Mutual Recognition
Raeez Lorgat, 2026
When an entity enters an additional jurisdiction, its compliance is evaluated afresh against that jurisdiction’s rules. The channel through which it enters — the corridor from a jurisdiction where it already operates to the one it is entering — carries this cost as a re-evaluation set: the compliance domains the destination re-evaluates locally instead of accepting the entity’s existing evaluations. The question is how small the re-evaluation set can be made in principle.
The redundancy problem
Much of the re-evaluation is redundant. Regulatory requirements descend, domain by domain, from common standards: anti-money-laundering (AML) regimes implement the Financial Action Task Force (FATF) Recommendations — the same know-your-customer duties, the same suspicious-transaction reporting; bank capital rules implement the Basel framework; data-privacy statutes in many jurisdictions track the EU’s General Data Protection Regulation. Where two jurisdictions implement the same standard and enforce it comparably, a second full evaluation at the destination adds cost without adding regulatory information. Where Pakistan and Singapore both build their AML regimes on the FATF Recommendations and hold comparable assessments, a second full AML evaluation discovers nothing the first did not; where the UAE and Bahrain impose materially equivalent data-privacy requirements, re-evaluation is duplicative.
The solution is mutual recognition: jurisdiction A accepts jurisdiction B’s evaluations in stated domains, and B accepts A’s. An entity that passes AML evaluation in A is not re-evaluated for AML on entering B. The compliance work is done once and honored twice.
The principle is established practice, and so is its application per domain and under conditions. A product lawfully marketed in one EU member state circulates in the others; the 1998 EU–US Mutual Recognition Agreement applies the principle to conformity assessment; professional-licensing reciprocity applies it to qualifications. The EU’s equivalence decisions recognize a third country’s regime one legal act at a time, on conditions, revocable, and at times for a stated period: a non-EU clearing house is recognized under Article 25 of the European Market Infrastructure Regulation only after the Commission has decided that its home framework is equivalent, and the equivalence granted to Swiss stock exchanges for the obligation to trade shares on recognized venues was limited from the start to the end of 2018, extended once to 30 June 2019, and not renewed. United States substituted compliance likewise recognizes per requirement and on conditions: foreign swap dealers satisfy stated Dodd-Frank requirements by complying with a home regime the Commodity Futures Trading Commission has found comparable, as it has for Australia, Canada, the EU, Hong Kong, Japan, and Switzerland since December 2013. What existing practice does not supply is one vocabulary of grades across domains and instruments, and the recognized terms in a form a system can execute.
Binary recognition is too coarse
The naive form of recognition is binary: a jurisdiction’s evaluations are accepted or they are not. This is too coarse to be useful.
Consider three jurisdictions evaluating AML compliance. Jurisdiction A has a robust, well-enforced regime. Jurisdiction B has the rules without the enforcement: compliant in letter, weak in operation. Jurisdiction C has fundamental deficiencies. Binary recognition puts A and B in the same class — accept both or reject both — when the right treatment is graded: accept A’s evaluations, accept B’s subject to review, decline C’s.
The FATF’s assessment methodology supplies the calibration, and a necessary caution. FATF rates each jurisdiction’s AML framework on two scales: technical compliance, per Recommendation, from Compliant down to Non-Compliant; and effectiveness, per outcome, from High down to Low. The scales diverge, and the divergence is exactly the distinction between A and B: a framework compliant in letter can still be weak in operation. But both scales rate national frameworks, not entities. A FATF mutual evaluation recognizes no entity’s compliance; it grades the regime under which entities are evaluated. A pair of favorable ratings is therefore evidence for setting a corridor’s recognition grade, never itself a portable pass. What recognition transports is the entity-level evaluation performed under the rated framework; the framework’s rating calibrates how far the destination trusts it.
A mutual recognition agreement should express that calibration directly, per domain:
Full recognition. The foreign evaluation is accepted without local re-evaluation. Warranted where the source regime is strong in letter and in operation.
Partial recognition. The foreign evaluation is accepted and flagged for local review. The natural grade where a regime is compliant in letter and uneven in operation.
