Sanctions vs PEP True Match: When to Block and When to Scrutinize

A screening alert is not a decision. It is a question, and the question has two parts. Is this a real match or a coincidence, and if it is real, what kind of match is it. Answer the first part wrong and you either block an innocent customer or wave through a sanctioned one. Answer the second part wrong and you block someone you were only supposed to scrutinize, or scrutinize someone you were legally required to block.

Some alerts are not real matches at all. A screening engine flags on name similarity, and name similarity is common: Shared common names, transliteration variants, and coincidental overlaps produce far more alerts than actual hits. The work of an alert queue is mostly the work of clearing noise. But the noise is not the risk. The risk is the one alert in the pile that is real, and the whole workflow exists to make sure that one gets handled correctly while the rest get cleared without drama.

This article walks the alert from the moment it fires to the moment it closes. The path forks early and hard. A true sanctions match and a true PEP match demand almost opposite responses, and the fork between them determines everything downstream. Get the triage right, take the correct branch, and document both, and the rest is procedure.

The sections below follow the alert in order:

  • First, confirm it is a true match
  • Sanctions versus PEP: Two very different responses
  • Handling a sanctions true match
  • Handling a PEP true match
  • The escalation tiers: L1, L2, MLRO
  • Documentation and audit trail
  • How Sanction Scanner helps

First, confirm it is a true match

Before any escalation, before any branch, one question has to be answered: Is this a true match or a false positive? False positives, and the reasons are the ones every screening team knows by heart. A name coincidence, where two unrelated people share a name. A transliteration variant, where one non-Latin name has several Latin spellings. A common name, where thousands of real people carry the string the engine flagged. The alert fired on the name. The name is the weakest identifier in the file.

Triage is the work of comparing the secondary identifiers. Date of birth, nationality, identification number, and place of birth are what separate the person on the list from the customer in front of you. The alert carries the listed person's identifiers, or some of them. The customer file carries the customer's. Line them up.

The comparison resolves in one of three ways.

The secondary identifiers clearly differ. The listed person was born in 1961 in one country, the customer in 1988 in another, with a different nationality and a different ID. This is a false positive. Document the rationale and dismiss it.

The identifiers match, or enough of them match that the customer cannot be excluded. This is a potential true match. Escalate it.

The identifiers are missing on one side. A list entry with no date of birth, or a customer file that never captured one, cannot be resolved by identifiers alone. Treat it as unresolved, which means escalate, not dismiss.

Two pieces of context make triage more accurate. The first is fuzzy matching awareness: Knowing that the engine scored this alert on approximate similarity tells you what kind of coincidence to check for. The second is transliteration awareness: A name that looks like a weak match in Latin letters may be an exact match in the original script, or the reverse. A triage analyst who understands why the alert fired makes better dismiss decisions than one who only sees a score.

There is a discipline question buried in triage that most programs get wrong at least once. The pressure in an alert queue is toward clearing, because the queue is large and most of it is genuinely noise, and an analyst who clears quickly is rewarded by the backlog going down. That pressure is exactly what a real match hides behind. The check against it is a rule that does not bend: An alert is only a false positive when something in the file positively excludes the match, not when nothing in the file confirms it. Absence of a confirming identifier is not evidence of a non-match. It is an unanswered question, and unanswered questions escalate.

One rule sits above all the others in this step. Never dismiss an alert without documenting the rationale. A dismissed alert with no written reason is indistinguishable, to an examiner, from an alert that was never reviewed. The dismissal is a decision, and every decision in this workflow has to leave a record. Most alerts end here, cleared and documented. The ones that survive triage move to the fork.

Sanctions versus PEP: Two very different responses

This is the fork that determines everything after it. A true sanctions match and a true PEP match are both real, both escalated, and both serious, and the correct response to each is close to the opposite of the correct response to the other.

A sanctions true match means block. Freeze or reject the transaction, do not let it proceed, do not tell the customer why, and report to the authorities. Sanctions compliance is strict liability: There is no risk based discretion to exercise, no judgment call about whether the relationship is worth keeping. The transaction stops because the law says it stops.

