FATF Grey Listing and Indian Banks: What Bankers Must Know

KYCAML By Ashish Jain · IIBF STORE Editorial · 24 August 2026 · Updated 08 Oct 2026 · 10 min read · 39 views
FATF Grey Listing and Indian Banks: What Bankers Must Know

Every time a country slips onto the FATF grey list, compliance desks across Indian banks get busy — correspondent banking limits get reviewed, country risk ratings get revised, and due diligence on affected customers tightens overnight. For JAIIB and CAIIB candidates, FATF grey listing and Indian banks is a recurring exam theme because it sits at the intersection of international AML standards and day-to-day branch compliance. This article breaks down what the grey list actually is, why it matters to an Indian bank's operations, and how the country-risk framework responds when a jurisdiction is flagged.

🌍 What Is the FATF Grey List

The Financial Action Task Force (FATF) is the global standard-setter for anti-money laundering and counter-terrorist financing (AML/CFT). It does not maintain a single "grey list" in its own documents — the formal name is "Jurisdictions under Increased Monitoring." A country lands here when FATF's review process finds strategic deficiencies in its AML/CFT framework, but the country has made a written, high-level political commitment to fix them within an agreed timeframe.

This is different from the "High-Risk Jurisdictions subject to a Call for Action" list — the informal "black list" — reserved for countries that have failed to act, where FATF calls on members to apply counter-measures. Both lists are updated at FATF plenary sessions, held roughly three times a year, after review by the FATF's International Co-operation Review Group.

For exam purposes, remember the distinction is about commitment and progress, not just risk level: a grey-listed country is working with FATF on an action plan, while a black-listed one is not. Candidates preparing this topic alongside international guidelines & standards will find the plenary process and mutual evaluation cycle covered in depth.

💡 Exam Tip: If a question asks which body issues the grey list, the answer is FATF, not FIU-India or the RBI — Indian regulators only transmit and enforce the resulting due diligence obligations domestically.

🏦 Why FATF Grey Listing and Indian Banks Are Closely Linked

Indian banks do not deal with FATF directly, but every grey-listing decision travels quickly into branch-level compliance. When a jurisdiction is placed under increased monitoring, banks with exposure to that country — through trade finance, remittances, correspondent accounts, or customers with ties there — are expected to apply enhanced due diligence (EDD) rather than standard KYC.

This connects directly to the RBI's KYC/AML framework, which requires banks to factor country risk into customer risk categorisation. A customer whose transactions route through, or whose beneficial owner is based in, a grey-listed jurisdiction typically gets escalated to high-risk status, triggering more frequent periodic KYC updation and closer transaction monitoring. That updated risk profile also gets reflected the next time the bank checks the customer's CKYC ID record, since risk category is one of the fields shared across the Central KYC Records Registry.

The practical impact shows up in three places: correspondent banking relationships get re-evaluated for continuation or restriction, trade finance documents from the affected country get extra scrutiny for trade-based money laundering red flags, and wire transfers involving the jurisdiction get flagged for manual review rather than straight-through processing.

None of this requires a new law each time — it flows from the existing PMLA framework and RBI's Master Direction on KYC, which already build in country-risk-based due diligence as a standing obligation.

FATF plenary review process for jurisdictions under increased monitoring
FATF plenary review process for jurisdictions under increased monitoring

📜 FATF Standards and India's Own Compliance Track Record

India has been a FATF member since 2010 and is periodically assessed itself through a Mutual Evaluation. The most recent round, concluding in 2024, placed India in the "regular follow-up" category — a group reserved for the strongest-performing jurisdictions, meaning no major follow-up action plan was required. This matters for bankers because it validates the domestic AML architecture — PMLA, the KYC Master Direction, and FIU-India's reporting mechanism — as broadly aligned with FATF's 40 Recommendations.

That domestic architecture is exactly what candidates study under legislation at national level, which maps how India's laws implement FATF standards. The link between global standard-setting and national law is a favourite examiner angle: FATF sets the benchmark, individual countries legislate to meet it, and mutual evaluations check whether the legislation actually works in practice, not just on paper.

