Aml/Cft International Compliance .

1. Meaning of International AML/CFT Compliance

International AML/CFT compliance seeks to prevent the international financial system from being used for:

  • money laundering;
  • terrorist financing;
  • proliferation financing;
  • corruption and related financial crime;
  • sanctions evasion;
  • fraud and other predicate offences.

The basic cycle is:

Identify → Assess Risk → Prevent → Detect → Investigate → Report → Freeze/Restrict where legally required → Cooperate internationally → Remediate

A modern financial institution therefore needs an AML/CFT programme capable of dealing with cross-border customers, transactions, correspondent banks, beneficial owners, sanctions, high-risk jurisdictions and international information requests.

2. FATF — The Core International Standard

The Financial Action Task Force (FATF) is the most important international standard-setting body in AML/CFT.

The FATF Recommendations are divided into seven broad areas:

  1. AML/CFT policies and coordination;
  2. money laundering and confiscation;
  3. terrorist financing and proliferation financing;
  4. preventive measures;
  5. beneficial ownership and transparency;
  6. powers and responsibilities of competent authorities; and
  7. international cooperation. 

The fundamental principle is the Risk-Based Approach (RBA).

FATF expressly describes the risk-based approach as the cornerstone of its Recommendations: countries and institutions should identify, understand and mitigate the risks to which they are exposed rather than applying identical controls to every customer and transaction.

3. FATF Recommendations most relevant to an institution

For an international financial institution, the following FATF Recommendations are particularly important.

FATF RecommendationMain subject
R.1Risk assessment and risk-based approach
R.2National cooperation and coordination
R.3Money laundering offence
R.4Confiscation
R.5Terrorist financing offence
R.6Targeted financial sanctions relating to terrorism
R.7Proliferation-financing sanctions
R.8Non-profit organisations
R.9–23Preventive measures for financial institutions/DNFBPs
R.10Customer due diligence
R.11Record keeping
R.12PEPs
R.13Correspondent banking
R.14Money/value transfer services
R.15New technologies/VASPs
R.16Payment transparency
R.18Internal controls and foreign branches/subsidiaries
R.19Higher-risk countries
R.20Suspicious transaction reporting
R.21Tipping-off and confidentiality
R.22–23DNFBP requirements
R.24–25Beneficial ownership
R.29FIUs
R.32Cash couriers
R.35Sanctions
R.36–40International cooperation

These standards should be read with their Interpretive Notes and FATF Glossary, which together form the FATF Standards.

4. FATF compliance has two dimensions

This is extremely important.

International AML/CFT assessment is not simply:

“Does the country have an AML law?”

FATF evaluates both:

A. Technical Compliance

Whether the necessary:

  • laws;
  • regulations;
  • institutions;
  • powers;
  • procedures; and
  • mechanisms

exist.

B. Effectiveness

Whether the framework actually works.

FATF's current methodology expressly distinguishes between technical compliance and effectiveness, and the fifth round of mutual evaluations commenced in 2024. The methodology was amended in June 2026.

This principle is equally useful for financial institutions.

Example

A bank may have:

  • AML policy;
  • sanctions policy;
  • transaction monitoring system;
  • KYC procedure;
  • Principal Officer;
  • compliance training.

That demonstrates design.

But if the bank fails to detect suspicious transactions, identify beneficial owners or file appropriate reports, its effectiveness is poor.

5. Enterprise AML/CFT Risk Assessment

An international AML/CFT programme starts with an Enterprise-Wide ML/TF Risk Assessment.

The institution should analyse at least:

Customer risk

  • PEPs;
  • high-net-worth customers;
  • complex structures;
  • trusts;
  • shell companies;
  • opaque ownership;
  • cash-intensive businesses;
  • high-risk professions.

Geographic risk

  • sanctioned countries;
  • jurisdictions with significant organised crime;
  • countries with weak AML/CFT regimes;
  • high-risk jurisdictions identified by FATF;
  • cross-border corridors.

Product risk

  • correspondent banking;
  • private banking;
  • trade finance;
  • remittance;
  • virtual assets;
  • cash services;
  • prepaid products;
  • cross-border payments.

Delivery-channel risk

  • remote onboarding;
  • agents;
  • intermediaries;
  • digital identification;
  • non-face-to-face relationships.

The risk assessment must then influence the control framework.

6. Customer Due Diligence — CDD

International AML/CFT compliance requires institutions to know:

Who is the customer?

But modern CDD goes considerably further.

