Table of contents
CFT stands for Combating the Financing of Terrorism, the controls that stop funds reaching terrorist organizations. AML, Anti-Money Laundering, stops criminal proceeds being disguised as legitimate money. The difference is direction: AML traces dirty money being made clean, CFT traces clean money being put to criminal use.
What does CFT stand for?
CFT stands for Combating the Financing of Terrorism. You will also see it written as countering the financing of terrorism, and UK texts often use CTF, counter-terrorist financing. All three label the same duty: detecting and disrupting funds destined for terrorist individuals, organizations, or acts.
The framework took its modern shape after September 11, 2001. Terrorist financing was a recognised concern before then, but it was not the organizing principle of financial regulation that it became afterward. Governments responded by layering designation regimes, reporting duties, and screening obligations on top of the anti-money-laundering machinery that already existed.
What is AML?
Anti-money laundering (AML) is the set of laws, regulations, and controls designed to stop criminals from disguising illegally obtained funds as legitimate income. The predicate crime — fraud, drug trafficking, corruption, tax evasion — has already happened, and the money is being cycled through the three stages of money laundering: placement, layering, and integration.
In practice, AML obligations for regulated firms include customer due diligence, transaction monitoring, record-keeping, and filing a suspicious activity report when something does not add up.
What is CFT?
CFT covers the controls that detect and disrupt funds destined for terrorist individuals, organizations, or acts. The critical difference is that in terrorist financing the money is often clean at the source: donations, charity flows, small business revenue, personal salaries. The crime lies in the destination, not the origin.
That inverts the detection problem. You cannot rely on spotting suspicious fund origins, because the origins may be entirely unremarkable. A radicalized individual drawing down their own savings does not look like someone cleaning drug money. A charity sending money overseas looks like a charity sending money overseas, until you trace where the funds actually land. This is why CFT leans on sanctions and watchlist screening against designated persons and entities rather than on tracing proceeds backward to a predicate offense.
AML vs CFT: the key difference
| AML | CFT | |
|---|---|---|
| Full form | Anti-Money Laundering | Combating the Financing of Terrorism |
| Goal | Stop criminal proceeds being legitimized | Stop funds reaching terrorist organizations |
| Direction of funds | Illicit money made to look clean | Often legitimate money put to illicit use |
| Direction of analysis | Backward: where did the money come from? | Forward: where is the money going? |
| Typical amounts | Frequently large, layered through complex structures | Frequently small, hard to spot by value alone |
| Source of funds | Criminal by definition | May be entirely lawful: salary, donation, business income |
| Core signal | Unexplained wealth, layering | Destination, affiliation, network |
| Key detection tools | Transaction monitoring, CDD and EDD, SAR filing | Sanctions and designated-list screening, network analysis, typology-based monitoring |
| Timing of the crime | The predicate offense has already occurred | The financed act may not have happened yet |
| Reporting | SAR / STR | SAR / STR |
Two rows in that table carry the page. "Typical amounts" and "source of funds" explain why a monitoring system tuned purely for AML misses terrorist financing: it is looking for large sums of dirty money, and CFT is frequently small sums of clean money. That is a design problem, not a tuning problem.
Why the distinction matters in practice
If regulators enforce AML and CFT as one package, why care about the difference? Because the two threats fail differently, and a program calibrated only for laundering patterns will miss terrorist financing.
Different red flags
AML monitoring often keys on large or structured amounts. Terrorist financing frequently moves in sums that sail under value-based rules, so detection depends more on who is involved and where funds are going than on how much moved.
The CFT-specific indicators worth building rules around:
- Nonprofits whose outbound donations substantially exceed legitimate program spending, or that transfer funds to regions where they run no apparent program.
- Charities or businesses operating in conflict zones without a clear humanitarian or commercial purpose, especially using cash or informal value transfer instead of the banking system they have access to.
- Dormant accounts that suddenly activate, accounts used purely as pass-throughs with rapid in-and-out activity, and multiple accounts funnelling to a single destination.
- Customers with unexplained connections to high-risk jurisdictions, or accounts opened shortly before or after travel to them.
- Conversion of fiat into privacy coins, routing through mixers or tumblers, and crowdfunding campaigns tied to extremist content.
Different data sources
For AML, politically exposed person screening and adverse media flag corruption and predicate-crime exposure. For CFT, screening against terrorist designation lists is the front line, and it has to run continuously rather than only at onboarding, because designations change constantly.
Those lists are not interchangeable. OFAC, the UN consolidated list, and the EU list overlap heavily but not completely, so a firm with exposure on both sides of the Atlantic needs all of them rather than whichever one its vendor ships by default.
Geography does different work too. FATF maintains a list of high-risk jurisdictions subject to a call for action, and a list of jurisdictions under increased monitoring. Both should drive enhanced scrutiny of connected customers and transactions.
