L-04 · Mastery

Programme design, metrics, and institutional integrity

Designing the analytics function of a revenue authority or FIU, risk-scoring and its failure modes, data protection limits after the CJEU BO-register rulings, measuring effectiveness against FATF's 11 Immediate Outcomes, greylisting dynamics, corruption of the enforcement function itself, and whistleblower protection.

Module lecturer: Dr. Collen Lediga, Ruhr-Universität Bochum

Module progress
0 / 3 lessons126 min remaining

Visual overview

Interactive figure

Placement · Layering · Integration

The three-stage laundering cycle

Click any node · hover for tooltip

PlacementCash → systemLayeringMove · disguiseIntegrationClean re-entryClick each stage · red flags · example

Lessons

LESSON 0143 min read

Designing the analytics function: risk-scoring models and their failure modes

Figure 3.1 · Geography

One kickback, five jurisdictions

Each hop is a deliberate secrecy choice — a doctrine, a treaty, a professional silence. The final step is always a legitimate-looking asset.

HOP 1HOP 2HOP 3HOP 4LusakaSOURCENicosiaLAYER 1 · TRUSTLuxembourgLAYER 2 · HOLDCOJerseyLAYER 3 · SPVLondonINTEGRATION

Source · Schematic based on ICIJ Panama/Pandora Papers narratives

Every revenue authority or FIU eventually reaches the point where the volume of reports, returns and transactional data flowing in vastly exceeds the capacity of human analysts to review case by case, and the institution must decide how to build a risk-scoring or analytics function to triage that volume. I have advised on several such build-outs across African revenue authorities and FIUs, and the recurring lesson is that the technology is rarely the binding constraint — governance, data quality and institutional incentives are.

Start with what the analytics function is actually for. In an FIU, it typically means scoring incoming suspicious transaction reports (STRs) and currency transaction reports against a combination of rule-based red flags (structuring patterns, PEP linkages, high-risk-jurisdiction counterparties, rapid in-and-out movement) and, increasingly, statistical or machine-learning models trained on historical case outcomes to predict which reports are most likely to correspond to genuine underlying criminality. In a revenue authority, it typically means scoring filed returns and third-party data (CRS files, customs declarations, VAT invoicing data) to select cases for audit, again using a mix of rule-based indicators (mismatches between declared income and asset holdings, industry-specific margin anomalies, related-party transaction volumes inconsistent with arm's-length pricing) and predictive models trained on the outcomes of past audits.

The design choice between rule-based and machine-learning approaches is not merely technical; it has real institutional-integrity consequences. Rule-based systems are transparent and auditable, an official facing a legal challenge or an oversight review can explain exactly why a case was flagged, because the rule is legible. Machine-learning models, particularly more opaque architectures, can achieve higher predictive accuracy on held-out historical data but are harder to explain to an affected taxpayer, a court, or a legislative oversight committee, and; critically, are vulnerable to reproducing and amplifying whatever bias exists in the historical case outcomes they were trained on. If past audit selection was itself biased (say, disproportionately targeting small informal-sector traders because they were easier targets, while systematically under-auditing complex multinational structures because they required scarce specialist skills the authority lacked), a model trained on that history will learn and perpetuate exactly that bias, dressed up in the appearance of statistical objectivity. I tell every analytics team I advise: a model is not neutral merely because it is mathematical: it inherits every bias present in its training data, and unexamined deployment of such models in a fragile institutional-trust environment is a serious risk, not a shortcut.

A second, distinct failure mode is overfitting to known typologiesOverfitting to known typologiesA model's weakness in detecting genuinely novel schemes because it was trained only on previously identified and caught patterns. at the expense of detecting genuinely novel schemes. Risk-scoring models are trained on cases that were caught; by construction, they are weaker at flagging the structurally different scheme that hasn't yet been identified as a typology, because there is no positive training example for the model to learn from. This is precisely why FATF guidance and virtually every serious analytics practitioner insist that automated scoring must remain a triage tool that feeds a human analytical review, not a replacement for it, and why a meaningful proportion of an FIU or revenue authority's analytical capacity should remain devoted to open-ended, hypothesis-driven investigation of patterns the models were never trained to look for.

