Skip to main content
Category: International Bodies and Standards

Financial Action Task Force (FATF)

Also known as:
Simply put

The Financial Action Task Force (FATF) is an intergovernmental body that leads global efforts to combat money laundering, terrorist financing, and proliferation financing. It sets international standards that countries are expected to implement, but it is not itself a lawmaking authority; its standards must be adopted into national law by individual jurisdictions to take legal effect.

Formal definition

The FATF is an intergovernmental body that establishes international standards for anti-money laundering (AML), countering the financing of terrorism (CFT), and countering proliferation financing. Its outputs, commonly referred to as the FATF Recommendations, function as standards rather than directly binding law; legal obligations for obliged entities generally arise only where jurisdictions transpose these standards into domestic regimes (for example, the US Bank Secrecy Act and FinCEN rules, the EU AML Directives and AML Regulation, or the UK Money Laundering Regulations and Proceeds of Crime Act). The FATF also identifies jurisdictions with strategic AML/CFT deficiencies, which national authorities and obliged entities may factor into risk-based measures. FATF-style regional bodies (such as MENAFATF) carry designated responsibilities for combating money laundering and/or terrorist financing within their respective regions. Practitioners should confirm the specific applicable obligations against the relevant national instrument, as the FATF standards themselves do not directly impose enforceable duties.

Why it matters

The FATF occupies a foundational position in the global AML/CFT architecture because it sets the standards against which national regimes are effectively benchmarked. For compliance professionals, understanding the FATF matters not because its Recommendations impose direct legal duties on obliged entities, but because the concrete obligations they must meet, such as those under the US Bank Secrecy Act and FinCEN rules, the EU AML Directives and AML Regulation, or the UK Money Laundering Regulations and Proceeds of Crime Act, are generally derived from these standards once transposed into domestic law. Tracing a requirement back to its FATF origin can help practitioners interpret the intent behind a national rule, though the enforceable text always lies in the applicable national instrument.

The FATF also identifies jurisdictions with strategic AML/CFT deficiencies, and these determinations can feed directly into the risk-based measures that firms apply. When a jurisdiction is flagged, national authorities and obliged entities may factor that status into their risk assessments and enhanced due diligence considerations. This is a risk-management input rather than a mechanical prohibition, and it does not by itself establish wrongdoing on the part of any customer or counterparty connected to a listed jurisdiction.

Because the FATF addresses money laundering, terrorist financing, and proliferation financing as distinct but related threats, its work reinforces that these are not interchangeable concepts. Practitioners should be careful to map each obligation to its correct source and to confirm exact requirements, thresholds, and jurisdictional listings against the relevant national regulation and current FATF publications, since these evolve over time.

Who it's relevant to

Compliance officers and MLROs
Those responsible for AML/CFT programs use FATF standards as a reference point for understanding the intent behind national obligations, but must build and document their controls against the enforceable domestic instrument that applies to their firm, such as FinCEN rules, the EU AML framework, or the UK Money Laundering Regulations.
Financial intelligence analysts and investigators
Analysts may factor FATF identifications of jurisdictions with strategic AML/CFT deficiencies into risk-based assessments and enhanced scrutiny, while recognizing that a jurisdictional link is a risk input and does not by itself establish wrongdoing.
Legal and risk professionals
Legal and risk teams need to distinguish clearly between the FATF Recommendations as non-binding standards and the binding national laws that transpose them, ensuring that advice and risk positions are anchored in the correct enforceable source rather than in the standards themselves.
Policymakers and national authorities
Governments and regulators are the actors that translate FATF standards into domestic law and give effect to jurisdictional listings, making the FATF's outputs directly relevant to their legislative, supervisory, and risk-based policy decisions.

Inside FATF

FATF Recommendations
A set of international standards on combating money laundering, terrorist financing, and proliferation financing. These are standards and recommendations rather than binding law; they take legal effect only when transposed into national legislation or regulation by member and assessed jurisdictions.
Mutual Evaluations
Peer-review assessments of a jurisdiction's AML/CFT framework, evaluating both technical compliance with the Recommendations and the effectiveness of the regime in practice. Outcomes inform each jurisdiction's standing and may drive reform.
Public Identification Lists
Processes through which FATF identifies jurisdictions with strategic AML/CFT deficiencies, commonly referred to in practice as 'grey' and 'black' lists. These are FATF designations and are distinct from sanctions lists issued by other bodies.
Typologies and Guidance
Studies of money laundering and terrorist financing methods, and guidance to help jurisdictions and obliged entities implement the Recommendations. Typologies are illustrative of observed methods and are not exhaustive or a legal test of criminality.
Intergovernmental Membership Structure
FATF operates as an intergovernmental body composed of member jurisdictions and regional bodies (FATF-Style Regional Bodies), which extend the reach of the standards and conduct evaluations within their regions.

Common questions

Answers to the questions practitioners most commonly ask about FATF.

