Country Risk Lookup
Search any jurisdiction to see its current FATF listing status, whether it carries significant sanctions programme exposure, and what that means for the due diligence you apply.
Look up a jurisdiction
—What each FATF status actually requires
The two FATF lists are routinely conflated in practice, and the difference matters because they carry different obligations. Getting this wrong in either direction creates a problem: treating the grey list as a prohibition produces unnecessary de-risking, while treating the call-for-action list as a mere risk factor leaves a genuine compliance gap.
| FATF status | Formal name | What FATF asks for | Practical response |
|---|---|---|---|
| Countermeasures | High-risk jurisdictions subject to a call for action | Enhanced due diligence and, for the most serious cases, countermeasures | Board-level position on whether to do business at all; EDD and senior sign-off where you do |
| Call for action | High-risk jurisdictions subject to a call for action | Enhanced due diligence proportionate to the risk | Mandatory EDD, documented source of wealth and funds, senior approval |
| Increased monitoring | Jurisdictions under increased monitoring — the grey list | Take the information into account in your risk analysis | Treat as a geographic risk input in your matrix; escalate only where the wider profile justifies it |
| Not listed | — | Nothing specific | Apply your own country risk methodology; absence of a listing is not evidence of low risk |
Why not-listed does not mean low risk
The FATF lists identify jurisdictions with strategic deficiencies in their AML frameworks. They are not a ranking of financial crime risk, and several jurisdictions with well-documented exposure to corruption, predicate offending or sanctions evasion have never appeared on either list. A country risk methodology that relies solely on FATF status will systematically under-rate those jurisdictions.
A defensible country risk model combines FATF status with sanctions programme exposure, corruption and governance indicators, tax transparency assessments, the presence of predicate offending relevant to your business, and your own experience of the jurisdiction — including your own suspicious activity reporting patterns. Weight them, document the weighting, and apply it consistently.
Where country risk actually appears in a file
- Customer nationality and residence — including dual nationality and recently changed residence.
- Place of incorporation — and the incorporation jurisdiction of every entity in the ownership chain, not just the applicant.
- Beneficial owner nationality and residence — frequently different from the entity's own jurisdiction and frequently missed.
- Source and destination of funds — including intermediary correspondent jurisdictions in the payment chain.
- Operating footprint — where the customer actually does business, which may bear no relation to where it is registered.
The highest-risk jurisdiction anywhere in that set should drive the country risk factor in your matrix. Taking only the applicant's stated country of residence is one of the most common weaknesses supervisors find.
Lists change. Your customer book should react.
FATF updates its lists three times a year. Sanctions designations change constantly. A country risk model that lives in a spreadsheet is out of date the moment a plenary concludes.
Maintained country data
Jurisdiction risk data is maintained centrally in the platform, so a change to a listing is reflected in scoring without anyone editing a spreadsheet.
Re-scoring on change
When a jurisdiction's status changes, every affected customer is re-scored and routed for review automatically — including customers onboarded years earlier.
Full-chain evaluation
Country risk is evaluated across the whole relationship — customer, entity, every UBO and the funds flow — rather than only the address on the application.
About country risk
Other free compliance tools
Country risk that updates itself
Book a 30-minute demo and see a listing change re-score an existing customer book automatically, with every affected file routed for review.
