Table of Contents▼
On 19 June 2026, the Financial Action Task Force (FATF) closed its Paris plenary by keeping Nepal on its list of "jurisdictions under increased monitoring" — the grey list — for the second consecutive review cycle since the country was re-listed in February 2025. Bosnia and Herzegovina and Iraq were added this round; Algeria and Namibia were removed. Nepal stayed exactly where it has been since first being placed on the list under a different government, a different finance minister, and a different APG delegation: under watch, with a six-point action plan and a shrinking clock.
For Silicon Himalayas, this is not primarily a diplomatic story or a legal one. It is an infrastructure story — about supervision systems, data visibility, and the technology layer that turns an AML/CFT law on paper into AML/CFT enforcement in practice. That is the layer this firm builds. This piece sets out what FATF actually said, why Nepal keeps failing the same categories of test, what comparable countries did differently, and where the practical build-out needs to happen over the next 18 months.
What FATF Actually Said
FATF's statement on Nepal, as reported following the 17–19 June Paris plenary, credited the government with closing some technical gaps on terrorist-financing and proliferation-financing sanctions, but concluded that the underlying "strategic deficiencies" remain unresolved. It set out six specific requirements Nepal must satisfy before it can exit:
- Deepen the understanding of money-laundering and terrorist-financing risk — at a sector and sub-sector level, not in the abstract.
- Strengthen risk-based supervision of commercial banks, high-risk cooperatives, casinos, dealers in precious metals and stones, and the real estate sector.
- Identify and act against hundi/MVTS operators — illegal money-or-value-transfer networks — without disrupting financial inclusion or legitimate remittances.
- Increase the investigative capacity and coordination of the Financial Information Unit, the Department of Money Laundering Investigation, and law enforcement.
- Demonstrate a measurable increase in money-laundering investigations and prosecutions that actually reach the courts.
- Build a functioning mechanism to identify, trace, freeze and confiscate criminal proceeds in line with the country's risk profile.
Two things are worth noticing about that list. First, four of the six points (1, 2, 3, 6) are fundamentally about visibility — knowing where the risk sits, seeing transactions as they happen, and being able to trace assets after the fact. Second, an APG delegation that visited Kathmandu in May 2026 to check progress came away unimpressed: according to reporting based on conversations with more than six officials present, the delegation flagged institutional interference in investigations, weak follow-through on confiscation, and continued gaps in monitoring the exact high-risk sectors FATF had already named a year earlier. The APG explicitly warned that Nepal risks moving toward the black list rather than off the grey list if the next four-month review cycle shows the same pattern.
The Visibility Gap, in One Statistic
The clearest evidence that this is a supervision-technology problem rather than a statute-book problem sits in Nepal's own suspicious transaction reporting (STR) data. Of total STRs filed, commercial banks accounted for roughly three-quarters. Cooperatives — repeatedly named by FATF as a high-risk sector — filed a small fraction of that volume. Casinos filed almost none. This is not because cooperatives and casinos are inherently cleaner than banks; it is because banks have core banking systems, transaction-monitoring software, and compliance officers, and most of Nepal's 31,000-plus cooperatives have none of that.
The cooperative sector's own crisis makes the point starkly. Parliamentary committees and the government's Problematic Cooperative Management Committee have traced tens of billions of rupees in embezzled depositor savings across dozens of failed or "crisis-ridden" cooperatives, with tens of thousands of depositors affected — funds diverted through unauthorised loans, fictitious transactions, and unrelated business ventures, often undetected for years because there was no real-time audit trail and no independent off-site supervision. The government's own 2026 reform roadmap explicitly calls for "technology-driven off-site supervision" of cooperatives as a remedy, and the IMF's 2024 Article IV consultation recommended creating a dedicated, properly resourced regulator for financial cooperatives. A new National Cooperatives Regulatory Authority task force, coordinated through Nepal Rastra Bank, is now drafting exactly that kind of supervisory standard.
In other words: Nepal's policymakers have already diagnosed that the missing piece is supervisory infrastructure, not supervisory intent. That diagnosis lines up precisely with what FATF is asking for in points 1, 2 and 6 of its action plan.
What Other Grey-Listed Countries Actually Built
Two precedents are directly instructive, because both treated FATF compliance as a systems-engineering problem rather than a legislative one.
Pakistan (2018–2022). Pakistan entered the grey list compliant with roughly ten of FATF's forty recommendations and exited compliant with around thirty-five. A meaningful part of that improvement came from designating the Institute of Chartered Accountants of Pakistan as the AML/CFT regulator for its Designated Non-Financial Businesses and Professions — accountants, real estate agents, and dealers in precious metals and stones, the exact category Nepal is now being told to supervise. ICAP built a risk-based supervision framework, an automated off-site monitoring system for reporting firms, and an automated risk-matrix engine to score each firm's ML/TF exposure from its own filings — essentially a regtech platform layered on top of a sector that had previously been supervised by name only. It paired that with a sustained, multi-year training programme reaching over a thousand professionals. The lesson Pakistan's own later experience reinforces: FATF re-flagged Pakistan in 2025 for renewed terror-financing channels moving through unregulated digital wallets and fintech platforms, three years after exit. Compliance infrastructure that isn't maintained decays; a one-time scramble to exit is not the same as a durable system.
