The FATF 40 Recommendations,explained
The FATF 40 Recommendations are the international standard for anti-money-laundering and counter-terrorist financing. FATF is an intergovernmental body, not a legislature, so the Recommendations are not directly binding on firms. Countries write them into national law, and FATF then assesses how well each country has done through peer mutual evaluations.
What FATF is, and what it is not
The Financial Action Task Force was set up in 1989 and is based at the OECD in Paris. It sets standards and evaluates countries against them. It does not license firms, issue certificates, or fine anyone. When someone says a business is "FATF compliant", what they usually mean is that it meets the national rules their country wrote to implement the Recommendations.
That distinction matters when you are answering a due-diligence questionnaire. The honest answer is what you do, mapped to the Recommendation it satisfies, not a claim to hold something FATF does not issue.
The risk-based approach
Recommendation 1 is the spine of the whole standard: identify, assess and understand your money-laundering and terrorist-financing risks, then apply measures proportionate to them. Everything downstream follows from that assessment, which is why an evaluator will ask to see it first and will treat a generic, undated risk assessment as a finding in its own right.
The preventive measures firms actually feel
- Customer due diligence: identify and verify the customer and any beneficial owner, understand the purpose of the relationship, and keep it under ongoing review.
- Record keeping: retain transaction records and CDD documentation for at least five years and make them available to the authorities.
- Politically exposed persons: additional approval, source-of-wealth checks and enhanced ongoing monitoring.
- Wire transfers: carry accurate originator and beneficiary information with the payment, the requirement usually called the travel rule.
- Suspicious transaction reporting: report promptly to the national financial intelligence unit, and do not tip off the customer.
- Targeted financial sanctions: screen against the relevant lists and freeze without delay where required.
Beneficial ownership transparency
Recommendations 24 and 25 push countries to make beneficial-ownership information on legal persons and legal arrangements adequate, accurate and available to the authorities in good time. This has been one of the most-tightened parts of the standard, and it is the reason so many onboarding questionnaires now dig into ownership structures rather than stopping at the registered entity.
Virtual assets
Recommendation 15 was extended to cover virtual assets and virtual asset service providers, which brought crypto exchanges and custodians into the same licensing or registration, CDD, and travel-rule expectations as other financial institutions. Implementation across countries is uneven, so the practical requirement depends heavily on where you operate.
Mutual evaluations, and the lists
FATF and its regional bodies assess each country on two axes: technical compliance, meaning whether the laws exist, and effectiveness, meaning whether they work in practice. Countries with strategic deficiencies that have committed to a plan go on the list of jurisdictions under increased monitoring, widely called the grey list. The much shorter high-risk list, the black list, triggers a call for countermeasures.
For a firm, listing changes matter operationally, because exposure to a listed jurisdiction usually pushes a relationship into enhanced due diligence. The lists are updated at FATF plenaries, so treat any list you hold as a snapshot with a date on it.
How it relates to security frameworks
FATF overlaps ISO 27001 and SOC 2 on the plumbing rather than the substance: governance and accountability, documented policy, staff training, records retention and integrity, access control over sensitive customer files, and independent assurance. The financial-crime substance, the CDD, screening, monitoring and reporting, sits alongside your security programme rather than inside it.
Frequently asked questions
Are the FATF 40 Recommendations legally binding?
Not directly on firms. FATF is an intergovernmental standard-setter, so countries implement the Recommendations in national law and firms comply with that national law. FATF then assesses the country, not the individual firm, through mutual evaluations.
What is the FATF travel rule?
Recommendation 16 requires that required originator and beneficiary information travels with a wire transfer, so that intermediaries and the receiving institution can screen it and act on it. Recommendation 15 extended the same expectation to virtual asset transfers.
What does it mean if a country is grey listed?
It is on FATF's list of jurisdictions under increased monitoring: strategic deficiencies have been identified and the country has committed to a remediation plan. It is not a prohibition, but firms usually treat exposure to a listed country as a trigger for enhanced due diligence.
Do this in a fraction of the time
Diligio centralises your approved answers, drafts each response grounded in your sources, and independently verifies it before you review. RFPs, DDQs, and security questionnaires, answered from one knowledge base.
Related guides
What is a DDQ (due-diligence questionnaire)?
Due diligenceDDQ vs RFP: what is the difference?
RFPsRFP vs RFI vs RFQ: what is the difference?
RFPsThe RFP response process: a step-by-step guide
RFPsHow to build an RFP content library
RFPsThe bid/no-bid decision: when to respond to an RFP
Security questionnairesHow to respond to security questionnaires faster
Security questionnairesSIG vs CAIQ vs VSAQ: the security questionnaires explained
Security questionnairesVendor security assessment checklist
ComplianceSOC 2 vs ISO 27001: what is the difference?
ComplianceISO 27001 readiness checklist: how to prepare for certification
ComplianceSOC 2 for startups: a practical guide
ComplianceGDPR compliance for SaaS: a practical guide
ComplianceHIPAA compliance for software vendors
CompliancePCI DSS compliance, explained
ComplianceThe NIST Cybersecurity Framework, explained
ComplianceISO 42001, the AI management standard, explained
ComplianceISO 27017 and ISO 27018: cloud security and privacy, explained
ComplianceISO 22301 and business continuity, explained
ComplianceDORA, explained
ComplianceCyber Essentials, explained
ComplianceThe CCPA and CPRA, explained
ComplianceNIST 800-53, explained
ComplianceNIST 800-171 and CMMC, explained
ComplianceFedRAMP, explained
ComplianceHITRUST CSF, explained
Financial regulationBSA/AML, explained
Financial regulationMiFID II and MAR, explained
Financial regulationConsumer credit and fair lending, explained
Due diligenceThird-party risk management (TPRM): a practical guide
Putting FATF 40 Recommendations into practice? See Diligio Compliance for FATF 40 Recommendations.