A third failure mode, common in under-resourced institutions, is what I call "scoring without capacityScoring without capacityThe failure mode of generating more correctly flagged high-risk cases than an institution has resources to investigate, creating an accountability exposure." — building a sophisticated risk-scoring system that correctly identifies far more high-risk cases than the institution has capacity to actually investigate, resulting in a growing backlog of correctly flagged but never-actioned cases. This is worse than not scoring at all in one specific respect: it creates a documented institutional record, discoverable in any later audit, mutual evaluation or oversight review, that the authority knew about the risk and failed to act — a serious accountability exposure. The correct design discipline is to size the scoring threshold to actual investigative capacity, accepting a higher score cut-off (and therefore fewer, more confidently flagged cases) rather than generating a flood of flagged cases the institution cannot realistically work.

Data quality is the unglamorous but decisive determinant of whether any of this works. Analytics built on inconsistent taxpayer identification numbers, unreconciled beneficial-ownership data, or STR narrative fields filled in inconsistently by reporting entities will simply produce garbage scores regardless of the sophistication of the modelling technique layered on top. I have seen institutions spend disproportionate resources on machine-learning model development while the underlying registry data, the beneficial-ownership register, the taxpayer master file — remains riddled with duplicate records, stale addresses and unresolved identity-matching problems that no model can compensate for. The sequencing discipline is: fix identity resolutionIdentity resolutionThe data-quality process of reliably matching records referring to the same individual or entity across disparate datasets and registries. and data quality first, deploy transparent rule-based scoringRule-based scoringA risk-scoring approach using explicit, legible indicators (e.g. structuring patterns, PEP status) that can be individually explained and audited. second, and only then layer in more sophisticated predictive modelling once there is a sufficient, well-governed data foundation and enough historical outcome data to train against responsibly.

Finally, governance of the model itself needs the same institutional rigour as governance of any other enforcement power. Every risk-scoring model deployed in a state institution with coercive powers over citizens' financial affairs should have a documented validation methodology, periodic bias and performance audits against demographic and sectoral breakdowns (not just aggregate accuracy), a clear human-override and appeal pathway for affected persons, and an accountable owner within the institution who can explain and defend the model's design and outcomes to oversight bodies, courts, and, where BO or personal data is involved — a data-protection authority. This last point is the subject of the next lesson.

Analytical matrixVERITAS · Dr. Lediga
LOWER PREDICTIVE NUANCE · HIGHER PREDICTIVE NUANCELOWER TRANSPARENCY · HIGHER TRANSPARENCYQUADRANT AAd hoc manual review
Transparent but slow and inconsistent.
QUADRANT BOpaque machine-learning model
High nuance, hard to explain or audit.
QUADRANT CRule-based scoring
Transparent, auditable, legible to oversight bodies.
QUADRANT DExplainable hybrid model
Combines rule-based transparency with model-assisted nuance.

Risk-scoring approach against transparency and predictive power

Institutions with fragile public trust should weight toward transparency even where it costs some predictive nuance.

Key terms

Rule-based scoring
A risk-scoring approach using explicit, legible indicators (e.g. structuring patterns, PEP status) that can be individually explained and audited.
Overfitting to known typologies
A model's weakness in detecting genuinely novel schemes because it was trained only on previously identified and caught patterns.
Scoring without capacity
The failure mode of generating more correctly flagged high-risk cases than an institution has resources to investigate, creating an accountability exposure.
Identity resolution
The data-quality process of reliably matching records referring to the same individual or entity across disparate datasets and registries.

Exercise

Design a governance checklist (8-10 items) that a revenue authority should apply before deploying any new risk-scoring model into live case-selection use, covering data quality, bias testing, capacity-sizing and appeal rights.

Mark complete (sign-in) →

Sources

Last reviewed 2026-08-01

  1. 01FATF Guidance on the Use of Digital Identity and analytics in AML/CFT contextsFATF, 2023.Guidance emphasising human oversight of automated risk-scoring tools.
  2. 02ATAF technical notes on tax administration risk analytics and audit case selectionAfrican Tax Administration Forum, 2022.
  3. 03OECD Forum on Tax Administration guidance on advanced analytics for compliance risk managementOECD, 2021.
Full bibliography →
LESSON 0242 min read

Data protection, CJEU proportionality, and measuring effectiveness against FATF's 11 Immediate Outcomes

Figure 4.2 · Attrition

From a million transactions to nine convictions

At every step, orders of magnitude are lost. The final ratio — under one-in-a-hundred-thousand — is the compliance system's honest self-portrait.

