Crypto regulation is no longer only about whether Bitcoin, Ethereum or stablecoins are legal.
A much bigger question is now being asked around the world:
How can governments allow digital assets to grow while preventing criminals, fraud networks, terrorist financiers and other illicit actors from using crypto to move money?
One of the most important organizations shaping the answer is the Financial Action Task Force (FATF).
FATF does not operate like a national financial regulator. It does not directly license a crypto exchange in India, the United States, Europe or another country. Instead, FATF develops international standards that countries use when building their own anti-money laundering and counter-terrorist financing frameworks.
For crypto, one of the most important standards is FATF Recommendation 15, together with its Interpretive Note.
Recommendation 15 brings virtual assets and businesses handling certain virtual-asset activities into the global AML/CFT framework. It covers areas such as:
- Virtual assets
- Virtual Asset Service Providers, or VASPs
- Customer due diligence
- KYC
- Transaction monitoring
- Suspicious transaction reporting
- Record keeping
- Licensing and registration
- Risk assessment
- International cooperation
- The Travel Rule
- Peer-to-peer transactions
- Stablecoins
- DeFi arrangements
- Unhosted or self-hosted wallets
The subject has become increasingly important because crypto markets are global by design. A person can hold an asset in one country, use an exchange registered in another country, interact with a protocol operating across multiple jurisdictions and transfer funds to a wallet controlled somewhere else.
That creates a regulatory challenge that traditional financial systems do not face in exactly the same way.
FATF’s latest targeted update, published on 16 July 2026, says countries have continued to make progress, but significant implementation gaps remain. FATF also highlighted increasing risks involving stablecoins, P2P transactions through unhosted wallets, offshore VASPs, fraud and certain DeFi arrangements.
Understanding FATF is therefore essential for anyone who wants to understand the future of global crypto regulation.
What Is FATF?
FATF stands for the Financial Action Task Force.
It is an international body that develops standards for combating:
- Money laundering
- Terrorist financing
- Proliferation financing
- Other forms of illicit financial activity
Its work influences financial regulation across a large global network of countries and jurisdictions.
FATF’s purpose is not to ban financial innovation.
Instead, its central idea is that financial systems should have safeguards that make it harder for criminals to hide, move and use illicit funds.
The same philosophy has increasingly been applied to crypto.
FATF describes virtual assets as digital representations of value that can be digitally traded, transferred or used for payment, while its standards require countries to understand the risks, regulate relevant VASPs and subject them to appropriate supervision.
Does FATF Directly Regulate Crypto?
No.
This is one of the most important points to understand.
FATF creates international standards. Individual countries implement those standards through their own laws and regulations.
For example, a country may create:
- A crypto licensing regime
- An AML registration requirement
- A VASP supervisory framework
- KYC requirements
- Travel Rule requirements
- Suspicious transaction reporting obligations
- Customer identification rules
- Record-retention requirements
Therefore, FATF compliance and local legal compliance are not exactly the same thing.
A crypto company cannot simply say:
“We follow FATF, therefore we are legally licensed everywhere.”
That would be incorrect.
A business must comply with the laws of every jurisdiction in which it operates or is otherwise subject to regulation.
Why FATF Matters So Much for Crypto
Crypto is borderless.
A traditional bank generally operates through a clearly identifiable legal entity, banking license, banking accounts and regulated payment infrastructure.
Crypto can involve:
- Centralised exchanges
- Decentralised exchanges
- Stablecoin issuers
- Wallet providers
- Custodians
- Brokers
- OTC desks
- Payment providers
- Smart contracts
- DAOs
- Bridges
- DeFi protocols
- Peer-to-peer markets
- Self-hosted wallets
This creates a difficult regulatory question:
Who should be responsible for preventing illicit financial activity when value can move through software and blockchain networks without passing through a traditional bank?
FATF’s framework attempts to answer part of this question by focusing on activities, risks and identifiable service providers rather than simply treating “crypto” as one single category.
What Is Recommendation 15?
Recommendation 15 is one of the central FATF standards for crypto regulation.
Its original purpose relates to new technologies and the need for countries and financial institutions to identify and manage risks arising from new products, business practices and technologies.
FATF subsequently extended the AML/CFT framework to virtual assets and VASPs.
The Interpretive Note to Recommendation 15 provides more specific requirements for virtual assets and VASPs.
In simple terms, Recommendation 15 tells countries that they should:
- Understand the risks created by virtual assets.
- Regulate relevant VASPs for AML/CFT purposes.
- Require appropriate licensing or registration.
- Supervise or monitor VASPs.
- Apply preventive AML/CFT measures.
- Require appropriate customer due diligence.
- Maintain transaction and customer records.
- Report suspicious transactions.
- Apply appropriate sanctions.
- Cooperate internationally.
FATF’s guidance explains that VASPs should be subject to relevant preventive measures similar to those applied to financial institutions.
