PRACTITIONER PLAYBOOK

A PEP file is a decision record, not a screening result

A politically exposed person (PEP) screening result is only the beginning of a client-risk decision. The useful question for a partner, compliance reviewer or external monitor is not “did the system find a name?” It is whether the file can explain who the customer and beneficial owners are, what PEP exposure exists, why the relationship received its risk rating, which enhanced due-diligence steps were applied, and how the conclusion will be revisited. A name-match report with no reasoning is weak evidence. A blanket rule that treats every PEP as equally high risk is also weak control design.

The Hong Kong Monetary Authority (HKMA) issued updated risk-based PEP guidance and Version 2.0 Smart Tips on 28 August 2026 for all authorised institutions.[1] [2] The guidance applies directly to authorised institutions, not to CPA firms or TCSP licensees as a new standalone rule. However, it is a timely and authoritative Hong Kong benchmark for designing and testing PEP, beneficial-owner, family-member, close-associate and former-PEP controls. It demonstrates what a risk-based process should look like when it is capable of review rather than merely written in a manual.

For a CPA or TCSP practice, applicable Hong Kong AML/CTF duties continue to arise under its own legal and sectoral framework. This article therefore does not import HKMA banking requirements into other professions. Instead, it translates the control logic into a practical file test. A recent New Zealand accountant-sector risk assessment supplies a clearly labelled comparative perspective: company and trust structures, complex ownership, formation or restructuring and financial transactions can be misused, but they are not inherently high risk.[3] The control objective is proportionate evidence, not automatic de-risking.

The EQC PEP file test: six questions before acceptance or continuation

EQC recommends a six-question PEP file test: identity, exposure, context, escalation, monitoring and exit. The sequence helps a firm turn a generic “PEP procedure” into a record that can be sampled, challenged and improved. Each question should have a named owner, a standard evidence requirement, a decision point and an exception path.

First, identity: do we know the customer, entity, controlling persons and beneficial owners? Second, exposure: is the customer, beneficial owner, family member or close associate a PEP, former PEP or connected to an entity with PEP risk? Third, context: what does the service, ownership structure, customer activity and transaction pattern say about the actual money-laundering, terrorist-financing or proliferation-financing risk? Fourth, escalation: what enhanced due diligence, approvals and restrictions are required before accepting or continuing the relationship? Fifth, monitoring: how will changes in role, ownership, adverse information, activity or transaction behaviour be identified and reviewed? Sixth, exit: if a PEP leaves office or a relationship changes, can the firm evidence a renewed risk decision rather than simply switching off a flag?

The framework does not replace professional judgement. It makes professional judgement visible. A concise decision record should allow an independent reviewer to reconstruct the facts known at the time, the sources checked, risk factors considered, safeguards selected, person who approved the outcome, review date and events that would require reconsideration.

1. Identity: start with the people behind the legal structure

Do not begin with a database search. The HKMA Smart Tips state that customer due diligence is the primary source for PEP identification, supplemented by declarations, commercial databases, reliable public information and ongoing monitoring.[2] The practical implication is that a practice should first build a complete people-and-control map: customer, directors, trustees, settlors, protectors where relevant, shareholders, ultimate beneficial owners, authorised persons, persons exercising effective control and any linked entities. The map should identify the role each person performs and the source that supports it.

A self-declaration is useful but is not self-validating. Gather occupation and employment information, compare it with onboarding documents and the client narrative, and assess discrepancies. Commercial databases can help, but the file should show why the database and matching logic are fit for purpose, who cleared potential matches and what reliable public source was used where corroboration was needed. A practice that keeps only a “no match” certificate cannot later explain whether its search population was complete or whether an ownership change was missed.

For entity clients, ownership is not a compliance formality. The HKMA material treats PEP exposure at beneficial-owner and entity level as relevant to the risk assessment.[2] A private entity controlled by a PEP in a high-risk business may warrant a different conclusion from a PEP associated with a well-regulated listed entity. The file should record the ownership and control facts that drove the conclusion, not merely the PEP label.

2. Exposure and context: classify the risk without stigmatising the client

PEP controls are preventive. They should not be treated as an allegation that a person is involved in criminal conduct. HKMA distinguishes non-Hong Kong PEPs from Hong Kong and international-organisation PEPs. For authorised institutions, PEP-specific enhanced due diligence applies to non-Hong Kong PEPs regardless of baseline risk, while Hong Kong and international-organisation PEPs trigger that specific treatment only if the relationship is assessed as high risk.[2] A CPA or TCSP should not copy this rule mechanically; its own obligations and risk assessment determine the required action. It can, however, use the distinction to avoid unsupported assumptions that every public function creates the same risk.

The contextual analysis should explain why a relationship is low, medium or high risk. Consider the nature and seniority of the public function, jurisdictional corruption and governance risk, role in the entity, degree of control over funds or assets, business sector, service requested, expected activity, transaction size and pattern, adverse information, complexity of the structure, intermediaries and links between public role and private activity. Do not convert this into a long checklist with no conclusion. Identify the factors that mattered, those that were considered but did not apply, and the evidence supporting the final rating.

Family members and close associates require a relationship analysis, not an automatic classification. The HKMA notes that relationships can change through divorce, separation, estrangement, death or termination of a commercial relationship.[2] The file should identify how the relationship was established, why it remains relevant and the date for reassessment. A TCSP dealing with trusts, holding companies or nominee structures should also test whether a PEP’s influence may be indirect through appointment rights, voting arrangements, financing, informal control or a chain of entities.

