Chapter 1 · Introduction to Financial Crime & the International Response

5 of 50 exam questions (~10%) · FATF · UN conventions · EU MLDs 1-6 · national frameworks · risk-based approach
← Back to quiz
Why this chapter matters. 5 of 50 exam questions (~10%). The FRAMEWORK chapter — every subsequent CFC chapter references the FATF standards, EU MLDs, and national regulators introduced here. Trap zones: FATF grey list vs black list (grey = increased monitoring, black = call for action), FATF mutual evaluations assess BOTH technical compliance AND effectiveness (11 Immediate Outcomes), 1MLD-6MLD dates + scope changes, UN Vienna vs Palermo (Vienna = drugs 1988, Palermo = organised crime 2000), Egmont Group is FIUs, Wolfsberg is banks, UK AML supervision is fragmented (FCA + HMRC + OPBAS + ~22 professional bodies). Post-workbook to know: UAE greylisted 2022 → removed 2024, EU AMLA operational 2025, US AMLA 2020 in force, UK ECCT 2023.

1.1 What financial crime is (and how big)

Financial crime is an umbrella term syllabus 1.1

"Financial crime" isn't a single offence — it's a category. Any modern AML/CFT programme must address all of the following:

  • Money laundering (ML)
  • Terrorist financing (TF)
  • Bribery and corruption
  • Fraud
  • Tax evasion
  • Insider dealing / market abuse
  • Sanctions evasion
  • Cybercrime and cryptoasset-enabled crime (growing rapidly)

A firm cannot say "we do AML" and ignore sanctions or bribery. Regulatory frameworks (UK MLR, EU MLDs, FATF Recommendations) explicitly cover the whole spectrum.

Scale — the IMF's 2-5% of GDP figure syllabus 1.2

The IMF's widely-cited estimate: money laundering globally runs at 2-5% of global GDP, roughly $1.6-4 trillion per year. FATF, UNODC and the IMF all use figures in this range.

Impossible to measure precisely — successful laundering is undetected by definition. The UNODC 2011 study is the standard citation. Treat "2-5% of GDP" as an exam-ready number.

Trap: distractors will offer <1% (too low, ignores estimates), 8-12% (too high), or 20-30% (wildly high — mixes up laundering with total illicit finance).

Consequences — firm AND individual syllabus 1.3

Firm-level: regulatory fines, criminal prosecution, licence revocation, remediation cost, reputational damage, loss of correspondent banking, de-banking by counterparties. Recent benchmark cases:

  • HSBC — $1.9bn (2012, Mexico cartel)
  • BNP Paribas — $8.9bn (2014, sanctions)
  • Danske Bank — €2bn+ (2018-22, Estonia branch)
  • NatWest — £264m (2021, first UK bank criminal ML conviction)
  • Binance — $4.3bn (2023)

Individual-level: criminal prosecution (years of imprisonment), regulatory bans, civil claims, loss of professional membership, career-ending damage. SMCR-style regimes attach personal accountability to Senior Managers even where they did not directly participate — Thomas Borgen (ex-Danske Estonia CEO), various former Deutsche Bank compliance heads.

1.2 FATF — the global standard-setter

Founded 1989, G7, Paris syllabus 2.1

The Financial Action Task Force (FATF) was established in 1989 by the G7 summit in Paris. Originally focused on drug-related money laundering, its mandate was expanded twice:

  • Post-9/11 (2001) — added terrorist financing (TF)
  • Post-2012 — added proliferation financing (WMD)

Headquartered at OECD offices in Paris — but independent of OECD. Membership: 40+ jurisdictions plus two regional organisations.

The 40 Recommendations syllabus 2.2

The current FATF standards are the "40 Recommendations" (revised 2012, updated periodically). Timeline:

YearEvent
1990Original 40 AML Recommendations
2001+ 8 Special Recommendations (TF, post-9/11)
2004+ 9th Special Recommendation (cash couriers)
2012Consolidated back to 40 Recs (current baseline)
2022Update to Rec 24 (beneficial ownership transparency)
2019+Rec 15 + Interpretive Note (virtual assets, VASPs)

Mutual evaluations — TECHNICAL + EFFECTIVENESS syllabus 2.3

FATF mutual evaluations now assess each country on two dimensions:

  1. Technical compliance with the 40 Recommendations — are the laws/regulations actually in place?
  2. Effectiveness across 11 Immediate Outcomes — do they work in practice? E.g. is money actually being confiscated? Are prosecutions happening? Do firms actually stop suspicious activity?

