Financial Inclusion Is Part of Effective AML/CFT: Key Lessons from FATF’s 2025 Guidance

Key Lessons from FATF’s 2025 Guidance

7/30/20268 min read

The Financial Action Task Force’s 2025 guidance on Financial Inclusion and Anti-Money Laundering and Terrorist Financing Measures challenges a persistent misconception in compliance: that stronger controls always require more documentation, more restrictions, and more customer rejection.

The guidance makes a different argument. An effective anti-money laundering and counter-terrorist financing framework should not only keep criminals out of the regulated financial system. It should also avoid pushing legitimate individuals, businesses, charities, remittance providers, and vulnerable communities into cash or unregulated channels.

FATF’s central message is that financial inclusion and financial integrity are mutually reinforcing. When more legitimate customers use regulated financial services, transactions become more visible, suspicious activity is easier to detect, and supervisors and law enforcement obtain better financial intelligence. When customers are excluded, activity may migrate to informal money-transfer networks, cash, personal accounts, or other channels with weaker oversight.

The guidance therefore asks governments, supervisors, banks, fintech companies, virtual-asset service providers, and other regulated entities to apply the risk-based approach as it was intended: proportionately.

Why FATF Updated the Guidance

FATF first issued financial-inclusion guidance in 2011 and revised it in 2013 and 2017. The 2025 update reflects amendments to FATF Recommendation 1 and the Interpretive Notes to Recommendations 1, 10, and 15. These amendments place greater emphasis on proportionate implementation and encourage countries to allow simplified measures where risks are assessed as lower.

The document is non-binding and does not create new legal obligations. Its purpose is to clarify how countries and regulated entities can use the flexibility already contained in the FATF Standards.

The guidance focuses particularly on financially unserved and underserved people, including:

  • low-income households;

  • people in rural or remote areas;

  • refugees and displaced persons;

  • migrants with limited documentation;

  • people with disabilities;

  • microenterprises and small businesses;

  • people in fragile or conflict-affected contexts; and

  • customers who technically have accounts but cannot use them effectively.

FATF does not say that these groups are automatically low risk. It says that they should not be automatically treated as high risk either. Their risk should be assessed using evidence, context, product design, expected activity, delivery channels, and available mitigation measures.

Financial Exclusion Is Itself an AML/CFT Risk

One of the most important points in the guidance is that financial exclusion is not merely a social-policy concern.

It can weaken AML/CFT effectiveness.

When legitimate customers cannot access regulated services, they may turn to cash, informal money-transfer systems, unlicensed providers, or accounts held in another person’s name. This reduces transparency and can make customers more vulnerable to fraud, exploitation, human trafficking, money-mule recruitment, and predatory lending.

FATF’s analysis therefore reframes financial inclusion as a financial-integrity tool. Bringing customers into regulated channels can create records, improve identity information, make transaction patterns visible, and expand the reach of suspicious-transaction reporting.

This does not mean every customer must be accepted. A regulated entity may still reject or terminate a relationship where the identified risk cannot be managed. The key requirement is that the decision should be based on the individual customer and the institution’s actual ability to mitigate the risk—not on a broad assumption about an entire nationality, profession, sector, or customer category.

The Risk-Based Approach Is Not a Zero-Failure Standard

Many institutions are reluctant to use simplified customer due diligence because they fear regulatory criticism if misconduct later occurs.

The FATF guidance directly addresses this concern. It states that the risk-based approach does not imply a “zero failure” regime. Supervisors should distinguish between an isolated breach occurring within an otherwise reasonable control framework and a genuine compliance failure caused by inadequate risk assessment or disproportionate mitigation.

This distinction matters.

A risk-based system cannot function if institutions believe that every lower-risk customer must be subjected to the same level of due diligence as a high-risk customer. If compliance teams are punished for any adverse event, regardless of whether their controls were reasonable, they will naturally default to excessive documentation, unnecessary escalation, or account closure.

FATF therefore places responsibility not only on regulated entities but also on supervisors. Supervisors must communicate clearly, provide practical guidance, support staff training, and create confidence that proportionate decisions will be assessed fairly.

Simplified Due Diligence Does Not Mean No Due Diligence

The guidance allows simplified customer due diligence in assessed lower-risk situations. This does not mean abandoning KYC, sanctions screening, suspicious-transaction reporting, or recordkeeping.

Simplification may instead involve:

  • collecting fewer identity attributes;

  • accepting a broader range of reliable documents;

  • delaying part of the verification process where legally permitted;

  • using non-documentary verification;

  • applying lower transaction or balance limits;

  • restricting account functionality;

  • using tiered or progressive accounts;

  • reducing the frequency or intensity of ongoing review; or

  • applying less intensive transaction monitoring to a genuinely lower-risk product.

