FATF 40 Recommendations Explained (KYC-AML 2026)
The FATF 40 Recommendations are the global benchmark against which every Indian bank's anti-money-laundering programme is measured, and in 2026 they sit at the heart of the IIBF Certificate in KYC, AML and CFT. When the Financial Action Task Force completed India's Mutual Evaluation in the last cycle, it graded the country "largely compliant" on most of the technical criteria — a result that flows directly from how the FATF 40 Recommendations are transposed into the PMLA 2002, the RBI KYC Master Direction, and FIU-IND reporting duties. For a candidate, understanding this framework is not academic: it explains why your branch demands beneficial-ownership declarations, screens against sanctions lists, and files Suspicious Transaction Reports.
This article unpacks the structure of the FATF 40 Recommendations, links each cluster to the Indian rulebook you apply at the counter, and shows how examiners frame questions around risk-based supervision, correspondent banking and virtual assets. Treat it as a bridge between an international standard and your daily compliance checklist.
The seven clusters of the FATF 40 Recommendations
The FATF organises its standards into seven groups. Understanding the grouping is the fastest way to memorise the framework for the exam and to reason about real cases at work:
- AML/CFT Policies and Coordination (R.1–2): mandates a national risk assessment and a risk-based approach — the source of India's National Risk Assessment on money laundering.
- Money Laundering and Confiscation (R.3–4): criminalising laundering and enabling asset seizure, mirrored in PMLA Sections 3, 4 and the attachment powers of the Enforcement Directorate.
- Terrorist Financing and Proliferation (R.5–8): covering the UAPA-linked sanctions screening banks perform against UNSC lists.
- Preventive Measures (R.9–23): the largest cluster — customer due diligence, record-keeping, PEPs, correspondent banking, wire transfers, and reliance on third parties.
- Transparency of Legal Persons (R.24–25): beneficial ownership of companies and trusts.
- Powers of Competent Authorities (R.26–35): supervision, FIUs and sanctions.
- International Cooperation (R.36–40): mutual legal assistance and extradition.
For the preventive-measures cluster especially, expect the IIBF paper to test whether you can match a recommendation number to its Indian equivalent. Reinforce the mapping with focused practice on the iibf.store mock tests before exam day.
Recommendation 10: Customer Due Diligence in Indian practice
Recommendation 10 is the beating heart of preventive measures and the single most examined idea in the certificate. It requires CDD in four situations: establishing a business relationship, occasional transactions above the threshold, suspicion of laundering or terrorist financing, and doubt about the veracity of earlier identification data. India codifies this through the RBI KYC Master Direction, which layers Aadhaar-based e-KYC, video-based Customer Identification (V-CIP) and periodic re-KYC on top of the FATF baseline.
Crucially, R.10 demands a risk-based intensity of due diligence. Low-risk customers — salaried resident individuals with small balances — receive simplified measures, while high-risk profiles trigger Enhanced Due Diligence: senior-management sign-off, source-of-funds verification and closer ongoing monitoring. This is why your core banking system flags a sudden spike in a dormant account for review. The examiner often presents a scenario and asks you to classify the customer's risk category and prescribe the matching CDD level. Study the three-tier risk categorisation (low, medium, high) until it is automatic, and connect it to the broader banking-law syllabus in the CAIIB programme.

