Why the Lists Matter to Your Desk

A country on the FATF grey list does not mean you cannot do business. It means you must look harder.

The FATF lists are among the most misunderstood tools in AML compliance. Many practitioners treat grey-listed status as an automatic trigger for transaction refusal or relationship exit. Many others barely engage with the lists at all, treating them as a national policy problem rather than an operational one. Neither approach is correct.

The grey list is a risk signal, not a prohibition. The black list is a risk signal with countermeasure expectations, not an automatic ban. Understanding the difference, knowing what the lists actually require of you as a compliance professional, and being able to make and document proportionate decisions โ€” that is what this guide is built to deliver.

This is Part 2 of the FinCrimeRadar FATF series. If you have not read Part 1, it covers the seven recommendations that drive your daily operational compliance decisions, including the risk-based approach that underpins everything in this article.

3
Countries on the FATF black list โ€” Iran, North Korea, Myanmar โ€” June 2026
22
Jurisdictions on the FATF grey list as of 19 June 2026
3ร—
Times per year FATF updates the lists โ€” February, June, October
June 2026 update โ€” what just changed

At the June 2026 Plenary (17โ€“19 June 2026): Iraq and Bosnia and Herzegovina were added to the grey list. Algeria and Namibia were removed after successful on-site visits confirmed they had completed their action plans. The black list remains unchanged at three countries. Giles Thomson of the United Kingdom became FATF President on 1 July 2026, with stated priorities on fraud, the risk-based approach, and information sharing.

The Mechanics

The Grey List and the Black List โ€” What Actually Distinguishes Them

These two lists are formally distinct instruments with different official names, different compliance expectations, and different regulatory consequences. They are commonly confused โ€” including by compliance professionals who should know better.

Official Name
Jurisdictions Under Increased Monitoring
Informally: The Grey List
  • Country has identified strategic deficiencies in its AML/CFT/CPF framework
  • Country has made a high-level political commitment to address deficiencies
  • Country is actively working with FATF under an agreed action plan
  • FATF does NOT call for mandatory EDD โ€” it says take the listing into account in your risk analysis
  • The listing is a factor in your risk assessment, not a blanket prohibition
  • Discourages indiscriminate de-risking โ€” proportionate response required
Official Name
High-Risk Jurisdictions Subject to a Call for Action
Informally: The Black List
  • Significant strategic deficiencies โ€” not merely identified, but unresolved and serious
  • Country is non-cooperative with FATF or has refused to address deficiencies
  • FATF explicitly calls on members to apply enhanced due diligence
  • In the most serious cases: countermeasures required to protect the international financial system
  • For Iran and North Korea: UN Security Council sanctions compound FATF listing โ€” maximum compliance friction
  • Correspondent banks routinely restrict or refuse transactions with blacklisted jurisdictions entirely
The critical distinction most guides get wrong

The FATF itself explicitly states that grey list status alone does not require firms to apply enhanced due diligence. It is an input to your risk assessment under the risk-based approach. However, in practice, virtually every major bank, payment institution, and compliance programme treats grey-listed counterparties as requiring EDD by default โ€” because the risk-based approach, properly applied, almost always produces that outcome when a jurisdiction has documented AML/CFT deficiencies. Understanding the technical position and the operational reality are both necessary.

How Countries Get Listed

The Mutual Evaluation Process โ€” From Assessment to Action Plan

Countries do not end up on the FATF lists by accident or political decision. They arrive there through a structured peer assessment process called a Mutual Evaluation, which takes several years to complete and measures both technical compliance with the 40 Recommendations and the effectiveness of the country's AML/CFT regime in practice.

