Skip to main content
Category: International Bodies and Standards

International Organization for Standardization (ISO)

Also known as: ISO, International Organization for Standardization
Simply put

ISO is an independent, non-governmental international organization that brings together experts from around the world to agree on standards, which are internationally agreed descriptions of the best way of doing something. The name "ISO" is not an acronym but a short name inspired by the Greek word isos, meaning "equal." Organizations can be certified as demonstrating compliance with certain types of ISO standards.

Formal definition

The International Organization for Standardization (ISO) is an independent, non-governmental international body that develops and publishes internationally agreed standards, produced through consensus among global experts. ISO standards articulate agreed methods or requirements for a given activity; certain standards, sometimes described as "Requirements Standards," can serve as the basis for formal certification of organizations demonstrating compliance. Note that "ISO" is a short name inspired by the Greek isos ("equal"), not an acronym. As a standard-setting body, ISO produces voluntary standards rather than binding law; the legal effect of any particular ISO standard depends on whether and how it is adopted or referenced by regulators or contracting parties in a given jurisdiction, which should be confirmed against the applicable regime.

Why it matters

For financial crime compliance professionals, ISO matters because it produces internationally agreed standards that can shape the operational language, data formats, and management-system frameworks used across the sector, even though ISO itself is a non-governmental body that produces voluntary standards rather than binding law. Where a regulator or contracting party adopts or references a particular ISO standard, it can acquire practical or contractual weight; absent such adoption, an ISO standard remains a voluntary benchmark. The legal effect of any specific standard therefore depends on how it is treated in the applicable jurisdiction, which should be confirmed against the relevant regime.

The value of ISO standards lies in their consensus-based development: they represent methods or requirements agreed by global experts, which can support consistency and interoperability between institutions and across borders. For compliance teams, this can mean a common reference point for how a given activity is described or performed, reducing ambiguity when firms in different jurisdictions need to work from a shared understanding. It is important to note, however, that alignment with an ISO standard is a matter of demonstrating conformity with an agreed method or set of requirements, not evidence that any legal or regulatory obligation has been satisfied.

Certification against certain ISO standards, those sometimes described as "Requirements Standards", provides a formal recognition that an organization demonstrates compliance with the standard in question. Compliance professionals should treat such certification as a demonstration of conformity with a defined benchmark rather than as a guarantee against financial crime risk or as a substitute for meeting jurisdiction-specific regulatory requirements.

Who it's relevant to

Compliance Officers
Compliance officers may encounter ISO standards as reference points for management systems and operational methods. They should understand that ISO standards are voluntary and that conformity or certification demonstrates alignment with an agreed benchmark rather than satisfaction of any jurisdiction-specific regulatory obligation, which must be assessed separately against the applicable regime.
Risk and Governance Professionals
Those responsible for risk frameworks and governance may consider certification against a Requirements Standard as one form of externally recognized assurance that an organization conforms to a defined method or set of requirements. Such certification should be treated as a demonstration of conformity, not as a guarantee that financial crime risk has been eliminated.
Legal and Regulatory Advisors
Legal and regulatory advisors are often called upon to assess whether a given ISO standard carries any binding effect. Because ISO produces voluntary standards, the legal significance of any particular standard depends on whether and how it is adopted or referenced by regulators or contracting parties in the relevant jurisdiction, which should be confirmed against the applicable law.
Vendors and Technology Providers
Firms supplying technology or services to obliged entities may pursue ISO certification to demonstrate conformity with recognized standards. They should be clear in representations that such certification evidences compliance with a specific standard and does not, on its own, establish compliance with any customer's regulatory requirements.

Inside ISO

ISO as a standard-setting body
ISO is an independent, non-governmental international organization that develops and publishes voluntary consensus standards across a wide range of industries and disciplines. In the AML and financial crime context, ISO does not act as a regulator or supervisor; its outputs are technical standards rather than binding law, and adoption is generally voluntary unless incorporated by reference into a jurisdiction's regulatory framework.
ISO 20022 (financial messaging)
A widely referenced ISO standard providing a common framework and data model for electronic financial messaging between institutions. Richer and more structured payment data under ISO 20022 can support sanctions screening, transaction monitoring, and originator/beneficiary information requirements, though it is a messaging standard and not itself an AML control or legal obligation.
ISO country and currency codes
Standardized code sets, such as ISO country codes and currency codes, commonly used in compliance systems to identify jurisdictions and currencies consistently. These support screening, risk scoring, and reporting processes, but the codes are identifiers only and do not themselves determine sanctions status or risk levels.
Management system and risk standards
ISO publishes management system standards (for example, those addressing quality, information security, and risk management principles) that organizations may adopt to structure governance and controls. Where relevant to compliance functions, these provide a framework methodology and are typically complementary to, not a substitute for, obligations arising from applicable AML law and supervisory expectations.
Voluntary consensus process
ISO standards are developed through a consensus process involving national standards bodies and technical experts. This distinguishes them from statutory instruments; a standard becomes mandatory for a given entity only where a law, regulation, contract, or supervisor requires its use.

