What is a politically exposed person?
A politically exposed person (PEP) is a natural person who holds or has held a prominent public function. The EU definition is in Article 2(1), point 34 of the Anti-Money Laundering Regulation (AMLR), Regulation (EU) 2024/1624, which applies from 10 July 2027. In Sweden today, the definition is in Chapter 1, Section 8, point 5 of the Swedish AML Act (2017:630): a person who holds or has held an important public function in a state or an international organisation.
Chapter 1, Section 9 of the Swedish AML Act lists the functions that count:
- heads of state or government, ministers, and deputy and assistant ministers
- members of parliament and similar legislative bodies
- members of the boards of political parties
- judges of supreme courts, constitutional courts or other high-level judicial bodies
- senior officials at audit authorities and members of central bank governing bodies
- ambassadors, heads of mission and high-ranking officers in the armed forces
- members of the administrative, management or supervisory bodies of state-owned enterprises
In an international organisation, directors, deputy directors, board members and similar posts count.
Are domestic PEPs covered?
Yes. The Swedish definition covers a function in any state. The Act does not distinguish between Swedish and foreign PEPs. A member of the Swedish parliament is a PEP in the same way as a foreign minister. The difference lies in the risk assessment, not the definition.
Who counts as a family member or close associate?
The PEP rules also cover people around the PEP. The Swedish definitions are in Chapter 1, Section 10 of the AML Act.
Family member means spouse, registered partner, cohabitant, children and their spouses, registered partners or cohabitants, and parents.
Known close associate means:
- a natural person who is known, or is reasonably believed, to be a joint beneficial owner of a legal person or arrangement with a PEP, or to have other close ties with a PEP
- a natural person who is the sole beneficial owner of a legal person or arrangement that is known, or reasonably believed, to have been set up for the benefit of a PEP
Close ties means close business relationships and other ties that may carry a higher risk of money laundering or terrorist financing.
What does the law require of you?
PEP screening has two steps. First you establish whether anyone is a PEP. Then you take the measures that follow from the answer.
Step 1: Assess whether the customer or beneficial owner is a PEP
Under Chapter 3, Section 10 of the Swedish AML Act, you must assess whether the customer or the customer's beneficial owner is a PEP, a family member or a known close associate. The check covers every beneficial owner you have identified, not only the customer. See beneficial ownership.
Step 2: Apply the enhanced measures
If the customer or beneficial owner is a PEP, Chapter 3, Section 19 requires you always, in addition to standard CDD, to:
- establish the source of the assets involved in the relationship or transaction, through appropriate measures
- apply enhanced ongoing monitoring of the relationship and monitor activity and transactions more closely
- obtain approval from a senior decision-maker before deciding to enter into or end the relationship
Under the second paragraph of Section 19, the same measures apply when the customer is a family member or known close associate of a PEP.
A senior decision-maker is defined in Chapter 1, Section 8, point 9. It is a board member, the CEO or another officer with enough knowledge of the risk exposure and enough authority to take decisions that affect it.
The word always in Section 19 matters. The Section 19 measures apply whatever risk level you would otherwise have reached.
How long does someone remain a PEP?
Under Chapter 3, Section 20 of the Swedish AML Act, the Section 19 measures apply for 18 months after the person leaves the public function. After that, they apply only if the risk in the customer relationship is assessed as high.
When the measures stop for the former PEP, they also stop for family members and known close associates (Section 20, second paragraph).
What changes with AMLR?
From 10 July 2027, AMLR applies directly (Article 90). For PEP screening, several points change:
| Question | Swedish AML Act (today) | AMLR (from 10 July 2027) |
|---|---|---|
| Definition | Ch. 1, Section 8 point 5 and Section 9 | Article 2(1)(34), with more levels, including regional and local functions in areas of at least 50,000 inhabitants |
| Family member | Spouse, partner, cohabitant, children and their partners, parents | Same circle, plus siblings of heads of state or government, ministers and deputy or assistant ministers (Article 2(1)(35)(d)) |
| Enhanced measures | Ch. 3, Section 19 | Article 42(1): senior management approval, source of wealth and source of funds, enhanced ongoing monitoring |
| After leaving office | 18 months, then only at high risk (Ch. 3, Section 20) | Until the risk no longer exists, and for at least 12 months (Article 45(2)) |
| List of functions | Listed in the Act | Each Member State issues a list; the Commission compiles a single EU list (Article 43) |
Article 2(2) states that middle-ranking and junior officials are not covered. Article 46 extends the PEP measures to family members and known close associates. Under Article 20(1)(g), you must determine whether the customer or beneficial owner is a PEP, family member or known close associate.
Note the wording shift: AMLR asks for both source of wealth and source of funds. The Swedish Act speaks of the source of the assets in the relationship.
How does PEP screening work in practice?
The law says what you must achieve, not which tool to use. In practice, most obliged entities combine several sources.
1. Ask the customer
Ask the customer to state whether they, or any beneficial owner, are a PEP, family member or close associate. A self-declaration is evidence, not a check. It is rarely enough on its own.
2. Screen against PEP data
Run name, date of birth and nationality against a PEP database. Commercial providers compile these from public sources. Review hits manually. A common name can give many false positives, and a real match can be missed if spelling differs.
PEP and sanctions screening often run in the same step, but they answer different questions. A PEP match triggers enhanced measures. A sanctions match may mean you cannot proceed at all. See sanctions screening.
3. Resolve each hit
Confirm or discard every hit. Record which data let you rule the identity in or out.
4. Establish the source of assets
For a confirmed PEP, establish where the assets come from. Collect evidence that fits the case: payslips, tax returns, sale agreements, estate distributions or annual accounts. Test it against the customer's known income and roles.
5. Senior approval
A senior decision-maker must approve entering into the relationship. Record who decided, when and on what evidence.
6. Monitor on an ongoing basis
Screening does not end at onboarding. Re-screen your customer base regularly and when something changes, such as new beneficial owners or new roles. Track when a PEP leaves office, so you know when the 18-month period starts.
How does PEP status affect the risk assessment?
PEP status is one risk factor among several. The Section 19 measures always apply, but the overall risk level decides how far you go otherwise. A local politician with a salary account is a different risk from a foreign minister with a complex corporate structure. Read more in customer risk assessment.
What should you document?
- that screening was done, when and against which sources
- the result for the customer and each beneficial owner
- how each hit was resolved and why it was confirmed or discarded
- evidence on the source of assets and your assessment of it
- the senior decision-maker's approval
- the date a PEP left office, and your decision once 18 months have passed
Keep records for five years from the end of the business relationship (Chapter 5, Section 3 of the Swedish AML Act). PEP screening is part of your overall CDD, described in the KYC guide. Banks and payment firms can see how this fits their set-up under banks and payments.
Screening in the customer file
AKT runs the KYC process and brings documents, screening, risk assessment and the decision together in one customer file with a full audit trail. Onboarding, periodic and event-driven review happen in the same file, and a person makes the decision. See the platform.