Tag: FATF

Ultimate Beneficial Ownership: Key Challenges and New FATF UBO Guidance

When money launderers disguise their identities behind corporate infrastructure or foreign shell companies, it falls to compliance teams to uncover the true criminal risk by running ultimate beneficial ownership (UBO) checks. Misuse of shell companies and corporate structures is a significant global threat, costing economies hundreds of millions of dollars in lost income per year, while enabling corruption and criminal activities around the world.  

Given the scale of the threat, intergovernmental money laundering watchdog, the Financial Action Task Force (FATF), includes a requirement for UBO checks as part of its 40 Recommendations – meaning that firms must consider UBO as part of their AML/CFT compliance solution. However, in a shifting risk landscape, in which criminals continuously develop new techniques to hide illegal funds, AML/CFT regulations must evolve to keep pace and, in 2023, the FATF updated its UBO guidance to reflect new challenges. 

With that in mind, we’re exploring the FATF’s UBO updates, along with some of their key compliance challenges. 

How has the FATF UBO guidance changed?

Following a 2022 commitment to “preventing the misuse of legal persons”, the FATF strengthened its UBO guidance during its February 2023 Plenary in Paris. The update specifically affected Recommendation 24, Guidance on Beneficial Ownership of Legal Persons, with the goal of ensuring that “competent authorities have access to adequate, accurate and up-to-date information on the true owners of companies” and that criminals, corrupt officials and sanctions targets cannot use shell companies “to hide their dirty money and illicit activities”. 

The FATF made 3 key updates to its UBO guidance: 

Multi-Pronged Approach

The FATF requires members to take a “multi-pronged approach” to establishing beneficial ownership that incorporates “several sources of information”. At its core, the multi-pronged approach refers to UBO information obtained by companies as part of customer due diligence (CDD), and to UBO information held by public authorities on a registry (or “alternative mechanism”) that can be accessed rapidly and efficiently. 

Under the multi-pronged approach, the FATF emphasises the importance of public and private entities being able to “access and exchange information on beneficial ownership”, and using that capability to “inform the national understanding of current and emerging risks.”

UBO Verification

The FATF clarified its guidance on the verification of UBO data in order to ensure its accuracy. The updated guidance made clear that UBO information verification must be risk-based and could include the following measures: 

  • A review of documents such as share certificates, shareholder registers, and board meeting resolutions. 
  • Manual or automated cross checks with government databases, including population registers, taxpayer registers, and vehicle and land registries. 

The verification process must prove that a natural person “actually exists and is who they claim to be”. In practice, this means conducting a review of government-issued documents and verifying a “combination of attributes” such as name, birth date, and nationality. In establishing that a person is a beneficial owner, firms should consider: 

  • Whether the person has ownership of or voting rights in the entity they control. 
  • Whether the person is actually exercising their control rights over the entity – or is taking instruction from a third party. 
  • Whether the beneficial owner is consistent with the “structure and risk profile” of the entity.  

Foreign Company Ownership

The FATF also clarified that its UBO standards should extend beyond a country’s borders, to foreign-created businesses “with sufficient links with their country”. The updated guidance states that beneficial ownership information about foreign-created businesses should be “timely”, “adequate”, and “up to date”. The 2023 update also sets out stronger controls to “prevent the misuse of bearer shares and nominee arrangements”. 

UBO Challenges in 2023

While FATF guidance calls for governments to establish public beneficial ownership registers, some countries have encountered legal friction in implementing that specific measure. 

The European Union: In the EU, the Fifth Anti-Money Laundering Directive (5AMLD) set out requirements for public beneficial ownership registries – a regulation which came into effect in January 2020. However, upon discovering that they had been added to the beneficial ownership registry in Luxembourg, several politically exposed persons (PEP) requested that their names be removed

After that request was denied in Luxembourg, the PEPs launched a legal bid, citing factors such as privacy and security risks. Ultimately, the EU Court of Justice upheld the legal bid – a decision which overrode 5AMLD and meant that many EU member states either restricted public access to their UBO registers, or suspended the registers entirely. AML/CFT experts have pointed out that the decision had significantly reduced AML/CFT transparency, and made it easier for criminals to use corporate infrastructure to conceal illegal activities. 

South Africa: In February 2023, South Africa was added to the FATF Grey List for failing to meet AML/CFT standards set out in the Recommendations. In its action plan for South Africa, the FATF set out a requirement that the South African government implement a UBO register in domestic legislation by the end of January 2025. 

Accordingly, South Africa’s Companies and Intellectual Property Commission (CIPC) is working urgently to implement amendments to current AML/CFT laws in order to bring the country into compliance with FATF standards. CIPC Commissioner Rory Voller has indicated that South Africa’s UBO register will be launched after amendments to the General Laws (Anti-Money Laundering and Combating Terrorism Financing) Amendment Act 22 of 2022 are passed. 

Address UBO Challenges with Next Generation Technology

The FATF’s 2023 update has made UBO compliance a priority for regulators around the world – and particularly in jurisdictions where legal challenges are taking valuable customer data offline. Where UBO verification has become more difficult – as a result of legal challenges or a lack of available information – firms will need to work harder to establish and verify the identities of their customers by gathering as much identifying data as possible. 

One of the best sources of information on beneficial ownership is negative news or adverse media, where breaking stories frequently reveal customer connections to corporate entities, including shell companies before that information is confirmed by official sources. Both the Panama Papers (2016) and the subsequent FINCEN Files (2020) featured revelations about shell company misuse, and exposed illicit financial activity in low-regulation jurisdictions around the world – triggering numerous AML/CFT investigations and leading to the recovery of over $500 million in lost revenue.

To capture adverse media data relevant to UBO verification, firms must implement a technology solution capable of sourcing data from around the world, while minimising false positives and noise by extracting only the most relevant information. Powered by next generation machine learning technology, Ripjar’s Labyrinth Screening platform delivers that capability, enabling firms to search for customer names across thousands of global media sources in real time, in over 20 foreign languages. Generating actionable financial intelligence in seconds, Labyrinth searches ensure your firm has the latest risk data at its fingertips, and can use that data to make faster, stronger decisions about UBO and other critical AML/CFT issues. 


Contact us to discuss how Ripjar can help you comply with the latest FATF UBO guidance

Understanding the FATF’s Digital Transformation Guidelines

As technology transforms the financial landscape, and criminal methodologies become more sophisticated, governments and authorities must address emerging risks by integrating suitable digital tools – a process known as digital transformation. 

Given the scale of the challenge, the Financial Action Task Force (FATF) has characterised the digital transformation of anti-money laundering (AML) and counter-financing of terrorism (CFT) as a “necessity”, and President T. Raja Kumar has stated that the FATF will be “exploring the opportunities that technology can offer to improve AML and CFT efforts”. The ongoing digital transformation of the intergovernmental organisation will have consequences for firms in every corner of the world, which must adjust their compliance frameworks to meet new challenges. 

The FATF has published a range of guidelines to help firms understand how it is achieving digital transformation. Let’s take a look at some of the key considerations, and explore what the process means for your AML/CFT compliance. 

The Adoption of New Technologies

The FATF’s digital transformation emphasises both the integration of new technologies and “innovative ways to use established technology-based processes”. In this context, digital transformation refers to the holistic adoption of digital tools and methods, rather than the process of simply converting analogue data to digital content. The FATF’s approach to digital transformation focuses on the following areas: 

  • New opportunities: The FATF is working to identify opportunities to leverage “emerging and existing technology-based solutions” for AML/CFT innovation. Following research, the FATF published a report into the possible opportunities and challenges of new technology-based AML/CFT solutions
  • Data analytics: The FATF is exploring how technology can enhance the analysis of “large amounts of structured and unstructured data”. This focus includes data pooling and collaborative analytics which can make it easier to identify and mitigate money laundering and terrorism financing activities, and reduce false positive alerts, while protecting user privacy rights. 
  • Operational capability: The FAFT will examine ways in which operational agencies can “harness technology to strengthen their operational capability and resilience”. Focus will also fall on optimising the use of technology, enhancing communication and information-sharing, and removing barriers to digital transformation. 
  • Digital identity: Research suggests that reliable digital ID makes it easier to perform customer identification and conduct transaction monitoring. To this end, the FATF is exploring the benefits of digital ID for AML/CFT and for improving access to financial services. 

