The FATF seventh targeted update finds 83% of jurisdictions have travel rule laws, yet most have never enforced them. What it means for VASP onboarding.
Table of contents
The FATF travel rule has now been written into law by 83% of surveyed jurisdictions, up from 73% a year ago, but the FATF's seventh targeted update, published on 16 July 2026, finds that most of those jurisdictions have never supervised or enforced it. Legislation is no longer the bottleneck. Checking that firms actually comply is.
- The FATF's seventh targeted update on virtual assets, released in Paris on 16 July 2026, draws on survey responses from 147 jurisdictions and 149 mutual evaluations.
- 83% of surveyed jurisdictions now have FATF travel rule legislation in force, up from 73% in 2025; a further set report work under way, taking the combined figure to about 93%.
- Of the jurisdictions with the rule in force, roughly six in ten have issued zero supervisory findings or enforcement actions on it.
- Technical compliance with Recommendation 15 improved only modestly: the share rated largely compliant rose from 29% to 34%, while nearly two thirds remain partially or non-compliant.
- FATF President Giles Thomson warned that implementation "can no longer be delayed" as criminals exploit weak links across borders.
What did the FATF seventh targeted update find?
The FATF published its seventh targeted update on the implementation of its standards for virtual assets and virtual asset service providers on 16 July 2026. The report measures how far the global network has applied Recommendation 15 and the FATF travel rule since the standards were extended to crypto in 2019. It is a progress report, and the headline is that the law has spread faster than the will to enforce it.
FATF President Giles Thomson framed the stakes plainly, saying implementation "can no longer be delayed" while criminal networks abuse virtual assets to commit fraud, evade sanctions and launder proceeds across borders. The update rests on responses from 147 jurisdictions and a review of 149 mutual evaluation and follow-up reports, making it the most complete picture of crypto supervision the FATF publishes each year.
| Metric | 2025 | 2026 |
|---|---|---|
| Travel rule legislation in force | 73% | 83% |
| Rated largely compliant with R.15 | 29% | 34% |
| Rated partially compliant | 50% | 43% |
| Rated non-compliant | 21% | 22% |
| Jurisdictions that completed a VA risk assessment | 76% | 86% |
The direction is positive, but the pace is slow. Only one jurisdiction is rated fully compliant with Recommendation 15, the largely-compliant share moved just five points in a year, and nearly two thirds of assessed jurisdictions are still only partially or non-compliant. A parallel trend is hardening: the share of jurisdictions that prohibit VASPs outright has more than doubled, from 11% in 2023 to 23% in 2026.
Why is enforcement, not legislation, now the gap?
The mechanics of the gap are simple. Passing a FATF travel rule statute is a one-off legislative act. Supervising it is a permanent operational burden that requires trained examiners, data, and the appetite to act. The report finds that many jurisdictions cleared the first hurdle and stopped.
Of the jurisdictions that have the FATF travel rule in force, roughly 60% have issued no supervisory findings, directives or enforcement actions on travel rule compliance at all. On paper the counterparty owes an obligation; in practice nobody is checking whether it is met. The FATF frames this as the second phase of the long-running "sunrise" problem: the original issue was counterparties in jurisdictions with no rule, and the new one is counterparties who have a rule but face no oversight.
Risk assessment shows the same pattern. 86% of jurisdictions have now assessed the money laundering and terrorist financing risks of virtual assets, up from 76%, yet only about a third have translated that assessment into concrete preventive measures. Understanding the risk and acting on it remain two very different things.
What does this mean for your obligations?
The update does not change the FATF standards, but it signals where supervisors will look next, and that reshapes how regulated firms should evidence compliance. Map it to the specific duties you already carry.
| Duty | FATF reference | What the update changes for you |
|---|---|---|
| Travel rule messaging | Recommendation 16 | Supervisors test whether originator and beneficiary data is complete, accurate and screened, not just switched on. |
| VASP licensing | Recommendation 15 | The registration gate is now expected to be actively supervised, with nested and offshore accounts under scrutiny. |
| Customer due diligence and screening | R.15, sanctions and PEP standards | Onboarding and ongoing monitoring must catch nested and offshore typologies, not only obvious risk. |
| Stablecoin activity | R.15 travel rule and CDD | Where an issuer or intermediary is a VASP, the same duties apply; the FATF is flagging jurisdictions that left this open. |
| Record-keeping | FATF record-keeping standard | An examiner will ask for the evidence trail behind each check, not a policy document. |
Recommendation 16, the FATF travel rule itself, is the sharpest edge. Ordering and beneficiary VASPs must transmit accurate originator and beneficiary information with each qualifying transfer. With 83% of jurisdictions now legislated, the "my counterparty has no obligation" defence is disappearing, and supervisors are expected to test whether your travel rule messaging is complete, accurate and screened, not merely switched on.
