The European Union's high-risk third-country list became effective on October 1, 2020, under Delegated Regulation EU 2020/855. This matters because your institution now operates under two parallel risk frameworks: FATF's global list and the EU's independent assessment. The divergence creates compliance complexity for any bank or fintech with EU operations.
What Changed
The EU added twelve countries to its high-risk list in 2020: Bahamas, Barbados, Botswana, Cambodia, Ghana, Jamaica, Mauritius, Mongolia, Myanmar, Nicaragua, Panama, and Zimbabwe. Combined with ten countries already designated (Afghanistan, DPRK, Iran, Iraq, Pakistan, Syria, Trinidad and Tobago, Uganda, Vanuatu, and Yemen), the EU now identifies eighteen high-risk third countries. Six countries were removed: Bosnia-Herzegovina, Ethiopia, Guyana, Lao PDR, Sri Lanka, and Tunisia.
This is the EU's second attempt. The Commission published an initial list in February 2019 but withdrew it in March 2019 after the US Treasury Department and Saudi Arabia objected to the methodology. The US specifically criticized the inclusion of American Samoa, Guam, Puerto Rico, and the US Virgin Islands, noting these territories don't appear on FATF's list and shouldn't trigger enhanced due diligence in US banking organizations.
Key Findings
The EU methodology mirrors FATF but adds independent review. The Commission evaluates eight criteria: customer due diligence standards, criminalization of money laundering and terrorist financing, beneficial ownership transparency, non-financial sector controls, supervisory powers, enforcement effectiveness, sanctions adequacy, and international cooperation. These align closely with FATF's Mutual Evaluation Reports, raising questions about whether the EU list adds substantive risk insight or administrative burden.
Mauritius stands out as a controversial inclusion. Between 2019 and 2020, the Mauritius Leaks investigation by the International Consortium of Investigative Journalists released 200,000 documents from law firm Conyers Dill & Pearman, plus communications from KPMG and Clifford Chance. The documents revealed shell company structures that allowed multinational corporations to route funds through Mauritius at a 3 percent effective tax rate, exploiting double taxation treaties to avoid higher taxes in countries including Egypt, Mozambique, and Thailand. Mauritius accelerated implementation of its FATF action plan items by August 2020, attempting to secure removal from the EU list.
The US rejected the EU's approach outright. Treasury's objection wasn't diplomatic posturing. The statement specified that US banking organizations should not incorporate the EU list into their AML/CFT risk assessments, creating a direct conflict for institutions operating in both jurisdictions.
Point 29 of the Fourth Anti-Money Laundering Directive (4AMLD) mandates enhanced customer due diligence for any natural person or legal entity established in these high-risk jurisdictions. This isn't guidance; it's a legal requirement for EU-regulated entities.
What This Means for Your Team
If you operate in the EU, you're now managing dual frameworks. Your country risk assessment must account for both FATF designations and EU-specific listings. When a customer or counterparty is established in one of the eighteen EU high-risk countries, you must apply enhanced due diligence regardless of FATF's position.
This creates operational friction. A Barbados-incorporated entity, for example, triggers enhanced due diligence under EU rules but not under FATF standards. Your team needs clear decision trees: Which list governs this relationship? If the customer has EU nexus, the EU list applies. If your institution is US-regulated with no EU operations, Treasury's guidance suggests you can ignore the EU list.
The divergence also complicates vendor risk management. If your sanctions screening or customer risk scoring platform relies exclusively on FATF data, it won't flag EU-specific high-risk countries. You'll need either manual overlays or a vendor that integrates both lists with jurisdiction-specific logic.
Action Items by Priority
Audit your country risk assessment methodology immediately. Document which sources you use (FATF, EU, Basel AML Index, Corruption Perceptions Index, Global Terrorism Index) and how frequently you refresh the data. If you're using a static spreadsheet updated annually, you're already behind. The EU list changed six months after initial publication; manual tracking won't scale.
Map your jurisdictional obligations. Create a matrix: Which of your legal entities are EU-regulated? Which customer segments have EU nexus? For US-only operations, document your decision to follow Treasury guidance and exclude the EU list. For EU operations, document your enhanced due diligence procedures for all eighteen countries.
Evaluate technology for dynamic risk assessment. If you're manually tracking multiple risk indices and regulatory lists, you're vulnerable every time a list updates. Consider platforms that aggregate regulatory data sources and push updates to your customer risk scoring engine automatically. The alternative is periodic fire drills when you discover your risk ratings are stale.
Review existing relationships with entities in the twelve newly added countries. Bahamas, Barbados, Botswana, Cambodia, Ghana, Jamaica, Mauritius, Mongolia, Myanmar, Nicaragua, Panama, and Zimbabwe all require enhanced due diligence retroactively. Prioritize accounts with transaction volumes above your institutional threshold or those in higher-risk business lines (correspondent banking, trade finance, private banking).
Pressure-test your escalation process. When Qatar faced a political crisis in 2017, how quickly could your institution adjust country risk ratings? If the answer is "weeks" or "we'd need to convene a committee," you have a structural problem. Build authority into your compliance function to adjust risk parameters within defined boundaries.



