Screening PEPs in Trusts and Complex Ownership Structures

A politically exposed person rarely walks into a bank in person. The account in front of you belongs to a holding company registered in a quiet jurisdiction, owned by another company, administered by a corporate services firm. The paperwork is complete, the registry checks come back clean, and the screening system finds nothing. Approval takes minutes. Somewhere behind two layers sits a former minister whose name appears nowhere in the onboarding file.

That is the scenario this article is about. Not the PEP who shows up directly and gets enhanced due diligence by default. The PEP who is engineered out of the paperwork, using structures that are legal, common, and available off the shelf. The compliance question is short and hard: Can you identify the natural person who ultimately owns or controls what is in front of you, and is that person a PEP? If your onboarding file cannot answer that question, the rest of the controls, screening lists and all, run blind.

Most PEP screening problems do not come from missing a name on a list. They come from never seeing the name at all. A PEP who banks in their own name is found in minutes. A PEP who sits behind a trust, a holding company, and a nominee shareholder can pass through an entire onboarding process without appearing in a single field, because the structure was built to absorb the question. The techniques below are for that second customer: How the structures hide a PEP, which roles matter, and how to screen through the layers instead of stopping at the front entity.

The article works through the problem in the following order:

Why PEPs hide behind trusts and complex structures

The structures that conceal PEP ownership

Trust analysis: more than just the beneficiary

How to screen through the layers

Red flags: when complexity signals PEP concealment

How Sanction Scanner helps

Why PEPs hide behind trusts and complex structures

The FATF defines a PEP as an individual entrusted with a prominent public function, and the label extends to family members and close associates. Being a PEP is not a crime. It is a risk classification, because public position brings influence, access to state assets, and exposure to bribery and corruption. That is why institutions owe PEPs enhanced due diligence: senior management approval, reasonable measures to establish source of wealth and source of funds, and enhanced ongoing monitoring. The same logic appears in Article 52 of the United Nations Convention against Corruption, which calls for enhanced scrutiny of accounts held by or on behalf of public officials, their families, and their close associates.

A PEP subject to that scrutiny has an incentive to avoid detection, and layered ownership is the classic way to do it. A trust, a holding company, and a nominee shareholder can place the PEP’s assets behind legal structures that do not obviously surface the PEP’s name at onboarding. The entity you see looks clean, so it passes. The person behind it was never identified. That is the compliance failure, and it is a structural one: Your screening worked. It just screened the wrong thing.

It is worth being fair here. Three motives sit behind PEP structuring, and they overlap. The first is legitimate: Succession planning, asset protection, and privacy are normal parts of managing serious wealth. The second is safety: Public officials in some countries use structures to shield family assets from kidnapping, extortion, and political reprisals. The third is concealment: Bribes, kickbacks, and embezzled state funds need a home, and a layered structure is the standard way to build one. The same architecture serves all three motives, which is why the structure itself proves nothing. The compliance question is not whether a structure exists. It is whether you can identify who ultimately owns and controls it, and whether that person is a PEP. If the answer to either question is no, the structure has done its job.

How common is the misuse? The World Bank and UNODC Stolen Asset Recovery study of 150 grand corruption cases found corporate vehicles misused in about three quarters of them. The FATF and Egmont Group's 2018 report on the concealment of beneficial ownership walks through the same toolbox: trusts, nominees, and layered companies. When the Pandora Papers landed in October 2021, 11.9 million documents from 14 offshore service providers connected more than 330 politicians and public officials, including 35 current and former national leaders, to offshore holdings. Trusts and holding chains were the recurring architecture. The pattern is not hypothetical. It is standard.

Enhanced due diligence for a PEP is specific: Approve the relationship at senior management level, establish the source of wealth and the source of funds, and monitor the relationship on an enhanced basis for as long as it lasts. None of that works if the relationship is not in the PEP’s name. That is what the structures in the next section are for, and it is why a bank’s PEP controls can be excellent on paper and silent in practice.

Regulators have been building against it. EU member states now maintain registers of beneficial ownership for companies and, in many cases, trusts. The UK has its People with Significant Control register for companies and its Trust Registration Service for trusts. In the US, FinCEN’s geographic targeting orders have required title insurers to identify the natural persons behind shell companies buying residential real estate with cash in major metros. None of these registers makes concealment impossible. They make it measurable, and they give a compliance team somewhere to start. The gap remains between the register and the person, and the structures below are how that gap gets exploited.

