Saudi Arabia has strengthened its anti-money laundering and counter-terrorist financing expectations, placing greater scrutiny on how regulated organizations identify and manage Politically Exposed Persons, commonly known as PEPs.
Financial institutions, fintech companies, designated non-financial businesses and professions, and other regulated entities operating in the Kingdom are expected to demonstrate a mature, risk-based approach when onboarding and monitoring customers connected to prominent public functions.
Understanding PEP obligations is no longer optional for organizations developing or strengthening their compliance programs.
Saudi regulators expect firms to align customer due diligence practices with international standards while meeting local requirements under the Saudi Central Bank and the Kingdom’s broader AML framework.
Organizations that fail to identify or properly manage PEP relationships may face:
-
Regulatory findings
-
Financial penalties
-
Remediation requirements
-
Reputational damage
-
Increased supervisory scrutiny
-
Exposure to corruption and financial crime risks
PEP compliance also connects directly to the broader customer identification, beneficial ownership, onboarding, and monitoring obligations covered in the Comprehensive Guide to KYC Compliance in Saudi Arabia.
This complete guide to KYC compliance requirements in Saudi Arabia provides the wider framework within which PEP screening and enhanced due diligence operate.
For official regulatory context, institutions should review the Saudi Central Bank’s guidance on Politically Exposed Persons.
What Is a Politically Exposed Person?
A Politically Exposed Person is an individual who is, or has been, entrusted with a prominent public function.
Because such individuals may exercise political influence, control public resources, or maintain access to sensitive government networks, they can present elevated exposure to:
-
Bribery
-
Corruption
-
Abuse of authority
-
Illicit enrichment
-
Misappropriation of public assets
-
Concealment of criminal proceeds
This increased exposure is why PEP relationships may require stronger customer due diligence and ongoing monitoring.

The classification can also extend to relevant family members and close associates because funds or assets may be held, transferred, or controlled indirectly through connected persons.
Being identified as a PEP does not mean the individual has engaged in criminal activity.
The designation indicates an elevated risk profile that requires the organization to understand the relationship, apply proportionate controls, and monitor the customer appropriately.
Why PEP Screening Matters in Saudi Arabia
Saudi Arabia’s financial system is closely connected to international banking, energy markets, foreign investment, public-sector projects, and cross-border commercial activity.
This creates significant economic opportunities, but it also increases the importance of identifying:
-
Corruption exposure
-
Hidden beneficial ownership
-
Unexplained wealth
-
Sanctions risks
-
Misuse of public funds
-
Suspicious cross-border payments
-
Undisclosed political connections
International standards established by the Financial Action Task Force require additional AML/CFT measures for business relationships involving PEPs.
The FATF’s guidance on Politically Exposed Persons explains why prominent public functions can create increased corruption and money-laundering risks.
In Saudi Arabia, regulated institutions are expected to maintain controls capable of:

Organisational-regulated institutions are expected to maintain controls capable of. Webpons relying on outdated databases, incomplete customer information, or one-time screening may struggle to identify political exposure when ownership structures or personal relationships are complex.
Domestic, Foreign, and International-Organization PEPs
PEP exposure can arise from several types of prominent public functions.
Foreign PEPs
Foreign PEPs are individuals entrusted with prominent public functions in another country.
Examples can include:
-
Foreign heads of state or government
-
Ministers and senior politicians
-
Ambassadors
-
Senior judicial or military officials
-
Senior executives of foreign state-owned companies
-
Important officials of political parties
Foreign PEP relationships may create additional challenges because the institution may have limited visibility into overseas government structures, public records, business interests, and political relationships.
Relevant risk factors include:
-
Corruption exposure in the customer’s jurisdiction
-
Access to public funds
-
Cross-border payment behaviour
-
Use of offshore companies
-
Sanctions exposure
-
Difficulty verifying declared wealth
Domestic PEPs
Domestic PEPs are individuals entrusted with prominent public functions within Saudi Arabia.
A domestic PEP should not be treated as suspicious merely because of their position. However, institutions must assess the relationship using a documented risk-based approach.
Relevant considerations may include:
-
Nature and seniority of the public function
-
Access to government funds or procurement decisions
-
Authority over licences or public assets
-
Business and ownership interests
-
Transaction patterns
-
Geographic exposure
-
Adverse media information
-
Use of related companies or intermediaries
Where the relationship presents higher risk, enhanced due diligence should be applied.