Same reporting obligation, different typologies
Both threads end in the same filing: a suspicious activity report in the United States, a suspicious transaction report in most other regimes. What differs is what triggers it, and how the narrative reads.
Under the Bank Secrecy Act, the general SAR thresholds are 5,000 dollars in aggregate for banks and 2,000 dollars for money services businesses. FinCEN encourages voluntary filing below those thresholds where terrorism is suspected, so the practical answer for a CFT hit is to file rather than to check whether the amount clears a bar.
AML analysts reconstruct where money came from. CFT analysts map networks to work out where it is going. Case templates, typology libraries, and escalation criteria should reflect both, because an investigator handed only a laundering playbook will write the wrong narrative.
AML/CFT as a combined framework
The compound term is not a stylistic habit. FATF does not publish separate AML and CFT rulebooks: countries are assessed against a single set of standards covering money laundering, terrorist financing, and proliferation financing together, which is why regulations and supervisors write "AML/CFT" as one word.
Counter-proliferation financing (CPF) is the third pillar, addressing funding for weapons of mass destruction. FATF Recommendation 7 requires countries to implement targeted financial sanctions under the relevant UN Security Council resolutions, and Recommendation 1 requires firms to assess and mitigate proliferation financing risk. Expect "AML/CFT/CPF" to appear more often in regulatory text.
FATF also strengthened Recommendation 1 to reinforce that controls must be proportionate to risk, including avoiding the kind of blanket de-risking that pushes whole customer categories out of the financial system.
The regulatory picture
Four layers of rule-making sit behind a working AML/CFT program, and they reference each other constantly.
FATF
The 40 Recommendations are the global standard. Recommendation 5 requires countries to criminalize terrorist financing. Recommendation 6 requires implementation of UN Security Council resolutions on terrorist financing, including asset freezing and prohibitions on making funds available to designated persons. Recommendation 7 covers proliferation financing sanctions. Recommendation 8 requires countries to review their nonprofit sectors for terrorist financing vulnerability and respond proportionately.
FATF assesses members through mutual evaluations, scoring technical compliance against the Recommendations and, separately, effectiveness across eleven Immediate Outcomes. A country can be technically compliant and still be found ineffective.
The United Nations
UN Security Council Resolution 1373 requires member states to criminalize terrorist financing. The 1999 International Convention for the Suppression of the Financing of Terrorism established the legal basis for cooperation, and the UN maintains a consolidated list of designated individuals and entities that national regimes build on.
The United States
The Bank Secrecy Act is the base obligation. The USA PATRIOT Act of 2001 extended it explicitly to terrorist financing, barred correspondent accounts for foreign shell banks, and required enhanced due diligence for correspondent and private banking relationships. The International Emergency Economic Powers Act gives the President authority to block assets and prohibit transactions with designated entities, and Executive Order 13224 blocks the property of persons who commit or threaten terrorism. OFAC administers the designations that screening actually runs against.
The European Union
The anti-money-laundering directives carried CFT duties into national law across the bloc. The AMLR and AMLA package now moves much of that into directly applicable regulation with a single EU-level supervisor, which narrows the divergence between member states that firms previously had to map jurisdiction by jurisdiction.
How AML/CFT controls work together in practice
One program, four load-bearing controls. Each does double duty, which is precisely why regulators expect them built once rather than twice.
- Sanctions and watchlist screening. At onboarding, against transactions, and again whenever a list changes. Match resolution and false-positive rationale both need documenting, because examiners test the quality of the decisions rather than the volume of the alerts.
- Customer due diligence and enhanced due diligence. Heavier scrutiny for high-risk jurisdictions, correspondent banking, private banking and wealth clients, and nonprofits operating internationally.
- Transaction monitoring. Rules tuned for laundering typologies will not catch terrorist financing on their own. The rule set needs destination, affiliation, and network logic alongside value-based logic.
- Reporting. SAR or STR filing within the applicable deadline, with retention and confidentiality handled properly, plus OFAC blocking reports where property has been frozen.
The penalty exposure is identical either way. Regulators examine AML and CFT as one program, and enforcement actions routinely cite failures in both — see our AML enforcement tracker for current cases and fines.
Modern AML software handles both in one workflow: sanctions and watchlist screening at onboarding, perpetual monitoring for new designations, and transaction monitoring tuned to laundering and terrorist-financing typologies alike. Zyphe runs these AML/CFT checks without storing your customers’ personal data in a central vendor database, so screening and audit trails stay intact while the honeypot does not exist.
Running AML and CFT as one program should not mean pooling every customer’s identity data in one breach-ready database. Book a demo to see how Zyphe delivers AML/CFT screening and monitoring without a central store of personal data.
Written by Michelangelo Frigo (Co-Founder at Zyphe) Reviewed September 11, 2026 Michelangelo Frigo is a privacy and identity infrastructure expert and co-founder of Zyphe.