Terrorist Financing, NPOs and Funding Channels
Terrorist financing differs from money laundering in one fundamental way: the source of funds can be completely lawful. Salary, business income, donations or ordinary bank balances can be misused to finance prohibited terrorist activity. That means a control framework focused only on identifying criminal proceeds will miss part of the risk.
For a bank, the practical question is not whether every donation, charity payment or cross-border transfer is suspicious. It is whether the parties, purpose, network, destination, pattern and available intelligence create a credible terrorist-financing concern under the applicable legal and regulatory framework.
Money laundering and terrorist financing are not the same
Money laundering typically concerns disguising the criminal origin of value. Terrorist financing concerns the collection or movement of funds or assets for terrorist purposes. Funds used for terrorism can have legal or illegal origin.
This distinction matters because an investigator should not assume that a TF case will show classic placement, layering and integration. Small-value, ordinary-looking transactions can still be relevant when connected to a prohibited network or purpose.
Collection of funds
Funding can come from donations, membership contributions, legitimate businesses, criminal activity, extortion, fraud, misuse of charities, online fundraising or other sources.
The presence of charitable or crowdfunding activity is not suspicious by itself. Context and intelligence matter.
Movement of funds
Funds can move through banks, remitters, cash, prepaid products, virtual assets, trade, informal value transfer and other channels.
The movement may involve relatively small amounts, so value thresholds alone are a weak control.
Storage of value
Funds can remain in ordinary accounts, cash, wallets or assets before being used. A bank may therefore observe long periods of apparently normal behaviour before a relevant event.
Use of funds
Final use can include travel, logistics, equipment, accommodation, communication, recruitment or other support. Banks typically have limited visibility into ultimate use and should avoid claiming certainty beyond evidence.
Targeted financial sanctions
Terrorism-related targeted financial sanctions can require freezing, prohibitions and reporting where a designated person or entity, or another legally covered party, is involved. The exact action depends on the applicable sanctions regime and domestic or regional implementation. These obligations are legally distinct from a general AML/CFT suspicion assessment.
A customer may present low behavioural AML risk but still be subject to a sanctions prohibition. Conversely, suspicious TF-related behaviour may arise without a listed party.
FATF Recommendation 6
FATF Recommendation 6 addresses targeted financial sanctions related to terrorism and terrorist financing. Banks should implement the legal measures applicable to their entities and transactions through screening, ownership and control analysis, escalation, freezing or other legally required outcomes.
The precise legal implementation depends on jurisdiction. A global bank should therefore map legal entity, branch, currency, payment route and other relevant nexus rather than assume one sanctions rule applies everywhere.
June 2026 humanitarian update to Recommendation 6
On 23 June 2026 FATF updated Recommendation 6 so that countries are expected to give effect to relevant UN humanitarian exemptions, including those reflected in UN Security Council resolutions 2664 and 2761, as well as 2615. The operational lesson for banks is important: counter-terrorism sanctions controls must protect against prohibited funding without turning humanitarian activity into an automatic rejection category.
Under the current UN ISIL (Da'esh) and Al-Qaida regime, the 1267/1989/2253 Committee describes the targeted measures under resolution 2734 (2024), while resolution 2761 (2024) continued the humanitarian exemption introduced by resolution 2664 (2022) for that regime. Banks still need to use the national or regional law that implements the relevant UN measure. A standing exemption is not the same thing as a transaction-specific licence, and an institution should be able to represent both in its control data.
Non-profit organisations
Non-profit organisations can provide vital humanitarian, religious, educational, development and community services. FATF has repeatedly emphasised that measures should be focused, proportionate and risk-based rather than treating the entire NPO sector as high risk.
FATF revised Recommendation 8 and its Interpretive Note in November 2023 to address disproportionate application. The focus is not every organisation that happens to be legally non-profit. Countries are expected to identify the subset of NPOs within FATF's functional definition that may be vulnerable to terrorist-financing abuse and apply focused, proportionate measures according to identified risk.
The objective is to protect legitimate NPO activity while identifying organisations or channels that may be abused.
Avoid blanket de-risking of NPOs
Banks should not infer terrorist-financing risk merely because a customer is a charity or operates in a conflict-affected region. Such organisations may be essential to humanitarian access.
Controls should consider the organisation's governance, funding sources, delivery model, local partners, countries, beneficiaries and financial transparency. FATF's current NPO work explicitly seeks to reduce unintended consequences caused by over-application of AML/CFT measures.
Humanitarian activity
Humanitarian organisations can operate in areas where designated groups or sanctioned authorities are present. Legal frameworks can contain standing humanitarian exemptions, other exceptions, general licences or specific authorisations intended to permit qualifying humanitarian activity.
Banks should involve sanctions and legal specialists rather than treating all payments into such areas as automatically prohibited. Where a standing exemption applies, the control should not invent a licence requirement that the law does not contain; where a licence or specific authorisation is relied upon, operations should verify its actual scope and conditions.
Governance of an NPO
Useful due-diligence questions include who controls the organisation, how funds are approved, how projects are monitored, how local partners are selected, whether accounts are audited and how beneficiary payments are documented.
Strong governance can reduce residual risk even in challenging geographies.
Funding sources
NPOs can receive public grants, corporate donations, individual donations, membership fees and fundraising proceeds. The bank should understand what is normal for the organisation.
A sudden new funding source or unexplained large transfers can warrant review, but should not be interpreted without context.
Delivery partners
International organisations may work through local partners. The bank may have limited visibility into those downstream parties.
Due diligence should reflect what the customer is expected to know and control. The bank should not claim direct knowledge of every final beneficiary if it does not have it.
Crowdfunding
Online fundraising can move money rapidly from many contributors. It can support legitimate causes and can also be abused.
Banks may see payment processors or aggregated settlement rather than individual donors. Control design should reflect actual data visibility.
The bank may see one settlement line rather than hundreds of individual contributions. Where risk justifies deeper review, useful evidence can include platform payout data, campaign ownership, stated purpose, distribution endpoints and reliable external information.
Social media, instant messaging and streaming platforms
FATF's 26 June 2026 report on social media, instant messaging applications and streaming platforms describes how digital fundraising, creator monetisation, virtual assets, fraudulent humanitarian appeals and other platform features can be abused for terrorist financing. It also emphasises targeted indicators, better cooperation and the need to link financial and digital intelligence.
For a bank, public campaigns can help assess stated purpose, but social-media content is not automatically reliable evidence. Adverse information should be assessed for source quality, identity match, date and context. Platform use, livestreaming, tipping or charitable language is not suspicious by itself.
Small-value payments
TF can involve low-value transactions that would not trigger large-value AML scenarios. Monitoring therefore needs behavioural, network and intelligence context.
Travel-related activity
Travel payments can be relevant in some cases, but ordinary travel is common. Banks should avoid simplistic geography-only rules and should not use religion, ethnicity, nationality or other protected characteristics as proxies for terrorist-financing risk.
Remittance channels
Remittance services are often essential for families and humanitarian support. They can also be misused to move funds to prohibited networks.
Banks serving remitters should understand corridor, agent and settlement risk without blanket exclusion.
Cash
Cash can reduce traceability, but many economies rely heavily on cash. Cash use alone is not a TF conclusion.
Virtual assets
Virtual assets can be used for legitimate payment and investment and may also be used to raise or move funds. Banks should assess counterparties, providers, wallet exposure and customer behaviour where relevant.
Blockchain analytics can support investigation but does not replace judgement. Attribution confidence and corroborating evidence matter.
Trade and commercial activity
Legitimate businesses can be used to generate or move funds. Payments may appear commercially ordinary.
Corporate ownership, counterparties, goods, jurisdictions and intelligence can provide context.
Informal value transfer
Informal transfer systems can be relevant where formal banking access is limited. They can support legitimate family, trade and humanitarian transfers and can also be misused.
FATF's September 2026 report on underground banking, hawala and similar service providers notes both legitimate value-transfer uses and criminal exploitation. That report is principally an illicit-finance and professional-money-laundering study, so a bank should use it to understand the architecture and vulnerabilities of these channels, not as a shortcut to infer terrorist financing.
Network analysis
TF investigations can benefit from network analysis because relationships may matter more than transaction value. Shared beneficiaries, devices, organisations, accounts or counterparties can create a broader picture.
Network association is not proof. Investigators should distinguish verified, inferred and weak links.
Open-source intelligence
Public information can support understanding of organisations and individuals, but quality varies. Analyst notes should distinguish confirmed information from allegation.
FIU and law-enforcement intelligence
Banks can receive requests, alerts or typologies from authorities. Such information should be handled under appropriate confidentiality, access and use restrictions.
Scenario: humanitarian charity
A charity sends funds to a conflict-affected region through vetted local partners. Payments are consistent with donor-funded projects and governance is strong.
