Introducing Complead. One AI-native platform for financial crime compliance. Read the story
New Ready Integrations available Check the new integrations
Meet Complead at Money20/20 USA, Las Vegas 18-21 October 2026 Meet with us

High-Risk Countries and FATF Lists: The Complete Guide (2026)

In short

High-risk countries are jurisdictions whose AML controls are weak enough to warrant extra scrutiny. This guide explains the FATF grey list and black list, why a listing is not a sanction, how country risk is scored from FATF status, the Basel AML Index and other indicators, and how to turn a plenary decision into re-scoring and enhanced due diligence.

A plenary concludes in Paris on a Friday, and by Monday a compliance team somewhere has to work out what it means for four hundred existing customers, none of whom did anything different that week. Country risk is the only risk factor that changes for reasons completely unrelated to the customer relationship, which makes it easy to source yet awkward to put into practice. This guide outlines what high-risk countries and the FATF lists are, how the grey list and black list work, why a FATF listing is not a sanction, how country risk is scored from several indicators, and what a compliance team should actually do when a jurisdiction's status changes.

What Are High-Risk Countries and FATF Lists?

High-risk countries are jurisdictions whose anti-money laundering controls are weak enough that customers and transactions connected to them need extra scrutiny. The Financial Action Task Force (FATF) keeps two lists: high-risk jurisdictions subject to a call for action, usually called the black list, and jurisdictions under increased monitoring, usually called the grey list.

Both lists are updated at each plenary, so current membership belongs on a page that is kept up to date on that cycle rather than in a guide written once. Our AML country risk index shows who sits where today.

Two points will save a lot of confusion later. Neither list is a sanctions program, and neither ranks the world's riskiest countries. Instead, they highlight jurisdictions whose AML regimes have been evaluated and found deficient, which is a narrower claim than it first sounds.

The FATF Grey List and Black List

The call-for-action list is the more serious of the two. FATF asks its members to apply enhanced due diligence to relationships involving those jurisdictions and, in the most serious cases, to apply countermeasures, which may include restricting business relationships and financial transactions. The list has stayed very small throughout its existence and its membership has not changed since October 2022, which makes it the stable part of the picture.

The list of jurisdictions under increased monitoring is always changing. A jurisdiction joins when a mutual evaluation reveals strategic deficiencies and its government makes a high-level political commitment to an action plan with agreed timeframes. It leaves once it has completed that plan and passed an on-site visit confirming that the reforms are actually working. The turnover is real: the June 2026 plenary added two jurisdictions and removed two, and the February 2026 plenary before it added two more.

Time on the list varies greatly. Some jurisdictions exit within two years, while others stay for five or more, usually because the problems are about capacity rather than legislative gaps. Passing new laws is quick. Showing that prosecutors bring complex laundering cases, that supervisors act on findings, and that beneficial ownership data is accurate is not, and the current evaluation round puts heavy weight on that effectiveness test.

Listings are based on mutual evaluation reports, peer reviews that examine both whether a country's laws meet the FATF Recommendations and whether they work in practice. FATF carries out some of these reviews itself, while FATF-style regional bodies conduct the rest within their own memberships. Plenaries meet three times a year, in February, June, and October, and list decisions are published at the end of each one.

The effects reach beyond compliance departments. A 2021 IMF working paper found that capital inflows fall by an average of 7.6 percent of GDP after grey listing, mainly because financial institutions reduce their exposure or leave altogether. That outcome is not universal, though. Croatia's economy and financial sector came through its 2023 to 2025 listing largely intact, and its sovereign credit ratings were upgraded during that period, which suggests the worst effects fall on smaller economies that rely on foreign investment.

High-Risk Countries vs Sanctioned Countries

Confusing the two is the most common mistake in country risk programs, and it happens in both directions.

A FATF listing is not a legal restriction. It does not ban business with a jurisdiction, freeze assets, or create liability for transacting. It triggers enhanced due diligence and, for call-for-action jurisdictions, possible countermeasures applied through national law. Sanctions, on the other hand, are legal measures issued by governments and international bodies. They carry civil and criminal penalties, and they prohibit rather than scrutinize.

