Risk-Based AML/CFT for GCC Nonprofits: Proportionate Controls in Practice
Risk-based anti-money-laundering and counter-terrorist-financing controls distinguish inherent exposure, control effectiveness, and residual risk. Focused, proportionate measures can protect both financial integrity and legitimate nonprofit activity when decisions reflect specific risks rather than blanket assumptions about organizations or geographies.
From blanket control to risk reasoning
Philanthropic organizations face genuine financial-crime risks, particularly when they move funds across borders, operate through downstream partners, deliver cash, or work in areas affected by conflict and sanctions. Yet broad restrictions on all nonprofit activity can be ineffective and harmful. FATF's current best-practice guidance calls for focused and proportionate measures based on an understanding of actual terrorist-financing risk (Financial Action Task Force, 2023).
A risk-based system separates inherent exposure from the quality of controls. Geography, delivery modality, counterparty type, value, anonymity, urgency, and complexity may raise inherent risk. Legal verification, governance, screening, account controls, monitoring, and audit reduce it. The decision should address residual risk after controls, not rely on one red-flag score.
The control architecture
Baseline due diligence should establish legal identity, purpose, governing persons, authorized signatories, institutional bank account, regulatory standing, and program capacity. Enhanced diligence may add beneficial-control analysis, source-of-funds or source-of-wealth evidence, site verification, deeper adverse-information review, sanctions and PEP analysis, financial-statement testing, downstream mapping, and independent references.
Screening is not a substitute for judgment. Name matches must be resolved, not merely recorded. Ownership and control may matter even where the entity name is absent from a list. Conversely, an unsubstantiated media allegation should not automatically outweigh verified evidence. The organization needs escalation criteria, documented decisions, and responsibility at a level proportionate to the risk.
Monitoring and learning
Due diligence is a point-in-time view. Agreements should require notice of material changes in ownership, governance, bank accounts, sanctions status, or implementation arrangements. Monitoring should combine financial data with program evidence: transaction patterns, budget variance, beneficiary verification, procurement, complaints, site information, and output delivery. Unusual activity should trigger inquiry before automatic accusation.
Boards should receive an aggregated risk view showing exposure, overdue reviews, exceptions, incidents, and de-risking effects. They should ask whether controls are preventing abuse and whether they are also excluding legitimate smaller organizations. That dual question reflects the public-interest purpose of risk-based regulation. Integrity and access are not opposing goals when controls are well designed.
What FATF Recommendation 8 requires
FATF Recommendation 8 does not classify the entire nonprofit sector as inherently high risk. Its 2023 best-practices paper calls for countries to identify the subset of organizations exposed to terrorist-financing abuse and to apply focused, proportionate measures. Saudi NCNP guidance and Qatar's amended charitable-activities law likewise connect nonprofit governance with AML/CFT and targeted-financial-sanctions controls (Financial Action Task Force, 2023; National Center for Non-Profit Sector, 2025; State of Qatar, 2014).
This distinction changes control design. A risk assessment must identify the specific exposure, show how controls alter that exposure, and record residual risk. Geography or nonprofit status alone is not a sufficient conclusion. Neither is a low-risk score a substitute for legal identity, authority, sanctions, account, purpose, and beneficiary checks.
The risk-control cycle
Calibrating controls against real cases
Calibration should be tested against real portfolio cases. Select examples across value, geography, partner maturity, delivery modality, and urgency. Compare the assigned risk rating, controls, approval level, and actual outcome. If all cases receive the same treatment, the system is not risk based. If similar cases receive inconsistent treatment, guidance or training is weak. The review should also examine declined opportunities to identify whether controls are producing unjustified exclusion.
Conclusion
FATF's current framework requires focused measures for the subset of nonprofits exposed to terrorist-financing abuse, not blanket classification of the sector as high risk. A defensible control system links identified risk drivers to specific mitigations, records residual risk, monitors change, and tests whether controls exclude legitimate activity without justification.
References
References
- Financial Action Task Force. (2023). Best practices: Combating the terrorist financing abuse of non-profit organisations, Recommendation 8. https://www.fatf-gafi.org/content/dam/fatf-gafi/guidance/BPP-Combating-TF-Abuse-NPO-R8.pdf.coredownload.inline.pdf
- National Center for Non-Profit Sector. (2025). Guidance for compliance with anti-money-laundering and counter-terrorist-financing requirements [Arabic]. https://ncnp.gov.sa/ar/evidence-procedures
- State of Qatar. (2014). Law No. 15 of 2014 regulating charitable activities, as amended by Law No. 4 of 2020 [Arabic]. Al Meezan Qatar Legal Portal. https://www.almeezan.qa/LawView.aspx?LawID=6367&language=ar&opt=