Sanctions, PEP & Adverse Media Screening: A 2026 Guide for Indian Payment Companies
Date Published

Most compliance failures at Indian payment companies do not happen at onboarding. They happen afterward, when a merchant that cleared KYC six months ago changes ownership, a customer's name starts appearing in a fraud investigation, or a beneficial owner is added to a sanctions list the week after account opening. Onboarding screening catches the obvious cases. It says nothing about what happens next. This is the gap AML screening, run continuously rather than once, is built to close.
For Payment Service Providers (PSPs) operating under RBI's PA-PG framework, this gap is where regulatory exposure actually accumulates. A merchant who passed screening on day one is not the same risk on day 180. Ownership structures shift, directors change, new adverse media surfaces, and sanctions lists are updated daily by design. Static, point-in-time screening treats risk as something you check once. RBI's Master Direction on KYC and the PMLA, 2002 treat it as something you monitor continuously, and anti-money laundering (AML) screening is the operational mechanism through which that continuous obligation gets discharged.
This guide breaks down the three screening disciplines that sit at the center of AML compliance for payments: sanctions screening, PEP screening, and adverse media screening. Each answers a different question, draws on different data, and fails in different ways when run as a one-time gate instead of a continuous process.
What Is Sanctions Screening
Sanctions screening checks whether a customer, merchant, director, or beneficial owner appears on a government or multilateral sanctions list. In India, two lists carry direct legal force for every regulated entity. The United Nations Security Council's consolidated list, implemented domestically through Section 51A of the Unlawful Activities (Prevention) Act, 1967, and the Ministry of Home Affairs' own schedules of banned organisations and individuals. RBI's Master Direction on KYC requires REs to verify the UNSCR 1718 list daily and to ensure no account is held in the name of any individual or entity appearing on these lists.
Beyond the mandatory domestic lists, payment companies with cross-border exposure, particularly PSPs handling export-import transactions or foreign remittances, typically also screen against OFAC's Specially Designated Nationals list, the EU consolidated list, and UK OFSI sanctions. These are not mandated by RBI for purely domestic operations, but any PSP processing cross-border payments effectively inherits counterparty exposure to them.
The operational challenge is not access to the lists. It is matching. Names transliterated from Arabic, Cyrillic, or other scripts produce dozens of valid spelling variants. A common Indian surname can generate hundreds of false positives against a global list. Fuzzy matching logic, phonetic algorithms, and alias resolution determine whether a screening system produces a manageable alert queue or one that compliance teams start ignoring out of fatigue. Poor matching does not just waste analyst hours. It buries the one true positive in noise.
What Is PEP Screening
A Politically Exposed Person is someone who holds, or has held, a position of public trust that creates elevated exposure to bribery and corruption risk. RBI's amended Master Direction on KYC (2024) defines PEPs as individuals entrusted with prominent public functions by a foreign country, including heads of state or government, senior politicians, senior government, judicial, or military officers, senior executives of state-owned corporations, and important political party officials. The definition extends to family members and close associates of PEPs, who inherit the same due diligence requirements.
Payment companies routinely underestimate PEP risk for two reasons. First, the RBI definition is foreign-PEP-anchored, so teams assume domestic political exposure falls outside scope. In practice, domestic PEPs and their associates still warrant risk-based scrutiny under general high-risk customer categorization, even where they sit outside the strict regulatory definition. Second, PEP status is not static. A regional politician can become a cabinet minister. A merchant's director can be appointed to a public sector board eighteen months after onboarding. Screening once, at KYC, tells you nothing about a status that changes with every election cycle and reshuffle.
Where a customer or beneficial owner is identified as a PEP, RBI requires REs to apply a risk-based approach, obtain senior management approval for the relationship, and take reasonable measures to establish source of funds and source of wealth. These are not one-time checkbox actions. They require an ongoing relationship management posture that most payment companies have not built for merchant portfolios running into the hundreds of thousands.
What Is Adverse Media Screening
Adverse media screening, also called negative news screening, checks whether a customer or merchant is associated with reported criminal activity, regulatory action, fraud allegations, terrorism financing, or other reputational red flags in publicly available media. Unlike sanctions and PEP screening, there is no single authoritative list. The universe is every credible news source, regulatory enforcement database, court record aggregator, and investigative report that might surface a name.
This is also where screening programs fail most quietly. Keyword matching, the most common approach, flags any article containing a customer's name near words like "fraud," "arrest," or "investigation." It cannot distinguish between a merchant who is the subject of a fraud investigation and a merchant who is quoted commenting on someone else's fraud case, or a common name that happens to share a headline with an unrelated criminal matter. The result is either a flood of irrelevant hits that gets deprioritized, or worse, a program tuned so conservatively that it misses genuine risk signals buried in language that does not match the keyword list.