The two groups overlap without matching. Some grey-listed jurisdictions have no country-level sanctions program attached, and heavily sanctioned countries can be missing from the FATF lists entirely, because listing depends on having been evaluated and on the government agreeing to an action plan. A state that refuses to cooperate is not listed; it simply never enters the process.

The practical result is that a country risk model needs both inputs and has to treat them differently. FATF status adjusts a risk score, while a sanctions designation is a hard control that stops a transaction regardless of the score. Combine them into one high-risk flag and two mistakes happen at once: transactions get blocked where only enhanced scrutiny was needed, and sanctions exposure gets scored instead of stopped.

Terminology adds to the confusion. Calling the call-for-action list a black list suggests prohibition, which it is not, and the informal names were in use long before the distinction mattered operationally. Country-level programs belong in your sanctions and watchlists data, and sanctions screening sits alongside country risk rather than inside it.

How Country Risk Is Scored

A country risk score draws on several separate sources, because no single one covers everything. FATF listing status is binary, authoritative, and updated three times a year. The Basel AML Index is an independent composite score published annually by the Basel Institute on Governance, now in its fourteenth public edition, and it takes in AML framework quality, corruption and fraud, financial transparency, public accountability, and political and legal risk. Corruption indices, with Transparency International's Corruption Perceptions Index as the standard reference, measure perceived public sector corruption rather than money laundering directly. Sanctions exposure covers whether the jurisdiction hosts sanctions programs, designated entities, or known evasion routes. Predicate crime prevalence includes drug production and trafficking, conflict, terrorism financing, and the presence of organized crime. Tax and ownership transparency reflects registry quality, the availability of beneficial ownership data, and secrecy jurisdiction status.

Four design problems keep coming up. Inputs are highly correlated, so a model that counts corruption through both the Basel Index and the Corruption Perceptions Index ends up giving the same signal double weight without meaning to. Update frequencies differ, so the score mixes data refreshed last week with data refreshed eighteen months ago. Banding matters more than weighting, because the line between medium and high decides what actually happens to a customer. And overrides need governance: a score no one can adjust gets ignored, and a score anyone can adjust means nothing.

Not being on the grey list does not mean a country is low risk. The grey list covers jurisdictions actively working with FATF on identified deficiencies, which is a different group from the jurisdictions with the weakest controls. A country can stay off it by never being evaluated, by refusing to engage, or because its deficiencies were never judged strategic. Models that treat unlisted as safe inherit that gap without noticing. A composite approach to risk scoring closes it.

Country risk in every customer score.

Complead brings jurisdiction risk, sanctions and PEP data into one customer risk assessment, from onboarding to ongoing review.

800+financial institutions use Complead
70+countries served

Turning a List Change Into Action

A plenary outcome is not useful information until it has turned into a set of updated customer files. It takes six steps to get there.

The first step is to establish exposure. Country risk can attach through many routes besides nationality: residence, place of incorporation, the registered address of beneficial owners, transaction corridors, counterparty banks, and trade routes. A customer with no connection to a jurisdiction on paper may still route most of its payments through it.

The second step is to re-score the country. Update the country rating and let it flow through, rather than adjusting affected customers by hand.

The third step is to recalculate customer ratings and find out which customers cross into a higher risk band as a result. This group is usually much smaller than the exposure population, and it is the one you can act on.

The fourth step is to apply enhanced due diligence where the band changed: source of funds and wealth, an ownership refresh, the purpose of the relationship, and senior approval to continue, scaled to how far the rating moved.

The fifth step is to review structural exposure. Correspondent relationships, trade finance lines, and payment corridors involving the jurisdiction should be reviewed at portfolio level, not customer by customer.

The sixth step is to document and report. Record each decision, including decisions not to act, and report the change in exposure through governance.

Thirty days after the plenary is the working target most programs aim for. The real risk is not slowness but reflexive de-risking. Exiting every customer linked to a newly listed jurisdiction is quick and easy to justify on paper, but it pushes legitimate flows into less transparent channels and removes the institution's own visibility. FATF has consistently criticized the practice.

Delistings need the same process in reverse, and they rarely get it. A jurisdiction leaving the grey list should trigger a re-score and a review of customers held at elevated ratings, yet enhanced measures put in place during a listing often stay for years because nothing forces a second look. Controls that only ever ratchet upward end up reflecting history rather than current risk.

