Skip to main content
Category: Regulatory Management

Jurisdictions Under Increased Monitoring

Also known as: Grey List, FATF Grey List
Simply put

Jurisdictions under increased monitoring, commonly called the FATF 'grey list', are countries that the Financial Action Task Force (FATF) has identified as having weaknesses in their systems for stopping money laundering, terrorist financing, and proliferation financing. Unlike higher-risk 'black list' countries, these jurisdictions have committed to working with the FATF to fix the identified problems within agreed timeframes. Being placed on this list signals that a country needs closer attention, which can affect how financial institutions and other businesses handle dealings connected to it.

Formal definition

Jurisdictions under increased monitoring is the formal FATF designation for countries that are actively working with the FATF to address identified strategic deficiencies in their regimes to counter money laundering, terrorist financing, and proliferation financing (AML/CFT/CPF) under agreed action plans and timeframes. This 'grey list' is distinct from the FATF's separate list of high-risk jurisdictions subject to a call for action (the 'black list'), reflecting a country's cooperative posture rather than the more severe measures FATF may call for against black-listed jurisdictions. The list is not static: FATF periodically updates it through published statements, adding and removing jurisdictions as circumstances change. FATF itself is a standard-setting body issuing recommendations rather than directly binding law; the practical compliance obligations arising from a jurisdiction's grey-list status depend on how individual national AML/CFT regimes and supervisors implement FATF standards, which typically informs risk-based enhanced due diligence and country-risk assessments by regulated entities. This entry is educational and not legal, audit, or compliance advice; the current composition of the list and applicable obligations depend on the FATF statement in force and the relevant jurisdiction's implementing framework.

Why it matters

For regulated entities, a jurisdiction's placement on the FATF grey list is a significant input into country-risk assessment. It signals that the FATF has identified strategic deficiencies in that country's regime to counter money laundering, terrorist financing, and proliferation financing, even though the country has committed to remediating them within agreed timeframes. Because the list is not static and FATF updates it periodically through published statements, compliance functions must monitor changes rather than treating any snapshot as permanent. For example, the FATF statement published on 19 June 2026 reflected a list of jurisdictions that included additions such as Bosnia and Herzegovina and Iraq, illustrating how the composition shifts over time.

The practical consequences of grey-list status depend on how national AML/CFT regimes and supervisors implement FATF standards. FATF is a standard-setting body that issues recommendations rather than directly binding law, so the obligations that flow from a jurisdiction's status are shaped by the relevant implementing framework in each country. In many jurisdictions, grey-list status typically informs the application of a risk-based approach, including enhanced due diligence and closer scrutiny of dealings connected to the identified country.

Getting this distinction right matters because the grey list is separate from the FATF's list of high-risk jurisdictions subject to a call for action (the so-called black list). Grey-list status reflects a cooperative posture and a commitment to work with the FATF, whereas black-listed jurisdictions may be subject to more severe measures that FATF calls for. Conflating the two can lead to over- or under-calibrated controls, so compliance and risk officers should confirm which designation applies before setting the response.

Who it's relevant to

Chief Compliance Officers and AML/CFT Teams
Compliance functions in regulated entities typically use grey-list status as an input into country-risk assessments and risk-based due diligence. Because the list changes as FATF publishes updated statements, these teams generally need processes to track additions and removals and to translate them into their institution's controls, consistent with the obligations set by their national regime and supervisor.
General Counsel and Legal Advisers
Legal advisers help interpret how FATF designations map onto binding obligations under the applicable national AML/CFT framework. Because FATF issues recommendations rather than directly binding law, counsel are often relied on to distinguish what is legally required in a given jurisdiction from what is a matter of risk-based judgment.
Risk Officers and Country-Risk Assessors
Those responsible for country risk generally incorporate grey-list status alongside other indicators when assessing exposure to jurisdictions with identified AML/CFT/CPF deficiencies. They should keep the grey list distinct from the FATF's separate list of high-risk jurisdictions subject to a call for action, as the two carry different implications.
Boards and Audit Committees
Boards and their committees exercise oversight of the entity's financial crime risk framework rather than performing the operational monitoring themselves. Awareness of how management responds to changes in FATF designations helps directors assess whether the compliance program is being maintained on a risk-sensitive basis, while accountability for day-to-day implementation sits with management and assurance functions.

