Aml/Cft International Compliance .
1. Meaning of International AML/CFT Compliance
International AML/CFT compliance seeks to prevent the international financial system from being used for:
- money laundering;
- terrorist financing;
- proliferation financing;
- corruption and related financial crime;
- sanctions evasion;
- fraud and other predicate offences.
The basic cycle is:
Identify → Assess Risk → Prevent → Detect → Investigate → Report → Freeze/Restrict where legally required → Cooperate internationally → Remediate
A modern financial institution therefore needs an AML/CFT programme capable of dealing with cross-border customers, transactions, correspondent banks, beneficial owners, sanctions, high-risk jurisdictions and international information requests.
2. FATF — The Core International Standard
The Financial Action Task Force (FATF) is the most important international standard-setting body in AML/CFT.
The FATF Recommendations are divided into seven broad areas:
- AML/CFT policies and coordination;
- money laundering and confiscation;
- terrorist financing and proliferation financing;
- preventive measures;
- beneficial ownership and transparency;
- powers and responsibilities of competent authorities; and
- international cooperation.
The fundamental principle is the Risk-Based Approach (RBA).
FATF expressly describes the risk-based approach as the cornerstone of its Recommendations: countries and institutions should identify, understand and mitigate the risks to which they are exposed rather than applying identical controls to every customer and transaction.
3. FATF Recommendations most relevant to an institution
For an international financial institution, the following FATF Recommendations are particularly important.
| FATF Recommendation | Main subject |
|---|---|
| R.1 | Risk assessment and risk-based approach |
| R.2 | National cooperation and coordination |
| R.3 | Money laundering offence |
| R.4 | Confiscation |
| R.5 | Terrorist financing offence |
| R.6 | Targeted financial sanctions relating to terrorism |
| R.7 | Proliferation-financing sanctions |
| R.8 | Non-profit organisations |
| R.9–23 | Preventive measures for financial institutions/DNFBPs |
| R.10 | Customer due diligence |
| R.11 | Record keeping |
| R.12 | PEPs |
| R.13 | Correspondent banking |
| R.14 | Money/value transfer services |
| R.15 | New technologies/VASPs |
| R.16 | Payment transparency |
| R.18 | Internal controls and foreign branches/subsidiaries |
| R.19 | Higher-risk countries |
| R.20 | Suspicious transaction reporting |
| R.21 | Tipping-off and confidentiality |
| R.22–23 | DNFBP requirements |
| R.24–25 | Beneficial ownership |
| R.29 | FIUs |
| R.32 | Cash couriers |
| R.35 | Sanctions |
| R.36–40 | International cooperation |
These standards should be read with their Interpretive Notes and FATF Glossary, which together form the FATF Standards.
4. FATF compliance has two dimensions
This is extremely important.
International AML/CFT assessment is not simply:
“Does the country have an AML law?”
FATF evaluates both:
A. Technical Compliance
Whether the necessary:
- laws;
- regulations;
- institutions;
- powers;
- procedures; and
- mechanisms
exist.
B. Effectiveness
Whether the framework actually works.
FATF's current methodology expressly distinguishes between technical compliance and effectiveness, and the fifth round of mutual evaluations commenced in 2024. The methodology was amended in June 2026.
This principle is equally useful for financial institutions.
Example
A bank may have:
- AML policy;
- sanctions policy;
- transaction monitoring system;
- KYC procedure;
- Principal Officer;
- compliance training.
That demonstrates design.
But if the bank fails to detect suspicious transactions, identify beneficial owners or file appropriate reports, its effectiveness is poor.
5. Enterprise AML/CFT Risk Assessment
An international AML/CFT programme starts with an Enterprise-Wide ML/TF Risk Assessment.
The institution should analyse at least:
Customer risk
- PEPs;
- high-net-worth customers;
- complex structures;
- trusts;
- shell companies;
- opaque ownership;
- cash-intensive businesses;
- high-risk professions.
Geographic risk
- sanctioned countries;
- jurisdictions with significant organised crime;
- countries with weak AML/CFT regimes;
- high-risk jurisdictions identified by FATF;
- cross-border corridors.
Product risk
- correspondent banking;
- private banking;
- trade finance;
- remittance;
- virtual assets;
- cash services;
- prepaid products;
- cross-border payments.
Delivery-channel risk
- remote onboarding;
- agents;
- intermediaries;
- digital identification;
- non-face-to-face relationships.
The risk assessment must then influence the control framework.
6. Customer Due Diligence — CDD
International AML/CFT compliance requires institutions to know:
Who is the customer?
