Relatives and Close Associates are family members, business partners, and other nearby connections of a Politically Exposed Person. They are often treated as higher risk because access to a PEP’s influence, resources, or network can be used to conceal ownership, move funds, or bypass controls. Screening them helps institutions see risk beyond the named individual.
Expanded Definition
Relatives and Close Associates, often abbreviated as RCA in anti-financial crime programs, extends the risk perimeter around a Politically Exposed Person by capturing family members, business partners, and other close personal or professional connections. The term is used to identify people who may not hold public office themselves, but who could plausibly benefit from proximity to influence, shared assets, or informal decision-making channels. Definitions vary across jurisdictions and supervisory guidance, so firms should treat the concept as a risk lens rather than a fixed relationship label.
In practice, RCA screening helps institutions detect indirect ownership, nominee arrangements, and relationship-based circumvention of due diligence controls. It also supports adverse media review, sanctions screening, and source-of-wealth investigation where a PEP connection creates elevated exposure. The concept is closely aligned with control-based governance approaches described in NIST SP 800-53 Rev 5 Security and Privacy Controls, especially where organisations need disciplined recordkeeping, access restrictions, and auditability around higher-risk entities. The most common misapplication is treating RCA as a static family-tree label, which occurs when firms ignore business ties, shared control, or repeated transactional links that can matter more than legal kinship.
Examples and Use Cases
Implementing RCA screening rigorously often introduces more manual review and false positives, requiring organisations to weigh broader coverage against onboarding speed and analyst capacity.
- A bank flags a PEP’s spouse as an RCA after discovering joint control over an offshore company that receives layered payments.
- An asset manager reviews a long-standing business partner who co-signs transactions and appears in ownership records for private investments.
- A fintech escalates a client’s adult child when adverse media and shared address data suggest indirect benefit from the PEP’s position.
- An insurer re-checks a nominee shareholder linked to a minister through repeated corporate filings and unexplained funding sources.
- A compliance team uses relationship mapping to distinguish a genuine supplier from a company effectively controlled through informal family influence.
RCA analysis is most effective when the data model can connect names, entities, addresses, beneficial ownership, and transaction patterns rather than relying on a single screening field. That matters because relationship risk is often contextual and evolves over time. Public-sector exposure, procurement influence, and fraud typologies all show how adjacent connections can create risk pathways that simple identity checks miss. Operational teams often need to pair screening with case notes, enhanced due diligence, and periodic refresh cycles to keep relationship status current.
Why It Matters for Security Teams
RCA controls matter because the risk is usually indirect and therefore easy to underestimate. If analysts screen only the named PEP, institutions can miss the entities most likely to move value, hide beneficial ownership, or front for prohibited activity. That creates weaknesses in customer due diligence, transaction monitoring, and escalation workflows. For security and governance teams, the core challenge is not just identifying a relationship, but proving why that relationship changes the risk posture and what evidence supports the decision. Regulatory programmes increasingly expect a defensible rationale, not a vague association flag.
RCA is also relevant to broader cyber and identity governance because relationship data often crosses systems, vendors, and case management tools. When those links are incomplete or stale, investigations slow down and control decisions become inconsistent. Teams should think about identity adjacency, not only primary identity, when deciding who can be trusted, monitored, or restricted. The value of the term becomes clearest after suspicious activity surfaces and investigators realise the primary subject was not the only useful node in the network. Organisational gaps typically become visible only after a suspicious payment, at which point RCA screening becomes operationally unavoidable to explain the exposure.
Standards & Framework Alignment
This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.
NIST CSF 2.0, NIST SP 800-53 Rev 5 and NIST SP 800-63 set the technical controls, while EU AI Act and DORA define the regulatory obligations.
| Framework | Control / Reference | Relevance |
|---|---|---|
| NIST CSF 2.0 | PR.AC-4 | Access and relationship risk mapping supports least-privilege decision-making. |
| NIST SP 800-53 Rev 5 | AU-2 | Audit events and traceable decisions are essential when documenting RCA-based escalation. |
| NIST SP 800-63 | Digital identity assurance informs how confidently a linked person is distinguished from the primary subject. | |
| EU AI Act | Risk-based governance logic aligns with controlled use of sensitive relationship data. | |
| DORA | Operational resilience depends on reliable screening and case handling for high-risk customers. |
Apply risk governance and human oversight when automated screening flags close associates.