FATF Travel Rule Implementation: The Enforcement Gap

On 16 July 2026 the Financial Action Task Force published its seventh targeted update on how countries are implementing the FATF standards for virtual assets and virtual asset service providers. The headline finding is that implementation remains uneven. Of the 109 jurisdictions answering the Travel Rule legislation question, 91, or 83 percent, reported legislation in place. Of those 91 jurisdictions, 55, or 60 percent, had not yet issued Travel Rule-related findings or directives or taken enforcement or other supervisory action. The report therefore distinguishes legislative adoption from effective supervision and enforcement.

The update assesses progress and remaining gaps in the implementation of Recommendation 15 across the FATF Global Network, following the extension of the FATF AML/CFT standards to virtual assets (VAs) and virtual asset service providers (VASPs). It is an implementation review, not a rewrite of the standard. That distinction matters for planning: nothing in the report changes what a VASP or an EU crypto-asset service provider must file tomorrow. It sets priority recommendations for public authorities and the private sector on supervision, enforcement, operational Travel Rule implementation and risk mitigation.

For a reporting team, the practical implication is to test operational effectiveness rather than treating the existence of a Travel Rule law as sufficient. This article walks through what the report found, how the European Union sits against the FATF baseline through Regulation (EU) 2023/1113, and what compliance and reporting teams should be doing about it now.

Related reading: our guide to the FATF Travel Rule consultation on Recommendation 16.

The dates that anchor this update

Virtual asset compliance is built on a short chain of decisions that still governs every scoping conversation. Keep these reference points close when you map obligations across borders.

  • June 2019: the FATF adopts the Interpretive Note to Recommendation 15, extending the wire-transfer information duties of Recommendation 16 to VASPs. This is the origin of the crypto Travel Rule.
  • 31 May 2023: Regulation (EU) 2023/1113, the recast Transfer of Funds Regulation, is adopted and published in the Official Journal on 9 June 2023.
  • 30 December 2024: Regulation (EU) 2023/1113 applies in the EU, aligned with the application date of the Markets in Crypto-Assets Regulation.
  • 26 June 2025: the FATF publishes its sixth annual update, urging stronger global action on illicit finance risks in virtual assets.
  • 16 July 2026: the FATF publishes the seventh targeted update, the subject of this article.

What the seventh targeted update actually measures

The report is the seventh in an annual series the FATF has run since 2020 to track how its virtual asset standards move from text into practice. It sits inside the roadmap set by the FATF Virtual Assets Contact Group to strengthen implementation of Recommendation 15. The findings draw on survey responses from across the FATF Global Network and its regional bodies, on analysis of mutual evaluation and follow-up reports, and on underlying blockchain data that the FATF says was provided by the analytics firms Chainalysis and TRM Labs for verification.

Two ideas sit at the centre of the standard. Recommendation 15 requires countries to assess the money-laundering and terrorist-financing risks of virtual assets, to license or register VASPs, and to supervise them for AML/CFT purposes. Recommendation 16 is the FATF payment-transparency standard for cross-border and domestic payments or value transfers. The Interpretive Note to Recommendation 15 applies its information requirements to virtual-asset transfers: an originating VASP must obtain and hold required and accurate originator information and required beneficiary information, submit that information immediately and securely to the beneficiary VASP or financial institution, if any, and make it available on request to appropriate authorities; a beneficiary VASP must obtain and hold required originator information and required and accurate beneficiary information. FATF permits countries to adopt a de minimis threshold no higher than USD/EUR 1,000 for cross-border payments or value transfers and also permits such a threshold for domestic transfers. Below an adopted threshold, a reduced information set applies.

A common mistake in board packs is to treat this report as a new obligation with a deadline. It is neither. The value of the update is diagnostic. It tells you which corridors your counterparties sit in, how mature supervision is in each, and which risks the FATF now expects the private sector to control. Read it as a risk-based implementation benchmark for control planning, not as a new filing trigger.

