Join our Newsletter — 33% off our NHI Course

How should jurisdictions implement FATF Recommendation 15 for virtual assets and VASPs without creating gaps in AML/CFT supervision?

Jurisdictions should treat Recommendation 15 as a coordinated AML/CFT framework, not just a registration rule. That means conducting a risk assessment, licensing or registering VASPs, applying customer due diligence, enforcing the travel rule, and supervising activity in practice. The report also suggests using both quantitative and on-chain qualitative data to prioritise resources and measure whether implementation is actually effective.

How FATF Recommendation 15 Should Be Implemented Across the Full VASP Lifecycle

Recommendation 15 works best when jurisdictions treat virtual asset activity as an end-to-end regulated ecosystem rather than a one-time registration event. The practical question is not only who is on a register, but whether activity is being supervised, customer due diligence is happening, transfers are traceable where required, and firms can be held accountable when business models change or activity moves cross-border.

A workable implementation model starts with scope clarity. Jurisdictions need to define which virtual asset activities and which classes of provider fall within the regime, then align licensing, registration, fit-and-proper checks, recordkeeping, customer due diligence, transaction monitoring and reporting obligations so the same activity is not regulated in one channel and ignored in another. The goal is a single supervisory picture, not fragmented oversight.

That is why the FATF standard itself matters as the baseline reference for virtual asset regulation and AML/CFT obligations, including customer due diligence and suspicious activity reporting: FATF Recommendations. For jurisdictions building their own supervisory approach, the core design choice is to make registration only one control point inside a broader compliance architecture, not the whole architecture.

Supervision, Travel Rule Enforcement, and the Gaps That Commonly Open Up

The biggest implementation gaps usually appear where supervision is too formalistic or too narrow. A register can exist without real oversight of business models, outsourcing, cross-border provision, or dormant providers. Likewise, a jurisdiction can mandate CDD and the travel rule on paper while failing to test whether firms can actually exchange, retain, and act on the required data in production workflows.

Effective supervision therefore needs more than periodic filing. Supervisors should validate whether firms are identifying customers and beneficial owners where required, assessing source and destination risk, monitoring for suspicious patterns, and preserving evidence that travel rule obligations are operational rather than aspirational. Where VASPs rely on third parties, regulators also need to understand which obligations remain with the regulated entity and which controls are merely delegated.

For jurisdictions in the EU perimeter, the EBA’s AML/CFT materials are a useful supervisory reference for aligning expectations across institutions and for avoiding a split between policy design and actual control testing: EBA AML/CFT guidance. The practical lesson is that travel rule compliance, CDD, and transaction monitoring need to be verified as working controls, not assumed because they were written into policy.

Jurisdictions should also plan for failure modes such as unregistered providers, misclassified intermediaries, and firms moving activity into lightly supervised segments. Those are not edge cases, they are the main ways gaps form when supervision is fragmented across licensing, financial intelligence, and conduct oversight.

What Good Jurisdictional Design Looks Like in Practice

Good implementation uses risk-based prioritisation, measurable supervision, and clear enforcement pathways. That means jurisdictions should segment VASPs by inherent risk, service model, customer exposure, and geographic reach, then direct supervisory attention toward the firms and flows most likely to create AML/CFT exposure. Quantitative data is useful for volume and trend analysis, but qualitative on-chain analysis helps determine whether firms are actually detecting risky patterns, sanctions exposure, layering behaviour, or mule-like movement.

Jurisdictions should also coordinate supervision across licensing authorities, AML supervisors, and financial intelligence units so that registration data, suspicious activity reporting, and enforcement outcomes inform one another. Where that coordination is weak, the system tends to create blind spots: a firm can be licensed, but not meaningfully supervised; or supervised for conduct, but not tested for AML/CFT control effectiveness.

Practitioner takeaway: The strongest Recommendation 15 regimes are the ones that connect authorisation, customer due diligence, travel rule execution, and ongoing supervisory testing into one operating model, because gaps usually emerge at the handoffs between those functions.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

MITRE ATT&CK address the attack and risk surface, while NIST CSF 2.0 and CIS Controls v8 set the governance and control requirements practitioners need to meet.

Framework Control / Reference Relevance
NIST CSF 2.0 GV.OC-01 — Organizational Context Virtual asset supervision depends on clear jurisdictional scope and accountable regulatory ownership.
GV.RM-01 — Risk Management Strategy Recommendation 15 implementation should be risk-based and prioritise the highest-exposure VASP activity.
ID.RA-01 — Asset Vulnerabilities and Risk Assessment Jurisdictions need periodic risk assessment to understand where VASP supervision gaps may form.
Recommendation — Define the regulatory scope and supervisory ownership for VASPs before enforcing AML/CFT controls. Use a risk-based supervisory strategy to prioritise VASPs with the greatest AML/CFT exposure. Assess VASP risk drivers regularly and update supervisory focus when activity patterns change.
CIS Controls v8 Control 6 — Access Control Management VASPs need enforced access and customer control gates to reduce misuse and unsupported account activity.
Control 8 — Audit Log Management AML/CFT supervision depends on records that prove monitoring, reporting, and travel rule execution.
Recommendation — Enforce access governance and revocation processes for regulated virtual asset services. Collect and retain logs that demonstrate transaction monitoring and reporting activity.
MITRE ATT&CK T1657 — Financial Theft Virtual asset regimes are designed in part to reduce criminal monetisation and laundering through VASPs.
Recommendation — Map laundering and theft-related behaviours to detection and response playbooks.