h hoge.gg
Subscribe
BTC$67,432.18+2.34%ETH$3,521.44+1.08%SOL$178.62-0.62%BNB$612.30+0.41%XRP$0.6234-0.18%ADA$0.4521+3.12%DOGE$0.1623+1.86%AVAX$38.71-1.24%LINK$17.84+0.92%HOGE$0.00004120+4.21%
BTC$67,432.18+2.34%ETH$3,521.44+1.08%SOL$178.62-0.62%BNB$612.30+0.41%XRP$0.6234-0.18%ADA$0.4521+3.12%DOGE$0.1623+1.86%AVAX$38.71-1.24%LINK$17.84+0.92%HOGE$0.00004120+4.21%
● Regulation & Policy

FATF Crypto Guidance in 2026: The Travel Rule and VASPs Explained

The FATF sets the global anti-money-laundering standards that shape how every crypto exchange operates. Here is how its guidance, the Travel Rule, and the VASP model actually work in 2026.

Almost every rule your crypto exchange follows when it asks for your ID, screens a withdrawal address, or refuses to send funds to a sketchy counterparty traces back to one body most traders have never heard of: the Financial Action Task Force. The FATF runs no courtroom, cannot fine anyone, and commands no police force. Yet its guidance on virtual assets has reshaped how exchanges operate more than almost any single national law. In July 2026 the group published its seventh targeted update on how countries are putting those standards into practice, and the message was blunt: the rules are spreading, enforcement is still thin, and criminals are moving billions through the gaps.

This guide explains what FATF guidance is, how crypto ended up inside it, and what the core requirements mean in practice: the definition of a virtual asset service provider, the Travel Rule, and the risk-based approach that ties them together. It is written for readers in the United States, where these anti-money-laundering standards are enforced mainly by the Treasury Department rather than the SEC, but the framework is global by design, and that global reach is exactly where the friction lives.

What the FATF Actually Is

The Financial Action Task Force was created in 1989 by the Group of Seven industrial nations, meeting in Paris, to coordinate a response to money laundering. Its remit later grew to cover terrorist financing and, after 2012, the financing of weapons of mass destruction. The organization is small and technocratic. It has around 40 members, including most large economies plus the European Commission and the Gulf Cooperation Council, and it sits inside the offices of the Organisation for Economic Co-operation and Development. Through nine associated regional bodies, its standards reach more than 200 jurisdictions.

What the FATF produces is a set of 40 Recommendations, a rulebook that member countries promise to translate into their own laws. The Recommendations are not a treaty and carry no direct legal force over any company or person. Their power is indirect. The FATF grades each country through a peer-review process called a mutual evaluation, scoring both technical compliance (are the right laws on the books?) and effectiveness (do they actually work in practice?). A poor grade can push a country onto one of two watchlists, and that is where soft law starts to bite, because banks worldwide treat a listing as a signal to slow down, price in extra risk, or cut ties altogether.

Crypto lives almost entirely inside one of those 40 rules. Recommendation 15, on new technologies, is the hook the FATF used to bring virtual assets and the firms that handle them into the same anti-money-laundering perimeter that already governs banks, money transmitters, and casinos. Understanding that single sentence is most of what a reader needs to make sense of every crypto compliance headline that follows.

How Crypto Got Pulled Into the FATF Net

For most of Bitcoin’s first decade, crypto sat outside the FATF framework. That changed in October 2018, when the FATF amended Recommendation 15 and its glossary to add two new defined terms, virtual asset and virtual asset service provider. The amendment settled a long argument by declaring that crypto businesses are subject to the same core obligations as other financial institutions: customer due diligence, record-keeping, suspicious-transaction reporting, and supervision.

In June 2019 the FATF filled in the detail. It adopted an Interpretive Note to Recommendation 15 and published its first Guidance for a Risk-Based Approach to Virtual Assets and VASPs, the document that introduced the crypto version of the Travel Rule. Countries were given a grace period, and the FATF committed to checking their homework. It ran a 12-month review in 2020, a second review in 2021, and then, in late October 2021, released a heavily expanded updated guidance running well past a hundred pages. That 2021 revision is still the single most important reference document, because it tackled the hard edges: decentralized finance, non-fungible tokens, stablecoins, peer-to-peer transfers, and wallets that no company controls.

