h hoge.gg
Subscribe
BTC$67,432.18+2.34%ETH$3,521.44+1.08%SOL$178.62-0.62%BNB$612.30+0.41%XRP$0.6234-0.18%ADA$0.4521+3.12%DOGE$0.1623+1.86%AVAX$38.71-1.24%LINK$17.84+0.92%HOGE$0.00004120+4.21%
BTC$67,432.18+2.34%ETH$3,521.44+1.08%SOL$178.62-0.62%BNB$612.30+0.41%XRP$0.6234-0.18%ADA$0.4521+3.12%DOGE$0.1623+1.86%AVAX$38.71-1.24%LINK$17.84+0.92%HOGE$0.00004120+4.21%
● Regulation & Policy

The FATF Grey List: Crypto’s Real Enforcement Lever in 2026

The FATF writes the world's crypto AML rules but cannot enforce a single one. Its grey list does the enforcing, and weak crypto supervision now lands countries on it.

The Financial Action Task Force has no army, no courtroom, and no power to levy a single fine. It cannot arrest a launderer, freeze a wallet, or shut an exchange. What it has instead is a list, and in 2026 that list is the closest thing global crypto regulation has to an enforcement mechanism.

Bitcoin trades near $84,000, with a market capitalization around $1.69 trillion, and the stablecoin supply that now carries most illicit crypto value sits above $292 billion. The rules meant to police those flows, the Travel Rule, VASP licensing, and sanctions screening, were all written by the FATF, a body most crypto users have never heard of and that cannot enforce anything it publishes. It writes standards. Someone else has to make them bite.

The thing that makes them bite is the grey list, and the next update to it lands at the FATF’s October 2026 plenary, the first under the United Kingdom’s Giles Thomson, who took over the presidency on 1 July 2026. To understand how a set of non-binding recommendations moves billions of dollars in capital, and why weak crypto supervision is increasingly what puts a country on the wrong list, you have to understand how that list works.

What the FATF actually is, and isn’t

The FATF was created in 1989 at a G7 summit in Paris to fight drug-money laundering, and it still sits at the OECD headquarters there. It has around 40 members (major economies plus the European Commission and the Gulf Cooperation Council) and reaches more than 200 jurisdictions through a Global Network of nine regional bodies. Its output is the 40 Recommendations, the international standard for anti-money-laundering and counter-terrorist-financing (AML/CFT) rules.

Here is the part that surprises people: the FATF is not a treaty organization, and its Recommendations are not law anywhere. They are soft law. No country is legally bound to implement them, no company can be fined by the FATF, and the FATF has no jurisdiction over any exchange, bank, or wallet. It is, in effect, a standard-setter with a reputation desk.

That design is deliberate, and it is the source of the enforcement gap this outlet has covered before. The FATF can write a crypto Travel Rule (it did, in 2019). It can tell every country to license and supervise virtual asset service providers, or VASPs (it has, since 2018). What it cannot do is make any of that happen. Enforcement is left to national regulators; in the United States that means FinCEN and OFAC at the Treasury, not the SEC, which handles only the securities dimension. So how does a body with no power move 200 jurisdictions? It grades them, and it publishes the grades.

The one lever: two lists

The grades take the form of two lists, and they are the entirety of the FATF’s hard power.

The first is the grey list, formally the list of jurisdictions under increased monitoring. A country here has strategic deficiencies in its AML/CFT regime but has committed to fix them on an agreed timeline. It is a warning, not a quarantine. As of the June 2026 plenary, 22 jurisdictions were on it, among them Monaco, Bulgaria, Venezuela, Vietnam, Kenya, Lebanon, and Syria, plus 2026 additions Kuwait, Papua New Guinea, Bosnia and Herzegovina, and Iraq.

The second is the black list, formally high-risk jurisdictions subject to a call for action. This is the quarantine. The FATF explicitly tells every member to apply enhanced due diligence and, in the most severe cases, countermeasures to any dealings with these countries. As of 2026 it has exactly three members: North Korea, Iran, and Myanmar, unchanged through recent plenaries.

FeatureGrey list (increased monitoring)Black list (call for action)
What it signalsStrategic AML/CFT gaps, fix underwaySerious, persistent deficiencies
FATF instructionIncreased monitoring, manage the riskEnhanced due diligence; countermeasures for the worst
Members (2026)22 jurisdictions (Monaco, Bulgaria, Kenya, Vietnam, Venezuela, and others)North Korea, Iran, Myanmar
Practical effectHigher compliance cost, de-risking, capital flightNear-isolation from the global financial system

The distinction matters for crypto because the consequence is financial, not legal. Nothing about being grey-listed breaks any law. What happens instead is that the world’s banks and payment networks read the list and quietly reprice the country’s risk. That repricing is the enforcement.

