A country on the FATF grey list does not mean you cannot do business. It means you must look harder.
The FATF lists are among the most misunderstood tools in AML compliance. Many practitioners treat grey-listed status as an automatic trigger for transaction refusal or relationship exit. Many others barely engage with the lists at all, treating them as a national policy problem rather than an operational one. Neither approach is correct.
The grey list is a risk signal, not a prohibition. The black list is a risk signal with countermeasure expectations, not an automatic ban. Understanding the difference, knowing what the lists actually require of you as a compliance professional, and being able to make and document proportionate decisions โ that is what this guide is built to deliver.
This is Part 2 of the FinCrimeRadar FATF series. If you have not read Part 1, it covers the seven recommendations that drive your daily operational compliance decisions, including the risk-based approach that underpins everything in this article.
At the June 2026 Plenary (17โ19 June 2026): Iraq and Bosnia and Herzegovina were added to the grey list. Algeria and Namibia were removed after successful on-site visits confirmed they had completed their action plans. The black list remains unchanged at three countries. Giles Thomson of the United Kingdom became FATF President on 1 July 2026, with stated priorities on fraud, the risk-based approach, and information sharing.
The Grey List and the Black List โ What Actually Distinguishes Them
These two lists are formally distinct instruments with different official names, different compliance expectations, and different regulatory consequences. They are commonly confused โ including by compliance professionals who should know better.
- Country has identified strategic deficiencies in its AML/CFT/CPF framework
- Country has made a high-level political commitment to address deficiencies
- Country is actively working with FATF under an agreed action plan
- FATF does NOT call for mandatory EDD โ it says take the listing into account in your risk analysis
- The listing is a factor in your risk assessment, not a blanket prohibition
- Discourages indiscriminate de-risking โ proportionate response required
- Significant strategic deficiencies โ not merely identified, but unresolved and serious
- Country is non-cooperative with FATF or has refused to address deficiencies
- FATF explicitly calls on members to apply enhanced due diligence
- In the most serious cases: countermeasures required to protect the international financial system
- For Iran and North Korea: UN Security Council sanctions compound FATF listing โ maximum compliance friction
- Correspondent banks routinely restrict or refuse transactions with blacklisted jurisdictions entirely
The FATF itself explicitly states that grey list status alone does not require firms to apply enhanced due diligence. It is an input to your risk assessment under the risk-based approach. However, in practice, virtually every major bank, payment institution, and compliance programme treats grey-listed counterparties as requiring EDD by default โ because the risk-based approach, properly applied, almost always produces that outcome when a jurisdiction has documented AML/CFT deficiencies. Understanding the technical position and the operational reality are both necessary.
The Mutual Evaluation Process โ From Assessment to Action Plan
Countries do not end up on the FATF lists by accident or political decision. They arrive there through a structured peer assessment process called a Mutual Evaluation, which takes several years to complete and measures both technical compliance with the 40 Recommendations and the effectiveness of the country's AML/CFT regime in practice.
What actually gets a country listed โ the six most common deficiencies
The Current Lists โ Updated 19 June 2026
These are the lists as formally published by the FATF following the June 2026 Plenary in Paris. FATF updates its lists three times per year. Always verify against fatf-gafi.org before making a compliance decision โ this guide is current as of publication but the lists change.
Jurisdictions Under Increased Monitoring. Two added at June 2026 Plenary are marked. Countries are listed alphabetically as per FATF's official publication.
Algeria and Namibia were removed in June 2026 after completing their action plans and passing on-site verification. South Africa was removed in October 2025 โ notably quickly, having only been listed since 2023, reflecting robust reforms to its AML framework. The UAE was removed in February 2024. These examples show that listing is not permanent and is responsive to genuine reform.
What Each List Actually Requires From Your Compliance Programme
Grey List โ the risk-based response
When a counterparty, customer, or transaction is connected to a grey-listed jurisdiction, your compliance programme must incorporate that fact into its risk assessment. The FATF standard does not mandate automatic EDD โ but it does require you to demonstrate that you have considered the listing and that your response is proportionate to the actual risk presented.
Black List โ the countermeasure expectation
For black-listed jurisdictions the FATF expectation is materially different. FATF calls on members to apply enhanced due diligence. In the most serious cases โ currently Iran and North Korea โ FATF calls for countermeasures.
