The Problem With Every Other Guide

The 40 Recommendations are not a reading list. They are a decision framework.

Every guide to the FATF 40 Recommendations does the same thing: lists all forty in order, writes two sentences about each, and calls it a handbook. The result is a document that satisfies a Google search but teaches you nothing about how to make a compliance decision under pressure.

The truth is that a compliance analyst, MLRO, or risk officer does not need to memorise forty items. They need to deeply understand the handful of recommendations that determine the outcome of every customer onboarding, every alert clearance, every SAR decision, and every regulatory examination.

This guide identifies those seven recommendations, explains what they actually require in operational terms, gives you a visual memory card for each, and then drops you into a real scenario from the analyst's desk so you can see how the recommendation plays out when it matters.

Part 2 of this series covers the FATF lists: grey list, black list, how countries get listed, what it means for your screening programme, and the EDD obligations that follow. For now, let's start with the foundation.

40
recommendations, first issued 1990, last updated June 2026
7
recommendations that drive 90% of operational compliance decisions
206
jurisdictions assessed against the FATF standards globally
Who the FATF is — in one sentence

The Financial Action Task Force is an intergovernmental policy-making body established in 1989 by the G7, whose 40 Recommendations form the global standard against which every country's AML and CFT regime is assessed. The Recommendations are not law, but countries that fail to implement them risk landing on the FATF grey or black list — which triggers EDD obligations from every bank and financial institution in the world dealing with them.

All 40 Recommendations — Your Seven in Context
R.1
Risk-Based Approach ★
R.2
National Cooperation
R.3
ML Offence
R.4
Confiscation
R.5
TF Offence
R.6
Targeted Sanctions
R.7
WMD Sanctions
R.8
Non-Profits
R.9
Financial Secrecy
R.10
CDD ★
R.11
Record Keeping ★
R.12
PEPs ★
R.13
Correspondent Banking
R.14
Money Services
R.15
New Technologies
R.16
Wire Transfers
R.17
Third Parties
R.18
Internal Controls ★
R.19
High-Risk Countries
R.20
SAR / STR ★
R.21
Tipping Off
R.22
DNFBPs: CDD
R.23
DNFBPs: Other
R.24
Beneficial Ownership ★
R.25
Legal Arrangements ★
R.26
FI Regulation
R.27
Supervisor Powers
R.28
DNFBPs Regulation
R.29
FIUs
R.30
Law Enforcement
R.31
Powers of LE
R.32
Cash Couriers
R.33
Statistics
R.34
Guidance
R.35
Sanctions
R.36
Int'l Instruments
R.37
MLA
R.38
MLA: Freezing
R.39
Extradition
R.40
Other Forms of Cooperation

★ Highlighted recommendations are the seven covered in detail in this guide.

1
Rec.
Risk-Based Approach
"The foundation on which every other recommendation is built."
⚖️
Visual Memory: The Scales
Imagine a set of scales. On one side: the risk of a customer or transaction. On the other: the controls you apply. Recommendation 1 says the scales must always balance. Low risk = lighter controls. High risk = heavier scrutiny. Equal treatment for all = regulatory failure. The RBA is not permission to do less — it is a requirement to do the right amount in the right places.

What it actually requires

Recommendation 1 requires countries — and through their domestic legislation, regulated firms — to identify, assess, and understand the money laundering and terrorist financing risks they face, and to take action proportionate to those risks. The critical word is proportionate. This is not a licence to do less for low-risk customers; it is an obligation to do more for high-risk ones and to be able to document why you made each decision.

In practice this means every firm subject to AML obligations must have a documented risk assessment covering its customers, products, delivery channels, and geography. That risk assessment must then translate directly into the way CDD, transaction monitoring, and suspicious activity reporting are calibrated. An FCA examination will not just ask "do you have a risk assessment?" They will ask "show me how this risk assessment changes the way you treat a customer from a high-risk jurisdiction versus a domestic retail customer."

