Table of contents
AML (anti-money laundering) targets criminal proceeds being disguised as legitimate money, while CFT (countering the financing of terrorism) targets funds — often legally earned — flowing toward terrorist activity. AML follows dirty money forward from a crime; CFT traces clean or dirty money toward a future harm. Regulators expect one program that does both.
What AML means
Anti-money laundering (AML) is the set of laws, regulations, and controls designed to stop criminals from disguising illegally obtained funds as legitimate income. The predicate crime — fraud, drug trafficking, corruption, tax evasion — has already happened, and the money is being cycled through the three stages of money laundering: placement, layering, and integration.
In practice, AML obligations for regulated firms include customer due diligence (CDD), transaction monitoring, record-keeping, and filing a suspicious activity report when something doesn't add up.
What CFT means
CFT stands for countering the financing of terrorism (you'll also see "combating the financing of terrorism" — same thing, and CTF in some UK texts). It refers to controls that detect and disrupt funds destined for terrorist individuals, organizations, or acts. See our full CFT glossary entry for the term on its own.
The critical difference: in terrorist financing, the money is often clean at the source — donations, charity flows, small business revenue, personal salaries. The crime lies in the destination, not the origin. That's why CFT leans heavily on sanctions and watchlist screening against designated persons and entities, rather than on tracing proceeds backward to a predicate offense.
AML vs CFT: side-by-side comparison
| Dimension | AML | CFT |
|---|---|---|
| Full name | Anti-money laundering | Countering the financing of terrorism |
| Source of funds | Illegal (proceeds of crime) | Often legal (donations, wages, business income) |
| Direction of analysis | Backward — where did the money come from? | Forward — where is the money going? |
| Typical amounts | Often large; layered through complex structures | Often small; hard to spot by value alone |
| Primary crime | The predicate offense already occurred | The financed act may not have happened yet |
| Key detection tools | Transaction monitoring, CDD/EDD, SAR filing | Sanctions/designated-lists screening, network analysis, typology-based monitoring |
| Core objective | Stop criminals profiting from crime | Prevent violence by cutting off funding |
| Shared foundation | FATF 40 Recommendations, risk-based approach, KYC/CDD, reporting obligations | Same |
How FATF frames AML/CFT — and now CPF
The Financial Action Task Force (FATF) is the global standard-setter, and its 40 Recommendations are explicitly the basis for tackling money laundering, terrorist financing, and proliferation financing together. Three points matter:
- One framework, three threats. FATF doesn't publish separate AML and CFT rulebooks. Countries are assessed against a single set of standards covering all three financial-crime types, which is why regulators and laws say "AML/CFT" as one compound term.
- CPF is the third pillar. Counter-proliferation financing (CPF) addresses funding for weapons of mass destruction. FATF Recommendation 7 requires countries to implement targeted financial sanctions under the relevant UN Security Council resolutions, and Recommendation 1 now requires firms to assess and mitigate proliferation financing risk. Expect "AML/CFT/CPF" to appear more often in regulatory texts.
- Risk-based, not checkbox. FATF strengthened Recommendation 1 to reinforce that AML/CFT/CPF controls must be proportionate to risk — including avoiding over-de-risking that pushes people out of the financial system.
Why the distinction matters operationally
If AML and CFT are enforced as one package, why care about the difference? Because the two threats fail differently, and a program tuned only for laundering patterns will miss terrorist financing.
- Thresholds mislead. AML monitoring often keys on large or structured amounts. Terrorist financing frequently moves in small sums that sail under value-based rules, so CFT detection depends more on who is involved and where funds flow than on how much.
- Screening does different work. For AML, PEP screening and adverse media flag corruption and predicate-crime exposure. For CFT, screening against terrorist designation lists (OFAC, UN, EU) is the front line — and it must run continuously, not just at onboarding, because designations change weekly.
- Investigations run in opposite directions. AML analysts reconstruct where money came from; CFT analysts map networks to see where it's going. Case files, typologies, and escalation criteria should reflect both.
- The penalty exposure is identical. Regulators examine AML and CFT as one program, and enforcement actions routinely cite failures in both — see our AML enforcement tracker for current cases and fines.
Modern AML software handles both in one workflow: sanctions and watchlist screening at onboarding, perpetual monitoring for new designations, and transaction monitoring tuned to both laundering and terrorist-financing typologies. Zyphe is a privacy-first, decentralized identity verification and compliance platform that runs these AML/CFT checks without storing your customers' PII in a central vendor database — screening and audit trails stay intact, the honeypot doesn't.
Running AML and CFT as one program shouldn't mean pooling all your customers' identity data in one breach-ready database. Book a demo to see how Zyphe delivers full AML/CFT screening and monitoring without a central PII honeypot.