Recommendation 15 Is Based on a Risk-Based Approach
An important concept in FATF regulation is the risk-based approach.
This means regulators and businesses should not treat every customer, transaction or crypto activity as having exactly the same level of risk.
For example:
A small customer making ordinary transactions through a regulated exchange may present a different risk profile from an entity moving large amounts through multiple jurisdictions, mixers, high-risk counterparties and complex transaction structures.
The risk-based approach therefore asks:
- Who is the customer?
- What is the customer’s business?
- Where is the customer located?
- Where are funds coming from?
- Where are funds going?
- What assets are being transferred?
- What counterparties are involved?
- What blockchain activity is visible?
- Is there unusual transaction behaviour?
- Is the customer connected to a high-risk jurisdiction or sanctioned person?
- Does the activity involve anonymity-enhancing technologies?
The goal is not simply to collect information.
The goal is to identify and manage financial crime risk.
What Is a Virtual Asset?
The FATF framework uses the term Virtual Asset, commonly abbreviated as VA.
A virtual asset generally refers to a digital representation of value that can be digitally traded, transferred or used for payment or investment purposes.
Cryptoassets such as Bitcoin and many other blockchain-based assets can fall within this framework depending on their characteristics and the applicable jurisdiction.
However, not every digital asset is automatically treated the same way.
National laws can use different terminology and classifications.
For this reason, businesses should never assume that an asset is regulated or unregulated simply because it is called a “token,” “coin,” “stablecoin” or “digital asset.”
The legal classification depends on the applicable law.
What Is a VASP?
VASP means Virtual Asset Service Provider.
This is one of the most important concepts in FATF’s crypto framework.
A VASP is broadly a business that, as a business, performs covered activities involving virtual assets.
Depending on the applicable FATF framework and national implementation, activities can include:
- Exchange between virtual assets and fiat currencies
- Exchange between different virtual assets
- Transfer of virtual assets
- Custody or administration of virtual assets or related instruments
- Certain financial services related to the issuance or sale of virtual assets
The important point is that FATF focuses on the activity being performed, not simply on what a company calls itself.
A company calling itself a “technology platform” does not automatically avoid regulation if it is actually performing activities that fall within the VASP definition under the applicable framework.
Examples of Businesses That May Fall Within VASP Regulation
Depending on their actual activities, businesses potentially covered by VASP rules can include:
- Centralised crypto exchanges
- Crypto brokers
- Custodial wallet providers
- Crypto payment businesses
- Certain OTC trading businesses
- Certain crypto transfer services
- Businesses facilitating covered virtual-asset transfers
- Certain token-related financial service providers
The exact legal treatment depends on the country.
This is why the same business model may be regulated differently in different jurisdictions.
VASP Licensing and Registration
FATF expects countries to require relevant VASPs to be licensed or registered.
This is a major part of the global regulatory model.
A country may require a crypto business to:
- Register with a financial intelligence authority
- Obtain a virtual-asset license
- Meet minimum capital requirements
- Maintain compliance systems
- Appoint compliance personnel
- Conduct KYC
- Monitor transactions
- Report suspicious activity
- Maintain records
- Submit to regulatory inspections
The purpose is to prevent businesses from operating anonymously or outside supervisory control.
FATF has repeatedly identified licensing and registration as areas where implementation remains incomplete in many jurisdictions.
What Is AML?
AML means Anti-Money Laundering.
Money laundering is the process of disguising the origin or ownership of illegally obtained funds so that they appear legitimate.
Crypto can potentially be used at different stages of such activity.
For example, illicit funds could be:
- Obtained through fraud.
- Converted into crypto.
- Transferred through multiple wallets.
- Swapped between different assets.
- Sent across jurisdictions.
- Converted back into fiat.
- Deposited into another financial system.
Blockchain transactions can create a permanent public record, but that does not automatically mean every blockchain address is linked to a real-world identity.
This is one reason AML systems use both blockchain intelligence and traditional customer information.
What Is CFT?
CFT means Countering the Financing of Terrorism.
The objective is to prevent financial resources from being provided to terrorists or terrorist organisations.
AML and CFT are usually discussed together as AML/CFT.
The two concepts overlap but are not identical.
AML focuses heavily on detecting and disrupting the movement or concealment of illicit proceeds.
CFT focuses on preventing funds and financial services from being used to support terrorism, including situations where the money itself may have originated from legitimate sources.
AML vs KYC
These terms are often used together but they are not the same.
KYC means Know Your Customer.
KYC is primarily about identifying and understanding the customer.
AML is the broader framework used to prevent, detect and report money laundering and related financial crime.
KYC is therefore one important component of an AML programme.
A typical crypto onboarding process may involve:
- Name
- Date of birth
- Address
- Government-issued identification
- Contact information
- Nationality or residency information
- Beneficial ownership information for businesses
- Source-of-funds information in higher-risk situations
The exact requirements depend on the jurisdiction and risk level.
