
The FATF released its 2 year roadmap a few months ago, and this is what it means for financial crime fighters in the ASEAN region.
Fraud and money laundering are no longer isolated cases. There are many scenarios currently where the two terms can be used interchangeably.
In his book The 5 Rings, legendary samurai Miyamoto Musashi stresses that all techniques are derivative, and must be tailored to suit the environment. Musashi warns of following rules too closely without a second thought. This applies to the roadmap.
What the roadmap isn’t, is a list of rules and checklist items that countries adhering to FATF’s principles must rigidly abide by. They function more as guidelines that each jurisdiction must modify to suit regional requirements. Some commonalities and standards can arise, but ultimately each economy faces its own set of challenges, approaches and infrastructure.
The days of static, siloed operations between fraud, AML and onboarding are at a close. In order to combat this wave of AI-enabled fincrime, and the next (quantum decryption), financial institutions can no longer afford to have separate teams each doing their own thing.
When there is a lack of communication and intelligence sharing between these departments, complications arise. Among them, duplicate processes, slower response times, fraud and ML patterns become disjointed and harder to discern, and a lack of pattern recognition visibility.
I disjointed workflows, patterns that are obvious when departments are fully communicating, fully cooperating, often fly under the radar. This becomes dangerous when each anomalous activity accumulates, often ending is losses for the consumer and the establishment.
Banks can no longer rely on generic defining statements when transaction anomalies happen. If a series of suspicious actions are not accurately mapped to the appropriate typology, this can lead to oversights.
If a descriptor states “large sum transfer at unusual time” but does not clarify whether it is a fraud, layering, social engineering and grooming, this hinders the efficacy and swiftness of the response that is necessary to put the brakes on an unauthorized transfer.
KYC, CDD and onboarding processes can not have an ounce of lax in them. Failure to adhere to high standards of data collection, cross-referencing, documentation, evaluation, behavioral analysis and risk profiling can leave the full picture incomplete. This half-finished painting is where criminals will come and vandalize at any opportunity.
Identity and originator data has to be more complete. Below is a helpful guideline to adhere to:
Identity data (individuals)
Identity data (legal entities)
Originator data (payment/transaction specific — this is where Travel Rule obligations live)
Recommendation 16 already requires originator and beneficiary data to travel with a payment. Most institutions treat this as solved once the field exists in the message format. Big mistake. The open consultation FATF has running now is aimed at exactly this gap: whether the data that travels is complete, accurate, and usable at the receiving end, not just present on paper.
Cross-border corridors in ASEAN are where this breaks down fastest. A transfer moving between Malaysia, Singapore, and Thailand can pass through several intermediary institutions before it lands, and each hop is a point where originator data can degrade, get truncated, or arrive jumbled-up. Like a game of Chinese whispers, the trick is in making the data survive the journey.
Worth an honest audit here: What your institution actually captures at origination versus what the Travel Rule obligates you to capture. Those two lists are rarely identical, and the gap between them is precisely what FATF is now asking supervisors to test.
Section 314(b) in the US. Domestic public-private partnerships elsewhere, including the fusion cell models taking shape between banks, telcos, and law enforcement in Malaysia and Singapore. These gateways have existed for years. Using them has mostly been discretionary, something a compliance team does when a case looks bad enough to justify the effort.
FATF's roadmap moves that from discretionary to baseline. A mature fraud programme is now one that uses the sharing mechanisms available to it as a matter of course, not as an exception.
Mule accounts and layering networks operate across borders by design. A fraud programme that only sees its own transaction data, isolated from neighbouring regions, is structurally incapable of seeing the network the fraud is running on.
FATF is not asking firms to be by-the-books, they are asking firms to prove that their fraud detection actually understands fraud, not just that it flags anomalies and files paperwork.
That's a bar we need to understand. It means monitoring systems that can name a typology, CDD that tests behaviour against claimed identity, data pipelines that don't leak originator detail crossing borders, and a genuine posture of using the information-sharing channels that already exist.
Scam compounds are a persistent threat to the integrity of financial systems in ASEAN, and this is the specific remit that FATF is working to crack down on. The gaps that this roadmap intends to address are the exact ones that these criminal syndicates exploit. Where there are inconsistencies in procedures and lax implementations, all these can compound to a case.
It is not expected that every single guideline be followed to a T. FATF's roadmap doesn't land the same way twice. Each ASEAN jurisdiction is building towards different foundations, and the KYC/CDD gaps that matter most shift accordingly.
Malaysia has BNM's Policy Document on Anti-Money Laundering and the newly reinforced Travel Rule requirements sitting alongside a maturing National Fraud Portal. The infrastructure for data sharing exists. The gap is closer to originator data actually surviving the jump between banks, e-wallets, and telcos, each of which historically ran its own onboarding standard. Sealing that gap requires standardization across industries.
Indonesia faces this at a different scale entirely. A population this large, spread across an archipelago, means identity verification leans hard on the national ID system (KTP/NIK) as the anchor. When that anchor is weak or duplicated, everything built on top of it inherits the weakness. Beneficial ownership tracing is also harder here, given how common informal and family-run corporate structures are outside the major cities.
Thailand has been pushed furthest by scam compound activity along its borders with Myanmar and Cambodia. This has forced faster movement on mule account detection and centre coordination (echoed in ETDA's AI Governance push), but KYC at the account-opening stage hasn't always kept pace with the sophistication of the monitoring built downstream. You end up with strong detection sitting on top of weak intake, catching fraud after it's already happened.
The common thread: every jurisdiction is solving the same underlying problem (identity that doesn't degrade as it moves) with different tools, different legacy systems, and different political urgency.
FATF's roadmap gives the direction. What each institution actually builds to close its own version of the gap is the part that doesn't come from a document.