML/CTF Act, the AML/CTF Rules or AUSTRAC guidance. Confirm your specific obligations with AUSTRAC or a qualified legal adviser. See our editorial and correction standards.