In 2019, the Financial Action Task Force (FATF), the global money laundering and terrorist financing watchdog, extended its global standards on anti-money laundering and counter-terrorist financing (AML/CFT) to apply to virtual assets (VAs) and virtual asset service providers (VASPs).
On July 16, 2026, the watchdog published its seventh annual targeted review of implementation of these standards also known as Recommendation 15.
Let’s unwrap the key findings from the report, progress made by different jurisdictions including India, and also its recommendations to both the private and public sectors in regulating and supervising VASPs for AML/CFT purposes.
| First things first. What are the FATF Standards on VAs/VASPs?
The FATF Recommendations, also referred to as standards, provide a comprehensive framework of measures to help countries tackle illicit financial flows. Out of the 40 standards, Recommendation 15 pertains to new technologies and VA/VASPs. |
Here are the criteria for assessment under this standard with respect to VA/VASPs:
| 15.3 | Risk assessment and application of a risk-based approach |
| 15.4 | Licensing/Registration of VASPs |
| 15.5 | Identification of natural persons or legal entities that conduct VASP activities |
| 15.6 | Supervision/Regulation of VASPs to ensure AML/CFT compliance |
| 15.7 | Establishment of guidelines which assist VASPs in AML/CFT compliance |
| 15.8 | Sanctions compliance |
| 15.9 | Preventative AML/CFT measures including the Travel Rule |
| 15.10 | Targeted Financial Sanctions compliance |
| 15.11 | International cooperation |
For each standard there are 4 possible levels of compliance:
- Compliant (there are no shortcomings)
- Largely compliant (there are only minor shortcomings)
- Partially compliant, and (there are moderate shortcomings)
- Non-compliant (There are major shortcomings)
Jurisdictions’ Implementation of FATF Standards on VAs/VASPs (R15)
As of April 2026, 149 jurisdictions have been assessed for compliance with the FATF standards for VAs and VASPs. 34% (51 of 149 jurisdictions) are now largely compliant (LC) with FATF’s standards for VA/VASPs compared to 29% of the jurisdictions in 2025. As in 2025, only one jurisdiction continues to be fully compliant (C) with R.15.

The results of the FATF’s 2026 survey show that the vast majority of respondents (86%; 124 of 145 jurisdictions) reported having conducted an ML/TF/PF risk assessment for VA/VASP risks.
However, challenges still remain in implementing preventive and/or mitigation measures in line with identified risks or using the results of the risk assessments to implement risk-based supervision.
Notably, an increasing proportion of jurisdictions have identified how they intend to regulate the VA sector, increasing from 82% in 2025 (134 of 163 jurisdictions) to 89% (128 of 144 jurisdictions) in 2026. However, a minority of jurisdictions continue to report that they have not yet decided if and how to regulate the sector. This proportion decreased from 2025 (18%; 29 of 163 jurisdictions had not decided on their approach) to 2026 (11%; 16 of 144 jurisdictions).
While a prohibition is permissible under the FATF Standards, as discussed in previous Targeted Updates, it may be difficult to implement effectively unless jurisdictions take proactive steps to identify prohibited VA/VASP activities and apply appropriate supervisory and enforcement measures to prevent and sanction such activities. An increase in the use of prohibitions may therefore raise concerns in the future if jurisdictions are not able to enforce them effectively.
Similar to the results in the 2025 report, survey responses show that members of MENAFATF (Middle East and North Africa region) have more commonly chosen a partial or total prohibition approach compared to members of other FATF-Style Regional Bodies.
Other jurisdictions are progressively developing regulatory frameworks through new legislation, sandbox initiatives, or alignment with models such as MiCA. Overall, there is a converging regulatory pattern toward restricting payment functions while integrating virtual asset activities into formal regulatory and supervisory systems.

Licensing/Registering VASPs
Jurisdictions have developed licensing or registration frameworks for VASPs, although progress in operational implementation remains uneven. 73% of respondents (95 of 130), excluding those that prohibit or plan to prohibit VASPs entirely, report that they require VASPs to be licensed or registered. However, progress in actual licensing or registration appears more limited.
In the 2026 survey, 58% of respondents (76 of 130) reported having licensed or registered a VASP in practice, compared with 65% (76 of 117) in 2025. While many respondents have implemented VASP licensing or registration requirements as part of their AML/CFT frameworks, several jurisdictions do not yet have operational licensing or registration frameworks.
This is similar to the findings of the 2025 Targeted Update, which also noted that assessment results may not fully reflect updates captured in survey responses. The difference may also reflect methodological differences or reporting inconsistencies in self-reported survey data.

Travel Rule Implementation
The Travel Rule applies the FATF’s payment transparency requirements (FATF Recommendation 16) to the VA context. The Travel Rule requires VASPs and financial institutions to obtain, hold, and transmit specific originator and beneficiary information immediately and securely when engaging in payments or value transfers, including VAs and hybrid payment chains. Jurisdictions have made progress on implementing the Travel Rule.
For the 2026 survey, 83% of respondents (91 of 109 jurisdictions) have passed legislation implementing the Travel Rule (see Figure 1.10), up from 73% (85 of 117) in 2025. An additional 11 of 109 jurisdictions reported being in the process of implementing the Travel Rule, compared to 14 of 117 jurisdictions in 2025.