The 11 Immediate Outcomes cover: risk understanding, international cooperation, supervisory action, preventive measures, TF investigation, sanctions implementation, etc. This post-2013 two-dimensional methodology is critical — many countries had "on paper" compliance but poor effectiveness.

Common trap: an answer suggesting the mutual evaluation is only about laws being on the statute book. It's laws AND how well they work in practice.

Grey list vs black list syllabus 2.4

ListMeaningCurrent examples
Grey list
("increased monitoring")
Country has committed to an action plan to fix identified deficienciesSouth Africa, Nigeria (added 2023). UAE grey Mar 2022 → removed Feb 2024. Pakistan removed 2022.
Black list
("call for action")
Most serious cases — FATF calls for countermeasures or EDDNorth Korea, Iran (countermeasures) · Myanmar (EDD)

Greylisting has real teeth: correspondent banks charge more or de-risk, compliance costs rise, sovereign credit ratings may be affected. Removal requires demonstrating effectiveness improvements over ~2 years of on-site visits.

UAE candidates: the 2022 → 2024 grey-listing cycle is a modern masterclass in what mattered to FATF — dedicated FIU, sanctions screening, DNFBP supervision, enforcement statistics, beneficial-ownership register. Effectiveness > paper compliance.

FATF's regional network — 9 FSRBs syllabus 2.5

FATF operates globally through 9 FATF-Style Regional Bodies (FSRBs), together reaching ~200 jurisdictions. Learn the names — exam-tested.

FSRBRegion
MENAFATFMiddle East + North Africa
MONEYVALCouncil of Europe
APGAsia/Pacific
GAFILATLatin America
ESAAMLGEastern + Southern Africa
GIABAWest Africa
GABACCentral Africa
CFATFCaribbean
EAGEurasian

1.3 EU AML Directives — 1MLD through 6MLD

Six directives in ~30 years — broader + stricter each time syllabus 3.1-3.5

The direction of travel: each MLD has EXPANDED scope and TIGHTENED requirements.

MLDYearKey innovation
1MLD1991First EU AML instrument — criminalise ML of drug proceeds only; CDD on banks
2MLD2001All serious crime + non-financial businesses
3MLD2005Risk-based approach introduced
4MLD2015 (transposed 2017)RBA formalised; BO registers; expanded PEP scope (incl. domestic PEPs); NRAs required
5MLD2018 (transposed 2020)Cryptoassets (custodian wallets + fiat-crypto exchanges); prepaid cards; art dealers (≥€10k); property letting agents (≥€10k/month)
6MLDJune 2021 (FIs)Harmonised 22 predicate offences; criminal liability for legal persons; min 4-year sentence; extended extraterritorial jurisdiction

Post-workbook: the AMLR + AMLA package. The EU is now consolidating into an Anti-Money Laundering Regulation (AMLR) with direct effect + an Anti-Money Laundering Authority (AMLA, operational 2025). Represents a shift from Directive (transposed differently per Member State) to Regulation (uniform). Biggest EU AML reform in decades.

Trap: 4MLD is often confused with 5MLD on scope. Remember: 4MLD formalised the RBA + BO registers. 5MLD added cryptoassets + prepaid cards + art dealers.

1.4 UN conventions — the binding backbone

Three conventions — remember them by year + focus syllabus 4.1-4.3

ConventionYearFocus
Vienna1988First major instrument requiring criminalisation of ML — drug proceeds only. Foundation of modern AML.
Palermo (UNTOC)2000Extended to transnational organised crime beyond drugs. Three protocols: trafficking in persons, smuggling of migrants, trafficking in firearms.
UNCAC2003The only legally binding global anti-corruption instrument. Prevention, criminalisation, cooperation, asset recovery. 190+ signatories.

FATF was established (1989) partly to help implement Vienna 1988. Palermo broadened the ML criminalisation base beyond drugs. UNCAC brought corruption into the same framework.

UN Security Council sanctions syllabus 4.4

UN Security Council sanctions imposed under Chapter VII of the UN Charter are binding on all UN member states and implemented via national law (UK: OFSI). Current regimes:

  • Al-Qaida / ISIL (Da'esh)
  • North Korea (DPRK)
  • Iran (nuclear, reduced under JCPOA)
  • Libya, Sudan, Somalia
  • Plus various individuals + entities

Beyond UN sanctions: individual countries (US OFAC, EU, UK OFSI) impose their OWN autonomous sanctions — often more extensive than UN measures. Firms must screen against multiple lists.

