FATF Travel Rule Implementation: The Enforcement Gap
On 16 July 2026 the Financial Action Task Force published its seventh targeted update on how countries are implementing the FATF standards for virtual assets and virtual asset service providers. The headline finding is that implementation remains uneven. Of the 109 jurisdictions answering the Travel Rule legislation question, 91, or 83 percent, reported legislation in place. Of those 91 jurisdictions, 55, or 60 percent, had not yet issued Travel Rule-related findings or directives or taken enforcement or other supervisory action. The report therefore distinguishes legislative adoption from effective supervision and enforcement.
The update assesses progress and remaining gaps in the implementation of Recommendation 15 across the FATF Global Network, following the extension of the FATF AML/CFT standards to virtual assets (VAs) and virtual asset service providers (VASPs). It is an implementation review, not a rewrite of the standard. That distinction matters for planning: nothing in the report changes what a VASP or an EU crypto-asset service provider must file tomorrow. It sets priority recommendations for public authorities and the private sector on supervision, enforcement, operational Travel Rule implementation and risk mitigation.
For a reporting team, the practical implication is to test operational effectiveness rather than treating the existence of a Travel Rule law as sufficient. This article walks through what the report found, how the European Union sits against the FATF baseline through Regulation (EU) 2023/1113, and what compliance and reporting teams should be doing about it now.
Related reading: our guide to the FATF Travel Rule consultation on Recommendation 16.
The dates that anchor this update
Virtual asset compliance is built on a short chain of decisions that still governs every scoping conversation. Keep these reference points close when you map obligations across borders.
- June 2019: the FATF adopts the Interpretive Note to Recommendation 15, extending the wire-transfer information duties of Recommendation 16 to VASPs. This is the origin of the crypto Travel Rule.
- 31 May 2023: Regulation (EU) 2023/1113, the recast Transfer of Funds Regulation, is adopted and published in the Official Journal on 9 June 2023.
- 30 December 2024: Regulation (EU) 2023/1113 applies in the EU, aligned with the application date of the Markets in Crypto-Assets Regulation.
- 26 June 2025: the FATF publishes its sixth annual update, urging stronger global action on illicit finance risks in virtual assets.
- 16 July 2026: the FATF publishes the seventh targeted update, the subject of this article.
What the seventh targeted update actually measures
The report is the seventh in an annual series the FATF has run since 2020 to track how its virtual asset standards move from text into practice. It sits inside the roadmap set by the FATF Virtual Assets Contact Group to strengthen implementation of Recommendation 15. The findings draw on survey responses from across the FATF Global Network and its regional bodies, on analysis of mutual evaluation and follow-up reports, and on underlying blockchain data that the FATF says was provided by the analytics firms Chainalysis and TRM Labs for verification.
Two ideas sit at the centre of the standard. Recommendation 15 requires countries to assess the money-laundering and terrorist-financing risks of virtual assets, to license or register VASPs, and to supervise them for AML/CFT purposes. Recommendation 16 is the FATF payment-transparency standard for cross-border and domestic payments or value transfers. The Interpretive Note to Recommendation 15 applies its information requirements to virtual-asset transfers: an originating VASP must obtain and hold required and accurate originator information and required beneficiary information, submit that information immediately and securely to the beneficiary VASP or financial institution, if any, and make it available on request to appropriate authorities; a beneficiary VASP must obtain and hold required originator information and required and accurate beneficiary information. FATF permits countries to adopt a de minimis threshold no higher than USD/EUR 1,000 for cross-border payments or value transfers and also permits such a threshold for domestic transfers. Below an adopted threshold, a reduced information set applies.
A common mistake in board packs is to treat this report as a new obligation with a deadline. It is neither. The value of the update is diagnostic. It tells you which corridors your counterparties sit in, how mature supervision is in each, and which risks the FATF now expects the private sector to control. Read it as a risk-based implementation benchmark for control planning, not as a new filing trigger.
Where FATF Travel Rule implementation now stands
The progress on paper is real. The report finds that 91 of the 109 jurisdictions answering the Travel Rule legislation question, or 83 percent, had passed legislation, up from 85 of 117, or 73 percent, in 2025. Another 11 of 109 reported that implementation was in progress. Those figures describe respondents to the relevant survey question, not the whole FATF Global Network.
The supervision picture undercuts the headline. A large number of the jurisdictions that have a Travel Rule in force have not yet taken any enforcement or supervisory action under it. A law on the statute book is not the same as an operating control that a supervisor has tested. This is the gap the report keeps returning to across Recommendation 15.
