Skip to content

Evidence request lists

FATF 40 Recommendations

Evidence request list. 16 controls, 16 carrying auditor artefact guidance. Generated from the compliance knowledge graph on 11 September 2026. Published by The Art of Service.

FATF Section A: AML/CFT Policies and Coordination (R.1-2)

FATF-Methodology
FATF Methodology - Technical Compliance and Effectiveness (Immediate Outcomes)

The FATF Methodology for Assessing Technical Compliance with the FATF Recommendations + Effectiveness of AML/CFT Systems is the assessment framework for Mutual Evaluations (currently 5th round 2020-2027 + 6th round in development for post-2027). TECHNICAL COMPLIANCE assessment: each of the 40 Recommendations is rated Compliant (C) / Largely Compliant (LC) / Partially Compliant (PC) / Non-Compliant (NC) based on the specific criteria + sub-criteria in the Methodology. EFFECTIVENESS assessment: against 11 IMMEDIATE OUTCOMES (IO.1 risk + policy + coordination + IO.2 international cooperation + IO.3 supervision + IO.4 preventive measures + IO.5 legal persons + arrangements + IO.6 financial intelligence + IO.7 ML investigation + prosecution + IO.8 confiscation + IO.9 TF investigation + prosecution + IO.10 TF preventive measures + financial sanctions + IO.11 proliferation financial sanctions).

Artefacts an auditor will ask for
  • Latest Mutual Evaluation Report ratings
  • Follow-up Reports + ICRG enhanced follow-up status
  • Country-level Technical Compliance + Effectiveness matrix
Where this commonly fails
  • Technical Compliance ratings stale (>5 years old)
  • Effectiveness Moderate / Low for IO.1-IO.11 outcomes not addressed in follow-up
  • ICRG (International Cooperation Review Group) Grey-List or Black-List status not addressed
FATF-R.1_2
Risk-Based Approach + National Cooperation (FATF R.1 and R.2)

Recommendation 1 (Risk-Based Approach): countries should identify + assess + understand their money laundering / terrorist financing risks + apply a RISK-BASED APPROACH to ensure that measures to prevent or mitigate ML/TF are commensurate with the risks identified. Countries should require financial institutions + DNFBPs to identify + assess + understand their own ML/TF risks + take action to mitigate them. The risk-based approach is the foundational principle of the entire FATF regime. National Risk Assessments (NRAs) are conducted periodically (typically every 3-5 years). Recommendation 2 (National Cooperation): countries should have national AML/CFT policies + designate authorities or coordination mechanisms to develop + implement those policies; ensure inter-agency cooperation including between policymakers + financial intelligence units (FIUs) + law enforcement + supervisors. The R.

Artefacts an auditor will ask for
  • NRA + sectoral risk assessment + entity-level risk assessment
  • Risk-mitigation policies + procedures
  • Documented inter-agency coordination + FIU + LEA + supervisor cooperation
Where this commonly fails
  • NRA not conducted or stale (>5 years old)
  • Risk-mitigation policies generic + not commensurate with identified risks
  • Inter-agency coordination informal + no documented mandate
FATF-Status
FATF 40 Recommendations - corpus status, 5th + 6th Mutual Evaluation Rounds + targeted updates

The FATF 40 Recommendations + Methodology are the global AML/CFT/CPF standard. Last comprehensive revision February 2012; subsequent TARGETED UPDATES: R.5 (Terrorist Financing) 2024; R.8 (NPO) 2023 narrowed scope to focused proportionate measures; R.15 (Virtual Assets / VASPs) 2018 + 2019 + 2024 + ongoing DeFi / NFT / stablecoin extensions; R.16 (Travel Rule) extended to VASPs 2019 + 2024 implementation reviews; R.24 (BO of Legal Persons) revised 2022; R.25 (BO of Legal Arrangements) revised 2024. The 5th Mutual Evaluation round (2020-2027) is in progress with most jurisdictions assessed by 2026-2027; the 6th round design is underway with anticipated emphasis on EFFECTIVENESS + RISK-PROPORTIONALITY + CLIMATE-RELATED FINANCIAL CRIMES + AI-AML/CFT applications + DeFi + NFTs + stablecoin issuance + cross-border interoperability of digital identity. The FATF Grey List as of mid-2025 includes

