Enhanced Due Diligence & Politically Exposed Persons

FATF Recommendations 12, 13 & 19 — EDD obligations, PEP categories, source of wealth, and high-risk jurisdiction controls

Page 1 of 7  |  Course Overview

Course Overview

Enhanced Due Diligence applies where standard CDD is insufficient to manage the ML/TF risk of a customer or relationship. This course covers the three mandatory EDD categories under FATF — Politically Exposed Persons (R.12), correspondent banking (R.13), and high-risk jurisdictions (R.19) — as well as EDD for non-face-to-face relationships and source of wealth investigations. The PEP framework is explored in depth, including the Africa-specific challenge of identifying PEP exposure in extended patronage networks.

Estimated completion time: 55–70 minutes

Module 1: What Is EDD and When Does It Apply?

The three mandatory EDD triggers and the general EDD obligation for higher-risk situations.

Not Started

Module 2: Politically Exposed Persons — Categories and Controls

The three PEP categories, family members, close associates, and the Africa PEP challenge.

Not Started

Module 3: Source of Wealth and Source of Funds

The critical distinction — how to establish and verify both for PEP and high-risk relationships.

Not Started

Module 4: Correspondent Banking EDD

FATF R.13 — assessing respondent controls, payable-through accounts, and shell bank prohibition.

Not Started

Module 5: High-Risk Jurisdictions and Non-Face-to-Face EDD

FATF black list and grey list — EDD requirements, counter-measures, and digital channel risks.

Not Started

Module 6: Final Assessment

30-question assessment. Pass mark: 80%. Certificate on completion.

Not Started

Module 1: What Is EDD and When Does It Apply?

1.1 What Is Enhanced Due Diligence?

Enhanced Due Diligence (EDD) is a more intensive form of customer due diligence applied when standard CDD measures are insufficient to manage the ML/TF risk of a relationship. EDD does not replace standard CDD — it builds upon it, requiring additional information, verification, and ongoing scrutiny.

EDD principle: Where higher risk exists, deeper scrutiny is required. The FATF framework does not prescribe a fixed EDD checklist — it requires that measures be proportionate to the identified risk. What constitutes adequate EDD for a domestic PEP differs from what is required for a foreign PEP, a correspondent bank in a black-listed jurisdiction, or an online-only customer from an anonymising jurisdiction.

EDD typically involves some combination of:

  • Additional identification and verification steps (more documents, independent verification).
  • Source of wealth and source of funds investigation.
  • Senior management approval before establishing or continuing the relationship.
  • Enhanced ongoing monitoring — more frequent reviews, lower alert thresholds, tighter transaction limits.
  • Senior relationship management ownership — a named senior person responsible for the relationship.
  • More frequent periodic review (e.g., annual rather than three-yearly).

1.2 The Three Mandatory EDD Triggers

FATF specifies three categories where EDD is always required — these are not discretionary risk decisions, but mandatory obligations:

TriggerFATF RecommendationCore EDD Requirement
Politically Exposed Persons (PEPs)Recommendation 12Senior management approval; source of wealth and funds; enhanced ongoing monitoring
Correspondent BankingRecommendation 13Gather sufficient information on respondent; assess AML controls; senior management approval; document responsibilities; prohibit shell banks
High-Risk JurisdictionsRecommendation 19EDD for business relationships and transactions with persons from FATF-listed jurisdictions; counter-measures for black-listed countries

The General Higher-Risk Obligation

Beyond the three mandatory triggers, the FATF Interpretive Note to R.10 requires FIs to apply EDD whenever higher risk is identified — even outside the three named categories. Examples:

  • Non-face-to-face customers where identity cannot be verified in person.
  • Customers with complex or opaque corporate structures not explained by legitimate business need.
  • Customers from sectors with documented high ML risk (real estate, precious metals, cash-intensive businesses).
  • New products or channels assessed as higher risk in the EWRA.
  • Relationships involving large cash transactions with no plausible business explanation.

1.3 EDD Is Not a Bureaucratic Exercise

A common compliance failure is treating EDD as a documentation exercise — collecting more documents without genuinely investigating the risk. FATF mutual evaluation reports frequently criticise institutions for applying "pro forma EDD" that satisfies the form but not the substance of the obligation.

High-quality EDD genuinely addresses the risk question: Why does this customer, with these funds, in this jurisdiction, want to conduct these transactions? Does the explanation make sense?

If the answer cannot be satisfactorily established after applying EDD measures, the institution must either:

  • Decline to establish or continue the relationship; or
  • File an STR if there are grounds for suspicion.

EDD is a risk management tool, not a compliance form to be filed.

