- 50 Percent Rule
- OFAC ownership guidance under which certain entities owned 50 percent or more, directly or indirectly in aggregate, by blocked persons are treated as blocked.
Modules 06- Account takeover
- Unauthorized access to an account, often using compromised credentials, device, session, or social-engineering techniques.
Modules 09- Accountable action
- A decision or operational act made by a person or permitted function with authority, evidence, and responsibility for its consequences.
Modules 16- Action acknowledgement
- A response or record from the destination process confirming that an approved financial-crime action was executed, rejected, or remains pending.
Modules 15- Activity-based regulation
- A regulatory approach that evaluates what a person or entity does rather than relying only on the technology label or incorporation form.
Modules 12- Address attribution
- A documented assignment of a blockchain address or cluster to a person, service, or category, including source and confidence.
Modules 12- Adverse media
- Publicly available information that may indicate financial-crime, integrity, or related risk and requires source-aware, identity-aware assessment.
Modules 04- Agentic workflow
- A bounded workflow in which an AI system can plan, retrieve, call approved tools, or execute permitted tasks under controlled authority.
Modules 14- Alert
- A system-generated prompt for review; it is not by itself a conclusion of suspicious activity.
Modules 07- AML
- Anti-money laundering: measures intended to prevent and detect the use of the financial system to conceal, move, or benefit from illicit proceeds.
Modules 01- AMLA
- The Authority for Anti-Money Laundering and Countering the Financing of Terrorism established by Regulation (EU) 2024/1620.
Modules 20- AMLD6
- Directive (EU) 2024/1640 on member-state AML/CFT mechanisms; distinct from earlier instruments commonly called AMLD6 in other contexts.
Modules 20- AMLO
- Hong Kong’s Anti-Money Laundering and Counter-Terrorist Financing Ordinance (Cap. 615).
Modules 23, 24- AMLR
- Regulation (EU) 2024/1624, the EU Anti-Money Laundering Regulation.
Modules 20- APP scam
- Authorised push payment scam, where a payer is deceived into authorising a payment.
Modules 21- Applicability assessment
- A documented determination of how a global standard, legal requirement, policy, product, or service applies to a local entity or market.
Modules 16- APTCP
- Japan’s Act on Prevention of Transfer of Criminal Proceeds.
Modules 23- Assessment methodology
- FATF's framework for assessing technical compliance with its Recommendations and the effectiveness of AML/CFT/CPF systems.
Modules 02- Assurance
- Independent or appropriately challenging evaluation of whether governance, risk management, and controls are designed and operate as intended.
Modules 17- Attribute-level lineage
- Lineage recorded at the specific data-attribute level, including source, transformation, permission, quality, and decision use.
Modules 13- AUSTRAC
- Australia’s financial-intelligence and AML/CTF regulator.
Modules 24- Authoritative source
- The designated reliable origin for a defined fact or status, within a stated purpose and time.
Modules 15- Authorized push payment scam
- A scam in which a customer is manipulated into authorizing a payment; customer authorization does not settle every legal or conduct question.
Modules 09- Authorized representative
- A person or entity with documented power to act for a customer. Authority is distinct from ownership or beneficial ownership.
Modules 05- Back-testing
- Retrospective testing of control performance against historical data or known events.
Modules 07- Beneficial owner
- A natural person or persons who ultimately own or control a customer and/or the natural person on whose behalf a transaction or activity is being conducted, as defined by the applicable legal or policy regime.
Modules 05- Beneficiary
- The intended recipient of a transfer; beneficiary identity, account, and institution data may have distinct quality issues.
Modules 10- Beneficiary risk
- Risk associated with the receiving end of a payment based on behavior, links, controls, and contextual facts.
Modules 09- Binding
- The degree to which a person presenting evidence or operating a session is linked to the claimed identity.
Modules 04- Blocking or freezing
- A legally required restriction on dealing with property or funds under an applicable sanctions regime; effect depends on the regime.