What Is Customer Due Diligence?
Customer Due Diligence, or CDD, goes beyond simply collecting an identity document.
A regulated crypto business may need to understand:
- Who the customer is
- Who ultimately owns a business account
- What the customer does
- Why the account is being opened
- Expected transaction activity
- Source of funds where appropriate
- Source of wealth in higher-risk cases
- Whether the customer presents increased financial crime risk
The objective is to create a reasonable understanding of the customer and their expected activity.
Enhanced Due Diligence
Some customers and transactions present higher risks.
In such situations, businesses may apply Enhanced Due Diligence, or EDD.
EDD can involve:
- Additional identity verification
- More detailed source-of-funds checks
- Source-of-wealth information
- Additional management approval
- More frequent transaction reviews
- Enhanced blockchain monitoring
- Greater scrutiny of counterparties
The purpose is not to treat every customer as suspicious.
It is to apply stronger controls when the risk justifies them.
What Is Suspicious Transaction Reporting?
A regulated crypto business may have a legal obligation to report suspicious activity to the relevant authority.
Depending on the jurisdiction, this can involve a Suspicious Transaction Report (STR) or a similarly named report.
Examples of potentially suspicious behaviour may include:
- Rapid movement of large amounts without an apparent economic purpose
- Structuring transactions to avoid reporting thresholds
- Transactions involving sanctioned parties
- Unusual use of multiple accounts
- Repeated transfers through high-risk counterparties
- Fraud-related patterns
- Complex transactions designed to obscure the source of funds
Importantly, a suspicious transaction report does not necessarily mean the customer committed a crime.
It means the activity has triggered a reporting obligation under the relevant rules.
Transaction Monitoring in Crypto
Crypto creates a unique advantage for compliance teams:
blockchain transactions are often publicly observable.
A crypto compliance system can combine:
- Customer identity data
- Exchange account data
- Blockchain addresses
- Transaction history
- Risk intelligence
- Sanctions information
- Wallet screening
- Behavioural analysis
This allows businesses to create a more complete risk picture.
For example, an exchange may identify that a customer’s deposit originated from an address associated with a high-risk service.
The exchange can then investigate the transaction according to its internal risk procedures and applicable law.
What Is the FATF Travel Rule?
The Travel Rule is one of the most important parts of crypto compliance.
It extends payment-transparency requirements into the virtual-asset environment.
In simple language:
When certain virtual-asset transfers take place between regulated entities, required information about the sender and recipient must travel with the transaction.
FATF describes the Travel Rule as requiring VASPs and financial institutions to obtain, hold and securely transmit specified originator and beneficiary information when transferring virtual assets.
The Travel Rule is associated with FATF Recommendation 16, applied to virtual assets through the framework surrounding Recommendation 15.
What Information Does the Travel Rule Cover?
The precise implementation differs by jurisdiction, but the framework generally involves information about:
Originator
- Name
- Account or wallet identifier where applicable
- Relevant address or identifying information
Beneficiary
- Name
- Account or wallet identifier where applicable
- Relevant identifying information
The information must be handled securely.
The purpose is to make it more difficult for criminals to move money through regulated financial institutions while hiding who sent and received it.
How the Travel Rule Works
Imagine Alice uses Exchange A.
She wants to send crypto to Bob, who uses Exchange B.
A simplified Travel Rule process looks like this:
Alice β Exchange A β Travel Rule information β Exchange B β Bob
Exchange A identifies Alice and obtains the required transaction information.
Exchange A sends the required information to Exchange B through an appropriate Travel Rule solution or communication mechanism.
Exchange B uses the information as part of its compliance process.
The blockchain transaction itself does not necessarily contain all of the personal information.
Instead, the regulated entities exchange the required information through compliance infrastructure.
Why the Travel Rule Is Difficult for Crypto
Traditional financial institutions already have established systems for transmitting payment information.
Crypto operates differently.
Transfers can happen:
- Exchange to exchange
- Exchange to personal wallet
- Personal wallet to exchange
- Wallet to wallet
- Across different blockchains
- Through smart contracts
- Through bridges
- Through decentralised applications
This creates difficult questions.
For example:
What happens when the recipient is a self-hosted wallet rather than another regulated VASP?
This is one reason Travel Rule implementation has required significant technical and regulatory development.
Travel Rule and Self-Hosted Wallets
A self-hosted wallet, sometimes called an unhosted wallet, is a wallet where the user controls the private keys rather than a third-party custodian holding the assets for the user.
Examples can include:
- Hardware wallets
- Mobile wallets
- Desktop wallets
- Browser wallets
- Other non-custodial wallet software
The wallet itself is not automatically a VASP simply because it can hold or transfer crypto.
This distinction is extremely important.
The FATF framework focuses on covered service providers and activities.
A person controlling their own wallet is not automatically a VASP merely because they own or use crypto.