Module 2: Politically Exposed Persons — Categories and Controls

2.1 The FATF PEP Definition

FATF definition: "A PEP is an individual who is or has been entrusted with a prominent public function."

Three categories of PEPs exist under the FATF framework:

Foreign PEPs

Entrusted with prominent public functions by a foreign country. Heads of state, senior government ministers, senior judicial officials, senior military officials, senior executives of state-owned enterprises, important political party officials. Mandatory EDD under R.12.

Domestic PEPs

Same roles as foreign PEPs but in the institution's home country. Countries determine whether EDD applies, but FATF expects EDD where elevated risk is present. In practice, domestic PEPs often warrant EDD given access to state resources.

International Organisation PEPs

Senior officials of international organisations — UN, World Bank, IMF, African Development Bank, regional development banks, major international sporting bodies. EDD required under R.12.

Key clarification — "has been": The PEP obligation does not end when a person leaves office. FATF does not set a fixed decommissioning period. In practice, institutions apply a risk-based approach — typically maintaining PEP EDD for 12–24 months after the person leaves the relevant position, with continuation where ML/TF risk remains elevated. Senior positions with significant access to state resources may warrant longer monitoring.

2.2 Family Members and Close Associates of PEPs

EDD obligations extend to family members and close associates of PEPs. These individuals may be used to hold or move funds on behalf of the PEP — a well-documented ML typology.

Family Members

FATF leaves the definition of "family" to national law. Standard guidance includes:

  • Spouse or partner (including non-registered partners in some jurisdictions).
  • Children and their spouses or partners.
  • Parents.

In high-risk jurisdictions with extended family patronage networks — common across Sub-Saharan Africa — FATF guidance recognises that the definition may need to extend to siblings, grandparents, aunts and uncles, cousins, and in-laws, depending on the cultural and political context.

Close Associates

Non-exhaustive FATF examples of close associates:

  • Persons with close business relationships with the PEP — joint business ownership, shared directorships, significant financial dealings.
  • Members of the same political party or organisation who are known to have close dealings with the PEP.
  • Any person known to have joint beneficial ownership of legal entities or arrangements with the PEP.
  • Any person who is a known sole beneficial owner of an entity set up for the benefit of the PEP.

2.3 The Africa PEP Challenge

Applying the PEP framework in Sub-Saharan Africa presents challenges that do not arise in the same form in European or North American markets:

Extensive Patronage Networks

In many African political systems, government officials exercise patronage over extended networks of family members, political allies, and business associates — many of whom receive economic benefits derived from the official's position. The ML risk extends well beyond the immediate family defined in Western frameworks.

Practical implication: PEP screening and EDD must be calibrated to the political environment of the relevant country, not applied using a generic framework designed for a different context.

State-Owned Enterprise Executives

Many of Africa's largest companies are state-owned or partially state-owned. Senior executives of these entities are PEPs under FATF's definition but are not always identified as such in commercial PEP databases, which focus heavily on political office-holders.

Weak PEP Databases

Commercial PEP databases have better coverage of Western political figures than of Sub-Saharan African, South Asian, or Southeast Asian officials. Compliance teams cannot rely solely on database hits — active research using local news sources, government websites, and regional media is essential.

Political Transitions

Rapid political changes (elections, coups, ministerial reshuffles) in some African jurisdictions mean that PEP status can change quickly. CDD systems must be capable of identifying PEP status changes in real time, not just at onboarding.

2.4 EDD Requirements for PEPs — R.12 Checklist

Every PEP relationship requires all three of the following EDD measures under Recommendation 12:

  1. Senior management approval: A named member of senior management (typically MLRO level or above, or a designated senior officer) must approve the establishment of the relationship — or, for existing customers who become PEPs, the continuation of the relationship. This approval must be documented.
  2. Source of wealth and source of funds: The institution must take reasonable measures to establish the PEP's source of wealth (how they accumulated their overall assets) and the source of the specific funds being placed with the institution. Both must be plausible given the PEP's career, salary, and legitimate business interests.
  3. Enhanced ongoing monitoring: The relationship must be subject to more intense ongoing monitoring — lower alert thresholds, more frequent periodic reviews (typically annual), closer scrutiny of transactions, and senior ownership of the relationship.
Source of wealth ≠ Source of funds: These are two distinct enquiries. Source of wealth asks: how did this PEP accumulate their total assets over their career? Source of funds asks: where did the specific funds being deposited/transferred come from? A PEP may have a plausible source of wealth (20 years as a minister with a declared salary and disclosed business interests) but present unexplained source of funds (a USD 5 million wire from an anonymous offshore entity that doesn't align with their declared business activities).

