Microfinance institutions (MFIs) exist to serve people traditional banking doesn't reach — small loans, savings, and insurance for the unbanked, delivered through a peer-to-peer lending model that has become a multi-trillion-dollar industry across Asia, Africa, Europe, and beyond. That same design, built specifically to lower the barriers formal banking imposes, is exactly what creates real AML/CTF exposure for the sector.
Why is microfinance structurally harder to secure than traditional banking?
Because the model's success depends on relaxing the rules a bank would normally apply: loan amounts are small, borrowers are geographically dispersed across villages, and most lack conventional legal identification. Waiving strict onboarding is the point — it's what makes microfinance work as a poverty-reduction and financial-inclusion tool — but it also means many MFIs operate informally, outside the regulatory perimeter that would normally require KYC, sitting closer to the shadow banking system than to a supervised financial institution.
How does laundering actually happen through an MFI?
Illicit funds — proceeds of bribery, corruption, or other crime — are invested into an MFI as shareholder capital or ordinary deposits. That money is then lent out as microloans to genuine borrowers; as loans are repaid and reissued, the original funds become progressively indistinguishable from the MFI's legitimate lending activity, completing the same integration that laundering always aims for, just through a channel with far less scrutiny than a bank.
Does this extend to terrorism financing too?
Yes, and through more than one route. Some NGOs with genuine international reach and funding networks have been identified — including by FATF's own publications on non-profit sector risk — as fronts for terrorism financing or channels for political influence-buying, in some cases transforming into or partnering with MFIs specifically because the sector is less regulated. Separately, foreign terrorist fighter financing schemes have used small, individually unremarkable microloans — nominally for household goods — specifically because the amounts are too small to trigger the scrutiny a larger transaction would face, while still functioning as a conduit for financing individual attacks or crowdsourced support for terror networks abroad.
What can MFIs actually do about this without undermining financial inclusion?
The tension is real — the whole value of microfinance depends on not recreating the onboarding barriers formal banking imposes — but several controls add real AML value without doing that. Formal licensing of MFI operations. Partnerships with fintech providers that already have compliance infrastructure built. Access to affordable, cloud-based sanctions and PEP screening rather than assuming a small MFI can't afford it. Transparent ownership structures, so the institution itself isn't a shell entity in disguise. And documented source-of-funds checks on the capital an MFI is actually lending out, not just on individual borrowers. The goal is separating ordinary microloan activity from the specific patterns — multiple small amounts, common beneficiaries, single locations, similar transaction shapes repeating — that indicate something else is happening underneath it.



