Politically Exposed Persons (PEPs): KSA Compliance Obligations Explained

Saudi Arabia has strengthened its anti-money laundering and counter-terrorist financing expectations, placing greater scrutiny on how regulated organizations identify and manage Politically Exposed Persons, commonly known as PEPs. Financial institutions, fintech companies, designated non-financial businesses and professions, and other regulated...

  • September 08, 2026
  • 17Mins
التزامات الامتثال للأشخاص المعرضين سياسياً في السعودية مع الفحص والعناية الواجبة ومراقبة العلاقات

Saudi Arabia has strengthened its anti-money laundering and counter-terrorist financing expectations, placing greater scrutiny on how regulated organizations identify and manage Politically Exposed Persons, commonly known as PEPs.

Financial institutions, fintech companies, designated non-financial businesses and professions, and other regulated entities operating in the Kingdom are expected to demonstrate a mature, risk-based approach when onboarding and monitoring customers connected to prominent public functions.

Understanding PEP obligations is no longer optional for organizations developing or strengthening their compliance programs.

Saudi regulators expect firms to align customer due diligence practices with international standards while meeting local requirements under the Saudi Central Bank and the Kingdom’s broader AML framework.

Organizations that fail to identify or properly manage PEP relationships may face:

  • Regulatory findings

  • Financial penalties

  • Remediation requirements

  • Reputational damage

  • Increased supervisory scrutiny

  • Exposure to corruption and financial crime risks

PEP compliance also connects directly to the broader customer identification, beneficial ownership, onboarding, and monitoring obligations covered in the Comprehensive Guide to KYC Compliance in Saudi Arabia.

This complete guide to KYC compliance requirements in Saudi Arabia provides the wider framework within which PEP screening and enhanced due diligence operate.

For official regulatory context, institutions should review the Saudi Central Bank’s guidance on Politically Exposed Persons.

What Is a Politically Exposed Person?

A Politically Exposed Person is an individual who is, or has been, entrusted with a prominent public function.

Because such individuals may exercise political influence, control public resources, or maintain access to sensitive government networks, they can present elevated exposure to:

  • Bribery

  • Corruption

  • Abuse of authority

  • Illicit enrichment

  • Misappropriation of public assets

  • Concealment of criminal proceeds

This increased exposure is why PEP relationships may require stronger customer due diligence and ongoing monitoring.

Categories of politically exposed persons including senior government, judicial and military officials

The classification can also extend to relevant family members and close associates because funds or assets may be held, transferred, or controlled indirectly through connected persons.

Being identified as a PEP does not mean the individual has engaged in criminal activity.

The designation indicates an elevated risk profile that requires the organization to understand the relationship, apply proportionate controls, and monitor the customer appropriately.

Why PEP Screening Matters in Saudi Arabia

Saudi Arabia’s financial system is closely connected to international banking, energy markets, foreign investment, public-sector projects, and cross-border commercial activity.

This creates significant economic opportunities, but it also increases the importance of identifying:

  • Corruption exposure

  • Hidden beneficial ownership

  • Unexplained wealth

  • Sanctions risks

  • Misuse of public funds

  • Suspicious cross-border payments

  • Undisclosed political connections

International standards established by the Financial Action Task Force require additional AML/CFT measures for business relationships involving PEPs.

The FATF’s guidance on Politically Exposed Persons explains why prominent public functions can create increased corruption and money-laundering risks.

In Saudi Arabia, regulated institutions are expected to maintain controls capable of:

Nine key controls for managing PEPs and high-risk customers in regulated Saudi institutions

Organisational-regulated institutions are expected to maintain controls capable of. Webpons relying on outdated databases, incomplete customer information, or one-time screening may struggle to identify political exposure when ownership structures or personal relationships are complex.

Domestic, Foreign, and International-Organization PEPs

PEP exposure can arise from several types of prominent public functions.

Foreign PEPs

Foreign PEPs are individuals entrusted with prominent public functions in another country.