Digital Transformation for FATF Operational Agencies

FATF operational agencies, which broadly refers to Financial Intelligence Units (FIU) within the FATF Global Network, have been integrating digital tools to enhance AML/CFT workflows and solve day-to-day challenges for years. Beyond the automated speed and accuracy of digitisation, the transformation trend reflects a desire amongst FIUs to take advantage of the following key benefits:

  • Data utility: Digital transformation offers FIUs real time access to a wider landscape of data, stored in multiple databases. That access facilitates better comprehension of AML/CFT data and analysis of AML/CFT alerts. 
  • Data capacity: Digital transformation increases data handling capacity, with FIUs able to analyse larger volumes of unstructured data. By drawing from a larger volume of data, analysts are more likely to be able to observe connections between disparate suspicious transactions.  
  • Data analysis: In the face of increasing volumes of suspicious activity reports (SAR) and suspicious transaction reports (STR), the digital transformation process enhances the efficiency and quality of AML/CFT analysis, enabling FIUs to integrate advanced analytic tools, and mine data more effectively for patterns that indicate criminal activity.  
  • Emergent risks: By integrating innovative new tools, such as AI and machine learning systems, digital transformation offers analysts a better understanding of emergent AML/CFT risks and criminal typologies, and a better chance of spotting behaviour that does not correlate with established risk profiles. 
  • Alert management: Digital tools enable FIUs to better communicate and disseminate SAR information across departments, with enhanced data security and privacy protection. Similarly, digital tools make it easier to store, analyse and provide reporting feedback for STRs. 

Digital Transformation for Law Enforcement 

Like operational agencies, global law enforcement agencies are also adopting digital tools and technologies to help them detect and investigate financial crimes. The FATF has acknowledged the importance of digital transformation to law enforcement agencies and published a confidential report into the possible AML/CFT applications and opportunities of digital technology. 

The FATF also published a public summary of the law enforcement report, which includes the following highlights:

  • Alignment of vision: The FATF suggests that law enforcement stakeholders should align their vision for their digital transformation objectives. This means considering mid and long-term issues, such as internal priorities, available resources, and technological capabilities, and ensuring that all parties are able to buy in to proposed digital initiatives. 
  • Integrating digital tools: Law enforcement agencies should be clear on which digital tools they need to to get the most out of AML/CFT data, and how to use them. The integration of digital tools should follow a clear roadmap, matched with necessary resources, and supported by in-house management or third-party partners. 
  • Ethical considerations: The integration of new screening and monitoring technologies often creates ethical considerations, especially for personal data privacy and protection. The FATF suggests that law enforcement authorities should consider whether their digital transformation efforts align with existing data protection and security frameworks, and whether legislative amendments are needed to accommodate them. 
  • Investigative support: The FATF suggests that law enforcement agencies should understand which money laundering and terrorism financing crimes would be most impacted by the application of digital tools. Agencies should also consider how to roll out their digital initiatives most effectively, and whether to develop core digital tools in-house or acquire them from third parties. 

Law Enforcement Intelligence

Digital tools enable law enforcement and other government organisations to maximise their use of valuable intelligence faster and more effectively. For example, AI-powered data fusion investigative tools, such as Ripjar’s Labyrinth Intelligence platform, enable the understanding of patterns across disparate complex data sets, deriving additional intelligence knowledge and undertaking collaborative reporting.

Those agencies can additionally utilise Ripjar’s Labyrinth Screening platform to enable searches for customers and counterparties while taking into account key characteristics, including mentions in the media or high risk jurisdictions, in order to identify suspicious activity more accurately.

The Future of the FATF’s Digital Transformation

The FATF has established the potential of new technologies to make AML/CFT measures “faster, cheaper and more effective”, and to enhance the implementation of the FATF Recommendations. While it explored the opportunities of data pooling, collaborative analytics, and data protection in 2020-21, in its Annual Report 2021-22, the FATF focused on advanced analytics, in particular machine learning systems, as a means to analyse financial intelligence, and better understand AML/CFT risks. 

The specific benefits of machine learning technology include: 

  • Automated analysis of established customer data in order to distinguish suspicious transactions from normal financial activity.
  • A reduction in the need for front-line human compliance intervention. 
  • Enhanced customer risk assessment and onboarding processes, along with improved customer experiences.
  • Enhanced information exchange between AML/CFT counterparts. 
  • Adaptive learning processes which account for emerging criminal methodologies and changes in regulation. 

Digital Transformation Compliance Solutions

Digital transformation represents a cultural change for the financial services community as much as a logistical one. Beyond seeking effective software systems to replace analogue processes, the FATF’s conception of digital transformation will require regulators and private sector firms to optimise their AML/CFT solutions by effectively harnessing the power of compliance technology – and taking advantage of the analytic possibilities of AI innovation.

In addition to delivering automated speed and accuracy, Ripjar’s Labyrinth Screening is designed to help firms meet the digital expectations of both the FATF and domestic regulators. Powered by cutting edge-machine learning technology, Labyrinth Screening is capable of fusing internal customer data with thousands of global data sources, including international watchlists, news stories, and corporate records, in real time, in over 20 foreign languages. Fully customisable to your firm’s compliance needs, Labyrinth delivers actionable financial intelligence in seconds, automatically extracting the most relevant risk data so that your firm can keep pace with criminal threats in a changing financial landscape.


Learn more about Ripjar’s AML/CFT compliance solutions to support your digital transformation, get in touch with us today

FATF Plenary, February 2023: What Compliance Officers Need to Know

The Financial Action Task Force (FATF) held its second Plenary meeting under President T. Raja Kumar in February 2023, with delegates from 206 jurisdictions and observer organisations attending in Paris. Following a turbulent 2022, the FATF Plenary involved the discussion of the world’s most significant financial crime issues, FATF membership changes, and the consequences of the Russian invasion of Ukraine. 

FATF anti-money laundering (AML) and counter-financing of terrorism (CFT) standards must be implemented in the domestic legislation of member states. In order to help your firm remain compliant with the new rules and regulations, let’s take a closer look at the key outcomes and points of interest from the FATF Plenary. 

Russia FATF Membership

Following the Plenary, the FATF released a statement on the Russian Federation’s “illegal, unprovoked and unjustified full-scale military invasion of Ukraine”. In addition to expressing sympathy for the Ukrainian people following the “huge loss of lives and malicious destruction”, the FATF noted that the actions of President Vladimir Putin’s regime posed a threat to the “security, safety, and integrity of the global financial system”. 

Accordingly, the FATF noted that it was suspending the Russian Federation’s FATF membership. With the suspension in place, the FATF added that Russia would be expected to continue to meet its AML/CFT obligations and that it would remain a member of the Eurasian Group on Combating Money Laundering (EAG). The FATF suggested that it would monitor the ongoing situation in Ukraine with a view to lifting or modifying Russia’s suspension at subsequent Plenary meetings. 

Changes to the FATF Black List and Grey List

The FATF’s list of High Risk Jurisdictions subject to a Call for Action, also known as the FATF black list, designates countries that have serious deficiencies in their AML/CFT regulatory frameworks. Black list countries pose an extremely high risk of financial crime and the FATF calls for the deployment of “counter-measures” when dealing with them. 

As of the Plenary session in February 2023, there were three countries on the FATF black list:

  • Democratic People’s Republic of Korea (unchanged since February 2020)
  • Iran (unchanged since February 2020)
  • Myanmar (added October 2022)

The FATF’s Jurisdictions Under Increased Monitoring, also known as the grey list, is a list of high risk countries that have “strategic deficiencies” in their AML/CFT infrastructure but that have committed to an action plan in order to resolve them. 

The following countries were added to the grey list at the Plenary:

  • South Africa: South Africa was added to the grey list as a result of its failure to address concerns raised in its 2021 Mutual Evaluation Report (MER). These included inadequate customer due diligence measures, and a lack of AML/CFT resources for compliance employees and law enforcement agencies. 
  • Nigeria: Nigeria’s grey list action plan sets out a series of regulatory requirements, including improvements to the country’s national AML/CFT strategy, improvements to risk-based AML/CFT supervision, and more effective investigations of money laundering and terrorism financing activities. 

The FATF also announced that two countries, Cambodia and Morocco, would be removed from the grey list, following their progress in addressing “technical deficiencies” outlined in their individual action plans. 

Beneficial Ownership Revisions

The FATF emphasised beneficial ownership as a priority in 2023 and beyond, building on details set out in its 2021-22 Annual Report. The report outlined the need for greater transparency around the “ultimate ownership and control of legal persons” in order to prevent criminals using corporate structures “to hide their identity and launder their illicit profits from criminal activities”. Accordingly, in March 2022, the FATF implemented amendments to its Recommendation 24, with a requirement for a “multi-pronged approach” to collecting beneficial ownership information.

