FATF Public-Private Partnerships: Sharing AML Data at Scale
On 8 July 2026 the Financial Action Task Force published a global stocktake of public-private partnerships for fighting illicit finance, and the message to reporting teams is blunt: the data that would expose a laundering network usually sits in fragments across separate banks, payment firms and law enforcement files, and criminals move faster than any single institution can react. The report, “Information Sharing to Combat Illicit Finance: Global Overview of Public and Private Sector Partnerships and Data Protection Arrangements”, counts at least 84 partnerships already running worldwide and argues they belong in the permanent toolkit for anti-money laundering and counter-terrorist-financing work.
The FATF report is non-binding and does not require institutions to join a public-private partnership. For EU obliged entities other than football agents and professional football clubs referred to in Article 3(3)(n) and (o), Article 75 of Regulation (EU) 2024/1624 applies from 10 July 2027 and creates a conditional legal route for information sharing where an entity chooses to participate; it does not impose a general participation obligation. The Regulation applies to those football-sector obliged entities from 10 July 2029.
This article walks through what the FATF found, where the legal gateways sit in the EU and elsewhere, and what a reporting team should be mapping now so that joining a partnership does not turn into a data-protection breach.
Related reading: what the EU AML Regulation changes for Luxembourg firms
How many public-private partnerships already run, and what they share
The FATF surveyed jurisdictions on the partnerships operating in their markets and identified at least 84 public-private partnerships globally. Of the surveyed jurisdictions, 52 reported at least one domestic partnership and 18 reported more than one. The results show broad adoption among the survey respondents, but the survey did not extend to the full FATF Global Network of more than 200 jurisdictions, and the identified partnerships were at varying stages of development and maturity.
The report also separates the kinds of information flowing through these forums, and the split matters more than the headline count. More than 75% of reporting jurisdictions use partnerships to share strategic information: typologies, red flags and risk trends. Fewer, between 55% and 66%, run partnerships that handle operational information such as case intelligence, suspicious transaction report indicators and customer due diligence or know-your-customer data. The gap between those two figures is the whole story of why information sharing is hard.
Strategic sharing is comparatively easy to justify. A typology bulletin about a new mule-account pattern names no customer, so it raises few privacy questions. Operational sharing points at identifiable people and accounts, which is where data-protection law, the tipping-off prohibition and liability concerns all converge at once. The report highlights the tools that are letting some jurisdictions cross that line responsibly, including encrypted platforms, secure exchange environments and the involvement of a broader set of participants such as telecom operators and digital platforms as fraud spills beyond banking.
Dates that matter
The FATF report is guidance and carries no deadline of its own, but it sits inside a calendar that reporting teams should already be tracking:
- 1 April 2024: Singapore’s COSMIC platform went live, with its legal basis in the Financial Services and Markets Act.
- 8 July 2026: the FATF publishes its global overview of public-private partnerships and data protection arrangements.
- Later in 2026: the European Data Protection Board and the Anti-Money Laundering Authority plan a stakeholder event ahead of joint guidelines on information-sharing partnerships.
- First half of 2027: expected public consultation on the EDPB and AMLA joint guidelines.
- 10 July 2027: Regulation (EU) 2024/1624 applies, and with it the Article 75 partnership route for obliged entities other than the football agents and professional football clubs referred to in Article 3(3)(n) and (o), for which the Regulation applies from 10 July 2029.
Strategic red flags versus operational case data
The most common misreading of a report like this is to treat “information sharing” as one thing that is either allowed or banned. In practice a partnership usually operates on several tiers, and your institution’s permission to take part in one tier says nothing about the next.
Sharing anonymised typologies and red-flag indicators is the entry level, and it is where most of the 84 partnerships concentrate. It improves everyone’s risk understanding without moving personal data. Sharing that a specific named customer is under review, or exchanging the underlying transaction records, is a different act with a different legal test. A firm that has signed up to receive strategic bulletins has not thereby earned the right to push case-level detail about a client into the same forum.
This is where the FATF’s case studies are useful, because they show what operational cooperation can achieve when the legal plumbing is in place. A transnational anti-scam alliance led by Singapore’s Project FRONTIER+, involving 13 jurisdictions, contributed to more than 2,100 arrests, the freezing of over 36,000 bank accounts and the seizure of approximately S$28.2 million. In South Africa, banks working through a tactical operation group analysed suspicious activity from clients, which led to the dismantling of a pyramid scheme and the freezing of 60 bank accounts worth more than USD 450,000. Neither outcome was available to any one bank looking at its own ledger.
