Connect with us

Insights

Financial Action Task Force Identifies Jurisdictions with Anti-Money Laundering, Combating the Financing of Terrorism, and Counter-Proliferation Deficiencies

Published

on

WASHINGTON—The Financial Crimes Enforcement Network (FinCEN) is informing U.S. financial institutions that the Financial Action Task Force (FATF), an intergovernmental body that establishes international standards for anti-money laundering, countering the financing of terrorism, and countering the financing of proliferation of weapons of mass destruction (AML/CFT/CPF), issued an additional public statement at the conclusion of its plenary meeting this month reiterating how the Russian Federation’s war of aggression against Ukraine continues to run counter to FATF’s principles, and, thus, the suspension of the membership of the Russian Federation continues to stand.[1] The FATF highlighted the potential risks to the international financial system, including growing financial connectivity of Russia with the Democratic People’s Republic of Korea (DPRK) and Iran, and risks of proliferation financing, malicious cyber activities, and ransomware attacks. In order to protect the international financial system, the FATF continues to urge all jurisdictions to remain vigilant to these risks.[2]

The FATF also updated its lists of jurisdictions with strategic AML/CFT/CPF deficiencies.[3] U.S. financial institutions should consider the FATF’s stance toward these jurisdictions when reviewing their obligations and risk-based policies, procedures, and practices.[4]

On February 23, 2024, the FATF added Kenya and Namibia to its list of Jurisdictions Under Increased Monitoring and removed Barbados, Gibraltar, Uganda, and the United Arab Emirates from that list.

The FATF’s list of High-Risk Jurisdictions Subject to a Call for Action remains the same, with Iran, DPRK, and Burma subject to calls for action. Iran and DPRK are still subject to the FATF’s countermeasures, while Burma is still subject to the application of enhanced due diligence, but not countermeasures.[5]

As part of the FATF’s listing and monitoring process to ensure compliance with its international standards, the FATF issued two statements: (1) Jurisdictions Under Increased Monitoring, which publicly identifies jurisdictions with strategic deficiencies in their AML/CFT/CPF regimes that have committed to, or are actively working with, the FATF to address those deficiencies in accordance with an agreed upon timeline; and (2) High-Risk Jurisdictions Subject to a Call for Action, which publicly identifies jurisdictions with significant strategic deficiencies in their AML/CFT/CPF regimes and calls on all FATF members to apply enhanced due diligence, and, in the most serious cases, apply countermeasures to protect the international financial system from the money laundering, terrorist financing, and proliferation financing risks emanating from the identified countries.

Jurisdictions Under Increased Monitoring

With respect to the FATF-identified Jurisdictions Under Increased Monitoring, U.S. covered financial institutions are reminded of their obligations to comply with the due diligence obligations for foreign financial institutions (FFI) under 31 CFR § 1010.610(a) in addition to their general obligations under 31 U.S.C. § 5318(h) and its implementing regulations. As required under 31 CFR § 1010.610(a), covered financial institutions should ensure that their due diligence programs, which address correspondent accounts maintained for FFIs, include appropriate, specific, risk-based, and, where necessary, enhanced policies, procedures, and controls that are reasonably designed to detect and report known or suspected money laundering activity conducted through or involving any correspondent account established, maintained, administered, or managed in the United States. Furthermore, money services businesses (MSBs) have parallel requirements with respect to foreign agents or foreign counterparties, as described in FinCEN Interpretive Release 2004-1, which clarifies that the AML program regulation requires MSBs to establish adequate and appropriate policies, procedures, and controls commensurate with the risk of money laundering and the financing of terrorism posed by their relationship with foreign agents or foreign counterparties. Additional information on these parallel requirements (covering both domestic and foreign agents and foreign counterparts) may be found in FinCEN’s Guidance on Existing AML Program Rule Compliance Obligations for MSB Principals with Respect to Agent Monitoring. Such reasonable steps should not, however, put into question a financial institution’s ability to maintain or otherwise continue appropriate relationships with customers or other financial institutions, and should not be used as the basis to engage in wholesale or indiscriminate de-risking of any class of customers or financial institutions. Financial institutions should also refer to previous interagency guidance on providing services to foreign embassies, consulates, and missions.