Common questions

Answers to the questions practitioners most commonly ask about ISO.

Does ISO create legally binding AML rules that obliged entities must follow?
No. ISO is a non-governmental international standard-setting body, and its standards are voluntary technical documents, not law. AML obligations flow from binding instruments such as national legislation transposing the EU AML Directives, the US Bank Secrecy Act and FinCEN rules, or the UK Money Laundering Regulations and Proceeds of Crime Act, and from the FATF Recommendations as standards. An ISO standard only carries legal force where a regulator or contract specifically incorporates it by reference. Its adoption is generally a matter of good practice rather than a statutory requirement.
Is ISO the same as, or a substitute for, the FATF Recommendations?
No. ISO and FATF are distinct bodies with different roles. FATF is an intergovernmental body that sets the global standards on anti-money laundering and counter-terrorist financing, which jurisdictions are assessed against and typically translate into binding national law. ISO develops technical and management-system standards that can support the operational implementation of compliance measures, but ISO does not set AML/CFT policy standards or conduct mutual evaluations. Using an ISO standard does not by itself demonstrate compliance with FATF standards or with applicable national AML law.
How can an ISO standard support an AML compliance program in practice?
ISO standards can provide a structured framework for elements of a compliance program, such as consistent terminology, data formats, or management-system processes that help an obliged entity document, govern, and audit its controls. In practice they are typically used alongside, not instead of, the applicable regulatory requirements. Any use should be mapped back to the specific obligations imposed by the relevant regime, since conformance with a standard is a means of supporting control quality rather than evidence of legal compliance.
Should adopting an ISO standard replace mapping our controls to the applicable AML regulations?
No. Adoption of an ISO standard should generally supplement, not replace, a mapping of controls to the binding obligations in your jurisdiction. Because AML requirements diverge across regimes such as the EU, the US, and the UK, an entity operating across borders still needs to satisfy each applicable regulation. The recommended practice is to treat any ISO framework as an organizing structure and confirm that each required control still meets the relevant statutory and regulatory expectations.
When implementing an ISO standard, how should we handle terminology that differs from our regulatory obligations?
Where standard terminology differs from the definitions used in applicable law, the regulatory definitions should generally take precedence for compliance purposes, and any differences should be documented. Terms that are related but not identical, such as KYC, CDD, and EDD, or a SAR versus an STR, may be used differently across a standard and a given regime. Maintaining a mapping between standard terminology and the definitions in the applicable regulation helps avoid gaps and misinterpretation.
How should we approach audit and assurance when we rely on an ISO standard alongside AML obligations?
Assurance activities should typically test both conformance with the chosen standard and compliance with the applicable AML regulatory requirements, since the two are not equivalent. Where a standard supports management-system processes, audit can assess whether those processes are operating as documented, while a separate compliance review confirms that the underlying regulatory obligations are met. Exact expectations should be confirmed against the applicable regulation and, where relevant, the specific standard being applied.

Common misconceptions

ISO standards are legally binding AML requirements.
ISO standards are voluntary consensus standards, not law. They become mandatory only when a jurisdiction, regulator, or contract incorporates them by reference. AML obligations themselves derive from instruments such as national legislation, FATF-aligned regimes, and supervisory rules, not from ISO.
Adopting ISO 20022 makes an institution AML-compliant.
ISO 20022 is a financial messaging standard that can improve the quality and structure of data used in screening and monitoring, but it is not an AML control and does not by itself satisfy any compliance obligation. Effective use still depends on the institution's own screening, monitoring, and governance measures.
ISO acts as a supervisor or enforcement authority over financial institutions.
ISO is a standard-setting body and does not supervise, examine, or sanction obliged entities. Supervision and enforcement of AML obligations rest with the relevant national regulators, supervisory bodies, and law enforcement authorities.

Best practices

Treat ISO standards as complementary tooling and methodology, and confirm actual AML obligations against the applicable statutory and regulatory framework in each relevant jurisdiction.
Where adopting ISO 20022, ensure the richer payment data is actually leveraged by screening and transaction monitoring systems rather than assuming the messaging standard delivers compliance on its own.
Use standardized ISO code sets consistently across compliance systems for jurisdictions and currencies, while recognizing that codes are identifiers and do not by themselves establish sanctions status or risk ratings.
Document clearly whether a given ISO standard is voluntarily adopted or incorporated by reference into a binding requirement, so that governance records distinguish standards from legal obligations.
Engage compliance, technology, and legal stakeholders together when implementing ISO-based frameworks, to align technical standards with supervisory expectations and internal risk-based controls.
Periodically review whether relevant ISO standards have been updated and reassess how any changes affect data quality, interoperability, and the effectiveness of existing detection and monitoring measures.