The FATF: a standard without binding force
The Financial Action Task Force (FATF, Groupe d'action financière in French) is the intergovernmental body that sets international standards for combating money laundering and terrorist financing. It was created in July 1989 by a decision of the G7 summit in Paris. It has three functions: writing the Recommendations, assessing the countries that implement them, and maintaining two public lists that compliance teams around the world consult. The FATF does not legislate. None of these three outputs has the force of law, and a legal obligation arises only when each jurisdiction's legislature writes the standard into national law. Yet the standards shape account opening, corridor pricing, and onboarding times in almost every market, because institutions and their supervisors treat them as the common benchmark.
The standards consist of 40 Recommendations, first published in 1990 and revised in 1996 and 2003. In February 2012, they absorbed the nine Special Recommendations on terrorist financing adopted after 2001, and the two sets have formed a single text ever since. About 10 of the Recommendations govern payment activity directly, chief among them customer due diligence, wire transfers, and suspicious transaction reporting. The rest cover criminal law, international judicial cooperation, and non-financial professions.
| Recommendation | Topic | What it requires in practice |
|---|---|---|
| R. 10 | Customer due diligence | Identify the customer, verify identity against reliable documents, understand the purpose of the relationship, and keep records up to date |
| R. 12 | Politically exposed persons | Screening at onboarding and on an ongoing basis, senior management approval, and establishing the source of funds |
| R. 13 | Correspondent banking | Due diligence on the respondent bank, a ban on shell banks, and controls on payable-through accounts |
| R. 14 | Money or value transfer services | Licensing or registration of MTOs, mobile money, and informal systems; listing and supervision of agents |
| R. 15 | New technologies | Licensing or registration of virtual asset service providers, under the same regime as banks |
| R. 16 | Wire transfers | Originator and beneficiary information travels with the payment through the entire chain of intermediaries |
| R. 20 | Suspicious transaction reporting | Prompt report to the financial intelligence unit, with no amount threshold, attempted transactions included |
| R. 21 | Protection and confidentiality | Legal immunity for good-faith reporting, and a ban on tipping off the customer |
| R. 24 and 25 | Beneficial ownership | Accurate, current information, available to authorities in a timely manner, for companies and legal arrangements |
The two lists and what they do to corridor pricing
The FATF publishes two lists of jurisdictions after each plenary, in February, June, and October. The first covers high-risk jurisdictions subject to a call for action, commonly called the blacklist. The second covers jurisdictions under increased monitoring, the gray list, whose governments have committed to an action plan with deadlines. Neither list creates a direct prohibition, because the FATF has no binding power over institutions. The effects are still immediate. They come through the decisions of the banks and supervisors that read the lists, and they reach both account opening and transaction pricing.
| List | Jurisdictions | What an institution does |
|---|---|---|
| Call for action (“blacklist”) | North Korea, Iran, Myanmar | Countermeasures and systematic enhanced due diligence, up to refusing to do business. Applies alongside sanctions regimes, which are separate and often stricter |
| Increased monitoring (“gray list”) | Algeria, Angola, Bolivia, Bulgaria, Cameroon, Côte d'Ivoire, Haiti, British Virgin Islands, Kenya, Kuwait, Laos, Lebanon, Monaco, Namibia, Nepal, Papua New Guinea, Democratic Republic of the Congo, Senegal, South Sudan, Syria, Venezuela, Vietnam, Yemen | Case-by-case enhanced due diligence, heavier correspondent questionnaires, longer onboarding, and review of existing accounts |
Gray-listing does not close a single account on its own. It shifts the burden onto the institution, which must now show that it has its flows under control. The correspondent bank asks for more documents, requires documented governance, and charges for the extra work. Two jurisdictions on the February 2026 list matter directly for European payments. Bulgaria is an EU member state, and Monaco participates in SEPA. Belonging to an integrated regulatory area therefore says nothing about a FATF rating. The rating covers the national framework itself: its laws and the results they achieve.
- Onboarding time stretches from a few weeks to several months for an institution whose headquarters or flows touch a listed jurisdiction.
- The correspondent questionnaire gets heavier: the Wolfsberg Group's CBDDQ, the industry standard since 2018, becomes the minimum expected.
