CryptaCount
EN
EnglishENDeutschDEEspañolESFrançaisFRItalianoIT日本語JA한국어KONederlandsNLPolskiPLPortuguêsPT
Log in Start Free

FATF 7th Targeted Update: What Accounting Firms and CFOs Must Act On Now

CryptaCount Editorial · · 9 min read
AML / KYC / LICENSING FATF 7th Targeted Update: WhatAccounting Firms and CFOs Must Act OnNow

The Financial Action Task Force released its seventh targeted update to Recommendation 15 on 16 July 2026, and the headline finding is deceptively simple: the world has passed more crypto laws, but is not enforcing them. For accounting firms, auditors, and CFOs with digital asset exposure, this update is not background reading. It redefines what regulators will expect from both supervised entities and their professional advisers going forward.

FATF 7th Targeted Update: What Accounting Firms and CFOs Must Act On Now

What the 7th Targeted Update Actually Measures

FATF surveys member jurisdictions annually on their adoption of Recommendation 15, the framework first published over seven years ago that sets out how nations should regulate virtual asset service providers (VASPs). The seventh update, covering 147 jurisdictions, shows headline improvement on almost every legislative metric.

The legislative gains

Risk assessments are now completed in 86% of jurisdictions, up from 76% in 2025. Legislation has been passed in 83% of jurisdictions, against 73% the prior year. The share of jurisdictions rated "Largely Compliant" rose from 29% to 34%. Among the 95 jurisdictions that require VASP licensing, 81% are now conducting supervisory inspections, up from 73%, and 71% have taken at least one enforcement action. These are genuine gains, not statistical noise.

Where the framework is breaking down

The enforcement picture is starkly different. Sixty percent of jurisdictions that have Travel Rule legislation on the books have taken zero supervisory or enforcement action on it. When FATF assessed preventive AML and counter-financing-of-terrorism measures, the controls meant to stop illicit activity before funds move rather than after, only 13 of 139 jurisdictions fully met the standard. That is fewer than 10%. The FATF's own language calls prevention "the greatest area of untapped potential in the entire R.15 framework."

Three structural gaps stand out. First, 73% of jurisdictions require VASP licensing, but only 58% have actually issued a single licence, and just 40% satisfactorily meet the licensing criterion in mutual evaluations. Second, 23% of jurisdictions now prohibit VASPs outright, up sharply from 11% in 2023, but the majority have "not progressed" on enforcement of that prohibition. Banning activity without monitoring it creates a regulatory blind spot where virtual asset activity continues outside any supervisory visibility. Third, 93% of jurisdictions have not identified so-called qualifying DeFi arrangements where an identifiable owner or operator exists and could be brought within VASP regulation. Only four jurisdictions have imposed licensing requirements on such arrangements; two have licensed one; one has enforced against any.

For firms managing clients active in DeFi or advising on DeFi treasury structures, that last data point matters: the absence of regulatory action is not the same as regulatory clarity, and FATF has now published supplemental guidance specifically to address DeFi. Firms should treat this as a signal that enforcement is coming, not a confirmation that it will not.

The update also introduces a notable structural change: the annexed survey results now include a dedicated column tracking stablecoin issuer licensing, reflecting the focus FATF established in its prior guidance on stablecoins. That column will be watched closely in future iterations.

Five Escalating Risk Areas Named by FATF

Beyond the compliance statistics, the update identifies five areas where the threat environment has materially worsened. Each carries direct implications for how firms conduct client due diligence and structure their own crypto accounting software workflows.

Industrialised fraud at scale

The FATF names Cambodia-based scam operations, including pig-butchering networks, as "significant generators of illicit proceeds." One conglomerate laundered at least USD 4 billion between August 2021 and January 2025, connecting organised crime, underground banking, and virtual-asset-based laundering. At least USD 37 million of that sum was attributed to DPRK cyber heists financing weapons-of-mass-destruction programmes. In Europe, Spain's Operation Borrelli dismantled a EUR 460 million investment fraud network affecting more than 5,000 victims across multiple countries. These are not fringe cases. They are the operating scale regulators now expect supervisors and VASPs to be equipped to detect.

Proprietary freeze-resistant stablecoins

This is arguably the most significant new risk flagged in the entire update, and it has direct implications for stablecoin due diligence. After a third-party issuer froze over USD 29 million in wallets linked to the Cambodia-based conglomerate, the same criminal network launched its own USD-pegged stablecoin, marketed explicitly as immune to asset freezing. It was issued across multiple public blockchains and a proprietary chain.