Where the EU turns the principle into law: AMLR Article 75
For firms inside the EU the binding text sits in EU law. Article 75 of Regulation (EU) 2024/1624, the chapter of the AML Regulation headed “Information sharing”, is what applies, and it becomes applicable on 10 July 2027. It is worth reading the article as a permission with conditions attached, not a green light.
Article 75 permits members to exchange information only where strictly necessary for compliance with Chapter III and Article 69. The information must fall within the categories listed in Article 75(3), and Article 75(4)(f) restricts sharing to customers whose behaviour or transactions are associated with higher risk, who fall within specified AMLR situations, or for whom additional information is needed to determine whether they present higher risk. Strict necessity is therefore only one part of the legal test.
The gateway comes with a supervisory checkpoint. Under Article 75(2), an obliged entity that intends to join a partnership must notify its supervisory authority before the partnership begins operating. The supervisor, in consultation where relevant with the authorities responsible for the General Data Protection Regulation and with the financial intelligence unit, verifies that the partnership has mechanisms to comply with the article and that a data protection impact assessment has been carried out. Responsibility for compliance stays with each participant; the partnership structure does not absorb the liability. Our guide to AML reporting in Luxembourg sets out how the CSSF sits in that supervisory chain for Luxembourg entities.
Two limits inside Article 75 catch teams out. Information on suspicious transactions under Article 75(3)(g) may be exchanged only where the FIU to which the relevant report was submitted under Article 69 or 70 has agreed to the disclosure. Partnership activity does not remove the FIU-reporting obligation, but Article 69(8) allows the participating obliged entities to designate one of them to submit a single report identifying all participating entities. Where participants are established in several Member States, the information must be reported to each relevant FIU through an obliged entity established in that Member State. If the single-report option is not used, each report must state that the suspicion arose from partnership activity. Information received through a partnership may be provided to AMLA pursuant to Article 93 of Regulation (EU) 2024/1620. It may be transmitted to law-enforcement or judicial authorities only where those authorities request it and subject to any prior authorisations or other procedural safeguards required by national law. AMLA may establish a cross-border partnership or, with the agreement of the authorities that established it, participate in an existing partnership. Participating firms also have to set out their sharing policies in the internal policies and procedures they maintain under Article 9. Teams tracking the supervisor side of this can follow our coverage of which obliged entities fall under direct AMLA supervision.
Data protection sets the ceiling
The FATF is careful to frame data protection as a design constraint that runs through the whole exercise, and the report calls for jurisdictions to establish common objectives and clear legal and regulatory expectations, including senior-level engagement and joint guidance between AML/CFT authorities and data protection and privacy authorities. The EU is following exactly that path: the European Data Protection Board and AMLA have announced joint guidelines on partnerships for information sharing under Article 75, with a stakeholder event planned for later in 2026 and a public consultation expected in the first half of 2027, before the rules apply.
The cautionary example already exists. Transaction Monitoring Netherlands, the joint initiative established by five Dutch banks, announced on 1 July 2024 that it would wind down its existing activities and capabilities and redesign its business model and structure to adapt to the AMLR before July 2027. The lesson for any team tempted to read a sharing permission as a pooling permission is that the two are not the same, and that the more data a design centralises, the heavier the data-protection justification it has to carry.
The practical reading for an EU obliged entity is that a data protection impact assessment is not a form to file after go-live. Under Article 75 it is a precondition the supervisor checks before the partnership operates, and getting it wrong stalls the whole arrangement.
One framework, many national models
Because the FATF sets standards but does not write statutes, each jurisdiction builds its own legal basis, and the models do not interlock automatically. A firm operating across borders cannot assume that a permission it enjoys in one market travels to another.
The United Kingdom runs the Joint Money Laundering Intelligence Taskforce, set up in 2015 and led by the National Crime Agency, which has grown into a JMLIT+ model with more than 200 members drawn from banks, regulators, law enforcement, telecoms and technology firms. The United States relies on section 314(b) of the USA PATRIOT Act, a voluntary regime providing a safe harbour where eligible participants satisfy the programme conditions and share information to identify and, where appropriate, report activity that may involve possible money laundering or terrorist activity. FinCEN’s 12 June 2026 guidance clarifies that this may include information about suspected fraud and other specified unlawful activities where that nexus is present. Singapore’s COSMIC platform, launched by the Monetary Authority of Singapore on 1 April 2024 with six major banks, lets prescribed institutions share information on customers who cross defined red-flag thresholds, focused initially on trade finance misuse, the misuse of legal persons and proliferation financing, with the Financial Services and Markets Act supplying the legal basis and safeguards. Luxembourg’s CSSF chairs a public-private AML/CFT forum specifically concerning specialised PFS (PSF-SP), with the CRF and named professional associations participating under published rules. Information supplied by the CSSF or CRF under those rules is anonymised, generic or statistical.
