Blog

What is the FATF Fraud Roadmap 2026-2028?

The Financial Action Task Force (FATF) has designated fraud as its central strategic priority for 2026-2028, releasing a formal roadmap to combat cyber-enabled fraud, organized scams, and AI-powered social engineering across all 173 member jurisdictions.

What is the FATF?

The Financial Action Task Force (FATF) is the global standard-setter for combating money laundering, terrorist financing, and proliferation financing. It is not a regulator and has no direct jurisdiction over banks; instead, it establishes the international framework through its 40 Recommendations. Countries transpose these standards into national laws and regulatory requirements, while FATF assesses how effectively they are implemented through peer-led Mutual Evaluations, with results published publicly. With 40 members and a wider network spanning more than 200 countries and jurisdictions, FATF exerts significant influence through a combination of global standards, public scrutiny, and national implementation giving its priorities substantial implications for governments, regulators, and financial institutions worldwide.

Why fraud is now a financial system threat

Fraud has outpaced being a consumer protection problem contained within national borders. It’s escalated to a systemic financial crime problem - industrialized, cross-border, technologically sophisticated, and accelerating. In the United Kingdom, fraud accounts for more than 40% of all recorded crime. In Singapore, cyber-enabled fraud cases surged 61% in just two years. Across the FATF's assessed membership, 156 jurisdictions - 90% of the total - have identified fraud as a major money laundering (ML) risk.

Source: FATF Paper: Cyber-Enabled Fraud Digitalisation and Money Laundering, Terrorist Financing and Proliferation Financing Risks, February 2026

These numbers show the fraud threat picture that drove the Financial Action Task Force (FATF), under its incoming UK 2026-2028 Presidency, to designate combating fraud as its central strategic priority, and to formalize that commitment in a dedicated multi-year Fraud Roadmap 2026-2028, which launched on 1 July 2026.

For FinCrime leaders, the message is clear: fraud has crossed the threshold from typology concern to AML/CFT compliance imperative. The regulatory environment is shifting to match.

Why the FATF Fraud Roadmap 2026-2028 Matters Now: A Regulatory Shift

The FATF's April 2026 Ministerial Meeting set the direction of travel explicitly. Ministers issued a formal declaration committing member states to deploy the full AML/CFT/CPF toolkit to disrupt fraud, including organized scam centres, the misuse of legal persons, virtual assets, and AI-enabled technologies. The declaration was a mandate for action.

The UK Presidency, led by FATF President Giles Thomson, took office on 1 July 2026 with fraud as its defining agenda. The Roadmap launch — attended by over 1,600 participants from across the FATF Global Network, observer bodies, and the private sector — marked the formal start of a three-year program spanning intelligence, regulation, asset recovery, and cross-sector collaboration.

The structural context is equally important. Fraud has evolved from a largely domestic, opportunistic crime into a professionalized, transnational industry. Organized scam compounds — particularly in South-East Asia — now operate at industrial scale. AI-generated deepfakes are lowering the barrier to high-conviction social engineering. Cryptocurrency rails provide rapid, cross-border movement of proceeds before detection is possible. These are not emerging risks on a horizon. They are operational realities in the fraud landscape today.

FATF Fraud Roadmap 2026-2028: Four Strategic Pillars

The 2026-2028 FATF Fraud Roadmap is a structured, three-year framework. Its objective is to mobilize the FATF toolkit across the full fraud lifecycle: prevention, detection, disruption, and asset recovery. The Roadmap is organized around four strategic pillars, each addressed at the launch event by operational and policy experts from every region of the world.

Pillar 1: Rethinking financial intelligence

The central question: are existing financial intelligence systems keeping pace with the speed and scale of fraud? The consensus from other national regulatory bodies, such as AUSTRAC (Money Laundering Update 2026), and the UK's National Economic Crime Centre (NECC Annual Report 2024–25), is not yet. Transaction monitoring models calibrated for traditional AML typologies routinely miss fraud-specific patterns, particularly where proceeds move rapidly across payment rails and jurisdictions before a suspicious activity report can be filed. The Roadmap calls for modernized financial intelligence frameworks that explicitly incorporate fraud as a money laundering (ML) predicate offence and leverage advanced analytics at national and institutional levels.

Pillar 2: Rethinking private sector information sharing

The Roadmap treats cross-sector information sharing as an urgent operational priority. Fraud exploits the boundaries between financial institutions, telecommunications companies, social media platforms, and technology providers — boundaries that AML frameworks were not designed to bridge. The Wolfsberg Group-moderated panel highlighted the need for structured public-private information sharing mechanisms that extend beyond banks to include Big Tech, telcos, and payment platforms. The FATF is expected to develop specific guidance on enabling frameworks during the current UK Presidency period.

