Skip to content
Antonio Membrides Espinosa edited this page Jun 5, 2026 · 1 revision

HRPC: High-Risk Person and Counterparty Categories

1. Purpose

HRPC defines the customer and counterparty categories that may require enhanced scrutiny where fraud detection, Anti-Money Laundering (AML), Know Your Customer (KYC), sanctions, and Enhanced Due Diligence (EDD) intersect.

HRPC serves as a common reference for the Fraud Detection System (FDS) and related control functions when identifying customer or counterparty profiles that warrant elevated review, prioritization, escalation, or additional evidence gathering. It should also guide engineering specifications, workflow design, access control decisions, detection logic, and escalation paths.

HRPC does not treat these categories as proof of fraud by themselves. Instead, they are used as contextual risk indicators, classification criteria, and governance triggers that support proportionate decision-making.

2. Relationship to FDS concepts

Fraud Detection System (FDS) concepts define how the fraud function operates, including roles, access model, detection logic, investigation workflow, and security controls.

HRPC complements those concepts by defining high-risk person and counterparty categories that may influence:

  • alert prioritization
  • enhanced due diligence
  • investigative depth
  • case routing
  • fraud and financial crime escalation
  • sanctions and watchlist review
  • source-of-funds and source-of-wealth checks

In practical terms:

  • Fraud Detection System (FDS) concepts explain how fraud is detected and investigated
  • HRPC explains which person and counterparty categories require enhanced scrutiny beyond standard fraud indicators

3. Guiding principles

The HRPC framework should be applied using the following principles:

  • Risk-based application: categories should trigger proportionate review rather than automatic adverse decisions
  • Corroboration: no HRPC category should be used as the sole basis for confirming fraud
  • Least privilege: access to HRPC-related data should be aligned to operational need
  • Segregation of duties: screening, investigation, escalation, and oversight should remain clearly separated
  • Explainability: any action influenced by an HRPC factor should be documented and auditable
  • Compliance alignment: HRPC usage should remain aligned to Anti-Money Laundering (AML), Know Your Customer (KYC), sanctions, privacy, and customer treatment requirements

4. HRPC categories

4.1 Politically Exposed Person

A Politically Exposed Person (PEP) is an individual who holds, or has held, a prominent public role, such as a politician, senior government official, senior judicial or military official, or an executive of a state-owned enterprise. The category also includes close family members and close associates where required by policy or regulation.

Why this matters

PEPs may present elevated corruption, bribery, influence, and abuse-of-position risk. In an FDS context, PEP status should not be treated as a direct fraud signal, but it may justify enhanced review where suspicious activity, unusual flows, beneficial ownership complexity, or politically connected counterparties are involved.

Typical treatment

  • enhanced due diligence
  • source-of-funds and source-of-wealth review
  • increased scrutiny of unusual counterparties or transaction patterns
  • escalation to compliance or AML where required

4.2 Special Interest Person

A Special Interest Person (SIP) is a person or entity flagged through internal or external intelligence due to potential links to organized crime, sanctions evasion, terrorism financing, serious financial crime, or other forms of elevated concern.

This label should only be used if it exists in the institution's internal taxonomy and is supported by a formal definition and governance process.

Why this matters

SIP status may be relevant when fraud monitoring intersects with external intelligence, organized fraud, mule activity, sanctioned networks, or criminal facilitation.

Typical treatment

  • mandatory validation of watchlist or intelligence source
  • enhanced case routing
  • restricted handling and controlled visibility
  • escalation to financial crime, sanctions, or security teams as appropriate

4.3 High Net Worth Individual

A High Net Worth Individual (HNWI) is a wealthy individual whose financial profile, holdings, transaction patterns, or legal structures may be more complex than those of a standard retail customer.

Why this matters

Wealth alone is not a fraud indicator. However, HNWIs may require enhanced review where there are opaque ownership structures, unusual wealth flows, complex cross-border activity, nominee relationships, or insufficient transparency around source of funds.

Typical treatment

  • enhanced contextual review only where justified
  • source-of-funds validation where required
  • closer review of complex ownership or payment structures
  • no automatic elevation based solely on wealth

4.4 Ultimate Beneficial Owner

An Ultimate Beneficial Owner (UBO) is the natural person who ultimately owns or controls a legal entity, arrangement, or account structure.

Why this matters

UBO analysis is highly relevant to fraud, shell-company misuse, mule networks, nominee arrangements, and the concealment of beneficial ownership. In the FDS context, UBO opacity, inconsistency, or unusual control relationships can materially affect risk assessment.

Typical treatment

  • verification of beneficial ownership
  • review of layered or opaque legal structures
  • graph analysis across linked entities and accounts
  • escalation where ownership complexity appears inconsistent with the stated business purpose

4.5 Individuals or entities linked to terrorism

This category covers persons or entities linked to terrorism, terrorism financing, or related facilitation activity, including those identified through sanctions lists, law enforcement intelligence, or regulatory sources.

Why this matters

This is primarily a financial crime and compliance trigger rather than a standard retail fraud category. However, it may be relevant in an FDS when suspicious flows, mule behavior, rapid movement of funds, or linked-party networks overlap with broader financial crime concerns.

