Latin America and Caribbean Financial Crime Controls
Latin America and the Caribbean cannot be treated as one financial-crime jurisdiction. The region contains large universal banking markets, small island financial centres, dollarised and non-dollarised economies, domestic and international banks, major remittance corridors, free-trade zones, securities markets, payment institutions, fintechs, virtual-asset businesses and very different legal traditions. The practical challenge for a bank is therefore not to memorise one regional rulebook. It is to build a control model that starts from common international standards, maps them into each local legal entity and product, and still lets the group see cross-border risk as one connected story.
Two FATF-style regional bodies are especially important to that story. GAFILAT, the Financial Action Task Force of Latin America, supports implementation and mutual evaluation across its member jurisdictions. Its 2026–2030 strategy places strong emphasis on risk-based supervision, effectiveness, regional cooperation, beneficial ownership, new technologies and the fifth round of mutual evaluations. CFATF, the Caribbean Financial Action Task Force, performs the same kind of regional role for Caribbean jurisdictions. CFATF completed the final fourth-round evaluations of Curaçao and Sint Maarten in 2025 and began its fifth round in 2026. For a bank, mutual-evaluation reports are not local law, but they are valuable evidence of where national frameworks are strong, where supervisors are focusing and where control effectiveness may still be developing.
The global baseline remains the FATF Recommendations. The current FATF Recommendations were updated in June 2026. They cover risk assessment, customer due diligence, beneficial ownership, suspicious-transaction reporting, correspondent banking, wire-transfer transparency, targeted financial sanctions, virtual assets, supervision, FIUs, international cooperation and other elements that appear throughout this chapter. A multinational bank should use those standards as a common control language, but it must never present them as if they automatically create identical legal obligations in Brazil, Mexico, Argentina, Panama, Jamaica, Barbados, Curaçao or any other jurisdiction. National law, regulator instructions, FIU reporting rules and product-specific obligations decide the binding requirement.
A practical mental model: common spine, local overlays
The most useful operating model has a common spine and local overlays.
The common spine contains controls that a banking group wants to recognise everywhere: customer identification, beneficial-ownership analysis, customer risk assessment, PEP and sanctions screening, transaction monitoring, payment transparency, correspondent-bank due diligence, case investigation, suspicious-activity reporting, record keeping, training, quality assurance and governance. The terminology and system components can be standardised enough to make data comparable and allow group oversight.
The local overlay defines what changes by jurisdiction. It identifies the reporting entity, competent supervisor, FIU, applicable AML/CFT/CPF laws, report types, thresholds, deadlines, local definitions, retention periods, beneficial-ownership rules, sanctions implementation, privacy or bank-secrecy restrictions, required approvals and any product-specific obligations. The overlay also records effective dates. A control can be correct in concept and still be wrong because the bank applied a threshold, report format or definition that belonged to another country or to an earlier version of the law.
This distinction is essential for delivery teams. A developer should not receive a requirement such as “apply the Latin America suspicious transaction rule”. There is no such universal rule. The requirement should say which legal entity is in scope, which event or suspicion threshold applies, which data is mandatory, which local report is produced, which FIU or authority receives it, what the due date is, whether filing creates customer-contact restrictions, what evidence must be retained and which version of the rule is effective for the transaction date.
The same approach applies to sanctions and targeted financial sanctions. FATF Recommendations 6 and 7 provide international standards relating to terrorist financing and proliferation financing, and countries implement relevant United Nations obligations through their own legal systems. A group may also face U.S., EU, UK or other sanctions exposure because of its entities, currencies, ownership, correspondent relationships or transaction nexus. That does not turn a foreign sanctions regime into a universal law for every local transaction. Systems and procedures need to preserve the legal basis for each action rather than reducing every outcome to a generic sanctions=true flag.
The region’s risk landscape without stereotypes
Regional financial-crime controls become weak when geography is treated as a substitute for analysis. Latin America and the Caribbean have real and documented exposures to organised crime, corruption, narcotics trafficking, trade-based laundering, tax crime, smuggling, illegal mining, environmental crime, cash-intensive activity and misuse of corporate structures. The region also contains many ordinary customers, legitimate remittance users, exporters, tourism businesses, family enterprises and international investors. Good risk management distinguishes the risk driver from the person’s nationality or the country name alone.
A bank should therefore ask what makes a relationship or flow higher risk. Cash intensity may matter because physical cash can obscure the origin of value. Remittance corridors may matter because funds move rapidly across borders and may involve agents or multiple counterparties. Trade finance may matter because value can be shifted through mispricing, false invoicing, phantom shipments, over- or under-shipment or manipulation of goods descriptions. Corporate structures may matter because nominee arrangements, layered ownership or trusts can make control harder to establish. Public-sector exposure may matter because bribery, procurement fraud or diversion of public funds can generate criminal proceeds. Virtual assets may matter because value can move through exchanges, wallets and cross-chain services outside the bank’s direct visibility.
None of those features is a finding by itself. A cash-heavy business can be legitimate. A family company can use holding companies for valid tax or governance reasons. A cross-border payment can move through Panama, the Caribbean, the United States and Europe for commercial reasons. The control objective is to combine customer purpose, ownership, product use, counterparties, geography, transaction behaviour and independent evidence into a view that a reviewer can explain.
Country risk also needs current data. FATF’s public statements change over time. As of 19 June 2026, the FATF list of jurisdictions under increased monitoring included, among others, Bolivia, Haiti, Venezuela and the British Virgin Islands, while FATF’s high-risk jurisdictions subject to a call for action were DPRK, Iran and Myanmar. That date matters. A bank should consume the live FATF source and local supervisory instructions rather than hard-code an old list into onboarding. Increased monitoring also does not mean that every customer or transaction from the jurisdiction must be rejected. FATF itself describes the list as identifying countries working with FATF to address strategic deficiencies; institutions should apply proportionate measures consistent with applicable law and risk.
National systems differ: four examples
A few examples make the regional-overlay principle concrete.
In Brazil, institutions authorised by the Banco Central do Brasil operate under the Brazilian AML/CFT framework and BCB regulation, including the risk-based requirements associated with Circular 3,978/2020 and subsequent amendments. The BCB states that supervised institutions must implement policies, procedures and controls and report suspicious situations and operations to COAF, Brazil’s FIU. COAF receives communications from obliged sectors through Siscoaf and also performs supervisory functions for sectors that do not have their own regulator. For a bank group, the practical point is that supervisory ownership, FIU reporting and sector-specific rules must be mapped separately even though they contribute to one national AML/CFT system.
