Skip to main content
Category: International Bodies and Standards

Grey List

Also known as: Greylist, Grey-List, Jurisdictions under Increased Monitoring, Greylisting, Grey-Listing
Simply put

The grey list is a public list issued by the Financial Action Task Force (FATF) that names countries identified as having weaknesses in their systems for combating money laundering and terrorist financing, but which are actively working with the FATF to fix them. Being grey-listed signals that a country is seen as not doing enough to prevent financial crimes, which can affect how other countries and investors view it. It is a monitoring and reputational measure rather than a formal prohibition on dealing with the country.

Formal definition

The Grey List is the FATF's designation officially titled 'Jurisdictions under Increased Monitoring,' identifying countries that have strategic deficiencies in their AML/CFT frameworks and that have made a high-level political commitment to address those deficiencies while actively working with the FATF under agreed timelines. It is distinct from the FATF 'black list' (High-Risk Jurisdictions subject to a Call for Action), and inclusion reflects increased monitoring rather than a directive to apply enhanced due diligence or countermeasures in every case. FATF Recommendations are international standards rather than binding law, so the operational consequences of a jurisdiction's grey-listing depend on how individual regimes and obliged entities incorporate FATF designations into their own risk-based country-risk assessments; grey-listing does not itself impose sanctions, and practitioners should confirm the current list and any applicable obligations against the relevant regulator's requirements.

Why it matters

For compliance functions, a jurisdiction's appearance on the FATF grey list is a signal that feeds into country-risk assessment rather than an automatic trigger for a specific control. Because the FATF designates grey-listed countries as 'Jurisdictions under Increased Monitoring', those with identified strategic deficiencies in their AML/CFT frameworks that are actively working with the FATF to address them, obliged entities generally weigh this designation as one input among many when scoring exposure to a particular market. It is important to distinguish this from the FATF 'black list' (High-Risk Jurisdictions subject to a Call for Action): grey-listing reflects increased monitoring, not a directive to apply enhanced due diligence or countermeasures in every case.

The consequences of grey-listing tend to be reputational and market-related as much as regulatory. As public commentary on the measure notes, being grey-listed can be read as a signal that a country is seen as not doing enough to prevent financial crimes such as money laundering, and this perception may affect how other jurisdictions, correspondent banks, and investors view dealing with that country. These effects flow from how third parties respond to the designation rather than from any prohibition imposed by the listing itself.

Because FATF Recommendations are international standards rather than binding law, the practical impact of any grey-listing depends on how individual regimes and obliged entities incorporate FATF designations into their own risk-based frameworks. A designation on the grey list does not itself impose sanctions or establish that transactions involving the jurisdiction are unlawful. Practitioners should confirm the current list and any resulting obligations against the requirements of their applicable regulator.

Who it's relevant to

Compliance officers and MLROs
Those responsible for AML/CFT programs use grey-list status as one input into country-risk assessment and the calibration of a risk-based approach. They should treat the designation as a signal to be weighed rather than an automatic trigger for enhanced due diligence, and confirm what, if anything, their applicable regulator requires in response.
Financial intelligence and risk analysts
Analysts who build and maintain country-risk models incorporate FATF designations, distinguishing grey-listed jurisdictions (under increased monitoring) from black-listed jurisdictions (subject to a Call for Action). Because the list changes over time, they should verify current status when scoring exposure.
Correspondent banking and onboarding teams
Teams assessing counterparties, respondent banks, and clients connected to grey-listed jurisdictions may factor the designation into how they evaluate and view those relationships, recognising that reputational and market-related effects can arise from how other parties respond to a listing rather than from any prohibition in the listing itself.
Legal and regulatory advisers
Advisers interpreting the operational consequences of grey-listing for clients need to explain that FATF Recommendations are standards rather than binding law, that grey-listing does not itself impose sanctions or establish wrongdoing, and that obligations depend on how the applicable regime incorporates FATF designations.
Policymakers and authorities in listed jurisdictions
Government and central-bank officials in countries facing or subject to grey-listing engage with the FATF under agreed timelines to address identified strategic deficiencies, and manage the reputational and investor-perception effects that can accompany the designation.

