FATF Crypto Standards in 2026: Virtual Assets, VASPs, and Recommendation 15 Explained

FATF Crypto Standards in 2026: Virtual Assets, VASPs, and Recommendation 15 Explained

FATF's Seventh Targeted Update, published on 16 July 2026, shows measurable progress in global implementation of Recommendation 15 — but also a shift in where the biggest gaps now sit. As of April 2026, 34% of assessed jurisdictions (51 of 149) are Largely Compliant with R.15, up from 29% a year earlier, while only one jurisdiction is fully Compliant. At the same time, only 40% of assessed jurisdictions (59 of 149) satisfactorily meet FATF's VASP licensing and registration criterion.

The problem is not simply whether a jurisdiction has announced a crypto AML framework. FATF is now focusing on whether risk assessments lead to real mitigation, whether licensing regimes operate in practice, whether supervisors identify unlicensed VASPs, whether the Travel Rule is actually enforced, and whether emerging risks involving stablecoins, unhosted wallets, offshore VASPs, and DeFi are reflected in operational controls.

In practical terms, the way crypto businesses experience FATF is indirect but inescapable. You feel FATF through your licensing regime, your customer due diligence obligations, your wallet and transaction screening, your sanctions checks, your Travel Rule readiness, and your suspicious activity reporting workflows. FATF does not write local crypto laws, does not license exchanges, and does not fine custodians. What it does is set the global AML/CFT baseline that countries are expected to translate into their own legislation — and as the 2026 figures show, that translation is still uneven across the jurisdictions covering approximately 97% of global VASP activity.

This guide explains the framework end-to-end: what FATF is, why Recommendation 15 sits at the center of crypto compliance, what counts as a virtual asset, who is a VASP, and what the standards mean for compliance teams heading into the second half of 2026.

What Is FATF and Why Does It Matter for Crypto?

The Financial Action Task Force is an intergovernmental body created to set international standards for combating money laundering, terrorist financing, and proliferation financing. It is a standard-setter, not a regulator. It does not issue crypto licenses, does not directly supervise exchanges, and has no authority to penalize an individual VASP. What it does have is enormous influence over the countries that do.

In practical terms, FATF works through three mechanisms that crypto businesses should understand:

  • Global Recommendations: FATF publishes a set of international AML/CFT standards that member states commit to implement. Recommendation 15 is the one that brought virtual assets and VASPs into the framework in 2018–2019.
  • Mutual Evaluations: FATF and its regional bodies (FSRBs) review each country's compliance through detailed peer assessments. Poor outcomes can lead to public listing on the FATF "grey list," which has direct consequences for banking relationships, foreign investment, and cross-border payment flows.
  • Targeted Updates and Guidance: FATF publishes periodic reports — including the 2025 Targeted Update on virtual assets and the March 2026 report on stablecoins and unhosted wallets — that signal supervisory expectations and shape how local regulators interpret existing rules.

The chain of influence runs from FATF Recommendations → National Legislation → Licensing and Supervisory Rules → Enforcement Actions against individual businesses. So when a crypto exchange in the EU is asked by its CASP supervisor for a documented risk assessment, or when a U.S. money services business is examined on its sanctions controls, the underlying logic is almost always traceable back to FATF expectations.

📖
For a deeper view of how these expectations harden into binding rules at the country level, see our overview of Global Crypto AML Regulations.

FATF Recommendation 15: The Core Standard for Virtual Assets

Recommendation 15 originally addressed risks from "new technologies" generally. In October 2018, FATF amended R.15 to explicitly cover virtual assets and VASPs, and in June 2019 it adopted an updated Interpretive Note (INR.15) that spells out exactly how countries should apply AML/CFT measures to the sector. That is the moment crypto formally entered the global AML framework. In practical terms, R.15 requires countries to do four things for the virtual asset sector: conduct a VA/VASP risk assessment, license or register VASPs, subject VASPs to supervision by a designated competent authority, and apply the full preventive measures toolkit — customer due diligence, recordkeeping, suspicious transaction reporting, internal controls, the Travel Rule, and sanctions screening — in the same way they apply to traditional financial institutions. What this means in plain language is that Recommendation 15 is not a single rule — it is the structural floor under everything else a crypto AML program does. Risk assessments, licensing, supervision, KYC, monitoring, recordkeeping, the Travel Rule: each of these flows from R.15 and INR.15.

