AuditXYZ

Compliance Framework

FATF Recommendations on Combating Money Laundering and the Financing of Terrorism and Proliferation (FATF)

The FATF Recommendations are the global standard for combating money laundering and terrorist financing. This guide covers the 40 recommendations, mutual evaluations, and implementation requirements.

$30,000–$1,000,0006–24 monthsAudit Required2023 (ongoing updates to recommendations and guidance)
Issuing BodyFinancial Action Task Force (FATF)
First Published1990-04-01
Latest Version2023 (ongoing updates to recommendations and guidance)
Typical Cost$30,000–$1,000,000
Typical Timeline6–24 months
Audit RequiredYes
Audit FrequencyFATF conducts Mutual Evaluations of member countries on a periodic cycle. Individual institutions are subject to national regulatory examinations.
Geographyglobal

FATF Recommendations: Global AML/CFT Standards Guide

The Financial Action Task Force (FATF) Recommendations are the internationally endorsed global standards for combating money laundering, terrorist financing, and proliferation financing. With 40 recommendations covering the legal, regulatory, and operational measures that countries should implement, the FATF framework shapes AML/CFT legislation in over 200 jurisdictions worldwide. For any financial institution operating internationally, FATF compliance — implemented through local law — is the unavoidable foundation of the AML program.

What FATF Is and Who Issues It

FATF is an intergovernmental body established by the G7 Summit in 1989. It operates as a policy-making body that sets international standards and assesses compliance. FATF has 39 member jurisdictions plus two regional organizations (the European Commission and the Gulf Cooperation Council) as associate members. More than 200 jurisdictions have committed to implementing FATF standards through FATF-Style Regional Bodies (FSRBs) — regional organizations that extend FATF's reach across Africa, Asia-Pacific, Latin America, the Middle East, and Eurasia.

FATF publishes its 40 Recommendations as the core standard, supplemented by interpretive notes, guidance documents on specific typologies and sectors, and best practice papers. The Recommendations are updated periodically — the current version reflects revisions through 2023, including updated guidance on virtual assets, beneficial ownership transparency, and proliferation financing.

FATF does not directly regulate financial institutions. Its influence operates through the Mutual Evaluation process, which assesses how effectively member countries implement the 40 Recommendations. Countries that fail their evaluation face being placed on FATF's grey list (jurisdictions under increased monitoring) or black list (high-risk jurisdictions subject to a call for action), which can restrict their access to the global financial system and increase costs for financial institutions transacting with those jurisdictions.

Who Must Follow FATF Standards

FATF Recommendations apply at two levels:

Country Level: FATF member jurisdictions must implement the Recommendations through national AML/CFT law. This means enacting criminal laws covering money laundering and terrorist financing, establishing financial intelligence units (FIUs), building supervisory capacity, implementing international cooperation mechanisms, and requiring financial institutions to implement customer due diligence and reporting programs.

Institution Level: Financial institutions in FATF member countries face AML/CFT obligations under the national laws that implement FATF standards. These obligations typically apply to banks, securities firms, insurance companies, money services businesses, casinos, real estate agents, accountants, lawyers (for certain activities), trust and company service providers, and dealers in high-value goods.

Recent FATF guidance has extended requirements to virtual asset service providers (VASPs), including cryptocurrency exchanges, wallet providers, and DeFi platforms — though VASP regulation remains uneven across jurisdictions.

The 40 Recommendations Explained

The 40 Recommendations are organized into seven thematic areas:

AML/CFT Policies and Coordination (Recommendations 1-2)

Recommendation 1 establishes the risk-based approach as the foundational principle. Countries and financial institutions must identify, assess, and understand money laundering and terrorist financing risks, and apply measures commensurate with those risks. This means that controls must be calibrated to actual risk — not applied uniformly regardless of risk level.

Recommendation 2 requires national cooperation and coordination between competent authorities.

Money Laundering and Confiscation (Recommendations 3-4)

Recommendations 3 and 4 require criminalization of money laundering covering all serious predicate offenses and enabling comprehensive asset confiscation and provisional measures.

Terrorist Financing and Proliferation Financing (Recommendations 5-8)

These recommendations require criminalization of terrorist financing (Recommendation 5), targeted financial sanctions against designated persons and entities (Recommendations 6-7), and regulation of non-profit organizations to prevent terrorist financing abuse (Recommendation 8).