The three tiers the RBA creates

  • Simplified Due Diligence (SDD): Applied where risk is demonstrably low and specific conditions are met. Not a shortcut — a deliberate, documented risk-based decision.
  • Standard CDD: The baseline for customers where no specific risk factors trigger either SDD or EDD. Still requires identification, verification, and ongoing monitoring.
  • Enhanced Due Diligence (EDD): Mandatory for high-risk customers, relationships, and transactions. PEPs, correspondent banking, high-risk jurisdictions, complex structures all trigger EDD as a minimum.
📋 At Your Desk
RBA in Action

Your bank onboards a retired teacher from Birmingham who wants a current account. She has a fixed income, a UK passport, no adverse media, no PEP connection, no complex source of funds. Under the RBA, the proportionate response is standard CDD with low-intensity monitoring. You do not run a full EDD file because there is no basis for it.

The same week, you onboard a director of a company incorporated in a FATF grey-listed jurisdiction, whose business involves cash-intensive services and who will be sending regular international transfers. The RBA demands EDD — source of funds, source of wealth, enhanced monitoring, senior management sign-off. The same firm treating both customers identically would fail a risk-based examination.

The regulator's question

"How does your risk assessment change the way you actually treat different customers?" If you cannot answer with specific, documented examples from your own portfolio, you have an RBA gap.

The Most Common RBA Failure

Building a risk assessment that lives in a policy document but never changes how analysts actually screen, onboard, or monitor customers. The FCA's enforcement cases on AML repeatedly cite firms where the documented risk appetite bore no resemblance to operational reality. A risk assessment that doesn't change behaviour isn't a risk assessment — it's a liability.

10
Rec.
Customer Due Diligence
"Know who you are actually dealing with — not just who they say they are."
🔦
Visual Memory: The Torch
CDD is a torch you shine at a customer before they enter the building. It answers four questions: Who are you? Who owns and controls you? What are you here to do? And does any of this match what I expect? Recommendation 10 says you must shine this torch at the start of the relationship, and again throughout it whenever something changes. A torch you only use at onboarding and never again is not CDD — it is a photo of who the customer used to be.

The four core CDD obligations

  • Identification and verification: Establish the customer's identity from a reliable, independent source. For a natural person: name, date of birth, address. For a legal entity: name, registration number, registered address, legal form.
  • Beneficial ownership: Identify the natural persons who ultimately own or control the customer — those with more than 25% ownership or effective control. Verify this is accurate and up to date. This is where CDD most commonly fails.
  • Purpose and intended nature: Understand why the customer is opening the account, what transactions they expect to conduct, and what the business relationship is expected to look like. This baseline is what makes transaction monitoring meaningful later.
  • Ongoing monitoring: CDD is not a one-time event. It requires reviewing existing information when it changes, when suspicious activity is identified, or at periodic intervals based on risk level. High-risk customers require more frequent review.

When CDD must be applied

The FATF standard requires CDD at the point of establishing a business relationship, when carrying out occasional transactions above applicable thresholds, when there is a suspicion of money laundering or terrorist financing, and when there is doubt about the accuracy of previously obtained identification data.

📋 At Your Desk
CDD Failure Mode

A company opens a business account. The onboarding analyst verifies the two directors who present themselves. Two years later, a new director joins following a corporate restructure. The account continues operating. The new director is not verified. The beneficial ownership register at Companies House shows that director now holds 40% of shares.

This is a textbook Recommendation 10 failure — CDD that was performed once but never updated despite a material change in beneficial ownership. The FCA has cited exactly this pattern in enforcement actions.

The fix

Ongoing monitoring under R.10 requires triggers that flag material changes in corporate structure, director changes, and ownership threshold breaches. A manual annual review is not sufficient for higher-risk customers.

11
Rec.
Record Keeping
"If it isn't documented, it didn't happen."
🗄️
Visual Memory: The Evidence Locker
Every compliance decision you make today is a piece of evidence that either supports or undermines your firm's regulatory standing five years from now. Recommendation 11 requires you to build and maintain that evidence locker. Transaction records for five years from the date of transaction. CDD documents for five years from the end of the relationship. The question you should ask before closing any file: "Could I defend this decision to a regulator from the documentation alone, without anyone's verbal explanation?" If the answer is no, the file is not complete.