The geography may increase inherent risk, but the control response should remain proportionate and support legitimate humanitarian activity where the activity is lawful.
Scenario: unexplained collection account
A personal account begins receiving hundreds of small donations referencing a humanitarian cause, then sends funds to unrelated individuals and crypto services. The customer is not a registered organisation and provides inconsistent explanations.
The bank should investigate the account, purpose, beneficiaries, network and any relevant intelligence without assuming terrorism solely from fundraising language.
Scenario: sanctioned connection
An NPO has a legitimate mission but one controlling person is designated under an applicable terrorism-related sanctions regime.
The legal response may be determined by sanctions rules, ownership or control analysis and applicable exemptions or licences. AML/CFT suspicion is a separate question.
Scenario: lawful funds, prohibited purpose
A customer uses normal salary income to make transfers connected by credible evidence to a prohibited terrorist organisation. The lawful source does not remove TF risk.
This illustrates why source-of-funds analysis alone cannot detect terrorist financing.
Screening
Screening can identify designated persons, aliases, entities and legally relevant ownership or control connections. It cannot detect every TF risk because not every relevant actor is listed.
Screening and behavioural monitoring therefore complement each other.
Transaction monitoring
Useful signals can include unusual fundraising, rapid dispersal, transfers to known risk networks, changes from expected NPO activity, unexplained third-party funding and activity linked to credible intelligence.
Controls should avoid relying exclusively on amount thresholds.
Customer due diligence
For NPO customers, due diligence can include legal status, purpose, governance, funding, countries, programmes, local partners and expected payment channels.
The level of detail should be proportionate to risk and applicable legal requirements.
Beneficial ownership and control
NPOs may not have conventional shareholders. Systems should represent trustees, directors, controllers, authorised persons and other relevant governance roles rather than forcing a commercial-company ownership model.
Sanctions ownership and control tests are a separate legal question and can differ by regime.
Data model
Important objects include donor or funding source where available, NPO, programme, local partner, payment, beneficiary category, controller, permission or licence, screening event, intelligence item, alert and case.
Role clarity matters.
Business analyst view
A BA should ensure customer models can distinguish non-profit legal forms and governance roles. Requirements should not assume that every customer has shareholders or a conventional beneficial-owner percentage.
The BA should also identify which controls are sanctions-driven, AML/CFT suspicion-driven or behavioural-monitoring driven, and which data can lawfully be shared across them.
Humanitarian exemptions and licensing
Systems may need to record standing exemptions, licences, other authorisations, scope, effective dates, expiry where relevant and conditions. A payment should not be released merely because a document exists; operations need to verify that any relied-upon authorisation actually covers the transaction. Equally, where the applicable law provides a standing exemption, the workflow should not falsely require a bespoke licence.
Escalation
Potential TF cases can be sensitive and time-critical. Escalation paths to the institution's designated AML/CFT reporting function, sanctions, legal and other appropriate specialists should be clear. Titles such as MLRO are jurisdiction- and institution-specific, so global system design should store decision roles rather than assume one universal job title.
Confidentiality
Suspicious reporting and law-enforcement information can be subject to strict confidentiality. Access controls and customer communication should reflect applicable legal requirements.
Investigation writing
A strong TF narrative explains the customer, funding source, transaction pattern, relationships, intelligence, destination, explanations and unresolved concerns. Avoid asserting terrorist intent unless evidence supports it.
Customer fairness
Overbroad controls can block humanitarian and charitable activity and can drive legitimate flows outside transparent financial channels. Risk management should protect the financial system without creating unjustified exclusion.
Common mistakes
Common mistakes include assuming TF funds must come from crime, treating all NPOs as high risk, relying only on high-value thresholds, conflating sanctions with suspicion and using conflict geography as proof.
Another mistake is forcing NPO governance into commercial ownership models or assuming that every humanitarian permission must take the form of an individual licence.
Learning checkpoint
A reader should be able to distinguish terrorist financing from money laundering, explain why lawful funds can create TF risk, describe proportionate NPO controls, understand targeted financial sanctions and humanitarian considerations, and design monitoring that combines network, purpose, behavioural and intelligence signals.
References and further reading
- FATF — The FATF Recommendations, current official Standards: https://www.fatf-gafi.org/en/publications/Fatfrecommendations/Fatf-recommendations.html
- FATF — Recommendation 6 humanitarian update, 23 June 2026: https://www.fatf-gafi.org/en/publications/Fatfrecommendations/update-recommendation-6-june-2026.html
- FATF — Non-profit organisations and Recommendation 8 resources: https://www.fatf-gafi.org/en/topics/non-profit-organisations.html
- FATF — Best Practices on Combating the Abuse of Non-Profit Organisations, 16 November 2023: https://www.fatf-gafi.org/en/publications/Fatfrecommendations/Bpp-combating-abuse-npo.html
- FATF — Comprehensive Update on Terrorist Financing Risks, 8 July 2025: https://www.fatf-gafi.org/en/publications/Methodsandtrends/comprehensive-update-terrorist-financing-risks-2025.html
- FATF — Detecting and Disrupting Terrorist Financing Activity through Social Media, Instant Messaging Applications and Streaming Platforms, 26 June 2026: https://www.fatf-gafi.org/en/publications/Methodsandtrends/detecting-and-disrupting-tf-through-smsps.html
- FATF — Crowdfunding for Terrorism Financing, 31 October 2023: https://www.fatf-gafi.org/en/publications/Methodsandtrends/crowdfunding-for-terrorism-financing.html
- FATF — Investigating Professional Money Laundering, Underground Banking, and the Use of Hawala and Other Similar Service Providers, 3 September 2026: https://www.fatf-gafi.org/en/publications/Methodsandtrends/pml-underground-banking-hawala-hossps.html
- United Nations Security Council — ISIL (Da'esh) and Al-Qaida sanctions regime: https://main.un.org/securitycouncil/en/sanctions/1267
- United Nations Security Council — Resolution 2664 (2022): https://main.un.org/securitycouncil/en/content/sres2664-2022
Educational note: terrorist-financing offences, sanctions designations, humanitarian exemptions, NPO regulation and reporting obligations vary by jurisdiction. Apply current local law and authoritative guidance.
Deep dive: building a defensible terrorist-financing control model
Terrorist-financing controls need to combine legal prohibitions, customer understanding, behavioural monitoring, intelligence and proportionate risk management. A single sanctions list, a transaction-value threshold or a country-risk score cannot provide a complete answer. The bank needs to understand which question each control is designed to answer.
Threat, vulnerability and consequence
A useful TF risk model distinguishes the external threat from the institution's vulnerability. Threat can include designated organisations, facilitators, recruitment networks, fundraising campaigns or regional conflict. Vulnerability depends on the bank's products, customers, channels, geographies, data and control environment.
This distinction helps prevent the assumption that every customer exposed to a higher-risk environment is itself suspicious.
Generation and collection of funds
Funds can originate from lawful salary, business revenue, donations and community fundraising or from fraud, extortion and other crime. The bank should therefore record source where relevant without assuming that a legitimate source resolves TF risk.
Movement
Value can move through retail transfers, remitters, cash, cards, prepaid products, virtual assets, trade and informal channels. Different channels provide different visibility and speed.
Storage
Funds may remain in ordinary accounts or wallets for extended periods. TF monitoring should therefore consider relationships and purpose as well as rapid movement.
Use
Financial institutions rarely observe the ultimate physical use of funds directly. Investigators should state what they can infer from payment and intelligence data without claiming knowledge they do not possess.
Recommendation 6 and targeted financial sanctions
Targeted financial sanctions related to terrorism can create legal obligations to freeze assets or prevent transactions. These obligations arise from applicable domestic implementation and relevant international measures.
Banks should maintain a clear legal-regime map showing which entities, branches, currencies, persons and transactions create jurisdictional nexus.
Designation data governance
List updates can be time critical. Controls should document source, update time, validation, loading, testing and rescreening where required. A delayed list feed can create a legal-control gap.
Ownership and control
A designated individual may own or control an entity that is not itself named. Applicable ownership/control rules differ by sanctions regime. Systems should support legal interpretation rather than hard-code one global percentage assumption.
Recommendation 8 and NPO risk
FATF's approach to NPOs emphasises focused, proportionate and risk-based measures. The relevant risk does not apply equally to the entire non-profit sector.
Banks should identify which features of the organisation, programme, geography, funding or delivery model create vulnerability and which governance measures mitigate it.
NPO population segmentation
A local sports charity, global humanitarian organisation, religious institution, advocacy organisation and development NGO can have very different operating models. Segmentation should reflect activity rather than treat legal form as a complete risk indicator.
Mission and programme understanding
Due diligence should understand the organisation's purpose, major programmes, funding model, locations and how funds reach intended activities. The bank does not need to validate every beneficiary to understand the overall model.
