← Industry Insights
Financial Crimes

FATF Blacklist and Grey List: What They Mean for AML Compliance

Updated Jun 2026 · 5 min read
SHAREinXf
What are FATF Blacklist and Grey List?

The Financial Action Task Force keeps two public lists. Both flag countries with weaknesses in their anti-money laundering and counter-terrorist financing regimes. The blacklist names "high-risk jurisdictions subject to a call for action," the most serious category. Sitting one rung below is the grey list, "jurisdictions under increased monitoring," where a country has committed to fixing identified gaps on a set timeline. For a compliance team, none of this is geopolitical trivia. These lists feed directly into country risk scoring, customer risk rating, and the level of due diligence you owe on any relationship that touches a listed jurisdiction.

What follows: what each list is, how they differ, how the FATF decides who goes on and comes off, and what a listing should change in your AML program.

What is the FATF Grey List?

The grey list, formally titled "Jurisdictions under Increased Monitoring," covers countries that have strategic deficiencies in their AML and CTF frameworks but have given the FATF a high-level political commitment to fix them within agreed timeframes. A grey listing does not bar a country from the global financial system. These jurisdictions are working with the FATF and the relevant FATF-Style Regional Body to close the gaps already identified.

For your program, read a grey-list designation as elevated risk, not prohibitive risk. Counterparties and customers connected to a grey-listed country warrant closer review, sharper transaction monitoring, and clearer documentation of source of funds. The relationship can usually continue under enhanced controls.

What is the FATF Blacklist?

The blacklist, formally titled "High-Risk Jurisdictions Subject to a Call for Action," is the FATF's most severe designation. These are jurisdictions with serious, persistent deficiencies the country has failed to remedy. For them the FATF calls on all members to apply enhanced due diligence, and in the most serious cases to apply countermeasures that go beyond standard EDD.

A blacklist designation effectively tells the global financial system one thing: treat any exposure to that jurisdiction as carrying a high risk of money laundering, terrorist financing, or proliferation financing. Transactions get slower. They get costlier. Some are avoided entirely.

The Difference Between the FATF Blacklist and Grey List

Both lists sit on a spectrum of severity and intent. The grey list is a monitoring tool aimed at correction: the country has acknowledged its weaknesses, agreed to a remediation plan, and the FATF tracks progress until the gaps close. Enforcement is the blacklist's job. Here the deficiencies are severe, remediation has stalled or failed, and the FATF is asking the world to actively guard the financial system against the risk.

Consequences scale accordingly. Grey-list exposure typically calls for risk-based enhanced measures and tighter monitoring. Blacklist exposure calls for systematic enhanced due diligence on every relevant relationship, and for the highest-risk jurisdiction it calls for countermeasures. Treating both lists as a single "risky countries" bucket is a common mistake. They demand different responses, and your country risk model should reflect that.

Book an AML Screening Demo

What a Listing Means for Compliance and EDD on High-Risk Jurisdictions

A FATF listing is one of the clearest external triggers for enhanced due diligence in your risk framework. When a customer, beneficial owner, counterparty, or correspondent relationship connects to a listed jurisdiction, the standard customer due diligence baseline no longer holds.

In practice, exposure to a listed jurisdiction usually means you should:

  • Raise the country risk weighting in your customer risk rating model, then re-score affected relationships.
  • Verify source of funds and source of wealth more rigorously. Documented evidence, not self-attestation.
  • Tighten the transaction monitoring thresholds and scenarios that catch flows touching the jurisdiction.
  • Escalate to senior compliance sign-off before onboarding or continuing higher-risk relationships.
  • Refresh due diligence more often instead of waiting on periodic review cycles.

For blacklisted jurisdictions, these measures move from advisable to expected, and you may be obligated to apply specific countermeasures depending on your regulator's guidance. Keeping pace is the hard part. Lists change several times a year, sanctions and adverse media shift constantly, and a manual lookup at onboarding leaves you blind to a customer who turns high-risk after the relationship begins. This is where continuous screening and perpetual KYC matter more than a one-time check.

How the FATF Lists Are Decided and Updated

Founded in 1989 at the request of the G7 and headquartered in Paris, the FATF is an intergovernmental body with 40 members covering most major financial centers. Its Recommendations set the global standards for combating money laundering and terrorist financing, and it assesses how well countries implement them.

Listing decisions flow from mutual evaluations. A jurisdiction gets assessed against the FATF Recommendations, on its own or in partnership with bodies such as the International Monetary Fund and the World Bank. Where significant deficiencies surface, the country may be placed under increased monitoring (the grey list) with an agreed action plan. Where they are severe and unaddressed, it becomes subject to a call for action (the blacklist).