Inside Jurisdictions Under Increased Monitoring

FATF Grey List Designation
"Jurisdictions Under Increased Monitoring" is the formal term used by the Financial Action Task Force (FATF) for what is commonly called the "grey list." It identifies countries that have strategic deficiencies in their frameworks to counter money laundering, terrorist financing, and proliferation financing (PF), but that have made a high-level political commitment to address those deficiencies within agreed timeframes.
Scope Across AML, CFT and PF
The deficiencies FATF flags typically span anti-money laundering (AML), countering the financing of terrorism (CFT), and countering proliferation financing (PF). Practitioners should not treat the designation as an AML-only signal, as FATF's mandate and mutual evaluation criteria encompass all three areas.
Action Plan and Ongoing Monitoring
Listed jurisdictions work with FATF (or a FATF-style regional body) under an agreed action plan and are subject to increased monitoring of their progress. This distinguishes the grey list from the separate, more severe "high-risk jurisdictions subject to a call for action" (commonly called the "black list").
Relationship to Risk Assessment, Not Automatic Prohibition
Increased monitoring status is generally a risk factor to be considered within a firm's risk-based approach rather than an automatic bar to doing business. FATF typically does not call for the application of enhanced due diligence solely on the basis of grey-list status, though many national regulators and firms treat it as a relevant geographic risk indicator.
Periodic Updates
The list is reviewed and updated periodically at FATF plenary meetings, with jurisdictions added or removed as their deficiencies are identified or remediated. The composition therefore changes over time, and the current list should always be verified against FATF's published statements.

Common questions

Answers to the questions practitioners most commonly ask about Jurisdictions Under Increased Monitoring.