The 2023 Plenary clarified the guidance set out in the Annual Report, with the publication of a document to help countries implement the amended Recommendation 24. The guidance sets out a requirement for countries to establish a domestic beneficial ownership registry, along with a public body to provide supervision. The Plenary also agreed to enhance Recommendation 25 in order to bring legal arrangements into alignment with the beneficial ownership standards set out in Recommendation 24. The FATF will prepare a new guidance document on the revised Recommendation 25.   

Ransomware Research

The Plenary recognised the significant increase in “the scale and number of ransomware attacks” in recent years, and the “crippling impact” that they have on businesses around the world. Given the nature of the global ransomware threat, the Plenary emphasised the need to “build on and leverage existing international cooperation mechanisms”, and for authorities to develop the necessary skillets to identify and trace virtual assets involved in ransomware attacks. 

The FATF has conducted research into the methodology of ransomware attacks and how criminals launder their financial proceeds, with a report on the research published in March 2023. 

Virtual Asset Regulations Implementation

The FATF has noted that “the lack of regulation of virtual assets” in jurisdictions around the world has created opportunities for both money launderers and terrorist financiers. In 2018, the FATF strengthened Recommendation 15, also known as the Travel Rule, to include virtual assets and virtual asset service providers. The Travel Rule requires firms to obtain identifying information about the originators and beneficiaries of virtual asset transactions, and to retain that data for AML/CFT purposes.

The 2023 Plenary agreed to strengthen AML/CFT provisions for virtual assets and virtual asset service providers, with the introduction of a roadmap for the implementation of regulations. The roadmap steps include a review of current regulatory implementations across the FATF global network, and a progress report to be published in 2024 on members’ progress in implementing new regulations. 

How Technology Can Help FATF Compliance

FATF members are required to implement FATF Recommendations in domestic legislation, which means that firms must be agile in their AML/CFT response to recent amendments. The changes announced at the Plenary, for example, require firms to conduct enhanced due diligence for customers from South Africa, Nigeria, and Russia (which is also subject to a range of international economic sanctions), and review their beneficial ownership and virtual asset AML/CFT screening capabilities. 

The global scope of FATF Plenary guidance means that firms must adjust their data collection and analysis process to capture new risks, and be able to remediate AML/CFT alerts quickly and efficiently. Ripjar’s Labyrinth Screening platform enables exactly this kind of compliance response, with real time risk screening across thousands of international data sources, including adverse media, sanctions lists, and watchlists. Blending structured and unstructured data seamlessly, in over 20 foreign languages, Labyrinth Screening brings enterprise-wide coherence to the screening process, and ensures your organisation reacts as swiftly as possible following the emergence of new regulatory standards or criminal threats. 


Learn more about Ripjar’s AML/CFT compliance solutions: get in touch with us today.

FATF Changes to Black and Grey Lists

The Financial Action Task Force (FATF) maintains a “black list” and “grey list” of countries that have “strategic deficiencies” in their anti-money laundering (AML) and counter-financing of terrorism (CFT) regimes. 

Officially known as the High Risk Jurisdictions subject to a Call for Action, the FATF black list serves to alert financial service providers to the risks of doing business with certain countries, and to encourage the governments of those countries to take appropriate action to implement the FATF’s AML/CFT Recommendations. The FATF calls on member states to apply enhanced due diligence measures when dealing with customers from black list countries and to “apply counter-measures to protect the international financial system from the money laundering, terrorist financing, and proliferation financing (ML/TF/PF) risks” that they pose.

In addition to the black list, the FATF maintains a “grey list”, referred to as Jurisdictions under Increased Monitoring. Like the black list, the grey list sets out countries that have strategic AML/CFT deficiencies, but that are cooperating with the FATF by working through an action plan to address them expeditiously.

While inclusion on the grey list denotes an elevated level of AML/CFT risk, the FATF does not advise enhanced due diligence (EDD) when dealing with designated countries. However, in the UK and EU it is a legal requirement to apply EDD when customers are based in High Risk Third Countries or if transactions involve those countries. In the UK, HMT’s list of High Risk Third Countries is the FATF grey list. In the EU, the European Commission also largely bases its list on the grey list.

As the FATF conducts its periodic reviews and Mutual Evaluation Reports (MER), countries may be added to, and withdrawn from, the black and grey lists depending on the progress (or lack thereof) that they have made in addressing relevant issues. In October 2022, following a Plenary session, the FATF updated its black list and grey list to reflect the new global AML/CFT risk landscape. In order to remain compliant with domestic AML/CFT regulations, and to avoid potential criminal risks, financial services providers and other obligated entities should be familiar with the updated lists, and understand how to achieve compliance when dealing with customers from designated countries.

Recent changes to the FATF black list

Myanmar

In February 2020, Myanmar committed to an FATF action plan to address strategic deficiencies in its AML/CFT infrastructure. That plan expired in September 2021 and, after noting a “continued lack of progress” in addressing AML/CFT issues, the FATF added Mynamar to its Jurisdictions under Increased Monitoring in October 2022. 

The FATF has identified key measures that Myanmar must implement in order to be removed from the black list. These include:

  • Demonstrating an improved understanding of key money laundering risks
  • Implementing risk-based on-site and off-site inspections 
  • Demonstrating enhanced use of financial intelligence in money laundering investigations
  • Ensuring that money laundering is investigated and prosecuted in line with its risks
  • Demonstrating international cooperation in the investigation of transnational money laundering cases
  • Increasing the seizure of the proceeds of crime, and managing the seized assets to preserve their value prior to confiscation
  • Implementing targeted financial sanctions to combat weapons proliferation financing

Myanmar joins two other countries on the black list:

  • Democratic People’s Republic of Korea 
  • Iran

Recent changes to the FATF grey list

The FATF has recently added the following countries to its Jurisdictions under Increased Monitoring: 

United Arab Emirates: In a 2022 Plenary and Working Group Meeting, the FATF noted that the UAE had made progress in addressing its money laundering and terrorism financing risk. However, it also noted that more work was required to improve the country’s money laundering investigations and prosecutions, and so added the UAE to the grey list in October 2022. 

Democratic Republic of the Congo: Following insufficient progress implementing the recommendations on its 2021 Mutual Evaluation Report (MER), the FATF added the DRC to the grey list in October 2022. 

Mozambique: While Mozambique made a political commitment to improve its AML/CFT deficiencies, the FATF noted that it had not made sufficient progress, and added it to the grey list in October 2022. 

Tanzania: Like Mozambique, the FATF noted that Tanzania had made improvements to its AML/CFT infrastructure following its 2021 MER, but had not made sufficient progress in addressing key points in its action plan. Tanzania was added to the grey list in October 2022. 

In December 2022, the FATF’s list of Jurisdictions under Increased Monitoring included the following countries: 

  • Albania
  • Barbados
  • Burkina Faso
  • Cambodia
  • Cayman Islands
  • Democratic Republic of the Congo
  • Gibraltar
  • Haiti
  • Jamaica
  • Jordan
  • Mali
  • Morocco
  • Mozambique
  • Panama
  • Philippines
  • Senegal
  • South Sudan
  • Syria
  • Tanzania
  • Turkey
  • Uganda
  • United Arab Emirates
  • Yemen

How to comply with black list and grey list changes

Countries on the FATF black list and grey list present a high risk of money laundering, and firms should exercise extreme caution when doing business with companies within those jurisdictions. While all transactions involving black list countries require firms to implement enhanced due diligence measures, firms should also treat grey list countries with a high degree of caution due to the elevated risk of financial crime. 

With this in mind, firms should review their compliance solutions to ensure that they are effectively applying the FATF AML/CFT recommendations. This means conducting risk assessments of each customer and then applying compliance measures, including ongoing screening and monitoring, that are commensurate with the risk profile that those customers present. 

In order to establish an accurate risk profile, however, it will be necessary to collect and analyse a vast amount of customer data, drawn from a range of information sources, including internal due diligence, watchlists, sanction lists, politically exposed person lists, and international media. Ripjar’s Labyrinth Screening platform has been developed for exactly this purpose: Labyrinth enables firms to screen customers in real time against thousands of data sources, including sanctions and watchlists, and foreign media sources in over 20 languages. Integrating cutting-edge machine learning technology, Labyrinth is designed to help you adapt quickly to a changing risk landscape, including updates to the FATF black and grey lists, by seamlessly blending structured and unstructured data to generate actionable compliance intelligence. 


To find out more about FATF black list and
grey list screening, contact us today.