Conditional recognition. The foreign evaluation is accepted only while a stated condition holds. The condition may bind the source jurisdiction’s standing — FATF membership in good standing, a treaty in force — or the particular evaluation, such as enhanced due diligence performed. While the condition fails, the grade behaves as no recognition.
No recognition. Full local re-evaluation. The foreign evaluation carries no reliable signal.
Recognition is assigned domain by domain. A jurisdiction may merit full recognition on AML and partial recognition on data privacy; its weak data-privacy regime says nothing about the quality of its AML evaluations, and its strong AML regime lends no credit to its data-privacy evaluations.
The sanctions exception
One domain is excluded from cross-sovereign recognition by default: sanctions. Recognition never carries a foreign sanctions clearance into local clearance; only the lists themselves can, under a condition this section makes exact. The exclusion is structural, and it turns on what recognition transports.
Recognition transports assessments of the entity. An AML evaluation asks whether the entity’s controls meet a standard; a data-privacy evaluation asks whether its handling of personal data meets one. These are facts about the entity, and where two standards are materially equivalent, one jurisdiction’s finding answers the other’s question.
Not every compliance domain has this shape. Whether an offering is registered, whether withholding has been remitted, whether goods have cleared customs, whether a currency transfer was authorized — these are statuses indexed to a single jurisdiction. Registration in A is not registration in B, and no equivalence of standards makes it so. Such statuses cross borders only under instruments that create the local status by law — passporting regimes, treaty credit for tax paid, customs unions — never by one jurisdiction accepting another’s finding. Recognition applies to the entity-intrinsic domains; the jurisdiction-indexed ones stay local regardless.
Sanctions is the limiting case, and the limit is exact. A sanctions clearance in A asserts exactly one thing: the entity appears on none of A’s lists. That is not an assessment of the entity; it is a membership test against A’s own designations. The destination’s question — does the entity appear on B’s lists — is a test against B’s designations, and A’s answer settles it exactly when every designation B applies is one A applies too, so that an entity on none of A’s lists is on none of B’s. Otherwise A’s clearance leaves B’s question open, and a corridor that accepted it as B’s would wrongly clear precisely the entities B has designated and A has not. The stakes compound where an extraterritorial regime is present. The United States regime reaches in practice the entire dollar-clearing system: dollar payments clear through United States banks, and 50 U.S.C. § 1702(a)(1) — section 203(a)(1) of the International Emergency Economic Powers Act — places transfers of credit or payments through any such bank, where a foreign interest is involved, under the President’s authority to regulate or prohibit. Its secondary sanctions rest on further authorities, the Countering America’s Adversaries Through Sanctions Act and the program-specific executive orders among them, which reach non-United States persons who deal with designated ones. A corridor that inherited clearance could carry forward a permissive verdict the United States does not recognize, exposing the entity’s dollar transactions to prohibition under the first authority and the entity itself to designation under the second.
The condition bears on how the lists are constituted, not on the entity, and it holds reliably only where it holds by construction: every list B applies is a list A applies, because both adopt it from the authority that sets it. It is directed, as the corridor is. Where B applies the United Nations Security Council’s consolidated list alone and A applies that list with national additions, A’s clearance settles B’s question, and B’s clearance does not settle A’s question, since the national designations are exactly what B never screened. Shared authority is the symmetric case, in which both sides apply exactly the shared lists and each direction inherits: Security Council designations under Chapter VII bind every member state, and EU sanctions are decided centrally and bind every member state identically. Within such a subnetwork, clearance against the shared lists is one test and the corridor inherits it; a member that adds national designations screens those itself, and sanctions leaves its re-evaluation set only where it adds none. This is also why the intra-EU case is no counterexample to the exclusion: member states share one centrally decided sanctions regime — the shared-authority case, not recognition between distinct sanctions sovereigns.
The corridor representation follows. Sanctions leaves a corridor’s re-evaluation set only under an explicit shared-authority certificate: a signed artifact certifying, for the corridor’s direction, that the destination applies no list the source does not, and naming the common authority or authorities, the covered lists or decision process, the bound parties, the validity window, and the revocation procedure. Every corridor outside such a certificate — every general-purpose corridor — re-evaluates sanctions locally, whatever else it recognizes, and so retains at least one domain evaluation.
