FATF's June 2026 grey list: what it means for onboarding in affected markets
On 19 June 2026 the FATF added Bosnia and Herzegovina and Iraq to its grey list and removed Algeria and Namibia. A grey listing is a risk factor to weigh, not an instruction to apply enhanced due diligence or to exit a market.

Charles Archibong, Co-founder
· 6 min read

Key takeaways
- On 19 June 2026 the FATF added Bosnia and Herzegovina and Iraq to its grey list and removed Algeria and Namibia.
- The FATF says a grey listing does not call for enhanced due diligence and does not envisage de-risking.
- Enhanced due diligence is mandatory under Recommendation 19 only where the FATF calls for it: today DPRK, Iran and Myanmar.
- Update country risk as one input among several, and record why each rating changed.
At its plenary in Paris from 17 to 19 June 2026, the FATF added Bosnia and Herzegovina and Iraq to its list of jurisdictions under increased monitoring (the "grey list") and removed Algeria and Namibia. Four listed jurisdictions, including Côte d'Ivoire and the Democratic Republic of the Congo, were judged to have substantially completed their action plans and now await on-site visits. The "black list" is unchanged in membership: DPRK, Iran and Myanmar.
The practical answer for onboarding teams is narrower than the headlines suggest. The FATF says in its own statement that it "does not call for the application of enhanced due diligence" to grey-listed jurisdictions and that its Standards "do not envisage derisking". A grey listing should move a country risk factor in your assessment, with a written reason. It should not trigger a blanket rule that every customer from Nairobi or Abidjan gets the same treatment as a customer with a sanctions exposure.
What exactly changed on 19 June 2026?
Here is the June 2026 position, taken from the FATF's statement on jurisdictions under increased monitoring (opens in a new tab) and the plenary outcomes (opens in a new tab), both dated 19 June 2026.
Change | Jurisdictions |
|---|---|
Added to the grey list | Bosnia and Herzegovina, Iraq |
Removed from the grey list | Algeria, Namibia |
Action plan substantially completed, on-site visit pending | Bulgaria, Côte d'Ivoire, Democratic Republic of the Congo, Monaco |
Chose to defer reporting (earlier statement repeated) | Kuwait, Papua New Guinea |
Call for countermeasures (black list) | DPRK, Iran |
Call for enhanced due diligence (black list) | Myanmar |
The full grey list after this plenary has 22 names: Angola, Bolivia, Bosnia and Herzegovina, Bulgaria, Cameroon, Côte d'Ivoire, the Democratic Republic of the Congo, Haiti, Iraq, Kenya, Kuwait, Lao PDR, Lebanon, Monaco, Nepal, Papua New Guinea, South Sudan, Syria, Venezuela, Vietnam, the Virgin Islands (UK) and Yemen.
For firms working in Africa, six of those are African: Angola, Cameroon, Côte d'Ivoire, the DRC, Kenya and South Sudan. Two of those six, Côte d'Ivoire and the DRC, have moved to the stage before removal. Kenya remains listed, with an action plan that covers risk-based supervision, suspicious transaction reporting, beneficial ownership transparency for trusts and targeted financial sanctions.
On the call for action (opens in a new tab), the FATF repeated its call for countermeasures on DPRK and Iran. For Myanmar it asks for enhanced due diligence, and says that "if no further progress is made by October 2026, the FATF will consider countermeasures". That is a date worth putting in your compliance calendar.
Is a grey listing an instruction to apply enhanced due diligence?
No, and the distinction matters because many firms treat the two lists as one.
The FATF Recommendations separate them cleanly. Recommendation 19 (opens in a new tab) requires enhanced due diligence for business relationships and transactions with persons "from countries for which this is called for by the FATF", with measures that are "effective and proportionate to the risks". As of June 2026, that call covers DPRK, Iran and Myanmar.
The grey list is different. The FATF's statement says the jurisdictions are "actively working with the FATF", that it does not call for enhanced due diligence on them, and that it encourages members "to take into account the information presented below in their risk analysis". It also asks that flows of funds for humanitarian assistance, legitimate non-profit activity and remittances are "neither disrupted nor discouraged".
So a grey listing belongs inside your country risk factor. The Interpretive Note to Recommendation 10 gives, as an example of higher geographic risk, "countries identified by credible sources, such as mutual evaluation or detailed assessment reports or published follow-up reports, as not having adequate AML/CFT systems". It also says those examples are guidance, not mandatory elements.
National rules can go further than the FATF. Some supervisors do require enhanced measures for grey-listed countries, so check the rules that apply to you. Requirements differ by jurisdiction, and this article is general information, not legal advice.