- The corridor gets more expensive, because the correspondent passes its due diligence costs on to volumes that stay small.
- Delistings matter as much as listings: the FATF removed Burkina Faso, Mozambique, Nigeria, and South Africa in October 2025, and the United Arab Emirates in February 2024.
- The latest additions, in February 2026, are Kuwait and Papua New Guinea.
The travel rule for credit transfers
The travel rule requires every institution in the payment chain to pass along the originator's and the beneficiary's identifying information with the payment. Recommendation 16 codifies it and requires that information to travel from one end of the chain to the other. It descends from Special Recommendation VII of 2001, which was folded into the standards in the 2012 overhaul. The rule addresses a basic feature of cross-border transfers: they pass through intermediaries that know neither the payer nor the payee, and no intermediary can screen information it never received.
| Data | Amount above threshold | Amount below threshold |
|---|---|---|
| Originator name | Required, verified against documents | Required, verified only if there is suspicion |
| Account number or unique transaction reference | Mandatory | Mandatory |
| Address, national ID number, date and place of birth, or customer number | At least one of these | Not required |
| Beneficiary name | Mandatory | Mandatory |
| Beneficiary account number | Mandatory | Mandatory |
| Market | Applicable law | Threshold | Watch out for |
|---|---|---|---|
| International standard | FATF Recommendation 16 and its interpretive note | $1,000 or €1,000 | A floor only. Each jurisdiction can be stricter, and many are |
| European Union | Regulation (EU) 2023/1113 of May 31, 2023, in force since December 30, 2024 | €1,000 for verification on intra-EU transfers; no threshold for crypto-assets | Replaces Regulation (EU) 2015/847 and extends the regime to crypto-asset transfers |
| United States | Bank Secrecy Act; 31 CFR 1010.410(f) for the travel rule | $3,000 | A 2020 proposed rule to lower the threshold to $250 for cross-border transfers was never finalized |
<CdtTrfTxInf>
<PmtId>
<EndToEndId>INV-2026-004821</EndToEndId>
<UETR>4c8a1f70-2b1e-4c9a-9d33-7b0e5a1c8f42</UETR>
</PmtId>
<IntrBkSttlmAmt Ccy="USD">18500.00</IntrBkSttlmAmt>
<Dbtr> <!-- originator -->
<Nm>NOVA TEXTILES LIMITED</Nm>
<PstlAdr> <!-- STRUCTURED address, not free text -->
<StrtNm>Jalan Sudirman</StrtNm>
<BldgNb>52</BldgNb>
<TwnNm>Jakarta</TwnNm>
<Ctry>ID</Ctry>
</PstlAdr>
<Id><OrgId><LEI>529900T8BM49AURSDO55</LEI></OrgId></Id>
</Dbtr>
<DbtrAcct><Id><Othr><Id>0123456789</Id></Othr></Id></DbtrAcct>
<DbtrAgt><FinInstnId><BICFI>BMRIIDJAXXX</BICFI></FinInstnId></DbtrAgt>
<Cdtr> <!-- beneficiary -->
<Nm>ATLAS IMPORT GMBH</Nm>
<PstlAdr><TwnNm>Hamburg</TwnNm><Ctry>DE</Ctry></PstlAdr>
</Cdtr>
<CdtrAcct><Id><IBAN>DE89370400440532013000</IBAN></Id></CdtrAcct>
</CdtTrfTxInf>The travel rule for crypto-assets
Virtual asset service providers (VASPs) are entities that exchange, transfer, or hold virtual assets on behalf of others. In June 2019, the FATF extended Recommendation 15 to them and made them subject to the same obligations as financial institutions. Since then, a token transfer between two platforms has had to carry the same data as a bank transfer, even though the underlying protocol has no field for it. The industry has therefore built an off-chain messaging layer that runs alongside the ledger and attaches both parties' identities to each transfer.
- What counts as a VASP: exchange between fiat currency and virtual assets, exchange between virtual assets, transfer, custody on behalf of others, and financial services related to issuance or sale.
- The data standard: IVMS 101, published by the InterVASP Messaging Standards Group, standardizes how the identities exchanged between providers are represented.
