FATF June 2026 Grey List: Iraq, Bosnia & KYC EDD
FATF added Iraq and Bosnia-Herzegovina to its June 2026 grey list. Here is what compliance teams must update in their KYC programs and EDD workflows.

From June 17 to 19, the Financial Action Task Force held its June 2026 plenary in Paris. The outcomes, published on June 19, led with a plain result: Iraq and Bosnia-Herzegovina have been added to the FATF grey list. Algeria and Namibia have come off it. The roster of jurisdictions under increased monitoring now stands at 22.
A grey list update looks like regulatory housekeeping to most compliance teams. It is not. The same cycle put two large, strategically positioned jurisdictions on the list. The incoming UK FATF Presidency launched with fraud as its headline priority. The same week, a public consultation on payment transparency opened — and that consultation has direct implications for how cross-border transactions are screened.
Act on this before the summer ends.
What the FATF Grey List Actually Means
The FATF grey list — formally, "Jurisdictions Under Increased Monitoring" — carries no legal sanctions. Business is not banned. The list is not a block list. What it does is name countries that have committed to fixing identified deficiencies in their anti-money laundering, counter-terrorist financing, and counter-proliferation frameworks.
The practical consequence is narrower. Country risk assessments at regulated firms must absorb grey-listed jurisdictions. Enhanced due diligence or enhanced ongoing monitoring then applies to the relevant customers and transactions only where that assessment supports it.
Automatic EDD is not the rule. Grey-listing feeds a risk-based assessment; it is not a tripwire. Blanket de-risking — shutting off every customer connected to a grey-listed country, with no documented rationale — is itself a compliance failure. That point has been made explicit by regulators, particularly under AMLA's evolving framework.
Compliance teams need to refresh these pieces of the framework:
- Scoring models for country risk
- Enterprise-wide risk assessments (EWRA)
- Triggers for customer due diligence and EDD
- Geographic risk parameters inside transaction monitoring
- Review schedules for ongoing monitoring of existing customers with exposure
AMLA's guidelines on ongoing monitoring require jurisdictional risk changes to flow through to customer-level risk posture reviews. Not as a one-off. As part of a continuous monitoring cycle. A grey list change is exactly the trigger those guidelines were written to catch.
Iraq: Why This Addition Is Significant
With a population of approximately 48 million and a regional economic footprint driven by oil exports, remittances, and an expanding formal banking sector, Iraq is among the largest jurisdictions added to the FATF grey list in recent years.
FATF's decision rests on identified strategic deficiencies across several risk areas. Treat the addition as material if the firm has exposure to Iraqi customers, correspondent banking relationships with Iraqi banks, or transaction flows through Gulf financial centers that channel Iraqi business.
| Sector | Key Risk Driver |
|---|---|
| Oil and gas payments | Routed via correspondent chains, which makes beneficiary tracing non-trivial |
| Remittances | Informal channels at high volume; hawala networks retain documented relevance |
| Real estate | Offshore holding structures are common, so beneficial ownership verification is complex |
| Virtual assets | Crypto adoption is growing; EU Travel Rule controls apply to all Iraq-linked transfers |
For crypto-asset service providers, Travel Rule obligations meet this addition head-on. The MiCA Travel Rule framework requires verified originator and beneficiary data on every transfer regardless of amount. A grey-listed jurisdiction lifts customer risk at the account level. That lift has to pass through to transaction-level screening thresholds. It is not a separate compliance event.
Bosnia-Herzegovina: The European Complexity
Bosnia-Herzegovina is a different problem. It is a candidate country for EU accession. Economic integration with the EU runs deep. Those two facts make the grey-listing politically sensitive and operationally complex for European financial institutions.
FATF did not cite documented high volumes of criminal proceeds. The deficiencies it identified sit in the country's AML/CFT institutional framework. Regulated firms with exposure to the region still have to act, above all around:
- Western Balkans trade finance flows
- Real estate deals whose beneficial owners are Bosnian
- Correspondent banking ties to Bosnian financial institutions
- Investment structures tied to EU-Bosnia economic corridors
A layered issue faces EU-regulated firms. AMLA's risk factor guidelines — part of the 23 Level 2/3 measures package due by July 10, 2026 — speak directly to geographic risk factors and require country risk assessments to be updated when the risk landscape changes. Grey-listing Bosnia-Herzegovina is that kind of change.
Algeria and Namibia: What Removal Means for KYC Programs
Coming off the grey list is the other half of the same event. Algeria and Namibia both completed successful on-site visits that showed meaningful progress against their action plans. Firms that raised measures on these jurisdictions specifically because of grey-list status now have a review to run.
Do not simply de-escalate by default:
- Record the removal and refresh the country risk model
- Revisit each customer whose EDD existed specifically because of grey-list status
- Decide whether other risk factors still justify the elevated measures
- Refresh the EWRA and the relevant risk appetite statements
- Keep an audit record of every step
Taking a jurisdiction off elevated monitoring without a documented review of each affected customer is as much a problem as never applying EDD at all. Risk-based compliance needs written reasoning in both directions.
The New UK FATF Presidency: What It Signals for KYC
The June 2026 plenary closed Mexico's Presidency. Giles Thomson of the UK takes over from July 1, 2026. The mandate runs two years, through June 2028. Declared priorities of the UK Presidency have direct implications for regulated firms.
Fraud, including scam compounds
Fraud leads the list. The UK Presidency will work to strengthen the international response to financial crime linked to scam compounds: large-scale organized operations that combine social engineering, synthetic identity, and laundering through informal channels. KYC programs should read that as heavier regulatory scrutiny of onboarding controls that catch fraud-linked financial flows.