Pillar 3: Rethinking asset recovery and international cooperation

Returning fraud proceeds to victims (i.e, asset recovery) is operationally one of the hardest problems with financial crimes. The Roadmap commits to addressing this directly: leveraging revised FATF Standards to require payment-suspension tools, non-conviction-based confiscation powers, and faster international cooperation mechanisms. Singapore Police Force (Annual scams & cybersecurity brief 2025), Interpol, and FIU Luxembourg  (CRF Rapport annuel 2024 & 2025 National Risk Assessment) each underscored that speed is the critical variable — proceeds dissipate within hours. The Roadmap aims to drive coordinated action that matches that pace.

Pillar 4: The global response - mobilizing the FATF network

The fourth pillar recognizes that fraud is disproportionately cross-jurisdictional. Regional bodies — APG, GAFILAT, MENAFATF — each face fraud threats with distinct local characteristics but shared underlying mechanics. The Roadmap builds in structured engagement with the FATF Global Network, the International Monetary Fund (IMF), and the Financial Stability Board to ensure the response is coherent at the global level, not fragmented by region or institutional mandate.

The cyber-enabled fraud paper: The evidence base underpinning the roadmap

Five months before the Roadmap launch, in February 2026, the FATF published a landmark analytical paper: Cyber-Enabled Fraud – Digitalisation and Money Laundering, Terrorist Financing and Proliferation Financing Risks. That paper is the intelligence layer that directly informs the Roadmap's strategic architecture.

"As fraudsters continue to adapt and accelerate their scams, we need to keep pace to safeguard people's money and protect victims from the effects of damaging losses. It is vital that countries make use of the expansive FATF toolkit to stop fraudsters preying on vulnerable people around the world."
- Source: FATF Former President Elisa de Anda Madrazo, Cyber-Enabled Fraud paper press release February 2026.
The paper maps six specific AML/CFT mechanisms to the fraud threat landscape. Each maps directly to one or more of the Roadmap's four pillars.

Critically, the February paper also identifies AI-enabled deepfakes, phishing, and messaging platforms as primary fraud vectors, providing the threat intelligence that the Roadmap's financial intelligence pillar must respond to. The two documents should be read together: the cyber fraud paper defines the problem; the Roadmap defines the three-year response.

What FinCrime leaders need to know

The Roadmap carries direct, near-term implications for compliance programs, risk frameworks, and technology investment. Leaders should be assessing and stress-testing the following areas now:

Fraud-to-ML linkages in your detection architecture

Check the alignment in your transaction monitoring models between fraud detection and AML detections. The Roadmap explicitly treats fraud proceeds as a money laundering predicate offense requiring integrated detection. Typology libraries should incorporate scam centre activity, authorised push payment (APP) fraud, and AI-enabled social engineering as ML risk scenarios.

Payment-layer controls and speed

Confirmation of payee mechanisms and payment-suspension tools are essential — the revised FATF Standards and the Roadmap's asset recovery pillar signals they will become supervisory expectations. Assess whether your institution has the technical and operational capability to act within hours, not days.

Beneficial ownership data

The FATF's cyber fraud paper emphasizes that organized fraudsters use shell company structures to layer and conceal proceeds. Beneficial ownership (BO) information must be used as an active investigative tool, not merely collected for regulatory compliance. If KYC process captures BO data without operationalizing it in investigation workflows, the gap needs to close.

Cross-sector information sharing readiness

The Roadmap's second pillar will drive new guidance on information sharing beyond the banking sector. Institutions should evaluate their existing public-private partnerships and consider where engagement with telcos, payment platforms, and technology companies could materially improve fraud signal quality, particularly for mule account detection and APP fraud disruption.

Mutual Evaluation exposure

The FATF's 5th Round Mutual Evaluations will increasingly scrutinize the extent to which fraud (as a major predicate offense) features in a jurisdiction's AML/CFT risk assessment and supervisory framework. For firms operating under regulatory oversight in FATF member jurisdictions, supervisory attention to fraud typologies and controls is likely to intensify over the 2026-2028 period.

AI and technology capability

The Roadmap's intelligence pillar will push the pace on AI adoption in financial crime detection. FIUs deploying machine learning on transaction data and payment risk-scoring are already ahead of the curve cited in the February 2026 paper. For institutions still operating rules-based detection on fraud typologies, the gap to supervisor expectations is widening.

Conclusion

The FATF has stressed that fraud is a systemic financial crime requiring the full force of the AML/CFT apparatus. The 2026–2028 Roadmap, grounded in the February 2026 cyber-enabled fraud evidence base, sets out a three-year agenda across financial intelligence, information sharing, asset recovery, and global coordination. It is the most significant regulatory signal on fraud in a decade.

