Skip to main content
Category: Terrorist and Proliferation Financing

Counter-Terrorist Financing

Also known as: CTF/CFT, Combating the Financing of Terrorism, Countering the Financing of Terrorism, Counter Terrorist Financing, AML/CFT (when paired with anti-money laundering)
Simply put

Counter-Terrorist Financing (CTF), also called Combating the Financing of Terrorism (CFT), refers to the set of policies, laws, and practices designed to stop terrorists and terrorist organizations from raising, moving, and accessing funds. The aim is to cut off the financial resources that support terrorist activity. It is closely related to, but distinct from, anti-money laundering (AML) measures, and the two are often implemented together as AML/CFT frameworks.

Formal definition

Counter-Terrorist Financing (CTF/CFT) comprises the strategies, regulations, controls, and actions applied by governments, international bodies, and obliged entities to detect, deter, and disrupt the raising and processing of funds intended to supply terrorists or terrorist organizations. In practice it is frequently combined with anti-money laundering measures as an integrated AML/CFT regime, and its objective is to prevent the abuse of the financial system by terrorists and criminals. Practitioners should note that terrorism financing differs conceptually from money laundering: money laundering typically involves disguising the proceeds of prior crime, whereas terrorism financing concerns the funding of future or ongoing terrorist activity and may involve funds from legitimate as well as illicit sources. The specific obligations, definitions, and controls that give effect to CTF/CFT vary by jurisdiction and applicable instrument; exact requirements should be confirmed against the relevant national law and regulatory framework.

Why it matters

Terrorist financing poses a distinct threat to the integrity of the financial system because it concerns the funding of future or ongoing terrorist activity rather than the concealment of proceeds from prior crime. As the FATF frames it, the purpose of implementing AML/CFT measures is to stop criminals and terrorists from abusing the financial system. Cutting off access to funds is therefore a central objective of counter-terrorism efforts, and financial institutions and other obliged entities are positioned as a key line of defense in detecting and disrupting the flow of resources to terrorists and terrorist organizations.

CTF/CFT matters operationally because terrorism financing can be more difficult to identify than classic money laundering. Funds intended to supply terrorists may originate from legitimate as well as illicit sources, and the amounts involved may not follow the patterns that money laundering typologies are designed to surface. This means practitioners cannot rely solely on controls calibrated to disguised criminal proceeds; they need an understanding of terrorism financing trends, red flags, and the applicable global CFT frameworks. It is important to stress that red flags and typologies are indicators to inform further review, not proof of wrongdoing, and no single control eliminates terrorism financing risk.

Because CTF/CFT obligations are typically implemented alongside anti-money laundering measures within integrated AML/CFT regimes, weaknesses in one area can undermine the other. However, the specific definitions, obligations, and controls that give effect to CTF/CFT vary by jurisdiction and applicable instrument, so firms operating across borders must map their programs to each relevant national law and regulatory framework rather than assuming a single global standard applies.

Who it's relevant to

Compliance officers at obliged entities
Compliance professionals are responsible for building and maintaining AML/CFT programs that reflect the specific CTF obligations applicable in their jurisdiction. They must ensure controls are calibrated not only to money laundering but to the distinct characteristics of terrorism financing, which may involve funds from legitimate as well as illicit sources, and confirm requirements against the relevant national law.
Financial intelligence analysts and investigators
Analysts and investigators apply their understanding of terrorism financing trends and red flags to review activity and escalate matters for further examination. They need to treat indicators as prompts for analysis rather than proof of wrongdoing, and to recognize that terrorism financing patterns can differ from those seen in money laundering.
Legal and risk professionals
Legal and risk teams advise on how international standards, such as the FATF Recommendations, translate into binding obligations under applicable national law, and on how divergences between jurisdictions affect cross-border operations. They help ensure the firm's CTF/CFT posture aligns with each relevant regulatory framework.
Governments and international bodies
Standard-setters and multilateral institutions such as the FATF and the IMF shape CTF/CFT expectations, while national governments give them legal effect. Their role includes setting the strategies and frameworks intended to prevent terrorists and criminals from abusing the financial system.

