From rules to results: FATF's seventh targeted update on virtual assets and VASPs
An analysis of how FATF's seventh targeted update on virtual assets and VASPs exposes the gap between licensing frameworks and counterparty visibility for compliance teams.
Introduction
Introduction
Most jurisdictions now have rules for virtual-asset service providers (VASPs). Fewer can say who is actually operating within them.
On 16 July 2026, the Financial Action Task Force (FATF) published its Seventh Targeted Update on Implementation of the FATF Standards on Virtual Assets/VASPs. More jurisdictions have assessed virtual-asset risks, established regulatory approaches, introduced licensing regimes and enacted the Travel Rule since the last update. Yet the report's recurring distinction is between having a framework and making it work.[1]
The distinction comes down to visibility: who is providing virtual-asset services, which legal entity is involved, where it is regulated, where it actually operates, and what its regulatory position means for a given market, relationship or transaction.
FATF's findings point to five connected conclusions for VASPs, banks and public authorities. This matters as much for banks and other financial institutions as for VASPs themselves: exposure to digital-asset businesses, offshore platforms, OTC brokers and fiat on- and off-ramp infrastructure can sit embedded within apparently conventional customer relationships.[2]
1. Rules on paper do not guarantee effective supervision
As of April 2026, 149 jurisdictions had been assessed for technical compliance with Recommendation 15. Only one remained fully compliant. The proportion rated largely compliant increased from 29% in 2025 to 34% in 2026, while 43% were partially compliant and 22% non-compliant.[3]
Figure 1. Assessment results: compliance with R.15, 2023–2026 Source: FATF (2026), Targeted Update on Implementation of the FATF Standards on Virtual Assets/VASPs, Figure 1.1. Illustrated by VASPnet.
Those figures show modest progress but must be read carefully. FATF's implementation survey is based on self-reported responses that were not independently verified. Recommendation 15 ratings come from mutual evaluations and follow-up reports conducted at different times, so some may not capture recent reforms. A new self-reported framework and an older weak rating can therefore appear alongside one another without either describing the current position in full.[4]
The same distinction appears in jurisdictions' risk assessments. Eighty-six percent of respondents reported having assessed money-laundering, terrorist-financing and proliferation-financing risks involving virtual assets and VASPs. Yet only 48 of 149 assessed jurisdictions met or mostly met FATF's criteria for applying preventive or mitigating measures in line with the risks identified.[5]
The harder step is turning a risk assessment into supervisory resourcing, inspection priorities, perimeter enforcement and mitigation. The data above shows most jurisdictions have not yet taken it.
Licensing data follows the same pattern: 73% of relevant respondents reported requiring VASPs to be licensed or registered, but only 58% reported having licensed or registered a VASP in practice. FATF notes that some jurisdictions have requirements without an operational licensing framework, while only 40% of assessed jurisdictions satisfactorily met its licensing or registration criterion.[6]
“…several jurisdictions do not yet have operational licensing or registration frameworks.” – FATF (2026), para. 18
For compliance purposes, three dimensions must remain separate, since a licence flag alone cannot answer any of them:
Regime status: what the law requires
Implementation: whether the regime is in effect and has established a regulated population
Effectiveness: whether the sector is actively supervised, and whether breaches or unlicensed activity are identified and addressed
2. You cannot enforce a regulatory perimeter that you cannot see
One of FATF's most fundamental findings is that jurisdictions continue to struggle to identify the natural and legal persons conducting VASP activities. [7]
Identification sits beneath almost every regulatory objective. A supervisor cannot licence, inspect or sanction an entity it cannot find. A regulated firm cannot apply meaningful counterparty due diligence until it has connected a brand, platform or service to the correct legal entity.
FATF's methodology recognises this in Recommendation 15.5, which examines whether jurisdictions identify people or entities conducting VASP activities without the required licence or registration. In the 2026 assessment data, only 26% of jurisdictions met this criterion, while 36% did not meet it. [8]
Figure 2. Compliance with individual R.15 criteria. Source: FATF (2026), Targeted Update on Implementation of the FATF Standards on Virtual Assets/VASPs, Table 1.2; Figure 1.3. Illustrated by VASPnet.
VASPnet's own tracking of unauthorised-VASP registers shows the same gap from a different angle. Across the wider set of jurisdictions VASPnet tracks, the proportion publishing a dedicated warnings and actions list that clearly identifies unauthorised crypto-asset activity rose from 25% in 2024 (25 of 99 countries) to 28% in 2026 (37 of 131 countries). Even so, 46% published no warnings or actions at all in 2026, down only slightly from 54% in 2024.