Preventive Measures (Recommendations 9-23)

This largest cluster addresses directly the obligations of financial institutions:

  • Recommendation 10: Customer due diligence — financial institutions must identify and verify customers, understand the purpose of business relationships, and conduct ongoing monitoring
  • Recommendation 11: Record-keeping — transaction records must be maintained for at least five years and be available to authorities
  • Recommendation 12: Politically exposed persons (PEPs) — enhanced due diligence for domestic and foreign PEPs, including additional approval, monitoring, and source of wealth verification
  • Recommendation 13: Correspondent banking — risk management requirements for correspondent banking relationships, including prohibition on dealing with shell banks
  • Recommendation 15: New technologies — requirement to assess money laundering and terrorist financing risks before launching new products, services, or delivery mechanisms, including virtual assets
  • Recommendation 16: Wire transfers — the "Travel Rule" requiring that originating financial institutions include originator and beneficiary information with wire transfers and that intermediary and beneficiary institutions verify and record this information
  • Recommendation 19: Higher-risk countries — enhanced due diligence for business relationships and transactions from countries identified by FATF as higher risk
  • Recommendation 20: Suspicious transaction reporting — financial institutions must file suspicious transaction reports (STRs) or suspicious activity reports with the financial intelligence unit when they suspect money laundering or terrorist financing
  • Recommendation 21: Tipping-off and confidentiality — financial institutions and their employees must be protected from criminal or civil liability for good-faith STR filings, and must not disclose that an STR has been filed
  • Recommendation 22-23: Designated non-financial businesses and professions (DNFBPs) — real estate agents, accountants, lawyers, trust service providers, and dealers in precious metals and stones must implement CDD, record-keeping, and reporting requirements

Transparency and Beneficial Ownership (Recommendations 24-25)

Recommendations 24 and 25 require countries to ensure that adequate, accurate, and up-to-date information on the beneficial ownership of legal persons and arrangements is available to competent authorities in a timely manner. The 2022 and 2023 FATF revisions significantly strengthened these requirements, driving beneficial ownership registry requirements in many jurisdictions including the EU (Corporate Sustainability Reporting Directive) and the US (Corporate Transparency Act).

Powers and Responsibilities of Competent Authorities (Recommendations 26-35)

These recommendations address supervisory frameworks, FIU powers, law enforcement capabilities, and the legal and institutional framework needed for effective AML/CFT implementation.

International Cooperation (Recommendations 36-40)

The final cluster covers international cooperation, including mutual legal assistance, extradition, and asset recovery cooperation between countries.

The FATF Mutual Evaluation Process

FATF conducts periodic Mutual Evaluations (MEs) of member countries, assessing:

  • Technical Compliance: Whether the country's laws, regulations, and institutional framework implement the 40 Recommendations
  • Effectiveness: Whether the system achieves the intended AML/CFT outcomes across 11 immediate outcomes

Countries receive ratings on both dimensions. Technical compliance ratings range from Compliant to Non-Compliant across each recommendation. Effectiveness ratings assess outcomes such as whether financial intelligence is effectively used, whether money laundering is being prosecuted and convicted, and whether financial institutions understand and implement preventive measures.

Countries rated Non-Compliant or Partially Compliant on key recommendations, or found to have significant effectiveness gaps, may be placed under increased monitoring (grey list) or called to apply enhanced due diligence measures (black list, formally the High-Risk Jurisdictions subject to a Call for Action).

Financial institutions globally must apply enhanced due diligence to customers and transactions from grey-listed and black-listed jurisdictions, creating commercial and operational implications that amplify the reputational and economic cost of FATF grey-listing for affected countries.

Costs and Timeline

Institution TypeImplementation TimelineAnnual Compliance Cost
Small financial institution6–9 months$30,000–$150,000
Mid-sized regional institution9–15 months$150,000–$500,000
Large international financial institution15–24 months$500,000–$1,000,000+

Country-level FATF implementation costs are borne collectively through government investment in FIUs, supervisory agencies, law enforcement, and judicial systems — costs that are substantial but diffuse.

  • AML/BSA: 75% overlap — US BSA/AML requirements directly implement FATF standards in the American context. For US-specific implementation detail, see the AML/BSA guide.
  • EU AML Directives: 85% overlap — the EU's AML Directives (currently on the sixth iteration) implement FATF standards within the EU legal framework, with additions reflecting EU-specific needs.
  • GLBA: 30% overlap around customer data protection and record-keeping. See the GLBA guide.
  • PSD2: Intersects with FATF on payment service provider AML obligations and the Travel Rule for payment initiation. See the PSD2 guide.

