Skip to main content
Category: AML and KYC

High-Risk Jurisdiction

Also known as: High-Risk Third Country, High-Risk and Other Monitored Jurisdiction
Simply put

A high-risk jurisdiction is a country or territory identified as having weaknesses in its ability to fight money laundering and terrorist financing. These weaknesses may stem from factors such as political instability, widespread corruption, or an inadequate legal framework to combat financial crime. Businesses dealing with such jurisdictions are generally expected to apply extra scrutiny.

Formal definition

A high-risk jurisdiction is a country or territory identified by an authoritative body as having strategic deficiencies in its anti-money laundering and countering the financing of terrorism (AML/CFT) regime. The Financial Action Task Force (FATF) publishes and periodically updates lists distinguishing jurisdictions under increased monitoring, which are actively working with FATF to address identified strategic deficiencies, from higher-risk categories; the European Commission is separately mandated to identify high-risk third countries with such strategic deficiencies. These designations reflect the principle that global AML/CFT safeguards are only as strong as the jurisdiction with the weakest measures. Because these lists are maintained by different bodies and are revised on an ongoing basis, practitioners should confirm current designations against the relevant issuing authority's published lists rather than relying on a static reference. Note that jurisdiction-level risk designation is distinct from, and does not substitute for, entity- or transaction-level risk assessment.

Why it matters

Jurisdiction-level risk is a foundational input to any risk-based AML/CFT program. The principle underlying these designations is that global safeguards against money laundering and terrorist financing are only as strong as the jurisdiction with the weakest measures, so a deficiency in one country's regime can create exposure that propagates through the financial system. For businesses that onboard customers, process payments, or maintain correspondent relationships across borders, knowing whether a counterparty is connected to a jurisdiction with strategic AML/CFT deficiencies helps determine the level of due diligence and monitoring that should be applied.

These designations carry practical weight because they are issued by authoritative bodies and are revised on an ongoing basis. The Financial Action Task Force (FATF) publishes and periodically updates lists that distinguish jurisdictions under increased monitoring, which are actively working with FATF to address identified strategic deficiencies, from higher-risk categories. The European Commission is separately mandated to identify high-risk third countries having strategic deficiencies in their AML/CFT regime. Because different bodies maintain their own lists on different schedules, relying on a static or outdated reference can leave a program applying the wrong level of scrutiny.

It is important to treat jurisdiction-level designation as one signal rather than a complete assessment. A country appearing on a list does not by itself establish that a specific customer or transaction is illicit, and a country's absence from a list does not guarantee low risk. Jurisdiction-level risk designation is distinct from, and does not substitute for, entity- or transaction-level risk assessment; it informs those assessments rather than replacing them.

Who it's relevant to

Compliance and AML/CFT Officers
These teams incorporate high-risk jurisdiction designations into risk-based due diligence and monitoring frameworks. They are responsible for confirming current designations against the issuing authorities' published lists, since FATF and the European Commission maintain separate lists that are revised on an ongoing basis.
Merchant Risk and Onboarding Teams
When evaluating customers or counterparties connected to a jurisdiction with strategic AML/CFT deficiencies, these teams generally apply extra scrutiny during onboarding. They should treat jurisdiction-level designation as one input that informs, but does not replace, entity- and transaction-level risk assessment.
Payment Processors and Acquirers
Organizations that process cross-border payments or maintain relationships spanning multiple jurisdictions use these designations to calibrate scrutiny, reflecting the principle that global AML/CFT safeguards are only as strong as the jurisdiction with the weakest measures.
Fraud and Financial Crime Analysts
Analysts use jurisdiction-level risk as one signal among many when assessing patterns tied to political instability, corruption, or weak legal frameworks. They should combine it with other indicators, recognizing that a jurisdiction's presence on or absence from a list does not by itself confirm or rule out illicit activity.

Inside High-Risk Jurisdiction

Jurisdictional Risk Designation
A classification applied to a country, territory, or region that is considered to present elevated risk for money laundering, terrorist financing, fraud, sanctions exposure, or weak regulatory oversight. Designations may originate from card brand rules, acquirer risk policies, regulatory bodies, or internal risk models, and the specific list of jurisdictions varies by source and changes over time.
Source Authority
The body or framework that defines a jurisdiction as high-risk. This may include card network and brand rules, financial regulators, government or intergovernmental bodies, or a payment processor's or acquirer's own risk program. Because sources differ in criteria and update cadence, a jurisdiction may be treated differently across programs.
Enhanced Due Diligence Triggers
Additional controls that may apply to transactions, merchants, or cardholders associated with a high-risk jurisdiction, such as heightened identity verification, transaction monitoring thresholds, or manual review. These are risk-management measures and their specifics depend on the governing policy or rule set rather than on PCI DSS, which addresses account data protection.
Relationship to Fraud and Compliance Programs
Jurisdictional risk is one input among many in fraud detection and compliance decisioning. It intersects with card-not-present fraud screening, sanctions and watchlist screening, and acquirer risk policies, but it is a contextual signal rather than a standalone determinant of a transaction's legitimacy.

