FATF Fraud Roadmap 2026-2028: Fraud as a Core AML Risk
On 1 July 2026 the United Kingdom took over the two-year Presidency of the Financial Action Task Force and used its first day to launch the FATF 2026-2028 Roadmap on Combatting Fraud. The launch event, opened by the incoming FATF President Giles Thomson and supported by Executive Secretary Violaine Clerc, set fraud as one of the FATF’s central strategic priorities through to mid-2028, building on a declaration that ministers issued at the FATF’s April 2026 Ministerial meeting.
For a reporting officer, the first question is whether the roadmap creates another return to file. It does not itself establish a new reporting template or submission deadline. Nor does it directly amend firm-level supervisory requirements. It establishes a FATF policy priority that may influence future national legislation, guidance, inspections and mutual-evaluation findings. Firms should therefore monitor the competent authorities and legislation that govern them before treating the roadmap as an operative supervisory requirement.
The roadmap does not itself bind governments or obliged entities. FATF members have made political commitments to pursue the agreed priorities, while enforceable duties for firms arise through applicable national or regional law. Mutual evaluations assess jurisdictions against the FATF Standards and may influence subsequent legislative, supervisory and enforcement action.
Related reading: our guide to the FATF Recommendation 16 payment-transparency consultation.
What the fraud roadmap actually commits the FATF to
The June 2026 Plenary identified three objectives for the UK Presidency: stepping up the international response to fraud, including the ML/TF risks from scam compounds; strengthening implementation of the risk-based approach and risk-based supervision; and enhancing information sharing and public-private partnerships. FATF described the 1 July event as launching and contributing to the development of a fraud roadmap. The public material reviewed does not set out a complete roadmap of dated deliverables.
The April declaration is the anchor. Ministers agreed to deploy the full AML, counter-terrorist-financing and counter-proliferation-financing toolkit to disrupt and combat the threat of fraud, and to deepen understanding of fraud in all its forms, including organised scam centres and the misuse of legal persons, virtual assets and emerging technologies such as artificial intelligence. The launch event structured its panels around the same logic: rethinking financial intelligence, private-sector information sharing, asset recovery and international cooperation, and the global response.
Read carefully, none of that is a rule change. A ministerial declaration, a roadmap and a launch event are policy instruments. They establish policy priorities and contribute to development of the fraud roadmap; they do not themselves amend the 40 Recommendations or the mutual-evaluation methodology, and they do not create a filing obligation for a bank, a payment institution or a crypto-asset service provider. The trap here is to over-read the announcement and start scoping a report that nobody has asked for. The useful response is to monitor whether FATF subsequently changes its Standards, assessment methodology or guidance, and whether relevant jurisdictions or supervisors amend applicable requirements.
Key dates behind the roadmap
The roadmap runs as a two-year programme, and a handful of dates frame it and belong on an AML planning calendar:
- April 2026: FATF Ministerial meeting issues the declaration committing the network to deploy the full AML/CFT/CPF toolkit against fraud.
- June 2026: the FATF Plenary confirms the UK Presidency programme and approves a public consultation on guidance supporting the strengthened Recommendation 16 standard on cross-border payment transparency, with fraud among its focal crimes.
- 1 July 2026: the United Kingdom assumes the FATF Presidency for 2026-2028 and formally launches the Roadmap on Combatting Fraud at a virtual event.
- 1 July 2026 to 30 June 2028: the term of the UK FATF Presidency. FATF has identified fraud, the risk-based approach and information sharing as Presidency objectives, but the public sources reviewed do not specify a complete timetable of roadmap deliverables.
These are FATF milestones, not your reporting dates. The reporting consequences arrive later and locally, when a national supervisor updates its expectations, a mutual evaluation lands, or a jurisdiction transposes standards into law. Where the roadmap connects to a live instrument, log the national date that actually governs you, which the sections below set out.
