‹ All resources · Electronic signatures and Australian law
Compliance · 18 August 2026 · 6 min read
PEP and sanctions screening, explained for Australian practices
What a politically exposed person actually is, why the DFAT Consolidated List matters, why namesake false positives are normal, and how screening fits into customer due diligence under Tranche 2.
Customer due diligence under Australia's AML/CTF regime has two halves. The first is verifying that your client is who they say they are. The second is understanding the risk they carry — and that is where PEP and sanctions screening comes in.
What is a politically exposed person?
A PEP is someone who holds, or has held, a prominent public function — heads of state, ministers, senior officials, judges, senior military officers, and executives of state-owned enterprises — plus their immediate family and close associates. PEPs aren't criminals by definition; the concern is that their position creates elevated corruption and money-laundering risk, so the AML/CTF Rules require reporting entities to identify them and apply closer scrutiny where warranted.
Sanctions are different — and stricter
Sanctions screening checks whether a person appears on lists like the DFAT Consolidated List — Australia's register of persons and entities subject to targeted financial sanctions. Unlike PEP status, this is not a risk signal to weigh: dealing with a listed person or their assets can be a criminal offence regardless of intent. A possible sanctions match must be resolved before proceeding, which is why serious screening tools flag sanctions hits differently from PEP hits.
Why false positives are normal — and what to do about them
Screening matches on names, and names collide. A client named John Smith will match politicians named John Smith; a common surname can surface dozens of possible matches from hundreds of lists. This is expected behaviour, not a broken tool.
What matters is the review: a human compares the matches against what the practice knows — date of birth, country, occupation — and records why they do or don't apply. That written review is itself compliance evidence: it shows the screening ran and was considered, which is exactly what a reviewer asks for.
Point-in-time versus ongoing monitoring
A screen answers the question on the day it runs. People become PEPs, and sanctions lists change weekly — so mature AML programs re-screen at sensible triggers: onboarding, and again when a client initiates higher-risk services. Be wary of any provider implying a single onboarding screen covers you forever; be equally wary of overbuying continuous monitoring your risk profile doesn't call for.
How Siggy handles it
Every Siggy identity check includes PEP and sanctions screening at the time of the check, drawn from 500+ sources updated weekly — including the DFAT Consolidated List — at no extra cost. A clean screen shows as cleared. Possible matches appear for your review, with sanctions-list hits flagged distinctly and more urgently than namesake PEP matches, and your clearance note is recorded in the check's tamper-evident audit trail.
Screening never changes the identity result itself — a verified person with a namesake match is still verified. The two answers are kept separate because they answer different questions: who is this person, and what risk do they carry? Which of those questions your practice is actually obliged to answer, and under which rules, is set out in TPB proof of identity and AML/CTF obligations.
This article is general information for Australian practices, current at the publication date — it is not legal or compliance advice. Confirm obligations for your circumstances with your professional adviser or the relevant regulator.
See it in practice
Send your first document in minutes. Free to start, no card, and signers never need an account.
Try for free