Module 3: Source of Wealth and Source of Funds

3.1 Source of Wealth — The Investigation

Source of wealth (SoW) is an enquiry into how a customer accumulated their total wealth over their lifetime. For PEPs and high-risk customers, SoW verification is an EDD measure — it tests whether the customer's wealth is consistent with their legitimate career and declared business interests.

How to Establish Source of Wealth

SoW investigation typically involves gathering and cross-referencing:

SoW SourceWhat It EstablishesLimitation
Employment history and salary recordsExpected lifetime earnings from employmentMay not capture supplementary income or undisclosed roles
Business ownership interestsBusiness income, dividends, capital gains from company stakesNeeds verification that the business was genuinely profitable
Inheritance documentationAssets received by inheritance or giftRequires verification of the original source (the deceased's wealth)
Property and asset ownership recordsCapital appreciation on property/investmentsMust verify how property was originally acquired
Public disclosuresFor PEPs — declared assets in official disclosures, parliamentary registers, stock exchange filingsSelf-declared; quality of disclosure varies significantly by jurisdiction
Media and open-source researchCross-reference against news reports, court records, regulatory findingsCoverage uneven; absence of negative media is not proof of legitimacy

The Plausibility Test

The core question in SoW is: Is the customer's claimed wealth plausible given their legitimate career and declared income?

A minister who has earned a public salary for 20 years, with limited declared private business interests, presenting USD 20 million in assets fails the plausibility test — the math does not work on legitimate income alone. The institution must either obtain a credible explanation or apply tighter controls / exit the relationship.

3.2 Source of Funds — The Transaction-Level Check

Source of funds (SoF) is the origin of the specific funds being deposited, transferred, or placed with the institution in a particular transaction or at a particular time. It is narrower and more specific than SoW.

Common SoF declarations and what they require:

  • "Sale of property": Verify with sale agreement, completion statement, and evidence of the buyer's payment. Check that the sale was at market value.
  • "Business income / dividend": Verify with company accounts, dividend resolution, and bank records showing the distribution.
  • "Inheritance": Verify with grant of probate, will, and estate accounts showing the distribution.
  • "Investment return": Verify with broker statements showing the investment and liquidation.
  • "Loan": Verify with loan agreement. Check that the lender is identifiable and the loan terms are commercial. Circular loan structures (where the loan is funded by the customer themselves) are a red flag.

3.3 Source of Wealth Red Flags in African and Asian Contexts

From FATF typologies and ESAAMLG/GIABA mutual evaluation findings, common SoW red flags in emerging market PEP cases include:

  • Wealth disproportionate to public salary: A public official on a declared annual salary of USD 50,000 whose assets include multiple luxury properties and foreign bank accounts worth millions.
  • "Successful business" with no verifiable revenue: A business described as profitable with no audited accounts, no tax filing history, and no identifiable customers or suppliers.
  • Land grants from government: Land acquired at below-market value through government connections — a documented corruption typology in several ESAAMLG member states.
  • Procurement-related income: Business income derived from government contracts awarded to companies controlled by the PEP or their family members — a direct conflict of interest and potential proceed of corruption.
  • Rapid wealth accumulation coinciding with period in office: A customer who was of modest means before taking public office and rapidly accumulated significant assets during their tenure.
  • Complex offshore structures holding domestic assets: A government official's local real estate and business assets held through offshore entities in low-disclosure jurisdictions — a classic asset concealment structure.

Module 4: Correspondent Banking EDD

4.1 FATF Recommendation 13 — Correspondent Banking EDD

Correspondent banking relationships — where one FI (the correspondent) provides services to another FI (the respondent) — carry significant ML/TF risk because the correspondent processes transactions for the respondent's customers without direct access to those customers' CDD information.

FATF R.13 requires correspondent banks to apply EDD when establishing such relationships:

  1. Gather sufficient information about the respondent institution: business model, ownership structure, reputation, quality of supervision in the respondent's home jurisdiction, and AML/CFT regulatory standing.
  2. Assess AML/CFT controls: Evaluate the respondent bank's AML/CFT programme and determine whether it is adequate and effective. This typically involves a correspondent banking questionnaire (Wolfsberg Group CBQ or equivalent).
  3. Obtain senior management approval before establishing a new correspondent relationship.
  4. Document respective AML/CFT responsibilities: Clearly set out in the correspondent agreement which entity is responsible for which AML/CFT obligations.
  5. Payable-through accounts: Where the respondent's customers have direct access to the correspondent's accounts, the correspondent must be satisfied that the respondent has applied CDD to those customers and can provide relevant CDD on request.

