1.1 What financial crime is (and how big)
▼Financial crime is an umbrella term syllabus 1.1
"Financial crime" isn't a single offence — it's a category. Any modern AML/CFT programme must address all of the following:
- Money laundering (ML)
- Terrorist financing (TF)
- Bribery and corruption
- Fraud
- Tax evasion
- Insider dealing / market abuse
- Sanctions evasion
- Cybercrime and cryptoasset-enabled crime (growing rapidly)
A firm cannot say "we do AML" and ignore sanctions or bribery. Regulatory frameworks (UK MLR, EU MLDs, FATF Recommendations) explicitly cover the whole spectrum.
Scale — the IMF's 2-5% of GDP figure syllabus 1.2
The IMF's widely-cited estimate: money laundering globally runs at 2-5% of global GDP, roughly $1.6-4 trillion per year. FATF, UNODC and the IMF all use figures in this range.
Impossible to measure precisely — successful laundering is undetected by definition. The UNODC 2011 study is the standard citation. Treat "2-5% of GDP" as an exam-ready number.
Consequences — firm AND individual syllabus 1.3
Firm-level: regulatory fines, criminal prosecution, licence revocation, remediation cost, reputational damage, loss of correspondent banking, de-banking by counterparties. Recent benchmark cases:
- HSBC — $1.9bn (2012, Mexico cartel)
- BNP Paribas — $8.9bn (2014, sanctions)
- Danske Bank — €2bn+ (2018-22, Estonia branch)
- NatWest — £264m (2021, first UK bank criminal ML conviction)
- Binance — $4.3bn (2023)
Individual-level: criminal prosecution (years of imprisonment), regulatory bans, civil claims, loss of professional membership, career-ending damage. SMCR-style regimes attach personal accountability to Senior Managers even where they did not directly participate — Thomas Borgen (ex-Danske Estonia CEO), various former Deutsche Bank compliance heads.
1.2 FATF — the global standard-setter
▼Founded 1989, G7, Paris syllabus 2.1
The Financial Action Task Force (FATF) was established in 1989 by the G7 summit in Paris. Originally focused on drug-related money laundering, its mandate was expanded twice:
- Post-9/11 (2001) — added terrorist financing (TF)
- Post-2012 — added proliferation financing (WMD)
Headquartered at OECD offices in Paris — but independent of OECD. Membership: 40+ jurisdictions plus two regional organisations.
The 40 Recommendations syllabus 2.2
The current FATF standards are the "40 Recommendations" (revised 2012, updated periodically). Timeline:
| Year | Event |
|---|---|
| 1990 | Original 40 AML Recommendations |
| 2001 | + 8 Special Recommendations (TF, post-9/11) |
| 2004 | + 9th Special Recommendation (cash couriers) |
| 2012 | Consolidated back to 40 Recs (current baseline) |
| 2022 | Update to Rec 24 (beneficial ownership transparency) |
| 2019+ | Rec 15 + Interpretive Note (virtual assets, VASPs) |
Mutual evaluations — TECHNICAL + EFFECTIVENESS syllabus 2.3
FATF mutual evaluations now assess each country on two dimensions:
- Technical compliance with the 40 Recommendations — are the laws/regulations actually in place?
- Effectiveness across 11 Immediate Outcomes — do they work in practice? E.g. is money actually being confiscated? Are prosecutions happening? Do firms actually stop suspicious activity?
The 11 Immediate Outcomes cover: risk understanding, international cooperation, supervisory action, preventive measures, TF investigation, sanctions implementation, etc. This post-2013 two-dimensional methodology is critical — many countries had "on paper" compliance but poor effectiveness.
Grey list vs black list syllabus 2.4
| List | Meaning | Current examples |
|---|---|---|
| Grey list ("increased monitoring") | Country has committed to an action plan to fix identified deficiencies | South Africa, Nigeria (added 2023). UAE grey Mar 2022 → removed Feb 2024. Pakistan removed 2022. |
| Black list ("call for action") | Most serious cases — FATF calls for countermeasures or EDD | North Korea, Iran (countermeasures) · Myanmar (EDD) |
Greylisting has real teeth: correspondent banks charge more or de-risk, compliance costs rise, sovereign credit ratings may be affected. Removal requires demonstrating effectiveness improvements over ~2 years of on-site visits.