Figure 3. Change in public availability of unauthorised VASP warning and enforcement data, 2024–2026. 2024 data covers 99 countries; 2026 data covers 131 countries. Source: VASPnet, VASPdata, April 2026.
Figure 4. Availability of unauthorised register data in countries with a virtual-asset regime in place, April 2026. Source: VASPnet, VASPdata.
Reading figures 1-4 together, the two data sets point to the same conclusion from different directions. FATF's assessors find that most jurisdictions cannot demonstrate they identify unauthorised operators. VASPnet's own register tracking finds that, independent of any assessment, most jurisdictions do not publish the data that would let a bank or VASP identify those operators either.
This is why regulatory registers of licensed or registered firms, while essential, do not necessarily provide a complete view of a market. They show the population known to and authorised by a regulator. They may not reveal:
firms operating without the required authorisation;
firms serving a jurisdiction from offshore jurisdictions;
activities conducted through related entities within a wider trading group;
businesses whose actual activities, as opposed to their stated activities, may bring them within the VASP definition;
entities that were formerly regulated, warned against or prohibited; or
institutional activity concealed inside apparently retail relationships with other VASPs.
The challenge also applies in markets prohibiting VASPs. The proportion of respondents reporting a prohibition approach has more than doubled, from 11% in 2023 to 23% in 2026. FATF permits prohibition as a policy choice but warns that it may be difficult to implement unless authorities proactively identify prohibited activity and take supervisory or enforcement action. [9]
“An increase in the use of prohibitions may therefore raise concerns in the future if jurisdictions are not able to enforce them effectively.” - FATF (2026), para. 12
Sixteen of the 21 jurisdictions explicitly prohibiting VAs and VASPs reported action against illegal operators, up from nine of 17 in 2025. FATF nevertheless describes implementation as uneven.[10]
Prohibition does not mean an empty market. If services remain accessible, activity has likely moved outside the regulated perimeter, and the operational task is the same: identifying which entities appear to be serving that jurisdiction.
The criminal cases in the report underline the importance of connecting identity, activity and regulatory position. Operation Borrelli involved an alleged crypto-investment fraud network using a Hong Kong corporate and banking structure, payment gateways and exchange accounts to launder approximately EUR 460 million.[11] Better entity and activity identification could have strengthened the ability of financial institutions to assess the relationships and escalate inconsistencies earlier, although it should not be presented as a control that would necessarily have prevented the scheme. The underlying point holds regardless: a VASP that cannot be identified cannot be regulated, supervised or risk-managed.
3. A licence somewhere doesn't mean permission everywhere
Offshore VASPs (oVASPs) feature prominently in the update. FATF describes the risks created when businesses operate across multiple markets from jurisdictions with weak or underdeveloped supervisory frameworks, solicit customers where they are unlicensed, or exploit differences in customer due diligence and Travel Rule requirements.[12]
Of the 114 responding jurisdictions with VASP licensing or registration requirements, 44% (50 of 114) require licensing only when a VASP is created or located in their own jurisdiction. Just 39 (34%) extended that requirement to certain offshore VASPs.[13] A growing group of jurisdictions use activity-based regulatory anchors instead, such as targeted marketing, onboarding residents or use of domestic payment rails.[14]
This changes the compliance question. “Where is the firm incorporated or licensed?” remains important, but it must now also be followed by: “Where does the firm appear to offer services, and what permissions or restrictions may apply to that activity?”
A useful assessment must distinguish among:
place of incorporation;
home and additional regulatory permissions;
the wider corporate or trading group;
apparent operating footprint; and
the activities and customers covered by each relevant regime.
FATF also highlights nested arrangements in which offshore VASPs access trading, liquidity or fiat infrastructure through accounts at licensed institutions. Some have misrepresented themselves as retail users while processing activity far beyond an expected retail profile.[15]
“While nested activity can be legitimate, oVASPs have been observed deliberately misrepresenting themselves as retail users when opening such accounts, and processing illicit transactions significantly exceeding typical retail volumes while accounting for only a marginal share of total host VASP activity.” - FATF (2026), para. 41.
Detecting this requires more than a register search or an on-chain risk score. Relevant information can include legal entities, trading groups, licences, expected customer behaviour, payment rails, bank accounts and evidence of where services are marketed or provided.