PEPs, correspondent banking and beneficial ownership
Three of the most error-prone topics in the certificate all live in the preventive cluster. Politically Exposed Persons (R.12) are individuals entrusted with prominent public functions; India applies EDD, senior-management approval and enhanced monitoring to them and their close associates. A common exam trap: domestic PEPs and foreign PEPs both require scrutiny under the current Master Direction, so do not assume only foreign officials qualify.
Correspondent banking (R.13) obliges the respondent-vetting, purpose-gathering and "payable-through account" controls that stop shell banks from riding on a legitimate institution's rails; it also prohibits relationships with shell banks outright. Beneficial ownership (R.24–25) requires banks to look through corporate veils and trusts to the natural person who ultimately owns or controls 10% or more (25% for companies under Indian rules in most cases) of the entity. These map to FIU-IND's expectations on Suspicious Transaction Reports and to the Companies Act significant-beneficial-owner register.
Sharpen recall of these definitions with quick drills on the match-the-concept game, which is well suited to definition-heavy AML terms.
A subtle point examiners exploit is the interaction between these controls. A correspondent-banking relationship with a bank that serves PEP-heavy jurisdictions, holding accounts for opaque trusts, stacks three high-risk factors at once — and the risk-based approach demands the intensity of due diligence scale with that accumulation, not merely with any single flag. Recommendation 20 then closes the loop: where suspicion arises, the bank must file a Suspicious Transaction Report to FIU-IND promptly, regardless of the amount, and must not tip off the customer. This "report, do not warn" discipline, drawn straight from the FATF standards, is frequently tested through short scenario prompts, so rehearse the trigger conditions until you can identify them instantly.
Virtual assets, the risk-based approach and India's evaluation
Recommendation 15 was amended to bring Virtual Asset Service Providers (VASPs) into the AML net, introducing the now-famous "Travel Rule" that requires originator and beneficiary information to accompany crypto transfers. India registers VASPs with FIU-IND and applies PMLA reporting to them — a live topic the 2026 exam is likely to probe. The overarching principle threaded through every recommendation is the risk-based approach (R.1): resources concentrate where laundering risk is highest rather than being spread uniformly.
India's FATF Mutual Evaluation rated the country strongly on technical compliance while flagging areas for improved effectiveness, particularly timely conclusion of prosecutions and supervision of designated non-financial businesses. You can read the authoritative standard directly from the source at the Financial Action Task Force.
Keep an eye on regulatory updates through iibf.store news, and revisit RBI's benchmark rates and circulars via the RBI resources page so your answers stay current.

Frequently asked questions

Related study material
Go deeper with the full chapter notes and the complete article hub for this subject:
- REPORTING OBLIGATIONS OF BANKS
- 10 A REPORTING OBLIGATIONS OF BANKS
- All KYC, AML and CFT articles & notes
How many FATF Recommendations are there and how are they organised?
There are 40 Recommendations, organised into seven thematic clusters ranging from national AML/CFT policies to international cooperation. The largest cluster, preventive measures (R.9–23), covers customer due diligence, PEPs, correspondent banking and wire transfers.
Which FATF Recommendation covers Customer Due Diligence?
Recommendation 10 covers CDD. It requires identifying and verifying customers, understanding the business relationship, conducting ongoing monitoring, and applying a risk-based intensity of due diligence — the basis for India's RBI KYC Master Direction.
What is the FATF Travel Rule for crypto?
Under Recommendation 15, the Travel Rule requires Virtual Asset Service Providers to obtain and transmit originator and beneficiary information alongside virtual-asset transfers, mirroring the wire-transfer rule (R.16) for traditional payments.
How do the FATF 40 Recommendations relate to India's PMLA?
The PMLA 2002, its rules, the RBI KYC Master Direction and FIU-IND reporting obligations transpose the FATF standards into enforceable Indian law. India's compliance is periodically assessed through the FATF Mutual Evaluation process.
Conclusion: turn the framework into marks
The FATF 40 Recommendations are the scaffolding on which India's entire KYC-AML-CFT edifice is built, so mastering the seven clusters and their PMLA counterparts gives you a durable advantage across the certificate. Focus your revision on Recommendation 10's risk-based CDD, PEP and beneficial-ownership definitions, and the virtual-asset amendments — these dominate the paper. Ready to test yourself under exam conditions? Take a full-length AML mock now at iibf.store/tests and lock in the framework before your exam date.
Quick quiz on this topic
5 exam-style questions from our free test bank — check yourself before you move on.
Practice this topic
Take a free mock test, download chapter PDFs, or watch a video class — all included on iibf.store.
Keep reading