Skip to main content
Category: Regulations and Standards

FATF-Style Regional Body

Also known as: FSRB, FATF-Style Regional Bodies, FSRBs
Simply put

A FATF-Style Regional Body (FSRB) is a regional organization that adopts and promotes the anti-money laundering and counter-terrorist financing standards set by the Financial Action Task Force (FATF). FSRBs have forms and functions similar to the FATF but operate at a regional level, and some FATF member countries also belong to these bodies. Together with the FATF, the FSRBs extend the reach of FATF standards to nearly every country in the world.

Formal definition

An FSRB is a regional inter-governmental organization that follows the standards and guidance of the FATF and carries out functions analogous to those of the FATF within its region, including promoting and monitoring implementation of AML/CFT policies. The relationship between the FATF and its FSRB partners is governed by a set of agreed high-level principles and objectives. According to the evidence, the FATF is composed of 39 member countries working alongside nine FSRBs, and membership overlaps in some cases, as certain FATF members are also members of an FSRB. Practitioners should note that the specific roles, membership, and procedures of an individual FSRB derive from the governing principles and the current FATF Recommendations rather than from any single fixed requirement; confirm details against current FATF publications.

Why it matters

FATF-Style Regional Bodies matter because they extend the reach of FATF anti-money laundering and counter-terrorist financing (AML/CFT) standards to nearly every country in the world. According to the evidence, the FATF is composed of 39 member countries working alongside nine FSRBs, and together they can claim almost every country as a member. For payment processors, acquirers, and merchant risk teams operating across borders, this means the AML/CFT expectations that shape correspondent banking relationships, sanctions screening, and know-your-customer obligations are propagated regionally through these bodies rather than only through the FATF directly.

For compliance officers, the practical significance is that a counterparty's home jurisdiction may derive its AML/CFT framework from an FSRB that promotes and monitors implementation of FATF standards within its region. Understanding which FSRB governs a given jurisdiction helps risk teams interpret the regulatory environment a partner operates in. It is worth noting that FSRBs address AML/CFT governance and are distinct from payment security standards such as PCI DSS; an FSRB does not set requirements for the protection of cardholder data or sensitive authentication data.

Practitioners should be careful not to overstate what FSRB membership implies. Membership indicates a jurisdiction participates in a body that follows FATF standards and guidance, but the specific roles, membership, and procedures of an individual FSRB derive from agreed high-level principles and the current FATF Recommendations rather than from any single fixed rule. Exact membership lists, mutual evaluation outcomes, and procedural details change over time and should be confirmed against current FATF publications rather than assumed.

Who it's relevant to

Compliance and AML Officers
Compliance teams use knowledge of which FSRB governs a jurisdiction to interpret the AML/CFT framework a counterparty operates under. Because FSRBs promote and monitor implementation of FATF standards regionally, understanding this structure supports risk-based assessment of cross-border relationships. Confirm current membership and procedural details against current FATF publications rather than assuming a fixed rule.
Acquirers and Payment Processors
Firms operating across multiple regions encounter counterparties whose home jurisdictions derive their AML/CFT expectations partly through FSRB participation. This context helps inform correspondent relationships and onboarding decisions. Note that FSRB governance is separate from payment security standards such as PCI DSS and does not address cardholder data protection.
Fraud and Merchant Risk Teams
Risk teams benefit from understanding the AML/CFT governance environment shaped regionally by FSRBs, which together with the FATF cover nearly every country. This regional context can inform how a partner's regulatory obligations are structured, though it does not by itself indicate the fraud controls or transaction-level authentication a partner applies.

Inside FSRB

Regional Mandate
A FATF-Style Regional Body (FSRB) is an intergovernmental group that promotes anti-money laundering (AML) and counter-terrorist financing (CTF) standards within a specific geographic region, modeled on the Financial Action Task Force (FATF). Its focus is on financial crime governance, not on payment card security standards such as PCI DSS.
Mutual Evaluation Function
FSRBs conduct peer reviews (mutual evaluations) of member jurisdictions to assess technical compliance with, and effectiveness of, AML/CTF measures. These evaluations produce findings and recommendations that member states are expected to address over time.
Adoption of FATF Recommendations
FSRBs promote implementation of the FATF Recommendations within their region, adapting oversight to regional context while aligning with the global standard-setting body. This is distinct from card brand and network rules that govern payment fraud liability and chargebacks.
Regional Membership
Membership consists of jurisdictions within a defined geographic area, along with observers that may include international organizations. The specific member composition and mandate vary by body and region.

Common questions

Answers to the questions practitioners most commonly ask about FSRB.

