FATF: What FCA-Regulated Firms Need to Know

FATF: What FCA-Regulated Firms Need to Know

Financial Action Task Force directly, yet its work shapes the anti-money-laundering obligations every regulated firm has to meet. FATF sets the global standards that flow into UK law and, ultimately, into a firm’s customer due diligence and financial crime controls. This article explains what FATF is, how its standards reach UK firms, and what a compliance or financial crime function needs to know.

What FATF is

The Financial Action Task Force is the international standard-setter for anti-money-laundering and counter-terrorist-financing. It is an inter-governmental body, not a regulator of individual firms — it does not supervise or fine a UK payments firm or bank. Instead it sets the international standards, known as the FATF Recommendations, that member countries are expected to implement in their own law, and it assesses how well they do so.

The UK is a founding member and is assessed against the standards like any other member. That assessment matters at national level: a poor evaluation pressures the government and regulators to tighten the domestic regime, which is one route by which FATF’s work eventually reaches individual firms.

How FATF standards reach UK firms

The chain from FATF to a firm’s controls runs through domestic law. The FATF Recommendations shape the UK’s anti-money-laundering framework — principally the Money Laundering Regulations 2017 — which in turn impose the obligations firms actually comply with: the risk-based approach, customer due diligence, enhanced due diligence for higher-risk situations, ongoing monitoring, and suspicious activity reporting. So a firm does not comply with FATF directly; it complies with UK law that implements FATF standards.

Understanding this chain matters because it explains why the domestic rules look as they do, and why changes at FATF level eventually work through into firms’ obligations. A financial crime professional who understands the standards behind the rules is better placed to interpret the rules purposively rather than mechanically.

The grey list and black list

The part of FATF’s work most directly relevant to day-to-day compliance is its identification of higher-risk jurisdictions. FATF publicly identifies countries with strategic deficiencies in their AML/CTF regimes — the widely-used shorthand is the ‘grey list’ for jurisdictions under increased monitoring, and the ‘black list’ for those subject to a call for action. These lists feed directly into firms’ risk-based approach.

When a country is grey-listed, firms are generally expected to factor that into their country risk assessment and may need to apply enhanced due diligence to customers or transactions connected to it. Black-listed jurisdictions attract the strongest response. A firm’s country risk framework and screening should reflect the current FATF listings, and keeping that current is an ongoing compliance task, because the lists change as FATF updates its assessments.

Why this matters for the financial crime function

For a compliance or financial crime function, FATF is the backdrop that explains and drives much of the day-to-day work. The firm-wide risk assessment should reflect FATF’s risk framing; the country risk model should reflect its listings; the enhanced due diligence triggers should capture higher-risk jurisdictions; and the whole approach should be recognisably risk-based in the way FATF’s standards require. A financial crime professional who can connect the firm’s controls back to the standards behind them demonstrates the depth that distinguishes a strong candidate.

Keeping current

Because FATF updates its listings and periodically revises its Recommendations, the function has to stay current rather than treat this as settled knowledge. Listing changes should flow through into the country risk framework promptly, and significant changes to the Recommendations eventually reshape domestic obligations. Building that monitoring into the compliance calendar is part of running a financial crime function properly.

FD Capital recruits MLROs and financial crime professionals who understand the standards behind the rules, into FCA-regulated firms.

The mutual evaluation process

One of FATF’s main tools is the mutual evaluation — a periodic, in-depth assessment of how effectively a country implements the standards. These evaluations carry weight: a poor result puts a country under pressure to strengthen its regime, which flows through into tougher domestic rules and more demanding supervision of firms. For a UK financial crime professional, the national evaluation is worth following, because its findings shape the direction of the regime they work within.

The evaluations also assess effectiveness, not just technical compliance — whether the country’s AML system actually works, not merely whether the laws are on the books. That effectiveness focus has increasingly influenced how the FCA supervises firms: it is not enough to have the policies, they have to work.

How FATF shapes day-to-day controls

Beyond the lists, FATF’s standards underpin the everyday architecture of a firm’s financial crime controls. The risk-based approach that runs through the Money Laundering Regulations is a FATF principle. The expectation of a firm-wide risk assessment reflects FATF’s framing. The customer due diligence and enhanced due diligence obligations trace back to the Recommendations. A financial crime professional who understands this lineage interprets the domestic rules with a surer grasp of what they are for.

Practical steps for the compliance function

  • Reflect current FATF listings in the country risk model, and update promptly when they change.
  • Ensure enhanced due diligence triggers capture higher-risk jurisdictions FATF has identified.
  • Ground the firm-wide risk assessment in FATF’s risk framing, not just a generic template.
  • Track significant revisions to the FATF Recommendations, which eventually reshape domestic obligations.
  • Follow the UK’s mutual evaluation findings for signals about where the regime is heading.

Common misconceptions

A few misunderstandings about FATF recur, and clearing them up sharpens a compliance professional’s grasp of the framework. FATF is not a law and does not regulate firms directly — it sets standards that countries implement, so a firm never complies with FATF as such. Its lists are not sanctions — grey-listing is not the same as a sanctions designation, though both feed a firm’s risk assessment and screening. And FATF membership is not a mark of low risk in itself — a member country can still be assessed as having deficiencies. Understanding these distinctions helps a financial crime function apply FATF’s output correctly rather than mechanically.

Why this knowledge matters in a candidate

For firms hiring MLROs and financial crime professionals, genuine FATF literacy is a useful signal of depth. A candidate who understands how the international standards flow into UK law, what the lists mean for the risk-based approach, and how the mutual evaluation process shapes the regime, brings a purposive understanding of the rules rather than a checklist familiarity. That depth tends to distinguish the professionals who can build and defend a genuinely risk-based framework from those who can only operate an inherited one — which is precisely the difference that matters most in the MLRO role.

The bigger picture for regulated firms

Stepping back, FATF matters to a regulated firm because it is the source of the logic behind the whole anti-money-laundering regime. The risk-based approach, the emphasis on effectiveness over box-ticking, the focus on higher-risk jurisdictions, the expectation of a firm-wide risk assessment — all trace back to FATF’s standards, filtered through UK law. A firm that understands this sees its financial crime obligations not as an arbitrary rulebook but as a coherent framework with a purpose, which makes for better judgement in the grey areas where the rules do not give a clear answer. That purposive understanding, at the top of the financial crime function, is what turns compliance from a cost into genuine protection against being used to launder money — which is, in the end, what the whole system exists to prevent.

Call 020 3287 9501 or email recruitment@fdcapital.co.uk to discuss an MLRO or financial crime appointment at an FCA-regulated firm.

FD Capital — MLRO and Financial Crime Recruitment

Fellow of the ICAEW | Placing MLROs and financial crime leaders into FCA-regulated firms since 2018. 4,600+ network. 160+ placements. Shortlists in 3–7 working days.

Related reading and services

SMF17 MLRO: Career Path

The route to the MLRO function.

How to Become a Head of Compliance

The route to SMF16 Compliance Oversight.

MLRO Recruitment

Specialist MLRO and nominated officer recruitment.

Financial Crime Recruitment

AML and financial crime leadership appointments.

About the author

Adrian Lawrence FCA is the founder and Managing Director of FD Capital. A Fellow of the Institute of Chartered Accountants in England and Wales and a former listed-company Finance Director, he leads every financial crime and compliance mandate FD Capital accepts personally. Verify his ICAEW membership.

Call 020 3287 9501 or email recruitment@fdcapital.co.uk.

This article is general information about UK financial services regulation and recruitment practice. It is not legal or regulatory advice. Firms and individuals should take their own professional advice on their specific circumstances.