us

216.73.216.122

Back
News

FATF Finds Travel Rule Enforcement Lagging in 2026 VASP Update

FATF Finds Travel Rule Enforcement Lagging in 2026 VASP Update
Richard M. AUGUST 13, 2026 1 minute read

Most jurisdictions have now written the crypto Travel Rule into law but almost none are policing it, according to the Financial Action Task Force’s seventh targeted update on virtual assets, published in July 2026. Of the 91 jurisdictions that have passed Travel Rule legislation, 55 have never issued a finding or directive or taken any supervisory or enforcement action against a virtual asset service provider for non compliance. 

The report draws on a 2026 survey of 147 jurisdictions (38 FATF members and 109 members of FATF-Style Regional Bodies), 149 published mutual evaluation and follow-up reports assessing Recommendation 15, and two meetings of the FATF Virtual Assets Contact Group. The FATF treats the 58 jurisdictions that did not respond as having made no progress on R.15. On paper the numbers improved: 86% of respondents (124 of 145) reported completing a VA/VASP risk assessment, up from 76% in 2025, and Travel Rule legislation rose to 83% of respondents from 73%. Technical compliance moved more slowly. Just 34% of assessed jurisdictions (51 of 149) are rated largely compliant with R.15, and only one jurisdiction in the entire Global Network is fully compliant. 

Licensing tells a similar story. While 73% of relevant respondents (95 of 130) require VASPs to be licensed or registered, only 58% (76 of 130) have actually licensed or registered one, down from 65% a year earlier, and FATF assessments find that only 40% of assessed jurisdictions (59 of 149) satisfactorily meet the licensing criterion. Prohibition is meanwhile becoming the default in some regions: 23% of respondents now prohibit VASPs fully or partially, up from 11% in 2023, with MENAFATF members most heavily represented. The FATF warns that a prohibition is only as good as its enforcement, noting that 16 of the 21 jurisdictions with explicit bans reported acting against VASPs operating illegally. 

The supervisory shortfall sits against a threat picture the FATF describes as increasingly industrialised. Competent authorities cited in the report found that a single Cambodia based financial services conglomerate laundered at least USD 4 billion between August 2021 and January 2025, of which at least USD 37 million is attributed to DPRK cyber theft supporting weapons and ballistic missile programmes. After a third-party issuer froze more than USD 29 million linked to the group, it launched its own USD-pegged stablecoin marketed as immune to asset freezing and issued across multiple chains, a case the FATF presents as evidence that obligated entities cannot assume issuer-level freeze capability exists. In Spain, Operation Borrelli dismantled a network in June 2025 that allegedly laundered roughly EUR 460 million from more than 5,000 victims, according to Europol

Decentralised finance and offshore platforms remain the weakest links. Only 18% of responding jurisdictions (26 of 142) have assessed DeFi risks, four have imposed licensing requirements on qualifying arrangements, two have licensed one in practice and a single jurisdiction has taken enforcement action. Offshore VASPs are being detected soliciting customers in markets where they hold no licence, coaching users toward VPNs and false information, and opening accounts at licensed onshore firms while misrepresenting themselves as retail users to obtain liquidity and fiat on- and off-ramps. Peer-to-peer activity is recognised as high risk by 88% of jurisdictions that rated it, yet only 23% (31 of 133) collect market metrics on unhosted wallet flows at all.

That combination leaves regulated firms carrying risk their supervisors have not measured. When a licensed exchange or bank onboards what looks like a retail client but is in fact an unlicensed offshore platform, or processes stablecoin flows that settle across borders in seconds with no obligated entity on the other side, the control has to sit inside the institution. The FATF’s private-sector recommendations reflect that, calling for enhanced due diligence on offshore counterparties, stronger monitoring of unhosted wallet activity, blockchain analytics to detect rapid layering, and freezing and blocking capabilities that can be updated as typologies shift.

Meeting that standard requires verification and monitoring built for cross-border virtual asset flows rather than retrofitted from traditional banking. Shufti’s AML screening checks customers and counterparties against global sanctions, PEP and adverse media data across 240+ countries and territories, while its transaction screening and KYC capabilities support the ongoing monitoring and originator and beneficiary checks the Travel Rule demands. Exchanges and financial institutions reassessing their virtual asset controls against the 2026 findings can request a demo to review the platform.

Disclaimer: The views and opinions expressed on this webpage or weblink are those of the author only, and are not necessarily the views or opinions of Shufti Pro Limited. The material and information on this weblink is solely for general information purposes. You should not rely upon the material or information on the website as a basis for making any business or legal decision.

While we endeavor to keep the information up-to-date and/or correct, we make no representations or warranties of any kind, express or implied, or for any purpose about the completeness, accuracy, reliability, suitability, or availability of the contents or information herein. Any reliance on its content is thus entirely at your own risk.

For the avoidance of doubt, Shufti Pro Limited will not be liable for any false, inaccurate, inappropriate, or incomplete information presented herein, and all liabilities with respect to actions taken, or not taken, based on the contents or information herein, or for any loss sustained by you as a consequence are hereby expressly disclaimed by us.

Share you link

Bring your voice

Bring Your Voice.

The community for every hand that writes and every voice that speaks against fraud.

Join Community

Pitch a piece and get a verified byline in the Media room.

“Industry Partnerships That Create Real Value”

Join Shufti’s partnership network to expand your connections, collaborate with industry leaders, and unlock new opportunities.

Pitch a piece and get a verified byline in the Media room.

Partnership Inquiries?
Email us at [email protected]

iBeta Level 1 — ISO 30107-3 Compliant iBeta Level 2 — ISO 30107-3 Compliant iBeta Level 3 — ISO 30107-3 Compliant PCI DSS SOC 2 Type 2 GDPR GDPR Fundamentals — Quality Guild ISO 27001:2022 KJM Age Verification CCPA / CPRA Cyber Essentials Cyber Essentials Plus
Copyright © 2026 Shufti. All rights reserved.