The Mutual Evaluation Journey
๐Ÿ“‹
Step 1 โ€” Questionnaire and Self-Assessment
The country under assessment completes a detailed technical compliance questionnaire covering all 40 Recommendations. This takes 12โ€“18 months. The country also submits statistical data on SARs, prosecutions, convictions, asset freezing and confiscation.
๐Ÿ”
Step 2 โ€” On-Site Visit by Assessors
A team of expert assessors โ€” typically 10โ€“15 people from FATF member countries โ€” conducts an intensive on-site visit lasting 2โ€“3 weeks. They meet with supervisors, law enforcement, prosecutors, financial intelligence units, and private sector representatives. They test whether the laws and regulations on paper actually function in practice.
๐Ÿ“Š
Step 3 โ€” Mutual Evaluation Report
The assessors produce a Mutual Evaluation Report (MER) covering 11 Immediate Outcomes โ€” the specific effectiveness measures FATF uses to determine whether a country's regime actually works. The MER rates technical compliance for each recommendation as Compliant, Largely Compliant, Partially Compliant, or Non-Compliant. Effectiveness is rated as High, Substantial, Moderate, or Low across the 11 outcomes.
โš–๏ธ
Step 4 โ€” FATF Plenary Discussion and Adoption
The MER is discussed and formally adopted at a FATF Plenary. The country has an opportunity to respond. After adoption, the report is published โ€” typically running to several hundred pages โ€” and available on the FATF website. A country with serious deficiencies enters enhanced follow-up, which is the mechanism that can lead to grey-listing.
๐Ÿšจ
Step 5 โ€” Action Plan and Grey List
Countries with significant deficiencies are required to agree an action plan with FATF โ€” a specific set of measures to be implemented within agreed timeframes. When a country makes a high-level political commitment to that action plan, it is placed under Increased Monitoring โ€” the grey list. The country then reports to FATF on progress at each Plenary session.
โœ…
Step 6 โ€” On-Site Verification and Removal
Once a country has substantially completed its action plan, FATF makes an initial determination and conducts an on-site assessment to verify that reforms are genuine and being sustained. If satisfied, the country is removed from the grey list at the following Plenary. Algeria and Namibia were both removed in June 2026 following this process.

What actually gets a country listed โ€” the six most common deficiencies

๐Ÿ”ญ
Weak Risk Understanding
The country cannot demonstrate that its authorities understand the actual ML/TF risks it faces. Its national risk assessment is superficial, outdated, or contradicted by its own data.
๐Ÿ‘๏ธ
Inadequate Supervision
Financial institutions and DNFBPs are not effectively supervised for AML/CFT compliance. Supervisors lack powers, resources, or willingness to enforce. Regulatory examinations are infrequent and non-dissuasive.
๐ŸŒณ
Beneficial Ownership Gaps
The country does not have adequate mechanisms to identify who ultimately owns and controls legal entities and arrangements. Corporate opacity is a primary enabler of money laundering through the jurisdiction.
โš–๏ธ
Low Prosecution and Conviction Rates
The country has adequate ML/TF laws on paper but fails to use them โ€” conviction rates are low, prosecutions are rare, and confiscation of criminal proceeds is minimal relative to the scale of known criminal activity.
๐ŸŽฏ
Targeted Financial Sanctions Failure
The country does not effectively implement UN Security Council targeted financial sanctions โ€” there are delays in designation, gaps in enforcement, or institutions are not screening against the designated list in real time.
๐Ÿค
International Cooperation Failures
The country is unresponsive or slow in responding to MLA requests, refuses to share financial intelligence with foreign counterparts, or imposes restrictions that prevent effective cross-border AML/CFT cooperation.
The Lists โ€” June 2026

The Current Lists โ€” Updated 19 June 2026

These are the lists as formally published by the FATF following the June 2026 Plenary in Paris. FATF updates its lists three times per year. Always verify against fatf-gafi.org before making a compliance decision โ€” this guide is current as of publication but the lists change.

The Black List โ€” 3 Countries โ€” Unchanged since October 2022
โ˜ ๏ธ

High-Risk Jurisdictions Subject to a Call for Action

FATF calls on all members to apply enhanced due diligence. In the most serious cases: countermeasures are required.

๐Ÿ‡ฎ๐Ÿ‡ท Iran
๐Ÿ‡ฐ๐Ÿ‡ต North Korea (DPRK)
๐Ÿ‡ฒ๐Ÿ‡ฒ Myanmar
The Grey List โ€” 22 Jurisdictions โ€” Updated 19 June 2026

Jurisdictions Under Increased Monitoring. Two added at June 2026 Plenary are marked. Countries are listed alphabetically as per FATF's official publication.

