## Introduction

## Source details

**Canonical URL:** [Introduction](https://www.imf.org/-/media/files/publications/ftn063/2021/english/ftnea2021003.pdf)

## Other formats

- [Markdown version](/-/media/files/publications/ftn063/2021/english/ftnea2021003.pdf.md)
- [Structured JSON version](/-/media/files/publications/ftn063/2021/english/ftnea2021003.pdf.json)

---

### Overview: opportunities and risks of virtual assets (VAs)
- VAs are a broad term describing systems of storing/capturing value in digital form, including “digital currencies,” “cryptocurrencies,” existing stablecoins and so-called global stablecoins currently being developed.
- Potential benefits: greater speed, lower cost, increased efficiency in making payments and transfers (including across borders), and potential to improve financial inclusion.
- Misuse: some VAs have been misused to commit narcotic-related crimes, fraud, theft, money laundering (ML), and terrorist financing (TF), among other illegal activities.
- Mitigation requires careful consideration and effective implementation of the Financial Action Task Force (FATF) anti–money laundering/combating the financing of terrorism (AML/CFT) standards.

### Purpose, scope, and context of this Fintech Note
- This is the second IMF Fintech Note on VAs and AML/CFT; it focuses on the AML/CFT regulation and supervision of virtual asset service providers (VASPs).
- Builds upon Fintech Note 1 (which explains VA vulnerability to misuse and which assets/service providers should be subject to AML/CFT measures).
- Aim: provide policy makers and competent authorities with a high-level overview of AML/CFT regulatory and supervisory frameworks envisaged for VAs and VASPs and legal and practical considerations.
- At the time of drafting:
  - The FATF noted progress in implementation as of June 2020, but challenges remain; many VASPs are only beginning to adopt required AML/CFT measures and many jurisdictions are at early stages of developing supervisory regimes for VASPs.
  - No country had been assessed against the new standards.
  - FATF comprises 39 members representing most major financial centers.

### Key regulatory and supervisory imperatives
- Jurisdictions should ensure all VASPs are properly licensed or registered and subject to adequate AML/CFT obligations.
- Supervisory objectives should be made clear (for example, whether regulation is for AML/CFT only or for AML/CFT plus prudential objectives).
- Legal frameworks may need amendments to establish institutional measures (for example, designation of a supervisory authority), licensing/registration, monitoring, and sanctioning of noncompliance.
- Designation of one or more agencies to authorize and supervise VASPs is required; authorities may leverage existing regulators or create a new dedicated agency.
- AML/CFT supervisors will often need to play a lead role in licensing/registration given that VASPs may not be subject to other prudential regimes.
- Where there is a large existing VASP population, careful planning and preparedness (knowledge and resources) is required before rolling out the framework.

### Licensing versus registration
- Jurisdictions may submit VASPs to licensing or registration processes:
  - Licensing: ex-ante regulatory assessment; criteria typically include minimum resource requirements (financial capital, human resources, physical location), corporate governance, internal controls and financial integrity requirements, financial reporting and disclosure. Screening to prevent criminals or undisclosed beneficial owners from holding significant or controlling interests is particularly important.
  - Registration: generally entails no or few prerequisites; regulatory assessment often ex-post but may consider similar issues.
- Choice depends on supervisory objectives and market entry approach; hybrid systems are possible.
- Minimum locus for licensing/registration per FATF:
  - VASPs that are natural persons: regulated based on their place of business.
  - VASPs that are legal persons: licensed or registered in the jurisdiction where they are “created” (incorporation or other mechanism).
- Jurisdictions may go beyond the minimum standard by regulating VASPs offering services to their citizens/residents or VASPs operating from their jurisdiction, potentially exposing a single VASP to multiple regimes.