3. Escalation: make source-of-wealth and approval decisions reviewable

Where PEP-specific enhanced due diligence is appropriate, the HKMA Smart Tips describe reasonable source-of-wealth and source-of-funds measures, senior-management approval before establishing or continuing the relationship, and enhanced ongoing monitoring including annual CDD review.[2] The strongest transferable lesson is not to collect more documents indiscriminately. It is to make the work proportionate and capable of challenge.

Separate source of wealth from source of funds. Source of wealth concerns how a person accumulated overall wealth. Source of funds concerns the origin of money or assets used in the specific relationship or transaction. A good file explains the hypothesis being tested, the information obtained, the public or independent sources used, inconsistencies identified, limitations and the reviewer’s conclusion. For example, where a client attributes wealth to remuneration, investments or property, the work should be sufficient to establish reasonableness in the context of the relationship. It should not become a request for every historic statement without a risk reason.

Senior approval should be a decision gate, not an email after the relationship starts. The approval record should state the PEP category, key risk factors, expected activity, source-of-wealth and source-of-funds conclusion, conditions or restrictions, monitoring frequency, reviewer, decision-maker and date. If an approval is conditional on a missing item, record a deadline and a consequence for non-completion. Sample testing should verify that approval predates service commencement or continuation and that any conditions were closed on time.

4. Monitoring: test for change, not only for annual completion

An annual review date is not an ongoing-monitoring system. A robust process defines the events that trigger reassessment between annual reviews. Examples include a new public appointment or resignation, an ownership or control change, new adverse information, an unexpected service request, a material transaction, change in business sector, new jurisdictional exposure, new intermediary, unexplained funding pattern or a change in a family or close-associate relationship. The trigger should create an auditable task, not remain in an employee’s memory.

The New Zealand Department of Internal Affairs’ 2026 accountant-sector assessment provides a useful comparative check. It identifies company and trust structures, complex ownership, business establishment or restructuring and financial transactions as services that can be attractive to criminal misuse. It stresses understanding who ultimately owns or controls the structure, whether activity makes sense in the relationship context, and the connection between customer due diligence, ongoing monitoring and suspicious-activity reporting.[3] This is overseas guidance, not Hong Kong law, but it reinforces an important operating point: onboarding information must be tested against later activity.

A firm should test monitoring through a file sample. Start with one PEP-linked relationship and trace the last annual review, screening refresh, ownership change check, activity review, exception, escalation and closure. Then select a changed relationship—such as a new director, new trust beneficiary, new company formation or unusual transfer—and test whether the system generated a timely reassessment. The metric that matters is not the number of completed reviews. It is whether meaningful changes reached the correct person and resulted in a documented response.

5. Exit: former-PEP reassessment is a risk decision, not a delete button

A former PEP remains a PEP for classification purposes, but the need for enhanced due diligence should be risk based. HKMA describes factors including time since the person left office, residual influence, former seniority and links between previous and current functions.[2] For former Hong Kong PEPs and their family members or close associates, the Smart Tips indicate that risk is generally lower and that enhanced measures should be applied only where justified by the assessment. This nuanced approach avoids both permanent high-risk treatment without evidence and premature removal of safeguards.

The exit control should begin when a current PEP leaves office, not when a review happens to be due. Require a trigger from screening, customer contact, public information or relationship management. The reassessment should compare the prior and current roles, update ownership and activity information, consider residual influence and new business connections, evaluate whether prior source-of-wealth conclusions remain reasonable, and record the decision to continue, reduce or remove enhanced measures. Retain the rationale and the approver; a reviewer must be able to see why the treatment changed.

Where a firm chooses to discontinue enhanced measures, it should still maintain ordinary ongoing monitoring and a route to re-escalate the relationship if new information appears. The goal is not to create a permanent exception list. It is to maintain a responsive risk profile that reflects current evidence.

A 90-day control-improvement plan

In the first 30 days, inventory all current PEP-related fields and files. Confirm that client, beneficial-owner, family-member and close-associate information is captured consistently across onboarding, corporate-services, trust, tax and accounting records. Create the six-question PEP file template, define primary and corroborating information sources, and identify relationships that lack a recorded risk rationale, approval or review date. Pause any new high-risk relationship that cannot reach the required decision gate.

In days 31–60, test the process rather than only rewriting the policy. Select a sample of current PEP and PEP-linked files. Reperform screening, corroborate a sample of declarations, trace beneficial ownership, evaluate source-of-wealth and source-of-funds evidence, inspect approval timing and test a monitoring trigger. Include at least one former-PEP case. Classify each gap as data completeness, risk assessment, approval, evidence, monitoring, training or systems issue, and assign an accountable owner with a remediation date.

In days 61–90, assess operating effectiveness. Check whether remediations changed the file outcome, whether staff use the template, whether senior approvals are timely, and whether trigger events are captured. Report recurring themes to the firm’s AML/CTF or quality-management lead. EQC Compliance Advisory can assist through a PEP, Beneficial-Owner and Former-PEP Risk-Control Effectiveness Review. The review maps client and control data, samples evidence and approvals, challenges risk decisions, tests monitoring and former-PEP reassessments, and delivers a prioritised remediation plan that is tailored to the firm’s applicable obligations and services.

This article provides general information only. It is not legal, tax, audit or regulatory advice and should be considered in light of a firm’s own circumstances.

Scroll to Top