What must be kept and for how long

  • Transaction records: Sufficient to permit reconstruction of individual transactions, including the amount, currency, and parties involved. Minimum five years from the date of transaction.
  • CDD records: All documents obtained during the due diligence process, including copies of identification documents, verification records, beneficial ownership information, and risk assessments. Minimum five years from the end of the business relationship.
  • Account files and business correspondence: Including the rationale for decisions made, escalations, and any determinations about suspicious activity. These are what allow a regulator or law enforcement agency to reconstruct the compliance decision-making process.
  • SAR documentation: Internal SAR reports, MLRO decisions, and DAML consent records must be retained separately and securely, with strict access controls to protect tipping-off obligations.
The UK-specific position

Under the UK Money Laundering Regulations 2017, the five-year retention requirement begins from the date the business relationship ends, not from the date the document was created. This means an identification document obtained in 2018 for a relationship that ended in 2024 must be retained until 2029. Systems that automatically delete records on a five-year rolling basis from creation date — rather than relationship end date — are a compliance gap that survives quietly until an enforcement inquiry surfaces it.

The Silent Record Keeping Failure

Firms frequently retain records but in formats or locations that render them unusable under time pressure. A regulator requiring transaction records to be produced within 24 hours will expose whether your record architecture is actually functional or whether everything technically exists but takes three weeks to reconstruct from legacy systems, paper files, and spreadsheets. Retention is a technical obligation; retrievability is the operational one that matters when it counts.

12
Rec.
Politically Exposed Persons
"Public trust equals public risk. Not a reason to refuse — a reason to look harder."
🏛️
Visual Memory: The Public Trust Premium
A PEP holds — or has held — a position of public trust. That trust gives them access to state resources, decisions over contracts, and influence over policy. Recommendation 12 exists because that access creates a specific and documented risk of corruption, bribery, and embezzlement of state funds. The EDD obligation under R.12 is not a presumption of guilt. It is a recognition that the position itself creates a risk profile that requires more scrutiny, not less, to satisfy yourself that the relationship is clean.

The three PEP categories under FATF

  • Foreign PEPs: Senior officials in a foreign government, head of state or government, senior politician, senior judicial or military official, senior executive of a state-owned enterprise, or senior official of an international organisation. Foreign PEPs are always high risk — there is no risk-based discretion to apply SDD to a foreign PEP.
  • Domestic PEPs: The same categories of public function but in the firm's own country. The FATF standard requires a risk-based approach for domestic PEPs — they are not automatically treated as high risk but must be assessed. In practice the FCA's FG25/3 guidance (July 2025) clarifies that domestic PEPs should not automatically receive EDD treatment but must be assessed proportionately.
  • RCAs — Relatives and Close Associates: Family members and known close associates of PEPs are subject to the same EDD requirements. The "known close associate" category is deliberately broad — it includes business partners and others with whom the PEP has a significant relationship that creates a risk of benefit from their position.

What EDD for PEPs actually requires

  • Senior management approval before establishing or continuing the relationship
  • Reasonable measures to establish source of wealth and source of funds
  • Enhanced ongoing monitoring of the relationship throughout its duration
  • Periodic review of the relationship with documented rationale for continuation
📋 At Your Desk
The PEP Identification Problem

A customer was onboarded three years ago as a standard retail customer. Last month, they were appointed as a non-executive director of a government-owned enterprise. Under R.12, this customer is now a domestic PEP. Your screening system will only flag this if it is running a live PEP check against a current database, not if it relied solely on a point-in-time check at onboarding.

The obligation under Recommendation 12 is not just to screen for PEPs at onboarding. It is to have a system that identifies when an existing customer becomes a PEP during the course of the relationship. This requires either ongoing periodic screening against live PEP data, or transaction monitoring rules that flag activity patterns consistent with a newly exposed public role.

The regulator's question

"How would you know if a customer became a PEP after onboarding?" If your answer is "we wouldn't" — that is a Recommendation 12 gap.

Screen for PEPs right now — free FinCrimeRadar's screening tool runs live PEP checks alongside sanctions and adverse media. No account required.
Run a PEP check →
18
Rec.
Internal Controls
"Policy without infrastructure is theatre."
🏗️
Visual Memory: The Building's Skeleton
Recommendations 1 through 17 tell you what compliance needs to achieve. Recommendation 18 is the skeleton that holds the building up. Without internal controls — a named MLRO, AML policies and procedures, staff training, independent audit — the other recommendations float on air. You cannot have a functioning risk-based approach if no one is accountable for it, no one has been trained to apply it, and no one has checked whether it works.