FATF notes that simplified identification may focus on essential identifiers and may allow alternative sources such as voter cards, tax documents, employment cards, expired identification, reference letters, biometrics, or secure digital identity tools. The appropriate method depends on the jurisdiction, the product, the customer’s circumstances, and the reliability of the evidence.

The underlying principle is proportionality. A low-value, limited-purpose account should not necessarily require the same controls as private banking, international trade finance, or a complex corporate relationship.

Tiered Accounts Can Balance Access and Risk

Tiered or progressive accounts are one of the most practical ideas in the guidance.

A customer may begin with a basic account that has limited functionality, transaction caps, restricted products, or tighter monitoring. As the institution obtains more reliable identity information and observes the customer’s activity over time, the account may be upgraded.

This model can support people who lack traditional identity documentation while still controlling risk. The FATF guidance explains that higher functionality and higher risk should be matched with stronger identity verification and more intensive due diligence.

For institutions, this creates a middle ground between full access and complete rejection.

Rather than asking, “Can we onboard this customer under our standard model?” the more useful question may be, “What controlled product can we safely offer while we learn more about the customer?”

Possible safeguards include:

  • low transaction and balance limits;

  • domestic-only use;

  • restrictions on cash deposits;

  • restrictions on international transfers;

  • no access to higher-risk products;

  • enhanced monitoring;

  • periodic review;

  • staged verification; and

  • automatic escalation when account activity exceeds expected parameters.

Digital Identity Can Reduce Exclusion

The guidance gives significant attention to digital identity and remote onboarding.

Approximately 850 million people globally lack official proof of identity. Women are disproportionately affected: in low-income countries, the guidance cites figures indicating that 44% of women lack formal identification, compared with 28% of men.

Secure digital identity systems can help address this problem. FATF notes that biometrics, national identity registries, remote verification, liveness testing, electronically certified documents, and other digital tools may support effective customer verification while reducing reliance on physical documents that some customers cannot obtain.

Digital onboarding is not automatically low risk. Institutions still need to assess:

  • identity-system assurance;

  • data accuracy;

  • fraud resistance;

  • device security;

  • deepfake and synthetic-identity risks;

  • privacy;

  • customer consent;

  • cybersecurity;

  • accessibility; and

  • the reliability of the underlying government or private database.

The guidance’s examples show that technology works best when combined with governance. Argentina, for example, uses biometric controls, identity-document scans, facial comparison, liveness checks, and verification against a national registry to support remote onboarding.

Alternative Identification Can Be Legitimate and Controlled

A major barrier to financial inclusion is the assumption that only one narrow category of government-issued identification is acceptable.

The guidance provides examples of institutions accepting alternative evidence where traditional identification is unavailable. These may include refugee documentation, employer identification, letters from reliable referees, alternative address information, or other independently verifiable records.

In Malawi, one bank accepted identification issued by the UN refugee agency and allowed customers to use a map of their residence within a refugee camp instead of a conventional utility bill. By December 2024, the bank reportedly maintained 14,800 active refugee accounts.

This is not a recommendation to accept weak evidence without controls. FATF warns that some alternative documents may be more vulnerable to fraud and may require compensating measures such as:

  • closer monitoring;

  • restricted products;

  • lower limits;

  • additional references;

  • database checks;

  • enhanced fraud controls; or

  • later-stage verification.

The lesson is that institutions should distinguish between “non-standard” and “unreliable.” They are not always the same.

De-Risking Can Increase Financial Crime Risk

FATF defines de-risking as refusing, terminating, or restricting relationships with customers or categories of customers to avoid risk rather than understand and manage it.

Wholesale de-risking is contrary to the risk-based approach.

The guidance notes that de-risking frequently affects:

  • money or value transfer services;

  • non-profit organizations;

  • refugees and migrants;

  • people from conflict-affected countries;

  • correspondent banks in smaller economies;

  • fintech companies;

  • virtual-asset businesses;

  • dealers in precious metals and stones; and

  • lower-income or under-documented customers.

FATF also recognizes that profitability is often the main driver. Compliance costs, unclear supervisory expectations, fear of enforcement, sanctions complexity, reputational concerns, and low commercial incentives can make certain customers unattractive even where their risks are manageable.

The problem is that de-risking may push activity into less transparent channels. Remittances may move through informal systems. Charities may rely on cash. Businesses may use personal accounts. Customers may use unregulated intermediaries.

In other words, eliminating the customer relationship does not necessarily eliminate the risk. It may simply move the risk outside the regulated institution’s view.

Grey-Listing Does Not Require Automatic Enhanced Due Diligence

The guidance includes an important clarification about FATF increased monitoring, commonly called grey-listing.