Plenary meetings, held three times a year, are where the FATF reviews and updates the lists. Countries join as new deficiencies emerge and exit once they show the agreed reforms are in place and effective. So the specific countries on each list change regularly. The reliable approach for a compliance team is to pull current designations from a maintained data source, not hard-code a country list that goes stale within months.

How KYC Hub Helps You Operationalize FATF Risk

Knowing the lists helps only if your systems act on them automatically. KYC Hub's AML screening and monitoring platform turns FATF designations from a manual lookup into a live control. It runs thorough AML screening against sanctions, watchlists, and high-risk jurisdiction data. Continuous monitoring with AML alerts catches a relationship that becomes high-risk after onboarding. Global adverse media intelligence surfaces negative news tied to listed countries and the entities operating in them.

Network intelligence maps the connections behind a customer, so exposure to a listed jurisdiction stays visible even when it sits a layer removed from the named party. Because the platform is tuned to reduce false positives, your analysts spend their time on genuine high-risk exposure rather than clearing noise. Pair that with customer risk rating that ingests country risk automatically, and FATF listings flow straight into your scoring and your enhanced due diligence workflows without manual reconciliation.

Book an AML Screening Demo

[ FREQUENTLY ASKED QUESTIONS ]

Any questions? We got you.

What is the difference between the FATF grey list and blacklist?

The grey list ("jurisdictions under increased monitoring") covers countries with strategic AML and CTF deficiencies that have committed to a remediation plan with the FATF. The blacklist ("high-risk jurisdictions subject to a call for action") covers countries with severe, unaddressed deficiencies where the FATF calls for enhanced due diligence and, in the most serious case, countermeasures. Grey-listed countries can still transact globally under closer scrutiny, while blacklisted jurisdictions face the strongest measures.

Does a FATF grey listing require enhanced due diligence?

Yes, in effect. A grey listing is a clear trigger to apply a risk-based enhanced approach to relationships connected to that jurisdiction. That typically means raising the country risk weighting, verifying source of funds more rigorously, tightening transaction monitoring, and refreshing due diligence more often. Exact obligations depend on your regulator's guidance, but treating grey-list exposure as elevated risk is the expected baseline.

How often does the FATF update its lists?

The FATF reviews and updates the blacklist and grey list at its plenary meetings, which are held three times a year. Countries are added as new deficiencies are identified and removed once they demonstrate effective reforms. Because the lists change on this schedule, compliance teams should pull current designations from a maintained data feed rather than relying on a static country list.

How should compliance teams monitor FATF list changes?

Manual lookups at onboarding leave gaps, because a customer or counterparty can connect to a jurisdiction that gets listed after the relationship begins. The reliable approach is automated, continuous screening that ingests FATF designations alongside sanctions and adverse media, feeds them into your customer risk rating, and generates alerts when exposure changes. This keeps your enhanced due diligence aligned with the current lists without manual reconciliation.

Why does FATF maintain a blacklist and grey list?

The lists are a pressure mechanism. By publicly identifying jurisdictions with AML and CTF weaknesses, the FATF encourages governments to strengthen their frameworks and warns the global financial system to apply appropriate caution. The grey list pushes correction through monitoring, while the blacklist protects the system by directing members to apply enhanced measures against the highest-risk jurisdictions.

[ KYC HUB ]

Screen and monitor for financial crime in real time

Sanctions, PEP and adverse-media screening with ongoing transaction monitoring and case management.

Explore the AML screening & monitoringBook a demo
[ RELATED READING ]
Combating Financial Crimes in 2026: Global Efforts to Fight Back
[ Financial Crimes ]

Combating Financial Crime in 2026: A Compliance Playbook

A B2B compliance view of combating financial crime in 2026: the global bodies, regulators, FIUs, and AI-driven controls that detect, report, and disrupt illicit finance.

Dec 2025 · 6 min read
Biggest Banking Frauds in India: All You Need to Know in 2025
[ Financial Crimes ]

Bank Fraud Examples in India: Top 15 Cases, Types and Prevention (2026)

Explore the top 15 banking frauds in India that shook the financial industry. Learn about key bank fraud cases, their impact, and ways to prevent financial scams.

Mar 2025 · 15 min read
Deepfake Laws and Regulations: All You Need to Know in 2025
[ Financial Crimes ]

What Are Deepfakes? Detection, Fraud Risks, and Global Laws in 2026

A practical guide to deepfakes for compliance and fraud teams: what they are, how detection works, the fraud risks to financial services, and how laws are evolving worldwide.

Feb 2025 · 12 min read