Adhering to FAFT recommendations can only mean better outcomes

This LinkedIn post by Muhammad Shakit provides a good summary of Financial Action Task Force (FAFT) recommendations that every country should follow and apply rigorously to the financial institutions which fall under the regulator’s purview. Money laundering and financial fraud are a global reality which needs to be addressed by countries working together and collaborating to apprehend the criminals perpetrating the crimes and leaving many victims in their wake.

His key message is worth citing here as it should not just be seen as a compliance matter. Mr. Shakit states below that the 40 FAFT recommendations “are a practical risk management framework for institutions to stay resilient against financial crime.”

Muhammad Shakil

Muhammad Shakil

Corporate Governance Enthusiast | Keynote Speaker | Risk and Compliance Strategist

FATF guidance on Risk-based approach

AML/CFT compliance is not about treating every customer the same, it’s about treating every risk differently.

That’s the essence of the Risk-Based Approach (RBA) promoted by the .

Think of it as a simple 4-step cycle:

✅ 1. Identify Risks
Know where risks exist

Example → A customer regularly sends funds to a high-risk country.

✅ 2. Assess Risks
Measure the likelihood and impact

Example → Rate the customer as:
– Low
– Medium or
– High risk
Based on products, geography, and transaction behavior.

✅ 3. Mitigate Risks
Apply controls that match the level of risk

Example:
• Low Risk → Simplified Due Diligence (SDD)
• Medium Risk → Standard Customer Due Diligence (CDD)
• High Risk → Enhanced Due Diligence (EDD), senior management approval, and closer monitoring.

✅ 4. Monitor & Review
Risk is dynamic—not static

Example → A low-risk customer suddenly starts making large international transfers. Review and update the risk rating immediately.

How to design effective AML/CFT controls?

✔️ Customer Risk Rating Model

✔️ Customer Due Diligence (CDD) & Enhanced Due Diligence (EDD)

✔️ Transaction Monitoring Rules & Alerts

✔️ Sanctions & PEP Screening

✔️ Beneficial Ownership Verification

✔️ Periodic KYC Reviews

✔️ Staff Training & Awareness

✔️ Strong Governance with independent oversight and regular testing

Remember:
The goal is not more controls, it’s the right controls for the right risks.

A well-designed Risk-Based Approach strengthens compliance, improves customer experience, and enables institutions to focus resources where financial crime risk is highest.

Question for the community:

Which step of the Risk-Based Approach do organizations struggle with the most; risk identification, assessment, mitigation, or Ongoing Monitoring?

Don't forget to share this post!
Social media & sharing icons powered by UltimatelySocial