Effective adverse media screening requires category classification (financial crime, violence, regulatory sanction, terrorism, and so on), source credibility weighting, and entity resolution that can tell two people with the same name apart. It is the least standardized of the three disciplines and, for that reason, the one most likely to be underbuilt.

Sanctions vs PEP vs Adverse Media: A Comparison
RBI and PMLA Obligations, Mapped
RBI's Master Direction on KYC and the PMLA together form the legal backbone for all three screening types, though each traces to a slightly different provision.
Sanctions screening is the most explicitly codified. REs are required under the MD on KYC to verify the UNSCR 1718 sanctions list daily and to ensure customer identities do not match names on lists referenced in Chapter IX of the direction. Matches must be reported to FIU-IND and the Ministry of Home Affairs, with accounts frozen under the procedure prescribed in the UAPA Order. A newer provision, Section 54A, specifically requires REs to deploy current technology for effective name-screening implementation, an explicit regulatory nod toward automation over manual list-checking.
PEP obligations sit within the customer due diligence framework of the MD on KYC. Where a customer or beneficial owner is a PEP, REs must apply enhanced due diligence, obtain senior management sign-off, and establish source of funds. This is reinforced by the risk-categorization requirements under PMLA, which direct reporting entities to treat PEP relationships as inherently higher risk requiring ongoing monitoring rather than static classification.
Adverse media obligations are less explicit in statute but flow from the broader risk-based due diligence mandate under Section 12AA of the PMLA, which requires reporting entities to assess a client's financial position, ownership, and the purpose behind a transaction before specified transactions, and to increase monitoring where a relationship appears suspicious. Section 12 further requires REs to maintain records enabling reconstruction of individual transactions for five years, which in practice means adverse media hits, investigation outcomes, and escalation decisions all need to be retained and auditable.
For PSPs specifically, these obligations sit on top of RBI's PA-PG guidelines, which require merchant due diligence at onboarding and ongoing merchant risk monitoring, not a single point-in-time check.
Why One-Time Screening Fails in a Payments Context
A bank's static customer base changes slowly. A PSP's merchant base does not. New merchants onboard daily, existing merchants change beneficial owners, directors rotate, and business models shift, sometimes without the PSP ever being informed through a formal update.
Three specific patterns explain why point-in-time screening is structurally inadequate for payments:
Merchant risk drift. A merchant onboarded as a low-risk retail business can pivot into a higher-risk category, cross-border transactions, or a business model closer to money services, without triggering any re-KYC event unless the PSP is actively monitoring for it.
Ownership and beneficial ownership changes. A change in shareholding or directorship can introduce a sanctioned individual, a newly designated PEP, or a director named in a fresh fraud investigation into a merchant relationship that was clean at onboarding. Static screening has no mechanism to catch this unless the merchant proactively discloses the change, which rarely happens.
Real-time transaction context. Sanctions lists are updated the moment a designation is made, not on a quarterly review cycle. A merchant clean at onboarding can appear on a fresh UNSC or MHA update the following week. Without daily list verification, as RBI's own MD on KYC requires, that exposure sits undetected until the next scheduled review, if one exists at all.
What Continuous, Risk-Tiered Screening Looks Like Operationally
Continuous screening is not "screen more often." It is a different architecture built around three operational components.
Real-time alerting on new hits. Rather than re-running the entire customer base periodically, the screening system ingests list and media updates continuously and flags only the customers or merchants newly implicated, since new entries or amendments are what actually change exposure day to day.
Event-based profile refresh. Certain triggers, a beneficial ownership change, a shift in transaction volume or geography, a director update, should automatically re-open a screening cycle for that specific merchant rather than waiting for the next scheduled review. This ties screening to actual risk events instead of an arbitrary calendar.
Risk-tiered scoring with audit trail. Not every merchant needs the same screening intensity. A risk-based framework, tiering merchants by transaction volume, geography, MCC category, and cross-border exposure, lets compliance teams apply deeper, more frequent screening to genuinely higher-risk relationships while avoiding alert fatigue on low-risk, high-volume segments. Every screening decision, match disposition, and escalation needs to be logged in a way that reconstructs the full decision trail for regulator review, consistent with the five-year record-keeping requirement under PMLA Section 12.
This is also where merchant due diligence connects to adjacent risk disciplines. A merchant flagged through adverse media screening often correlates with patterns picked up through mule account detection or anomalies later confirmed through UPI fraud detection. Screening does not operate in isolation from transaction monitoring, and the strongest programs treat the two as feeding each other rather than running as separate workflows.