Synthetic identity fraud and money laundering have been drawing closer together. In the US alone, synthetic identity fraud already costs $3.1 billion annually, and that problem now sits at the center of FATF's incoming agenda. Programs that still treat identity verification as a one-time onboarding check, rather than a continuous risk function, sit further from the regulatory standard as it is moving.
Strengthening the risk-based approach
Uneven implementation has always dogged FATF's foundational principle. The UK Presidency's attention here points to continued pressure on two failure modes: over-compliance, meaning blanket de-risking without documented assessment, and under-compliance, meaning nominal risk frameworks that are not calibrated to actual customer behavior.
Information sharing and public-private partnerships
Deeper intelligence-sharing between financial institutions and law enforcement is on the stated agenda. That raises the value of KYC data that is structured and kept current. Firms whose identity records are well organized and up to date will be in a stronger position as sharing obligations expand.
The Recommendation 16 Payment Transparency Consultation
A public consultation on updated guidance for FATF Recommendation 16 — the wire transfer and payment transparency standard — was approved by the plenary. That consultation opened the week of June 22, 2026.
Recommendation 16 requires identification information to travel with wire transfers and electronic payments. Fraud is the primary concern of the updated guidance, which is aimed at modern payment infrastructure.
Compliance teams can already see the outline of where payment transparency rules are going:
- Correspondent banking: beneficiary verification is likely to become more detailed
- Crypto Travel Rule: pressure to align the FATF standard with jurisdictions that still keep minimum thresholds
- Instant payment systems: a test of whether existing controls cover fast-payment rails adequately
The path is not ambiguous. More verified identity data will travel with payments, not less. Firms that still run identity verification as a periodic exercise, rather than as an infrastructure layer, will find these evolving standards harder to meet.
Joinble's AI Agents were built around that architecture: verified, structured identity records that stay current and can travel with transactions. As Recommendation 16 guidance continues to evolve, firms with continuous identity infrastructure and firms still on periodic review cycles will drift further apart.
The Practical Compliance Checklist
Within two weeks:
- Refresh country risk scores for Iraq and Bosnia-Herzegovina
- Record the Algeria and Namibia removals in the EWRA
- Mark existing customer portfolios with exposure to all four jurisdictions for review
Within 30 days:
- Finish customer-level risk reassessments on high-exposure relationships
- Refresh geographic risk parameters in transaction monitoring
- Brief relationship managers on the grey list changes and what those changes mean for risk
Within 90 days:
- Fold UK Presidency fraud priorities into the annual AML policy review
- Register for the Recommendation 16 consultation where it is relevant to operations
- Refresh EDD procedures documentation against the current 22-jurisdiction grey list
Firms already on continuous monitoring see a grey list change drop straight into risk scoring recalculations and review workflows. Firms still on periodic review cycles get another reason, with every grey list update, to move onto infrastructure that pushes jurisdictional changes through to individual customer risk profiles in real time.
FAQ
Does FATF grey-listing require automatic enhanced due diligence? No. Grey-listing feeds a risk-based assessment. It does not, by itself, trigger EDD. Firms have to update country risk models and apply enhanced measures only where the documented assessment supports that step. Applying blanket EDD or de-risking solely because of grey-list status, with no individual assessment, is itself a compliance problem.
Which sectors are most affected by Iraq's grey-listing? Highest risk sits with correspondent banking involving Iraqi banks, remittance flows, real estate with Iraqi beneficial owners, and virtual asset transfers linked to Iraq. Complex oil and gas payment chains that run through Gulf correspondent intermediaries also warrant heightened review.
What should firms do about existing customers from Algeria and Namibia? Document the removal first, then review each customer risk profile. EDD that existed specifically because of grey-list status needs a formal reassessment. If other risk factors still justify elevated measures, leave those measures in place and write down the rationale. The same process applies in both directions.
How does the grey list affect crypto-asset service providers specifically? For CASPs under the Travel Rule, grey-listed jurisdictions raise customer risk scores, and those scores should pass through to transaction monitoring thresholds. MiCA's TFR may require extra verification steps, beyond standard Travel Rule data transmission, on transfers linked to higher-risk counterparties.
What is the significance of the UK FATF Presidency's fraud focus? FATF's research, mutual evaluation, and guidance programs sit under the UK's two-year presidency. A fraud-first agenda means typologies reports, mutual evaluations, and guidance documents ahead will spend more time on the intersection of fraud, money laundering, and identity-based financial crime. That is how regulators will read what counts as adequate KYC controls.
What does the Recommendation 16 consultation mean for payment compliance? The signal is that FATF plans to update its wire transfer standard for modern payment systems, with fraud as a primary concern. Watch the outcomes. Then test whether current payment identification controls will satisfy the updated expectations once final guidance is published.
Related Articles

SR 26-2: The Governance Gap in AI-Powered KYC
The Fed's new model risk guidance explicitly excludes generative and agentic AI. For banks using AI in KYC, that gap is now a compliance liability.

KYB Under AMLR: The UBO Threshold Trap of 2027
44% of KYB processes will fail the EU AMLR's new UBO threshold rules from July 2027. Here's how to audit your beneficial ownership verification now.

EU Digital Omnibus: What the AI Act Delay Means for KYC
The EU Digital Omnibus entered into force July 27, extending high-risk AI deadlines to December 2027. Here is what it means for your KYC compliance stack.