Why AML Red Flags Alone Are Not Enough for Terrorist Financing: What the FIN-FSA Guidance Says

Why AML Red Flags Alone Are Not Enough for Terrorist Financing: What the FIN-FSA Guidance Says

On 14 July 2026, the Finnish Financial Supervisory Authority (FIN-FSA) published an update for supervised entities on terrorist financing risk. Its central message is direct: anti-money laundering indicators are usually insufficient on their own to identify terrorist financing, and terrorist financing has to be assessed as a framework in its own right.

1. Two frameworks, not one

FIN-FSA describes combating terrorist financing as a parallel but independent framework alongside anti-money laundering, with risk elements and indicators that must be determined separately. Reusing an AML analysis and relabelling part of it as terrorist financing risks leaving the factors that are specific to terrorist financing insufficiently addressed, because the two do not behave in the same way.

2. Origin versus use of funds

One of the clearest differences is directional. In money laundering, attention centres on the origin of funds. In terrorist financing, FIN-FSA states that the main suspicion relates to the use of the funds, not their origin.

Looking at the origin of funds still has value, but it does not settle the question. Funds may come from entirely legal sources, such as salary income, grants, donations, consumer credit or legitimate business activity, and still be directed toward terrorist financing. A legitimate origin, in other words, does not rule the risk out. That is why FIN-FSA places weight on information about recipients: where funds are passed onward, understanding the full recipient chain is treated as essential.

What this means in practice: A clean origin is not the end of the enquiry. The recipients of the funds, their intended use and any onward transfer carry particular weight in this context.

3. Small, ordinary transactions and misused legitimate activity

Scale and appearance differ as well. FIN-FSA notes that individual transactions may be small and appear ordinary, and that the size of a single transaction is often of lesser significance than it would be in an AML context. Funds can also come from legal or illegal sources.

Terrorist financing can be connected to otherwise legitimate activity in which funds, or part of them, are misused. FIN-FSA points to several channels: charitable organisations that can be exploited, front or fictitious businesses through which money flows despite little or no real trade, and value transfer systems operating outside conventional banking, including hawala. It draws particular attention to money transfer agents not registered in Finland or elsewhere in the EEA, operating as so-called dark hawalas.

Taken together, these characteristics point toward the need for terrorist financing indicators that do not rely mainly on large transaction values or on conventional AML patterns. That is an operational implication of the risk profile FIN-FSA describes, rather than a specific instruction in the document.

4. Not one model, but several

FIN-FSA does not treat terrorist financing risk as a single thing. Different ideologies that may engage in terrorist activity can call for different indicators and risk profiles, and the guidance gives the example that far-right and extremist Islamist actors can differ in how funds are raised and in which indicators are relevant.

To capture this, the guidance suggests dividing terrorist financing into stages, namely fundraising, transfer and use of funds, and assessing each extremist movement separately across those stages. In FIN-FSA's view, a differentiated assessment of movements and their operating models generally provides better preconditions for prevention than one based on a single uniform model.

5. A dynamic risk

Terrorist financing risk is described as significantly dynamic. Geopolitical conflicts, radicalisation, societal change and even shifts in charitable activity can move it, and new payment methods, crypto-assets and social media are identified as channels that have been exploited for raising funds.

The expectation on timing follows from this. Assessments must be updated regularly and in connection with material changes, and rapidly developing external events, such as the escalation of conflicts in the Middle East or in African countries, may require prompt updates to both the assessment and operations.

6. What a defensible assessment covers

FIN-FSA sets out what a supervised entity's own terrorist financing risk assessment should do. It should identify risks across products, services, clients, distribution channels and geographical connections. It should document the nature and likelihood of those risks. It should scale mitigation to the risk, assess residual risk against the firm's risk appetite, and be updated regularly and on material change.

Two requirements are easy to overlook. The assessment must be sufficiently concrete, describing the actual mitigation measures in place rather than stating them in general terms. And it must assess the effectiveness and quality of the firm's own controls, not merely list them.

What this means in practice: Whether the terrorist financing analysis sits inside a broader risk document or elsewhere, the terrorist financing risk factors, mitigation measures, residual risk and control effectiveness all need to be separately and concretely assessed.

7. A useful benchmark to work from

This is Finnish guidance, addressed to entities supervised by FIN-FSA. It does not by itself establish a supervisory position for other jurisdictions. Even so, the way it frames the problem, separating terrorist financing from money laundering, focusing on the use and recipients of funds, differentiating by movement and stage, and assessing control effectiveness, gives firms elsewhere a practical benchmark to test their own approach against.

It reduces to one question worth putting to your own assessment: if you had to show how terrorist financing risk is handled specifically, would the separate reasoning, indicators and control assessment be there to point to?

Build a more defensible business-wide risk assessment. Our Business-Wide Risk Assessment seminar works through how to treat terrorist financing as a distinct risk inside a concrete, well-reasoned assessment.

Explore the BWRA seminar at cpds.academy

Source: Finnish Financial Supervisory Authority (FIN-FSA),"Update for supervised entities – Consider terrorist financing risks," 14 July 2026. [INSERT LINK TO FIN-FSA UPDATE]

Nikolas Demetriades

Article by Nikolas Demetriades

Published 20 Jul 2026