How a country lands on the grey list

Nobody is grey-listed on a whim. The path starts with a mutual evaluation, the FATF’s peer-review audit of a country’s AML/CFT system. Each evaluation scores two separate things: technical compliance with the 40 Recommendations (are the right laws on the books?) and effectiveness against 11 Immediate Outcomes (do those laws actually work?). Technical ratings run from compliant to largely compliant, partially compliant, and non-compliant; effectiveness runs from high to substantial, moderate, and low.

A poor scorecard triggers a referral to the International Co-operation Review Group (ICRG), the committee that manages the two lists. The Basel Institute on Governance summarizes the rough thresholds: fifteen or more non-compliant or partially-compliant ratings, non-compliance in three or more of the core areas (money-laundering and terrorist-financing offences, customer due diligence, record-keeping, suspicious-transaction reporting), or low effectiveness across several Immediate Outcomes.

From there, the sequence is roughly this:

  • A one-year observation period, during which the country can start fixing deficiencies before any public listing.
  • If that is not enough, the FATF agrees a formal action plan with the government and adds the country to the grey list.
  • The country works the action plan, item by item, under scheduled progress reviews.
  • An on-site visit by assessors confirms the reforms are real and durable, not just words in a statute.
  • A plenary then votes to remove the country.

The FATF does not chase every small economy. Its prioritization rules focus on jurisdictions that matter to the global financial system; in an October 2024 reform it raised the size threshold for automatic review from $5 billion to $10 billion in broad money and said it would generally spare UN-designated least-developed countries except in rare high-risk cases.

Where crypto comes in

For most of the FATF’s history, grey-listing was about cash smuggling, shell companies, and weak bank supervision. Crypto changed that. In October 2018 the FATF amended Recommendation 15 to bring virtual assets and VASPs into scope, and in June 2019 it issued the interpretive note that created the crypto Travel Rule. Since then, VASP supervision has become a standard line item in mutual evaluations, which means it has become a standard reason to be grey-listed, or to stay there.

The 2026 evidence is blunt. When Nigeria was grey-listed in 2023, one finding was that its authorities had not assessed the risks from new technologies and had no power to run AML inspections on crypto businesses at all. When South Africa landed on the list the same year, building VASP licensing under the Financial Sector Conduct Authority became part of its exit plan. Both countries operationalized Recommendation 15 at a speed that would have been unthinkable without the pressure; the need to exit the list forced regulators to stand up crypto supervision with unusual urgency.

This is the mechanism the Travel Rule explainers could only gesture at. The FATF cannot make Lagos or Johannesburg regulate exchanges. The grey list can. For much of the Global South, the crypto Travel Rule is not being enforced by domestic political choice; it is being enforced by the threat of capital flight. And that threat is not abstract.

The real cost of grey: 7.6% of GDP

The number that makes finance ministers pay attention comes from the IMF. A 2021 working paper by Mizuho Kida and Simon Paetzold, using machine learning to isolate the effect, found that grey-listing cuts a country’s capital inflows by an average of 7.6% of GDP. Foreign direct investment falls by around 3% of GDP, portfolio inflows by roughly 2.9%, and other investment by about 3.6%. For an emerging economy, that is not a rounding error; it is a recession-scale shock delivered by a press release.

The channel is de-risking. Global banks, already wary of AML penalties, read a grey-listing as a signal to cut correspondent relationships and tighten scrutiny on every transaction touching that country. It compounds with the macro cycle, too; when a hawkish Fed is already pulling capital toward dollar assets, a fresh listing pushes a vulnerable economy the same way at the worst possible time. Analysis of SWIFT data has found payment volumes into grey-listed countries dropping by as much as 10%.

ChannelAverage impact of grey-listingSource
Total capital inflowsDown about 7.6% of GDPIMF Working Paper 21/153
Foreign direct investmentDown about 3% of GDPIMF Working Paper 21/153
Portfolio inflowsDown about 2.9% of GDPIMF Working Paper 21/153
Other investment inflowsDown about 3.6% of GDPIMF Working Paper 21/153
Cross-border payments receivedDown up to about 10%SWIFT-data analysis

It does not hit everyone equally. Croatia was grey-listed in 2023 and still had S&P Global upgrade its credit rating from BBB+ to A- during the episode, a reminder that a strong economy inside the EU absorbs the blow far better than a small, open, capital-dependent one. But the average effect is real, and it is why a single line in a mutual evaluation about crypto supervision can end up costing a country billions.