1.5 Other international bodies

Who does what — the memorise-this table syllabus 5.1-5.4

BodyWhat it does
OECDAnti-Bribery Convention (1997) · CRS (2014, auto tax-info exchange) · BEPS · CARF (2027 crypto reporting). Hosts FATF at Paris offices.
Egmont GroupGlobal network of Financial Intelligence Units (FIUs). 160+ member FIUs. Founded 1995. Enables SAR/STR sharing via Egmont Secure Web.
BCBSBanking-focused AML guidance — "Sound management of risks related to ML/TF" + "General Guide to Account Opening" (2016).
Wolfsberg GroupPrivate group of 12+ global banks — Barclays, BoA, Citi, Deutsche, Goldman, HSBC, JPM, MUFG, Santander, Société Générale, Standard Chartered, UBS. Publishes AML best-practice (e.g. Correspondent Banking DDQ / CBDDQ).
Common trap pair: Egmont Group is FIUs (public-sector receiving points for SARs — UK NCA, US FinCEN, France TRACFIN). Wolfsberg Group is banks (private-sector best-practice publisher). Don't confuse them.

1.6 National frameworks — UK, US, UAE

UK AML framework — layered syllabus 6.1-6.2

StatuteRole
POCA 2002Creates the ML offences (s.327-329 principal, s.330-333 regulated sector) + SAR regime — see [[Ch 2 — ML offences]]
Terrorism Act 2000Creates TF offences — see [[Ch 5 — TF]]
MLR 2017 (as amended)Preventive obligations on regulated firms — CDD, RBA, MLRO, training — see [[Ch 4 — Prevention framework]]
SAMLA 2018Post-Brexit autonomous sanctions framework
Criminal Finances Act 2017Corporate Criminal Offence (CCO) — failure to prevent facilitation of tax evasion
ECCT 2023Failure-to-prevent-fraud offence (in force Sept 2025)

UK AML supervision is fragmented across:

  • FCA — banks, investment firms, insurers under FSMA
  • HMRC — money service businesses, high-value dealers, TCSPs, letting/estate agents
  • OPBAS (Office for Professional Body AML Supervision, 2018) — oversees ~22 professional-body AML supervisors for lawyers, accountants
  • SRA, ICAEW, etc. — supervise their own members

FATF has repeatedly criticised this fragmentation as a UK weakness.

US AML framework — BSA + PATRIOT Act + AMLA syllabus 6.3

StatuteRole
BSA 1970The foundational statute — records + reporting
USA PATRIOT Act 2001Post-9/11 strengthening + specific CFT provisions
AMLA 2020 (part of NDAA 2021)Major modernisation — includes the Corporate Transparency Act (BO register), whistleblower rewards, expanded FinCEN authority. Implementation started 2024 (though facing legal challenges).

Enforcement is fragmented across FinCEN + banking regulators + DOJ + OFAC (sanctions).

UAE AML framework — post-greylist reform syllabus 6.4

Anchor statute: Federal Decree-Law No. 20 of 2018 (amended by Federal Decree-Law 26/2021). Implementing regulations: Cabinet Decision 10/2019.

Supervisory role split across:

  • Central Bank of the UAE
  • Securities and Commodities Authority (SCA)
  • DFSA / FSRA for the free zones (DIFC / ADGM)

UAE greylisted March 2022 → removed February 2024. Removal followed major reforms: dedicated FIU, sanctions screening, DNFBP supervision, enforcement statistics, beneficial-ownership register. Post-removal, UAE remains under scrutiny — GCC candidates should be able to speak to this trajectory.

1.7 The risk-based approach (RBA)

Origin — the 2012 FATF Recs put RBA at the centre syllabus 7.1

The risk-based approach (RBA) emerged progressively — but the pivotal moment was the 2012 FATF Recommendations, where Recommendation 1 explicitly required countries to identify, assess and mitigate their national ML/TF risks, and required firms to do the same.

Before this, rules-based (transaction-threshold-driven) approaches dominated — inflexible, easy to game via structuring / smurfing.

The RBA cascade — 5 layers syllabus 7.2

RBA operates as a top-down cascade. Each layer informs the next:

  1. FATF standards (global baseline)
  2. National Risk Assessment (NRA) — country-level, published by governments (UK NRA is by HM Treasury / Home Office)
  3. Sector Risk Assessments — industry-level (e.g. FCA thematic reviews)
  4. Firm-wide risk assessment — each firm identifies its own risks
  5. Customer-level risk rating — each customer scored

Firms must consider the NRA and sector assessments in their own — treating a "high-risk" NRA finding as no risk in your own firm needs justification.