The institution should understand:

  • identity;
  • ownership;
  • control;
  • beneficial ownership;
  • business activities;
  • purpose of the relationship;
  • expected transactions;
  • source of funds;
  • source of wealth where appropriate;
  • geographic exposure;
  • expected counterparties.

The FATF framework places CDD among the core preventive measures.

The four basic CDD questions

1. Who is the customer?

2. Who ultimately owns or controls the customer?

3. Why does the customer need the relationship?

4. Are the customer's actual transactions consistent with the expected profile?

7. Beneficial Ownership

Beneficial ownership is one of the most important international AML/CFT concepts.

A financial institution should not stop at:

Company A → owned by Company B.

It must continue examining the ownership/control chain until it identifies the relevant natural person(s) who ultimately own or control the entity.

FATF has specifically strengthened its beneficial-ownership standards and guidance in recent years. Its current Recommendations include specific requirements concerning transparency and beneficial ownership of legal persons and arrangements.

8. PEP Compliance

A Politically Exposed Person (PEP) creates enhanced corruption and bribery risk.

International AML/CFT programmes generally require enhanced controls for:

  • foreign PEPs;
  • domestic PEPs; and
  • persons associated with or related to PEPs, subject to the applicable legal framework.

Typical controls include:

  • senior management approval;
  • source of wealth;
  • source of funds;
  • enhanced monitoring;
  • continuing review.

The key point is:

PEP status is a risk factor, not automatic proof of criminal conduct.

An institution should therefore apply proportionate enhanced due diligence rather than treating PEP status itself as evidence of money laundering.

9. Correspondent Banking

Correspondent banking is one of the most significant international AML/CFT risks because one bank can provide services that enable another bank's underlying customers to access the international financial system.

FATF Recommendation 13 addresses correspondent banking.

The Wolfsberg Group's current correspondent-banking principles similarly emphasise:

  • risk-based due diligence;
  • enhanced due diligence;
  • monitoring;
  • suspicious-activity reporting;
  • ongoing review;
  • governance; and
  • integration with the broader financial-crime compliance programme. 

The Wolfsberg framework specifically notes that correspondent relationships may involve the correspondent acting as an intermediary for the respondent bank's underlying customers, which can increase risk.

10. Transaction Monitoring

An international AML/CFT programme must monitor transactions for unusual or suspicious behaviour.

Examples include:

Structuring

Multiple transactions designed to avoid reporting or monitoring thresholds.

Rapid movement of funds

Money enters an account and quickly leaves through another jurisdiction.

Layering

Multiple transactions designed to obscure the origin of funds.

Circular transactions

Funds move through multiple accounts/entities and eventually return to the originator.

Unusual cross-border transactions

Transactions inconsistent with the customer's business or geographic profile.

Pass-through activity

An account receives large amounts and transfers substantially all funds elsewhere without a reasonable economic explanation.

11. Suspicious Transaction Reporting

The international model generally requires reporting entities to report suspicious transactions to the relevant Financial Intelligence Unit (FIU).

The important principle is:

Suspicion does not require proof of the underlying crime.

An institution is generally not expected to conduct a criminal prosecution before reporting.

The institution's role is to:

detect → investigate internally → assess suspicion → report according to law → maintain confidentiality → continue monitoring where appropriate.

12. Tipping-Off

A major AML/CFT obligation is confidentiality.

Once an institution submits or is considering submitting a suspicious transaction report, employees generally cannot improperly inform the customer that:

“You have been reported to the FIU.”

This is known as tipping-off.

The purpose is obvious: informing the suspect could cause:

  • destruction of evidence;
  • movement of funds;
  • closure of accounts;
  • movement of assets to another jurisdiction;
  • obstruction of an investigation.

FATF Recommendation 21 addresses tipping-off and confidentiality.

13. Terrorist Financing — Difference from Money Laundering

This distinction is extremely important.

Money laundering

Generally involves:

Illegal proceeds → concealment/layering → integration into legitimate economy

Terrorist financing

Can involve:

Funds → terrorist activity

The money itself may be completely legitimate.

For example:

Legitimate donations → terrorist organisation.

Therefore:

AML controls that only search for criminal proceeds are insufficient for CFT.

CFT requires attention to:

  • terrorist designations;
  • sanctions;
  • suspicious networks;
  • fundraising;
  • NPO-related risks;
  • unusual transfers;
  • terrorist financing typologies.

14. Targeted Financial Sanctions

International AML/CFT compliance also overlaps with sanctions compliance.

The institution must consider applicable:

  • UN sanctions;
  • domestic sanctions;
  • regional sanctions;
  • applicable extraterritorial sanctions regimes.

