A plenary concludes in Paris on a Friday, and by Monday a compliance team somewhere has to work out what it means for four hundred existing customers, none of whom did anything different that week. Country risk is the only risk factor that changes for reasons completely unrelated to the customer relationship, which makes it easy to source yet awkward to put into practice. This guide outlines what high-risk countries and the FATF lists are, how the grey list and black list work, why a FATF listing is not a sanction, how country risk is scored from several indicators, and what a compliance team should actually do when a jurisdiction's status changes.
What Are High-Risk Countries and FATF Lists?
High-risk countries are jurisdictions whose anti-money laundering controls are weak enough that customers and transactions connected to them need extra scrutiny. The Financial Action Task Force (FATF) keeps two lists: high-risk jurisdictions subject to a call for action, usually called the black list, and jurisdictions under increased monitoring, usually called the grey list.
Both lists are updated at each plenary, so current membership belongs on a page that is kept up to date on that cycle rather than in a guide written once. Our AML country risk index shows who sits where today.
Two points will save a lot of confusion later. Neither list is a sanctions program, and neither ranks the world's riskiest countries. Instead, they highlight jurisdictions whose AML regimes have been evaluated and found deficient, which is a narrower claim than it first sounds.
The FATF Grey List and Black List
The call-for-action list is the more serious of the two. FATF asks its members to apply enhanced due diligence to relationships involving those jurisdictions and, in the most serious cases, to apply countermeasures, which may include restricting business relationships and financial transactions. The list has stayed very small throughout its existence and its membership has not changed since October 2022, which makes it the stable part of the picture.
The list of jurisdictions under increased monitoring is always changing. A jurisdiction joins when a mutual evaluation reveals strategic deficiencies and its government makes a high-level political commitment to an action plan with agreed timeframes. It leaves once it has completed that plan and passed an on-site visit confirming that the reforms are actually working. The turnover is real: the June 2026 plenary added two jurisdictions and removed two, and the February 2026 plenary before it added two more.
Time on the list varies greatly. Some jurisdictions exit within two years, while others stay for five or more, usually because the problems are about capacity rather than legislative gaps. Passing new laws is quick. Showing that prosecutors bring complex laundering cases, that supervisors act on findings, and that beneficial ownership data is accurate is not, and the current evaluation round puts heavy weight on that effectiveness test.
Listings are based on mutual evaluation reports, peer reviews that examine both whether a country's laws meet the FATF Recommendations and whether they work in practice. FATF carries out some of these reviews itself, while FATF-style regional bodies conduct the rest within their own memberships. Plenaries meet three times a year, in February, June, and October, and list decisions are published at the end of each one.
The effects reach beyond compliance departments. A 2021 IMF working paper found that capital inflows fall by an average of 7.6 percent of GDP after grey listing, mainly because financial institutions reduce their exposure or leave altogether. That outcome is not universal, though. Croatia's economy and financial sector came through its 2023 to 2025 listing largely intact, and its sovereign credit ratings were upgraded during that period, which suggests the worst effects fall on smaller economies that rely on foreign investment.
High-Risk Countries vs Sanctioned Countries
Confusing the two is the most common mistake in country risk programs, and it happens in both directions.
A FATF listing is not a legal restriction. It does not ban business with a jurisdiction, freeze assets, or create liability for transacting. It triggers enhanced due diligence and, for call-for-action jurisdictions, possible countermeasures applied through national law. Sanctions, on the other hand, are legal measures issued by governments and international bodies. They carry civil and criminal penalties, and they prohibit rather than scrutinize.
The two groups overlap without matching. Some grey-listed jurisdictions have no country-level sanctions program attached, and heavily sanctioned countries can be missing from the FATF lists entirely, because listing depends on having been evaluated and on the government agreeing to an action plan. A state that refuses to cooperate is not listed; it simply never enters the process.
The practical result is that a country risk model needs both inputs and has to treat them differently. FATF status adjusts a risk score, while a sanctions designation is a hard control that stops a transaction regardless of the score. Combine them into one high-risk flag and two mistakes happen at once: transactions get blocked where only enhanced scrutiny was needed, and sanctions exposure gets scored instead of stopped.
Terminology adds to the confusion. Calling the call-for-action list a black list suggests prohibition, which it is not, and the informal names were in use long before the distinction mattered operationally. Country-level programs belong in your sanctions and watchlists data, and sanctions screening sits alongside country risk rather than inside it.
How Country Risk Is Scored
A country risk score draws on several separate sources, because no single one covers everything. FATF listing status is binary, authoritative, and updated three times a year. The Basel AML Index is an independent composite score published annually by the Basel Institute on Governance, now in its fourteenth public edition, and it takes in AML framework quality, corruption and fraud, financial transparency, public accountability, and political and legal risk. Corruption indices, with Transparency International's Corruption Perceptions Index as the standard reference, measure perceived public sector corruption rather than money laundering directly. Sanctions exposure covers whether the jurisdiction hosts sanctions programs, designated entities, or known evasion routes. Predicate crime prevalence includes drug production and trafficking, conflict, terrorism financing, and the presence of organized crime. Tax and ownership transparency reflects registry quality, the availability of beneficial ownership data, and secrecy jurisdiction status.
