
The Financial Action Task Force (FATF) does not ban cryptocurrencies. Instead, FATF standards aim to bring crypto assets and virtual asset activities within an AML/CFT framework broadly comparable to rules applied to traditional financial institutions.
For exchanges, custodians, other asset service providers (VASPs), compliance can involve licensing or registration, customer due diligence, record keeping, sanctions controls, suspicious transaction reporting and the Travel Rule. The rules matter to crypto users because they can determine what customer information is requested when funds move between platforms.
FATF extended its anti money laundering and counter-terrorist financing framework to virtual assets and virtual asset service providers in 2019 through Recommendation 15 and related changes involving Recommendation 16.
The latest FATF 2026 implementation update found that 83% of surveyed jurisdictions had passed legislation implementing the Travel Rule, up from 73% in 2025; another 11 jurisdictions reported implementation under way. Significant gaps nevertheless remain in licensing, supervision and enforcement.
That uneven implementation creates the so-called sunrise issue: one VASP may face Travel Rule obligations while a counterparty VASP operates in a country where equivalent requirements are not yet enforced.
Under FATF's Recommendation 15, countries should assess illicit financing risks associated with assets and virtual asset activities and require covered VASPs to be licensed or registered and supervised.
Key FATF crypto requirements include:
| Area | FATF expectation |
|---|---|
| VASP regulation | Countries should identify, license or register and supervise virtual asset service providers VASPs. |
| AML/CFT | Compliance programs should combat money laundering, terrorist financing and sanctions evasion. |
| Due diligence | VASP due diligence includes customer identification, risk assessment and monitoring suspicious transactions. |
| Reporting | Covered businesses may face suspicious transaction reporting and record keeping requirements under local regulations. |
| Transfers | Virtual asset transactions must meet applicable FATF Travel Rule requirements, including originator and beneficiary information. |
| Counterparties | VASPs should assess counterparty VASPs rather than treating every crypto business as automatically trustworthy. |
The FATF virtual-assets framework also addresses illicit actors, P2P activity, stablecoins, offshore VASPs and DeFi. Peer-to-peer transactions are particularly challenging because no regulated intermediary may exist to transmit customer information.
The crypto Travel Rule adapts payment-transparency principles used for wire transfers and correspondent banking relationships to virtual currency transfers. FATF's Recommendation 16 requires information about the transmitting originator and beneficiary to accompany or otherwise be securely available for covered VA transfers.
For qualifying virtual asset transfers, originating and beneficiary financial institutions or VASPs may need information including:
originator name;
originator account number, wallet address or equivalent identifier;
originator address, national ID, customer number, or date and place of birth where required;
beneficiary name; and
beneficiary account number or wallet identifier.
The information does not necessarily travel on-chain with the crypto assets. VASPs can transmit information securely through separate systems while retaining a unique transaction reference linking the data to the transfer.
FATF allows countries to adopt a de minimis threshold no higher than USD/EUR 1,000 for certain virtual asset transfers. This should not be interpreted as a universal exemption below $1,000: FATF requirements still contemplate basic originator and beneficiary information, while local regulations may impose lower thresholds or no threshold.
Travel Rule compliance is only one part of AML/CFT. VASPs may also need ongoing due diligence, transaction monitoring, sanctions screening, suspicious transaction reporting and procedures for detecting criminal activity.
These controls help law enforcement agencies trace payments connected with money laundering and terrorist financing. Information can also help identify terrorist financiers, fraud networks and other illicit activities moving value between crypto assets, fiat currency and the traditional financial system.
FATF recommends a risk-based approach, meaning controls should reflect the customer, transaction, jurisdiction, product and counterparty risk rather than applying identical treatment to every transfer.
Implementation differs because FATF recommendations become operational through national laws rather than functioning as one global crypto statute. Different countries therefore impose different transaction thresholds, licensing systems, customer-information fields and enforcement practices.
FATF's July 2026 report says progress continues, but effective supervision remains uneven. The report highlights regulatory gaps involving offshore VASPs, stablecoins, P2P transactions through unhosted wallets, DeFi and organised financial crime.
This fragmentation increases compliance costs, especially for smaller money services businesses, while mass adoption increases the volume of financial transactions that compliance systems must process.
In the United States, the Financial Crimes Enforcement Network (FinCEN) applies the Bank Secrecy Act to covered money transmitters and money services businesses. The current federal funds Travel Rule threshold remains $3,000. A 2020 proposal sought to reduce the threshold to $250 for transfers beginning or ending outside the United States, but it should not be described as an enacted $250 rule.
The practical effect of Travel Rule requirements can also be seen in Gate's discussion of Travel Rule compliance when using cryptocurrency exchanges, where users may need to provide additional sender and recipient details before virtual asset transfers can proceed.
When depositing or withdrawing crypto, Gate.com users should check the information requested for the destination, sender, beneficiary and counterparty institution. Travel Rule requirements can vary by jurisdiction, transfer route and wallet type, so accurate account information can help avoid compliance delays.
Gate News also tracks changes in international implementation; FATF's latest finding that 83% of surveyed jurisdictions have Travel Rule legislation illustrates how quickly the regulatory landscape is changing.
FATF crypto standards require countries to address money laundering and counter-terrorist financing risks in virtual assets through VASP regulation, due diligence, reporting and transfer transparency. The FATF Travel Rule is central to that framework, but implementation is not identical worldwide. Users and VASPs therefore need to consider both FATF's international standards and the local laws governing each transaction.
No. FATF permits a maximum USD/EUR 1,000 de minimis threshold for certain requirements, but transfers below that amount are not automatically exempt from all information requirements, and jurisdictions can adopt stricter rules.
Required customer information can include the originator's and beneficiary's names, account or wallet identifiers, and specified originator identification information. VASPs must obtain, retain and transmit required information securely in accordance with applicable rules.
Travel Rule implementation requires compatible data-sharing systems, secure handling of customer information, counterparty VASP due diligence and compliance across jurisdictions with different rules. Uneven adoption creates the sunrise issue, particularly for cross-border transfers.
FATF standards primarily impose obligations through regulated intermediaries, but FATF guidance asks countries to assess illicit financing risks from P2P transactions and unhosted wallets. The absence of a VASP makes information collection and enforcement more difficult.
No. FATF's recommendation is to mitigate money laundering, terrorist financing and proliferation-financing risks by integrating covered virtual asset activities into national AML/CFT systems. Countries retain discretion over whether they regulate or prohibit particular virtual asset activities under their own laws.











