FATF's 2026 virtual assets update: what VASP compliance teams should take from it
The FATF's seventh targeted update, published 16 July 2026, finds most jurisdictions now have Travel Rule laws but few enforce them, and asks VASPs to strengthen wallet screening, unhosted-wallet due diligence and scrutiny of offshore platforms.

Charles Archibong, Co-founder
· 6 min read

Key takeaways
- The FATF published its seventh targeted update on virtual assets on 16 July 2026.
- 83% of surveyed jurisdictions (91 of 109) report passing Travel Rule legislation, up from 73% in 2025.
- Of those 91, 55 had not yet taken Travel Rule supervisory or enforcement action.
- The FATF asks VASPs to strengthen wallet screening, unhosted-wallet EDD and checks for offshore VASPs posing as retail users.
The FATF's seventh targeted update on virtual assets, published on 16 July 2026, says the rules for crypto businesses now largely exist on paper and are still thin in practice. Most jurisdictions have passed Travel Rule laws, but fewer than half of those have taken any supervisory or enforcement action on them. The report also names four areas where it sees risk growing: stablecoins, peer-to-peer transfers through unhosted wallets, offshore VASPs and decentralised finance.
For a VASP compliance team, the useful part is the list of recommendations addressed to the private sector. They are specific: screen wallets, be able to block and freeze, apply enhanced due diligence to higher-risk unhosted-wallet activity, and look hard at accounts that may be offshore platforms posing as retail customers. The rest of this article sets out what the report found and turns those recommendations into work you can plan.
What did the 2026 update find?
The report (FATF, 16 July 2026 (opens in a new tab)) combines mutual evaluation ratings with a survey of jurisdictions. The figures below are quoted from it.
Measure | 2025 | 2026 |
|---|---|---|
Jurisdictions assessed on R.15 | 138 | 149 (as of April 2026) |
Largely compliant with R.15 | 29% (40) | 34% (51) |
Partially compliant | 50% (68) | 43% (64) |
Not compliant | 21% (29) | 22% (33) |
Passed Travel Rule legislation (survey) | 73% (85 of 117) | 83% (91 of 109) |
One jurisdiction remains fully compliant with R.15, as in 2025. The FATF calls the improvement "modest", and its own summary is blunt: significant gaps remain in turning risk assessments into mitigation, in making licensing work in practice and in identifying people who run VASP businesses without a licence.
Two further findings stand out:
Enforcement of the Travel Rule is rare. Of the 91 jurisdictions with Travel Rule legislation, 55 had not yet issued findings, directives or enforcement action focused on Travel Rule compliance (paragraph 25). The report's key findings describe this as "almost half"; paragraph 25 gives the count.
Prohibition is growing but not enforced. 23% of respondents now prohibit VASPs, up from 11% in 2023. The FATF says jurisdictions taking this route "have not progressed in taking supervisory or enforcement actions" and that unenforced prohibitions "can represent significant risks".
Which risks does the FATF say are growing?
Stablecoins designed to resist freezing
The report describes a financial services conglomerate that launched a dollar-pegged stablecoin "marketed as immune to asset freezing", after a different issuer had frozen over USD 29 million linked to it. The FATF's conclusion is the part that matters for VASPs: obliged entities "may be unable to rely on issuer-level asset freeze/burn mechanisms as a compliance safeguard". If your controls assume the issuer can always claw back, that assumption needs a second look.
Peer-to-peer transfers through unhosted wallets
Of the jurisdictions that rated the risk, 88% (58 of 66) rated P2P transactions as high risk. The report notes that these transfers happen without a regulated intermediary, so no obliged entity files a suspicious transaction report on them. For a VASP, the exposure arrives when funds from such chains reach a customer's deposit address.
Offshore VASPs, including nested accounts
The report describes offshore platforms that solicit customers where they are unlicensed, sometimes advising users to use VPNs or give false information. It also describes nested activity: offshore VASPs "deliberately misrepresenting themselves as retail users" when opening accounts at licensed VASPs and financial institutions, then processing volumes far above a typical retail customer.
Decentralised finance
Only 18% of respondents (26 of 142) have assessed DeFi risks. Four jurisdictions have imposed licensing or registration requirements on DeFi arrangements, and two have actually licensed or registered one. The June 2026 plenary approved a separate targeted report (opens in a new tab) on regulatory challenges from DeFi.
What does the FATF ask VASPs to do?
