FATF fraud roadmap and AML compliance convergence
Blogs

FATF fraud roadmap: why your AML program needs a fraud reset

Fraud costs the global economy an estimated $500 billion every year, according to data cited by the FATF in its 2026-2028 strategy. On 1 July 2026, new FATF President Giles Thomson made tackling that number a major strategic priority. The FATF’s 2026-2028 Roadmap on Combatting Fraud, launched under the UK Presidency, signals a significant shift in how financial crime risks associated with fraud are being prioritised at the international level. It is no longer a separate problem handled by a different team down the corridor.

For compliance professionals, the message is direct. FATF’s recent work increasingly emphasises the close links between fraud and the laundering of its proceeds, particularly in large-scale and cyber-enabled fraud. Institutions should consider whether transaction monitoring designed primarily around traditional money-laundering scenarios adequately captures fraud-related financial flows. Cross-border intelligence sharing, improved detection of mule networks and stronger coordination between fraud and AML functions are all areas of growing regulatory focus. In this article, we break down what the FATF fraud roadmap covers, why fraud and AML convergence is accelerating and what compliance teams should do now to prepare.

Compliance area Key development Why it matters
FATF fraud roadmap 2026-2028 program focused on understanding fraud-related illicit financial flows, strengthening the use of the existing FATF toolkit and supporting effective action Significant elevation of fraud as a strategic FATF priority
AML and fraud convergence Regulators emphasise effective coordination across financial crime functions Separate fraud and AML teams may miss connected criminal activity
Scam compounds Industrial-scale operations in Southeast Asia with significant annual revenues Proceeds enter the financial system through channels AML teams already monitor
FRAML integration Shared data, cross-trained staff and unified case management platforms Institutions with integrated approaches can improve detection of connected activity
EU AI Act AI systems used in financial services may be subject to additional requirements depending on classification Organisations should assess specific use cases rather than assume automatic high-risk classification
Practical preparation Fraud risk assessments, updated monitoring rules and cross-team training Aligning with FATF priorities early positions compliance teams to respond as the FATF’s findings emerge

What the FATF fraud roadmap actually says

On 1 July 2026, the FATF officially launched its 2026-2028 Roadmap on Combatting Fraud under the UK Presidency. The roadmap sets out a program of work across the two-year presidency period. The work includes gathering evidence and analysing fraud typologies from across the FATF’s global network, including input from relevant public and private-sector stakeholders. Scam compounds receive particular attention, with the FATF analysing how these operations generate and move illicit proceeds.

As the work progresses, the FATF is expected to build on this evidence to identify how countries can more effectively use the existing FATF toolkit to prevent, detect, disrupt and recover the proceeds of fraud.

The work is expected to examine how countries can use existing AML/CFT/CPF tools more effectively to address fraud and the laundering of its proceeds.

This roadmap builds on the FATF’s February 2026 paper on cyber-enabled fraud, which documented how fraud and money laundering converge in practice. That paper found that in the UK alone, fraud now accounts for more than 40% of all crimes. In Singapore, cyber-enabled fraud cases increased 61% in just two years.

At the FATF’s April 2026 ministerial meeting, ministers issued a declaration agreeing to deploy the full AML/CFT/CPF toolkit to disrupt fraud. They committed to deepening understanding of scam centres, the misuse of legal persons, virtual assets and emerging technologies such as artificial intelligence.

Why fraud and AML are converging

Fraud and money laundering used to operate in separate lanes. A customer made a fraudulent payment and the fraud team investigated. A suspicious pattern appeared in wire transfers and the AML team filed a report. The two teams rarely shared data, tools or workflows.

That separation no longer reflects how criminals operate. Modern financial crime unfolds as a continuous chain. A scam generates the proceeds. A mule network moves them. Shell companies layer them. Crypto platforms convert them. Each stage blends fraud and laundering into a single operation that crosses borders in minutes.

The speed of these operations is striking. Research from RUSI and Lloyds Bank found that 28% of illicit funds exit mule accounts within 15 minutes of arrival. A further 25% moves within an hour. In total, 57% of those funds flow through faster payment systems. By the time a traditional AML team reviews a suspicious activity alert through batch processing, the money is already gone.

Regulators have taken notice. The EU’s Anti-Money Laundering Authority (AMLA) was established to strengthen AML/CFT supervision across the EU. In October 2025, FinCEN issued a final rule severing the Cambodia-based Huione Group from the U.S. financial system after identifying at least $4 billion in illicit proceeds flowing through its accounts. In June 2026, FinCEN proposed extending this action to H-Pay Service PLC, a successor entity. These actions illustrate the growing focus of U.S. authorities on financial networks connected to cyber-enabled fraud and the laundering of its proceeds.

For compliance teams, the practical takeaway is straightforward. Fraud and AML functions should have appropriate mechanisms to share relevant information, intelligence and escalation outcomes.

The scam compound problem and its AML implications

The FATF fraud roadmap gives particular attention to scam compounds because they sit at the intersection of fraud, money laundering and human trafficking. These operations, concentrated in Southeast Asia, represent industrial-scale financial crime.

According to estimates cited by the United Nations Office on Drugs and Crime, hundreds of thousands of people from dozens of countries have been trafficked into compounds across Cambodia, Myanmar and Laos. Annual revenues from these cyber-scam operations are estimated at tens of billions of dollars. The proceeds flow through layered networks of mule accounts, crypto exchanges, front companies and correspondent banking relationships.

