MONEYVAL. FATF. CFATF.

Different names appear across different jurisdictions, but behind them sits the same global system.

The Financial Action Task Force sets the international standards for combating money laundering, terrorist financing and proliferation financing. FATF itself assesses some jurisdictions. Regional bodies including MONEYVAL and the Caribbean Financial Action Task Force assess others using the same underlying standards and broadly common evaluation framework. For financial services businesses, it can all feel several steps removed from the boardroom..... It isn't.

Because when an international assessment identifies a weakness in a jurisdiction, the consequences rarely remain at government or regulator level.

They move. Into legislation. Into regulatory handbooks. Into supervisory priorities. Into thematic reviews. Into enforcement and ultimately, into the boardroom.

Across the thirteen jurisdictions currently covered by MyDirector-OS, that process is happening at very different stages.

Some have recently completed major evaluations. Some are implementing the findings. Some are preparing for their next assessment. Others are already experiencing the consequences of weaknesses identified through the process. But the direction is remarkably consistent.

The question is increasingly not whether a framework exists. It is whether you can demonstrate that it works.

The standard itself is changing That distinction matters because the international assessment process is changing too.

FATF's fifth round of mutual evaluations places significant emphasis on effectiveness. Assessors are not simply examining whether laws, regulations and policies have been introduced. They are looking for evidence that those measures are being implemented and are producing results.

The evaluation cycle is also becoming shorter and more targeted towards the areas of greatest risk. That changes the dynamic considerably.

A jurisdiction can have sophisticated legislation, detailed regulatory handbooks and well-designed compliance frameworks and still face difficult questions if it cannot demonstrate that those arrangements work in practice.

And if a jurisdiction needs to demonstrate effectiveness, its regulators need evidence from the firms they supervise. Those firms, in turn, need evidence from the people responsible for governing them.

That is where an international standard becomes a boardroom issue.

The Channel Islands show what happens after the assessment Jersey and Guernsey provide particularly good examples because both have recently completed MONEYVAL evaluations, but are now at different stages of responding to them.

Jersey's 2024 assessment was exceptionally strong from a technical compliance perspective. It was rated Compliant or Largely Compliant with 39 of the 40 FATF Recommendations.

But a strong assessment did not mean the process stopped. The JFSC subsequently consulted on changes to its AML/CFT/CPF Handbook arising from MONEYVAL's recommended actions. Among them was the treatment of complex structures. The resulting approach is revealing.

The revised guidance, effective from 31 May 2026, makes clear that complexity alone does not automatically make a structure high risk or require enhanced due diligence. That is a relatively small regulatory change, but it illustrates something much larger.

International assessment identifies an issue. The regulator responds. Industry practice changes. And boards need to understand the difference.

Guernsey is following its own post-evaluation path. Its MONEYVAL evaluation was published in early 2025. In July 2026, the GFSC and the Policy & Resources Committee launched a consultation proposing changes to both the Handbook on Countering Financial Crime and the underlying legislative framework specifically to address MONEYVAL's recommended actions.

That consultation remains open until October.

For a Guernsey director, MONEYVAL therefore isn't a report sitting somewhere on a government website.

Its findings are actively feeding into the rules and supervisory framework against which businesses will be judged.

The Isle of Man is about to experience the assessment itself The Isle of Man sits at a different point in the cycle. Its MONEYVAL on-site assessment is scheduled for 28 September to 9 October 2026. The significance is greater than simply undergoing another periodic review.

The Island's previous on-site assessment took place in 2016. Since then, the international methodology has evolved significantly, with far greater emphasis on demonstrating effectiveness.

The Isle of Man already performs strongly on technical compliance. It is positively rated on 39 of the 40 FATF Recommendations. The challenge now is different. Can the jurisdiction demonstrate that the system works in practice? That requires evidence from government, law enforcement and regulators. But it also requires evidence from industry.

Policies are part of that evidence. Risk assessments are part of it. Suspicious activity reporting is part of it. Governance and oversight are part of it. For boards operating in a jurisdiction undergoing an evaluation, that distinction matters.

Having the framework is no longer the end of the question. Being able to demonstrate its effective operation is increasingly the beginning of it.

The Caribbean shows what happens when weaknesses become strategic The same cycle can be seen across Cayman, Bermuda and the British Virgin Islands. But the BVI demonstrates what happens when the stakes become considerably higher. The BVI was placed under FATF increased monitoring, commonly referred to as the grey list, in June 2025.