The practical consequence for a cross-border VASP is the sunrise problem, and it has not gone away. When your counterparty sits in a jurisdiction that has legislated the Travel Rule but never operationalised it, the information you push may have nowhere to land, and the information you expect back may never arrive. Uneven implementation across the network is exactly what makes counterparty scoping hard, because the legal map and the operational map no longer match. Before transmitting required information, a VASP should identify the counterparty and conduct risk-based counterparty due diligence; that due diligence should be refreshed periodically or when new risk emerges.
The distance between a rule and a working control
Technical compliance ratings tell the same story from the assessor side. The report indicates that the share of assessed jurisdictions rated largely compliant with Recommendation 15 rose to about 34 percent, up from roughly 29 percent the year before, while the share rated only partially compliant fell to around 43 percent from about 50 percent. Movement is in the right direction, but 97 of the 149 assessed jurisdictions were still rated partially compliant or non-compliant.
Risk assessment shows a clear implementation gap. In the 2026 survey, 124 of 145 respondents, or 86 percent, reported conducting a VA/VASP risk assessment, up from 76 percent in 2025. The report says challenges remain in implementing preventive or mitigating measures aligned with identified risks and in using assessment results for risk-based supervision. Only 48 of the 149 assessed jurisdictions met or mostly met sub-criterion 15.3 on risk assessment and the risk-based approach.
For reporting officers this is where the report gets close to the desk. Where a national risk assessment identifies a specific typology, firms should assess whether that risk is reflected appropriately in their own risk assessment, transaction-monitoring controls and suspicious-transaction reporting. The FATF’s recommendations emphasise effective mitigating measures and practical supervision; firms should therefore retain evidence that relevant controls operate as designed.
Offshore VASPs and the edge of the licensing perimeter
One of the report’s sharper findings concerns entities that operate at the border of any single supervisor’s reach. Identifying the persons or entities actually conducting VASP activity remains one of the hardest parts of Recommendation 15, and offshore providers that serve users in a country without being established there are the clearest example. The report states that 34 percent of jurisdictions with VASP licensing or registration requirements, 39 of 114, reported applying a more extensive approach to offshore VASPs that meet specified jurisdictional conditions.
That leaves a wide seam. An offshore VASP may serve customers across multiple markets from a jurisdiction with weak or underdeveloped AML/CFT supervision, increasing ML/TF/PF risk in both its home and host jurisdictions. The report identifies offshore VASPs operating outside effective regulatory and supervisory oversight as an emerging and increasing risk and a significant implementation challenge.
The EU addresses these risks through separate transaction-level and relationship-level duties. Article 14 of Regulation (EU) 2023/1113 requires the originating CASP to ensure that the prescribed originator and beneficiary information accompanies the transfer and is submitted securely in advance of, or simultaneously or concurrently with, the transfer. Separately, Article 19b of Directive (EU) 2015/849, inserted by Article 38 of Regulation (EU) 2023/1113, requires an EU CASP entering into a cross-border correspondent relationship with a non-EU respondent entity to check its registration or licensing, reputation, quality of supervision and AML/CFT controls and to apply risk-sensitive mitigating measures. It does not impose a transfer-by-transfer requirement to prove that every non-EU recipient can receive and retain Travel Rule data. For a fuller picture of the EU CASP reporting perimeter, see our explainer on MiCA reporting obligations for crypto-asset service providers.
Stablecoins, unhosted wallets and the P2P edge
The report is explicit that the risk mix has shifted since 2025. It highlights the growing industrialisation of virtual-asset-enabled fraud by organised crime groups, the misuse of stablecoins, the risks arising from peer-to-peer transactions through unhosted wallets, and the continuing difficulty of identifying who controls a decentralised finance arrangement. The report identifies stablecoin misuse as an emerging and increasing risk and says stablecoins continue to present significant risks as virtual-asset-enabled illicit activity becomes more complex.
Unhosted wallets are the point where the Travel Rule meets its structural limit. The rule binds intermediaries. When there is no VASP or CASP on one side of a transfer, there is no one to obtain and transmit the data. The FATF standard and the EU regime both handle this by attaching duties to the regulated side of a mixed transfer, not by pretending the unhosted side can be policed directly. We covered the mechanics of this in detail in our note on FATF expectations for stablecoins and unhosted wallets.