- Transport: several competing protocols coexist with no guaranteed interoperability, which remains the weak point of the system.
- Self-hosted wallets: in the EU, a transfer of more than €1,000 to or from a self-hosted address requires the provider to verify that the customer actually owns it.
- Address screening: blockchain analytics partly replaces conventional transaction monitoring, with its own limits when privacy-enhancing protocols are involved.
| Market | Legal basis | Implementation status | Observed effect |
|---|---|---|---|
| European Union | MiCA, Regulation (EU) 2023/1114, supplemented by Regulation (EU) 2023/1113 on transfers | Titles III and IV in force since June 30, 2024; the transfer regime since December 30, 2024 | Non-compliant stablecoins, USDT first among them, have been delisted from platforms serving the EU |
| Hong Kong | Stablecoins Ordinance (Cap. 656), passed May 21, 2025 | In force since August 1, 2025 | 77 expressions of interest received by the HKMA as of August 31, 2025; no license granted before the first quarter of 2026 |
| United States | GENIUS Act, the federal framework for payment stablecoins | Signed into law July 18, 2025; takes effect January 18, 2027 at the earliest | Full reserve backing required, not classified as securities, no direct access to the Federal Reserve |
The biggest blind spot in the system is geographic. Tether's USDT, the leading stablecoin rail by real-world use, serves as a substitute dollar in economies with capital controls or high inflation, from Turkey to Argentina and from Nigeria to Southeast Asia. Its market capitalization exceeds $183 billion (CoinGecko, late July 2026). It does not comply with MiCA, and platforms serving the EU have delisted it. The rail keeps running outside those platforms. Bringing one market into compliance therefore pushes transfers outside the supervised scope rather than eliminating them.
Suspicious transaction reporting by market
A suspicious transaction report (STR) is how a regulated institution alerts its country's financial intelligence unit (FIU) to a transaction it suspects is linked to a crime. Recommendation 20 requires prompt reporting of any transaction suspected of involving criminal proceeds or terrorist financing. No amount threshold applies, and attempted transactions count as much as completed ones. Recommendation 21 adds two rules that go together: immunity for good-faith reporting and an absolute ban on tipping off the customer.
| Market | Financial intelligence unit | Report name | Operational specifics |
|---|---|---|---|
| United States | FinCEN, created April 25, 1990 (Treasury) | Suspicious Activity Report (SAR) | Obligation stems from the Annunzio-Wylie Act of 1992. Filed within 30 calendar days. $2,000 trigger threshold for money services businesses. Tipping off the customer is a criminal offense |
| United Kingdom | UK Financial Intelligence Unit, part of the National Crime Agency | Suspicious Activity Report (SAR) | Consent regime specific to the Proceeds of Crime Act 2002: a defence against money laundering request holds the transaction for 7 working days, followed by a 31-calendar-day moratorium |
| European Union | One FIU per member state, coordinated by AMLA | Suspicious transaction report | AMLA is based in Frankfurt and has been operating since July 1, 2025. It is expected to start directly supervising a first group of institutions in 2028 |
| France | Tracfin, France's FIU, created in 1990 | Suspicious transaction report | A national agency under the economy ministry, with the power to block a transaction before it is executed |
| Australia | AUSTRAC | Suspicious matter report (SMR) | Three separate reports that add up: the SMR, reporting of cash transactions above A$10,000, and reporting of every international funds transfer instruction (IFTI) |
| India | FIU-IND | Suspicious Transaction Report (STR) | Governed by the Prevention of Money Laundering Act of 2002. Digital asset providers have been covered since March 2023, including offshore platforms that serve Indian residents |
| Brazil | COAF | Comunicação de operação suspeita | Filed electronically, with specific obligations for payment institutions under Banco Central do Brasil rules |
| Singapore | Suspicious Transaction Reporting Office, part of the police | Suspicious Transaction Report (STR) | Payment service providers are subject to the Monetary Authority of Singapore's AML/CFT notices issued under the Payment Services Act of 2019 |
| Kenya | Financial Reporting Centre | Suspicious Transaction Report | Under FATF increased monitoring since February 2024, which adds to any foreign correspondent's due diligence |
| Nigeria | Nigerian Financial Intelligence Unit | Suspicious Transaction Report | Removed from the FATF gray list in October 2025, after an action plan that covered supervision of money transfer operators, among other things |
FIUs communicate with each other through the Egmont Group, founded in 1995 at the Egmont Palace in Brussels, which now has more than 170 members. Its encrypted network, the Egmont Secure Web, carries their requests for assistance. Only the FIUs themselves have access; regulated institutions do not. A payment provider feels its effects only when its supervisor or its bank passes on a request for information about a customer or a transaction.
