Skip to main content
Category: Terrorist and Proliferation Financing

Terrorist Financing

Also known as: TF, Financing of Terrorism, FT, Financing of the Financing of Terrorism
Simply put

Terrorist financing refers to the raising, moving, or processing of funds to provide terrorists or terrorist organizations with resources. Unlike money laundering, which generally seeks to disguise the criminal origins of funds, terrorist financing can draw on both legitimate and illicit sources, and the focus is on the intended use of the money. Both activities are often addressed together because they can exploit the same weaknesses in the financial system.

Formal definition

Terrorist financing (TF) is conceptually distinct from money laundering (ML): TF concerns the raising and movement of funds intended to supply terrorists and terrorist organizations with resources, and those funds may derive from legitimate as well as illicit sources, whereas ML typically involves disguising the criminal origin of proceeds. Combating TF is a core objective of the FATF Recommendations, which are international standards (not binding law) requiring countries to identify, assess, and understand their ML and TF risks and to implement measures to detect, deter, and disrupt the raising and movement of funds for terrorist purposes. Practitioners should note that ML and TF, while differing in many respects, often exploit the same vulnerabilities in the international financial system, and that the precise legal definition and scope of TF offences, as well as the obliged entities and controls required, vary by jurisdiction and should be confirmed against the applicable national framework.

Why it matters

Terrorist financing poses a distinct threat from other financial crimes because the harm lies in the intended use of funds rather than their origin. Funds destined for terrorist purposes may derive from entirely legitimate sources, such as donations or business income, as well as from illicit activity, which makes TF particularly difficult to detect through controls designed primarily to identify criminal proceeds. According to FATF, combating terrorist financing is a core objective of its international standards, and countries are expected to identify, assess, and understand their TF risks alongside their money laundering risks.

The challenge for obliged entities is that TF and money laundering, while conceptually different, often exploit the same vulnerabilities in the international financial system. FATF's 2025 Comprehensive Update on Terrorist Financing Risks reflects the persistent ability of terrorists to exploit the international financial system, underscoring that this is an evolving rather than static threat. Because the sums involved in moving funds for terrorist purposes may be small and drawn from lawful sources, traditional indicators of criminality may not surface, requiring practitioners to combine transaction monitoring with contextual risk understanding.

It is important to note that the precise legal definition and scope of TF offences, the range of obliged entities, and the specific controls required vary by jurisdiction and should be confirmed against the applicable national framework. The FATF Recommendations are international standards rather than binding law, and their implementation differs across countries. Neither an alert nor a match establishes that terrorist financing has occurred; such determinations are matters for the applicable legal and investigative processes.

Who it's relevant to

Compliance officers at obliged entities
Compliance professionals must design and operate controls that address TF risk as well as money laundering risk, recognizing that funds intended for terrorist purposes may originate from legitimate sources and therefore may not trigger indicators calibrated to detect criminal proceeds. The specific obligations that apply depend on the jurisdiction and the category of obliged entity, and should be confirmed against the applicable national framework.
Financial intelligence analysts and investigators
Analysts and investigators need to understand the methods terrorists use to raise and move funds, as examined in FATF typologies work, while recognizing that TF and money laundering often exploit the same vulnerabilities in the financial system. They should treat typologies as conceptual guidance rather than exhaustive or conclusive tests, and understand that an alert or match does not itself establish wrongdoing.
Risk assessment and program leadership
Those responsible for enterprise-wide risk assessment must identify, assess, and understand TF risks alongside ML risks, consistent with the FATF Recommendations. Because FATF's standards are not binding law and national implementations differ, leadership should ensure the institution's risk understanding reflects the applicable jurisdictional framework and evolving threat picture.
Legal and policy professionals
Legal and policy specialists should be aware that the precise legal definition and scope of TF offences vary by jurisdiction, and that the compliance treatment of TF is distinct from any criminal-law determination. Confirming the applicable national framework is essential before drawing conclusions about obligations or liability.

Inside TF

Definition and conceptual scope
Terrorist financing refers to the provision, collection, or making available of funds or other assets with the intention or knowledge that they are to be used to carry out terrorist acts, or by terrorist organizations or individual terrorists. The FATF Recommendations, particularly Recommendation 5, call on countries to criminalize terrorist financing consistent with the International Convention for the Suppression of the Financing of Terrorism. As FATF issues standards rather than binding law, the precise offence is defined in each jurisdiction's national legislation.
Source of funds
Unlike money laundering, which processes the proceeds of a predicate crime, terrorist financing may draw on funds derived from entirely legitimate sources such as legal business income, salaries, or donations, as well as from illicit sources. This means the funds themselves are not necessarily 'dirty,' which distinguishes TF from ML at a conceptual level.
Purpose-driven versus proceeds-driven
Money laundering is generally concerned with disguising the origin of illicit proceeds, whereas terrorist financing is generally concerned with the destination and intended use of funds. This forward-looking, intent-focused character affects how detection and typologies are approached, though the two offences and their controls frequently overlap in practice.
Transaction characteristics
TF activity may involve comparatively small amounts and low-value transactions that fall below thresholds typically associated with ML monitoring, which can make detection more challenging. This is a general operational observation rather than a legal test or an exhaustive indicator.
Regulatory and control framework
In many jurisdictions, anti-money laundering and counter-terrorist financing (AML/CFT) obligations are combined within the same regime, applying to obliged entities through customer due diligence, transaction monitoring, sanctions screening, and suspicious activity or transaction reporting. Specific obligations derive from the applicable instruments in each jurisdiction, such as the EU AML framework, the US Bank Secrecy Act and FinCEN rules, or the UK Money Laundering Regulations and Proceeds of Crime Act, and their exact scope should be confirmed against those instruments.

