Skip to main content
Category: International Bodies and Standards

Black List

Also known as: Blacklist
Simply put

A black list, or blacklist, is a list of persons or entities that are disapproved of and may be subject to being punished, boycotted, or otherwise excluded. The term is used in everyday language to describe naming someone or something as unwanted or barred.

Formal definition

In general usage, a blacklist denotes a list of persons who are disapproved of or are to be punished or boycotted. The evidence provided supports only this general dictionary meaning and does not establish a specialized AML, sanctions, or financial crime compliance definition; any regime-specific application (for example, jurisdictional listings under a particular sanctions or high-risk-country framework) should be confirmed against the applicable regulation and is outside the scope of the evidence supplied.

Why it matters

In financial crime compliance, the word "blacklist" is used loosely in everyday and industry conversation to describe any roster of persons, entities, or jurisdictions that are barred, boycotted, or otherwise disapproved of. This colloquial usage can create confusion, because practitioners may apply the term to very different types of lists that carry distinct legal weight and consequences. A precise definition matters because the operational and legal implications of appearing on a formally binding designation differ substantially from being informally regarded as unwanted.

The evidence supplied supports only the general dictionary meaning of the term and does not establish a specialized AML, sanctions, or financial crime definition. As a result, compliance professionals should treat "blacklist" as an informal label rather than a defined regulatory instrument. Where the term is used in policies, procedures, or vendor documentation, its intended scope should be clarified, because a loosely applied "blacklist" reference does not by itself indicate the source, legal authority, or consequences attached to inclusion.

Because any regime-specific application, such as jurisdictional listings under a particular sanctions or high-risk-country framework, falls outside the scope of the evidence provided, users should not assume that "blacklist" corresponds to any single authoritative list. The exact meaning, source instrument, and effect of any specific listing should be confirmed against the applicable regulation and the issuing body.

Who it's relevant to

Compliance officers and policy drafters
Those who write internal policies and procedures should avoid using "blacklist" as a defined term without clarifying its source and scope, since the word carries only a general meaning and does not correspond to a specific regulatory instrument in the evidence provided.
Financial intelligence analysts and screening teams
Analysts encountering "blacklist" references in alerts, vendor data, or documentation should confirm the underlying list, its issuing body, and its legal basis, rather than assuming the term denotes any particular authoritative or binding designation.
Legal and risk professionals
Given that any regime-specific application is outside the scope of the supplied evidence, legal and risk staff should verify the exact meaning and effect of any specific listing against the applicable regulation before relying on the term in a compliance or legal context.

Inside Black List

High-Risk Jurisdictions Identification
A 'black list' in the AML context typically refers to a list of countries or jurisdictions identified as presenting significant deficiencies in their anti-money laundering and counter-terrorist financing (AML/CFT) frameworks. The most widely referenced example is the FATF list of 'High-Risk Jurisdictions subject to a Call for Action,' colloquially known as the 'black list,' which is distinct from the FATF 'grey list' of jurisdictions under increased monitoring.
Issuing Body
Such lists are published by standard-setting bodies or authorities. The FATF issues its high-risk jurisdiction lists as part of its standards, which are not themselves binding law but are commonly transposed into national or regional requirements. Separately, bodies such as the European Commission maintain their own lists of high-risk third countries under the EU AML framework, which may not be identical to the FATF list.
Associated Compliance Measures
Identification on a 'black list' generally triggers enhanced measures. For FATF 'Call for Action' jurisdictions, this may include the application of enhanced due diligence (EDD) and, in the most serious cases, counter-measures. The specific obligations depend on how the applicable regime (for example, the EU AML Directives, the UK Money Laundering Regulations, or US FinCEN rules) implements or references these designations.
Distinction from Sanctions Lists
A jurisdictional 'black list' is conceptually different from a sanctions list (such as those maintained by OFAC in the US, HM Treasury/OFSI in the UK, or the EU). A country's presence on an AML high-risk list generally triggers heightened scrutiny and due diligence, whereas sanctions designations may impose asset freezes, prohibitions on dealings, or other legal restrictions on specific persons, entities, or jurisdictions.
Dynamic and Periodic Review
These lists are not static; issuing bodies typically review and update them periodically, adding or removing jurisdictions as their AML/CFT frameworks change. Practitioners should treat any given list as a point-in-time reference and consult the current published version.

Common questions

Answers to the questions practitioners most commonly ask about Black List.