Slightly more than half of the 91 jurisdictions (60%; 55 of 91) that have passed legislation implementing the Travel Rule have not yet issued findings or directives or taken enforcement or other supervisory actions against VASPs focused on Travel Rule compliance. This likely reflects that many jurisdictions have only recently enacted Travel Rule legislation and are currently focused on establishing supervision frameworks in this new area.
The report also includes status of implementation of recommendation 15 by FATF members and jurisdictions with materially important VASP Activity, where India’s progress and survey responses are captured.
(Read our earlier blog on India’s FATF Mutual Evaluation here)

Finally, what are the Recommendations for the Public and Private sectors?
Recommendations for the Public Sector:
| Recommendations for the Public Sector | ||
|---|---|---|
| Understand and comprehensively assess the ML/TF/PF risks posed by VAs and VASPs (even where choosing to prohibit VASPs) | 1. Develop a clear and thorough understanding of the ML/TF/PF risks posed by VAs and VASPs in order to allocate supervisory and enforcement resources proportionate to the national risk and context. The risk assessment of VAs and VASPs should consider the jurisdiction’s overall exposure (materiality) as well as the specific ML/TF/PF risks associated with: i. VASPs established or created in the jurisdiction; ii. VASPs operating or offering services within the jurisdiction (oVASPs); iii. Stablecoin issuers and DeFi arrangements that have controllers based or operating in the jurisdiction; iv. Peer-to-peer transactions and unhosted wallets;v. Emerging technologies, business models, trends and methods in the VA ecosystem. 2. Rely on a broad range of credible resources to conduct the VAs/VASPs risk assessment. While the FATF does not prescribe a specific methodology for assessing the VA/VASP sector, jurisdictions should be able to demonstrate that they have identified and understood the ML/TF/PF risks posed by VAs and VASPs and that they have implemented appropriate and effective mitigating measures |
|
| Adopt a robust supervisory framework for VAs and VASPs | 3. Prioritise efforts and allocate supervisory resources to identify and assess the ML/TF/PF risks associated with VAs and VASPs and implement an appropriate supervisory framework in line with Recommendation 15.
This should include: ii. Supervisory inspections and guidance: Conducting both off-site and on-site inspections of VASPs and providing feedback and guidance on the effectiveness of their AML/CFT/CPF compliance frameworks, including the implementation of the Travel Rule. iii. Enforcement against unlicensed activity: Adopting effective measures to identify and sanction natural or legal persons that, in practice, conduct VASP activities without the required license or registration. |
|
| Enhance international and public-private cooperation to investigate and seize illicit assets | 4. Substantially strengthen collaboration with foreign counterparts and relevant private-sector stakeholders to ensure that criminal activities linked to existing and emerging ML/TF/PF risks can be effectively disrupted in practice, whether these activities involve VASPs, peer-to-peer transactions, or unhosted wallets.
This may be achieved by: i. Establishing cooperation mechanisms: Creating and utilising both formal and informal international and domestic cooperation channels to facilitate timely information sharing for the identification of illicit assets and threat actors. ii. Enabling effective asset freezing and confiscation: developing adequate operational infrastructure, legal frameworks, and protocols involving public authorities and private-sector partners to enable the rapid tracing, freezing and seizure of illicit virtual assets. |
|
Recommendations for the Private Sector:
| Recommendations for the Private Sector | |
|---|---|
| Travel Rule | VASPs, including Stablecoin issuers and qualifying DeFi arrangements, should establish robust AML/CFT/CPF compliance frameworks and implement the Travel Rule in line with the requirements of R.15.
VASPs should ensure that: i. they thoroughly understand their institutional risk, and assess emerging risks associated with stablecoins, P2P transactions, unhosted wallets, oVASPs and DeFi-related activities. ii. their AML/CFT controls, including KYC, wallet screening, blacklisting, and, where appropriate, whitelisting mechanisms as well as freezing and blocking capabilities adequately mitigate identified risks and can be swiftly updated to respond to emerging ML/TF/PF trends and typologies. iii. they proactively collaborate with competent authorities and private sectors to identify, investigate and prosecute illicit activity by sharing typologies, red flags, good practices, and ensuring that they can provide tactical and operational assistance in the course of law enforcement investigations. |
| Other recommended actions | On the basis of the findings of the FATF Targeted Reports and related recommended actions, VASPs should: i. strengthen the monitoring of transactions involving unhosted wallets by applying enhanced due diligence measures for higher-risk wallet activity. ii. identify suspicious patterns in VA transactions and detect rapid transfer of VAs using transactions monitoring and blockchain analytics tools. iii. Conduct enhanced due diligence of oVASPs, detect accounts used by oVASPs that misrepresent themselves as retail users, restrict or exit higher-risk relationships, and monitor fiat on and off-ramp activity linked to unlicensed or weakly supervised offshore platforms. iv. Assess risks arising from DeFi activities, including exposure to protocols, bridges, mixers, cross-chain tools, and apply appropriate AML/CFT/CPF measures to mitigate those risks. |