Recommendation 15 and Its Interpretive Note

The Interpretive Note to Recommendation 15 is where the practical substance lives. It defines a virtual asset, defines a VASP, sets the activities-based scope of who is covered, and explains how the preventive measures in FATF's other Recommendations should be applied to virtual asset transfers — including the specific information that must accompany VA transfers under the Travel Rule. In practical terms, when a national regulator drafts a crypto AML regime, it is almost always working from INR.15 paragraph by paragraph. The structure of the EU's MiCA-adjacent AML rules, the UK's FCA registration regime for crypto-asset businesses, and the US FinCEN approach to convertible virtual currency all map onto INR.15 categories, even where the local terminology differs.

What FATF Means by Virtual Assets

FATF's definition of a virtual asset is deliberately broad and function-based. A virtual asset is a digital representation of value that can be digitally traded or transferred and used for payment or investment purposes. It does not have to be a "coin" in the colloquial sense.

Cryptocurrencies — Bitcoin, Ether, and other native blockchain assets used for payment or investment — fall squarely within the FATF VA definition. Stablecoins — both fiat-backed and crypto-collateralized — are virtual assets under FATF's framing. FATF's March 2026 Targeted Report on Stablecoins and Unhosted Wallets reaffirmed that stablecoin issuers, intermediary VASPs, and other participants should be covered by R.15-aligned controls. Many tokens qualify based on their function — payment and investment-purpose tokens generally are; pure utility tokens with no transferable value may not be.

A few things are deliberately not virtual assets in the FATF sense: fiat currencies, securities and other financial assets already covered by other FATF Recommendations, and central bank digital currencies (which FATF treats as fiat). NFTs and DeFi assets are handled case-by-case based on the actual function they perform — a tokenized investment product behaves like a VA, a unique collectible without payment or investment use generally does not. The cautious framing matters because FATF takes a substance-over-form approach. What determines coverage is the activity and the function of the asset, not the label its issuer uses. A compliance team cannot decide it is outside scope simply because a token is marketed as a "utility" or a service is described as "decentralized." The test is what the asset and the service actually do.

What FATF Means by VASPs

The VASP definition is similarly activities-based. A virtual asset service provider is any natural or legal person who, as a business, conducts one or more of the following activities on behalf of another natural or legal person: exchange between VAs and fiat, exchange between forms of VAs, transfer of VAs, safekeeping or administration of VAs or instruments enabling control over VAs, or participation in and provision of financial services related to an issuer's offer and/or sale of a VA.

The two phrases that do the heavy lifting are "as a business" and "on behalf of another." A wallet you run for yourself is not VASP activity. Pure software development without operational control is generally not VASP activity. But the moment a company holds, moves, or exchanges someone else's virtual assets in a business context, the VASP test is in play.

Why VASP Classification Matters

VASP status is the on-switch for nearly the entire crypto AML obligation set. Once a business is identified as a VASP under local law, it inherits the same kinds of obligations that apply to a bank, a payment institution, or a money transmitter: licensing or registration, an AML program, designated compliance personnel, customer due diligence, transaction monitoring, sanctions screening, Travel Rule compliance, recordkeeping, and suspicious activity reporting. The classification question is therefore not academic — it determines whether a business is operating legally and whether its banking partners, exchange counterparties, and institutional clients will engage with it at all.

📖
For the detailed scope test, see our explainer on Who Qualifies as a VASP.

Main AML/CFT Obligations Under FATF Crypto Standards

FATF crypto standards are sometimes mistaken for "just the Travel Rule." That undersells the framework by a wide margin. The full set of obligations that flow from R.15 and INR.15 forms a complete AML/CFT program: risk-based approach, customer due diligence (CDD), ongoing monitoring, sanctions screening, transaction monitoring (KYT), suspicious transaction reporting, recordkeeping, Travel Rule compliance, and internal controls and governance.