Since then the FATF has settled into a rhythm of annual targeted updates, short progress reports that grade global implementation rather than rewrite the rules. The June 2025 edition, the sixth, arrived alongside a separate Best Practices paper on how to supervise the Travel Rule. The seventh, published in July 2026, is the most recent snapshot, and it frames the current state of play for the rest of this decade.

Virtual Asset and VASP: The Two Definitions That Decide Everything

Every FATF crypto obligation flows from two definitions, and both are written broadly on purpose. A virtual asset is a digital representation of value that can be digitally traded or transferred and used for payment or investment. The definition deliberately excludes anything already captured elsewhere: digital versions of national currencies (a central bank digital currency is treated as fiat, not a virtual asset), and tokens that already qualify as securities or other regulated financial instruments under existing rules.

The second term does the heavy lifting. A virtual asset service provider is any natural or legal person who, as a business and on behalf of someone else, does any of five things: exchanges crypto for cash, exchanges one crypto for another, transfers virtual assets, holds or administers them (custody), or provides financial services connected to the issuance or sale of a token. If a firm does any one of those five, it is a VASP, and the whole anti-money-laundering rulebook attaches to it.

The guiding principle is technology-neutral: same activity, same risk, same rule. The FATF does not care whether a business calls itself an exchange, a broker, a wallet provider, or a slick fintech app. It cares what the business does with customer funds. That framing sweeps in centralized exchanges, custodians, over-the-counter desks, and many payment firms. It is far harder to apply to software that runs itself, which is why decentralized finance and self-custody remain the most contested corners of the entire regime, a point the guidance keeps circling back to.

The Travel Rule, Explained

The Travel Rule is the most demanding and most discussed piece of FATF crypto guidance, and its name is borrowed from an old idea. For decades, Recommendation 16 has required banks to attach sender and recipient information to wire transfers so that the data travels with the money. The 2019 guidance extended the same logic to crypto: when one VASP sends virtual assets to another, it must obtain, hold, and pass along identifying details about both the originator and the beneficiary.

In practice that means a sending exchange has to transmit the originator’s name, the wallet address or account used, and at least one further identifier such as a physical address, a national ID number, or a date and place of birth, along with the beneficiary’s name and wallet address. The FATF recommends a de minimis threshold of $1,000. Below it, firms can share a lighter data set (names and wallet addresses) without verifying the information unless something looks suspicious. Above it, full collection and verification apply.

The technical problem is that a blockchain transaction carries none of this. A Bitcoin or Ethereum transfer moves value between addresses and says nothing about who owns them. So the industry had to build a parallel messaging layer that rides alongside the on-chain transaction. A shared data format, the interVASP Messaging Standard known as IVMS 101, lets firms speak the same language, and a patchwork of competing networks and protocols actually moves the messages between them. That parallel plumbing is where most Travel Rule pain, and most of the compliance industry that has grown up around it, now lives.

There is a second, subtler obligation buried in the Travel Rule: counterparty due diligence. Before a firm sends the data, it is expected to form a view of the receiving VASP itself, whether it is licensed, whether it has adequate controls, and whether it is safe to share a customer’s personal information with it at all. That turns every transfer into a miniature risk assessment of another company, often one on the far side of the world. Send personal data to a rogue VASP and a firm may hand a criminal exactly what it needs; refuse to send it and the transaction stalls. This tension, between sharing data and protecting it, is why privacy regulators and anti-money-laundering regulators do not always pull in the same direction.

A Timeline of FATF Crypto Guidance

The FATF has never rewritten its crypto rules wholesale. Instead it set the core standard once, then revised the guidance and checked implementation on a near-annual cadence. The table below tracks the milestones that matter.