The FATF's warning to the private sector is explicit: VASPs "may be unable to rely on issuer-level asset freeze and burn mechanisms as a compliance safeguard" when dealing with stablecoins not issued by regulated, cooperative counterparties. The update also notes that terrorist organisations including ISIL and Al-Qaeda are increasingly favouring stablecoins over Bitcoin for fundraising and transfer, consistent with the broader trend of stablecoins accounting for a growing share of total illicit on-chain volume.

For accounting firms and CFOs, the practical implication is immediate: stablecoin holdings on client or corporate balance sheets need to be assessed not just for valuation and liquidity risk, but for the AML profile of the issuer itself. Firms relying on digital asset accounting software that tracks stablecoin positions should verify whether those systems flag issuer-level risk attributes, not just token price.

AI as a structural amplifier

FATF frames artificial intelligence not as a standalone technical curiosity but as "a structural factor that can amplify money laundering, terrorist financing, and sanctions-evasion risks." The cases cited include deepfake-powered recruitment scams exceeding USD 1 million in losses, AI-assisted development of smart contract exploits, and use of open-weight AI models to bypass commercial content safeguards. AI impersonation scams have been identified separately as the fastest-growing fraud subcategory in recent reporting periods. For firms conducting client onboarding and KYC, this means identity verification processes that were adequate two years ago may no longer withstand a deepfake-capable threat environment. Enhanced liveness checks and corroborating identity documentation are no longer optional best practice.

Convergence of proliferation financing, terrorist financing, and sanctions evasion

The FATF is explicit that these three threat categories should no longer be treated as separate risk silos. They share infrastructure, including VASP accounts, DeFi protocols, network nodes, and multi-party security systems. The DPRK in particular is identified as exploiting not just VASPs and DeFi but the underlying technical infrastructure those platforms depend on. For firms conducting sanctions screening on digital asset clients, this convergence means a single risk event may simultaneously trigger AML reporting obligations, sanctions exposure, and proliferation financing red flags. Compliance workflows need to be designed to catch all three, not just the most obvious one.

Offshore VASPs and peer-to-peer gaps

Offshore VASPs are actively soliciting customers in jurisdictions where they are not licensed, advising clients to use VPNs to obscure their location, and operating nested accounts that make them appear to regulators as retail users rather than VASPs. Meanwhile, 88% of jurisdictions rate peer-to-peer activity via unhosted wallets as high risk, yet only 23% collect any metrics on it. For firms advising clients who transact through unhosted wallets or offshore platforms, these data points confirm that the absence of a licensing requirement in a given channel does not mean the activity falls below the AML threshold.

What FATF Now Expects from Supervisors and the Private Sector

The update's recommendations to both regulators and the private sector are more operationally specific than previous editions, which matters for how accounting firms interpret client obligations.

Supervisory expectations

Jurisdictions are expected to close the gap between having a licensing requirement and actually issuing licences. That means conducting real on-site and off-site inspections, actively identifying entities operating without a licence, and taking enforcement action when violations are found. FATF is also explicit that supervisors themselves need to use on-chain data. Regulators who lack the tools to trace flows, assess risk, and evidence their findings will struggle to demonstrate the effective implementation the FATF is now demanding. This has a secondary implication for firms: regulators armed with on-chain analytics will increasingly identify discrepancies between what clients report and what the blockchain records show.

Private sector technical expectations

FATF's recommendations to the private sector explicitly list wallet screening, blacklisting and whitelisting, blockchain analytics tools, and freezing and blocking capabilities as expected components of a compliant AML framework. These are no longer framed as advanced or optional capabilities. They are baseline expectations. For accounting firms advising VASPs on compliance programme design, and for CFOs evaluating whether their firm's crypto bookkeeping software integrates with these tools, this language sets the minimum bar the next round of mutual evaluations will test against.

The update also reinforces a point that practitioners often underestimate: blockchain's on-chain transparency is an AML advantage, not just a complication. Unlike traditional finance, where transaction visibility depends on intermediary reporting after the fact, crypto transactions are visible in real time. Firms and supervisors that deploy screening and analytics proactively, before funds move rather than after, are better positioned both for compliance and for demonstrating effective implementation to examiners.

Firms that already have structured crypto compliance programmes should treat this update as a prompt to review whether their digital asset accounting software produces audit trails that would satisfy a FATF-aligned examination. Those that are still working from spreadsheets or manual processes face a more urgent remediation timeline than the headline legislative statistics might suggest.