Artefacts an auditor will ask for
  • Tracking of FATF targeted updates + new Methodology
  • Monitoring of Grey List + Black List composition
  • Internal compliance program tuned to 5th + 6th round Effectiveness expectations
Where this commonly fails
  • Compliance program tied only to 2012 baseline without tracking targeted updates
  • Grey + Black List monitoring formalistic + not driving EDD
  • No internal preparation for 6th Mutual Evaluation round emphasis on Effectiveness + AI-AML/CFT + DeFi + NFTs

FATF Section B: Money Laundering and Confiscation (R.3-4)

FATF-R.3_4
ML Offence + Confiscation (FATF R.3 and R.4)

Recommendation 3 (Money Laundering Offence): countries should criminalise money laundering on the basis of the 1988 Vienna Convention + the 2000 Palermo Convention; apply the crime of ML to all serious offences with the goal of including the widest range of predicate offences (designated categories under the Glossary); the predicate-offence list includes participation in organised criminal groups + racketeering + terrorism + trafficking + corruption + bribery + fraud + counterfeiting + environmental crime + murder + kidnapping + robbery + smuggling + tax crimes + extortion + forgery + piracy + insider trading + market manipulation. Recommendation 4 (Confiscation + Provisional Measures): countries should adopt measures to enable competent authorities to freeze + seize + confiscate property laundered + proceeds of crime + instrumentalities used in ML / predicate offences; consider non-conv

Artefacts an auditor will ask for
  • National ML offence statute + predicate offence schedule
  • Confiscation + freezing-order legal framework
  • NCB confiscation regime where applicable
  • Cross-border confiscation cooperation
Where this commonly fails
  • Predicate offence list narrower than FATF designated categories
  • Confiscation limited to conviction-based (no NCB pathway)
  • Tax crimes excluded from ML predicate offences

FATF Section C: Terrorist Financing and Proliferation Financing (R.5-8)

FATF-R.5_6_7_8
Terrorist Financing + Targeted Financial Sanctions + NPO sector (FATF R.5, R.6, R.7, R.8)

Recommendation 5 (Terrorist Financing Offence): countries should criminalise terrorist financing on the basis of the 1999 Terrorist Financing Convention; criminalise the financing of terrorist organisations + individual terrorists + terrorist acts; the offence should extend to any funds collected or provided with the intention that they should be used or in the knowledge that they are to be used in full or in part by a terrorist organisation or by an individual terrorist or for terrorist acts. Recommendation 6 (Targeted Financial Sanctions - Terrorism): countries should implement TARGETED FINANCIAL SANCTIONS to comply with UN Security Council Resolutions (UNSCRs) under Chapter VII relating to the prevention + suppression of terrorism + terrorist financing (UNSCR 1267 + 1373 regimes + successor resolutions). Recommendation 7 (Targeted Financial Sanctions - Proliferation): countries should

Artefacts an auditor will ask for
  • TF criminalisation statute
  • TFS implementation framework for UNSCR 1267 + 1373
  • TFS proliferation regime for DPRK + Iran
  • NPO vulnerability assessment + focused proportionate measures avoiding humanitarian disruption
Where this commonly fails
  • TF offence does not cover financing without specific act
  • TFS implementation delayed beyond UNSCR adoption
  • NPO regulation over-broad + disrupts legitimate humanitarian activity

FATF Section D: Preventive Measures (R.9-23)

FATF-R.10_11
Customer Due Diligence + Record Keeping (FATF R.10 and R.11)

Recommendation 10 (Customer Due Diligence / CDD): financial institutions should be required to undertake CDD measures: (a) identifying the customer + verifying that customer's identity using reliable + independent source documents + data + information; (b) identifying the beneficial owner + taking reasonable measures to verify the beneficial owner's identity; (c) understanding + obtaining information on the purpose + intended nature of the business relationship; (d) conducting ongoing due diligence on the business relationship + scrutiny of transactions throughout the course of that relationship to ensure that the transactions being conducted are consistent with the institution's knowledge of the customer + the customer's business + risk profile. CDD applies to new + existing customers + occasional transactions above the designated threshold + wire transfers + suspicions of ML/TF + doubt

Artefacts an auditor will ask for
  • CDD policy + procedure
  • BO-identification + verification evidence
  • Ongoing-due-diligence transaction monitoring
  • 5-year + 10-year record-retention policy
Where this commonly fails
  • CDD limited to identification without ongoing due diligence
  • BO identification skipped or limited to a single tier
  • Record retention shorter than 5 years
  • Transaction monitoring tuned for compliance metric rather than ML/TF risk
FATF-R.12_13
Politically Exposed Persons (PEPs) + Correspondent Banking (FATF R.12 and R.13)