Modules 06- Bridge
- A mechanism that enables assets or representations of value to move between blockchain ecosystems; it can add technical, counterparty, and tracing complexity.
Modules 12- BSA
- The Bank Secrecy Act, the U.S. statutory recordkeeping and reporting framework administered in significant part by FinCEN.
Modules 19- Business-wide risk assessment
- A documented assessment of the enterprise's exposure across products, customers, channels, geographies, legal entities, and other relevant factors.
Modules 03- Calibration
- The relationship between model score/probability and observed outcome in the defined use population.
Modules 14- Capacity
- The risk-appropriate ability to make required decisions at required quality and speed; more than staffed headcount.
Modules 18- Case package
- A structured evidence set assembled for a defined investigation, escalation, report, authority request, or decision.
Modules 13- Case strategy
- A documented plan that states scope, questions, evidence, assumptions, owners, timing, and escalation triggers.
Modules 08- CDD
- Customer due diligence; risk-based measures to understand and manage a customer relationship.
Modules 04- Central register
- A registry operated by or for a public authority that holds specified information. Its access, coverage, verification, and legal effect vary by jurisdiction.
Modules 05- CFT
- Countering the financing of terrorism: measures addressing the collection, movement, use, or availability of funds or economic resources connected to terrorist activity, subject to applicable law.
Modules 01- Chapter X
- Treasury regulations in 31 CFR Chapter X implementing many BSA obligations.
Modules 19- CIP
- Customer Identification Program; a specific U.S. regulatory term for certain financial institutions, including banks.
Modules 04- Close associate / RCA
- A person known to have a close relationship with a PEP, as defined under an applicable regime; terminology varies.
Modules 04- Closure validation
- Evidence-based confirmation that remediation addresses scope, cause, outcome, and recurrence risk.
Modules 17- Cluster
- A set of addresses analytically associated with one another under a stated method; it is not inherently a legal person or a verified owner.
Modules 12- CNBV
- Mexico’s Comisión Nacional Bancaria y de Valores, a financial-sector supervisory authority with AML/CFT roles within its remit.
Modules 22- Conceptual soundness
- Whether a model's theory, assumptions, methodology, and intended use are appropriate for the stated decision.
Modules 14- Configuration debt
- Accumulated undocumented or weakly governed parameter, rule, interface, and exception changes that raise control risk.
Modules 15- Control
- The power to direct the management, policy, or material decisions of an entity or arrangement. Control can arise through ownership, voting, appointment rights, contract, trustee/protector powers, or other means.
Modules 05- Control coverage
- The extent to which the population, data, routes, and timing intended by a control are actually reached.
Modules 03- Control economics
- The analysis of cost, risk reduction, quality, customer friction, and resilience across a financial-crime decision path.
Modules 18- Control hypothesis
- A precise statement of population, trigger, expected action, owner, timing, evidence, and outcome that can be tested.
Modules 17- Control object
- A business/data/evidence object that a financial-crime control depends on, such as identity, ownership, transaction, case, control, or obligation.
Modules 01- Control objective
- The risk-reduction or legal-compliance result a control is designed to achieve, expressed independently from a particular system or procedure.
Modules 02, 03- Control owner
- The named person accountable for a control's design, operation, monitoring, evidence, and remediation.
Modules 16- Control spine
- The connected seven-stage enterprise framework used in this module: understand exposure; prevent; interdict; detect; investigate; act/report/restrict; assure and redesign.
Modules 01- Control stack
- The connected data, technology, workflow, people, policy, evidence, and assurance components that deliver a control outcome.
Modules 15- Correspondent bank
- A bank that provides services, such as payments, clearing, settlement, or FX access, to another financial institution.
Modules 10- Coverage
- The extent to which all intended records, entities, events, products, channels, and time periods reach a control.
Modules 14- CPF
- Counter-proliferation financing: measures addressing financing and related financial activity connected to the proliferation of weapons of mass destruction and associated targeted financial sanctions frameworks.