Inside CTF/CFT

Terrorist Financing (TF)
The provision, collection, or making available of funds or other assets with the intention or knowledge that they will be used to carry out terrorist acts, or by terrorist organizations or individual terrorists. Unlike money laundering, TF is concerned primarily with the intended future use of funds rather than the illicit origin of proceeds; funds involved may derive from entirely legitimate sources, which distinguishes CTF analysis from traditional anti-money laundering analysis.
FATF Standards
The FATF Recommendations address terrorist financing (notably the recommendations concerning TF offences, targeted financial sanctions related to terrorism and proliferation, and non-profit organizations). These are international standards rather than binding law, and jurisdictions implement them through their own domestic legal instruments, which may diverge in scope and detail.
Targeted Financial Sanctions
Measures typically requiring obliged entities to freeze without delay the funds or assets of designated persons and entities and to prohibit making funds available to them. These obligations generally derive from designations made under United Nations Security Council resolutions and their implementation in domestic or regional regimes. The precise designated lists, freezing obligations, and reporting duties vary by jurisdiction and should be confirmed against the applicable regime.
Distinction from Money Laundering
Money laundering seeks to disguise the illicit origin of criminal proceeds, whereas terrorist financing focuses on the destination and purpose of funds that may be legitimate or illicit in origin. As a result, transaction values in TF may be small and may not exhibit the placement-layering-integration pattern associated with laundering, making detection reliant on different indicators.
Obliged Entity Obligations
In many jurisdictions, financial institutions and other regulated entities are expected to incorporate TF risk into customer due diligence, transaction monitoring, sanctions screening, and suspicious activity or transaction reporting. The exact obligations, the entities in scope, and applicable thresholds depend on the domestic framework, such as the US Bank Secrecy Act and FinCEN rules, the UK Money Laundering Regulations, or the EU AML framework.
Reporting of Suspicious Activity
Where a practitioner suspects funds are linked to terrorist financing, reporting is generally made to the relevant financial intelligence unit through a suspicious activity report (SAR) or suspicious transaction report (STR), depending on the jurisdiction's terminology. Such a filing reflects suspicion for compliance purposes and does not itself establish that any offence has been committed.

Common questions

Answers to the questions practitioners most commonly ask about CTF/CFT.