International-Organization PEPs
Individuals holding senior management or equivalent positions in international organizations may also qualify as PEPs.
These can include directors, deputy directors, board members, or individuals performing comparable senior functions within intergovernmental or international public bodies.
Institutions should understand the person’s role, influence, access to organizational funds, and associated financial relationships.
Family Members and Close Associates

One of the most important areas of PEP compliance involves individuals connected to a PEP rather than the PEP directly.
The obligations under Saudi AML rules extend to relevant family members and close associates because financial activity may be conducted indirectly through connected persons or entities.
These relationships may include:
-
Spouses or equivalent partners
-
Children
-
Parents
-
Business partners
-
Known close associates
-
Beneficial co-owners
-
Persons controlling companies with a PEP
-
Individuals known to maintain close financial relationships with a PEP
For example, a company formally owned by a relative or business associate may still present elevated risk when a PEP exercises indirect control or receives financial benefits from it.
Organizations therefore need beneficial ownership controls capable of identifying:
-
Shared ownership
-
Common directors
-
Family-controlled entities
-
Nominee arrangements
-
Joint investments
-
Indirect control
-
Connected counterparties
Screening only the customer’s name is not enough.
The institution must understand the wider ownership and relationship network.
Saudi Regulatory Expectations for PEP Compliance
Saudi regulators expect organizations to move beyond basic name screening.
PEP compliance should be integrated into the wider customer due diligence, enhanced due diligence, transaction monitoring, and governance framework.
The Saudi Central Bank’s due diligence measures require financial institutions to verify whether a customer is a PEP and apply more frequent reviews to higher-risk customers.
Key expectations include the following.
1. Risk-Based Customer Due Diligence
Every regulated institution should maintain documented procedures explaining how PEPs are:
-
Identified
-
Verified
-
Categorized
-
Risk-rated
-
Approved
-
Monitored
-
Reviewed
-
Escalated
The assessment should consider more than the customer’s job title.
Relevant information may include:
-
Identity and nationality
-
Current and previous public functions
-
Family and close-associate relationships
-
Business interests
-
Beneficial ownership
-
Source of funds
-
Source of wealth
-
Geographic exposure
-
Expected transaction activity
-
Sanctions exposure
-
Adverse media findings
The organization should document why the customer was classified as a PEP and how the resulting risk level was determined.
2. Enhanced Due Diligence
When a PEP relationship presents higher AML or terrorist-financing risk, the institution should apply enhanced due diligence.
The Saudi Central Bank’s enhanced due diligence requirements require stronger measures for high-risk customers, complex ownership structures, and relationships connected to higher-risk jurisdictions.
Enhanced measures may include:
-
Obtaining senior management approval
-
Collecting additional identity information
-
Establishing source of funds
-
Establishing source of wealth
-
Investigating business and ownership interests
-
Reviewing adverse media
-
Increasing monitoring frequency
-
Applying tighter transaction thresholds
-
Conducting more frequent KYC reviews
-
Documenting the rationale for continuing the relationship
EDD procedures should reflect the actual level of risk rather than being applied mechanically.
A senior public official with transparent finances and predictable account activity may present a different risk from a customer using unexplained offshore entities and making complex cross-border transfers.
3. Source-of-Funds Verification
Source of funds explains where the money used in a specific transaction, investment, deposit, or account relationship originated.
Examples may include:
-
Salary income
-
Business revenue
-
Dividends
-
Property-sale proceeds
-
Investment returns
-
Loan proceeds
-
Capital contributions
Supporting records can include:
-
Bank statements
-
Employment documents
-
Contracts
-
Invoices
-
Sale agreements
-
Tax records
-
Financial statements
The institution should evaluate whether the declared source is consistent with the customer’s profile, occupation, public role, and expected activity.
4. Source-of-Wealth Assessment
Source of wealth explains how the customer accumulated their overall financial position over time.
This may arise from:
-
Long-term business ownership
-
Inheritance
-
Investments
-
Executive compensation
-
Property ownership
-
Family wealth
-
Sale of assets
Institutions should avoid accepting vague statements without evidence.
For example, stating that wealth came from “business activities” may not be sufficient when the customer holds substantial assets, maintains complex companies, or conducts unusually large transactions.
A reliable source-of-wealth assessment may involve:
-
Corporate ownership records
-
Audited financial statements
-
Tax documentation
-
Investment portfolios
-
Inheritance documents
-
Property records
-
Independent public information
The explanation should be reasonable and proportionate to the customer’s known background.