Examples can include:

  • Foreign heads of state or government

  • Ministers and senior politicians

  • Ambassadors

  • Senior judicial or military officials

  • Senior executives of foreign state-owned companies

  • Important officials of political parties

Foreign PEP relationships may create additional challenges because the institution may have limited visibility into overseas government structures, public records, business interests, and political relationships.

Relevant risk factors include:

  • Corruption exposure in the customer’s jurisdiction

  • Access to public funds

  • Cross-border payment behaviour

  • Use of offshore companies

  • Sanctions exposure

  • Difficulty verifying declared wealth

Domestic PEPs

Domestic PEPs are individuals entrusted with prominent public functions within Saudi Arabia.

A domestic PEP should not be treated as suspicious merely because of their position. However, institutions must assess the relationship using a documented risk-based approach.

Relevant considerations may include:

  • Nature and seniority of the public function

  • Access to government funds or procurement decisions

  • Authority over licences or public assets

  • Business and ownership interests

  • Transaction patterns

  • Geographic exposure

  • Adverse media information

  • Use of related companies or intermediaries

Where the relationship presents higher risk, enhanced due diligence should be applied.

International-Organization PEPs

Individuals holding senior management or equivalent positions in international organizations may also qualify as PEPs.

These can include directors, deputy directors, board members, or individuals performing comparable senior functions within intergovernmental or international public bodies.

Institutions should understand the person’s role, influence, access to organizational funds, and associated financial relationships.

Family Members and Close Associates

PEP family members and close associates screening through relationship mapping in Saudi Arabia

One of the most important areas of PEP compliance involves individuals connected to a PEP rather than the PEP directly.

The obligations under Saudi AML rules extend to relevant family members and close associates because financial activity may be conducted indirectly through connected persons or entities.

These relationships may include:

  • Spouses or equivalent partners

  • Children

  • Parents

  • Business partners

  • Known close associates

  • Beneficial co-owners

  • Persons controlling companies with a PEP

  • Individuals known to maintain close financial relationships with a PEP

For example, a company formally owned by a relative or business associate may still present elevated risk when a PEP exercises indirect control or receives financial benefits from it.

Organizations therefore need beneficial ownership controls capable of identifying:

  • Shared ownership

  • Common directors

  • Family-controlled entities

  • Nominee arrangements

  • Joint investments

  • Indirect control

  • Connected counterparties

Screening only the customer’s name is not enough.

The institution must understand the wider ownership and relationship network.

Saudi Regulatory Expectations for PEP Compliance

Saudi regulators expect organizations to move beyond basic name screening.

PEP compliance should be integrated into the wider customer due diligence, enhanced due diligence, transaction monitoring, and governance framework.

The Saudi Central Bank’s due diligence measures require financial institutions to verify whether a customer is a PEP and apply more frequent reviews to higher-risk customers.

Key expectations include the following.

1. Risk-Based Customer Due Diligence

Every regulated institution should maintain documented procedures explaining how PEPs are:

  • Identified

  • Verified

  • Categorized

  • Risk-rated

  • Approved

  • Monitored

  • Reviewed

  • Escalated

The assessment should consider more than the customer’s job title.

Relevant information may include:

  • Identity and nationality

  • Current and previous public functions

  • Family and close-associate relationships

  • Business interests

  • Beneficial ownership

  • Source of funds

  • Source of wealth

  • Geographic exposure

  • Expected transaction activity

  • Sanctions exposure

  • Adverse media findings

The organization should document why the customer was classified as a PEP and how the resulting risk level was determined.

2. Enhanced Due Diligence

When a PEP relationship presents higher AML or terrorist-financing risk, the institution should apply enhanced due diligence.

The Saudi Central Bank’s enhanced due diligence requirements require stronger measures for high-risk customers, complex ownership structures, and relationships connected to higher-risk jurisdictions.

Enhanced measures may include:

  • Obtaining senior management approval

  • Collecting additional identity information

  • Establishing source of funds

  • Establishing source of wealth

  • Investigating business and ownership interests

  • Reviewing adverse media

  • Increasing monitoring frequency

  • Applying tighter transaction thresholds

  • Conducting more frequent KYC reviews

  • Documenting the rationale for continuing the relationship

EDD procedures should reflect the actual level of risk rather than being applied mechanically.