### Enforcement and unauthorized VASPs
- Jurisdictions should proactively enforce the regulatory framework with outreach and engagement to ensure VASPs understand AML/CFT obligations.
- Proactive identification of unauthorized VA-related activities is required; stakeholders (including FIU and law enforcement) should work with the supervisory authority.
- Techniques for identifying unauthorized activities include web crawling, public feedback/whistleblowing, suspicious transaction reports (STRs), financial intelligence, open-source advertisements, and information on past unsuccessful applications.
- Enforcement tools: public warnings and alerts, prohibiting/suspending individuals, deactivating websites, imposing regulatory fines, bringing (criminal) charges.
- Cross-border enforcement challenges: where operators are abroad or purely online, jurisdictions should conduct joint operations with relevant overseas authorities.
- Bans or restrictions on VAs:
  - Some jurisdictions may ban or limit use of VAs for reasons such as misuse concerns or limited regulatory capacity.
  - Inactivity is not an option; specific measures are needed to mitigate domestic and international risks, including identification and enforcement against illegal activities and international cooperation to prevent regulatory arbitrage.

### Preventive framework: VASPs as gatekeepers
- VASPs must implement preventive measures equivalent to those for financial institutions and DNFBPs, adapted to the virtual context.
- Required measures include:
  - Customer due diligence (CDD) and record-keeping.
  - Politically exposed persons (PEPs) screening.
  - Correspondent banking-like considerations where applicable.
  - Measures for money or value transfer services, wire transfers, and reliance on third parties.
  - Internal controls, policies for foreign branches and subsidiaries, and handling of higher-risk jurisdictions.
  - Reporting of suspicious transactions, and rules on tipping-off and confidentiality.
  - Ensuring no funds or assets (including VAs) are made available to designated persons/entities under targeted financial sanctions (terrorism, TF, and PF).
- Jurisdictions must ensure secrecy laws do not inhibit VASPs from implementing AML/CFT obligations.

### Risk-based controls and enterprise-wide risk assessments
- VASPs should identify and understand ML/TF/PF risks and document enterprise-wide risk assessments considering customer, products and services, geographical regions, and delivery channels.
- VASPs must consider unique VA features (for example, anonymity-enhancing features, mixers/tumblers) that may present higher risks by obfuscating transactions or undermining CDD.
- Preventive controls should be commensurate to identified risks; technological solutions may assist in risk assessment and implementation of AML/CFT controls.
- Customer risk assessments must be carried out in all cases; enhanced measures are required for heightened risk factors (for example, PEPs or customers from high-risk jurisdictions), while proven low risks may justify simplified measures.
- Customer risk assessments should be revisited at regular intervals or on trigger events (change in customer behavior/profile).
- Monitoring of business relationships is necessary in all cases; intensity depends on customer risk ranking.

### Customer identification, CDD thresholds, and digital identification
- Traditional face-to-face identification and physical documents are often unsuitable in virtual environments; jurisdictions should consider electronic and biometric identification as appropriate alternatives.
- VASPs should use all available information to carry out CDD (for example, unique user codes linked to customers), but controls must confirm the integrity of such information and steps must be taken to verify customer identity after initial linkage.
- CDD obligations:
  - CDD must be performed when a VASP enters into a business relationship and when performing an occasional (one-off) transaction for non-customers above a certain threshold of US$/EUR 1,000 or less.
  - Certain customer information must be obtained for all customers, even those conducting occasional transactions below US$/EUR 1,000, to enable linkage of multiple transactions that may be related.
  - VASPs must demonstrate whether transactions are occasional (one-off) rather than part of a consistent pattern.
  - CDD must also be conducted where there is suspicion of ML/TF or doubt as to previously obtained CDD information.
- The FATF published guidance on digital identification (“digital ID”) clarifying that digital ID and other “information or data” may be used for CDD provided they constitute “reliable, independent source documents, data or information.”

### Targeted financial sanctions (TFS)
- The framework for targeted financial sanctions for terrorism, TF, and PF applies to VAs and VASPs.
- VASPs must ensure compliance with TFS obligations, including screening for designated persons or entities; digital identifiers may not substitute for person/entity name screening required for TFS.