Risk-Based Approach

The risk-based approach (RBA) is the principle that runs through every other obligation. Rather than applying identical controls to every customer and every transaction, FATF expects businesses to focus resources where the ML/TF risk is highest — and to be able to document and defend that judgment.

The Seventh Targeted Update shows that 86% of responding jurisdictions (124 of 145) now report having conducted a VA/VASP risk assessment, up from 76% in 2025. But having a risk assessment is no longer enough. FATF specifically notes that many jurisdictions still struggle to translate those assessments into effective preventive measures, mitigation, supervision, and enforcement. The harder question is whether the findings actually change controls.

Transaction Monitoring and Suspicious Activity

KYC at onboarding answers the question "who is this customer." It does not tell you what they do next. FATF standards therefore require ongoing monitoring of customer activity to detect unusual patterns, identify potentially suspicious transactions, and trigger enhanced review or reporting where warranted. In a crypto context, that monitoring is inherently dual: it covers the customer's account activity and the on-chain risk profile of the addresses they interact with.

📖
Identity checks and transaction monitoring answer different but connected compliance questions — see our explainer on KYC vs KYT in Сrypto Сompliance for how the two fit together.

FATF Travel Rule: Important, but Not the Whole Framework

The Travel Rule is the most discussed FATF crypto requirement and one of the least consistently enforced. It requires VASPs and financial institutions to obtain, hold, and transmit specific originator and beneficiary information when they conduct qualifying virtual asset transfers — analogous to the wire-transfer information rules that have applied to banks for decades. The Seventh Update numbers show why the Travel Rule keeps appearing on FATF's priority list.

  1. Legislative Progress. 83% of relevant respondents (91 of 109) have passed Travel Rule legislation, up from 73% (85 of 117) in 2025. An additional 11 jurisdictions are in the process of implementing it.
  2. Operational Gap. Legal adoption is now much broader than practical enforcement. Of the jurisdictions that already have Travel Rule legislation, 60% (55 of 91) had not yet issued relevant findings or directives or taken Travel Rule-focused supervisory or enforcement action. The gap is no longer primarily about whether countries have written the law — it is about whether the law is supervised and enforced.
  3. Cross-Border Fragmentation. Counterparty implementation continues to differ across jurisdictions. The challenge is now broader than classic "sunrise" issues: law may exist, technical implementation may exist, but supervision may still be immature and counterparty practices may vary.

For a focused walkthrough of the rule itself — what data must travel, what the thresholds are, and how VASP-to-VASP messaging works — see our guide to the FATF Crypto Travel Rule. For the operational reality across counterparties, our piece on Travel Rule Implementation Challenges covers where teams are still getting stuck.

The point to keep in mind is that the Travel Rule is one obligation among many under Recommendation 15. Treating Travel Rule compliance as a proxy for FATF compliance leaves significant blind spots in licensing, risk assessment, monitoring, and reporting.

How FATF Standards Become Local Crypto Regulations

FATF Recommendations are not law. They only become enforceable when a country transposes them into national legislation, regulation, or supervisory rules. That transposition is where the variation lives.

European Union — a combined regulatory package covering crypto-asset markets, AML obligations, and a transfer-of-funds regime that operationalizes the Travel Rule for crypto. United States — the Bank Secrecy Act and FinCEN regulations for money services businesses, layered with state money-transmitter regimes and product-specific rules. United Kingdom — FCA registration for crypto-asset businesses under the Money Laundering Regulations, with the UK Travel Rule applied from 2023. Other jurisdictions — a wide spectrum, from comprehensive VASP regimes (Singapore, UAE, Hong Kong) to partial frameworks or outright prohibition.

💡
For region-specific deep dives, see our guides to US crypto AML Regulations, EU Crypto Travel Rule Requirements, and UK Crypto AML Regulations.

A multi-jurisdictional crypto business cannot just "comply with FATF." It has to comply with the specific local transposition wherever it operates, while also accounting for the gaps between countries that affect cross-border activity.

What Changed by 2026: FATF Implementation Progress and Remaining Gaps

FATF published its Seventh Targeted Update on 16 July 2026. The core takeaway: progress continues, but implementation quality is now the bigger problem.