RBA — trade-offs vs prescriptive rules syllabus 7.3

AspectRisk-basedPrescriptive
FlexibilityHigh — deploy resources to highest riskLow — one-size-fits-all
OutcomesBetter in principle — hard to gameEasy to game via structuring
SupervisionHarder — regulators must check judgementEasier — tick-box compliance
Small firmsHeavier burden (need risk-assessment expertise)Easier — clear rules to follow
Risk of under-scoringReal — firms may under-rate to save costNot applicable

Regulators must supervise the quality of risk assessment, not just its presence — an under-thought RBA is worse than a solid rules-based programme.

1.8 Information sharing + emerging risks

Public-private partnerships — JMLIT + peers syllabus 8.1

The UK Joint Money Laundering Intelligence Taskforce (JMLIT) — launched 2015 — is a public-private partnership between the National Crime Agency and major banks, enabling structured intelligence-sharing on active financial-crime investigations. Globally considered best-practice.

International peers: FinCEN Exchange (US), FinTerra (Australia).

Information-sharing constraints syllabus 8.2

Sharing customer information between firms is constrained by:

  • Data protection (GDPR, national privacy laws)
  • Tipping-off offences — can't disclose in a way that prejudices investigation
  • Commercial sensitivity — banks reluctant to disclose customer lists to competitors
  • Liability — sharing wrong info can expose the sharer

Safe harbours exist: UK Economic Crime Plan (2019, 2023), US Section 314(b) of USA PATRIOT Act, EU 6MLD info-sharing provisions.

Emerging risks — beyond traditional AML syllabus 9.1

Modern threat landscape has expanded to include:

  • Cybercrime + cyber-enabled crime (ransomware, business email compromise)
  • Cryptoasset-enabled crime (mixers, cross-chain bridges, privacy coins) — see [[Ch 7 — Recent Developments]]
  • Deepfake + AI-enabled fraud
  • Sanctions evasion at scale (post-2022 Russia)
  • Trade-based ML — see [[Ch 3 — Sources + methods]]
  • NFT wash-trading
  • State-sponsored financial attacks (particularly DPRK)
  • ESG-related fraud (greenwashing, carbon-credit scams)

Compliance cost: a major global bank typically spends hundreds of millions to low billions per year on AML/CFT — HSBC has publicly disclosed $3bn+ annual financial-crime spend. Includes thousands of analysts + investigators, transaction monitoring, sanctions screening, external assurance, legacy remediation.

The "effectiveness gap" debate: academic Ronald Pol has argued that despite $180bn+ global annual compliance cost, less than 1% of illicit proceeds are seized. Counter: deterrent effect is unmeasurable. Aware professionals speak to both sides.

1.9 Ch 1 cheat sheet — the exam-day list

All the numbers + names

ItemAnswer
FATF founded1989 · G7 · Paris
FATF standardsThe "40 Recommendations" (2012 revision)
Mutual evaluation dimensionsTechnical compliance + Effectiveness (11 Immediate Outcomes)
FATF grey list"Increased monitoring" — action plan
FATF black list"Call for action" — countermeasures (DPRK, Iran); EDD (Myanmar)
UAE grey periodMar 2022 → Feb 2024
FSRBs9 regional bodies covering ~200 jurisdictions
ML scale (IMF)2-5% of global GDP · ~$1.6-4tn/year
1MLD (1991)Drug proceeds only · banks only
4MLD (2015-17)Formalised RBA · BO registers · domestic PEPs
5MLD (2018-20)Crypto · prepaid cards · art dealers · letting agents
6MLD (2021)22 predicate offences · legal-person liability · 4y min sentence
EU AMLR + AMLAAMLA operational 2025 · Regulation replaces Directive-style rules
Vienna 1988UN — criminalise ML of drug proceeds
Palermo 2000 (UNTOC)UN — organised crime · 3 protocols (trafficking, smuggling, firearms)
UNCAC 2003Only legally binding global anti-corruption instrument
UN sanctions basisChapter VII UN Charter · binding on all members
Egmont Group160+ FIUs · founded 1995 · Egmont Secure Web
Wolfsberg Group12+ private banks · publishes CBDDQ
OECD (AML)Anti-Bribery Convention 1997 · CRS 2014 · CARF 2027
UK anchor statutesPOCA 2002 · TA 2000 · MLR 2017 · SAMLA 2018
UK AML supervisorsFCA · HMRC · OPBAS · ~22 professional bodies
US anchor statutesBSA 1970 · USA PATRIOT Act 2001 · AMLA 2020 (with CTA)
UAE anchorFederal Decree-Law 20/2018 (amended 26/2021)
RBA cascade (5 layers)FATF → NRA → sector → firm → customer
JMLITUK NCA + major banks · public-private intelligence sharing
Print this table (or the full CFC cram sheet) the day before the exam. Every fact above is directly tested. Next stop: Ch 2 — ML: The Offences.