Governance
Relevant governance can include trustees, directors, senior officers, authorised signatories, programme managers and financial-control responsibilities. Traditional shareholder fields may be meaningless for many NPOs.
Funding sources
Institutional grants, public donations, subscriptions, religious giving and corporate sponsorship can all be legitimate. Monitoring should compare actual funding with the organisation's expected model.
Local implementing partners
International NPOs may deliver programmes through local organisations. Banks should understand how the customer selects and oversees partners where risk warrants it while recognising that the bank may not directly know every downstream party.
Beneficiary populations
A beneficiary population can be broad or sensitive. The bank should avoid collecting personal beneficiary data that is unnecessary for its control purpose, particularly in humanitarian settings.
Humanitarian exemptions
Applicable legal frameworks can include humanitarian exemptions, exceptions, general licences or specific authorisations. These are not generic waivers. Operations should confirm that the relevant provision covers the parties, activity, geography and conditions of the transaction.
Licence data model
Where a bank relies on a licence or authorisation, useful fields include issuing authority, legal basis, scope, permitted parties, transaction type, value or programme conditions, effective date, expiry and supporting evidence.
Conflict-affected regions
Conflict can increase TF, sanctions and operational risk while also increasing legitimate humanitarian need. Country risk should therefore trigger informed controls rather than automatic exclusion.
Correspondent and remittance dependencies
NPOs operating in difficult regions may rely on correspondent banks or remitters. The bank should understand the route and intermediaries where relevant, but should avoid assuming that the use of a remitter indicates concealment.
Cash in humanitarian operations
Cash can be necessary where infrastructure is weak. Controls can examine governance around cash disbursement, authorisation, local partners and reconciliation without assuming all cash distribution is suspicious.
Digital wallets and mobile money
Aid programmes may use mobile money or wallets. These can improve traceability and inclusion but may introduce new providers, agent networks and identity limitations.
Crowdfunding risk model
Crowdfunding can involve many small donors, platforms and beneficiaries. A bank may see the platform settlement rather than each donor. Controls should be designed around actual visibility.
Social-media intelligence
Fundraising narratives and public posts can inform investigation, but identity, authenticity and source reliability should be assessed. A social-media allegation is not proof of terrorism.
Small-value pattern analysis
TF-related funding can use small values, but small transactions are extremely common. Monitoring should combine value with network, destination, purpose, customer profile and intelligence.
Network analysis
Graph methods can connect customers, beneficiaries, devices, organisations and counterparties. High connectivity does not imply wrongdoing. A remitter, charity or popular merchant can be legitimately central.
Relationship confidence and role must be visible to investigators.
Intelligence provenance
Information can come from public sources, internal cases, FIUs, law enforcement, sanctions authorities or trusted partnerships. Systems should record provenance, confidentiality and permitted use.
Adverse information
News alleging extremist association can materially affect risk, but analysts should assess source credibility, identity match, date and whether allegations were substantiated.
Scenario: legitimate humanitarian programme
An established charity receives institutional grants and transfers project funds to vetted local partners in a conflict region. Governance and programme reporting are strong. The geography increases inherent risk, but evidence supports a controlled operating model.
The bank should not confuse inherent risk with suspicion.
Scenario: opaque fundraising network
Several personal accounts collect small donations using similar online appeals and send funds to the same foreign intermediaries. Controllers cannot explain the organisational structure or ultimate purpose.
The bank should investigate network relationships, funding flows and available intelligence before determining whether suspicion exists.
Scenario: listed controller
A charitable entity itself is not named on a list, but a person who may exercise control is designated under an applicable regime. Sanctions specialists should assess ownership/control and any relevant legal consequences. The AML/CFT case can use the same ownership evidence while maintaining a separate suspicion decision.
Scenario: false positive designation
A customer shares a common name with a designated individual but date of birth, nationality and other identifiers clearly differ. Screening should resolve the false positive rather than treat the customer as high TF risk indefinitely.
Scenario: humanitarian licence
A payment to a restricted geography is potentially permitted under a humanitarian authorisation. Operations should verify that the authorisation applies, capture its evidence and route exceptions to the correct legal or sanctions decision maker.
Transaction-monitoring hypotheses
Monitoring can target unexplained fundraising, rapid dispersal, repeated transfers to concerning networks, unexpected cash activity, new high-risk counterparties and material deviation from an NPO's stated programme.
Scenarios should not use religious, ethnic or nationality characteristics as proxies for TF risk.
Screening versus monitoring
Screening asks whether a person, entity or other relevant data matches a designation or watchlist. Monitoring asks whether behaviour or relationships create concern. Both can contribute to a case, but their logic and legal outcomes differ.
Suspicious reporting
A decision to submit a SAR/STR or equivalent report depends on applicable law and the institution's suspicion threshold. It should not be automated solely because a sanctions alert or country-risk score exists.
Tipping off
Customer communication must respect local confidentiality and tipping-off rules. Front-line employees should have clear scripts and escalation paths.
Law-enforcement requests
A lawful request can change the bank's understanding of a customer or network. The bank should preserve the request, response, scope and confidentiality and avoid exposing protected information in ordinary customer notes.
Case management
TF cases can involve customer, organisation, programme, local partner, payment, designation, licence, intelligence item and related account. Case platforms should support these objects and role-based access.
Customer restrictions
Potential responses can include enhanced monitoring, payment review, product restriction, relationship review, legal freeze or exit depending on the facts and legal framework. The terms should not be used interchangeably.
Financial inclusion
Overbroad de-risking can exclude legitimate charities and communities from formal finance, potentially reducing transparency. Controls should seek proportionate risk management where legally and operationally feasible.
Data minimisation
TF risk management should not become a justification for collecting unlimited sensitive information. Data should be relevant to a defined control purpose and handled according to privacy law and policy.
Model governance
If analytical models score organisations or networks, governance should cover data quality, bias, feature rationale, validation and explainability. A model score should not become an allegation of terrorist association.
BA object model
Represent NPO legal entity, governing persons, programme, funding source, implementing partner, beneficiary-payment mechanism, transaction, designation, authorisation, intelligence item, alert and case separately.
BA acceptance criteria
Include name false positive, new local partner, expired humanitarian licence, missing programme code, underlying beneficiary data unavailable, list update during payment processing, conflict-region corridor change and law-enforcement information received after case closure.
Management information
Useful MI can include NPO population by risk, list-update timeliness, humanitarian-payment exceptions, aged TF alerts, false-positive rates, high-risk programme changes and control defects. It should not equate high case volumes with effective detection.
Quality assurance
QA should look for unsupported statements of terrorist intent, conflation of sanctions and suspicion, overreliance on geography, poor handling of humanitarian exemptions, and unnecessary collection of sensitive data.
Regulatory examination readiness
The bank should be able to explain its TF risk assessment, NPO segmentation, designation controls, monitoring hypotheses, escalation, reporting, humanitarian process, training and assurance.
Final deep-dive exercise
Build a case for an international charity operating through two local partners in a conflict region. One payment triggers a name-screening alert and another involves a new partner. Separate the sanctions question, NPO-risk question, behavioural-monitoring question and suspicious-reporting question. Then identify the evidence and decision owner for each. This exercise demonstrates why a mature TF programme needs several coordinated but distinct control paths.
Advanced practice: CFT investigations, humanitarian safeguards and NPO proportionality
Counter-terrorist-financing controls require unusually careful reasoning because lawful money and ordinary payment channels can still become relevant when credible information indicates a prohibited purpose or relationship. The practical objective for a bank is not to profile ordinary customers or charities. It is to combine reliable intelligence, customer context, payment behaviour, sanctions information and proportionate due diligence while protecting legitimate humanitarian and civil-society activity.
Lawful source of funds does not close the CFT question
A customer can receive normal salary or business income and still create a CFT concern if credible information changes the interpretation of later payments. This is fundamentally different from a conventional money-laundering analysis that often begins by asking whether funds are proceeds of crime.
The investigator should therefore separate two questions: where did the money come from, and why is the destination, relationship or purpose concerning? A case narrative is clearer when it states that the source appears legitimate but other evidence creates suspicion.
Designation and suspicion are separate legal concepts
A sanctions or targeted-financial-sanctions match can create immediate legal obligations depending on the applicable regime. A CFT suspicion can also exist where no party is designated. The same case can contain both, but the decisions should be recorded separately.
This distinction matters operationally. Screening teams resolve identity and legal restrictions. CFT investigators assess broader customer and network behaviour. Case tooling should allow the two teams to share facts without turning one decision into a substitute for the other.
Humanitarian activity after the June 2026 Recommendation 6 update
FATF updated Recommendation 6 in June 2026 to better support humanitarian assistance and align the standard with relevant UN humanitarian exemptions. For banks, the control lesson is practical: a transaction involving a difficult geography or sanctions environment is not automatically prohibited.