Typical treatment

  • immediate escalation under financial crime procedures
  • controlled case handling
  • sanctions and watchlist validation
  • restricted operational visibility on a need-to-know basis

4.6 Persons in high-risk jurisdictions

This category includes persons, entities, counterparties, or transaction relationships tied to jurisdictions with weak AML or counter-terrorist financing controls, elevated corruption exposure, sanctions exposure, or significant financial crime risk.

Why this matters

Geographic exposure is a contextual risk factor. It should not be treated as evidence of wrongdoing on its own. In combination with suspicious activity, however, it may justify deeper review, especially where transactions are complex, cross-border, unusual for the customer, or linked to opaque structures.

Typical treatment

  • geographic risk weighting
  • enhanced transaction review
  • source-of-funds or counterparty validation
  • escalation where jurisdictional risk coincides with other material signals

4.7 Sanctioned persons or entities

This category includes persons, organizations, vessels, legal entities, or counterparties subject to restrictions under applicable sanctions frameworks.

Why this matters

Sanctions exposure is a material financial crime trigger and may require immediate handling outside normal fraud workflows. It is especially relevant where the FDS encounters blocked parties, indirect matches, related-party exposure, or suspicious circumvention behavior.

Typical treatment

  • screening and match validation
  • immediate escalation under sanctions procedures
  • restricted handling of case data
  • decision-making based on formal sanctions governance rather than fraud operations alone

4.8 Individuals with a history of financial fraud

This category includes persons or entities previously involved in confirmed or substantiated financial fraud, including fraud against financial institutions, payment abuse, account takeover schemes, identity fraud, chargeback abuse, embezzlement, or related misconduct.

Why this matters

This is one of the strongest categories for direct fraud relevance. Prior confirmed fraud can materially affect prioritization, risk scoring, network analysis, and enhanced monitoring.

Typical treatment

  • elevated monitoring
  • stronger authentication or challenge controls
  • relationship analysis across linked accounts, devices, and counterparties
  • lower tolerance for unexplained anomalies when combined with new suspicious signals

4.9 Clients or counterparties with suspicious transaction patterns

This category covers customers, beneficiaries, merchants, or other parties showing transaction behavior that is unusual, unexplained, inconsistent with profile, or indicative of structuring, mule activity, layered movement, or cross-border irregularity.

Why this matters

This is a behavioral category rather than a static customer category. It is directly relevant to the FDS and often serves as an operational bridge between fraud monitoring and AML transaction monitoring.

Typical treatment

  • alert generation and prioritization
  • deeper behavioral review
  • peer-group or baseline comparison
  • escalation when patterns cannot be reasonably explained

5. Classification dimensions

HRPC categories can be organized across four practical dimensions.

5.1 By risk level

High risk

  • Politically Exposed Persons (PEPs) where policy or regulation requires enhanced treatment
  • Special Interest Persons (SIPs) or equivalent high-concern subjects
  • individuals or entities linked to terrorism
  • sanctioned persons or entities
  • persons in high-risk jurisdictions when combined with material activity risk
  • individuals with confirmed history of financial fraud

Moderate risk

  • Ultimate Beneficial Owners (UBOs) with opaque or unusually complex ownership structures
  • High Net Worth Individuals (HNWIs) where wealth structure or transaction behavior lacks sufficient transparency
  • counterparties with unresolved suspicious patterns pending investigation

Low risk

  • customers and counterparties with transparent ownership, explainable transaction behavior, and no material adverse indicators

Risk level should always be adjusted by context, evidence, and control outcome. It should not be assigned solely from category label.

5.2 By regulatory and control context

Anti-Money Laundering (AML)

Relevant for exposure to money laundering, structuring, concealment of beneficial ownership, and movement of illicit funds.

Know Your Customer (KYC)

Relevant for customer identification, beneficial ownership, customer profile consistency, and expected activity validation.

Enhanced Due Diligence (EDD)

Relevant where enhanced due diligence is required, especially for Politically Exposed Persons (PEPs), sanctioned exposure, terrorism-related concerns, opaque structures, and unresolved high-risk patterns.

Sanctions

Relevant where persons, entities, or counterparties are directly or indirectly linked to restricted parties or prohibited jurisdictions.

Fraud

Relevant where categories materially change the probability, impact, pattern, or operational treatment of suspected fraud.

5.3 By identification source

Global lists and external data

  • sanctions lists
  • PEP databases
  • intelligence feeds
  • regulatory notices
  • adverse media or equivalent external screening sources where permitted

Transaction monitoring

  • unusual payment flows
  • cross-border irregularities
  • velocity anomalies
  • beneficiary risk
  • behavioral deviations

Manual review

  • ownership structure clarification
  • source-of-funds review
  • source-of-wealth review
  • entity relationship analysis
  • documentation validation

Network analytics

  • graph links to known fraudulent entities
  • shared device or contact attributes
  • linked beneficiaries
  • mule clusters
  • ring behavior

5.4 By nature of risk

Political exposure

  • PEPs
  • politically connected parties
  • state-owned enterprise relationships
  • politically exposed UBO structures

Criminal or illicit exposure

  • SIPs or equivalent high-concern subjects
  • sanctioned parties
  • terrorism-linked subjects
  • confirmed fraud actors

Structural or ownership opacity

  • UBO complexity
  • nominee structures
  • layered corporate ownership
  • legal entities with unclear control

Geographic risk

  • customers or counterparties operating in high-risk jurisdictions
  • cross-border patterns involving elevated-risk corridors

Behavioral risk

  • suspicious transaction patterns
  • unusual velocity, timing, amount, or destination behavior
  • patterns inconsistent with stated customer profile

6. How HRPC should be used in the FDS

The HRPC framework should support the FDS in a disciplined and limited way.