๐Ÿ‡ฆ๐Ÿ‡ด
Angola
Since Oct 2024
๐Ÿ‡ง๐Ÿ‡ด
Bolivia
Since Jun 2024
๐Ÿ‡ง๐Ÿ‡ฆ
Bosnia & Herzegovina
โญ Added Jun 2026
๐Ÿ‡ง๐Ÿ‡ฌ
Bulgaria
Since Oct 2023
๐Ÿ‡จ๐Ÿ‡ฒ
Cameroon
Since Oct 2023
๐Ÿ‡จ๐Ÿ‡ฎ
Cรดte d'Ivoire
Since Jun 2022
๐Ÿ‡จ๐Ÿ‡ฉ
DR Congo
Since Oct 2022
๐Ÿ‡ญ๐Ÿ‡น
Haiti
Since Jun 2021
๐Ÿ‡ฎ๐Ÿ‡ถ
Iraq
โญ Added Jun 2026
๐Ÿ‡ฐ๐Ÿ‡ช
Kenya
Since Jun 2024
๐Ÿ‡ฐ๐Ÿ‡ผ
Kuwait
Since Feb 2026
๐Ÿ‡ฑ๐Ÿ‡ฆ
Laos
Since Jun 2021
๐Ÿ‡ฑ๐Ÿ‡ง
Lebanon
Since Jun 2024
๐Ÿ‡ฒ๐Ÿ‡จ
Monaco
Since Jun 2024
๐Ÿ‡ณ๐Ÿ‡ต
Nepal
Since Jun 2024
๐Ÿ‡ต๐Ÿ‡ฌ
Papua New Guinea
Since Feb 2026
๐Ÿ‡ธ๐Ÿ‡ธ
South Sudan
Since Jun 2021
๐Ÿ‡ธ๐Ÿ‡พ
Syria
Since Jun 2021
๐Ÿ‡ป๐Ÿ‡ช
Venezuela
Since Jun 2024
๐Ÿ‡ป๐Ÿ‡ณ
Vietnam
Since Jun 2023
๐Ÿ‡ป๐Ÿ‡ฌ
Virgin Islands (UK)
Since Feb 2024
๐Ÿ‡พ๐Ÿ‡ช
Yemen
Since Jun 2021
Notable recent removals โ€” what success looks like

Algeria and Namibia were removed in June 2026 after completing their action plans and passing on-site verification. South Africa was removed in October 2025 โ€” notably quickly, having only been listed since 2023, reflecting robust reforms to its AML framework. The UAE was removed in February 2024. These examples show that listing is not permanent and is responsive to genuine reform.

The Compliance Obligations

What Each List Actually Requires From Your Compliance Programme

Grey List โ€” the risk-based response

When a counterparty, customer, or transaction is connected to a grey-listed jurisdiction, your compliance programme must incorporate that fact into its risk assessment. The FATF standard does not mandate automatic EDD โ€” but it does require you to demonstrate that you have considered the listing and that your response is proportionate to the actual risk presented.

Grey List Risk Decision Framework
Customer or transaction connected to grey-listed jurisdiction
โ†“
Assess: What is the nature of the connection?
Customer IS from grey-listed country โ€” primary nexus
Treat as high risk. EDD almost always warranted. Document thoroughly.
Transaction routes through or to grey-listed country
Assess purpose. Standard CDD may be sufficient if legitimate commercial reason is clear and documented.
Incidental connection โ€” e.g. correspondent bank is located there
Factor into correspondent banking EDD. Does not automatically elevate transaction risk.

Black List โ€” the countermeasure expectation

For black-listed jurisdictions the FATF expectation is materially different. FATF calls on members to apply enhanced due diligence. In the most serious cases โ€” currently Iran and North Korea โ€” FATF calls for countermeasures.

