SardineCon SF/2026

Learn More
Regulation & bodies4 分で読めます

Financial Action Task Force (FATF)とは?

SUBSCRIBE

The Financial Action Task Force is the intergovernmental body that writes the global standards for anti-money-laundering, counter-terrorist-financing, and counter-proliferation. It does not supervise a single bank, yet its Recommendations and its country lists end up baked into the rules almost every operator works under.

What is FATF, in plain English?

FATF is a standard-setter, not a regulator. Founded in 1989 and based in Paris, it is a club of member jurisdictions and regional organizations that agree on what a serious financial-crime regime should look like. Its flagship output is the 40 Recommendations, a blueprint covering customer due diligence, beneficial ownership, suspicious-activity reporting, sanctions, and supervision.

FATF has no power to fine your firm. What it has instead is peer pressure and a scoring process. It runs mutual evaluations that grade each country on both technical compliance with the Recommendations and real-world effectiveness, and it maintains the black list and grey list of jurisdictions with strategic deficiencies. Countries move heaven and earth to stay off those lists because the reputational and correspondent-banking cost of being listed is severe.

For a fraud or AML team, the key point is that FATF sits upstream of everything. Your local law, your regulator's expectations, and your country risk model all trace back, directly or indirectly, to a FATF Recommendation or a FATF typology report.

How FATF standards reach your desk

FATF guidance rarely lands on you directly. It travels down a chain into your day-to-day controls:

  1. Set — FATF issues a standard. A Recommendation, a typology report, or an updated interpretive note is published.
  2. Transpose — Countries write it into law. National legislators and regulators turn the standard into binding rules for local firms.
  3. Supervise — Your regulator enforces it. Exams and enforcement actions test whether your program meets the transposed rule.
  4. Operate — You build the control. Country risk scores, EDD triggers, and screening logic update when a list or typology changes.

Who is involved?

Who

Their role

FATF plenary

The member delegations that agree standards, approve evaluations, and decide list changes.

FSRBs

FATF-style regional bodies that apply the same standards to countries outside core membership.

National regulators

Turn FATF standards into enforceable local rules and examine firms against them.

Your compliance team

Reads listings and typologies and folds them into risk ratings, EDD, and monitoring.

What it looks like in practice

In practice

FATF adds a mid-sized jurisdiction to its grey list at a plenary meeting, citing weak beneficial-ownership controls. Within days, the country risk team at a payments firm re-rates that jurisdiction from medium to high in the onboarding model.

The change ripples outward: new customers with ties to that country now trigger enhanced due diligence, existing correspondent relationships get a fresh review, and the transaction-monitoring team tightens thresholds on flows to and from the region. None of this was ordered by the local regulator yet, but the firm acts on the FATF signal because it knows the exam questions are coming.

Why FATF matters to operators

FATF is the reason your program looks broadly the same as a peer's on the other side of the world. When you want to know where AML expectations are heading, the FATF agenda is the earliest reliable signal, often a year or two before the same idea appears as a local rule. Its typology reports are also a free, high-quality library of how launderers actually move money, useful raw material for tuning rules and writing detection scenarios.

Ignoring FATF is not really an option, because your regulator will not. Grey-listing and black-listing decisions move real money and reshape risk appetite overnight, so a team that tracks the plenary calendar is simply less likely to be caught flat-footed.

What to watch

  • List changes. Grey- and black-list updates at each plenary should flow straight into your country risk model and EDD triggers.
  • New typologies. A fresh FATF typology report often predicts your regulator's next exam focus, so read them for scenario ideas.
  • Effectiveness, not just compliance. Mutual evaluations grade real outcomes; a country can have good laws on paper and still score poorly in practice.
  • Guidance updates. Revised interpretive notes on virtual assets, beneficial ownership, or the travel rule signal where global standards are tightening.
  • Regional bodies. An FSRB evaluation can flag weaknesses in a jurisdiction FATF itself has not formally listed.

Quick questions

Does FATF regulate my firm directly?

No. FATF sets standards and evaluates countries; it never supervises or fines an individual institution. Your obligations come from the local laws that transpose FATF standards, and from the regulator that enforces them.

What are the 40 Recommendations?

They are FATF's core standards covering customer due diligence, beneficial ownership, reporting, sanctions, international cooperation, and supervision. Most national AML frameworks are built around them, which is why programs look similar across borders.

What is the difference between the grey list and the black list?

The grey list flags jurisdictions with deficiencies that are under increased monitoring and have committed to fix them. The black list is reserved for high-risk jurisdictions that call for countermeasures. Black-list countries carry far heavier consequences.

How often do the lists change?

FATF reviews and updates its public listings at its plenary meetings, typically three times a year. Any change should prompt a review of your country risk ratings and exposed relationships.

What is a mutual evaluation?

It is a peer review of a country's AML regime measuring both technical compliance with the Recommendations and effectiveness in practice. Poor results can lead to listing and follow-up monitoring, which raises the risk of dealing with that country.

How should I actually use FATF outputs?

Feed listings into country risk scoring, mine typology reports for detection scenarios, and watch guidance updates as an early warning of where local rules and exams are heading. Treat FATF as your forward-looking signal.

Go deeper

  • FATF ↗ — The global standard-setter for AML, counter-terrorist-financing, and counter-proliferation. Recommendations, guidance, and jurisdiction lists.
  • FinCEN ↗ — The US financial intelligence unit. Bank Secrecy Act rules, advisories, and SAR and CTR guidance.

Financial Action Task Force (FATF)と併せて知っておきたい用語