Free guide: How to use AI in compliance
Back

AML vs CFT

Updated September 11, 2026

Table of contents

CFT stands for Combating the Financing of Terrorism, the controls that stop funds reaching terrorist organizations. AML, Anti-Money Laundering, stops criminal proceeds being disguised as legitimate money. The difference is direction: AML traces dirty money being made clean, CFT traces clean money being put to criminal use.

What does CFT stand for?

CFT stands for Combating the Financing of Terrorism. You will also see it written as countering the financing of terrorism, and UK texts often use CTF, counter-terrorist financing. All three label the same duty: detecting and disrupting funds destined for terrorist individuals, organizations, or acts.

The framework took its modern shape after September 11, 2001. Terrorist financing was a recognised concern before then, but it was not the organizing principle of financial regulation that it became afterward. Governments responded by layering designation regimes, reporting duties, and screening obligations on top of the anti-money-laundering machinery that already existed.

What is AML?

Anti-money laundering (AML) is the set of laws, regulations, and controls designed to stop criminals from disguising illegally obtained funds as legitimate income. The predicate crime — fraud, drug trafficking, corruption, tax evasion — has already happened, and the money is being cycled through the three stages of money laundering: placement, layering, and integration.

In practice, AML obligations for regulated firms include customer due diligence, transaction monitoring, record-keeping, and filing a suspicious activity report when something does not add up.

What is CFT?

CFT covers the controls that detect and disrupt funds destined for terrorist individuals, organizations, or acts. The critical difference is that in terrorist financing the money is often clean at the source: donations, charity flows, small business revenue, personal salaries. The crime lies in the destination, not the origin.

That inverts the detection problem. You cannot rely on spotting suspicious fund origins, because the origins may be entirely unremarkable. A radicalized individual drawing down their own savings does not look like someone cleaning drug money. A charity sending money overseas looks like a charity sending money overseas, until you trace where the funds actually land. This is why CFT leans on sanctions and watchlist screening against designated persons and entities rather than on tracing proceeds backward to a predicate offense.

AML vs CFT: the key difference

AMLCFT
Full formAnti-Money LaunderingCombating the Financing of Terrorism
GoalStop criminal proceeds being legitimizedStop funds reaching terrorist organizations
Direction of fundsIllicit money made to look cleanOften legitimate money put to illicit use
Direction of analysisBackward: where did the money come from?Forward: where is the money going?
Typical amountsFrequently large, layered through complex structuresFrequently small, hard to spot by value alone
Source of fundsCriminal by definitionMay be entirely lawful: salary, donation, business income
Core signalUnexplained wealth, layeringDestination, affiliation, network
Key detection toolsTransaction monitoring, CDD and EDD, SAR filingSanctions and designated-list screening, network analysis, typology-based monitoring
Timing of the crimeThe predicate offense has already occurredThe financed act may not have happened yet
ReportingSAR / STRSAR / STR

Two rows in that table carry the page. "Typical amounts" and "source of funds" explain why a monitoring system tuned purely for AML misses terrorist financing: it is looking for large sums of dirty money, and CFT is frequently small sums of clean money. That is a design problem, not a tuning problem.

Why the distinction matters in practice

If regulators enforce AML and CFT as one package, why care about the difference? Because the two threats fail differently, and a program calibrated only for laundering patterns will miss terrorist financing.

Different red flags

AML monitoring often keys on large or structured amounts. Terrorist financing frequently moves in sums that sail under value-based rules, so detection depends more on who is involved and where funds are going than on how much moved.

The CFT-specific indicators worth building rules around:

  • Nonprofits whose outbound donations substantially exceed legitimate program spending, or that transfer funds to regions where they run no apparent program.
  • Charities or businesses operating in conflict zones without a clear humanitarian or commercial purpose, especially using cash or informal value transfer instead of the banking system they have access to.
  • Dormant accounts that suddenly activate, accounts used purely as pass-throughs with rapid in-and-out activity, and multiple accounts funnelling to a single destination.
  • Customers with unexplained connections to high-risk jurisdictions, or accounts opened shortly before or after travel to them.
  • Conversion of fiat into privacy coins, routing through mixers or tumblers, and crowdfunding campaigns tied to extremist content.