A PEP true match means scrutinize, not block. Being a politically exposed person is not a crime. It is a risk classification that triggers enhanced due diligence (EDD), senior management approval, source of wealth checks, and closer ongoing monitoring. A PEP is presumed to carry higher corruption and bribery risk, so the relationship gets more scrutiny, not a closed door. Blocking a customer solely for being a PEP is not compliance. It is de-risking, and it raises its own regulatory problems.

The distinction is block versus scrutinize, and it decides which of the next two sections applies. Confusing the two is a real failure in both directions. Treating a sanctions hit as a PEP style scrutiny case leaves a prohibited transaction running. Treating a PEP as a sanctions style block denies service to a customer you were only required to monitor.

Step

Sanctions true match

PEP true match

Legal nature

Strict liability, prohibited

Higher risk, not prohibited

Immediate action

Block or reject the transaction

Let it proceed under review

The customer

Do not tip off

Engage; request EDD information

Decision maker

MLRO or sanctions officer

Senior management approval

Core obligation

Report to OFAC; consider a SAR

Enhanced due diligence and monitoring

Wrong move

Letting the transaction proceed

Rejecting solely for PEP status

Timing

Urgent; the transaction is held

Onboarding or EDD timeline

 

The rest of the workflow runs down whichever column the fork selected.

Handling a sanctions true match

The sanctions path is a sequence, and the order matters because the early steps are time sensitive and the later steps are legally required.

Step 1: Block or reject the transaction immediately. Do not process it. Whether you block or reject depends on the sanctions program and the nature of the property, but in both cases the transaction does not go through. This is the step that has to happen first, because every minute the transaction sits unblocked is exposure.

Step 2: Do not tip off the customer. The customer can be told a transaction cannot be completed; the customer cannot be told the compliance reason behind it, because disclosing that a transaction was stopped over a sanctions or suspicious activity concern is itself an offense in many jurisdictions.

Step 3: Escalate to the Money Laundering Reporting Officer or sanctions officer. The block is an operational action; the reporting and the relationship decision belong to the officer who owns the program. The escalation is not optional and it is not slow.

Step 4: Report to OFAC. A blocked transaction requires a blocked property report within 10 business days of blocking, under 31 CFR 501.603. A rejected transaction requires a rejected transaction report within 10 business days, under 31 CFR 501.604. The two reports cover two different actions, and the clock on both is short.

Step 5: Consider a SAR. If the match suggests sanctions evasion or a broader pattern of suspicious activity, a suspicious activity report may be required on top of the OFAC report. SAR filing and OFAC reporting are separate obligations under separate authorities, and one does not satisfy the other. A single blocked transaction can generate both.

Step 6: Document everything for examination. The block, the non-disclosure, the escalation, the reports filed and their dates, and the SAR decision all go into the record.

One structural point sits underneath the whole path. A hit does not always mean the counterparty is directly listed. Under OFAC's 50 percent rule, an entity is blocked when one or more listed persons own it 50 percent or more in the aggregate, even though the entity's own name appears on no list. A sanctions true match can therefore be a match on ownership rather than on the name in front of you, which is why the investigation has to reach the beneficial owners, not just the named party.

Two timing traps catch teams on this path. The first is treating the block as the end of the urgent work. It is the start of it, because the 10 business day reporting clock begins at the moment of blocking, and a report filed late is a violation in its own right, separate from anything to do with the underlying transaction. The second is the difference between a block and a reject, which is not a matter of preference. Property in which a sanctioned person has an interest is blocked and held; a transaction that is merely prohibited, with no blockable property to hold, is rejected and returned. The program should decide which applies before the money moves, because the two actions trigger two different reports under two different sections of the rule. Get the action right and the report follows; get it wrong and the report is filed against the wrong obligation.

Truematchinarticle

Handling a PEP true match

The PEP path is also a sequence, but its logic is management rather than prohibition. The goal is to understand and control the relationship, not to end it.

