FATF's PPP Report: Crypto AML Gaps Firms Must Close Now
The Financial Action Task Force published its landmark review of public-private partnerships (PPPs) in financial crime fighting in July 2026, and the headline finding for any firm handling digital assets is uncomfortable: the cryptoasset industry remains under-integrated into the very networks that regulators and law enforcement are now treating as the front line of AML defence. For accounting firms, auditors, and CFOs whose clients touch crypto, that finding is not a background policy curiosity. It is a leading indicator of where supervisory expectations are heading next.
What FATF's Report Actually Found
The FATF report catalogued at least 84 PPPs operating across every region of the world, arrangements through which governments and private-sector organisations share information and capability to detect and disrupt financial crime. The number sounds substantial. The quality, however, varies enormously.
A Spectrum from Advisory to Operational
FATF describes these partnerships on a spectrum. At one end sit advisory forums: bodies that convene periodically to exchange typologies, trend data, and sector-level red flags. At the other end sits full operational collaboration, where public and private analysts work live cases together against named subjects, and where cooperation crosses borders to follow criminal networks between jurisdictions.
The report's candid conclusion is that most PPPs cluster toward the shallower end. The deeper, case-level work remains constrained by privacy legislation, banking secrecy regimes, and legal uncertainty about the authority to share information at all. The cryptoasset sector, specifically, is identified as under-integrated even within that already limited landscape.
Why Crypto Lags
The reasons the report surfaces are familiar to compliance professionals: crypto-specific typologies are newer and less well understood across agencies; blockchain data requires specialist capability that most public-sector bodies are still building; and the legal gateways that allow sharing of personal data were drafted before crypto was a material financial crime vector. The gap between where the sector is and where FATF wants it is real, and the report's direction of travel is toward closing it over the next two years.
The UK as the Operational Test Case
FATF explicitly recognises both permanent structures and time-bound exercises as legitimate forms of PPP. The UK is already operating at the more advanced, operational end of that spectrum through the Crypto Cash Fusion Cell (CCFC), a joint initiative that brings together law enforcement, regulators, and private-sector partners to disrupt criminal use of cryptoassets.
How Operational Collaboration Works in Practice
The CCFC model is instructive for understanding what FATF considers best practice. Rather than exchanging reports or attending forums, private-sector analysts worked directly alongside agency counterparts in real time. That proximity meant questions about on-chain data could be answered the same day, analytical scripts could be built and iterated immediately, and OFSI sanctions data could be cross-referenced against blockchain intelligence on sanctioned entities in the same session. Work that would previously have taken days was compressed into hours.
The result of this particular sprint was production of freezing orders, a concrete enforcement outcome rather than a policy recommendation. That is the shift FATF says it wants its members to replicate: from advisory forum to wallet freezing order.
For accounting firms advising regulated crypto businesses, this is a signal worth filing carefully. The CCFC is described in the report as a pilot, not a permanent standing body. The explicit direction is to make this kind of collaboration routine. When it becomes routine, the regulated entities feeding data into it, including virtual asset service providers (VASPs) and any financial institution with crypto exposure, will face heightened expectations around data quality, record-keeping, and transaction monitoring speed.
Cross-Border Capacity Building: Essential but Underdeveloped
The report identifies cross-border capacity building as foundational to effective PPPs yet simultaneously among the least developed forms of cooperation currently in existence. That pairing matters for global firms.
Training Across Jurisdictions
One example the report highlights is regional training delivered to law enforcement officers across multiple Asia-Pacific countries, bringing analysts from 11 jurisdictions together to understand how blockchain data can expose scam compound ecosystems and trace cryptoasset flows to specific actors within those networks. The FATF report frames this kind of cross-border skill transfer as both essential and rare.
For accounting firms with clients operating across the UK, EU, and beyond, the implication is that the regulatory floor is actively rising in jurisdictions that previously lacked blockchain investigative capacity. A VASP or crypto-exposed financial institution that was comfortable with its AML controls in a lower-capacity jurisdiction two years ago may find those same controls subject to much sharper scrutiny as local agencies build capability through exactly these PPP training programmes.
Data Protection as Architecture, Not Obstacle
The data-sharing tension at the heart of the FATF report deserves specific attention from compliance officers and the advisers who serve them. More than half of the surveyed jurisdictions cited data protection rules as their primary obstacle to information sharing, ranking it above banking secrecy and unclear legal gateways. That figure reflects a genuine structural problem, but the report's conclusion is nuanced.
Designing for Privacy Within PPPs
The partnerships that function effectively at the operational level do not treat data protection as an obstacle to be worked around. They design their information-sharing architecture to comply with it from the outset, working within established legal gateways, under need-to-know access controls, and with confidentiality undertakings that govern how shared information can be used downstream.
Blockchain intelligence is a natural fit for this model. A significant volume of analytical work can be completed using data that is already public on-chain before any personal information changes hands at all. The ability to establish connections between wallet addresses, trace transaction flows, and map entity relationships from public ledger data means that much of the intelligence picture can be assembled without triggering data protection obligations that would apply to off-chain personal data sharing.