Where FATF Travel Rule implementation now stands

The progress on paper is real. The report finds that 91 of the 109 jurisdictions answering the Travel Rule legislation question, or 83 percent, had passed legislation, up from 85 of 117, or 73 percent, in 2025. Another 11 of 109 reported that implementation was in progress. Those figures describe respondents to the relevant survey question, not the whole FATF Global Network.

The supervision picture undercuts the headline. A large number of the jurisdictions that have a Travel Rule in force have not yet taken any enforcement or supervisory action under it. A law on the statute book is not the same as an operating control that a supervisor has tested. This is the gap the report keeps returning to across Recommendation 15.

The practical consequence for a cross-border VASP is the sunrise problem, and it has not gone away. When your counterparty sits in a jurisdiction that has legislated the Travel Rule but never operationalised it, the information you push may have nowhere to land, and the information you expect back may never arrive. Uneven implementation across the network is exactly what makes counterparty scoping hard, because the legal map and the operational map no longer match. Before transmitting required information, a VASP should identify the counterparty and conduct risk-based counterparty due diligence; that due diligence should be refreshed periodically or when new risk emerges.

The distance between a rule and a working control

Technical compliance ratings tell the same story from the assessor side. The report indicates that the share of assessed jurisdictions rated largely compliant with Recommendation 15 rose to about 34 percent, up from roughly 29 percent the year before, while the share rated only partially compliant fell to around 43 percent from about 50 percent. Movement is in the right direction, but 97 of the 149 assessed jurisdictions were still rated partially compliant or non-compliant.

Risk assessment shows a clear implementation gap. In the 2026 survey, 124 of 145 respondents, or 86 percent, reported conducting a VA/VASP risk assessment, up from 76 percent in 2025. The report says challenges remain in implementing preventive or mitigating measures aligned with identified risks and in using assessment results for risk-based supervision. Only 48 of the 149 assessed jurisdictions met or mostly met sub-criterion 15.3 on risk assessment and the risk-based approach.

For reporting officers this is where the report gets close to the desk. Where a national risk assessment identifies a specific typology, firms should assess whether that risk is reflected appropriately in their own risk assessment, transaction-monitoring controls and suspicious-transaction reporting. The FATF’s recommendations emphasise effective mitigating measures and practical supervision; firms should therefore retain evidence that relevant controls operate as designed.

Offshore VASPs and the edge of the licensing perimeter

One of the report’s sharper findings concerns entities that operate at the border of any single supervisor’s reach. Identifying the persons or entities actually conducting VASP activity remains one of the hardest parts of Recommendation 15, and offshore providers that serve users in a country without being established there are the clearest example. The report states that 34 percent of jurisdictions with VASP licensing or registration requirements, 39 of 114, reported applying a more extensive approach to offshore VASPs that meet specified jurisdictional conditions.

That leaves a wide seam. An offshore VASP may serve customers across multiple markets from a jurisdiction with weak or underdeveloped AML/CFT supervision, increasing ML/TF/PF risk in both its home and host jurisdictions. The report identifies offshore VASPs operating outside effective regulatory and supervisory oversight as an emerging and increasing risk and a significant implementation challenge.

The EU addresses these risks through separate transaction-level and relationship-level duties. Article 14 of Regulation (EU) 2023/1113 requires the originating CASP to ensure that the prescribed originator and beneficiary information accompanies the transfer and is submitted securely in advance of, or simultaneously or concurrently with, the transfer. Separately, Article 19b of Directive (EU) 2015/849, inserted by Article 38 of Regulation (EU) 2023/1113, requires an EU CASP entering into a cross-border correspondent relationship with a non-EU respondent entity to check its registration or licensing, reputation, quality of supervision and AML/CFT controls and to apply risk-sensitive mitigating measures. It does not impose a transfer-by-transfer requirement to prove that every non-EU recipient can receive and retain Travel Rule data. For a fuller picture of the EU CASP reporting perimeter, see our explainer on MiCA reporting obligations for crypto-asset service providers.

