Back to Glossary

Entry · Legal

Combating the Financing of Terrorism

Combating the Financing of Terrorism (CFT) is the collection of laws, controls and checks that firms use to stop money reaching groups that carry out or support terrorism. It sits alongside anti-money laundering rules and usually appears inside a business as customer screening, payment monitoring and reporting duties.

For most companies it is a compliance obligation rather than a number you calculate.

From the Money Master HQ dictionary, founded by Shihan Sheriff (FCMA, VP of Finance at Nomod, CFO at Esanjo Ventures). How these definitions are written.

What it means

Anti-money laundering work chases dirty money that someone is trying to make look clean, while CFT chases clean money heading towards a harmful purpose. That difference matters more than it sounds: terrorist financing often involves small amounts, and the source funds can be entirely legitimate, such as wages, business takings or genuine charitable donations.

Because the money looks normal, the controls lean heavily on who the parties are rather than on how odd the amount is. Banks, payment processors, money transfer businesses and digital asset platforms carry the heaviest obligations, but ordinary trading companies feel the consequences too.

A supplier or customer whose name matches a sanctions listing can freeze a payment run, stall a shipment or hold up a contract signature for weeks. Finance teams therefore end up dealing with CFT even when they never see the underlying rules.

In practice the work is delivered through a handful of repeatable controls: identity checks at onboarding, screening names against government sanctions and terrorist designation lists, ongoing monitoring of payments, and reporting anything suspicious to the national financial intelligence unit. Larger organisations layer a risk score on top so that higher-risk customers, countries and products get closer attention and more frequent review.

The whole arrangement is documented in a written policy that a regulator can inspect at short notice. The hard part is proportion.

Screening produces a great many false positives, since common names match listed names all the time, and over-reacting pushes legitimate charities and remittance firms out of the banking system altogether. Regulators call that de-risking and actively discourage it, so firms are expected to manage risk sensibly rather than simply refuse anyone who looks awkward.

Accountability sits with senior management rather than the compliance team alone, and most regimes require a named responsible officer, staff training and periodic independent testing. Penalties for weak controls range from fines and licence conditions through to personal liability for individuals, which is why the subject reaches board agendas rather than staying in the back office.

In practice

Real-world examples.

1

Example

A payments company wants to open a corridor sending money from the United States to a region with active armed groups. Before launch it screens every receiving agent against sanctions lists, caps transaction sizes, and requires source-of-funds questions above $1,000. The CFT review adds six weeks to the project but keeps the sponsoring bank comfortable.

2

Example

A freight forwarder notices that a new counterparty in a shipping chain shares a name and date of birth with a designated individual. It halts the booking, files a report with the relevant authority, and asks its bank for guidance before releasing any funds. The shipment is delayed, but the company avoids handling a prohibited payment.

3

Example

A medical charity opening an account for overseas relief work is asked for its grant agreements, trustee identities and details of local partners. The bank is not accusing the charity of anything; it is documenting that it understands where donations travel. Once the file is complete, the account is approved with an annual review.

Case study

Seen in the real world.

Northwind Remittance Partners is a fictional money transfer business used here for illustrative purposes. It grew quickly by serving migrant workers sending small sums home, and its screening system was tuned to catch large or unusual transfers. That design missed the pattern that mattered: dozens of small, individually unremarkable payments from unrelated senders arriving at the same three receiving agents.

A routine bank review flagged the concentration, and Northwind's sponsor threatened to withdraw its banking relationship. The finance director rebuilt the monitoring rules around receiving-side concentration, added agent-level due diligence, and appointed a named compliance officer with a direct line to the board.

The illustrative lesson is that CFT controls tuned only for size will miss financing patterns built on volume. Northwind kept its banking relationship, but only after accepting that the cost of the rebuild was far lower than the cost of losing access to the payment system.

Watch out

Common mistakes.

  • Treating CFT as identical to anti-money laundering and assuming one set of rules covers both. The controls overlap, but terrorist financing frequently involves legitimate money and small amounts, so size-based monitoring alone will not find it.
  • Assuming that only banks have obligations. Insurers, accountants, lawyers, estate agents, dealers in high-value goods and many payment firms are covered in most jurisdictions, and ordinary businesses still face frozen payments if a counterparty is listed.
  • Clearing a screening alert quickly to keep a customer happy without recording why. Regulators judge the quality of the decision trail, and an undocumented clearance is treated as no control at all.

Questions

People also ask.

What is the difference between a sanctions list and a terrorist designation list?

Sanctions lists cover a wider range of targets including countries, sectors and individuals for many policy reasons, while terrorist designation lists specifically name people and groups linked to terrorism, and firms are usually required to screen against both.

Does a small company need a formal CFT policy?

If it is not in a regulated sector it may not need a full policy, but it should still screen counterparties against published lists and know who its customers and suppliers actually are, because breaching sanctions is a strict liability offence in many places.

Can a business tell a customer that it has filed a suspicious activity report?

Almost never, because most regimes make tipping off a criminal offence in its own right, and staff should be trained to decline politely and escalate internally instead.

Was this explanation helpful?

From the founder's library

Accounting Fundamentals: A Non-Finance Manager's Guide to Finance and Accounting, by Shihan Sheriff

Take it further with the book.

Build your financial confidence beyond this definition. Shihan's full-length guide, Accounting Fundamentals, takes the same plain-English approach and turns it into a complete, practical playbook for non-finance managers, business owners and students - with chapter-end quiz answers and presentation slides included.

US$2.24US$2.99

25% off with code MMHQ25, applied at checkout. Priced in USD - checkout may show the equivalent in your local currency.

View the book and save 25%
Last updated · October 8, 2026
Browse all terms →

Disclaimer

The information provided in this finance dictionary is for educational and informational purposes only. It should not be construed as financial, investment, legal, or tax advice. Always consult with a qualified professional before making any financial decisions. Money Master HQ makes no representations or warranties about the accuracy, completeness, or suitability of this information. Use of this content is at your own risk.