Inside Grey List

Jurisdictions Under Increased Monitoring
The 'grey list' is the informal name for FATF's list of 'Jurisdictions under Increased Monitoring', countries that have been identified as having strategic deficiencies in their anti-money laundering and counter-terrorist financing (AML/CFT) frameworks but that have made a high-level political commitment to address those deficiencies within agreed timeframes.
Action Plan Commitment
A defining feature of grey-listed jurisdictions is their agreement to an action plan developed with the FATF (and, in many cases, FATF-style regional bodies) to remedy identified strategic deficiencies. The jurisdiction actively works with FATF, distinguishing it from the 'black list' of high-risk jurisdictions subject to a call for action.
Non-Binding FATF Standard
The grey list derives from the FATF Recommendations and FATF's monitoring processes, which are international standards rather than binding law. Its practical effect on obliged entities depends on how individual jurisdictions and regulators transpose or respond to FATF findings within their own regimes.
Risk Signal, Not Prohibition
Grey listing generally functions as a risk indicator that may inform an obliged entity's risk-based approach and country-risk assessment. It typically does not, by itself, mandate a prohibition on dealing with a jurisdiction, in contrast to the enhanced measures often associated with black-listed countries.
Periodic Review and Delisting
The composition of the grey list is subject to periodic review, with jurisdictions added or removed as FATF assesses progress against their action plans. Because it changes over time, it must be monitored against the current published FATF statements rather than relied upon as a fixed list.

Common questions

Answers to the questions practitioners most commonly ask about Grey List.

Does being placed on the FATF Grey List mean a country is subject to sanctions?
No. The Grey List, formally FATF's list of 'Jurisdictions under Increased Monitoring', is not a sanctions regime and does not impose asset freezes, trade restrictions, or prohibitions on dealing with the listed country. It identifies jurisdictions that have strategic deficiencies in their anti-money laundering and counter-terrorist financing frameworks but that have made a high-level political commitment to address those deficiencies within an agreed timeframe, while working with FATF. This should not be confused with the FATF 'Black List' (Call for Action jurisdictions) or with country-specific sanctions administered by bodies such as OFAC, the EU, or the UN Security Council, which are distinct instruments with different legal effects. Firms should confirm the specific implications of any listing against the applicable regulatory guidance in their jurisdiction.
Does the FATF Grey List automatically require obliged entities to apply enhanced due diligence to all transactions involving a listed country?
Not automatically or uniformly. FATF Recommendations are standards rather than binding law, and the extent to which a Grey List designation triggers enhanced due diligence (EDD) depends on how each jurisdiction transposes and applies FATF's guidance. In some regimes, a FATF Grey List designation feeds into a firm's country risk assessment as one factor among several, informing a risk-based decision on the level of due diligence, rather than mandating EDD across the board. Other regimes, for example, certain EU frameworks, maintain their own separate lists of high-risk third countries that may carry more prescriptive EDD obligations, and these lists do not always align with FATF's Grey List. Firms should confirm the exact obligations against the applicable law in their jurisdiction rather than assuming a single global rule.
How should a compliance team incorporate a Grey List designation into its country risk assessment?
A Grey List designation is typically treated as one input into a jurisdiction's overall risk rating, alongside factors such as the applicable local legal framework, corruption indicators, sanctions exposure, predicate offence prevalence, and the firm's own transaction experience. Rather than mechanically elevating every relationship to high risk, many firms weight the designation within a broader methodology and document the rationale. It is generally advisable to review the specific FATF statement accompanying the listing, as it identifies the particular strategic deficiencies concerned, which can help calibrate whether and how the designation affects the firm's exposure. Any resulting control changes should be assessed against the firm's applicable regulatory obligations.
What operational steps typically follow when a country is newly added to the Grey List?
Common operational responses may include refreshing the affected country's risk rating, re-screening or reviewing existing customers with exposure to that jurisdiction, reassessing whether current due diligence measures remain proportionate, and updating relevant policies, procedures, and system parameters. Firms often also brief relevant business lines and consider whether transaction monitoring scenarios or thresholds warrant review. The precise steps depend on the firm's risk appetite, its regulatory environment, and internal governance requirements. These measures are intended to help detect, deter, and manage financial crime risk associated with the jurisdiction, not to guarantee prevention, and their scope should be confirmed against applicable regulatory expectations.
How should firms handle the difference between the FATF Grey List and their local regulator's high-risk country list?
Because FATF's Grey List and jurisdiction-specific high-risk country lists (such as those maintained under certain EU frameworks) do not always align, firms generally need to track multiple lists concurrently and understand which carries binding legal effect in their operating jurisdiction. In many cases the locally transposed or regulator-issued list drives the mandatory obligations, while the FATF Grey List informs the broader risk picture. Firms typically document how each source feeds into their methodology and reconcile discrepancies transparently, applying the more stringent requirement where obligations conflict. The applicable position should be confirmed against the relevant local regulation and guidance.
How often should a firm review Grey List designations, and how are changes managed?
FATF generally updates its list of Jurisdictions under Increased Monitoring on a periodic basis following its plenary meetings, and both additions and removals can occur. Firms typically establish a process to monitor these updates, assess the impact of any change on affected relationships and country risk ratings, and update systems, policies, and screening parameters accordingly. When a jurisdiction is removed from the list, firms may reassess whether previously heightened measures remain proportionate. The cadence and governance of these reviews should align with the firm's risk-based approach and applicable regulatory requirements, and exact timing of FATF updates should be confirmed against FATF's published schedule.