In Mexico, the Comisión Nacional Bancaria y de Valores, or CNBV, has a dedicated preventive-supervision function for money laundering, terrorist financing and proliferation financing. Its current public material explains that it supervises covered entities and acts as a technological bridge for regulatory reports submitted to the Secretaría de Hacienda y Crédito Público. The exact obligations depend on the type of financial institution and the applicable provisions. A global platform therefore needs institution-type and legal-entity attributes; it cannot assume that one reporting rule covers banks, money transmitters, exchange centres and every other supervised sector in the same way.
In Argentina, the Unidad de Información Financiera, or UIF, maintains current lists of resolutions by obliged-entity type. For financial and foreign-exchange entities, the UIF identifies Resolution 14/2023 together with later amendments including Resolution 199/2024 and threshold changes in Resolution 78/2025. Resolution 14/2023 is explicitly risk based, requiring covered financial institutions to identify, assess, monitor, manage and mitigate ML/TF risk. That example illustrates why a regulatory inventory must capture amendments and not only the original rule number.
In Panama, the Unidad de Análisis Financiero is the national FIU, while banking supervision and preventive-control requirements for banks sit with the Superintendencia de Bancos de Panamá. The SBP’s current prevention library includes 2026 measures, and in June 2026 it published new criteria for imposing administrative sanctions on banks for failures in the regime to prevent money laundering, terrorist financing and proliferation financing. The significance for a bank is operational: a local control framework must follow the live supervisor and FIU sources, not an assumption that a country’s removal from an international monitoring list means the regulatory programme is finished.
These examples are deliberately not a legal checklist. They show the architecture: local statute and regulation, sector supervisor, FIU, reporting channel, bank policy, systems and evidence. Other Latin American and Caribbean jurisdictions have different combinations of central banks, banking commissions, financial-services regulators, FIUs, securities supervisors and ministerial authorities. The bank’s jurisdiction register has to identify the right combination for each entity.
Customer due diligence and beneficial ownership
Beneficial ownership is one of the most important cross-border control problems in the region because legitimate commerce frequently uses holding companies, family groups, trusts, foundations, partnerships, special-purpose vehicles and international ownership chains. FATF strengthened Recommendation 24 for legal persons and Recommendation 25 for legal arrangements. Its guidance emphasises adequate, accurate and up-to-date beneficial-ownership information and a multi-pronged approach rather than reliance on one source.
The bank should separate four questions. Who is the legal customer? Who owns the customer? Who controls it through voting, contractual rights or other means where relevant? Who ultimately benefits from the relationship or transaction? Local legal thresholds and definitions differ, so a group system should store the source rule and not only an ownership percentage.
The data model should preserve the ownership chain and effective dates. If Company A is owned by Holding B, which is owned by two individuals and a trust, the case file should allow an investigator to reconstruct the structure as it existed when the transaction occurred. Registry data can be useful but should not automatically replace customer evidence or verification. A public registry may be incomplete, stale, scoped only to certain entity types or designed for a different legal purpose. Conversely, a discrepancy between reliable registry information and customer-provided ownership can be a material trigger for review.
PEP controls need the same jurisdictional discipline. FATF provides an international framework for foreign, domestic and international-organisation PEPs, but local definitions, family-member treatment, close-associate concepts and required enhanced measures can vary. The control should identify why the person is considered politically exposed, the jurisdiction and role, source quality, date, relationship to the customer and the measures that follow. Being a PEP is a risk factor, not an allegation of corruption.
Payments, remittances and corridor risk
Cross-border payments make the regional operating model visible because one transaction can touch several legal regimes in seconds. A payment from a corporate customer in Brazil to a supplier in Mexico may use a U.S. dollar correspondent in New York, pass through a group payment hub in Europe and settle with institutions that have their own screening and data-quality controls. The originating bank still needs to understand which local customer and reporting obligations it owns while preserving enough payment data for screening, monitoring, tracing and investigation.
FATF revised Recommendation 16 on payment transparency in June 2025. FATF’s June 2026 consultation on implementation guidance notes that all countries are expected to be ready to implement the strengthened standard by the end of 2030. The transition period matters. Banks should track when local law and scheme rules adopt the revised requirements rather than pretending the 2030 end-state is already binding everywhere. Architecture should nevertheless be designed for richer and more structured originator and beneficiary data, fraud and error controls, and traceability across newer payment methods.
Remittance services require proportionate control rather than blanket suspicion. They are economically important and often used for ordinary family support. Risk can rise where there are opaque agents, inconsistent sender identity, unexplained third-party funding, rapid aggregation or splitting, unusual corridor changes, cash funding inconsistent with profile, repeated beneficiaries with no credible relationship or links to known mule networks. A bank providing services to a remittance company also needs respondent-style due diligence on the business model, licensing, agent network, customer controls, monitoring, sanctions framework, governance and settlement flows.
Correspondent banking is closely connected. Latin American and Caribbean banks may depend on international correspondents for major currencies and cross-border reach. The Wolfsberg Correspondent Banking Due Diligence Questionnaire provides a widely used standardised framework for gathering information about a respondent’s financial-crime programme. It supports risk-based due diligence but does not replace judgement. A correspondent should understand the respondent’s ownership, management, regulatory status, customer base, products, nested relationships, sanctions and AML controls, geography, audit results and material regulatory history.
The wrong response to risk is indiscriminate de-risking. Ending a relationship can be appropriate when risk is outside appetite or cannot be mitigated, but broad exits can push customers toward less transparent channels and damage legitimate remittance, trade and financial-inclusion needs. The decision should be relationship specific, evidenced and consistent with applicable legal and regulatory expectations.
Trade, free zones and value movement
Trade-based money laundering deserves special attention because many regional economies are deeply connected to commodities, manufacturing, agriculture, energy, tourism and international distribution. The bank does not need to become a customs authority to recognise trade risk. It should understand what goods or services the customer normally trades, where counterparties are located, how invoices are financed, which shipping or trade documents are available, how prices compare with commercial logic and whether payment behaviour matches the stated business.
A single difference between invoice value and a reference price does not prove laundering. Goods can vary in quality, freight, insurance, seasonality and contractual terms. Strong investigations therefore look for combinations: unexplained price anomalies, repeated use of unrelated intermediaries, circular payments, mismatched goods descriptions, routes inconsistent with the commercial story, sudden changes in counterparties, payments from third parties with no clear role, documents that conflict with each other or transactions inconsistent with the customer’s capacity.