However, transactions between VASPs and self-hosted wallets can still create AML/CFT risk, so regulated businesses may apply appropriate risk-based controls.
Are Self-Hosted Wallets Illegal?
No.
FATF standards do not simply say that people cannot own self-hosted wallets.
A self-hosted wallet is fundamentally a technology for controlling private keys.
The regulatory issue usually concerns the financial activity surrounding the wallet, rather than merely the existence of the wallet.
For example:
A person holding Bitcoin in a hardware wallet is one situation.
A business facilitating large-scale transfers between customers and external wallets is another.
A regulated exchange may therefore ask for additional information when a customer sends or receives assets involving external wallets, depending on local requirements and risk.
What Are P2P Crypto Transactions?
P2P means Peer-to-Peer.
A P2P crypto transaction occurs directly between users without necessarily using a traditional centralised exchange as the intermediary.
For example:
Alice β Bitcoin β Bob
The transaction may take place directly between their wallets.
P2P activity is important because it can reduce the number of regulated intermediaries that observe the transaction.
That does not automatically make P2P crypto illegal or suspicious.
But it can create additional AML/CFT challenges.
FATF has specifically identified P2P transactions involving unhosted wallets as an area requiring continued risk monitoring.
Why P2P Transactions Create Regulatory Challenges
A traditional exchange can generally identify its customer.
A direct wallet-to-wallet transaction may provide much less information about the real-world identity of the parties.
For regulators, this creates questions such as:
- Who owns the wallet?
- Where did the funds originate?
- Why is the transfer occurring?
- Is the wallet linked to criminal activity?
- Is the recipient sanctioned?
- Is the transaction part of a larger laundering pattern?
Blockchain analytics can help answer some of these questions, but blockchain addresses are not automatically equivalent to verified identities.
FATF and Stablecoins
Stablecoins have become an increasingly important part of the crypto financial system.
They are designed to maintain a relatively stable value, often through a reference to:
- A fiat currency
- A reserve of assets
- Other mechanisms
Stablecoins are used for:
- Trading
- Payments
- Remittances
- DeFi
- Settlement
- Transfers between exchanges
- Treasury management
Their liquidity and global accessibility can also make them attractive to illicit actors.
FATF’s recent work specifically highlights the misuse of stablecoins as an emerging financial crime risk.
Why Stablecoins Matter for AML Regulation
Stablecoins can move value quickly across borders.
A user may convert fiat into a stablecoin, move it between wallets, transfer it internationally and eventually convert it back into fiat.
That makes stablecoins particularly important from an AML perspective.
Regulators may therefore examine:
- Stablecoin issuers
- Reserve arrangements
- Redemption mechanisms
- Distribution channels
- Exchanges
- Wallet providers
- Transfer activity
- Blockchain monitoring
- Sanctions exposure
The regulatory treatment of stablecoins varies significantly between jurisdictions.
FATF and DeFi
DeFi means Decentralised Finance.
It refers to financial applications built primarily using blockchain-based smart contracts.
Examples include:
- Decentralised exchanges
- Lending protocols
- Borrowing protocols
- Derivatives protocols
- Liquidity protocols
- Yield protocols
DeFi creates one of the hardest questions for regulators:
Who is responsible when financial services are provided through software rather than a traditional company?
FATF’s approach does not simply mean:
“If something calls itself DeFi, it is outside regulation.”
Instead, FATF examines whether there are identifiable persons or entities that perform covered activities or retain sufficient control or influence over an arrangement.
This is why the legal structure and actual operation of a protocol matter.
Is Every DeFi Protocol a VASP?
No.
This is an area where oversimplification can create confusion.
A DeFi application is not automatically a VASP simply because it involves virtual assets.
Regulators and authorities may examine:
- Who developed the protocol
- Who controls or operates it
- Whether a person or entity provides services as a business
- Whether there is meaningful control or influence
- Whether transactions are automated
- Whether governance participants have relevant powers
- Whether there is a central operator
- Whether covered activities are being performed
Therefore, the phrase “decentralised” does not automatically determine the regulatory outcome.
The actual facts and applicable law matter.
DeFi and the Problem of Responsibility
Traditional finance normally has identifiable intermediaries.
For example:
Customer β Bank β Payment Network β Bank β Customer
DeFi can look more like:
User β Smart Contract β Blockchain
There may be no conventional bank in the middle.
This creates questions around:
- Customer identification
- Transaction monitoring
- Sanctions compliance
- Reporting obligations
- Licensing
- Jurisdiction
- Governance
- Enforcement
FATF has continued to monitor these issues rather than treating DeFi as a solved regulatory question.
FATF and Privacy-Enhancing Technologies
Privacy technologies can make blockchain transactions harder to trace.
Examples can include:
- Privacy-focused assets
- Mixers
- Tumblers
- Privacy-enhancing protocols
- Certain anonymity-enhancing technologies
These technologies can have legitimate privacy uses.