DateMilestoneWhat it did
October 2018Recommendation 15 amendedAdded virtual asset and VASP to the FATF glossary, bringing crypto into scope
June 2019Interpretive Note and first guidanceSet out the risk-based approach and introduced the crypto Travel Rule
2020 to 2021First and second 12-month reviewsFound early implementation was far from sufficient
October 2021Updated guidanceAddressed DeFi, NFTs, stablecoins, peer-to-peer, and unhosted wallets
2022 to 2024Annual targeted updatesTracked slow, uneven adoption across jurisdictions
June 2025Sixth update and Travel Rule supervision best practicesPushed countries from writing rules to supervising them
March 2026Offshore VASPs reportTargeted firms operating from light-touch jurisdictions
July 2026Seventh targeted updateLatest scorecard on Travel Rule and Recommendation 15 compliance

What the July 2026 Targeted Update Found

The seventh targeted update, published in July 2026 with data collected through April, tells a story of steady legal progress shadowed by a persistent execution gap. On paper, adoption is now the norm rather than the exception. According to a detailed breakdown of the report, 83 percent of surveyed jurisdictions (91 of 109) have Travel Rule legislation in force, up from 73 percent a year earlier, and 93 percent have it either in force or in progress.

Technical compliance with Recommendation 15 is climbing too, though from a low base. As of April 2026, 34 percent of assessed jurisdictions were rated largely compliant, up from 29 percent, while 43 percent remained only partially compliant and 22 percent non-compliant. Nearly two-thirds of assessed countries still sit below full compliance. More jurisdictions are also completing formal risk assessments, but far fewer are turning those assessments into real supervisory action, which is where the story turns.

Metric20252026
Travel Rule legislation in force73%83% (91 of 109)
In force or in progress85%93%
Rated largely compliant with R.1529%34%
Jurisdictions conducting VA risk assessments76%86% (124 of 145)

One counterintuitive finding sits underneath these numbers: a growing minority of countries have chosen to ban VASPs outright rather than license them. Roughly 23 percent now prohibit virtual asset services, up from around 11 percent in 2023. Prohibition is not the same as safety, though, because activity simply migrates offshore or underground, which is the theme the FATF returned to again and again through 2026.

The report is not only a scorecard; it is also a to-do list. The FATF asked jurisdictions to finish licensing and registering the VASPs operating in their markets, to actually use the risk assessments they have completed, to move from writing Travel Rule statutes to supervising and enforcing them, and to sharpen their focus on stablecoins, DeFi, and offshore providers. It also leaned on the private sector, urging exchanges and Travel Rule vendors to keep building the interoperable plumbing that compliance depends on. None of these asks are new. The fact that the FATF is repeating them, update after update, is itself part of the story.

The Enforcement Gap: Rules on Paper, Silence in Practice

The single most important number in the 2026 update is not about adoption; it is about enforcement. Of the 91 jurisdictions that have Travel Rule laws in force, roughly 60 percent (55 of them) had not yet taken a single supervisory or enforcement action related to the rule. Writing a statute is one thing. Standing up a supervisor who inspects firms, issues findings, and levies penalties is another, and most countries have not yet made that leap.

This gap matters because criminals do not exploit the rulebook; they exploit the enforcement calendar. A jurisdiction can pass a picture-perfect Travel Rule and still be a soft target if no examiner ever checks whether exchanges actually collect and transmit the data. The FATF has spent two consecutive updates trying to move the conversation from legislation to supervision, and its June 2025 Best Practices paper on Travel Rule supervision was aimed squarely at the countries that stalled after passing a law. For readers tracking how enforcement culture develops elsewhere in crypto, the same pattern of rules outpacing action shows up in US securities enforcement, where the distance between a written standard and a filed case is what defines the real risk to a business.

Supervision, in the FATF’s sense, is unglamorous and expensive. It means hiring examiners who understand blockchains, running on-site inspections, testing whether a firm’s Travel Rule messages actually reach their destination, and being willing to fine or delicense a company that falls short. Many smaller jurisdictions simply lack the staff and technical skill to do this, and some larger ones have not made it a priority. The result is a widening split between a handful of tough supervisors and a long tail of countries where the rules exist mainly on paper, a split the 2026 update measures but cannot, on its own, close.