FATF recommends enhanced due diligence on offshore VASPs, detecting accounts used by offshore VASPs that misrepresent themselves as retail users, restricting or exiting higher-risk relationships and monitoring fiat flows connected to unlicensed or weakly supervised platforms. [16]
4. The Travel Rule's next challenge is operational
Travel Rule legislation has continued to be adopted. Of the 109 jurisdictions eligible for the relevant survey questions, 91 (83%) reported having enacted the Travel Rule, compared with 73% in 2025. A further 11 were in the process of doing so.[17] FATF's mutual evaluations put the number lower: on R15.9, the criterion covering preventive measures including the Travel Rule, only 29% of jurisdictions met or mostly met the standard, 30% did not meet it, and 34% only partly met it. [18]
The original “sunrise problem” arose when obliged firms had to transact with counterparties in jurisdictions where equivalent requirements did not yet exist. This legislative gap is narrowing among survey respondents, but an operational gap remains.
Of the 91 jurisdictions reporting legislation in force, 55 (60%) had not issued findings or directives or taken Travel Rule-focused supervisory or enforcement action. FATF acknowledges that some frameworks are recent, but describes persistent implementation gaps as a serious concern.[19]
“The persistent gaps in Travel Rule implementation remain a serious concern.” - FATF (2026), para. 26
Legislation alone does not demonstrate that a counterparty is ready, reachable or compliant. Before exchanging sensitive originator and beneficiary information, a VASP may need to establish:
Counterparty status: whether the entity is a VASP or another obliged institution, and which legal entity operates the service.
Regulatory standing: where that entity is regulated, and whether it appears permitted to provide the relevant service.
Operational readiness: whether it can exchange the required information securely.
Relationship risk: what risk the relationship presents.
Messaging standards and Travel Rule solutions enable information exchange.
Messaging standards and Travel Rule solutions enable information exchange. Counterparty VASP due diligence (CVDD) helps determine who is on the other side and how the relationship should be treated.
CVDD operates as connective tissue across the report. Enhanced due diligence on offshore VASPs, identifying weakly supervised platforms, detecting nested relationships and restricting dealings with unlicensed operators all depend on reliable counterparty identification.
The next phase of Travel Rule effectiveness is about more than transmitting data: it is about knowing and assessing the institution receiving it.
5. Effective counterparty intelligence requires more than one data source
FATF encourages jurisdictions to rely on a broad range of credible resources when assessing virtual-asset and VASP risks.[20] The report itself demonstrates why.
FATF's own guidance underscores the point: identification of a counterparty VASP must be undertaken 'completely and accurately'. That standard cannot be met from a single source; it requires combining complementary forms of intelligence rather than relying on one.
Blockchain analytics can detect transaction patterns, trace flows and assess wallet exposure. Counterparty reference intelligence addresses identity, legal structure, regulatory standing and operating footprint. Neither replaces the other.
The report also shows how criminal networks exploit common infrastructure and adapt when controls become effective. Organised fraud, cyber theft, sanctions evasion, terrorist financing and proliferation financing converge around shared infrastructure: offshore intermediaries, global exchanges, OTC brokers, stablecoins, unhosted wallets, bridges and DeFi arrangements.[21]
In one example, after a third-party issuer froze assets connected to an alleged laundering network, the group issued its own dollar-pegged token marketed as resistant to freezing. FATF concludes that obliged entities cannot rely on issuer-level freeze or burn mechanisms as a universal safeguard. [22]
“A particularly notable development in the misuse of virtual assets within VA-enabled fraud ecosystems is the deliberate issuance of proprietary stablecoins specifically designed to circumvent law enforcement intervention.” - FATF (2026), para. 35.
FATF's own recommendation to VASPs reflects this: AML/CFT controls, including KYC, wallet screening, blacklisting and whitelisting, should be capable of being updated quickly as new typologies emerge, rather than relying on any single freeze or block mechanism. [23]
The wider lesson is that no single control or dataset provides a complete picture. Effective assessments should bring together entity identity, regulatory information, operating-footprint evidence, transaction intelligence and an institution's own risk appetite.
For compliance teams, this can be distilled into three dimensions:
Identity: the VASP, its relevant legal entities and trading group.
Footprint: where it operates and what permissions may apply, set against its apparent cross-border activity.
Risk: supervisory context, transaction exposure and the institution's own risk-based controls.
The same three dimensions apply beyond VASPs; banks and other financial institutions face the same exposure, often embedded within apparently conventional customer relationships.
This is the role VASPnet is working to support: helping compliance teams connect VASP identity, legal entities, regulatory information and cross-border activity so they can make better-informed counterparty assessments.
Most jurisdictions now have rules in place. The remaining gap, on this data, is visibility and operational effectiveness.
