TL;DR: FATF has added Iraq and Bosnia and Herzegovina to its grey list while removing Algeria and Namibia, highlighting how AML/CFT supervision, beneficial ownership transparency, sanctions-evasion controls, and suspicious transaction reporting remain the operational levers, according to SumSub. Grey-listing is a governance test, not a blanket customer exclusion decision, and practitioners should treat it as a signal to tighten risk-based controls rather than default to indiscriminate de-risking.
Editorial analysis by NHI Mgmt Group, based on content published by SumSub: “FATF: Iraq and Bosnia & Herzegovina on Grey List as Algeria and Namibia Removed”.
Key questions
Q: What breaks when grey-listing is treated like a blanket de-risking order?
A: Blanket de-risking turns a monitoring signal into an exit decision and removes the nuance AML programmes need.
Q: Why do grey-listed jurisdictions create higher AML and sanctions risk?
A: Grey-listed jurisdictions often point to weaker supervision, incomplete ownership transparency, and less reliable suspicious transaction reporting.
Q: How can compliance teams tell if risk-based screening is working?
A: Risk-based screening is working when high-risk relationships receive deeper review without triggering unnecessary friction for ordinary customers.
Practitioner guidance
- Calibrate grey-list treatment to exposure Separate jurisdictional monitoring status from customer-level decisions and define when grey-list membership changes due diligence, transaction monitoring, or approval thresholds.
- Refresh beneficial ownership data Validate ownership records for high-risk customers, entities, and counterparties so monitoring logic can resolve control chains rather than relying on stale registrations.
- Test sanctions-evasion scenarios Run monitoring tests against indirect routing patterns, layered entities, and third-party payment paths that could conceal exposure to monitored jurisdictions.
Bottom line: Grey-listing is a governance signal that should change scrutiny levels, not trigger automatic de-risking of entire customer groups.
Explore further
View Full Forum → | NHI Foundation Course → | Our Services → | Read the full analysis →
Grey-listing is a governance signal, not a de-risking mandate: FATF monitoring status changes the control posture, but it does not justify automatic exclusion of entire customer populations. Institutions that treat grey-listing as a binary switch collapse risk-based decision-making into country-based blunt force. The better discipline is to align enhanced review only to the exposure that the monitoring status actually indicates.
A question worth separating out:
Q: When should institutions tighten controls after FATF grey-list changes?
A: Institutions should tighten controls as soon as the monitoring status is confirmed, but only in proportion to the exposure. That usually means reviewing high-risk counterparties, payment corridors, beneficial ownership data, and sanctions-evasion scenarios first. The aim is faster risk calibration, not automatic customer exclusion.
👉 Read our full editorial: Grey listing and risk-based screening reshape AML governance