The Shell Bank Prohibition

Shell bank definition (FATF Glossary): A bank that has no physical presence in any country in which it is incorporated or licensed and which is unaffiliated with a regulated financial group that is subject to effective consolidated supervision.

Correspondent banks are explicitly prohibited from entering into or maintaining correspondent relationships with shell banks. The rationale: a shell bank cannot be effectively supervised by any regulator, has no accountable management in any jurisdiction, and provides essentially anonymous access to the international financial system.

4.2 De-Risking and the African Correspondent Banking Crisis

Major global banks have significantly reduced their correspondent banking relationships with African institutions over the past decade. This is the de-risking problem in its starkest form:

Scale of the problem: IMF research demonstrates that grey-listing a country reduces average capital inflows by 7.6% of GDP, driven largely by correspondent banking withdrawal and increased compliance costs for counterparties. For smaller African economies, the loss of USD or EUR clearing access forces institutions to use more expensive intermediaries, increasing transaction costs for individuals and businesses throughout the economy.

FATF's position: FATF has published specific guidance on correspondent banking (October 2016) to clarify that R.13 does not require blanket de-risking. Correspondent banks that exit entire regional markets — rather than making individual assessments of each respondent's AML/CFT controls — are not applying the risk-based approach.

Impact of Nigeria and South Africa exiting the grey list (October 2025): Both countries' removal from FATF's increased monitoring list is expected to reduce de-risking pressure from global correspondent banks — though the improvement in correspondent banking access typically takes 12–24 months to materialise after grey-list exit.

4.3 Nested Correspondent Banking

Nested correspondent banking occurs when a respondent bank uses its correspondent relationship to provide services to third-party banks that the correspondent does not know about. This is a significant ML risk:

  • The correspondent bank's correspondent account effectively becomes a conduit for institutions it has never assessed or approved.
  • The correspondent bank cannot verify the AML/CFT standards of the nested institutions.
  • The true originator of transactions may be the nested institution's customers — invisible to the correspondent.

Controls: Correspondent banking agreements should explicitly prohibit nesting without prior written approval. Due diligence should include identifying whether the respondent itself offers correspondent services and, if so, assessing the scope and quality of sub-correspondents.

Module 5: High-Risk Jurisdictions and Non-Face-to-Face EDD

5.1 FATF Recommendation 19 — High-Risk Jurisdictions

FATF Recommendation 19 requires countries to apply enhanced due diligence measures to business relationships and transactions with natural and legal persons from countries identified by FATF as high-risk.

Black List — High-Risk Jurisdictions Subject to a Call for Action

As of February 2026, three countries are on the FATF Black List:

  • North Korea (DPRK) — on the list since 2009. Counter-measures required: FIs must apply EDD and, at the country level, additional counter-measures such as enhanced reporting, limits on financial transactions, and heightened supervisory scrutiny. DPRK is the highest-risk jurisdiction globally for proliferation financing.
  • Iran — on the list since 2011. Counter-measures required for transactions with Iranian counterparts.
  • Myanmar — added in 2020 following a significant deterioration in the AML/CFT environment.
Counter-measures vs EDD: EDD means more intensive due diligence. Counter-measures go further — they may include requiring institutions to report all transactions to the FIU, apply enhanced reporting obligations, or consider whether to terminate relationships entirely. Counter-measures are imposed by countries, not individual FIs, but FIs must implement them.

Grey List — Jurisdictions Under Increased Monitoring

Grey-listed countries are those that have committed to address strategic deficiencies within agreed timeframes. As of February 2026, approximately 21 countries are on the grey list, including additions of Kuwait and Papua New Guinea in February 2026. Recent exits include Nigeria and South Africa (October 2025), and Burkina Faso and Mozambique (October 2025).

For grey-listed jurisdictions, FIs should apply:

  • Heightened awareness and scrutiny of transactions — not necessarily full EDD, but elevated monitoring.
  • Closer assessment of correspondent banking relationships with institutions from grey-listed countries.
  • Customer risk ratings adjusted to reflect the geographic risk of grey-listed jurisdiction exposure.

5.2 Non-Face-to-Face Customer EDD

Where a customer cannot be verified in person — online-only onboarding, remote account opening, app-based services — additional ML/TF risk arises from the reduced ability to verify identity and detect document fraud. FATF recognises non-face-to-face as a higher-risk channel.

Compensating controls for non-face-to-face channels:

  • Digital identity verification: Biometric liveness checks, document scanning with AI verification, facial comparison against government ID database. Must meet an appropriate assurance level relative to the risk of the product.
  • Device and behavioural signals: IP address geolocation, device fingerprinting, operating system and browser data captured at onboarding — used as part of the risk profile, particularly for high-risk customers onboarding remotely.
  • Additional document verification: Requiring a second form of identification beyond the primary document, certified by a regulated professional or government body.
  • Transaction limits: Restricting transaction values and velocities for customers onboarded via non-face-to-face channels until full verification is completed.
  • Enhanced monitoring at account inception: More sensitive TM rules applied to new non-face-to-face accounts during a probationary period.