How should a country risk rating change?
A defensible approach treats the FATF status as one input, weighted alongside the others you already use, and records the reason for any change.
Separate the three FATF states in your data. Black list with countermeasures, black list with enhanced due diligence, and grey list are different obligations. Store them as distinct values, not one "FATF flag".
Re-score the countries that moved. Bosnia and Herzegovina and Iraq move up. Algeria and Namibia move down, though their rating should still reflect everything else you know. A removal is not a clean bill of health.
Read the action plan items as well as the list. Kenya's items include beneficial ownership information for trusts. If you onboard Kenyan legal arrangements, that is a specific gap your own beneficial ownership checks need to cover. A retail customer in Mombasa sending wages home carries a very different risk.
Keep the rating out of individual decisions where it adds nothing. Country is one factor. Customer type, product, channel and behaviour usually tell you more about an individual customer than the country's supervisory regime does.
Date and justify every change. "Raised to medium on 19 June 2026 following FATF increased-monitoring listing" is the kind of line an examiner expects to find.
A worked example: two customers, one country
A payments company onboards customers in Côte d'Ivoire and Kenya. Consider two applicants.
The first is an individual in Nairobi opening a wallet to receive salary and pay bills. Their identity is checked against the government record, their selfie matches the record photo, and nothing in screening flags. Their country is grey-listed, so the country factor rises. Every other factor is low. Under a risk-based approach this customer is standard risk, and adding enhanced due diligence would add friction without reducing risk.
The second is a newly registered Kenyan company with a trust among its shareholders, expecting high-value cross-border flows. Here the grey listing interacts with a named weakness in the action plan: beneficial ownership information for trusts. That combination justifies more: identifying who stands behind the trust, understanding the source of funds and monitoring the relationship more closely. The Interpretive Note to Recommendation 10 (opens in a new tab) (paragraph 20) lists those measures as examples of enhanced due diligence.
Same country, different answers. That is the risk-based approach working as the FATF describes it.
Where do the new listings show up in day-to-day controls?
Three places tend to need an update after each plenary.
Onboarding rules. If your decision rules route certain nationalities or countries of residence to manual review, update the list and check that the rule only reviews when combined with other factors, where your policy allows it.
Transaction monitoring. Country lists used by transaction rules drift out of date quickly. A payment from Algeria should no longer score as it did in May, and one to Iraq should score higher.
Periodic review scheduling. Customers whose country rating rose may move into a shorter review cycle. Customers whose rating fell do not need to be reviewed early just because of the change.
Myaza Trust can hold these settings in one place. The Transaction Monitoring Geography rule fires when an event's country is on your own high-risk or blocked list, and you edit those lists yourself as FATF statements change (monitoring rules documentation). Workflows include a geographic risk routing template that sends higher-risk nationalities or IP-country mismatches to review. You decide which countries go on the lists and why; the product does not decide that for you.
What should you do before the next plenary?
Update your country risk table for Bosnia and Herzegovina, Iraq, Algeria and Namibia, with the date and source.
Store black-list countermeasures, black-list EDD and grey-list status as separate values.
Check whether any regulator you answer to mandates enhanced measures for grey-listed countries, and write that down per market.
Review customers in newly listed jurisdictions only where the country change moves their overall rating, not all of them.
Diary Myanmar: the FATF has said it will consider countermeasures if there is no further progress by October 2026.
Re-check the FATF pages after each plenary. Statements are updated at every plenary, and this article reflects the June 2026 position as verified on 27 September 2026.
Sources
Jurisdictions under Increased Monitoring, FATF, 19 June 2026 (opens in a new tab)
High-Risk Jurisdictions subject to a Call for Action, FATF, 19 June 2026 (opens in a new tab)
Outcomes FATF Plenary, 17-19 June 2026, FATF, 19 June 2026 (opens in a new tab)
The FATF Recommendations, updated October 2025 (R.19, INR.10) (opens in a new tab)

Charles Archibong
Co-founder
Charles Archibong co-founded Myaza Trust. He writes about identity verification, financial technology, and the practical work of building trusted digital services.