Specialists need to identify the applicable legal regime, relevant designation, exemption or licence, conditions, scope and validity. AML/CFT teams can still assess diversion or suspicious activity. Legal permission and financial-crime risk management can coexist.
A well-designed system should therefore provide a route for permitted humanitarian activity rather than forcing every payment into a binary high-risk-country decision.
NPOs should not be treated as inherently high risk
FATF's revised Recommendation 8 and 2023 best-practices work emphasise targeted, proportionate measures for the subset of NPOs that may be exposed to terrorist-financing abuse. Banks should understand the actual organisation rather than apply one sector-wide assumption.
Useful due-diligence areas include purpose, governance, controllers or trustees, funding, countries of operation, delivery partners, programme controls, payment channels, cash use and reconciliation. Strong governance and transparent delivery can reduce residual risk even where inherent geographic risk is elevated.
The aim is to identify specific vulnerabilities without suppressing legitimate charitable, humanitarian, educational or religious activity.
Worked comparison: same geography, different control quality
Organisation A and Organisation B both deliver aid in the same conflict-affected region. Organisation A has audited accounts, independent governance, documented programme budgets, vetted local partners, approval controls and reconciled field expenditure. Organisation B has unclear controllers, frequently changing partners, unexplained cash withdrawals and incomplete accounting.
A geography-only model treats both customers the same. A risk-based model recognises the material difference in governance and transparency.
This is an important design test for customer risk scoring: can positive control evidence reduce residual risk, or does the model only accumulate negative factors?
Digital fundraising requires context, not assumptions
FATF's June 2026 work on terrorist-financing risks associated with social media, instant messaging and streaming platforms highlights how online fundraising and monetisation features can be abused. Banks may see platform settlements, payment-processor credits, card payments or virtual-asset-related transfers rather than the public campaign itself.
An investigation should establish who controls the campaign, whether a legitimate organisation or purpose can be verified, who receives funds, how disbursement is governed and whether reliable external information changes the risk assessment.
The presence of crowdfunding, creator income or charitable language is not itself suspicious. These are mainstream activities. The value of the typology is to help investigators ask better questions when other evidence creates a reason for review.
Low-value activity and threshold limitations
CFT controls should not depend only on large values. At the same time, broad monitoring of ordinary low-value remittances can generate enormous false-positive volumes and unfairly affect customers.
A stronger model combines amount with relationship, frequency, customer profile, beneficiary pattern, network links, credible intelligence and geographic context. The goal is to identify meaningful patterns without treating normal family support or charitable giving as suspicious by default.
Remitters and informal value-transfer services
Remitters can be essential for migrant communities and humanitarian access. Banks serving them should understand licensing or registration where applicable, agent networks, corridors, settlement counterparties and customer controls.
Informal value-transfer systems can also have legitimate community roles. FATF's September 2026 work on underground banking and hawala-like service providers reinforces that such channels can be used legitimately while also being vulnerable to criminal misuse. A category label is therefore not a conclusion.
Banks should focus on undeclared intermediation, unexplained settlement, opaque counterparties, legal status and activity inconsistent with the customer's stated business.
Virtual-asset exposure
Virtual assets can be used for ordinary investment and payment activity and can also appear in financial-crime cases. A bank should avoid a blanket crypto risk conclusion.
Useful investigation factors can include the customer's stated purpose, provider status and jurisdiction, source of funds, rapid conversion patterns, links to reliable intelligence and the confidence of any blockchain-analytics attribution. Analytics should be documented as an evidence source rather than treated as an automatic legal finding.
Intelligence quality and provenance
CFT investigations can rely heavily on information from FIUs, law-enforcement authorities, regulators and other competent bodies. Access controls, provenance and confidentiality are therefore particularly important.
Case records should distinguish official intelligence from public information, customer statements and analyst inference. A weak public association should not be presented with the same confidence as verified government information.
Network analytics need confidence labels
A shared beneficiary, phone number, service provider or address can help identify relationships, but common service providers can connect many legitimate NPOs or remittance customers.
Graph edges should therefore store type and confidence. Verified control, direct transaction, shared contact information, common regulated intermediary and public-information association should not be visualised as if they were equivalent.
Customer contact and local legal rules
Customer outreach can help clarify programme purpose, funding relationships or unusual payments, but institutions must respect local confidentiality and tipping-off requirements. These rules differ by jurisdiction.
Global educational content should therefore state the principle—coordinate outreach with applicable legal and internal requirements—without pretending one universal script or prohibition applies everywhere.
BA design: programme and permission data
Traditional corporate KYB models are often a poor fit for NPOs. The data model should support organisation, trustee or controller, programme, donor or funding source where relevant, delivery partner, payment channel, licence or exemption, sanctions decision, alert and external report as separate objects.
For humanitarian permissions, store legal regime, authority, permission type, scope, effective date, expiry and conditions. A document should not suppress screening merely because it exists; the transaction must fall within the permission's scope.
Monitoring and investigation workflow
A disciplined workflow can be expressed as:
signal or intelligence → identify customer and relevant parties → resolve sanctions/designation issues separately → establish source of funds → reconstruct payments and relationships → understand NPO/remitter/programme context where relevant → assess reliable digital-platform or virtual-asset evidence → test legitimate explanations → confirm any humanitarian permissions → decide CFT reporting and customer-risk actions under applicable law.
This workflow keeps the focus on evidence while recognising lawful-source TF risk.
Decision-writing exercise
Compare these two conclusions:
"Customer sent small payments to a high-risk country; terrorist-financing concern."
versus:
"Customer's income is consistent with declared employment. Review was initiated after credible official information identified a beneficiary relationship of concern. The customer made recurring payments to that beneficiary and two related parties over six months. No designation match was confirmed, so the sanctions decision remained separate. The relationship and payment pattern were escalated for CFT assessment under local reporting rules."
The second conclusion is more precise because it identifies what is known, what triggered the concern and what legal question remains.
Final practitioner standard
A strong CFT programme is precise rather than indiscriminately restrictive. It recognises that lawful funds can create CFT risk, that designations and suspicion are different, that NPO controls must be targeted and proportionate, that humanitarian permissions need operational support, and that digital fundraising or virtual assets require contextual evidence. The objective is high-quality financial intelligence while preserving legitimate access to financial services.
Practitioner close: terrorist financing, NPOs and proportionate bank controls
Terrorist financing differs from many money-laundering cases because the original funds can be entirely lawful. Salary, business income, donations or family funds can be diverted to terrorist purposes. This means source-of-funds legitimacy does not answer the terrorist-financing question. Investigators need to understand purpose, recipient, network, behaviour and credible intelligence, while keeping sanctions and terrorist-financing conclusions legally separate.
Lawful source does not mean lawful purpose
A customer with ordinary salary income makes repeated low-value transfers to several individuals or organisations connected through credible official information to a terrorism-related network. The lawful salary explains where the funds originated, but not why they were sent.
The investigation should consider transaction pattern, relationship to recipients, payment descriptions, customer profile, geography, device or network links where lawfully available, and authoritative intelligence. Low value should not automatically reduce concern where the network or purpose is significant. Equally, a network association must be graded by source and confidence rather than presented as proof.
NPOs require targeted and proportionate controls
Non-profit organisations perform essential humanitarian, charitable and community work. FATF's revised Recommendation 8 emphasises focused, proportionate measures rather than treating the entire NPO sector as inherently high risk.
A bank should understand the organisation's purpose, operating locations, governance, funding model, beneficiary model and delivery channels according to risk. Activity in conflict-affected or sanctioned areas can require deeper review without justifying blanket de-risking.
Controls should distinguish genuine humanitarian delivery, fraud against a charity, misuse by insiders, sanctions exposure and deliberate diversion. These are different risks requiring different evidence and potentially different decision owners.
Case lab: humanitarian payment into a sanctions-sensitive environment
An established humanitarian organisation sends funds to a local partner in a conflict zone. The geography creates elevated sanctions and terrorist-financing questions, but the payment may fall within a standing humanitarian exemption or another applicable authorisation depending on the legal regime.
The sanctions or legal team should determine the applicable legal basis and any conditions. The CFT investigation should separately consider partner due diligence, purpose, delivery mechanism and diversion indicators. One control should not replace the other.
A legally permitted humanitarian payment can still require AML/CFT risk management, while a legitimate humanitarian purpose does not override a prohibition unless the applicable legal framework permits the activity. A standing exemption should not be described as though a bespoke licence is always required.
Digital fundraising and platform risk
Terrorist actors and supporters can exploit social media, instant messaging, streaming platforms and crowdfunding to solicit or direct funds. Banks may see card payments, transfers, e-money, platform settlements or virtual-asset purchases associated with fundraising campaigns.
A payment to a crowdfunding or social platform is not suspicious by itself. The bank needs campaign context, recipient information where available, credible intelligence and behavioural patterns. Fraudulent charitable fundraising, scam activity, extremist content and terrorist financing can overlap in an investigation, but one should not be used as a synonym for another.