Step 1: Confirm the PEP status and category. A foreign PEP, a domestic PEP, and an official of an international organization carry different risk levels and, in some frameworks, different requirements. The category shapes how much scrutiny follows, so it is the first thing to establish.

Step 2: Apply enhanced due diligence. Establish the source of wealth and the source of funds, understand the purpose of the relationship, and define the expected activity so that deviations later will stand out. EDD for a PEP is the substance of the whole response, and it is where most of the work lives.

Step 3: Obtain senior management approval. Establishing or continuing a relationship with a PEP requires sign off above the analyst level. This is a deliberate control: It puts the decision, and the accountability for it, where the risk warrants.

Step 4: Set ongoing monitoring at an elevated level. A PEP relationship is monitored more closely and for as long as it lasts, because the risk does not end at onboarding. Someone who is clean today can become exposed later, and the monitoring is what catches the change.

Step 5: Do not automatically reject. Rejecting a customer solely because they are a PEP is de-risking, and regulators have been explicit that blanket exclusion of a customer category is its own compliance problem. The response to a PEP is scrutiny, applied properly, not refusal.

Step 6: Document the risk assessment and the approval. The category determination, the EDD findings, the source of wealth conclusion, and the senior management sign off all go into the file. If the relationship is later questioned, this record is the answer.

There is a judgment call inside the PEP path that the steps alone do not capture. Enhanced due diligence is proportional, not uniform. A domestic PEP in a low corruption role with a plausible, documented source of wealth is a different risk from a foreign PEP in a position with control over public funds, and the depth of the EDD should track that difference rather than applying one heavy template to everyone. The FATF frames PEP status as a starting point for a risk assessment, not a verdict, and the assessment is where the real work sits. Over applying EDD to every PEP wastes the scrutiny that the genuinely high risk cases need; under applying it to the high risk ones is the failure the whole category exists to prevent. The record should show not just that EDD was done, but why it was set at the level it was.

The escalation tiers: L1, L2, MLRO

The workflow runs through three tiers: L1 triages and clears the noise, L2 investigates and classifies the match, and the MLRO or sanctions officer decides and signs off. What each tier does is common to any alert investigation, and the alert investigation workflow sets that out in full.

What is specific to this fork is the clock. A potential sanctions match is urgent because the transaction is held: It cannot wait in a queue for days while the customer's money sits in limbo and the exposure runs. A PEP match follows the onboarding or EDD timeline, which is measured in days rather than minutes, because nothing is frozen while the review proceeds. Same tier structure, very different clocks.

Tier

Responsibility

Output

Typical SLA

L1 triage

Compare identifiers, clear false positives

Dismissal with rationale, or escalation

Sanctions: Same day; PEP: Onboarding timeline

L2 investigation

Gather evidence, classify, check ownership

Recommendation with supporting file

Sanctions: Urgent; PEP: Within the EDD window

MLRO or sanctions officer

Final decision and sign off

Block, report, EDD, or exit, with approval

Sanctions: Before releasing any held funds; PEP: Before onboarding completes

 

Documentation and audit trail

Every step in this workflow produces a record, and the record is branch specific. On the sanctions side: The time of the block, the identifiers that made it a true match, whether the action was a block or a rejection and why, the report filed with its date under 31 CFR 501.603 or 501.604, and the SAR decision with its reasoning. The block timestamp carries more weight than it looks, because the 10 business day clock runs from it and the file is where you prove the report was on time. On the PEP side: The category determination, the source of wealth conclusion, the level EDD was set at and why it was set there, and the senior management approval with a name against it.

The dismissals need the same discipline as the escalations, and a screening queue is where that gets hard, because most of the volume is noise. An alert cleared on identifiers should record which identifiers were compared and which one excluded the match. A file that says only "no match" is indistinguishable, to an examiner, from an alert nobody read. Write the reason at the time rather than reconstructing it later. The general documentation standard, including the narrative structure examiners expect and the samples they pull at exam, sits with the investigation workflow rather than with this fork.

