The clearest signs are practical gaps: no risk assessment, no framework requiring VASPs to register or license, no VASP supervision plan, no enforcement activity, or no enacted travel rule. The report shows these gaps remain common across the 58 jurisdictions reviewed. A jurisdiction can also look compliant on paper while still lacking evidence that supervision and controls are operating in practice.
How to tell R15 is incomplete in practice
The clearest sign is that the jurisdiction has adopted the language of implementation without the machinery that makes it real. If there is no documented risk assessment, no VASP registration or licensing framework, no supervision plan, no enforcement activity, or no travel rule in force, R15 is still partial even if policy statements exist. Compliance on paper is not the same as operating control.
A useful way to test maturity is to ask whether a regulator can show decision, oversight, and follow-through rather than only intent. A jurisdiction that cannot show how it identifies covered firms, supervises them, escalates breaches, and compels reporting has not completed the implementation cycle.
- Look for a formal risk assessment that drives supervisory priorities, not a generic policy memo.
- Check whether VASPs are actually registered, licensed, or otherwise brought into scope.
- Confirm there is a named supervisor, an inspection or review process, and evidence of enforcement.
- Verify whether the travel rule is enacted and whether firms are expected to exchange the required originator and beneficiary information.
Why paper compliance is the wrong test
R15 implementation becomes meaningful only when the legal requirement is matched by supervisory capacity and operational evidence. A jurisdiction can appear aligned with FATF expectations while still lacking the controls needed to detect non-compliance, investigate breaches, or create deterrence. That gap matters because virtual asset regulation is only as strong as the weakest point between rulemaking and enforcement.
In practice, incomplete implementation often shows up as fragmented responsibility. One agency may publish guidance while another has no licensing authority, no inspection cadence, or no enforcement record. That creates a false sense of coverage: the framework exists, but the jurisdiction cannot demonstrate that VASPs are being brought under effective oversight.
For readers tracing the broader control environment, the absence of operating evidence is the same basic warning sign that applies when a security control exists in policy but not in practice. FATF’s expectations are about implementation, not symbolism, and the gap is easiest to see when you compare what is written with what is actually supervised.
Standards & Framework Alignment
This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.
DORA and NIS2 set the governance and control requirements practitioners need to meet.
| Framework | Control / Reference | Relevance |
|---|---|---|
| DORA | Art. 9 — Protection and Prevention | Implementation gaps matter when legal requirements do not translate into operating controls. |
| Recommendation — Verify that written requirements are backed by operating controls and supervision evidence. | ||
| NIS2 | Art. 21 — Cybersecurity Risk-Management Measures | The question turns on whether required measures are actually implemented and enforced. |
| Recommendation — Confirm that required controls exist in practice, not only in policy or guidance. | ||
Practitioner Guidance
What to verify: Treat the implementation question as evidence-based. Ask for the current legal basis, the list of licensed or registered VASPs, recent supervisory actions, and the latest public or internal assessment showing how the jurisdiction reached its R15 status.
Decision rule: If you cannot find both a functioning supervisory mechanism and at least some visible enforcement or review activity, classify the jurisdiction as materially incomplete even if it has published guidance or draft rules.
What practitioners underestimate: A jurisdiction may satisfy a checklist item while still failing the operational test. The most common mistake is assuming that enacted text equals effective implementation, when the real signal is whether firms are being monitored, challenged, and required to comply.
Practitioner takeaway: Judge R15 by the presence of living controls, not by the presence of policy language; if supervision, registration, enforcement, and travel-rule operation are not observable, implementation is still unfinished.
Related resources from NHI Mgmt Group
- What are the signs that an OAuth 2.0 implementation is still carrying security debt?
- Why do phishing attacks still succeed even when people know the warning signs?
- Why do IAM programmes still fail even after tool implementation?
- Who is accountable when active exploitation is known but enrichment is still incomplete?
Deepen Your Knowledge
Reviewed and updated by the NHIMG editorial team on September 17, 2026.
NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org