The structures that conceal PEP ownership

Five structures do most of the hiding. The choice of structure is not random. A trust suits someone who wants to separate legal title from enjoyment, and it suits a PEP who wants control without ownership. A nominee suits someone who wants a name kept off a register. Layered companies suit someone who wants the chain long enough that nobody finishes the walk. Bearer shares, where they still exist, suit someone who wants no chain at all. Each works differently, so each needs a different check.

Trusts. A trust separates legal title from beneficial ownership. The trustee holds the assets, the beneficiaries benefit, and a PEP can sit anywhere in that arrangement without appearing as the owner of anything. The relevant roles: The settlor, who funded the trust; the trustee, who administers it; the protector, who can direct or replace the trustee; and the beneficiaries, who may be named individuals or a class. A PEP can be any of them. There is no public register to check in most jurisdictions, so the trust deed is usually the only document that reveals the roles.

This is the structural gap that matters. A company has a registry entry you can pull. A trust, in most jurisdictions, does not. What you can see is the corporate trustee, and possibly a bank account in the trust’s name. Everything else depends on the deed, and on being given the deed.

Nominee shareholders and directors. A nominee holds shares or a directorship for the real owner, so the PEP’s name never appears on the register. The tell is a nominee with no genuine connection to the business: A director of a trading company who is also a junior employee at the corporate services provider that formed it. Substance checks exist to catch exactly this pattern: Does the director have a real role, real contact with the business, real decision power, or is the name there because someone needed a name?

Shell and holding companies. Layers of companies across jurisdictions obscure the chain. Each layer adds a registry, a jurisdiction, and a filing delay.

Private investment vehicles. High net worth asset holding companies with few investors, often called private investment companies or PICs. Easy to layer with nominees, easy to wrap in a trust, and easy to file under a name that says nothing about the people inside. The vehicle itself looks inert, which is the point.

Bearer shares. Ownership follows physical possession of the certificate, which leaves no register trail at all. Most major financial centers have abolished or immobilized bearer shares, but older instruments still surface and a few jurisdictions still issue them. Treat any bearer instrument as a red flag until ownership is proven by something other than the certificate itself.

Structure

How it conceals a PEP

Key roles and signals

Screening action

Trusts

Legal title separated from beneficial ownership; nothing on a public register

Settlor, trustee, protector, beneficiaries (named or class)

Identify and screen every role; review the trust deed

Nominee shareholders/directors

Real owner’s name never appears on the register

Nominees with no genuine connection to the business

Ask who stands behind the nominee; verify substance

Shell and holding companies

Layers of entities across jurisdictions

Multi-jurisdiction chains; shared TCSP addresses

Map the full chain; screen every UBO at every layer

Private investment vehicles

Few investors, easy to layer with nominees

HNW structures with unusual complexity

Identify investors and controllers, not just the vehicle

Bearer shares

Ownership follows possession of the certificate

Bearer instruments still in issue

Treat as red flag; demand ownership evidence beyond the certificate

Trust analysis: More than just the beneficiary

The trust is the most misunderstood structure in this group, because most compliance teams screen it the way they screen a company: find the owner, screen the owner, move on. A trust has no single owner, so the shortcut fails. A trust has several relevant persons, and a PEP can sit in any role.

The settlor funds the trust. This is where the money came from, which makes the settlor central to any source of wealth check.

The trustee administers the trust. A corporate trustee from a service provider is common and is not evidence of wrongdoing, but the trustee’s identity tells you where administration actually happens.

The protector exercises control. Protectors can veto distributions, approve decisions, or replace the trustee. It is a control role with no ownership label attached, which is exactly why a PEP uses it.

The beneficiaries receive the assets. They may be named individuals, or they may be a class.

An example: A former minister who is the protector of a trust exercises control without being a beneficiary. The trust pays nobody, distributes nothing, and holds the family’s assets while the minister directs it from a role that appears in exactly one document. If you only screen the named beneficiary, you have screened the wrong person.

Fixed trusts name their beneficiaries. Discretionary trusts do not, or name a class, and the trustee chooses who gets what and when. From a screening perspective the difference is everything: A fixed trust gives you names on day one, a discretionary trust gives you a question that stays open for the life of the trust. Most high value family trusts are discretionary, which is why the open question is the normal state of affairs, not the exception.

