A practical reminder that AML compliance must evolve with changing international risk indicators.
Quick Take
The Financial Action Task Force (FATF) has released the outcomes of its June 2026 Plenary, confirming updates to its list of jurisdictions under increased monitoring, commonly known as the FATF Grey List.
Following the June 2026 update, Bosnia and Herzegovina and Iraq have been added to the Grey List, while Algeria and Namibia have been removed.
There were no changes to the FATF list of High-Risk Jurisdictions Subject to a Call for Action, commonly referred to as the Black List. The jurisdictions currently listed remain DPRK, Iran, and Myanmar.
For regulated businesses, these updates are not simply international announcements. They may directly affect customer risk assessments, onboarding procedures, country-risk classifications, ongoing monitoring, and internal AML/CFT controls.
What Is the FATF Grey List?
The FATF Grey List identifies jurisdictions that are actively working with the FATF to address strategic deficiencies in their Anti-Money Laundering, Counter-Terrorist Financing, and Counter-Proliferation Financing frameworks.
A Grey List designation does not mean that businesses are prohibited from dealing with customers, counterparties, or transactions connected to those jurisdictions.
It means that the jurisdiction should be considered as part of the business’s wider risk assessment.
In simple terms, the Grey List is a risk indicator.
It should not automatically lead to refusal, termination, or Enhanced Due Diligence in every case. Instead, businesses should assess the full customer profile, the nature of the relationship, the source of funds, transaction patterns, and any relevant country-risk exposure.
What Changed in June 2026?
Following the FATF June 2026 Plenary:
Added to the FATF Grey List
Bosnia and Herzegovina
Iraq
Removed from the FATF Grey List
Algeria
Namibia
High-Risk Jurisdictions Subject to a Call for Action
No change was announced.
The jurisdictions remain:
DPRK
Iran
Myanmar
Why This Matters for Businesses
FATF updates are important because they can influence how financial institutions, Designated Non-Financial Businesses and Professions, Virtual Asset Service Providers, and other regulated businesses assess country risk.
A customer connected to a newly listed jurisdiction may require a review of the business relationship.
This does not necessarily mean the customer becomes high risk automatically.
However, it may require the business to ask important questions:
Is the customer connected to a newly listed jurisdiction?
Does the customer have ownership, control, source of wealth, or transaction exposure linked to that jurisdiction?
Does the existing customer risk rating remain appropriate?
Are the current due diligence documents still sufficient?
Should ongoing monitoring be enhanced for that relationship?
Has the internal country-risk list been updated?
These questions help businesses apply a risk-based approach rather than a blanket approach.
What Businesses Should Review Now
Following any FATF update, businesses should consider reviewing their AML/CFT framework to ensure it remains current and defensible.
Key areas to review include:
Customer Risk Assessment methodology.
Country-risk classification lists used during onboarding.
Existing customers and business relationships connected to newly listed jurisdictions.
Customer risk ratings where there is exposure to Bosnia and Herzegovina or Iraq.
Internal AML/CFT policies and procedures.
Enhanced Due Diligence triggers and escalation rules.
Ongoing monitoring processes.
Screening and transaction-monitoring controls.
Internal training materials for compliance and client-facing teams.
Compliance documentation and audit trail.
Keeping these records updated helps demonstrate that the business is actively monitoring regulatory developments and maintaining a living compliance framework.
A Risk-Based Approach Remains Essential
One of the most important points is that Grey List inclusion should not be treated as an automatic decision-making tool.
It should be considered alongside the customer’s full risk profile.
For example, a customer with a limited and transparent connection to a Grey List jurisdiction may not require the same level of review as a customer with complex ownership structures, unexplained source of wealth, unusual transaction activity, or high-value cross-border exposure.
The objective is not to de-risk blindly.
The objective is to understand the risk, document the assessment, and apply controls that are proportionate to the facts.
Why Proactive Compliance Matters
AML compliance is not a one-time exercise.
International risks evolve. FATF publications change. Regulatory expectations develop. Customer profiles also change over time.
Businesses that regularly review FATF updates and align their internal policies accordingly are usually better prepared for inspections, audits, banking queries, and regulatory reviews.
A well-maintained compliance framework shows that the business is not only aware of international developments, but is also actively responding to them.
Dawia’s Takeaway
FATF updates should not be viewed simply as changes to an international list.
They are practical risk signals that help businesses assess whether their AML/CFT framework remains appropriate, current, and aligned with evolving international standards.
At Dawia, we assist businesses in reviewing Customer Risk Assessments, AML/CFT policies, country-risk methodologies, Enhanced Due Diligence procedures, onboarding controls, and ongoing monitoring processes.
Effective compliance is not only about knowing what has changed.
It is about ensuring that internal systems, documents, and decisions evolve with those changes.