One Constellation
Free Interactive Tool

Country Risk Lookup

Search any jurisdiction to see its current FATF listing status, whether it carries significant sanctions programme exposure, and what that means for the due diligence you apply.

FATF data as at 19 June 2026 No sign-up required Nothing is stored

Look up a jurisdiction

Countermeasures Call for action — EDD Increased monitoring Not listed ⚑ Significant sanctions programme exposure
How to read this. FATF listing status reflects the plenary statements published on 19 June 2026 and changes at each plenary, normally in February, June and October — always confirm against the FATF's own published statements before acting. The sanctions flag indicates that a jurisdiction is associated with significant sanctions programmes in one or more major regimes; it is a prompt to check current designations, not a statement of what is prohibited for you. FATF listing is a country risk input, not a reason to exit a customer or a class of customers: FATF expressly does not call for enhanced due diligence on grey-listed jurisdictions as a class, and warns against indiscriminate de-risking. Nothing you type here is transmitted or stored.
Interpretation

What each FATF status actually requires

The two FATF lists are routinely conflated in practice, and the difference matters because they carry different obligations. Getting this wrong in either direction creates a problem: treating the grey list as a prohibition produces unnecessary de-risking, while treating the call-for-action list as a mere risk factor leaves a genuine compliance gap.

FATF statusFormal nameWhat FATF asks forPractical response
CountermeasuresHigh-risk jurisdictions subject to a call for actionEnhanced due diligence and, for the most serious cases, countermeasuresBoard-level position on whether to do business at all; EDD and senior sign-off where you do
Call for actionHigh-risk jurisdictions subject to a call for actionEnhanced due diligence proportionate to the riskMandatory EDD, documented source of wealth and funds, senior approval
Increased monitoringJurisdictions under increased monitoring — the grey listTake the information into account in your risk analysisTreat as a geographic risk input in your matrix; escalate only where the wider profile justifies it
Not listedNothing specificApply your own country risk methodology; absence of a listing is not evidence of low risk

Why not-listed does not mean low risk

The FATF lists identify jurisdictions with strategic deficiencies in their AML frameworks. They are not a ranking of financial crime risk, and several jurisdictions with well-documented exposure to corruption, predicate offending or sanctions evasion have never appeared on either list. A country risk methodology that relies solely on FATF status will systematically under-rate those jurisdictions.

A defensible country risk model combines FATF status with sanctions programme exposure, corruption and governance indicators, tax transparency assessments, the presence of predicate offending relevant to your business, and your own experience of the jurisdiction — including your own suspicious activity reporting patterns. Weight them, document the weighting, and apply it consistently.

Where country risk actually appears in a file

  • Customer nationality and residence — including dual nationality and recently changed residence.
  • Place of incorporation — and the incorporation jurisdiction of every entity in the ownership chain, not just the applicant.
  • Beneficial owner nationality and residence — frequently different from the entity's own jurisdiction and frequently missed.
  • Source and destination of funds — including intermediary correspondent jurisdictions in the payment chain.
  • Operating footprint — where the customer actually does business, which may bear no relation to where it is registered.

The highest-risk jurisdiction anywhere in that set should drive the country risk factor in your matrix. Taking only the applicant's stated country of residence is one of the most common weaknesses supervisors find.

Country risk in the platform

Lists change. Your customer book should react.

FATF updates its lists three times a year. Sanctions designations change constantly. A country risk model that lives in a spreadsheet is out of date the moment a plenary concludes.

🌍

Maintained country data

Jurisdiction risk data is maintained centrally in the platform, so a change to a listing is reflected in scoring without anyone editing a spreadsheet.

🔔

Re-scoring on change

When a jurisdiction's status changes, every affected customer is re-scored and routed for review automatically — including customers onboarded years earlier.

🧭

Full-chain evaluation

Country risk is evaluated across the whole relationship — customer, entity, every UBO and the funds flow — rather than only the address on the application.

Questions

About country risk

What is the difference between the FATF blacklist and grey list?+
The blacklist is properly called high-risk jurisdictions subject to a call for action, and FATF asks all members to apply enhanced due diligence, with countermeasures in the most serious cases. The grey list is properly called jurisdictions under increased monitoring: these countries have committed to action plans, and FATF asks members to take the information into account in their risk analysis rather than applying enhanced due diligence to the whole class.
Which countries are on the FATF blacklist?+
As at the June 2026 plenary the call-for-action list comprises Iran, the Democratic People's Republic of Korea and Myanmar. FATF calls for countermeasures in respect of Iran and the DPRK, and enhanced due diligence in respect of Myanmar. The list is reviewed at each plenary, so confirm the current position before acting.
How often does the FATF grey list change?+
FATF reviews it at each plenary, held three times a year in February, June and October. Countries are added when strategic deficiencies are identified and removed after they complete their action plan and pass an on-site assessment. At the June 2026 plenary, Bosnia and Herzegovina and Iraq were added while Algeria and Namibia were removed, leaving 22 jurisdictions under increased monitoring.
Should we exit customers connected to grey-listed countries?+
FATF explicitly says no. Its standards do not envisage de-risking or cutting off entire classes of customers, and it asks that flows of humanitarian assistance, legitimate non-profit activity and remittances are not disrupted. Grey-list exposure is a geographic risk input to be weighed alongside the rest of the customer profile, not a decision rule.
Is the EU high-risk third country list the same as the FATF list?+
No. The EU maintains its own list of high-risk third countries, which draws heavily on FATF's assessments but is a separate legal instrument with its own additions, removals and timing. Firms subject to EU rules need to track both, and the same applies to the UK, which maintains its own equivalent schedule.
Where does country risk sit in a risk matrix?+
It is one of the three core factors FATF Recommendation 10 requires, alongside customer risk and product, service and channel risk. In practice it should be evaluated across the whole relationship — nationality, residence, incorporation, every beneficial owner, and the source and route of funds — with the highest-risk jurisdiction in that set driving the factor. Try our AML risk scoring calculator.

Country risk that updates itself

Book a 30-minute demo and see a listing change re-score an existing customer book automatically, with every affected file routed for review.

Scroll to Top