Setting Sanctions and PEP Match Thresholds: Why They Shouldn't Be the Same Number

Most firms set one fuzzy-matching threshold at implementation and apply it to every list they screen, including sanctions and PEP data, without ever revisiting the decision. This post argues that's a configuration accident, not a risk decision, and walks through why sanctions and PEP screening deserve different settings, with worked examples across payments, B2B onboarding, and insurance.

Basit Nayani
,
October 6, 2026

Ask OFAC what threshold to use for sanctions screening and it will tell you, in writing, that it cannot answer the question. OFAC's own FAQ on the matter states plainly: "OFAC cannot make such a recommendation because each search has its own unique set of facts surrounding it. Users of Sanctions List Search must make their own match threshold determinations based upon their own internal risk assessments and established compliance practices." 

Most firms respond to that absence of a number by picking one at implementation, applying it uniformly across every list they screen, sanctions, PEP, adverse media. That’s not the best approach. 

Why the Regulator Won't Give You a Number

OFAC's broader guidance reinforces the same position: their regulations don't mandate a specific screening regime, and financial institutions and other screening entities are expected to make choices based on their own circumstances and compliance approach. 

A threshold that's appropriate for a domestic B2B firm with a small, well-documented customer base is not appropriate for a global payments platform processing millions of low-value transactions daily, and no single number could serve both without either missing matches in one case or overwhelming the compliance team in the other.

The absence of a mandated threshold is not an invitation to skip the decision altogether but for an instruction to make the decision deliberately, document why, and revisit it. Never reconsidering a threshold after implementation isn't a risk-based decision.

Why Sanctions and PEP Aren't the Same Risk

A missed sanctions hit is a strict-liability breach. Under OFAC's enforcement framework, intent is irrelevant, the violation exists whether the failure was negligent or deliberate, and it comes with a firm reporting deadline once it's caught: a blocking or rejected-transaction report is due within 10 business days regardless of when the original match should have been caught. The exposure compounds the longer a missed match goes undetected, because every transaction that clears in the interim adds to the eventual penalty calculation.

A missed PEP is a different kind of gap. It's a due diligence shortfall, not a sanctions breach, and it's one you can typically remediate the moment you catch it: flag the relationship, apply enhanced due diligence retroactively, document the correction. 

There's no equivalent 10-business-day reporting clock attached to discovering that a customer should have been treated as a PEP three months ago. This makes it a different category of risk, with a different tolerance for the delay a stricter threshold might introduce.

Screening both at identical sensitivity treats these as the same problem, even though they aren't, and it's hard to defend a policy that doesn't reflect the difference.

Why PEP Data Is “Noisier” at Any Given Setting

At any given threshold setting, PEP screening generates more false positives than sanctions screening. This isn't an implementation failure on any individual firm's part, but a structural feature of the underlying data that FATF itself has documented.

There is no single authoritative, government-published PEP list equivalent to OFAC's SDN List. 

FATF's own June 2013 guidance on Recommendations 12 and 22 states directly that commercial PEP databases "are not necessarily comprehensive or reliable," since they generally draw solely from publicly available information and subscribing institutions have no way to independently verify their accuracy or completeness, and that countries publishing lists of domestic PEPs is not required under the FATF standards at all. 

FATF goes further, noting that with elections, cabinet changes, and routine turnover of public officials happening almost daily worldwide, these lists cannot be relied upon as consistently up to date. This contrasts with sanctions data, where a single government body publishes and maintains one authoritative list.

Transliteration variance is also heavier in PEP data than in sanctions data, because PEP coverage spans a far broader set of jurisdictions and naming conventions than the more curated sanctions lists. Common names dominate the PEP corpus in a way they don't on a list of a few thousand specifically designated individuals. 

And family and close-associate records inflate the dataset substantially, since PEP screening scope typically extends well beyond the officeholder to relatives and business associates whose relationship to the PEP is often loosely defined.

As a result, the list that carries the lower per-match consequence is the one generating the higher per-search noise. 

If you apply the same threshold to both, the higher-stakes list is either screened too loosely (because the threshold was tuned to keep PEP noise manageable) or the lower-stakes list generates an alert volume nobody can sustainably review. 

{{snippets-guide}}

Examples

This is what this may look like in practice with:

A payments firm screening millions of low-value transactions

At this volume, even a small percentage-point increase in false positive rate translates into an unsustainable review queue. A payments platform has strong reason to tune its sanctions threshold tightly around precision, because the transaction volume means even a well-calibrated setting generates meaningful absolute alert counts, while its PEP exposure (if it screens PEPs at the transaction level at all, which many payments firms don't) would need an even tighter setting or a shift to account-level rather than transaction-level PEP screening, because the noise problem worsen with volume the same way the sanctions problem does.

A B2B firm onboarding a few thousand customers a year

Low volume means the firm can afford a looser threshold that catches more potential matches, sanctions and PEP alike, because the absolute number of alerts a looser setting generates is still manageable for a compliance team reviewing a few thousand onboardings annually rather than millions of transactions. The consequence argument still holds, sanctions matches still deserve tighter scrutiny than PEP matches, but the volume argument that forces a payments firm toward precision doesn't apply with the same force here.

An insurtech screening at quote and again at claim

At quote stage, the firm is screening a large volume of applicants who will mostly never become customers, arguing for a threshold tuned toward not generating friction in a competitive, price-sensitive sales flow. At the claim stage, the same customer is now asking the firm to pay out money, a moment with a materially different risk profile and a much smaller volume of events, arguing for a more conservative threshold applied to a re-screen at the point of payment. A single threshold applied identically at both points in the policy lifecycle is optimized for neither moment.

{{snippets-case}}

A Threshold Is a Number Plus a Rationale and a Revisit Date

The practical takeaway is not "use this specific number for sanctions and this one for PEP." OFAC has already said, correctly, that no such universal number exists, and FATF's own guidance confirms why PEP data in particular resists a fixed setting. 

The takeaway here is that a defensible threshold has three components: the number itself, a written rationale tied to the specific risk profile it's meant to address (list type, use case, volume), and a date to revisit it as that risk profile changes.

Our Sanctions Screening Guide covers how to build threshold calibration into a broader screening implementation from the start.

sanctions.io is a highly reliable and cost-effective solution for real-time screening. AI-powered and with an enterprise-grade API with 99.99% uptime are reasons why customers globally trust us with their compliance efforts and sanctions screening needs.

To learn more about how our sanctions, PEP, and criminal watchlist screening service can support your organisation's compliance program: Book a free Discovery Call.

We also encourage you to take advantage of our free 7-day trial to get started with your sanctions and AML screening (no credit card is required).

‍

New Sanctions Screening Guide
Download our free Sanctions Screening Guide
Download our FREE Sanctions Screening Guide and learn how to set up an effective sanctions screening process in your organization.
Download our FREE Sanctions Screening Guide and learn how to set up an effective sanctions screening process in your organization.
New Case Study
The Comprehensive, Unified Guide to Screening
Discover how technology companies streamline global sanctions compliance with sanctions.io
Our Unified Guide to Screening covers everything you need to know about setting up a comprehensive, unified screening process and workflow for the 3 ain pillars: sanctions, PEP and adverse media screening.
Basit Nayani
With experience in digital marketing, business development, and content strategy across mainland Europe, the UK and Asia, Basit Nayani joined the team as Head of Marketing & Growth in 2025.
Enjoyed this read?

Subscribe to our Newsletter right now and never miss again any new Articles, Guides and more useful content for your AML and Sanctions compilance.

Success! Your email has been successfully registered for our newsletter.
Oops! Something went wrong while submitting the form.