Modules 01- Critical activity
- An activity whose failure would materially impair legal compliance, control effectiveness, customer protection, or operational resilience.
Modules 18- Critical data element
- A data item whose failure would materially impair a financial-crime decision, control, report, or evidence package.
Modules 13- Crypto-asset service provider
- A regulated term under EU MiCA for in-scope crypto-asset services; it should not be assumed to be identical to FATF's VASP definition.
Modules 12- Customer declaration
- Information supplied by or for the customer. It may be required and useful, but should be distinguished from independent corroboration.
Modules 05- Customer risk profile
- A documented understanding of risk factors, purpose, expected activity, and control needs relevant to a customer relationship.
Modules 04- Customer vulnerability
- A context that can affect a person's ability to recognize, resist, or recover from financial harm and requires careful, non-stigmatizing handling.
Modules 09- DAML
- Defence Against Money Laundering, a UKFIU/NCA process that requires careful fact- and law-specific use.
Modules 21- Data contract
- A controlled agreement describing interface fields, quality, timing, use, error handling, ownership, and reconciliation.
Modules 15- Data localization
- A requirement or constraint related to where data must be stored, processed, accessed, or transferred.
Modules 13- Data provenance
- The documented origin and history of data, including source, custody, transformations, and use.
Modules 13- Decision path
- The linked process, data, authority, evidence, and assurance steps that produce an operational financial-crime decision.
Modules 18- DeFi
- Decentralized-finance arrangements using distributed-ledger technology and smart contracts; their risk treatment depends on functions and persons with control or influence.
Modules 12- Degraded mode
- A defined way to operate a service when normal capability is unavailable or unsafe, with limits, authority, and reconciliation.
Modules 15- Delegation
- Assignment of an activity or decision authority under a defined mandate while retained accountability and oversight remain clear.
Modules 16- Design effectiveness
- Whether a control, if operated as intended, is capable of addressing its stated risk and objective.
Modules 17- DIA
- New Zealand Department of Internal Affairs, the sole AML/CFT supervisor from 1 July 2026 according to current official sources.
Modules 24- Digital-currency identifier
- A blockchain address or related identifier that can be relevant to a sanctions, fraud, or AML/CFT control.
Modules 12- Direct applicability
- The characteristic of an EU regulation that applies as EU law without the same transposition mechanism as a directive, subject to its own provisions and dates.
Modules 20- Disposition
- The recorded case decision and rationale; it must be distinct from any later account, payment, or reporting action.
Modules 08- Drift
- Material change in data, relationships, performance, use population, workflow, or outcome that can affect model behavior.
Modules 14- Dual-use item
- An item that can have both civil and military applications and may be subject to export-control rules.
Modules 11- Economic-security risk
- Enterprise risk covering sanctions, export controls, trade, national-security, and related legal or policy exposure.
Modules 06- EDD
- Enhanced due diligence; additional risk-based or required measures for higher-risk relationships or events.
Modules 04- Effective date
- The date on which an attribute or relationship began or ceased to be true. It is different from a source retrieval date.
Modules 05- Effectiveness
- The extent to which a system produces intended outcomes in its actual risk context; distinct from the formal presence of laws, policies, or controls.
Modules 02- Effectiveness outcome
- A measurable or evidence-supported indication that a control has produced its intended prevention, detection, action, reporting, or risk-reduction result.
Modules 17- End use
- The intended application or use of goods, technology, or services that can affect export-control or sanctions risk.
Modules 11- End user
- The ultimate user of goods, technology, or services; it may differ from purchaser, consignee, intermediary, or freight forwarder.
Modules 11- Entity List
- A U.S. BIS list that can impose licensing requirements and related restrictions for specified entities and end users.
Modules 06- Entity resolution
- The process of deciding whether records across sources refer to the same legal person, arrangement, or natural person.
