
Why legislation, licensing and the Travel Rule matter only when supervision works in practice
Virtual asset regulation has expanded significantly over the past several years.
More jurisdictions now require virtual asset service providers to be licensed or registered. Risk assessments are becoming more common. The Travel Rule is entering national legislation, and regulators have developed increasingly detailed expectations around customer due diligence, transaction monitoring, sanctions screening and suspicious activity reporting.
On paper, the direction looks encouraging.
In practice, the global compliance framework remains uneven.
The Financial Action Task Force’s latest targeted review shows that the central challenge is no longer only the absence of rules. It is the gap between formally adopting those rules and making them operational through licensing, supervision, enforcement and cross-border cooperation.
Legislation is advancing
Travel Rule implementation offers the clearest evidence of regulatory progress.
The rule requires financial institutions and VASPs to obtain, retain and securely transmit specified information about the originator and beneficiary of a virtual asset transfer. Its purpose is similar to payment-transparency requirements in traditional finance: regulated firms should know who is sending value, who is receiving it and whether the transaction presents a financial-crime risk.
According to FATF’s 2026 survey, 91 of 109 responding jurisdictions—83%—had passed legislation implementing the Travel Rule. This represents an increase from 73% in 2025, while another 11 jurisdictions reported that implementation was under way.
That is meaningful progress.
However, legislation alone does not confirm that firms are complying, that supervisors can assess them effectively or that violations produce consequences.
The enforcement gap
Among the 91 jurisdictions that had introduced Travel Rule legislation, 55—approximately 60%—had not yet issued findings or directives or taken supervisory or enforcement action focused on Travel Rule compliance.
Some of this can be explained by timing. Many frameworks are relatively new, and authorities may still be developing supervisory procedures, training staff and engaging with regulated firms.
But the gap remains important.
A requirement that is rarely tested can become a documentation exercise rather than an effective financial-crime control. Providers may maintain formal policies without consistently obtaining complete information, validating counterparties, handling missing data or escalating higher-risk transfers.
FATF therefore argues that jurisdictions must move from adoption to operationalisation, including effective supervision and enforcement where firms fail to comply.
Risk assessments must lead to action
The same problem appears in national risk assessments.
Eighty-six per cent of responding jurisdictions reported that they had assessed money-laundering, terrorist-financing or proliferation-financing risks associated with virtual assets and VASPs. That is a substantial increase from the previous year.
Yet FATF found that many jurisdictions still struggle to convert those assessments into practical risk-based controls, supervisory priorities and enforcement measures.
This distinction matters.
A risk assessment should influence which activities require closer scrutiny, which providers are inspected first, which transaction patterns trigger concern and where additional reporting or restrictions may be justified.
If the assessment does not change supervisory behaviour, it provides limited protection.
Effective regulation requires a full chain:
risk identification → regulatory requirements → provider controls → supervisory testing → remediation or enforcement.
Weakness at any point can create space for regulatory arbitrage.
Global compliance remains uneven
Of the 149 jurisdictions assessed for compliance with FATF Recommendation 15, 34% were rated largely compliant as of April 2026, up from 29% in 2025. Another 43% were partially compliant, while 22% remained non-compliant.
Only one jurisdiction was rated fully compliant.
These figures should be interpreted carefully. FATF’s survey responses were self-reported and were not independently verified, while the organisation inferred that the 58 jurisdictions that did not respond had made no progress.
Even with that methodological limitation, the overall picture is clear: implementation is improving, but it remains fragmented.
Virtual assets move across borders almost instantly. Regulation still operates through national licensing, supervisory and enforcement systems. A weakness in one jurisdiction can therefore affect firms and customers far beyond its borders.
Offshore providers remain a structural challenge
Offshore VASPs are central to this problem.
A provider may be incorporated in one jurisdiction, operate its technology from another and serve customers across many additional markets without maintaining a meaningful local presence.
When the provider is based in a jurisdiction with limited regulation or weak supervision, host-country authorities may struggle to obtain information, enforce requirements or protect customers.
