Blog

Jurisdictions & Regulation

A Detailed Guide to AML Compliance Around the World

How the FATF Recommendations become binding national law: supervisors, reporting thresholds and deadlines across the US, EU, UK, Australia, Canada, Singapore and Asia.

There is no global AML law. The FATF Recommendations set one standard, and each jurisdiction transposes it into its own statute, rules and supervisory architecture. What varies is not the principle but the detail that programmes run on: who supervises you, which sectors are in scope, what you report, and by when.

Key takeaways

  • Obligations come from national law, never from FATF directly. FATF pressure works through mutual evaluation and listing for increased monitoring, of which 22 jurisdictions were subject after the June 2026 plenary.
  • Filing clocks diverge sharply. Australia allows three business days for a suspicious matter report and 24 hours where terrorism financing is suspected; a US bank has 30 calendar days.
  • Scope is expanding on fixed dates. Australia regulates its tranche 2 professions from 1 July 2026, and the US investment adviser rule applies from 1 January 2028.
  • The EU is replacing directive-based national variation with directly applicable Regulation (EU) 2024/1624 from 10 July 2027, supervised in part by AMLA from 2028.
  • Grey listing is a risk factor to weigh, not an automatic legal trigger. Mandatory enhanced due diligence in the UK attaches to call-for-action countries only.

What force do the FATF Recommendations actually have?

None, directly. The 40 Recommendations are political commitments, and no business has ever been fined for breaching them. They become enforceable only when a legislature writes them into statute, which is why the same standard produces a 31 CFR chapter in the United States, a directly applicable regulation in the EU, and a principal Act plus supervisor-made rules in Australia.

The leverage sits in mutual evaluation and follow-up. Assessors score both technical compliance with each Recommendation and effectiveness in practice, and a weak result can lead to increased monitoring, which raises correspondent banking friction long before any domestic law changes.

Two standard revisions matter for planning. Recommendation 16, covering payment transparency, was revised in June 2025 with global implementation expected by the end of 2030, and Recommendation 6 was amended in June 2026 so that targeted financial sanctions do not obstruct humanitarian flows.

Which supervisor and FIU do you actually answer to?

The supervisor and the financial intelligence unit are frequently different bodies, and confusing them wastes remediation effort. You report to the FIU; you are examined by the supervisor.

JurisdictionPrincipal instrumentAML supervisorFinancial intelligence unit
United StatesBank Secrecy Act, 31 CFR Chapter XDelegated to functional regulators (OCC, FDIC, Federal Reserve, SEC, IRS)FinCEN
European UnionRegulation (EU) 2024/1624, Directive (EU) 2024/1640National supervisors, plus AMLA directly from 2028National FIUs
United KingdomMoney Laundering Regulations 2017 (SI 2017/692)FCA, HMRC and the professional body supervisors overseen by OPBASUK Financial Intelligence Unit, in the National Crime Agency
AustraliaAML/CTF Act 2006 and AML/CTF RulesAUSTRACAUSTRAC
CanadaProceeds of Crime (Money Laundering) and Terrorist Financing ActFINTRACFINTRAC
SingaporeMAS Notice 626 and sector noticesMASSuspicious Transaction Reporting Office
JapanAct on Prevention of Transfer of Criminal ProceedsFSA and sector ministriesJAFIC, in the National Police Agency
ChinaAnti-Money Laundering LawPeople's Bank of China for AML, NFRA prudentiallySits within the People's Bank of China

Note the two structural models. Australia, Canada and Singapore combine intelligence and supervision in one body, while the US and EU split them, which means an examiner who has never seen your filings.

How far do reporting thresholds and deadlines diverge?

Far enough that a single global reporting rule is unbuildable. The thresholds below are the ones most often mis-set in configuration, because teams copy a familiar figure from a home jurisdiction into a foreign entity.

JurisdictionCash or occasional-transaction triggerSuspicious report deadline
United StatesCurrency transaction report above USD 10,000 in a business day, filed within 15 days30 calendar days from initial detection, 60-day maximum, from USD 5,000 with a suspect
AustraliaThreshold transaction report at AUD 10,000 or more in physical currency, filed within 10 business daysThree business days, or 24 hours for terrorism financing
CanadaLarge cash and large virtual currency transaction reporting under the PCMLTFAAs soon as practicable, no fixed day count
SingaporeCDD on occasional transactions above SGD 20,000 and wire transfers above SGD 1,500Immediately on suspicion, to the Suspicious Transaction Reporting Office
European UnionCash payment ceiling of EUR 10,000 from 10 July 2027Set by national law, to the national FIU

Australia also introduced a AUD 5,000 threshold for certain gambling services alongside its reformed customer due diligence obligations, per AUSTRAC's transitional rules. Thresholds like that one are the reason jurisdiction-specific rules belong in a configurable engine, not in code.

What changes when the EU moves from directives to a regulation in 2027?

Everything about how you maintain an EU programme. Directives had to be transposed, so 27 member states produced 27 variants of the same obligation, and a group treasury function had to track all of them. The 2024 package replaces the substantive rules with Regulation (EU) 2024/1624, which applies directly from 10 July 2027 without national transposition.

Directive (EU) 2024/1640 still governs supervisory powers, FIU arrangements and registers, so national variation survives on the institutional side rather than in the customer-facing rules. The beneficial ownership definition remains a 25% ownership prong plus a separate control prong.

The practical work is a rule-by-rule diff between your current national implementation and the regulation. Anything you built to accommodate a local carve-out now needs a decision: retire it, or justify it as a stricter internal control.

Which sectors are being brought into scope, and on what dates?