Are the FATF Recommendations legally binding on financial institutions?
No. The FATF Recommendations are international standards, not binding law. FATF itself has no power to compel compliance by obliged entities. The Recommendations only acquire legal force when individual jurisdictions transpose them into domestic law and regulation, for example, through the EU AML Directives and AML Regulation, the US Bank Secrecy Act and FinCEN rules, or the UK Money Laundering Regulations and Proceeds of Crime Act. As a result, the specific obligations, thresholds, and definitions that apply to a given institution derive from its national framework, which may implement, exceed, or diverge from the FATF standards. Exact requirements should be confirmed against the applicable domestic regime rather than the Recommendations themselves.
Does being placed on a FATF list mean transactions with that country are prohibited?
Not automatically. FATF's public identification of jurisdictions with strategic deficiencies (commonly discussed as its 'grey list' and 'black list' processes) is a call for enhanced monitoring or, in higher-risk cases, for countermeasures, but these are recommendations to member jurisdictions, not self-executing prohibitions. Whether any restriction, enhanced due diligence, or countermeasure applies to your institution depends on how your own jurisdiction and regulator respond to the FATF statement. FATF listing is also distinct from sanctions: a country appearing on a FATF list is not the same as being subject to a sanctions program, and the two should be assessed separately against the relevant legal instruments.
How should an AML program treat the FATF Recommendations in practice?
Generally, institutions should use the FATF Recommendations as a reference framework for understanding the international expectations behind their domestic obligations, while building controls to the specific requirements of the law and regulator that govern them. Where national rules are silent or ambiguous, the Recommendations and FATF guidance can inform reasonable interpretation, but they do not substitute for the applicable legal instrument. Documenting how program elements map to both domestic requirements and the underlying FATF standards can help demonstrate a considered, risk-based approach.
What is the practical difference between FATF Recommendations and the FATF methodology used in evaluations?
The Recommendations set out the standards themselves, while the assessment methodology is the tool FATF and FATF-style regional bodies use to evaluate a jurisdiction during mutual evaluations. The methodology typically distinguishes technical compliance (whether laws and rules exist that reflect the standards) from effectiveness (whether the system produces intended outcomes in practice). For compliance teams, this distinction matters because a jurisdiction can be technically compliant yet assessed as having effectiveness gaps, which may shape supervisory priorities and expectations placed on obliged entities.
Should compliance teams monitor FATF plenary outcomes and guidance updates?
Yes, monitoring FATF plenary statements, updated Recommendations, and sector-specific guidance is generally advisable, because these often signal changes that national regulators may later implement or emphasize. However, FATF outputs should be treated as forward indicators rather than immediate obligations: a change at the FATF level typically takes effect for an institution only once reflected in domestic law, regulation, or supervisory expectations. Teams should track how their own regulator responds before adjusting controls.
How does a jurisdiction's FATF mutual evaluation result affect an individual institution?
A mutual evaluation assesses the jurisdiction's overall framework and its effectiveness, not any single institution. Its practical impact on an individual firm is indirect: evaluation findings may prompt legislative change, sharpen supervisory focus in weak areas, or influence how counterparties and correspondent banks assess country risk. Institutions may find it useful to review relevant evaluation findings to anticipate regulatory attention, but the binding obligations on the institution continue to flow from domestic law rather than from the evaluation itself.

Common misconceptions

The FATF Recommendations are legally binding on financial institutions worldwide.
The Recommendations are international standards, not binding law. They create obligations only where a jurisdiction transposes them into its own legislation or regulation, and the resulting requirements can differ in scope and detail between jurisdictions.
FATF enforces AML rules and imposes penalties on institutions or countries.
FATF is a standard-setting and assessment body; it does not directly regulate, supervise, or penalize obliged entities. Enforcement is carried out by national authorities, and FATF's principal levers are peer evaluation and public identification of jurisdictions with deficiencies.
FATF's grey and black lists are the same as sanctions lists.
FATF's public identifications relate to strategic AML/CFT deficiencies at the jurisdiction level and are distinct from sanctions programs administered by bodies such as the UN, the EU, or national authorities like OFAC. They should be treated and screened for separately.

Best practices

Treat the FATF Recommendations as a baseline reference, but always confirm the specific obligations that apply to your entity against the transposing national legislation or regulation in each relevant jurisdiction.
Monitor FATF's public identification updates and factor changes to grey- and black-listed jurisdictions into your country and customer risk assessments, while keeping them separate from your sanctions screening processes.
Use FATF typologies and guidance to inform risk indicators and control design, but do not treat published typologies as exhaustive or as evidence that any particular activity is criminal.
Review your jurisdiction's mutual evaluation findings to understand supervisory expectations and known regime weaknesses that may affect your risk-based approach.
Document how your AML/CFT program maps to applicable transposed standards, noting where jurisdictional requirements diverge for entities operating across multiple regimes.
Verify any specific thresholds, timelines, or requirements against the applicable national regulation rather than assuming a uniform global rule derived from the Recommendations.