Informal transfer and remittance channels
Remittance and informal value-transfer systems can provide essential legitimate services. Their use does not establish terrorist financing. Risk analysis should focus on customer and agent behaviour, corridor, counterparties, settlement mechanism, legal status where relevant and links to reliable intelligence.
Correspondent banks may have only partial visibility of end users. Their controls should be designed around actual data and respondent-bank due diligence rather than an impossible assumption of full end-customer knowledge.
Virtual assets
Virtual assets can support legitimate transfers and fundraising as well as illicit activity. Blockchain analysis can provide wallet attribution and transaction paths, but attribution confidence and customer control matter. Indirect exposure several hops away is not equivalent to a direct transfer to a reliably attributed address.
The investigator should combine blockchain evidence with customer identity, fiat on/off-ramp, timing, account behaviour and any relevant intelligence rather than treating an analytics label as a legal conclusion.
Intelligence provenance and customer-contact risk
Terrorist-financing cases can involve sensitive information. Case systems should record source, confidence and handling restrictions, and investigators should follow local rules on customer contact, information sharing, confidentiality and tipping off.
A routine request for information may be inappropriate where applicable law, an intelligence-handling restriction or an active investigation requires a different approach. Escalation to specialist CFT, sanctions or legal teams should therefore be built into the workflow, but the exact customer-contact decision remains jurisdiction- and case-specific.
Final practitioner checkpoint
A strong learner should be able to explain why lawful funds can finance terrorism, apply proportionate risk-based controls to NPOs, keep humanitarian permissions and CFT analysis distinct, interpret low-value and digital fundraising patterns in context, use virtual-asset intelligence carefully and preserve sensitive evidence without turning geography, charity status, platform use or remittance activity into automatic suspicion.
Practitioner masterclass: analysing terrorist-financing risk without overclaiming
Terrorist-financing analysis is difficult because lawful money can be used for a prohibited purpose and because ordinary-looking customers can have links that matter more than transaction size. The investigator therefore needs a disciplined approach that combines customer purpose, relationships, geography, sanctions, intelligence and behavioural evidence.
Start with the distinction from money laundering
Do not begin by looking for criminal proceeds. Ask first whether the concern is about the origin of funds, the intended use of funds, a prohibited person or network, or a combination of these.
A salary payment can be lawful in origin and still be relevant to TF if it is intentionally directed to a prohibited purpose.
NPO proportionality exercise
Consider two charities operating in the same higher-risk region. Charity A has audited accounts, clear governance, vetted local partners, donor restrictions and transparent project reporting. Charity B has weak governance, unexplained cash withdrawals and unclear downstream recipients.
Geography is the same. Control quality and transparency are different. A risk-based approach should recognise that difference.
Funding-chain exercise
Map donor, NPO, programme, local partner, beneficiary-payment mechanism and bank account. Mark which relationships are direct, which are downstream and which are unknown to the bank.
This prevents the institution from claiming knowledge it does not have.
Lawful funds, prohibited purpose case
A customer receives ordinary salary and makes small recurring transfers to a network later identified by competent authorities as linked to terrorism. The source is not suspicious. The destination and intelligence are the important factors.
This is why low-value thresholds alone are insufficient.
Designation versus suspicion
A sanctions designation can create a legal freeze or prohibition depending on the applicable regime. Suspicion is a separate AML/CFT judgement. A bank should not use the words interchangeably.
Systems should preserve separate decision types even when the same case supplies evidence to both.
Humanitarian-payment exercise
An aid organisation sends funds to a conflict-affected area where sanctioned actors are present. The bank should identify whether applicable humanitarian exemptions, licences or authorisations apply and whether the transaction fits them.
A high-risk geography does not automatically mean the payment must be rejected.
Crowdfunding exercise
A personal account receives hundreds of small payments with a charitable narrative and then sends money to several individuals abroad. The pattern warrants understanding. Investigators should establish who controls the campaign, whether there is a legitimate organisation, what beneficiaries are intended and whether credible intelligence changes the risk.
Fundraising language alone does not establish TF.
NPO governance exercise
Review governing body, decision rights, financial controls, audit, partner due diligence, programme oversight and sanctions/AML procedures. The objective is to understand whether the organisation can account for how money is used.
Cash and field operations
Humanitarian organisations can need cash where banking infrastructure is limited. Cash use therefore requires context. Controls should understand why cash is needed, how it is authorised, who distributes it and what monitoring is possible.
Informal-transfer interaction
Aid and family support may use remitters or informal systems where formal banking access is weak. Banks should assess legal status, transparency and counterparties rather than assume the mechanism is illicit.
Network-analysis caution
A common beneficiary, phone number or address can create a link, but connection strength matters. A widely used charity, remitter or service provider can be highly connected for legitimate reasons.
Network tools produce hypotheses, not conclusions.
Intelligence handling
Government requests, FIU feedback and law-enforcement information can materially alter risk. Access should be restricted and provenance preserved. The investigator should distinguish public information from protected intelligence.
BA design exercise
Model customer, NPO, controller, programme, local partner, donor, beneficiary, payment, licence/exemption, sanctions event, alert and investigation. Do not force NPOs into a shareholder-centric corporate schema.
Quality assurance test
Review a sample of NPO or TF cases. Check whether geography was used as proof, whether sanctions outcomes were confused with suspicion, whether investigators described evidence rather than ideology, and whether humanitarian exceptions were properly escalated.
Final practitioner test
A strong learner should be able to explain why lawful funds can create TF risk, apply proportionate NPO controls, separate sanctions designation from suspicion, understand humanitarian-payment complexity and write conclusions that are factual rather than accusatory.
60-minute mastery extension: terrorist financing, NPOs and funding channels
This extension deepens the chapter into a full practitioner learning session. The emphasis is not on memorising red flags. It is on learning how to reason when lawful money, humanitarian activity, sensitive intelligence, sanctions law and ordinary customer behaviour can all appear in the same case.
Terrorist financing is not simply money laundering with smaller amounts
Money laundering usually begins with criminal proceeds. Terrorist financing can involve funds from lawful or unlawful sources. The key risk can therefore sit in intended use, destination, controlling party, network or prohibited purpose rather than in the origin of the funds. A small recurring payment can matter when credible information changes its meaning even though the customer's salary or business income is legitimate.
Controls should not rely on value thresholds alone. Customer relationships, counterparties, product and channel, geographic context, designations, network information, behavioural change and reliable intelligence can all matter. Equally, none of those factors should be turned into a shortcut for suspicion. The objective is a specific, evidence-led explanation of why the activity is or is not concerning.
Worked case: lawful source, concerning relationship
A retail customer receives ordinary salary and has a stable account history. Over several months, the customer sends modest recurring transfers to individuals that later become connected through credible official information to a terrorist-support network. There is no concern about the source of the salary. The question is whether the beneficiary relationships, payment pattern and reliable intelligence create a reporting or sanctions issue under the law applicable to the bank.
The bank should distinguish terrorism-related targeted-financial-sanctions obligations from CFT suspicion. A confirmed designated-party or legally covered connection can produce a sanctions outcome where the applicable regime requires it. A separate suspicious-reporting decision can also arise under the jurisdiction's AML/CFT framework. The two decisions may use some of the same evidence but are not interchangeable.
NPOs and proportionality
Non-profit organisations perform legitimate humanitarian, charitable, religious, educational and social work. FATF's 2023 revision of Recommendation 8 was expressly designed to correct over-application and clarify a focused, proportionate approach. The FATF standard does not treat an entire domestic non-profit sector as inherently high risk. Countries are expected to understand which NPOs fall within FATF's functional definition, identify the subset exposed to terrorist-financing abuse, and apply measures proportionate to the risk.
For a bank, this means understanding the actual organisation: purpose, governance, funding, partners, countries of operation, financial controls, programme delivery, payment channels and transparency. Compare two organisations working in the same conflict-affected region. One has independent governance, documented budgets, vetted local partners and reconciled expenditure. The other has unclear controllers, unexplained cash withdrawals and repeatedly changing downstream partners. Geography is the same; governance and evidential quality are not.
Risk scoring should therefore allow credible mitigating evidence to affect residual risk. A model that only accumulates negative factors will tend to turn high inherent geographic risk into automatic high residual risk even when governance and delivery controls are strong.
Humanitarian activity and sanctions after the June 2026 update
Humanitarian organisations can operate where designated actors or sanctioned authorities are present. Applicable regimes may contain standing humanitarian exemptions, other exceptions, general licences or specific authorisations. A high-risk geography does not automatically mean every payment should be rejected.