Recommendation 12 (Politically Exposed Persons / PEPs): financial institutions should be required to: (a) have appropriate risk-management systems to determine whether a customer or beneficial owner is a PEP - foreign + domestic + international organisation; (b) obtain senior management approval for establishing + continuing business relationships with foreign PEPs + their family members + close associates; (c) take reasonable measures to establish source of wealth + source of funds; (d) conduct enhanced ongoing monitoring of the business relationship; (e) apply enhanced due diligence to family members + close associates of foreign PEPs. For domestic PEPs + international organisation PEPs the EDD applies where the business relationship is higher-risk. Recommendation 13 (Correspondent Banking): financial institutions should be required to gather sufficient information about a respondent i

Artefacts an auditor will ask for
  • PEP screening tool + risk-management procedure
  • Source-of-wealth + source-of-funds documentation
  • Senior-management approval records for foreign PEPs
  • Correspondent banking EDD records + senior-management approval
Where this commonly fails
  • PEP screening limited to foreign PEPs + ignoring domestic + IO PEPs
  • Source-of-wealth verification superficial
  • Correspondent banking established without EDD or senior-management approval
FATF-R.14_15_16
Money or Value Transfer Services + New Technologies + Wire Transfers (FATF R.14, R.15, R.16)

Recommendation 14 (Money or Value Transfer Services / MVTS): countries should require MVTS providers (formal + informal hawala + hundi networks) to be LICENSED OR REGISTERED + subject to effective systems for monitoring + ensuring compliance with the AML/CFT obligations. Recommendation 15 (New Technologies + Virtual Assets / Virtual Asset Service Providers / VASPs) - REVISED 2018 + 2024 TARGETED UPDATES: countries + financial institutions should identify + assess the ML/TF risks that may arise from the development of new products + new business practices + the use of new or developing technologies for both new + pre-existing products. Countries should ensure that VIRTUAL ASSET SERVICE PROVIDERS (VASPs) - covering centralised exchanges + custodial wallet providers + ICO issuers + DeFi protocols where appropriate + NFT issuers where applicable - are LICENSED OR REGISTERED + subject to AML/

Artefacts an auditor will ask for
  • MVTS licence / registration
  • VASP licence / registration + AML/CFT compliance
  • Travel Rule implementation for wire transfers + VASP transfers above threshold
  • New-technology risk assessment cycle
Where this commonly fails
  • Unlicensed MVTS / hawala networks
  • Crypto exchange or DeFi protocol operating without VASP license
  • Travel Rule incomplete for cross-jurisdictional virtual asset transfers (the 'sunrise problem' before global implementation)
FATF-R.17_18_19
Reliance on Third Parties + Internal Controls + Higher-Risk Countries (FATF R.17, R.18, R.19)

Recommendation 17 (Reliance on Third Parties): countries may permit financial institutions to RELY on third parties to perform elements of CDD (R.10 + R.11 elements (a) (b) (c)) provided that: the institution relying on the third party immediately obtains the necessary CDD information; takes adequate steps to satisfy itself that the third party will provide CDD records on request; the third party is regulated + supervised + monitored for + has measures in place for compliance with FATF Recommendations 10-11. THE ULTIMATE RESPONSIBILITY REMAINS WITH THE FINANCIAL INSTITUTION RELYING ON THE THIRD PARTY. Recommendation 18 (Internal Controls + Foreign Branches and Subsidiaries): financial institutions should implement AML/CFT internal controls including (a) compliance management arrangements; (b) screening procedures for personnel hiring; (c) ongoing employee training; (d) independent audit

Artefacts an auditor will ask for
  • Third-party reliance procedure + due diligence on relied-upon parties
  • Internal AML/CFT controls + training + audit
  • FATF Grey + Black List screening + EDD for relevant countries
Where this commonly fails
  • Third-party reliance without verification that the third party is regulated + supervised
  • Foreign branches / subsidiaries with weaker AML/CFT than home-country
  • FATF Grey List jurisdictions not flagged + EDD not applied
FATF-R.20_21_22_23
Reporting of Suspicious Transactions + Tipping-Off + DNFBPs (FATF R.20, R.21, R.22, R.23)

