FATF's 7th Crypto Report Card: The Enforcement Gap Is Now the Central Problem
The Financial Action Task Force released its seventh targeted update on virtual assets and virtual asset service providers on 16 July 2026, and the headline finding is uncomfortable: the global regulatory community has made genuine legislative progress, but enforcement is not keeping pace. For accounting firms, auditors, and CFOs operating in the digital asset space, that gap is not an abstraction. It shapes the supervisory scrutiny your clients face, the AML controls you are expected to embed in crypto compliance reporting workflows, and the liability exposure that comes with getting it wrong.
What the FATF's Survey of 147 Jurisdictions Actually Shows
The FATF surveyed 147 jurisdictions to produce this report card. The headline numbers are encouraging on the surface. Jurisdictions that have completed a virtual asset risk assessment rose from 76% in 2025 to 86% this year. Those with legislation in place climbed from 73% to 83%. The share rated "Largely Compliant" moved from 29% to 34%. Among the 95 jurisdictions that require VASP licensing, 81% are now conducting supervisory inspections, up from 73%, and 71% have taken at least some enforcement action.
That trajectory is real. Jurisdictions that committed to licensing frameworks are increasingly following through, which matters for any firm advising clients who operate across multiple markets.
Where the Numbers Fall Apart
Look past the headline percentages and the picture changes. Sixty percent of jurisdictions that have Travel Rule legislation on the books have not yet taken any supervisory or enforcement action against non-compliant VASPs. The Travel Rule, which requires originating and beneficiary institutions to share counterparty data on transfers above a threshold, has been part of the FATF standard since 2019. Seven years in, the majority of legislating jurisdictions are still not enforcing it.
The preventive controls gap is starker still. When FATF assessed how well jurisdictions meet the AML/CFT preventive measures criterion, only 13 out of 139 — fewer than 10% — fully satisfied the standard. These are the proactive controls designed to stop illicit flows before they move, not after. Screening, blocking, and flagging at the point of transaction rather than reconstructing trails post-incident. The FATF's own framing: prevention is the greatest area of untapped potential across the entire Recommendation 15 framework.
There is also a structural disconnect between licensing requirements and their practical application. While 73% of jurisdictions require VASP licensing, only 58% have actually issued a licence to at least one entity. Only 40% satisfactorily meet that criterion in mutual evaluations. Requiring something and operationalising it are two different things, and the FATF is no longer treating that distinction as acceptable.
Three Structural Gaps the Report Explicitly Flags
Prohibition Without Monitoring Creates Blind Spots
Twenty-three percent of jurisdictions now prohibit VASPs outright, up from 11% in 2023. The FATF's concern is not the prohibition itself but what follows: most of those jurisdictions have "not progressed" in enforcement. Banning activity without an active monitoring regime does not eliminate the activity. It pushes it into opacity. The report is direct on this point: every jurisdiction, including those that have banned VASPs, is expected to assess its virtual asset exposure comprehensively. Domestic VASPs, offshore VASPs soliciting local customers, stablecoin issuers, qualifying DeFi arrangements, peer-to-peer activity via unhosted wallets, and new business models must all be accounted for.
DeFi Classification Remains Almost Entirely Unresolved
Ninety-three percent of jurisdictions have not identified what the FATF calls "qualifying DeFi arrangements," meaning protocols where there is an identifiable owner or operator who can be brought within a VASP licensing regime. Only four jurisdictions have imposed any licensing requirement on such arrangements, two have issued at least one licence, and one has taken enforcement action. The FATF has issued supplementary guidance to help jurisdictions work through the classification question, but the practical result is that an enormous share of DeFi activity sits outside any regulatory perimeter globally. For firms advising clients who interact with DeFi protocols, this is not a future risk. It is a present one, and the direction of travel from the FATF is clear: FATF's guidance on centralised elements in DeFi and VASP classification has been tightening for two years.