### Box 1 — Digital ID: screening, record-keeping, travel rule, and monitoring
- Screening and targeted financial sanctions:
  - All transactions must be screened against designated lists; total anonymity is not an option for VASPs.
  - Screening controls should detect positive matches, enable freezing/stopping transactions immediately, and provide mechanisms to report matches and file an STR.
  - While a CDD threshold may exist, such a threshold is not applicable for sanctions screening: all transactions must be screened.
  - Names of originator and beneficiary must be obtained in all instances for effective sanctions screening; additional verifying information must also be obtained.
- Record-keeping and DLT:
  - Customer and transaction information must remain available to competent authorities; DLT can act as an immutable ledger but reliance solely on DLT is not sufficient.
  - VASPs must link transaction information on the DLT to the relevant customer/beneficiary and implement compensatory controls where necessary.
- Wire transfer rules and the “travel rule”:
  - VASPs must obtain, hold, and transmit required originator and beneficiary information when transferring VAs.
  - Challenges include implementing secure, real-time mechanisms for information transfer; few technological solutions currently enable holistic, instantaneous, and secure compliance.
  - Initiatives such as interVASP’s IVMS-101 Messaging Standard may assist; absent a global solution, ensuring interoperability is key.
- Monitoring and reporting of suspicious transactions:
  - VASPs should implement robust monitoring systems with VA ML/TF red flag indicators; report STRs to the FIU with relevant details.
  - FIUs should consider whether VA-specific information (device identifiers, VA wallet addresses, transaction hashes) is required and update reporting mechanisms accordingly.
  - AI and machine learning can enhance detection but require continuous enrichment, assessment, and adequate in-house knowledge; caution against overreliance.

### Supervision, cooperation, and enforcement
- Supervision and monitoring:
  - Effective AML/CFT implementation requires cooperation among supervisors, competent authorities, and the private sector.
  - Supervisors should communicate expectations, provide guidance, apply a risk-based approach, and may request supervisory returns and use FIU/law enforcement inputs and public information to inform risk understanding.
  - Inherent risk assessments should consider customers; products and services; geographic regions; and delivery channels.
  - Supervisory strategies should target higher-risk VASPs with enhanced offsite and onsite engagement and may involve third-party experts.
  - Supervisors need resources, skills, and capabilities and should impose dissuasive, proportionate, and effective sanctions (including suspension or revocation of license or registration and sanctioning of directors and senior managers).
- Regulatory and supervisory cooperation:
  - Cross-border and online nature of VA activities makes international cooperation key.
  - Regulators may consult foreign counterparts at licensing/registration; establishing AML/CFT supervisory colleges can facilitate information sharing.
  - Sharing knowledge and experiences enhances capacity to understand and mitigate ML/TF/PF risks.

### Conclusion and forward actions
- The 2018 and 2019 changes to FATF standards constitute major progress by clarifying regulation and supervision of VASPs and reducing regulatory arbitrage.
- Subjecting VASPs to measures similar to those applicable to FIs and DNFBPs encourages fair treatment of new virtual actors and increases VASPs’ interaction with the traditional financial sector; several VASPs have indicated benefits of implementing sound AML/CFT systems outweigh costs, notably by reassuring banks.
- Implementation remains challenging and uneven; emergence of global stablecoins may increase supervisory challenges.
- Jurisdictions should ensure VASPs are subject to appropriate AML/CFT measures and that supervisors have know-how, powers, and resources to monitor compliance effectively.
- The international AML/CFT community should continue to monitor financial integrity risks related to VAs, ensure standards remain appropriate, assist jurisdictions in implementation, and address issues from uneven implementation and multiplicity of regulatory frameworks.
- The FATF has committed to issue more guidance (for example, on stablecoins, anonymous peer-to-peer transactions, the “travel rule,” and red flags for potential ML/TF); promote understanding of VA-specific ML/TF/PF risks; engage with the private sector; enhance international cooperation among VASP supervisors; and periodically take stock of implementation of standards on VA and VASP globally.
- IMF staff is committed to assist members through relevant workstreams, including capacity development activities, to strengthen financial integrity in the VA space.