But modern CDD goes considerably further.
The institution should understand:
- identity;
- ownership;
- control;
- beneficial ownership;
- business activities;
- purpose of the relationship;
- expected transactions;
- source of funds;
- source of wealth where appropriate;
- geographic exposure;
- expected counterparties.
The FATF framework places CDD among the core preventive measures.
The four basic CDD questions
1. Who is the customer?
2. Who ultimately owns or controls the customer?
3. Why does the customer need the relationship?
4. Are the customer's actual transactions consistent with the expected profile?
7. Beneficial Ownership
Beneficial ownership is one of the most important international AML/CFT concepts.
A financial institution should not stop at:
Company A → owned by Company B.
It must continue examining the ownership/control chain until it identifies the relevant natural person(s) who ultimately own or control the entity.
FATF has specifically strengthened its beneficial-ownership standards and guidance in recent years. Its current Recommendations include specific requirements concerning transparency and beneficial ownership of legal persons and arrangements.
8. PEP Compliance
A Politically Exposed Person (PEP) creates enhanced corruption and bribery risk.
International AML/CFT programmes generally require enhanced controls for:
- foreign PEPs;
- domestic PEPs; and
- persons associated with or related to PEPs, subject to the applicable legal framework.
Typical controls include:
- senior management approval;
- source of wealth;
- source of funds;
- enhanced monitoring;
- continuing review.
The key point is:
PEP status is a risk factor, not automatic proof of criminal conduct.
An institution should therefore apply proportionate enhanced due diligence rather than treating PEP status itself as evidence of money laundering.
9. Correspondent Banking
Correspondent banking is one of the most significant international AML/CFT risks because one bank can provide services that enable another bank's underlying customers to access the international financial system.
FATF Recommendation 13 addresses correspondent banking.
The Wolfsberg Group's current correspondent-banking principles similarly emphasise:
- risk-based due diligence;
- enhanced due diligence;
- monitoring;
- suspicious-activity reporting;
- ongoing review;
- governance; and
- integration with the broader financial-crime compliance programme.
The Wolfsberg framework specifically notes that correspondent relationships may involve the correspondent acting as an intermediary for the respondent bank's underlying customers, which can increase risk.
10. Transaction Monitoring
An international AML/CFT programme must monitor transactions for unusual or suspicious behaviour.
Examples include:
Structuring
Multiple transactions designed to avoid reporting or monitoring thresholds.
Rapid movement of funds
Money enters an account and quickly leaves through another jurisdiction.
Layering
Multiple transactions designed to obscure the origin of funds.
Circular transactions
Funds move through multiple accounts/entities and eventually return to the originator.
Unusual cross-border transactions
Transactions inconsistent with the customer's business or geographic profile.
Pass-through activity
An account receives large amounts and transfers substantially all funds elsewhere without a reasonable economic explanation.
11. Suspicious Transaction Reporting
The international model generally requires reporting entities to report suspicious transactions to the relevant Financial Intelligence Unit (FIU).
The important principle is:
Suspicion does not require proof of the underlying crime.
An institution is generally not expected to conduct a criminal prosecution before reporting.
The institution's role is to:
detect → investigate internally → assess suspicion → report according to law → maintain confidentiality → continue monitoring where appropriate.
12. Tipping-Off
A major AML/CFT obligation is confidentiality.
Once an institution submits or is considering submitting a suspicious transaction report, employees generally cannot improperly inform the customer that:
“You have been reported to the FIU.”
This is known as tipping-off.
The purpose is obvious: informing the suspect could cause:
- destruction of evidence;
- movement of funds;
- closure of accounts;
- movement of assets to another jurisdiction;
- obstruction of an investigation.
FATF Recommendation 21 addresses tipping-off and confidentiality.
13. Terrorist Financing — Difference from Money Laundering
This distinction is extremely important.
Money laundering
Generally involves:
Illegal proceeds → concealment/layering → integration into legitimate economy
Terrorist financing
Can involve:
Funds → terrorist activity
The money itself may be completely legitimate.
For example:
Legitimate donations → terrorist organisation.
Therefore:
AML controls that only search for criminal proceeds are insufficient for CFT.
CFT requires attention to:
- terrorist designations;
- sanctions;
- suspicious networks;
- fundraising;
- NPO-related risks;
- unusual transfers;
- terrorist financing typologies.
14. Targeted Financial Sanctions
International AML/CFT compliance also overlaps with sanctions compliance.
The institution must consider applicable:
- UN sanctions;
- domestic sanctions;
- regional sanctions;
- applicable extraterritorial sanctions regimes.