The frequent misreading here is that the Travel Rule captures every crypto movement. It does not. A genuine person-to-person transfer between two self-hosted wallets, with no intermediary involved, falls outside the information duty under both frameworks. Where Regulation (EU) 2023/1113 applies because the relevant crypto-asset service provider has its registered office in the Union, a transfer to or from a self-hosted address is in scope when a crypto-asset service provider is involved on one side, and the regulated provider must obtain and hold the required originator and beneficiary information. For a transfer exceeding EUR 1,000, the originating CASP must take adequate measures to assess whether a destination self-hosted address is owned or controlled by the originator, while the beneficiary CASP must do the equivalent for a source self-hosted address and the beneficiary. That EUR 1,000 figure is a verification trigger for self-hosted wallets, and it is a different thing from the FATF USD/EUR 1,000 de minimis threshold.
How the EU sits against the FATF baseline
This is where jurisdiction matters, and where a common cross-border error creeps in. The FATF standard is not law anywhere by itself. Each country implements it through a domestic instrument, and those instruments differ in ways that change what you actually file. Mapping a corridor to the FATF text instead of the local rule is how firms end up with the wrong data set on the wire.
In the EU, Regulation (EU) 2023/1113 extends originator and beneficiary information duties to in-scope transfers of crypto-assets and amends Directive (EU) 2015/849. Article 2 excludes, among other cases, qualifying transfers of funds or transfers of electronic money tokens carried out using a payment card, electronic money instrument, mobile phone or similar digital or IT device used exclusively to pay for goods or services, where the number of that card, instrument or device accompanies all transfers flowing from the transaction; transfers where both the originator and beneficiary crypto-asset service providers act on their own behalf; and person-to-person crypto-asset transfers conducted without a crypto-asset service provider. It applies from 30 December 2024, in step with the Markets in Crypto-Assets Regulation, Regulation (EU) 2023/1114. The EU regime is stricter than the FATF baseline in one important respect. For in-scope transfers involving a crypto-asset service provider on each side, the prescribed originator and beneficiary information applies regardless of value, so there is no de minimis carve-out of the kind the FATF permits below USD/EUR 1,000. Article 2(4)(a) excludes transfers where both the originator and the beneficiary are crypto-asset service providers acting on their own behalf. The information must travel securely and in advance of, or at the same time as, the crypto-asset transfer, and the beneficiary CASP must run procedures to detect when originator or beneficiary information is missing or incomplete.
The Union framework also connects to the wider EU AML reform. The single Anti-Money Laundering Regulation and the Anti-Money Laundering Authority reshape how obliged entities, including CASPs, are supervised across the bloc. If you are scoping how the EU rulebook fits together, our overview of what the AML Regulation changes for obliged entities sets out the direction of travel.
Outside the EU, the onshoring trap is real. The United Kingdom applies its own Travel Rule through amendments to the Money Laundering Regulations, in force since 1 September 2023, and it is a separate instrument from the EU regulation with its own data expectations and its own supervisor. A firm that assumes UK and EU obligations are identical because both descend from the same FATF standard will get the detail wrong. The rule for any cross-border VASP is to map each corridor to the local implementing instrument, and to treat the FATF text as the common ancestor of those rules, while the local instrument stays the operative law.
What compliance and reporting teams should do now
For entities with a Union nexus, transaction controls and counterparty due diligence should be kept distinct. Before executing a transfer, the originating CASP must ensure compliance with Article 14 of Regulation (EU) 2023/1113. Separately, Article 19b of Directive (EU) 2015/849 applies when entering into a cross-border correspondent relationship with a non-EU respondent entity. FATF’s 2021 guidance also supports counterparty VASP due diligence before customer information is transmitted, but states that the process need not be repeated for every transfer and should instead be refreshed periodically or when new risk emerges.
Several concrete steps follow from the findings, and each maps to a specific ask in the report or the regulation. None of them rests on a prediction about enforcement.
- Refresh the counterparty due diligence file so it captures registration status, jurisdiction, and the counterpart’s demonstrated ability to send and receive Travel Rule data, with extra scrutiny for offshore and unregistered providers.
- Reconcile your own virtual asset risk assessment against the risks the update foregrounds, in particular scaled fraud, stablecoin misuse and P2P flows through unhosted wallets, and check that each named risk has a matching control.
- Test the beneficiary-CASP procedures under Articles 16 to 18 of Regulation (EU) 2023/1113 so that missing or incomplete information is detected; transfers are executed, rejected, returned or suspended on a risk-sensitive basis as applicable; repeated failures trigger the required follow-up; and missing information is taken into account when assessing whether a transfer or related transaction is suspicious and reportable to the FIU.