5. Senior Management Approval
Higher-risk PEP relationships may require approval from senior management before the relationship begins or continues.
The approval process should provide decision-makers with sufficient information about:
-
The customer’s public function
-
Identified risk factors
-
Source of funds and wealth
-
Ownership structure
-
Adverse media findings
-
Expected transactions
-
Proposed mitigation measures
-
Remaining concerns
Management approval should not be treated as a routine signature.
The institution should retain a clear record explaining why the relationship was accepted and how identified risks will be controlled.
6. Continuous Monitoring
PEP status and risk can change over time.
A customer who was not politically exposed during onboarding may later assume a prominent public function. A current PEP may leave office but continue to exercise influence through government, business, family, or political networks.
Effective monitoring can include:
-
Automated PEP rescreening
-
Sanctions screening
-
Adverse media monitoring
-
Transaction anomaly detection
-
Periodic KYC refreshes
-
Trigger-based customer reviews
-
Beneficial ownership updates
-
Changes in employment or public function
-
Reviews of related parties
The Saudi Central Bank’s transaction-monitoring requirements emphasize monitoring unusual and suspicious transactions as a central part of the risk-based approach.
When Does Someone Stop Being a PEP?
Determining when a former official should no longer be treated as politically exposed is a common compliance challenge.
Leaving public office does not automatically remove every related risk.
A former PEP may continue to possess:
-
Political influence
-
Government relationships
-
Access to decision-makers
-
Business links to state entities
-
Control over related companies
-
Influence through family members or associates
Institutions should therefore apply a risk-based assessment instead of relying only on a fixed expiration period.
Relevant factors include:
-
Time elapsed since leaving office
-
Seniority of the former position
-
Remaining political influence
-
Continuing public-sector relationships
-
Current business activities
-
Access to public funds or contracts
-
Transaction behaviour
-
Adverse media exposure
The institution should document why enhanced measures were continued, reduced, or discontinued.
Red Flags Associated With PEP Customers
Not every PEP relationship presents the same risk.
However, certain indicators should trigger closer review.
Common PEP red flags include:
-
Unexplained accumulation of wealth
-
Large cross-border transfers
-
Use of multiple offshore entities
-
Complex ownership without a clear business purpose
-
Sudden increases in transaction volume
-
Inconsistent source-of-funds explanations
-
High levels of cash activity
-
Use of nominees or intermediaries
-
Payments from government contractors
-
Transactions involving unrelated third parties
-
Real estate purchases without clear economic rationale
-
Transfers involving high-risk jurisdictions
-
Frequent movement of funds between connected companies
-
Refusal to provide beneficial ownership information
Compliance teams should evaluate these indicators together rather than relying on one isolated alert.
A single unusual payment may have a legitimate explanation.
However, repeated unusual activity combined with political exposure, hidden ownership, or unexplained wealth can significantly increase financial crime risk.
Common PEP Compliance Challenges

Even organizations with formal AML policies may struggle with implementation.
False Positives
PEP databases frequently generate possible matches involving customers with similar or common names.
This issue can be especially challenging where:
-
Arabic names have multiple spellings
-
Transliteration varies
-
Dates of birth are unavailable
-
Nationalities are shared by several potential matches
-
Public records are incomplete
Excessive false positives may:
-
Delay onboarding
-
Increase compliance costs
-
Frustrate legitimate customers
-
Overload investigators
-
Reduce attention on higher-risk alerts
Organizations should use additional identifiers and documented match-resolution procedures.
Incomplete Customer Information
Screening effectiveness is weakened when institutions fail to collect sufficient information.
Common gaps include:
-
Missing nationality
-
Incomplete employment history
-
Vague job descriptions
-
Missing date of birth
-
Incomplete beneficial ownership information
-
Undisclosed related parties
-
Outdated contact information
Strong screening depends on accurate customer data.
Fragmented Compliance Systems
Organizations using disconnected onboarding, screening, transaction-monitoring, and case-management systems may struggle to maintain a complete customer risk profile.
This can create gaps between:
-
Initial KYC screening
-
Ownership records
-
Transaction activity
-
Sanctions alerts
-
Adverse media findings
-
Ongoing customer reviews
Compliance teams need a consolidated view of relevant risk information.
Cross-Border Ownership Structures
Multinational companies may use several holding entities, trusts, partnerships, or nominee arrangements.