MAS Announces Strategy For Combating the Financing of Terrorism

The Monetary Authority of Singapore (MAS), the city’s primary financial regulator, published its five-pronged National Strategy for Countering the Financing of Terrorism (CFT) on 7 October 2022. The Strategy serves as a roadmap for the development of action plans to counter the financing of terrorism through Singapore’s financial system, and emphasises the role of local law enforcement agencies with international partnerships and counterparts, reflecting the global nature of the terrorism threat.

MAS published the CFT strategy following a holistic assessment conducted in 2020. Following that assessment, the regulator identified Singapore’s key terrorism financing threats as stemming from “regional and international terrorist groups”, and from “radicalised individuals” operating alone. The CFT strategy was devised to enhance coordination between Singapore’s law enforcement agencies, government policy makers, supervisory agencies, regulators, and private sector organisations.

The five prongs of MAS’ CFT strategy are as follows:

1. Coordinated and Comprehensive Risk Identification

Under this prong of the CFT strategy, MAS will ensure that it takes a whole-of-government approach to preventing terrorism financing. In particular, MAS states that government agencies should work closely with each other through “already well-established cooperation committees and networks”. It states that these agencies should review the terrorism financing landscape on a regular basis, considering “current and emerging typologies, international standards and requirements, and inputs from the private sector and academia”.

Under the Strategy, MAS will put a comprehensive legal framework in place so that Singapore’s law enforcement authorities will be able to take “swift and effective action” against the financiers of terrorism, which may include terrorist organisations and terrorists themselves. MAS will also ensure that Singpaore’s financial sanctions framework matches international standards and conventions, and that there is a clear policy framework in place to help identify terrorists that are attempting to raise funds.

3. Robust Regulatory Regime and Risk Targeted Supervisory Framework

MAS will work to ensure that Singapore’s AML/CFT regulatory framework remains robust and resilient. Similarly, it will ensure that the city’s “risk-based supervisory framework” and private sector AML/CFT compliance requirements continue to meet international best practice standards, and the standards set out by the Financial Action Task Force (FATF).

As terrorism financing methodologies become more sophisticated, MAS will also work to improve Singapore’s surveillance and supervisory measures “through the use of data analytics and technological tools”. MAS will use those tools to collect and analyse data from global sources, and to “detect and target higher risk activities and entities” that may present terrorism financing threats.

4. Decisive Law Enforcement Actions

MAS notes that law enforcement agencies already have “an effective operational framework to investigate and prosecute” incidents of terrorism financing, but points out that there is still scope for greater inter-agency cooperation. To that end, the Strategy includes a commitment to enhance cooperation between Singapore’s law enforcement agencies in order to detect and investigate terrorism financing cases promptly. 

MAS will also expand its collaboration with private sector businesses to “better detect and disrupt” terrorism financing. Similarly, it will work to enhance Singapore’s legal framework to ensure that terrorism financing investigations are prosecuted successfully.

5. International Partnerships and Cooperation

MAS notes the importance of international cooperation in the fight against terrorism financing. With that in mind, the Strategy will see MAS “continue to rigorously implement” international anti-money laundering and counter-financing of terrorism standards, which are set by bodies such as the FATF and the United Nations Security Council (UNSC). MAS will also continue to work and cooperate with other international jurisdictions, both seeking and providing legal assistance in order to “proactively tackle” funding flows associated with terrorist financing. 

The Strategy states that MAS will use a range of mechanisms to achieve its CFT partnership and cooperation objectives, including entering into bilateral agreements, and using intelligence sharing platforms. As part of the Strategy, MAS restates Singapore’s commitment to contributing to the international fight against terrorism financing by taking “firm and resolute action” wherever it detects criminal activities.

MAS Compliance

MAS’ five pronged strategy underlines the importance of effective AML/CFT compliance for firms that operate within Singapore. The Strategy is still relatively new to the city-state’s regulatory landscape, so its immediate impact remains to be seen, but the details set out in the five prongs suggest that multilateral cooperation, with Singapore’s law enforcement agencies and with other private sector entities, will be central to AML/CFT regulatory framework going forward. 

Risk based AML/CFT will also continue to underpin Singapore’s compliance landscape, meaning that firms must continue to implement effective automated customer screening and monitoring in order to detect criminal activities. Accordingly, in order to enable that level of risk-based compliance, and cooperation with other entities, firms in Singapore must be able to harness customer data quickly and efficiently. 

Ripjar’s Labyrinth Screening platform has been developed to enable firms to achieve that compliance objective, with the capacity to screen thousands of data sources in real time, including sanctions lists, watch lists, and adverse media in over 20 languages. Labyrinth seamlessly blends structured and unstructured data, delivering actionable intelligence to help you firm understand when risk profiles change or when customers engage in suspicious activities, and then to act decisively to inform MAS in order to prevent terrorist activities


To learn more about compliance with MAS AML/CFT regulations, contact us today.

De-risking in banking: the challenges and alternatives for risk management

The financial landscape changes constantly and, as new regulations and criminal trends affect global regulatory compliance, banks sometimes act to reduce the amount of risk they face through de-risking policies. While de-risking is a way to protect banks from criminal risk, it often represents a controversial compliance option since it can result in the exclusion of certain businesses from financial markets. 

What is de-risking?

De-risking is the practice of declining or limiting financial services based on prevailing regulatory compliance requirements. More specifically, under a de-risking policy, a bank or financial service provider may adjust, end, or choose not to enter into a business relationship with a customer based on the compliance demands that doing so would present. 

Since anti-money laundering regulations require banks to put policies and procedures in place to identify, prevent, and report financial criminal activities (such as money laundering and terrorism financing), de-risking represents an alternative option for those that cannot comply effectively with the rules. In most cases, de-risking is a commercially-motivated decision: a bank may decide that it is necessary to de-risk in order to be able to afford satisfactory financial compliance in other areas of its services. 

There are no regulatory requirements for the way de-risking policies should be implemented. Financial institutions may apply de-risking measures broadly by restricting their services to entire categories of customer, or assess each customer’s risk level individually. Similarly, de-risking does not always mean that a financial institution limits their financial services: in some cases de-risking may be achieved by increasing compliance spending to boost performance. Some banks devote resources towards ongoing de-risking programmes which constantly assess the commercial viability of certain customer relationships and inform de-risking decisions. 

Why is de-risking problematic?

While de-risking has regulatory and commercial benefits for banks, its exclusionary effects mean that many customers lose or are unable to gain access to the financial system. The de-risking process particularly affects organisations that are viewed as presenting a high money laundering risk, including money transfer businesses, non-profits, charities, correspondent banking services, and fintechs. 

Many of the financial services affected by de-risking policies involve customers and clients that are located overseas, and so the practice disproportionately affects foreign customer groups, which may include vulnerable persons such as immigrants, refugees and asylum seekers, or legitimate businesses in developing countries that need access to international financial markets to grow. Studies by the World Bank have shown that de-risking takes place around the world but affects certain regions disproportionately, especially those with smaller countries or countries with only limited access to financial markets. With that in mind, the consequences of de-risking include:

  • Negative effects on financial inclusion. Customers that are unable to access financial markets are likely to remain in poverty and are less able to contribute to the economic growth of their country.   
  • Humanitarian organisations may lose access to crucial financial services and be unable to provide aid to people and areas in need. 
  • Customers that are unable to access higher quality banking services may be forced to use less-regulated banks. Similarly, criminals may resort to money laundering methodologies outside the scope of traditional AML/CFT controls. 
  • When one bank de-risks, others may follow suit out of competitive necessity, creating significant knock-on effects for the financial system and undermining confidence in the wider financial sector. 
  • De-risking can be a complex administrative process and may not be entirely effective in reducing a bank’s risk exposure. High risk customers that are declined services may be able to access others via a different branch of the same bank.  

What are the alternatives to de-risking?

De-risking policies work against Financial Action Task Force (FATF) guidance that banks should take a risk-based approach to AML/CFT. In practice, the risk-based approach means that banks should assess the compliance risk that individual customers pose, and then adjust their compliance response accordingly. This approach enables banks to balance their compliance obligations with customer service considerations, and offer their services to as broad a customer base as possible. 

With that in mind, banks may address some of the cost concerns that drive de-risking policies by implementing automated software solutions designed to streamline the compliance process. By automating customer data collection and analysis, for example, firms may build accurate risk profiles for their customers quickly and in large volumes, and use that information to make compliance decisions. Similarly, automated software enables firms to conduct transaction screening in seconds, establishing money laundering risk without compromising customer experiences.

