Purpose

Capture the FATF source material that applies specifically to virtual assets and virtual asset service providers as a consolidated BCMS source for Bitkaya’s VASP compliance framework.

This source is intentionally consolidated. The FATF materials operate as one standards package: the Recommendations provide the binding standard, the VASP guidance explains implementation, the red flags support monitoring, the risk-assessment guide supports sector and enterprise risk assessment, and the targeted update captures current implementation and emerging-risk themes.

If future BCMS work requires detailed paragraph-by-paragraph FATF mapping, this source may be split into separate child source objects while retaining this object as the parent FATF VA/VASP source.

Authority

  • Publisher: Financial Action Task Force (FATF)
  • Authority level: International AML/CFT/CPF standard-setter and guidance body
  • Scope: Virtual assets, virtual asset service providers, AML/CFT/CPF, Travel Rule, licensing or registration, supervision, risk assessment, suspicious transaction reporting, sanctions and proliferation-financing risk mitigation
  • Language reviewed: English
  • Current version verified: 2026-07-26
  • Applicability to Bitkaya: applicable as international standards and guidance informing Curacao VASP regulation, CBCS expectations and Bitkaya’s compliance framework

Source Materials Included

RefFATF materialPublication or update dateURLBCMS use
FATF-VA-001The FATF RecommendationsAdopted 2012; page states amended June 2026https://www.fatf-gafi.org/en/publications/Fatfrecommendations/Fatf-recommendations.htmlBaseline standard, including Recommendation 15, Interpretive Note to Recommendation 15, revised Recommendation 16, CDD, recordkeeping, reporting, supervision, sanctions and PF expectations
FATF-VA-002Updated Guidance for a Risk-Based Approach to Virtual Assets and Virtual Asset Service Providers2021-10-28https://www.fatf-gafi.org/en/publications/Fatfrecommendations/Guidance-rba-virtual-assets-2021.htmlMain implementation guidance for VA/VASP definitions, licensing or registration, stablecoins, P2P risks, counterparty VASP due diligence, Travel Rule and supervisory cooperation
FATF-VA-003Virtual Assets Red Flag Indicators of Money Laundering and Terrorist Financing2020-09-14https://www.fatf-gafi.org/en/publications/Methodsandtrends/Virtual-assets-red-flag-indicators.htmlTransaction monitoring typologies, alert logic, escalation criteria, suspicious activity review and UTR support
FATF-VA-004Quick guide on assessing the Money Laundering risks of virtual assets and virtual asset service providersFATF web guide, reviewed 2026-07-25https://www.fatf-gafi.org/en/publications/Methodsandtrends/quick-guide-on-assessing-ML-risks-of-VA-and-VASPs.htmlEnterprise and sector risk assessment, jurisdiction risk, unlicensed activity, private-sector data and VA/VASP risk indicators
FATF-VA-0052025 Targeted Update on Implementation of the FATF Standards on VA and VASPs2025-06-26https://www.fatf-gafi.org/en/publications/Fatfrecommendations/targeted-update-virtual-assets-vasps-2025.htmlCurrent implementation gaps and emerging risks, including Travel Rule implementation, offshore VASPs, stablecoins, DPRK thefts, scams, fraud, international cooperation and supervisory priorities
FATF-VA-006Virtual Assets: Targeted Update on Implementation of the FATF Standards on VAs and VASPs (June 2023)2023-06-01https://www.fatf-gafi.org/en/publications/Fatfrecommendations/targeted-update-virtual-assets-vasps-2023.html75% of jurisdictions partially/not compliant with R.15; over half have no Travel Rule steps; emerging risks from DeFi, P2P, NFTs, unhosted wallets, stablecoins
FATF-VA-007Virtual Assets: Targeted Update on Implementation of the FATF Standards on VAs and VASPs (July 2024)2024-07-01https://www.fatf-gafi.org/en/publications/Fatfrecommendations/targeted-update-virtual-assets-vasps-2024.html75% still partially/not compliant; one-third have no Travel Rule legislation; DPRK VA theft, scams, fraud, and PF risks highlighted
FATF-VA-008Seventh Targeted Update on Implementation of the FATF Standards on VA and VASPs2026-07-16https://www.fatf-gafi.org/en/publications/Fatfrecommendations/targeted-updated-virtualassets-vasps-2026.htmlUpdated jurisdiction compliance with R.15; emerging risks: VA-enabled fraud industrialisation, stablecoin misuse, P2P/unhosted wallet risks, offshore VASP exposure, DeFi; recommendations for private sector
FATF-VA-009Understanding and Mitigating the Risks of Offshore Virtual Asset Service Providers (oVASPs)2026-03-11https://www.fatf-gafi.org/en/publications/Virtualassets/Understanding-Mitigating-Risks-Offshore-VASPs.htmlOffshore VASP risks: gaps in oversight exploited for fraud, ML, TF; recommendations: assess exposure, consistent AML/CFT/CPF rules, no business with unregistered oVASPs
FATF-VA-010Targeted Report on Stablecoins and Unhosted Wallets — Peer-to-Peer Transactions2026-03-03https://www.fatf-gafi.org/en/publications/Virtualassets/targeted-report-stablecoins-unhosted-wallets.htmlStablecoins = 84% of illicit VA transaction volume in 2025; P2P unhosted wallet risks; cross-chain activity; wallet verification; 30+ red flag indicators for stablecoin/unhosted wallet transactions
FATF-VA-011Targeted Report on Regulatory Challenges from Decentralised Finance (DeFi)2026-07-21https://www.fatf-gafi.org/en/publications/Virtualassets/targeted-report-decentralised-finance-2026.html93% of jurisdictions haven’t implemented FATF Standards for DeFi; only 2 of 142 have licensed/registered a DeFi arrangement; functional risk-based approach recommended; VASP-DeFi interaction risk assessment

Summary

FATF Recommendation 15 and its Interpretive Note require countries to assess and mitigate risks from virtual assets and VASPs, license or register VASPs, subject VASPs to supervision or monitoring, and require VASPs to apply relevant preventive measures. These preventive measures include customer due diligence, recordkeeping, suspicious transaction reporting, targeted financial sanctions controls, proliferation-financing risk mitigation and Travel Rule information exchange.

