Morocco: what a country does after it leaves the grey list
Morocco came off the FATF grey list in February 2023. The interesting part is what happened next — because de-listing is the point at which most jurisdictions slow down, and Morocco did the opposite.
Morocco came off the FATF grey list in February 2023. The interesting part is what happened next — because de-listing is the point at which most jurisdictions slow down, and Morocco did the opposite.
Two markers tell that story better than any policy statement.
Cross-border cooperation went up, not down. In 2024 the ANRF — Morocco’s FIU — handled more than 340 cross-border data requests. A de-listed country with a quiet FIU is a country that reformed for the assessors. A de-listed country whose FIU is busier than before is one that reformed for itself.
The Exchange Office tightened where the risk actually sits. In 2026 the Office des Changes introduced stringent AML/CFT obligations for offshore holding companies, including a mandatory compliance officer. Offshore holding structures are exactly the vehicle a grey-list exit is supposed to clean up, and Morocco went back to them a year after leaving.
Who supervises what
| Body | Scope |
|---|---|
| ANRF | The FIU — STR processing, Egmont and Interpol cooperation, national AML strategy |
| Bank Al-Maghrib | Central bank and primary supervisor of financial institutions; issued the practical AML-CTF guide with ANRF and AMMC |
| AMMC | Capital Market Authority — AML/CFT co-regulator for the securities sector |
| Office des Changes | Exchange control — the 2026 offshore holding company obligations |
| CNDP | Data protection — directly relevant to how you process KYC and CDD data |
Two things about that table are worth pausing on.
First, Bank Al-Maghrib, the ANRF and the AMMC published joint practical guidance. Joint guidance is rare and it is a signal: it means the three bodies intend to be read together, and a programme that satisfies one while contradicting another has no defence.
Second, CNDP is on the list. Morocco treats KYC data processing as a data protection question as well as an AML one. Firms that lift a group CDD programme from another jurisdiction routinely miss this, and it is the kind of gap that surfaces in a complaint rather than an inspection.
The regional frame
Morocco is a MENAFATF member state, and the 42nd MENAFATF Plenary was held in Rabat in 2026. Hosting a plenary the year after tightening offshore rules is a positioning move as much as a procedural one — regional typologies emerging from that plenary are a reasonable preview of where Moroccan supervisory attention goes next.
Three things worth doing this week
- If you have Moroccan offshore holding structures in your book, confirm the compliance officer exists. Named, appointed, reachable — not a line in a service agreement.
- Read the joint BAM/ANRF/AMMC guide as one document, and check your programme against all three perspectives rather than the one that supervises you directly.
- Add CNDP to your data-processing register review. If your KYC retention and transfer language was written for another jurisdiction, it probably does not survive contact with Moroccan data protection law.
Leaving the grey list is a milestone, not a finish line. Morocco appears to be treating it that way — and firms operating there should read the 2026 offshore rules as the opening move, not the closing one.
Sources
This article draws on the following sources. Follow the links for the original text.
AML beginner compliance financial-crime jurisdiction-briefing know-your-regulator morocco