Skip to main content
Category: Terrorist and Proliferation Financing

Terrorist Financing Risk Assessment

Also known as: TF Risk Assessment, TF Risk Assessment, Terrorist Financing Risk Assessment (TFRA)
Simply put

A terrorist financing risk assessment is a structured process for identifying, assessing, and understanding the risks that a country, sector, or organization may be used to raise, move, or use funds for terrorism. Its purpose is to help direct resources and mitigation efforts to where the risks are greatest. It is generally distinct from money laundering risk assessment, though the two are often carried out together.

Formal definition

A terrorist financing (TF) risk assessment is a framework-based exercise to identify, assess, and understand TF risks so that they can be mitigated and countered effectively. Under the FATF standards, each country is expected to identify, assess, and understand the TF risks it faces in order to mitigate them and disrupt terrorist financing activity; this expectation is reflected in the FATF methodology (including the criteria relating to risk assessment) and forms the basis for national money laundering and terrorist financing risk assessments. Analytically, the assessment typically considers the likelihood of an event occurring and the consequences if it does, and may be conducted at national, sectoral (for example, non-profit organizations), or entity levels. It should be treated as distinct from a money laundering risk assessment even where the two are combined in a single national exercise, and the specific methodologies, scope, and criteria applied should be confirmed against the applicable FATF guidance and the relevant national framework.

Why it matters

Terrorist financing risk is not the same as money laundering risk, and treating the two as interchangeable can leave meaningful gaps in a country's or an organization's defenses. Money laundering is generally concerned with disguising the illicit origin of funds, whereas terrorist financing can involve funds from entirely legitimate sources being raised, moved, or used to support terrorism. A dedicated terrorist financing risk assessment matters because it forces assessors to focus on this distinct threat, understand how funds may be raised, moved, or used for terrorist purposes, and direct mitigation efforts to where the risk is greatest rather than assuming that anti-money laundering controls automatically cover it.

Under the FATF standards, each country is expected to identify, assess, and understand the terrorist financing risks it faces in order to mitigate them and disrupt terrorist financing activity. This expectation underpins national risk assessments and shapes how resources are allocated across sectors. As the World Bank frames it, a framework designed to combat terrorist financing is most effective when it targets resources where they will have the most impact; without a structured assessment, that targeting becomes guesswork, and lower-risk areas may be over-resourced while genuine vulnerabilities go unaddressed.

The stakes are also reputational and strategic for particular sectors. FATF guidance highlights that certain areas, such as non-profit organizations, may warrant sectoral assessment, and a poorly calibrated response can either fail to detect abuse or impose disproportionate burdens that disrupt legitimate activity. A well-conducted terrorist financing risk assessment helps balance these outcomes by grounding decisions in an evidence-based understanding of likelihood and consequence rather than blanket assumptions.

Who it's relevant to

National authorities and policymakers
Governments and competent authorities are expected under the FATF standards to identify, assess, and understand the terrorist financing risks their country faces so that they can mitigate them and direct resources where they will have the greatest impact. National risk assessments produced by these bodies typically inform legislation, supervisory priorities, and the allocation of enforcement and intelligence resources.
FATF assessors and evaluation teams
Those conducting mutual evaluations or applying the FATF methodology rely on the risk assessment criteria, including those relating to risk assessment set out in the FATF methodology, to gauge whether a country adequately identifies, assesses, and understands its terrorist financing risks. The quality of a national assessment can therefore shape evaluation outcomes.
Non-profit organizations and their supervisors
FATF guidance recognizes that certain sectors, such as non-profit organizations, may warrant dedicated sectoral assessment. NPOs and the authorities overseeing them have an interest in assessments that are proportionate and evidence-based, so that genuine vulnerabilities are addressed without imposing undue burdens on legitimate activity.
Compliance and risk professionals at obliged entities
Practitioners designing entity-level risk assessments and control frameworks use terrorist financing risk assessment principles to ensure their programs address this distinct threat rather than assuming money laundering controls cover it. The specific methodologies and expectations applicable to a given institution should be confirmed against the relevant national framework and applicable guidance.

Inside TF Risk Assessment

Threat identification
An analysis of the terrorist financing (TF) threats relevant to the entity or jurisdiction, which may include the sources of funds (both legitimate and illicit), the actors involved, and the methods used to raise, move, and use funds. Unlike money laundering assessments, TF assessments must account for the fact that funds may originate from legal sources, making value and volume less reliable as risk indicators.
Vulnerability assessment
An evaluation of the products, services, delivery channels, customer types, and geographies that could be exploited for TF purposes. This examines weaknesses in controls that could be abused, recognizing that vulnerabilities relevant to TF may differ from those relevant to money laundering.
Risk rating and consequence analysis
A methodology combining threat and vulnerability to produce a risk assessment, often considering the potential consequences of TF. This is generally a documented, risk-based exercise rather than a legal test, and outputs should inform the calibration of controls.
Geographic and jurisdictional exposure
Consideration of exposure to higher-risk jurisdictions, conflict zones, or areas associated with terrorist activity, as identified through national risk assessments, FATF statements, or other credible sources. Scope depends on the entity's footprint and customer base.
Sector and typology inputs
Use of typologies and red-flag indicators drawn from bodies such as FATF, national authorities, or financial intelligence units. These serve as illustrative and non-exhaustive references rather than exhaustive lists or proof of criminality.
Linkage to the risk-based approach
The assessment feeds into the entity's broader risk-based approach, informing customer due diligence, transaction monitoring, and control design. It is typically a component of the wider business-wide risk assessment expected under regimes such as the FATF Recommendations, the EU AML framework, and the UK Money Laundering Regulations.