However, they can also create challenges for AML/CFT controls.
FATF guidance states that VASPs should be able to manage and mitigate risks associated with anonymity-enhancing technologies and mechanisms. Where a VASP cannot adequately manage those risks, FATF guidance indicates that the VASP should not engage in the relevant activities.
This is another example of the FATF’s risk-based philosophy.
The issue is not simply whether a technology exists.
The question is whether its risks can be properly managed.
Sanctions Compliance and Crypto
AML regulation is closely connected with sanctions compliance, although sanctions and AML are separate legal areas.
Crypto businesses may need to screen customers, counterparties and transactions against applicable sanctions requirements.
This can involve:
- Wallet screening
- Customer screening
- Entity screening
- Transaction monitoring
- Geographic risk analysis
- Blocking or restricting prohibited activity where legally required
A crypto transaction can therefore raise compliance concerns even when it does not look like traditional money laundering.
Beneficial Ownership
A major AML concept is beneficial ownership.
Suppose a company opens an account at a crypto exchange.
The exchange may need to understand not only the company’s registered name but also:
Who ultimately owns or controls the company?
This helps prevent criminals from hiding behind:
- Shell companies
- Nominee structures
- Complex ownership chains
- Offshore entities
For crypto businesses, beneficial ownership can become particularly important when dealing with institutional customers, funds, trading firms and other legal entities.
Record Keeping
AML/CFT compliance is not only about identifying customers.
Businesses also need to maintain appropriate records.
Records can include:
- Customer identification information
- Account information
- Transaction history
- Beneficial ownership information
- Risk assessments
- Compliance decisions
- Suspicious activity investigations
- Relevant Travel Rule information
The exact retention period depends on local law.
The purpose is to ensure that authorities can investigate financial activity when legally necessary.
Risk-Based Supervision
FATF expects countries to supervise VASPs using a risk-based approach.
This means regulators should consider the actual risks of the business rather than applying exactly the same level of supervision to every entity.
A large global exchange may present a different risk profile from a small regulated crypto business.
Supervisors may examine:
- AML programmes
- Governance
- Compliance staffing
- Customer due diligence
- Transaction monitoring
- Suspicious transaction reporting
- Travel Rule implementation
- Cybersecurity and operational controls
- Risk assessments
- Record keeping
FATF has identified weak supervision and enforcement as continuing challenges in some jurisdictions.
What Happens If a VASP Does Not Comply?
The consequences depend on national law.
Possible regulatory actions can include:
- Warnings
- Administrative penalties
- Monetary fines
- Restrictions
- Increased supervision
- License suspension
- License cancellation
- Criminal enforcement in serious cases
The FATF framework expects countries to have effective, proportionate and dissuasive sanctions for non-compliance.
FATF and Offshore Crypto Exchanges
One of the biggest challenges in crypto regulation is the existence of offshore businesses.
A crypto exchange may be incorporated in one jurisdiction while serving customers around the world.
This creates a regulatory gap when:
- The home jurisdiction has weak supervision.
- The exchange serves customers abroad.
- The customer’s country has stronger requirements.
- Regulators have limited access to information.
FATF’s 2026 update specifically highlights offshore VASPs operating outside effective regulatory and supervisory oversight as an ongoing concern.
This is why international cooperation is so important.
Why International Cooperation Matters
Crypto does not respect national borders.
Consider this simplified example:
Customer in India β Exchange in another country β Stablecoin β Wallet β DeFi protocol β Exchange in another jurisdiction
Several legal systems may potentially become relevant.
No single regulator can easily understand the entire transaction chain alone.
International cooperation can therefore involve:
- Information sharing
- Supervisory cooperation
- Financial intelligence cooperation
- Law enforcement cooperation
- Cross-border investigations
- Joint regulatory work
- Coordination between financial intelligence units
FATF standards are designed partly to reduce regulatory gaps between jurisdictions.
FATF’s “Global Baseline” Concept
FATF standards are often best understood as a global baseline.
They establish expectations that countries can implement through domestic law.
But countries can go beyond FATF requirements.
This means two countries can both follow FATF standards while having very different crypto regulatory systems.
One country might:
- Permit crypto broadly
- License exchanges
- Apply detailed AML rules
Another might:
- Restrict certain crypto activities
- Ban particular business models
- Permit only specific types of virtual-asset services
FATF compliance does not force every country to adopt an identical crypto market structure.
FATF Does Not Decide Whether Bitcoin Is “Good” or “Bad”
FATF is primarily concerned with financial crime risks.
It does not determine whether Bitcoin should become a national currency.
It does not set Bitcoin’s price.
It does not decide whether a country should permit crypto trading.
Its focus is on preventing financial systems from being exploited for illicit purposes.
This distinction is important because crypto regulation has several different dimensions:
AML/CFT regulation
Focuses on money laundering, terrorist financing and related financial crime.
Market regulation
Focuses on exchanges, trading, investor protection, market integrity and financial products.