Free zones and international business structures also need contextual review. They can support legitimate trade and investment. The control issue is whether the bank can identify the real business, beneficial owners, counterparties, source of funds and economic purpose. A generic rule that labels every free-zone customer high risk can generate false positives while missing genuinely suspicious structures elsewhere.
From monitoring signal to FIU report
Every country has its own terminology and filing mechanics, but the control chain is recognisable. Monitoring, staff referral, law-enforcement information, sanctions screening or customer review generates a signal. An investigator gathers customer, account, payment, counterparty and external context. The investigator decides whether the applicable legal threshold for suspicious reporting has been met. The bank files through the correct local channel, preserves the acknowledgement and continues any required monitoring or relationship action.
The regional complication is that report type, threshold, deadline and narrative requirements differ. The bank should never reuse a foreign-country SAR or STR deadline just because the group case tool uses the same screen. The obligation engine should hold the local rule. The case tool can still standardise evidence capture: transaction identifiers, customer profile, ownership, related parties, reason for alert, investigative steps, facts supporting suspicion, disposition, approver and report reference.
FIUs are central to the model. The Egmont Group describes FIUs as national centres for receiving and analysing suspicious transaction reports and relevant financial information and disseminating analysis to competent authorities. Egmont’s information-exchange principles support lawful international cooperation between FIUs, with confidentiality and purpose controls. For a banking group, that does not mean investigators can freely exchange every case file across borders. Internal sharing must still comply with local privacy, secrecy, employment and data-transfer rules, while external FIU-to-FIU exchange follows official channels.
A strong investigator distinguishes unusual from suspicious. A new corridor, high-value cash deposit or offshore counterparty may justify review without reaching the reporting threshold. Conversely, a pattern that looks individually small can become suspicious when linked across accounts, entities, agents or time. Network analysis is useful where common device, address, beneficial owner, beneficiary, merchant, IP, wallet or document relationships connect activity that isolated account monitoring would miss.
Sanctions, targeted financial sanctions and proliferation financing
Sanctions controls in the region require more than name screening. The bank has to know which national sanctions and targeted-financial-sanctions measures apply, how UN designations are implemented, whether domestic lists exist, how ownership or control is interpreted, which assets or services are restricted and what reporting action is required. Global groups then add other applicable regimes based on entity and transaction nexus.
Proliferation-financing risk can appear in trade, correspondent payments, dual-use goods, shipping, intermediary companies and complex procurement networks. FATF’s standards require countries to implement relevant targeted financial sanctions and assess risks of breach, non-implementation or evasion of proliferation-financing sanctions. For banks, this creates a need to connect sanctions screening with customer due diligence, trade-finance review and payment investigation rather than treating proliferation as a separate specialist topic with no operational data.
The system should preserve the legal regime and reason for every interdiction decision. A name match can be a false positive, a potential match or a confirmed match. A country indicator may trigger enhanced review without creating a prohibition. A trade restriction can depend on goods, end use or services rather than the counterparty name. The workflow must let legal and sanctions specialists apply the correct local rule and document the operational outcome.
Data and technology architecture
The regional control model needs a jurisdiction-aware data architecture. At minimum, the bank should be able to link customer, account, legal entity, product, branch or channel, transaction, payment message, counterparty, beneficial owner, device or agent where relevant, case, external report and control version. Each important attribute should carry provenance and effective dates where change matters.
Names require careful handling across Spanish, Portuguese, English, French, Dutch and local naming conventions. Diacritics, compound surnames, multiple given names, married names, aliases and corporate suffixes can affect screening. Transliteration may be less central than in some other regions, but normalisation still needs testing. Removing every accent or punctuation mark may improve recall while increasing false positives; the matching engine should preserve original values and explain the normalised form used for comparison.
Identifiers can be stronger than names. National tax IDs, company registration numbers, account identifiers, passport or national ID numbers, bank codes and legal-entity identifiers can improve entity resolution when law and data availability permit. A matching model should use them as corroborating evidence rather than assume every source is error free.
Payment data quality is equally important. ISO 20022 can provide structured debtor, creditor, agent and remittance information, but only if channels and upstream systems populate it accurately and mappings preserve the data. Legacy domestic rails or free-text instructions may provide less structure. The monitoring and screening design should reflect what each rail actually carries rather than claim a field is available everywhere.
BA, architecture and testing considerations
A business analyst working on this control should maintain a jurisdiction obligation matrix. For each legal entity and product, it should map the authoritative source, obligation, trigger, threshold where applicable, deadline, data fields, decision owner, reporting channel, retention rule, customer-impact constraints and effective date. Requirements can then point to that controlled source instead of embedding legal logic in prose across multiple Jira stories.
Architecture should separate reusable components from local configuration. Customer and ownership data services, screening engines, transaction-monitoring platforms, case management, audit logging and reporting gateways may be shared. Jurisdiction-specific rules should be configurable and versioned. A local requirement should not force duplication of the whole platform when a policy table, workflow branch or reporting adapter can express the difference safely.
Testing has to cover more than the happy path. Teams should test a customer moving from low to high risk, an ownership change, a new PEP relationship, a late-arriving cash or payment event, duplicate transactions, two channels contributing to an aggregation rule, a sanctions-list update, a payment with missing originator data, a false-positive name match, a customer with legitimate high-volume remittances, and a suspicious network spread across several accounts. For local reporting, test submission, rejection, correction, acknowledgement, resubmission and reconciliation between cases and reports.
Change management is a control in its own right. GAFILAT and CFATF fifth-round activity, FATF updates, local regulatory amendments, new FIU schemas and supervisor guidance can alter requirements. The bank needs horizon scanning, legal interpretation, impact assessment, ownership, implementation, testing, deployment and post-implementation evidence. An old but successful rule is still a control failure if the law has changed.
What good looks like
A strong Latin America and Caribbean financial-crime operating model does not pretend the region is uniform. It gives the group a common language while preserving local legal accuracy. It links customer risk, beneficial ownership, payments, trade, remittances, correspondent banking, sanctions, monitoring, investigations and FIU reporting instead of running them as unrelated control silos.
It also produces evidence. A reviewer can see which rule applied on the relevant date, which data fed the decision, what the analyst concluded, who approved it, what customer or payment action followed and what was reported externally. Senior management can see not only case volumes but also backlog risk, data gaps, scenario performance, report quality, overdue remediation, sanctions-list failures, correspondent-risk trends and jurisdictional change.
Most importantly, the model is proportionate. It protects the bank and the financial system without assuming that cash use, remittances, offshore structures, a Caribbean address or a Latin American trade corridor is suspicious by itself. The professional standard is to understand the legitimate business first, identify the actual risk indicators and make decisions that can be defended with evidence.
