Purpose
Capture FATF guidance and targeted-update expectations for ongoing monitoring of emerging virtual asset risks and the application of FATF VA/VASP red flag indicators in transaction monitoring, CDD, and suspicious activity detection.
Normative
Bitkaya shall monitor and assess emerging VA/VASP risks relevant to its business, including stablecoins, peer-to-peer activity, unhosted wallets, offshore or weakly regulated VASPs, scams, fraud, DPRK-linked theft activity, sanctions evasion and material changes in FATF implementation expectations.
Bitkaya shall maintain a registered catalog of FATF VA/VASP red flag indicators, classified by monitoring layer, mapped to systems and controls, and reviewed annually as part of the emerging-risk review cycle. The catalog shall draw from FATF red flag indicator publications including the 2020 Red Flag Indicators report, the 2026 Stablecoins and Unhosted Wallets report, the 2026 DeFi report, and the 2026 Seventh Targeted Update.
FATF red flag indicators are non-binding guidance, not FATF Recommendations. The underlying obligations that the red flags support — Recommendation 10 (CDD / ongoing monitoring), Recommendation 20 (suspicious transaction reporting), and Recommendation 15 (VASP AML/CFT controls) — are already binding in the BCMS. The red flag catalog demonstrates to CBCS that Bitkaya applies a risk-based approach informed by current FATF guidance.
Descriptive
The 2025 targeted update and FATF risk-assessment materials highlight uneven global implementation and evolving illicit finance threats. Bitkaya should use regulatory-change monitoring and risk assessment updates to decide whether policies, monitoring rules, controls or training need revision.
The June 2023 and July 2024 targeted updates found that 75% of jurisdictions remain partially or not compliant with FATF R.15, with over half having taken no steps toward Travel Rule implementation and nearly one-third having no Travel Rule legislation. The 2026 seventh targeted update highlights the growing industrialisation of VA-enabled fraud, stablecoin misuse, P2P risks through unhosted wallets, offshore VASPs operating outside effective oversight, and DeFi challenges.
Red Flag Indicator Catalog
The red flag indicator catalog comprises 41 indicators from FATF 2020 Red Flags + 2026 Stablecoins/Unhosted Wallets + 2026 DeFi + 2026 Seventh Targeted Update, classified by monitoring layer:
- Layer 1: On-Chain Blockchain Analytics (Crystal Intelligence — SYS-KYT-001) — Indicators 1-12: mixer/tumbler connections, dark web transactions, cross-chain bridging, stablecoin wrapping/unwrapping, dense transaction chains, DeFi integration, unhosted wallet patterns, sanctioned address interactions, offshore issuer interactions
- Layer 2: Fiat-Crypto Interface (Odoo Accounting — SYS-FIN-001) — Indicators 13-21: rapid fiat-stablecoin-fiat conversions, disadvantageous economic conditions, threshold circumvention (smurfing), cash transaction threshold alerts, recurrent large-value patterns, multi-account coordination
- Layer 3: CDD/Behavioral (Odoo Compliance — SYS-IT-001 + KYC Procedures) — Indicators 22-30: multiple account patterns, unhosted wallet beneficial owner verification failures, counterparty risk assessment, offshore issuer use, cross-jurisdictional schemes, OTC broker CDD bypass, weak AML jurisdiction off-ramping, DeFi exposure, anonymisation services
- Layer 4: TF/PF-Specific (Manual Investigation — MLRO, PROC-AML-004) — Indicators 31-36: donation patterns, humanitarian diversion, procurement patterns, dense chain + procurement, cross-chain PF bridges, sanctioned address interactions
- Layer 5: General VA Red Flags (2020 Report — Already Tracked as FATF-VA-003) — Indicators 37-41: unusual transaction size/frequency, geographical risk, sender/recipient profile concerns, source of funds inconsistency, anonymity-enhancing features
The catalog is reviewed annually alongside the emerging-risk review cycle. Each indicator is mapped to the system responsible for detection.
Source reference: SRC-FATF-001 FATF Virtual Assets and VASP Standards.
Assurance Assertions
- Emerging FATF VA/VASP risks are reviewed at least annually.
- Material emerging-risk changes trigger impact assessment.
- Monitoring, training or control updates are documented where needed.
- FATF red flag indicators are registered, classified by monitoring layer, and mapped to detection systems and controls.
Relationships
- Source: SRC-FATF-001 FATF Virtual Assets and VASP Standards
- Parent policy: POL-ECM-001 Enterprise Compliance Manual
- Process: PRC-OTC-001 High-Level Overview of Principal OTC Service Delivery
- Regulatory-change procedure: PROC-ECM-002 Assess Regulatory Change and Framework Impact
- Regulatory-change control: CTRL-ECM-002 Ensure Regulatory Change Impact Assessment Is Completed
- Framework library: SYS-ECM-001 Compliance Framework Library
- Related VASP requirements: REQ-VASP-001 through REQ-VASP-015, where applicable
- Detailed AML/CFT/CPF manual objects: pending
Assurance
- Source verified: yes
- Implementation linked: parent-framework only
- Wording unambiguous: review
- Detailed operating procedure linked: pending future detailed manuals where applicable
History
- 2026-07-25: Created from consolidated FATF VA/VASP source object.
- 2026-07-29: Renamed to “Monitor Emerging VA Risks and Apply FATF Red Flag Indicators”; expanded normative section to require registered FATF red flag indicator catalog with monitoring layer classification and annual review; expanded descriptive section with 2023/2024/2026 FATF findings and 5-layer red flag indicator catalog (41 indicators); added depends_on REQ-MOT-002 and REQ-TM-001 (CHG-RES-008).