Stablecoin Issuers Now Have Their Own Tracking Column
The report's annexed survey table now includes a dedicated column for stablecoin issuer licensing, a structural change that signals how seriously the FATF is treating stablecoin-specific risks. Terrorist organisations including ISIL and Al-Qaeda have shifted toward stablecoins for fundraising and transfer, favouring their liquidity and convertibility over Bitcoin. The FATF notes that stablecoins now account for a significant and growing share of illicit transaction volume.
Five Escalating Risk Areas Accounting Firms Must Track
Industrialised Fraud and Laundering at Scale
The report documents Cambodia-based scam operations that have become what the FATF describes as "significant generators of illicit proceeds." One conglomerate laundered at least USD 4 billion between August 2021 and January 2025, with its infrastructure connecting organised crime fraud, underground banking, and virtual asset laundering. At least USD 37 million of those proceeds were attributed to North Korean cyber heists supporting weapons of mass destruction programmes. Spain's Operation Borrelli dismantled a separate EUR 460 million investment fraud network affecting more than 5,000 victims across multiple countries.
Proprietary "Freeze-Resistant" Stablecoins
This is arguably the most operationally significant risk the report identifies for compliance teams. After a third-party issuer froze over USD 29 million held in its wallets, the same conglomerate launched its own USD-pegged stablecoin explicitly marketed as immune to asset freezing, issued across multiple public blockchains and a proprietary chain. The FATF's warning is direct: VASPs "may be unable to rely on issuer-level asset freeze or burn mechanisms as a compliance safeguard." Any AML framework that treats stablecoin freeze capability as a sufficient control needs to be revisited. The report calls for robust AML/CFT requirements to apply to stablecoin issuance itself, not just to the exchanges and wallets that distribute the tokens.
AI as a Structural Amplifier of Financial Crime
The FATF frames artificial intelligence not as a standalone technical curiosity but as "a structural factor that can amplify money laundering, terrorist financing, and sanctions-evasion risks." Documented cases include deepfake-powered recruitment scams stealing over USD 1 million, AI-assisted development of smart-contract exploits, and the use of open-weight models to bypass commercial AI safeguards built into frontier systems. For compliance teams, the implication is that transaction monitoring rules calibrated to human-speed fraud patterns may not be adequate against AI-accelerated attack vectors.
Convergence of Proliferation Financing, Terrorist Financing, and Sanctions Evasion
The report is explicit that these threat categories should no longer be treated as separate risk silos. North Korea exploits not just VASPs and DeFi protocols but the third-party infrastructure those systems depend on, including network nodes and multi-party security systems. This convergence means that a client who poses a proliferation financing risk may simultaneously pose a sanctions and terrorist financing risk. Siloed risk assessments will miss this.
Offshore VASPs and Peer-to-Peer Gaps
Offshore VASPs are actively soliciting customers in regulated markets, advising the use of VPNs to obscure jurisdiction, and misrepresenting themselves as retail users through nested accounts within regulated platforms. Eighty-eight percent of jurisdictions rate peer-to-peer activity via unhosted wallets as high risk. Only 23% collect any metrics to measure it. That gap between risk assessment and data collection is itself a supervisory failure the FATF is flagging.
What the FATF Now Expects from Supervisors and the Private Sector
The report's recommendations to supervisors are unambiguous. Jurisdictions are expected to operationalise their regimes, not simply have them on paper. That means licensing VASPs, stablecoin issuers, and qualifying DeFi arrangements; conducting genuine on-site and off-site inspections; and actively identifying and sanctioning unlicensed entities. The gap between having a licensing requirement and actually issuing licences is one the FATF wants closed in the next reporting cycle.
Critically, the report includes a prerequisite that directly affects how supervisors audit the firms you advise: supervisors themselves need to leverage on-chain data. Credibly assessing a VASP's compliance posture requires understanding what is happening on-chain, not just reviewing policy documents. Regulators who cannot trace flows or evidence their findings will struggle to demonstrate the effective implementation the FATF is now demanding. This is directly relevant to how AI-driven AML supervision is reshaping regulatory expectations at the jurisdictional level.