On 23 June 2026 FATF updated Recommendation 6 so that countries are expected to give effect to relevant UN humanitarian exemptions, including those reflected in UN Security Council resolutions 2664 and 2761 as well as 2615. For the UN ISIL (Da'esh) and Al-Qaida regime, resolution 2761 continued the humanitarian exemption introduced by resolution 2664. A global bank still needs to determine how the relevant UN measure has been implemented in the law applicable to the transaction and legal entity.
The operational distinction matters. A standing exemption may permit qualifying activity without a bespoke licence. Other activity may require a general or specific authorisation depending on the legal regime. A bank's workflow should therefore store the legal basis, covered provider or activity, dates and conditions rather than treating every humanitarian case as a request for a licence.
Funding-chain exercise
Map donor or funding source, NPO, programme, local implementing partner, payment channel and programme-delivery mechanism. Mark which relationships the bank knows directly, which are known through customer evidence and which are genuinely outside the bank's visibility. Then identify where cash, remitters, mobile money or other mechanisms are used and why.
The purpose is to avoid claiming visibility the bank does not have. A bank can understand its direct customer and payment while still having limited knowledge of final programme beneficiaries. That limitation can influence the level of due diligence and evidence needed, but it should not result in impossible documentation demands merely to create the appearance of control.
Crowdfunding and online fundraising
A personal account receiving many small payments with a charitable narrative may be legitimate community fundraising, fraud, sanctions evasion or a CFT concern depending on context. Investigators should establish who controls the campaign, whether a legitimate organisation or purpose can be verified, how funds are disbursed, who receives them and whether reliable intelligence changes the picture.
FATF's 2023 report on crowdfunding for terrorist financing emphasises that the vast majority of crowdfunding is legitimate while identifying ways donations-based campaigns and social-media promotion can be abused. FATF's 26 June 2026 report on social media, instant messaging applications and streaming platforms adds current typologies involving creator monetisation, livestreaming, virtual assets, rotating wallets, fraudulent humanitarian appeals and coded or ephemeral content.
The practical lesson is not to flag platform use itself. The financial institution may see a payment processor or aggregated settlement while the campaign identity and narrative sit with the platform. Effective investigation may therefore require lawful cooperation, reliable external information and careful reconciliation of stated purpose against payout behaviour.
Cash and field operations
Humanitarian organisations can need cash where banking infrastructure is weak. Cash use therefore needs context. The bank can understand why cash is required, who approves it, how local partners are selected, how disbursements are reconciled and what evidence is realistically available. Requiring banking documentation that cannot exist in the operating environment may create exclusion without improving assurance.
The control question is whether the organisation has a credible method for governing and reconciling the cash it must use, not whether cash is present at all.
Network-analysis caution
Common beneficiaries, phone numbers, addresses, devices or intermediaries can be useful links, but large charities, remitters, hospitals and service providers can naturally be highly connected. Graph centrality is not suspicion. Relationship source, role, effective date and confidence should be visible to investigators.
A mature graph model distinguishes a direct transaction from shared contact information, a common service provider, a verified control relationship and an unconfirmed public association. Rendering every edge identically invites overstatement.
Information handling
FIU feedback, law-enforcement information and government intelligence can materially affect risk. Access should be restricted, provenance preserved and downstream use controlled according to the legal or contractual conditions attached to the information. Analysts should distinguish official intelligence from public reporting, customer statements and their own inference.
The system should record enough metadata to answer: who supplied the information, when, under what authority or gateway, how reliable it is considered, who may view it, whether it may be used for customer action, and whether it may be disclosed outside the investigation team.
BA data model
Model NPO, controller or trustee where relevant, programme, local partner, donor or funding source where available, beneficiary category, payment, exemption or licence, sanctions event, intelligence item, alert, investigation and external report as separate objects. Avoid forcing charities into a shareholder-centric corporate model where that is not legally or operationally appropriate.
For permissions, store legal regime, authority, permission type, covered provider or activity, scope, effective date, expiry where relevant and conditions. The object model should support both a standing exemption and a transaction-specific authorisation.
Worked case: travel and transaction context
Consider a retail account that shows a change from its historic pattern: new payments to unfamiliar counterparties, travel-related expenditure in a corridor that becomes relevant because of credible external information, and new incoming transfers from previously unseen parties. None of those facts is a universal terrorist-financing indicator and each may have an innocent explanation.
The investigation should begin with customer and transaction facts, not stereotypes. The analyst reconstructs the timeline, identifies who the counterparties are, checks whether reliable intelligence or a designation is genuinely relevant, tests lawful explanations and considers whether the pattern meets the institution's local reporting threshold. Religion, ethnicity, nationality, age, political opinion or diaspora status must not be used as substitutes for evidence.
A control design that relies only on a 'high-risk travel corridor' can generate large numbers of low-quality cases and discriminatory customer impact. Better scenarios require combinations of evidence that can be tested and calibrated, with QA specifically looking for cases where geography has silently become proof.
Stored value, prepaid products and the low-value problem
Stored-value products, prepaid cards and mobile-money wallets can move value in small increments and across different channels. The CFT challenge is therefore product capability and behavioural pattern, not a claim that these products are inherently suspect.
A product-risk assessment should understand loading limits, aggregation, person-to-person functionality, cross-border use, redemption channels, agent networks and the customer-identification model. Monitoring can then test for behaviour inconsistent with the customer's profile, rapid or circular load-and-redemption patterns, common devices or funding sources across apparently unrelated accounts, and unexplained geographic changes.
Agent oversight is also relevant where distribution is delegated. The bank or programme manager should understand what responsibility it actually retains under applicable law and contract, how agent controls are tested, and how exceptions are escalated. Avoid language that assumes every bank has the same statutory responsibility for every distributor model.
Operationalising terrorism-related designation data
Targeted financial sanctions create obligations distinct from suspicion-based reporting. The required action depends on the regime and the law that applies to the bank. Where applicable law requires freezing without delay, preventing funds or economic resources from being made available, or making regulatory reports, the institution's control must execute those obligations accurately and within the required timeframe.
Operationalising this means controlling the list-data lifecycle: authoritative source, timestamp, validation, load, aliases and identifiers supplied by the authority, matching logic, rescreening rules, case disposition and evidence. Screening should account for relevant spelling variants, aliases and transliteration where supported by the source and risk model, but no single global matching method or threshold should be presented as legally universal.
Ownership and control analysis can be critical where a named person is connected to an unlisted entity. Those tests differ across sanctions regimes. A generic beneficial-owner threshold should not be hard-coded as a universal terrorism-sanctions rule.
Association data can support investigation without becoming guilt by association. Shared addresses, family relationships, common financial infrastructure or references in designation narratives can justify questions; they do not automatically establish that an associated person is legally designated or knowingly financing terrorism.
Humanitarian exemptions are a control path, not a bypass
Humanitarian exemptions and authorisations do not mean 'switch screening off'. The bank still needs to resolve the relevant parties, determine the applicable regime, confirm that the activity falls within the permission and preserve evidence supporting the decision. Equally, a compliant control should not impose a bespoke-licence requirement where a standing exemption already covers the activity.
The operational model therefore routes a potential terrorism-sanctions issue to specialist legal or sanctions analysis, identifies whether a permission applies, records the rationale and returns the payment decision to operations. AML/CFT investigators may still examine diversion or suspicious behaviour separately. Legal permission and risk assessment can coexist.
Intelligence handling: provenance, protection and action
CFT work can consume sensitive inputs such as law-enforcement disclosures, FIU guidance, government briefings, internal case intelligence and open-source extremism research. Each source may have different handling constraints. A practical protocol classifies information by provenance, confidence, permitted use and access rather than placing every signal in the same unrestricted case field.
Information received for intelligence purposes may not, depending on the gateway and jurisdiction, be usable as the sole basis for a customer action. Open-source material may require corroboration. A formal legal order may require a specific response. These differences should be visible in the case model and operating procedure.
Customer contact also needs care. Tipping-off, confidentiality and law-enforcement-coordination rules vary by jurisdiction. The safe global principle is that outreach should follow applicable law and internal escalation requirements; there is no universal rule that every CFT case requires senior approval or law-enforcement involvement before customer contact.
Worked case: crowdfunding with a hidden diversion risk
A payments team observes a personal account receiving hundreds of small transfers over several weeks with narrative references to a medical appeal shared widely on social media. The account holder then transfers most of the funds to a person described as a local coordinator in a conflict-adjacent jurisdiction. The amount in this fictional example is illustrative and is not a detection threshold.
The investigation tests the campaign rather than assuming either innocence or terrorist financing. It compares the stated fundraising purpose with the account's receipts and payouts, verifies the organiser and coordinator as far as lawful data allows, checks whether medical providers or humanitarian partners can be corroborated, and reviews whether credible official or reliable external information changes the risk.
