Skip to main content
Promotional banner for the pentest readiness checklist
Category: AML Framework

FATF Recommendations

Also known as: The FATF Recommendations, FATF 40 Recommendations, FATF Standards
Simply put

The FATF Recommendations are an internationally endorsed set of global standards designed to help countries combat money laundering and terrorist financing. Issued by the Financial Action Task Force (FATF), they set out measures that countries are expected to adopt, such as increasing transparency and criminalising certain conduct. They are standards that countries are expected to implement rather than a single binding law, and how they take effect depends on each country's own legislation.

Formal definition

The FATF Recommendations are the global standards developed by the Financial Action Task Force (FATF) that form the basis on which countries are expected to meet the shared objective of tackling money laundering and terrorist financing, and they also address proliferation financing. They are internationally endorsed standards rather than directly binding legislation; their legal force in any given jurisdiction depends on national transposition and implementation, and requirements may therefore vary by country. Individual Recommendations address specific measures—for example, the evidence notes Recommendation 5 (criminalisation of terrorist financing) and Recommendation 6 (targeted financial sanctions related to terrorism). Compliance with the Recommendations, and the effectiveness of a country's AML/CFT system, is assessed through the FATF Methodology and the associated mutual evaluation process. This entry describes the standards at a high level; determining specific obligations for a given entity or jurisdiction generally requires reference to the applicable national laws and professional or legal advice.

Why it matters

The FATF Recommendations serve as the reference point around which the global anti-money laundering and counter-terrorist financing (AML/CFT) system is organised. Because they are internationally endorsed standards rather than a single binding law, their practical force flows through national legislation: countries are expected to transpose and implement them, and much of the AML/CFT regulation that firms encounter day to day ultimately traces back to these standards. For compliance teams, this means that understanding the Recommendations provides context for why national obligations—such as customer due diligence, transparency, and criminalisation requirements—exist and how they are likely to evolve.

The Recommendations matter operationally because compliance with them, and the effectiveness of a country's AML/CFT system, is assessed through the FATF Methodology and the associated mutual evaluation process. The outcomes of these evaluations can influence a jurisdiction's international standing and the expectations placed on institutions operating there. As a result, the Recommendations shape not only the text of national rules but also the intensity of supervisory scrutiny and the risk environment in which regulated entities operate.

It is important to recognise the limits of the Recommendations as a source of obligation. They set out measures that countries are expected to adopt—for example, increasing transparency and criminalising certain conduct such as terrorist financing—but they do not, by themselves, impose direct obligations on private entities. The specific duties that apply to any given firm depend on how the relevant jurisdiction has implemented the standards, and requirements may therefore differ between countries. Determining precise obligations generally requires reference to applicable national law and professional or legal advice.

Who it's relevant to

Compliance officers and AML/CFT leads
Those responsible for AML/CFT programmes benefit from understanding the Recommendations as the underlying source of many national obligations. While the standards themselves do not impose direct duties on firms, they inform how implementing legislation—covering areas such as transparency and customer due diligence—is likely to be framed and interpreted. Specific obligations should be confirmed against the applicable national law.
Risk managers assessing jurisdictional exposure
Risk professionals evaluating cross-border activity may use a jurisdiction's alignment with the FATF Recommendations, as assessed through the mutual evaluation process, as one input into country and counterparty risk considerations. Because implementation and effectiveness vary by country, such assessments should not treat FATF standards as a uniform rule applied identically everywhere.
Sanctions and financial crime specialists
Practitioners focused on terrorist financing and targeted financial sanctions have direct interest in Recommendations addressing these areas—such as the criminalisation of terrorist financing (Recommendation 5) and targeted financial sanctions related to terrorism (Recommendation 6)—as implemented within their own jurisdiction's legal framework.
Policy, government affairs, and legal advisers
Those advising on regulatory developments or engaging with supervisory expectations may reference the Recommendations and the FATF Methodology to anticipate how national AML/CFT requirements could change following mutual evaluations. Applying the standards to a specific situation generally requires professional or legal advice grounded in the relevant national legislation.

Inside FATF Recommendations

International AML/CFT Standards
The FATF Recommendations set out a comprehensive framework of measures to combat money laundering, terrorist financing, and the financing of proliferation of weapons of mass destruction. They are issued by the Financial Action Task Force (FATF), an intergovernmental body, and function as internationally recognized standards rather than directly binding law in themselves.
Risk-Based Approach
A central principle of the Recommendations is that countries and obligated entities should identify, assess, and understand their money laundering and terrorist financing risks and apply mitigating measures commensurate with those risks. Higher-risk situations generally call for enhanced measures, while lower-risk situations may permit simplified measures, subject to national law.
Customer Due Diligence (CDD)
The Recommendations call for measures to identify and verify customers and, where applicable, beneficial owners, and to understand the purpose and intended nature of the business relationship. The specific thresholds, timing, and verification methods are typically implemented through national legislation and may vary by jurisdiction.
Preventive Measures for Financial Institutions and DNFBPs
The framework addresses obligations for financial institutions and designated non-financial businesses and professions (DNFBPs), covering areas such as record-keeping, ongoing monitoring, and internal controls. The precise scope of covered entities is determined by each implementing country.
Suspicious Transaction Reporting
The Recommendations provide for reporting of suspicious transactions to national financial intelligence units and address related matters. How reporting obligations, formats, and timelines operate depends on the transposing national framework.
Institutional Framework and International Cooperation
The Recommendations cover the powers and responsibilities of competent authorities, transparency of legal persons and arrangements, and mechanisms for international cooperation such as mutual legal assistance and extradition, as implemented by member jurisdictions.
Mutual Evaluation and Assessment
Implementation of the Recommendations is assessed through peer review mechanisms that evaluate both technical compliance with the standards and their effectiveness in practice. Outcomes of these assessments can influence a jurisdiction's international standing.

