Unusual activity can trigger enhanced due diligence, management review, and closer ongoing monitoring. Signs include sudden spikes in transfer volume, new counterparties, offshore routes, or business activity that does not match the customer profile. These changes are not automatically suspicious, but they should prompt investigation and clear documentation. The purpose is to distinguish genuine change from behaviour that may conceal illicit financial movement.
Why a Relative’s Pattern Change Matters in AML Monitoring
When a politically exposed person’s relative starts transacting in a way that no longer fits the expected profile, the issue is not the relationship alone but the change in behaviour. That shift can indicate a legitimate change in activity, or it can be an attempt to move value through a connected person who may attract less scrutiny. The key question is whether the pattern now fits the known risk profile.
In practice, firms should treat the family link as a risk factor that raises the baseline for review, but not as proof of wrongdoing. The relative’s activity becomes more meaningful when it introduces new geographies, counterparties, cash-like movement, circular flows, or other features that do not align with the stated source of funds or expected account purpose.
Institutionally, this is a customer-risk assessment problem as much as a transaction-monitoring problem. A relative can be a normal customer with ordinary activity, but once the pattern changes, the relationship to a PEP can justify deeper scrutiny, tighter thresholds, and faster escalation to a human reviewer.
What Changes in the Review Process
Once unusual behaviour appears, the response usually moves from routine monitoring to enhanced due diligence, management attention, and a fuller evidence check against the customer file. That means comparing the new pattern with onboarding information, expected transaction purpose, source of wealth or source of funds data, and any prior alerts that were already closed with explanations.
The investigation should focus on whether the new activity is coherent, explainable, and documented. For example, a new business line, a change in payment geography, or the sudden use of multiple counterparties may be legitimate, but only if the supporting records make that change credible. Without that support, the pattern remains an unresolved exception rather than a cleared anomaly.
This is also where consistent documentation matters. The reviewer needs to record why the activity was judged normal or abnormal, what evidence was checked, and whether any additional controls were placed on the relationship. That record is important for internal governance and for showing that the alert was handled proportionately.
How to Distinguish a Real Change from Concealment
The core analytical task is separating ordinary life changes from behaviour that could mask illicit movement. A genuine change often has a clear operational reason, such as a new employer, relocation, inheritance, sale of an asset, or a newly explained business relationship. Concealment is more likely when the activity appears fragmented, layered, routed through opaque channels, or inconsistent with the customer’s stated profile.
Signals that deserve closer attention include sudden volume spikes, first-time offshore transfers, unexplained third-party payments, repeated transfers just below reporting or internal review thresholds, and counterparties that have no obvious connection to the customer’s known activity. None of these signs proves misconduct on its own, but together they can create a stronger suspicion that merits escalation.
For a relative of a PEP, the practical standard is not “is there any unusual activity,” but “does the new pattern make sense in context and can it be supported by evidence?” That distinction prevents both overreaction and complacency.
Risk and Threat Considerations
A PEP’s relative can become an attractive conduit because the relationship may create reputational sensitivity, indirect access, or the assumption that lower visibility is available. The risk is that ordinary-looking accounts are used to layer funds, obscure beneficial ownership, or route transactions away from the most heavily scrutinised account holder.
Failure mechanism: Unusual patterns may reflect placement, layering, or the use of nominees and connected parties to disguise the origin, destination, or purpose of funds while still appearing superficially consistent with the customer’s profile.
Impact: If the change is not investigated, the firm can miss suspicious activity, weaken sanctions or AML controls, and allow connected-party risk to spread across accounts that appear separately low risk.
Standards & Framework Alignment
This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.
NIST SP 800-53 Rev 5 and NIST CSF 2.0 set the technical controls, while ISO/IEC 27001:2022 defines the regulatory obligations.
| Framework | Control / Reference | Relevance |
|---|---|---|
| NIST SP 800-53 Rev 5 | AU-6 — Audit Record Review, Analysis, and Reporting | Relevant because unusual transaction patterns require review, escalation, and documented handling. |
| AC-6 — Least Privilege | Relevant because higher-risk customers should face tighter access to sensitive transaction capabilities and approvals. | |
| Recommendation — Review alerts promptly and document the rationale for clearing or escalating the case. Limit high-risk transaction privileges and require additional approval for exceptions. | ||
| ISO/IEC 27001:2022 | A.5.18 — Access rights | Relevant where unusual behaviour justifies tighter control over who can authorise or override monitoring decisions. |
| Recommendation — Restrict override and approval rights for higher-risk cases to authorised reviewers. | ||
| NIST CSF 2.0 | GV.RM-01 — Risk Management Strategy | Relevant because connected-party activity must be assessed within a formal customer-risk model. |
| DE.CM-01 — Anomalies and Events Monitored | Relevant because the trigger here is an anomalous transaction pattern that needs monitoring. | |
| Recommendation — Classify connected-party alerts within the institution’s risk strategy and escalation thresholds. Monitor for transaction anomalies that deviate from expected customer behaviour. | ||
Practitioner Guidance
What to verify: Compare the new activity against the original customer profile, declared source of funds, expected counterparties, and normal geography of payments. If the explanation depends on a new business, asset sale, or family arrangement, verify that the evidence matches the timing and scale of the transactions.
Decision rule: If the pattern is explainable but materially different, keep the case in enhanced monitoring rather than closing it as routine. If the activity is inconsistent, fragmented, or poorly supported, escalate for review and consider whether the relationship itself warrants a higher-risk classification.
Practitioner takeaway: The right response is to test the new behaviour against the known customer story, not to treat the PEP connection as automatic suspicion or the family relationship as a reason to downplay the alert.
Related resources from NHI Mgmt Group
- How do organisations reduce the dwell time of exposed credentials at scale?
- How should security teams respond when API access logs start showing abnormal login activity and unusual data access patterns?
- What happens when transaction authorization is added after account takeover patterns are already established?
- What happens when a patch management rollout starts showing more non-compliant devices?
Deepen Your Knowledge
Reviewed and updated by the NHIMG editorial team on September 29, 2026.
NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org