FATF Recommendations 6 and 7 address targeted financial sanctions relating to terrorism and proliferation financing.

Typical controls

Customer onboarding → sanctions screening

Payment initiation → sanctions screening

Beneficiary screening → sanctions screening

Ongoing customer screening → sanctions screening

List update → rescreening

A sanctions control should also address:

  • name variations;
  • transliteration;
  • aliases;
  • ownership/control;
  • false positives;
  • escalation;
  • blocking/freezing where legally required.

15. Proliferation Financing

Modern international compliance extends beyond AML and CFT to Counter-Proliferation Financing (CPF).

The concern is financing the proliferation of:

  • nuclear;
  • chemical; or
  • biological weapons

and related delivery systems.

FATF's current framework expressly incorporates proliferation-financing risks.

Therefore, a mature international FCC programme is increasingly:

AML + CFT + CPF + Sanctions + broader Financial Crime Compliance.

16. International Information Sharing

Money laundering frequently crosses jurisdictions.

Example:

Criminal proceeds in Country A → bank in Country B → shell company in Country C → investment in Country D.

No single regulator may possess the entire picture.

International AML/CFT therefore depends on:

  • FIU-to-FIU cooperation;
  • law-enforcement cooperation;
  • supervisory cooperation;
  • mutual legal assistance;
  • extradition;
  • asset recovery;
  • information sharing.

FATF's Recommendation 40 deals with other forms of international cooperation.

17. Important Case Law

There is no single “International AML Court.” International AML/CFT principles are reflected through judgments of national courts, the Court of Justice of the European Union (CJEU), the European Court of Human Rights (ECtHR) and other jurisdictions.

Several cases are particularly useful.

Case 1 — Jyske Bank Gibraltar Ltd v Administración del Estado

CJEU, Case C-212/11, judgment 25 April 2013

This is one of the most important international AML/CFT cases involving cross-border banking and FIU reporting.

Jyske Bank Gibraltar operated in Spain under the freedom-to-provide-services regime. Spain required certain information relevant to AML/CFT to be supplied directly to the Spanish authorities.

The issue was whether such a requirement was compatible with EU rules governing financial services.

The CJEU held that EU law did not preclude the Spanish requirement where it strengthened the effectiveness of combating money laundering and terrorist financing and was proportionate.

Compliance principle

This case demonstrates:

Cross-border financial-services freedom does not eliminate AML/CFT obligations imposed to protect the financial system.

For an international bank, this means that it cannot simply say:

“Our headquarters/FIU is in another country, therefore we do not need to comply with local AML reporting requirements.”

Local requirements can apply, subject to the applicable legal framework and proportionality.

18. Case 2 — Ordre des barreaux francophones et germanophone v Conseil des Ministres

CJEU, Case C-305/05, judgment 26 June 2007

This case concerned AML obligations imposed on lawyers and the tension between:

  • AML reporting;
  • professional secrecy;
  • lawyer independence; and
  • the right to a fair trial.

The CJEU held that AML information/cooperation obligations could apply to lawyers in specified financial and real-estate transactions, while recognising the special position of lawyers when acting in the context of judicial proceedings.

Compliance principle

AML obligations are powerful, but they are not unlimited.

An AML programme must take account of:

  • legal professional privilege;
  • confidentiality;
  • fundamental rights;
  • legitimate legal representation.

This is important when a bank or financial institution obtains information through professional intermediaries.

19. Case 3 — Michaud v France

European Court of Human Rights, Application No. 12323/11, judgment 6 December 2012

This is an important human-rights case concerning AML reporting obligations imposed on lawyers.

The case involved the French requirement for lawyers to report certain suspicions in the AML framework and the relationship between that obligation and Article 8 of the European Convention on Human Rights, concerning private and family life.

The ECtHR considered the balance between:

AML/CFT public interest

and

professional confidentiality and legal privilege.

The case was decided on 6 December 2012.

Compliance principle

AML/CFT controls must be:

  • legally grounded;
  • proportionate;
  • targeted;
  • compatible with fundamental rights.

This is particularly important for multinational groups operating across jurisdictions with different privacy and professional-secrecy rules.

20. Case 4 — Luxembourg Business Registers and Sovim

CJEU, Joined Cases C-37/20 and C-601/20, judgment 22 November 2022

This is a landmark case concerning beneficial ownership transparency.

EU legislation had required beneficial ownership information to be entered in a register, with certain information accessible to the general public.

