Learn more about the latest security and privacy threats
Back

The FATF travel rule gap: the seventh targeted update finds enforcement lagging the law

Michelangelo Frigo Michelangelo Frigo (Co-Founder at Zyphe) Published July 21, 2026 Reviewed by Charlene Wang
Editorial illustration for the article "The FATF travel rule gap: the seventh targeted update finds enforcement lagging the law".

The FATF seventh targeted update finds 83% of jurisdictions have travel rule laws, yet most have never enforced them. What it means for VASP onboarding.

Table of contents

The FATF travel rule has now been written into law by 83% of surveyed jurisdictions, up from 73% a year ago, but the FATF's seventh targeted update, published on 16 July 2026, finds that most of those jurisdictions have never supervised or enforced it. Legislation is no longer the bottleneck. Checking that firms actually comply is.

  • The FATF's seventh targeted update on virtual assets, released in Paris on 16 July 2026, draws on survey responses from 147 jurisdictions and 149 mutual evaluations.
  • 83% of surveyed jurisdictions now have FATF travel rule legislation in force, up from 73% in 2025; a further set report work under way, taking the combined figure to about 93%.
  • Of the jurisdictions with the rule in force, roughly six in ten have issued zero supervisory findings or enforcement actions on it.
  • Technical compliance with Recommendation 15 improved only modestly: the share rated largely compliant rose from 29% to 34%, while nearly two thirds remain partially or non-compliant.
  • FATF President Giles Thomson warned that implementation "can no longer be delayed" as criminals exploit weak links across borders.

What did the FATF seventh targeted update find?

The FATF published its seventh targeted update on the implementation of its standards for virtual assets and virtual asset service providers on 16 July 2026. The report measures how far the global network has applied Recommendation 15 and the FATF travel rule since the standards were extended to crypto in 2019. It is a progress report, and the headline is that the law has spread faster than the will to enforce it.

FATF President Giles Thomson framed the stakes plainly, saying implementation "can no longer be delayed" while criminal networks abuse virtual assets to commit fraud, evade sanctions and launder proceeds across borders. The update rests on responses from 147 jurisdictions and a review of 149 mutual evaluation and follow-up reports, making it the most complete picture of crypto supervision the FATF publishes each year.

Metric20252026
Travel rule legislation in force73%83%
Rated largely compliant with R.1529%34%
Rated partially compliant50%43%
Rated non-compliant21%22%
Jurisdictions that completed a VA risk assessment76%86%

The direction is positive, but the pace is slow. Only one jurisdiction is rated fully compliant with Recommendation 15, the largely-compliant share moved just five points in a year, and nearly two thirds of assessed jurisdictions are still only partially or non-compliant. A parallel trend is hardening: the share of jurisdictions that prohibit VASPs outright has more than doubled, from 11% in 2023 to 23% in 2026.

Why is enforcement, not legislation, now the gap?

The mechanics of the gap are simple. Passing a FATF travel rule statute is a one-off legislative act. Supervising it is a permanent operational burden that requires trained examiners, data, and the appetite to act. The report finds that many jurisdictions cleared the first hurdle and stopped.

Of the jurisdictions that have the FATF travel rule in force, roughly 60% have issued no supervisory findings, directives or enforcement actions on travel rule compliance at all. On paper the counterparty owes an obligation; in practice nobody is checking whether it is met. The FATF frames this as the second phase of the long-running "sunrise" problem: the original issue was counterparties in jurisdictions with no rule, and the new one is counterparties who have a rule but face no oversight.

Risk assessment shows the same pattern. 86% of jurisdictions have now assessed the money laundering and terrorist financing risks of virtual assets, up from 76%, yet only about a third have translated that assessment into concrete preventive measures. Understanding the risk and acting on it remain two very different things.

What does this mean for your obligations?

The update does not change the FATF standards, but it signals where supervisors will look next, and that reshapes how regulated firms should evidence compliance. Map it to the specific duties you already carry.

DutyFATF referenceWhat the update changes for you
Travel rule messagingRecommendation 16Supervisors test whether originator and beneficiary data is complete, accurate and screened, not just switched on.
VASP licensingRecommendation 15The registration gate is now expected to be actively supervised, with nested and offshore accounts under scrutiny.
Customer due diligence and screeningR.15, sanctions and PEP standardsOnboarding and ongoing monitoring must catch nested and offshore typologies, not only obvious risk.
Stablecoin activityR.15 travel rule and CDDWhere an issuer or intermediary is a VASP, the same duties apply; the FATF is flagging jurisdictions that left this open.
Record-keepingFATF record-keeping standardAn examiner will ask for the evidence trail behind each check, not a policy document.

Recommendation 16, the FATF travel rule itself, is the sharpest edge. Ordering and beneficiary VASPs must transmit accurate originator and beneficiary information with each qualifying transfer. With 83% of jurisdictions now legislated, the "my counterparty has no obligation" defence is disappearing, and supervisors are expected to test whether your travel rule messaging is complete, accurate and screened, not merely switched on.

Recommendation 15 and VASP licensing tie the rest together. Registration is the gate; customer due diligence, sanctions and PEP screening, and record-keeping are the ongoing duties behind it. The report's focus on nested VASPs, accounts that pose as ordinary retail customers on a licensed platform while processing illicit volume, means CDD at onboarding and continuous monitoring both matter more.