5.3 Digital Channel Red Flags

From FATF and ACAMS practitioner guidance, specific red flags in digital and non-face-to-face channels include:

  • IP address in a different country from the declared address at onboarding.
  • Use of a VPN or anonymising proxy service during onboarding or transacting.
  • Multiple onboarding attempts from the same device with different identity documents.
  • Device used to access multiple accounts simultaneously.
  • Onboarding data (name, date of birth) inconsistent with facial match on submitted document.
  • Large transactions immediately after account opening — no relationship-building period.
  • Immediate transfers out to an unrelated third party after receiving funds.

Digital financial products in Africa — including mobile money, neo-banks, and digital lenders — must incorporate these signals into their AML monitoring frameworks. The rapid growth of digital financial services in Sub-Saharan Africa and South Asia has outpaced the development of AML controls in many jurisdictions.

Module 6: Final Assessment

Answer all 30 questions. A score of 80% or higher (24/30) is required to receive your certificate.

Section A: Multiple Choice (Questions 1–15)

1. Which of the following is NOT one of the three mandatory EDD triggers under the FATF framework?

2. The FATF definition of a PEP is an individual who:

3. For which PEP category does FATF Recommendation 12 make EDD explicitly mandatory?

4. "Source of wealth" in an EDD context refers to:

5. Under FATF R.12, which three EDD measures are required for all PEP relationships?

6. A FATF "shell bank" is defined as a bank that:

7. Under FATF R.13, correspondent banks must refuse to establish or continue relationships with:

8. How many countries are on the FATF Black List as of February 2026?

9. IMF research has found that grey-listing reduces a country's capital inflows by an average of:

10. A customer's close associate is defined as including:

11. "Nested" correspondent banking refers to:

12. Which two African countries were removed from the FATF grey list in October 2025?

13. For non-face-to-face customer onboarding, which of the following is a compensating control?

14. A foreign PEP presents a source of wealth declaration claiming "business income" from a company with no audited accounts, no tax filing history, and no identifiable clients. This is:

15. Under FATF R.13, a correspondent bank must obtain what approval before establishing a new correspondent relationship?

Section B: Scenario Questions (Questions 16–25)

16. A minister of finance in a neighbouring country applies to open a private banking account. She has left office six months ago. Is she still a PEP?

17. A PEP customer's adult son applies to open a trading account. He is not politically active himself. Does EDD apply?

18. A compliance officer is reviewing a PEP file. The PEP is a senior SOE executive in a GIABA member state who accumulated USD 8 million in property assets while earning a declared salary of USD 40,000 per year for 15 years. What is the key issue?

19. A bank is assessing whether to accept a correspondent relationship with a bank in a grey-listed country. What is the appropriate action?

20. During a digital onboarding session, the compliance system detects that the customer's IP address is in Country X but their declared address is in Country Y. Country X is on the FATF black list. What should happen?

21. A respondent bank's correspondent banking questionnaire (CBQ) reveals that it offers correspondent services to 15 other small banks in the region, none of which have been disclosed to the correspondent. What risk does this represent?

22. A customer declares that their USD 2 million deposit originated from a "loan" from a company they wholly own. What is the risk issue?

23. A domestic PEP (a senior judge) approaches a bank to open a standard savings account. Which of the following is correct?

24. Which of the following is a source of wealth red flag specific to emerging market PEP contexts?

25. Which of the following represents the difference between EDD and counter-measures under FATF R.19?

Section C: True / False (Questions 26–30)

26. A person who has left a senior government position is no longer a PEP under FATF and no longer requires EDD from the moment they leave office.

27. FATF's definition of a shell bank includes any bank that is located in a low-tax jurisdiction.

28. Source of wealth and source of funds are two distinct enquiries in EDD — they are not interchangeable.

29. Under FATF's position on de-risking, correspondent banks that exit entire African regional markets — without individual assessment of each respondent — are applying the risk-based approach correctly.

30. A non-face-to-face customer onboarding channel is recognised by FATF as a higher-risk delivery channel requiring compensating controls.

Congratulations — you have passed. Enter your name to generate your certificate.

Certificate of Completion

Anqa Compliance watermark

Certificate of Completion

This certifies that

has successfully completed

Enhanced Due Diligence & Politically Exposed Persons

Issued by Anqa Compliance