The Sunrise Problem

Even where the Travel Rule is fully enforced, a structural headache remains. Because countries switch the rule on at different times, a compliant exchange in one jurisdiction routinely has to transact with a counterparty in a jurisdiction where the rule does not yet exist. The industry calls this the sunrise issue, because compliance dawns over the world at different hours, and it is widely described as the biggest practical obstacle to Travel Rule adoption.

The problem is not just legal timing; it is interoperability. A sending firm has to identify which VASP controls the receiving wallet, confirm that firm can accept a Travel Rule message, and agree on a shared protocol before any data can move. With several competing networks in the market and no universal directory of who controls which address, even two willing, fully regulated firms can struggle to hand off the required information. Pelle Braendgaard, chief executive of the compliance firm Notabene, once summed up the awkward fit in a Chainalysis podcast, saying flatly, “The Travel Rule is really the worst possible name for what this is.” The label suggests a simple data transfer; the reality is a coordination problem across thousands of firms that were never designed to talk to one another.

Stablecoins Move to the Center of the Risk Map

When the FATF first wrote its crypto guidance, Bitcoin was the assumed vehicle for illicit flows. That has changed. Dollar-pegged stablecoins are now the dominant rail for on-chain crime, because they combine the speed and reach of crypto with the price stability of the currency criminals actually want to hold. Chainalysis reported that stablecoins accounted for roughly 63 percent of illicit crypto transaction volume in 2024, the year its 2025 Crypto Crime Report found illicit addresses received close to $41 billion. The share kept climbing into 2025, when sanctions-related crypto activity surged and sanctioned entities alone received more than $100 billion.

The seventh targeted update leaned hard into this shift, and it had a case study ready. In May 2025 the US Treasury’s Financial Crimes Enforcement Network designated the Cambodia-based Huione Group a primary money laundering concern, finding that the conglomerate had moved at least $4 billion in illicit proceeds and served as a critical node for laundering the profits of North Korean cyber heists and Southeast Asian investment scams. After regulators began cutting off its access to established stablecoins, Huione did something telling: it launched its own token, marketed as unfreezable and beyond the reach of regulators. Treasury Secretary Scott Bessent did not mince words, saying the group “has established itself as the marketplace of choice for malicious cyber actors like the DPRK and criminal syndicates, who have stolen billions of dollars from everyday Americans.” Elliptic research underpinned the case, and the special measure took full effect later in 2025.

The Huione playbook exposes a paradox at the heart of stablecoin risk. The dominant regulated stablecoins are, in some ways, easier to police than Bitcoin, because their issuers can freeze tokens sitting at a specific address and have done so at law enforcement request, sometimes locking up sums running into the hundreds of millions of dollars. That freeze power is a compliance feature. It is also exactly what a laundering operation wants to escape, which is why a cornered network eventually tries to mint its own coin that no one can freeze. The FATF standards are meant to keep that kind of unregulated issuance from finding an easy on-ramp into the legitimate financial system.

For the FATF, Huione is a near-perfect illustration of why the standards exist and why gaps in them are dangerous. A firm operating from a light-touch jurisdiction, issuing an unregulated stablecoin, and serving a global customer base is precisely the shape of risk that the VASP model and the Travel Rule were built to contain, and precisely the shape that slips through when supervision is missing.

DeFi and Unhosted Wallets: The Hard Cases

The VASP model assumes there is a company in the middle. Decentralized finance and self-custody both challenge that assumption, and the FATF has spent years trying to fit them into a framework designed for intermediaries.

On DeFi, the 2021 guidance took a controversial position: even where a protocol looks fully decentralized, the people who own or operate it, or otherwise keep control or sufficient influence, may themselves be VASPs, regardless of whether the software runs autonomously. Critics argued this stretched the definition past its breaking point. The 2026 update shows how little has been resolved on the ground: only around 18 percent of jurisdictions had assessed DeFi risks at all, and the overwhelming majority reported that they had identified no DeFi arrangements qualifying as VASPs in their territory. The distance between the FATF’s theory and national practice remains wide, which matters as on-chain credit markets grow more sophisticated, from perpetual liquidity pools to the fixed-rate lending markets now taking shape.