Operational deep dive: where regional risk actually appears
The regional operating model becomes useful only when it explains where risk enters the bank and how a reviewer separates a genuine concern from an ordinary regional feature. Latin America and the Caribbean contain very different economies and financial systems, so typologies should be used as hypotheses to test, not as shortcuts that label whole sectors or countries as suspicious.
Cash, informal value and remittance activity
Cash remains important in many markets for legitimate reasons: small-business commerce, tourism, agriculture, informal employment and uneven access to digital financial services. That makes cash a relevant risk factor but a poor conclusion. The investigator should compare deposits and withdrawals with the customer’s occupation or business model, declared turnover, seasonality, branch or ATM usage, counterparties and later movement of funds.
Risk becomes more meaningful when cash is combined with behaviour that is difficult to explain. Examples include repeated deposits by unrelated third parties, rapid conversion into cross-border transfers, use of several accounts to keep individual transactions below control thresholds, cash activity in locations unrelated to the business, or funds moving immediately to newly added beneficiaries. Even then, the bank needs evidence. A distributor may legitimately collect cash through agents; a tourism business can have seasonal spikes; a family remittance user may receive support from several relatives.
Remittance monitoring should follow the same principle. The objective is not to treat migrant workers or families as higher risk. It is to identify patterns inconsistent with the customer or provider profile: rapid corridor changes, sender or beneficiary networks that behave like commercial aggregation, unexplained third-party funding, high-frequency cash-funded transfers, repeated use of agents with abnormal exception rates, or settlement flows that do not reconcile with the provider’s customer activity.
Where a bank services a money transmitter or other non-bank payment provider, due diligence should extend beyond the respondent’s licence. The bank should understand agent governance, onboarding standards, screening, transaction monitoring, complaint and fraud processes, settlement accounts, corridor exposure, use of sub-agents, quality assurance and regulatory history. Wolfsberg’s 2026 guidance on banking services to non-bank payment service providers is useful because it treats the relationship as a financial-crime control problem rather than a binary choice between accepting and exiting the sector.
Trade-based laundering and commercial complexity
Trade-based money laundering can be difficult because banks usually see only part of the commercial chain. An open-account payment may contain little more than party names, amount, currency and a short invoice reference. A trade-finance bank may also see invoices, bills of lading, certificates, guarantees or letters of credit. Monitoring requirements should reflect that difference in visibility.
The strongest trade review asks whether the commercial story is coherent. Does the customer normally trade these goods? Is the counterparty in a plausible market? Are volumes consistent with capacity? Do invoice, shipping and payment details agree? Is there an unexplained intermediary? Is the payment made by or to a third party with no obvious commercial role? Does the route make sense for the goods? Are there repeated amendments, unusual prepayments, circular refunds or payments split across unrelated accounts?
Price checking can support an investigation but should not become an automated accusation. Commodity grade, freight, insurance, delivery terms, financing, scarcity, contractual discounts and quality can all produce legitimate price differences. The control should use pricing as one evidence source and record the basis of comparison.
Free-trade zones, ports and logistics hubs deserve contextual risk assessment because high transaction volumes and international counterparties can create opportunities for misuse. They also support legitimate trade. Requirements should therefore focus on beneficial ownership, business purpose, goods and counterparties, customs or trade documentation where available, and behaviour over time rather than a static geographic label.
Corruption, public procurement and PEP exposure
Corruption and misuse of public funds are important predicate-crime risks in parts of the region, but a bank should avoid reducing the issue to PEP screening. A PEP indicator tells the bank that enhanced understanding may be required; it does not establish that funds are corrupt.
The investigator should look at the economic story. A public official or close associate may have legitimate salary, investments and family wealth. Concern rises when wealth or transactions are difficult to reconcile with known sources, when companies linked to public officials receive unexplained public-contract proceeds, when payments involve consultants with vague services, when there are rapid transfers through layered entities, or when beneficial ownership appears designed to conceal the relationship.
Source-of-wealth and source-of-funds controls are different. Source of wealth explains how a person built their overall economic position. Source of funds explains the origin of the specific money entering a transaction or relationship. Good case tools keep both concepts visible and link evidence to the conclusion rather than accepting a generic document upload as proof.
Adverse media can help, especially where public records are fragmented, but language and source quality matter. Spanish and Portuguese media screening requires more than English-language search. Local legal terminology, abbreviations and naming conventions may change the result. Analysts should distinguish allegation, investigation, charge, conviction, regulatory finding and political controversy; those categories carry different evidential weight.
Corporate opacity, trusts and international structures
International business companies, trusts, foundations and holding structures are common in legitimate cross-border wealth, investment, shipping, insurance and family planning. Risk arises when the bank cannot establish who ultimately owns or controls the structure, why it exists, how funds are generated and whether transactions match that purpose.
FATF’s strengthened Recommendations 24 and 25 matter here because they emphasise timely access to adequate, accurate and up-to-date beneficial-ownership information. For the bank, that means customer declarations should be tested against reliable corporate, registry, trust, tax or independent information where appropriate and available. The exact evidence depends on jurisdiction and entity type.
A useful ownership graph records each entity and person, ownership percentage where relevant, other control rights, trust role, source of evidence and effective dates. This lets investigators identify shared owners across apparently unrelated customers and reconstruct a structure at the time of a historical payment. It also supports sanctions analysis where ownership or control can affect legal treatment under an applicable regime.
Citizenship- or residence-by-investment programmes, where they exist, should be handled through ordinary risk logic. A second citizenship does not itself make a customer suspicious. The bank should understand identity history, tax residence, source of wealth, reason for the programme, jurisdictions involved and whether the structure creates gaps in customer information or sanctions screening.
Virtual assets, fintech and rapid value movement
The region has active fintech and virtual-asset markets. Banks can encounter virtual-asset service providers as customers, counterparties or sources of funds even when they do not offer digital-asset products themselves. FATF Recommendation 15 and the Travel Rule provide the global baseline, but licensing, registration, supervision and implementation differ locally.
Risk assessment should distinguish a regulated exchange with transparent ownership, customer controls and auditable settlement flows from an opaque intermediary that cannot explain wallet governance or counterparties. Investigators should understand whether funds came from a hosted exchange, an unhosted wallet, a peer-to-peer platform or a chain of services, and what the bank can actually evidence. Blockchain analytics can provide useful exposure information but should not be treated as an infallible legal conclusion.