Counting what recognition removes
To make the effect concrete, count domain evaluations. Take six jurisdictions forming two federations of three. Each pair of jurisdictions defines a corridor; there are fifteen, six choose two. A corridor is directed — each direction carries its own terms — but for counting let both directions carry the same terms and count each pair once; counting directions separately doubles every figure and changes no ratio. Suppose each cross-border corridor re-evaluates six domains: AML, sanctions, foreign-exchange controls, customs, tax withholding, and data privacy. Each intra-federal corridor re-evaluates three: AML, tax withholding, and data privacy — sanctions, customs, and exchange controls drop out because a single federal authority sets them for both sides, which for sanctions is exactly the shared-authority case.
The baseline across the network is the sum of domain evaluations over corridors: nine cross-border corridors at six each and six intra-federal corridors at three each, seventy-two evaluations.
Now introduce a four-party agreement at full recognition covering AML and data privacy — two entity-intrinsic domains present in every corridor’s baseline. The agreement reaches the six corridors among its parties, four choose two, and removes two evaluations from each: twelve of the seventy-two, one sixth of the network’s evaluations, from one agreement covering two domains. In general, a k-party agreement at full recognition over a domain set D removes |D| \cdot k(k-1)/2 evaluations, provided each covered domain lies in each affected corridor’s baseline.
These are counts of evaluations, not measures of cost. A count stands for cost only under an assumption of equal evaluation costs, and evaluation costs are not equal: a sanctions list screen is a lookup; an AML controls assessment is an audit. The counts are exact; an economic reading inherits whatever weights the domains carry.
Membership compounds the effect. When a fifth jurisdiction accedes, four new corridors come under the agreement at once: the (k{+}1)-th accession creates k recognized corridors, so the benefit of acceding grows linearly with membership. The cost of acceding depends on the instrument — negotiation with each member pair by pair, or a single act where the agreement carries an accession clause admitting new parties on its standard terms. The accession clause, not the recognition itself, is what keeps the cost of joining from growing with the membership.
The floor persists under any expansion. Recognition reaches the entity-intrinsic domains; the jurisdiction-indexed ones leave a baseline only under their own instruments — a customs union, an exchange-control exemption, treaty treatment of withholding. A corridor whose parties have all of those still screens sanctions locally. Recognition and union-type instruments together can bring a cross-sovereign corridor’s baseline to a single evaluation; only a certificate that the destination applies no sanctions list the source does not — shared authority being the symmetric case — brings it to zero.
The naming problem
Jurisdictions name the same regulatory concept differently: one’s “securities regulation” is another’s “capital markets oversight”; one’s “foreign-exchange controls” are another’s “currency transfer restrictions.” And the same name can span different substance: one jurisdiction’s “AML” covers money laundering alone, while another’s spans counter-terrorism financing as well.
A system that matches compliance domains by name inherits both failure modes. Different names for the same substance, and the destination finds no source evaluation to accept: work is redone that recognition should have saved. The same name for different substance, and a label-level match clears components the source never evaluated: the broader jurisdiction’s counter-terrorism-financing requirement stands satisfied by an evaluation that never examined it. The first failure wastes; the second admits what should have been checked.
The remedy is a domain map agreed at corridor formation: a translation between the two regulatory vocabularies, recorded as part of the corridor’s definition, and defined only where the corridor instrument certifies that the source evaluation covers the destination domain’s substance. The map is partial. A domain without a certified counterpart is not mapped, so a missing entry costs redundant evaluation, never a missed requirement; where coverage is genuinely partial, the corridor declines the mapping or recognizes at a grade conditioned on local evaluation of the remainder.
The map also bounds what recognition can do. An agreement shrinks the re-evaluation set only over domains the map connects; full recognition of AML is inert until the corridor records which destination domain that recognition reaches.