The report's recommendations for the private sector (recommendations 5 and 6) translate into a practical checklist.
FATF recommendation | What it means in practice |
|---|---|
Understand institutional risk, including stablecoins, P2P, unhosted wallets, offshore VASPs and DeFi | Your business-wide risk assessment names each of these and says how exposed you are |
KYC, wallet screening, blacklisting, whitelisting, freezing and blocking that "can be swiftly updated" | You can add an address to a block list and stop a withdrawal within hours, not a release cycle |
Enhanced due diligence for higher-risk unhosted wallet activity | Rules that treat large or frequent flows to and from self-hosted addresses differently from exchange-to-exchange flows |
Transaction monitoring and blockchain analytics to detect rapid movement | Monitoring that looks at speed and direction, not only amount |
EDD of offshore VASPs, detecting those posing as retail users | Account-level review of retail customers with institutional volumes or counterparties |
Assess DeFi exposure (protocols, bridges, mixers, cross-chain tools) | A documented view of which protocols your customers interact with, and what you do about it |
How would this change a real control set?
Take an illustrative exchange serving customers in Nigeria and Kenya.
Retail account behaving like a platform. A customer onboarded as an individual trader starts receiving deposits from hundreds of distinct addresses and sending consolidated withdrawals to a small set of exchange addresses abroad. That is the nested-offshore pattern the report describes. A monitoring rule on many distinct inbound counterparties, combined with a volume far above the declared profile, should put this account in front of an analyst. The outcome might be a request for business documents, a reclassification to a business customer with KYB, or an exit.
Withdrawal to a self-hosted wallet. A customer asks to withdraw a large amount to a new address they say they control. The report asks for enhanced due diligence on higher-risk unhosted activity. In practice that can mean screening the address, asking the customer to prove control of it, and holding first-time large withdrawals for review. Some jurisdictions also have specific rules here; the EU's transfer of funds regulation, for example, requires an assessment of ownership or control above EUR 1,000. Requirements differ by jurisdiction, and this article is general information, not legal advice.
Counterparty VASP in a jurisdiction with no Travel Rule enforcement. The survey figures mean many counterparties sit in places where the Travel Rule exists in law but nobody has checked compliance. A counterparty's licence status is not proof that it can receive and protect originator and beneficiary information. Your due diligence on counterparties needs to ask.
Where does Myaza Trust fit?
Two parts of the checklist are covered by products that are available today.
Watchlist Screening includes a WALLET screening type. Wallet addresses you attach to a customer are checked against sanctioned-wallet data, re-screened on a schedule, and re-screened promptly when the set of addresses changes (screening documentation). Wallets are treated as risk attributes of a customer, never as identity keys, because shared and custodial addresses would otherwise merge unrelated people.
Transaction Monitoring scores events in real time with rules such as velocity, many distinct inbound counterparties, rapid movement and pass-through, and lets you write your own rules as data without a deploy.
Wallet screening checks addresses against lists. It is not blockchain analytics and does not trace exposure through intermediate hops, so it complements rather than replaces the analytics the FATF mentions. For the Travel Rule itself, the Crypto & Travel Rule workspace is where we are building that capability; talk to us about your requirements rather than assuming counterparty exchange is available.
What should a VASP compliance team do this quarter?
Add stablecoins, unhosted wallets, offshore VASPs and DeFi as named sections in your business-wide risk assessment, with your own exposure for each.
Test how fast you can block an address and freeze a customer's funds after a new designation. Aim for hours.
Write enhanced due diligence triggers for unhosted-wallet activity: first withdrawal to a new address, large or frequent flows, rapid round trips.
Review retail accounts whose volumes or counterparty counts look institutional.
Stop treating an issuer's ability to freeze a stablecoin as your control.
Keep the report to hand: it is the reference your supervisor will be reading. Figures here were verified against the report on 27 September 2026.
Sources

Charles Archibong
Co-founder
Charles Archibong co-founded Myaza Trust. He writes about identity verification, financial technology, and the practical work of building trusted digital services.