Transactions monitored1,200,000Rules-based alerts42,0003.5%Analyst-reviewed6,10014.5%STR / SAR filed84013.8%Referred to prosecutor627.4%Convictions / recoveries914.5%

Source · European FIU composite, 2018–2022

The analytics capability described in the previous lesson does not operate in a legal vacuum. It sits directly on top of personal data — beneficial-ownership information, financial-transaction records, and increasingly, biometric and behavioural data, and the legal limits on how that data can be collected, stored, matched and shared have shifted materially in the last several years, above all through the jurisprudence of the Court of Justice of the European Union (CJEU).

The decisive judgment for this field is the CJEU's ruling of 22 November 2022 in the joined cases C-37/20 and C-601/20 (WM and Sovim SA v Luxembourg Business Registers), which struck down the provision of the EU's Fifth Anti-Money Laundering Directive requiring that beneficial-ownership registers be accessible to the general public without any need to demonstrate a legitimate interest. The Court's reasoning is worth understanding precisely because it will keep shaping BO-register design well beyond the EU: the Court held that general public access to beneficial-ownership data constitutes a serious interference with the fundamental rights to respect for private life and to protection of personal data under Articles 7 and 8 of the EU Charter of Fundamental Rights, and that this interference was not proportionate to the (legitimate) objective of preventing money laundering, because unrestricted public access went further than was strictly necessary and lacked adequate safeguards against misuse of the data (including, the Court noted, use for purposes unrelated to AML, such as identifying wealthy individuals for unrelated commercial or even criminal purposes). The immediate practical effect was that several member states suspended or restricted public access to their BO registers pending redesign, and the subsequent EU AML Package; Regulation (EU) 2024/1624 (AMLR) and Directive (EU) 2024/1640 (AMLD6), was drafted with this ruling squarely in mind, reintroducing access on a "legitimate interest" basis (extending explicitly to journalists and civil-society organisations working on AML, among others) rather than unrestricted public access, an attempt to thread the needle between transparency objectives and the proportionality standard the Court set.

This matters directly for officials outside the EU, for two reasons. First, FATF's own R.24 revision (March 2022) and R.25 revision (February 2023) require countries to ensure beneficial-ownership information is adequate, accurate and available to competent authorities in a timely manner, but do not themselves mandate unrestricted public access — so jurisdictions designing or reforming BO registers now have a genuine choice, informed by the CJEU's proportionality reasoning even where the CJEU has no direct jurisdiction, about how to balance transparency against data-protection and even personal-security concerns (a live issue in jurisdictions where wealthy or politically prominent individuals face genuine kidnapping or extortion risk if beneficial-ownership data is fully public). Second, and more broadly, the proportionality methodology the Court applied — is the measure suitable to the objective, is it necessary (i.e., is there a less-restrictive alternative that achieves the same objective), and is it proportionate stricto sensu (does the severity of the interference outweigh the benefit)?, is a transferable analytical tool that any official designing a data-sharing, risk-scoring or surveillance-adjacent AML measure should apply to their own design choices, regardless of jurisdiction, because it captures a real and durable tension inherent in this field rather than a peculiarly European one.