Common questions

Answers to the questions practitioners most commonly ask about High-Risk Jurisdiction.

Does a merchant or transaction being tied to a high-risk jurisdiction automatically mean the transaction is fraudulent?
No. A high-risk jurisdiction designation is a risk indicator, not a determination of fraud. It may raise the aggregate probability that additional scrutiny is warranted, but many legitimate transactions originate from or involve such jurisdictions. Treating the designation as conclusive tends to produce elevated false positives. The classification is best used as one weighted input alongside other signals rather than as a standalone accept or decline rule.
Is 'high-risk jurisdiction' a term defined by PCI DSS?
No. High-risk jurisdiction is not a PCI DSS defined term or requirement. It arises primarily from anti-money-laundering and sanctions frameworks, card brand and network rules, and individual acquirer or processor risk policies, which vary by region and change over time. PCI DSS governs the protection of cardholder data and the security of the cardholder data environment; jurisdictional risk classification is a separate concern governed by different bodies. Confirm any obligations against the specific regulatory or network source that applies to you.
How should jurisdictional risk be incorporated into a fraud scoring model?
It is typically implemented as one weighted feature among many, such as combined with device, velocity, behavioral, and historical signals, rather than as a hard block. Because it can drive false positives when used in isolation, teams often calibrate its weight against observed outcomes for their own portfolio and monitor the false-positive and false-negative trade-off. The appropriate weighting depends on your customer base, product, and risk appetite.
What sources should be used to build and maintain a high-risk jurisdiction list?
Common inputs include applicable sanctions and AML program requirements, card brand and network rules, and acquirer or processor policies. Because these sources vary by region and are revised over time, lists should be reviewed on a defined cadence and updated when the underlying sources change. Document which source drives each classification so decisions can be traced and defended during review.
How can jurisdictional risk be applied without over-blocking legitimate customers?
Rather than declining outright, many teams route higher-risk cases to step-up measures or additional review, for example requesting additional authentication or manual review, while reserving hard declines for cases with multiple corroborating signals. Monitoring approval rates, disputes, and customer friction by segment helps tune thresholds. The goal is to manage the false-positive and false-negative balance for your specific portfolio.
How does jurisdictional risk relate to authentication controls such as 3-D Secure or strong customer authentication?
Jurisdictional risk is a signal that may inform whether to invoke additional authentication, but it is distinct from the authentication mechanisms themselves. Controls such as 3-D Secure, strong customer authentication, and multi-factor authentication address different risks at different points in a transaction and none eliminate fraud on their own. Jurisdictional risk can help decide when to apply step-up authentication, but it does not replace the underlying authentication or liability rules, which are governed by card brand and network rules that vary by region.

Common misconceptions

A single authoritative list of high-risk jurisdictions applies uniformly across all payment programs.
There is no single universal list. Designations depend on the source authority, whether card brand rules, regulators, or an organization's internal risk model, and these lists differ in criteria and are updated on different schedules. Practitioners should confirm against the specific governing source relevant to their program.
Blocking or flagging transactions from high-risk jurisdictions prevents fraud.
Jurisdictional screening may help reduce exposure to certain risks, but it does not prevent fraud on its own. It produces both false positives, where legitimate transactions are blocked, and false negatives, where risky transactions from lower-risk jurisdictions pass. It is intended to be one signal within a layered detection and decisioning approach.
High-risk jurisdiction status is a PCI DSS concept that changes how account data must be protected.
PCI DSS addresses the protection of cardholder data and sensitive authentication data regardless of jurisdiction. High-risk jurisdiction designations come from fraud, sanctions, and risk-management contexts and from card brand or regulatory rules, not from PCI DSS. The two address different concerns and should not be conflated.

Best practices

Identify the specific source authority governing your program's high-risk jurisdiction designations, such as card brand rules, regulators, or your acquirer's risk policy, and confirm designations against that source rather than assuming a fixed list.
Treat jurisdictional risk as one contextual signal within a layered fraud and compliance program alongside sanctions screening, identity verification, and transaction monitoring, rather than as a standalone accept-or-decline rule.
Establish a review cadence to refresh jurisdiction designations, since lists and criteria change over time and vary by region and source.
Monitor and tune the false-positive and false-negative trade-offs of jurisdiction-based rules so legitimate transactions are not unnecessarily blocked while genuinely risky activity is still surfaced for review.
Document the rationale, source, and effective date for each jurisdictional control to support auditability and to distinguish these fraud and risk measures from PCI DSS account-data protection obligations.
Coordinate jurisdictional risk decisions with your acquirer and compliance function, since liability, chargeback, and regulatory obligations are governed by card brand, network, and regional rules that vary and change.