FATF Recommendations 6 and 7 address targeted financial sanctions relating to terrorism and proliferation financing.
Typical controls
Customer onboarding → sanctions screening
Payment initiation → sanctions screening
Beneficiary screening → sanctions screening
Ongoing customer screening → sanctions screening
List update → rescreening
A sanctions control should also address:
- name variations;
- transliteration;
- aliases;
- ownership/control;
- false positives;
- escalation;
- blocking/freezing where legally required.
15. Proliferation Financing
Modern international compliance extends beyond AML and CFT to Counter-Proliferation Financing (CPF).
The concern is financing the proliferation of:
- nuclear;
- chemical; or
- biological weapons
and related delivery systems.
FATF's current framework expressly incorporates proliferation-financing risks.
Therefore, a mature international FCC programme is increasingly:
AML + CFT + CPF + Sanctions + broader Financial Crime Compliance.
16. International Information Sharing
Money laundering frequently crosses jurisdictions.
Example:
Criminal proceeds in Country A → bank in Country B → shell company in Country C → investment in Country D.
No single regulator may possess the entire picture.
International AML/CFT therefore depends on:
- FIU-to-FIU cooperation;
- law-enforcement cooperation;
- supervisory cooperation;
- mutual legal assistance;
- extradition;
- asset recovery;
- information sharing.
FATF's Recommendation 40 deals with other forms of international cooperation.
17. Important Case Law
There is no single “International AML Court.” International AML/CFT principles are reflected through judgments of national courts, the Court of Justice of the European Union (CJEU), the European Court of Human Rights (ECtHR) and other jurisdictions.
Several cases are particularly useful.
Case 1 — Jyske Bank Gibraltar Ltd v Administración del Estado
CJEU, Case C-212/11, judgment 25 April 2013
This is one of the most important international AML/CFT cases involving cross-border banking and FIU reporting.
Jyske Bank Gibraltar operated in Spain under the freedom-to-provide-services regime. Spain required certain information relevant to AML/CFT to be supplied directly to the Spanish authorities.
The issue was whether such a requirement was compatible with EU rules governing financial services.
The CJEU held that EU law did not preclude the Spanish requirement where it strengthened the effectiveness of combating money laundering and terrorist financing and was proportionate.
Compliance principle
This case demonstrates:
Cross-border financial-services freedom does not eliminate AML/CFT obligations imposed to protect the financial system.
For an international bank, this means that it cannot simply say:
“Our headquarters/FIU is in another country, therefore we do not need to comply with local AML reporting requirements.”
Local requirements can apply, subject to the applicable legal framework and proportionality.
18. Case 2 — Ordre des barreaux francophones et germanophone v Conseil des Ministres
CJEU, Case C-305/05, judgment 26 June 2007
This case concerned AML obligations imposed on lawyers and the tension between:
- AML reporting;
- professional secrecy;
- lawyer independence; and
- the right to a fair trial.
The CJEU held that AML information/cooperation obligations could apply to lawyers in specified financial and real-estate transactions, while recognising the special position of lawyers when acting in the context of judicial proceedings.
Compliance principle
AML obligations are powerful, but they are not unlimited.
An AML programme must take account of:
- legal professional privilege;
- confidentiality;
- fundamental rights;
- legitimate legal representation.
This is important when a bank or financial institution obtains information through professional intermediaries.
19. Case 3 — Michaud v France
European Court of Human Rights, Application No. 12323/11, judgment 6 December 2012
This is an important human-rights case concerning AML reporting obligations imposed on lawyers.
The case involved the French requirement for lawyers to report certain suspicions in the AML framework and the relationship between that obligation and Article 8 of the European Convention on Human Rights, concerning private and family life.
The ECtHR considered the balance between:
AML/CFT public interest
and
professional confidentiality and legal privilege.
The case was decided on 6 December 2012.
Compliance principle
AML/CFT controls must be:
- legally grounded;
- proportionate;
- targeted;
- compatible with fundamental rights.
This is particularly important for multinational groups operating across jurisdictions with different privacy and professional-secrecy rules.
20. Case 4 — Luxembourg Business Registers and Sovim
CJEU, Joined Cases C-37/20 and C-601/20, judgment 22 November 2022
This is a landmark case concerning beneficial ownership transparency.
EU legislation had required beneficial ownership information to be entered in a register, with certain information accessible to the general public.
The CJEU held that the provision making such information accessible in all cases to the general public was invalid because the resulting interference with fundamental rights was neither limited to what was strictly necessary nor proportionate to the objective pursued.