- Confirm that self-hosted-address controls apply the EUR 1,000 threshold correctly: for a transfer exceeding that amount, the relevant CASP must take adequate measures to assess whether the address is owned or controlled by its customer. Do not confuse this with the FATF de minimis threshold.
- Maintain evidence that controls operate, alerts are investigated and suspicious transactions are reported, rather than relying only on policy documentation.
For teams that also carry the wider AML reporting load, the virtual asset controls should sit inside the same governance as the rest of the financial-crime programme, sharing the same escalation and reporting paths. Our practitioner guide to AML reporting in Luxembourg shows how the suspicious-transaction and supervisory reporting pieces connect.
Frequently Asked Questions
Does the seventh targeted update create a new reporting obligation for VASPs?
No. It is an implementation review of Recommendation 15 across the FATF Global Network. It does not amend the standard. Your filing obligations continue to flow from the domestic instrument that applies to you, such as Regulation (EU) 2023/1113 in the EU. The report matters because it identifies implementation gaps and priority actions, especially practical supervision and effective risk mitigation.
What is the difference between Recommendation 15 and Recommendation 16 for crypto?
Recommendation 15 is the broad standard requiring countries to assess virtual asset risks, license or register VASPs and supervise them for AML/CFT. Recommendation 16 is the FATF payment-transparency standard for cross-border and domestic payments or value transfers. The Interpretive Note to Recommendation 15 applies its originator- and beneficiary-information requirements to virtual-asset transfers involving VASPs or financial institutions.
Why does the report say most jurisdictions have the Travel Rule but enforcement is weak?
Passing legislation is a discrete, visible act: 91 of the 109 jurisdictions answering the relevant 2026 survey question reported Travel Rule legislation in place. Building supervisory capacity, examining VASPs and taking action are slower and harder, and many jurisdictions with a law in force have not yet used it. The report treats this gap between adoption and effective supervision as the central weakness in current Recommendation 15 implementation.
Does the EU Travel Rule have a de minimis threshold like the FATF standard?
For in-scope transfers involving a crypto-asset service provider on each side, Regulation (EU) 2023/1113 does not provide a de minimis carve-out: the prescribed originator and beneficiary information applies regardless of amount. Article 2(4)(a) excludes transfers where both the originator and the beneficiary are crypto-asset service providers acting on their own behalf. The EUR 1,000 figure is instead a trigger for the relevant crypto-asset service provider to take adequate measures to assess whether a self-hosted address is owned or controlled by its customer.
Are transfers to and from unhosted wallets in scope?
Where Regulation (EU) 2023/1113 applies because the crypto-asset service provider or intermediary crypto-asset service provider of either the originator or the beneficiary has its registered office in the Union, a transfer to or from a self-hosted address is in scope when a crypto-asset service provider is involved on one side, and the relevant crypto-asset service provider must obtain and hold the required originator and beneficiary information. A pure person-to-person transfer between two self-hosted wallets with no CASP involved falls outside the information duty, because there is no obliged intermediary to carry the data. For a transfer exceeding EUR 1,000, the relevant CASP must take adequate measures to assess whether the self-hosted address is owned or controlled by its customer: the originator for a transfer to a self-hosted address, or the beneficiary for a transfer from one.
How should a cross-border VASP handle counterparties in jurisdictions that have not enforced the Travel Rule?
Treat legal status and operational capability as two separate checks. A counterparty in a jurisdiction that has legislated but not operationalised the rule may be unable to receive or return the required data, which affects both your ability to comply and your risk exposure. Document the counterparty’s actual capability at onboarding, apply enhanced due diligence to offshore and unregistered providers, and record how you handle transfers where the data cannot be exchanged.
Where do stablecoins fit into the report’s risk picture?
The update foregrounds the misuse of stablecoins as one of the increasing risks in the sector, alongside industrialised fraud, unhosted-wallet P2P activity and decentralised finance. For an EU issuer or CASP, stablecoin transfers still run through the Travel Rule where a CASP is involved, and electronic money tokens are treated as crypto-assets for these purposes under Regulation (EU) 2023/1113.
Related Articles
- FATF Travel Rule Consultation on Recommendation 16 – How the FATF is refining the wire-transfer standard for VASPs and what it means for EU firms.
