Skip to main content
Category: Compliance Programs

Countering the Financing of Terrorism

Also known as: CFT, Combating the Financing of Terrorism, Counter-Terrorist Financing, Fight Against the Financing of Terrorism
Simply put

Countering the financing of terrorism (CFT) refers to the collective efforts, laws, and controls designed to detect and prevent funds from reaching terrorist groups. It aims to disrupt the movement of money that could be used to support terrorist activity. CFT is generally treated as a core component of broader counter-terrorism and financial crime strategies.

Formal definition

Countering the Financing of Terrorism (CFT) encompasses the legal tools, regulatory frameworks, and institutional controls used to detect, prevent, and suppress the flow of funds to terrorist groups and individuals. It typically operates alongside anti-money laundering (AML) programs and includes obligations that vary by jurisdiction and entity type, such as detecting suspicious movements of funds, applying red-flag typologies, and reporting. At the international level, instruments such as UN Security Council Resolution 2462 (adopted under Chapter VII) address the prevention and suppression of terrorist financing and provide for international cooperation, while regional strategies, such as those of the EU, incorporate CFT as a core counter-terrorism measure. This entry describes the concept generally and does not set out the specific binding requirements of any single jurisdiction or framework; applicable obligations depend on the relevant laws, sector, and facts and should be confirmed against primary sources. This entry is educational and is not legal, audit, or compliance advice.

Why it matters

Terrorist financing represents a distinct financial crime risk that differs in important ways from money laundering. Where laundering typically seeks to disguise the illicit origin of funds, terrorist financing may involve funds from entirely legitimate sources that are diverted toward illicit ends, which makes detection through conventional red-flag typologies more challenging. Countering the financing of terrorism (CFT) matters because disrupting the movement of money is generally treated as a core component of broader counter-terrorism and financial crime strategies, and failures in this area can carry legal, regulatory, and reputational consequences for institutions that handle funds.

Who it's relevant to

Chief Compliance and Financial Crime Officers
Compliance functions generally own the design and operation of CFT controls, which typically sit within or alongside AML programs. These officers are responsible for maintaining red-flag typologies, transaction monitoring, and reporting processes, and for confirming applicable obligations against the relevant laws and sector requirements, since these vary by jurisdiction and entity type.
General Counsel and Legal Teams
Legal teams typically advise on the legal tools and frameworks relevant to CFT, including how international instruments and regional strategies intersect with the specific binding requirements applicable to the organization. Because applicable obligations depend on the relevant laws, sector, and facts, legal counsel plays a role in confirming requirements against primary sources.
Boards and Risk Committees
The board and its relevant committees generally hold oversight responsibility for the organization's financial crime risk framework, including CFT, without assuming operational execution. Their focus is typically on satisfying themselves that management has implemented adequate controls and that the framework reflects the organization's risk exposure.
Internal Audit and Assurance Functions
Assurance functions provide independent evaluation of whether CFT controls are appropriately designed and operating effectively, distinct from the compliance function that owns those controls. This includes testing detection, monitoring, and reporting processes against applicable obligations.

Inside CFT

CFT Legal and Regulatory Framework
The body of binding obligations, which in many jurisdictions derives from statutes, regulations, and financial sector rules that criminalize terrorist financing and impose preventive duties on regulated entities. The specific requirements vary by jurisdiction, sector, and entity type, and are often informed by, but distinct from, non-binding international standards such as the FATF Recommendations.
Customer Due Diligence and Screening
Processes by which regulated entities identify and verify customers and, where applicable, beneficial owners, and screen relationships and transactions against relevant sanctions and designated-person lists. CFT screening is typically integrated with, but analytically distinct from, anti-money laundering (AML) due diligence.
Transaction Monitoring and Detection
Ongoing monitoring intended to identify activity that may be associated with terrorist financing. Because terrorist financing can involve small, licit-source funds, detection methods often differ in emphasis from those aimed at laundering large proceeds of crime.
Sanctions and Asset-Freezing Measures
Obligations that may require entities to freeze funds or economic resources of designated persons or entities and to refrain from making assets available to them. The scope and lists depend on the applicable jurisdiction and the sanctions regimes to which an entity is subject.
Reporting and Disclosure Obligations
Requirements, where they apply, to report suspicious activity or transactions to the relevant national authority (such as a financial intelligence unit). The triggers, timing, and format of reporting are set by applicable law and vary by jurisdiction.
Governance, Roles, and Assurance
The allocation of accountability for CFT across the organization: the board and relevant committee typically provide oversight; management and first-line business functions own and execute controls; the compliance function commonly designs and monitors the CFT program; and internal audit provides independent assurance over its design and operating effectiveness.

Common questions

Answers to the questions practitioners most commonly ask about CFT.