With that legal grounding in place, the second half of this lesson turns to measuring whether an AML/CFT system actually works; a question distinct from, and in some respects more important than, whether it is merely compliant on paper. FATF's Effectiveness Methodology, used in every Mutual Evaluation since the 2013 revision of the assessment methodology, assesses each country against 11 Immediate Outcomes (IOs), covering: (IO1) risk understanding and coordination; (IO2) international cooperation; (IO3) supervision; (IO4) preventive measures by the private sector; (IO5) legal persons and arrangements (beneficial ownership); (IO6) financial intelligence use; (IO7) money-laundering investigation and prosecution; (IO8) confiscation; (IO9) terrorist-financing investigation and prosecution; (IO10) preventing terrorist-financing abuse of non-profit organisations and proliferation financing, and (IO11) proliferation-financing targeted financial sanctions. Each IO is rated High, Substantial, Moderate or Low effectiveness, a deliberately distinct scale from the parallel Technical Compliance ratings (Compliant/Largely Compliant/Partially Compliant/Non-Compliant) assessing whether the country's laws match the FATF standards on paper. The critical insight for officials designing a national programme is that Technical Compliance and Effectiveness frequently diverge sharply: a country can have excellent laws on the books (strong Technical Compliance) and still show Low effectiveness on the IOs that measure whether those laws produce real-world outcomes — genuine prosecutions, genuine confiscations, genuine use of financial intelligence to disrupt actual criminal networks. Most FSRB Mutual Evaluations of developing-country members over the past decade have shown exactly this pattern: reasonable-to-good Technical Compliance ratings following legislative reform programmes, but Moderate-to-Low Effectiveness ratings, because implementation, institutional capacity, and genuine enforcement follow-through lag well behind legislative drafting.

I use the IO framework directly with the revenue authorities and FIUs I advise as an internal self-assessment tool, independent of the formal Mutual Evaluation cycle (which typically runs only once every five to seven years per FSRB member): running an internal, honest IO6-and-IO7-focused self-assessment annually — how much financial intelligence is actually disseminated and actually used to open investigations (IO6), and how many of those investigations actually result in prosecution or conviction proportionate to the country's real ML/TF risk profile (IO7), surfaces implementation gaps far earlier than waiting for the next formal Mutual Evaluation to reveal them, and gives management a genuine internal accountability tool rather than a purely external, once-a-cycle compliance exercise.

Sequenced stepsVERITAS · Dr. Lediga
1Suitability
Is the measure capable of achieving the stated objective?
2Necessity
Is there a less-restrictive alternative achieving the same objective?
3Proportionality stricto sensu
Does the severity of the rights interference outweigh the benefit gained?

The CJEU's three-part proportionality test

Key terms

CJEU C-37/20 & C-601/20
The 22 November 2022 CJEU judgment invalidating unrestricted public access to EU beneficial-ownership registers on fundamental-rights proportionality grounds.
Proportionality test (suitability, necessity, proportionality stricto sensu)
The CJEU's three-part analytical framework for assessing whether an interference with a fundamental right is lawful.
FATF Immediate Outcomes (IOs)
The 11 effectiveness measures used in FATF Mutual Evaluations to assess whether an AML/CFT system produces real-world outcomes, rated High/Substantial/Moderate/Low.
Technical Compliance vs. Effectiveness
The two distinct FATF assessment scales; whether laws match the standards on paper, versus whether the system actually works in practice.

Exercise

Apply the CJEU's three-part proportionality test to a hypothetical national proposal to make beneficial-ownership data fully and unconditionally publicly searchable online, and write a 400-word legal-policy opinion on whether the proposal would likely survive proportionality scrutiny.

Mark complete (sign-in) →

Sources

Last reviewed 2026-08-01

  1. 01CJEU Joined Cases C-37/20 and C-601/20, WM and Sovim SA v Luxembourg Business RegistersCourt of Justice of the European Union, 2022.Invalidated unrestricted public BO-register access under Articles 7 and 8 of the EU Charter.
  2. 02Regulation (EU) 2024/1624 (AMLR) and Directive (EU) 2024/1640 (AMLD6)European Parliament and Council of the European Union, 2024.Reintroduced legitimate-interest-based BO access post-CJEU ruling.
  3. 03FATF Recommendation 24 (rev. March 2022) and Recommendation 25 (rev. February 2023)FATF, 2023.
  4. 04FATF Methodology for Assessing Technical Compliance and the Effectiveness of AML/CFT SystemsFATF, 2022.Defines the 11 Immediate Outcomes and rating scale.
Full bibliography →
LESSON 0341 min read

Greylisting dynamics, corruption of the enforcement function, and protecting the people who speak up

Figure 3.2 · Composition

Vehicle mix inside a typical layered portfolio

Where the money actually sits, aggregated across seven leaked incorporator datasets. British Virgin Islands entities remain dominant.

