Skip to main content
FATF's 2025 Standards Shift to Risk-Based ComplianceInternational Bodies & Standards
4 min readFor AML Compliance Officers

FATF's 2025 Standards Shift to Risk-Based Compliance

The Financial Action Task Force (FATF) revised its Recommendations in 2025, introducing a mandate that changes how you build your AML/CFT framework: identify your risks first, then allocate resources accordingly. This isn't a suggestion. It's the new compliance architecture.

What Changed

The FATF integrated most terrorist financing measures into its general AML/CFT framework, eliminating the separate Special Recommendations structure that had existed since 2001. Only three recommendations remain specific to terrorist financing: Recommendation 5 (criminalizing terrorist financing), Recommendation 6 (targeted financial sanctions related to terrorism and terrorist financing), and Recommendation 8 (preventing misuse of non-profit organizations).

The revision strengthens requirements for high-risk situations while allowing a more focused approach where risks are lower. The core shift: you must identify, assess, and understand your money laundering and terrorist financing risks before applying preventive measures. Your control framework should match the nature and level of those risks.

Key Findings

Risk assessment becomes the foundation. The updated standards require countries and financial institutions to conduct risk assessments before designing controls. This reverses the traditional approach of implementing uniform controls across all customer segments and products. If you're still applying the same Customer Due Diligence procedures to a correspondent banking relationship and a domestic retail checking account, you're not compliant with the risk-based approach.

Terrorist financing measures integrate into standard AML workflows. The FATF eliminated the conceptual separation between anti-money laundering and counter-terrorist financing. Your transaction monitoring rules, name screening protocols, and Customer Risk Rating models must now address both typologies within a single framework. This doesn't mean adding new systems; it means your existing controls must be designed to detect both money laundering and terrorist financing patterns.

Beneficial ownership transparency gets sharper focus. The revision emphasizes the availability and transparency of beneficial ownership information for legal persons and arrangements. This addresses a persistent gap: shell companies and complex ownership structures that obscure the natural persons who ultimately control funds. If your Beneficial Owner Identification process relies solely on customer attestations without independent verification mechanisms, you're exposed.

High-risk situations demand enhanced measures. The standards strengthen requirements when you identify elevated risk. This includes higher-risk jurisdictions, politically exposed persons, and complex cross-border transactions. The FATF explicitly rejects a one-size-fits-all approach. Your enhanced due diligence procedures for a PEP from a Grey List jurisdiction should be materially different from your standard due diligence for a domestic business customer.

Flexibility applies only within the FATF framework. The risk-based approach doesn't mean you can skip requirements. It means you calibrate the intensity of your controls based on assessed risk. You still need name screening for all customers, but the frequency of ongoing due diligence and the depth of source of funds inquiries should vary based on your Customer Risk Profile.

What This Means for Your Team

Your risk assessment methodology becomes the compliance blueprint. If your current risk assessment is an annual checkbox exercise that produces a generic "medium risk" rating for most customers, you don't have a foundation for risk-based controls. You need a methodology that produces differentiated risk ratings and drives specific control decisions.

You'll need to justify your control calibration. When a regulator asks why you conduct Periodic Review every 24 months for certain customer segments, your answer must reference specific risk factors in your assessment. "Industry standard" isn't an acceptable rationale under a risk-based framework.

Your terrorist financing controls can't be an afterthought. If your transaction monitoring rules focus exclusively on money laundering typologies (structuring, rapid movement of funds, round-tripping), you're missing the terrorist financing obligation. Terrorist financing often involves smaller amounts, legitimate sources, and different patterns than money laundering. Your rules must detect both.

Action Items by Priority

1. Audit your risk assessment methodology. Review how you identify and assess money laundering and terrorist financing risks across customer types, products, delivery channels, and geographic exposure. If your risk assessment doesn't produce specific, differentiated risk ratings that drive control decisions, rebuild it. Document the specific risk factors that elevate or reduce risk for each customer segment.

2. Map controls to risk levels. Create a matrix showing how your Customer Due Diligence intensity, ongoing due diligence frequency, and transaction monitoring sensitivity vary by Customer Risk Rating. If you can't articulate meaningful differences in controls between low, medium, and high-risk customers, you're not implementing risk-based compliance.

3. Integrate terrorist financing into existing controls. Review your transaction monitoring rules, name screening protocols, and suspicious activity detection procedures. Add terrorist financing typologies where they're missing. This includes transactions involving high-risk jurisdictions under FATF Recommendation 6, non-profit organizations, and small-value transfers to conflict zones. Don't build separate terrorist financing systems; enhance what you have.

4. Strengthen beneficial ownership verification. If you accept customer attestations of beneficial ownership without independent verification, implement a verification layer. This might include corporate registry searches, adverse media screening of beneficial owners, or requiring supporting documentation. The FATF expects you to know who ultimately controls the funds flowing through your institution.

5. Document your risk-based decisions. Create a compliance policy that explains how your risk assessment drives control calibration. When you apply simplified due diligence to certain low-risk customers or enhanced due diligence to high-risk segments, document the risk factors that justified those decisions. Regulators will ask.

The 2025 FATF Recommendations don't add fundamentally new obligations. They clarify that your compliance framework must be built on risk assessment, not uniform procedures. If you can't explain how your controls vary based on assessed risk, start there.

You Might Also Like