Stablecoins, unhosted wallets and the P2P edge

The report is explicit that the risk mix has shifted since 2025. It highlights the growing industrialisation of virtual-asset-enabled fraud by organised crime groups, the misuse of stablecoins, the risks arising from peer-to-peer transactions through unhosted wallets, and the continuing difficulty of identifying who controls a decentralised finance arrangement. The report identifies stablecoin misuse as an emerging and increasing risk and says stablecoins continue to present significant risks as virtual-asset-enabled illicit activity becomes more complex.

Unhosted wallets are the point where the Travel Rule meets its structural limit. The rule binds intermediaries. When there is no VASP or CASP on one side of a transfer, there is no one to obtain and transmit the data. The FATF standard and the EU regime both handle this by attaching duties to the regulated side of a mixed transfer, not by pretending the unhosted side can be policed directly. We covered the mechanics of this in detail in our note on FATF expectations for stablecoins and unhosted wallets.

The frequent misreading here is that the Travel Rule captures every crypto movement. It does not. A genuine person-to-person transfer between two self-hosted wallets, with no intermediary involved, falls outside the information duty under both frameworks. Where Regulation (EU) 2023/1113 applies because the relevant crypto-asset service provider has its registered office in the Union, a transfer to or from a self-hosted address is in scope when a crypto-asset service provider is involved on one side, and the regulated provider must obtain and hold the required originator and beneficiary information. For a transfer exceeding EUR 1,000, the originating CASP must take adequate measures to assess whether a destination self-hosted address is owned or controlled by the originator, while the beneficiary CASP must do the equivalent for a source self-hosted address and the beneficiary. That EUR 1,000 figure is a verification trigger for self-hosted wallets, and it is a different thing from the FATF USD/EUR 1,000 de minimis threshold.

How the EU sits against the FATF baseline

This is where jurisdiction matters, and where a common cross-border error creeps in. The FATF standard is not law anywhere by itself. Each country implements it through a domestic instrument, and those instruments differ in ways that change what you actually file. Mapping a corridor to the FATF text instead of the local rule is how firms end up with the wrong data set on the wire.

In the EU, Regulation (EU) 2023/1113 extends originator and beneficiary information duties to in-scope transfers of crypto-assets and amends Directive (EU) 2015/849. Article 2 excludes, among other cases, qualifying transfers of funds or transfers of electronic money tokens carried out using a payment card, electronic money instrument, mobile phone or similar digital or IT device used exclusively to pay for goods or services, where the number of that card, instrument or device accompanies all transfers flowing from the transaction; transfers where both the originator and beneficiary crypto-asset service providers act on their own behalf; and person-to-person crypto-asset transfers conducted without a crypto-asset service provider. It applies from 30 December 2024, in step with the Markets in Crypto-Assets Regulation, Regulation (EU) 2023/1114. The EU regime is stricter than the FATF baseline in one important respect. For in-scope transfers involving a crypto-asset service provider on each side, the prescribed originator and beneficiary information applies regardless of value, so there is no de minimis carve-out of the kind the FATF permits below USD/EUR 1,000. Article 2(4)(a) excludes transfers where both the originator and the beneficiary are crypto-asset service providers acting on their own behalf. The information must travel securely and in advance of, or at the same time as, the crypto-asset transfer, and the beneficiary CASP must run procedures to detect when originator or beneficiary information is missing or incomplete.

The Union framework also connects to the wider EU AML reform. The single Anti-Money Laundering Regulation and the Anti-Money Laundering Authority reshape how obliged entities, including CASPs, are supervised across the bloc. If you are scoping how the EU rulebook fits together, our overview of what the AML Regulation changes for obliged entities sets out the direction of travel.

Outside the EU, the onshoring trap is real. The United Kingdom applies its own Travel Rule through amendments to the Money Laundering Regulations, in force since 1 September 2023, and it is a separate instrument from the EU regulation with its own data expectations and its own supervisor. A firm that assumes UK and EU obligations are identical because both descend from the same FATF standard will get the detail wrong. The rule for any cross-border VASP is to map each corridor to the local implementing instrument, and to treat the FATF text as the common ancestor of those rules, while the local instrument stays the operative law.