How Automation Helps

FATF-aligned AML compliance is inherently data-intensive and process-heavy. Transaction monitoring, KYC management, and STR case management require specialized AML technology. Compliance automation platforms support the governance layer:

  • Policy management tools maintain AML compliance policies aligned to national implementations of FATF requirements
  • Risk assessment frameworks document the institution's risk-based approach, including methodology and risk factor weighting
  • Training tracking ensures all required personnel complete AML training with FATF-current content
  • Vendor risk workflows assess AML compliance of correspondent banks and key service providers

LowerPlane supports AML program governance and documentation across 50-plus frameworks, including FATF-aligned requirements implemented through national AML regimes. Starting at $4,000 per year with a free tier available, and rated 9.4/10 on AuditXYZ, LowerPlane helps financial institutions maintain compliant, audit-ready programs. For fintech companies navigating cross-border AML requirements, see /for/fintech. Compare platforms at /compare/best-compliance-automation-platforms.

Frequently Asked Questions

What is the FATF grey list and how does it affect financial institutions?

The FATF grey list — formally "Jurisdictions under Increased Monitoring" — identifies countries that have committed to addressing strategic deficiencies in their AML/CFT frameworks but have not yet fully done so. Financial institutions worldwide are expected to apply enhanced due diligence (EDD) to transactions involving grey-listed countries. This means additional checks on customers and counterparties from those jurisdictions, closer monitoring of transactions, and in some cases requiring senior management approval for relationships with grey-listed country entities. Being grey-listed significantly increases the cost and complexity of doing business with and within affected jurisdictions.

Does the FATF Travel Rule apply to cryptocurrency?

Yes. FATF Recommendation 16 (the Travel Rule) requires that originating institutions include originator and beneficiary information with wire transfers. FATF clarified in 2019 that virtual asset service providers (VASPs) must comply with the Travel Rule for virtual asset transfers, passing customer information to the receiving VASP. Implementation has been challenging due to the technical complexity of passing information between VASPs using different systems. Industry solutions — including TRUST, Sygna Bridge, and OpenVASP — have emerged to facilitate Travel Rule compliance for crypto transactions. Regulatory implementation varies by jurisdiction.

How does the risk-based approach work in practice?

The risk-based approach means that AML controls should be calibrated to actual money laundering and terrorist financing risk, not applied uniformly regardless of risk level. In practice: higher-risk customers (PEPs, customers from high-risk jurisdictions, high-value transaction users) receive enhanced due diligence, more frequent monitoring, and greater scrutiny of their transactions. Lower-risk customers (domestic businesses with transparent ownership structures, government entities) may qualify for simplified due diligence in some jurisdictions. The institution must document its risk assessment methodology, apply it consistently, and be able to demonstrate to regulators that its calibration is appropriate for its risk profile.

What is a Designated Non-Financial Business or Profession (DNFBP) and do FATF rules apply?

DNFBPs are non-financial businesses and professions that FATF has identified as vulnerable to money laundering abuse. They include real estate agents (for certain transactions), accountants, lawyers and notaries (for certain activities), trust and company service providers, dealers in precious metals and stones, and casinos. FATF Recommendations 22 and 23 require DNFBPs to implement customer due diligence, record-keeping, and suspicious transaction reporting requirements similar to those applied to financial institutions. Implementation in national law varies, and many jurisdictions have been criticized in Mutual Evaluations for inadequate DNFBP oversight.

How often does FATF update its Recommendations?

FATF updates its Recommendations periodically, with significant revisions occurring approximately every decade (the current Recommendations are the 2012 version, significantly updated since). More frequent updates occur through revised Interpretive Notes, Guidance papers, and Best Practice papers on specific topics. Recent significant guidance has addressed virtual assets and VASPs (multiple updates since 2019), beneficial ownership transparency (2022-2023 revisions), and environmental crime as a predicate offense. Financial institutions should monitor FATF publications and assess the impact of new guidance on their programs.

Request a FATF consultation

Step 1 of 520%

Which framework do you need?

Framework Mappings

Overlap with other frameworks

Related frameworks

Get matched with a FATF auditor in 24 hours

Free, no-obligation — just tell us your email and we'll do the rest.

By submitting, you agree to our privacy policy.