Compliance principle
This case is extremely important because it demonstrates that:
AML transparency requirements must be balanced against privacy and data-protection rights.
Therefore:
“More AML information” does not automatically mean “better legal compliance.”
The institution must consider:
- purpose;
- necessity;
- proportionality;
- lawful access;
- data protection;
- confidentiality.
21. Case 5 — Ratzlaf v United States
U.S. Supreme Court, 510 U.S. 135 (1994)
This case concerned the U.S. Bank Secrecy Act and structuring transactions to avoid reporting requirements.
The Supreme Court held that, for the criminal offence at issue at that time, the Government had to prove that the defendant knew the structuring conduct was unlawful.
Compliance significance
The case demonstrates an important distinction between:
regulatory reporting obligations
and
criminal liability.
An AML compliance professional should never automatically equate:
unusual transaction = criminal offence.
The institution's regulatory obligation to identify/report suspicious activity is distinct from proving criminal liability.
22. Case/Enforcement Example — HSBC
Although not a traditional appellate judgment, the HSBC enforcement/DPA is one of the most important real-world international AML compliance examples.
In 2012, HSBC Holdings and HSBC Bank USA entered into a deferred prosecution agreement with the U.S. Department of Justice.
The authorities alleged serious failures including:
- inadequate AML staffing;
- ineffective transaction monitoring;
- inadequate correspondent due diligence;
- failures involving HSBC Mexico;
- significant volumes of transactions not adequately monitored.
HSBC agreed to forfeit $1.256 billion and pay additional civil penalties.
The DOJ stated that HSBC Bank USA had failed to maintain an effective AML programme and failed to conduct appropriate due diligence concerning foreign correspondent relationships.
Compliance lesson
This case illustrates a fundamental principle:
An AML programme must work in practice, not merely exist on paper.
23. International AML/CFT Governance Model
A strong multinational institution normally needs:
Board
Responsible for:
- risk appetite;
- governance;
- oversight;
- resources.
Senior Management
Responsible for:
- implementation;
- escalation;
- staffing;
- remediation.
Group AML/CFT Function
Responsible for:
- group standards;
- risk methodology;
- global controls;
- monitoring.
Local Compliance
Responsible for:
- jurisdiction-specific requirements;
- local FIU reporting;
- local regulator interaction.
First Line
Business and operations.
Second Line
Compliance/AML/CFT.
Third Line
Internal Audit.
This creates the classic:
Three Lines Model
24. Group AML Policy vs Local Law
This is a major issue for multinational companies.
Suppose:
Global AML Policy: applies worldwide.
But:
Country A law: requires certain information to be collected.
Country B privacy law: restricts transfer of that information overseas.
Country C: has additional sanctions requirements.
The institution cannot simply impose the global policy without analysing local law.
A practical hierarchy is:
Applicable law → regulator requirements → group minimum standards → risk-based enhanced controls
The group standard can normally be more stringent, but it must not violate mandatory local requirements.
25. Foreign Branches and Subsidiaries
International groups should have mechanisms ensuring AML/CFT controls operate across:
- branches;
- subsidiaries;
- representative offices;
- agents;
- affiliates.
FATF Recommendation 18 is particularly relevant to internal controls and foreign branches/subsidiaries.
The institution should ensure:
- consistent minimum standards;
- group-wide risk assessment;
- information sharing;
- training;
- escalation;
- independent testing.
26. AML/CFT Programme Validation
For an international institution, validation should test:
1. Governance
Question: Who owns AML/CFT risk?
2. Enterprise Risk Assessment
Question: Are international ML/TF risks properly identified?
3. Customer Risk Rating
Question: Does the rating reflect actual risk?
4. KYC/CDD
Question: Is customer identity properly established?
5. Beneficial Ownership
Question: Is the ultimate owner/controller identified?
6. PEP Screening
Question: Are PEPs correctly identified and subjected to appropriate EDD?
7. Sanctions Screening
Question: Are customers and transactions screened against applicable lists?
8. Transaction Monitoring
Question: Can the system identify suspicious cross-border activity?
9. STR/SAR
Question: Are suspicious matters escalated and reported correctly?
10. Correspondent Banking
Question: Is respondent-bank risk adequately assessed?
11. Information Sharing
Question: Can the group legally and securely exchange AML information across jurisdictions?
12. Independent Testing
Question: Has an independent function tested whether controls actually work?
27. AML/CFT Validation — Four levels
A sophisticated international validation programme should examine four levels.
Level 1 — Policy
Does the policy comply with:
- FATF;
- local law;
- regulator requirements?
