Skip to main content
Category: Regulatory Management

FATF 40 Recommendations

Also known as: The FATF Recommendations, The 40 Recommendations
Simply put

The FATF 40 Recommendations are an internationally recognized set of standards developed by the Financial Action Task Force (FATF) to help countries combat money laundering, terrorist financing, and the financing of weapons proliferation. They set out measures that governments are generally expected to put in place, such as criminal justice, law enforcement, and financial-sector safeguards. They are a global standard rather than a binding law in themselves; individual countries implement them through their own national legislation and rules, and how fully each country does so varies.

Formal definition

The FATF 40 Recommendations are the FATF's comprehensive framework of standards intended to serve as the basis on which countries should meet the shared objective of countering money laundering (ML), terrorist financing (TF), and the financing of proliferation of weapons of mass destruction. As originally articulated, they provide a complete set of counter-measures spanning the criminal justice system and law enforcement, the financial sector, and related preventive and institutional measures. The Recommendations constitute a non-binding international standard, not directly enforceable law, which member and assessed jurisdictions transpose into domestic statutes, regulations, and supervisory regimes; jurisdiction-specific implementation is subject to periodic FATF mutual evaluation. Under that assessment methodology, each of the 40 Recommendations is rated for technical compliance on a scale that typically includes compliant, largely compliant, partially compliant, and non-compliant. For example, per the FATF's assessment as of March 2024, the United States was rated compliant on 9 Recommendations, largely compliant on 23, partially compliant on 5, and non-compliant on 3 (the fourth-tier rating), illustrating that even a single jurisdiction's status is spread across multiple compliance levels. This entry summarizes the framework's stated scope and does not reproduce the individual Recommendations or country-specific legal requirements; it is educational and not legal, audit, or compliance advice.

Why it matters

For countries and the financial institutions operating within them, the FATF 40 Recommendations function as the reference point against which anti-money laundering, counter-terrorist-financing, and counter-proliferation-financing regimes are measured. Because they are a global standard rather than binding law, their practical force comes from the way jurisdictions transpose them into domestic legislation and from the periodic FATF mutual evaluations that assess how fully each country has done so. A jurisdiction's assessed compliance can affect its international standing and the risk calculus that cross-border counterparties apply to institutions based there, which is why boards and compliance leaders track both the Recommendations and their own country's implementation status.

The Recommendations matter precisely because compliance is rarely uniform. Under the FATF assessment methodology, each of the 40 Recommendations is rated on a scale that typically runs from compliant through largely compliant and partially compliant to non-compliant. As of the FATF's March 2024 assessment, for example, the United States was rated compliant on 9 Recommendations, largely compliant on 23, partially compliant on 5, and non-compliant on 3. That spread across multiple compliance levels within a single jurisdiction illustrates why it is misleading to treat any country as simply "compliant" or not; governance and compliance functions need to understand where gaps sit and how they may translate into domestic legal or supervisory expectations.

Because the Recommendations span the criminal justice system, law enforcement, and the financial sector, they touch functions well beyond a compliance department, but the accountability for implementation ultimately rests with national governments through their own laws and supervisory regimes. This entry is educational and summarizes the framework's stated scope; it does not reproduce the individual Recommendations or any country's specific legal requirements, and it is not legal, audit, or compliance advice.

Who it's relevant to

Chief compliance officers and financial-crime teams
Compliance leaders in regulated institutions use the FATF 40 Recommendations as the underlying reference for the anti-money laundering, counter-terrorist-financing, and counter-proliferation-financing standards that shape their domestic obligations. Because the Recommendations themselves are not directly enforceable, the operative requirements come from the national legislation and supervisory rules that transpose them, and the applicable rules depend on the jurisdiction and sector in which the institution operates.
Boards and audit or risk committees
Boards and their committees exercise oversight of whether management has established a financial-crime control environment consistent with applicable law. Understanding a home jurisdiction's FATF mutual-evaluation status, including where it is rated less than compliant, can inform board-level questions about residual exposure, without the board assuming management's operational responsibility for the underlying controls.
General counsel and legal advisers
Legal teams translate the way a country implements the FATF standard into concrete obligations for the organization. Because the Recommendations are a global standard rather than binding law in themselves, counsel typically focus on the domestic statutes, regulations, and listing or licensing requirements that give them effect in the relevant jurisdiction.
Internal auditors and assurance functions
Assurance functions may assess whether financial-crime controls are designed and operating in line with applicable domestic requirements derived from the FATF standard. The compliant, largely compliant, partially compliant, and non-compliant ratings used in FATF mutual evaluations can offer useful context for scoping, though audit conclusions rest on the entity's own legal obligations rather than on the Recommendations directly.
Policy and government-affairs professionals
Because national governments own the implementation of the Recommendations through their own laws and supervisory regimes, professionals tracking regulatory change monitor mutual-evaluation outcomes and follow-up assessments to anticipate how a jurisdiction may strengthen its framework in areas rated partially or non-compliant.