Case study, the UAE: the crypto hub that raced off the list

The clearest picture of the grey list as a forcing function is the United Arab Emirates. The FATF added the UAE to the grey list on 4 March 2022, citing strategic deficiencies from its 2020 mutual evaluation. The timing was awkward: Dubai was positioning itself as a global crypto capital just as it got flagged as a money-laundering risk.

What followed was a sprint. The UAE overhauled its AML law, stood up the Dubai Virtual Assets Regulatory Authority (VARA) as a dedicated crypto supervisor, prosecuted more cases, and tightened beneficial-ownership rules. By its July 2023 follow-up it was rated compliant or largely compliant on the large majority of the 40 Recommendations, and on 23 February 2024 the FATF removed it from the grey list, with the EU dropping it from its own high-risk list soon after.

The lesson for crypto is that a serious financial center cannot court crypto capital, the same capital chasing the global wave of spot ETF approvals, while ignoring the FATF. The grey list gave the UAE a deadline, and the crypto supervision it built (VARA, licensing, Travel Rule tooling) was in large part an answer to that deadline.

The Cambodia problem: when the list misses

The grey list’s weakness is the mirror image of its strength: it measures whether a country has the right rules and processes, not whether laundering actually stopped. Cambodia is the cautionary tale.

Cambodia was grey-listed in February 2019 and, after completing its action plan, removed on 24 February 2023. By the FATF’s own process, that was a success: reforms made, boxes checked, country delisted. But look at what was happening in the same window. The Cambodia-based Huione Group was scaling into what US authorities would later call one of the largest illicit-finance marketplaces on earth. When the US Treasury moved against Huione in 2025, it found the network had laundered at least $4 billion between 2021 and early 2025, much of it proceeds from North Korean cyber-heists and Southeast Asian pig-butchering scams. Huione even launched its own stablecoin, marketed as impossible to freeze.

In other words, Cambodia was cleared by the FATF at almost the exact moment its most notorious laundering hub hit full stride. That is not proof the grey list is broken, but it is a precise illustration of its blind spot: a regime can look healthy on paper while the real money moves through channels the evaluation never priced in, especially crypto channels that barely existed when the action plan was drafted. Former FATF president Elisa de Anda Madrazo made the point when the body’s offshore-VASP report landed in March 2026, warning that such providers “create blind spots that criminals are clearly exploiting, to scam vulnerable people through fraud or fuel terror around the world.”

JurisdictionGrey-listedRemovedCrypto angle
United Arab EmiratesMarch 2022February 2024Built VARA and VASP licensing on the way off the list
Nigeria2023October 2025Had no power to inspect VASPs when listed; began licensing to exit
South Africa2023October 2025Stood up FSCA VASP supervision as an action-plan item
CambodiaFebruary 2019February 2023Delisted while the Huione laundering hub scaled to billions

The enforcement gap, in numbers

The Cambodia gap is visible in the FATF’s own crypto data. The seventh targeted update on virtual assets, published in July 2026, found that 83% of assessed jurisdictions had Travel Rule laws on the books, up from 73% a year earlier. That is the good news. The bad news is what happens after the law passes: of 91 jurisdictions with Travel Rule legislation, 55 had taken no supervisory or enforcement action at all. Analyzing the same data, Chainalysis found that only 13 of 139 jurisdictions fully met the FATF’s preventive standards for crypto.

The pattern repeats across this whole topic. Writing the rule is the easy part; the grey list is very good at catching a country that has no VASP law, and much weaker at catching one that has the law but never uses it. A government can pass a Travel Rule statute, license a few exchanges, satisfy its action plan, and exit the list, all without a single enforcement case. The list rewards the statute, not the supervision.

FATF president Giles Thomson has been candid that the work is not done. In the July 2026 update he warned that criminal networks “continue to abuse virtual assets for illicit purposes and exploit their borderless nature to commit fraud and scams, evade sanctions and launder the proceeds of crime.” His stated priority for the UK presidency is to move past writing rules and toward making them work.

From the list to the chokepoint

The FATF list does not act on anyone directly. It works by feeding national systems that do have teeth. Once a country is grey- or black-listed, three things tend to follow.

First, other governments fold the list into their own rules. The EU maintains its own list of high-risk third countries that tracks the FATF’s closely, and landing on it triggers mandatory enhanced due diligence across the bloc. Second, banks and VASPs build the list into their compliance software, so a customer or counterparty in a listed country automatically draws extra scrutiny or gets cut off. Third, and most powerfully, national regulators use a listing as cover for direct action.