A licence somewhere is useful information. It does not mean permission everywhere, and it does not remove the need to know who is actually on the other side.
Conclusion: one capability runs through all five findings
Each finding above turns on the same underlying capability: knowing which entity sits on the other side of a relationship or transaction, and whether it is actually permitted to be there.[24] A VASP that has passed Travel Rule legislation but cannot verify its counterparty has not closed the operational gap described in section 4. An institution reading a single data source cannot see the nested or misrepresented activity described in section 5.
For compliance teams, that points to a specific task: treating counterparty identification as its own control, resourced and tested on its own terms, rather than as a by-product of a licensing check or a transaction alert.
FATF has said it will keep monitoring implementation and emerging risk through its existing toolkit of assessment, risk analysis and capacity building.[25] The next Targeted Update will show whether identification has caught up with legislation, or whether the gap this one describes has simply moved.
For access to more comprehensive data on the world's regulated VASPs, please write to us at contact@vaspnet.com.
[1] FATF (2026), Targeted Update on Implementation of the FATF Standards on Virtual Assets/VASPs, paras. 9–12, 18 and 24–26.
[2] FATF (2026), Targeted Update on Implementation of the FATF Standards on Virtual Assets/VASPs, paras. 32–33, 41 and 45.
[3] FATF (2026), Targeted Update on Implementation of the FATF Standards on Virtual Assets/VASPs, paras. 5–7; Figure 1.1.
[4] FATF (2026), Targeted Update on Implementation of the FATF Standards on Virtual Assets/VASPs, para. 3; para. 18; Annex A, paras. 3–4.
[5] FATF (2026), Targeted Update on Implementation of the FATF Standards on Virtual Assets/VASPs, paras. 9–10; Figures 1.3–1.4.
[6] FATF (2026), Targeted Update on Implementation of the FATF Standards on Virtual Assets/VASPs, para. 18; Figures 1.3 and 1.8.
[7] FATF (2026), Targeted Update on Implementation of the FATF Standards on Virtual Assets/VASPs, para. 22.
[8] FATF (2026), Targeted Update on Implementation of the FATF Standards on Virtual Assets/VASPs, Table 1.2; Figure 1.3.
[9] FATF (2026), Targeted Update on Implementation of the FATF Standards on Virtual Assets/VASPs, para. 12; Figure 1.5.
[10] FATF (2026), Targeted Update on Implementation of the FATF Standards on Virtual Assets/VASPs, paras. 16–17; Figure 1.7.
[11] FATF (2026), Targeted Update on Implementation of the FATF Standards on Virtual Assets/VASPs, para. 31.
[12] FATF (2026), Targeted Update on Implementation of the FATF Standards on Virtual Assets/VASPs, paras. 39–42.
[13] FATF (2026), Targeted Update on Implementation of the FATF Standards on Virtual Assets/VASPs, para. 21; Figure 1.9.
[14] FATF (2026), Targeted Update on Implementation of the FATF Standards on Virtual Assets/VASPs, para. 43.
[15] FATF (2026), Targeted Update on Implementation of the FATF Standards on Virtual Assets/VASPs, para. 41.
[16] FATF (2026), Targeted Update on Implementation of the FATF Standards on Virtual Assets/VASPs, Recommendations for the Private Sector, Recommendation 6(iii).
[17] FATF (2026), Targeted Update on Implementation of the FATF Standards on Virtual Assets/VASPs, para. 24; Figure 1.10.
[18] FATF (2026), Targeted Update on Implementation of the FATF Standards on Virtual Assets/VASPs, Table 1.2; Figure 1.3.
[19] FATF (2026), Targeted Update on Implementation of the FATF Standards on Virtual Assets/VASPs, paras. 25–26.
[20] FATF (2026), Targeted Update on Implementation of the FATF Standards on Virtual Assets/VASPs, Recommendations for the Public Sector, Recommendation 2.
[21] FATF (2026), Targeted Update on Implementation of the FATF Standards on Virtual Assets/VASPs, paras. 29–34.
[22] FATF (2026), Targeted Update on Implementation of the FATF Standards on Virtual Assets/VASPs, para. 35.
[23] FATF (2026), Targeted Update on Implementation of the FATF Standards on Virtual Assets/VASPs, Recommendations for the Private Sector, Recommendation 5(ii).
[24] FATF (2026), Targeted Update on Implementation of the FATF Standards on Virtual Assets/VASPs, paras. 9–10 and 22.
[25] FATF (2026), Targeted Update on Implementation of the FATF Standards on Virtual Assets/VASPs, Next steps.