Ripjar’s Labyrinth Screening platform is capable of screening customers against thousands of structured and unstructured data sources in real time, including sanctions and watchlists, and adverse media stories in 21 languages. Rather than declining services to customers as part of a de-risking strategy, Labyrinth Screening enables you to enhance customer safety and regulatory compliance, in a challenging financial landscape, and adapt quickly when new methodologies or regulatory responsibilities emerge.  


To learn more about how Ripar can help you find alternatives to de-risking, contact us today

FATF’s 2022 Mutual Evaluation Report on Germany: An Overview

The Financial Action Task Force (FATF) has released its latest Mutual Evaluation Report (MER) on Germany. As a intergovernmental anti-money laundering (AML) and counter-financing of terrorism (CFT) regulator, the FATF conducts mutual evaluation reports on its members in order to gauge their compliance with the regulatory standards that it sets – specifically its 40 Recommendations. The MER process is in-depth and, when published, sets out details of the country’s AML/CFT compliance performance along with recommendations for regulatory improvements to help combat financial criminal threats. 

The FATF released its Germany MER in August 2022. As a prominent regional and global economy, Germany’s response to the MER will have consequences both for the businesses that operate within its borders and those beyond. Given that significance, it is important that firms in Germany understand the contents of the latest MER and what consequences it may have for Germany’s regulatory landscape.

German AML/CFT Progress

The FATF found that while Germany continues to face significant financial criminal threats, its regulatory response is generally well-suited to managing risks, and its financial institutions are generally well supervised by the Federal Financial Services Authority (BaFin) and the Financial Intelligence Unit (FIU). Similarly, Germany’s authorities are effective at detecting and prosecuting terrorism financing threats within its financial system.  

The FATF also found that Germany made “significant improvements” to its AML/CFT framework in the five years since its last assessment. Notable AML/CFT advances included: 

  • Use of the National Risk Assessment (NRA) process as a way to enhance the national understanding of money laundering risks. 
  • Introduction of cooperation and coordination mechanisms between federal and state governments. 
  • Boosting human resources for state financial regulator BaFin and the FIU. 
  • Removing asset recovery limitations for money laundering offences. 
  • Introduction of a Transparency Register to allow improved access to beneficial ownership information. 

FATF AML/CFT Recommendations 

While the FATF praised positive developments in Germany’s approach to AML/CFT regulation, it also stressed a need to address a range of regulatory deficiencies. The key areas for regulatory attention included: 

Sources of Risk

Although Germany had demonstrated a strong response to domestic money laundering and terrorist financing risks, its perspective of the wider risk landscape was limited. 

The FATF found that the regulatory focus on money laundering risks from real estate and cash was causing German authorities to “overlook other important risks” such as those created by complex corporate structures including shell companies and foreign companies. This kind of threat was attributed to Germany’s status as a global financial hub, which made it a target for international financial criminals. The FATF noted that German law enforcement authorities “tend to focus on natural persons” rather than foreign criminals and professional enablers, an approach which ends up “limiting the information available for assessing risks”.

Correspondent Banks

The FATF noted that, as an international destination for financial services, Germany faces a significant money laundering threat from the higher risk correspondent banking sector. The MER found that German correspondent banking institutions had problems with the scope and accuracy of the data that they were accessing to address and verify those types of banking threats. 

In order to improve the way that correspondent banks access and utilise their AML/CFT data, the FATF noted that Germany should accelerate the integration of advanced analytics technologies within public and private sector compliance frameworks. In particular, larger correspondent banks should seek to integrate bespoke technology solutions to address the increased AML/CFT risk that they face. 

Risk Assessment

While the FATF found that Germany’s larger financial institutions tended to address their risk exposure with suitable customer due diligence (CDD) measures, smaller institutions, institutions outside the financial sector, and designated non-financial businesses and professions (DNFBP) were not matching that response. In particular, the FATF found that the weaker level of risk understanding from these institutions was negatively impacting “their ability to develop and implement preventative measures aligned to their ML/TF risks”.

The FATF characterised this deficiency as a “reactive rather than proactive” approach to risk based anti-money laundering with the implication that regulators need to take a unified, strategic approach to the problem, strengthened by coordinated AML initiatives such as data-sharing between financial and non-financial organisations. 

Sanctions Implementation

The FATF identified failings in the implementation of global economic sanctions amongst firms in Germany’s financial sector. In particular, the FATF criticised Germany for not proactively designating individuals listed on international sanctions lists (such as the UNSC list) in its domestic legislation in line with its AML/CFT strategy. 

Similarly, the FATF noted that German regulatory supervision of sanctions compliance was “not fully effective”, with the problem again particularly notable “in the DNFBP sectors”. It also criticised the impact of German financial sanctions on their targets, suggesting that, for example, the amounts of assets frozen in sanctions actions were low “compared to total amounts raised in Germany”. 

German FATF Compliance

Germany has committed to addressing the AML/CFT issues raised by its 2022 MER, which placed a strong focus on risk management and customer data. With that in mind, German regulators are likely to emphasise a need for accurate and agile risk management, with a need for firms to integrate software solutions tailored to their specific compliance needs. 

With that challenge in mind, Ripjar’s Labyrinth Screening platform is a powerful compliance tool that enables firms to screen against thousands of global risk data sources in real time, including sanctions lists, PEP lists, and adverse media sources in 21 languages. Integrating cutting edge machine learning technology, Labyrinth seamlessly blends structured and unstructured data enabling firms in Germany to stay in control of their risk environments. As the German government responds to the FATFs findings, Labyrinth will also help firms adjust quickly and efficiently to new legislation with tailored risk management solutions – ensuring you stay compliant even as customer risk profiles change. 


To learn more about how Labyrinth Screening can support your risk management in Germany, contact us today. 

FATF Guidance On Virtual Assets

The Financial Action Task Force (FATF) has applied its anti-money laundering (AML) and counter-financing of terrorism (CFT) standards to virtual assets and virtual asset service providers (VASP) since 2019. The intergovernmental body has noted that virtual assets have “the potential to radically change the financial landscape” but that regulators must also become familiar with a “new vocabulary” in order to effectively address the criminal threats that the technology brings. 

Regulatory Progress

The FATF has issued periodic updates and guidance on how its standards should be applied to virtual assets and VASPs, with a heavy focus on Recommendation 16, also known as the ‘Travel Rule’. Recommendation 16 requires private sector institutions to trace both the originators and recipients of funds when they are sent across borders, and maintain suitable records of those transactions. 

In practice the Travel Rule requires firms to implement suitable Know Your Customer (KYC) measures, including capturing names, addresses, and account numbers in order to establish the identity of customers and counterparties. In the context of virtual assets, service providers must ensure they collect this information despite the anonymity challenges associated with cryptocurrency transactions. 

As of 2022, the FATF noted that the vast majority of jurisdictions had not passed the relevant laws necessary to implement the Travel Rule for virtual assets. A 2022 FATF report revealed that, since June 2021, of 98 responding jurisdictions only 29 had passed virtual asset Travel Rule legislation and only 11 had implemented any enforcement or supervisory measures. The report suggests that the level of Travel Rule implementation amongst non-reporting FATF jurisdictions is likely to be slower than reporting jurisdictions. 

The FATF found that the delay in the implementation of the Travel Rule in some jurisdictions was a result of undeveloped or in-progress virtual asset regulatory regimes, or a lack of domestic expertise in Travel Rule compliance. 

Travel Rule Implementation

Both the FATF’s research and open source reports suggest that the private sector has led in the implementation of the Travel Rule, often going beyond requirements for the public sector. Private sector VASPs are taking advantage of novel technological solutions to achieve Travel Rule compliance, with a focus on interoperability with other AML/CFT solutions, and the need to scale with global solutions implemented by counterparts. 

Despite the private sector progress, the FATF has highlighted a number of challenges affecting Travel Rule implementation. These include:

  • Some Travel Rule compliance solutions are only compatible with certain types of virtual assets.
  • Some VASPs, along with counterparties or third-party service providers, require approval over Travel Rule compliance solutions. 
  • A lack of consensus over which solution (or solutions) will meet FATF and local compliance obligations. 
  • A lack of shared and clear information about VASP Travel Rule obligations from official sources. 

The FATF has acknowledged that many VASPs are still in the very early stages of Travel Rule implementation. In order to accelerate that process, the FATF has emphasised the need to engage with jurisdictional authorities and the private sector, and encourage the further development of solutions “that are global, interoperable, and can accommodate for nuances across national requirements.”