What compliance and reporting teams should do now

For entities with a Union nexus, transaction controls and counterparty due diligence should be kept distinct. Before executing a transfer, the originating CASP must ensure compliance with Article 14 of Regulation (EU) 2023/1113. Separately, Article 19b of Directive (EU) 2015/849 applies when entering into a cross-border correspondent relationship with a non-EU respondent entity. FATF’s 2021 guidance also supports counterparty VASP due diligence before customer information is transmitted, but states that the process need not be repeated for every transfer and should instead be refreshed periodically or when new risk emerges.

Several concrete steps follow from the findings, and each maps to a specific ask in the report or the regulation. None of them rests on a prediction about enforcement.

  • Refresh the counterparty due diligence file so it captures registration status, jurisdiction, and the counterpart’s demonstrated ability to send and receive Travel Rule data, with extra scrutiny for offshore and unregistered providers.
  • Reconcile your own virtual asset risk assessment against the risks the update foregrounds, in particular scaled fraud, stablecoin misuse and P2P flows through unhosted wallets, and check that each named risk has a matching control.
  • Test the beneficiary-CASP procedures under Articles 16 to 18 of Regulation (EU) 2023/1113 so that missing or incomplete information is detected; transfers are executed, rejected, returned or suspended on a risk-sensitive basis as applicable; repeated failures trigger the required follow-up; and missing information is taken into account when assessing whether a transfer or related transaction is suspicious and reportable to the FIU.
  • Confirm that self-hosted-address controls apply the EUR 1,000 threshold correctly: for a transfer exceeding that amount, the relevant CASP must take adequate measures to assess whether the address is owned or controlled by its customer. Do not confuse this with the FATF de minimis threshold.
  • Maintain evidence that controls operate, alerts are investigated and suspicious transactions are reported, rather than relying only on policy documentation.

For teams that also carry the wider AML reporting load, the virtual asset controls should sit inside the same governance as the rest of the financial-crime programme, sharing the same escalation and reporting paths. Our practitioner guide to AML reporting in Luxembourg shows how the suspicious-transaction and supervisory reporting pieces connect.

Frequently Asked Questions

Does the seventh targeted update create a new reporting obligation for VASPs?

No. It is an implementation review of Recommendation 15 across the FATF Global Network. It does not amend the standard. Your filing obligations continue to flow from the domestic instrument that applies to you, such as Regulation (EU) 2023/1113 in the EU. The report matters because it identifies implementation gaps and priority actions, especially practical supervision and effective risk mitigation.

What is the difference between Recommendation 15 and Recommendation 16 for crypto?

Recommendation 15 is the broad standard requiring countries to assess virtual asset risks, license or register VASPs and supervise them for AML/CFT. Recommendation 16 is the FATF payment-transparency standard for cross-border and domestic payments or value transfers. The Interpretive Note to Recommendation 15 applies its originator- and beneficiary-information requirements to virtual-asset transfers involving VASPs or financial institutions.

Why does the report say most jurisdictions have the Travel Rule but enforcement is weak?

Passing legislation is a discrete, visible act: 91 of the 109 jurisdictions answering the relevant 2026 survey question reported Travel Rule legislation in place. Building supervisory capacity, examining VASPs and taking action are slower and harder, and many jurisdictions with a law in force have not yet used it. The report treats this gap between adoption and effective supervision as the central weakness in current Recommendation 15 implementation.

Does the EU Travel Rule have a de minimis threshold like the FATF standard?

For in-scope transfers involving a crypto-asset service provider on each side, Regulation (EU) 2023/1113 does not provide a de minimis carve-out: the prescribed originator and beneficiary information applies regardless of amount. Article 2(4)(a) excludes transfers where both the originator and the beneficiary are crypto-asset service providers acting on their own behalf. The EUR 1,000 figure is instead a trigger for the relevant crypto-asset service provider to take adequate measures to assess whether a self-hosted address is owned or controlled by its customer.