FinCrime leaders who treat this as a compliance watch item rather than a strategic one will find themselves behind both the regulatory curve and the threat. The window to align programs, controls, and technology investment with the Roadmap's direction is now.  

Related resources

Blog | The UK’s New Fraud Strategy 2026-2029: What it means for financial crime and compliance

Webinar | From Regulation to Action: Getting EU AMLA-ready

Blog | FCA Insurance Financial Crime Review 2026: Six Findings Insurers Needs to Act On

Blog | Saudi Arabia Tightens the Net: What the April 2026 AML Law Amendments Mean for Regulated Entities and AI-Enabled Solutions

Learn more about Symphony Risk Intelligence

Discover the Symphony Risk Intelligence platform and begin your journey towards Always-on Compliance.

FATF Fraud Roadmap 2026-2028: Compliance Guide FAQs
What is the FATF Fraud Roadmap 2026-2028, and why did the FATF create it?

The FATF Fraud Roadmap 2026-2028 is a formal, three-year strategic initiative launched in July 2026 under the UK Presidency to combat fraud as a systemic financial crime. It was created because fraud has evolved from a consumer protection issue to an industrialized, cross-border financial crime threat: 90% of FATF member jurisdictions identify fraud as a major money laundering risk, and cyber-enabled fraud cases are surging (61% growth in Singapore alone). The Roadmap mobilizes the full AML/CFT toolkit across prevention, detection, disruption, and asset recovery.

What are the four pillars of the FATF Fraud Roadmap, and what does each address?

The four pillars are:

  1. Rethinking Financial Intelligence - Modernizing transaction monitoring to detect fraud-specific patterns at speed
  2. Rethinking Private Sector Information Sharing - Extending data sharing beyond banks to include Big Tech, telcos, and payment platforms
  3. Rethinking Asset Recovery - Enabling faster payment suspension and non-conviction-based confiscation to return fraud proceeds to victims
  4. Mobilizing the FATF Global Network - Ensuring coordinated, cross-jurisdictional responses via regional bodies (APG, GAFILAT, MENAFATF) and international partners (IMF, FSB)
How will the FATF Fraud Roadmap 2026-2028 impact my institution's compliance program?

Your compliance program should expect: heightened supervisory scrutiny on fraud-to-ML linkages during Mutual Evaluations; pressure to implement confirmation-of-payee and payment-suspension controls within hours (not days); active operationalization of beneficial ownership data in investigation workflows; and potential new guidance on cross-sector information sharing with non-bank entities. Institutions not aligned with these priorities by 2027 may face supervisory findings.

What is the difference between the FATF Cyber-Enabled Fraud Paper (February 2026) and the Fraud Roadmap (July 2026)?

The Cyber-Enabled Fraud Paper (published February 2026) is the evidence base and threat intelligence layer - it maps fraud vectors (deepfakes, phishing, organized scam centers) to six AML/CFT mechanisms and identifies where existing compliance tools fall short. The Fraud Roadmap (published July 2026) is the operational response; a three-year action plan that translates the paper's findings into four strategic pillars and implementation requirements for FATF member states, supervised institutions, and law enforcement. Both documents should be read together.

Is the FATF Fraud Roadmap mandatory, and what happens if my jurisdiction or institution doesn't comply?

The Roadmap itself is a directive from FATF member states' political leadership (formalized at the April 2026 Ministerial Meeting), not a binding standard. However, compliance expectations will harden over 2026-2028 through:

  1. Revised FATF Standards incorporating fraud requirements (expected 2027)
  2. Mutual Evaluations scoring jurisdictions on fraud-specific AML/CFT controls
  3. Supervisory guidance from national regulators interpreting the Roadmap for their jurisdiction.

Institutions and jurisdictions that lag behindrisk supervisory sanctions, negative Mutual Evaluation ratings, and exclusion from trusted financial networks by late 2027.

about the author
Charmian Simmons
Financial Crime & Compliance Expert and Strategy Leader

Charmian Simmons is a Financial Crime and Compliance Expert covering Financial Services at SymphonyAI. She has over 20 years of experience in the financial sector across risk management, financial crime, internal controls and IT advisory. She is a technology evangelist specialising in AI innovations and transformation. Charmian is responsible for providing practitioner expertise, thought leadership and analysing key policy, regulatory and technology drivers transforming the compliance market. Prior to joining Symphony AI, Charmian was a Fincrime Expert with BAE Systems, a Regional Director of Strategy and Performance for the Risk business at Refinitiv, the Head of Audit in North America at Lloyds Banking Group USA and a Vice President at Morgan Stanley covering Institutional Securities and Capital Markets. Charmian is CAMS, CDPSE, CRMA and CISA certified.

Learn more about the author >