Skip to main content
Category: Insider Trading Controls

Gray List

Also known as: Grey List, Greylisting, Grey-Listing, Jurisdictions Under Increased Monitoring
Simply put

A gray list is a formal designation identifying countries that have shortcomings in their systems for preventing financial crimes such as money laundering, but that are actively working with an oversight body to fix them. Being placed on the list signals heightened scrutiny rather than an outright prohibition, and it can affect a country's reputation and investment appeal. The term is used most prominently by the Financial Action Task Force (FATF), though it also carries a distinct, unrelated meaning in securities trading.

Formal definition

In the anti-money laundering and countering the financing of terrorism (AML/CFT) context, the 'gray list' refers to the FATF's public roster of 'Jurisdictions under Increased Monitoring', countries identified as having strategic deficiencies in their AML/CFT regimes that have committed to, and are actively working with the FATF to resolve, those deficiencies within agreed timeframes. Placement subjects a jurisdiction to increased monitoring and can prompt other countries and financial institutions to apply enhanced due diligence to transactions involving that jurisdiction; it is distinct from the FATF 'black list' of high-risk jurisdictions calling for countermeasures. The term also has a separate, jurisdiction-specific meaning in securities markets, where a 'gray list' is a formal roster of stocks that a bank's block trading desk may trade but that are restricted from risk arbitrage activity because the investment bank is involved with the issuing company. This entry is educational and not a substitute for qualified legal or compliance advice; specific listing criteria, current listed jurisdictions, and applicable obligations should be confirmed against primary FATF publications and relevant local regulators.

Why it matters

For AML/CFT compliance teams, a jurisdiction's placement on the FATF gray list is a signal that can reshape how an organization treats transactions and business relationships connected to that country. Because gray-listing identifies strategic deficiencies in a country's AML/CFT regime, financial institutions and other regulated entities may respond by applying enhanced due diligence to transactions involving the listed jurisdiction. This is a matter of heightened scrutiny rather than prohibition, and it is distinct from the FATF black list of high-risk jurisdictions for which countermeasures are called for.

Beyond direct compliance obligations, gray-listing carries reputational and economic consequences for the affected country. Being placed on the list signals that a jurisdiction is seen as not doing enough to prevent financial crimes such as money laundering, which can reduce its investment appeal. At the same time, listing reflects that the country has committed to working with the FATF to remediate the identified deficiencies within agreed timeframes, so the designation is meant to drive improvement rather than to permanently penalize.

The term also requires care because it carries a second, unrelated meaning in securities markets. In that context, a gray list is a bank's internal roster of stocks that a block trading desk may trade but that are restricted from risk arbitrage activity because the investment bank is involved with the issuing company. Compliance and training staff should be alert to which meaning applies in a given context, as the two concepts serve entirely different functions. Specific listing criteria, the current roster of listed jurisdictions, and any applicable obligations should be confirmed against primary FATF publications and relevant local regulators, and this entry is educational rather than a substitute for qualified legal or compliance advice.

Who it's relevant to

AML/CFT Compliance Officers
Compliance officers use the FATF gray list to identify jurisdictions where enhanced due diligence may be warranted. Because listing signals strategic AML/CFT deficiencies rather than an outright prohibition, teams must calibrate their response and confirm current listed jurisdictions and applicable obligations against primary FATF publications and local regulators.
Ethics and Compliance Training Designers
Those building training content should present the gray list accurately as one input into risk-based due diligence, and clearly distinguish it from the FATF black list and from the unrelated securities-trading meaning of the term to avoid confusion among learners.
Legal and Audit Teams
Legal and audit staff assess how gray-listing affects the organization's obligations and controls. Because specific listing criteria and requirements vary and can change, and because the designation touches matters that may require qualified counsel, these teams should verify current details against primary sources and applicable local law.
Investment Bank Compliance and Trading Supervision
In the securities context, compliance and supervision staff maintain and enforce the internal gray list, ensuring that stocks on the roster may be traded by block desks but are kept out of risk arbitrage activity where the bank is involved with the issuing company.

