Response to FATF’s consultation on the Guidance on implementation of Recommendation 16

VASPnet’s recommendations on counterparty identification, proportionate due diligence and consistent party identification across fiat and virtual asset payment chains.

Pier extending into calm water at dusk, photo by John-Mark Strange

Thank you! Your submission has been received!
Oops! Something went wrong while submitting the form.

Introduction

On 24 June 2026, the Financial Action Task Force (FATF) launched a public consultation on its proposed Guidance on the implementation of Recommendation 16. The Guidance supports the revised R.16 standard adopted by FATF in June 2025, which countries are expected to be ready to implement by the end of 2030.[1]

VASPnet submitted its response on 28 July 2026. Given VASPnet’s role as a regulatory reference data provider, the response focuses on three closely connected implementation challenges:

  • identifying and assessing the VASP involved in a virtual asset transfer;
  • distinguishing payment-counterparty due diligence from the fuller requirements associated with correspondent relationships; and
  • identifying the correct institutions and customers across virtual asset, fiat and hybrid payment chains.

The full response presents recommendations against the relevant provisions of the draft Guidance. It also addresses nested VASPs, batch transfers, messaging interoperability, data reliability, sanctions risk, Legal Entity Identifiers and the treatment of virtual asset transfers as cross-border.

A wallet address cannot reliably identify the counterparty VASP

An ordering VASP may know its customer and the destination wallet address without knowing whether that address is controlled by another VASP, a self-hosted wallet or another participant.

FATF’s existing virtual asset guidance acknowledges that there is no technically proven method of identifying the VASP managing a beneficiary wallet exhaustively and accurately from the virtual asset address alone.[2] This remains one of the practical challenges facing the global implementation of FATF’s standards for VASPs.

Travel Rule information is nevertheless expected to be transmitted before or concurrently with the transfer. FATF’s existing guidance states that post-facto transmission should not ordinarily be permitted.[2] Reliable attribution of the destination address, however, may occur only after the transfer has been executed.

VASPnet’s response therefore asks FATF to distinguish between retrospective attribution of a wallet address and retrospective collection or transmission of the required originator and beneficiary information. The former may sometimes be unavoidable; the latter should not become a substitute for an effective pre-transfer counterparty-identification process.

Counterparty assessment should remain proportionate

Ordering institutions may need to identify and assess the institution at the other end of a payment or virtual asset transfer. This is necessary to determine whether it is an appropriate counterparty with which to transact and share customer information.

However, identifying and assessing a payment counterparty should not automatically be treated as establishing a correspondent relationship. FATF’s existing virtual asset guidance recognises that counterparty due diligence for R.16 is distinct from the obligations applicable to cross-border correspondent relationships, although elements of Recommendation 13 may provide useful reference points.[2]

Draft paragraphs 52 and 55 also emphasise proportionality and the need to avoid misclassifying lower risks as higher risks.[3]

In practice, many VASPs apply full correspondent-style due diligence to every payment counterparty. VASPnet’s response argues that this can result in increased costs, delayed transfers and the de-risking of smaller providers and jurisdictions, even where more targeted controls could address the underlying risks. VASPnet previously examined this distinction in The EU’s due diligence requirements for CASPs.

Clearer guidance on the boundary between Recommendations 13 and 16 would allow institutions to conduct effective counterparty due diligence while preserving a proportionate, risk-based approach.

Payment messages should identify the correct parties

The response also considers how institutions and customers should appear in payment messages across hybrid fiat and virtual asset payment chains.

Where a fiat payment is made to fund a customer’s account or wallet at a VASP, VASPnet recommends that the receiving VASP ordinarily appear as the beneficiary or creditor. The underlying customer can then be identified as the ultimate creditor. This treatment is consistent with the CASP and virtual IBAN example in section 5.3, Box 7, Case Study 2 of the draft Guidance.[3]

Without this distinction, a payment message may incorrectly suggest that the account-servicing institution holds an account directly for the VASP’s customer.

The wider principle is that payment messages should distinguish between the institutions facilitating a transfer and the customers who are its ultimate originator and beneficiary. Clear and consistent party identification is essential if institutions are to understand the true structure and risk of a payment.

These questions are closely related to the issues considered in VASPnet’s response to the EBA’s consultation on the EU’s Travel Rule guidelines.

Further recommendations in the full response

VASPnet’s submission also asks FATF to clarify:

  • how responsibilities should be divided between nested VASPs and host VASPs;
  • how batch-transfer provisions apply to bundled or atomic virtual asset transactions;
  • how institutions should assess the reliability of information received from counterparties;
  • how sanctions risk may arise from the institutions involved in a transfer, as well as its originator and beneficiary;
  • how IVMS 101 can coexist with other interoperable messaging frameworks, including ISO 20022;
  • why the simplified domestic-transfer regime should not apply to virtual-asset-to-virtual-asset transfers;
  • how Legal Entity Identifiers can support consistent institutional identification; and
  • when technical or ancillary service providers fall within the scope of the FATF Standards.

Draft paragraphs 49 and 50 recognise the importance of global messaging standards and cooperation with payment market infrastructures, SWIFT and the Committee on Payments and Market Infrastructures.[3] VASPnet’s response recommends that the final Guidance also recognise the progress made in the virtual asset sector through IVMS 101.

Why counterparty identification matters

The Travel Rule is sometimes reduced to the transmission of specified customer-data fields. Effective implementation also depends on understanding which institutions are involved, the functions they perform and whether the information they provide can be relied upon.

VASPnet’s regulatory data supports the identification and assessment of a counterparty VASP once a potential counterparty has been established through pre-transfer messaging or another reliable mechanism. It allows institutions to examine regulatory status, jurisdiction and other relevant risk attributes before deciding how to proceed.

VASPnet’s full consultation response sets out the detailed reasoning, paragraph-specific recommendations and practical examples behind these positions.

Download VASPnet’s full response to FATF’s Recommendation 16 consultation.

[1] FATF, Public consultation on guidance to increase payment transparency, 24 June 2026, FATF.
[2] FATF,
Updated Guidance for a Risk-Based Approach to Virtual Assets and Virtual Asset Service Providers, October 2021: paragraph 197(a) on wallet attribution; paragraphs 185 and 187 on transmission timing; and paragraph 169 on the distinction between counterparty due diligence and correspondent relationships. FATF.
[3] FATF,
Guidance on Implementation of FATF Recommendation 16, draft public consultation, June 2026: paragraphs 52 and 55 on proportionality; section 5.3, Box 7, Case Study 2 on party identification; and paragraphs 49 and 50 on messaging standards. FATF.