Skip to content

FATF's payment transparency changes: what payment firms should prepare for

In June 2025 the FATF revised Recommendation 16: standard originator and beneficiary data above USD/EUR 1,000, a defined start to the payment chain and new checks against misdirected payments. Countries are expected to implement by the end of 2030.

Charles Archibong

, Co-founder

· 7 min read

Headline "Recommendation 16, revised" beside an illustration of a path of connected steps, on a warm cream gradient.

Key takeaways

  • The FATF agreed a revised Recommendation 16, now titled Payment transparency, on 18 June 2025. The changes take effect by the end of 2030.
  • Cross-border payments above USD/EUR 1,000 carry a standard data set: names, account numbers, originator address and date of birth, beneficiary country and town.
  • Beneficiary institutions must act against misdirected payments by one of three routes: per-payment alignment checks, holistic monitoring or payee pre-validation.
  • The FATF consulted on draft implementation guidance from 24 June to 21 August 2026. Plan data and systems work now.

In June 2025 the FATF rewrote Recommendation 16, the standard that decides what information travels with a payment. It is now titled "Payment transparency" rather than "Wire transfers". Cross-border payments above USD/EUR 1,000 must carry a standard set of data about both parties, the payment chain has a defined start and end, and the institution paying out must take steps against payments that reach the wrong person. The FATF expects countries to implement the changes by the end of 2030.

For a payment service provider or remittance firm, the preparation is mostly data and systems work: holding verified originator details you can send, working out where your firm sits in each payment chain, and choosing how you will check that incoming payments match the account they land in. The FATF consulted on draft implementation guidance between 24 June and 21 August 2026, so the detail is still settling, but the obligations themselves are fixed.

What did the FATF change in Recommendation 16?

The FATF announced the revision on 18 June 2025 (opens in a new tab) and published an explanatory note (opens in a new tab) with the full marked-up text. The changes that matter most to payment firms:

Change

What the revised text says

Who it touches most

Payment chain defined

The chain starts at the institution that receives the customer's instruction and ends at the one that services the beneficiary's account or pays out cash

PSPs, wallets and remittance firms that sit in front of banks

Standard data above USD/EUR 1,000

Names, account numbers, originator address and date of birth, beneficiary country and town

Every sending institution

Misdirected payments

Beneficiary institutions must check alignment, monitor holistically or use payee pre-validation

Receiving banks, wallets, mobile money

Virtual account numbers

Account numbers must not disguise the country where the account is serviced

Firms issuing virtual accounts or IBANs

Origin of funds

If funds are drawn from another institution, that account and institution name go in the message

Payment initiation and pay-by-bank models

Cards

Purchases of goods and services stay exempt; card-funded person-to-person transfers are covered

Card issuers and acquirers

Cross-border cash withdrawals

Cardholder name sent to the acquirer on request within three business days

Issuers and ATM acquirers

The FATF also clarified that Recommendation 16 does not itself require real-time sanctions screening (footnote 49 of the revised Interpretive Note). Your sanctions obligations still apply; they come from targeted financial sanctions rules and national regulation, not from R.16.

Virtual asset service providers are not brought directly into R.16. The explanatory note says the updated requirements apply to them through Recommendation 15.

When do the changes take effect?

The FATF says the changes "will come into effect by the end of 2030". It departed from its normal practice of immediate effect because institutions and payment infrastructures need time to change systems.

Three dates are worth knowing now:

  • 28 October 2025. The FATF published Annex IV to its assessment methodology, which sets out how compliance with the revised R.16 will be assessed in mutual evaluations.

  • 24 June to 21 August 2026. The FATF consulted on draft guidance (opens in a new tab) covering misdirected payments and the three alignment options, financial inclusion, how R.16 applies to digital wallets and mobile money, and meeting data protection rules at the same time. The consultation is closed.

  • Late 2026. The June 2025 explanatory note said the guidance paper was expected in late 2026. Check the FATF site for the final text.

Your national regulator will set the binding dates, and some may move earlier than 2030. Requirements differ by jurisdiction, and this article is general information, not legal advice.

What data must travel with a cross-border payment?

Above the threshold, paragraph 9 of the revised Interpretive Note sets the data set:

Field

Originator

Beneficiary

Name

Required

Required

Account number, or unique transaction reference

Required

Required

Address

Full address; country and town if there is no standardised postal address

Country and town only

Date of birth (individuals)

Required; year of birth if the full date is unavailable

Not required

BIC, LEI or unique official identifier (legal persons)

Where it exists

Where it exists

Two points about accuracy shape the work. The sending institution must send originator information that has been verified for accuracy, but it only passes on the beneficiary details it was given. The receiving institution verifies its own customer's identity if it has not already done so.

Below the threshold, countries may apply a de minimis regime of no more than USD/EUR 1,000, where names and account numbers (or a reference) are enough and need not be verified unless there is suspicion.

