Skip to content

FATF's June 2026 grey list: what it means for onboarding in affected markets

On 19 June 2026 the FATF added Bosnia and Herzegovina and Iraq to its grey list and removed Algeria and Namibia. A grey listing is a risk factor to weigh, not an instruction to apply enhanced due diligence or to exit a market.

Charles Archibong

, Co-founder

· 6 min read

Headline "The June 2026 grey list" beside an illustration of a globe with latitude and longitude lines, on a warm cream gradient.

Key takeaways

  • On 19 June 2026 the FATF added Bosnia and Herzegovina and Iraq to its grey list and removed Algeria and Namibia.
  • The FATF says a grey listing does not call for enhanced due diligence and does not envisage de-risking.
  • Enhanced due diligence is mandatory under Recommendation 19 only where the FATF calls for it: today DPRK, Iran and Myanmar.
  • Update country risk as one input among several, and record why each rating changed.

At its plenary in Paris from 17 to 19 June 2026, the FATF added Bosnia and Herzegovina and Iraq to its list of jurisdictions under increased monitoring (the "grey list") and removed Algeria and Namibia. Four listed jurisdictions, including Côte d'Ivoire and the Democratic Republic of the Congo, were judged to have substantially completed their action plans and now await on-site visits. The "black list" is unchanged in membership: DPRK, Iran and Myanmar.

The practical answer for onboarding teams is narrower than the headlines suggest. The FATF says in its own statement that it "does not call for the application of enhanced due diligence" to grey-listed jurisdictions and that its Standards "do not envisage derisking". A grey listing should move a country risk factor in your assessment, with a written reason. It should not trigger a blanket rule that every customer from Nairobi or Abidjan gets the same treatment as a customer with a sanctions exposure.

What exactly changed on 19 June 2026?

Here is the June 2026 position, taken from the FATF's statement on jurisdictions under increased monitoring (opens in a new tab) and the plenary outcomes (opens in a new tab), both dated 19 June 2026.

Change

Jurisdictions

Added to the grey list

Bosnia and Herzegovina, Iraq

Removed from the grey list

Algeria, Namibia

Action plan substantially completed, on-site visit pending

Bulgaria, Côte d'Ivoire, Democratic Republic of the Congo, Monaco

Chose to defer reporting (earlier statement repeated)

Kuwait, Papua New Guinea

Call for countermeasures (black list)

DPRK, Iran

Call for enhanced due diligence (black list)

Myanmar

The full grey list after this plenary has 22 names: Angola, Bolivia, Bosnia and Herzegovina, Bulgaria, Cameroon, Côte d'Ivoire, the Democratic Republic of the Congo, Haiti, Iraq, Kenya, Kuwait, Lao PDR, Lebanon, Monaco, Nepal, Papua New Guinea, South Sudan, Syria, Venezuela, Vietnam, the Virgin Islands (UK) and Yemen.

For firms working in Africa, six of those are African: Angola, Cameroon, Côte d'Ivoire, the DRC, Kenya and South Sudan. Two of those six, Côte d'Ivoire and the DRC, have moved to the stage before removal. Kenya remains listed, with an action plan that covers risk-based supervision, suspicious transaction reporting, beneficial ownership transparency for trusts and targeted financial sanctions.

On the call for action (opens in a new tab), the FATF repeated its call for countermeasures on DPRK and Iran. For Myanmar it asks for enhanced due diligence, and says that "if no further progress is made by October 2026, the FATF will consider countermeasures". That is a date worth putting in your compliance calendar.

Is a grey listing an instruction to apply enhanced due diligence?

No, and the distinction matters because many firms treat the two lists as one.

The FATF Recommendations separate them cleanly. Recommendation 19 (opens in a new tab) requires enhanced due diligence for business relationships and transactions with persons "from countries for which this is called for by the FATF", with measures that are "effective and proportionate to the risks". As of June 2026, that call covers DPRK, Iran and Myanmar.

The grey list is different. The FATF's statement says the jurisdictions are "actively working with the FATF", that it does not call for enhanced due diligence on them, and that it encourages members "to take into account the information presented below in their risk analysis". It also asks that flows of funds for humanitarian assistance, legitimate non-profit activity and remittances are "neither disrupted nor discouraged".

So a grey listing belongs inside your country risk factor. The Interpretive Note to Recommendation 10 gives, as an example of higher geographic risk, "countries identified by credible sources, such as mutual evaluation or detailed assessment reports or published follow-up reports, as not having adequate AML/CFT systems". It also says those examples are guidance, not mandatory elements.