Unhosted wallets (self-custodied addresses that no VASP controls) are the other flashpoint. The FATF does not require countries to ban them or to force individuals to register, and a purely private transfer between two self-custodied wallets falls outside the Travel Rule. But when a VASP interacts with an unhosted wallet, the guidance expects the firm to collect the required customer information and apply enhanced scrutiny based on risk. The spread of smart-contract wallets complicates the picture further, since a modern account can behave like custody software one moment and a self-custodied wallet the next; standards such as EIP-7702, which turns ordinary Ethereum accounts into programmable smart wallets, blur the very line the FATF’s categories depend on.

Offshore VASPs and the Blind-Spot Economy

If prohibition pushes activity offshore and DeFi resists the intermediary model, the two forces meet in the figure of the offshore VASP: a firm that incorporates in a jurisdiction with weak supervision while serving customers everywhere else. In March 2026 the FATF devoted a dedicated report to the problem, warning that these providers create oversight blind spots that fraudsters, scam networks, and sanctioned actors exploit at scale.

Elisa de Anda Madrazo of Mexico, who served as FATF President when the report launched, framed the stakes in stark terms, saying it “exposes how oVASPs create blind spots that criminals are clearly exploiting, to scam vulnerable people through fraud or fuel terror around the world.” The recommended fix is to regulate based on where the activity actually reaches, not just where a company files its paperwork. The 2026 update found that only about a third of jurisdictions with licensing frameworks (39 of 114) yet regulate offshore providers using activity anchors such as targeted marketing to local users or reliance on domestic payment rails. Until that share rises, the offshore route remains the path of least resistance for anyone trying to serve customers while dodging the rules.

The Grey List and Black List: FATF’s Real Leverage

Because the FATF cannot fine anyone, its enforcement power runs through reputation, and specifically through two lists maintained by its International Co-operation Review Group. The first, formally the Jurisdictions under Increased Monitoring and universally called the grey list, names countries with strategic deficiencies that are working with the FATF on an agreed action plan. The second, the High-Risk Jurisdictions subject to a Call for Action, is the black list, reserved for the worst cases.

As of 2026 the black list holds three names: Iran, North Korea, and Myanmar, with member states urged to apply counter-measures against them. The grey list is longer and more fluid, standing at 22 jurisdictions after the June 2026 plenary added Iraq and Bosnia and Herzegovina and removed Algeria and Namibia. A grey listing is not a crypto penalty as such, but weak virtual asset supervision has become one of the recurring deficiencies that can land a country there or keep it stuck, and the resulting friction (heightened bank scrutiny, slower correspondent banking, higher costs for ordinary businesses) is exactly the pressure that turns a voluntary standard into a national priority.

How the United States Implements FATF Standards

The United States is a founding FATF member, and much of the American anti-money-laundering system predates the crypto guidance. The relevant authority here is not the SEC but the Treasury Department’s Financial Crimes Enforcement Network, which administers the Bank Secrecy Act. In May 2019 guidance, FinCEN confirmed that businesses accepting and transmitting convertible virtual currency are money transmitters, and therefore money services businesses that must register, run an anti-money-laundering program, verify customers, and file suspicious activity reports.

The US has had its own Travel Rule since well before crypto, applying to funds transfers at or above $3,000, and FinCEN treats it as covering convertible virtual currency. Regulators once proposed lowering the threshold to $250 for cross-border transfers, though that change was never finalized. Sanctions are a separate and powerful layer: the Treasury’s Office of Foreign Assets Control can place wallet addresses on its blacklist, as it has done with mixing services, and dealing with a listed address is illegal regardless of any FATF standard. The SEC, for its part, governs the securities dimension of crypto, deciding when a token sale is an investment contract, while the CFTC oversees commodities and derivatives. FATF guidance sits underneath all of this as the anti-money-laundering baseline, and the broader American rulebook keeps moving; readers can follow the shifting deadlines in our guide to crypto’s 2026 regulatory calendar.