How Sanction Scanner helps

Sanction Scanner's case management routes screening alerts through the full workflow: L1 triage, L2 investigation, and MLRO sign off, with a complete audit trail behind every step. The system keeps the sanctions branch and the PEP branch distinct, so a block response and a scrutinize response follow their own paths rather than collapsing into a single generic queue, and it supports both OFAC reporting and SAR filing where each applies. See the AML screening and monitoring, AML sanctions screening, and PEP screening capabilities for the mechanics.

The alert is where screening ends and judgment begins. The value of the workflow is that it makes the judgment repeatable: Confirm the match before acting on it, take the branch the match requires, and write down each decision as you make it. Do that consistently, and the one real match in a thousand gets handled exactly like it should, while the other nine hundred and ninety nine close cleanly behind it.

 

Sources

[1] Office of Foreign Assets Control, U.S. Department of the Treasury. OFAC FAQ 401: Revised Guidance on Entities Owned by Blocked Persons (50 Percent Rule). 2025.

[2] eCFR, U.S. Code of Federal Regulations. 31 CFR 501.603: Reports on Blocked Property. 2025.

[3] eCFR, U.S. Code of Federal Regulations. 31 CFR 501.604: Reports on Rejected Transactions. 2025.

[4] Financial Action Task Force. FATF Guidance on Politically Exposed Persons (Recommendations 12 and 22). 2013.

FAQ's Blog Post

Enhanced due diligence is proportional, not uniform. FATF treats PEP status as the starting point for a risk assessment rather than a verdict, so a domestic PEP with a documented source of wealth warrants less depth than a foreign PEP controlling public funds. The file should record why the level was set where it was.

Sanctions true matches are not always name matches. Under OFAC's 50 percent rule an entity is blocked when listed persons own it 50 percent or more in the aggregate, though the entity's own name appears on no list. The investigation therefore has to reach the beneficial owners, not stop at the named party.

An alert with a missing identifier cannot be dismissed. When the list entry carries no date of birth, or the customer file never captured one, the match cannot be excluded and the alert is unresolved rather than false. Unresolved alerts escalate. Absence of a confirming identifier is an unanswered question, not evidence of a non-match.

L1 triages: It compares identifiers, dismisses clear false positives with a written rationale, and escalates everything unresolved. L2 investigates: It gathers evidence, classifies the match as sanctions or PEP, checks ownership where the 50 percent rule may apply, and recommends. The MLRO or sanctions officer decides and signs off. L1 and L2 do not close a true match.

Tipping off is prohibited. A customer can be told a transaction cannot be completed, but not that it was stopped for a sanctions or suspicious activity reason. Disclosure is an offense in many jurisdictions and can compromise an investigation. The line runs between the fact of the outcome and the compliance reason behind it.

OFAC reporting and SAR filing are separate obligations under separate authorities, and one does not satisfy the other. A single blocked transaction can require both: The blocked property report to OFAC, and a suspicious activity report where the match suggests evasion or a wider pattern. Filing one and closing the file leaves the other undone.

Blocked property reports are due to OFAC within 10 business days of blocking, under 31 CFR 501.603, and rejected transaction reports run on the same 10 business day clock under 501.604. The clock starts at the moment of the block, not at the end of the investigation. A late report is a violation in its own right.

Blocked property is held; a rejected transaction is returned. Property in which a sanctioned person has an interest is blocked and frozen, while a transaction that is merely prohibited, with no blockable property to hold, is rejected. The two trigger different reports: 31 CFR 501.603 for blocking, 501.604 for rejection.

PEP status is not a reason to block. Being a politically exposed person is not a crime; it is a risk classification that triggers enhanced due diligence, source of wealth checks, senior management approval and closer monitoring. Rejecting a customer solely for PEP status is de-risking, which carries its own regulatory problems.

Triage compares secondary identifiers, not names. Date of birth, nationality, identification number and place of birth are what separate the listed person from the customer. The rule: An alert is a false positive only when something in the file positively excludes the match, never when nothing confirms it. Unanswered questions escalate.