What Is FATF?
The Financial Action Task Force (FATF) is an intergovernmental body established in 1989 by the G7 Summit in Paris to develop policies to combat money laundering. Its mandate expanded in 2001 to include counter-terrorism financing following the September 11 attacks, and again in 2012 to cover counter-proliferation financing (blocking the financing of weapons of mass destruction).
FATF is headquartered in Paris and currently has 40 member jurisdictions, including the United States, United Kingdom, European Union, Japan, Australia, Canada, and most major economies, plus two regional organisations as members. It is not a supranational regulator and cannot directly impose rules on financial firms. Its authority comes from the political commitment of its members and the reputational and economic consequences of being placed on FATF's monitoring lists.
FATF works in close collaboration with the International Monetary Fund (IMF), the World Bank, and the United Nations to ensure AML and CFT standards are embedded in global financial architecture.
Mandate and Structure
FATF's primary functions are threefold. First, it sets international standards through its Recommendations. Second, it assesses how effectively countries implement those standards through a peer-review process called mutual evaluations. Third, it identifies jurisdictions with strategic AML and CFT deficiencies and applies pressure for reform.
FATF operates through a plenary that meets three times per year, bringing together delegates from all member jurisdictions. A Secretariat based in Paris handles day-to-day work. FATF also coordinates a network of nine FATF-Style Regional Bodies (FSRBs), such as MONEYVAL (Europe), APG (Asia Pacific), and GAFILAT (Latin America), which extend FATF's reach to non-member jurisdictions.
Mutual evaluations are the core accountability mechanism. A team of assessors from FATF and FSRBs visits a country, reviews its legal framework, and interviews regulators, banks, and law enforcement agencies. The resulting report rates the country on both technical compliance and effectiveness. Countries with poor ratings face follow-up assessments and, in serious cases, listing processes.
The FATF 40 Recommendations
The 40 Recommendations are the cornerstone of the global AML and CFT framework. They cover every element of the system, from national risk assessment and legal infrastructure to the specific obligations of financial institutions and designated non-financial businesses and professions (DNFBPs) such as real estate agents, lawyers, and accountants.
Key Recommendations directly relevant to financial firms include Recommendation 10 (Customer Due Diligence), which requires firms to verify customer identity and understand the nature of the business relationship; Recommendation 20 (Suspicious Transaction Reporting), which requires reporting of transactions suspected to involve money laundering or terrorism financing to a Financial Intelligence Unit; and Recommendation 15, which as updated in 2019 extends AML obligations to virtual asset service providers (VASPs), including crypto exchanges.
The Travel Rule (Recommendation 16) requires financial institutions transferring funds to include and transmit originator and beneficiary information. Its application to cryptocurrency transfers has been a major area of regulatory development, with jurisdictions such as the EU (under TFR), the US (FinCEN), and Singapore (MAS) each implementing versions adapted for digital assets.
FATF updates the Recommendations periodically to respond to evolving threats and financial innovation. The 2012 revision introduced a risk-based approach, allowing countries and firms to allocate AML resources proportionately to the actual risk they face, rather than applying uniform requirements to all customers and transactions.
Grey List and Black List
FATF's most powerful compliance tool is its public listing process. The grey list, formally called "Jurisdictions under Increased Monitoring," identifies countries that have agreed to work with FATF to address strategic deficiencies in their AML and CFT frameworks. Being grey-listed does not mean transactions with these jurisdictions are prohibited, but financial institutions in FATF-member countries are expected to apply enhanced due diligence to business relationships and transactions involving grey-listed countries.
The black list, formally "High-Risk Jurisdictions subject to a Call for Action," is reserved for countries with severe AML and CFT deficiencies where FATF calls on member jurisdictions to apply counter-measures. Historically, only a small number of countries have been black-listed, including North Korea and Iran. The practical effect on financial institutions is severe: banks in FATF-member countries typically restrict or refuse correspondent banking relationships and transactions involving black-listed jurisdictions, making it extremely difficult for businesses and individuals in those countries to access the global financial system.
The grey and black lists are reviewed and updated at each FATF Plenary, approximately three times per year. Countries can be added or removed based on their progress in implementing FATF Recommendations and the effectiveness of their systems.
How FATF Standards Affect Investors
Investors encounter FATF's influence primarily through the compliance requirements that their financial intermediaries, including banks, brokerages, and cryptocurrency exchanges, must meet under national AML law. In practice, this means investors face Know Your Customer (KYC) onboarding checks, periodic re-verification of identity documents, source-of-funds enquiries for large transactions, and sometimes enhanced due diligence if their profile is assessed as higher risk.
Account restrictions and transaction delays can occur when FATF-related compliance controls are triggered. Sending large wire transfers, trading in high-risk assets, or transacting with counterparties in grey-listed jurisdictions may prompt a firm to request additional documentation or temporarily restrict account activity while compliance reviews are conducted.
For cryptocurrency investors specifically, FATF's Recommendation 15 and the Travel Rule have introduced significant compliance requirements on exchanges. Most regulated crypto exchanges now require identity verification, restrict withdrawals to self-hosted wallets without additional verification, and may decline to process transfers from or to exchanges in jurisdictions not meeting FATF standards.
FATF itself offers no complaint mechanism for individuals. If you believe AML compliance procedures have been applied incorrectly by a financial institution, the recourse is through the firm's internal complaints process and then the relevant national financial ombudsman or regulator in your jurisdiction.
Frequently Asked Questions
What is FATF and is it a government regulator?
FATF is an intergovernmental policy-making body, not a government regulator. It was founded in 1989 by the G7 and now has 40 member jurisdictions. FATF does not directly supervise or license financial firms. Instead, it publishes Recommendations that member countries translate into national law, which their own regulators then enforce. The actual supervision of banks and brokerages happens at the national level, through bodies such as FinCEN and the Federal Reserve in the US, or the FCA in the UK.
What is the FATF grey list and black list?
FATF's grey list (formally "Jurisdictions under Increased Monitoring") identifies countries that have committed to address AML and CFT deficiencies but have not yet completed the necessary reforms. The black list (formally "High-Risk Jurisdictions subject to a Call for Action") identifies countries with serious AML and CFT deficiencies. Financial institutions in FATF-member countries are expected to apply enhanced due diligence for transactions involving grey-listed jurisdictions and may be required to restrict or limit transactions with black-listed ones.
How does FATF affect individual investors?
Investors experience FATF's influence indirectly through the compliance requirements their banks and brokerages must meet. FATF-aligned national rules require financial institutions to collect Know Your Customer (KYC) information, verify identity documents, monitor transactions for suspicious activity, and report certain transactions to authorities. Investors may face account restrictions, enhanced due diligence requests, or transaction delays when FATF rules are triggered, particularly for large transfers, crypto transactions, or activity connected to higher-risk jurisdictions.
What are the FATF 40 Recommendations?
The FATF 40 Recommendations are the international standard for AML, CFT, and counter-proliferation financing. They cover areas including customer due diligence, record keeping, reporting of suspicious transactions, the powers and responsibilities of financial intelligence units, and international cooperation. Member countries are evaluated through mutual evaluations to assess how effectively they implement these standards. Recommendation 15, updated in 2019, extends AML obligations to virtual asset service providers including cryptocurrency exchanges.
References
- FATF: Official Website: Home of the FATF 40 Recommendations, mutual evaluation reports, grey and black list publications, and guidance documents for financial institutions and virtual asset service providers.
- FinCEN: Bank Secrecy Act Resources: The US implementation of FATF-aligned AML standards through the Bank Secrecy Act, administered by the Financial Crimes Enforcement Network.