Common misconceptions

Grey listing means transactions with that jurisdiction are prohibited or that the country is sanctioned.
The grey list is a monitoring designation, not a sanctions regime. It generally signals elevated country risk that should feed into a risk-based approach; it does not, in itself, prohibit business or equate to sanctions. Sanctions screening and country-risk assessment are distinct exercises, and prohibitions would stem from separate legal instruments rather than from FATF's list.
The grey list and the black list are the same thing or carry the same consequences.
They are distinct. The grey list covers 'Jurisdictions under Increased Monitoring' that are actively cooperating with the FATF on an action plan, whereas the 'black list' covers high-risk jurisdictions subject to a call for action, which typically attracts stronger countermeasures. Treating them as interchangeable misstates the level of expected response.
The FATF grey list is legally binding on obliged entities everywhere in the same way.
FATF Recommendations and its public statements are international standards, not binding law. Their operational impact depends on how each jurisdiction's regulators and legal framework respond, so the required treatment of grey-listed countries may vary and should be confirmed against the applicable national rules.

Best practices

Monitor FATF's published statements directly and on an ongoing basis, since the grey list changes at review cycles; do not rely on a static or cached version of the list.
Incorporate grey-list status as one input into a broader country-risk assessment rather than as a standalone determinant, weighing it alongside other risk factors within your risk-based approach.
Confirm how your applicable national regime and regulators expect obliged entities to treat grey-listed jurisdictions, recognising that FATF standards are not directly binding and that responses may differ by jurisdiction.
Distinguish grey-list treatment from black-list ('call for action') treatment in policies and procedures, and avoid applying prohibitions or countermeasures that are not required for merely grey-listed countries.
Document the rationale for any adjustments to due diligence or monitoring triggered by grey-list status, so the risk-based decision is auditable and defensible.
Keep grey-list considerations separate from sanctions and PEP screening workflows, ensuring staff understand that grey listing is a risk signal and not evidence of wrongdoing by any counterparty in that jurisdiction.