Modules 05, 14- Event-driven review
- A review triggered by a material change or signal, rather than solely by a scheduled date.
Modules 04- Evidence fallback
- A lawful alternative information pattern used when the normal data path is unavailable or restricted.
Modules 13- Evidence lineage
- The ability to trace a conclusion, decision, action, or report to its source data, methodology, policy/legal basis, analysis, and approval record.
Modules 01, 05- Evidence replay
- Reconstruction of a past decision using contemporaneous source data, versions, analysis, authority, and action proof.
Modules 15- Exception
- A controlled, time-bound deviation from an approved rule or procedure.
Modules 03- Exception rate
- The share of work that cannot follow the standard path and needs additional evidence, specialist judgment, or escalation.
Modules 18- Explainability
- The ability to understand and communicate the evidence, logic, assumptions, and limitations relevant to a model-supported result.
Modules 14- Export
- A term whose scope depends on the applicable regime and may include export, reexport, transfer, or release of controlled items or technology.
Modules 06- Fact table
- A structured record that separates source facts, dates, amounts, parties, transactions, sources, and confidence from inference.
Modules 08- Fallback
- A tested alternate process or capability used to preserve a required control outcome during a disruption or unsafe condition.
Modules 15- False negative
- A risk event or condition that the control should have identified but did not. A false-negative assessment can be direct, sampled, inferred, or scenario based.
Modules 01, 07, 14- False positive
- An alert that does not support the intended concern after appropriate review; it is not necessarily a system defect.
Modules 07- FATF-style regional body (FSRB)
- A regional organization that participates in the FATF Global Network and carries out, among other activities, mutual evaluations in its region.
Modules 02- Federated analysis
- A design pattern in which analytic logic operates across distributed/local data without necessarily centralizing all raw records.
Modules 23- Federated query
- An authorized query to a local source system that returns a bounded result without transferring the full underlying dataset.
Modules 13- FinCEN
- The U.S. Treasury bureau that administers key BSA rules, collects and analyzes financial intelligence, and operates specified information-sharing programs.
Modules 19- FINTRAC
- Canada’s Financial Transactions and Reports Analysis Centre, with reporting, financial-intelligence and compliance functions.
Modules 22- FIU
- Financial Intelligence Unit; national reporting and intelligence functions differ by Member State.
Modules 20- FIU-IND
- Financial Intelligence Unit-India.
Modules 24- Foundation model
- A broadly trained AI model adaptable to multiple tasks, often including language or multimodal capability.
Modules 14- FRAML
- A coordinated fraud-risk and AML operating approach that shares permitted intelligence and controls while preserving distinct legal standards and decision rights.
Modules 09- GenAI
- Generative AI that can produce text, code, images, or other content from instructions and context.
Modules 14- Global Core
- The common enterprise standards, taxonomy, evidence expectations, decision architecture, data semantics, and assurance discipline that should remain coherent across markets.
Modules 02, 15, 16- Global core / local edge
- An operating design that standardizes control objectives, taxonomy, data/evidence discipline, and governance while localizing legal accountability, execution, data permissions, reporting, and supervisory engagement.
Modules 01, 03- Historic lookback
- Retrospective assessment of records, actions, reports, or outcomes potentially affected by a known or suspected control defect.
Modules 17- Human-in-the-loop
- A governance design requiring defined human review or approval; effectiveness depends on real authority and evidence access.
Modules 14- Identity confidence
- An evidence-based assessment of how well the enterprise can rely on an identity claim for a specific decision.
Modules 04- Immediate Outcome
- One of the eleven outcome areas FATF uses to assess the effectiveness of a national AML/CFT/CPF system.
Modules 02- Independent evaluation
- Review performed with sufficient independence, competence, scope, access, and authority to challenge the program or control owner.
Modules 17- Information sharing
- A controlled disclosure or exchange of information that requires an applicable authority, purpose, and safeguards.