Recommendation 15 and VASP licensing tie the rest together. Registration is the gate; customer due diligence, sanctions and PEP screening, and record-keeping are the ongoing duties behind it. The report's focus on nested VASPs, accounts that pose as ordinary retail customers on a licensed platform while processing illicit volume, means CDD at onboarding and continuous monitoring both matter more.
In the EU, these duties already bite through MiCA, whose transitional period closed on 1 July 2026 and whose licensing gate has already locked one major exchange out of the bloc. Record-keeping gains teeth too, because an examiner arriving to test travel rule compliance will ask for the evidence trail, not a policy document.
What is still uncertain, and what could go wrong?
The largest risk is that the enforcement gap persists. Writing a law is cheap and visible; standing up a crypto supervision function is expensive and slow, and the report gives supervisors little cover to keep deferring it. Firms should expect uneven, unpredictable enforcement, with some regulators moving hard and others still dormant, which makes cross-border consistency hard to plan around.
Decentralised finance is a near total blind spot. Only about 18% of jurisdictions have assessed DeFi risks, and the vast majority have not identified any DeFi arrangement that qualifies as a VASP, leaving a large space where the FATF travel rule simply is not applied. Unhosted wallets and offshore providers compound the problem. The report also documents criminals adapting faster than rules, including a case in which a network responded to a stablecoin freeze by issuing its own token marketed as immune to freezing. Liability is the open question underneath all of this: when a compliant VASP transmits data to a counterparty that no regulator supervises, who owns the resulting failure remains unresolved.
How does this compare with previous years?
Compared with the 2025 update, the 2026 report shows steady legislative progress and stubborn operational lag. Travel rule adoption rose ten points, risk assessments rose ten points, and technical compliance crept up five points. The trend line is consistent rather than transformative.
The deeper shift is rhetorical. Earlier updates emphasised getting laws on the books. This one, under the FATF's UK presidency, pivots to enforcement and supervision as the measure that matters, echoing the presidency's wider focus on fraud and operational outcomes. Thomson urged governments and industry to "deny criminals the opportunity to exploit weak links in the global system". For firms, that means the benchmark for "good" is moving from having a compliant policy to producing evidence that the policy runs every day.
How should compliance teams respond?
Treat the enforcement gap as a countdown, not a reprieve. First, test your own FATF travel rule flows end to end: confirm that originator and beneficiary data is complete, accurate, screened against sanctions and PEP lists, and logged in a form an examiner can inspect. Second, map your counterparties by jurisdiction and note which regulators have started enforcing, so you can prioritise the relationships most likely to be tested. Third, tighten onboarding and ongoing monitoring against nested and offshore VASP typologies, and make sure your record-keeping produces an exportable trail rather than a policy PDF. Treat stablecoin and DeFi exposure as in scope until you have assessed it, not the reverse.
The identity layer underneath all of this is where a lot of firms lose evidence. Zyphe issues a reusable KYC credential: a customer verifies once through an NFC chip read with two-step liveness and no image upload, and that verified identity can be re-presented for each new VASP relationship, with data sharded so no single node holds a complete record and an exportable audit trail for every check. That gives a travel rule programme clean, current counterparty identity data and a defensible record without building a fresh honeypot. If that fits your roadmap, book a demo.
The bottom line
The seventh targeted update marks a turning point in tone. The global network has largely won the argument that virtual assets belong inside the FATF travel rule, and the legislative map is filling in. The unfinished work is supervision, and that is now where the pressure moves. For any firm running crypto onboarding, the practical lesson is to stop treating a compliant policy as the finish line and start producing daily evidence that identity, counterparty data and screening controls genuinely run, because the next round of scrutiny will ask to see it.
Cited sources
Michelangelo Frigo (Co-Founder at Zyphe) Michelangelo Frigo is a privacy and identity infrastructure expert and co-founder of Zyphe.