Join our Newsletter — 33% off our NHI Course

Why do relatives and close associates of politically exposed persons increase financial crime risk for banks and fintechs?

RCAs increase risk because they can be used to move funds indirectly when a PEP wants distance from the transaction. Their activity may look ordinary on its own, yet still be linked to bribery, corruption, or money laundering. That makes RCA screening an extension of PEP monitoring, not a separate box-ticking exercise. The key risk is hidden association, not obvious customer behaviour.

Why RCAs are a financial crime signal, not just an onboarding detail

relatives and close associates of politically exposed persons sit close to the same corruption and bribery exposure, but often without the obvious profile that would trigger a normal PEP review. That makes them useful intermediaries for moving value, disguising source of funds, or separating the PEP from the visible transaction path. The risk is relationship-based concealment, not unusual transaction behavior.

For banks and fintechs, the practical issue is that RCA activity can look individually legitimate while still inheriting the risk context of the politically exposed person. Screening has to treat the relationship as a material signal because the financial crime model is often indirect, not overt.

How hidden association changes the control problem

RCA risk matters because it breaks a common assumption in customer due diligence: that the account holder’s own profile is enough to explain the transaction. In practice, an apparently ordinary spouse, adult child, business partner, or close associate may be the nominal actor in a flow that really belongs to the PEP’s network. That is why RCA review is part of customer risk assessment, beneficial ownership analysis, and source-of-funds scrutiny.

When the relationship is missed, the institution may understate the customer’s true risk rating and set monitoring thresholds too loosely. That creates a gap between the visible customer and the concealed economic beneficiary.

For institutions that need a regulatory baseline, the FATF Recommendations are the main global reference for AML and KYC controls, including beneficial ownership, customer due diligence, and enhanced measures for higher-risk relationships. In the US, FinCEN guidance and reporting expectations shape how suspicious relationship patterns are escalated. In Europe, EBA AML/CFT Guidance supports similar risk-based treatment.

Why banks and fintechs must screen RCA relationships continuously

RCA exposure is dynamic. A person who was low-risk yesterday can become relevant tomorrow if a family member is appointed to public office, wins a procurement role, or comes under corruption investigation. That means the control is not a one-time onboarding check. It is an ongoing monitoring problem tied to adverse media, ownership changes, new counterparties, transaction patterns, and periodic refresh of risk data.

For fintechs especially, the operational challenge is scale. High-volume onboarding and lightweight payment journeys can make RCA links easy to miss unless screening, transaction monitoring, and case review are integrated. The right question is not whether the customer is a PEP, but whether the customer’s network creates the same bribery, corruption, or laundering exposure.

Where institutions want a practical fraud-and-AML lens, NHIMG’s The 52 NHI Breaches Report is useful as a reminder that hidden relationships and indirect abuse paths often matter more than the visible actor alone. For a banking-adjacent example of how credentialed access can support financial crime exposure, the Zacks Investment Research breach shows how compromised records and financial context can amplify downstream abuse.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

NIST SP 800-53 Rev 5 and CIS Controls v8 set the technical controls, while ISO/IEC 27001:2022 defines the regulatory obligations.

Framework Control / Reference Relevance
NIST SP 800-53 Rev 5 IA-2 — Identification and Authentication (Organizational Users) RCA screening depends on reliable user/customer identity assurance in higher-risk financial workflows.
AC-6 — Least Privilege Limits account abuse when a customer or associate is acting as an indirect conduit.
AU-6 — Audit Review, Analysis, and Reporting Transaction monitoring and suspicious-pattern review are central to detecting hidden association risk.
Recommendation — Strengthen identity proofing and authentication before allowing higher-risk account activity. Restrict account permissions to the minimum needed for the declared business purpose. Correlate logs and alerts to detect indirect movement patterns tied to high-risk relationships.
ISO/IEC 27001:2022 A.5.15 — Access control Access governance supports limiting who can move value or initiate sensitive financial actions.
A.5.16 — Identity management Identity records must capture relationship context when an account is linked to a PEP network.
A.5.17 — Authentication information Strong authentication reduces abuse when high-risk accounts are used as laundering channels.
Recommendation — Apply access control rules that reflect customer and account risk classification. Maintain identity records that support reliable PEP and RCA relationship checks. Protect authentication information and require stronger controls for high-risk accounts.
CIS Controls v8 CIS-5 — Account Management Account lifecycle controls help ensure risky relationships are reviewed, limited, and revoked when needed.
CIS-8 — Audit Log Management Logging and review are essential for spotting indirect transactions and concealment patterns.
Recommendation — Review and revoke high-risk account access when relationship or risk status changes. Retain and review logs to support investigation of suspicious relationship-driven activity.

Practitioner Guidance

What to prioritise: Treat RCA screening as part of the same high-risk customer workflow used for PEPs, not as a separate list. If the relationship is plausible and the funds are material, escalate the case to enhanced due diligence rather than relying on standard KYC.

What to verify: Confirm the relationship evidence, expected economic purpose of the account, source of wealth or source of funds, and whether the RCA has independent activity consistent with the profile. If the explanation depends on a vague business rationale, that is usually not enough.

What to measure: Watch for RCA accounts with unusual funding routes, third-party transfers, rapid pass-through movement, or repeated links to the same public official network. Those patterns are often more informative than the customer’s stated occupation.

Practitioner takeaway: The control objective is to identify hidden proximity to political power early enough to stop the institution from mistaking indirect corruption exposure for ordinary retail or SME activity.