Suppose the medical need is genuine but some payouts go to unrelated parties and the coordinator's role cannot be reconciled with the stated purpose. That finding supports deeper investigation. It does not by itself prove terrorist financing. The case becomes a CFT matter only if the evidence supports a terrorism-related purpose or network, or if an applicable designation or other legal restriction is identified.
This distinction is important because fraud, theft from charitable collections, sanctions evasion and terrorist financing can produce overlapping payment patterns. Correct classification affects reporting, confidentiality, operational action and which specialists own the decision.
Assessing NPO governance without stereotyping
Non-profit organisations range from local volunteer associations to global humanitarian agencies. A proportionate governance assessment should be calibrated to the specific organisation, legal framework and risk. Relevant areas can include registration or supervision status where applicable, governing-body structure, financial transparency, programme documentation, delivery-partner controls and the organisation's own sanctions or diversion-risk processes where material.
Each area should be assessed on evidence rather than formal appearance alone. An organisational chart does not prove independent governance; an audit report does not explain every programme risk; a local partner's registration does not prove how funds are used. Conversely, the absence of sophisticated corporate-style controls at a small NPO should not automatically be treated as misconduct if its scale and risk do not justify them.
The outcome should be a proportionate control plan rather than a binary accept-or-exit logic. Strong evidence may support standard monitoring. Identified gaps may justify enhanced review, remediation conditions or closer transaction oversight. Material unresolved risk may trigger product restriction or relationship review under applicable law, contract, policy and risk appetite. Those outcomes are institution- and jurisdiction-specific, not universal FATF commands.
Field operations require particular care. Cash may be unavoidable, documentation may be delayed, and local partners may be necessary. The bank should distinguish unavoidable operating friction from unexplained control failure and should understand the humanitarian context sufficiently to avoid impossible requirements.
Fundraising intermediaries and sponsored projects
Between donors and end causes may sit crowdfunding platforms, fiscal sponsors, umbrella charities, professional fundraisers, payment processors and other intermediaries. Each can add legitimate efficiency while reducing the bank's direct visibility.
The practical questions are: who verifies the fundraiser, who controls the account, who owns payout data, what purpose is represented to donors, who selects recipients, and what evidence exists that distributions match the stated programme. Where the bank cannot see underlying contributors because it receives aggregated settlement, it should not pretend otherwise; it can identify what additional platform or customer evidence is justified by risk.
Long intermediary chains are not automatically suspicious. They become relevant when roles are unclear, controls are weak, fees or transfers cannot be explained, or credible information indicates diversion. Due diligence should follow material risk and actual visibility rather than demand that every downstream organisation 'prove itself' directly to a bank with which it has no relationship.
Community impact and discrimination risk
CFT controls can disproportionately affect communities with legitimate ties to conflict-affected regions. A strong programme therefore measures false positives, customer friction and case outcomes across relevant segments while respecting data-protection and anti-discrimination law.
The purpose is not to lower the standard for genuine risk. It is to detect when a proxy such as geography, language, remittance corridor or customer type is doing more decision work than the actual evidence. Controls that create widespread unjustified friction can push legitimate activity into less transparent channels and can weaken trust in the formal financial system.
Training should focus staff on behaviour, relationships, legal restrictions and reliable intelligence. Vague concerns about culture, religion, nationality or activism should never be converted into CFT conclusions.
Kidnap, extortion and terrorism-related payment requests
Kidnap or extortion cases can create severe operational and human consequences. Where a demand may involve a terrorist organisation or designated party, sanctions, criminal-law and terrorist-financing rules may be highly relevant and can differ sharply by jurisdiction. Banks should not improvise legal conclusions or treat victim safety as a reason to disable controls.
A mature institution has a pre-defined escalation route to legal, sanctions, AML/CFT and security specialists, with access to law enforcement where permitted and appropriate. The payment process should preserve evidence, protect confidentiality and follow applicable law. No universal statement such as 'ransom payments are permitted' or 'ransom payments must be blocked' is safe across jurisdictions and fact patterns.
Operational controls should remain active. What may change is the handling path: instead of routine front-line processing or automated disposition, the case moves to specialist review because the consequences and legal questions are exceptional. Customer and family safety should inform how communication is conducted, but the institution should never present control suspension as the solution.
Management information and quality assurance
Useful MI can include NPO population by risk tier, age of CFT alerts, list-update timeliness, false-positive rates, humanitarian-permission cases, unresolved partner changes, repeat case drivers and material control defects. High alert volumes do not demonstrate effective detection.
QA should test whether analysts distinguish lawful source from prohibited purpose, whether designations are separated from suspicion, whether network links are graded by confidence, whether NPOs are assessed proportionately, whether humanitarian permissions are handled correctly and whether customer-impact decisions have a documented legal or policy basis.
Testing should include false-positive names, standing humanitarian exemptions, expired specific licences, new local partners, aggregated crowdfunding settlements, low-value network patterns, law-enforcement information with restricted handling, and cases where a conflict-area payment is fully explained and should be cleared.
Final practitioner test
A strong learner should be able to explain why each of these statements is wrong: 'terrorist financing always uses criminal money'; 'small payments are low risk'; 'NPOs are high risk by definition'; 'a conflict-area payment must be rejected'; 'designation and suspicion are the same'; 'a network link proves support'; and 'humanitarian activity always needs a licence'.
The correct approach is to turn each statement into an evidence-led question: what is the source and purpose; who are the relevant parties; which relationships are verified; what legal regime applies; what does the bank actually see; what reliable intelligence exists; what permission applies; what remains unexplained; and who owns the final decision?
Authoritative anchors
FATF Recommendations: https://www.fatf-gafi.org/en/publications/Fatfrecommendations/Fatf-recommendations.html
FATF Recommendation 6 humanitarian update, 23 June 2026: https://www.fatf-gafi.org/en/publications/Fatfrecommendations/update-recommendation-6-june-2026.html
FATF Non-profit organisations and Recommendation 8 resources: https://www.fatf-gafi.org/en/topics/non-profit-organisations.html
FATF Best Practices on Combating the Abuse of Non-Profit Organisations, 16 November 2023: https://www.fatf-gafi.org/en/publications/Fatfrecommendations/Bpp-combating-abuse-npo.html
FATF Comprehensive Update on Terrorist Financing Risks, 8 July 2025: https://www.fatf-gafi.org/en/publications/Methodsandtrends/comprehensive-update-terrorist-financing-risks-2025.html
FATF Detecting and Disrupting Terrorist Financing Activity through Social Media, Instant Messaging Applications and Streaming Platforms, 26 June 2026: https://www.fatf-gafi.org/en/publications/Methodsandtrends/detecting-and-disrupting-tf-through-smsps.html
United Nations Security Council ISIL (Da'esh) and Al-Qaida sanctions regime: https://main.un.org/securitycouncil/en/sanctions/1267
United Nations Security Council Resolution 2664 (2022): https://main.un.org/securitycouncil/en/content/sres2664-2022
Boundary case: small value, significant network context
A low-value transfer should not automatically be dismissed as immaterial in a terrorist-financing investigation, but small value is not suspicious by itself either. Relevance can come from recipient relationships, repeated fundraising patterns, credible intelligence, geographic context or links among several customers. The analyst should explain why the network or purpose makes the activity significant instead of relying on amount alone. This protects both detection quality and legitimate low-value humanitarian, family and community payments from indiscriminate treatment.
2026 practitioner enhancement: terrorist financing, digital fundraising and proportionate NPO controls
Terrorist financing must remain analytically distinct from conventional money laundering. Funds used for terrorist purposes can come from crime, but they can also come from salary, business income, donations, crowdfunding or other lawful sources. FATF's 2025 comprehensive update describes a wide range of financing methods and emphasises that methods vary by context. For a bank, the strongest signal can therefore sit in destination, network, intended use or credible intelligence rather than in the origin of the money.
The June 2026 FATF Recommendation 6 update matters operationally
On 23 June 2026 FATF announced an update to Recommendation 6 on terrorism-related targeted financial sanctions. The revised Standard requires countries to give effect to relevant UN humanitarian exemptions, including those in UN Security Council resolutions 2664 and 2761 as well as 2615. The change is important for banks because a terrorism-related sanctions framework should not be implemented as an indiscriminate block on permitted humanitarian assistance or activities supporting basic human needs.
The legal analysis still depends on the regime that actually applies to the bank and transaction. Operations need to identify the relevant designation, ownership or control rule, jurisdictional nexus, standing exemption, licence or other authorisation, and any conditions attached to it. A conflict-affected geography is not the same thing as a prohibited transaction.
For the UN ISIL (Da'esh) and Al-Qaida regime, the Security Council's current 1267/1989/2253 Committee material states that designated persons and entities are subject to an asset freeze, travel ban and arms embargo under resolution 2734 (2024). Resolution 2761 (2024) continued the humanitarian exemption introduced by resolution 2664 (2022) for that regime. Those UN measures are implemented through national and regional legal frameworks, so a bank must use the law applicable to the relevant entity rather than treating the UN webpage as a complete operating rulebook.