Fraud proceeds are the laundering risk the roadmap targets
Fraud has long been a predicate offence for money laundering, but it has often been managed on a separate track inside financial institutions. Fraud teams chase authorised push payment scams, card fraud and account takeover in near real time; AML teams file suspicious activity reports and run periodic risk assessments. The roadmap’s underlying premise is that the proceeds of fraud are laundered like any other criminal proceeds, and that the two disciplines have to be joined up if the money is to be traced, frozen and returned to victims.
FATF’s February 2026 cyber-enabled fraud paper describes fraud proceeds moving through nominee or mule accounts, rapid transfers and virtual assets. Whether those flows engage transaction-monitoring, suspicious-reporting, freezing or information-production duties depends on the applicable local framework. The roadmap itself does not prescribe a new firm-level supervisory test or create a new freezing, tracing or reporting requirement.
Firms may choose to test whether fraud risks are adequately connected across their fraud and AML frameworks. That is a control recommendation, not a new requirement created by the roadmap. The governing risk-assessment obligation remains the one established by the applicable national or regional AML/CFT framework.
How the roadmap reaches your institution
The FATF sets international standards and does not regulate banks directly. The Recommendations identify measures that countries should implement through legal, regulatory and operational arrangements adapted to their circumstances. FATF then assesses countries’ technical compliance and effectiveness through peer-led mutual evaluations.
In the European Union, the 2024 anti-money-laundering package is relevant but is not yet generally applicable to obliged entities. Regulation (EU) 2024/1624 applies from 10 July 2027, except for the specified football-sector obliged entities, to which it applies from 10 July 2029. Directive (EU) 2024/1640 is subject to phased national transposition deadlines, principally 10 July 2027. Regulation (EU) 2024/1620 established AMLA, which has EU-level supervisory and coordination functions. Any fraud-related requirement must be traced to an applicable EU or national measure rather than inferred from the FATF roadmap.
The United Kingdom implements the same international standards through its own instruments, and this is a classic onshoring trap for anyone tempted to reach for the EU text. UK obliged entities are governed by the Money Laundering Regulations 2017 and the Proceeds of Crime Act 2002, not by the EU Regulation. The UK has also gone further than most on the corporate side. Section 199 of the Economic Crime and Corporate Transparency Act 2023 created a “failure to prevent fraud” offence that came into force on 1 September 2025. The offence applies to relevant bodies covered by sections 199 to 202. A body is a large organisation if it meets at least two of three thresholds in the financial year preceding the year of the base fraud offence: turnover above GBP 36 million, a balance-sheet total above GBP 18 million, or more than 250 employees. For a parent undertaking, section 202 applies those thresholds to aggregate group turnover, balance-sheet total and employee numbers. Section 199(2) can also bring a subsidiary undertaking of a large organisation within scope even where the subsidiary undertaking is not itself large. A relevant organisation has a defence if it had reasonable fraud prevention procedures in place, or if it can demonstrate that it was not reasonable in all the circumstances to expect it to have such procedures. The Home Office first published statutory guidance on 6 November 2024 and updated it on 10 October 2025. Whether the defence is established is ultimately a matter for the court.
National implementation must be verified jurisdiction by jurisdiction. Australian and Singaporean participation in FATF fraud work or launch-event panels does not itself establish a local legal or supervisory requirement. Any Australian claim should be supported by the applicable legislation or AUSTRAC material, and any Singapore claim by the applicable legislation or MAS, Singapore Police or other competent-authority material.
The risk-based approach supervisors will test harder
The second Presidency priority concerns stronger implementation of the risk-based approach and risk-based supervision. The public FATF material does not specify whether or when an individual supervisor will change its inspection approach. The risk-based approach requires an institution to identify and assess the money-laundering and terrorist-financing risks it faces, and to apply resources in proportion to those risks. The roadmap does not amend Recommendation 1 or create a new firm-level risk-assessment rule. FATF’s February 2026 paper reports that 156 assessed jurisdictions identify fraud as a major money-laundering risk. Whether and how a firm must reflect that risk is determined by its applicable AML/CFT framework, business model and risk exposure.