In April 2026, U.S. authorities launched a coordinated crackdown. OFAC designated Cambodian Senator Kok An, his business empire and 28 other individuals and entities for their roles in facilitating human trafficking and cyber-enabled fraud.

The challenge for compliance teams extends beyond screening these sanctioned names. Scam compound proceeds enter the financial system through familiar channels: remittance services, crypto-to-fiat conversions, trade invoicing and real estate purchases. As a result, transaction monitoring scenarios designed primarily for traditional money laundering patterns may not flag these flows. Institutions should consider whether relevant fraud typologies and indicators are adequately reflected in their AML monitoring and escalation frameworks.

The FATF’s evidence-gathering work under the UK Presidency should provide clearer guidance on the specific patterns to watch for. Until then, compliance teams should review whether their current monitoring rules can detect the rapid, multi-channel movement of scam proceeds.

What a converged compliance function looks like

Some financial institutions have moved toward more integrated fraud and financial-crime operating models, sometimes described as FRAML. However, the shift requires more than renaming a department and effective coordination does not necessarily require full organisational integration.

An effective converged approach typically depends on appropriate information sharing. Fraud alerts, AML alerts and cyber threat intelligence should be accessible through interoperable systems, shared platforms or structured data-sharing arrangements. Relevant information about an account flagged for mule activity by the fraud team should be available to the AML analyst assessing related suspicious activity, subject to appropriate access controls and data-governance requirements. Without this shared view, institutions investigate the same criminal network in two separate silos and miss the connections between them.

Cross-trained staff and unified governance

Cross-trained staff are equally important. Fraud investigators need to understand suspicious activity reporting obligations. AML analysts need to recognise scam patterns, social engineering tactics and mule recruitment indicators.

Technology plays a supporting role. Unified platforms that apply machine learning across both fraud and AML data sets can identify patterns that neither team would catch working alone. The EU AI Act introduces a phased regulatory framework for AI systems. Depending on their intended purpose and classification, certain AI systems used in financial-crime controls may be subject to additional requirements, including risk management, documentation and human oversight. Organisations deploying AI in fraud or AML controls should assess the specific use case rather than assume that all such systems are automatically classified as high-risk.

Clear reporting lines

Any move towards closer coordination also demands clear governance. Reporting lines, escalation protocols and regulatory filing responsibilities need to reflect the operating structure. Without clear ownership, institutions risk gaps where fraud incidents generate suspicious activity but no SAR is filed because neither team considers it their responsibility.

Five steps compliance teams should take now

The FATF fraud roadmap sets a clear strategic direction and compliance teams have an opportunity to assess their exposure as the FATF’s work develops. The following steps offer a practical starting point.

Conduct a fraud risk assessment. Run a fraud-specific risk assessment alongside your existing ML/TF risk assessment. Identify which fraud typologies are most relevant to your customer base, product set and geographic exposure. Scam-related risks, mule account activity and authorised push payment fraud deserve particular attention.

Review your transaction monitoring rules. Assess whether your current scenarios can detect fraud-to-laundering chains, not just standalone laundering patterns. Consider adding velocity checks, behavioural analytics and device-level signals to your monitoring framework.

Break down data silos. Where appropriate, ensure that relevant fraud and AML alerts, investigations and escalation outcomes can be considered together when assessing customer risk and connected activity.

Invest in cross-training. Fraud investigators and AML analysts should attend joint workshops and review each other’s case studies. Understanding how the other function operates builds the institutional knowledge needed for convergence.

Monitor the FATF’s evidence-gathering outputs. As the UK Presidency progresses, the FATF’s work on fraud-related typologies and illicit financial flows may provide further insight into the patterns and risks receiving international attention. Aligning your monitoring and reporting frameworks with these priorities early will position you well as the FATF’s findings and future outputs emerge.

Preparing for the new reality

The 2026-2028 UK Presidency represents a significant elevation of fraud as a strategic FATF priority. The direction is clear: the global standard-setter for AML/CFT is placing fraud firmly within the scope of its existing toolkit.

Institutions that begin strengthening coordination between fraud and AML functions may be better positioned to respond as the FATF’s findings and future outputs emerge. Assess your fraud exposure, review your monitoring capabilities and start building the bridges between your fraud and AML teams.

If your organisation needs support in assessing fraud and AML convergence readiness, book a free consultation with Compliance7.

This article is for informational purposes only and does not constitute legal or regulatory advice. For guidance specific to your business, consult a qualified compliance professional.

Ajith Abraham is a Financial Crime Compliance professional with over 14 years of experience in Anti-Money Laundering (AML), Counter-Terrorist Financing (CFT), KYC, Customer Due Diligence (CDD), Enhanced Due Diligence (EDD), Transaction Monitoring, Sanctions Screening and Financial Crime Investigations. He is a Certified Anti-Money Laundering Specialist (CAMS) and Merkle Science Certified Crypto Investigator (CCI). Ajith has worked with Big Four consulting firms and advises Financial Institutions, fintechs, DNFBPs and Virtual Asset Service Providers (VASPs) on AML/CFT compliance, risk assessments, regulatory audits, financial crime risk management, crypto compliance, blockchain investigations and FATF-aligned compliance frameworks through Compliance7 Consulting LLP.

Leave a Reply

Your email address will not be published. Required fields are marked *