The CJEU held that the provision making such information accessible in all cases to the general public was invalid because the resulting interference with fundamental rights was neither limited to what was strictly necessary nor proportionate to the objective pursued.

Compliance principle

This case is extremely important because it demonstrates that:

AML transparency requirements must be balanced against privacy and data-protection rights.

Therefore:

“More AML information” does not automatically mean “better legal compliance.”

The institution must consider:

  • purpose;
  • necessity;
  • proportionality;
  • lawful access;
  • data protection;
  • confidentiality.

21. Case 5 — Ratzlaf v United States

U.S. Supreme Court, 510 U.S. 135 (1994)

This case concerned the U.S. Bank Secrecy Act and structuring transactions to avoid reporting requirements.

The Supreme Court held that, for the criminal offence at issue at that time, the Government had to prove that the defendant knew the structuring conduct was unlawful.

Compliance significance

The case demonstrates an important distinction between:

regulatory reporting obligations

and

criminal liability.

An AML compliance professional should never automatically equate:

unusual transaction = criminal offence.

The institution's regulatory obligation to identify/report suspicious activity is distinct from proving criminal liability.

22. Case/Enforcement Example — HSBC

Although not a traditional appellate judgment, the HSBC enforcement/DPA is one of the most important real-world international AML compliance examples.

In 2012, HSBC Holdings and HSBC Bank USA entered into a deferred prosecution agreement with the U.S. Department of Justice.

The authorities alleged serious failures including:

  • inadequate AML staffing;
  • ineffective transaction monitoring;
  • inadequate correspondent due diligence;
  • failures involving HSBC Mexico;
  • significant volumes of transactions not adequately monitored.

HSBC agreed to forfeit $1.256 billion and pay additional civil penalties.

The DOJ stated that HSBC Bank USA had failed to maintain an effective AML programme and failed to conduct appropriate due diligence concerning foreign correspondent relationships.

Compliance lesson

This case illustrates a fundamental principle:

An AML programme must work in practice, not merely exist on paper.

23. International AML/CFT Governance Model

A strong multinational institution normally needs:

Board

Responsible for:

  • risk appetite;
  • governance;
  • oversight;
  • resources.

Senior Management

Responsible for:

  • implementation;
  • escalation;
  • staffing;
  • remediation.

Group AML/CFT Function

Responsible for:

  • group standards;
  • risk methodology;
  • global controls;
  • monitoring.

Local Compliance

Responsible for:

  • jurisdiction-specific requirements;
  • local FIU reporting;
  • local regulator interaction.

First Line

Business and operations.

Second Line

Compliance/AML/CFT.

Third Line

Internal Audit.

This creates the classic:

Three Lines Model

24. Group AML Policy vs Local Law

This is a major issue for multinational companies.

Suppose:

Global AML Policy: applies worldwide.

But:

Country A law: requires certain information to be collected.

Country B privacy law: restricts transfer of that information overseas.

Country C: has additional sanctions requirements.

The institution cannot simply impose the global policy without analysing local law.

A practical hierarchy is:

Applicable law → regulator requirements → group minimum standards → risk-based enhanced controls

The group standard can normally be more stringent, but it must not violate mandatory local requirements.

25. Foreign Branches and Subsidiaries

International groups should have mechanisms ensuring AML/CFT controls operate across:

  • branches;
  • subsidiaries;
  • representative offices;
  • agents;
  • affiliates.

FATF Recommendation 18 is particularly relevant to internal controls and foreign branches/subsidiaries.

The institution should ensure:

  • consistent minimum standards;
  • group-wide risk assessment;
  • information sharing;
  • training;
  • escalation;
  • independent testing.

26. AML/CFT Programme Validation

For an international institution, validation should test:

1. Governance

Question: Who owns AML/CFT risk?

2. Enterprise Risk Assessment

Question: Are international ML/TF risks properly identified?

3. Customer Risk Rating

Question: Does the rating reflect actual risk?

4. KYC/CDD

Question: Is customer identity properly established?

5. Beneficial Ownership

Question: Is the ultimate owner/controller identified?

6. PEP Screening

Question: Are PEPs correctly identified and subjected to appropriate EDD?

7. Sanctions Screening

Question: Are customers and transactions screened against applicable lists?

8. Transaction Monitoring

Question: Can the system identify suspicious cross-border activity?

9. STR/SAR

Question: Are suspicious matters escalated and reported correctly?

10. Correspondent Banking

Question: Is respondent-bank risk adequately assessed?

11. Information Sharing

Question: Can the group legally and securely exchange AML information across jurisdictions?