In practice, the new country rating flows through customer risk assessment, and the structural exposure that causes the most trouble usually sits in correspondent banking. If you want to see how this works in a live program, you can request a demo.

Other Country-Risk Indicators

FATF status is just one input among several, and the others fill the gaps it leaves.

Instead of a binary flag, the Basel AML Index gives a continuous score, which helps tell apart jurisdictions that share the same FATF status. Corruption rankings capture governance weaknesses that come before AML failure and often predict it. Major money laundering countries, as identified in annual government assessments, reflect observed laundering volume rather than framework quality, which is a different question and sometimes has a different answer.

Two less obvious indicators are worth including. Travel Rule adoption by jurisdiction shows where virtual asset transfers still move without originator and beneficiary information, which leaves a clear traceability gap for crypto businesses. The lowest-risk jurisdictions matter as a calibration reference: if a model cannot tell the top of the range from the middle, it is not scoring anything useful at the bottom.

EU and Other High-Risk Third-Country Lists

The European Union keeps its own list of high-risk third countries, which the Commission adopts as delegated regulations and which carries mandatory enhanced due diligence obligations under EU law. It follows FATF decisions closely and is updated after plenaries, but it is not a copy.

The clearest example came on 29 January 2026, when a delegated regulation adding the Russian Federation to the EU list entered into force. Russia is not on either FATF list, and the United Kingdom, whose post-Brexit regime treats the FATF lists themselves as its high-risk third country list, has not listed it either. So a multinational firm has three different correct answers to the same question depending on which entity is asking, and only the EU answer carries EDD obligations.

That divergence is the general lesson, not an exception. A firm operating across the EU, the UK, and a third jurisdiction needs a country risk model that holds multiple list memberships per country rather than a single high-risk flag, and that knows which obligation attaches to which listing. A model with one field for country risk cannot show a jurisdiction that is EDD-mandatory in Frankfurt and unremarkable in London.

Timing adds a second complication. The EU list follows FATF decisions but arrives months later, since each update runs through a delegated regulation subject to parliamentary scrutiny before entry into force. A jurisdiction can leave the FATF grey list and remain on the EU list for a further reporting cycle.

Lead on compliance.

Join 800+ companies that trust Complead to detect risk, prevent fraud and stay compliant.

One Platformall compliance, risk & fraud requirements in a platform

Sources

Frequently asked questions

What is the FATF grey list?

The FATF grey list is the informal name for the list of jurisdictions under increased monitoring. A country appears on it when a mutual evaluation has identified strategic deficiencies in its anti-money laundering and counter-terrorist financing regime and the government has made a high-level political commitment to fix them under an action plan with agreed timeframes. Grey listing therefore signals two things at once: The controls have gaps that FATF considers strategic, and the country is actively working with FATF to close them.

Membership is reviewed at each of the three annual plenaries, in February, June, and October, and the list is republished at the close of each one. Jurisdictions are added when a new action plan is agreed and removed after they complete their plan and pass an on-site visit that confirms the reforms are operating in practice rather than only on paper. Time on the list ranges from under two years to well over five, and the difference usually comes down to whether the deficiencies are legislative, which can be fixed quickly, or a matter of capacity and effectiveness, which cannot.

For a compliance team, grey listing is a risk input rather than a prohibition. FATF does not ask members to apply countermeasures to grey-listed jurisdictions; it asks them to take the listing into account in their risk-based approach. In practice that means the country's risk rating rises, customers and transactions connected to it may cross into a higher risk band, and enhanced due diligence applies where they do. Several national and regional regimes, including the EU's list of high-risk third countries, draw on the grey list when setting their own mandatory measures, which is why a plenary outcome can carry legal consequences even though the FATF list itself does not.

What is the difference between the FATF grey list and the black list?

The two lists sit at different levels of severity and carry different expectations. The black list is the informal name for high-risk jurisdictions subject to a call for action. FATF asks all members to apply enhanced due diligence to business relationships and transactions involving those jurisdictions and, in the most serious cases, to apply countermeasures, which can include restricting or terminating relationships and limiting financial transactions. Membership has been very small throughout the list's existence and has not changed since October 2022, so it is the stable half of the country risk picture.