Without strong beneficial ownership analysis, an institution may fail to identify a politically connected individual exercising indirect control.
Outdated Screening Information
PEP status can change quickly.
Institutions relying only on information collected during onboarding may fail to identify customers who later obtain public roles or become connected to politically exposed individuals.
Industries Most Affected by PEP Compliance
Banks generally face significant scrutiny, but PEP obligations extend beyond traditional financial institutions.
Relevant sectors can include:
-
Banks and finance companies
-
Fintech platforms
-
Insurance providers
-
Investment firms
-
Money exchange businesses
-
Real estate companies
-
Precious metals and jewellery dealers
-
Accounting firms
-
Legal firms
-
Corporate service providers
-
Other regulated or reporting entities
The precise obligations depend on the laws, regulatory authority, business model, and risk exposure applicable to each organization.
As Saudi Arabia expands its digital economy and international investment landscape, more businesses may encounter politically connected customers, investors, beneficial owners, or counterparties.
The Role of Technology in PEP Screening
Many organizations are replacing purely manual reviews with automated compliance technologies.
Modern screening platforms may compare customer data against:
-
Global PEP databases
-
Sanctions lists
-
Adverse media sources
-
Regulatory enforcement records
-
Corporate ownership databases
-
Internal watchlists
Technology can help organizations:
-
Detect political exposure
-
Identify related persons
-
Improve screening consistency
-
Reduce onboarding delays
-
Maintain audit trails
-
Support ongoing monitoring
-
Prioritize higher-risk matches
However, technology alone is not enough.
Saudi regulators expect institutions to understand:
-
What data sources are used
-
How matching logic operates
-
How false positives are resolved
-
How screening thresholds are configured
-
Who approves high-risk relationships
-
How model changes are controlled
-
How results affect customer risk ratings
Overreliance on automated tools without appropriate human oversight can create serious compliance weaknesses.
Technology should support professional judgment, not replace it.
Regulatory Consequences of Weak PEP Controls
Weak PEP controls may indicate wider deficiencies in:
-
Customer due diligence
-
Beneficial ownership verification
-
Governance
-
Source-of-wealth assessment
-
Transaction monitoring
-
Compliance training
-
Internal escalation
-
Recordkeeping
Potential consequences can include:
-
Financial penalties
-
Regulatory enforcement
-
Mandatory remediation
-
Increased supervisory reviews
-
Restrictions on business activities
-
Reputational damage
-
Weakened correspondent banking relationships
-
Cross-border regulatory exposure
Regulators commonly assess whether the institution maintained adequate controls before and during the relationship, not only whether confirmed criminal activity occurred.
A weakly documented PEP decision can therefore create regulatory risk even when no laundering offence is ultimately established.
Best Practices for Managing PEP Risk in Saudi Arabia

Build a Risk-Based Framework
Not all PEPs present the same level of risk.
Institutions should assess factors such as:
-
Type and seniority of public function
-
Domestic or foreign exposure
-
Access to public assets
-
Geographic risk
-
Business interests
-
Ownership complexity
-
Transaction behaviour
-
Adverse media
-
Sanctions exposure
Strengthen Beneficial Ownership Reviews
Organizations should identify the natural persons who ultimately own or control customer entities.
Reviews should examine:
-
Direct ownership
-
Indirect ownership
-
Voting rights
-
Control through agreements
-
Nominee arrangements
-
Shared directors
-
Family-controlled companies
-
Related-party transactions
Maintain Role-Based Training
Frontline employees, relationship managers, compliance analysts, investigators, and senior management need training appropriate to their responsibilities.
Training should cover:
-
PEP definitions
-
Family members and close associates
-
Risk-rating methods
-
Enhanced due diligence
-
Source-of-funds checks
-
Source-of-wealth analysis
-
Red flags
-
Escalation procedures
-
Reporting obligations
Document Every Decision
Institutions should maintain records showing:
-
Why the customer was classified as a PEP
-
How the risk rating was determined
-
What evidence was collected
-
What screening was completed
-
Who approved the relationship
-
What monitoring controls were applied
-
Why the customer was accepted, rejected, or exited
The Saudi Central Bank’s recordkeeping requirements support the need to preserve records that allow financial activity and compliance decisions to be reconstructed.
Conduct Independent Testing
Internal audit or independent compliance reviews should test whether PEP controls operate effectively.