Emerging Issues and Risks

The need for VASPs to implement the Travel Rule has grown more urgent as a result of developments on the cryptocurrency landscape. The FATF has set out some of the key emerging risks and market developments:

Decentralised finance

FATF research suggests that decentralised finance (DeFi) markets have grown significantly from 2021-22, with increasing use of stablecoins and cross-chain bridge software. The FATF has stated that it will continue to monitor DeFi developments to ensure that AML/CFT standards remain relevant. 

Non-fungible tokens

Like DeFi markets, use of non-fungible tokens (NFT) has also increased, along with opportunities for criminals to use them to launder money. The FATF notes that the increase in active wallets trading in NFTs and disparities in the way NFTs are defined across jurisdictions has created new AML/CFT risks. 

Peer-to-peer payments

The FATF has noted that peer-to-peer (P2P) payments of virtual assets potentially fall outside the scope of the AML/CFT recommendations – and will continue to monitor emerging risks. 

Stablecoins

As stablecoin liquidity increases, so do the potential risks to consumers. The FATF has stated that it will “continue to facilitate discussion between jurisdictions and other standard setting bodies” on VASP regulation implementation issues as they relate to stablecoins. 

Sanctions evasion

The FATF has recognised the potential for the anonymity of virtual assets to aid attempts at sanctions evasion – although liquidity limitations have prevented this happening on a large scale. With that in mind, the FATF has noted that the Travel Rule is vital in helping VASPs identify counterparties involved in transactions. 

Ransomware

The criminal use of virtual assets is often linked to ransomware money laundering, with criminals using non-compliant VASPs to transform illegal proceeds. In addition to implementing the Travel Rule, the FATF has highlighted opportunities to use blockchain analytics technology to trace ransomware-related money laundering. 

VASP Compliance: Next Steps

The FATF has urged member states and jurisdictions to “lead by example” in order to promote the implementation of the Travel Rule by encouraging VASPs to share knowledge and good practices. In particular, the FATF has highlighted the importance of technological solutions in achieving Travel Rule compliance and especially in cross-border compliance. Similarly, the FATF suggests that the private sector should work to “facilitate interoperability across Travel Rule technological solutions”. 

In order to comply with the Travel Rule, and adapt to the changing landscape of virtual asset regulations, VASPs and other obligated entities must implement suitable risk management solutions to analyse vast amounts of customer and transaction data. Ripjar’s Labyrinth platform is designed with that requirement in mind, integrating advanced screening software and machine learning systems capable of capturing data in real time from across the world – and ensuring that your organisation is informed as soon as its risk exposure changes. 


To learn how Ripjar can help you comply with the FATF’s virtual assets guidance, contact us today.

FATF Objectives Under the Singapore Presidency

On 1 July 2022, T. Raja Kumar became the first Singaporean president of the Financial Action Task Force (FATF), succeeding the outgoing German Presidency of Dr Marcus Pleyer. President Kumar brings a depth of experience to his role at the head of the inter-governmental anti-money laundering authority, including senior leadership roles in Singapore’s police force and Ministry of Home Affairs. Kumar described his new position as “an honour and a privilege” and stated that the FATF Singapore Presidency would “focus on enhancing the effectiveness of anti-money laundering and counter-terrorist financing measures across FATF member jurisdictions and the wider Global Network”. 

Kumar set out the FATF’s objectives under the Singapore Presidency which will run from 2022 to 2024. Those objectives fall into the following categories: 

  • Strengthening asset recovery
  • Countering illicit finance of cyber-enabled crime
  • Increasing effectiveness of global AML measures
  • Reinforcing FATF partnerships with FATF-stye regional bodies (FSRB)

Given the important role that the FATF plays in setting global anti-money laundering (AML) and counter-financing of terrorism (CFT) policy and regulations, it is important that banks and financial institutions become familiar with the FATF’s objectives under the Singapore Presidency. 

With that in mind, we’re taking a closer look at the key points of interest raised in the FATF’s recently published Objectives for 2022-2024. 

Cyber-Enabled Crime

The FATF Singapore Presidency recognised that cyber-enabled crime (cybercrime) has dominated the financial compliance landscape since 2020 – and will only continue to increase in sophistication. If authorities do not implement strategies to address the threat, the Singapore Presidency notes that more criminal organisations will engage in cybercrime, and pose a growing threat to global financial stability. 

Given that threat, and the potential for criminals to take advantage of new technologies to perpetrate sophisticated crimes, the Singapore Presidency will introduce a new initiative focusing on money laundering and terrorism financing strategies that are linked to cyber-enabled crimes such as frauds and scams. The initiative will: 

  • Seek to understand the challenges associated with cybercrime AML/CFT.
  • Analyse the types of money laundering techniques used in relation to cybercrime. 
  • Identity appropriate tools to fight cybercrime, including data analytics and industry partnerships.
  • Highlight best practices to help FATF members learn how to fight cybercrime-related money laundering and terrorism financing. 

Global AML Measures

The FATF Singapore Presidency has announced that “increasing the effectiveness of AML/CFT measures” will be a key focus of its role. It has committed to continuing and completing the FATF’s existing work plans which include a review of FATF standards to ensure that they remain relevant and up to date, and undertaking groundwork for the fifth round of FATF mutual evaluations. In more detail, the work plans will include: 

  • Virtual assets: The FATF will monitor the new money lanudering and terrorism financing risks relating to virtual assets and virtual asset service providers (VASP). The work will include the implementation of best practices and mitigation measures, and efforts to ensure that countries are able to apply FATF recommendations to virtual assets. 
  • Beneficial ownership: The FATF will oversee the completion of new guidance on amendments to FATF recommendations on beneficial ownership information for trusts and other legal arrangements. 
  • Data analytics: The FATF will promote the adoption of data analytics by financial authorities by “sharing and focusing on” case studies. 
  • Risk awareness: The FATF will continue to raise awareness of money laundering and terrorism financing risks associated with environmental crime, the illegal wildlife trade, and grand and systemic corruption. 
  • Strategic Review outcomes: Following the FATF Strategic Review in April 2022, the Singapore Presidency will work to implement the relevant outcomes. This effort will include updating training materials and making sure that financial experts are available to conduct effective mutual evaluations and reviews based on these new areas of assessment focus. 

In continuing the FATF’s work plans, the Singapore Presidency will also focus on strengthening a culture within the FATF that identifies best practices quickly and that drives AML/CFT effectiveness by sharing knowledge. 

Download APAC Report

Additional AML/CFT Priorities

In addition to the key cyber-enabled crime initiative and the implementation of ongoing FATF work plans, the Singapore Presidency has committed to a number of additional operational initiatives. 

Asset Recovery

The FATF Singapore Presidency has indicated that it will help countries enhance asset recovery related to financial crimes – and in particular from “fraud, scams, and ransomware”. The FATF will conduct an assessment of current asset recovery networks in order to develop strong operational systems and to encourage “substantive changes” in the way that countries approach the asset recovery process. The effort will include increased collaboration between the FATF, FSRBs and asset recovery networks, and cooperation with strategic partners such as the UN, the IMF and INTERPOL. The FATF will convene a Global Roundtable with law enforcement agencies, regulators and investigators in order to focus on actionable changes. 

FSRB Partnerships

Building on the work of the German Presidency, the FATF Singapore Presidency will seek to closely partner with FSRBs in order to strengthen the FATF’s Global Network in the fight against money laundering and the financing of terrorism. The Singapore Presidency will aim to focus on the specific needs of FSRBs, their current levels of expertise, and the next round of mutual evaluations. 

FATF Compliance

The FATF Singapore Presidency’s priorities indicate a growing focus on the risk of cybercrime, and a need for banks and financial service providers to respond to the sophistication of criminal money laundering methodologies. With that in mind, organisations should seek to implement a risk management solution capable of capturing a broad range of risk data in a constantly-changing regulatory environment, and do so with a global perspective by incorporating information from foreign sources. 

Ripjar’s Labyrinth Screening solution is designed to meet that requirement, integrating cutting-edge compliance technology and machine learning tools. Labyrinth includes next generation adverse media screening enabling clients to match customer names against a spectrum of foreign language news stories and stay informed of changes to risk profiles – before that news is confirmed by domestic outlets or even official sources. 


To learn more about how Labyrinth Screening can support your AML/CFT risk management, get in touch with Ripjar today.

What is the FATF?

