Skip to main content
FATF Compliance Readiness: Your 40-Point ChecklistRegulations and Standards
6 min readFor AML/KYC Compliance Officers

FATF Compliance Readiness: Your 40-Point Checklist

Your institution's Anti-Money Laundering (AML) program is measured against the Financial Action Task Force (FATF) 40 Recommendations. Whether you operate in a member jurisdiction or do business with one, this checklist translates those recommendations into operational requirements you can verify today.

What This Checklist Covers

This tool helps institutions comply with FATF-aligned AML regulations. It's structured around the technical compliance elements FATF evaluators use during mutual evaluations: your legal framework, institutional powers, and operational procedures. If you're preparing for regulatory examination, onboarding a correspondent bank, or conducting internal compliance reviews, this checklist provides a clear pass/fail assessment against international standards.

Prerequisites

Before you begin:

  • Identify your primary AML regulatory authority and confirm whether your jurisdiction has committed to FATF implementation.
  • Obtain your institution's current AML/CFT policies, procedures, and risk assessment documentation.
  • Verify access to transaction monitoring rules, customer due diligence procedures, and Suspicious Activity Report (SAR) filing records.
  • Confirm you can review correspondent banking relationships and enhanced due diligence files.
  • Check your institution's exposure to jurisdictions on FATF's "Call for action" list (currently Iran and North Korea) or "Other monitored jurisdictions" list.

Compliance Checklist

Legal and Regulatory Foundation

1. Money laundering criminalization
Your jurisdiction criminalizes money laundering consistent with the Vienna and Palermo Conventions, covering predicate offenses like fraud, corruption, and drug trafficking.
Good looks like: Statutory citations showing money laundering offenses carry criminal penalties and cover self-laundering.

2. Terrorist financing criminalization
Financing of terrorism and terrorist organizations is a criminal offense under your national law.
Good looks like: Legal authority to prosecute terrorist financing independent of whether a terrorist act occurred.

3. Confiscation and provisional measures
Your jurisdiction provides legal authority to freeze, seize, and confiscate proceeds of crime and instrumentalities.
Good looks like: Court orders or administrative powers enabling asset restraint without prior conviction.

Customer Due Diligence

4. CDD trigger events documented
You perform customer due diligence when establishing business relationships, conducting occasional transactions above applicable thresholds, and when you suspect money laundering or terrorist financing.
Good looks like: Procedure manual specifying USD/EUR 15,000 threshold for occasional transactions (or your jurisdiction's equivalent) and money laundering/terrorist financing suspicion triggers.

5. Beneficial ownership identification
You identify and verify beneficial owners for legal entities, using a risk-based threshold (typically 25% ownership or control).
Good looks like: Corporate account files containing verified beneficial ownership charts and supporting documentation.

6. Politically Exposed Person (PEP) procedures
You've implemented enhanced due diligence for domestic and foreign PEPs, including senior management approval for establishing relationships.
Good looks like: PEP screening at onboarding and ongoing monitoring, with documented senior approval in account files.

7. Correspondent banking due diligence
For correspondent relationships, you've assessed the respondent institution's AML controls, ownership, regulatory standing, and purpose of the account.
Good looks like: Correspondent files containing completed due diligence questionnaires, regulatory status verification, and documented approval chain.

Record Keeping and Reporting

8. Transaction records retained
You maintain transaction records for at least five years, sufficient to reconstruct individual transactions.
Good looks like: Retention policy citing five-year minimum, with retrievable records including account files and business correspondence.

9. SAR filing mechanism operational
You file Suspicious Activity Reports with your Financial Intelligence Unit when you know, suspect, or have reasonable grounds to suspect money laundering or terrorist financing.
Good looks like: SAR filing procedures, staff training records, and evidence of filed SARs (subject to confidentiality rules).

10. Tipping-off prohibitions enforced
Your policies prohibit disclosing SAR filings or ongoing investigations to customers or third parties.
Good looks like: Confidentiality procedures in SAR policy and staff acknowledgment of tipping-off restrictions.