Rapid movement between bank accounts, payment wallets and virtual assets can shorten the time available for intervention. The architecture should connect fraud, AML and sanctions signals where possible. A compromised customer account may send scam proceeds to a mule, which then moves value to an exchange. Fraud authentication, beneficiary intelligence, transaction monitoring and virtual-asset due diligence are separate controls but describe the same movement of value.
Correspondent banking, de-risking and access
Correspondent banking is a structural issue for many smaller Caribbean and Latin American institutions because access to major currencies and international settlement often depends on foreign correspondents. A bank should therefore distinguish respondent risk from country risk. The respondent’s ownership, governance, regulator, customer base, products, nested relationships, sanctions programme, transaction-monitoring framework and audit evidence matter more than a country label alone.
Periodic review should use current evidence. A respondent that has remediated supervisory findings and strengthened controls may no longer present the same risk as when it was onboarded. Conversely, a previously stable respondent can become higher risk because of ownership change, new products, regulator action, sanctions exposure, rapid growth or opaque downstream relationships.
Exit remains a legitimate control when risk cannot be understood or mitigated. But mass exit can create financial-inclusion and transparency consequences. The decision record should therefore explain the specific risk, the mitigation considered, residual exposure, customer and payment impact, approvals and any transition controls. That documentation is important for both risk governance and later challenge.
FIU cooperation and cross-border intelligence
A multinational bank often sees signals that cross legal entities. One customer may have accounts in two group countries, a related company in a third and payments through an external correspondent. Group-level analytics can be valuable, but data sharing must be lawful.
The Egmont Group’s role is helpful for understanding the public-sector model. FIUs exchange financial intelligence through secure, governed channels, subject to confidentiality, purpose limitation and national law. The 2025 revision of the Egmont Principles reinforces wide cooperation while preserving safeguards. A bank should not imitate FIU powers. It should maintain a documented legal basis for internal cross-border data access, purpose limitations, access controls, retention and escalation.
This is especially important where bank secrecy, privacy, localisation or employment rules restrict information movement. The right architecture may use controlled regional data hubs, federated queries, pseudonymised analytics or case-to-case sharing rather than unrestricted replication of every customer file. Compliance, privacy, legal, cyber and architecture teams need one design decision rather than contradictory controls implemented independently.
Targeted financial sanctions and dynamic country status
FATF public statements, UN designations and national sanctions measures change. Banks should consume authoritative updates through controlled list-management processes and preserve the version used for a decision. A country moving on or off a FATF monitoring list is a regulatory-change event, not an automatic onboarding verdict.
List governance should include source ownership, acquisition time, validation, maker-checker controls, deployment confirmation, rescreening policy, failed-load alerts and reconciliation between the source and production screening engine. Screening logic should retain original and normalised names and use dates of birth, identifiers, nationality, address and entity data to resolve potential matches.
Regional operations also need a clear sanctions escalation path. Operations may identify the hit, but legal interpretation belongs with authorised sanctions specialists. The decision must record which regime applies, whether the party is the listed person, whether ownership or control is relevant, what activity is prohibited or permitted, and what action the bank is required or allowed to take. That separation prevents a fuzzy match score from becoming a legal conclusion.
Advanced practice: control architecture, calibration and assurance
A regional financial-crime programme becomes durable when the legal interpretation, data, detection, case workflow and governance can change independently without losing traceability. The architecture should therefore separate obligation logic from detection logic. An obligation decides what the bank must do because of law, regulation or approved policy. A detection rule decides which activity deserves attention. Mixing the two makes tuning dangerous: lowering a monitoring threshold should not accidentally alter a statutory reporting requirement, and changing a reporting schema should not silently change the customer-risk score.
Build a jurisdiction-aware obligation service
A useful obligation record contains the jurisdiction, legal entity, business line or product, authoritative source, requirement type, trigger, threshold where relevant, deadline, responsible function, required data, reporting destination, retention period, customer-contact constraint, effective-from date and superseded date. Legal or compliance owners approve the interpretation; technology consumes the approved rule.
This model solves several recurring problems. A group can identify which entities have implemented a change, distinguish current from historical rules, produce an audit trail for a past case and stop teams copying a rule from one country into another. It also lets change managers ask a precise question: which controls, reports, procedures, tests and training materials depend on this obligation?
The data model should not hard-code legal conclusions into customer master fields. Store facts separately from decisions. CountryOfIncorporation=PA is a fact. HighRiskCountry=true is a derived assessment that depends on methodology and date. FATFIncreasedMonitoring=true is time-sensitive external information. EDDRequired=true is a control outcome that should identify the rule that produced it. Keeping those layers separate makes decisions explainable and easier to retest after policy changes.
Detection should reflect products and corridors
Monitoring scenarios should use the data available in each product rather than one regional template. Cash scenarios need branch, ATM, depositor and aggregation data. Cross-border payment scenarios need originator, beneficiary, agents, account, currency, country, purpose and remittance information. Merchant or payment-provider scenarios need merchant, terminal, sub-merchant, refund, chargeback and settlement data. Trade controls may need invoices, goods, ports, shipment and documentary data. Virtual-asset reviews may need exchange, wallet and blockchain-exposure information.
Calibration should be segmented enough to avoid meaningless thresholds. A cash-intensive supermarket, a private-banking customer, an exporter, a remittance company and a digital-wallet provider should not all be compared to the same peer group. Segmentation should still be governed: the bank needs to know why a peer group exists, which population it covers, whether it is large enough to be useful and whether high-risk customers are accidentally being compared only with other high-risk customers.
Scenario performance cannot be measured by alert closure rate alone. Useful measures include coverage of known typologies, conversion into cases, confirmed or reportable outcomes, false-positive causes, time to decision, analyst effort, missed-event testing, customer impact and stability after data or model changes. A scenario that produces fewer alerts may be better, but only if the bank can show it retained important detection capability.
Case management needs facts, hypotheses and decisions
Investigators should be able to distinguish sourced facts from analytical reasoning. Customer and transaction facts should retain source-system links. External information should record source and retrieval date. Analyst hypotheses should remain editable but auditable. The final disposition should identify the applicable decision threshold and the evidence that supports it.
Regional cases often need multiple currencies and time zones. The case should preserve original transaction currency and amount as well as any normalised value used for analytics. Timestamps should record the original event time and a common comparison time. This prevents an investigator from misreading two transfers as simultaneous or outside an aggregation window because systems converted time differently.
Language also matters. A case can contain Spanish, Portuguese, French, Dutch or English names and documents. Translation can support understanding, but the original text should remain available. Material legal or evidential meaning should not depend solely on an uncontrolled machine translation. Search and entity-resolution tools should support accents, compound names and local corporate abbreviations without destroying the original value.