Tax regulation
Focuses on taxation of crypto transactions and income.
Consumer protection
Focuses on fraud, disclosure, custody and investor protection.
Securities regulation
Determines whether particular digital assets or activities fall within securities laws.
FATF is primarily associated with the AML/CFT side of this regulatory framework.
How FATF Rules Affect Ordinary Crypto Users
You do not need to operate a crypto exchange to be affected by FATF-inspired regulation.
Ordinary users may notice the impact through:
- KYC requirements
- Identity verification
- Withdrawal checks
- Deposit screening
- Travel Rule questions
- Wallet verification
- Source-of-funds checks
- Transaction monitoring
- Account restrictions
- Additional checks for higher-risk activity
For many users, these are the most visible effects of global AML regulation.
Why Your Exchange May Ask About Your Wallet
Suppose you withdraw crypto from an exchange to your personal hardware wallet.
The exchange may ask for information about the destination wallet or may perform additional checks.
This does not necessarily mean that self-hosted wallets are illegal.
The exchange is trying to satisfy its own regulatory obligations and manage financial crime risk.
Similarly, when crypto is deposited from an external wallet, the exchange may analyse the transaction before making the funds available.
The precise process varies between platforms and jurisdictions.
Travel Rule vs Blockchain Transparency
These are two different concepts.
Blockchain transparency means transactions can often be viewed on a public blockchain.
Travel Rule compliance means regulated entities exchange required identifying information associated with certain transfers.
A blockchain may show:
Wallet A β Wallet B β 2 BTC
But that transaction alone may not tell you:
- Who owns Wallet A
- Who owns Wallet B
- Why the transaction happened
- Whether either party is a customer of a regulated institution
The Travel Rule attempts to add the required customer information layer when regulated entities are involved.
The 2026 FATF Picture
FATF’s latest targeted update gives an important picture of where global implementation stands.
According to the July 2026 update, 83% of surveyed jurisdictions had passed legislation implementing the Travel Rule, compared with 73% in 2025. FATF also reported that another 11 jurisdictions said implementation was underway.
This shows significant progress.
But progress does not mean the global system is complete.
FATF continues to identify gaps involving:
- Effective licensing and registration
- Risk assessments
- Identification of unregistered VASPs
- Supervision
- Enforcement
- Travel Rule implementation
- Offshore VASPs
- Stablecoins
- P2P transactions
- Unhosted wallets
- DeFi
- Fraud
The direction is therefore clear:
Global crypto regulation is moving from basic rule-making toward implementation, supervision and enforcement.
The Biggest FATF Challenges for the Crypto Industry
The crypto industry faces several major challenges as FATF standards become more widely implemented.
Challenge 1: Global Regulatory Fragmentation
Different countries implement FATF standards differently.
A company operating internationally may therefore need to manage several regulatory regimes simultaneously.
Challenge 2: Travel Rule Interoperability
Different Travel Rule providers and systems must communicate reliably.
This creates technical and operational challenges.
Challenge 3: Self-Hosted Wallets
Regulated businesses must manage risk involving external wallets without automatically treating every self-hosted wallet as suspicious.
Challenge 4: DeFi
Regulators must determine where responsibility exists in systems that use smart contracts and decentralised governance.
Challenge 5: Stablecoins
Stablecoins can transfer value quickly across borders and have become increasingly important to both legitimate and illicit financial activity.
Challenge 6: Offshore VASPs
A business operating from a weakly supervised jurisdiction can create regulatory gaps.
Challenge 7: Fraud
Crypto-enabled fraud has become a major concern, including large-scale organised fraud networks.
FATF’s 2026 update specifically identifies the increasing industrialisation of virtual-asset-enabled fraud as an emerging risk.
What Crypto Exchanges Need to Build
A serious crypto exchange operating under an AML/CFT framework may need an integrated compliance system covering:
Customer Layer
- KYC
- Customer risk scoring
- Beneficial ownership
- Enhanced due diligence
Transaction Layer
- Transaction monitoring
- Blockchain analytics
- Wallet screening
- Sanctions screening
- Behavioural analysis
Reporting Layer
- Suspicious transaction reporting
- Regulatory reporting
- Record keeping
Transfer Layer
- Travel Rule compliance
- Originator information
- Beneficiary information
- Counterparty VASP checks
Governance Layer
- Compliance policies
- Risk assessments
- Internal controls
- Employee training
- Independent testing
- Regulatory cooperation
This is why modern crypto compliance is much more than simply asking customers to upload an identity document.
What Crypto Businesses Should Understand About FATF
A crypto business should think about FATF compliance as a complete risk-management system.
A strong framework should answer:
Who are our customers?
What services do we provide?
Which jurisdictions do we operate in?
What are our highest financial crime risks?
How do we identify suspicious transactions?
How do we handle external wallets?
How do we comply with the Travel Rule?
