A PEP attestation is the formal record of whether your client is (or isn't) a Politically Exposed Person. FINTRAC requires it for any flagged client.
What A PEP Is
A Politically Exposed Person is someone who holds (or has held) a prominent public function - heads of state, senior government officials, senior judges, senior military, senior executives of state-owned companies, etc. The definition also extends to family members and close associates.
PEPs face additional compliance scrutiny because they're at higher risk of being involved in corruption or money laundering.
When An Attestation Is Required
You'll be prompted for an attestation when the risk rating checklist flags it. Triggers include:
- You ticked the PEP flag in the checklist.
- The screening result returned a possible PEP match.
- The client falls into a category that requires PEP review.
Two Ways To Capture It
Capture It Yourself
If you've already verified with the client (e.g., on a phone call, in person), fill it in directly in the screening dialog:
- PEP status - Domestic PEP / Foreign PEP / HIO / Family of PEP / Close Associate / Not a PEP.
- Method - how you verified (verbal, written, document).
- Family or Associate - if applicable, the relationship.
- Notes - anything relevant.
Send A Token-Gated Form To The Borrower
If you want the client to formally attest in writing:
- In the screening dialog, choose Send Form To Borrower.
- The borrower receives an email with a secure link.
- They open it (no login), answer the PEP questions, and submit.
- Their response comes back to your dashboard and is attached to the screening.
The token expires after a set window. If they don't fill it in time, you can resend.
Attestation Expiry
PEP attestations are time-bound - typically valid for 12 months. After that, the client needs a fresh attestation. You'll be prompted automatically at the next screening cycle.
What Happens After
If the attestation confirms a high-risk PEP, a foreign PEP, or family/close associate of a PEP, an EDD case is auto-opened for admin handling. See Managing EDD Cases.
What To Do Next
- Run the screening: Running A Screening On A Client.
- See the risk rating logic: The Risk Rating Checklist.