Being off the grey and black lists gives Indian banks a lighter compliance burden when dealing with each other and with correspondents abroad — foreign banks apply standard, not enhanced, due diligence on Indian counterparties as a result.

⚠️ Common Mistake: Students often assume grey-listing is purely about a country's crime rate. It is actually about the adequacy of that country's AML/CFT laws, supervision, and enforcement — a low-crime country with weak legislation can still be grey-listed.
Correspondent banking due diligence checkpoints for high-risk countries
Correspondent banking due diligence checkpoints for high-risk countries

🔗 Correspondent Banking and Country Risk After a Grey Listing

Correspondent banking is where grey-list effects bite hardest. A correspondent bank in India that maintains a "nostro/vostro" relationship with a bank headquartered in a grey-listed country must apply enhanced due diligence on that relationship under RBI's correspondent banking norms — this includes gathering more information on the respondent bank's ownership, AML controls, and the purpose of the account.

This is covered in detail under correspondent banking, where the specific due diligence steps — verifying the respondent's regulatory status, assessing its AML/CFT controls, and obtaining senior management approval before establishing new relationships — are laid out. Grey-listing is one of the clearest real-world triggers for that heightened scrutiny.

Country risk itself is scored using multiple inputs beyond FATF status — sanctions exposure, corruption indices, and the strength of a jurisdiction's regulatory and supervisory regime all feed in. The country risk and money laundering chapter walks through how banks build a country-risk matrix and slot customers into it, which is the mechanism that actually operationalises a FATF grey-list update into a branch-level EDD trigger.

Country risk categorisation flow inside a bank's AML compliance function
Country risk categorisation flow inside a bank's AML compliance function

🧭 How Indian Banks Respond: EDD, Structure and Escalation

When FATF adds or removes a jurisdiction from its lists, the response inside a bank typically flows through a defined structure rather than ad hoc branch decisions. The Principal Officer and the bank's AML/CFT compliance function update the internal country-risk list, which then feeds automated alerts in the transaction monitoring system and resets risk ratings for affected customer profiles.

This governance chain is exactly what is tested under organization structure in India — who owns the decision, who reports to FIU-India, and how the board-approved AML policy gets updated when external risk factors like a FATF list change. Front-line staff also need to re-verify officially valid documents for KYC where a customer's declared jurisdiction has shifted risk category, and PEP screening gets tightened for customers connected to newly grey-listed states — see our related piece on politically exposed persons in KYC for how PEP status compounds with country risk.

Increasingly, cross-border laundering schemes also lean on cyber-enabled channels — fraudulent trade invoices routed through compromised systems, or mule accounts opened using stolen credentials — which is why compliance teams are expected to have baseline awareness of computer insecurity threats in banking alongside their AML training.

📌 Remember: Grey-list status is reviewed and can change at every FATF plenary — banks must treat their country-risk list as a living document, not a one-time setup.

🚨 Consequences of Grey Listing: A Quick Comparison

The table below summarises how FATF's two lists differ in practice, and what each means for an Indian bank's compliance response.

ListOfficial FATF NameWhat It SignalsBank Action Required
Grey ListJurisdictions under Increased MonitoringDeficiencies identified; country has committed to an action planEnhanced due diligence mandatory; relationships generally continue
Black ListHigh-Risk Jurisdictions subject to a Call for ActionCountry has failed to address deficienciesCounter-measures applied; correspondent ties often ❌ restricted or severed
Neither ListRegular follow-up jurisdictionAML/CFT framework assessed as broadly adequateStandard CDD applies; EDD only if customer-specific risk warrants it

Historically, jurisdictions like Pakistan spent several years on the grey list (2018–2022) before being removed once FATF assessed its action plan as substantially complete — a widely cited example in exam answers on this topic. Candidates should focus on the mechanism, not on memorising which countries are currently listed, since the list is revised multiple times a year.

🧠 Practice MCQs: FATF Grey Listing and Indian Banks

Q1. What is the formal FATF name for the list commonly called the "grey list"? (a) High-Risk Jurisdictions subject to a Call for Action (b) Jurisdictions under Increased Monitoring (c) Non-Cooperative Countries and Territories (d) Restricted Compliance Jurisdictions

Answer: (b) — The grey list's formal FATF name is "Jurisdictions under Increased Monitoring."