Inside Gray List

Restricted Securities Scope
A list of securities in which trading is subject to conditions or limitations rather than an outright ban, typically because the firm possesses or may possess material non-public information (MNPI) or faces a potential conflict of interest. It sits within a firm's internal information-barrier and conflicts-management controls rather than being an externally mandated register.
Conditional Trading Permissions
Rules that allow certain activity to continue under supervision or with pre-approval, distinguishing the Gray List from a Restricted List where trading is generally prohibited. Conditions commonly include compliance pre-clearance, volume limits, or heightened surveillance.
Confidentiality and Need-to-Know Basis
Gray Lists are typically maintained confidentially and shared only with compliance and control-function personnel, so that the market and even some internal staff are not signaled that a firm may hold MNPI on a named issuer.
Trigger Events and Sources
The circumstances that cause a security to be added, such as the firm beginning work on a potential mandate, receiving sensitive information, or identifying a conflict. This links the list to the firm's deal-flow, research, and conflicts-clearance processes.
Monitoring and Surveillance Linkage
Connection to the firm's monitoring and auditing function, where trades in listed securities are surveilled to detect potential misuse of MNPI. The list is one input to surveillance, not a standalone control.

Common questions

Answers to the questions practitioners most commonly ask about Gray List.

Is the gray list the same as the restricted list, and can I use the terms interchangeably?
No. The gray list and the restricted list are distinct controls within information barrier frameworks, and treating them as interchangeable is a common misconception. They serve different functions and generally trigger different trading and disclosure consequences. Because the specific handling of each list is governed by internal policy and applicable securities regulation that varies by jurisdiction, you should confirm your organization's definitions against its own policies and qualified legal counsel.
Does placing a security on the gray list guarantee the firm avoids insider trading or regulatory liability?
No. Inclusion on a gray list is intended to support the management of conflicts and material non-public information, but it does not guarantee prevention of misconduct or provide legal protection. Effectiveness depends on how the control is implemented, monitored, and enforced alongside other program elements. This entry is educational and not a substitute for advice from qualified legal counsel.
Who is typically responsible for maintaining the gray list within a firm?
Responsibility generally sits with a control function such as compliance, often working with a control room or information barrier team. The specific ownership, escalation paths, and approval authority are defined by internal policy and should be documented so that roles are clear. Confirm your organization's assigned responsibilities against its own governance structure.
How does a gray list fit within a broader compliance program rather than functioning on its own?
A gray list is one control within a larger information barrier and conflicts-management system; it does not by itself constitute a complete compliance program. It typically operates alongside other components such as policies, monitoring and auditing, training, and escalation channels. Its value depends on integration with these elements and on consistent implementation.
What should training on gray list procedures aim to cover?
Training on gray list procedures is generally intended to help relevant staff understand when and how the list is applied, what restrictions or monitoring may follow, and how to escalate questions. Note that a training module is only one component and does not substitute for the underlying controls, monitoring, or governance that give the list effect.
How should firms handle the confidentiality of the gray list itself?
Because the gray list may reflect sensitive information about pending or potential activity, its contents are typically restricted to authorized personnel and handled under confidentiality controls. The specific access restrictions and handling requirements are set by internal policy and applicable regulation, which vary by jurisdiction, and should be confirmed with qualified counsel and against your organization's own procedures.

Common misconceptions

A Gray List and a Restricted List are the same thing.
They are distinct control tools. A Restricted List generally prohibits trading or activity in named securities, while a Gray List (also called a Watch List) permits activity under monitoring or conditions and is often maintained more confidentially. Firms commonly operate both as complementary layers.
A Gray List is a regulatory requirement with a standardized, externally defined format.
The Gray List is an internal firm-designed control used to manage MNPI and conflicts. Its structure, triggers, and thresholds vary by firm and by applicable local law. Specific regulatory obligations that inform its use should be confirmed against primary sources and qualified legal counsel for the relevant jurisdiction.
Placing a security on the Gray List prevents insider trading or guarantees legal protection.
The list is intended to support the management and surveillance of information barriers, but it does not by itself prevent misconduct or confer legal protection. Its effectiveness depends on implementation, the strength of surrounding controls, and consistent enforcement.

Best practices

Document clear, written criteria for what triggers addition to and removal from the Gray List, and tie those triggers to deal-flow, research, and conflicts-clearance processes.
Maintain the list on a strict need-to-know basis limited to compliance and relevant control functions to preserve confidentiality and avoid signaling potential MNPI.
Integrate the Gray List with active trade surveillance so that activity in listed securities is monitored, and define the conditions or pre-clearance steps that apply.
Clearly differentiate Gray List and Restricted List procedures in policy so staff understand which restrictions and conditions apply to each.
Establish a defined review and escalation cadence to update entries promptly as trigger events arise or conclude, and record the rationale for each change.
Confirm the specific legal and regulatory obligations shaping the list against primary sources and qualified legal counsel for each applicable jurisdiction, treating this guidance as educational rather than legal advice.