How do we screen sanctions exposure?
How do we report suspicious activity?
How do we respond to regulators?
How do we prove that our controls actually work?
This last question is particularly important.
Having a written AML policy is not enough.
A regulator may want evidence that the business actually follows the policy.
FATF Compliance Is Not Just a Technology Problem
Blockchain analytics can be extremely useful.
But technology alone cannot create a complete AML programme.
A serious compliance system also requires:
- People
- Policies
- Governance
- Legal analysis
- Risk assessments
- Training
- Monitoring
- Escalation procedures
- Reporting
- Regulatory cooperation
Technology can identify patterns.
Compliance teams must interpret those patterns and make decisions within the applicable legal framework.
FATF’s Risk-Based Approach in Simple Words
The easiest way to understand FATF’s philosophy is:
Higher risk β stronger controls.
Lower risk β proportionate controls.
For example:
A normal customer making ordinary transactions may require standard due diligence.
A customer connected to complex offshore structures and unusual high-value transfers may require enhanced due diligence.
Similarly:
A normal blockchain transaction may not be treated the same way as a transaction involving multiple high-risk indicators.
The goal is not to eliminate all risk.
The goal is to identify, understand and reduce unacceptable risk.
What FATF Means for the Future of Crypto
FATF’s influence suggests that the future crypto market will increasingly be built around regulated access points.
The blockchain itself may remain decentralised.
But the businesses connecting crypto to the traditional financial system are increasingly likely to face formal compliance obligations.
This can create a structure that looks something like:
Traditional Finance
β
Regulated Crypto Gateway
β
KYC / AML / Travel Rule
β
Blockchain Network
β
Wallets / DeFi / Digital Assets
The result may not be a completely regulated blockchain.
Instead, regulation may concentrate heavily around the points where people and businesses interact with the financial system.
Will FATF Eliminate Crypto Privacy?
Probably not.
The more realistic outcome is that privacy and compliance will continue to exist in tension.
Users want:
- Financial privacy
- Personal security
- Self-custody
- Permissionless transactions
Regulators want:
- Traceability
- Identity verification
- Sanctions compliance
- Financial crime prevention
The challenge for the industry is finding technologies and regulatory frameworks that can support legitimate privacy while reducing serious financial crime risks.
FATF and the Global Crypto Regulatory Direction
The global direction can now be understood through several major themes:
1. Regulated VASPs
Crypto businesses providing covered services are increasingly expected to become identifiable, licensed or registered and supervised.
2. Stronger AML Controls
KYC, customer due diligence, transaction monitoring and suspicious transaction reporting are becoming core parts of regulated crypto operations.
3. Travel Rule Expansion
More jurisdictions are implementing Travel Rule requirements.
4. Greater Scrutiny of Stablecoins
Stablecoins are receiving increased attention because of their growing role in global crypto transfers.
5. P2P and Self-Hosted Wallet Monitoring
Regulators are increasingly examining risks at the boundary between regulated businesses and non-custodial wallets.
6. DeFi Regulation Questions
Regulators are continuing to examine who has sufficient control or influence over decentralised arrangements and whether covered services are being provided.
7. Stronger Enforcement
The focus is increasingly moving from simply writing laws to ensuring that businesses actually comply with them.
FATF Crypto Regulation: A Simple Framework
You can remember the entire FATF crypto framework through this model:
IDENTIFY
Know the customer and beneficial owner.
β
ASSESS
Understand the financial crime risk.
β
VERIFY
Perform appropriate KYC and customer due diligence.
β
MONITOR
Monitor transactions and behaviour.
β
SCREEN
Check sanctions and relevant risk indicators.
β
TRANSMIT
Apply the Travel Rule where required.
β
REPORT
Report suspicious activity where legally required.
β
SUPERVISE
Regulators monitor VASPs.
β
ENFORCE
Non-compliance can result in sanctions.
This is the basic compliance architecture behind much of modern crypto AML regulation.
FATF vs National Crypto Regulation
It is important not to confuse these two layers.
FATF
Creates international AML/CFT standards.
National Government
Creates domestic laws.
Financial Regulator
Supervises regulated businesses.
Financial Intelligence Unit
Receives and analyses financial intelligence and suspicious transaction reports, depending on the country’s structure.
Crypto Business
Implements compliance controls.
Crypto User
Experiences requirements such as KYC, transaction monitoring and potentially Travel Rule-related checks.
This creates a chain from international standards to everyday crypto transactions.
What Investors Should Know
For ordinary crypto investors, FATF regulation may sound distant.
In reality, it can affect everyday access to crypto.
You may encounter:
- More detailed KYC
- Withdrawal restrictions
- Questions about external wallets
- Additional checks for large transactions
- Source-of-funds questions
- Delays caused by compliance reviews
- Limits involving certain jurisdictions
- Restrictions involving high-risk counterparties
These controls are not necessarily signs that crypto is becoming illegal.