It has since continued implementing an agreed action plan. FATF's June 2026 update records progress but identifies areas where further work remains necessary, including risk-based supervision of trust and company service providers, investment businesses and virtual asset service providers; beneficial ownership information; suspicious activity reporting; money laundering investigations and prosecutions; and asset recovery.

That is the distinction between technical compliance and effectiveness in its clearest form. Rules can be improved relatively quickly.

Demonstrating that they consistently produce the intended outcome takes longer.

Cayman is at an earlier stage. Its next CFATF mutual evaluation is scheduled to begin in 2027, but preparation is already well underway. Its 2025-2026 National Risk Assessment is explicitly intended to support that process and covers financial institutions, securities, insurance, virtual assets, trust and company service providers, real estate and legal professionals.

Again, the assessment may be national. The evidence base is not.

Bermuda provides another variation. Its fifth-round CFATF evaluation begins in October 2026. Ahead of it, Bermuda has been reviewing its AML framework against revised FATF standards and has already introduced significant changes, including a new beneficial ownership regime.

The technical compliance submissions are due in October. The process then moves towards examination of effectiveness through data, case studies and evidence of real-world implementation. That phrase matters.

Real-world implementation.

It is becoming increasingly difficult to separate regulatory compliance from the evidence demonstrating that compliance actually works.

Singapore shows that even a strong result produces a next agenda Singapore's 2026 FATF/APG assessment provides another useful example. Overall, Singapore demonstrated a high level of effectiveness across much of its AML/CFT/CPF framework.

But the assessment also identified areas requiring improvement. Most notably, FATF's technical assessment rated both Recommendation 24, covering transparency and beneficial ownership of legal persons, and Recommendation 25, covering legal arrangements, as Partially Compliant.

The corresponding effectiveness outcome was rated Moderate. For directors, the important lesson is not whether Singapore's overall result was good or bad. It is what happens next.

Because the weaknesses identified by an international assessment have a habit of becoming tomorrow's legislative amendments, supervisory priorities, regulatory guidance and boardroom questions. That pattern repeats across jurisdictions.

Luxembourg shows the assessment continuing after the assessors leave Luxembourg received a strong FATF assessment in 2023, with FATF describing its AML/CFT framework as solid and highlighting strong domestic coordination and access to beneficial ownership information.

But the assessment also identified areas requiring further attention. The regulatory response has continued. In January 2026, the CSSF published an updated money laundering and terrorist financing risk assessment for professionals providing corporate services.

The document expressly draws on Luxembourg's 2023 FATF evaluation, alongside subsequent national and sectoral risk assessments. More importantly, the CSSF states that supervised entities providing corporate services are expected to integrate its findings, conclusions and recommendations into their own AML/CFT frameworks. That is the transmission mechanism in plain sight.

International assessment becomes national assessment. National assessment becomes regulatory expectation. Regulatory expectation becomes an obligation for the firm to respond.

And somewhere within that firm sits a board responsible for overseeing whether that response is adequate.

The UAE demonstrates how quickly the cycle begins again The UAE was removed from FATF's increased-monitoring list in February 2024 following significant reform. That was not the end of the process. Its next FATF assessment cycle is already underway, with the timetable indicating a 2026 on-site period and plenary consideration expected in 2027.

Meanwhile, the regulatory frameworks within its financial centres continue to develop. ADGM, for example, introduced whistleblower protection requirements requiring all registered entities to have appropriate and effective arrangements in place by 31 May 2025, with additional written policy requirements applying to specified categories of firms.

It has also continued issuing specific regulatory communications on beneficial ownership. Again, the broader pattern matters more than any single rule.

Regulatory improvement is no longer a project with a finishing date. It is a cycle.

Then there is the United States The United States provides perhaps the most interesting counterpoint. It is undergoing its fifth-round FATF evaluation at a time when its approach to beneficial ownership reporting has changed substantially.

In March 2025, FinCEN amended the Corporate Transparency Act reporting regime so that entities created in the United States, and their beneficial owners, are exempt from beneficial ownership information reporting to FinCEN. The remaining reporting regime is principally directed at qualifying foreign entities registered to do business in the United States.

That matters because beneficial ownership has historically been an area of FATF concern for the US. In 2024, FATF upgraded the United States on Recommendation 24, covering transparency and beneficial ownership of legal persons, from Non-Compliant to Largely Compliant following reforms.