The grey list is the informal name for jurisdictions under increased monitoring. These are countries that have strategic deficiencies but have committed to an action plan and are working with FATF to complete it. No countermeasures are called for, and FATF explicitly encourages members to take the listing into account in risk analysis rather than to de-risk wholesale. The list changes at nearly every plenary as jurisdictions join and complete their plans.

The distinction matters for how a program responds. A black list status generally justifies the most restrictive treatment a firm's policy allows short of a sanctions block, and in some national regimes it triggers mandatory measures directly. A grey list status should raise the country's risk score and pull affected customers into enhanced due diligence where they cross a band, but it should not by itself trigger exits. Treating the two lists the same way overstates grey list risk and understates black list risk. A well-designed country risk model holds them as separate fields with separate consequences, and its policy states in advance what each status triggers so that the response to a plenary is a lookup rather than a debate.

Which countries are on the FATF grey list right now?

The membership of the grey list changes at each plenary, so any list printed in a long-form guide will be out of date within months. That is why this guide deliberately does not name current members and instead routes the question to a dedicated page that is updated after every plenary. Checking that page, or the FATF's own publication of jurisdictions under increased monitoring, is the reliable way to answer the question at any given moment.

What can be said durably is how to read the list once you have it. Each entry comes with a short statement summarizing the jurisdiction's action plan and the progress FATF has recorded, and those statements are more useful than the bare membership because they show whether a country is close to completing its plan or has stalled. A jurisdiction whose statement notes that an on-site visit has been scheduled is likely to exit at the following plenary; one whose statement has repeated the same outstanding items for several cycles is not.

It is equally important to read what the list does not say. Absence from the grey list is not evidence that a country has strong controls. The list contains jurisdictions that have been evaluated, found to have strategic deficiencies, and agreed to an action plan. A country that has not yet been evaluated in the current round, that declined to engage, or whose deficiencies were judged less than strategic will not appear, whatever the actual state of its controls. Country risk models that treat unlisted as low risk inherit that gap, which is why the grey list should be one input into a composite score rather than the score itself.

AML country risk index
Is a FATF high-risk country the same as a sanctioned country?

No, and confusing the two is the most common structural error in country risk programs. A FATF listing is an assessment finding. It says that a jurisdiction's anti-money laundering regime has strategic deficiencies and asks financial institutions to respond through their risk-based approach, with enhanced due diligence and, for the call-for-action list, potential countermeasures applied through national law. Nothing about it prohibits doing business with the country, freezes assets, or creates legal liability for a transaction.

A sanction is a legal instrument. Governments and international bodies such as the United Nations issue sanctions programs that prohibit specified dealings with a country, a sector, or named persons and entities, and breaching them carries civil and criminal penalties. Sanctions do not scrutinize; they prohibit.

The two populations overlap only partly. Some grey-listed jurisdictions have no country-level sanctions program attached to them at all. Some heavily sanctioned countries do not appear on either FATF list, because appearing requires having been evaluated and having engaged with an action plan, and a state that refuses to cooperate simply never enters the process.

The operational consequence is that a country risk model needs both inputs and must treat them differently. FATF status adjusts a risk score and may move a customer into enhanced due diligence. A sanctions designation is a hard control that stops a transaction regardless of any score. Collapsing both into one high-risk flag produces two failures at once: Transactions get blocked where only additional scrutiny was required, and sanctions exposure gets scored when it should have been stopped. Keeping the fields separate, and documenting which obligation flows from which, is the fix, and it is also what an examiner will look for when testing how the two controls interact.

What is the Basel AML Index?

The Basel AML Index is an independent, annually published ranking of money laundering and terrorist financing risk by country, produced by the Basel Institute on Governance, a not-for-profit organization associated with the University of Basel. The 2025 edition was its fourteenth public edition and covered 177 jurisdictions. Rather than measuring laundering directly, which cannot be observed, it measures the conditions that make laundering more or less likely and assigns each jurisdiction a composite score on a scale from low to high risk.