The United Nations (UN) continues to adopt several resolutions implementing economic and financial sanctions. Member States are bound by the provisions of these UN Security Council Resolutions (UNSCRs), and certain provisions of these resolutions are especially relevant to financial institutions. Financial institutions should be familiar with the requirements and prohibitions contained in relevant UNSCRs. In addition to UN sanctions, the U.S. Government maintains a robust sanctions program. For a description of current Office of Foreign Assets Control (OFAC) sanctions programs, please consult OFAC’s Sanctions Programs and Country Information.

High-Risk Jurisdictions Subject to a Call for Action

With respect to the FATF-identified High-Risk Jurisdictions Subject to a Call for Action, Burma remains in this category and the FATF urges jurisdictions to apply enhanced due diligence proportionate to the risks. As a general matter, FinCEN advises U.S. financial institutions to apply enhanced due diligence when maintaining correspondent accounts for foreign banks operating under a banking license issued by a country designated by an intergovernmental group or organization of which the United States is a member, as noncooperative with respect to international anti-money laundering principles or procedures, and with which designation the U.S. representative to the group or organization concurs.[6] U.S. financial institutions should continue to consult existing FinCEN and OFAC guidance on engaging in financial transactions with Burma.[7]

With respect to the FATF-identified High-Risk Jurisdictions Subject to a Call for Action, specifically, countermeasures, in the case of DPRK and Iran, U.S. financial institutions must comply with the extensive U.S. restrictions and prohibitions against opening or maintaining any correspondent accounts, directly or indirectly, for North Korean or Iranian financial institutions. Existing U.S. sanctions and FinCEN regulations already prohibit any such correspondent account relationships.

The Government of Iran and Iranian financial institutions remain persons whose property and interests in property are blocked under E.O. 13599 and section 560.211 of the Iranian Transactions and Sanctions Regulations (ITSR), 31 CFR Part 560. U.S. financial institutions and other U.S. persons continue to be broadly prohibited under the ITSR from engaging in transactions or dealings with Iran, the Government of Iran, and Iranian financial institutions, including opening or maintaining correspondent accounts for Iranian financial institutions. These sanctions impose obligations on U.S. persons that go beyond the relevant FATF recommendations. In addition to OFAC-administered sanctions, on October 25, 2019, FinCEN found Iran to be a Jurisdiction of Primary Money Laundering Concern and issued a final rule, pursuant to Section 311 of the USA PATRIOT Act, imposing the fifth special measure available under Section 311. This rule prohibits U.S. financial institutions from opening or maintaining correspondent accounts for, or on behalf of, an Iranian financial institution, and the use of foreign financial institutions’ correspondent accounts at covered United States financial institutions to process transactions involving Iranian financial institutions (31 CFR § 1010.661).

For jurisdictions removed from the FATF listing and monitoring process, U.S. financial institutions should take the FATF’s decisions and the reasons behind the delisting into consideration when assessing risk, consistent with financial institutions’ obligations under 31 CFR § 1010.610(a) and 31 CFR § 1010.210.

If a financial institution knows, suspects, or has reason to suspect that a transaction involves funds derived from illegal activity or that a customer has otherwise engaged in activities indicative of money laundering, terrorist financing, or other violation of federal law or regulation, the financial institution must file a Suspicious Activity Report.

***

Questions or comments regarding the contents of this release should be addressed to the FinCEN Regulatory Support Section at [email protected].

Continue Reading

Insights

Navigating Sovereign Data Residency Mandates in the Age of AI

Published

on

Navigating sovereign data residency mandates

A critical strategic insight shaping global enterprise operations on July 21, 2026, is the mounting friction between seamless global cloud computing and strict sovereign data residency mandates. As nations worldwide enforce comprehensive digital privacy laws, localized data storage rules, and critical infrastructure protection standards, multinational corporations can no longer rely on centralized, single-region cloud architectures. Instead, forward-thinking organizations are adopting a strategy of deliberate digital decoupling—building modular IT frameworks that comply with local data sovereignty laws while preserving global operational connectivity.

This structural shift toward digital sovereignty is driven by heightened geopolitical awareness and assertive regulatory oversight. Sovereign governments are prioritizing national data security, requiring sensitive citizen information, financial transactions, and proprietary technological data to remain physically hosted within national borders. Consequently, storing multi-national corporate data within a single centralized cloud repository exposes enterprises to severe legal liabilities, regulatory fines, and operational disruption if cross-border data transfer agreements stall.