### Annex 1 — FATF Standards Related to VAs and VASPs (high-level points)
- Recommendation 15 “New Technologies”:
  - Countries should ensure that virtual asset service providers are regulated for AML/CFT purposes, and licensed or registered and subject to effective systems for monitoring and ensuring compliance with the relevant measures called for in the FATF Recommendations.
  - Countries should consider virtual assets as “property,” “proceeds,” “funds,” “funds or other assets,” or other “corresponding value” for purposes of applying the FATF Recommendations.
  - Countries should identify, assess, and understand ML/TF risks emerging from virtual asset activities and VASP operations and apply a risk-based approach.
- Licensing, supervision, and sanctions:
  - VASPs should be required to be licensed or registered; at a minimum in the jurisdiction(s) where they are created. Natural persons should be licensed/registered in the jurisdiction where their place of business is located.
  - Competent authorities should prevent criminals or their associates from holding significant or controlling interests in VASPs and should identify and sanction persons carrying out VASP activities without requisite license/registration.
  - A country need not impose a separate licensing/registration system on entities already licensed as financial institutions that are permitted to perform VASP activities and are subject to the full range of applicable obligations.
  - Supervisors should be competent authorities (not SRBs), conduct risk-based supervision, have powers to inspect, compel information, and impose sanctions including withdrawal/suspension of license or registration.
  - Sanctions should be effective, proportionate, and dissuasive and applicable to VASPs and their directors and senior management.
- Preventive measures and CDD:
  - Application of Recommendations 10 to 21 to VASPs, with qualifications:
    - (a) R.10 – The occasional transactions designated threshold above which VASPs are required to conduct CDD is USD/EUR 1 000.
    - (b) R.16 – Originating and beneficiary VASPs must obtain and hold required and accurate originator and beneficiary information on virtual asset transfers, submit that information immediately and securely to the beneficiary VASP or financial institution (if any), and make it available on request to appropriate authorities. Other requirements of R.16 apply on the same basis as set out in R.16.
- International cooperation:
  - Countries should rapidly, constructively, and effectively provide the widest possible range of international cooperation in relation to ML, predicate offences, and TF relating to virtual assets, based on Recommendations 37–40.
  - Supervisors of VASPs should exchange information promptly and constructively with foreign counterparts.

### Annex 2 — ML/TF Red Flag Indicators (summary)
- FATF guidance: countries should ensure virtual asset red flag indicators are incorporated into transaction monitoring systems.
- VASPs should use six categories to identify red flags:
  - Transactions
  - Transaction Patterns
  - Anonymity
  - Senders or Recipients
  - Source of Funds or Wealth
  - Geographical Risks
- US Financial Crimes Enforcement Network examples (selected):
  - “A customer receives a series of deposits from disparate sources that, in aggregate, amount to nearly identical aggregate funds transfers to a known virtual currency exchange platform within a short period of time.”
  - “A customer’s transactions are initiated from non-trusted IP addresses, IP addresses from sanctioned countries, or IP addresses previously flagged as suspicious.”
  - “A customer provides identification or account credentials (for example, non-standard password, IP address, or flash cookies) shared by another account.”
  - “A common wallet address is shared between customers.”
  - “A customer initiates multiple rapid trades between multiple virtual currencies with no related purpose, which may be indicative of attempts to break the chain of custody on the respective blockchains or further obfuscate the transaction.”

*International Monetary Fund | October 2021*

### Introduction 1

### Introduction 1

### Contents
- Effective Regulatory and Supervisory AML/CFT System—Legal and Practical 2
- Conclusion 10
- Annex 1. FATF Standards Related to VAs and VASPs 11
- Annex 2. ML/TF Red Flag Indicators 14

### Abbreviations
- AI Artificial Intelligence
- AML/CFT Anti-Money Laundering/Combating the Financing of Terrorism
- CDD Customer Due Diligence
- Digital ID Digital Identification
- DLT Distributed Ledger Technology
- DNFBPs Designated Non-Financial Businesses and Professions
- FATF Financial Action Task Force
- FI Financial Institution
- FIU Financial Intelligence Unit
- ML Money Laundering
- PEP Politically Exposed Person
- PF Financing of Proliferation of Weapons of Mass Destruction
- STR Suspicious Transaction Report
- TF Terrorist Financing
- UNSC United Nations Security Council
- VA Virtual Asset
- VASP Virtual Asset Service Provider

