
2025 in Numbers: How Financial Crime and Enforcement Scaled in a Single Year
July 26, 2026October 2025 brought significant changes in anti-money laundering supervision, jurisdiction risk, asset recovery, artificial intelligence, and digital-asset enforcement. This edition summarizes the developments and sets out practical actions for compliance teams.
FATF October 2025 Plenary Outcomes
At its Paris plenary on 22–24 October 2025, the Financial Action Task Force removed Burkina Faso, Mozambique, Nigeria, and South Africa from its list of jurisdictions under increased monitoring after they completed their agreed action plans.
FATF also adopted:
- asset-recovery guidance intended to support the confiscation and repatriation of criminal assets; and
- a horizon scan examining how artificial intelligence and autonomous agents may enable deepfake fraud, cybercrime, and money laundering.
What the grey-list exits mean
Removal from increased monitoring can reduce sovereign-risk concerns and correspondent-banking pressure. It does not eliminate residual financial crime risk. Institutions should make risk-rating changes through their documented governance process and continue to assess the strength and durability of each jurisdiction’s reforms.
Actions for compliance teams
- Reassess jurisdiction risk ratings for the four countries and record the evidence supporting each decision.
- Retain proportionate monitoring while regulatory reforms mature.
- Map data owners and escalation routes for cross-border asset-recovery requests.
- Add AI-enabled abuse scenarios, including deepfake identification and scripted fraud, to fraud and transaction-monitoring reviews.
Global AML Round-Up
- United Kingdom: The government confirmed plans for the Financial Conduct Authority to become the single AML supervisor for legal, accountancy, and trust and company service provider sectors. Implementation details were expected in 2026.
- European Union: The EU Anti-Money Laundering Authority began operating and is expected to directly supervise selected high-risk cross-border institutions from 2028.
- Africa: The removal of Nigeria, South Africa, Mozambique, and Burkina Faso from FATF increased monitoring marked an important regional milestone.
- United States: FinCEN highlighted the use of convertible virtual-currency kiosks in scams and money laundering and called for stronger monitoring and more descriptive suspicious activity reporting.
- Singapore: The Monetary Authority of Singapore announced S$27.45 million in third-quarter penalties across nine financial institutions for AML/CFT failures.
Regulatory and Policy Tracker
The tracker below brings together developments with different scopes and implementation horizons. FATF’s plenary outcomes influence jurisdiction and enterprise risk assessments, while the UK and EU changes concern the structure of supervision. FinCEN’s kiosk notice is more operational, requiring institutions to consider whether their transaction-monitoring data and suspicious activity reporting capture crypto-kiosk exposure.
Compliance teams can use the tracker as a triage tool: identify which developments affect their legal entities, products, customers, and geographic exposure, then assign an owner to confirm the applicable requirements and implementation dates. The visual is a summary and should be read alongside the relevant authority’s primary materials.
Regulatory and Policy Tracker for Compliance Teams
| Authority | Development | Date | Focus | Primarily affected |
|---|---|---|---|---|
| FATF | Plenary outcomes | October 2025 | Strategic priorities and technology risk | All obliged entities |
| UK government and FCA | Single professional-services supervisor model | October 2025 | Consolidated supervision | Legal, accountancy, and TCSP firms |
| EU AMLA | Operational launch | H2 2025–2028 | EU-wide supervision | Banks, crypto-asset service providers, and cross-border groups |
| FinCEN | Notice FIN-2025-NTC1 on CVC kiosks | August 2025 | Illicit use of crypto kiosks | Banks, money services businesses, and virtual-asset service providers |
| European Banking Authority | Advice on the new AML/CFT rulebook | October 2025 | Harmonized framework | EU financial sector |
Enforcement Watch
The enforcement actions highlight how AML obligations extend beyond traditional banking. The FINTRAC case focuses attention on reporting and policy failures in the crypto and money-services sector, while the UK Gambling Commission action shows how AML controls and broader customer-protection responsibilities can intersect in gambling supervision.
For compliance leaders, the practical lesson is to test whether regulatory reports are complete and submitted on time, policies reflect the current business model, and identified weaknesses move through a documented remediation process. Firms should also retain evidence of ownership, challenge, escalation, and closure rather than relying on the existence of written controls alone.
Enforcement Watch in October 2025
| Enforcement detail | FINTRAC (Canada) | Gambling Commission (UK) |
|---|---|---|
| Entity | Xeltox Enterprises Ltd. | Platinum Gaming Limited |
| Violation | Failure to submit reports and maintain required policies | AML failures and social-responsibility failings |
| Penalty and date | CAD 176,960,190 — October 16, 2025 | GBP 10 million fine — October 22, 2025 |
| Compliance significance | Major enforcement action involving the crypto and money-services-business sector | Demonstrates the AML standards applied within the gambling sector |
Emerging Typology: Virtual-Currency Kiosks
Cash-to-crypto kiosks can enable criminals and scam networks to convert fiat currency into digital assets before rapidly moving the value through exchanges, unhosted wallets, or mixers.
Red Flags
- Sudden clusters of kiosk deposits from customers with little previous activity.
- Rapid transfers to unhosted wallets or mixing services.
- Funds originating in one country and moving offshore within hours.
- Customer explanations involving an “investment coach” or a recovery fee.
Control priorities
- Capture kiosk-source indicators in transaction-monitoring data.
- Apply blockchain analytics and sanctions screening to subsequent wallet movements.
- Include the kiosk operator and location in suspicious activity narratives where relevant.
- Use clear customer warnings and proportionate friction for suspicious first-time activity.
What Compliance Leaders Should Do Next
FATF’s plenary outcomes and the UK’s proposed supervisory consolidation point toward closer oversight and faster responses to emerging technology. Compliance teams should revisit geographic risk, AI-enabled fraud scenarios, crypto payment channels, and asset-recovery readiness rather than treating these developments as isolated regulatory news.
For supporting guidance, review Financial Crime Lab’s resources on financial crime compliance frameworks, AML transaction monitoring, and crypto-asset compliance.
Adapted from the Financial Crime Lab LinkedIn newsletter published on 2 November 2025.
This article is for informational purposes only and does not constitute legal, regulatory, or compliance advice. Requirements and regulatory positions may have changed since the original publication date.