The 2021 VA/VASP guidance explains how the standards apply to virtual assets, VASPs, stablecoins, peer-to-peer activity, licensing and registration, counterparty VASP due diligence, Travel Rule implementation and information sharing among VASP supervisors.

FATF now states that the 2021 VA/VASP guidance does not reflect revisions made after publication, including the 2025 revisions to Recommendation 1. It must therefore be read with the current June 2026 FATF Recommendations and more recent FATF risk-assessment guidance. The effect of the revised Recommendation 16 on Bitkaya’s Travel Rule implementation remains subject to the review tracked in ISS-FATF-001.

The red-flag guidance identifies indicators relevant to transaction monitoring and suspicious activity review, including anonymity-enhancing features, geographical risk, unusual transaction patterns, transaction size or frequency, sender or recipient profile concerns and source-of-funds or source-of-wealth concerns.

The quick risk-assessment guide supports VA/VASP risk assessment by explaining how VA/VASP activity differs from traditional financial activity, why private-sector input matters, and why countries and firms should consider cross-border, unlicensed and foreign-hosted VA/VASP activity.

The 2025 targeted update identifies continuing implementation gaps and emerging threats, including weak licensing and registration implementation, offshore VASP risk, Travel Rule challenges, stablecoin misuse, DPRK virtual asset theft, scams and fraud.

The June 2023 and July 2024 targeted updates found that 75% of jurisdictions remain partially or not compliant with FATF R.15, with over half having taken no steps toward Travel Rule implementation and nearly one-third having no Travel Rule legislation. The reports identified emerging risks from DeFi, P2P transactions, NFTs, unhosted wallets, and stablecoins, along with continued DPRK virtual asset theft, scams, fraud, and proliferation-financing risks.

The 2026 seventh targeted update highlights the growing industrialisation of VA-enabled fraud, stablecoin misuse, P2P risks through unhosted wallets, offshore VASPs operating outside effective oversight, and DeFi challenges. The 2026 offshore VASP (oVASP) report recommends assessing exposure to unlicensed oVASPs, applying consistent AML/CFT/CPF rules across group entities, and refraining from business relationships with unlicensed providers. The 2026 stablecoins and unhosted wallets report finds stablecoins accounted for 84% of illicit VA transaction volume in 2025 and provides 30+ red flag indicators. The 2026 DeFi report finds 93% of jurisdictions have not implemented FATF Standards for qualifying DeFi arrangements and recommends a functional, risk-based approach. These emerging risks serve as input for the next annual SARA/EWRA cycle.

Relevant Provisions

Provision themes for BCMS mapping:

  • Virtual asset and VASP definitions.
  • VASP licensing or registration and supervisory expectations.
  • Risk-based approach and VA/VASP risk assessment.
  • Customer due diligence and ongoing monitoring.
  • Recordkeeping and retrieval of VA/VASP transaction data.
  • Travel Rule originator and beneficiary information requirements.
  • Counterparty VASP due diligence and jurisdiction risk.
  • Suspicious transaction detection, escalation and reporting.
  • Sanctions and proliferation-financing risk mitigation.
  • Stablecoin, peer-to-peer, unhosted wallet and offshore VASP risk.
  • Red-flag indicators for blockchain and transaction monitoring.
  • Supervisory cooperation, international cooperation and enforcement trends.

Relationships

Assurance

  • Official FATF URLs verified: yes
  • Current FATF Recommendations page checked: yes, amended June 2026
  • VASP-specific guidance identified: yes
  • Red-flag indicators identified: yes
  • Risk-assessment guidance identified: yes
  • Latest targeted implementation update identified: yes, 2025-06-26
  • Combined-source decision recorded: yes
  • Requirement-level extraction completed: yes, REQ-FATF-001 through REQ-FATF-011
  • Full paragraph-level extraction completed: no
  • Applicability confirmed: review pending

Split Criteria

Split this consolidated source into separate FATF source objects if one of the following occurs:

  • BCMS requires paragraph-level mapping to specific FATF guidance sections.
  • A subordinate AML/CFT/CPF manual needs independent source approval for a specific FATF document.
  • A FATF document becomes stale or is superseded while the others remain current.
  • A review pack needs to evidence detailed coverage of only one FATF document.

History

  • 2026-07-25: Created consolidated FATF VA/VASP source object covering the FATF Recommendations, 2021 VA/VASP guidance, 2020 red flags, VA/VASP ML risk-assessment guide and 2025 targeted update.
  • 2026-07-25: Extracted FATF-derived requirements into REQ-FATF-001 through REQ-FATF-011.
  • 2026-07-26: Reverified the five official FATF materials, updated the current Recommendations edition to June 2026 and linked the FATF review pack and remediation issues.
  • 2026-07-26: Linked the approved KYC & CDD policy, specialized operating layer, procedures and controls.
  • 2026-07-29: Added FATF-VA-006 through FATF-VA-011 (2023 and 2024 targeted updates, 2026 seventh targeted update, offshore VASP report, stablecoins/unhosted wallets report, DeFi report) and expanded summary with findings from these reports (CHG-RES-006, CHG-RES-007, CHG-RES-008).