In many cases, they are signs that crypto is becoming integrated into the regulated financial system.
What Businesses Should Do Now
Crypto businesses should not wait for a regulator to identify their weaknesses.
A strong compliance programme should begin with a detailed risk assessment.
Businesses should identify:
- Customers
- Products
- Services
- Jurisdictions
- Transaction types
- Wallet exposure
- Counterparty risks
- Stablecoin exposure
- DeFi exposure
- P2P exposure
- Sanctions exposure
- Fraud risks
They should then build controls around those risks.
The exact requirements should always be determined with reference to the applicable country’s laws and, where necessary, qualified legal and compliance professionals.
FATF Crypto Regulation Checklist
For a quick review, ask these questions:
For Crypto Users
- Is my exchange properly regulated where I live?
- Does the platform require KYC?
- Can I withdraw to a self-hosted wallet?
- Could additional checks apply to external-wallet transactions?
- Should I keep records showing the source of my crypto?
- Do I understand the tax and regulatory rules in my country?
For Crypto Businesses
- Are we required to register or obtain a license?
- Have we completed a VA/VASP risk assessment?
- Do we have a written AML/CFT programme?
- Do we conduct appropriate CDD?
- Do we identify beneficial owners?
- Do we monitor transactions?
- Do we screen sanctions?
- Can we detect suspicious behaviour?
- Can we submit required reports?
- Do we comply with applicable Travel Rule requirements?
- Do we monitor external-wallet exposure?
- Do we understand our DeFi and stablecoin risks?
- Are our records complete?
- Can we demonstrate compliance to a regulator?
The Most Important Takeaway
FATF is one of the most important forces shaping the global AML/CFT architecture for crypto.
Recommendation 15 brought virtual assets and VASPs into the FATF framework.
The resulting regulatory model focuses on:
Risk assessment β VASP licensing/registration β KYC/CDD β Transaction monitoring β Suspicious transaction reporting β Record keeping β Travel Rule β Supervision β Enforcement
At the same time, crypto continues to create new regulatory questions.
Stablecoins are growing.
DeFi is evolving.
P2P markets remain active.
Self-hosted wallets remain an important part of crypto ownership.
Offshore businesses continue to operate across borders.
And fraud networks are becoming more sophisticated.
FATF’s July 2026 update makes one thing particularly clear: global crypto AML regulation is moving beyond simply creating rules. The next stage is effective implementation, supervision and enforcement.
For the crypto industry, this means compliance is increasingly becoming part of the infrastructure itself.
For investors, it means understanding KYC, AML, Travel Rule requirements and wallet controls is becoming just as important as understanding blockchain technology.
And for regulators, the challenge is to protect the financial system without unnecessarily blocking legitimate innovation, privacy, financial inclusion and technological development.
The future of crypto regulation will therefore not be determined by one rule or one regulator.
It will be shaped by the interaction between international standards, national laws, financial regulators, crypto businesses, blockchain technology and the users themselves.
Final Word
Crypto regulation is often presented as a battle between innovation and regulation.
The reality is more complicated.
A mature crypto ecosystem needs both.
Innovation creates new financial infrastructure. Regulation attempts to prevent that infrastructure from becoming a tool for fraud, money laundering, terrorist financing and other financial crime.
FATF sits at an important point in that global system.
Its standards do not create one worldwide crypto law. Instead, they influence how countries build the AML/CFT foundations around crypto.
As Travel Rule implementation expands, VASPs become more regulated, stablecoins grow, DeFi evolves and self-hosted wallets remain popular, the boundary between traditional finance and crypto will continue to change.
The key lesson for every crypto participant is simple:
Understanding crypto regulation is no longer optional. It is becoming part of understanding crypto itself.
Official FATF Resources and Further Reading
For readers who want to go deeper, the following official FATF resources are the best starting points:
- FATF β Virtual Assets β Official overview of FATF’s work on virtual assets and VASPs.
- FATF β Seventh Targeted Update on Implementation of the FATF Standards on Virtual Assets/VASPs (2026) β The latest major FATF implementation update, published July 16, 2026.
- FATF β FATF calls for closing regulatory gaps as virtual asset illicit finance risks become more complex β Summary of the 2026 update and current implementation challenges.
- FATF β Updated Guidance for a Risk-Based Approach to Virtual Assets and VASPs β Detailed guidance covering risk-based AML/CFT implementation.
- FATF β Virtual Assets and FATF Standards β FATF’s explanation of how its standards apply to virtual assets and VASPs.
- FATF β Best Practices: Travel Rule Supervision β Detailed material on implementation and supervision of the Travel Rule.
- FATF β 2025 Targeted Update on Virtual Assets and VASPs β Previous annual update for comparing the development of global implementation.
- FATF β 2024 Targeted Update on Virtual Assets and VASPs β Earlier implementation assessment covering DeFi, stablecoins, P2P and unhosted-wallet risks.