1,240ENTITIES · 7 LEAKSBritish Virgin Islands shellsRANK 01 · 42% of portfolioDelaware LLCsRANK 02 · 21% of portfolioCayman trustsRANK 03 · 15% of portfolioLuxembourg SARLsRANK 04 · 12% of portfolioOther vehiclesRANK 05 · 10% of portfolio

Source · ICIJ leak datasets (Panama, Paradise, Pandora); n = 1,240 entities

This closing lesson deals with the institutional-integrity dimension of AML/CFT work that technical training too often skips: what happens when the enforcement system's own credibility is externally challenged through greylisting, and what happens when the enforcement function itself becomes corrupted from within, and how the individuals who detect and report that corruption are, or are not — protected.

FATF's public "increased monitoring" list (commonly called the "grey list") identifies jurisdictions with strategic AML/CFT deficiencies that have committed to an action plan to address them, distinct from the much smaller "Call for Action" (black) list reserved for the most serious cases. Greylisting has become one of the most consequential reputational and market-access instruments in this field, because correspondent banks, institutional investors and multinational counterparties treat listing as a de facto risk signal irrespective of the underlying technical detail, often triggering de-riskingDe-riskingCorrespondent banks and counterparties withdrawing or restricting relationships with entities in listed or high-risk jurisdictions, often disproportionate to the specific deficiencies identified. (correspondent banks withdrawing relationships) that imposes real economic cost well beyond what the specific deficiencies identified would independently justify. South Africa was placed on the FATF grey list in February 2023, following its 2021 Mutual Evaluation Report which identified deficiencies including in the investigation and prosecution of serious money laundering, particularly in cases linked to state capture, and in beneficial-ownership transparency and supervision of certain sectors. South Africa's action plan focused on demonstrating improved investigation and prosecution of complex money-laundering and state-capture-linked cases, strengthening beneficial-ownership data at the Companies and Intellectual Property Commission, and improving supervisory effectiveness — and South Africa was removed from the list in October 2025, in a delisting that FATF and South African authorities both attributed to demonstrated improvement across those specific action-plan items, though observers noted the two-and-a-half-year listing period had already imposed real reputational and correspondent-banking costs.

Nigeria was placed on the grey list in February 2023 alongside South Africa, with an action plan addressing beneficial-ownership information, financial intelligence use, and terrorist-financing-related supervision and investigation, reflecting deficiencies identified in its own Mutual Evaluation. Kenya was placed on the grey list in February 2024, with an action plan covering risk-based supervision of non-bank financial institutions and designated non-financial businesses and professions, beneficial-ownership transparency, and improving the investigation and prosecution of money laundering and terrorist-financing cases consistent with Kenya's risk profile. The pattern across all three cases is instructive and consistent with the Technical-Compliance-versus-Effectiveness divergence discussed in the previous lesson: each listing followed a Mutual Evaluation identifying Effectiveness gaps, real-world enforcement, beneficial-ownership data quality, and investigation/prosecution outcomes; rather than purely legislative deficiencies, confirming that greylisting today is substantially an effectiveness-and-implementation instrument, not merely a legislative-drafting scorecard.

The lesson for programme designers is direct: an action plan built around the specific Effectiveness gaps a Mutual Evaluation identified, with visible, evidenced improvement in real prosecutions, real confiscations, and real beneficial-ownership data quality (not just amended statutes), is what FATF's ICRG process and the relevant FSRB actually assess when considering delisting, and jurisdictions that treat greylisting purely as a legislative-drafting exercise, without the accompanying institutional capacity and enforcement follow-through, extend their own listing period unnecessarily.

The final and, in my view, most important theme of this entire Mastery level is the corruption of the enforcement function itself. Every framework covered across this curriculum, customer due diligence, suspicious-transaction reporting, beneficial-ownership registers, exchange of information, asset recovery, risk-scoring analytics — depends on the integrity of the officials and institutions operating it. Where the enforcement function itself is captured — where FIU staff leak STRs to targets, where prosecutors selectively decline cases involving politically connected individuals, where customs or tax officials extract bribes to suppress adverse findings, where asset-recovery proceeds are themselves diverted before reaching any legitimate use, the entire apparatus becomes not simply ineffective but actively harmful, because it retains the legitimating appearance of a functioning AML/CFT system while providing cover for exactly the conduct it purports to prevent. State-capture-era South Africa is the most thoroughly documented recent example: the Zondo Commission's findings detailed how key law-enforcement and revenue institutions were deliberately weakened and, in some documented instances, actively used to shield politically connected individuals and networks from investigation over an extended period, a central input into the Effectiveness deficiencies that later drove the FATF greylisting itself.