Report quality is the system's acknowledged weakness. An institution that fears penalties files defensively, and the receiving FIU gets a growing volume of reports with nothing actionable in them. In 2020, the Bank Policy Institute found that US authorities followed up on a median of just 4% of reports. The number of reports filed therefore says nothing about how well the underlying program works. Supervisors look instead at the alert-to-report conversion rate, the written rationale for alerts closed without a filing, and the time from detection to filing.
De-risking and its impact on corridors
De-risking means terminating or refusing business relationships wholesale, for entire categories of customers or countries, instead of managing risk case by case. It typically takes one of two forms: a bank closes the accounts of every money transfer operator, or a correspondent pulls out of an entire region. The FATF has condemned the practice since 2014, and in 2021 it launched work on the unintended consequences of its own standards. Correspondent relationships have kept declining since then.
De-risking shows up most clearly in correspondent banking, the layer of bilateral relationships that makes any payment possible between two banks with no direct link. The Committee on Payments and Market Infrastructures (CPMI) of the Bank for International Settlements publishes the benchmark indicator. Built from Swift messages under a mandate from the Financial Stability Board, it covers more than 200 jurisdictions. The network has been shrinking and concentrating since the early 2010s. Every relationship that disappears lengthens the chain of intermediaries needed to reach a destination, and the cost of that chain falls on corridors whose volumes are too small to absorb it.
- Document your risk appetite by country, business line, and channel, and be ready to present it. A written, dated policy approved by the board holds up in front of a supervisor or a correspondent, which an improvised call in a credit committee never will.
- Complete the Wolfsberg Group CBDDQ before anyone asks. It has become the entry ticket to any correspondent relationship.
- Secure a fallback route to settlement: CENTROlink, run by the Bank of Lithuania since 2016, gives payment institutions and e-money institutions direct access to SEPA without a sponsor bank.
- Watch concentration: relying on a single correspondent for a corridor exposes you to a unilateral exit with no meaningful notice.
- Prepare for the portfolio reviews that a gray-listing triggers, even when the institution's exposure to the country is only indirect.
Transaction monitoring
Transaction monitoring is the review of transactions that have already been executed, designed to flag those that deviate from a customer's expected behavior. It is distinct from two related controls it is often confused with, even in requirements documents. Sanctions screening runs before execution and blocks the transaction. Transaction monitoring detects after the fact. Onboarding due diligence builds the customer file when the account is opened. The confusion is costly, because each control has its own legal regime and its own tolerance for error.
| Sanctions screening | Transaction monitoring | Onboarding due diligence | |
|---|---|---|---|
| Timing | Before execution, in real time | After execution, continuously or in batches | At account opening, then periodic refresh |
| Legal basis | National and international sanctions regimes | FATF Recommendation 20 | FATF Recommendations 10 and 12 |
| Logic | Name matching, strict liability | Risk-based approach, best-efforts obligation | Risk-based approach, documented file |
| Typical failure | False positive on a namesake or a transliteration | Alert not cleared within the internal deadline | Outdated file, beneficial owner not updated |
| Consequence of a failure | Criminal offense, asset freeze, fine, loss of the correspondent | Failure to report, supervisory penalty | Supervisory penalty, mandated remediation |
SCENARIO ST-014 "structuring / splitting"
SCOPE consumer payment accounts, account age < 180 days
TRIGGER
nb_inbound_transactions(window = 10 days) >= 5
AND each amount between 0.80 x THRESHOLD and 0.99 x THRESHOLD
AND cumulative_total > 3 x THRESHOLD
AND nb_distinct_counterparties >= 3
AUTOMATIC ENRICHMENT
+ counterparty country on a FATF list -> score +30
+ account credited, then > 90% drained in 48 h -> score +40
+ IP address outside the declared country -> score +10
OUTPUT
score >= 60 -> level 2 alert, 5 business days to process
score < 60 -> level 1 alert, written closing rationale required
TUNING thresholds reviewed every six months, deviations justified in writing,
test set replayed before any production releaseTwo markets show how regulators have responded to this upstream shift in controls. In China, NetsUnion Clearing Corporation has required since June 2018 that all online payments by non-bank institutions be routed through it rather than through direct connections to banks. Since then, the central bank has had a centralized view of Alipay and Tenpay flows, and in 2025 it placed the three entities under direct AML/CFT supervision. In India, the Reserve Bank of India tightened onboarding rules in 2025 for operators of the Aadhaar Enabled Payment System, a rural inclusion rail that has become a documented fraud vector.