FATF does not call for automatic enhanced due diligence against every customer or transaction connected to a grey-listed jurisdiction. Nor does it support terminating entire categories of business relationships solely because of grey-list status.

Institutions should assess the specific deficiencies identified by FATF and evaluate how those deficiencies affect the particular customer, product, transaction, and control environment. Legitimate humanitarian assistance, remittances, and non-profit activity should not be unnecessarily disrupted.

This is especially important for country-risk methodologies. A country rating should be a risk factor—not an automatic decision.

Supervisors Have a Critical Role

The guidance makes clear that financial inclusion cannot be delivered by private institutions alone.

Supervisors should:

  • issue clear guidance on simplified due diligence;

  • identify lower-risk products and scenarios;

  • avoid creating a perceived zero-tolerance regime;

  • support staff training;

  • encourage dialogue with industry;

  • publish typologies and case studies;

  • coordinate with financial-inclusion authorities;

  • monitor de-risking trends;

  • clarify expectations for alternative identification; and

  • recognize responsible attempts to serve difficult customer groups.

FATF also encourages public-private dialogue and shared risk understanding. Institutions may hesitate to apply simplified measures when they fear their assessment will conflict with the supervisor’s view. Regular engagement, feedback, and industry baselines can reduce this uncertainty.

What Financial Institutions Should Do

The guidance has practical consequences for AML policies, customer risk models, product design, and account-closure procedures.

Review automatic high-risk classifications

Institutions should identify whether nationality, migration status, occupation, sector, geography, or document type automatically produces a high-risk rating or rejection.

These factors may be relevant, but they should not replace an individualized assessment.

Create a documented simplified-due-diligence framework

Policies should define:

  • when simplified measures are permitted;

  • which products qualify;

  • what evidence is acceptable;

  • what limits apply;

  • how monitoring differs;

  • what triggers an upgrade;

  • when full CDD becomes necessary; and

  • how decisions are documented.

Develop tiered products

Basic accounts, limited wallets, low-value remittance products, and restricted digital-payment products can provide access while controlling exposure.

Expand acceptable identification

Institutions should assess whether reliable alternative documents, government databases, employer records, refugee documentation, digital identity, biometric verification, or trusted third-party data can be used.

Strengthen de-risking governance

Account rejection and closure should require:

  • a documented individual assessment;

  • evidence that mitigation options were considered;

  • clear reasons;

  • appropriate approval;

  • consideration of limited-service alternatives; and

  • monitoring for patterns affecting particular groups.

Train staff to distinguish risk from uncertainty

Frontline employees and compliance analysts should understand that unfamiliar customers are not automatically high risk. A lack of conventional documentation may require a different verification method, not immediate rejection.

Measure inclusion outcomes

Institutions should monitor:

  • rejection rates;

  • account-closure patterns;

  • inactive accounts;

  • geographic access;

  • approval rates by customer group;

  • use of simplified measures;

  • false-positive rates;

  • reasons for customer exits; and

  • whether product restrictions remain proportionate over time.

What the Guidance Does Not Permit

The FATF document should not be read as a relaxation of core AML/CFT obligations.

It does not remove requirements relating to:

  • suspicious-transaction reporting;

  • targeted financial sanctions;

  • record retention;

  • ongoing monitoring;

  • beneficial ownership where applicable;

  • enhanced measures in genuinely higher-risk situations; or

  • rejection where risk cannot be managed.

It also does not say that all unserved customers are low risk.

The guidance instead requires better analysis. Higher-risk customers may still be served where effective mitigation is available, while lower-risk customers should not be burdened with controls designed for significantly more complex relationships.

The 2025 guidance marks a significant evolution in how financial institutions should think about compliance effectiveness.

For years, many AML programs have measured strength by the volume of documents collected, alerts generated, accounts closed, or customers rejected. FATF’s guidance asks a harder question:

Did the institution understand the risk and apply a proportionate response?

A system that excludes legitimate customers may appear conservative, but it can reduce transparency, weaken financial intelligence, increase informal finance, disrupt remittances, and make vulnerable people more exposed to exploitation.

The strongest AML/CFT framework is therefore not the strictest possible framework. It is the framework that applies strong controls where risk is high, simplified controls where risk is lower, and thoughtful mitigation where customers do not fit standard onboarding models.

Financial inclusion is not the opposite of financial integrity.

Properly designed, it is one of the ways financial integrity is achieved.

Source: FATF (2025), Guidance on Financial Inclusion and Anti-Money Laundering and Terrorist Financing Measures, June 2025.

Contact us

amltraining@zoho.com

© 2026. All rights reserved.