A senior public official with transparent finances and predictable account activity may present a different risk from a customer using unexplained offshore entities and making complex cross-border transfers.

3. Source-of-Funds Verification

Source of funds explains where the money used in a specific transaction, investment, deposit, or account relationship originated.

Examples may include:

  • Salary income

  • Business revenue

  • Dividends

  • Property-sale proceeds

  • Investment returns

  • Loan proceeds

  • Capital contributions

Supporting records can include:

  • Bank statements

  • Employment documents

  • Contracts

  • Invoices

  • Sale agreements

  • Tax records

  • Financial statements

The institution should evaluate whether the declared source is consistent with the customer’s profile, occupation, public role, and expected activity.

4. Source-of-Wealth Assessment

Source of wealth explains how the customer accumulated their overall financial position over time.

This may arise from:

  • Long-term business ownership

  • Inheritance

  • Investments

  • Executive compensation

  • Property ownership

  • Family wealth

  • Sale of assets

Institutions should avoid accepting vague statements without evidence.

For example, stating that wealth came from “business activities” may not be sufficient when the customer holds substantial assets, maintains complex companies, or conducts unusually large transactions.

A reliable source-of-wealth assessment may involve:

  • Corporate ownership records

  • Audited financial statements

  • Tax documentation

  • Investment portfolios

  • Inheritance documents

  • Property records

  • Independent public information

The explanation should be reasonable and proportionate to the customer’s known background.

5. Senior Management Approval

Higher-risk PEP relationships may require approval from senior management before the relationship begins or continues.

The approval process should provide decision-makers with sufficient information about:

  • The customer’s public function

  • Identified risk factors

  • Source of funds and wealth

  • Ownership structure

  • Adverse media findings

  • Expected transactions

  • Proposed mitigation measures

  • Remaining concerns

Management approval should not be treated as a routine signature.

The institution should retain a clear record explaining why the relationship was accepted and how identified risks will be controlled.

6. Continuous Monitoring

PEP status and risk can change over time.

A customer who was not politically exposed during onboarding may later assume a prominent public function. A current PEP may leave office but continue to exercise influence through government, business, family, or political networks.

Effective monitoring can include:

  • Automated PEP rescreening

  • Sanctions screening

  • Adverse media monitoring

  • Transaction anomaly detection

  • Periodic KYC refreshes

  • Trigger-based customer reviews

  • Beneficial ownership updates

  • Changes in employment or public function

  • Reviews of related parties

The Saudi Central Bank’s transaction-monitoring requirements emphasize monitoring unusual and suspicious transactions as a central part of the risk-based approach.

When Does Someone Stop Being a PEP?

Determining when a former official should no longer be treated as politically exposed is a common compliance challenge.

Leaving public office does not automatically remove every related risk.

A former PEP may continue to possess:

  • Political influence

  • Government relationships

  • Access to decision-makers

  • Business links to state entities

  • Control over related companies

  • Influence through family members or associates

Institutions should therefore apply a risk-based assessment instead of relying only on a fixed expiration period.

Relevant factors include:

  • Time elapsed since leaving office

  • Seniority of the former position

  • Remaining political influence

  • Continuing public-sector relationships

  • Current business activities

  • Access to public funds or contracts

  • Transaction behaviour

  • Adverse media exposure

The institution should document why enhanced measures were continued, reduced, or discontinued.

Red Flags Associated With PEP Customers

Not every PEP relationship presents the same risk.

However, certain indicators should trigger closer review.

Common PEP red flags include:

  • Unexplained accumulation of wealth

  • Large cross-border transfers

  • Use of multiple offshore entities

  • Complex ownership without a clear business purpose

  • Sudden increases in transaction volume

  • Inconsistent source-of-funds explanations

  • High levels of cash activity

  • Use of nominees or intermediaries

  • Payments from government contractors

  • Transactions involving unrelated third parties

  • Real estate purchases without clear economic rationale

  • Transfers involving high-risk jurisdictions

  • Frequent movement of funds between connected companies

  • Refusal to provide beneficial ownership information

Compliance teams should evaluate these indicators together rather than relying on one isolated alert.

