28 August 2026: Country Lists: A Quick Guide

At the recent countering Financial Crime conference, a panel was held which covered the use of country lists. The panel sparked much debate over the best way to implement the lists effectively. The following is a quick guide on how operators can use Country Lists effectively.

 

Isle of Man DHA Lists

The Isle of Man Department of Home Affairs publishes three lists.

  •   ‘List A’ specifies jurisdictions on which the Financial Action Task Force (FATF), has called its members (and other jurisdictions) to apply countermeasures to protect the international financial system from the on-going and substantial risks of Money Laundering, Terrorist Financing, Proliferation Financing (ML/TF/PF) emanating from the jurisdiction;
  •  ‘List B’ specifies jurisdictions with strategic AML/CFT deficiencies or those considered to pose a higher risk of ML/TF/PF; and
  • ‘List C’ is a list specifying jurisdictions which are considered to operate laws of approximately equivalent standard to those of the Isle of Man.

 

Where list A jurisdictions require an automatic response, Lists B and C require a holistic assessment. The list result should therefore inform, rather than replace, the operators wider risk assessment. For gambling-sector compliance professionals and supervisors, the challenge is to apply country information consistently while keeping the assessment proportionate, evidence-based and capable of adapting as risks change.

 

The FATF grey list: an indicator, not an automatic conclusion

Grey-listing is a risk indicator and should trigger further consideration, but the firm still needs to assess the specific relationship, activity and wider risk profile in relation to their business. The FATF grey list contains jurisdictions where strategic deficiencies have been identified, but which have made a high-level political commitment to work with FATF or regional body to address those deficiencies within agreed timeframes. It signals that the jurisdiction deserves closer consideration – However, a grey list status does not automatically indicate that every person, entity or transaction connected to that jurisdiction is automatically to also be deemed high risk in the same way.

 

Gambling Sector

For the gambling sector, a genuine risk-based approach requires the operator to understand why the jurisdiction is relevant and how it connects to the customer, business model or wider structure.

 

Jurisdictional risk is not limited to where the customer is resident or located. Operators need to consider the wider structure:

  • Where ownership and control sit;
  • Why group entities or service companies are in particular jurisdictions;
  • How funds and services flow;
  • Whether network partner or software supply licence arrangements introduce additional exposure; and
  • Whether any jurisdictional links create complexity or reduce transparency.

 

It is also important to recognise that criminal methodologies are adaptive. Where particular routes, jurisdictions, payment methods or structures attract focus from supervisors, LEAs or industry, criminals will change tactics and move activity elsewhere. A strong approach would show how the country list position has been considered alongside the firm’s own exposure and other relevant information. The National Risk Assessment (NRA) and NRAS will also provide important context, but the outcome must still reflect the specific facts of the business relationship.

 

Online Gambling

This point is particularly relevant to online gambling because it is a remote, international sector. The use of cross-border customer relationships, international corporate structures, third-party providers, payment intermediaries and digital onboarding can create risk indicators that are not captured by a country list alone.

It is therefore important to consider other sources such as the NRA and NRAS, and to stay abreast of international and geopolitical developments.

 

Supervisory expectations

During an onsite inspection, supervisors expect to see a documented and clear path from the country-list information to the final decision. That path should show what was identified, what other evidence was considered, why the controls were proportionate and when the assessment will be reviewed.

Supervisors are often interested in whether firms understand why their structures and relationships operate as they do. For example:

  • Why are particular group service companies located in specific jurisdictions?
  • Why do funds or services flow through multiple entities or countries?
  • Are there jurisdictions within the wider structure that introduce unnecessary complexity or reduce transparency?
  • Does the rationale for the arrangement make commercial and operational sense?

 

It is not only about whether a connection exists, but whether the connection creates a risk that is material in the circumstances and whether the risk can be understood and managed through proportionate controls.

 

Best practice would be to show:

  • A documented methodology;
  • Clear rationale for ratings;
  •  Consideration of DHA lists alongside the NRA, NRAS, FATF updates, sanctions and typologies;
  • Minutes or sign-off where higher-risk relationships are considered;
  • EDD records;
  • Payment flow analysis;
  • Escalation decisions;
  • Monitoring rules; and
  • Evidence that assessments are updated when risk changes.

 

In Conclusion

Country lists have value, but only when applied proportionately and appropriately. The lists should not be used in isolation or treated as a shortcut to automatic de-risking.

The right response is enhanced understanding and proportionate mitigation, not automatic de-risking - unless the firm cannot understand or manage the risk. The lists are not a substitute for understanding the unique ML/TF/PF risk presented by a customer, relationship, service or transaction so ensure a risk-based approach is undertaken and documented.

 

For more information on the GSC’s AML Code Requirements, view the video series on YouTube, or read the AML/CFT resources on our website.