Headline data. R.15 Largely Compliant: 34% (51 of 149), up from 29% in 2025. VA/VASP risk assessment completed: 86% (124 of 145), up from 76%. Regulatory approach decided: 89% (128 of 144), up from 82%. VASP licensing or registration requirement: 73% (95 of 130) of relevant respondents. At least one VASP actually licensed or registered: 58% (76 of 130). Assessed jurisdictions satisfactorily meeting the licensing criterion: 40% (59 of 149). Travel Rule legislation: 83% (91 of 109), up from 73%.

Operational licensing remains uneven despite broader regulatory frameworks. FATF cautions that different respondent groups and self-reported data across survey cycles affect comparability — year-over-year numeric comparisons should be read carefully.

The gaps that define 2026. Risk assessments are not consistently translated into mitigation — many jurisdictions report having conducted one but struggle to demonstrate that findings actually change preventive measures or supervisory intensity. Licensing frameworks exist more often than they operate effectively in practice. Identifying entities performing VASP activity without appropriate licensing remains difficult for most supervisors. Travel Rule legislation has advanced faster than supervision and enforcement. And offshore VASPs and DeFi continue to expose gaps between jurisdictional frameworks.

FATF separately notes that offshore VASPs exploit weaker regulatory environments through cross-border operations without effective supervision, nested activity through regulated onshore VASPs, and cases where offshore entities may misrepresent themselves as retail customers. Regulatory arbitrage remains a persistent challenge — a problem explored in depth in our article on how crypto businesses should identify and manage offshore VASP exposure.

DeFi. The Seventh Update reports that 31% (44 of 142) of jurisdictions have risk-mitigation measures applying to DeFi arrangements. Only four jurisdictions reported licensing or registration requirements for qualifying DeFi arrangements, and only two reported actually licensing or registering such arrangements. The problem is not that FATF automatically treats every DeFi protocol as a VASP — it remains identifying where control or sufficient influence exists and then applying the standards to qualifying arrangements. For the operational compliance side of DeFi interactions, our article on AML due diligence for DEXs, bridges, and DeFi protocols covers how businesses assess protocol-level risk.

Risks. FATF's risk focus has become noticeably broader. The Seventh Update documents convergent risk patterns involving organised crime-linked scam centres, pig-butchering and investment fraud, DPRK-related cyber theft, terrorist and proliferation financing, sanctions evasion, stablecoins, P2P transactions through unhosted wallets, offshore VASPs, OTC brokers, cross-chain tools, and DeFi. FATF increasingly describes these risks as convergent rather than isolated — a single fraud network may simultaneously use stablecoins, unhosted wallets, OTC channels, offshore VASPs, and cross-chain infrastructure.

Stablecoins and unhosted wallets. FATF now explicitly includes institutional risk from stablecoins, P2P transactions, and unhosted wallets among private-sector priorities. The 2026 survey found that 88% of the 66 jurisdictions that rated P2P risk classified it as High Risk — but only 23% (31 of 133) of respondents reported collecting and assessing P2P market metrics. This combination of high perceived risk and weak measurement capacity does not mean that an individual self-hosted-wallet transfer should automatically be classified as suspicious or prohibited — it means that the sector-wide risk assessment is still developing.

What This Means for Crypto Businesses

FATF's Seventh Update includes specific recommendations to the private sector. FATF recommends that VASPs understand institutional risk, assess stablecoin, P2P, unhosted-wallet, offshore VASP, and DeFi risks, keep AML controls adaptable to new typologies, strengthen monitoring of higher-risk unhosted-wallet activity, use transaction monitoring and blockchain analytics to identify suspicious patterns and rapid fund movement, conduct deeper due diligence on higher-risk offshore VASPs, assess DeFi exposure including bridges, mixers, and cross-chain tools, and cooperate with authorities and relevant private-sector participants.

The practical implication is that controls need to respond to the risk assessment rather than merely exist as isolated compliance features. Identifying unhosted-wallet risk but not changing monitoring is weak implementation. Identifying offshore VASP risk but doing no counterparty enhanced due diligence is weak implementation. Having Travel Rule policy but no operational supervisory readiness is incomplete implementation. Identifying cross-chain and DeFi exposure but having no relevant monitoring response is a disconnect between risk assessment and mitigation.

