Most jurisdictions have now written the crypto Travel Rule into law but almost none are policing it, according to the Financial Action Task Force’s seventh targeted update on virtual assets, published in July 2026. Of the 91 jurisdictions that have passed Travel Rule legislation, 55 have never issued a finding or directive or taken any supervisory or enforcement action against a virtual asset service provider for non compliance.
The report draws on a 2026 survey of 147 jurisdictions (38 FATF members and 109 members of FATF-Style Regional Bodies), 149 published mutual evaluation and follow-up reports assessing Recommendation 15, and two meetings of the FATF Virtual Assets Contact Group. The FATF treats the 58 jurisdictions that did not respond as having made no progress on R.15. On paper the numbers improved: 86% of respondents (124 of 145) reported completing a VA/VASP risk assessment, up from 76% in 2025, and Travel Rule legislation rose to 83% of respondents from 73%. Technical compliance moved more slowly. Just 34% of assessed jurisdictions (51 of 149) are rated largely compliant with R.15, and only one jurisdiction in the entire Global Network is fully compliant.
Licensing tells a similar story. While 73% of relevant respondents (95 of 130) require VASPs to be licensed or registered, only 58% (76 of 130) have actually licensed or registered one, down from 65% a year earlier, and FATF assessments find that only 40% of assessed jurisdictions (59 of 149) satisfactorily meet the licensing criterion. Prohibition is meanwhile becoming the default in some regions: 23% of respondents now prohibit VASPs fully or partially, up from 11% in 2023, with MENAFATF members most heavily represented. The FATF warns that a prohibition is only as good as its enforcement, noting that 16 of the 21 jurisdictions with explicit bans reported acting against VASPs operating illegally.
The supervisory shortfall sits against a threat picture the FATF describes as increasingly industrialised. Competent authorities cited in the report found that a single Cambodia based financial services conglomerate laundered at least USD 4 billion between August 2021 and January 2025, of which at least USD 37 million is attributed to DPRK cyber theft supporting weapons and ballistic missile programmes. After a third-party issuer froze more than USD 29 million linked to the group, it launched its own USD-pegged stablecoin marketed as immune to asset freezing and issued across multiple chains, a case the FATF presents as evidence that obligated entities cannot assume issuer-level freeze capability exists. In Spain, Operation Borrelli dismantled a network in June 2025 that allegedly laundered roughly EUR 460 million from more than 5,000 victims, according to Europol.
Decentralised finance and offshore platforms remain the weakest links. Only 18% of responding jurisdictions (26 of 142) have assessed DeFi risks, four have imposed licensing requirements on qualifying arrangements, two have licensed one in practice and a single jurisdiction has taken enforcement action. Offshore VASPs are being detected soliciting customers in markets where they hold no licence, coaching users toward VPNs and false information, and opening accounts at licensed onshore firms while misrepresenting themselves as retail users to obtain liquidity and fiat on- and off-ramps. Peer-to-peer activity is recognised as high risk by 88% of jurisdictions that rated it, yet only 23% (31 of 133) collect market metrics on unhosted wallet flows at all.
That combination leaves regulated firms carrying risk their supervisors have not measured. When a licensed exchange or bank onboards what looks like a retail client but is in fact an unlicensed offshore platform, or processes stablecoin flows that settle across borders in seconds with no obligated entity on the other side, the control has to sit inside the institution. The FATF’s private-sector recommendations reflect that, calling for enhanced due diligence on offshore counterparties, stronger monitoring of unhosted wallet activity, blockchain analytics to detect rapid layering, and freezing and blocking capabilities that can be updated as typologies shift.
Meeting that standard requires verification and monitoring built for cross-border virtual asset flows rather than retrofitted from traditional banking. Shufti’s AML screening checks customers and counterparties against global sanctions, PEP and adverse media data across 240+ countries and territories, while its transaction screening and KYC capabilities support the ongoing monitoring and originator and beneficiary checks the Travel Rule demands. Exchanges and financial institutions reassessing their virtual asset controls against the 2026 findings can request a demo to review the platform.