Recommendation 20 (Reporting of Suspicious Transactions): if a financial institution suspects or has reasonable grounds to suspect that funds are the proceeds of a criminal activity or are related to terrorist financing, it should be required by law to REPORT PROMPTLY its suspicions to the Financial Intelligence Unit (FIU) - the Suspicious Transaction Report (STR). Recommendation 21 (Tipping-Off + Confidentiality): financial institutions + their directors + officers + employees should be: (a) PROTECTED BY LAW from criminal + civil liability for disclosure if they report their suspicions in good faith to the FIU even if they did not know precisely what the underlying criminal activity was - the 'safe harbour' rule; (b) PROHIBITED BY LAW from disclosing ('tipping-off') the fact that an STR or related information is being filed with the FIU. Recommendation 22 (DNFBPs - Designated Non-Financ

Artefacts an auditor will ask for
  • STR-filing procedure with prompt-reporting workflow
  • Tipping-off training for staff
  • DNFBP-sector AML/CFT compliance programme
  • Real estate + lawyers + accountants + TCSPs + casinos CDD coverage
Where this commonly fails
  • STR-filing delayed + not 'prompt'
  • Tipping-off occurring through informal disclosure to the customer
  • DNFBP sectors (lawyers + notaries) invoking professional secrecy without proper AML/CFT carve-out
FATF-R.9
Financial Institution Secrecy Laws (FATF R.9)

Recommendation 9 (Financial Institution Secrecy Laws): countries should ensure that financial institution secrecy laws DO NOT INHIBIT IMPLEMENTATION of the FATF Recommendations; the bank-secrecy regime in any jurisdiction must give way to AML/CFT obligations including: customer due diligence (CDD); suspicious transaction reporting (STR); information sharing with the FIU; supervisor access to information; cross-border information exchange. R.9 is the foundational rule that the bank-secrecy regimes of certain jurisdictions (historically Switzerland + Luxembourg + Singapore + Cayman + Bermuda + others) cannot block AML/CFT implementation - the bank-secrecy regime must yield to AML/CFT obligations + the international cooperation framework.

Artefacts an auditor will ask for
  • Legal framework establishing AML/CFT primacy over bank-secrecy
  • FIU + supervisor + LEA information-access procedures
  • Cross-border information-exchange protocols
Where this commonly fails
  • Bank-secrecy law treated as preserving confidentiality beyond AML/CFT carve-outs
  • Cross-border information exchange limited by bank-secrecy invocation

FATF Section E: Transparency and Beneficial Ownership of Legal Persons and Arrangements (R.24-25)

FATF-R.24_25
Transparency and Beneficial Ownership of Legal Persons and Legal Arrangements (FATF R.24 and R.25)

Recommendation 24 (Transparency + Beneficial Ownership of LEGAL PERSONS) - REVISED 2022: countries should ensure that there is adequate + accurate + up-to-date information on the beneficial ownership + control of legal persons (companies + foundations + Anstalten + partnerships etc.) that can be obtained or accessed in a timely manner by competent authorities. Countries should require legal persons to obtain + hold beneficial ownership information + ensure that such information is held at a CENTRAL or other LOCATION known to the competent authorities (the BO REGISTER architecture). The 2022 revision tightened the obligation: countries should now MAINTAIN A REGISTRY OF BENEFICIAL OWNERSHIP for all legal persons OR an ALTERNATIVE MECHANISM that delivers equivalent outcomes. Recommendation 25 (Transparency + Beneficial Ownership of LEGAL ARRANGEMENTS) - REVISED 2024: countries should ensure

Artefacts an auditor will ask for
  • BO Register central or equivalent mechanism
  • BO data quality + verification + update process
  • Trustee due diligence + disclosure regime
Where this commonly fails
  • BO data outdated or unverified
  • Trust + Anstalt + fiducie BO disclosure gaps
  • Cross-border BO request response times non-compliant

FATF Section F: Powers and Responsibilities of Competent Authorities and Other Institutional Measures (R.26-35)

FATF-R.26_27_28
Regulation and Supervision of Financial Institutions + Powers of Supervisors + DNFBPs (FATF R.26, R.27, R.28)

Recommendation 26 (Regulation + Supervision of Financial Institutions): countries should ensure that financial institutions are subject to ADEQUATE REGULATION + SUPERVISION + are effectively implementing the FATF Recommendations + that the supervisors apply the Core Principles for Effective Banking Supervision in a risk-sensitive manner. Recommendation 27 (Powers of Supervisors): supervisors should have adequate powers to (a) compel production of any information relevant to monitoring compliance; (b) impose adequate sanctions for failure to comply; (c) the powers should include the authority to inspect; (d) the supervisor should also have powers in respect to compliance with AML/CFT requirements + including fit-and-proper criteria for owners + senior managers + controllers. Recommendation 28 (Regulation + Supervision of DNFBPs): casinos should be subject to a comprehensive regulatory + s