Common questions

Answers to the questions practitioners most commonly ask about TF Risk Assessment.

Is a terrorist financing risk assessment just the same exercise as a money laundering risk assessment?
No. While the two are often combined in a single ML/TF risk assessment document and share methodology, terrorist financing and money laundering are distinct risks that should not be treated as interchangeable. Money laundering typically concerns disguising the illicit origin of funds, whereas terrorist financing concerns the destination and use of funds, which may be entirely legitimate in origin and often involve small amounts. Because of this difference, indicators that are effective for detecting laundering may be poorly suited to identifying terrorist financing, and a risk assessment should consider TF-specific factors distinctly rather than assuming ML controls automatically cover TF exposure.
Does a low money laundering risk rating mean an entity also has low terrorist financing risk?
Not necessarily. A low ML risk profile does not automatically translate to low TF risk, because the two risks arise from different factors. Terrorist financing can involve small-value transactions, funds from legitimate sources, and geographic or sectoral exposures that a purely ML-focused view may under-weight. For this reason, TF risk should generally be assessed on its own terms, considering factors such as exposure to conflict zones or high-risk jurisdictions, certain customer or channel types, and relevant national and supranational threat information, rather than being inferred from the ML rating alone.
What sources should inform a terrorist financing risk assessment?
A TF risk assessment generally draws on a combination of internal and external inputs. These typically include national and, where applicable, supranational risk assessments, guidance from the relevant supervisory or FIU body, applicable sanctions and designated-persons information, and the entity's own data on customers, products, delivery channels, and geographies. The FATF Recommendations frame TF as a standard to be addressed within a risk-based approach, but the precise expectations flow from the applicable domestic framework, so obliged entities should confirm which sources they are required to consider under their own regime.
How often should a terrorist financing risk assessment be reviewed or updated?
In many jurisdictions the expectation is that risk assessments are reviewed periodically and also updated when there is a material change, rather than on a fixed universal timetable. Triggers may include new or updated national risk assessments, significant threat intelligence, changes to the entity's products, customer base, or geographic footprint, or relevant regulatory developments. The exact frequency and triggering events should be confirmed against the applicable regulation and supervisory guidance, as requirements vary by regime and by the nature and size of the obliged entity.
Who within an obliged entity is typically responsible for the terrorist financing risk assessment?
Responsibility is generally allocated across governance layers. The compliance function or nominated officer often owns the design and execution of the assessment, while senior management or the board is typically expected to approve it and ensure adequate resourcing. The specific roles, and any formal sign-off requirements, depend on the applicable framework and the entity's structure. Firms should confirm the accountability expectations set by their own regulator, as some regimes prescribe particular officer roles or approval steps.
How does the terrorist financing risk assessment connect to an entity's controls and customer due diligence?
The TF risk assessment is intended to inform, and be operationalised through, the entity's broader control framework. Findings typically feed into risk-rating methodologies, the calibration of customer due diligence and any enhanced due diligence, transaction monitoring scenarios, and screening arrangements. These measures are designed to detect, deter, and mitigate TF risk rather than to guarantee its prevention, and the assessment should be revisited where controls reveal exposures not previously captured. The connection between assessment and controls is a risk management practice, and an alert or match arising from these controls does not by itself establish wrongdoing.

Common misconceptions

A terrorist financing risk assessment is essentially the same as a money laundering risk assessment and can be covered by the same analysis.
While often documented together as part of a business-wide assessment, TF and ML risks are distinct. ML typically involves disguising the illicit origin of proceeds, whereas TF funds may derive from legitimate sources and often involve small values, meaning threat and vulnerability indicators, and therefore the assessment methodology, generally differ.
High-value transactions are the primary indicator of terrorist financing risk.
TF frequently involves low-value transactions and funds from lawful sources, so monetary value and volume are generally less reliable indicators than for money laundering. A risk assessment should account for this rather than relying on transaction size alone.
Completing a TF risk assessment and applying controls prevents terrorist financing.
A risk assessment and associated controls are measures to detect, deter, and mitigate TF risk; they do not guarantee prevention or eliminate risk. No single control removes financial crime risk, and the assessment is a risk-management tool, not a legal determination of wrongdoing.

Best practices

Conduct and document the TF risk assessment separately or as a clearly distinguished component within the business-wide assessment, ensuring TF-specific threats and vulnerabilities are addressed rather than subsumed under money laundering analysis.
Incorporate credible external inputs such as national risk assessments, FATF statements, and financial intelligence unit typologies, treating red-flag indicators as illustrative and non-exhaustive rather than as proof of criminality.
Calibrate customer due diligence, monitoring, and control design to the outputs of the assessment in line with a risk-based approach, applying enhanced measures where higher TF risk is identified.
Account for the possibility that funds may originate from legitimate sources and may involve low values, and avoid over-reliance on transaction size or volume as the sole risk indicators.
Review and update the assessment periodically and in response to material changes in threats, products, delivery channels, customer base, or geographic exposure.
Confirm applicable obligations, thresholds, and expectations against the relevant regime, such as the FATF Recommendations, the EU AML framework, the US Bank Secrecy Act and FinCEN rules, or the UK Money Laundering Regulations, since requirements diverge across jurisdictions.