Building vs Buying AML Screening Infrastructure
The build-vs-buy decision for sanctions, PEP, and adverse media screening usually comes down to coverage breadth, not core logic. Matching algorithms are a solved problem at this point. What differentiates AML screening infrastructure in practice is the number of sanction programs and country lists covered, the depth of PEP databases across jurisdictions, and the number and quality of adverse media sources ingested, delivered through an AML screening API that can sit inside an existing onboarding and monitoring stack rather than as a bolt-on tool.
IDfy's AML, PEP & Watchlist screening solution is built around exactly this coverage model: 360+ sanction programs and blacklists spanning 75+ countries, PEP screening across 200+ countries, and adverse media records drawn from 20+ sources, paired with real-time alerts for new hits or profile changes and risk-tiered scoring backed by a full audit trail. That combination, broad list and media coverage plus continuous re-screening rather than a single onboarding pass, is what turns AML screening from a one-time gate into an ongoing signal, closer to what RBI's own regulatory language, daily list verification, event-driven due diligence, already assumes payment companies are doing.
For PSPs evaluating vendors, the more useful question is rarely "does this API return matches." It is "how current is the underlying list data, how many false positives will this generate against my merchant base, and can this system re-screen automatically when a merchant's profile changes." Those three questions determine whether AML screening becomes a genuine risk control or a compliance formality that happens once and is never revisited.
This connects directly to broader merchant due diligence practices, including merchant due diligence and MCC prediction and the onboarding controls required under RBI's PA-PG merchant onboarding framework. Screening is one layer in a stack that also has to account for the wider landscape of payment fraud in India, which increasingly originates from relationships that looked clean at the point of onboarding.
Conclusion
Sanctions, PEP, and adverse media screening answer three different questions: is this party designated, is this party a corruption risk by virtue of public office, and is this party associated with reported wrongdoing. Treating them as interchangeable, or as three boxes to tick once at onboarding, misses the point of why RBI and PMLA require AML screening in the first place. Merchant risk in payments does not stay still after KYC clears. Ownership changes, sanctions lists update daily, and adverse media appears on its own schedule.
AML, PEP & watchlist screening built for continuous compliance combines broad list coverage, sanction programs across multiple countries, PEP databases, adverse media sources, with real-time alerting and risk-tiered scoring, so that screening functions as an ongoing signal rather than a one-time gate. For compliance and risk teams at Payment Service Providers (PSPs), that shift, from static check to continuous system, is what actually closes the gap between passing KYC and staying compliant.
FAQs
- What is sanctions screening in banking and payments?
Sanctions screening is a core component of AML screening. It checks customers, merchants, and beneficial owners against government and multilateral sanctions lists, such as the UNSC consolidated list implemented via UAPA Section 51A, to ensure no account or transaction relationship exists with a sanctioned individual or entity.
- What is a PEP (Politically Exposed Person) in banking compliance?
Under RBI's Master Direction on KYC, a PEP is an individual entrusted with a prominent public function by a foreign country, including heads of state, senior politicians, senior government, judicial, or military officials, senior state-owned enterprise executives, and important political party officials. Family members and close associates are covered by the same due diligence requirements.
- What is adverse media screening and why does it matter for AML?
Adverse media screening checks publicly available news, enforcement records, and court data for reported associations between a customer and financial crime, fraud, terrorism financing, or other reputational risk. It matters because sanctions and PEP lists capture designated individuals, while adverse media often surfaces emerging risk before any formal designation exists.
- Is sanctions screening mandatory under RBI/PMLA rules in India?
Yes. RBI's Master Direction on KYC mandates daily verification of the UNSCR 1718 sanctions list and requires REs to ensure no customer matches names on lists referenced in the direction, with matches reported to FIU-IND and the Ministry of Home Affairs under the UAPA Order.
- How often should PEP and sanctions screening be refreshed post-onboarding?
Sanctions list verification against the UNSC 1718 list is required daily under RBI's MD on KYC. PEP and adverse media status should be refreshed continuously, either through real-time list ingestion or event-based triggers tied to ownership changes, transaction pattern shifts, or periodic risk-based review cycles, rather than left to annual or onboarding-only checks.
- What's the difference between one-time screening and continuous monitoring?
One-time screening checks a customer against sanctions, PEP, and adverse media data at a single point, typically onboarding. Continuous monitoring re-screens against updated lists and new media on an ongoing basis and re-triggers deeper review when specific risk events occur, such as beneficial ownership changes or new adverse findings.
See how IDfy's AML, PEP & Watchlist screening fits into a risk-tiered compliance stack built for RBI-regulated payment companies.
Onboarding checks aren't enough. Discover how merchant category drift happens within 60 days—and why continuous monitoring is critical.
Discover what CPV means for payment aggregators, how digital CPV works, and what to evaluate before switching your merchant verification stack in 2026.