AML/CFT suspicion and targeted financial sanctions are separate decisions
A designated person or entity can trigger immediate legal restrictions under applicable sanctions law even when there is no wider behavioural suspicion. Conversely, a bank can have credible terrorist-financing suspicion where none of the parties is designated.
Case management should therefore preserve separate decision tracks: the sanctions or legal outcome and the AML/CFT suspicious-reporting outcome. The same evidence can support both, but one is not a substitute for the other. The reporting threshold, timing, confidentiality rules and required operational action depend on applicable law.
NPO risk must be targeted and proportionate
FATF revised Recommendation 8 and its Interpretive Note in November 2023 to address misapplication that had produced disproportionate measures against non-profit organisations. FATF's current NPO material is explicit that Recommendation 8 is not a direction to treat an entire domestic non-profit sector as inherently high risk. The focus is the subset of organisations falling within FATF's functional NPO definition and the risks of terrorist-financing abuse that a country has identified.
Banks should understand the organisation's mission, governance, controllers or trustees, funding, countries of operation, programmes, delivery partners, financial controls and payment channels. A well-governed humanitarian organisation operating in a difficult geography can present a very different residual-risk profile from an organisation with unclear controllers, unexplained cash, opaque partners and inconsistent funding.
FATF's 2023 Best Practices on Combating the Abuse of Non-Profit Organisations stresses targeted, proportionate implementation that protects legitimate NPO activity. FATF also introduced a procedure in 2025 to identify and address unintended consequences when misapplication of its Standards disrupts legitimate NPO activity. These developments make blanket de-risking particularly difficult to justify as a faithful application of the FATF risk-based approach.
Digital fundraising, social media and streaming platforms
FATF published Detecting and Disrupting Terrorist Financing Activity through Social Media, Instant Messaging Applications and Streaming Platforms on 26 June 2026. It describes how integrated payment features, virtual assets, creator monetisation, crowdfunding, coded language and ephemeral content can be abused, while also stressing structured public-private cooperation, better risk understanding and targeted indicators. FATF also notes that social-media, instant-messaging and streaming platforms are not automatically a FATF-regulated sector simply because they host content; particular financial activities may fall within already regulated sectors depending on what is being provided.
Banks may see only the payment processor, merchant descriptor, wallet provider or aggregated settlement rather than the public campaign itself. An investigator should combine the financial pattern with reliable external or official information and should not treat fundraising language, livestreaming, tipping or platform use as proof of terrorist financing.
Useful questions include who controls the campaign, whether a legitimate organisation or purpose can be verified, who receives the money, how quickly and to whom it is dispersed, whether the distribution matches the stated purpose, and what confidence can be placed on any external association.
FATF's 2023 report on crowdfunding for terrorist financing is also useful because it distinguishes mainstream legitimate crowdfunding from abuse and describes indicators as reasons for further examination rather than automatic conclusions.
Low value does not mean low risk
Terrorist-financing activity can involve modest values, and FATF's terrorist-financing risk-assessment guidance specifically recognises that low-value activity can make the risk difficult to identify. Large-value thresholds are therefore weak as a primary CFT control.
At the same time, low-value remittances and donations are extremely common. Controls need network, customer, purpose and intelligence context so that ordinary family support, charitable giving or community fundraising is not converted into suspicion by amount or geography alone.
Remitters, hawala and other value-transfer services
Remitters and informal or community-based value-transfer systems can be important for families, trade and humanitarian access, particularly where formal banking infrastructure is limited. They can also be exploited for illicit finance. The bank should understand the customer's legal status where relevant, corridors, agents, settlement model, counterparties and actual activity rather than infer criminality from a category label.
On 3 September 2026 FATF published Investigating Professional Money Laundering, Underground Banking, and the Use of Hawala and Other Similar Service Providers. The report explains that these systems vary significantly, may serve legitimate remittance and value-transfer needs, and may also be exploited by criminal actors. It is primarily an illicit-finance and professional-money-laundering study, so it should be used here as current context on value-transfer architecture and opacity, not as proof that a hawala or similar provider is connected to terrorist financing.
Virtual assets
Virtual assets can be used for legitimate investment, payment and fundraising and can also be exploited for terrorist financing. Relevant factors can include the provider and jurisdiction, the customer's stated purpose, transaction path, rapid conversion, use of anonymity-enhancing features and links identified through credible intelligence.
Blockchain analytics can support tracing but does not establish intent or legal status by itself. Wallet attribution, confidence level, provider status, transaction history and corroborating evidence should be reviewed together.
Humanitarian programme visibility
A bank may know its NPO customer and the immediate payment beneficiary but not every final person receiving aid. Requirements should reflect that reality. Due diligence can assess programme governance, local-partner selection, approval controls, reconciliation and how the organisation manages sanctions or diversion risk without demanding personal data that is unnecessary or impossible to obtain.
The objective is reasonable, risk-based assurance aligned with what the customer can legitimately know and document. Where a standing humanitarian exemption applies, it should not be described as if a transaction-specific licence is always required. Where a licence or specific authorisation is relied upon, operations still need to verify its scope, conditions and validity.
Network analysis with evidential confidence
Shared beneficiaries, controllers, devices, phone numbers, intermediaries or organisations can reveal useful relationships. Connections must be graded by confidence and role. A common humanitarian service provider can legitimately connect many charities; an official intelligence link is different from an unverified social-media allegation.
Case notes and graph tools should clearly separate verified relationships, direct transactions, credible external information, weak associations and analyst hypotheses. Network centrality is an investigative prompt, not a finding of terrorist support.
BA and architecture requirements
The data model should support NPO, trustee or controller, programme, donor or funding source where relevant, delivery partner, beneficiary category, payment, permission or licence, sanctions decision, CFT alert, intelligence item, case and external report as distinct objects. It should not force every NPO into a shareholder or ownership-percentage model designed for commercial companies.
Permissions should be effective-dated with legal regime, authority, scope, covered activity, conditions and expiry where applicable. A document being present is not enough; operations must verify that it actually covers the transaction. Equally, a system must be able to represent a standing exemption that does not require an individual licence.
References and further reading
- FATF — The FATF Recommendations, current official Standards including the June 2026 Recommendation 6 update: https://www.fatf-gafi.org/en/publications/Fatfrecommendations/Fatf-recommendations.html
- FATF — The FATF strengthens its standards to help ensure access to financial services for humanitarian assistance, 23 June 2026: https://www.fatf-gafi.org/en/publications/Fatfrecommendations/update-recommendation-6-june-2026.html
- FATF — Non-profit organisations, including the 2023 Recommendation 8 revision and current unintended-consequences work: https://www.fatf-gafi.org/en/topics/non-profit-organisations.html
- FATF — Best Practices on Combating the Abuse of Non-Profit Organisations, 16 November 2023: https://www.fatf-gafi.org/en/publications/Fatfrecommendations/Bpp-combating-abuse-npo.html
- FATF — Comprehensive Update on Terrorist Financing Risks, 8 July 2025: https://www.fatf-gafi.org/en/publications/Methodsandtrends/comprehensive-update-terrorist-financing-risks-2025.html
- FATF — Detecting and Disrupting Terrorist Financing Activity through Social Media, Instant Messaging Applications and Streaming Platforms, 26 June 2026: https://www.fatf-gafi.org/en/publications/Methodsandtrends/detecting-and-disrupting-tf-through-smsps.html
- FATF — Crowdfunding for Terrorism Financing, 31 October 2023: https://www.fatf-gafi.org/en/publications/Methodsandtrends/crowdfunding-for-terrorism-financing.html
- FATF — Terrorist Financing Risk Assessment Guidance: https://www.fatf-gafi.org/en/publications/methodsandtrends/documents/terrorist-financing-risk-assessment-guidance.html
- FATF — Investigating Professional Money Laundering, Underground Banking, and the Use of Hawala and Other Similar Service Providers, 3 September 2026: https://www.fatf-gafi.org/en/publications/Methodsandtrends/pml-underground-banking-hawala-hossps.html
- FATF — Guidance for a Risk-Based Approach to Virtual Assets and Virtual Asset Service Providers: https://www.fatf-gafi.org/en/publications/Fatfrecommendations/Guidance-rba-virtual-assets.html
- United Nations Security Council — ISIL (Da'esh) and Al-Qaida sanctions regime (1267/1989/2253 Committee): https://main.un.org/securitycouncil/en/sanctions/1267
- United Nations Security Council — Resolution 2664 (2022), humanitarian exemption: https://main.un.org/securitycouncil/en/content/sres2664-2022
- United Nations Security Council — Resolution 2761 (2024), continuation of the humanitarian exemption for the ISIL/Al-Qaida regime: https://docs.un.org/S/RES/2761(2024)