Are transfers to and from unhosted wallets in scope?

Where Regulation (EU) 2023/1113 applies because the crypto-asset service provider or intermediary crypto-asset service provider of either the originator or the beneficiary has its registered office in the Union, a transfer to or from a self-hosted address is in scope when a crypto-asset service provider is involved on one side, and the relevant crypto-asset service provider must obtain and hold the required originator and beneficiary information. A pure person-to-person transfer between two self-hosted wallets with no CASP involved falls outside the information duty, because there is no obliged intermediary to carry the data. For a transfer exceeding EUR 1,000, the relevant CASP must take adequate measures to assess whether the self-hosted address is owned or controlled by its customer: the originator for a transfer to a self-hosted address, or the beneficiary for a transfer from one.

How should a cross-border VASP handle counterparties in jurisdictions that have not enforced the Travel Rule?

Treat legal status and operational capability as two separate checks. A counterparty in a jurisdiction that has legislated but not operationalised the rule may be unable to receive or return the required data, which affects both your ability to comply and your risk exposure. Document the counterparty’s actual capability at onboarding, apply enhanced due diligence to offshore and unregistered providers, and record how you handle transfers where the data cannot be exchanged.

Where do stablecoins fit into the report’s risk picture?

The update foregrounds the misuse of stablecoins as one of the increasing risks in the sector, alongside industrialised fraud, unhosted-wallet P2P activity and decentralised finance. For an EU issuer or CASP, stablecoin transfers still run through the Travel Rule where a CASP is involved, and electronic money tokens are treated as crypto-assets for these purposes under Regulation (EU) 2023/1113.

Key Takeaways

  • The FATF published its seventh targeted update on virtual asset standards implementation on 16 July 2026, reviewing progress and gaps in Recommendation 15 across the Global Network.
  • Travel Rule legislation now covers most surveyed jurisdictions, but many that have a law in force have not yet supervised or enforced it, so the sunrise problem persists.
  • Technical compliance with Recommendation 15 is improving slowly, and risk assessments are widespread, but many jurisdictions still face challenges using those assessments to inform effective preventive, mitigation, supervisory and enforcement measures.
  • Offshore VASPs, stablecoin misuse, unhosted-wallet P2P activity and decentralised finance are risks foregrounded by the report; 34 percent of jurisdictions with VASP licensing or registration requirements, 39 of 114, reported applying a more extensive approach to offshore VASPs that meet specified jurisdictional conditions.
  • The report changes no filing obligation. It recommends stronger practical supervision and effective risk mitigation.
  • In the EU, Regulation (EU) 2023/1113 applies from 30 December 2024. For in-scope transfers involving a crypto-asset service provider on each side, the prescribed originator and beneficiary information applies regardless of amount; Article 2(4)(a) excludes transfers where both crypto-asset service providers act on their own behalf.
  • Non-EU implementations, including the UK Money Laundering Regulations Travel Rule, are separate instruments; map each corridor to the local implementing rule and treat the FATF text as background.
  • The immediate action for reporting teams is to distinguish Article 14 transfer controls from counterparty due diligence: ensure the required information accompanies each transfer and maintain risk-based, periodically refreshed counterparty evidence rather than repeating full due diligence for every transfer.