Does a jurisdiction appearing on the list of those under increased monitoring mean firms should stop doing business there or apply the harshest countermeasures?
Generally, no. Being under increased monitoring is typically distinct from being subject to a call for enhanced due diligence or countermeasures. Jurisdictions under increased monitoring are commonly understood to have committed to work with FATF to address identified strategic deficiencies in their anti-money laundering (AML), countering the financing of terrorism (CFT), and counter-proliferation financing (PF) regimes within agreed timeframes. This status does not, in itself, typically require firms to cease business or automatically apply enhanced due diligence; that expectation is more often associated with the separate, higher-risk category. However, whether and how a firm adjusts its risk-based approach depends on its own risk assessment, applicable law in its jurisdiction, and the expectations of its supervisor. This entry is educational and not legal or compliance advice.
Is the FATF list of jurisdictions under increased monitoring a binding legal instrument that automatically changes a firm's obligations?
Generally, no. FATF is an intergovernmental standard-setting body, and its designations are not themselves binding law in the way a statute or regulation is. The practical effect typically arises when individual jurisdictions, supervisors, or regional bodies incorporate FATF's assessments into their own legal or supervisory frameworks, or when firms factor them into a risk-based approach. As a result, the obligations that follow from a jurisdiction's status vary by jurisdiction, sector, and entity type. Firms should confirm how their own regulator treats these designations rather than assuming a uniform legal consequence. This entry does not constitute legal advice.
How should a compliance function typically incorporate this status into a customer or country risk assessment?
In many risk-based frameworks, a jurisdiction's presence on the increased monitoring list is treated as one risk-relevant factor among several, rather than a single determinative trigger. Compliance functions typically weigh it alongside customer type, product, channel, transaction patterns, and other geographic factors when assigning a risk rating. The appropriate weighting is a matter of the firm's methodology and professional judgment, and it should align with the firm's documented risk appetite and any supervisory expectations. Firms generally document the rationale so that decisions are auditable. What is out of scope here is any specific rating a firm should assign; that depends on the firm's own facts and methodology.
Who within an organization typically owns the response to changes in this list?
Ownership generally sits with the compliance function under the second line of defense, which typically maintains the AML/CFT/PF program, updates country risk ratings, and monitors FATF publications. The first line, business and operational units, typically applies the resulting controls in onboarding and transaction monitoring. Internal audit, as an assurance function, typically evaluates whether the process operates effectively but does not own it. The board or a designated committee generally holds oversight responsibility for the adequacy of the overall program, without performing the operational updates itself. These allocations vary by entity type and governance structure and should be confirmed against the firm's own policies.
How frequently should firms typically review the list, and how is that reflected in procedures?
FATF generally updates its public statements on a periodic cycle following its plenary meetings, so many firms build a corresponding review step into their procedures to check for additions, removals, and changes in status. The appropriate review frequency for a given firm depends on its risk profile, the volume and geographic spread of its business, and supervisory expectations. Procedures typically specify who monitors the source, how changes are escalated, and how updated country risk ratings flow through to affected customers and transactions. This entry does not state a required frequency, as that depends on the firm's risk-based approach and applicable regulatory expectations.
What controls are typically expected when a firm has exposure to a jurisdiction under increased monitoring?
Because the status does not, in itself, mandate a fixed set of measures, firms generally calibrate controls through their risk-based approach. Depending on the firm's assessment, this may involve reviewing existing customer relationships connected to the jurisdiction, considering additional information-gathering, adjusting transaction monitoring parameters, and documenting the rationale for the chosen response. Firms typically distinguish between control design (whether the measures are appropriately configured) and operating effectiveness (whether they function as intended in practice), and assurance functions may test both. The specific controls that are appropriate depend on the firm's facts, jurisdiction, and professional judgment, and this entry does not prescribe them or constitute compliance advice.

Common misconceptions

Being on the list of jurisdictions under increased monitoring is the same as being on the FATF "black list."
These are two distinct FATF categories. "Jurisdictions Under Increased Monitoring" (grey list) covers countries actively cooperating with FATF under an action plan to fix deficiencies, whereas "High-Risk Jurisdictions Subject to a Call for Action" (black list) is a more severe category where FATF calls for countermeasures or enhanced due diligence.
The designation concerns money laundering only.
FATF describes these deficiencies as spanning AML, terrorist financing (CFT), and proliferation financing (PF). Treating the status as an AML-only signal understates its scope and can leave gaps in a firm's sanctions and proliferation-financing controls.
Grey-list status automatically requires firms to apply enhanced due diligence or to cease business with the jurisdiction.
FATF generally does not mandate enhanced due diligence based solely on grey-list status, and the designation is typically a risk factor within a risk-based approach rather than a prohibition. However, specific obligations depend on the applicable national law and regulator expectations, which vary by jurisdiction.

Best practices

Verify the current composition of the list directly against FATF's most recent published plenary statement, since jurisdictions are added and removed periodically and prior lists become outdated.
Incorporate increased-monitoring status as one geographic risk factor within a documented risk-based approach, rather than applying it as a mechanical rule or automatic prohibition.
Confirm the specific obligations imposed by your own national regulator and applicable law, as requirements relating to listed jurisdictions vary by jurisdiction, sector, and entity type.
Ensure controls address all three dimensions FATF covers, money laundering, terrorist financing, and proliferation financing, rather than treating the designation as an AML-only concern.
Distinguish clearly between "jurisdictions under increased monitoring" (grey list) and "high-risk jurisdictions subject to a call for action" (black list) in policies, screening logic, and staff training, because the expected responses differ.
Treat this entry as educational rather than legal, audit, or compliance advice, and seek qualified professional judgment where a specific jurisdiction, relationship, or transaction raises material risk.