For CFOs and compliance leads, this has a direct practical implication. When your organisation is drawn into a PPP, whether through a regulatory request, a law enforcement liaison, or a joint typologies exercise, the legal basis for any information you share will matter. Firms that have already mapped their legal gateways for data sharing, documented their need-to-know access controls, and understood which of their analytical outputs are derived from public blockchain data versus personal data will be in a far stronger position than those who have not.
The UK FATF Presidency and What Comes Next
The timing of this report is not incidental. The UK assumed the FATF Presidency on 1 July 2026, and information sharing through PPPs is explicitly listed among the presidency's stated priorities. Fraud, identified in the report as the threat driving new partnership formation fastest globally, is another priority area.
Implications for UK and EU Regulated Firms
The combination of UK FATF leadership and an active operational pilot in the CCFC means that the standards being tested in London are likely to inform what FATF recommends to its full membership over the next two years. UK-regulated VASPs and financial institutions with crypto exposure are, in effect, operating in a proving ground for the next generation of global AML expectations.
EU-regulated firms face a parallel trajectory. The AML Authority (AMLA) begins direct supervision of selected crypto entities from 2025 onward, and the broader EU AML package builds data-sharing obligations into its supervisory architecture. The FATF report's emphasis on designing PPPs around data protection law rather than despite it aligns closely with how AMLA is expected to approach information exchange between national supervisors, financial intelligence units, and private-sector entities under the new EU framework.
Firms using crypto accounting software to maintain transaction records need to consider whether those records are structured in a way that supports rapid, legally compliant information sharing if a regulator or law enforcement body requests it. A well-structured audit trail, with wallet addresses, counterparty identifiers, transaction hashes, and timestamps consistently recorded, is not only good bookkeeping practice but also the raw material of any productive PPP engagement. Firms that rely on fragmented or manual records will struggle to respond at the pace the CCFC model, and the report's direction of travel, now implies. Related: see our note on CSSF's warning on unlicensed crypto operators for how regulatory gaps can crystallise into enforcement action without warning.
Practical Steps for Accounting Firms and CFOs
The FATF report does not create immediate new legal obligations. But it maps the direction of supervisory travel with unusual clarity, and accounting firms advising crypto-exposed clients should be helping those clients prepare now rather than reacting later.
Key Actions to Take Before Year-End
First, review transaction monitoring coverage for crypto assets. If your client's monitoring is calibrated only to traditional payment flows, the typologies FATF is asking PPPs to address, including scam compound networks, sanctions evasion, and cross-border layering, may not be triggering alerts.
Second, map the legal gateways available for information sharing. Firms operating under UK FSMA, EU AML directives, or both need to know which gateways exist, what conditions attach to their use, and which staff have authority to act on them. This mapping should be documented before a request arrives, not during it.
Third, assess record quality against the operational standard the CCFC model implies. If a request arrived tomorrow for all transactions involving a specific counterparty or wallet address over the past three years, could your team produce that data in hours? If not, the gap between your current record structure and the implied standard is worth closing now.
Fourth, engage with the broader MiCA and EU AML package on data obligations. The MiCA licensing obligations for crypto custodians already embed record-keeping and reporting expectations that overlap significantly with what effective PPP participation requires. Treating these as a single compliance exercise rather than separate workstreams reduces duplication and builds a more coherent control environment.
Frequently Asked Questions
What is FATF's PPP report and why does it matter for crypto firms?
FATF published its review of public-private partnerships in financial crime fighting in July 2026. It catalogues 84 partnerships globally and identifies the cryptoasset sector as under-integrated into these networks. The report matters because it signals where supervisory expectations for VASPs and crypto-exposed financial institutions are heading over the next two years.
What is the Crypto Cash Fusion Cell and what did it produce?
The CCFC is a UK initiative that brings law enforcement, regulators, and private-sector partners together to disrupt criminal use of cryptoassets. In at least one time-bound exercise, CCFC participants cross-referenced OFSI sanctions data against blockchain intelligence on sanctioned entities, traced transactions to UK-regulated exchanges, and produced freezing orders as a concrete enforcement outcome.
How does data protection law affect crypto information sharing in PPPs?
More than half of FATF's surveyed jurisdictions cited data protection rules as their main obstacle to sharing. The report concludes that effective PPPs design their architecture to comply with privacy law from the start, working within legal gateways and access controls. Blockchain intelligence derived from public on-chain data can often be shared before any personal data obligations are triggered, which makes it a natural fit for compliant PPP information exchange.
What does the UK FATF Presidency mean for compliance timelines?
The UK assumed the FATF Presidency on 1 July 2026 with PPPs and fraud among its stated priorities. Standards being piloted through UK initiatives like the CCFC are likely to inform FATF recommendations to its full membership over the presidency period, effectively setting the benchmark that other jurisdictions will be measured against.
What record-keeping changes should firms make in response to this report?
Firms should ensure transaction records include wallet addresses, counterparty identifiers, transaction hashes, and timestamps in a structured and searchable format. Digital asset accounting software that captures this data consistently makes it possible to respond to regulatory or law enforcement requests at the pace operational PPPs now imply. Manual or fragmented records create both compliance risk and reputational exposure if a request cannot be fulfilled promptly.
Source: Elliptic