The anti-money-laundering baseline is only one layer of a fast-moving American stack. Congress passed the GENIUS Act in 2025, a federal framework for payment stablecoins that requires issuers to hold full reserves and meet Bank Secrecy Act obligations, which pulls the most systemically important tokens further inside the regulated perimeter the FATF describes. The direction of travel in the US is toward treating serious stablecoin issuers less like crypto startups and more like regulated financial institutions, with the customer-identification and reporting duties that status brings.

The European Union took a different route, folding the Travel Rule into its Transfer of Funds Regulation and pairing it with the broader MiCA regime, a contrast we cover in our look at Europe’s live crypto rulebook. The FATF sets the common floor; each jurisdiction builds its own house on top of it, which is precisely why a single global standard produces such different experiences depending on where a user or firm sits.

What FATF Guidance Means for Users and Builders

For everyday users, FATF guidance is the invisible reason your exchange behaves the way it does. The identity checks at signup, the questions about a large withdrawal, the occasional refusal to send funds to an unfamiliar address, and the request to name the owner of a receiving wallet all descend from the risk-based approach and the Travel Rule. None of it is optional for a regulated firm, and the trend is toward more data collection, not less.

For builders, the decisive question is a single line: are you acting as a business on behalf of someone else in a way that touches one of the five VASP activities? The answer determines whether an entire compliance stack attaches to your project. The table below sketches the rough dividing line, though every real case turns on the specific facts and on local law.

Usually a VASPUsually not a VASP
Centralized exchange holding customer fundsAn individual trading their own crypto
Custodial wallet or custody providerA non-custodial wallet that only provides software
Over-the-counter and brokerage desksA developer publishing open-source code
Crypto payment processor moving funds for clientsMiners or validators confirming transactions
Token issuer offering related financial servicesA person paying a merchant directly from self-custody

The practical takeaways for anyone operating in the space are straightforward:

  • Assume identity data will follow your transfers between regulated firms, and that the amount of data rises once you cross the $1,000 threshold.
  • Expect withdrawals to unhosted wallets to draw extra questions, not because self-custody is banned, but because the FATF asks firms to apply risk-based scrutiny.
  • Watch the jurisdiction of any service you use; an offshore VASP with no meaningful supervision is exactly the profile regulators are now targeting.
  • Treat stablecoins as the most heavily monitored corner of crypto, since they now dominate both legitimate settlement and illicit flows.

Frequently Asked Questions

What is FATF guidance and is it legally binding?

The FATF is an intergovernmental standard-setter, not a lawmaking body, so its guidance is not directly binding on individuals or companies. Countries adopt the standards into their own laws, and the FATF enforces compliance indirectly through mutual evaluations and its grey and black lists, which can raise a nation’s cost of accessing the global financial system.

What is the FATF Travel Rule for crypto?

The Travel Rule requires virtual asset service providers, such as exchanges, to collect and share identifying information about the sender and recipient whenever they transfer crypto above a threshold the FATF sets at $1,000. It mirrors a long-standing requirement for bank wire transfers and is meant to keep an audit trail as funds move between regulated firms.

Who counts as a VASP under FATF rules?

A VASP is any business that, on behalf of customers, exchanges crypto for cash or other crypto, transfers virtual assets, holds or safeguards them, or provides financial services tied to a token issuance. Centralized exchanges, custodians, and many brokers qualify, while individuals transacting for themselves and developers who only publish software generally do not.

Does the Travel Rule apply to self-custody or unhosted wallets?

The Travel Rule applies to VASPs, not to private individuals, so a transfer between two self-custodied wallets is not directly covered. When a VASP sends to or receives from an unhosted wallet, however, the FATF expects the firm to collect the required customer information and apply extra scrutiny based on risk.

How does the United States enforce FATF crypto standards?

In the US, the Treasury’s Financial Crimes Enforcement Network applies the Bank Secrecy Act to crypto firms it treats as money services businesses, requiring registration, customer identification, suspicious activity reports, and a version of the Travel Rule. The SEC, CFTC, OFAC, and state regulators cover other parts of the crypto perimeter, from securities law to sanctions.

By Priya Reddy, regulation correspondent at HOGE Wire.

Share 𝕏 Post Telegram