A single unusual payment may have a legitimate explanation.

However, repeated unusual activity combined with political exposure, hidden ownership, or unexplained wealth can significantly increase financial crime risk.

Common PEP Compliance Challenges

Saudi compliance professionals reviewing common PEP screening challenges, risk alerts and global connections

Even organizations with formal AML policies may struggle with implementation.

False Positives

PEP databases frequently generate possible matches involving customers with similar or common names.

This issue can be especially challenging where:

  • Arabic names have multiple spellings

  • Transliteration varies

  • Dates of birth are unavailable

  • Nationalities are shared by several potential matches

  • Public records are incomplete

Excessive false positives may:

  • Delay onboarding

  • Increase compliance costs

  • Frustrate legitimate customers

  • Overload investigators

  • Reduce attention on higher-risk alerts

Organizations should use additional identifiers and documented match-resolution procedures.

Incomplete Customer Information

Screening effectiveness is weakened when institutions fail to collect sufficient information.

Common gaps include:

  • Missing nationality

  • Incomplete employment history

  • Vague job descriptions

  • Missing date of birth

  • Incomplete beneficial ownership information

  • Undisclosed related parties

  • Outdated contact information

Strong screening depends on accurate customer data.

Fragmented Compliance Systems

Organizations using disconnected onboarding, screening, transaction-monitoring, and case-management systems may struggle to maintain a complete customer risk profile.

This can create gaps between:

  • Initial KYC screening

  • Ownership records

  • Transaction activity

  • Sanctions alerts

  • Adverse media findings

  • Ongoing customer reviews

Compliance teams need a consolidated view of relevant risk information.

Cross-Border Ownership Structures

Multinational companies may use several holding entities, trusts, partnerships, or nominee arrangements.

Without strong beneficial ownership analysis, an institution may fail to identify a politically connected individual exercising indirect control.

Outdated Screening Information

PEP status can change quickly.

Institutions relying only on information collected during onboarding may fail to identify customers who later obtain public roles or become connected to politically exposed individuals.

Industries Most Affected by PEP Compliance

Banks generally face significant scrutiny, but PEP obligations extend beyond traditional financial institutions.

Relevant sectors can include:

  • Banks and finance companies

  • Fintech platforms

  • Insurance providers

  • Investment firms

  • Money exchange businesses

  • Real estate companies

  • Precious metals and jewellery dealers

  • Accounting firms

  • Legal firms

  • Corporate service providers

  • Other regulated or reporting entities

The precise obligations depend on the laws, regulatory authority, business model, and risk exposure applicable to each organization.

As Saudi Arabia expands its digital economy and international investment landscape, more businesses may encounter politically connected customers, investors, beneficial owners, or counterparties.

The Role of Technology in PEP Screening

Many organizations are replacing purely manual reviews with automated compliance technologies.

Modern screening platforms may compare customer data against:

  • Global PEP databases

  • Sanctions lists

  • Adverse media sources

  • Regulatory enforcement records

  • Corporate ownership databases

  • Internal watchlists

Technology can help organizations:

  • Detect political exposure

  • Identify related persons

  • Improve screening consistency

  • Reduce onboarding delays

  • Maintain audit trails

  • Support ongoing monitoring

  • Prioritize higher-risk matches

However, technology alone is not enough.

Saudi regulators expect institutions to understand:

  • What data sources are used

  • How matching logic operates

  • How false positives are resolved

  • How screening thresholds are configured

  • Who approves high-risk relationships

  • How model changes are controlled

  • How results affect customer risk ratings

Overreliance on automated tools without appropriate human oversight can create serious compliance weaknesses.

Technology should support professional judgment, not replace it.