Recognition as a computable object
Mutual recognition today lives in legal text: treaties and equivalence decisions, implemented through regulations and supervisory guidance, applied by compliance staff, updated on regulatory time. That implementation sets the pace at which recognition acts. When entities cross dozens of corridors daily and every crossing must produce a re-evaluation set, the operative content of the agreement has to be queryable at machine speed.
What is needed is a computable representation of the treaty’s operative provisions: an object recording which jurisdictions are party, which domains are recognized, at what grade, under which conditions — an object a system can query (“does the agreement between A and B cover domain d, and how?”) and apply to a corridor so that the re-evaluation set adjusts mechanically.
This is not a replacement for the treaty. Treaty text carries preambles, definitions, dispute-resolution procedures, sunset clauses. The computable object carries the one part every crossing consults: which domains, at what grade, under which conditions.
The formalization forces precision. Recognition expressed as a grade per domain admits no residual ambiguity: either AML is fully recognized or it is not; either data privacy is conditionally recognized, with the condition stated, or it is not. Formalizing surfaces at negotiation time the gaps an informal arrangement leaves to be discovered at the border.
The shape of the solution
The pieces assemble into one parameterization. A corridor from jurisdiction A to jurisdiction B is a directed triple (R, \mu, \gamma): a re-evaluation set R of destination-side domains that B re-evaluates locally; a partial domain map \mu from A’s domain names to B’s, defined only where coverage of substance is certified and one-to-one — each recognized source domain reaches one destination domain, and each destination domain is fed by at most one source domain; and per-domain grade maps \gamma stating how B consumes recognized evaluations — at full strength, flagged for review, or under conditions, and never at more than their source strength, so recognition cannot strengthen a foreign verdict in transit. The one-to-one form is chosen for its grade maps, which then run from one source coordinate to one destination coordinate, and it has a bounded price. Where one source evaluation certifiably covers several destination domains — a broad AML evaluation that examined terrorism financing covers a destination’s separate money-laundering and terrorism-financing domains — the instrument records one of them at formation and the rest fall to local re-evaluation: redundant work, never a missed requirement. The maps are partial and fail closed: a destination domain \mu does not reach, and a source grade \gamma does not define, both fall to local re-evaluation. Corridors are directed because recognition is directed: A’s acceptance of B’s AML evaluations does not imply B’s acceptance of A’s, and each direction carries its own triple.
A mutual recognition agreement is an instrument that instantiates (\mu, \gamma) and shrinks R. Several agreements may apply to one corridor, and they compose by a fixed rule. The map is one recorded object: where applicable agreements certify different source domains for the same destination domain, the corridor records one entry at formation, and only grades attached to the recorded source evaluation count. Grades compose by taking the strongest. At a crossing, each applicable grade resolves — a conditional grade to full while its condition holds and to none while it fails — and B consumes the strongest resolved grade under the order none, partial, full; each agreement is a separate undertaking by B to accept the evaluation on its terms, so the entity crosses on the most favorable one. A destination domain leaves R when its strongest resolved grade is above none. Two properties follow from the definitions. Applying an agreement never enlarges R: a further agreement adds a ground for acceptance, and the strongest of more grounds is never weaker. And partiality is safe: because undefined inputs fail closed into local re-evaluation, an incomplete map degrades to redundant work, never to a missed requirement.
Sanctions is the standing exception. It leaves R only under an explicit shared-authority certificate, never by ordinary recognition, because a foreign clearance answers a question about foreign lists, and answers the local question only where the local lists are among them by construction.
The result is a precise, auditable answer to the question every crossing must ask: what compliance work remains? The re-evaluation set answers which domains B evaluates afresh: the domains that stand in R after every applicable agreement is applied. The work that remains is that local evaluation together with the obligations \gamma attaches to what it recognizes — the local review that partial recognition carries and the condition monitoring that conditional recognition carries. Under fixed corridor parameters R is deterministic, because the map is one recorded object and the grades compose by taking the strongest, which does not depend on the order in which agreements are applied; it is never enlarged by recognition; and, absent a shared-authority certificate over sanctions lists, it is never smaller than one domain: the local sanctions evaluation. The grades B consumes, and the obligations they carry, are determined with R: each is the strongest resolved grade for its domain under the same parameters.