Learn more about the latest security and privacy threats
Back

AML vs CFT

Updated August 8, 2026

Table of contents

AML (anti-money laundering) targets criminal proceeds being disguised as legitimate money, while CFT (countering the financing of terrorism) targets funds — often legally earned — flowing toward terrorist activity. AML follows dirty money forward from a crime; CFT traces clean or dirty money toward a future harm. Regulators expect one program that does both.

What AML means

Anti-money laundering (AML) is the set of laws, regulations, and controls designed to stop criminals from disguising illegally obtained funds as legitimate income. The predicate crime — fraud, drug trafficking, corruption, tax evasion — has already happened, and the money is being cycled through the three stages of money laundering: placement, layering, and integration.

In practice, AML obligations for regulated firms include customer due diligence (CDD), transaction monitoring, record-keeping, and filing a suspicious activity report when something doesn't add up.

What CFT means

CFT stands for countering the financing of terrorism (you'll also see "combating the financing of terrorism" — same thing, and CTF in some UK texts). It refers to controls that detect and disrupt funds destined for terrorist individuals, organizations, or acts. See our full CFT glossary entry for the term on its own.

The critical difference: in terrorist financing, the money is often clean at the source — donations, charity flows, small business revenue, personal salaries. The crime lies in the destination, not the origin. That's why CFT leans heavily on sanctions and watchlist screening against designated persons and entities, rather than on tracing proceeds backward to a predicate offense.

AML vs CFT: side-by-side comparison

DimensionAMLCFT
Full nameAnti-money launderingCountering the financing of terrorism
Source of fundsIllegal (proceeds of crime)Often legal (donations, wages, business income)
Direction of analysisBackward — where did the money come from?Forward — where is the money going?
Typical amountsOften large; layered through complex structuresOften small; hard to spot by value alone
Primary crimeThe predicate offense already occurredThe financed act may not have happened yet
Key detection toolsTransaction monitoring, CDD/EDD, SAR filingSanctions/designated-lists screening, network analysis, typology-based monitoring
Core objectiveStop criminals profiting from crimePrevent violence by cutting off funding
Shared foundationFATF 40 Recommendations, risk-based approach, KYC/CDD, reporting obligationsSame

How FATF frames AML/CFT — and now CPF

The Financial Action Task Force (FATF) is the global standard-setter, and its 40 Recommendations are explicitly the basis for tackling money laundering, terrorist financing, and proliferation financing together. Three points matter:

  1. One framework, three threats. FATF doesn't publish separate AML and CFT rulebooks. Countries are assessed against a single set of standards covering all three financial-crime types, which is why regulators and laws say "AML/CFT" as one compound term.
  2. CPF is the third pillar. Counter-proliferation financing (CPF) addresses funding for weapons of mass destruction. FATF Recommendation 7 requires countries to implement targeted financial sanctions under the relevant UN Security Council resolutions, and Recommendation 1 now requires firms to assess and mitigate proliferation financing risk. Expect "AML/CFT/CPF" to appear more often in regulatory texts.
  3. Risk-based, not checkbox. FATF strengthened Recommendation 1 to reinforce that AML/CFT/CPF controls must be proportionate to risk — including avoiding over-de-risking that pushes people out of the financial system.

Why the distinction matters operationally

If AML and CFT are enforced as one package, why care about the difference? Because the two threats fail differently, and a program tuned only for laundering patterns will miss terrorist financing.

  • Thresholds mislead. AML monitoring often keys on large or structured amounts. Terrorist financing frequently moves in small sums that sail under value-based rules, so CFT detection depends more on who is involved and where funds flow than on how much.
  • Screening does different work. For AML, PEP screening and adverse media flag corruption and predicate-crime exposure. For CFT, screening against terrorist designation lists (OFAC, UN, EU) is the front line — and it must run continuously, not just at onboarding, because designations change weekly.
  • Investigations run in opposite directions. AML analysts reconstruct where money came from; CFT analysts map networks to see where it's going. Case files, typologies, and escalation criteria should reflect both.
  • The penalty exposure is identical. Regulators examine AML and CFT as one program, and enforcement actions routinely cite failures in both — see our AML enforcement tracker for current cases and fines.

Modern AML software handles both in one workflow: sanctions and watchlist screening at onboarding, perpetual monitoring for new designations, and transaction monitoring tuned to both laundering and terrorist-financing typologies. Zyphe is a privacy-first, decentralized identity verification and compliance platform that runs these AML/CFT checks without storing your customers' PII in a central vendor database — screening and audit trails stay intact, the honeypot doesn't.

Running AML and CFT as one program shouldn't mean pooling all your customers' identity data in one breach-ready database. Book a demo to see how Zyphe delivers full AML/CFT screening and monitoring without a central PII honeypot.

Frequently Asked Questions

CFT stands for countering (or combating) the financing of terrorism. It covers the laws and controls that stop funds — even legally earned funds — from reaching terrorist individuals, organizations, or activities. The UK and some regulators use CTF (counter-terrorist financing) to mean the same thing.

AML targets money that is already criminal — proceeds of fraud, trafficking, or corruption being disguised as legitimate. CFT targets money heading toward terrorism, which is often clean at the source. AML analysis looks backward at origin; CFT analysis looks forward at destination and intent.

Operationally, yes — regulators expect a single AML/CFT program with shared foundations: risk assessment, KYC/CDD, screening, monitoring, and suspicious activity reporting. Legally they address different crimes, so FATF and most national laws name both explicitly, and examiners test controls against each threat separately.

It is the FATF's full framing of financial-crime controls: anti-money laundering, countering the financing of terrorism, and counter-proliferation financing (funding of weapons of mass destruction). FATF Recommendation 7 requires targeted financial sanctions against proliferation, and firms must now assess proliferation financing risk alongside ML/TF risk.

Because the funds are often legal, small, and unremarkable until they reach their destination. Value-based transaction monitoring rules that catch laundering can miss it entirely. Detection relies on continuously screening customers and counterparties against terrorist designation lists and on network analysis of where funds flow.

No — the same platform should cover both. What matters is that it includes sanctions and terrorist-list screening with ongoing re-screening as designations change, plus transaction monitoring tuned to both laundering and terrorist-financing typologies, not just large-value rules.

See why teams switch to Zyphe

Privacy-first KYC that verifies identity without holding your customers' PII — reusable credentials, usage-based pricing, no central honeypot.

Book a demo