Inside FATF 40 Recommendations

Scope: ML, TF, and PF
The FATF 40 Recommendations set out an internationally recognised framework of standards to combat money laundering (ML), terrorist financing (TF), and, since revisions in the 2012-present period, the financing of proliferation of weapons of mass destruction (PF). Practitioners should treat all three as core scopes rather than a money-laundering standard alone. The Recommendations are non-binding standards issued by FATF, not directly binding law; they take legal effect only as jurisdictions implement them through domestic statutes and regulations, which vary by country.
Risk-based approach
A foundational principle running through the Recommendations is that countries and obliged entities should identify, assess, and understand their ML/TF/PF risks and apply measures commensurate with those risks. This allows resources to be directed toward higher-risk areas and permits simplified measures where risk is lower, subject to the standard as implemented in each jurisdiction.
Preventive measures for the private sector
The Recommendations address customer due diligence, record-keeping, enhanced measures for higher-risk customers and activities, reliance on third parties, and reporting of suspicious transactions. These obligations typically fall on financial institutions and designated non-financial businesses and professions once transposed into national law, rather than being self-executing.
Institutional framework and competent authorities
The Recommendations describe expectations for national institutions, including financial intelligence units, supervisors, law enforcement, and mechanisms for international cooperation and information sharing. They allocate roles across public authorities rather than to any single body.
Transparency of legal persons and arrangements
Several Recommendations address beneficial ownership transparency for companies, trusts, and similar arrangements, aiming to prevent their misuse for ML, TF, or PF.
Assessment and ratings methodology
FATF assesses jurisdictions against the 40 Recommendations for technical compliance using a four-level scale, generally described as Compliant (C), Largely Compliant (LC), Partially Compliant (PC), and Non-Compliant (NC). Ratings are recorded across all 40 Recommendations, so a complete picture must reflect every category. In the U.S. March 2024 Follow-Up Report, the ratings referenced in the prior context include 9 Compliant, 23 Largely Compliant, 5 Partially Compliant, and 3 Non-Compliant Recommendations.

Common questions

Answers to the questions practitioners most commonly ask about FATF 40 Recommendations.