Common questions

Answers to the questions practitioners most commonly ask about FATF Recommendations.

Are the FATF Recommendations legally binding on financial institutions?
No, the FATF Recommendations are not themselves law. FATF is an intergovernmental standard-setting body, and its Recommendations are voluntary international standards on combating money laundering, terrorist financing, and proliferation financing. They generally become binding on institutions only once individual member jurisdictions transpose them into domestic legislation, regulation, or supervisory guidance. As a result, the specific obligations, thresholds, and enforcement mechanisms that actually apply to a firm depend on the national framework in the jurisdictions where it operates, and these may differ from the Recommendations' text. Legal advice should be sought when determining the precise obligations applicable to a specific situation.
Does the FATF maintain a list of high-risk countries and impose penalties on firms directly?
This is a common misconception. FATF does publicly identify jurisdictions with strategic deficiencies in their AML/CFT regimes, but it does not act as a supervisor or enforcement authority over individual financial institutions and does not levy fines on firms. Enforcement and penalties are the responsibility of national regulators and supervisors operating under domestic law. FATF's role is to set standards and to assess countries, not firms, through mutual evaluation processes. How a firm must treat any FATF-identified jurisdiction is generally driven by the requirements its own national regulator imposes.
How should a compliance function translate the FATF Recommendations into its own AML program?
Because the Recommendations operate through domestic law, a compliance function should typically start from the applicable national AML/CFT requirements in each jurisdiction of operation rather than from the FATF text directly. The Recommendations can be useful as a reference for understanding the intent behind local rules and for benchmarking, but the enforceable obligations flow from local legislation and supervisory guidance. Where a firm operates across multiple jurisdictions, program design generally needs to account for the highest or most specific applicable standard in each location. Application to a specific institution's risk profile may require legal or specialist advice.
How does the risk-based approach reflected in the FATF Recommendations affect implementation?
The FATF Recommendations are commonly associated with a risk-based approach, under which measures such as customer due diligence and monitoring are calibrated to the assessed level of money laundering and terrorist financing risk. In practice, how this is implemented depends on how the relevant national regulator has adopted and interprets the approach. Firms generally need to document a risk assessment, apply proportionate controls, and be able to justify their decisions to supervisors. The precise expectations for enhanced or simplified measures vary by jurisdiction, so local requirements should govern the actual controls applied.
What is the practical relevance of FATF mutual evaluations to a compliance team?
FATF and its regional bodies assess countries, not individual firms, through mutual evaluations that examine both technical compliance and effectiveness of a jurisdiction's AML/CFT regime. For a compliance team, the practical relevance is generally indirect: evaluation findings can influence how national regulators tighten rules, adjust supervisory priorities, or update guidance. Monitoring evaluation outcomes in relevant jurisdictions can help a team anticipate regulatory change, but the obligations a firm must meet still derive from the domestic requirements in force at any given time.
How should firms handle changes or updates to the FATF Recommendations?
The FATF Recommendations are periodically revised, and updates do not take effect for firms automatically. Because the standards operate through national transposition, a change to the Recommendations typically becomes relevant to a firm only once the applicable jurisdiction amends its own laws, regulations, or guidance. Compliance teams generally monitor both FATF developments and the corresponding domestic implementation timelines, since these may lag or diverge. Distinguishing current, proposed, and transitional requirements is important, and legal or specialist advice may be needed to determine when and how a specific change applies to a firm.

Common misconceptions

The FATF Recommendations are directly enforceable law that firms must comply with as written.
The Recommendations are international standards issued by an intergovernmental body, not legislation in themselves. Their obligations generally take legal effect for firms only once transposed into national law and regulation, which can vary in detail and scope between jurisdictions. Practitioners should apply the specific implementing law that governs their operations.
Meeting the FATF standards guarantees an entity is fully AML/CFT compliant.
The Recommendations set a baseline framework and emphasize a risk-based approach whose adequacy is context-dependent and subject to supervisory interpretation. Following the standards does not by itself guarantee compliance outcomes; effectiveness in practice, not just formal alignment, is generally assessed.
The FATF Recommendations only concern money laundering.
The scope extends beyond anti-money laundering to include countering the financing of terrorism and the financing of proliferation of weapons of mass destruction, among related institutional and cooperation measures.

Best practices

Rely on the specific national legislation and regulations that transpose the FATF Recommendations into your jurisdiction, rather than treating the Recommendations themselves as directly binding rules.
Conduct and document a risk assessment that identifies your money laundering, terrorist financing, and proliferation financing risks, and calibrate mitigating controls proportionately to those risks.
Implement customer due diligence procedures aligned to your applicable national requirements, including beneficial ownership identification and ongoing monitoring where required.
Maintain clear processes for detecting and reporting suspicious transactions to the relevant financial intelligence unit in accordance with local law.
Monitor updates to the Recommendations and their national implementation, and note where requirements have been amended, to keep policies and controls current.
Seek qualified legal or compliance advice when applying the standards to specific situations, as thresholds, timelines, and covered-entity definitions differ across jurisdictions.
Promotional banner for the Penetration Report Template Kit