ReadSafety.com
International RecommendationsFinancial Action Task Force (FATF)Last reviewed: August 2026

FATF Recommendations

FATF Recommendations are the international standards for combating money laundering, terrorist financing, and proliferation financing - the global rulebook that shapes every country's AML laws.

What You'll Learn

  • What FATF is and how it works
  • The 40 Recommendations structure
  • Know Your Customer (KYC) and Customer Due Diligence (CDD)
  • Beneficial ownership requirements
  • Suspicious Activity Reporting (SAR)
  • The risk-based approach
  • FATF mutual evaluations and grey/black lists

First: What Is This?

The Financial Action Task Force (FATF) is an intergovernmental body that sets international standards for combating money laundering (ML), terrorist financing (TF), and proliferation financing (PF). Its 40 Recommendations form the basis for anti-money laundering (AML) laws in virtually every country.

FATF does not write laws directly - it sets standards that countries must implement through their own legislation. Countries that fail to comply face being placed on FATF's 'grey list' or 'black list,' which can severely restrict their access to the international financial system.

Who Does It Apply To?

Banks and financial institutions
Money service businesses and payment providers
Designated non-financial businesses (real estate, lawyers, accountants, dealers in precious metals)
Virtual asset service providers (VASPs/crypto exchanges)
Fintech companies handling customer funds
Individuals (FATF applies to institutions, not personal transactions)
Purely domestic cash transactions below reporting thresholds

Is It Mandatory?

FATF Recommendations are not directly legally binding on institutions - they are standards for countries. However, once a country implements them into national law (which virtually all do), compliance becomes legally mandatory for regulated entities. Non-compliance can result in criminal penalties, regulatory sanctions, and loss of banking relationships.

Know Your Customer (KYC) and Customer Due Diligence (CDD)

Professional

Recommendation 10 requires financial institutions to identify and verify the identity of customers using reliable, independent source documents. CDD must be conducted when: establishing a business relationship, carrying out occasional transactions above the threshold, there is a suspicion of ML/TF, or there are doubts about previously obtained identification data. Enhanced due diligence (EDD) is required for higher-risk situations.

In Plain English

Before a bank opens your account or processes a large transaction, it must verify who you are. This means checking your ID, understanding what you do for a living, and knowing where your money comes from. For higher-risk customers (politically exposed persons, complex company structures, high-risk countries), the bank must dig deeper.

🧠Explain Like I'm 10

Imagine you want to join a club. Before they let you in, they check your school ID to make sure you are who you say you are. They also ask: 'Where did you get the money for the membership fee?' If your answer seems suspicious (like 'I found a suitcase of cash'), they ask more questions. That is KYC - making sure people are not using the club to hide stolen money.

Practical Example

A bank opens an account for a new corporate customer. Standard CDD: verify the company's registration documents, identify directors, understand the business activity, determine expected transaction patterns. The company is owned by a trust in a high-risk jurisdiction: Enhanced CDD triggered - identify the trust's beneficiaries, obtain source of wealth documentation, obtain senior management approval, conduct ongoing enhanced monitoring.

Why Does This Rule Exist?

Without KYC, criminals could open anonymous accounts to move dirty money through the financial system undetected. CDD creates a paper trail that makes it much harder to launder proceeds of crime or finance terrorism.

Common Mistake

Treating KYC as a one-time onboarding exercise. FATF requires ongoing due diligence - continuously monitoring transactions and updating customer information. A customer's risk profile can change over time (e.g., they become a politically exposed person, or their transaction patterns change dramatically).

The Risk-Based Approach

Professional

Recommendations 1 and 10 establish that countries and institutions should identify, assess, and understand their ML/TF risks, and apply AML/CFT measures commensurate with those risks. Higher-risk situations require enhanced measures; lower-risk situations may permit simplified measures. This allows resources to be allocated where they are most needed.

In Plain English

Not every customer or transaction is equally risky. A retired teacher opening a savings account is lower risk than a cash-intensive business in a high-risk country. The risk-based approach means: spend more time and resources on the risky ones, and less on the obviously low-risk ones. It is about being smart with limited compliance resources.

🧠Explain Like I'm 10

Imagine you are a lifeguard at a pool. You watch the deep end more carefully than the shallow end because that is where people are more likely to get in trouble. You do not ignore the shallow end completely, but you focus your attention where the risk is highest. That is the risk-based approach.

Common Mistake

Interpreting 'risk-based' as 'do less compliance.' The risk-based approach means doing MORE for high-risk and LESS for low-risk - but never doing nothing. A simplified approach still requires basic identification and monitoring. Some institutions use 'risk-based' as an excuse to under-invest in compliance, which regulators penalize severely.

Frequently Asked Questions

What is the FATF grey list?

The grey list (officially 'Jurisdictions under Increased Monitoring') identifies countries with strategic deficiencies in their AML/CFT frameworks that have committed to resolving them. Being grey-listed does not mean sanctions, but it signals to banks worldwide that transactions involving that country require enhanced scrutiny, often resulting in reduced correspondent banking relationships.

What is a Suspicious Activity Report (SAR)?

A SAR is a report filed by a financial institution with its national Financial Intelligence Unit (FIU) when it suspects or has reasonable grounds to suspect that funds are proceeds of crime or related to terrorist financing. Filing a SAR does not mean the customer is guilty - it means the institution has identified something unusual that warrants investigation by authorities.

What is beneficial ownership?

Beneficial ownership refers to the natural person(s) who ultimately own or control a legal entity (company, trust, foundation). FATF requires countries to ensure that beneficial ownership information is available to competent authorities. This prevents criminals from hiding behind layers of shell companies to disguise the true owner of assets.

Related Guides

Issuing organization: Financial Action Task Force (FATF)
Current version: FATF Recommendations (updated October 2023)
Effective date: Ongoing (first issued 1990, major revisions 2003, 2012, 2023)
Last reviewed: August 2026
Back to Finance