Modules 08- Inherent risk
- Risk before controls or mitigation.
Modules 03- Interdiction
- A timely decision that stops, holds, rejects, blocks, restricts, challenges, or routes an event before a prohibited, harmful, or otherwise unacceptable outcome occurs.
Modules 01- Interim control
- A temporary, owned, and tested risk-reducing measure operated while permanent remediation is implemented.
Modules 17- Interpretive Note
- FATF material that elaborates how a Recommendation should be applied or understood in the national implementation framework.
Modules 02- Intervention
- A proportionate action intended to prevent, authenticate, delay, warn, pause, recover, or otherwise reduce harm.
Modules 09- Investigation
- A controlled inquiry that gathers and analyzes relevant facts to support an accountable decision; it is not a finding of wrongdoing.
Modules 08- Issue taxonomy
- A controlled set of categories and relationships used to classify defects, causes, impacts, dependencies, and remediation across a program.
Modules 17- JAFIC
- Japan Financial Intelligence Center.
Modules 23- Kill switch
- The technical and operational ability to suspend an AI component, its tool access, or its actions and transition safely to fallback.
Modules 14- KYC
- Know your customer; a practical operational label, not a single universal legal construct.
Modules 04- KYC Direction
- RBI’s Master Direction - Know Your Customer (KYC) Direction, 2016, as updated from time to time.
Modules 24- Legal arrangement
- In FATF terminology, express trusts or other similar legal arrangements. The legal treatment differs by jurisdiction.
Modules 05- Legal basis
- The applicable legal ground for a processing or transfer activity under the relevant law; it must be assessed in context.
Modules 13- Legal floor
- The minimum binding legal and regulatory requirement; not subject to commercial waiver.
Modules 03- Legal person
- An entity, other than a natural person, that can establish a permanent customer relationship with a financial institution or otherwise own property, usually including companies, bodies corporate, foundations, and similar entities.
Modules 05- Legal-entity accountability
- Responsibility of an entity and its accountable officers for applicable obligations and its actual customer, product, and market risk.
Modules 16- Letter of credit
- A trade-finance instrument in which a bank undertakes to honor compliant presentation of specified documents, subject to its terms.
Modules 11- LFPIORPI
- Mexico’s Federal Law for the Prevention and Identification of Operations with Illicit Resources.
Modules 22- License
- An authorization that may permit activity otherwise restricted, subject to exact legal scope, dates, and conditions.
Modules 06- Lineage
- The end-to-end record of data origin, transformation, access, use, disclosure, retention, and deletion.
Modules 13- Local Edge
- The legally accountable and market-specific layer of a global control system: local law, supervisory practice, data permission, reporting, operating workflow, language, and market execution.
Modules 02, 15, 16- Local overlay
- An approved and tested market-specific requirement, configuration, process, data use, or evidence pattern layered on the Global Core.
Modules 16- Minimum necessary
- A proportionality principle requiring information, access, or sharing to be limited to what is necessary for the defined purpose.
Modules 13- Mixer
- A service or mechanism designed to obfuscate transaction provenance by pooling, splitting, or otherwise altering transaction paths.
Modules 12- MLRs
- The Money Laundering, Terrorist Financing and Transfer of Funds (Information on the Payer) Regulations 2017.
Modules 21- Model risk
- Risk of adverse consequences from incorrect or misused model outputs, assumptions, data, implementation, or governance.
Modules 14- Mule account
- An account used to receive, move, or conceal illicit value; the account holder's knowledge and role require investigation, not assumption.
Modules 09- Mutual evaluation
- A FATF or FSRB peer review of a jurisdiction's AML/CFT/CPF system, including technical compliance and effectiveness analysis.
Modules 02- National competent authority
- A national body with AML/CFT supervisory or related responsibilities within the EU framework.
Modules 20- Nested relationship
- An indirect use of a correspondent relationship through another respondent or intermediary, often with limited direct visibility.