- FATF on Stablecoins and Unhosted Wallets – The AML/CFT expectations for stablecoin flows and self-hosted wallet transfers.
- MiCA Reporting Obligations for CASPs – The EU authorisation and reporting perimeter for crypto-asset service providers.
- What the AML Regulation Changes for Obliged Entities – How the single AML Regulation and AMLA reshape supervision across the EU.
- AML Reporting in Luxembourg – A practitioner walkthrough of suspicious-transaction and supervisory reporting duties.
- Stablecoin Reporting Obligations – Where MiCA, e-money token rules and payments law meet for stablecoin issuers.
Key Takeaways
- The FATF published its seventh targeted update on virtual asset standards implementation on 16 July 2026, reviewing progress and gaps in Recommendation 15 across the Global Network.
- Travel Rule legislation now covers most surveyed jurisdictions, but many that have a law in force have not yet supervised or enforced it, so the sunrise problem persists.
- Technical compliance with Recommendation 15 is improving slowly, and risk assessments are widespread, but many jurisdictions still face challenges using those assessments to inform effective preventive, mitigation, supervisory and enforcement measures.
- Offshore VASPs, stablecoin misuse, unhosted-wallet P2P activity and decentralised finance are risks foregrounded by the report; 34 percent of jurisdictions with VASP licensing or registration requirements, 39 of 114, reported applying a more extensive approach to offshore VASPs that meet specified jurisdictional conditions.
- The report changes no filing obligation. It recommends stronger practical supervision and effective risk mitigation.
- In the EU, Regulation (EU) 2023/1113 applies from 30 December 2024. For in-scope transfers involving a crypto-asset service provider on each side, the prescribed originator and beneficiary information applies regardless of amount; Article 2(4)(a) excludes transfers where both crypto-asset service providers act on their own behalf.
- Non-EU implementations, including the UK Money Laundering Regulations Travel Rule, are separate instruments; map each corridor to the local implementing rule and treat the FATF text as background.
- The immediate action for reporting teams is to distinguish Article 14 transfer controls from counterparty due diligence: ensure the required information accompanies each transfer and maintain risk-based, periodically refreshed counterparty evidence rather than repeating full due diligence for every transfer.
Sources and References
- FATF, Seventh Targeted Update on Implementation of the FATF Standards on Virtual Assets/VASPs, 16 July 2026: fatf-gafi.org
- FATF news story, FATF calls for closing of regulatory gaps as virtual asset illicit finance risks become more complex, July 2026: fatf-gafi.org
- FATF, 2025 Targeted Update on Implementation of the FATF Standards on Virtual Assets and VASPs, 26 June 2025: fatf-gafi.org
- FATF, International Standards on Combating Money Laundering and the Financing of Terrorism & Proliferation, the FATF Recommendations, updated June 2026 (Recommendation 15, Interpretive Note to Recommendation 15, Recommendation 16 and Interpretive Note to Recommendation 16): fatf-gafi.org
- FATF, Updated Guidance for a Risk-Based Approach to Virtual Assets and VASPs, October 2021, to be read subject to subsequent amendments to the FATF Recommendations: fatf-gafi.org
- Regulation (EU) 2023/1113 of 31 May 2023 on information accompanying transfers of funds and certain crypto-assets (recast Transfer of Funds Regulation), OJ L 150, 9.6.2023: eur-lex.europa.eu
- Regulation (EU) 2023/1114 on Markets in Crypto-Assets (MiCA): eur-lex.europa.eu
- Financial Conduct Authority, FCA sets out expectations for UK cryptoasset businesses complying with the Travel Rule, first published 17 August 2023 and updated 6 February 2026: fca.org.uk
The implementation focus moves to effectiveness
The seventh targeted update is best read as a supervisory signpost. Among respondents to the relevant 2026 survey question, Travel Rule legislation was widely reported, while the FATF continued to identify major gaps in operational implementation, supervision and enforcement. For a cross-border VASP or an EU CASP, the work that follows is unglamorous and specific: know your counterparties’ real capability, wire your risk assessment into live controls, and keep evidence that those controls actually run. Firms that treated the Travel Rule solely as a data-format project should also test whether the end-to-end control operates effectively when a transfer is executed.
Last updated: July 2026
Disclaimer: The information on RegReportingDesk.com is for educational and informational purposes only. It does not constitute legal, regulatory, tax, or compliance advice. Always consult your compliance officer, legal counsel, or the relevant supervisory authority for guidance specific to your institution.