Sources and References

  • FATF, Seventh Targeted Update on Implementation of the FATF Standards on Virtual Assets/VASPs, 16 July 2026: fatf-gafi.org
  • FATF news story, FATF calls for closing of regulatory gaps as virtual asset illicit finance risks become more complex, July 2026: fatf-gafi.org
  • FATF, 2025 Targeted Update on Implementation of the FATF Standards on Virtual Assets and VASPs, 26 June 2025: fatf-gafi.org
  • FATF, International Standards on Combating Money Laundering and the Financing of Terrorism & Proliferation, the FATF Recommendations, updated June 2026 (Recommendation 15, Interpretive Note to Recommendation 15, Recommendation 16 and Interpretive Note to Recommendation 16): fatf-gafi.org
  • FATF, Updated Guidance for a Risk-Based Approach to Virtual Assets and VASPs, October 2021, to be read subject to subsequent amendments to the FATF Recommendations: fatf-gafi.org
  • Regulation (EU) 2023/1113 of 31 May 2023 on information accompanying transfers of funds and certain crypto-assets (recast Transfer of Funds Regulation), OJ L 150, 9.6.2023: eur-lex.europa.eu
  • Regulation (EU) 2023/1114 on Markets in Crypto-Assets (MiCA): eur-lex.europa.eu
  • Financial Conduct Authority, FCA sets out expectations for UK cryptoasset businesses complying with the Travel Rule, first published 17 August 2023 and updated 6 February 2026: fca.org.uk

The implementation focus moves to effectiveness

The seventh targeted update is best read as a supervisory signpost. Among respondents to the relevant 2026 survey question, Travel Rule legislation was widely reported, while the FATF continued to identify major gaps in operational implementation, supervision and enforcement. For a cross-border VASP or an EU CASP, the work that follows is unglamorous and specific: know your counterparties’ real capability, wire your risk assessment into live controls, and keep evidence that those controls actually run. Firms that treated the Travel Rule solely as a data-format project should also test whether the end-to-end control operates effectively when a transfer is executed.

Last updated: July 2026

Disclaimer: The information on RegReportingDesk.com is for educational and informational purposes only. It does not constitute legal, regulatory, tax, or compliance advice. Always consult your compliance officer, legal counsel, or the relevant supervisory authority for guidance specific to your institution.

Similar Posts

  • MiFID II Triangular Passporting: ESMA’s July 2026 Supervisory Briefing

    On 7 July 2026 ESMA published a supervisory briefing on triangular passporting under MiFID II (reference ESMA35-243228190-8065), and the CSSF relayed it to Luxembourg professionals in a communique dated 17 July 2026. Triangular passporting is the arrangement where an authorised investment firm serves clients in one Member State through a branch or tied agent it…

  • SEPA Request-to-Pay Rulebook v4.0: What Scheme Participants Must Update

    Updated June 2026In this guideWhat the SEPA Request-to-Pay Rulebook v4.0 actually changesThe thing teams still get wrong: SRTP is messaging, not a paymentThe four-corner model and who has to adhereThe EPC Directory Service becomes mandatorySimplified homologation: the route that changedAPI changes: sealing, examples, the test toolbox and MVP optionsReason codes and the option modelTiming: the…

  • EMIR Reporting Requirements – What You File, When, and How to Get It Right

    Updated July 2026In this guideEMIR Transaction Reporting: Who Reports, Which Trades, and What You FileEMIR Reporting to Trade Repositories: Submission, Reconciliation, and Error HandlingEMIR Regulatory and Supervisory Reporting: How NCAs and ESMA Use the DataFrequently Asked QuestionsRelated ArticlesKey TakeawaysSources and ReferencesGetting EMIR Reporting Right Across All Three DisciplinesA single lapsed LEI can cascade into hundreds…

  • Bank of England Form PL: What UK Teams Must Check for 2027

    The Bank of England published Statistical Notice 2026/06 on 30 June 2026, setting out updated definitions for Form PL, its Profit and Loss statistical return. The changes apply from the first-quarter 2027 reporting period, first submitted in May 2027, which gives UK statistical reporters a fixed window to remap their definitions before that return falls…

  • CSSF IFM Ancillary Services Notification: What Luxembourg Fund Managers Must File Before Going Live

    Last updated: June 2026In this guideWhat the CSSF IFM ancillary services notification actually requiresWhere the legal certainty comes from: AIFMD II Article 6The MiFID II overlay teams underestimateUpdating the articles of incorporation is not a rubber stampWhen this applies and what the CSSF did not sayFrequently Asked QuestionsRelated ArticlesKey TakeawaysSources and ReferencesFiling the notification before…