The Financial Action Task Force (FATF) is a global money laundering and terrorist financing authority that works to prevent financial criminal activity and promote global compliance standards. The FATF was founded in 1989 following an agreement by the G7, which at the time comprised Canada, France, West Germany, Italy, Japan, the UK and the US. The agreement recognised the need for an international organisation that could study emerging financial crime trends, and monitor the anti-money laundering (AML) standards of world governments. In 2001, following the September 11 terrorist attacks, the FATF added the counter-financing of terrorism (CFT) to its mandate.

Upon its foundation, the FATF had 16 member states. By 2022, that number had grown to 39, with hundreds more committed to implementing its AML/CFT policies and recommendations.

What does the FATF do?

The FATF’s stated objectives are to ‘set standards and promote effective implementation of legal, regulatory, and operational measures for combating money laundering, terrorist financing and other related threats to the integrity of the international financial system’. The FATF achieves those objectives in two main ways: by developing and implementing AML/CFT policy in the form of a series of recommendations, and by issuing mutual evaluation reports (MER) on individual countries in order to assess their domestic AML/CFT compliance performance. 

The FATF’s 40 Recommendations

The FATF’s recommendations represent a list of AML/CFT compliance measures and controls that member states must implement and enforce via domestic legislation. There are currently 40 recommendations, each of which address some aspect of money laundering methodology, and an additional 9 Special Recommendations that address terrorism financing. The 40 Recommendations set out details of specific compliance controls and require member states to adopt the following regulatory principles: 

  • Money laundering should be treated as a criminal offence and authorities should be able to confiscate its proceeds. 
  • Member states should establish a national authority known as a financial intelligence unit (FIU) to analyse and process money laundering reports submitted by financial service providers. 
  • Domestic firms should be required to implement a risk-based approach to AML/CFT compliance, conducting assessments of their customers and transactions and then deploying an AML response commensurate with the risk that they face. 
  • Firms should conduct suitable due diligence on their customers in order to build accurate individual risk profiles and determine the appropriate compliance response.
  • Firms should monitor their customers’ financial activity on an ongoing basis. 
  • Firms should submit suspicious activity reports (SAR) to the authorities in a timely manner when they detect potential money laundering activity. 
  • Member states should co-operate with international money laundering investigations and prosecutions. 

Mutual Evaluation Reports

FATF mutual evaluation reports are in-depth reports which analyse a country’s success in implementing the 40 Recommendations. The MER process involves a peer review by representatives of different FATF member states who assess the target country’s technical compliance with the FATF’s AML/CFT recommendations, and the effectiveness of those measures in combatting money laundering and terrorism financing. 

When an assessment is completed, the FATF publishes the country’s mutual evaluation report. The report sets out a detailed description of the target country’s AML/CFT performance, and provides recommendations for that country to enhance its AML/CFT framework. 

A mutual evaluation report is extremely important for a country’s global economic profile. Positive MERs may provide a significant economic boost; the lower the AML/CFT compliance risk, the more likely it is that a country will be able to establish business connections with international partners. Conversely, countries that perform poorly on their MER may be considered too high a compliance risk for many potential business partners. 

The FATF Greylist

When a MER reveals serious AML/CFT deficiencies, the FATF may add that country to its high risk AML watchlists. Firms should exercise a high degree of caution when dealing with countries included on the lists since the designation denotes an increased risk of financial crime and regulatory compliance violations. The FATF maintains the following high risk watchlists:

Jurisdictions Under Increased Monitoring

Sometimes referred to as the ‘greylist’, the FATF’s Jurisdictions Under Increased Monitoring list designates countries that have ‘strategic deficiencies in their regimes to counter money laundering, terrorist financing, and proliferation financing.’ Greylist countries represent high AML/CFT risks but have committed to working with the FATF to resolve the relevant deficiencies and facilitate their removal from the list. In 2022, following the addition of Turkey, Jordan, and Mali, there were 24 countries on the greylist.

High Risk Jurisdictions Subject to a Call for Action

Sometimes referred to as the ‘blacklist’, the High Risk Jurisdictions Subject to a Call for Action list refers to countries that the FATF deems to have serious deficiencies in their AML/CFT frameworks and that represent a significant criminal threat. These countries are highly likely to be the target of international sanctions and the FATF calls on member states to apply ‘counter-measures’ when dealing with them. As of 2022, there were two FATF blacklist countries: Iran and North Korea.

How to Comply with FATF AML/CFT Regulations

FATF member states must implement the 40 Recommendations through domestic legislation, imposing a range of AML/CFT compliance standards on firms within their jurisdiction. In the UK, for example, FATF Recommendations are implemented via the the Proceeds of Crime Act 2002 (POCA), the Terrorism Act 2000 and the Money Laundering, Terrorist Financing and Transfer of Funds Act 2017. In the US, FATF Recommendations are implemented via the Bank Secrecy Act and the Patriot Act, and in the EU via the Anti-Money Laundering Directives – the most recent being the Sixth Anti-Money Laundering Directive.

These regulations set out a range of reporting and record-keeping obligations, and require firms to implement a risk-based approach to AML/CFT. Broadly, FATF compliance requires firms to: 

  • Conduct suitable customer due diligence in order to establish the identities of their customers. 
  • Screen customers and their transactions in order to verify their status as politically exposed persons (PEP) and to find out whether they are included on international sanctions lists
  • Conduct adverse media screening in order to capture changes in customers’ risk profiles quickly and efficiently. 
  • Submit suspicious activity reports to the relevant financial authority when money laundering alerts are generated. 

FATF Compliance Technology

In order to comply with FATF AML/CFT regulations, firms must analyse a vast amount of customer and transaction data for signs of money laundering, terrorism financing, and other financial crimes. In practice, this means integrating effective compliance technology capable of analysing data with speed and efficiency, helping firms build accurate customer risk profiles, and adapting to future changes to the FATF’s AML/CFT guidance. 

Future FATF regulations

As the financial landscape changes, the FATF’s regulatory focus shifts to engage with emerging threats, including the influence of fintech and regtech innovations. Recently, the FATF has highlighted the money laundering risks associated with cryptocurrencies and virtual assets, and released a report in 2020 on Virtual Assets Red Flag Indicators of Money Laundering and Terrorist Financing. The report included a range of characteristic signs of money laundering involving cryptocurrencies, and was based on research conducted by the FATF into prior money laundering investigations. In 2021, the FATF issued updated guidance on the risk-based approach for cryptocurrency service providers, pointing out that ‘continued monitoring and engagement between the public and private sectors’ would be necessary to protect the global financial system. 


Get in touch to learn how Ripjar can help you comply with FATF recommendations

FATF Black Lists and Grey Lists

The Financial Action Task Force (FATF) maintains and publishes lists of countries that fall short of its anti-money laundering (AML) and counter-financing of terrorism (CFT) recommendations. While countries that are non-cooperative with FATF recommendations are included on its ‘Black List’, countries that fall short or that are working towards those standards are included on its ‘Grey List’. 

The Grey and Black lists change as countries improve their regulatory AML/CFT standards, and it is important that firms understand what a listed status means for their compliance expectations when doing business.

What is the FATF Grey List?

The FATF’s Jurisdictions under Increased Monitoring – also known as the ‘Grey List’ – is a list of countries that the intragovernmental organization has determined have “strategic deficiencies in their regimes to counter money laundering, terrorist financing, and proliferation financing.” Inclusion on the Grey List means that FATF feels that a country poses an elevated AML/CFT risk – and that firms should reflect that risk in their compliance response when handling relevant transactions. In contrast to its Black List, FATF does not call for its member states to automatically apply enhanced due diligence (EDD) measures as part of their compliance response – but instead asks that they take Grey List information “into account” when performing risk analysis. 

In addition to the elevated AML/CFT risk, designation on the Grey List also means that a country has committed to working with FATF, and with FATF-style regional bodies (FSRB), to resolve its strategic deficiencies under agreed timeframes. Grey list countries must identify the causes of their money laundering problems, and then report to FATF on the progress they make in addressing them. The Grey List is a changing document, with new countries added to and withdrawn from it as they are reviewed by FATF on an ongoing basis. In 2021, the Grey List included the following countries: 

  • Albania
  • Barbados
  • Burkina Faso
  • Cambodia
  • Cayman Islands
  • Haiti (added in June 2021)
  • Jamaica
  • Jordan
  • Mali
  • Malta (added in June 2021)
  • Morocco
  • Myanmar
  • Nicaragua
  • Pakistan
  • Panama  
  • Philippines (added in June 2021)
  • Senegal
  • South Sudan (added in June 2021)
  • Syria
  • Turkey (added in October 2021)
  • Uganda
  • Yemen
  • Zimbabwe

The Black List

While the FATF Grey List includes countries that are subject to increased monitoring as a result of their AML/CFT deficiencies, the Black List includes those countries that FATF has deemed to have “significant strategic deficiencies” in their AML/CFT regimes. 

