The FATF 40 Recommendations are the global baseline standards for anti-money-laundering, counter-terrorist-financing, and counter-proliferation controls. They are not law themselves, but nearly every country's AML rules trace back to them, and countries are graded on how well they meet them.
What are the 40 Recommendations, in plain English?
The FATF 40 Recommendations are the global rulebook that is not a rulebook. Issued by the Financial Action Task Force, they set the baseline standards for fighting money laundering, terrorist financing, and the financing of weapons proliferation. They cover customer due diligence, beneficial ownership, suspicious-activity reporting, supervision, and international cooperation, among much else.
Crucially, they are not law on their own. FATF has no power to bind a bank in any single country. Instead, the Recommendations take effect when national governments write them into their own laws and regulations. Nearly every AML rule you deal with, in almost any jurisdiction, traces back to one of these 40 standards.
Countries are then graded on how well they implement the Recommendations through mutual evaluations, peer reviews that assess both the technical rules and how effectively they work in practice. Those ratings shape a country's reputation and influence how others treat financial dealings with it.
What the Recommendations cover
- Prevent — Customer due diligence. Standards for identifying customers, understanding beneficial ownership, and applying a risk-based approach.
- Detect — Reporting and monitoring. Expectations for suspicious-activity reporting and ongoing transaction monitoring.
- Supervise — Oversight and powers. Requirements for supervision of financial institutions and the powers authorities need.
- Cooperate — International cooperation. Standards for cross-border information sharing, mutual legal assistance, and asset recovery.
Who is involved?
Who | Their role |
FATF | Sets and updates the 40 Recommendations and runs the evaluation process. |
National governments | Write the Recommendations into their own laws and regulations. |
Supervisors | Enforce the resulting national rules and examine firms against them. |
Obliged institutions | Banks and others that must comply with the national rules built on the standards. |
What it looks like in practice
In practice
A compliance analyst is puzzling over why a local rule requires collecting beneficial-ownership information for corporate customers. Tracing it back, the national law was written to satisfy a FATF Recommendation, which is why the requirement exists in that form.
The same analyst is assessing risk for a correspondent relationship in another country. She checks how that country scored in its FATF evaluation. A weak rating on key Recommendations raises the jurisdiction's risk and the level of diligence her firm applies. The standards shape both the rule she follows and the risk she assigns.
Why it matters to operators
The 40 Recommendations are the common ancestor of the AML rules you work under. When a national requirement looks arbitrary, it usually maps back to one of these standards, so knowing them helps you understand why local rules take the shape they do. They give you a coherent framework instead of a pile of unrelated obligations.
They also drive jurisdiction risk. A country's rating against the Recommendations, measured in mutual evaluations, shapes how risky it looks and what expectations attach to correspondent relationships with it. Reading those ratings tells you where a weak jurisdiction is likely exposed, which is exactly the kind of insight that feeds a country-risk model.
Operator notes
- Standards, not law. The Recommendations bind firms only after a country writes them into national law.
- Global baseline. Nearly every national AML rule maps back to one of the 40, which helps explain why rules exist.
- Ratings drive risk. A country's evaluation against the Recommendations feeds its jurisdiction risk and correspondent-banking expectations.
- Broader than laundering. They cover terrorist financing and proliferation financing too, not just money laundering.
- They evolve. FATF updates the Recommendations over time, for example on virtual assets, so track revisions.
Quick questions
Are the 40 Recommendations legally binding?
Not directly. They are global standards that become binding only when national governments write them into their own laws. FATF itself cannot bind a firm in any single country.
What do the Recommendations cover?
Customer due diligence, beneficial ownership, suspicious-activity reporting, supervision, and international cooperation, spanning money laundering, terrorist financing, and proliferation financing.
How are countries judged against them?
Through mutual evaluations, peer reviews that assess both the technical rules a country has and how effectively those rules work in practice. The results influence the country's risk reputation.
Why should operators care about a country's FATF rating?
Because it shapes jurisdiction risk. A poor rating raises the risk attached to that country and the diligence expected on correspondent and cross-border dealings with it.
How do the Recommendations relate to national rules?
National AML rules are largely built to satisfy the Recommendations. When you see a local requirement, it usually maps back to one of the 40, which explains its purpose.
Do the Recommendations change?
Yes. FATF periodically updates them to address new risks, such as virtual assets and proliferation financing, so it is worth tracking revisions rather than assuming a fixed text.