- Model governance is examined as closely as model performance: who approves a threshold, based on what data, and with what independent review.
- Tuning decisions must be justified in writing. Raising a threshold to cut alert volume without a documented analysis is the most common finding in examinations.
- Typology coverage must be demonstrable: every risk identified in the risk assessment needs at least one active scenario.
- Data completeness matters more than engine sophistication. A channel that is not connected to the engine is a complete blind spot.
- Name screening must handle transliteration and non-Latin scripts. Without that, the real detection rate collapses on exactly the corridors where customer names are not written in the Latin alphabet.
What compliance costs and what gets penalized
An AML/CFT penalty is a measure imposed on an institution by a supervisor or a court for failures in its due diligence, monitoring, and reporting obligations. Nothing else in payments comes close in scale. Amounts run into the billions, some settlements include a guilty plea, and some measures cap an institution's growth for years. The table below lists public decisions only. They rarely rest on proven money laundering; most often, they target the failure of the control framework itself.
| Year | Institution | Authority | Amount or measure | Grounds |
|---|---|---|---|---|
| 2020 | Westpac | AUSTRAC (Australia) | A$1.3B | Failure to report international transfers and no due diligence on flows to Southeast Asia |
| 2022 | Danske Bank | US Department of Justice | $2.059B | Guilty plea to bank fraud over flows that went through the Estonian branch |
| 2023 | Binance | US authorities | $4.3B | Bank Secrecy Act violations and no effective compliance program |
| 2024 | TD Bank | US authorities | ≈ $3.09B | AML/CFT program failures, guilty plea, and an asset cap |
| 2024 | Qiwi Bank | Bank of Russia | License revoked (February 21, 2024) | Repeated AML/CFT failures; wallets shut down and removal from the Contact transfer system |
The day-to-day cost of the framework does not come from penalties. It falls into three buckets: designated roles, third-party software, and building an audit trail. The AML/CFT officer is personally liable in most regimes, and the decision to file remains a personal one. Screening and monitoring tools are priced per active customer or per transaction, and tuning them takes more time than deploying them. A clean external audit matters as much for keeping banking relationships as for keeping the license.
- Risk assessment documented by business line, channel, product, customer segment, and geography, and updated whenever the scope changes.
- Policies and procedures approved by the board, with quantified thresholds and binding handling times.
- A proportionate due diligence framework, including simplified rules for low-value accounts. Colombia's Daviplata, a low-value deposit product launched in 2011, became the regulatory template for the entire Andean region.
- Screening and monitoring connected to every channel, with an inventory of active scenarios and the rationale for each.
- Reporting and record-keeping: an internal escalation path, neutral wording for customers, and records kept for at least five years.
- Training and independent testing: an annual plan for each at-risk group of employees, and periodic audits reported to the board.
Payment infrastructure offers one possible path forward. Project Mandala tested encoding regulatory checks into the payment protocol itself, so that compliance checks run before the transfer. The BIS Innovation Hub ran it with the Reserve Bank of Australia, the Bank of Korea, Bank Negara Malaysia, and the Monetary Authority of Singapore. The project starts from the premise that cross-border payments are held back by compliance, not by transfer technology.