Four design problems keep coming up. Inputs are highly correlated, so a model that counts corruption through both the Basel Index and the Corruption Perceptions Index ends up giving the same signal double weight without meaning to. Update frequencies differ, so the score mixes data refreshed last week with data refreshed eighteen months ago. Banding matters more than weighting, because the line between medium and high decides what actually happens to a customer. And overrides need governance: a score no one can adjust gets ignored, and a score anyone can adjust means nothing.
Not being on the grey list does not mean a country is low risk. The grey list covers jurisdictions actively working with FATF on identified deficiencies, which is a different group from the jurisdictions with the weakest controls. A country can stay off it by never being evaluated, by refusing to engage, or because its deficiencies were never judged strategic. Models that treat unlisted as safe inherit that gap without noticing. A composite approach to risk scoring closes it.
Turning a List Change Into Action
A plenary outcome is not useful information until it has turned into a set of updated customer files. It takes six steps to get there.
The first step is to establish exposure. Country risk can attach through many routes besides nationality: residence, place of incorporation, the registered address of beneficial owners, transaction corridors, counterparty banks, and trade routes. A customer with no connection to a jurisdiction on paper may still route most of its payments through it.
The second step is to re-score the country. Update the country rating and let it flow through, rather than adjusting affected customers by hand.
The third step is to recalculate customer ratings and find out which customers cross into a higher risk band as a result. This group is usually much smaller than the exposure population, and it is the one you can act on.
The fourth step is to apply enhanced due diligence where the band changed: source of funds and wealth, an ownership refresh, the purpose of the relationship, and senior approval to continue, scaled to how far the rating moved.
The fifth step is to review structural exposure. Correspondent relationships, trade finance lines, and payment corridors involving the jurisdiction should be reviewed at portfolio level, not customer by customer.
The sixth step is to document and report. Record each decision, including decisions not to act, and report the change in exposure through governance.
Thirty days after the plenary is the working target most programs aim for. The real risk is not slowness but reflexive de-risking. Exiting every customer linked to a newly listed jurisdiction is quick and easy to justify on paper, but it pushes legitimate flows into less transparent channels and removes the institution's own visibility. FATF has consistently criticized the practice.
Delistings need the same process in reverse, and they rarely get it. A jurisdiction leaving the grey list should trigger a re-score and a review of customers held at elevated ratings, yet enhanced measures put in place during a listing often stay for years because nothing forces a second look. Controls that only ever ratchet upward end up reflecting history rather than current risk.
In practice, the new country rating flows through customer risk assessment, and the structural exposure that causes the most trouble usually sits in correspondent banking. If you want to see how this works in a live program, you can request a demo.
Other Country-Risk Indicators
FATF status is just one input among several, and the others fill the gaps it leaves.
Instead of a binary flag, the Basel AML Index gives a continuous score, which helps tell apart jurisdictions that share the same FATF status. Corruption rankings capture governance weaknesses that come before AML failure and often predict it. Major money laundering countries, as identified in annual government assessments, reflect observed laundering volume rather than framework quality, which is a different question and sometimes has a different answer.
Two less obvious indicators are worth including. Travel Rule adoption by jurisdiction shows where virtual asset transfers still move without originator and beneficiary information, which leaves a clear traceability gap for crypto businesses. The lowest-risk jurisdictions matter as a calibration reference: if a model cannot tell the top of the range from the middle, it is not scoring anything useful at the bottom.
EU and Other High-Risk Third-Country Lists
The European Union keeps its own list of high-risk third countries, which the Commission adopts as delegated regulations and which carries mandatory enhanced due diligence obligations under EU law. It follows FATF decisions closely and is updated after plenaries, but it is not a copy.
The clearest example came on 29 January 2026, when a delegated regulation adding the Russian Federation to the EU list entered into force. Russia is not on either FATF list, and the United Kingdom, whose post-Brexit regime treats the FATF lists themselves as its high-risk third country list, has not listed it either. So a multinational firm has three different correct answers to the same question depending on which entity is asking, and only the EU answer carries EDD obligations.
That divergence is the general lesson, not an exception. A firm operating across the EU, the UK, and a third jurisdiction needs a country risk model that holds multiple list memberships per country rather than a single high-risk flag, and that knows which obligation attaches to which listing. A model with one field for country risk cannot show a jurisdiction that is EDD-mandatory in Frankfurt and unremarkable in London.
Timing adds a second complication. The EU list follows FATF decisions but arrives months later, since each update runs through a delegated regulation subject to parliamentary scrutiny before entry into force. A jurisdiction can leave the FATF grey list and remain on the EU list for a further reporting cycle.
Sources
- FATF, Outcomes of the FATF Plenary, 17-19 June 2026
- FATF, Jurisdictions under Increased Monitoring, 19 June 2026
- FATF, Jurisdictions under Increased Monitoring, 13 February 2026
- FATF, High-Risk Jurisdictions subject to a Call for Action, 19 June 2026
- FATF, Croatia country page
- IMF Working Paper WP/21/153, The Impact of Gray-Listing on Capital Flows (Kida and Paetzold, 2021)
- Basel Institute on Governance, Basel AML Index 2025 (14th Public Edition)
- Commission Delegated Regulation (EU) 2026/46 (EU high-risk third countries), EUR-Lex
- Willkie Compliance Concourse, EU Deems Russia a High-Risk Third Country for AML Purposes
- S&P Global Ratings, Croatia Upgraded To 'A/A-1' From 'A-/A-2'