Common questions

Answers to the questions practitioners most commonly ask about TF.

Is terrorist financing just a specific type of money laundering?
No. While the two offences are often addressed together in AML/CFT frameworks and share some detection techniques, they are conceptually distinct. Money laundering generally involves disguising the illicit origin of funds derived from predicate crimes, whereas terrorist financing concerns the provision or collection of funds intended to be used for terrorist acts or by terrorist organisations. Critically, TF funds may originate from entirely legitimate sources, such as legal income, donations, or business proceeds. The distinction matters because the AML three-stage model (placement, layering, integration) does not map neatly onto TF, and screening or investigative logic focused on illicit-origin funds may miss TF activity. Precise definitions and offences vary by jurisdiction and should be confirmed against the applicable regime.
Does terrorist financing always involve large sums of money?
Not necessarily. Terrorist financing can involve relatively small amounts, and the value transacted is not by itself an indicator of TF. This differs from some money laundering scenarios where large or structured flows draw attention. Because funds may be modest and may derive from legitimate sources, transaction value and origin are often less useful as standalone signals than in money laundering contexts. Detection typically relies on a combination of factors rather than amount alone, and no single indicator establishes that TF is present.
How should an obliged entity approach screening for terrorist financing risk?
Screening for TF risk commonly includes sanctions and watchlist screening against designated persons and entities associated with terrorism, alongside customer due diligence and transaction monitoring calibrated to the entity's risk assessment. This is distinct from PEP screening, which addresses a different risk category. Because TF funds may be legitimately sourced and small in value, entities generally cannot rely on illicit-origin or value-based logic alone. The specific screening obligations, list sources, and required frequency depend on the applicable jurisdiction and the entity's regulatory regime, which should be confirmed against the relevant rules.
What is the relationship between a TF suspicion and a suspicious activity or transaction report?
Where an obliged entity forms a suspicion relating to terrorist financing, it is generally required to report to the relevant financial intelligence unit through the applicable reporting mechanism, which is termed a SAR or an STR depending on the jurisdiction. Some regimes provide dedicated channels or expedited procedures for suspected TF. Filing such a report reflects a suspicion and a compliance obligation; it does not itself establish that terrorist financing has occurred, which is a matter for the relevant authorities. Exact reporting triggers, timelines, and formats vary by regime and should be confirmed against the applicable regulation.
How can TF risk be incorporated into a risk-based approach?
TF risk is typically treated as a distinct risk category within an entity's risk assessment, informed by factors such as customer type, geographic exposure, products and services, and delivery channels. Controls such as enhanced due diligence may be applied where higher TF risk is identified. These measures are intended to detect, deter, and mitigate TF risk rather than to guarantee its prevention, and no single control eliminates the risk. How TF risk should be weighed and documented depends on the applicable framework and any guidance issued by the relevant authorities.
Why can't an entity rely solely on money laundering typologies to detect TF?
Because TF can involve legitimately sourced and low-value funds, indicators built around concealing illicit proceeds or unusual large flows may not surface TF activity. The placement-layering-integration model is a conceptual framework for money laundering and is not a reliable template for TF. Entities generally supplement transaction-based logic with sanctions and designated-party screening and contextual risk factors. Any typologies or red flags used should be treated as non-exhaustive and as prompts for further review rather than as proof of wrongdoing.

Common misconceptions

Terrorist financing always involves money derived from crime, just like money laundering.
TF may be funded from legitimate sources such as lawful business revenue, wages, or donations, as well as from illicit sources. The distinguishing feature is typically the intended use or destination of the funds rather than their origin, which is why TF and ML are conceptually distinct offences even where they are addressed under a combined AML/CFT regime.
A match against a sanctions or terrorism watchlist, or a filed suspicious report, proves that terrorist financing has occurred.
Screening matches, alerts, and suspicious activity or transaction reports are risk-management and detection outputs; they support further inquiry and, where required, reporting to the relevant authority. They do not by themselves establish criminal wrongdoing, which is a matter for competent authorities and courts under applicable criminal law.
Because TF and ML controls are often combined, the same monitoring will catch both equally well.
TF can involve small, low-value transactions and legitimately sourced funds that may not trigger controls calibrated primarily for laundering large illicit proceeds. Effective programs generally require CFT-specific consideration in risk assessment and monitoring rather than relying solely on ML-oriented parameters, and no single control can be treated as a guarantee against TF risk.

Best practices

Confirm the applicable terrorist financing offence and CFT obligations against the specific instruments in your jurisdiction (for example the relevant EU framework, US BSA/FinCEN rules, or UK MLR and POCA) rather than assuming a single uniform global standard, since FATF issues standards rather than binding law.
Design transaction monitoring to account for TF patterns that may differ from ML, including comparatively small or low-value transactions, and avoid relying exclusively on thresholds and typologies calibrated for laundering large illicit proceeds.
Address the destination and intended use of funds, not only their origin, in customer due diligence and risk assessment, recognizing that TF funds may come from legitimate sources.
Integrate sanctions and terrorism-related screening with monitoring and reporting workflows, while treating any match or alert as a trigger for further inquiry rather than as proof of wrongdoing.
Escalate and report suspicious activity to the relevant authority through the required channels, and document the basis for decisions, keeping compliance reporting distinct from any conclusion about criminal liability.
Treat published typologies and red flags as non-exhaustive indicators to inform risk-based judgment, and periodically reassess CFT-specific risk exposure rather than assuming existing ML controls fully mitigate TF risk.