FATF Plenary Meeting: What banks need to know now

Aug. 12, 2026

EU flag

The Financial Action Task Force (FATF) made several important decisions for banks and financial service providers at its recent plenary meeting. The focus was on new country risks, stricter requirements for cross-border payments, and the handling of digital financial flows.

New countries on the grey list

Bosnia and Herzegovina and Iraq have been newly added to the FATF list of jurisdictions under increased scrutiny. Algeria and Namibia, on the other hand, have been removed from the list.

For banks, this means that country lists, customer risk models, and monitoring rules should be updated promptly. Customers, beneficial owners, payment flows, and correspondent banking relationships with the affected countries are particularly relevant.

However, being listed does not automatically mean that business relationships have to be terminated. A documented, risk-based case-by-case review remains crucial.

More transparency in payment transactions

Another focus was the revision of FATF Recommendation 16. It concerns the transparency of originator and recipient data in cross-border payments.

Banks should therefore check whether payment information is complete, structured, and available throughout the entire payment chain. Missing or contradictory data must be identified and handled appropriately.

Digital risks are increasingly coming into focus.

The FATF is also focusing more intensively on virtual assets, decentralized financial systems (DeFi), self-hosted wallets, and the use of digital platforms for terrorist financing and fraud.

Even banks without their own crypto business should consider these risks. Relevant connections can arise through customers, payment service providers, trading platforms, or business partners.

What banks should do now

The following measures are derived directly from the current FATF decisions, the revised FATF recommendations (especially Recommendation 16), as well as from existing supervisory expectations of BaFin and European requirements (e.g. EBA guidelines).

Institutions should therefore pursue a clear, systematic approach:

 

Update country and risk lists:

The inclusion of Bosnia and Herzegovina and Iraq on the FATF Grey List necessitates a timely adjustment of internal risk classifications. This adjustment is based on the FATF Public Statements and the regularly published "Jurisdictions under Increased Monitoring."

 

Identify affected customers and business relationships:

Banks should systematically examine whether direct or indirect links exist to the countries concerned – for example, via customers, beneficial owners, payment flows, or correspondent banks. This requirement arises from the risk-based approach according to FATF Recommendation 1 and KYC requirements.

 

Transaction monitoring and scenario review:

Existing monitoring rules should be reviewed to ensure they adequately reflect increased risks from the newly listed countries. This includes, in particular, thresholds, scenarios for unusual payment structures, and the consideration of indirect country links.

 

Check payment details for completeness and quality:

As part of the revision of FATF Recommendation 16, the expectation for complete and consistent originator and recipient data is further specified. Banks should therefore ensure that their systems detect missing or incorrect information and handle it accordingly.

 

Consider crypto and platform risks:

The FATF is increasingly highlighting risks associated with virtual assets, DeFi structures, and digital platforms. Even without their own crypto business, banks should examine whether such risks arise through customer relationships or payment flows.

 

Ensure documentation and traceability:

All adjustments, from risk analysis to operational implementation, should be clearly documented. This complies with both FATF principles and BaFin's expectations for effective and auditable compliance management.

 

In its interpretive and application guidelines on the Money Laundering Act, BaFin also emphasizes the importance of a current, risk-based approach and clearly documented safeguards.

 

Conclusion

The FATF decisions show that money laundering prevention is increasingly linked to payment transactions, fraud prevention and technology risks.

Therefore, simply updating country lists is not enough for banks. KYC, transaction monitoring, sanctions checks, and fraud prevention must work together more effectively.

Sophie Karl

AMLR is coming. How well prepared are your KYC processes?

X