Is there a single global "black list" that all financial institutions must screen against?
No. There is no universal, unified black list applicable everywhere. Different bodies and jurisdictions maintain distinct lists for distinct purposes. For example, the FATF publishes its list of high-risk jurisdictions subject to a call for action (sometimes informally called a "blacklist"), which reflects standard-setting rather than binding law. Separately, sanctions authorities such as the US Office of Foreign Assets Control, the EU, the UK Office of Financial Sanctions Implementation, and the UN maintain designated persons and entities lists that carry legal effect within their respective regimes. These lists differ in scope, legal basis, and consequences, so obliged entities generally must screen against those relevant to their jurisdiction and exposure rather than relying on any single global list.
Does appearing on a black list mean a person or entity has been convicted of a crime?
Not necessarily. Inclusion on a list is an administrative or regulatory designation, not a criminal conviction. Sanctions designations, for instance, are typically imposed through administrative processes and may be based on grounds that do not require a finding of guilt in a criminal court. Similarly, a jurisdiction being placed on a FATF-related list reflects an assessment of strategic deficiencies in its AML/CFT framework, not proof of wrongdoing by any individual. A listing should be treated as a compliance and risk signal, not as evidence establishing criminal liability.
How should an obliged entity determine which black lists it needs to screen against?
The applicable lists generally depend on the jurisdictions in which the entity operates, the currencies it transacts in, the location of its customers and counterparties, and the regimes to which it is subject. An institution operating under multiple regimes may need to screen against several distinct lists concurrently. Determining scope is typically part of a risk-based approach and should be documented, with the exact obligations confirmed against the applicable sanctions and AML regulations in each relevant jurisdiction.
What should happen when a customer or transaction generates a potential match against a listed name?
A screening alert generally indicates a potential match that requires review, not a confirmed match. Institutions typically apply an escalation and disposition process to assess whether the alert is a true match or a false positive, using additional identifying data. Where a genuine match to a sanctions designation is confirmed, obligations may include freezing or blocking, refusing the transaction, and reporting to the relevant authority, as required under the applicable sanctions regime. The specific steps and timeframes should be confirmed against the governing rules.
How often should list-based screening data be updated?
Lists can change frequently as designations are added, amended, or removed. Institutions generally seek to keep their screening reference data current so that new designations are captured on a timely basis, and many apply ongoing or periodic rescreening of existing customers against updated lists. The appropriate frequency is typically driven by a risk-based approach and any specific expectations set by the applicable regulator.
How does screening against a FATF-related jurisdiction list differ operationally from sanctions list screening?
They serve different purposes and typically feed different controls. A jurisdiction appearing on a FATF-related list generally informs the assessment of geographic risk and may trigger enhanced due diligence or countermeasures for exposure to that jurisdiction, rather than a freeze on a specific named party. Sanctions list screening, by contrast, targets specific designated persons and entities and can require blocking, freezing, or refusal where a match is confirmed. Treating these as interchangeable can lead to misapplied controls, so they are generally handled through separate but complementary processes.

Common misconceptions

The 'black list' and 'grey list' are the same thing, or the terms are interchangeable.
They are distinct designations. In the FATF framework, the 'black list' generally refers to 'High-Risk Jurisdictions subject to a Call for Action,' reflecting the most serious deficiencies, while the 'grey list' refers to 'Jurisdictions under Increased Monitoring.' The associated expectations and any counter-measures differ, so they should not be conflated.
There is a single, universal 'black list' that applies globally.
Multiple lists exist and may diverge. The FATF list, the EU's list of high-risk third countries, and lists or references used under individual national regimes are not necessarily identical. FATF standards are not binding law in themselves; obligations arise from how a given jurisdiction transposes or references them, so practitioners should confirm which list applies under their governing regime.
A jurisdiction appearing on an AML 'black list' means transactions with that country are prohibited.
Inclusion on an AML high-risk list generally triggers enhanced due diligence and heightened scrutiny, and in the most serious cases may prompt counter-measures, but it is not the same as a sanctions prohibition. Whether specific dealings are restricted depends on separate sanctions measures and the specific requirements of the applicable regime; listing alone does not establish that a customer or transaction is unlawful.

Best practices

Consult the current, official version of any relevant list directly from the issuing body (for example, FATF or the European Commission), since these are updated periodically and prior versions may be outdated.
Identify which list or lists apply under your governing regime, and confirm the specific obligations against the applicable regulation (such as the EU AML Directives, UK Money Laundering Regulations, or US FinCEN rules) rather than assuming a single global standard.
Distinguish AML high-risk jurisdiction lists from sanctions lists in policies, screening logic, and staff training, as they trigger different measures and legal consequences.
Apply enhanced due diligence (EDD) proportionate to the risk where a jurisdiction is identified as high-risk, and document the rationale and measures taken, noting where counter-measures may be expected for the most serious designations.
Treat any listing as risk-relevant information to be assessed within a risk-based approach, not as conclusive proof of wrongdoing by any associated customer or counterparty.
Maintain a monitoring process to capture updates to these lists and re-assess affected relationships and controls when jurisdictions are added or removed, confirming exact requirements against the applicable regulation.