Navigating this fragmented landscape requires C-suite leaders to re-architect enterprise IT infrastructure. Progressive organizations are replacing monolithic cloud setups with multi-region, sovereign cloud topologies. By utilizing localized edge computing hubs and automated compliance routing, companies ensure that regional data remains strictly bounded within local jurisdictions while anonymized operational metrics aggregate smoothly into primary strategic dashboards.

Ultimately, proactive digital decoupling should be embraced as a strategic market enabler rather than an administrative burden. Organizations that construct flexible, sovereign-compliant digital architectures can expand into international markets seamlessly, earn regional regulatory trust, and maintain unbroken business continuity amidst changing global trade and technology policies.

Continue Reading

Insights

The Strategic Imperative of Digital Decoupling: Balancing Innovation with Data Sovereignty

Published

on

Balancing Innovation with Data Sovereignty

An insightful analysis of the global business landscape in July 2026 reveals a profound structural tension: the conflict between seamless global cloud integration and sovereign data protection regulations. As nations enforce strict data residency laws, localized privacy mandates, and critical infrastructure protection frameworks, multinational enterprises can no longer operate under a single, unified global IT architecture. Instead, forward-thinking organizations are adopting a strategy of intentional ‘digital decoupling’—architecting modular IT environments that comply with regional sovereign regulations while preserving core global interoperability.

This shift toward digital sovereignty is driven by increasing geopolitical friction and growing regulatory enforcement. Governments worldwide are prioritizing domestic data control, requiring sensitive corporate data, financial transactions, and citizen information to reside physically and legally within national borders. Consequently, relying on centralized global cloud data centers introduces severe regulatory exposure and legal non-compliance risks that can stall international business operations.

Navigating this fragmented regulatory landscape requires business leaders to re-imagine enterprise architecture. Strategic leaders are moving away from monolithic cloud dependencies toward multi-region, sovereign cloud topologies. By leveraging localized edge computing, regional data hubs, and automated compliance routing, companies ensure that regional data remains strictly bounded within local jurisdictions while aggregated, anonymized operational metrics feed into global strategic dashboards.

Ultimately, intentional digital decoupling should not be viewed as an operational hurdle, but as a strategic competitive advantage. Organizations that proactively build compliance flexibility into their digital infrastructure will navigate international expansion seamlessly, earn deeper trust from regional regulators and consumers, and withstand abrupt geopolitical changes without suffering catastrophic operational disruptions.

Continue Reading

Insights

The Productivity Paradox of 2026: Re-aligning Human Agency in Automated Workflows

Published

on

Re-aligning Human Agency in Automated Workflows

As enterprise deployment of automated tools and specialized software agents reaches near-universal saturation in mid-2026, corporate leadership is confronting a subtle yet critical management challenge: the modern ‘productivity paradox.’ While initial technical implementation promised exponential output growth, recent organizational data indicates that unfiltered automation without deliberate workflow design often leads to operational fragmentation, cognitive fatigue, and diminishment of critical strategic decision-making across teams.

The root cause of this paradox lies in the uncoordinated proliferation of automated processes. When individual departments deploy autonomous software tools independently, the aggregate volume of system alerts, automated updates, and computer-generated reporting increases exponentially. Employees spend excessive working hours reviewing, filtering, and managing automated outputs rather than executing high-value strategic thinking. Furthermore, over-reliance on automated synthesis can degrade foundational domain expertise, leaving junior professionals ill-equipped to handle complex operational edge cases when systems fail.

To resolve this friction, progressive organizational theorists and senior executives are championing the concept of ‘human-in-the-loop agency.’ Rather than delegating complete end-to-end process control to software platforms, leading organizations are establishing clear boundaries for automated execution. Automation is assigned to routine data collection, initial synthesis, and standard pattern recognition, while qualitative evaluation, strategic risk interpretation, and final ethical approval remain strictly anchored to experienced human professionals.

Achieving sustained productivity gains in late 2026 requires continuous organizational auditing and deliberate workflow simplification. Corporate leaders must measure productivity not by the sheer volume of automated task output, but by meaningful strategic business outcomes. Empowering human talent with focused, contextual automated support—rather than drowning teams in continuous digital noise—represents the true path to sustainable operational excellence.

Continue Reading

Trending