The practical work sits in the enterprise-wide risk assessment. Fraud typologies worth reflecting include authorised push payment fraud, investment and romance scams run out of organised compounds, business email compromise, and the mule networks that move the proceeds. The EBA’s April 2024 Opinion analysed emerging payment-fraud patterns and proposed additional measures for the future PSD3 and Payment Services Regulation framework. It did not itself establish an AML risk-assessment or suspicious-reporting integration requirement. Firms may nevertheless use relevant fraud data as an input where this is appropriate under their applicable AML/CFT risk-assessment methodology. Supervisors probe that calibration on de-risking and risk management already, as discussed in our note on CSSF expectations for MLFT risk management.
There is a misconception worth heading off. Risk-based does not mean a firm can quietly deprioritise fraud because its residual risk looks low on paper. Where a supervisor’s national risk assessment flags fraud as a leading generator of criminal proceeds, a firm that scores fraud as immaterial without evidence is inviting a challenge to its methodology. The risk-based approach is a reason to justify your calibration, not a reason to look away.
Information sharing and the public-private tilt
The third priority, information sharing and public-private partnerships, is where the roadmap will meet the hardest operational and legal constraints. Fraud moves faster than the money-laundering reporting cycle, and the FATF’s view is that intelligence has to move faster too, both between the public and private sectors and between firms. The roadmap’s financial-intelligence and information-sharing panels put that question at the centre.
The constraint is that information sharing runs into data-protection law and confidentiality rules, and those do not dissolve because a roadmap asks for more collaboration. Any expansion of sharing has to sit inside a legal gateway. In April 2024, the EBA proposed additional anti-fraud measures intended to inform the future PSD3 and Payment Services Regulation framework. Those proposals do not themselves provide a current legal gateway or impose a current obligation for payment service providers to exchange fraud-related personal data. Any sharing arrangement must be based on applicable legislation and data-protection requirements. That route runs through legislation. Firms building sharing capability should map it to a specific legal basis and document the data-protection assessment behind it.
Better fraud intelligence may improve the usefulness of suspicious transaction reports, but the roadmap does not establish a new report-quality test for firms. Reporting teams should assess existing FIU instructions and supervisory guidance in each relevant jurisdiction before changing report content, classifications or procedures. The UK regulator has been signalling the same direction on financial-crime controls, as we covered in our summary of the FCA financial crime speech.
Scam centres, virtual assets and the payment-transparency thread
The roadmap names three risk vectors explicitly through the April declaration: organised scam centres, the misuse of legal persons, and virtual assets and emerging technologies such as artificial intelligence. Each maps to a standard a firm already lives with. Scam-centre proceeds test transaction monitoring and mule-account detection. The misuse of legal persons tests beneficial-ownership diligence, the ability to see through a shell to the person who controls it. Virtual assets test the crypto-specific controls that the FATF has been building out for years.
On virtual assets, FATF Recommendation 15 and its Interpretive Note apply the AML/CFT framework to virtual assets and virtual-asset service providers, while Recommendation 16 contains transfer-information requirements. Regulation (EU) 2023/1113 applies EU payer, payee, originator and beneficiary information requirements to transfers of funds and certain crypto-assets from 30 December 2024. It implements the EU transfer-information component, but it does not by itself implement the full scope of Recommendation 15 or the strengthened Recommendation 16 changes agreed by FATF in June 2025. The exposure of crypto-asset service providers to fraud typologies is a theme in our analysis of FATF guidance on stablecoins and unhosted wallets.