The five pillars of R.18 internal controls

  • Policies, controls and procedures: Documented AML/CFT policies approved by senior management, covering all aspects of the firm's obligations. These must be implemented in practice, not just on paper.
  • Designated compliance officer (MLRO): A named individual with the authority, resources, and independence to implement and oversee the AML programme. In the UK this is the SMF17 function — a Senior Manager Function carrying personal accountability.
  • Staff screening: Ensuring that employees in positions that could be abused for financial crime purposes meet appropriate integrity standards before and during employment.
  • Training: Regular, documented training for all relevant staff on AML obligations, typologies, red flags, and the firm's internal procedures. One-size-fits-all annual compliance training is unlikely to be sufficient for high-risk roles.
  • Independent audit function: Regular review of the adequacy and effectiveness of the AML programme by a function independent of the first and second lines of defence. The audit must test whether controls are working in practice, not just whether procedures exist.
The MLRO accountability trap

Recommendation 18 requires a "compliance officer at management level." In the UK, this translates to the SMF17 function under the Senior Managers and Certification Regime. The MLRO carries personal regulatory accountability for the adequacy of the AML programme. This is not a delegation of accountability from senior management — it is a specific regulatory responsibility that sits with a named individual who can be held personally liable for systemic failures. Appointing a compliance officer without giving them the budget, authority, and access to information they need to do the job is a structural failure under R.18, even if the box is technically ticked.

20
Rec.
Suspicious Transaction Reporting
"You don't need to prove it. You need to suspect it."
🚨
Visual Memory: The Red Button
Recommendation 20 is the red button that connects the financial sector to law enforcement intelligence. When a firm suspects — not knows, but suspects — that funds are the proceeds of crime or that a transaction is connected to terrorist financing, Recommendation 20 requires that suspicion to be reported to the Financial Intelligence Unit without delay and without tipping off the subject. The threshold for reporting is suspicion, not certainty. A firm waiting for proof before filing a SAR has misunderstood the obligation.

The obligation in operational terms

Recommendation 20 requires firms to report suspicious transactions to the relevant Financial Intelligence Unit promptly, regardless of the amount involved, and regardless of whether the transaction has been completed or abandoned. In the UK, this is the SAR regime administered by the UKFIU at the NCA. The reporting obligation applies to all employees, but in practice it flows through the MLRO who makes the final determination on whether to submit.

What makes a transaction suspicious — the four lenses

  • Inconsistency: The transaction does not match the customer's stated profile, expected transaction pattern, or business purpose. A cash-intensive deposit from a customer who described their business as wholly electronic invoicing is inconsistent.
  • Unexplained complexity: The transaction involves unnecessary complexity — multiple jurisdictions, unusual routing, or layered structures — that has no obvious legitimate commercial reason.
  • Behaviour: The customer's behaviour during the transaction raises concern — unusual urgency, reluctance to provide information, attempts to avoid identification, or direct reference to evading reporting requirements.
  • Third-party intelligence: Information from law enforcement, a SAR received from another institution, adverse media, or a FATF typology report that connects the customer or transaction to known financial crime patterns.
📋 At Your Desk
The DAML Situation

A customer requests a large international transfer to a jurisdiction you know is high risk. You suspect the funds may be linked to fraud based on inconsistencies in the account activity over the past month. The transfer is scheduled for tomorrow.

In the UK, where you need to conduct a transaction you suspect is connected to criminal property, you must file a Defence Against Money Laundering SAR with the NCA and await their consent before proceeding. You have a seven-working-day moratorium from the date of filing in which the NCA can either grant consent, refuse it, or allow it to expire and the transfer to proceed.

The tipping-off obligation

Recommendation 20 sits alongside the tipping-off prohibition in Recommendation 21. You must file the SAR without informing the customer that you have done so or that they are under investigation. The DAML process must be managed without any communication to the customer that would alert them to the reporting or the investigation.