Regulatory change should behave like production change
GAFILAT and CFATF evaluation findings, FATF amendments, national laws, supervisor circulars and FIU technical specifications should enter a controlled change process. Horizon scanning identifies the change. Legal or compliance interprets its effect. A change owner maps impacted entities, products, policies, systems, reports and controls. Requirements are approved, code or configuration is updated, tests are executed, procedures and training are changed, deployment is evidenced and post-implementation review confirms that the intended control works.
A regulatory change register should also record items that were assessed as not applicable. That decision can matter later. Without it, the bank may be unable to show whether a change was considered or simply missed.
Backward compatibility is a real issue. If a case from March 2026 is reopened after a rule changes in September, the investigator may need both the current rule and the rule that applied to the March activity. Versioning should therefore preserve prior obligation logic and report schemas where historical reconstruction is required.
Testing strategy
Functional testing should begin from business outcomes, not screens. A test pack for a new jurisdictional reporting rule should prove that the correct population is captured, thresholds or suspicion logic are applied correctly, excluded activity is handled correctly, mandatory data is populated, due dates are calculated, approvals work, the report reaches the expected channel and acknowledgements reconcile back to cases.
Boundary testing is critical. Test exact threshold values, transactions immediately before and after time-window boundaries, leap days, daylight-saving differences where relevant, currency conversions, reversals, cancellations and late-arriving events. For beneficial ownership, test direct ownership, layered ownership, joint control, trust relationships, unknown owners, conflicting sources and ownership changes over time. For screening, test aliases, diacritics, partial identifiers, common names and list updates during a payment journey.
Negative testing is just as important. A legitimate remittance pattern should not be forced into a suspicious outcome because of corridor alone. A PEP with well-evidenced wealth should not be blocked merely because of status. A company using a Caribbean holding entity should be able to pass controls when ownership and purpose are transparent. These tests protect customer outcomes and expose over-broad rules.
Failure-mode testing should cover missing feeds, duplicate files, stale lists, unavailable FIU gateways, case-system outages, delayed enrichment, corrupted timestamps and analyst capacity constraints. The control design needs a fallback response for each material dependency. “System unavailable” cannot mean the bank silently stops monitoring or reporting.
Governance and assurance
Management information should show whether controls are healthy, not just busy. Useful regional views include overdue KYC reviews, unresolved beneficial-ownership discrepancies, screening-list deployment status, payment-data completeness, transaction-monitoring backlogs, high-risk correspondent reviews, suspicious-report timeliness and quality, regulatory-change implementation status, repeat QA findings and open remediation by country.
Second-line testing should challenge whether the control design still matches local obligations and whether first-line execution is effective. Internal audit should be able to reproduce selected cases from source data through decision and external report. Independent review should also ask whether group standards create conflicts with local privacy, secrecy or customer-protection requirements.
A finding should not close because a procedure was rewritten. Closure evidence needs to address root cause. If the problem was missing payment data, the bank should demonstrate repaired lineage and back-testing. If the problem was analyst judgement, it should demonstrate training, QA and improved decisions. If the problem was an incorrect jurisdiction rule, it should show the corrected interpretation, system change, impacted-population review and any necessary remediation.
The strongest regional programmes therefore treat compliance architecture as a living system. They can absorb a local rule change without rebuilding the whole platform, and they can explain exactly which customers, payments, reports and controls were affected.
Practice close: turning the regional model into delivery decisions
A learner should leave this chapter able to challenge a regional control without falling into either of two traps: assuming every country works the same way, or treating every local requirement as so unique that nothing can be standardised. The practical skill is to identify the common control capability, isolate the jurisdiction-specific legal logic and prove that the two fit together.
A requirements workshop example
Assume a global bank is replacing separate suspicious-activity workflows in four legal entities with one regional case platform. The proposed design has a shared customer view, transaction timeline, alert queue, investigator workspace and approval screen. The project team initially proposes one “file SAR” button with a common due date and one narrative template.
That design is incomplete. The business analyst should ask which local reporting obligation each entity has, what legal threshold triggers filing, whether attempted transactions are reportable, how the due date is calculated, which mandatory fields differ, whether an FIU acknowledgment must be stored, whether a correction process exists, who can approve the report and what customer-contact restrictions apply. The shared platform can still be used, but the reporting adapter and workflow must be jurisdiction aware.
The requirement should also address evidence. If the same customer has accounts in two group countries, can investigators see both? If yes, what legal basis and access control apply? If no, what lawful escalation route lets the second entity request relevant information? Can the case link related customers without exposing restricted data? These questions belong in the functional design, not in a later privacy review after development is complete.
Acceptance criteria that prove the control
A good acceptance criterion describes observable control behaviour. For example: when the customer’s legal entity is Entity A and the investigator reaches the locally approved suspicion threshold, the workflow must select the current Entity A report schema, calculate the deadline from the approved local rule, require all mandatory fields, route the report to authorised approvers, transmit only through the approved FIU channel, store the submission response and reconcile the report identifier back to the case.
For beneficial ownership, acceptance criteria should test structure rather than one percentage field. The system should allow direct and indirect ownership, control by other means, trust roles where applicable, effective dates, source evidence and unresolved ownership. A change in ownership should create a new effective-dated relationship rather than overwrite history.
For payment monitoring, criteria should prove data completeness. A cross-border payment case should retain originator, beneficiary, relevant agents, amount, currency, transaction identifiers, payment purpose or remittance information where available, channel, timestamps and source-system provenance. If a required upstream feed fails, the control should raise an operational exception rather than silently treating missing data as “no risk”.
For sanctions, acceptance criteria should separate match resolution from legal action. A potential name match should route to review. The reviewer should see list source, identifiers and relevant relationship data. Only an authorised decision should determine whether the transaction is released, rejected, frozen, blocked or otherwise handled under the applicable regime and local process.
Test cases worth running
One test should use a legitimate remittance customer who sends regular family support through the same corridor. The monitoring model may generate a signal because of frequency, but the investigator should be able to establish the relationship and close the case with evidence. This proves that the control can distinguish risk indicators from suspicious conclusions.
Another should use a corporate customer whose ownership changes from a transparent domestic structure to a layered cross-border structure involving a trust and two holding companies. The system should trigger the required review, preserve the previous ownership, capture the new evidence and update risk only after the change has been assessed.
A trade test should include an invoice, payment and shipping document with one meaningful inconsistency and several ordinary commercial differences. The investigator should identify the relevant inconsistency without treating every price or route variation as suspicious. The case should show what was checked and why the final conclusion was reached.