That variety is also the trap for onshoring assumptions. The UK’s JMLIT is not a proxy for the EU’s Article 75 partnerships, and post-Brexit a UK group cannot rely on JMLIT membership to satisfy an EU supervisor about an EU partnership. Each arrangement has its own scope, its own permitted data and its own legal foundation, which is why the FATF spends much of the report describing models instead of prescribing one. For the crypto-native side of this, our analysis of the FATF report on decentralised finance risks shows the same pattern of principle-first, jurisdiction-specific implementation.
What AML teams should map before 2027
Before joining any partnership, I work out one thing first: exactly which data fields our institution may lawfully contribute, and under which legal gateway. The upside of a forum is obvious; the exposure comes from putting in data you had no basis to share. A short mapping exercise now avoids that later.
Start by listing the partnerships available in each market where the group operates, and classify each by tier: strategic typologies only, or operational case-level data. Match each tier against the legal basis that would authorise your participation, whether that is Article 75 in the EU, section 314(b) in the US, the COSMIC framework in Singapore or a national forum elsewhere. For EU participation, confirm the notification-to-supervisor step, the data protection impact assessment and the internal policies required under Article 9 are built into the project plan, not bolted on. Keep the tipping-off line visible throughout: FATF Recommendation 21 requires protection from liability for good-faith reporting and prohibits disclosure that an STR or related information is being filed with the FIU. The clarification that the tipping-off provisions are not intended to inhibit information sharing under Recommendation 18 was adopted in November 2017. The CSSF AML/CFT data collection gives a sense of how supervisors already expect firms to evidence their financial-crime controls.
Participation in an information-sharing partnership does not displace the applicable customer-due-diligence, FIU-reporting or other regulatory-reporting obligations. A partnership is an additional intelligence channel layered on top of those duties. The FATF report encourages jurisdictions to adopt or strengthen PPP frameworks aligned with the FATF Recommendations and data-protection principles; it does not require institutions to participate.
Frequently Asked Questions
Does the FATF report create a new reporting obligation for my institution?
No. The report is a global stocktake and a call to action, not a binding standard on its own. It encourages jurisdictions to build and strengthen partnerships and to align them with data-protection law. The binding obligations come from national and EU instruments, such as Article 75 of Regulation (EU) 2024/1624. For EU obliged entities other than the football agents and professional football clubs referred to in Article 3(3)(n) and (o), the Regulation applies from 10 July 2027; it applies to those football-sector obliged entities from 10 July 2029.
Can we share a customer’s transaction data with another bank once we join a partnership?
Only within all the conditions of Article 75. Sharing must be strictly necessary for compliance with Chapter III or Article 69, limited to the information categories in Article 75(3), and restricted to customers falling within Article 75(4)(f). The obliged entity must notify its supervisor, which verifies before the partnership begins operating that the required mechanisms exist and that a data protection impact assessment has been carried out. Information on suspicious transactions may be exchanged only with the agreement of the FIU to which the relevant report was submitted.
Do we still file a suspicious transaction report if the partnership already flagged the activity?
Yes. Partnership intelligence does not remove the FIU-reporting obligation. Under Article 69(8), participating obliged entities may designate one of them to submit a single report identifying all participating entities. Where participants are established in several Member States, the information must be reported to each relevant FIU through an obliged entity established in that Member State. If the single-report option is not used, each report must state that the suspicion arose from partnership activity.
How does the tipping-off prohibition interact with information sharing?
FATF Recommendation 21 requires confidentiality around suspicious reports so that subjects are not tipped off. Its revision clarifies that this is not intended to inhibit legitimate group-wide sharing under Recommendation 18. In practice your internal policies have to define what can be shared, with whom and through which gateway, so that operational cooperation does not cross into unlawful disclosure.
What is the difference between a partnership under Article 75 and AMLA setting up its own partnership?
Article 75 governs the conditions for obliged entities participating in information-sharing partnerships. Article 93 of Regulation (EU) 2024/1620 permits AMLA to establish cross-border partnerships or, with the agreement of the authorities that established them, participate in existing partnerships. An AMLA-established partnership must comply specifically with Article 75(3), (4) and (5), and AMLA may invite the authorities and Union bodies identified in Article 93 where their participation is relevant.
We operate in both the UK and the EU. Can one partnership membership cover both?
Treat them separately. UK participation, for example through JMLIT, rests on UK law and does not satisfy an EU supervisor about an EU partnership under Article 75. Each arrangement has its own scope, permitted data and legal foundation, so map participation market by market.
When do the EU joint guidelines on information-sharing partnerships arrive?