Q2. A jurisdiction is grey-listed mainly because it: (a) has a high crime rate (b) has weak or deficient AML/CFT laws and controls, with a committed action plan (c) has refused to join FATF (d) has been sanctioned by the UN Security Council

Answer: (b) — Grey-listing reflects strategic AML/CFT deficiencies plus a commitment to remediate, not the country's crime rate.

Q3. When a country is grey-listed, an Indian bank's typical response to affected customers is to: (a) close all their accounts immediately (b) apply enhanced due diligence and closer transaction monitoring (c) ignore the change until RBI issues a new circular (d) report every transaction as suspicious automatically

Answer: (b) — Enhanced due diligence and tighter monitoring, not automatic account closure or automatic STR filing, is the expected response.

Q4. Correspondent banking due diligence is heightened most directly when the respondent bank is based in a: (a) FATF member country in good standing (b) grey-listed or black-listed jurisdiction (c) country with a bilateral trade agreement with India (d) country using the same currency as India

Answer: (b) — Grey- or black-listed jurisdictions trigger enhanced correspondent banking due diligence under RBI norms.

Q5. India's most recent FATF Mutual Evaluation, concluded in 2024, placed India in which category? (a) Grey list (b) Black list (c) Regular follow-up (d) Enhanced follow-up

Answer: (c) — India was placed in the "regular follow-up" category, reserved for the strongest-performing jurisdictions.

Want chapter-wise mock tests with 100+ MCQs? Start practising free →

❓ Frequently Asked Questions

Is the FATF grey list the same as economic sanctions?

No. FATF's list is about AML/CFT compliance and triggers enhanced due diligence obligations for banks, while sanctions are separate legal restrictions imposed by bodies like the UN Security Council or individual governments.

Has India ever been on the FATF grey or black list?

No. India has been a FATF member since 2010 and has never been placed on either list. Its most recent Mutual Evaluation, concluded in 2024, placed it in the regular follow-up category.

How often does FATF update its grey and black lists?

FATF reviews and updates both lists at its plenary sessions, which are typically held around three times a year.

Does grey-listing automatically stop correspondent banking with that country?

Not automatically. Banks are required to apply enhanced due diligence and reassess the relationship, but continuation depends on the bank's own risk appetite and the respondent bank's specific controls, not an outright ban.

FATF grey listing and Indian banks is a topic that rewards understanding the mechanism over memorising which country is currently listed — examiners test the process, the due diligence response, and where it sits within India's broader KYC/AML framework. For a structured revision path across correspondent banking, country risk, and the legislative backbone, work through the KYC, AML and CFT article series and pair it with full-length practice on iibf.store's CAIIB course. For the underlying FATF documentation on jurisdictions under increased monitoring, refer to rbi.org.in, which links RBI circulars implementing FATF-aligned AML/CFT requirements for Indian banks.

Quick quiz

Quick quiz on this topic

5 exam-style questions from our free test bank — check yourself before you move on.

KYC, AML and CFT · 5 questions · instant result
Q1. Among the five FIU reports, why is the STR described as the 'keystone' that consumes the maximum resources of a reporting entity, while CTR/NTR/CBWTR carry only supplementary AML value?
Q2. Counterfeit currency is detected during a cash deposit, and separately a forged valuable security is used in another cash transaction. How are these reported to FIU-IND under CCR norms?
Q3. A trade-finance branch reviews an account where inward remittances are immediately withdrawn, the goods description on documents is vague, the value/quantity of goods is not readily ascertainable, and LCs are repeatedly amended without justification. Which monitoring focus do these indicators point to?
Q4. A bank is designing its monitoring intensity under the Risk Based Approach (RBA) recommended by FATF. Which set of customers/products should attract the most intense monitoring as illustrated in the chapter?
Q5. A society registered under the Societies Registration Act, 1860 receives a single donation of Rs. 12 lakh in its account. The relationship manager is unsure which report applies. What is the correct reporting?
Next step

Practice this topic

Ready to put this into practice?

Take a free mock test, download chapter PDFs, or watch a video class — all included on iibf.store.

Keep reading