In the EU, these duties already bite through MiCA, whose transitional period closed on 1 July 2026 and whose licensing gate has already locked one major exchange out of the bloc. Record-keeping gains teeth too, because an examiner arriving to test travel rule compliance will ask for the evidence trail, not a policy document.

What is still uncertain, and what could go wrong?

The largest risk is that the enforcement gap persists. Writing a law is cheap and visible; standing up a crypto supervision function is expensive and slow, and the report gives supervisors little cover to keep deferring it. Firms should expect uneven, unpredictable enforcement, with some regulators moving hard and others still dormant, which makes cross-border consistency hard to plan around.

Decentralised finance is a near total blind spot. Only about 18% of jurisdictions have assessed DeFi risks, and the vast majority have not identified any DeFi arrangement that qualifies as a VASP, leaving a large space where the FATF travel rule simply is not applied. Unhosted wallets and offshore providers compound the problem. The report also documents criminals adapting faster than rules, including a case in which a network responded to a stablecoin freeze by issuing its own token marketed as immune to freezing. Liability is the open question underneath all of this: when a compliant VASP transmits data to a counterparty that no regulator supervises, who owns the resulting failure remains unresolved.

How does this compare with previous years?

Compared with the 2025 update, the 2026 report shows steady legislative progress and stubborn operational lag. Travel rule adoption rose ten points, risk assessments rose ten points, and technical compliance crept up five points. The trend line is consistent rather than transformative.

The deeper shift is rhetorical. Earlier updates emphasised getting laws on the books. This one, under the FATF's UK presidency, pivots to enforcement and supervision as the measure that matters, echoing the presidency's wider focus on fraud and operational outcomes. Thomson urged governments and industry to "deny criminals the opportunity to exploit weak links in the global system". For firms, that means the benchmark for "good" is moving from having a compliant policy to producing evidence that the policy runs every day.

How should compliance teams respond?

Treat the enforcement gap as a countdown, not a reprieve. First, test your own FATF travel rule flows end to end: confirm that originator and beneficiary data is complete, accurate, screened against sanctions and PEP lists, and logged in a form an examiner can inspect. Second, map your counterparties by jurisdiction and note which regulators have started enforcing, so you can prioritise the relationships most likely to be tested. Third, tighten onboarding and ongoing monitoring against nested and offshore VASP typologies, and make sure your record-keeping produces an exportable trail rather than a policy PDF. Treat stablecoin and DeFi exposure as in scope until you have assessed it, not the reverse.

The identity layer underneath all of this is where a lot of firms lose evidence. Zyphe issues a reusable KYC credential: a customer verifies once through an NFC chip read with two-step liveness and no image upload, and that verified identity can be re-presented for each new VASP relationship, with data sharded so no single node holds a complete record and an exportable audit trail for every check. That gives a travel rule programme clean, current counterparty identity data and a defensible record without building a fresh honeypot. If that fits your roadmap, book a demo.

The bottom line

The seventh targeted update marks a turning point in tone. The global network has largely won the argument that virtual assets belong inside the FATF travel rule, and the legislative map is filling in. The unfinished work is supervision, and that is now where the pressure moves. For any firm running crypto onboarding, the practical lesson is to stop treating a compliant policy as the finish line and start producing daily evidence that identity, counterparty data and screening controls genuinely run, because the next round of scrutiny will ask to see it.

Cited sources

Michelangelo Frigo Michelangelo Frigo (Co-Founder at Zyphe) Michelangelo Frigo is a privacy and identity infrastructure expert and co-founder of Zyphe.

Frequently Asked Questions

The FATF travel rule, set out in Recommendation 16, requires virtual asset service providers to collect and transmit accurate originator and beneficiary information alongside qualifying crypto transfers, mirroring the wire transfer rule long applied to banks. It lets each party screen the counterparty against sanctions and detect suspicious flows. The seventh targeted update measures how widely it has been adopted and enforced.

Published on 16 July 2026, the update found that 83% of surveyed jurisdictions now have travel rule legislation in force, up from 73% in 2025, but that most have not supervised or enforced it. Technical compliance with Recommendation 15 rose only modestly, and decentralised finance remains largely unassessed.

The FATF sets international standards, not directly binding law. Its recommendations become enforceable when jurisdictions write them into national rules, which 83% of those surveyed have now done. Firms comply with the local implementation, such as the EU transfer of funds regulation or a national VASP regime, rather than with the FATF text itself.

Supervisors are expected to test whether travel rule and customer due diligence controls actually work, not just whether they exist. That raises the bar on identity verification, counterparty data quality, sanctions and PEP screening, and record-keeping at onboarding, and it puts nested accounts and offshore providers under sharper scrutiny.

The sunrise problem describes travel rule gaps created when counterparties sit in jurisdictions without the rule, so data cannot be exchanged. The FATF says it is entering a second phase: the counterparty now has a legal obligation, but no supervisor is checking whether it is met, shifting the gap from law to enforcement.

See privacy-first KYC in action

Verify identity without storing a single document. Reusable credentials, an exportable audit trail, and a 15-minute integration.

Book a demo