FATF's regional network — 9 FSRBs syllabus 2.5
FATF operates globally through 9 FATF-Style Regional Bodies (FSRBs), together reaching ~200 jurisdictions. Learn the names — exam-tested.
| FSRB | Region |
|---|---|
| MENAFATF | Middle East + North Africa |
| MONEYVAL | Council of Europe |
| APG | Asia/Pacific |
| GAFILAT | Latin America |
| ESAAMLG | Eastern + Southern Africa |
| GIABA | West Africa |
| GABAC | Central Africa |
| CFATF | Caribbean |
| EAG | Eurasian |
1.3 EU AML Directives — 1MLD through 6MLD
▼Six directives in ~30 years — broader + stricter each time syllabus 3.1-3.5
The direction of travel: each MLD has EXPANDED scope and TIGHTENED requirements.
| MLD | Year | Key innovation |
|---|---|---|
| 1MLD | 1991 | First EU AML instrument — criminalise ML of drug proceeds only; CDD on banks |
| 2MLD | 2001 | All serious crime + non-financial businesses |
| 3MLD | 2005 | Risk-based approach introduced |
| 4MLD | 2015 (transposed 2017) | RBA formalised; BO registers; expanded PEP scope (incl. domestic PEPs); NRAs required |
| 5MLD | 2018 (transposed 2020) | Cryptoassets (custodian wallets + fiat-crypto exchanges); prepaid cards; art dealers (≥€10k); property letting agents (≥€10k/month) |
| 6MLD | June 2021 (FIs) | Harmonised 22 predicate offences; criminal liability for legal persons; min 4-year sentence; extended extraterritorial jurisdiction |
Post-workbook: the AMLR + AMLA package. The EU is now consolidating into an Anti-Money Laundering Regulation (AMLR) with direct effect + an Anti-Money Laundering Authority (AMLA, operational 2025). Represents a shift from Directive (transposed differently per Member State) to Regulation (uniform). Biggest EU AML reform in decades.
1.4 UN conventions — the binding backbone
▼Three conventions — remember them by year + focus syllabus 4.1-4.3
| Convention | Year | Focus |
|---|---|---|
| Vienna | 1988 | First major instrument requiring criminalisation of ML — drug proceeds only. Foundation of modern AML. |
| Palermo (UNTOC) | 2000 | Extended to transnational organised crime beyond drugs. Three protocols: trafficking in persons, smuggling of migrants, trafficking in firearms. |
| UNCAC | 2003 | The only legally binding global anti-corruption instrument. Prevention, criminalisation, cooperation, asset recovery. 190+ signatories. |
FATF was established (1989) partly to help implement Vienna 1988. Palermo broadened the ML criminalisation base beyond drugs. UNCAC brought corruption into the same framework.
UN Security Council sanctions syllabus 4.4
UN Security Council sanctions imposed under Chapter VII of the UN Charter are binding on all UN member states and implemented via national law (UK: OFSI). Current regimes:
- Al-Qaida / ISIL (Da'esh)
- North Korea (DPRK)
- Iran (nuclear, reduced under JCPOA)
- Libya, Sudan, Somalia
- Plus various individuals + entities
Beyond UN sanctions: individual countries (US OFAC, EU, UK OFSI) impose their OWN autonomous sanctions — often more extensive than UN measures. Firms must screen against multiple lists.