| Countermeasure | What It Means in Practice | Applicability |
|---|---|---|
| Enhanced Due Diligence | Full EDD on any customer, counterparty or transaction with a nexus to the jurisdiction. Source of funds, source of wealth, beneficial ownership, senior management approval, enhanced monitoring. | All 3 Black-Listed |
| Introducing EDD for Business Relationships | Treating any new or existing relationship with a nexus to the jurisdiction as presumptively high risk. Reviewing existing business relationships for exposure. | All 3 Black-Listed |
| Targeted Financial Sanctions | For Iran and North Korea: UN Security Council targeted sanctions compound the FATF obligations. Any transaction connected to designated parties is prohibited, not merely EDD-subject. | Iran & DPRK |
| Limiting or Severing Business Relationships | FATF permits โ and in extreme cases calls for โ limiting new business from or with the jurisdiction, or exiting existing relationships where risk cannot be managed adequately through EDD. | Discretionary / Risk-Based |
| Subsidiary Transactions | Enhanced oversight of financial groups' transactions through subsidiaries or branches in the jurisdiction, where the jurisdiction's AML/CFT framework is inadequate to the risk. | For Financial Groups |
| Refusing Transactions | For the most serious jurisdictions, FATF standards permit โ in extreme cases โ outright refusal of transactions. This is rare and requires documented proportionate justification. | Discretionary |
The FATF explicitly discourages indiscriminate de-risking โ blanket refusal to deal with entire classes of customers, transaction types, or countries without individual risk assessment. A policy of refusing all customers from grey-listed countries regardless of individual circumstances is not a proportionate risk-based response. It is the kind of systemic over-reaction that pushes legitimate transactions into informal channels and damages financial inclusion. The risk-based approach requires you to assess individuals and transactions โ not countries as homogenous blocks.
Three Real Scenarios โ Making the Call
A new customer applies to open a business account. He is a Bulgarian national โ Bulgaria was added to the FATF grey list in October 2023. He is a director of a legitimate UK-registered software company, has a stable employment history, straightforward business model, and all transactions are expected to be electronic B2B payments to UK clients.
Bulgaria's grey-listing relates to systemic deficiencies in its supervision of DNFBPs and beneficial ownership transparency โ not a finding that all Bulgarian businesses are high-risk.
Standard CDD is the starting point. The customer's Bulgarian nationality is a risk factor to document โ but by itself, it does not trigger EDD. Your risk assessment should note the grey-listing, apply enhanced scrutiny to source of funds and beneficial ownership verification (given Bulgaria's specific deficiencies in beneficial ownership), and calibrate transaction monitoring accordingly. This is not an automatic EDD case. Document your reasoning and move on.
A UK-based customer โ fully onboarded, clean profile, no prior issues โ requests a transfer of ยฃ45,000 to a company registered in Myanmar. The stated purpose is payment for goods under a trade contract. Myanmar has been on the FATF black list since October 2022.
Myanmar's listing also overlaps with UK sanctions โ HM Treasury has Myanmar-specific sanctions in place relating to the military regime. The transaction requires both a FATF countermeasure assessment and a sanctions screening pass before proceeding.
Step one: sanctions screen the Myanmar recipient against OFSI and UN lists. Step two: if clear, apply EDD to the transaction โ full source of funds documentation, counterparty verification, understanding of the Myanmar company's beneficial ownership and the goods being traded. Step three: escalate to the MLRO for senior sign-off before executing. If any element cannot be satisfactorily verified, the MLRO must assess whether a DAML SAR is required before the funds move. This is not a routine transaction, even if the customer's overall profile is clean.
Iraq was added to the FATF grey list on 19 June 2026. You have fifteen existing customers with Iraqi connections โ some Iraqi nationals, some UK-based businesses with Iraqi trading partners. You receive a new application from an Iraqi citizen the day after the listing is published.
The question your head of compliance is asking: "What do we do with existing relationships, and what do we do with the new application?"
For existing relationships: conduct a triggered review. Flag all fifteen customer files for reassessment within a risk-proportionate timeframe โ higher-risk customers immediately, lower-risk within your standard periodic review cycle. Update risk ratings to reflect the listing. Increase monitoring sensitivity for Iraqi-nexus transactions. For the new application: process normally but ensure your standard CDD incorporates Iraq's grey-listed status as an elevated risk factor. Document that you have considered the listing in your risk assessment. Do not refuse the application solely on the basis of nationality โ that is de-risking, not risk management.
What FATF Expects on the Path to Delisting
Understanding what a country must do to be removed from the grey list is useful for two reasons: it tells you what FATF considers a functioning AML/CFT regime, and it tells you how long grey-listed status is likely to last for specific jurisdictions โ which informs your medium-term risk planning for customer portfolios with those exposures.
Most countries complete their action plans and are removed within two to four years. Some have remained listed for over a decade โ typically where the deficiencies are structural or where political commitment to reform is inconsistent. When planning your medium-term risk appetite for grey-listed jurisdiction exposure, this timeframe is your working assumption unless specific intelligence about the country's reform trajectory suggests otherwise.
The FATF lists are a risk input. Your judgement is still required.
The grey list and the black list are two of the most powerful public tools in financial crime compliance โ but they are tools, not answers. A country being grey-listed tells you that FATF has identified systemic deficiencies. It does not tell you which specific customers, transactions, or counterparties connected to that country pose an elevated risk to your firm. That determination requires the risk-based approach โ your judgement, your documented reasoning, and your proportionate response.
The most competent compliance professionals are not those who apply the most rules mechanically. They are those who understand why the rules exist โ and can make defensible, proportionate decisions when the rules and the facts of an individual case pull in different directions. That is the standard this guide, and the FATF framework it explains, is asking you to meet.