24 & 25
Rec.
Beneficial Ownership
"Every entity is owned by a human being. Find them."
🌳
Visual Memory: The Ownership Tree
Every corporate entity is a tree. The leaves are the shares and legal structures. The trunk is the registered company. The roots — buried underground, sometimes deliberately — are the natural persons who ultimately own and control the entity. Recommendations 24 and 25 say: you must find the roots. Not just the leaves, not just the trunk, but the actual humans at the bottom of the ownership chain. Until you reach a natural person, you have not completed your UBO analysis.

Recommendation 24 — Companies

Countries must ensure that accurate and up-to-date beneficial ownership information on legal persons is accessible to competent authorities without delay. For firms, this translates into the obligation to identify all natural persons who own or control more than 25% of a company, or who otherwise exercise effective control over it. The 25% threshold is a floor — effective control can exist without reaching it, and your policy must address this.

Recommendation 25 — Legal Arrangements

Recommendation 25 extends the beneficial ownership obligation to trusts and other legal arrangements. For a trust, this means identifying the settlor, the trustees, the protector (if any), the beneficiaries or class of beneficiaries, and any other natural person exercising effective control. This is the recommendation that most compliance programmes underserve — trust structures are genuinely more complex to unwind than corporate ones, and the temptation to accept trustee-level information without looking further is a documented compliance gap.

The four UBO identification failures

  • Accepting nominee directors as controllers: A nominee director listed in the registration documents who has no real decision-making power is not the beneficial owner. The real controller must be identified.
  • Stopping at one corporate layer: Where a company is owned by another company, the analysis must continue until natural persons are reached, regardless of how many layers it takes.
  • Accepting "members of the family" as beneficiaries: An unspecified beneficiary class is not an identified beneficial owner. Each member of the class that can receive benefit must be individually identified where practicable.
  • Treating Companies House as sufficient verification: The PSC register is a useful starting point, not a sufficient endpoint. It must be independently verified against the information provided by the customer and any discrepancies investigated.
The Updated June 2026 FATF Standard

The FATF updated its Recommendations in June 2026, with the most significant changes affecting R.24 and R.25. The revised standard now explicitly addresses nominee arrangements and requires countries to ensure that beneficial ownership information is verified, not merely declared. Firms relying solely on customer declarations of beneficial ownership without independent verification steps have a gap under the updated standard.

Screening beneficial owners? Each UBO you identify through your corporate structure analysis needs a PEP and sanctions check. Run them here for free.
Screen a UBO →
Knowledge Check — The Seven Recommendations
Five questions. Can you apply the recommendations under pressure?
1. A customer from a low-risk domestic background wants to open a basic savings account. Under Recommendation 1, what is the correct CDD response?
2. Under Recommendation 11, how long must CDD records be retained after a business relationship ends?
3. A customer who was onboarded two years ago has just been appointed Minister of Energy in a foreign government. What does Recommendation 12 require?
4. Under Recommendation 20, what is the threshold for filing a Suspicious Activity Report?
5. A company is owned by a holding company, which is itself owned by a trust with unspecified "family member" beneficiaries. Under Recommendations 24 and 25, what must you do?
0/5
The Complete Picture

The Remaining 33 — Decoded in Plain English

The seven recommendations above drive your daily operational decisions. The remaining 33 set the wider legal, institutional, and international framework within which those decisions sit. Every compliance professional should understand what they cover — even if they are not personally responsible for implementing them.

R.2 National Cooperation & Coordination

Countries must have domestic AML/CFT policies informed by their national risk assessment, with all relevant authorities coordinating on policy design and implementation. This is the governance layer above individual firm compliance.

R.3 Money Laundering Offence

Countries must criminalise money laundering on the basis of the Vienna and Palermo Conventions. The offence must cover all serious crimes as predicate offences — not just drugs. In the UK this is implemented through POCA 2002.

R.4 Confiscation & Provisional Measures

Countries must have laws enabling confiscation of proceeds of crime, instrumentalities used in crime, and property of equivalent value. Also covers freezing and seizure powers. For firms: this is why production orders and account freezing orders can land with little warning.

R.5 Terrorist Financing Offence

Terrorist financing must be criminalised regardless of whether the funds are from a legitimate or illegitimate source, and whether the financing actually results in a terrorist act. Key distinction from ML: the money can be clean — it is the destination that matters.

