VASP-mediated transactions involve a virtual asset service provider acting as an intermediary, while peer to peer transactions move directly between parties without a VASP in the middle. FATF standards currently apply to VASP activity, which makes identification, recordkeeping, and information sharing more practical. Peer to peer transfers are harder to govern, which is why analytics and risk-based monitoring matter.
How VASP-mediated and peer-to-peer transfers differ in FATF compliance
VASP-mediated transfers sit inside a regulated intermediary relationship, so FATF-style compliance can attach to the service provider’s onboarding, monitoring, recordkeeping, and information-sharing duties. Peer-to-peer transfers happen without that intermediary layer, which makes the compliance problem less about the provider and more about visibility, attribution, and risk-based detection across the transaction flow.
Why the intermediary changes the compliance model
When a virtual asset service provider stands between the sender and recipient, the provider becomes the practical compliance choke point. That is where customer due diligence, screening, transaction monitoring, travel-rule style information exchange, and suspicious activity escalation are most feasible. This is also why FATF guidance focuses so heavily on regulated virtual asset businesses rather than on every direct wallet-to-wallet transfer.
By contrast, peer-to-peer transfers remove that intermediary control point. The transfer may still be observable on-chain or through related infrastructure, but there is no obligated VASP in the middle to collect identity data, enrich records, or enforce policy at the point of execution. The compliance burden shifts toward perimeter controls, blockchain analytics, and risk scoring around the participants and surrounding activity.
What changes operationally for compliance teams
The key difference is not simply who sends value, but what evidence is available and who can be asked to act on it. In a VASP-mediated transaction, the institution can usually link an account to a customer profile and apply governance to the transfer event. In a peer-to-peer transfer, compliance teams often have to infer risk from patterns, counterparties, exposure to hosted services, address reuse, typologies, and linkages to known entities rather than from a direct customer record.
That difference affects controls. VASP flows are better suited to rules, thresholds, and case management because the provider can interrupt or review the transaction. Peer-to-peer flows are better suited to intelligence-led monitoring because the control point is external to the transfer itself. Both still need documentation, but the quality and completeness of the evidence base are very different.
How FATF treatment affects practical enforcement
The FATF Recommendations and virtual asset standards are built around risk-based supervision, customer due diligence, and information sharing by intermediaries that can reasonably perform those duties. That means a VASP is usually the primary compliance actor, while a pure peer-to-peer transfer is harder to bring into the same workflow unless another regulated touchpoint exists.
This does not make peer-to-peer activity “outside compliance.” It means the compliance model changes from direct intermediary obligations to detection, investigation, and source-of-funds or counterparty-risk assessment where a regulated business has visibility. In practice, the main question becomes whether the organisation can establish enough context to justify action under its risk-based policy.
Risk and Threat Considerations
Peer-to-peer transfers create more room for opacity, attribution gaps, and layering behaviour because no VASP is required to hold the transaction metadata that a supervised intermediary would normally capture. That makes them attractive when the objective is to reduce traceability, fragment value movement, or bypass controls tied to customer relationships.
Failure mechanism: The compliance failure occurs when organisations treat the absence of a VASP as equivalent to low risk, or when they rely on incomplete on-chain data without compensating analytics and escalation paths.
Impact: The result can be missed suspicious activity, weak source-of-funds assessment, poor recordkeeping, and inconsistent application of FATF-aligned controls across different transaction types.
Standards & Framework Alignment
This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.
NIST CSF 2.0 and NIST SP 800-53 Rev 5 set the technical controls, while ISO/IEC 27001:2022 and GDPR define the regulatory obligations.
| Framework | Control / Reference | Relevance |
|---|---|---|
| NIST CSF 2.0 | GV.RM-01 — Risk Management Strategy | FATF compliance differences depend on a risk-based model for intermediary and peer-to-peer flows. |
| Recommendation — Apply GV.RM-01 to distinguish monitored VASP flows from higher-uncertainty peer-to-peer transfers. | ||
| NIST SP 800-53 Rev 5 | AU-6 — Audit Record Review, Analysis, and Reporting | VASP-mediated transfers rely on reviewable records and escalation of suspicious activity. |
| IA-5 — Authenticator Management | VASP-mediated compliance depends on account and credential governance for customer-facing access. | |
| AC-6 — Least Privilege | Only a limited set of roles should approve, review, or override virtual asset transaction decisions. | |
| Recommendation — Use AU-6 to review transaction evidence and escalate anomalous virtual asset activity. Use IA-5 to govern credentials that link users to transaction records and actions. Use AC-6 to restrict who can approve, review, or override transaction cases. | ||
| ISO/IEC 27001:2022 | A.5.15 — Access control | Access control supports who may view, alter, or approve regulated transaction records. |
| Recommendation — Apply A.5.15 to limit access to customer and transaction evidence. | ||
| GDPR | Art. 5 — Principles relating to processing of personal data | Where identity data is processed for VASP monitoring, data use must remain purpose-limited and documented. |
| Recommendation — Align monitoring data use with Art. 5 purpose limitation and minimisation. | ||
Practitioner Guidance
What to prioritise: Separate “regulated intermediary present” from “low risk” in your operating model. A VASP-mediated transfer should trigger standard customer and transaction controls, while a peer-to-peer transfer should trigger a different evidence standard, not an automatic pass.
What to verify: Confirm whether your monitoring logic actually distinguishes provider-mediated flows, self-hosted activity, and direct wallet-to-wallet movement. If those cases collapse into one rule set, the program will either over-alert or miss the highest-friction scenarios.
Practitioner takeaway: The important distinction is evidentiary, not just technical: VASP-mediated activity gives compliance a controllable intermediary, while peer-to-peer activity forces the programme to rely more heavily on analytics, context, and documented risk judgment.
Related resources from NHI Mgmt Group
- What is the difference between design effectiveness and operating effectiveness in compliance audits?
- What is the difference between policy compliance and evidence-based compliance for AI systems?
- What is the difference between compliance metrics and identity value metrics?
- What is the difference between compliance-driven identity control and threat-centric identity control?
Deepen Your Knowledge
Reviewed and updated by the NHIMG editorial team on September 25, 2026.
NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org