For firms serving customers in Africa, the address fallback and the year-of-birth fallback matter. Many customers have no standardised postal address, and some do not have a full recorded date of birth. The FATF built both fallbacks in to protect financial inclusion.

What is an alignment check, and which option fits your firm?

The new duty sits with the beneficiary institution: for payments above the threshold, it must take measures against transfers reaching an unintended beneficiary. Paragraph 30 gives three options, and at least one must be used:

  1. Per-transaction alignment check. Compare the beneficiary name and account number in the message with what you hold.

  2. Holistic ongoing monitoring. Monitor accounts and activity for anomalies, including misaligned beneficiary information, on a risk basis.

  3. Pre-validation. Where both institutions take part in a scheme such as confirmation or verification of payee, check the name and account before the payment.

A footnote adds that alignment "does not imply that there must be an exact match". A wallet registered to "Chukwuemeka Okafor" receiving a payment addressed to "C. Okafor" is a different signal from one addressed to an unrelated company.

A practical way to choose:

Your position

Likely starting point

Mobile money or wallet provider receiving international remittances

Per-transaction check against the wallet holder's verified name, with holistic monitoring behind it

Bank in a market with a confirmation of payee scheme

Pre-validation where the sender also participates, a fallback check where it does not

Remittance firm controlling both the sending and paying sides

Holistic monitoring across both sides; paragraph 32 also asks you to consider both sides when deciding whether to file an STR, and to file in any affected country

PSP issuing virtual accounts

Make sure account numbers show where the account is serviced, and monitor for payments to accounts whose use does not match the holder

A worked example: one remittance, three institutions

An illustrative remittance firm in London takes an instruction from a customer to send GBP 400 to her brother's mobile wallet in Nigeria. The firm settles through a correspondent bank, which pays a Nigerian partner bank, which credits the wallet.

Under the revised standard, the chain starts with the remittance firm, because it received the customer's instruction. It ends with the wallet provider, because that is the institution servicing the beneficiary's account. The originator's name, account, address and date of birth, plus the brother's name, wallet number, country and town, need to travel the whole way rather than being lost when the payment becomes a domestic transfer at the partner bank. The explanatory note calls out exactly this problem: cross-border chains broken into separate domestic transfers where nobody holds the full picture.

The amount is below USD/EUR 1,000, so a national de minimis regime may reduce the data required. The firm still has to know which regime applies in each corridor.

What should payment firms prepare now?

  • Map your chains. For each product and corridor, write down who receives the instruction, who pays out, and which institutions sit between. Your obligations follow your position.

  • Check your originator data. Can you send a verified name, address (or country and town) and date of birth for every individual sender? If your onboarding captures typed values rather than verified ones, that gap will show.

  • Check message capacity. Structured fields, ISO 20022 where used, and any domestic rails used for the last mile. The explanatory note records that some domestic infrastructures cannot yet carry the data end to end.

  • Choose an alignment approach for each inbound product and write down why.

  • Review virtual accounts and pay-by-bank flows for the country-disguise rule and the origin-of-funds footnote.

  • Track the final guidance and your regulator's implementation date, then set an internal date well before it.

Myaza Trust covers part of the data side. Identity Verification checks customers against the government record in five markets, which gives you a verified name and date of birth to send, and our proof-of-address check reads and checks the address on a utility bill, bank statement or tenancy agreement (Address Intelligence documentation). Transaction Monitoring scores activity with rules such as new beneficiary, many distinct inbound counterparties and rapid movement, which can form one part of a holistic monitoring approach. We do not run confirmation of payee or name-to-account alignment checks; those depend on your own account data or a payment scheme.

Sources

Charles Archibong

About the author

Charles Archibong

Co-founder

Charles Archibong co-founded Myaza Trust. He writes about identity verification, financial technology, and the practical work of building trusted digital services.

  • Headline "The Travel Rule, explained" beside an illustration of information passing between two providers alongside a transfer, on a warm cream gradient.

    Risk & Compliance

    The Travel Rule explained for teams launching crypto transfers

    The Travel Rule requires the sending VASP to collect originator and beneficiary information, pass it to the receiving VASP immediately and securely, and make it available to authorities. The hard parts are finding the counterparty, handling self-hosted wallets and jurisdictions that disagree.

  • Headline "Backtest before you switch on" beside an illustration of a laboratory flask with bubbles, on a warm cream gradient.

    Risk & Compliance

    Backtest before you switch on: testing monitoring rule changes safely

    Replay recent scored events through the proposed configuration, then read each decision that would change as well as the count. A backtest shows what a change would have done to the past; your written expectation is what tells you whether that is the right result.

Build your product.We'll handle the rest.

Identity and compliance, end to end, built to global standards, priced for founders.