Different data sources

For AML, politically exposed person screening and adverse media flag corruption and predicate-crime exposure. For CFT, screening against terrorist designation lists is the front line, and it has to run continuously rather than only at onboarding, because designations change constantly.

Those lists are not interchangeable. OFAC, the UN consolidated list, and the EU list overlap heavily but not completely, so a firm with exposure on both sides of the Atlantic needs all of them rather than whichever one its vendor ships by default.

Geography does different work too. FATF maintains a list of high-risk jurisdictions subject to a call for action, and a list of jurisdictions under increased monitoring. Both should drive enhanced scrutiny of connected customers and transactions.

Same reporting obligation, different typologies

Both threads end in the same filing: a suspicious activity report in the United States, a suspicious transaction report in most other regimes. What differs is what triggers it, and how the narrative reads.

Under the Bank Secrecy Act, the general SAR thresholds are 5,000 dollars in aggregate for banks and 2,000 dollars for money services businesses. FinCEN encourages voluntary filing below those thresholds where terrorism is suspected, so the practical answer for a CFT hit is to file rather than to check whether the amount clears a bar.

AML analysts reconstruct where money came from. CFT analysts map networks to work out where it is going. Case templates, typology libraries, and escalation criteria should reflect both, because an investigator handed only a laundering playbook will write the wrong narrative.

AML/CFT as a combined framework

The compound term is not a stylistic habit. FATF does not publish separate AML and CFT rulebooks: countries are assessed against a single set of standards covering money laundering, terrorist financing, and proliferation financing together, which is why regulations and supervisors write "AML/CFT" as one word.

Counter-proliferation financing (CPF) is the third pillar, addressing funding for weapons of mass destruction. FATF Recommendation 7 requires countries to implement targeted financial sanctions under the relevant UN Security Council resolutions, and Recommendation 1 requires firms to assess and mitigate proliferation financing risk. Expect "AML/CFT/CPF" to appear more often in regulatory text.

FATF also strengthened Recommendation 1 to reinforce that controls must be proportionate to risk, including avoiding the kind of blanket de-risking that pushes whole customer categories out of the financial system.

The regulatory picture

Four layers of rule-making sit behind a working AML/CFT program, and they reference each other constantly.

FATF

The 40 Recommendations are the global standard. Recommendation 5 requires countries to criminalize terrorist financing. Recommendation 6 requires implementation of UN Security Council resolutions on terrorist financing, including asset freezing and prohibitions on making funds available to designated persons. Recommendation 7 covers proliferation financing sanctions. Recommendation 8 requires countries to review their nonprofit sectors for terrorist financing vulnerability and respond proportionately.

FATF assesses members through mutual evaluations, scoring technical compliance against the Recommendations and, separately, effectiveness across eleven Immediate Outcomes. A country can be technically compliant and still be found ineffective.

The United Nations

UN Security Council Resolution 1373 requires member states to criminalize terrorist financing. The 1999 International Convention for the Suppression of the Financing of Terrorism established the legal basis for cooperation, and the UN maintains a consolidated list of designated individuals and entities that national regimes build on.

The United States

The Bank Secrecy Act is the base obligation. The USA PATRIOT Act of 2001 extended it explicitly to terrorist financing, barred correspondent accounts for foreign shell banks, and required enhanced due diligence for correspondent and private banking relationships. The International Emergency Economic Powers Act gives the President authority to block assets and prohibit transactions with designated entities, and Executive Order 13224 blocks the property of persons who commit or threaten terrorism. OFAC administers the designations that screening actually runs against.

The European Union

The anti-money-laundering directives carried CFT duties into national law across the bloc. The AMLR and AMLA package now moves much of that into directly applicable regulation with a single EU-level supervisor, which narrows the divergence between member states that firms previously had to map jurisdiction by jurisdiction.

How AML/CFT controls work together in practice

One program, four load-bearing controls. Each does double duty, which is precisely why regulators expect them built once rather than twice.