Level 2 — Design
Are controls properly designed?
Level 3 — Operating Effectiveness
Do the controls actually operate?
Level 4 — Outcome Effectiveness
Are the controls actually producing the intended result?
This last level corresponds closely with the FATF emphasis on effectiveness, rather than merely technical compliance.
28. Example International AML Finding
Finding
A multinational bank's global policy requires enhanced due diligence for high-risk correspondent banks.
However:
- Country A performs EDD;
- Country B uses a simplified questionnaire;
- Country C has no documented senior-management approval;
- the global system does not capture respondent-bank risk consistently.
Risk
The group has a global policy but inconsistent implementation.
Regulatory concern
The institution may be unable to demonstrate effective implementation of its risk-based AML/CFT framework.
Recommended action
Create a minimum global control standard:
Risk classification → CDD → EDD → senior approval → transaction monitoring → periodic review → escalation → independent testing
with local add-ons where required by law.
29. International AML/CFT Compliance Checklist
| Area | Key question |
|---|---|
| Governance | Is Board oversight effective? |
| Risk Assessment | Are ML/TF risks identified? |
| KYC | Is identity verified? |
| BO | Is ultimate ownership/control established? |
| PEP | Are PEPs appropriately identified? |
| Sanctions | Are applicable sanctions lists screened? |
| CDD | Is customer purpose understood? |
| EDD | Are high-risk customers enhanced? |
| Monitoring | Are suspicious patterns detected? |
| STR/SAR | Are reports filed appropriately? |
| Tipping-off | Is confidentiality protected? |
| Correspondent Banking | Is respondent risk assessed? |
| Cross-border | Are local laws considered? |
| Information Sharing | Are transfers legally permitted? |
| Recordkeeping | Can evidence be retrieved? |
| Training | Are employees trained? |
| QA | Is quality assurance performed? |
| Independent Audit | Is testing genuinely independent? |
| Remediation | Are deficiencies closed? |
| Effectiveness | Can the institution demonstrate results? |
30. Key legal principles emerging from international case law
The cases above produce several important principles:
Principle 1 — AML/CFT is a legitimate public-interest objective
Courts generally recognise the importance of preventing financial systems from being abused for crime and terrorism.
Principle 2 — AML obligations can have cross-border effect
Jyske Bank demonstrates that cross-border financial-service activity does not necessarily prevent host-state AML requirements.
Principle 3 — AML obligations are not unlimited
Ordre des barreaux and Michaud demonstrate the importance of legal privilege, confidentiality and fair-trial considerations.
Principle 4 — Beneficial ownership transparency must respect fundamental rights
Luxembourg Business Registers/Sovim demonstrates that AML transparency must satisfy necessity and proportionality.
Principle 5 — Regulatory compliance and criminal liability are different questions
Ratzlaf demonstrates the importance of distinguishing reporting obligations from the elements required for criminal liability.
Principle 6 — Effectiveness matters
FATF's methodology explicitly places substantial emphasis on whether the AML/CFT framework actually produces effective outcomes, not simply whether laws and policies exist.
31. International AML/CFT compliance — the simplest framework
You can remember the whole subject through this model:
RISK
↓
KYC / CDD
↓
BENEFICIAL OWNERSHIP
↓
PEP / SANCTIONS SCREENING
↓
EDD
↓
TRANSACTION MONITORING
↓
ALERT INVESTIGATION
↓
STR/SAR
↓
FIU / REGULATOR / LAW-ENFORCEMENT COOPERATION
↓
FREEZE / CONFISCATION / OTHER LEGAL ACTION WHERE APPLICABLE
↓
INDEPENDENT TESTING
↓
REMEDIATION
↓
EFFECTIVENESS
That is essentially the architecture of a mature international AML/CFT programme.
Bottom line
International AML/CFT compliance is not simply FATF compliance. FATF provides the international standards; individual jurisdictions convert those standards into enforceable law; regulators supervise implementation; FIUs receive and analyse financial intelligence; and courts determine the boundaries of enforcement, privacy, privilege, proportionality and due process.
For a multinational financial institution, the strongest approach is therefore:
FATF Standards + applicable local law + sanctions requirements + risk-based controls + effective implementation + evidence + independent validation + international cooperation.
The most important modern lesson is the distinction between technical compliance and effectiveness: having policies, systems and procedures is insufficient if the institution cannot demonstrate that those controls actually identify, prevent, detect and report financial crime. FATF's fifth-round methodology expressly makes effectiveness a central part of international assessment.

comments