Modules 10- Nominee
- A person or entity that holds a position or interest on behalf of another person. Nominee status must be identified and understood; it does not by itself establish beneficial ownership.
Modules 05- OFAC 50 Percent Rule
- OFAC’s rule that property and interests in property of entities owned, directly or indirectly, 50 percent or more in the aggregate by blocked persons are considered blocked.
Modules 19- Offshore VASP
- A VASP providing services into a jurisdiction from another jurisdiction, potentially creating supervisory and information-sharing blind spots.
Modules 12- OFSI
- Office of Financial Sanctions Implementation, within HM Treasury.
Modules 21- Open-account trade
- A trade arrangement in which goods are shipped before payment is made, often creating less structured document visibility for a financial institution.
Modules 11- Operating effectiveness
- Whether the control executed as designed for the intended population and period, supported by evidence.
Modules 17- Operating model
- The arrangement of people, decision rights, processes, services, systems, evidence, and governance used to deliver outcomes.
Modules 16- Ordering institution
- The institution that initiates a transfer instruction on behalf of the originator in the relevant payment context.
Modules 10- Originator
- The person or entity that initiates a transfer from an account or otherwise gives the transfer instruction.
Modules 10- Ownership graph
- A dated network of persons, entities, arrangements, and relationships used to represent direct/indirect ownership, control, authority, benefit, and related roles.
Modules 05- Payment repair
- A controlled correction or enrichment of payment data or instruction; it must preserve original facts and decision history.
Modules 10- PCMLTFA
- Canada’s Proceeds of Crime (Money Laundering) and Terrorist Financing Act.
Modules 22- PEP
- Politically exposed person; a person entrusted with a prominent public function, with definitions and measures set by applicable regimes.
Modules 04- Person with significant control (PSC)
- A UK company-law term that has a specified legal meaning. It should not be used as a global synonym for beneficial owner.
Modules 05- PIPL
- People’s Republic of China Personal Information Protection Law.
Modules 23- PMLA
- India’s Prevention of Money-laundering Act, 2002.
Modules 24- POCA
- Proceeds of Crime Act 2002.
Modules 21- Population coverage
- The degree to which the complete and intended population of customers, entities, transactions, accounts, products, or events is subject to a control.
Modules 01, 07- Population reconciliation
- Comparison between an authoritative in-scope population and the population that reached a downstream control or process.
Modules 13, 15, 16, 17- Precision
- The share of selected alerts/predictions that are relevant under a defined evaluation outcome.
Modules 14- Proliferation financing
- Providing funds or financial services related to the development or movement of WMD-related capabilities in the relevant legal and standards context.
Modules 11- PSC
- Person with Significant Control, a Companies House corporate-transparency concept distinct from every firm’s own CDD conclusion.
Modules 21- Pseudonymization
- Processing that reduces direct identifiability while retaining a controlled link that may permit re-identification under safeguards.
Modules 13- Purpose limitation
- The obligation to collect and use personal data only for specified, explicit, legitimate purposes subject to lawful exceptions.
Modules 13- RACI
- A role map identifying who is responsible, accountable, consulted, and informed for a decision or activity.
Modules 16- Recall
- A request or mechanism to attempt recovery of a payment; it does not guarantee return of funds.
Modules 09, 14- Regional evidence graph
- A linked set of entities, people, transactions, reports, actions and sources that retains country-specific facts and accountability.
Modules 22- Registry intelligence
- Data from corporate, beneficial-ownership, licensing, regulated-market, or comparable registers used to establish, corroborate, or challenge KYB facts.
Modules 05- Reject
- A decision not to process a transaction; it is not automatically equivalent to a block or freeze.
Modules 06- Reopening trigger
- A defined new fact, linked event, quality finding, request, or behavior change that requires a closed case to be reassessed.
Modules 08- Residual risk
- Risk remaining after considering the design and operation of controls; it is not necessarily acceptable risk.
