Join our Newsletter — 33% off our NHI Course
Home FAQ Cyber Security What are the signs that R15 implementation is…
Cyber Security

What are the signs that R15 implementation is still incomplete in a jurisdiction?

← Back to all FAQ
By NHI Mgmt Group Editorial Team Updated September 17, 2026 Domain: Cyber Security

The clearest signs are practical gaps: no risk assessment, no framework requiring VASPs to register or license, no VASP supervision plan, no enforcement activity, or no enacted travel rule. The report shows these gaps remain common across the 58 jurisdictions reviewed. A jurisdiction can also look compliant on paper while still lacking evidence that supervision and controls are operating in practice.

How to tell R15 is incomplete in practice

The clearest sign is that the jurisdiction has adopted the language of implementation without the machinery that makes it real. If there is no documented risk assessment, no VASP registration or licensing framework, no supervision plan, no enforcement activity, or no travel rule in force, R15 is still partial even if policy statements exist. Compliance on paper is not the same as operating control.

A useful way to test maturity is to ask whether a regulator can show decision, oversight, and follow-through rather than only intent. A jurisdiction that cannot show how it identifies covered firms, supervises them, escalates breaches, and compels reporting has not completed the implementation cycle.

  • Look for a formal risk assessment that drives supervisory priorities, not a generic policy memo.
  • Check whether VASPs are actually registered, licensed, or otherwise brought into scope.
  • Confirm there is a named supervisor, an inspection or review process, and evidence of enforcement.
  • Verify whether the travel rule is enacted and whether firms are expected to exchange the required originator and beneficiary information.

Why paper compliance is the wrong test

R15 implementation becomes meaningful only when the legal requirement is matched by supervisory capacity and operational evidence. A jurisdiction can appear aligned with FATF expectations while still lacking the controls needed to detect non-compliance, investigate breaches, or create deterrence. That gap matters because virtual asset regulation is only as strong as the weakest point between rulemaking and enforcement.

In practice, incomplete implementation often shows up as fragmented responsibility. One agency may publish guidance while another has no licensing authority, no inspection cadence, or no enforcement record. That creates a false sense of coverage: the framework exists, but the jurisdiction cannot demonstrate that VASPs are being brought under effective oversight.

For readers tracing the broader control environment, the absence of operating evidence is the same basic warning sign that applies when a security control exists in policy but not in practice. FATF’s expectations are about implementation, not symbolism, and the gap is easiest to see when you compare what is written with what is actually supervised.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

DORA and NIS2 set the governance and control requirements practitioners need to meet.

FrameworkControl / ReferenceRelevance
DORAArt. 9 — Protection and PreventionImplementation gaps matter when legal requirements do not translate into operating controls.
Recommendation — Verify that written requirements are backed by operating controls and supervision evidence.
NIS2Art. 21 — Cybersecurity Risk-Management MeasuresThe question turns on whether required measures are actually implemented and enforced.
Recommendation — Confirm that required controls exist in practice, not only in policy or guidance.

Practitioner Guidance

What to verify: Treat the implementation question as evidence-based. Ask for the current legal basis, the list of licensed or registered VASPs, recent supervisory actions, and the latest public or internal assessment showing how the jurisdiction reached its R15 status.

Decision rule: If you cannot find both a functioning supervisory mechanism and at least some visible enforcement or review activity, classify the jurisdiction as materially incomplete even if it has published guidance or draft rules.

What practitioners underestimate: A jurisdiction may satisfy a checklist item while still failing the operational test. The most common mistake is assuming that enacted text equals effective implementation, when the real signal is whether firms are being monitored, challenged, and required to comply.

Practitioner takeaway: Judge R15 by the presence of living controls, not by the presence of policy language; if supervision, registration, enforcement, and travel-rule operation are not observable, implementation is still unfinished.

Deepen Your Knowledge

Sign up to our weekly newsletter — get 33% off our NHI Foundation Level Course

    NHIMG Editorial Note
    Reviewed and updated by the NHIMG editorial team on September 17, 2026.
    NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org