By NHI Mgmt Group Editorial TeamBased on SumSub: “FATF: Iraq and Bosnia & Herzegovina on Grey List as Algeria and Namibia Removed” (June 23, 2026)

TL;DR: FATF has added Iraq and Bosnia and Herzegovina to its grey list while removing Algeria and Namibia, highlighting how AML/CFT supervision, beneficial ownership transparency, sanctions-evasion controls, and suspicious transaction reporting remain the operational levers, according to SumSub. Grey-listing is a governance test, not a blanket customer exclusion decision, and practitioners should treat it as a signal to tighten risk-based controls rather than default to indiscriminate de-risking.


At a glance

What this is: This is a brief analysis of FATF’s June 2026 grey-list changes and the AML governance controls they put under pressure.

Why it matters: It matters because compliance teams must translate country-level monitoring into risk-based screening decisions without overcorrecting into indiscriminate customer exits.


Context

Grey listing is a Financial Action Task Force monitoring status, not a verdict that every customer, transaction, or counterparty linked to a jurisdiction must be treated as high risk. The governance challenge is deciding which controls should tighten, by how much, and under what evidence.

For AML, CFT, and sanctions teams, the article points to the operating layer that matters most: risk assessment, beneficial ownership visibility, suspicious transaction reporting, and supervision quality. The question is not whether to respond, but how to make the response proportionate to the actual exposure.

Iraq’s return to the grey list also shows that remediation is not a one-time event. Jurisdictions can move back into increased monitoring when control frameworks fail to hold, which makes continuous governance more useful than static country lists.


Key questions

Q: What breaks when grey-listing is treated like a blanket de-risking order?

A: Blanket de-risking turns a monitoring signal into an exit decision and removes the nuance AML programmes need. It can push teams to overblock low-risk activity while missing the actual controls that need tightening, such as ownership checks, transaction monitoring, and escalation thresholds. Grey-listing should change scrutiny, not replace judgement.

Q: Why do grey-listed jurisdictions create higher AML and sanctions risk?

A: Grey-listed jurisdictions often point to weaker supervision, incomplete ownership transparency, and less reliable suspicious transaction reporting. That combination makes it easier for illicit actors to route funds through entities or intermediaries without immediate detection. The risk is not the label alone but the control gaps the label signals.

Q: How can compliance teams tell if risk-based screening is working?

A: Risk-based screening is working when high-risk relationships receive deeper review without triggering unnecessary friction for ordinary customers. Teams should see clearer escalation decisions, better ownership visibility, and fewer false positives from geography-only rules. If every grey-list hit gets the same treatment, the model is too blunt.

Q: When should institutions tighten controls after FATF grey-list changes?

A: Institutions should tighten controls as soon as the monitoring status is confirmed, but only in proportion to the exposure. That usually means reviewing high-risk counterparties, payment corridors, beneficial ownership data, and sanctions-evasion scenarios first. The aim is faster risk calibration, not automatic customer exclusion.


Technical breakdown

How grey-listing changes AML screening logic

Grey-listing places a jurisdiction under increased monitoring because its AML/CFT controls need remediation, but it does not automatically mean every linked relationship is prohibited or should be de-risked. In practice, this turns the screening problem from a binary country flag into a control-calibration problem. Institutions still need customer due diligence, sanctions screening, transaction monitoring, and risk scoring, but the intensity should reflect the actual exposure, product, and counterparty context. The key technical point is that grey-listing is a governance signal, not an identity decision in itself.

Practical implication: tune screening rules to risk indicators and documented evidence, not to a reflexive jurisdiction-wide cutoff.

Why beneficial ownership and suspicious transaction reporting matter here

The article puts beneficial ownership transparency and suspicious transaction reporting at the center of AML governance because opaque control of entities and weak reporting are exactly where illicit finance hides. Beneficial ownership data helps resolve who ultimately controls a customer, while suspicious transaction reporting gives investigators a structured path to escalate patterns that automation alone will miss. When either control is weak, screening can look complete on paper while real risk remains buried in entity structures, intermediaries, or transaction chains.

Practical implication: verify that beneficial ownership data is current, usable, and actually feeding monitoring logic and escalation workflows.

What sanctions-evasion controls add to grey-list governance

Sanctions-evasion controls matter because grey-listed jurisdictions can become routing points for attempts to mask prohibited flows through third parties, shell entities, or indirect payment paths. That does not make every transaction suspicious, but it does raise the importance of linkage analysis across counterparties, payment corridors, and ownership chains. The governance task is to detect indirect exposure, not simply match a country name. In other words, the screening model has to see through the structure of the transaction, not just the geography attached to it.

Practical implication: test whether your monitoring can trace indirect exposure through owners, intermediaries, and payment routes, not just direct country references.


Threat narrative

Attacker objective: The objective is to move or disguise illicit funds while avoiding detection, reporting, or sanctions controls.

  1. Entry occurs when illicit actors exploit weak AML/CFT supervision and opacity in entity ownership to move funds through monitored jurisdictions without immediate detection.
  2. Escalation follows when suspicious transaction patterns, informal transfer services, or sanctions-linked routing are not surfaced quickly enough for investigators to intervene.
  3. Impact is the continued movement of funds through financial channels that should have been risk-scaled, reported, or interrupted earlier.

NHI Mgmt Group analysis

Grey-listing is a governance signal, not a de-risking mandate: FATF monitoring status changes the control posture, but it does not justify automatic exclusion of entire customer populations. Institutions that treat grey-listing as a binary switch collapse risk-based decision-making into country-based blunt force. The better discipline is to align enhanced review only to the exposure that the monitoring status actually indicates.