Is a FATF-Style Regional Body part of the PCI DSS compliance framework?
No. A FATF-Style Regional Body (FSRB) operates in the anti-money laundering and counter-terrorist financing (AML/CFT) domain, promoting adoption of FATF standards within a specific geographic region. It is separate from PCI DSS and the related PCI standards such as PA-DSS, the PCI Software Security Framework, PCI PIN, PCI P2PE, and PCI 3DS. Payment security and fraud teams should not treat FSRB assessments as substitutes for, or equivalents to, PCI DSS validation; the objectives, governing bodies, and scope differ.
Does membership in a FATF-Style Regional Body mean a jurisdiction meets PCI DSS or card brand fraud requirements?
No. FSRB participation reflects a jurisdiction's engagement with AML/CFT standard-setting and mutual evaluation processes, not its handling of cardholder data or sensitive authentication data. Chargeback rules, liability shift, and fraud-prevention obligations are governed by card brand and network rules and by applicable PCI standards, which are distinct from AML/CFT frameworks. Compliance in one domain should not be assumed to imply compliance in the other.
How does an FSRB context relate to payment fraud investigations?
AML/CFT frameworks promoted through FSRBs address money laundering and terrorist financing risks, which may intersect with certain payment fraud scenarios but are analyzed under different rules and objectives. Fraud types such as card-present versus card-not-present fraud, account takeover, first-party or friendly fraud, chargeback fraud, and synthetic identity fraud are handled under card brand and network processes and internal risk controls, which operate separately from AML/CFT obligations. Teams should coordinate but not conflate these workstreams.
Should PCI DSS scoping decisions reference FSRB requirements?
No. PCI DSS scope is determined by where cardholder data and sensitive authentication data are stored, processed, or transmitted, and by the controls and validation applied. FSRB-related AML/CFT obligations do not define PCI DSS scope. When documenting scope, confirm PCI DSS requirements against the current published standard, since requirement numbering and wording differ between versions, and keep AML/CFT documentation in a separate governance track.
Can data-protection controls used for PCI DSS satisfy AML/CFT obligations tied to FSRB frameworks?
Not automatically. Techniques such as tokenization, encryption, truncation, masking, and hashing transform or reduce data differently, and their effect depends on implementation and validation. These controls address protection of cardholder data under PCI DSS but do not, by themselves, meet AML/CFT recordkeeping, monitoring, or reporting expectations. Each obligation should be mapped independently to its governing framework.
How should a merchant or processor operating across multiple regions treat differing FSRB and card network rules?
Treat them as distinct, region-specific obligations. AML/CFT expectations promoted through FSRBs vary by region and evolve over time, and card brand and network rules, including chargeback and liability-shift provisions, also change and vary by region. Maintain separate documentation and confirm current requirements against the relevant authoritative source for each domain, rather than assuming a single fixed set of rules applies everywhere.

Common misconceptions

An FSRB sets or enforces payment security standards such as PCI DSS.
FSRBs address AML/CTF policy and regulation at a regional, governmental level. PCI DSS and related standards (PA-DSS, PCI Software Security Framework, PCI PIN, PCI P2PE, PCI 3DS) are governed separately through the payment industry standards ecosystem, not by FSRBs. The two operate in different domains and should not be conflated.
FSRB mutual evaluations directly certify or validate a merchant's or processor's compliance controls.
FSRB evaluations assess jurisdiction-level AML/CTF frameworks and their effectiveness, not the compliance status of individual merchants, acquirers, or processors. Payment entity validation is handled through separate assessment processes tied to the applicable payment security standards.
Adherence to FSRB-promoted measures eliminates financial crime or fraud in a region.
FSRB frameworks are intended to help reduce and mitigate money laundering and terrorist financing risk; they do not guarantee prevention. They also do not address the full range of payment fraud types, such as card-not-present fraud, account takeover, or synthetic identity fraud, which are governed by different controls and by card brand and network rules that vary by region and change over time.

Best practices

Keep AML/CTF obligations arising from FSRB-aligned regional frameworks distinct from payment security obligations under PCI DSS and related standards, and map each set of requirements to its own governing authority.
Confirm which specific standard or rule governs a given control before acting, rather than assuming an FSRB requirement covers payment card data protection or vice versa.
Track the regional applicability of any FSRB-derived obligation, since mandates, member composition, and expectations vary by body and region and may change over time.
Coordinate compliance and fraud teams so that AML/CTF findings and payment fraud controls are handled through their correct, separate processes without overlap or gaps.
Verify liability shift and chargeback treatment against current card brand and network rules for the relevant region, and do not rely on FSRB frameworks to define payment fraud liability.
Document known limitations when describing the effect of AML/CTF measures, using qualified language such as 'intended to reduce' rather than implying that any single framework prevents financial crime or fraud.