The score draws on seventeen publicly available sources organized into five domains: The quality of the AML, counter-terrorist financing, and counter-proliferation framework, which draws heavily on FATF mutual evaluation results; corruption and fraud risk; financial transparency and standards; public transparency and accountability; and political and legal risk. The framework quality domain carries the largest weight, so a poor mutual evaluation, especially on effectiveness, pushes a country up the ranking considerably.

For a compliance program the Index has two uses. First, it provides a continuous score rather than a binary flag, which lets a model distinguish between jurisdictions that share the same FATF status. Two countries can both be off the grey list and sit at very different points on the Index. Second, it aggregates sources a firm would otherwise have to collect and weight itself. The caution that goes with it is correlation: Because the Index already incorporates FATF results and corruption data, a model that adds FATF status and the Corruption Perceptions Index as separate inputs alongside it is counting the same signal two or three times. Using the Index well means understanding what it already contains.

What happens when a country is added to the grey list?

Two sets of consequences follow, one for the country and one for the institutions dealing with it. For the country, the most immediate effect is on capital flows. A 2021 IMF working paper found that capital inflows fall by an average of 7.6 percent of GDP after grey listing, with the decline driven largely by foreign financial institutions reducing exposure or exiting relationships. The effect is not uniform: Larger, diversified economies with strong domestic banking sectors often come through a listing with limited damage, while smaller economies dependent on foreign investment and correspondent banking feel it hardest. Croatia's experience between 2023 and 2025, during which its sovereign ratings were upgraded, shows how much depends on the starting position.

For a financial institution, a grey listing changes the country's risk rating and everything that rating feeds. Customers connected to the jurisdiction through nationality, residence, incorporation, beneficial ownership, transaction corridors, or counterparties may cross into a higher risk band, and where they do, enhanced due diligence applies: Source of funds and wealth, refreshed ownership, purpose of relationship, and senior approval to continue. Structural exposures such as correspondent relationships and trade finance lines need a portfolio-level review. In the EU, the listing usually flows through to the Commission's list of high-risk third countries some months later, at which point enhanced measures become mandatory rather than risk-based.

What should not happen is wholesale de-risking. Exiting every customer with a connection to a newly listed jurisdiction is quick and looks defensible, but it pushes legitimate flows into less transparent channels and removes the institution's own visibility of them. FATF has consistently criticized the practice, and the better response is targeted: Re-score, identify who actually crosses a band, and apply proportionate measures to those customers.

How does a country get off the FATF grey list?

Exit follows a defined path, and it is longer than most people expect. When a jurisdiction is listed, it agrees an action plan with FATF that sets out the specific deficiencies to be addressed and a timeframe for each. The country then reports progress at each plenary cycle, and FATF updates the public statement to record which items remain outstanding. A jurisdiction is only considered for removal once FATF judges that all items in the plan have been substantially completed.

At that point FATF conducts an on-site visit. The purpose is to verify that the reforms are not just enacted but operating: That the new legislation is being applied, that supervisors are inspecting and sanctioning, that financial intelligence is being used, that beneficial ownership information is accurate and accessible, and that prosecutors are bringing and concluding money laundering cases. If the visit confirms sustained implementation, the plenary agrees to remove the jurisdiction, and the decision is published at the close of that plenary.

The reason time on the list varies so widely is the effectiveness test. Legislative deficiencies can be fixed within a year by passing laws. Capacity deficiencies cannot, because demonstrating that a system works requires cases to move through it, and complex laundering prosecutions take years. Jurisdictions that leave quickly generally had narrow, legislative gaps; those that stay for five years or more usually have institutional weaknesses that reforms on paper do not cure.

For a compliance program, a delisting should trigger a process, not just a note. The country's risk score should be revisited, customers held at elevated ratings because of the listing should be reviewed, and enhanced measures introduced during the listing should be reconsidered. In practice this rarely happens, because nothing forces it, and controls that only ratchet upward end up reflecting history rather than risk.

What should a compliance team do when a country's FATF status changes?

The working answer is a six-step process completed within about thirty days of the plenary. The first step is to establish exposure, and it is wider than most teams assume. Country risk attaches through nationality, residence, place of incorporation, the registered address of beneficial owners, transaction corridors, counterparty banks, and trade routes, so a customer with no visible connection to a jurisdiction on the customer file may still route most of their payments through it.

