Research Compliance

Bueche (2022) - FATF and Virtual Assets: The Evolution of Global AML Standards for Crypto

Key Insights

  • Bueche tracks the FATF's extension of AML regulation to virtual assets, including the Travel Rule for crypto transfers, and analyzes implementation challenges in the decentralized finance landscape.
Difficulty: Intermediate Type: Research

Edit on GitHub — registry.json

Background

For the first two decades of crypto, the FATF Recommendations said nothing about it. That changed in 2019, when the standard-setter extended its framework to virtual assets (VAs) and virtual asset service providers (VASPs) — and in doing so created the first global AML regime for crypto. Bueche's analysis traces that evolution and the implementation gap it opened.

The Regulatory Shift

The June 2019 FATF guidance revised the Recommendations to bring VAs and VASPs into scope: licensing or registration, customer due diligence, monitoring, and — most consequentially — the Travel Rule. Recommendation 16 now requires VASPs to pass originator and beneficiary information with transfers of virtual assets, the crypto equivalent of wire-transfer transparency.

Deep Dive

The paper examines how the standard interacts with crypto's architecture. P2P transfers between unhosted (self-custody) wallets fall outside VASP jurisdiction entirely — a structural gap the FATF's own 12-month reviews acknowledged. DeFi protocols, often non-custodial, resist the VASP framing. Privacy coins and mixing services obscure the very attribution the Travel Rule depends on. Meanwhile, implementation is uneven: VASPs in regulated jurisdictions bear the compliance load while unlicensed exchanges elsewhere serve the same customers, creating arbitrage and forum-shopping incentives.

Why It Matters

The FATF's crypto framework is now the baseline for every national regime, and the Travel Rule's technical solutions (interoperability standards like IVMS 101) are an active infrastructure build. For compliance teams the analysis maps where the regime holds — custodial, centralized activity — and where it cannot reach.

Key Takeaways

  • The Travel Rule applies at VASP boundaries; unhosted-wallet and P2P activity sits outside it.
  • Licensing arbitrage is the compliance risk — jurisdiction gaps concentrate flow where controls are weakest.
  • Attribution is the scarce resource: privacy-enhancing tech undermines the regime's core assumption.
Article Metadata

Cross-Pillar Connections

Further Reading

  • FATF

    Financial Action Task Force — global AML/CFT standards and grey/black lists

  • FinCEN Press

    FinCEN press releases — rulemakings, advisories, enforcement orders

  • ACAMS

    Association of Certified Anti-Money Laundering Specialists — training, research, typologies

  • FinCEN

    US Financial Crimes Enforcement Network — SAR filings, advisories, BSA guidance

  • OFAC

    US Office of Foreign Assets Control — sanctions lists, enforcement actions

  • AMLA

    EU Anti-Money Laundering Authority — rulebook, RTS, direct supervision

Related Research

Related Lessons

Stay Updated

Get the latest research summaries delivered to your inbox.