12. Independent Testing

Question: Has an independent function tested whether controls actually work?

27. AML/CFT Validation — Four levels

A sophisticated international validation programme should examine four levels.

Level 1 — Policy

Does the policy comply with:

  • FATF;
  • local law;
  • regulator requirements?

Level 2 — Design

Are controls properly designed?

Level 3 — Operating Effectiveness

Do the controls actually operate?

Level 4 — Outcome Effectiveness

Are the controls actually producing the intended result?

This last level corresponds closely with the FATF emphasis on effectiveness, rather than merely technical compliance.

28. Example International AML Finding

Finding

A multinational bank's global policy requires enhanced due diligence for high-risk correspondent banks.

However:

  • Country A performs EDD;
  • Country B uses a simplified questionnaire;
  • Country C has no documented senior-management approval;
  • the global system does not capture respondent-bank risk consistently.

Risk

The group has a global policy but inconsistent implementation.

Regulatory concern

The institution may be unable to demonstrate effective implementation of its risk-based AML/CFT framework.

Recommended action

Create a minimum global control standard:

Risk classification → CDD → EDD → senior approval → transaction monitoring → periodic review → escalation → independent testing

with local add-ons where required by law.

29. International AML/CFT Compliance Checklist

AreaKey question
GovernanceIs Board oversight effective?
Risk AssessmentAre ML/TF risks identified?
KYCIs identity verified?
BOIs ultimate ownership/control established?
PEPAre PEPs appropriately identified?
SanctionsAre applicable sanctions lists screened?
CDDIs customer purpose understood?
EDDAre high-risk customers enhanced?
MonitoringAre suspicious patterns detected?
STR/SARAre reports filed appropriately?
Tipping-offIs confidentiality protected?
Correspondent BankingIs respondent risk assessed?
Cross-borderAre local laws considered?
Information SharingAre transfers legally permitted?
RecordkeepingCan evidence be retrieved?
TrainingAre employees trained?
QAIs quality assurance performed?
Independent AuditIs testing genuinely independent?
RemediationAre deficiencies closed?
EffectivenessCan the institution demonstrate results?

30. Key legal principles emerging from international case law

The cases above produce several important principles:

Principle 1 — AML/CFT is a legitimate public-interest objective

Courts generally recognise the importance of preventing financial systems from being abused for crime and terrorism.

Principle 2 — AML obligations can have cross-border effect

Jyske Bank demonstrates that cross-border financial-service activity does not necessarily prevent host-state AML requirements.

Principle 3 — AML obligations are not unlimited

Ordre des barreaux and Michaud demonstrate the importance of legal privilege, confidentiality and fair-trial considerations.

Principle 4 — Beneficial ownership transparency must respect fundamental rights

Luxembourg Business Registers/Sovim demonstrates that AML transparency must satisfy necessity and proportionality.

Principle 5 — Regulatory compliance and criminal liability are different questions

Ratzlaf demonstrates the importance of distinguishing reporting obligations from the elements required for criminal liability.

Principle 6 — Effectiveness matters

FATF's methodology explicitly places substantial emphasis on whether the AML/CFT framework actually produces effective outcomes, not simply whether laws and policies exist.

31. International AML/CFT compliance — the simplest framework

You can remember the whole subject through this model:

RISK

KYC / CDD

BENEFICIAL OWNERSHIP

PEP / SANCTIONS SCREENING

EDD

TRANSACTION MONITORING

ALERT INVESTIGATION

STR/SAR

FIU / REGULATOR / LAW-ENFORCEMENT COOPERATION

FREEZE / CONFISCATION / OTHER LEGAL ACTION WHERE APPLICABLE

INDEPENDENT TESTING

REMEDIATION

EFFECTIVENESS

That is essentially the architecture of a mature international AML/CFT programme.

Bottom line

International AML/CFT compliance is not simply FATF compliance. FATF provides the international standards; individual jurisdictions convert those standards into enforceable law; regulators supervise implementation; FIUs receive and analyse financial intelligence; and courts determine the boundaries of enforcement, privacy, privilege, proportionality and due process.

For a multinational financial institution, the strongest approach is therefore:

FATF Standards + applicable local law + sanctions requirements + risk-based controls + effective implementation + evidence + independent validation + international cooperation.

The most important modern lesson is the distinction between technical compliance and effectiveness: having policies, systems and procedures is insufficient if the institution cannot demonstrate that those controls actually identify, prevent, detect and report financial crime. FATF's fifth-round methodology expressly makes effectiveness a central part of international assessment.

LEAVE A COMMENT