Is countering the financing of terrorism (CFT) the same as anti-money laundering (AML)?
No, though the two are closely related and often addressed within a combined AML/CFT program. AML is generally concerned with detecting and preventing the laundering of proceeds derived from predicate crimes, meaning the funds typically originate from illicit activity. CFT is concerned with preventing funds from being used to support terrorism, and a key distinction is that the funds may originate from entirely legitimate sources, such as legal income or donations. This difference affects detection because CFT cannot rely solely on identifying illicit origins; it often depends on identifying suspicious destinations, connections, or patterns. Many jurisdictions and frameworks address the two together, but treating them as identical can create blind spots in a compliance program. The specific obligations that apply depend on the jurisdiction, sector, and entity type, and this entry is educational rather than legal or compliance advice.
Does CFT only concern large financial institutions?
Not necessarily. While banks and other financial institutions are often subject to detailed obligations in many jurisdictions, CFT-related requirements can extend to other entities depending on the applicable legal regime, such as money service businesses, certain designated non-financial businesses and professions, and, in some cases, non-profit organizations viewed as potentially vulnerable to abuse. The precise scope of who is covered, and to what degree, varies by jurisdiction, sector, and the nature of the activity. Whether a particular organization has CFT obligations, and what those obligations entail, is a fact-specific and jurisdiction-specific question that generally requires professional judgment and, where appropriate, legal advice.
Who within an organization is typically accountable for the CFT program, and how do the lines of defense apply?
Accountability generally follows the same structure used for broader compliance programs, though specific arrangements depend on the entity and jurisdiction. Under a three-lines model, the first line, business and operational units, typically owns the day-to-day activities, such as customer onboarding and transaction handling, and the controls embedded in those processes. The second line, which often includes a compliance function, typically designs the CFT framework, sets policy, provides oversight and monitoring, and reports on the program. Internal audit, as the third line, generally provides independent assurance over the design and operating effectiveness of the program. The board, or a designated committee, typically holds oversight responsibility rather than operational responsibility. Many regimes also expect a designated compliance officer role. Titles and precise duties vary, so entities should confirm the requirements applicable to them.
How does a risk-based approach apply to CFT?
Many CFT frameworks and regimes encourage or require a risk-based approach, meaning resources and controls are calibrated to the assessed level of risk rather than applied uniformly. In practice this generally begins with a risk assessment that considers factors such as customer types, products and services, delivery channels, and geographic exposure. Because CFT risk can involve funds from legitimate sources, the assessment often emphasizes connections, destinations, and behavioral patterns in addition to source-of-funds considerations. The output typically informs the intensity of due diligence, monitoring, and escalation. It is useful to distinguish inherent risk, before controls, from residual risk after controls are applied. The specific expectations for how a risk-based approach is documented and implemented vary by jurisdiction and sector, and the appropriate calibration is a matter of professional judgment.
What role do sanctions and watchlist screening play in a CFT program?
Screening against relevant designated-persons lists and sanctions regimes is commonly a component of CFT-related controls, because certain individuals and entities are designated in connection with terrorism or its financing. However, sanctions compliance and CFT are distinct though overlapping obligations, and the specific lists, legal bases, and prohibitions differ by jurisdiction. Screening supports the identification of prohibited relationships or transactions, but it is generally only one control among several, alongside customer due diligence, ongoing monitoring, and suspicious activity reporting. The design of screening, including matching thresholds, list coverage, and escalation, affects its effectiveness, and control design should be distinguished from operating effectiveness, which is assessed through testing. The precise applicable requirements are jurisdiction-specific and should be confirmed for the entity in question.
How should suspicious activity related to terrorist financing be handled once identified?
In many jurisdictions, where an entity forms a suspicion of terrorist financing, there are typically legal obligations to report to the relevant authority or financial intelligence unit, and in some regimes there may be restrictions on alerting the subject, often referred to as tipping-off prohibitions. The specific reporting channels, thresholds, timeframes, and prohibitions vary by jurisdiction and entity type. Internally, a CFT program generally establishes escalation procedures, defined decision-making responsibilities, documentation practices, and a clear interface with the designated compliance officer. Because the legal consequences of both reporting and failing to report can be significant, and because the requirements are fact- and jurisdiction-specific, entities should establish procedures based on the applicable regime and appropriate professional or legal advice. This entry is educational and does not constitute legal, audit, or compliance advice.

Common misconceptions

Countering the financing of terrorism is the same activity as anti-money laundering.
CFT and AML are related and often administered through shared systems, but they address different risks. Money laundering generally concerns disguising the illicit origin of funds, whereas terrorist financing may involve funds from legitimate sources directed toward illicit ends. This difference affects how risk is assessed and how detection is designed, so treating the two as interchangeable can leave gaps.
Adherence to an international framework such as the FATF Recommendations is itself a binding legal obligation.
International standards typically function as non-binding guidance that countries choose to implement. The binding obligations on any given entity arise from the statutes, regulations, and rules of the jurisdictions in which it operates. What an organization must actually do depends on applicable local law, its sector, and its entity type.
CFT is solely a compliance department responsibility.
Effective CFT depends on the roles being distributed across lines. First-line business functions and management generally own and operate day-to-day controls; the compliance function typically designs and monitors the program; internal audit provides independent assurance; and the board or its committee provides oversight. Accountability is shared rather than confined to a single function.

Best practices

Confirm the specific binding CFT obligations that apply to your jurisdiction, sector, and entity type before relying on general frameworks, and document how international guidance has been translated into local legal requirements.
Maintain a documented CFT risk assessment that reflects the distinct nature of terrorist financing, and calibrate customer due diligence, screening, and monitoring to that assessment rather than assuming AML controls are sufficient on their own.
Clarify and document the allocation of roles across the three lines, so that first-line ownership of controls, compliance monitoring, internal audit assurance, and board or committee oversight are clearly delineated and not conflated.
Integrate sanctions and designated-person screening into onboarding and ongoing monitoring, and keep processes for freezing assets and handling reporting obligations current with the applicable regimes and lists.
Test both the design and the operating effectiveness of CFT controls on a periodic basis, and record the distinction between the two in assurance findings.
Escalate matters that turn on jurisdiction-specific facts or legal interpretation to qualified legal, compliance, or audit professionals, recognizing that program design should reflect professional judgment and applicable advice.