Protecting the people who detect and report this internal corruption is therefore not a peripheral human-resources concern; it is a structural precondition for the entire system's integrity. Whistleblower and investigator protection needs to address several distinct risks: protection from retaliatory dismissal or demotion (requiring clear statutory protection and, in the strongest models, reversal of the burden onto the employer to justify any adverse action taken against a report-linked employee); protection from physical threat, which is a real and, in several documented African and Latin American cases, lethal risk for investigators and whistleblowers exposing organised-crime-linked corruption, requiring genuine witness and investigator protection programme capacity, not merely a statutory promise; protection of anonymity and confidentiality of the reporting channel itself, including internal-affairs and external-oversight-body reporting routes independent of the chain of command the report concerns (since reporting to a compromised superior defeats the purpose entirely), and career protection, ensuring that officials who make politically difficult but professionally correct decisions are not systematically passed over for promotion or transferred to marginal postings, a subtler but pervasive form of institutional discouragement that formal whistleblower statutes rarely reach. I close this level with this point deliberately: every technical instrument in this curriculum is only as good as the willingness of an individual official, at some specific moment, to apply it honestly against pressure not to, and building institutions that protect and reward that individual choice is, in the end, the actual work of AML/CFT reform.

ComparisonVERITAS · Dr. Lediga
Common deficiencies cited01
Weak investigation/prosecution of complex ML cases
02
Beneficial-ownership data quality gaps
03
Supervisory effectiveness gaps
04
State-capture-linked enforcement failures (SA specifically)
Delisting requirements01
Demonstrated real prosecutions and convictions
02
Improved BO registry accuracy and access
03
Evidenced supervisory follow-through
04
Sustained action-plan implementation over multiple ICRG review cycles

2023-2025 African greylistings: common Effectiveness-gap pattern

South Africa: listed Feb 2023, delisted Oct 2025. Nigeria: listed Feb 2023. Kenya: listed Feb 2024.

Key terms

FATF grey list (increased monitoring)
FATF's public list of jurisdictions with strategic AML/CFT deficiencies under an agreed action plan, distinct from the more severe 'Call for Action' black list.
De-risking
Correspondent banks and counterparties withdrawing or restricting relationships with entities in listed or high-risk jurisdictions, often disproportionate to the specific deficiencies identified.
Capture of the enforcement function
The corruption of AML/CFT institutions themselves such that they provide legitimating cover for, rather than genuine prevention of, illicit conduct.
Reversed-burden retaliation protection
A whistleblower-protection design in which the employer must justify any adverse action against a report-linked employee, rather than the employee bearing the burden of proving retaliation.

Exercise

Draft the outline of a delisting action plan (one page) for a hypothetical grey-listed jurisdiction, structured explicitly around Effectiveness (Immediate Outcome) gaps rather than legislative amendments, modelled on the South Africa 2023-2025 pattern.

Mark complete (sign-in) →

Sources

Last reviewed 2026-08-01

  1. 01FATF Public Statement: Jurisdictions under Increased MonitoringFATF, 2023.South Africa and Nigeria added to the grey list, February 2023.
  2. 02FATF Public Statement: Jurisdictions under Increased MonitoringFATF, 2024.Kenya added to the grey list, February 2024.
  3. 03FATF Statement on South Africa delistingFATF, 2025.South Africa removed from increased monitoring, October 2025.
  4. 04Judicial Commission of Inquiry into Allegations of State Capture (Zondo Commission) ReportsRepublic of South Africa, 2022.Documented capture and weakening of law-enforcement and revenue institutions.
  5. 05ESAAMLG Mutual Evaluation Report of South AfricaESAAMLG, 2021.Effectiveness findings underlying the 2023 FATF grey-listing decision.
Full bibliography →

Case study

South Africa: from 2023 grey-listing to 2025 delisting

Jurisdiction: South Africa

South Africa's February 2023 FATF grey-listing followed a 2021 Mutual Evaluation Report exposing Effectiveness gaps closely linked to state-capture-era institutional weakening. Its October 2025 delisting followed a structured action plan focused on demonstrable enforcement outcomes rather than legislative amendment alone.