*International Monetary Fund | October 2021*

### Introduction

### Introduction

### Overview: opportunities and risks of virtual assets (VAs)
- VAs are a broad term describing systems of storing/capturing value in digital form, including “digital currencies,” “cryptocurrencies,” existing stablecoins and so-called global stablecoins currently being developed.
- Potential benefits: greater speed, lower cost, increased efficiency in making payments and transfers (including across borders), and potential to improve financial inclusion.
- Misuse: some VAs have been misused to commit narcotic-related crimes, fraud, theft, money laundering (ML), and terrorist financing (TF), among other illegal activities.
- Mitigation requires careful consideration and effective implementation of the Financial Action Task Force (FATF) anti–money laundering/combating the financing of terrorism (AML/CFT) standards.

### Purpose, scope, and context of this Fintech Note
- This is the second IMF Fintech Note on VAs and AML/CFT; it focuses on the AML/CFT regulation and supervision of virtual asset service providers (VASPs).
- Builds upon Fintech Note 1 (which explains VA vulnerability to misuse and which assets/service providers should be subject to AML/CFT measures).
- Aim: provide policy makers and competent authorities with a high-level overview of AML/CFT regulatory and supervisory frameworks envisaged for VAs and VASPs and legal and practical considerations.
- At the time of drafting:
  - The FATF noted progress in implementation as of June 2020, but challenges remain; many VASPs are only beginning to adopt required AML/CFT measures and many jurisdictions are at early stages of developing supervisory regimes for VASPs.
  - No country had been assessed against the new standards.
  - FATF comprises 39 members representing most major financial centers.

### Key regulatory and supervisory imperatives
- Jurisdictions should ensure all VASPs are properly licensed or registered and subject to adequate AML/CFT obligations.
- Supervisory objectives should be made clear (for example, whether regulation is for AML/CFT only or for AML/CFT plus prudential objectives).
- Legal frameworks may need amendments to establish institutional measures (for example, designation of a supervisory authority), licensing/registration, monitoring, and sanctioning of noncompliance.
- Designation of one or more agencies to authorize and supervise VASPs is required; authorities may leverage existing regulators or create a new dedicated agency.
- AML/CFT supervisors will often need to play a lead role in licensing/registration given that VASPs may not be subject to other prudential regimes.
- Where there is a large existing VASP population, careful planning and preparedness (knowledge and resources) is required before rolling out the framework.

### Licensing versus registration
- Jurisdictions may submit VASPs to licensing or registration processes:
  - Licensing: ex-ante regulatory assessment; criteria typically include minimum resource requirements (financial capital, human resources, physical location), corporate governance, internal controls and financial integrity requirements, financial reporting and disclosure. Screening to prevent criminals or undisclosed beneficial owners from holding significant or controlling interests is particularly important.
  - Registration: generally entails no or few prerequisites; regulatory assessment often ex-post but may consider similar issues.
- Choice depends on supervisory objectives and market entry approach; hybrid systems are possible.
- Minimum locus for licensing/registration per FATF:
  - VASPs that are natural persons: regulated based on their place of business.
  - VASPs that are legal persons: licensed or registered in the jurisdiction where they are “created” (incorporation or other mechanism).
- Jurisdictions may go beyond the minimum standard by regulating VASPs offering services to their citizens/residents or VASPs operating from their jurisdiction, potentially exposing a single VASP to multiple regimes.