A correspondent test should simulate a respondent that introduces a new downstream payment-service-provider business. The review should identify whether the new activity changes risk, whether enhanced due diligence is required, whether transaction monitoring needs new coverage and whether the relationship remains within appetite.
A regulatory-change test should change a local reporting schema while leaving the suspicion decision unchanged. Existing cases created under the old version must remain reconstructable, while new cases after the effective date should use the new schema. This proves that obligation versioning works.
Common mistakes to challenge
Do not use the FATF grey list as an automatic customer rejection list. It is a country-level monitoring mechanism and must be interpreted through applicable law, policy and the customer’s actual risk.
Do not assume a company is opaque because it uses a Caribbean or offshore structure. Ask who owns and controls it, why the structure exists, what activity occurs and whether the evidence is coherent.
Do not assume cash or remittances are suspicious. Compare them with the customer’s legitimate profile and look for combinations of indicators.
Do not assume the local FIU, banking supervisor and sanctions authority are the same organisation. Map each role correctly.
Do not let a group standard erase local legal differences. A minimum group control can be stricter than local requirements where lawful and approved, but the bank must still know which outcome is legal obligation, which is policy and which is risk appetite.
Do not close a control issue because a document was updated. Validate the source data, system behaviour, backlog or affected population that created the failure.
Final review checklist
Before calling a Latin America or Caribbean financial-crime change complete, the delivery team should be able to answer the following questions in plain language: which legal entity and products are in scope; which authoritative sources define the obligation; which regulator and FIU are involved; what customer, ownership and transaction data is needed; how screening and monitoring use that data; what decision threshold applies; what report or action follows; how the customer is affected; what happens when data or systems fail; how the control is tested; and what evidence proves the deployed version is correct.
If those answers are visible in requirements, configuration, test evidence and operating procedures, the regional model is working as intended. If the answer depends on one experienced employee remembering how “that country usually works”, the control is not yet mature.
Masterclass: one regional case, several legal entities
Consider a composite case built from common banking patterns. The names and figures are illustrative; the purpose is to show how a regional control model should reason across jurisdictions without turning geography into guilt.
A long-standing corporate customer of a Brazilian bank distributes industrial components. The customer has transparent domestic ownership and several years of ordinary payments to suppliers in Brazil, Mexico and Europe. Over three months the pattern changes. Incoming funds begin arriving from multiple unrelated commercial accounts in two Caribbean jurisdictions. The Brazilian company then sends larger U.S. dollar payments to a newly introduced supplier in Mexico and to a Panamanian trading intermediary. Payment narratives refer to equipment invoices, but the customer’s stated business has not changed.
No single fact is enough to conclude money laundering. International distributors can change suppliers, receive third-party settlement and use trading intermediaries. The investigator starts with the customer story rather than the country names.
Step 1: establish the facts
The case team verifies the Brazilian customer’s current ownership, directors, business activity, account history, expected geographies and recent KYC changes. It retrieves the actual payment messages, not only monitoring extracts. The investigator identifies the senders of the Caribbean payments, the Mexican beneficiary, the Panamanian intermediary, amounts, currencies, dates, correspondent banks and payment references.
The team also establishes what data is missing. Some incoming messages contain only abbreviated remittance information. The case records that limitation rather than inventing a purpose. Customer-contact rules are checked before questions are sent.
The investigator notices that the Mexican supplier was incorporated recently and shares an address with another company that appeared in a separate internal case. That is a useful link, not proof. Beneficial-ownership information is requested and checked against available reliable sources. The Panamanian intermediary has a credible registration but does not appear in the contracts originally provided by the Brazilian customer.
Step 2: understand the commercial explanation
The relationship manager obtains updated contracts and invoices. The customer explains that a new wholesaler introduced the Mexican supplier and that the Caribbean payments are settlements from downstream buyers. That explanation is commercially possible, so the team tests it.
Invoice quantities are plausible, but several documents use nearly identical descriptions despite different goods. Two incoming Caribbean payments arrive before the associated sale dates, and one sender has no clear connection to the downstream buyer named by the customer. The Panamanian intermediary receives a fee significantly larger than prior intermediaries, but the contract gives only a vague “commercial facilitation” description.
The case is becoming more concerning because independent facts do not fully support the customer’s explanation. The concern is the inconsistency between parties, timing, documents and economic purpose, not the use of Brazil, Mexico, Panama or Caribbean jurisdictions by itself.
Step 3: connect local and group responsibilities
The Brazilian legal entity owns the customer relationship and must apply its local AML/CFT obligations, BCB-supervised controls and any reporting decision to COAF through the approved process. The bank’s group investigation function may provide analytics and related-entity information only within the lawful information-sharing framework.
The Mexican beneficiary is not automatically a customer of the Brazilian bank. If another group entity in Mexico holds that supplier as a customer, access to its KYC and case information depends on approved cross-border sharing rules. If sharing is restricted, the Brazilian investigator uses the defined request and escalation process rather than bypassing controls.
The U.S. dollar correspondent path may create additional sanctions-screening obligations for correspondent institutions, but it does not replace the Brazilian bank’s own local decision. Likewise, the FATF monitoring status of any country involved is treated as a risk input current for the transaction date, not as a legal verdict.
Step 4: move from signal to suspicion decision
The investigator builds a chronology. It shows the customer’s historical activity, the point at which new counterparties appeared, the sequence of incoming third-party funds, subsequent outgoing payments, the document inconsistencies, ownership findings and customer explanations. The analysis distinguishes verified facts from unresolved questions.
The case is escalated because several elements now reinforce each other: unexplained third-party funding, new counterparties, inconsistent commercial documentation, a fee-paying intermediary with vague purpose and linked-address information suggesting a broader network. The authorised local decision maker assesses whether the facts reach the applicable Brazilian suspicious-reporting threshold. If they do, the report is filed through the local process and the case stores the report reference and decision rationale. If the threshold is not reached, the closure still explains why and identifies any enhanced monitoring or KYC action.
Step 5: manage customer and payment outcomes separately
A suspicious-reporting decision does not automatically mean the bank must block every payment or exit the customer. Sanctions, fraud, credit, legal and AML decisions have different triggers. The bank may choose to restrict certain activity under policy or risk appetite, but that decision should be documented separately from the FIU report.
If a payment produces a sanctions match, the sanctions team applies the relevant legal regime and ownership or control analysis. If the customer’s documents appear fraudulent, legal or fraud teams may become involved. If the relationship can no longer be understood or controlled, the business and compliance functions may consider exit under approved governance. Keeping these decision paths separate prevents one risk label from driving every outcome without legal basis.