National rules can go further than the FATF. Some supervisors do require enhanced measures for grey-listed countries, so check the rules that apply to you. Requirements differ by jurisdiction, and this article is general information, not legal advice.

How should a country risk rating change?

A defensible approach treats the FATF status as one input, weighted alongside the others you already use, and records the reason for any change.

  1. Separate the three FATF states in your data. Black list with countermeasures, black list with enhanced due diligence, and grey list are different obligations. Store them as distinct values, not one "FATF flag".

  2. Re-score the countries that moved. Bosnia and Herzegovina and Iraq move up. Algeria and Namibia move down, though their rating should still reflect everything else you know. A removal is not a clean bill of health.

  3. Read the action plan items as well as the list. Kenya's items include beneficial ownership information for trusts. If you onboard Kenyan legal arrangements, that is a specific gap your own beneficial ownership checks need to cover. A retail customer in Mombasa sending wages home carries a very different risk.

  4. Keep the rating out of individual decisions where it adds nothing. Country is one factor. Customer type, product, channel and behaviour usually tell you more about an individual customer than the country's supervisory regime does.

  5. Date and justify every change. "Raised to medium on 19 June 2026 following FATF increased-monitoring listing" is the kind of line an examiner expects to find.

A worked example: two customers, one country

A payments company onboards customers in Côte d'Ivoire and Kenya. Consider two applicants.

The first is an individual in Nairobi opening a wallet to receive salary and pay bills. Their identity is checked against the government record, their selfie matches the record photo, and nothing in screening flags. Their country is grey-listed, so the country factor rises. Every other factor is low. Under a risk-based approach this customer is standard risk, and adding enhanced due diligence would add friction without reducing risk.

The second is a newly registered Kenyan company with a trust among its shareholders, expecting high-value cross-border flows. Here the grey listing interacts with a named weakness in the action plan: beneficial ownership information for trusts. That combination justifies more: identifying who stands behind the trust, understanding the source of funds and monitoring the relationship more closely. The Interpretive Note to Recommendation 10 (opens in a new tab) (paragraph 20) lists those measures as examples of enhanced due diligence.

Same country, different answers. That is the risk-based approach working as the FATF describes it.

Where do the new listings show up in day-to-day controls?

Three places tend to need an update after each plenary.

  • Onboarding rules. If your decision rules route certain nationalities or countries of residence to manual review, update the list and check that the rule only reviews when combined with other factors, where your policy allows it.

  • Transaction monitoring. Country lists used by transaction rules drift out of date quickly. A payment from Algeria should no longer score as it did in May, and one to Iraq should score higher.

  • Periodic review scheduling. Customers whose country rating rose may move into a shorter review cycle. Customers whose rating fell do not need to be reviewed early just because of the change.

Myaza Trust can hold these settings in one place. The Transaction Monitoring Geography rule fires when an event's country is on your own high-risk or blocked list, and you edit those lists yourself as FATF statements change (monitoring rules documentation). Workflows include a geographic risk routing template that sends higher-risk nationalities or IP-country mismatches to review. You decide which countries go on the lists and why; the product does not decide that for you.

What should you do before the next plenary?

  • Update your country risk table for Bosnia and Herzegovina, Iraq, Algeria and Namibia, with the date and source.

  • Store black-list countermeasures, black-list EDD and grey-list status as separate values.

  • Check whether any regulator you answer to mandates enhanced measures for grey-listed countries, and write that down per market.

  • Review customers in newly listed jurisdictions only where the country change moves their overall rating, not all of them.

  • Diary Myanmar: the FATF has said it will consider countermeasures if there is no further progress by October 2026.

  • Re-check the FATF pages after each plenary. Statements are updated at every plenary, and this article reflects the June 2026 position as verified on 27 September 2026.

Sources

Charles Archibong

About the author

Charles Archibong

Co-founder

Charles Archibong co-founded Myaza Trust. He writes about identity verification, financial technology, and the practical work of building trusted digital services.

  • Headline "CBN automated AML standards" beside an illustration of stacked verification cards, on a warm cream gradient.

    Risk & Compliance

    CBN's baseline standards for automated AML: preparing your stack

    The CBN's baseline standards, issued on 10 March 2026, set mandatory minimum requirements for automated systems that detect, analyse and report suspicious activity in real time. The CBN has said compliance is assessed at the level of the institution, so buying a tool is a start, not an answer.

Build your product.We'll handle the rest.

Identity and compliance, end to end, built to global standards, priced for founders.

FATF June 2026 grey list: what changed · Myaza Trust