1.5 Other international bodies
▼Who does what — the memorise-this table syllabus 5.1-5.4
| Body | What it does |
|---|---|
| OECD | Anti-Bribery Convention (1997) · CRS (2014, auto tax-info exchange) · BEPS · CARF (2027 crypto reporting). Hosts FATF at Paris offices. |
| Egmont Group | Global network of Financial Intelligence Units (FIUs). 160+ member FIUs. Founded 1995. Enables SAR/STR sharing via Egmont Secure Web. |
| BCBS | Banking-focused AML guidance — "Sound management of risks related to ML/TF" + "General Guide to Account Opening" (2016). |
| Wolfsberg Group | Private group of 12+ global banks — Barclays, BoA, Citi, Deutsche, Goldman, HSBC, JPM, MUFG, Santander, Société Générale, Standard Chartered, UBS. Publishes AML best-practice (e.g. Correspondent Banking DDQ / CBDDQ). |
1.6 National frameworks — UK, US, UAE
▼UK AML framework — layered syllabus 6.1-6.2
| Statute | Role |
|---|---|
| POCA 2002 | Creates the ML offences (s.327-329 principal, s.330-333 regulated sector) + SAR regime — see [[Ch 2 — ML offences]] |
| Terrorism Act 2000 | Creates TF offences — see [[Ch 5 — TF]] |
| MLR 2017 (as amended) | Preventive obligations on regulated firms — CDD, RBA, MLRO, training — see [[Ch 4 — Prevention framework]] |
| SAMLA 2018 | Post-Brexit autonomous sanctions framework |
| Criminal Finances Act 2017 | Corporate Criminal Offence (CCO) — failure to prevent facilitation of tax evasion |
| ECCT 2023 | Failure-to-prevent-fraud offence (in force Sept 2025) |
UK AML supervision is fragmented across:
- FCA — banks, investment firms, insurers under FSMA
- HMRC — money service businesses, high-value dealers, TCSPs, letting/estate agents
- OPBAS (Office for Professional Body AML Supervision, 2018) — oversees ~22 professional-body AML supervisors for lawyers, accountants
- SRA, ICAEW, etc. — supervise their own members
FATF has repeatedly criticised this fragmentation as a UK weakness.
US AML framework — BSA + PATRIOT Act + AMLA syllabus 6.3
| Statute | Role |
|---|---|
| BSA 1970 | The foundational statute — records + reporting |
| USA PATRIOT Act 2001 | Post-9/11 strengthening + specific CFT provisions |
| AMLA 2020 (part of NDAA 2021) | Major modernisation — includes the Corporate Transparency Act (BO register), whistleblower rewards, expanded FinCEN authority. Implementation started 2024 (though facing legal challenges). |
Enforcement is fragmented across FinCEN + banking regulators + DOJ + OFAC (sanctions).
UAE AML framework — post-greylist reform syllabus 6.4
Anchor statute: Federal Decree-Law No. 20 of 2018 (amended by Federal Decree-Law 26/2021). Implementing regulations: Cabinet Decision 10/2019.
Supervisory role split across:
- Central Bank of the UAE
- Securities and Commodities Authority (SCA)
- DFSA / FSRA for the free zones (DIFC / ADGM)
UAE greylisted March 2022 → removed February 2024. Removal followed major reforms: dedicated FIU, sanctions screening, DNFBP supervision, enforcement statistics, beneficial-ownership register. Post-removal, UAE remains under scrutiny — GCC candidates should be able to speak to this trajectory.
1.7 The risk-based approach (RBA)
▼Origin — the 2012 FATF Recs put RBA at the centre syllabus 7.1
The risk-based approach (RBA) emerged progressively — but the pivotal moment was the 2012 FATF Recommendations, where Recommendation 1 explicitly required countries to identify, assess and mitigate their national ML/TF risks, and required firms to do the same.
Before this, rules-based (transaction-threshold-driven) approaches dominated — inflexible, easy to game via structuring / smurfing.
The RBA cascade — 5 layers syllabus 7.2
RBA operates as a top-down cascade. Each layer informs the next:
- FATF standards (global baseline)
- National Risk Assessment (NRA) — country-level, published by governments (UK NRA is by HM Treasury / Home Office)
- Sector Risk Assessments — industry-level (e.g. FCA thematic reviews)
- Firm-wide risk assessment — each firm identifies its own risks
- Customer-level risk rating — each customer scored
Firms must consider the NRA and sector assessments in their own — treating a "high-risk" NRA finding as no risk in your own firm needs justification.
RBA — trade-offs vs prescriptive rules syllabus 7.3
| Aspect | Risk-based | Prescriptive |
|---|---|---|
| Flexibility | High — deploy resources to highest risk | Low — one-size-fits-all |
| Outcomes | Better in principle — hard to game | Easy to game via structuring |
| Supervision | Harder — regulators must check judgement | Easier — tick-box compliance |
| Small firms | Heavier burden (need risk-assessment expertise) | Easier — clear rules to follow |
| Risk of under-scoring | Real — firms may under-rate to save cost | Not applicable |
Regulators must supervise the quality of risk assessment, not just its presence — an under-thought RBA is worse than a solid rules-based programme.