What the masterclass teaches
The case demonstrates why regional financial-crime capability is mostly an evidence and governance problem. The bank needed local law mapping, accurate customer data, payment transparency, beneficial-ownership information, entity resolution, lawful cross-border sharing, investigator judgement and a case tool that preserved chronology.
It also demonstrates proportionality. The first Caribbean payment did not justify an allegation. The Mexican supplier’s new incorporation did not justify an allegation. The Panamanian intermediary did not justify an allegation. Concern emerged when several independently verified facts made the commercial explanation increasingly difficult to reconcile.
For business analysts and architects, the design lesson is equally important. The system must support local reporting and decision rights while allowing controlled group intelligence. For investigators, the lesson is to tell the case as a sequence of facts, explanations and unresolved contradictions. For governance, the lesson is to measure whether the bank can reproduce that reasoning months later during supervisory review.
References and further reading
These public sources support the chapter’s regional operating principles and the jurisdiction examples used above. Local legal advice and the bank’s approved country policy remain necessary for transaction-level decisions.
- FATF, The FATF Recommendations, last updated June 2026: https://www.fatf-gafi.org/en/publications/Fatfrecommendations/Fatf-recommendations.html
- FATF, Guidance on Beneficial Ownership of Legal Persons, 10 March 2023: https://www.fatf-gafi.org/en/publications/Fatfrecommendations/Guidance-Beneficial-Ownership-Legal-Persons.html
- FATF, Guidance on Beneficial Ownership and Transparency of Legal Arrangements, 11 March 2024: https://www.fatf-gafi.org/en/publications/Fatfrecommendations/Guidance-Beneficial-Ownership-Transparency-Legal-Arrangements.html
- FATF, Black and grey lists, current statements including 19 June 2026: https://www.fatf-gafi.org/en/countries/black-and-grey-lists.html
- FATF, Public consultation on guidance to increase payment transparency, 24 June 2026, explaining the 2025 Recommendation 16 revisions and 2030 implementation horizon: https://www.fatf-gafi.org/en/publications/Fatfrecommendations/R16-Public-Consultation-June-2026.html
- GAFILAT, Plan Estratégico 2026–2030, regional priorities including effectiveness, risk-based supervision, cooperation and the fifth round of mutual evaluations: https://gafilat.org/index.php/es/noticias/327-el-gafilat-presenta-su-plan
- GAFILAT, Preparación estratégica para la Evaluación Mutua de Guatemala, June 2026, illustrating fifth-round focus on risk, beneficial ownership, supervision, financial intelligence, asset recovery and targeted financial sanctions: https://gafilat.org/index.php/es/noticias/337-encuentro-preparacion-estrategica-mutua-guatemala
- CFATF, 2024–2025 Annual Report, published 2 April 2026: https://cfatf-gafic.org/the-cfatf-publishes-its-2024-2025-annual-report/
- CFATF, Mutual Evaluation Reports of Curaçao and Sint Maarten, 20 July 2025, marking completion of CFATF’s fourth round and transition to the fifth round in 2026: https://cfatf-gafic.org/the-mutual-evaluation-reports-of-curacao-and-sint-maarten/
- Egmont Group, Financial Intelligence Units, explaining the FIU receipt, analysis and dissemination role: https://egmontgroup.org/about/financial-intelligence-units/
- Egmont Group, Principles for Information Exchange between Financial Intelligence Units, revised July 2025: https://egmontgroup.org/wp-content/uploads/2022/07/EG-Principles-for-Information-Exchange-Revised-July-2025.pdf
- Basel Committee on Banking Supervision, Sound management of risks related to money laundering and financing of terrorism: revisions to supervisory cooperation, 2 July 2020: https://www.bis.org/publications/202007-guidelines-sound-management-risks-related-money-laundering-and-financing-terrorism-revisions-supervisory-cooperation
- Banco Central do Brasil, Prevenção à lavagem de dinheiro e ao financiamento do terrorismo: https://www.bcb.gov.br/estabilidadefinanceira/lavagemdinheiro
- COAF, Siscoaf, official reporting-system information: https://www.gov.br/coaf/pt-br/sistemas/siscoaf
- COAF, Recepção de Comunicações, explaining cash and suspicious-operation communications received by the Brazilian FIU: https://www.gov.br/coaf/pt-br/acesso-a-informacao/Institucional/a-producao-de-inteligencia-financeira/inteligencia-financeira
- Comisión Nacional Bancaria y de Valores, Mexico, Prevención de Lavado de Dinero, Financiamiento al Terrorismo y Financiamiento de la Proliferación de Armas de Destrucción Masiva, updated 23 October 2025: https://www.gob.mx/cnbv/acciones-y-programas/prevencion-de-lavado-de-dinero-financiamiento-al-terrorismo-y-financiamiento-de-la-proliferacion-de-armas-de-destruccion-masivapld-ft-fpadm
- CNBV, Marco Jurídico PLD/FT/FPADM, sector-specific legal framework and reminder to verify current rules: https://www.gob.mx/cnbv/acciones-y-programas/marco-juridico-pld-ft-fpadm
- Argentina, Unidad de Información Financiera, Resoluciones aplicables a cada Sujeto Obligado, showing current rules for financial and foreign-exchange entities: https://www.argentina.gob.ar/node/7897
- Argentina, UIF Resolución 14/2023, risk-management requirements for covered financial and exchange entities: https://www.argentina.gob.ar/normativa/nacional/norma-379085
- Superintendencia de Bancos de Panamá, Acuerdos de Prevención, including 2026 preventive requirements: https://www.superbancos.gob.pa/acuerdos/prevencion
- Superintendencia de Bancos de Panamá, Acuerdo No. 3-2026 sanction criteria for AML/CFT/CPF failures, published 25 June 2026: https://www.superbancos.gob.pa/node/1744
- Unidad de Análisis Financiero de Panamá, official site and current prevention activity: https://www.uaf.gob.pa/
- Wolfsberg Group, Correspondent Banking Due Diligence Questionnaire v1.4 and supporting guidance, 10 February 2023: https://wolfsberg-group.org/news/36/
- Wolfsberg Group, Financial Crime Principles for Correspondent Banking, 28 October 2022: https://wolfsberg-group.org/news/42
- Wolfsberg Group, Guidance on the Provision of Banking Services to non-bank Payment Service Providers, 2026: https://wolfsberg-group.org/resources/correspondent-banking/206