The EDPB and AMLA have announced joint guidelines under Article 75, with a stakeholder event planned for later in 2026 and a public consultation expected in the first half of 2027, ahead of the AMLR applying on 10 July 2027. Building your design against the draft guidance once it is consulted on will reduce rework.
Related Articles
- AMLR: What Changes for Luxembourg Firms – How the EU AML Regulation reshapes obligations for obliged entities ahead of the 2027 application date.
- Which Obliged Entities Face Direct AMLA Supervision – How the CSSF identification process works and what selected Luxembourg firms should prepare for.
- FATF VASP Travel Rule Implementation 2026 – Where member jurisdictions stand on Recommendations 15 and 16 for cross-border crypto compliance.
- FATF’s Targeted Report on Decentralised Finance – What AML teams need to understand about DeFi risk and the gaps in current frameworks.
- CSSF on De-Risking and ML/FT Risk Management – How Luxembourg expects firms to manage rather than avoid higher-risk relationships.
- Wolfsberg Guidance on Banking Non-Bank PSPs – What correspondent-banking AML frameworks must cover when serving payment firms.
Key Takeaways
- The FATF’s 8 July 2026 report identifies at least 84 public-private partnerships globally, based on survey responses and open-source information. Separately, 52 survey respondents reported at least one domestic partnership and 18 reported more than one.
- Strategic sharing (typologies, red flags) is used by more than 75% of reporting jurisdictions; operational sharing (case data, STR indicators, CDD or KYC data) by 55% to 66%. The two carry very different legal tests.
- For EU obliged entities choosing to participate, Article 75 of Regulation (EU) 2024/1624 provides a conditional information-sharing route from 10 July 2027, except for the football agents and professional football clubs referred to in Article 3(3)(n) and (o), for which the Regulation applies from 10 July 2029. Sharing must be strictly necessary for Chapter III or Article 69, fall within the Article 75(3) data categories, concern customers within Article 75(4)(f), and satisfy the remaining safeguards. Before activities begin, the supervisor verifies that compliance mechanisms exist and that the required DPIA has been carried out.
- Suspicion-revealing information may be exchanged among members only where the FIU to which the relevant report was submitted has agreed, and Article 69(8) introduces a single-report option for partnership-derived suspicions across multiple entities.
- Data protection is a precondition, not an afterthought: the TMNL wind-down shows that centralising pooled data is a heavier legal lift than sharing. The EDPB and AMLA are developing joint guidelines and plan to consult publicly on the draft in the first half of 2027, but they have not announced a final publication date.
- National models differ. UK JMLIT, US section 314(b), Singapore COSMIC and Luxembourg’s CSSF-chaired PSF-SP forum each rest on their own legal basis, so map participation market by market and do not assume permissions travel.
Sources and References
- FATF, Information Sharing to Combat Illicit Finance: Global Overview of Public and Private Sector Partnerships and Data Protection Arrangements (8 July 2026)
- FATF Recommendations (as amended October 2025), including Recommendation 2, Recommendation 18 and Recommendation 21
- FATF Guidance on Private Sector Information Sharing (November 2017)
- Regulation (EU) 2024/1624 (AML Regulation), Chapter VI and Article 75, applicable from 10 July 2027
- Regulation (EU) 2024/1620 (AMLA Regulation), Article 93 on cross-border partnerships for information sharing
- EDPB and AMLA to develop joint guidelines on partnerships for information sharing
- Monetary Authority of Singapore, COSMIC platform
- UK National Crime Agency, Joint Money Laundering Intelligence Taskforce (JMLIT)
- FinCEN, Section 314(b) voluntary information sharing among financial institutions
- CSSF, Rules of functioning of the public-private exchange forum (PSF-SP) in AML/CFT matters
- Transaction Monitoring Netherlands, adapting its working method to new European legislation
The window before Article 75 applies
The FATF report encourages jurisdictions to develop or strengthen public-private partnerships, but neither the report nor the FATF Standards require institutions to join one. From 10 July 2027, Article 75 provides an optional, conditional EU legal gateway for obliged entities that choose to participate, except for the football agents and professional football clubs referred to in Article 3(3)(n) and (o), for which the Regulation applies from 10 July 2029. Firms considering participation should map the proposed data, legal basis, Article 75 customer conditions, supervisory notification, internal procedures and DPIA before personal-data processing. The EDPB and AMLA guidelines are being developed, with public consultation planned for the first half of 2027.
Last updated: July 2026
Disclaimer: The information on RegReportingDesk.com is for educational and informational purposes only. It does not constitute legal, regulatory, tax, or compliance advice. Always consult your compliance officer, legal counsel, or the relevant supervisory authority for guidance specific to your institution.