Its next evaluation therefore takes place against a materially changed domestic framework. What FATF ultimately concludes should be watched carefully. It provides an unusual test of the same underlying question being asked everywhere else.

Not simply what rules exist, but whether the system produces the outcomes the international standard expects.

What happens next matters more than the score It is easy to reduce mutual evaluations to league tables. How many Recommendations were Compliant? How many were Largely Compliant? Was the jurisdiction placed into regular or enhanced follow-up? Was it grey-listed? Those things matter. But for directors, they are not necessarily the most useful part of the process.

The more important question is what happens next.

A weakness in beneficial ownership can become a new register, verification requirement or supervisory priority. A weakness in risk-based supervision can become more inspections, more information requests and more detailed scrutiny of business risk assessments. Weaknesses in suspicious activity reporting can lead to increased expectations around escalation, training, governance and management information. Concerns around legal persons and complex structures can change customer risk assessments and due diligence expectations. Weaknesses around sanctions or proliferation financing can move rapidly into policies, controls, board reporting and testing. The mutual evaluation report is therefore not the end product.

It is often the beginning of the next regulatory cycle.

And that cycle eventually reaches the board This is where the subject becomes much more relevant to directors. A director does not need to memorise every FATF Recommendation. They do not need to become an expert in MONEYVAL methodology. And they certainly do not need to follow every international assessment taking place around the world. But they should understand where the jurisdictions in which they hold appointments sit within that cycle. Has the jurisdiction recently been assessed? What weaknesses were identified? What recommended actions followed? How has the regulator responded? Has legislation changed? Has the Handbook changed? Have supervisory priorities changed?

And, most importantly:

Has the governance of the entity changed with them?

Because once a regulatory expectation changes, yesterday's good governance may no longer be sufficient evidence of today's compliance.

That has implications for the information directors receive, the questions they ask, the assurances they seek and the evidence recorded in the minutes.

It may mean asking whether a business risk assessment has been updated following a National Risk Assessment. Whether beneficial ownership information has been independently verified where required. Whether changes to enhanced due diligence requirements have actually flowed through into procedures. Whether regulatory findings have been translated into board reporting. Whether remediation has been completed. And whether the board has evidence to demonstrate that it challenged and oversaw that process.

That is a very different exercise from simply asking:

“Are we compliant?”

Regulation does not change on one timetable There is a further problem for modern directors. These changes are not happening simultaneously. Jersey is responding to one assessment. Guernsey is implementing recommendations from another. The Isle of Man is about to enter its on-site assessment. Bermuda is entering a new evaluation cycle. Cayman is preparing for 2027. The BVI is working through an FATF action plan. Singapore is digesting the findings of a newly completed fifth-round assessment. Luxembourg continues translating its 2023 assessment into sector-specific supervisory expectations. The UAE has moved from grey-list remediation into another assessment cycle. And the US is being assessed against a framework that has itself materially changed.

For a director with appointments across jurisdictions, keeping track of that moving landscape becomes a governance challenge in its own right. Because the relevant question is not:

What does FATF say? It is:

What does FATF's assessment mean for this entity, in this jurisdiction, under this regulator, today?

That is a much harder question.

From global standard to individual director This is one of the reasons MyDirector-OS was built around jurisdiction-specific regulatory frameworks rather than generic governance information. The international standard matters.

But directors operate at the point where that standard has already travelled through a national government, legislation, a regulator, a Handbook, guidance and supervisory practice.

That final layer is what matters when sitting around a board table.

MyDirector-OS maintains the regulatory framework relevant to each jurisdiction it covers, while BoardLens reviews the information presented to a director through the regulatory lens applicable to that particular appointment.

The Director's Assistant allows the director to interrogate that framework using grounded regulatory sources rather than relying on a generic answer about what good AML governance might look like somewhere else.

Because there is an important difference between knowing the global standard and knowing what is expected of you.

Across the jurisdictions covered by MyDirector-OS, the assessment bodies may differ.

The evaluation dates differ. The findings differ. The regulatory responses differ. But the direction is becoming increasingly difficult to miss.

Have the framework.

Apply the framework.

Test the framework.

Understand whether it works.

And be able to evidence that it does.

For directors, knowing where their jurisdiction sits within that cycle is no longer peripheral regulatory knowledge. It is becoming part of understanding the environment in which they are expected to govern. Because when the regulator is being asked to demonstrate effectiveness, the same question eventually reaches the firms it supervises. And from there, it reaches the board.