That is why the June 2026 payment-transparency consultation belongs in this picture. The FATF opened a public consultation on guidance supporting the strengthened Recommendation 16 standard on cross-border payment transparency, and its stated crime focus includes fraud alongside money laundering, terrorist financing and proliferation financing. It remains at consultation stage. The consultation concerns supporting guidance. The strengthened Recommendation 16 standard was already agreed in June 2025, and FATF expects countries to be ready to implement the revisions by the end of 2030. Firm-level legal obligations depend on the relevant jurisdiction’s implementation. For firms already implementing travel-rule data requirements, the direction of travel is toward better-quality payment data that serves fraud tracing as well as sanctions screening.
Frequently Asked Questions
Does the FATF fraud roadmap create a new report or return we have to file?
No. The roadmap is a two-year work programme for the FATF and its global network. It sets strategic priorities and drives guidance and typology work; it does not itself impose a new template or submission deadline on obliged entities. New obligations, where they arise, come through national law and updated supervisory expectations.
Our fraud team and AML team sit in different functions. Does the roadmap change that?
The roadmap encourages stronger use of AML/CFT tools against fraud but does not prescribe an organisational structure or a new firm-level integration requirement. Firms should determine whether fraud typologies are appropriately reflected in their AML risk assessments and suspicious-reporting processes by reference to their applicable law, supervisory guidance and risk exposure.
How does the roadmap reach a firm outside FATF membership?
The roadmap is not a FATF Standard and does not itself apply to firms in non-member jurisdictions. FATF-style regional bodies assess participating jurisdictions against the FATF Standards, while any firm-level duty depends on applicable local law, regulation or supervisory requirements.
What is the Recommendation 16 payment-transparency consultation, and does it apply to us?
Recommendation 16 is the FATF standard on payment transparency and is commonly referred to as the travel rule in the virtual-asset context. FATF adopted strengthened Recommendation 16 requirements in June 2025 and opened a consultation on supporting guidance in June 2026. Regulation (EU) 2023/1113 already applies EU transfer-information rules for funds and certain crypto-assets, but it predates and should not be presented as full implementation of the June 2025 FATF revisions. FATF expects jurisdictions to be ready to implement those revisions by the end of 2030, subject to the relevant local legislative process.
Does the UK failure to prevent fraud offence come from the FATF roadmap?
No. The offence in section 199 of the Economic Crime and Corporate Transparency Act 2023 is a separate UK statute that came into force on 1 September 2025, before the roadmap launched. It reflects the same policy direction, treating fraud prevention as a corporate responsibility, though it is not a roadmap deliverable. Large organisations within scope should assess the offence and its statutory defence by reference to their circumstances and the current Home Office guidance, updated on 10 October 2025. The defence also covers circumstances in which it was not reasonable to expect the organisation to have prevention procedures.
What should go into the next enterprise-wide risk assessment?
Represent fraud as a predicate offence generating launderable proceeds. That means covering the fraud typologies relevant to your business, such as authorised push payment fraud, investment and romance scams, and business email compromise; assessing exposure to mule networks and scam-centre flows; and, where relevant, exposure to fraud proceeds moving through virtual assets. Then justify the residual-risk rating with evidence the supervisor can follow.
Does the roadmap’s information-sharing push override data-protection rules?
No. Enhanced information sharing has to operate inside a legal gateway and a documented data-protection basis. The FATF direction encourages public-private partnerships and firm-to-firm sharing, and the enabling legislation, such as the EU’s forthcoming Payment Services Regulation for payment-fraud data, is what actually permits it. Build sharing capability on a specific legal basis you can point to.
Related Articles
- FATF Travel Rule Consultation: Recommendation 16 and the EU: how the payment-transparency standard maps onto EU crypto and wire-transfer rules.
- AMLR: What Changes for Obliged Entities: the obligations under Regulation (EU) 2024/1624 and its application timeline.
- AUSTRAC 2026 Financial Crime Risk Snapshot: scam and mule typologies and what they mean for AML teams.
- FATF on Stablecoins and Unhosted Wallets: the AML/CFT expectations for virtual-asset exposure.