FATF also describes cases in which offshore providers solicit customers in restricted markets, recommend the use of VPNs or false information, or compete through lower KYC requirements and reduced compliance costs. Some gain indirect access to liquidity and fiat services through accounts held with regulated onshore institutions while presenting themselves as ordinary retail customers.
This makes counterparty due diligence increasingly important.
A provider’s website availability does not confirm that it is legally authorised to serve customers in a particular jurisdiction. Businesses need to examine the licensing entity, geographic permissions, contractual counterparty and underlying providers used for custody, liquidity and fiat access.
Financial crime is becoming more industrialised
The new FATF report also describes a more organised and interconnected financial-crime environment.
Large fraud networks increasingly combine social engineering, fraudulent investment platforms, bank transfers, OTC brokers, payment gateways, exchange accounts and chains of unhosted wallets. FATF reports that some operations generate multi-billion-dollar proceeds annually and move funds through several jurisdictions and service providers.
The problem is therefore not accurately described as “crypto crime” existing separately from traditional finance.
Many schemes move between bank accounts, shell companies, payment firms, virtual assets, OTC intermediaries and informal financial networks. The compliance challenge lies at the points where those systems connect.
This requires more than blockchain analytics.
Firms need to combine on-chain indicators with customer behaviour, counterparties, device and access data, source-of-funds evidence, payment information and the commercial purpose of the transaction.
Stablecoins create a new control question
FATF also highlights increasing misuse of stablecoins.
One particularly notable case involved a proprietary dollar-pegged stablecoin reportedly designed to resist freezing and remain outside conventional regulatory oversight. FATF contrasts this with legitimate issuers that can block or freeze assets when acting on lawful requests from competent authorities.
This raises a difficult policy question.
The ability to freeze tokens can support sanctions enforcement, fraud recovery and criminal investigations. At the same time, it introduces centralisation, governance and due-process concerns.
For regulated businesses, the practical issue is whether an issuer has a clear legal entity, transparent reserve arrangements, credible AML controls and documented procedures for responding to lawful blocking, freezing and seizure orders.
The label “stablecoin” alone says very little about the quality of the compliance structure behind it.
What regulated firms should do
FATF’s findings do not mean that every VASP needs to rebuild its compliance programme. They do suggest that authorities will increasingly expect evidence of effective operation rather than policies alone.
Providers should be able to demonstrate:
- how Travel Rule data is collected, validated and securely transmitted;
- how transfers involving missing or unreliable information are handled;
- how counterparties and offshore VASPs are assessed;
- how unhosted-wallet exposure affects transaction risk;
- how sanctions, blockchain analytics and customer information are combined;
- how alerts lead to investigations, escalation and regulatory reporting;
- how control effectiveness is tested and documented.
The distinction between having a control and proving that it works will become increasingly important.
What businesses should check
Companies using virtual asset providers also have compliance responsibilities of their own.
Provider selection should include more than pricing, liquidity and product functionality. Businesses should verify the legal entity delivering the service, its authorisation status, supported jurisdictions, Travel Rule capabilities, banking relationships and approach to sanctions and transaction monitoring.
They should also understand whether the provider relies on offshore entities, nested accounts or third-party liquidity arrangements that could create additional exposure.
Even where the provider performs customer-facing AML checks, the business still needs enough transaction data and internal evidence to explain its own payments, treasury movements and counterparties.
Outsourcing the transaction does not fully outsource the risk.
MetaNord’s view
At MetaNord, we see the latest FATF report as a reminder that compliance maturity cannot be measured only by the number of regulations adopted or licences issued.
The more meaningful test is whether controls work inside real operating flows.
A compliant digital asset transaction needs more than an approved provider. It requires reliable counterparty information, transaction visibility, escalation procedures, reconciliation data and an evidence trail that can support internal review, banking relationships, audit and regulatory scrutiny.
Rules establish the perimeter.
Supervision and enforcement give that perimeter credibility.
For the virtual asset market, closing the distance between the two is now one of the most important compliance challenges.
See where MetaNord fits in your payment workflow.
Review the systems around your payment flow, from provider connections through to reconciliation and operating handover.