The Huione case is the template. The FATF framework identified the risk category; the US Treasury pulled the trigger with a Section 311 action that barred Huione from the US financial system, the correspondent-banking equivalent of a death sentence. The same layering shows up with sanctions: OFAC blacklists specific wallets and entities, and the FATF sets the standard those designations rest on. Value that tries to route around these chokepoints, increasingly across chains and bridges rather than through a single exchange, is exactly what the next generation of rules is chasing; our look at the cross-chain interoperability wars traces how that money actually moves.

The point is that the grey list is the first domino, not the last. It turns a soft standard into a hard consequence by handing national regulators a pre-packaged reason to act.

The black list: the nuclear option

If the grey list is a warning, the black list is exile. The three current members, North Korea, Iran, and Myanmar, face a formal FATF call for members to apply enhanced due diligence and, for North Korea and Iran, active countermeasures. In practice that means near-total exclusion from the regulated global financial system.

Crypto is central to why two of the three are there. North Korea is the most prolific state crypto thief on record; Chainalysis attributed roughly $2 billion in stolen crypto to North Korea-linked actors in 2025 alone, moved through mixers, over-the-counter brokers, and increasingly stablecoins. For a regime cut off from banks, crypto is not a convenience; it is the treasury. Myanmar is both blacklisted and one of the world’s densest clusters of crypto scam compounds, the same pig-butchering economy that fed networks like Huione, a reminder that a call for action does not, by itself, clean anything up.

There is also a pointed gap. Russia’s FATF membership was suspended in February 2023 after the invasion of Ukraine, but Russia has never been grey- or black-listed, even as ruble-backed stablecoins and sanctioned exchanges have processed large sanctions-evasion flows. The difference is not technical; listing a G20 economy is a political act the FATF has so far declined to take. That selective quality is the sharpest criticism the lists face.

Grey list, black list, sanctions list: not the same thing

Crypto readers routinely conflate three different lists, and the distinction matters. The FATF grey and black lists grade whole countries on the quality of their AML systems; they are soft law, and their bite is reputational and financial, not criminal. A US sanctions listing is something else entirely: when OFAC adds a person, an entity, or a specific wallet address to its Specially Designated Nationals list, it becomes a legal prohibition, and dealing with that address can be a crime for any US person. The EU keeps yet another list, its own roster of high-risk third countries, which mirrors the FATF’s but carries direct legal effect across the bloc.

The lists overlap but are not interchangeable. A country can sit on the FATF grey list without any of its exchanges being sanctioned, and a wallet can be OFAC-sanctioned while the country it operates from is nowhere on a FATF list. North Korea is the rare case where all three converge: FATF-blacklisted, heavily OFAC-sanctioned, and a fixture of every compliance blocklist in the industry. For a VASP building screening tools, the practical takeaway is that FATF status sets the risk weighting for a jurisdiction, while sanctions lists set the hard yes-or-no on individual counterparties. One shapes your risk model; the other can put you in prison.

Does the grey list actually work?

The honest answer is that it works as a market-pressure tool, and that it is a blunt and uneven one.

On the credit side, the mechanism clearly changes behavior. The UAE, Nigeria, and South Africa all built or upgraded crypto supervision under grey-list pressure, and the IMF’s capital-flow findings show the cost is real enough to force action. When nothing else moves a finance ministry, a threat worth 7.6% of GDP does.

On the debit side, the criticisms are serious. The Basel Institute on Governance, whose analyst Dr Kateryna Boguslavska tracks the list closely, notes that it has fallen disproportionately on lower-income countries, with more than half of grey-listed jurisdictions historically in Sub-Saharan Africa, even as recent additions (Bulgaria, Croatia, Monaco) have shifted toward Europe. De-risking can choke off legitimate remittances and financial inclusion while sophisticated launderers simply move to the next channel. And the Cambodia and Russia cases show the list can miss the biggest real-world risks while penalizing paperwork failures elsewhere.

The FATF has responded to some of this. The October 2024 prioritization reforms were meant to focus the list on jurisdictions that genuinely matter to the global system and to spare the poorest countries from being listed for capacity problems they cannot quickly fix. Whether that makes the tool fairer or simply concentrates its firepower on mid-size economies is still being argued.

What the October 2026 plenary means for crypto

The next act plays out at the October 2026 plenary, the first run by the UK’s Giles Thomson. Two threads are worth watching.