Artefacts an auditor will ask for
  • FI AML/CFT supervision framework
  • Supervisory powers + sanctions records
  • DNFBP supervision arrangements + SRO oversight
Where this commonly fails
  • FI AML/CFT supervision risk-insensitive or formalistic
  • Supervisor lacking effective sanctioning powers
  • DNFBP supervision delegated to SRO without effective oversight
FATF-R.29
Financial Intelligence Units / FIUs (FATF R.29)

Recommendation 29 (Financial Intelligence Units): countries should establish a Financial Intelligence Unit (FIU) that serves as a national centre for the (a) RECEIPT + ANALYSIS of (i) suspicious transaction reports (STRs) + (ii) other information relevant to ML / associated predicate offences + TF + (b) DISSEMINATION of the results of that analysis. The FIU should be able to obtain ADDITIONAL information from reporting entities + have access on a timely basis to the financial + administrative + law enforcement information that it requires to undertake its functions properly. FIUs should be OPERATIONALLY INDEPENDENT + AUTONOMOUS + have adequate resources + be able to engage independently with their counterparts (the Egmont Group cooperation framework). The 165+ FIUs participating in the Egmont Group of Financial Intelligence Units form the operational backbone of international AML/CFT coo

Artefacts an auditor will ask for
  • FIU operational autonomy evidence
  • Egmont Group membership
  • FIU operational metrics (STRs received / analysed / disseminated)
Where this commonly fails
  • FIU operationally subordinated to law enforcement or supervisor without operational autonomy
  • FIU lacking timely access to financial + LEA + administrative information
FATF-R.30_31_32_33_34_35
Law Enforcement Powers + Cash Couriers + Statistics + Guidance + Sanctions (FATF R.30-R.35)

Recommendation 30 (Responsibilities of Law Enforcement + Investigative Authorities): countries should designate competent law enforcement authorities + ensure that they have responsibilities to pursue ML + predicate offences + TF investigations within the framework of national AML/CFT policies. Recommendation 31 (Powers of LEA): LEA should have powers to obtain information for use in investigations + prosecutions + including: production orders + search of persons + premises + records + records of communications + financial records + computer + digital records. Recommendation 32 (Cash Couriers): countries should have measures in place to detect + restrain + confiscate the physical cross-border transportation of currency + bearer negotiable instruments through declaration + disclosure systems at borders. Recommendation 33 (Statistics): countries should maintain comprehensive statistics on

Artefacts an auditor will ask for
  • LEA powers + cross-border cooperation
  • Cash courier declaration + disclosure system
  • AML/CFT statistics
  • Sanctions regime
Where this commonly fails
  • LEA powers fragmented across multiple agencies without coordination
  • Cash courier declaration limited to currency + excluding bearer negotiable instruments
  • Sanctions effective + proportionate + dissuasive criteria not met

FATF Section G: International Cooperation (R.36-40)

FATF-R.36_37_38_39_40
International Cooperation (FATF R.36-R.40)

Recommendation 36 (International Instruments): countries should take immediate steps to become party to + implement fully the relevant international instruments: the Vienna Convention 1988 + the Palermo Convention 2000 + the Merida Convention 2003 (UNCAC) + the Terrorist Financing Convention 1999 + the Council of Europe Conventions. Recommendation 37 (Mutual Legal Assistance / MLA): countries should rapidly + constructively + effectively provide the widest possible range of MLA in relation to ML + associated predicate offences + TF investigations + prosecutions + related proceedings; provide MLA on the basis of a request for non-coercive measures + applicable in ML cases + based on dual criminality. Recommendation 38 (MLA - Freezing + Confiscation): countries should ensure that they have authority to take expeditious action in response to requests by foreign countries to identify + freez

Artefacts an auditor will ask for
  • MLA framework + treaty network
  • Cross-border freezing + confiscation procedures
  • Extradition framework
  • Egmont + Interpol + Europol + FATF Network cooperation evidence
Where this commonly fails
  • MLA response times slow
  • Dual-criminality interpretation overly restrictive
  • Extradition political + national-interest exceptions broad
Assembled from the framework's own control set. Every line traces to a control in the graph, so this pack is regenerated rather than written, and stays current as the graph does.

Assembled from the framework’s own control set, so this list is regenerated rather than written and stays current as the graph does. See the FATF 40 Recommendations framework page.