1.8 Information sharing + emerging risks
▼Public-private partnerships — JMLIT + peers syllabus 8.1
The UK Joint Money Laundering Intelligence Taskforce (JMLIT) — launched 2015 — is a public-private partnership between the National Crime Agency and major banks, enabling structured intelligence-sharing on active financial-crime investigations. Globally considered best-practice.
International peers: FinCEN Exchange (US), FinTerra (Australia).
Information-sharing constraints syllabus 8.2
Sharing customer information between firms is constrained by:
- Data protection (GDPR, national privacy laws)
- Tipping-off offences — can't disclose in a way that prejudices investigation
- Commercial sensitivity — banks reluctant to disclose customer lists to competitors
- Liability — sharing wrong info can expose the sharer
Safe harbours exist: UK Economic Crime Plan (2019, 2023), US Section 314(b) of USA PATRIOT Act, EU 6MLD info-sharing provisions.
Emerging risks — beyond traditional AML syllabus 9.1
Modern threat landscape has expanded to include:
- Cybercrime + cyber-enabled crime (ransomware, business email compromise)
- Cryptoasset-enabled crime (mixers, cross-chain bridges, privacy coins) — see [[Ch 7 — Recent Developments]]
- Deepfake + AI-enabled fraud
- Sanctions evasion at scale (post-2022 Russia)
- Trade-based ML — see [[Ch 3 — Sources + methods]]
- NFT wash-trading
- State-sponsored financial attacks (particularly DPRK)
- ESG-related fraud (greenwashing, carbon-credit scams)
Compliance cost: a major global bank typically spends hundreds of millions to low billions per year on AML/CFT — HSBC has publicly disclosed $3bn+ annual financial-crime spend. Includes thousands of analysts + investigators, transaction monitoring, sanctions screening, external assurance, legacy remediation.
1.9 Ch 1 cheat sheet — the exam-day list
▼All the numbers + names
| Item | Answer |
|---|---|
| FATF founded | 1989 · G7 · Paris |
| FATF standards | The "40 Recommendations" (2012 revision) |
| Mutual evaluation dimensions | Technical compliance + Effectiveness (11 Immediate Outcomes) |
| FATF grey list | "Increased monitoring" — action plan |
| FATF black list | "Call for action" — countermeasures (DPRK, Iran); EDD (Myanmar) |
| UAE grey period | Mar 2022 → Feb 2024 |
| FSRBs | 9 regional bodies covering ~200 jurisdictions |
| ML scale (IMF) | 2-5% of global GDP · ~$1.6-4tn/year |
| 1MLD (1991) | Drug proceeds only · banks only |
| 4MLD (2015-17) | Formalised RBA · BO registers · domestic PEPs |
| 5MLD (2018-20) | Crypto · prepaid cards · art dealers · letting agents |
| 6MLD (2021) | 22 predicate offences · legal-person liability · 4y min sentence |
| EU AMLR + AMLA | AMLA operational 2025 · Regulation replaces Directive-style rules |
| Vienna 1988 | UN — criminalise ML of drug proceeds |
| Palermo 2000 (UNTOC) | UN — organised crime · 3 protocols (trafficking, smuggling, firearms) |
| UNCAC 2003 | Only legally binding global anti-corruption instrument |
| UN sanctions basis | Chapter VII UN Charter · binding on all members |
| Egmont Group | 160+ FIUs · founded 1995 · Egmont Secure Web |
| Wolfsberg Group | 12+ private banks · publishes CBDDQ |
| OECD (AML) | Anti-Bribery Convention 1997 · CRS 2014 · CARF 2027 |
| UK anchor statutes | POCA 2002 · TA 2000 · MLR 2017 · SAMLA 2018 |
| UK AML supervisors | FCA · HMRC · OPBAS · ~22 professional bodies |
| US anchor statutes | BSA 1970 · USA PATRIOT Act 2001 · AMLA 2020 (with CTA) |
| UAE anchor | Federal Decree-Law 20/2018 (amended 26/2021) |
| RBA cascade (5 layers) | FATF → NRA → sector → firm → customer |
| JMLIT | UK NCA + major banks · public-private intelligence sharing |