Do the FATF 40 Recommendations only address money laundering?
No. Although often associated primarily with anti-money laundering (AML), the FATF 40 Recommendations, as revised in 2012 and maintained since, set out standards spanning three interconnected scopes: combating money laundering, countering the financing of terrorism (CFT), and countering the financing of the proliferation of weapons of mass destruction (CPF). Treating the Recommendations as an AML-only instrument understates their scope and can leave terrorist-financing and proliferation-financing obligations underweighted in a country's or institution's control framework. This is an educational overview, not legal or compliance advice; how each scope applies depends on the relevant national implementing law.
Are the FATF 40 Recommendations legally binding on countries or financial institutions?
Not directly. The FATF Recommendations are non-binding international standards rather than a treaty or statute. They generally take legal effect only when a jurisdiction transposes them into national law, regulation, or supervisory requirements, and the precise obligations that result vary by jurisdiction, sector, and entity type. FATF assesses countries' compliance through mutual evaluations and follow-up processes, and non-compliance can carry reputational and practical consequences (including listing processes), but the binding requirements that regulated firms must actually meet are those set out in applicable local law, not the Recommendations themselves. This entry is educational and not legal advice.
How does a country's FATF assessment translate into ratings, and what do those ratings mean?
FATF and its regional bodies assess a country in two dimensions: technical compliance (whether laws and regulations meet each Recommendation) and effectiveness (whether the system produces intended outcomes). For technical compliance, each of the 40 Recommendations is generally rated on a four-level scale, typically expressed as Compliant, Largely Compliant, Partially Compliant, and Non-Compliant. When reviewing a country's rating profile, all four categories should be read together; citing only some categories (for example, omitting the Non-Compliant count) can give a misleading picture of remaining gaps. Ratings are periodically updated through follow-up reports as countries address deficiencies, so any figures should be checked against the most current published assessment.
How should a financial institution use the FATF Recommendations in practice, given they apply at the country level?
The Recommendations are addressed primarily to countries, not directly to firms, so institutions generally implement them through the national laws and supervisory expectations that transpose them. In practice, firms typically use the Recommendations and their interpretive notes as a reference to understand the policy intent behind local requirements, to inform a risk-based approach across money-laundering, terrorist-financing, and proliferation-financing risks, and to benchmark controls where they operate across multiple jurisdictions. Because binding obligations flow from local law, institutions should map their programs to the applicable domestic regime rather than to the Recommendations alone. Whether a specific control is required depends on the facts, the jurisdiction, and professional judgment.
Who within an organization is accountable for aligning the compliance program with FATF-derived requirements?
Accountability is generally distributed across the lines of defense. Management, typically led by a compliance function (often a chief compliance or money-laundering reporting officer), usually owns the design and day-to-day operation of AML/CFT/CPF controls that implement applicable local requirements. Internal audit or an equivalent assurance function typically provides independent evaluation of whether those controls are well designed and operating effectively. The board or a designated committee generally holds oversight responsibility, setting tone, approving the risk-based framework and risk appetite, and challenging management, rather than performing operational compliance tasks itself. The precise allocation depends on the entity's size, sector, jurisdiction, and governance structure.
How do the FATF Recommendations relate to the risk-based approach a firm is expected to take?
The Recommendations generally endorse a risk-based approach, under which countries and regulated entities are expected to identify, assess, and understand their money-laundering, terrorist-financing, and proliferation-financing risks and to apply mitigating measures commensurate with those risks. In practice this means allocating more intensive controls (such as enhanced due diligence) to higher-risk relationships and products, and lighter measures where risk is lower, within the bounds permitted by applicable law. The approach requires distinguishing the inherent risk of a customer, product, or geography from the residual risk remaining after controls, and calibrating measures to the firm's defined risk appetite. How risk is assessed and what mitigation is adequate remain matters of documented professional judgment shaped by local requirements; this entry is educational only.

Common misconceptions

The FATF 40 Recommendations only address money laundering.
In their 2012-present form the Recommendations cover money laundering, terrorist financing, and proliferation financing. Treating them as a money-laundering-only standard understates their scope and can leave TF and PF obligations unaddressed.
The FATF 40 Recommendations are binding law that entities must follow directly.
The Recommendations are internationally recognised standards issued by FATF; they are not themselves binding law. They generally become enforceable on entities only through domestic statutes, regulations, or supervisory rules, and the specific obligations vary by jurisdiction, sector, and entity type.
A country rated as compliant on most Recommendations has no gaps.
FATF uses a graded scale (typically C, LC, PC, and NC), and a jurisdiction can hold ratings across all four categories at once. Focusing only on the higher ratings, for example citing Compliant, Largely Compliant, and Partially Compliant counts while omitting Non-Compliant ones, gives a misleading picture. The U.S. March 2024 Follow-Up Report ratings referenced here include Non-Compliant Recommendations alongside the others.

Best practices

Design AML/CFT/CPF programs to address money laundering, terrorist financing, and proliferation financing together, rather than treating the FATF standard as money-laundering-only.
Anchor the program in a documented, risk-based approach: identify and assess ML/TF/PF risks and calibrate customer due diligence, monitoring, and controls to those risk levels.
Map obligations to the specific domestic laws and supervisory rules that transpose the Recommendations in each relevant jurisdiction, since FATF standards are not directly binding and requirements vary by country, sector, and entity type.
When relying on FATF assessment results, review ratings across all four categories, including Non-Compliant and Partially Compliant, to avoid an incomplete or overly favourable view of a jurisdiction's compliance.
Assign clear accountability across the three lines: management owns and operates preventive controls, assurance functions test them, and the board or its relevant committee provides oversight rather than day-to-day execution.
Treat this entry as educational context on the framework's structure and scope, not as legal, audit, or compliance advice; confirm current requirements and ratings against primary FATF and national sources before acting.