Modules 01, 03- Respondent bank
- A financial institution that receives correspondent services from another institution.
Modules 10- Restrictive measures
- EU and national measures, including financial sanctions, that require their own legal and operating decision path.
Modules 20- Retained accountability
- The institution’s continuing responsibility for an outsourced or automated activity, including governance and evidence.
Modules 18- Risk acceptance
- A formally authorized decision to accept a defined residual risk within stated limits, duration, evidence, and escalation requirements.
Modules 01, 03- Risk appetite
- The boundary system that distinguishes prohibited, conditional, acceptable, and escalated exposure.
Modules 03- Risk scenario
- A structured description of a threat exploiting a vulnerability through a route in the business with plausible impact.
Modules 03- Risk-based approach
- A method of identifying, assessing, understanding, monitoring, managing, and mitigating risk with measures proportionate to the risk identified and applicable legal requirements.
Modules 02- Root cause
- The underlying design, governance, data, process, capacity, incentive, dependency, or oversight condition that allowed an issue to occur or persist.
Modules 17- Rule pack
- A versioned set of jurisdictional or product-specific conditions governing data collection, access, use, transfer, retention, and action.
Modules 13- SAR
- Suspicious Activity Report filed with FinCEN under applicable BSA rules; confidential and distinct from a judicial finding.
Modules 19, 21- SAR/STR
- A jurisdiction-specific suspicious activity or suspicious transaction report submitted under the applicable regime and threshold.
Modules 08- SAT
- Mexico’s Servicio de Administración Tributaria; relevant to the preventive-law operating environment.
Modules 22- Scenario
- Documented detection logic, often rules or thresholds, designed to identify a defined behavior in a stated population.
Modules 07- Scenario test
- A controlled test of expected and adverse conditions, including disruption, change, failure, unusual volume, or time-critical action.
Modules 17- SCR
- Hong Kong Significant Controllers Register.
Modules 23- Section 314(a)
- A FinCEN information-sharing program supporting certain law-enforcement requests to financial institutions.
Modules 19- Section 314(b)
- A statutory voluntary information-sharing framework available to eligible participating financial institutions subject to conditions.
Modules 19- Segmentation
- Grouping exposure units by risk-relevant characteristics so treatment and aggregation can differ meaningfully.
Modules 03- Service catalog
- A controlled description of a service's customer, scope, owners, inputs, outputs, evidence, levels, dependencies, and fallback.
Modules 16- Shared service
- A capability performed for more than one entity or market under defined scope, performance, governance, and evidence.
Modules 16- Smart contract
- Code deployed to a distributed ledger that executes logic under defined conditions; it may be associated with identifiable developers, operators, users, or controllers.
Modules 12- Source lineage
- The trace of where data, legal rules, risk signals, and decisions originated and how they were used.
Modules 03- Source of funds (SOF)
- The origin and traceable path of specific funds involved in a transaction or relationship.
Modules 04- Source of record
- The authoritative system or repository for a defined data item, subject to stated scope and quality conditions.
Modules 13- Source of wealth (SOW)
- How a person accumulated overall wealth sufficient to make the relationship or activity plausible.
Modules 04- Source provenance
- Information about where a data point originated, how it was obtained, and what legal/operational restrictions apply to its use.
Modules 05- Stablecoin
- A crypto-asset designed to maintain stable value relative to a reference; risk analysis must consider issuer, reserve, redemption, distribution, custody, and transfer functions.
Modules 12- STR
- Suspicious Transaction Report under Canada’s FINTRAC reporting framework; do not use the label as a substitute for country-specific report analysis.
Modules 22- Straight-through processing
- Automated processing without manual intervention; it is an operational mode, not proof that risk was assessed correctly.
Modules 10- Surge capacity
- Reserved ability to absorb abnormal demand without silently degrading service levels, quality, or risk controls.
Modules 18- Sustainable remediation
- Corrective action that resolves historical and future-state scope, causal conditions, evidence, ownership, validation, and recurrence monitoring.