- FCA Financial Crime Speech, June 2026: the UK supervisory tone on AML reporting and controls.
- CSSF on De-Risking and MLFT Risk Management: how a supervisor probes risk-based calibration.
Key Takeaways
- The FATF 2026-2028 Roadmap on Combatting Fraud launched on 1 July 2026 under the UK Presidency. It is a strategic FATF work programme; it does not add a reporting obligation.
- Its three priorities are the fraud response including scam-centre risks, the risk-based approach and risk-based supervision, and information sharing and public-private partnerships.
- The roadmap does not itself impose firm-level duties. Any binding effect arises through applicable national or regional law or supervisory requirements, while FATF mutual evaluations assess jurisdictions against the FATF Standards. Cite the local instrument that governs you, such as the EU AML package or the UK Money Laundering Regulations 2017.
- The practical monitoring point for AML teams is whether applicable national requirements and the institution’s risk exposure require stronger treatment of fraud proceeds in the enterprise-wide risk assessment or suspicious-reporting processes.
- Recommendation 15 addresses virtual-asset and virtual-asset service-provider risks, while Recommendation 16 addresses payment and transfer transparency. Regulation (EU) 2023/1113 implements EU transfer-information requirements for funds and certain crypto-assets, but it does not constitute full implementation of Recommendation 15 or the strengthened Recommendation 16 revisions agreed in June 2025.
- Information sharing must run inside a legal gateway and a documented data-protection basis.
- The UK failure to prevent fraud offence under ECCTA 2023, in force from 1 September 2025, is a separate but aligned corporate obligation. Group scoping: section 202 applies size thresholds on an aggregate basis for parent undertakings, and section 199(2) can bring a subsidiary within scope even where the subsidiary itself is not large.
Sources and References
- FATF, “EVENT: Launching the FATF’s Roadmap 26-28 on Combatting Fraud” (Paris, 25 June 2026): fatf-gafi.org
- FATF, “Outcomes FATF Plenary, 17-19 June 2026”: fatf-gafi.org
- FATF, “Cyber-Enabled Fraud: Digitalisation and ML/TF/PF Risks” (February 2026): fatf-gafi.org
- FATF, “Update to FATF Recommendation 16 on Payment Transparency” (June 2025): fatf-gafi.org
- Regulation (EU) 2024/1624 (Anti-Money Laundering Regulation): eur-lex.europa.eu
- Directive (EU) 2024/1640 (sixth Anti-Money Laundering Directive): eur-lex.europa.eu
- Regulation (EU) 2024/1620 (establishing the Authority for Anti-Money Laundering and Countering the Financing of Terrorism, AMLA): eur-lex.europa.eu
- Regulation (EU) 2023/1113 (information accompanying transfers of funds and certain crypto-assets, application from 30 December 2024): eur-lex.europa.eu
- EBA, “Opinion on new types of payment fraud and possible mitigations” (29 April 2024): eba.europa.eu
- Economic Crime and Corporate Transparency Act 2023 (failure to prevent fraud, sections 199 to 202): legislation.gov.uk
- Home Office, guidance on the failure to prevent fraud offence (first published 6 November 2024, updated 10 October 2025): gov.uk
Putting the roadmap on the AML work plan
For a reporting team, the roadmap is a horizon-scanning item rather than a new filing requirement. Firms can use the next risk-assessment cycle to check whether fraud risks are treated consistently with applicable national law, supervisory guidance and the institution’s documented exposure. Suspicious-reporting content and information-sharing arrangements should likewise be tested against the governing FIU instructions, legal gateways and data-protection requirements. The FATF roadmap itself does not determine the outcome of those assessments.
Last updated: July 2026
Disclaimer: The information on RegReportingDesk.com is for educational and informational purposes only. It does not constitute legal, regulatory, tax, or compliance advice. Always consult your compliance officer, legal counsel, or the relevant supervisory authority for guidance specific to your institution.