Countermeasure What It Means in Practice Applicability
Enhanced Due Diligence Full EDD on any customer, counterparty or transaction with a nexus to the jurisdiction. Source of funds, source of wealth, beneficial ownership, senior management approval, enhanced monitoring. All 3 Black-Listed
Introducing EDD for Business Relationships Treating any new or existing relationship with a nexus to the jurisdiction as presumptively high risk. Reviewing existing business relationships for exposure. All 3 Black-Listed
Targeted Financial Sanctions For Iran and North Korea: UN Security Council targeted sanctions compound the FATF obligations. Any transaction connected to designated parties is prohibited, not merely EDD-subject. Iran & DPRK
Limiting or Severing Business Relationships FATF permits โ€” and in extreme cases calls for โ€” limiting new business from or with the jurisdiction, or exiting existing relationships where risk cannot be managed adequately through EDD. Discretionary / Risk-Based
Subsidiary Transactions Enhanced oversight of financial groups' transactions through subsidiaries or branches in the jurisdiction, where the jurisdiction's AML/CFT framework is inadequate to the risk. For Financial Groups
Refusing Transactions For the most serious jurisdictions, FATF standards permit โ€” in extreme cases โ€” outright refusal of transactions. This is rare and requires documented proportionate justification. Discretionary
The de-risking problem the FATF specifically warns against

The FATF explicitly discourages indiscriminate de-risking โ€” blanket refusal to deal with entire classes of customers, transaction types, or countries without individual risk assessment. A policy of refusing all customers from grey-listed countries regardless of individual circumstances is not a proportionate risk-based response. It is the kind of systemic over-reaction that pushes legitimate transactions into informal channels and damages financial inclusion. The risk-based approach requires you to assess individuals and transactions โ€” not countries as homogenous blocks.

At Your Desk

Three Real Scenarios โ€” Making the Call

๐Ÿ“‹ Scenario 1
Grey List Customer

A new customer applies to open a business account. He is a Bulgarian national โ€” Bulgaria was added to the FATF grey list in October 2023. He is a director of a legitimate UK-registered software company, has a stable employment history, straightforward business model, and all transactions are expected to be electronic B2B payments to UK clients.

Bulgaria's grey-listing relates to systemic deficiencies in its supervision of DNFBPs and beneficial ownership transparency โ€” not a finding that all Bulgarian businesses are high-risk.

The proportionate response

Standard CDD is the starting point. The customer's Bulgarian nationality is a risk factor to document โ€” but by itself, it does not trigger EDD. Your risk assessment should note the grey-listing, apply enhanced scrutiny to source of funds and beneficial ownership verification (given Bulgaria's specific deficiencies in beneficial ownership), and calibrate transaction monitoring accordingly. This is not an automatic EDD case. Document your reasoning and move on.

๐Ÿ“‹ Scenario 2
Black List Transaction

A UK-based customer โ€” fully onboarded, clean profile, no prior issues โ€” requests a transfer of ยฃ45,000 to a company registered in Myanmar. The stated purpose is payment for goods under a trade contract. Myanmar has been on the FATF black list since October 2022.

Myanmar's listing also overlaps with UK sanctions โ€” HM Treasury has Myanmar-specific sanctions in place relating to the military regime. The transaction requires both a FATF countermeasure assessment and a sanctions screening pass before proceeding.

The required response

Step one: sanctions screen the Myanmar recipient against OFSI and UN lists. Step two: if clear, apply EDD to the transaction โ€” full source of funds documentation, counterparty verification, understanding of the Myanmar company's beneficial ownership and the goods being traded. Step three: escalate to the MLRO for senior sign-off before executing. If any element cannot be satisfactorily verified, the MLRO must assess whether a DAML SAR is required before the funds move. This is not a routine transaction, even if the customer's overall profile is clean.

๐Ÿ“‹ Scenario 3
Newly Listed Jurisdiction โ€” Iraq

Iraq was added to the FATF grey list on 19 June 2026. You have fifteen existing customers with Iraqi connections โ€” some Iraqi nationals, some UK-based businesses with Iraqi trading partners. You receive a new application from an Iraqi citizen the day after the listing is published.

The question your head of compliance is asking: "What do we do with existing relationships, and what do we do with the new application?"