A realistic note: no tool or vendor "delivers FATF compliance" as a product. FATF compliance is a legal status determined by jurisdiction-specific law and supervisory judgment. What tools can do is support specific controls — KYT, sanctions screening, Travel Rule messaging, case management — that compliance teams use to meet those obligations.

What FATF Crypto Standards Mean for Compliance Teams

For compliance teams, FATF crypto standards function as a design specification. Even where local law is silent or lighter, building to the FATF baseline gives a defensible structure that holds up across regulators, auditors, and counterparties. A compliance program built on the FATF baseline typically covers an AML/CFT risk assessment, onboarding and CDD, wallet and transaction screening, alert review process, sanctions exposure checks, Travel Rule readiness, recordkeeping and audit trail, and internal policies and training.

Those FATF-aligned controls should be documented and testable when examined by a supervisor or external reviewer. For preparation, see our guide on Crypto AML Audit Requirements.

Common Misunderstandings About FATF and Crypto

FATF Standards Are Not the Same as Local Law

A business claims to be "FATF compliant," or treats FATF Recommendations as if they were directly binding obligations. In reality, FATF Recommendations have no direct legal force on private companies. They are international standards that countries voluntarily commit to implement through their own legislation. A crypto exchange in Germany is bound by EU and German AML law — not by the FATF Recommendations themselves. The distinction matters for audit-facing language, because implementation variance is real between countries, and because counterparty expectations may exceed local law.

Travel Rule Is Only One Part of Recommendation 15

Travel Rule readiness is treated as a proxy for full Recommendation 15 alignment. In reality, the Travel Rule is one preventive measure inside a much broader framework. Travel Rule legislation has been passed by 83% of relevant respondents, yet only 34% of assessed jurisdictions are Largely Compliant with R.15 overall, and only 40% satisfactorily meet the licensing criterion. A crypto business that builds an excellent Travel Rule solution but neglects its risk assessment, supervisory dialogue, or suspicious transaction reporting workflow is exactly the profile that fails a serious examination.

Not Every Crypto Project Is a VASP

VASP classification is activities-based and depends on whether the business performs covered activities on behalf of another person, as a business. A non-custodial protocol developer, a blockchain analytics provider, a software vendor, or a node operator may legitimately fall outside the VASP definition. A small custodial wallet service that holds customer keys sits squarely inside it. FATF guidance has been explicit that the test is functional, not based on branding. Labeling a service "decentralized" does not exempt it if a natural or legal person exercises operational control. Equally, labeling a token "utility" does not remove it from the VA definition if it is used for payment or investment.

The Seventh Update confirms that identifying control or sufficient influence over DeFi arrangements remains a major global implementation problem. Only a very small number of jurisdictions have moved from risk recognition to licensing qualifying DeFi arrangements in practice.

FATF Compliance Is Not Just KYC

KYC at onboarding answers one question — who is this customer at the moment they join. It does not answer what they do afterwards, where their funds come from, whether they appear on a sanctions list a year later, or whether their transaction patterns develop in suspicious ways. The businesses that fail examinations rarely fail at KYC. They fail at the layer below it: alerts that were generated but never reviewed, sanctions matches that were missed because lists were not refreshed, transaction patterns that should have triggered enhanced due diligence and did not, suspicious activity that was identified internally but never reported externally.

Conclusion

The July 2026 Seventh Targeted Update shows that Recommendation 15 implementation is moving forward, but the global challenge is shifting from rulemaking toward effectiveness. Countries increasingly have risk assessments, regulatory approaches, licensing frameworks, and Travel Rule legislation. But FATF is now asking harder questions: do those risk assessments change controls? Are VASPs actually licensed and supervised? Is unlicensed activity identified? Is the Travel Rule enforced? Are emerging stablecoin, offshore VASP, unhosted-wallet, and DeFi risks mitigated?