The first is fraud. Thomson has made it the signature theme of his presidency, launching a roadmap for 2026 to 2028 built around a striking claim: fraud, he says, “is the predominant predicate offense in 90% of the FATF mutual evaluations done across the global network,” and costs on the order of $500 billion a year worldwide. Because so much modern fraud, from pig-butchering to investment scams, cashes out in crypto, a fraud-first FATF is implicitly a crypto-first FATF, and future mutual evaluations are likely to weigh crypto-scam exposure more heavily.

The second is implementation. Thomson has signaled that the era of writing virtual-asset standards is over and the era of enforcing them has begun. For countries on or near the grey list, that raises the bar: passing a Travel Rule law may no longer be enough to satisfy an action plan if supervisors are not actually using it. The seventh update’s gap, 55 of 91 jurisdictions taking no enforcement action, is precisely the metric a tougher regime would target.

None of this changes the fundamental design. The FATF will still not fine or arrest anyone. It will keep doing the only thing it can: grading countries, publishing the grades, and letting the world’s banks turn those grades into consequences.

What it means for crypto users and builders

For most readers the grey list is invisible until it is not. Here is where it actually touches you.

  • If you use an exchange based in a grey-listed jurisdiction, expect heavier onboarding, more frequent re-verification, and occasional trouble moving funds to banks abroad, because your platform’s correspondent banks treat the whole jurisdiction as elevated risk.
  • If you are a builder or a VASP, the list is a roadmap of where licensing is about to tighten. A country on an action plan with a crypto deficiency will be standing up VASP registration and Travel Rule requirements on a deadline, and getting ahead of that is cheaper than scrambling.
  • If you hold self-custodied assets, the list is a reminder of where the rules run out. The FATF’s model assumes an intermediary who can screen and report; a self-custody wallet has none, which is why unhosted wallets sit at the hardest edge of the regime. Our explainer on whose code actually runs your wallet under EIP-7702 digs into where that intermediary now sits.
  • If you trade on DeFi rails, remember that a decentralized exchange is not a VASP in most readings, which is exactly why the FATF keeps circling DeFi; the volume flowing through perp DEXs shows how much activity already lives outside the licensed perimeter.

The through-line: the grey list does not regulate you. It regulates your government, which regulates your bank, which regulates your exchange. By the time the pressure reaches your account, it has passed through three hands, and it started with a list published by a body in Paris that cannot fine anyone.

Frequently asked questions

What is the difference between the FATF grey list and black list?

The grey list (jurisdictions under increased monitoring) flags countries with AML/CFT deficiencies that are working with the FATF to fix them; it is a warning that raises compliance costs and can trigger de-risking. The black list (high-risk jurisdictions subject to a call for action) is far more severe, urging every member to apply enhanced due diligence and, in the worst cases, countermeasures, which amounts to near-isolation. In 2026 the black list has three members: North Korea, Iran, and Myanmar.

Can the FATF fine or punish a crypto exchange?

No. The FATF has no legal authority over any company and cannot levy fines, freeze assets, or make arrests. It only sets standards, including the crypto Travel Rule, and grades countries on how well they implement them. Enforcement against an exchange comes from national regulators such as FinCEN and OFAC in the United States, not from the FATF and not from the SEC, which handles only the securities side.

How does crypto regulation affect whether a country is grey-listed?

Since 2018, supervising virtual asset service providers under Recommendation 15 has been part of FATF mutual evaluations. A country with no VASP licensing, no crypto risk assessment, or no Travel Rule can be grey-listed or kept on the list for it. Nigeria and South Africa both built crypto supervision as part of their exit plans, and the UAE overhauled its regime and stood up a dedicated crypto regulator on its way off the list in 2024.

How much does being grey-listed actually cost a country?

A 2021 IMF working paper found that grey-listing reduces a country’s capital inflows by an average of 7.6% of GDP, with foreign direct investment and portfolio flows each falling by around 3% of GDP. The main channel is de-risking, where global banks cut correspondent ties to avoid AML exposure. Effects vary: a large EU economy like Croatia weathered its 2023 listing far better than a small, capital-dependent country would.

When is the next FATF grey list update?

The next scheduled update comes at the FATF’s October 2026 plenary, the first led by the new president, the United Kingdom’s Giles Thomson. Grey and black list changes are decided at the FATF’s plenary meetings, held roughly three times a year, in February, June, and October. At the June 2026 plenary the list stood at 22 jurisdictions, with Bosnia and Herzegovina and Iraq added and Algeria and Namibia removed.

Anneke de Vries is HOGE Wire’s regulation correspondent, covering AML, sanctions, and the machinery of global crypto rules.

Share 𝕏 Post Telegram