Join our Newsletter — 33% off our NHI Course

Recommendation 15

Recommendation 15 is FATF’s AML/CFT standard for virtual assets and virtual asset service providers. It requires countries to regulate and supervise the sector, including customer due diligence, licensing or registration, and travel rule obligations. In practice, it is the main global benchmark for bringing crypto activity into formal financial crime controls.

What Recommendation 15 Covers in Practice

Recommendation 15 is the FATF rule set that brings virtual assets and virtual asset service providers into the same basic compliance logic used for other regulated financial activity. Its practical effect is to move crypto activity from a purely technical or platform issue into a supervised control environment.

The standard matters because it translates AML/CFT expectations into concrete sector obligations: firms need customer due diligence, licensing or registration where required, and controls that can support transaction traceability. That makes the recommendation less about the asset class itself and more about whether the organisation can identify customers, understand risk, and maintain records that regulators can rely on.

Why the Travel Rule and Due Diligence Matter

The best-known operational feature of Recommendation 15 is the travel rule expectation for originator and beneficiary information to follow qualifying transfers. In practice, that creates a compliance bridge between counterparties, payment flows, and recordkeeping, so the transfer is not treated as an anonymous value movement.

Customer due diligence is equally central because virtual asset activity can scale quickly across wallets, exchanges, custodians, and intermediaries. A FATF Recommendations, AML and KYC Framework perspective is useful here because Recommendation 15 sits inside the wider FATF model for knowing customers, understanding beneficial ownership, and monitoring suspicious activity.

How Regulation and Supervision Change the Sector

Recommendation 15 is not just a paper standard, it depends on national adoption, licensing, supervision, and enforcement. That means the same crypto business can face very different obligations depending on jurisdiction, but the underlying expectation remains consistent, regulated actors should be identifiable, accountable, and subject to oversight.

This is why the recommendation shapes product design and operating model decisions. Firms that handle virtual assets need onboarding, monitoring, screening, record retention, and reporting processes that can stand up to supervisory review. For technical teams, this often becomes a cross-functional problem involving compliance, operations, data engineering, and risk management rather than a single control owner.

Where Recommendation 15 Commonly Fails

The hardest part of implementing Recommendation 15 is usually not writing a policy, it is making sure the controls work across fragmented ecosystems. Virtual asset transfers can involve multiple platforms, self-hosted wallets, chain analytics tools, and third-party service providers, which can create blind spots in attribution, monitoring, and evidence retention.

That is why industry control discussions often map to broader safeguards such as NIST Cybersecurity Framework 2.0 for governance and response, and to technical hardening of identity and access paths where transaction systems and compliance tooling depend on secure credentials. For implementation detail on cryptographic trust and token handling, NIST SP 800-57 Key Management is a useful companion reference.

Risk and Threat Considerations

Recommendation 15 concentrates financial crime risk into a sector that can move value quickly, cross borders, and rely on pseudonymous infrastructure. Weak customer due diligence, poor travel rule implementation, or uneven supervision can make it easier for sanctioned actors, laundering networks, or fraud operations to obscure source and destination.

Failure mechanism: Controls break when platforms cannot reliably tie transfers to verified parties, cannot exchange required originator and beneficiary data, or cannot preserve records that support investigations and reporting.

Impact: The result is higher exposure to money laundering, sanctions evasion, fraud proceeds movement, and regulatory action against firms that cannot demonstrate effective compliance.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

NIST CSF 2.0 and CIS Controls v8 set the governance and control requirements practitioners need to meet.

Framework Control / Reference Relevance
NIST CSF 2.0 GV — Govern Recommendation 15 depends on governance, oversight, and accountability for regulated virtual asset controls.
Recommendation — Assign oversight for virtual asset AML/CFT controls and validate supervision, policy, and accountability regularly.
CIS Controls v8 5 — Account Management Recommendation 15 relies on knowing and managing who can access regulated transfer and compliance systems.
6 — Access Control Management Virtual asset compliance depends on limiting access to customer, transaction, and reporting data.
Recommendation — Enforce strong account lifecycle controls for systems that support virtual asset compliance and reporting. Restrict access to virtual asset compliance data and tools to approved roles with least privilege.

Practitioner Guidance

Why practitioners should care: Recommendation 15 is a governance test as much as a compliance rule, because it forces organisations to prove that virtual asset activity can be supervised with the same discipline expected in other regulated financial channels. Teams should treat travel rule readiness, onboarding evidence, and transaction traceability as operational controls, not just legal obligations.

Practitioner takeaway: The strongest implementations make compliance data, customer identity evidence, and transfer metadata part of the operating design rather than an after-the-fact manual review.