Scope expansion is the most predictable part of global AML, because it follows FATF's designated non-financial businesses and professions category. Australia is the current example. From 1 July 2026 AUSTRAC regulates real estate professionals, conveyancers, accountants, legal professionals, trust and company service providers, dealers in precious metals and stones, and virtual asset services beyond the previously regulated exchange model.

The United States is expanding differently, by entity type rather than profession. FinCEN has postponed the investment adviser rule to 1 January 2028, and residential real estate transfer reporting began on 1 March 2026. Beneficial ownership went the other way: US-formed entities are now exempt from Corporate Transparency Act reporting, so the registry is no longer a verification source for domestic companies.

For firms already in scope, the effect is second-order. Newly regulated professions become customers who now hold AML obligations of their own, which changes what you can reasonably expect them to evidence. Our tranche 2 guidance sets out the Australian detail.

How should a global programme treat FATF grey-listing?

As an input to risk scoring, not as a legal trigger. After the June 2026 plenary, 22 jurisdictions were under increased monitoring, with Iraq and Bosnia and Herzegovina added and Algeria and Namibia removed.

The legal distinction matters. Under regulation 33 of the UK Money Laundering Regulations 2017, mandatory enhanced due diligence attaches to high-risk third countries subject to a call for action, alongside PEPs, correspondent relationships and unusually complex transactions. A grey-listed country is not automatically in that set, so treating the two lists identically is a policy choice you must document rather than an obligation.

Listing also moves in both directions, and exits are where programmes go stale. If your country risk table is a spreadsheet updated after each plenary by hand, you will be applying enhanced measures to a jurisdiction that left the list months earlier, and failing to apply them to one that joined.

Why does supervisory architecture change your operating model?

Because it determines who asks you questions and what evidence they accept. Where supervision is delegated, as in the United States, a bank, a broker-dealer and a money services business face different examiners applying the same underlying rules with different examination manuals. Consistency across group entities becomes your problem, not the supervisor's.

The trend is towards consolidation. New Zealand moved to a single supervisor on 1 July 2026, with the Department of Internal Affairs taking responsibility for banks, casinos, law firms, accountants, real estate agents and virtual asset service providers that were previously split across three agencies. The EU is heading the same way, with AMLA in Frankfurt am Main directly supervising selected cross-border institutions from 2028.

Consolidation cuts duplicated engagement but raises the bar on documentation, because a single supervisor sees your whole population at once. Inconsistent risk ratings for comparable customers in different business lines become visible immediately.

What does a defensible multi-jurisdiction programme look like?

It applies the strictest applicable standard per relationship and records which standard it applied, why, and when. A uniform global policy fails in both directions at once: over-engineered where local law is lighter, and short of the mark where a jurisdiction sets an enumerated trigger your generic process does not recognise.

Four things make that workable in practice:

  • A jurisdiction risk methodology with a documented refresh cadence tied to plenary outcomes.
  • Threshold and deadline values held as configuration per entity, rather than hard-coded.
  • Screening that rescreens the customer record continuously rather than at scheduled review dates.
  • An audit trail that can reconstruct the rule set in force on the day a decision was made.

MemberCheck maintains country-level sanctions, PEP and adverse media coverage against this kind of per-jurisdiction configuration, which is what makes the last requirement achievable. Start with our jurisdiction risk and AML risk assessment pages, the country coverage index for regime-level detail on markets such as the United States and Singapore, and the definitions in our glossary of AML terms. Related reading sits in FATF mutual evaluations, AML in the USA and our jurisdictions and regulation collection.

FAQ

Common questions.

Are the FATF Recommendations legally binding?
No. The FATF Recommendations are not law anywhere. They bind jurisdictions politically through mutual evaluation and the risk of being listed for increased monitoring, and they only create obligations for a business once a national parliament or regulator transposes them into domestic law and rules.
Which reporting thresholds differ most between jurisdictions?
Cash and occasional-transaction thresholds. The United States requires a currency transaction report above USD 10,000 and a bank suspicious activity report from USD 5,000. Australia requires a threshold transaction report at AUD 10,000 in physical currency. Singapore requires customer due diligence on occasional transactions above SGD 20,000 and wire transfers above SGD 1,500. The EU will cap cash payments at EUR 10,000.
How quickly must a suspicious report be filed in different countries?
There is no common clock. A US bank has 30 calendar days from initial detection, with a 60-day maximum. An Australian reporting entity has three business days, or 24 hours where terrorism financing is suspected. In Canada a suspicious transaction report is due as soon as practicable after the assessment is complete, with no fixed day count.
Does a FATF grey listing automatically require enhanced due diligence?
Not by itself in most regimes. Under regulation 33 of the UK Money Laundering Regulations 2017, mandatory enhanced due diligence attaches to high-risk third countries subject to a call for action, not to every jurisdiction under increased monitoring. Grey listing is a risk factor your methodology must weigh and document, not an automatic legal trigger.
Who supervises AML compliance in the European Union from 2028?
The Anti-Money Laundering Authority (AMLA), created by Regulation (EU) 2024/1620 and headquartered in Frankfurt am Main, will directly supervise a selected group of the EU's most significant cross-border financial institutions from 2028. National supervisors retain responsibility for everyone else.
Which sectors are being brought into AML scope next?
Australia begins regulating real estate professionals, conveyancers, accountants, legal professionals, trust and company service providers, dealers in precious metals and stones, and additional virtual asset services from 1 July 2026. In the United States, the investment adviser rule takes effect on 1 January 2028.

See MemberCheck against your own risk data.

Book a walkthrough with our compliance team and screen a real case in the first session.