For context on how these obligations interact with regional frameworks, see our analysis of MiCA transitional period compliance obligations for CASPs and our breakdown of the Travel Rule obligations in Taiwan: the October 2026 deadline.

FATF 7th Targeted Update: What Accounting Firms and CFOs Must Act On Now

Accounting and Audit Implications: A Practical Checklist

The FATF update does not create new legal obligations directly. It signals where the next wave of regulatory examinations will focus, and that signal is worth translating into concrete internal actions.

For accounting firms and auditors

  • Assess whether client VASPs have moved from paper licensing to active supervisory engagement, including documented inspections and enforcement readiness.
  • Review stablecoin holdings in client accounts for issuer AML profile, not just price stability. Stablecoins issued by entities without robust freeze and burn mechanisms now carry a distinct compliance risk layer.
  • Verify that KYC procedures can withstand AI-generated identity fraud, including deepfake video and synthetic documentation.
  • Confirm that Travel Rule compliance is operationally active, not just policy-documented. The FATF's finding that 60% of jurisdictions with Travel Rule laws have taken no supervisory action means enforcement catch-up is likely.
  • Document on-chain data sources used in client risk assessments. Examiners will increasingly expect firms to show their working, not just their conclusions.

For CFOs with digital asset treasury exposure

  • If the corporate treasury holds stablecoins, confirm the issuer is subject to AML and CFT regulation and cooperates with law enforcement freeze requests.
  • Evaluate whether your crypto bookkeeping software or digital asset accounting software produces transaction records sufficient for a regulatory examination, including counterparty data and wallet screening outputs.
  • If any treasury activity involves DeFi protocols, assess whether those protocols have an identifiable operator and whether that operator is licensed in any jurisdiction. FATF's guidance on qualifying DeFi arrangements is now a live document.
  • Review sanctions screening coverage for all digital asset counterparties, including offshore exchanges and unhosted wallet interactions.

Source: Chainalysis

GLOBALOECD#stablecoins#defiEnforcementAML/KYC & Licensing

FAQ

What is the FATF 7th Targeted Update and why does it matter for accounting firms?

It is the seventh annual progress report on how well jurisdictions are implementing FATF Recommendation 15, the global standard for regulating virtual asset service providers. It matters for accounting firms because it signals where regulatory examinations will focus next: preventive AML measures, stablecoin issuer due diligence, DeFi identification, and Travel Rule enforcement are all areas where the FATF found significant gaps in 2026.

What does FATF say about freeze-resistant stablecoins?

FATF warns that criminal networks have launched stablecoins specifically marketed as immune to asset freezing, issued across multiple blockchains to avoid a single point of control. The FATF advises that VASPs cannot rely solely on issuer-level freeze and burn mechanisms as a compliance safeguard when those mechanisms may not exist or may not be enforceable.

How does the Travel Rule enforcement gap affect VASP clients?

Sixty percent of jurisdictions that have Travel Rule legislation have not yet taken supervisory or enforcement action on it. This means VASP clients operating in those jurisdictions may have under-invested in Travel Rule compliance. Accounting firms should treat this as a leading indicator of upcoming enforcement catch-up rather than continued tolerance.

What does FATF expect from private sector firms in terms of technical tools?

The update explicitly lists wallet screening, blacklisting and whitelisting, blockchain analytics, and freezing and blocking capabilities as expected baseline components of a compliant AML framework. These are no longer described as advanced optional features. Firms advising VASPs should verify that client compliance programmes include all of these capabilities.

Does the FATF update change anything for DeFi treasury activity?

Not directly in terms of new law, but it reinforces that 93% of jurisdictions have not yet identified qualifying DeFi arrangements for regulation. FATF has published supplemental guidance on this and the trend is toward broader identification. CFOs using DeFi protocols in treasury operations should assess whether those protocols have identifiable operators and monitor whether licensing requirements emerge in their key jurisdictions.

Related articles

AML/KYC & Licensing
FATF's 7th Crypto Report Card: The Enforcement Gap Is Now the Central Problem
AML/KYC & Licensing
FATF Urges Faster Crypto AML Enforcement as Stablecoin Crime Grows
AML/KYC & Licensing
OFAC Sanctions DPRK IT-Worker Scheme Facilitator: What Accounting Firms and CFOs Must Act On Now
AML/KYC & Licensing
Digital Asset AML and Sanctions: BDO's Best Practices for Firms