The required response

For existing relationships: conduct a triggered review. Flag all fifteen customer files for reassessment within a risk-proportionate timeframe โ€” higher-risk customers immediately, lower-risk within your standard periodic review cycle. Update risk ratings to reflect the listing. Increase monitoring sensitivity for Iraqi-nexus transactions. For the new application: process normally but ensure your standard CDD incorporates Iraq's grey-listed status as an elevated risk factor. Document that you have considered the listing in your risk assessment. Do not refuse the application solely on the basis of nationality โ€” that is de-risking, not risk management.

Screening customers connected to listed jurisdictions? Run free PEP, sanctions, and adverse media checks on any individual or entity โ€” no account required.
Open the screening tool โ†’
The Road Back

What FATF Expects on the Path to Delisting

Understanding what a country must do to be removed from the grey list is useful for two reasons: it tells you what FATF considers a functioning AML/CFT regime, and it tells you how long grey-listed status is likely to last for specific jurisdictions โ€” which informs your medium-term risk planning for customer portfolios with those exposures.

1
๐Ÿ›๏ธ
Legislative Reform
Pass or amend AML/CFT laws to meet the technical requirements of the 40 Recommendations โ€” the specific gaps identified in the mutual evaluation report.
2
๐Ÿ‘๏ธ
Supervision Improvement
Demonstrate that supervisors are actively and effectively examining financial institutions and DNFBPs for AML/CFT compliance โ€” with meaningful sanctions for failures.
3
๐ŸŒณ
Beneficial Ownership Register
Establish and maintain an accurate, accessible beneficial ownership register โ€” and demonstrate that it is actually used in practice by supervisors and law enforcement.
4
โš–๏ธ
Prosecutions and Convictions
Increase money laundering investigations, prosecutions, and convictions to a level commensurate with the country's risk profile. Confiscation of criminal proceeds must also improve.
5
๐ŸŽฏ
TFS Implementation
Demonstrate real-time, effective implementation of targeted financial sanctions โ€” including screening by financial institutions, timely domestic designations, and enforcement.
6
โœ…
On-Site Verification
FATF must verify reforms are genuine, operational, and being sustained โ€” not just legislated. A country can pass all the laws it likes; if they are not implemented effectively, it stays listed.
Average time on the grey list: 2 to 4 years

Most countries complete their action plans and are removed within two to four years. Some have remained listed for over a decade โ€” typically where the deficiencies are structural or where political commitment to reform is inconsistent. When planning your medium-term risk appetite for grey-listed jurisdiction exposure, this timeframe is your working assumption unless specific intelligence about the country's reform trajectory suggests otherwise.

Knowledge Check โ€” Country Risk & the FATF Lists
Five questions. Testing operational understanding, not just recall.
1. The FATF formally calls its grey list by which name?
2. A customer from a grey-listed jurisdiction applies for a standard business account. Which of the following is the correct FATF-aligned response?
3. Which two jurisdictions were added to the FATF grey list at the June 2026 Plenary?
4. A Mutual Evaluation assesses a country across how many "Immediate Outcomes" to determine effectiveness?
5. How often does FATF formally update its grey and black lists?
0/5
What to Take Away

The FATF lists are a risk input. Your judgement is still required.

The grey list and the black list are two of the most powerful public tools in financial crime compliance โ€” but they are tools, not answers. A country being grey-listed tells you that FATF has identified systemic deficiencies. It does not tell you which specific customers, transactions, or counterparties connected to that country pose an elevated risk to your firm. That determination requires the risk-based approach โ€” your judgement, your documented reasoning, and your proportionate response.

The most competent compliance professionals are not those who apply the most rules mechanically. They are those who understand why the rules exist โ€” and can make defensible, proportionate decisions when the rules and the facts of an individual case pull in different directions. That is the standard this guide, and the FATF framework it explains, is asking you to meet.

Build on this guide Go back to Part 1 โ€” the seven recommendations that drive your daily compliance decisions, with visual memory cards and desk scenarios.
Read Part 1 โ†’
Screen any counterparty connected to a listed jurisdiction Free PEP, sanctions, and adverse media checks โ€” no account required.
Open the screening tool โ†’