The second step is to re-score the country itself and let the new rating propagate through the customer risk model, rather than adjusting affected customers one by one. The third is to recalculate customer ratings and identify who actually crosses a risk band as a result. That population is usually much smaller than the exposure population, and it is the group that needs action. The fourth is to apply enhanced due diligence to those customers, calibrated to how far the rating moved: Source of funds and wealth, ownership refresh, purpose of relationship, and senior approval to continue.

The fifth step is to review structural exposure at portfolio level. Correspondent relationships, trade finance lines, and payment corridors involving the jurisdiction are where the concentrated risk sits, and reviewing them customer by customer misses it. The sixth is to document and report: Record each decision, including decisions not to act, and report the change in exposure through the governance chain.

Two things distinguish a mature program. It resists reflexive de-risking, because exiting an entire segment is fast and defensible on paper but removes the institution's own visibility and pushes legitimate activity into less transparent channels. And it runs the same process in reverse when a jurisdiction is delisted, revisiting the elevated ratings and enhanced measures the listing introduced rather than leaving them in place indefinitely.

How does the EU list of high-risk third countries differ from the FATF lists?

The EU maintains its own list of high-risk third countries under its anti-money laundering framework. The Commission adopts it as delegated regulations, and once a jurisdiction is on it, obliged entities across the EU must apply enhanced due diligence to relationships and transactions involving that country. That mandatory character is the first difference from FATF: A FATF listing asks institutions to respond through their risk-based approach, while an EU listing imposes a legal obligation.

The EU list tracks FATF decisions closely and is updated after plenaries, but it is not a copy and can diverge in both content and timing. On content, the Commission can list a country that FATF has not. The clearest example took effect on 29 January 2026, when a delegated regulation adding the Russian Federation to the EU list entered into force even though Russia sits on neither FATF list. On timing, each EU update passes through a delegated regulation subject to scrutiny by the European Parliament and Council before it enters into force, so a jurisdiction can leave the FATF grey list and remain on the EU list for a further cycle.

The United Kingdom's approach differs again. Since 2024, the UK's money laundering regulations define high-risk third countries by direct reference to the two FATF lists, so the UK list moves exactly when FATF's does and contains nothing FATF has not listed.

The consequence for a multinational firm is that one country can have three different high-risk statuses depending on which entity is asking. A country risk model with a single high-risk field cannot represent a jurisdiction that carries mandatory EDD in an EU entity and no special obligation in a UK entity. The model needs to hold multiple list memberships per country and to know which obligation attaches to which listing.

How often are the FATF lists updated?

The FATF reviews and republishes both lists at each of its three annual plenaries, which are held in February, June, and October. List decisions are agreed at the plenary and published at its close, usually on the final Friday, together with an updated statement for each listed jurisdiction. Between plenaries the lists do not change, so a compliance team can plan its review cycle around three fixed points in the year.

The two lists move at very different rates. The call-for-action list, informally the black list, has changed rarely and its membership has been the same since October 2022. The increased-monitoring list, informally the grey list, changes at almost every plenary. The February 2026 plenary added two jurisdictions and removed none, and the June 2026 plenary added two and removed two. Over a typical year, several jurisdictions join and several leave.

Other lists follow FATF on a lag. The EU's list of high-risk third countries is updated after FATF plenaries but only once a delegated regulation has passed scrutiny and entered into force, which typically takes several months, and the Commission can also list jurisdictions FATF has not. The UK's list moves in step with FATF because it is defined by reference to the FATF lists directly. Composite indicators such as the Basel AML Index are annual, and corruption indices are also annual, so a country risk score built from all of these is blending inputs refreshed on very different cycles.

The practical implication is a review cadence. Country risk ratings should be revisited after every plenary, with a working benchmark of thirty days to complete the resulting customer re-scoring and any enhanced due diligence. Annual indicators can be refreshed on their own publication dates. Any guide or internal policy that hard-codes current membership will be wrong within months, which is why current lists belong in a maintained reference page rather than in a document written once.

Minhac Celik
Written by Minhac Celik Marketing Lead

Minhac Celik is Marketing Lead at Complead, covering US regulation, PEP and entity screening, onboarding fraud and company news.

Originally published , updated

Back to blog