A corporate trustee changes the questions without answering them. It tells you a licensed firm is administering the trust, which is usually good for governance and says nothing about who controls it. The protector, the settlor, and the class are still the people who matter, and they are not in the trustee’s registry entry.

Discretionary trusts and class beneficiaries are the hardest case. The beneficiary may not be named until a distribution occurs, which means there is no person to screen at onboarding. What you can do is less satisfying but still real: Identify the class, screen the settlor, trustee, and protector now, and put the structure on ongoing monitoring so that a future distribution, or a future change in who is a PEP, triggers a review. Ongoing monitoring is essential here, and not as a formality. A person who is clean at onboarding can become a PEP later. If that person sits in any trust role, the risk of the whole structure changes, and nothing in a static onboarding file will tell you.

Two practical notes. First, trust deeds are private in most jurisdictions, unlike company registers. Asking for the deed is therefore a test as well as a requirement, and a refusal, or a deed that arrives redacted around the roles that matter, is information in itself. Second, letters of wishes matter. They are not legally binding in most cases, but they reveal intent, and they often name the people the settlor actually cares about. When a trust is involved, ask for them, and read them for names as much as for instructions.

Pep trusts in article

How to screen through the layers

Screening through a structure is a process, not a list check. Six steps.

Step 1: Map the ownership structure. Corporate registries, beneficial ownership registers, trust deeds, shareholder records. Draw the chain before you screen anyone in it. If the chain has a hole, the hole is the priority, not the people you can already see. Some of that mapping is quick: The UK’s People with Significant Control register names companies’ controllers directly, and EU beneficial ownership registers do similar work. Trusts are the exception again. A trust may not appear on any register at all, in which case the map starts with the deed, not with a search.

Step 2: Identify every natural person with ownership or control. Not just 25% equity. Control can be contractual, like a protector’s veto, or it can run through nominee arrangements and voting agreements. A 24% shareholder can exercise control through a management contract. A zero percent shareholder can be the only person with signature authority. If the step stops at percentages, it stops too early. The FATF’s approach to beneficial ownership treats ownership and control as separate questions for this reason.

Step 3: Screen each identified person against PEP, sanctions, and adverse media lists. Every layer, every role. The exercise fails wholesale if layer two goes unscreened. That is not a partial miss. It is the miss. The lists differ in kind, which matters: A PEP match is a risk question, a sanctions match is a legal prohibition, and adverse media is context for both. The three answers combine into a decision, not a checkbox.

Step 4: Where declarations conflict with independent records, do not proceed. Resolve, escalate, or document the rationale. Conflicts are common when someone is hiding, and the conflict itself is a finding. Proceeding anyway converts a red flag into an unexplainable approval.

Step 5: Treat a nominee or a TCSP as a signal, not an endpoint. Ask who stands behind it and why the structure exists. TCSP administration is normal for families and funds. It is also the standard front for concealment, so the same fact cuts both ways, and the only way to tell the cases apart is to keep asking. The FATF made this point as far back as 2006, in its report on the misuse of corporate vehicles and trust and company service providers. The question is never whether a provider is licensed. It is who that provider is working for.

Step 6: Apply the proportionality test. Is the structure’s complexity justified by a legitimate business purpose? A three-jurisdiction chain holding a small trading company is a problem. A family holding structure for a diversified estate can be normal. Either way, document the reasoning, because the examiner’s first question will be why you accepted it or why you did not.

The data side matters too. Public registers are the floor, not the ceiling. Independent databases, adverse media, and leak reporting fill in what registers do not show, and a name that appears in one leak database and no register is still a name worth screening. The point of the six steps is to make sure the screening happens after the mapping, not instead of it.

Red flags: When complexity signals PEP concealment

None of these proves concealment on its own. Several together change the picture, and the job is to read them in combination.

  • Ownership structure is disproportionately complex for the business size or purpose.
  • Resistance or vague responses when UBO information is requested.
  • Nominee shareholders or directors with no genuine business connection.
  • Frequent, unexplained changes in shareholders or controllers.
  • Jurisdictions with weak beneficial ownership transparency.
  • Structures established or administered by TCSPs in secrecy jurisdictions.
  • Trust protector or settlor from a high-corruption jurisdiction.

The last item deserves a second look. The settlor is the source-of-wealth question in person, and a settlor from a high-corruption jurisdiction raises the stakes on every other check in the file. That is where source-of-wealth verification stops being diligence and becomes the whole decision.