6.1 Appropriate uses

  • prioritizing alerts for review
  • increasing investigative depth
  • triggering EDD or source-of-funds checks
  • routing cases to compliance, AML, sanctions, or security functions
  • improving graph and linked-entity analysis
  • applying additional control steps to high-risk scenarios

6.2 Inappropriate uses

  • confirming fraud solely because a customer falls into an HRPC category
  • applying blanket adverse treatment without corroborating evidence
  • using wealth, geography, or political exposure as standalone proof of illegitimate activity
  • expanding access to sensitive HRPC information beyond operational need

6.3 Decisioning standard

Where an HRPC factor is present, the case decision should still be based on:

  • transactional evidence
  • behavioral evidence
  • identity confidence
  • device and channel indicators
  • linked-party analysis
  • source validation
  • prior case outcomes
  • documented rationale and approvals

7. Roles and review responsibilities

Role HRPC responsibilities
Level 1 (L1) Fraud Analyst identify visible HRPC flags, route correctly, avoid over-interpreting category labels
Level 2 (L2) Investigator assess relevance of HRPC indicators in full case context
Fraud Subject Matter Expert (SME) or Lead resolve complex overlaps between fraud, Anti-Money Laundering (AML), sanctions, and networked abuse
Compliance or Anti-Money Laundering (AML) Investigator assess regulatory significance and Enhanced Due Diligence (EDD) implications
Security Auditor verify appropriate use, access control, evidence trail, and escalation governance
Fraud Strategy Analyst ensure HRPC factors are used proportionately in rules, prioritization, and analytics
Platform or Access Administrator enforce controlled visibility and least-privilege access

8. Data and access considerations

HRPC-related data may include:

  • customer and counterparty classification flags
  • watchlist or screening outcomes
  • ownership and control information
  • geographic risk indicators
  • intelligence-derived status indicators
  • prior confirmed fraud history
  • suspicious transaction pattern summaries
  • case escalation history

Access to this data should be controlled as follows:

  • Level 1 (L1) users should generally see only the minimum indicators necessary for triage
  • investigators should see detailed context only when needed to assess the case
  • compliance and Anti-Money Laundering (AML) teams may require deeper visibility into screening and Enhanced Due Diligence (EDD) evidence
  • auditors should have read-only oversight access
  • administrators should not access customer intelligence content unless required for controlled operational support

9. Governance requirements

A mature HRPC framework should include:

  • formal definitions approved by risk, compliance, and fraud governance
  • documented source systems and list provenance
  • quality checks for classification accuracy
  • time-bound review of category assignments
  • appeal, correction, or exception handling where appropriate
  • auditability for changes, use, and access
  • clear ownership across fraud, AML, compliance, and security functions

If a category such as SIP is used internally, the institution should maintain a specific definition, approval path, data source standard, and handling procedure.

10. Key control statement

HRPC categories are not fraud conclusions. They are structured indicators that help determine whether a person or counterparty requires enhanced scrutiny, deeper investigation, or cross-functional escalation.

The value of the HRPC framework is not in labeling customers. Its value is in improving prioritization, consistency, governance, and defensibility across fraud and financial crime review processes.

Appendix A. Reference paragraphs for the Fraud Detection System (FDS) core content

Option 1. Short reference paragraph

Certain customer and counterparty categories may require enhanced scrutiny where fraud monitoring intersects with Anti-Money Laundering (AML), Know Your Customer (KYC), sanctions, and Enhanced Due Diligence (EDD) controls. These categories are defined in HRPC, which provides the classification framework for high-risk person and counterparty profiles, together with associated escalation and review considerations.

Option 2. Stronger governance-oriented paragraph

Where customer or counterparty risk extends beyond standard fraud indicators, the Fraud Detection System (FDS) should reference the HRPC framework to support consistent classification, prioritization, escalation, and evidentiary review. HRPC defines high-risk person and counterparty categories, including regulatory, behavioral, ownership, and geographic risk dimensions, and clarifies how these factors should be used in a proportionate and controlled manner within fraud and financial crime processes.

Option 3. Control-focused paragraph for the security and audit sections

The FDS should incorporate controlled references to the HRPC framework when alerts, cases, or investigations involve elevated customer or counterparty risk beyond ordinary fraud signals. This ensures that categories such as politically exposed persons, beneficial ownership complexity, sanctions exposure, fraud history, and high-risk jurisdictional links are handled consistently, escalated appropriately, and subject to auditable governance and least-privilege access controls.

Clone this wiki locally