Testing may examine:
-
Screening accuracy
-
Match-resolution quality
-
Customer risk ratings
-
Management approvals
-
Source-of-wealth evidence
-
Monitoring scenarios
-
Periodic reviews
-
Escalation decisions
-
Staff understanding
Why Many Compliance Teams Still Fail PEP Reviews
Some organizations continue treating PEP screening as a checkbox exercise instead of a genuine risk-management function.
Common failures include:
-
Screening only during onboarding
-
Using outdated databases
-
Ignoring family members and close associates
-
Failing to identify beneficial owners
-
Accepting vague source-of-wealth explanations
-
Ignoring adverse media alerts
-
Applying inconsistent escalation standards
-
Failing to document management approval
-
Closing alerts without sufficient investigation
The problem is often not the absence of policies.
It is weak execution.
That is why advanced training is increasingly valuable for professionals working in regulated sectors.
The AML/CTF Specialist Course is designed for professionals seeking deeper knowledge of customer due diligence, enhanced due diligence, PEP screening, beneficial ownership, sanctions controls, transaction monitoring, suspicious activity investigations, and modern AML risk management.
Employers increasingly need professionals who can evaluate complex high-risk relationships rather than simply process onboarding documents.
Suspicious Transaction Reporting and PEP Relationships
A customer’s PEP status does not automatically make their transactions suspicious.
However, the combination of political exposure and unexplained or inconsistent activity may create grounds for further investigation.
Potential indicators include:
-
Unexplained deposits
-
Hidden ownership interests
-
Transactions inconsistent with known income
-
Rapid movement of funds
-
Payments involving government contractors
-
Use of intermediaries without a clear purpose
-
Transfers to high-risk jurisdictions
-
Serious adverse media findings
-
Unexplained real estate purchases
-
Refusal to provide supporting documents
When concerns arise, the institution should follow its internal investigation and escalation procedures.
Where reasonable grounds for suspicion exist, the institution should comply with the applicable reporting requirements.
Employees must also avoid informing customers that a suspicious transaction report or related investigation may have been initiated.
The Future of PEP Compliance in Saudi Arabia

Saudi Arabia’s PEP compliance environment will continue evolving as financial services become more digital and regulators gain access to more data.
Important trends include:
Greater Use of Artificial Intelligence
AI-supported screening, transaction monitoring, and behavioural analytics can help identify unusual relationships and activity more quickly.
Increased Regulatory Cooperation
Cross-border information sharing can improve visibility into international political exposure, corruption risks, ownership structures, and financial networks.
Stronger Real-Time Monitoring
Periodic reviews alone may not be sufficient for higher-risk relationships.
Organizations are increasingly adopting:
-
Continuous PEP rescreening
-
Dynamic risk scoring
-
Real-time sanctions screening
-
Automated adverse media alerts
-
Trigger-based KYC reviews
Greater Beneficial Ownership Transparency
Improved corporate ownership records and data-sharing arrangements may help institutions identify indirect political connections more effectively.
Greater Accountability for Decisions
Institutions will increasingly need to demonstrate not only that screening occurred, but how alerts were investigated, why decisions were made, and whether controls were effective.
Conclusion
PEP compliance in Saudi Arabia is no longer limited to basic name screening or manual onboarding checks.
Regulated organizations are expected to implement mature, risk-based AML frameworks capable of identifying, assessing, approving, monitoring, and managing politically connected customers throughout the relationship.
Effective PEP compliance requires:
-
Reliable customer identification
-
Enhanced due diligence
-
Beneficial ownership transparency
-
Source-of-funds verification
-
Source-of-wealth assessment
-
Continuous monitoring
-
Employee training
-
Management accountability
-
Documented decision-making
Technology can strengthen these controls, but it cannot replace informed human judgment and clear governance.
As Saudi Arabia continues developing its AML ecosystem, organizations that fail to modernize their PEP controls may face increasing regulatory, operational, financial, and reputational exposure.
Organizations that invest early in effective screening, trained employees, strong ownership verification, and ongoing monitoring will be better prepared to manage politically exposed relationships responsibly.
For a full explanation of customer due diligence, onboarding, beneficial ownership, risk classification, and ongoing monitoring obligations, explore the Comprehensive Guide to KYC Compliance in Saudi Arabia.
Featured Course
Anti-Money Laundering & Counter-Terrorism Financing (AML/CTF)
Anti-Money Laundering in Saudi Arabia: Master Financial Crime Compliance with Confidence and Authority.