Risk Assessment and Enhanced Due Diligence

11. Institutional risk assessment completed
You've conducted and documented a money laundering and terrorist financing risk assessment covering your products, customers, geographic exposure, and delivery channels.
Good looks like: Written risk assessment updated within the past 12-24 months, identifying high-risk areas and corresponding controls.

12. Enhanced due diligence for high-risk jurisdictions
You apply enhanced due diligence to customers and transactions involving jurisdictions identified by FATF as high-risk, including those on the blacklist.
Good looks like: Procedures requiring additional verification, source of funds documentation, and senior approval for Iran and North Korea exposure.

13. Wire transfer information requirements
Your wire transfers include complete originator information (name, account number, address) and beneficiary information.
Good looks like: SWIFT message templates or payment system configurations enforcing complete originator/beneficiary data fields.

Internal Controls and Governance

14. Compliance officer designated
You've appointed a compliance officer at the management level with authority and resources to implement your AML/CFT program.
Good looks like: Organizational chart showing compliance officer reporting to senior management or board, with defined responsibilities.

15. Independent audit function
Your AML/CFT program undergoes independent testing, either through internal audit or external review.
Good looks like: Audit reports from the past 12-18 months covering transaction monitoring, CDD, and SAR filing adequacy.

16. Employee screening procedures
You screen employees in AML-sensitive positions for criminal history and conduct ongoing suitability assessments.
Good looks like: HR procedures requiring background checks and documented screening for compliance, operations, and customer-facing staff.

17. AML training program
Staff receive ongoing training on money laundering risks, regulatory obligations, and internal procedures.
Good looks like: Training curriculum, attendance records, and testing results for employees in relevant functions.

Transaction Monitoring

18. Monitoring rules calibrated to risk
Your transaction monitoring system includes rules tailored to your risk assessment, covering structuring, rapid movement of funds, and unusual patterns.
Good looks like: Documented monitoring rules with risk-based thresholds and evidence of periodic tuning based on typologies.

19. Alert disposition documented
You investigate and document the resolution of transaction monitoring alerts, including decisions not to file SARs.
Good looks like: Case management records showing investigative steps, evidence reviewed, and documented rationale for each alert disposition.

Targeted Financial Sanctions

20. Sanctions screening operational
You screen customers and transactions against sanctions lists, including United Nations Security Council designations and domestic lists.
Good looks like: Watchlist screening at onboarding and for ongoing transactions, with documented hit resolution procedures.

21. Asset freezing capability
You can immediately freeze funds or assets of designated persons without prior notice to the customer.
Good looks like: Procedures enabling same-day account blocking upon sanctions designation, with reporting to competent authorities.

Common Mistakes

Confusing technical compliance with effectiveness
FATF's mutual evaluation methodology assesses both. You can have perfect policies but fail on effectiveness if you're not filing SARs on actual suspicious activity or if your transaction monitoring produces only false positives.

Applying uniform CDD to all customers
Risk-based compliance means enhanced measures for high-risk customers and simplified measures where appropriate. Treating a domestic retail customer the same as a correspondent bank relationship misallocates resources.

Treating greylisted jurisdictions as blacklisted
Enhanced due diligence doesn't mean prohibition. Countries on the "Other monitored jurisdictions" list require additional scrutiny, not automatic relationship termination. Document your enhanced measures and risk acceptance.

Ignoring the mutual evaluation cycle
FATF evaluates member countries on a rotating basis. If your jurisdiction is approaching evaluation, expect your regulators to intensify examinations. Monitor FATF's published evaluation schedule and assessment reports for peer jurisdictions.

Next Steps

Run this checklist quarterly as a compliance health check. Any "not done" items become remediation projects with assigned owners and deadlines.

For items requiring enhanced due diligence, document your risk-based rationale. FATF's effectiveness assessment looks for evidence that you're making risk-informed decisions, not just checking boxes.

If you operate in or with jurisdictions on FATF's lists, obtain the published mutual evaluation report. It identifies specific deficiencies your counterparties are addressing and informs your enhanced due diligence approach.

Your AML program isn't static. As FATF updates its Recommendations and Interpretive Notes, translate those changes into operational requirements. The 2012 codification won't be the last revision.

You Might Also Like