For the private sector, the FATF's recommendations explicitly list wallet screening, blacklisting and whitelisting, blockchain analytics, and freezing and blocking capabilities as expected components of a compliant AML framework. These are no longer optional enhancements. They are baseline expectations. For accounting firms and CFOs advising digital asset businesses, ensuring your clients can demonstrate these capabilities in a supervisory inspection is now a core deliverable.
Accounting and Operational Implications for Firms and CFOs
AML Control Documentation Must Reflect Enforcement-Ready Standards
The shift from paper compliance to enforcement-ready compliance changes what adequate documentation looks like. A policy that describes screening without evidence that screening is operationally embedded, tested, and producing actionable outputs will not satisfy an inspector applying the FATF's preventive measures criterion. Firms advising VASPs or holding digital assets on behalf of clients need to ensure that AML control documentation maps to operational reality, not just regulatory aspiration.
Crypto accounting software that integrates wallet screening and transaction monitoring outputs directly into the audit trail is increasingly relevant here. When a supervisor asks for evidence of preventive controls, the ability to produce timestamped, on-chain-linked records is materially more defensible than a narrative description of a process.
Stablecoin Holdings Require a Fresh Risk Assessment
The emergence of freeze-resistant stablecoins as a documented compliance circumvention tool has direct balance sheet implications. For any client holding stablecoins as treasury assets or using them for payment settlement, the compliance team needs to assess whether the issuer of those stablecoins maintains robust AML controls, including genuine freeze and burn capability, and whether that capability is subject to any regulatory oversight. A stablecoin that markets its resistance to asset freezing is, from a compliance standpoint, a red flag that warrants enhanced due diligence regardless of its price stability.
DeFi Client Exposure Needs Explicit Scoping
With 93% of jurisdictions yet to classify qualifying DeFi arrangements, there is regulatory uncertainty, but there is also regulatory direction. The FATF has made clear that identifiable owners and operators of DeFi protocols are within scope of VASP requirements. For any client that operates, invests in, or generates yield from DeFi protocols, an explicit scoping exercise should determine whether a licensing or registration obligation exists or is emerging in the relevant jurisdiction. Leaving this question open is itself a governance risk.
Travel Rule Compliance Warrants a Gap Analysis Now
The finding that 60% of jurisdictions with Travel Rule legislation have not enforced it cuts both ways. It means enforcement pressure is likely to increase as the FATF pushes jurisdictions to close this gap. For clients who have deferred Travel Rule implementation on the basis that supervisors have not been active, that window is narrowing. A gap analysis conducted now, before an inspection, is considerably less expensive than one conducted in response to a regulatory notice.
Source: Chainalysis
FAQ
It is the latest in an annual series of report cards assessing how well jurisdictions globally are implementing FATF Recommendation 15, which sets out the steps nations should take to regulate and supervise the virtual asset sector for AML and CFT purposes. The seventh edition, released 16 July 2026, covers 147 jurisdictions and identifies both progress and a widening gap between legislation and enforcement.
The Travel Rule requires VASPs to share originator and beneficiary data on qualifying transfers. The FATF found that 60% of jurisdictions with Travel Rule legislation have not yet taken supervisory or enforcement action. This signals that enforcement pressure is set to increase, and clients who have not fully implemented Travel Rule processes are carrying a regulatory risk that is likely to materialise sooner rather than later.
The report documents criminal groups launching proprietary stablecoins specifically marketed as immune to asset freezing, in direct response to third-party issuers freezing illicit funds. The FATF warns that VASPs cannot rely solely on issuer-level freeze mechanisms as a compliance safeguard and calls for robust AML and CFT requirements to apply to stablecoin issuance directly.
The report states that supervisors need to leverage on-chain data to credibly audit VASPs. Regulators who cannot independently trace transaction flows or evidence their findings from on-chain sources will struggle to demonstrate effective implementation of the FATF standard. This raises the bar for what a supervisory inspection looks like in practice.
The FATF's private sector recommendations explicitly list wallet screening, blacklisting and whitelisting, blockchain analytics tools, and freezing and blocking capabilities as expected components of a compliant AML framework. These are framed as baseline requirements, not optional enhancements.