Beneficial ownership opacity is the core control failure here: When ownership data is incomplete, stale, or hard to operationalise, AML screening cannot reliably distinguish legitimate exposure from hidden control. That failure is more important than the country label itself because it undermines customer due diligence, entity resolution, and investigation quality. Compliance teams should treat ownership visibility as an operational control, not a filing exercise.

Sanctions-evasion monitoring must look beyond direct jurisdiction flags: Grey-listed jurisdictions can be part of indirect routing patterns even when the surface transaction appears ordinary. The practical problem is not geography alone but the combination of intermediaries, shell structures, and incomplete counterparty data. That makes network-aware screening more valuable than static list checking.

Grey-list remediation shows why AML governance has to be continuous: Iraq’s previous grey-list period and return to monitoring illustrate that control improvement can stall or regress. A jurisdiction can satisfy commitments and later re-enter increased monitoring if supervision, investigations, or reporting do not hold. The implication for practitioners is that risk state must be reviewed dynamically, not preserved as a one-time onboarding decision.

Risk-based screening is the only defensible operating model: The article reinforces a broader governance principle that one-size-fits-all escalation produces noise while missing actual risk concentration. A proportionate model preserves resources for higher-risk relationships and transactions without turning compliance into indiscriminate customer attrition. The right standard is evidence-led escalation, not blanket reaction.

What this signals

Grey-list status only becomes operationally useful when it feeds customer risk decisions, monitoring thresholds, and escalation rules. Compliance teams should avoid treating country monitoring as a substitute for evidence-led judgment. The better model is to adjust scrutiny where the actual exposure sits, not where the headline label points.

Beneficial ownership visibility is the named concept that matters most here: without it, screening cannot reliably connect a customer to the people or entities that ultimately control it. That is why grey-list governance belongs inside customer due diligence, not only inside sanctions operations.

For AML programmes, the practical signal is simple: if your controls only react to jurisdiction names, you are blind to indirect routing and layered ownership structures. That is where suspicious transaction reporting, entity resolution, and counterparty analysis need to work together.


For practitioners

  • Calibrate grey-list treatment to exposure Separate jurisdictional monitoring status from customer-level decisions and define when grey-list membership changes due diligence, transaction monitoring, or approval thresholds.
  • Refresh beneficial ownership data Validate ownership records for high-risk customers, entities, and counterparties so monitoring logic can resolve control chains rather than relying on stale registrations.
  • Test sanctions-evasion scenarios Run monitoring tests against indirect routing patterns, layered entities, and third-party payment paths that could conceal exposure to monitored jurisdictions.
  • Review suspicious reporting triggers Check that alert thresholds and escalation rules still capture informal transfer services, unexplained structuring, and repeated cross-border patterns that merit filing.

Key takeaways

  • Grey-listing is a governance signal that should change scrutiny levels, not trigger automatic de-risking of entire customer groups.
  • The article links FATF monitoring to the controls that actually matter in practice, including beneficial ownership visibility, suspicious transaction reporting, and sanctions-evasion detection.
  • Compliance teams need risk-based screening that reacts to real exposure, because jurisdiction labels alone are too blunt to separate legitimate activity from higher-risk flows.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

NIST CSF 2.0 and CIS Controls v8 set the technical controls, while GDPR defines the regulatory obligations.

FrameworkControl / ReferenceRelevance
NIST CSF 2.0GV.RM-01 — Risk Management StrategyGrey-listing requires risk-based governance decisions rather than blanket de-risking.
PR.AA-05 — Access Permissions, Entitlements and AuthorizationsBeneficial ownership and counterparty controls determine who can move value through financial systems.
Recommendation — Align AML response thresholds to risk appetite and documented exposure rather than jurisdiction labels alone. Review entitlement and approval logic so higher-risk relationships trigger stronger transaction scrutiny.
CIS Controls v8CIS-5 — Account ManagementIdentity and entity control quality underpins reliable AML screening and escalation.
Recommendation — Maintain current ownership and account records so screening and investigation workflows use accurate identity data.
GDPRArt.32 — Security of ProcessingWhere AML data includes personal information, security of processing and access control remain relevant.
Recommendation — Protect personal data in AML workflows with access limits, accuracy checks, and monitored processing paths.

Key terms

  • Grey Listing: Grey listing is FATF’s increased monitoring status for jurisdictions with AML/CFT weaknesses. It signals that a country has committed to an action plan, and that institutions should adjust their risk posture with evidence, not with blanket exclusion.
  • Beneficial Ownership: Beneficial ownership identifies the person or entity that ultimately controls or benefits from an account, company, or asset. In EDD, it matters because nominal ownership can hide the real decision-maker, which is often the entity regulators and investigators need to understand.
  • Risk-based Screening: Risk-based screening is a control approach that adjusts due diligence, monitoring, and escalation based on the actual exposure presented by a customer, counterparty, or transaction. It is stronger than rule-only geography checks because it uses context, behaviour, and ownership data to shape the response.
  • Suspicious Transaction Report: A suspicious transaction report is a formal regulatory filing made when activity appears inconsistent with the customer profile or presents potential money laundering or terrorism financing risk. The report is usually the outcome of investigation, not the first control event in the workflow.

Deepen your knowledge

NHI governance, agentic AI identity, and machine identity lifecycle are core topics in our NHI Foundation Level course, the industry's only accredited NHI security programme. If you are responsible for identity security strategy or NHI governance in your organisation, it is worth exploring.
NHIMG Editorial Note
Published by the NHIMG editorial team on June 24, 2026.
Updated on October 11, 2026.
NHI Mgmt Group, the independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org