February 2025 updated guide to high risk jurisdictions for money laundering

Following the FATF’s plenary at the end of February 2025, VinciWorks has released its updated guide for all of the high risk jurisdictions for money laundering. This guide includes all of the jurisdictions subject to increased FATF monitoring, alongside countries on the EU’s High Risk Third Countries. 

 

This guide also includes those jurisdictions which have recently been removed from international lists. For a comprehensive approach to money laundering compliance, it is advisable to factor in decisions of international bodies when conducting due diligence. 

 

In the February 2025 FATF plenary, the Philippines was removed from the Grey List. Laos and Nepal were added to the Grey List. This guide contains detailed information on the AML challenges facing these countries, why they were grey listed, and what they must do to be removed.

 

The FATF voted to revise their standards to take better account of the 1.4 billion people in the world who do not have a bank account. The changes encourage financial institutions to apply simplified measures where the risks are lower. 

 

A report into the financial aspects of child sexual exploitation was approved, and aims to better detect financial transactions of offenders and abusers. 

Download the guide here. 

How are you managing your GDPR compliance requirements?

GDPR added a significant compliance burden on DPOs and data processors. Data breaches must be reported to the authorities within 72 hours, each new data processing activity needs to be documented and Data Protection Impact Assessments (DPIA) must be carried out for processing that is likely to result in a high risk to individuals. Penalties for breaching GDPR can reach into the tens of millions of Euros.

GDPR added a significant compliance burden on DPOs and data processors. Data breaches must be reported to the authorities within 72 hours, each new data processing activity needs to be documented and Data Protection Impact Assessments (DPIA) must be carried out for processing that is likely to result in a high risk to individuals. Penalties for breaching GDPR can reach into the tens of millions of Euros.

“In a world older and more complete than ours they move finished and complete, gifted with extensions of the senses we have lost or never attained, living by voices we shall never hear.”

Picture of James

James

VinciWorks CEO, VInciWorks

Spending time looking for your parcel around the neighbourhood is a thing of the past. That’s a promise.

How are you managing your GDPR compliance requirements?

GDPR added a significant compliance burden on DPOs and data processors. Data breaches must be reported to the authorities within 72 hours, each new data processing activity needs to be documented and Data Protection Impact Assessments (DPIA) must be carried out for processing that is likely to result in a high risk to individuals. Penalties for breaching GDPR can reach into the tens of millions of Euros.

GDPR added a significant compliance burden on DPOs and data processors. Data breaches must be reported to the authorities within 72 hours, each new data processing activity needs to be documented and Data Protection Impact Assessments (DPIA) must be carried out for processing that is likely to result in a high risk to individuals. Penalties for breaching GDPR can reach into the tens of millions of Euros.

How are you managing your GDPR compliance requirements?

GDPR added a significant compliance burden on DPOs and data processors. Data breaches must be reported to the authorities within 72 hours, each new data processing activity needs to be documented and Data Protection Impact Assessments (DPIA) must be carried out for processing that is likely to result in a high risk to individuals. Penalties for breaching GDPR can reach into the tens of millions of Euros.

GDPR added a significant compliance burden on DPOs and data processors. Data breaches must be reported to the authorities within 72 hours, each new data processing activity needs to be documented and Data Protection Impact Assessments (DPIA) must be carried out for processing that is likely to result in a high risk to individuals. Penalties for breaching GDPR can reach into the tens of millions of Euros.