Is counter-terrorist financing just another name for anti-money laundering?
No. While AML and CTF are frequently addressed together in the same programs, legislation, and FATF standards, they target different phenomena. Money laundering generally concerns disguising the illicit origin of funds derived from predicate crimes, so the money starts out 'dirty.' Terrorist financing, by contrast, focuses on the use or provision of funds to support terrorism regardless of their source, meaning the funds may originate from entirely legitimate activity. Because the underlying logic differs, some controls calibrated to detect proceeds of crime may not surface terrorist financing, which often involves small amounts moving toward, rather than away from, an illicit purpose. Institutions typically maintain integrated but distinct risk assessments to reflect these differences.
Does terrorist financing always involve large sums of money moving through the financial system?
Not necessarily. A common misconception is that terrorist financing mirrors large-scale laundering. In practice, the funds involved can be modest, and detection based primarily on transaction size or aggregation thresholds may not be effective on its own. Because the defining feature is the intended purpose rather than the amount or origin, monitoring approaches generally need to consider contextual factors, connections to designated persons or high-risk areas, and other indicators, rather than relying on value-based triggers alone. These indicators help manage and detect risk but are not proof of wrongdoing in any individual case.
Which obligations require an institution to implement CTF measures, and where do they come from?
CTF obligations derive from several sources depending on the jurisdiction. The FATF Recommendations set international standards addressing terrorist financing and proliferation financing, but these are standards rather than binding law. Individual regimes then transpose comparable requirements into domestic frameworks, for example, through the EU AML Directives and the AML Regulation, the US Bank Secrecy Act and associated FinCEN rules, or the UK Money Laundering Regulations alongside relevant counter-terrorism legislation. Institutions should map their specific obligations to the instruments applicable in each jurisdiction where they operate, as scope and detail diverge, and exact requirements should be confirmed against the governing law.
How does CTF screening relate to sanctions screening against designated terrorist entities?
The two overlap but are not identical. Sanctions and designation regimes maintain lists of persons and entities associated with terrorism, and screening customers and transactions against those lists is typically a core CTF control. However, CTF is broader than list screening: it also encompasses risk assessment, transaction monitoring for indicators not tied to a named party, customer due diligence, and reporting suspicions. A screening match against a designated party may carry immediate legal consequences under the applicable sanctions regime, whereas broader CTF monitoring generally supports the identification of suspicious activity for reporting purposes. A screening alert, on its own, does not establish that a customer has engaged in terrorist financing.
How should a suspicion of terrorist financing be reported operationally?
Where an obliged entity forms a suspicion of terrorist financing, the general expectation across many regimes is to file a report with the relevant financial intelligence unit or competent authority, variously termed a Suspicious Activity Report or Suspicious Transaction Report depending on the jurisdiction. Some regimes also impose specific obligations relating to terrorist property or designated persons that may differ from, or run in parallel to, ordinary suspicious activity reporting. Institutions should follow the reporting channels, timeframes, and any tipping-off restrictions set out in their applicable framework. Filing a report reflects a suspicion for regulatory purposes and does not itself constitute a determination of criminal conduct.
How can a risk-based approach be applied to CTF given that transaction amounts are often low?
A risk-based approach to CTF generally emphasizes contextual and qualitative factors alongside, rather than instead of, value-based indicators. This can include assessing exposure to higher-risk jurisdictions or activities, customer connections to designated persons or relevant networks, unusual patterns inconsistent with a customer's profile, and typologies identified by authorities, understanding that such typologies are illustrative rather than exhaustive and are not proof of criminality. Because low-value activity may still warrant attention, institutions typically calibrate monitoring, customer due diligence, and escalation to reflect terrorist-financing-specific risk drivers. These measures are intended to detect, deter, and mitigate risk, not to guarantee that terrorist financing is prevented.

Common misconceptions

CTF and AML are the same discipline with identical detection methods.
While CTF and AML controls often share infrastructure such as customer due diligence and monitoring, they address different problems. AML targets the illicit origin of criminal proceeds, whereas CTF targets the intended use of funds that may be legitimately sourced. Detection indicators, transaction values, and analytical approaches can therefore differ significantly.
Terrorist financing always involves large sums of money.
Funds involved in terrorist financing may be small in value and may originate from legitimate sources, which can make them harder to detect than large-scale laundering. Reliance on value-based thresholds alone may not surface TF risk.
A sanctions match or a filed report proves involvement in terrorism.
A screening match, alert, or suspicious activity report reflects a potential risk or a compliance-driven suspicion that requires review; it does not by itself establish wrongdoing or a criminal offence. Determinations of guilt are matters for competent authorities under criminal law.

Best practices

Integrate terrorist financing risk explicitly into your risk assessment rather than assuming AML controls automatically cover it, recognizing that TF indicators differ from those used to detect the laundering of criminal proceeds.
Confirm the specific designated lists, freezing obligations, and reporting duties that apply under your jurisdiction's regime, since these derive from domestic implementation of UN and other measures and vary in scope and detail.
Do not rely solely on monetary thresholds to flag potential terrorist financing, as relevant transactions may be low in value and drawn from legitimate sources.
Where suspicion of terrorist financing arises, escalate and report to the relevant financial intelligence unit using the applicable SAR or STR mechanism, and document the basis for the suspicion.
Treat sanctions screening for terrorism designations and broader TF monitoring as distinct but complementary controls, and calibrate each to the risks your entity faces.
Verify all specific obligations, thresholds, and designated-list requirements against the applicable regulation, as CTF frameworks diverge across jurisdictions and the FATF Recommendations are standards rather than binding law.