Modules 17- System effectiveness
- The ability to prove that connected controls, people, data, decisions, evidence, and assurance deliver intended risk outcomes in the context of the relevant exposure.
Modules 01- System of record
- The controlled repository that holds the official workflow, determination, or evidence for a defined object or process.
Modules 15- Targeted financial sanctions
- Asset-freezing and related measures directed at designated persons, entities, or other targets under an applicable regime.
Modules 06- Technical compliance
- The extent to which a jurisdiction has enacted the laws, powers, institutions, and other technical elements required by the relevant FATF Recommendations.
Modules 02- Tension escalation
- The controlled process for resolving a conflict between global standard, local legal obligation, risk appetite, capability, or market action.
Modules 16- Third-party relationship
- An arrangement in which an external party provides an activity, service, technology, data, model, or dependency relevant to the institution.
Modules 15- Three lines
- A governance model distinguishing management ownership, risk/compliance oversight, and independent internal audit assurance.
Modules 17- Tipping off
- Improperly disclosing a report, investigation, or related information where law or policy restricts the disclosure.
Modules 08- Trade diversion
- Rerouting, re-exporting, or otherwise redirecting goods, technology, or value away from a stated or permitted destination or end user.
Modules 11- Trade-based money laundering
- Moving or disguising illicit value through trade transactions, often by misrepresenting price, quantity, quality, goods, parties, or other trade facts.
Modules 11- Transformation debt
- Unresolved data, process, governance, training, or evidence gaps carried forward after a change is declared complete.
Modules 18- Translation debt
- An accumulated gap between an external standard or obligation and the implemented operating capability, including gaps in interpretation, policy, data, design, configuration, workflow, evidence, or governance.
Modules 02, 04, 20, 24- Transliteration
- Rendering a name from one script into another; a control-relevant source and match attribute, not a single definitive identity field.
Modules 23- Travel Rule
- The requirement under FATF's virtual-asset framework for VASPs and other obliged entities in scope to obtain, hold, and exchange specified originator and beneficiary information in the prescribed context.
Modules 02, 12- Trustee
- A person or entity holding legal title to trust property and administering the trust under its terms and applicable law.
Modules 05- Tuning
- Controlled adjustment to detection logic to improve coverage, investigative value, capacity, or customer impact.
Modules 07- U.S. nexus
- The facts that may connect conduct to a U.S. legal, regulatory, supervisory, or sanctions requirement.
Modules 19- UIF
- Mexico’s Unidad de Inteligencia Financiera.
Modules 22- UKFIU
- United Kingdom Financial Intelligence Unit, housed in the National Crime Agency.
Modules 21- Unhosted wallet
- A wallet controlled directly by a user rather than an identified intermediary; it may change due diligence and transfer-control design.
Modules 12- Value leakage
- Cost, delay, rework, risk, or customer friction created when a control is not designed around the whole decision path.
Modules 18- VASP
- A virtual-asset service provider under FATF's activity-based definition; local scope and licensing treatment vary.
Modules 12, 23- VDA
- Virtual digital asset, a defined term relevant to India’s 2023 PMLA notification.
Modules 24- Verification
- A controlled process that tests an identity or other claim through defined methods and produces a recorded result with limitations.
Modules 04- Version control
- Recorded identification and governance of the specific code, rule, model, list, configuration, schema, or content used at a point in time.
Modules 15- Wallet
- A technical and/or service arrangement that manages private keys or allows interaction with virtual assets; custody and control models vary.
Modules 12- Workaround debt
- Accumulated informal local processes or exceptions that obscure scope, reduce evidence, and increase change and assurance risk.
Modules 16- Workflow orchestration
- The controlled routing, assignment, escalation, approval, and evidence capture that moves a case or task through a process.
Modules 15- Workforce mix
- The deliberate allocation of standardized, assisted, specialist, independent-review, and management work.
Modules 18