Facts

  • The 2021 ESAAMLG Mutual Evaluation Report found South Africa Largely Compliant or Compliant on most Technical Compliance items but Low or Moderate on several Immediate Outcomes, including investigation/prosecution of money laundering and beneficial-ownership transparency.
  • FATF placed South Africa on the increased-monitoring (grey) list in February 2023, citing deficiencies including insufficient investigation and prosecution of serious and complex money laundering, notably state-capture-linked cases.
  • The Zondo Commission's findings, published in stages through 2022, documented how key institutions including SARS and elements of the National Prosecuting Authority had been deliberately weakened during the state-capture period.
  • South Africa's action plan included strengthening beneficial-ownership data at CIPC, improving risk-based supervision, and, centrally — demonstrating an increased volume and quality of money-laundering investigations, prosecutions and confiscations.
  • Over the listing period, National Treasury and law-enforcement agencies published periodic progress reports tracking action-plan items against ICRG review cycles.
  • FATF removed South Africa from the grey list in October 2025, citing substantial completion of the action plan's items, though correspondent-banking and reputational effects of the roughly two-and-a-half-year listing period had already been incurred.

Investigative questions

  1. Why did South Africa's reasonable Technical Compliance ratings not prevent grey-listing, and what does this confirm about the primacy of Effectiveness in the modern FATF process?
  2. What specific link exists between the Zondo Commission's institutional-capture findings and the Effectiveness deficiencies cited in the 2021 Mutual Evaluation?
  3. What evidence would FATF's ICRG process realistically require to be satisfied that investigation and prosecution capacity had genuinely improved, rather than merely that new legislation had been passed?
  4. What lessons does the roughly two-and-a-half-year listing-to-delisting timeline offer other grey-listed jurisdictions (e.g. Nigeria, Kenya) about realistic delisting horizons?

Learning points

  • Greylisting decisions turn substantially on Effectiveness (Immediate Outcome) findings, not primarily on Technical Compliance.
  • Institutional capture directly produces the enforcement-outcome gaps that trigger and prolong greylisting.
  • Delisting requires demonstrated real-world enforcement outcomes sustained across multiple ICRG review cycles, not a single legislative reform package.
  • The economic cost of de-risking during a listing period accrues regardless of the eventual delisting outcome, reinforcing the value of front-loaded institutional reform.

Where the field disagrees

What should an AML programme be measured on?

Counting STRs measures activity, not outcomes. Counting convictions measures prosecutorial capacity more than AML quality. Counting recovered assets favours a few large cases. Every metric I have seen distorts behaviour in a predictable direction, and I have not found one that does not. Design your dashboard knowing it will be gamed.

Lecturer's note · not examinable, but argue it in your essay

Assessment

Module quiz

8 multiple-choice questions. Pass at 70%. Scores are saved to your dashboard.

Begin quiz →

Written work

Essay prompts

  • Q1Assess whether the CJEU's proportionality reasoning in C-37/20 & C-601/20 offers a transferable framework for non-EU jurisdictions designing beneficial-ownership access regimes, weighing transparency objectives against genuine personal-security and data-protection concerns.
  • Q2Compare South Africa's 2023-2025 greylisting trajectory with Nigeria's and Kenya's ongoing action plans, and assess what each case demonstrates about the relationship between institutional capture and FATF Effectiveness ratings.
  • Q3Argue for or against the proposition that no risk-scoring or analytics system should be deployed in a fragile-institutional-trust environment without a mandatory, externally-audited bias and capacity-sizing review prior to live deployment.
Submit essay →

Assignment

"Design a complete institutional-integrity annex (1,000-1,400 words) for a national AML/CFT reform programme, covering: (1) a risk-scoring governance checklist addressing bias, capacity-sizing and appeal rights; (2) a BO-register access-tier design informed by CJEU proportionality reasoning; (3) an internal annual self-assessment protocol against IO6 and IO7, and (4) a whistleblower and investigator protection framework addressing all four risk categories identified in this module."