R.6 Targeted Financial Sanctions — Terrorism

Countries must implement UN Security Council resolutions on terrorist financing — freezing assets and prohibiting dealings with designated individuals and entities without delay. For firms: your sanctions screening must cover UN, OFAC, OFSI and EU designation lists as a minimum.

R.7 Targeted Financial Sanctions — Proliferation

Countries must implement UN Security Council resolutions on the financing of proliferation of weapons of mass destruction. The DPRK and Iran programmes are the live examples. Your WMD sanctions screening sits under this recommendation.

R.8 Non-Profit Organisations

Countries must review their NPO sector for terrorist financing risk and apply proportionate, risk-based measures without over-restricting legitimate charitable activity. For firms: charities sending funds to conflict zones require specific EDD and MLRO-level scrutiny under this recommendation.

R.9 Financial Institution Secrecy Laws

Countries must ensure that financial institution secrecy laws do not inhibit the implementation of the FATF Recommendations — particularly information sharing with authorities. This is why bank secrecy jurisdictions face scrutiny: their secrecy laws can structurally prevent compliance with other FATF standards.

R.13 Correspondent Banking

Before establishing correspondent relationships, financial institutions must understand the respondent's AML/CFT controls, assess their regulatory environment, and obtain senior management approval. Shell bank relationships are prohibited. This is one of the highest-risk product areas in global banking.

R.14 Money or Value Transfer Services

All money or value transfer service providers must be licensed or registered and subject to AML/CFT supervision. Informal remittance networks (hawala) operating outside this framework are a documented typology for terrorism financing and sanctions evasion.

R.15 New Technologies & Virtual Assets

Countries and financial institutions must assess and manage risks from new technologies and virtual assets before launching products or services. VASPs must be regulated, licensed, and supervised for AML/CFT. The Travel Rule (R.16) for crypto transactions sits within this framework.

R.16 Wire Transfers & The Travel Rule

Originator and beneficiary information must accompany all wire transfers throughout the payment chain. The same obligation now applies to virtual asset transfers between VASPs. Missing or incomplete Travel Rule data is a red flag in any payment screening review.

R.17 Reliance on Third Parties

Financial institutions can rely on third parties to perform elements of CDD — but they remain ultimately responsible for compliance. The third party must be appropriately regulated and the relying firm must immediately obtain the CDD information. Outsourcing the process does not outsource the liability.

R.19 Higher-Risk Countries

Countries on the FATF grey and black lists require enhanced due diligence. For black-listed jurisdictions, countermeasures beyond EDD may be required — including limiting or severing business relationships entirely. This is the recommendation that Part 2 of this series unpacks in full.

R.21 Tipping-Off & Confidentiality

Firms and their staff must not disclose to the customer or third parties that a SAR has been filed or that an investigation is underway. Tipping off is a criminal offence in the UK. The protected disclosure regime — where staff who file in good faith are shielded from liability — also sits under this recommendation.

R.22 DNFBPs — CDD

Designated Non-Financial Businesses and Professions — casinos, real estate agents, lawyers, accountants, dealers in precious metals and stones — must apply the same CDD obligations as financial institutions when they conduct specific categories of transactions. Their exposure to financial crime is substantial and historically under-regulated.

R.23 DNFBPs — Other Measures

DNFBPs must also comply with SAR reporting obligations, record-keeping requirements, and internal controls obligations. A lawyer who handles client funds or facilitates a property transaction is subject to AML obligations — a fact that surprises many non-financial sector professionals.

R.26 Regulation & Supervision of Financial Institutions

All financial institutions must be subject to adequate regulation and AML/CFT supervision. The supervisor must have powers to compel compliance and sanction violations. In the UK this is the FCA for most financial institutions, with HM Treasury maintaining the overarching regulatory framework.

R.27 Powers of Supervisors

Supervisors must have the authority to conduct on-site and off-site inspections, compel production of documents, and impose meaningful sanctions including financial penalties, revocation of licences, and removal of management. The FCA's enforcement powers under this framework are directly traceable to FATF R.27.

R.28 Regulation & Supervision of DNFBPs

DNFBPs must be subject to effective AML/CFT supervision — either by a competent authority or by a self-regulatory body. The adequacy of DNFBP supervision is one of the most commonly criticised areas in FATF mutual evaluations, including the UK's own evaluation history.