  • Sanctions and watchlist screening. At onboarding, against transactions, and again whenever a list changes. Match resolution and false-positive rationale both need documenting, because examiners test the quality of the decisions rather than the volume of the alerts.
  • Customer due diligence and enhanced due diligence. Heavier scrutiny for high-risk jurisdictions, correspondent banking, private banking and wealth clients, and nonprofits operating internationally.
  • Transaction monitoring. Rules tuned for laundering typologies will not catch terrorist financing on their own. The rule set needs destination, affiliation, and network logic alongside value-based logic.
  • Reporting. SAR or STR filing within the applicable deadline, with retention and confidentiality handled properly, plus OFAC blocking reports where property has been frozen.

The penalty exposure is identical either way. Regulators examine AML and CFT as one program, and enforcement actions routinely cite failures in both — see our AML enforcement tracker for current cases and fines.

Modern AML software handles both in one workflow: sanctions and watchlist screening at onboarding, perpetual monitoring for new designations, and transaction monitoring tuned to laundering and terrorist-financing typologies alike. Zyphe runs these AML/CFT checks without storing your customers’ personal data in a central vendor database, so screening and audit trails stay intact while the honeypot does not exist.

Running AML and CFT as one program should not mean pooling every customer’s identity data in one breach-ready database. Book a demo to see how Zyphe delivers AML/CFT screening and monitoring without a central store of personal data.

Michelangelo Frigo Written by Michelangelo Frigo (Co-Founder at Zyphe) Reviewed September 11, 2026 Michelangelo Frigo is a privacy and identity infrastructure expert and co-founder of Zyphe.

Frequently Asked Questions

CFT stands for Combating the Financing of Terrorism, the laws and controls that stop funds — even legally earned funds — from reaching terrorist individuals, organizations, or acts. You will also see it written as countering the financing of terrorism, and UK texts often use CTF, counter-terrorist financing. All three mean the same thing.

AML stops criminal proceeds being disguised as legitimate money. CFT stops money, which may itself be entirely legitimate, from reaching terrorist organizations. AML follows dirty money being cleaned; CFT follows clean money being put to criminal use. AML analysis looks backward at origin, CFT analysis looks forward at destination and intent.

AML/CFT is the combined framework covering both obligations. Most regulations, including the FATF Recommendations and the EU anti-money-laundering directives, treat them together because the underlying controls overlap heavily: customer due diligence, sanctions screening, transaction monitoring, and suspicious activity reporting serve both purposes.

Because the controls are largely the same even though the crimes differ. A firm builds one program that satisfies both, and supervisors examine it as one program. FATF reinforces this by assessing countries against a single set of standards covering money laundering, terrorist financing, and proliferation financing rather than publishing separate rulebooks.

No, and this is the key operational difference. Terrorist financing frequently involves small amounts from lawful sources such as salaries, donations, or business income, which is precisely why monitoring calibrated only for large-value laundering patterns misses it. Detection relies on continuous screening against terrorist designation lists and on network analysis of where funds are going.

Internationally, the FATF 40 Recommendations, with Recommendations 5, 6 and 8 addressing terrorist financing specifically. In the EU, the anti-money-laundering directives and the AMLR/AMLA framework. In the United States, the Bank Secrecy Act and the USA PATRIOT Act, with OFAC administering designations under IEEPA and Executive Order 13224.

It is FATF’s full framing of financial-crime controls: anti-money laundering, combating the financing of terrorism, and counter-proliferation financing, which covers funding for weapons of mass destruction. FATF Recommendation 7 requires targeted financial sanctions against proliferation, and firms must assess proliferation financing risk alongside money laundering and terrorist financing risk.

No, the same platform should cover both. What matters is that it includes sanctions and terrorist-list screening with ongoing re-screening as designations change, plus transaction monitoring tuned to both laundering and terrorist-financing typologies rather than large-value rules alone.

See why teams switch to Zyphe

Privacy-first KYC that verifies identity without holding your customers' PII. Reusable credentials, usage-based pricing, no central honeypot.

Book a demo