Mauritius (2020–2021). Mauritius went from listing to delisting in about eighteen months — the fastest comparable exit on record — under a committee chaired by the Prime Minister. The specific reforms FATF credited were: outreach that genuinely improved sector-level understanding of ML/TF risk; a working risk-based supervision plan for its capital markets regulator; and, critically, ensuring competent authorities had timely access to accurate beneficial ownership information. Mauritius didn't pass new laws and stop there — it built the registries, the access protocols, and the supervisory cadence that made the laws operable.
The common thread: both countries' fastest progress came from building the data and supervision infrastructure that sits underneath the legal text — not from passing additional acts of parliament.
What Should Be Built, Concretely
Mapped against FATF's six points, the practical build-out for Nepal over the next 18 months looks like this:
- A sectoral ML/TF risk-mapping system. A living, data-backed risk register across banking, cooperatives, real estate, casinos, and precious metals/stones — not a static document, but a dashboard fed by actual filings, refreshed each review cycle, and shared across NRB, SEBON, the Department of Cooperatives, and the FIU.
- Off-site, automated supervision for cooperatives, casinos and DPMS. A Nepali analogue to the ICAP model: a reporting and risk-scoring platform that lets a small regulatory authority supervise thousands of entities without physically inspecting each one — directly answering both the cooperative crisis and FATF's point 2.
- A functioning beneficial-ownership registry, digitised and queryable by the FIU, the Department of Money Laundering Investigation, and law enforcement in real time — the single reform Mauritius's case shows matters most for closing point 1 and point 6 simultaneously.
- Formalised, lower-friction digital remittance and lending rails that out-compete hundi on cost and convenience rather than relying on enforcement alone — channelling FATF's explicit instruction to act against MVTS operators "without hindering financial inclusion." This is squarely where regulatory-sandbox-tested digital lending and payment models, built and supervised correctly from day one, do double duty: financial inclusion and AML/CFT compliance, not a trade-off between them.
- Tamper-evident audit trails for high-risk asset classes — gold and precious-metal dealers, real estate transactions, and large cooperative loans — using the same distributed-ledger logic already proven in verifiable certificate issuance for renewable energy assets: a record that regulators, auditors and law enforcement can all trust without trusting each other first.
- Interagency data interoperability so that NRB's goAML system, SEBON's surveillance data, the Department of Cooperatives, and law enforcement are working from one shared, current risk picture rather than five separate ones — directly addressing FATF's point 4 on coordination capacity.
None of this requires Nepal to invent new legal categories. The Asset (Money) Laundering Prevention Act, the AML/CFT National Strategy and Action Plan (2081–2086), and the SEBON and Department of Cooperatives AML/CFT directives already exist. What is missing is the technology and data layer that makes those instruments observable and enforceable in real time — the same gap that both Pakistan's DNFBP regulator and Mauritius's beneficial-ownership push were built to close.
Where This Connects to Silicon Himalayas' Work
This is precisely the layer Silicon Himalayas operates in: advisory and technology infrastructure for regulated, high-risk, and capital-intensive sectors in Nepal. The firm's blockchain-based verification work for renewable energy certificates demonstrates the same underlying capability FATF's points 1, 2 and 6 require — tamper-evident, auditable records that regulators and counterparties can rely on without re-verifying from scratch. The advisory work already underway on Nepal Rastra Bank's regulatory sandbox process, and on structuring digital lending partnerships, sits directly inside FATF's instruction to formalise remittance and lending channels without undermining financial inclusion. And the firm's Expert Committee structure across Finance, Law & Governance and Infrastructure & Urban Development clusters maps closely onto the institutions that will need to build or commission exactly the systems described above: NRB, the Department of Cooperatives, SEBON, and the banks and developers operating in sectors FATF has flagged.
For large infrastructure and energy projects moving through advisory pipelines right now — the kind that depend on clean FDI inflows and DFI participation — Nepal's grey-list status is not background noise. It is a live variable in how those deals get priced, documented, and timed. Building the supervisory infrastructure described above is not just a national compliance exercise; it is the precondition for the FDI and DFI capital that Nepal's broader infrastructure ambitions depend on.
The Clock
FATF reviews progress on a four-month cycle. Nepal entered its current action plan in February 2025 against a roughly two-year horizon, which puts the working deadline somewhere around early-to-mid 2027 — with several review checkpoints, not one final exam, in between. The APG's May 2026 warning that backsliding risks a move toward the black list, not just continued grey-listing, makes the next two review cycles the ones that matter most. Countries that treated this period as systems-building work — not paperwork — have exited in 18 months. Countries that treated it as paperwork are still on the list after a decade of intermittent effort. Nepal has been both kinds of country at different points in its history. Which one it is for the next 18 months is still being decided.
Silicon Himalayas is an advisory, technology, and green-verification partner to Nepal's energy, infrastructure, and fintech sectors. This article is part of an ongoing thought-leadership series connecting Nepal's regulatory developments to the infrastructure choices the country's institutions and investors need to make next.
Related Expert Committees
Regtech & Compliance Committee
AML/KYC automation systems, regulatory reporting infrastructure, smart contract audit frameworks, and compliance technology.