Regulatory Consequences of Weak PEP Controls

Weak PEP controls may indicate wider deficiencies in:

  • Customer due diligence

  • Beneficial ownership verification

  • Governance

  • Source-of-wealth assessment

  • Transaction monitoring

  • Compliance training

  • Internal escalation

  • Recordkeeping

Potential consequences can include:

  • Financial penalties

  • Regulatory enforcement

  • Mandatory remediation

  • Increased supervisory reviews

  • Restrictions on business activities

  • Reputational damage

  • Weakened correspondent banking relationships

  • Cross-border regulatory exposure

Regulators commonly assess whether the institution maintained adequate controls before and during the relationship, not only whether confirmed criminal activity occurred.

A weakly documented PEP decision can therefore create regulatory risk even when no laundering offence is ultimately established.

Best Practices for Managing PEP Risk in Saudi Arabia

Saudi compliance team reviewing PEP screening and risk management best practices in Saudi Arabia

Build a Risk-Based Framework

Not all PEPs present the same level of risk.

Institutions should assess factors such as:

  • Type and seniority of public function

  • Domestic or foreign exposure

  • Access to public assets

  • Geographic risk

  • Business interests

  • Ownership complexity

  • Transaction behaviour

  • Adverse media

  • Sanctions exposure

Strengthen Beneficial Ownership Reviews

Organizations should identify the natural persons who ultimately own or control customer entities.

Reviews should examine:

  • Direct ownership

  • Indirect ownership

  • Voting rights

  • Control through agreements

  • Nominee arrangements

  • Shared directors

  • Family-controlled companies

  • Related-party transactions

Maintain Role-Based Training

Frontline employees, relationship managers, compliance analysts, investigators, and senior management need training appropriate to their responsibilities.

Training should cover:

  • PEP definitions

  • Family members and close associates

  • Risk-rating methods

  • Enhanced due diligence

  • Source-of-funds checks

  • Source-of-wealth analysis

  • Red flags

  • Escalation procedures

  • Reporting obligations

Document Every Decision

Institutions should maintain records showing:

  • Why the customer was classified as a PEP

  • How the risk rating was determined

  • What evidence was collected

  • What screening was completed

  • Who approved the relationship

  • What monitoring controls were applied

  • Why the customer was accepted, rejected, or exited

The Saudi Central Bank’s recordkeeping requirements support the need to preserve records that allow financial activity and compliance decisions to be reconstructed.

Conduct Independent Testing

Internal audit or independent compliance reviews should test whether PEP controls operate effectively.

Testing may examine:

  • Screening accuracy

  • Match-resolution quality

  • Customer risk ratings

  • Management approvals

  • Source-of-wealth evidence

  • Monitoring scenarios

  • Periodic reviews

  • Escalation decisions

  • Staff understanding

Why Many Compliance Teams Still Fail PEP Reviews

Some organizations continue treating PEP screening as a checkbox exercise instead of a genuine risk-management function.

Common failures include:

  • Screening only during onboarding

  • Using outdated databases

  • Ignoring family members and close associates

  • Failing to identify beneficial owners

  • Accepting vague source-of-wealth explanations

  • Ignoring adverse media alerts

  • Applying inconsistent escalation standards

  • Failing to document management approval

  • Closing alerts without sufficient investigation

The problem is often not the absence of policies.

It is weak execution.

That is why advanced training is increasingly valuable for professionals working in regulated sectors.

The AML/CTF Specialist Course is designed for professionals seeking deeper knowledge of customer due diligence, enhanced due diligence, PEP screening, beneficial ownership, sanctions controls, transaction monitoring, suspicious activity investigations, and modern AML risk management.

Employers increasingly need professionals who can evaluate complex high-risk relationships rather than simply process onboarding documents.

Suspicious Transaction Reporting and PEP Relationships

A customer’s PEP status does not automatically make their transactions suspicious.

However, the combination of political exposure and unexplained or inconsistent activity may create grounds for further investigation.

Potential indicators include:

  • Unexplained deposits

  • Hidden ownership interests

  • Transactions inconsistent with known income

  • Rapid movement of funds

  • Payments involving government contractors

  • Use of intermediaries without a clear purpose

  • Transfers to high-risk jurisdictions

  • Serious adverse media findings

  • Unexplained real estate purchases

  • Refusal to provide supporting documents

When concerns arise, the institution should follow its internal investigation and escalation procedures.