R.29 Financial Intelligence Units

Every country must have a national Financial Intelligence Unit as the central authority for receiving, analysing, and disseminating SAR intelligence. In the UK this is the UKFIU within the NCA. All SARs you file go to the UKFIU, which analyses them for operational intelligence and passes relevant material to law enforcement.

R.30 Responsibilities of Law Enforcement

Countries must designate law enforcement authorities responsible for AML/CFT investigations and ensure they have adequate resources and investigative powers. Multidisciplinary investigative teams — combining financial intelligence with law enforcement capability — are the FATF's preferred model for complex financial crime.

R.31 Powers of Law Enforcement

Investigators must have access to all documents and information needed for ML/TF investigations, including financial records held by banks and other institutions. This is why production orders, account monitoring orders, and customer information orders exist — they are the legal mechanisms through which R.31 is operationalised in UK law.

R.32 Cash Couriers

Countries must have mechanisms for detecting physical cross-border transportation of currency and negotiable instruments, with declaration requirements at thresholds. The EU's €10,000 cash declaration requirement is a direct implementation of this recommendation. Failure to declare is itself a confiscation trigger.

R.33 Statistics

Countries must maintain comprehensive statistics on SARs received and analysed, investigations and prosecutions, assets frozen, seized and confiscated, and mutual legal assistance requests. These statistics are what FATF assessors examine during mutual evaluations to measure effectiveness rather than just technical compliance.

R.34 Guidance & Feedback

Competent authorities must provide guidance to financial institutions on implementing FATF standards, and feedback to the sector on SAR utility. The FCA's AML Annual Reports, thematic reviews, and publications like the Joint Money Laundering Steering Group (JMLSG) guidance are direct implementations of R.34.

R.35 Sanctions

Countries must have effective, proportionate, and dissuasive sanctions — criminal, civil, and administrative — available for natural and legal persons who fail to comply with AML/CFT requirements. FCA financial penalties against firms and MLROs sit squarely under this recommendation.

R.36 International Instruments

Countries must ratify and implement the Vienna Convention, Palermo Convention, UN Convention Against Corruption, and the Terrorist Financing Convention. These international instruments form the legal backbone on which the FATF recommendations are built — without them, cross-border cooperation is structurally impossible.

R.37 Mutual Legal Assistance

Countries must provide the widest possible range of mutual legal assistance in ML, TF, and predicate offence investigations. MLA requests are how evidence and assets cross borders in major financial crime prosecutions. A country that routinely refuses or delays MLA requests faces FATF scrutiny.

R.38 MLA — Freezing & Confiscation

Countries must be able to take freezing and confiscation action on behalf of another country through mutual legal assistance — including enforcing foreign confiscation orders. This is how internationally mobile criminal assets get recovered across borders.

R.39 Extradition

Countries must constructively execute extradition requests for ML and TF offences and should not refuse solely on the grounds that the offence involves fiscal matters. A country that consistently refuses extradition for financial crime suspects faces direct FATF pressure.

R.40 Other Forms of International Cooperation

Countries must ensure that supervisors and law enforcement can cooperate with their foreign counterparts directly — sharing information, conducting joint investigations, and providing assistance — without always requiring a formal MLA process. This facilitates faster real-time intelligence sharing between FIUs and supervisors across borders.

The colour key

Recommendation numbers are colour-coded by theme: Navy = institutional/legal framework; Red = terrorism and proliferation financing; Blue = specific product/sector obligations; Purple = DNFBPs; Teal = supervision, intelligence and international cooperation; Gold = non-profit and sector-specific risks.

What Part 2 Covers

Now that you know the rules — Part 2 covers the consequences of breaking them.

Part 2 of this series focuses on the FATF lists: how countries end up on the grey list and black list, what distinguishes them, what the real-world business and compliance consequences are, and what FATF expects from listed countries on the path to delisting. It also covers your EDD obligations when dealing with counterparties, customers, or transactions connected to listed jurisdictions, and includes the current 2026 grey and black list with a visual jurisdiction risk map.

While you're here The FinCrimeRadar screening tool covers PEPs, sanctions, and adverse media — the three data sources that activate the EDD requirements in every recommendation above.
Try the tool →