When several flags stack, the response changes in kind: stop onboarding until the structure is explained, escalate to the money laundering reporting officer, and in serious cases consider whether the relationship belongs in a suspicious activity report. The flags are not the decision. They are the instructions to go back to step one and ask harder.

Whatever you decide, the file should show it: That you asked for the ownership information, what you received, and the documented rationale for proceeding or stopping. Documentation is what separates a defensible decision from an unexplainable one.

How Sanction Scanner helps

Sanction Scanner's Know Your Business capability maps the ownership structure and screens each identified UBO against PEP, sanctions, and adverse media lists, so the screening follows the chain instead of stopping at the front entity. The workflow is built around that order: Map, then screen, then document. Ongoing monitoring catches what onboarding cannot: A hidden owner who later becomes a PEP or gets sanctioned, or a new role in a trust that surfaces mid-relationship. See KYB, PEP screening, and adverse media monitoring for the mechanics, and the shell companies article for the specific case of layered corporate chains.

The uncomfortable part is that the PEP who matters most is the one whose name never appears in the file. Everything about a layered structure is designed, legitimately or not, to make the natural person invisible, and onboarding systems are built to process what is presented, not what is hidden. The fix is procedural rather than technical: map the structure before you screen it, screen every role and every layer, and write down why you accepted the result. A clean holding company with an empty ownership file is not a clean customer. It is an unanswered question, and it is a question the file should show you asked.

Sources

[1] Financial Action Task Force. FATF Glossary (Politically Exposed Persons, Recommendation 12). 2025.

[2] United Nations Office on Drugs and Crime. United Nations Convention against Corruption (Article 52). 2004.

[3] Stolen Asset Recovery Initiative, World Bank and UNODC. The Puppet Masters: How the Corrupt Use Legal Structures to Hide Stolen Assets and What to Do About It. 2011.

[4] Financial Action Task Force and Egmont Group. Concealment of Beneficial Ownership. 2018.

[5] International Consortium of Investigative Journalists. Pandora Papers. 2021.

FAQ's Blog Post

Someone can become a PEP after onboarding, which is why a clean check at account opening does not stay clean. A person clean at onboarding can take public office later, and if they sit in any trust or ownership role, the risk of the whole structure changes. Ongoing monitoring is what catches this.

Source of wealth is the core question for a PEP, because the corruption concern is whether their fortune is proportionate to a public salary, not which account sent the money. Establishing source of wealth is what a trust settlor from a high-corruption jurisdiction makes urgent, turning diligence into the whole decision.

PEP use of a trust or holding company is not illegal in itself. The same structures serve legitimate aims like succession planning, asset protection, and safety, as well as concealment of corrupt proceeds. The structure alone proves nothing. What matters is whether you can identify who controls it and whether they are a PEP.

Beneficial ownership screening should not stop at the 25 percent equity threshold. Control can exist without ownership: A protector's veto, a management contract held by a 24 percent shareholder, or signature authority held by someone with no shares at all. FATF treats ownership and control as separate questions, so screening must cover both.

Trust or company service providers, or TCSPs, are firms that form and administer companies and trusts for clients, including acting as corporate trustee or director. Their administration is normal for legitimate families and funds, but it is also the standard front for concealment, so a TCSP is a signal to keep asking, not an answer.

Bearer shares, where ownership follows whoever physically holds the certificate, have been abolished or immobilized in most major financial centers, but a few jurisdictions still issue them and older instruments still surface. They leave no register trail, so treat any bearer instrument as a red flag until ownership is proven otherwise.

Private investment companies, or PICs, are asset-holding companies with a small number of investors, often used by high-net-worth individuals. They are easy to layer with nominees and wrap inside a trust, and easy to name in a way that reveals nothing about the people inside, which is why they can conceal a PEP.

Nominee shareholders hold shares in a company on behalf of the real owner, so that owner's name never appears on the register. This is legal and common, but it can also hide a PEP. The warning sign is a nominee with no genuine connection to the business, whose only role is to be a name.

Fixed trusts name their beneficiaries, so you have names to screen from day one. Discretionary trusts name only a class, and the trustee decides who receives what and when, so there may be no individual to screen at onboarding. Most high-value family trusts are discretionary, which makes ongoing monitoring essential.

Trust roles that matter for screening are the settlor, who funds the trust, the trustee, who administers it, the protector, who can direct or replace the trustee, and the beneficiaries, who receive the assets. A politically exposed person can occupy any of these roles, so all four need screening, not just the beneficiary.