Answers to the questions practitioners most commonly ask about CFT.
Is countering the financing of terrorism (CFT) the same as anti-money laundering (AML)?
No, though the two are closely related and often addressed within a combined AML/CFT program. AML is generally concerned with detecting and preventing the laundering of proceeds derived from predicate crimes, meaning the funds typically originate from illicit activity. CFT is concerned with preventing funds from being used to support terrorism, and a key distinction is that the funds may originate from entirely legitimate sources, such as legal income or donations. This difference affects detection because CFT cannot rely solely on identifying illicit origins; it often depends on identifying suspicious destinations, connections, or patterns. Many jurisdictions and frameworks address the two together, but treating them as identical can create blind spots in a compliance program. The specific obligations that apply depend on the jurisdiction, sector, and entity type, and this entry is educational rather than legal or compliance advice.
Does CFT only concern large financial institutions?
Not necessarily. While banks and other financial institutions are often subject to detailed obligations in many jurisdictions, CFT-related requirements can extend to other entities depending on the applicable legal regime, such as money service businesses, certain designated non-financial businesses and professions, and, in some cases, non-profit organizations viewed as potentially vulnerable to abuse. The precise scope of who is covered, and to what degree, varies by jurisdiction, sector, and the nature of the activity. Whether a particular organization has CFT obligations, and what those obligations entail, is a fact-specific and jurisdiction-specific question that generally requires professional judgment and, where appropriate, legal advice.
Who within an organization is typically accountable for the CFT program, and how do the lines of defense apply?
Accountability generally follows the same structure used for broader compliance programs, though specific arrangements depend on the entity and jurisdiction. Under a three-lines model, the first line, business and operational units, typically owns the day-to-day activities, such as customer onboarding and transaction handling, and the controls embedded in those processes. The second line, which often includes a compliance function, typically designs the CFT framework, sets policy, provides oversight and monitoring, and reports on the program. Internal audit, as the third line, generally provides independent assurance over the design and operating effectiveness of the program. The board, or a designated committee, typically holds oversight responsibility rather than operational responsibility. Many regimes also expect a designated compliance officer role. Titles and precise duties vary, so entities should confirm the requirements applicable to them.
How does a risk-based approach apply to CFT?
Many CFT frameworks and regimes encourage or require a risk-based approach, meaning resources and controls are calibrated to the assessed level of risk rather than applied uniformly. In practice this generally begins with a risk assessment that considers factors such as customer types, products and services, delivery channels, and geographic exposure. Because CFT risk can involve funds from legitimate sources, the assessment often emphasizes connections, destinations, and behavioral patterns in addition to source-of-funds considerations. The output typically informs the intensity of due diligence, monitoring, and escalation. It is useful to distinguish inherent risk, before controls, from residual risk after controls are applied. The specific expectations for how a risk-based approach is documented and implemented vary by jurisdiction and sector, and the appropriate calibration is a matter of professional judgment.
What role do sanctions and watchlist screening play in a CFT program?
Screening against relevant designated-persons lists and sanctions regimes is commonly a component of CFT-related controls, because certain individuals and entities are designated in connection with terrorism or its financing. However, sanctions compliance and CFT are distinct though overlapping obligations, and the specific lists, legal bases, and prohibitions differ by jurisdiction. Screening supports the identification of prohibited relationships or transactions, but it is generally only one control among several, alongside customer due diligence, ongoing monitoring, and suspicious activity reporting. The design of screening, including matching thresholds, list coverage, and escalation, affects its effectiveness, and control design should be distinguished from operating effectiveness, which is assessed through testing. The precise applicable requirements are jurisdiction-specific and should be confirmed for the entity in question.
How should suspicious activity related to terrorist financing be handled once identified?
In many jurisdictions, where an entity forms a suspicion of terrorist financing, there are typically legal obligations to report to the relevant authority or financial intelligence unit, and in some regimes there may be restrictions on alerting the subject, often referred to as tipping-off prohibitions. The specific reporting channels, thresholds, timeframes, and prohibitions vary by jurisdiction and entity type. Internally, a CFT program generally establishes escalation procedures, defined decision-making responsibilities, documentation practices, and a clear interface with the designated compliance officer. Because the legal consequences of both reporting and failing to report can be significant, and because the requirements are fact- and jurisdiction-specific, entities should establish procedures based on the applicable regime and appropriate professional or legal advice. This entry is educational and does not constitute legal, audit, or compliance advice.