Set out in FATF’s High Risk Jurisdictions subject to a Call for Action, Black List countries represent severe criminal risks to financial systems. Black List countries may be engaging in ongoing illegal activities, including the proliferation of weapons of mass destruction, or have failed to enact AML/CFT action plan measures set out by FATF.  Accordingly, FATF calls on its members to implement a more intensive compliance response to Black List countries than it does Grey List countries, including applying enhanced due diligence measures to any relevant transactions. 

In “serious cases” of AML/CFT risk with Black List countries, FATF calls upon its members to actively apply countermeasures as a means to protect the global financial system from the threats that they pose. During 2021, the only countries on the Black List were:

  • Democratic People’s Republic of Korea (North Korea)
  • Iran

Both North Korea and Iran have featured on the Black List as far back as 2012. In 2020, Iran was re-designated on the Black List after its failure to implement points on its action plan. 

Recent Changes to the Grey List

Following reviews of their AML/CFT regimes, and success in addressing FATF action plan points, countries may be removed from the Grey and Black Lists. Similarly, countries that demonstrate deficiencies in their AML/CFT regimes may be added. Recent changes to the Grey List include:

Countries removed:

  • Ghana: FATF added Ghana to the Grey List in 2018. After it successfully completed its action plan, and passed an on-site FATF inspection, it was removed from the list in June 2021. 
  • Botswana: After being included on the Grey List in 2018, Botswana committed to working with the FATF to address outlined deficiencies in its AML/CFT framework. Following an assessment by the Eastern and South Africa money Anti-Money Laundering Group (ESAAMLG), Botswana was removed from the Grey List in June 2021. 
  • Mauritius: After adding it to the Grey List in 2020, FATF assigned Mauritius an AML/CFT action plan. Mauritius subsequently convened several working groups and announced a range of regulatory changes. In June 2021, following an on-site visit, FATF determined that Mauritius had completed its action plan and removed it from the Grey List.

Countries added:

Turkey: FATF has criticized Turkey’s progress in addressing AML/CFT threats in its banking industry. In particular, FATF cited concerns that terrorist groups in the neighboring Iran, Iraq, Syria, and Lebanon may be feeding funds into Turkey’s financial system. Accordingly, FATF added Turkey to the Grey List in October 2021. 

Grey List Compliance for Banks

When dealing with Grey List countries, the increased risk of money laundering, terrorism financing, and other financial crimes, means that firms must exercise suitable compliance caution – by implementing the measures set out in the FATF Recommendations, and screening and monitoring customers for connections with designated countries. FATF Grey List compliance requires firms to conduct assessments of their customers in order to understand the risk that they present. Firms may then use data from those assessments to build out individual customer profiles – and then deploy a compliance response commensurate with the risk they face. This risk-based approach to compliance entails measures that include:

  • Customer due diligence: Firms should establish and verify the identities of their customers in order to build accurate risk profiles. Particularly high risk customers from Grey List countries may be subject to enhanced due diligence measures. 
  • Customer monitoring: Transactions with Grey List countries should be closely monitored for ‘red flag’ indicators of criminal activity. 
  • Screening: Customers from Grey List (and Black List) countries may be sanctions targets or politically exposed persons (PEP). Accordingly, firms should screen against the relevant sanctions watch lists and PEP lists in order to ensure an appropriate risk response. 
  • Adverse media: News stories may reveal customer involvement in criminal activities before that information is confirmed by official sources. With that in mind, firms should implement an effective adverse media screening solution to detect stories that involve high risk customers from Grey List countries. 

Supply chain consequences: Firms that do business with Grey List countries should adjust their risk management solution to account for any regulatory effects on supply chains. In practice, this means extending AML/CFT controls to partners and counterparties down the chain to reflect the level of Grey List exposure that a firm has taken on. Some jurisdictions include mandatory supply chain risk management in their AML/CFT regimes. Firms in Germany, for example, must conduct supply chain due diligence on firms in Turkey now that it has been added to the Grey List.

Automated Grey List Screening

Grey List compliance obligations require firms to collect and manage large amounts of data in order to facilitate assessments of the risks that individual customers present and to manage effective AML/CFT responses.  Automated software solutions are essential to the Grey List screening process, adding speed and efficiency and reducing the potential for costly human error. Next generation screening solutions further enhance Grey List compliance by adding levels of depth and analysis to screening capabilities, increasing capacity, reducing false positives, and consolidating data sources – including adverse media and sanctions lists – from around the world, in real time.


FIND OUT HOW RIPJAR CAN HELP You WITH Watchlists and Sanctions Screening. PLEASE GET IN TOUCH.

Adverse Media And The Importance Of Risk Categorization

Adverse media is an important tool in the fight against financial crime. News stories can reveal important information about a customer’s involvement in crime long before that information is officially confirmed by government or law enforcement sources. However, the scope of the adverse media landscape means that organizations must screen against a vast amount of information in order to ensure their customer risk profiles are as up-to-date and accurate as possible.

Managing adverse media is a significant administrative challenge. The incoming information may be incorrect, irrelevant, confusing, and contradictory, and organizations may expend significant effort attempting to scrutinize it effectively for actionable financial crime data. By contrast, screening solutions that are deployed with too narrow an adverse media focus may miss important stories, and develop potentially costly risk blindspots.

The power of categorization

Ideally, an organization should be able to categorize the adverse media information that they collect in order to cut down on administrative noise and to better gauge the significance of each story as part of the risk-based approach to regulatory compliance recommended by the Financial Action Task Force (FATF). Under a risk-based approach, organizations must assess their customers individually, and then deploy compliance measures commensurate with the risk that those customers present. Adverse media should inform that process, adding depth to customer profiles and serving to alert organizations of meaningful changes to the risk they present. 

It is important to remember that categorization isn’t a one-size-fits-all solution: the accuracy and recall capabilities of the technology that an organization uses will have a significant effect on the outcomes of adverse media searches. A platform that uses sophisticated money laundering classifiers, for example, may be able to capture adverse media data with greater nuance and depth than a platform that uses more simplistic keyword searches.   

Individual organizations will inevitably approach adverse media categorization differently, and in a manner that reflects their risk landscape. Similarly, organizations should understand how different categories of adverse media relate to their unique compliance concerns. With those factors in mind, an adverse media screening solution may organize stories into the following categories:

Criminal and non-criminal

While many adverse media stories denote explicit criminal liability, non-criminal adverse media stories may still be useful as a way of informing customer risk profiles or highlighting potential criminal liabilities that may emerge in the future. Similarly, the legal status of certain behaviors may change in the future or be classified as illegal in other jurisdictions.

Anti-Money Laundering risk

Adverse media may be sourced from the conventional screen and print media sources, or from a diverse landscape of online media sources. The categorization of analogue and online sources may inform the credibility of adverse A broad spectrum of news stories may be relevant to anti-money laundering (AML) risk, reflecting the number of predicate crimes that generate illegal funds. Grouping those stories together enables firms to quickly identify the criminal behavior involved, and to gauge the level of risk in relation to their customer or client.

Financial crimes

Financial crime covers a range of offences, including both civil and criminal risk. Some financial activities are explicitly illegal but may also reveal a customers’ involvement in other types of criminal behavior: bribery, for example, is often committed in connection to other crimes such as environmental crime.

Terrorist activities

A range of adverse media stories may reveal customer involvement in the financing of terrorist activities. Stories relating to terrorism may generate significant adverse attention and cover a spectrum of criminal offences – from reading or distributing extremist publications to perpetrating acts of terror.

Regulatory compliance violations

Serious regulatory compliance violations may generate adverse media and may even constitution criminal offences. The categorization of compliance violations, by seriousness or by type, is useful because news stories often feature connections to other criminal activities: reporting violations, for example, may indicate financial misconduct.

Predicate offences

Money laundering and terrorism-related crimes involve a range of predicate offences that have been criminalized in jurisdictions around the world. Predicate offences may generate significant adverse media and vary greatly in terms of seriousness. Sex crimes, for example, may include prostitution, trafficking, and the production of illegal material – all of which generate illegal funds and confer a range of criminal punishments. Similarly, offences such as drug trafficking, theft, cybercrime, and fraud also constitute common predicate offences for money laundering and terrorism.


WANT TO LEARN HOW RIPJAR CAN HELP WITH ADVERSE MEDIA SCREENING? PLEASE GET IN TOUCH.