The FATF Recommendations, Summarised

Almost every national AML law traces back to one source: the Financial Action Task Force and its 40 Recommendations. FATF is an intergovernmental body that sets the global standard for combating money laundering, terrorist financing and the financing of proliferation. This post summarises what the Recommendations cover and how they are enforced.
What FATF is
FATF was established in 1989 by the G7 to develop policies against money laundering, later expanding its mandate to terrorist financing after 2001 and to proliferation financing. It has no power to make law directly; instead it issues standards that member jurisdictions commit to implement, and it assesses how well they do so. Its influence comes from peer pressure and the practical consequences of being named as deficient.
The structure of the 40 Recommendations
The Recommendations are organised into thematic groups. In broad terms they cover:
- AML/CFT policies and coordination, including the requirement that countries identify and assess their own risks and apply a risk-based approach (Recommendation 1).
- Money laundering and confiscation, criminalising laundering and enabling authorities to seize illicit assets.
- Terrorist financing and proliferation financing, including targeted financial sanctions.
- Preventive measures for financial institutions and designated non-financial businesses, the operational heart most firms interact with.
- Transparency of legal persons and arrangements, requiring accessible beneficial-ownership information for companies and trusts.
- Powers and responsibilities of authorities, covering supervisors, financial intelligence units and law enforcement.
- International cooperation, including mutual legal assistance and information sharing.
The measures firms feel directly
A handful of Recommendations shape day-to-day compliance:
- Recommendation 10 (Customer Due Diligence): identify and verify customers and beneficial owners, and understand the relationship.
- Recommendation 12 (PEPs): apply enhanced measures to politically exposed persons.
- Recommendation 16 (the Travel Rule): require that originator and beneficiary information travels with wire transfers, a rule that has been extended to virtual asset transfers.
- Recommendation 20 (Reporting suspicious transactions): report suspicions to the financial intelligence unit.
- Recommendation 15 (New technologies): assess the risks of new products and technologies, including virtual assets.
FATF does not run your compliance programme, but nearly every obligation in it, from CDD to the Travel Rule, is a national implementation of a FATF Recommendation.
Mutual evaluations and the lists
Enforcement runs through mutual evaluations: peer reviews in which assessors examine both a country's technical compliance (are the right laws on the books?) and its effectiveness (do they actually work in practice?). The effectiveness dimension, assessed against a set of immediate outcomes, is often the harder test.
Countries with serious deficiencies can be placed on one of two lists. The grey list (jurisdictions under increased monitoring) signals identified weaknesses and a commitment to fix them; grey-listing raises the risk rating firms apply to those jurisdictions and can dampen investment. The black list (high-risk jurisdictions subject to a call for action) is reserved for the most serious cases and triggers enhanced countermeasures. These listings, updated at FATF's plenary meetings, are watched closely because they translate directly into due-diligence obligations.
Why it matters to builders
If you build financial products, the FATF Recommendations are the ultimate reason your onboarding, screening, monitoring and reporting requirements exist. Understanding them helps you anticipate where rules are heading, virtual assets and the Travel Rule are a clear example of FATF standards driving national law, and lets you read regulatory change as the local expression of a global framework rather than a series of unrelated demands.
Recommendations plus Interpretive Notes
The 40 Recommendations are deliberately concise, so FATF publishes Interpretive Notes alongside them that flesh out how each should be applied in practice, together with a glossary of defined terms. When a national regulator writes detailed rules, it is usually operationalising both the headline Recommendation and its Interpretive Note. FATF also issues guidance papers on specific topics, such as the risk-based approach for particular sectors or the application of standards to virtual assets, which, while not binding, strongly shape supervisory expectations.
A living standard
The Recommendations are not frozen. FATF revises them as new risks emerge, the extension of the Travel Rule to virtual asset service providers and a sharpened focus on beneficial-ownership transparency are recent examples, and it periodically re-weights its emphasis, notably by elevating effectiveness over mere technical compliance in its evaluation methodology. For compliance teams, this means treating the FATF standards as a moving target worth tracking directly, rather than assuming that last year's national rulebook captures the current global expectation.
Key takeaways
- FATF sets the global AML, counter-terrorist-financing and counter-proliferation standard through its 40 Recommendations.
- The Recommendations span national policy, criminalisation, preventive measures, beneficial-ownership transparency, authorities and cooperation.
- Firms feel Recommendations 10 (CDD), 12 (PEPs), 16 (Travel Rule) and 20 (suspicious reporting) most directly.
- Mutual evaluations assess both technical compliance and real-world effectiveness.
- Grey-listing and black-listing raise the risk rating applied to jurisdictions and drive enhanced due diligence.