Where reasonable grounds for suspicion exist, the institution should comply with the applicable reporting requirements.

Employees must also avoid informing customers that a suspicious transaction report or related investigation may have been initiated.

The Future of PEP Compliance in Saudi Arabia

Future of PEP compliance in Saudi Arabia with AI screening, real-time monitoring and risk analytics

Saudi Arabia’s PEP compliance environment will continue evolving as financial services become more digital and regulators gain access to more data.

Important trends include:

Greater Use of Artificial Intelligence

AI-supported screening, transaction monitoring, and behavioural analytics can help identify unusual relationships and activity more quickly.

Increased Regulatory Cooperation

Cross-border information sharing can improve visibility into international political exposure, corruption risks, ownership structures, and financial networks.

Stronger Real-Time Monitoring

Periodic reviews alone may not be sufficient for higher-risk relationships.

Organizations are increasingly adopting:

  • Continuous PEP rescreening

  • Dynamic risk scoring

  • Real-time sanctions screening

  • Automated adverse media alerts

  • Trigger-based KYC reviews

Greater Beneficial Ownership Transparency

Improved corporate ownership records and data-sharing arrangements may help institutions identify indirect political connections more effectively.

Greater Accountability for Decisions

Institutions will increasingly need to demonstrate not only that screening occurred, but how alerts were investigated, why decisions were made, and whether controls were effective.

Conclusion

PEP compliance in Saudi Arabia is no longer limited to basic name screening or manual onboarding checks.

Regulated organizations are expected to implement mature, risk-based AML frameworks capable of identifying, assessing, approving, monitoring, and managing politically connected customers throughout the relationship.

Effective PEP compliance requires:

  • Reliable customer identification

  • Enhanced due diligence

  • Beneficial ownership transparency

  • Source-of-funds verification

  • Source-of-wealth assessment

  • Continuous monitoring

  • Employee training

  • Management accountability

  • Documented decision-making

Technology can strengthen these controls, but it cannot replace informed human judgment and clear governance.

As Saudi Arabia continues developing its AML ecosystem, organizations that fail to modernize their PEP controls may face increasing regulatory, operational, financial, and reputational exposure.

Organizations that invest early in effective screening, trained employees, strong ownership verification, and ongoing monitoring will be better prepared to manage politically exposed relationships responsibly.

For a full explanation of customer due diligence, onboarding, beneficial ownership, risk classification, and ongoing monitoring obligations, explore the Comprehensive Guide to KYC Compliance in Saudi Arabia.

Featured Course

Anti-Money Laundering & Counter-Terrorism Financing (AML/CTF)

Anti-Money Laundering in Saudi Arabia: Master Financial Crime Compliance with Confidence and Authority.

Explore Course →

 

Frequently Asked Questions

Find quick answers to frequently asked questions. Can't find what you're looking for?

A Politically Exposed Person is an individual who is or has been entrusted with a prominent public function. The classification can also affect relevant family members and close associates because of potential indirect financial relationships.

Domestic PEPs should be assessed using a risk-based approach. Where the public function, financial behaviour, ownership structure, or other factors indicate higher risk, enhanced due diligence should be applied.

Enhanced due diligence can include additional identity checks, source-of-funds verification, source-of-wealth assessment, senior management approval, beneficial ownership analysis, more frequent reviews, and stronger transaction monitoring.

Relevant family members and close associates should be considered within PEP risk controls because funds, assets, or companies may be held or controlled indirectly through connected persons.

PEP controls are relevant to banks, fintech companies, insurers, investment businesses, money exchange companies, real estate firms, professional service providers, and other regulated or reporting entities according to their applicable legal obligations.

Yes. Former officials may continue to present elevated risk depending on their remaining influence, political connections, business interests, transaction activity, and time since leaving office.

Organizations may face regulatory findings, remediation orders, financial penalties, increased supervision, operational restrictions, and reputational damage.

PEP screening should form part of ongoing monitoring. Institutions should conduct periodic and trigger-based reviews to identify changes in political exposure, ownership, sanctions status, adverse media, and transaction behaviour.