For crypto businesses operating in 2026, the practical takeaway is straightforward: treat FATF-aligned controls as the baseline, not the ceiling. Build a documented risk assessment, run real customer due diligence, screen wallets and transactions, prepare for the Travel Rule, screen for sanctions, retain records, and make the whole program testable. Where local law is stricter, follow the stricter rule. Where local law is lighter, expect that your banking partners, payment counterparties, and institutional clients will still apply the FATF-aligned standard — because they have to.

For VASPs, the 2026 FATF message is therefore less "add another AML policy" and more "show that the controls behind the policy actually address the risks your business faces."

FAQ

What Are FATF Crypto Standards?

FATF crypto standards are the global AML/CFT recommendations that set out how countries should regulate virtual assets and virtual asset service providers. They are not local laws on their own, but they shape almost every national crypto AML regime, including licensing, risk assessment, monitoring, the Travel Rule, and reporting obligations.

Does FATF Directly Regulate Crypto Businesses?

No. FATF is a standard-setter, not a regulator. It does not license, supervise, or fine individual crypto businesses. It publishes Recommendations that countries are expected to transpose into national law, and those national laws are what actually bind individual companies.

What Is FATF Recommendation 15?

Recommendation 15 is the core FATF standard that applies AML/CFT controls to new technologies, including virtual assets and VASPs. Together with its Interpretive Note, R.15 covers VA/VASP risk assessment, licensing or registration of VASPs, supervision, customer due diligence, monitoring, Travel Rule obligations, recordkeeping, and suspicious transaction reporting.

What Is a Virtual Asset Under FATF Standards?

A virtual asset is a digital representation of value that can be digitally traded or transferred and used for payment or investment purposes. Cryptocurrencies and stablecoins generally qualify; certain tokens qualify based on their function. Fiat currencies, securities already covered by other FATF Recommendations, and central bank digital currencies are not virtual assets in the FATF sense.

What Is a VASP Under FATF Standards?

A VASP is a natural or legal person who, as a business, conducts one or more covered activities on behalf of customers: exchanging VAs and fiat, exchanging between forms of VAs, transferring VAs, providing safekeeping or administration of VAs, or participating in VA issuance and related financial services.

Is Every Crypto Company a VASP?

No. VASP status depends on the activities a company performs and whether those activities are conducted on behalf of other persons. Non-custodial protocols, pure software vendors, and analytics providers may fall outside the VASP definition, while exchanges, custodians, and transfer services typically fall inside it.

Is the FATF Travel Rule the Same as Recommendation 15?

No. The Travel Rule is one preventive measure within the broader R.15 framework. Recommendation 15 also covers licensing or registration, supervision, risk assessments, customer due diligence, monitoring, sanctions, recordkeeping, and reporting. Travel Rule compliance alone does not amount to full R.15 alignment.

What Do FATF Standards Mean for Crypto Compliance Teams?

They serve as a design baseline for AML/CFT programs. Compliance teams use FATF-aligned principles to structure customer due diligence, wallet and transaction screening, sanctions checks, alert review, Travel Rule readiness, reporting, recordkeeping, and audit trails — regardless of whether the local statute spells out every requirement in the same words.

Why Do FATF Standards Matter if Local Laws Are Different?

Because most local laws are built on FATF expectations, and because banking partners, payment institutions, exchange counterparties, and institutional investors apply FATF-aligned standards as their due diligence benchmark. A business that meets only the local minimum may still struggle to maintain critical commercial relationships.

What Changed for FATF Crypto Standards in 2026?

FATF's June 2025 sixth Targeted Update showed gradual progress — 29% of assessed jurisdictions are now largely compliant with R.15, and 85 jurisdictions have passed Travel Rule legislation — but persistent gaps remain in risk assessment quality, licensing in practice, offshore VASP oversight, and Travel Rule enforcement. FATF's March 2026 Targeted Report on Stablecoins and Unhosted Wallets sharpened the focus on stablecoins as a high-risk segment, and the next R.15 implementation status update is due in 2026.

Did the Seventh Targeted Update Change Recommendation 15?

No. The Seventh Targeted Update did not replace or rewrite Recommendation 15. It assesses how jurisdictions are implementing the existing FATF standards, identifies remaining gaps and emerging virtual-asset risks, and provides recommendations for public authorities and private-sector participants.