### Enforcement and unauthorized VASPs
- Jurisdictions should proactively enforce the regulatory framework with outreach and engagement to ensure VASPs understand AML/CFT obligations.
- Proactive identification of unauthorized VA-related activities is required; stakeholders (including FIU and law enforcement) should work with the supervisory authority.
- Techniques for identifying unauthorized activities include web crawling, public feedback/whistleblowing, suspicious transaction reports (STRs), financial intelligence, open-source advertisements, and information on past unsuccessful applications.
- Enforcement tools: public warnings and alerts, prohibiting/suspending individuals, deactivating websites, imposing regulatory fines, bringing (criminal) charges.
- Cross-border enforcement challenges: where operators are abroad or purely online, jurisdictions should conduct joint operations with relevant overseas authorities.
- Bans or restrictions on VAs:
  - Some jurisdictions may ban or limit use of VAs for reasons such as misuse concerns or limited regulatory capacity.
  - Inactivity is not an option; specific measures are needed to mitigate domestic and international risks, including identification and enforcement against illegal activities and international cooperation to prevent regulatory arbitrage.

### Preventive framework: VASPs as gatekeepers
- VASPs must implement preventive measures equivalent to those for financial institutions and DNFBPs, adapted to the virtual context.
- Required measures include:
  - Customer due diligence (CDD) and record-keeping.
  - Politically exposed persons (PEPs) screening.
  - Correspondent banking-like considerations where applicable.
  - Measures for money or value transfer services, wire transfers, and reliance on third parties.
  - Internal controls, policies for foreign branches and subsidiaries, and handling of higher-risk jurisdictions.
  - Reporting of suspicious transactions, and rules on tipping-off and confidentiality.
  - Ensuring no funds or assets (including VAs) are made available to designated persons/entities under targeted financial sanctions (terrorism, TF, and PF).
- Jurisdictions must ensure secrecy laws do not inhibit VASPs from implementing AML/CFT obligations.

### Risk-based controls and enterprise-wide risk assessments
- VASPs should identify and understand ML/TF/PF risks and document enterprise-wide risk assessments considering customer, products and services, geographical regions, and delivery channels.
- VASPs must consider unique VA features (for example, anonymity-enhancing features, mixers/tumblers) that may present higher risks by obfuscating transactions or undermining CDD.
- Preventive controls should be commensurate to identified risks; technological solutions may assist in risk assessment and implementation of AML/CFT controls.
- Customer risk assessments must be carried out in all cases; enhanced measures are required for heightened risk factors (for example, PEPs or customers from high-risk jurisdictions), while proven low risks may justify simplified measures.
- Customer risk assessments should be revisited at regular intervals or on trigger events (change in customer behavior/profile).
- Monitoring of business relationships is necessary in all cases; intensity depends on customer risk ranking.

### Customer identification, CDD thresholds, and digital identification
- Traditional face-to-face identification and physical documents are often unsuitable in virtual environments; jurisdictions should consider electronic and biometric identification as appropriate alternatives.
- VASPs should use all available information to carry out CDD (for example, unique user codes linked to customers), but controls must confirm the integrity of such information and steps must be taken to verify customer identity after initial linkage.
- CDD obligations:
  - CDD must be performed when a VASP enters into a business relationship and when performing an occasional (one-off) transaction for non-customers above a certain threshold of US$/EUR 1,000 or less.
  - Certain customer information must be obtained for all customers, even those conducting occasional transactions below US$/EUR 1,000, to enable linkage of multiple transactions that may be related.
  - VASPs must demonstrate whether transactions are occasional (one-off) rather than part of a consistent pattern.
  - CDD must also be conducted where there is suspicion of ML/TF or doubt as to previously obtained CDD information.
- The FATF published guidance on digital identification (“digital ID”) clarifying that digital ID and other “information or data” may be used for CDD provided they constitute “reliable, independent source documents, data or information.”

### Targeted financial sanctions (TFS)
- The framework for targeted financial sanctions for terrorism, TF, and PF applies to VAs and VASPs.
- VASPs must ensure compliance with TFS obligations, including screening for designated persons or entities; digital identifiers may not substitute for person/entity name screening required for TFS.

*Source: IMF Fintech Note — VIRTUAL ASSETS AND ANTI-MONEY LAUNDERING AND COMBATING THE FINANCING OF TERRORISM (2): EFFECTIVE AML/CFT REGULATORY AND SUPERVISORY FRAMEWORK—SOME LEGAL AND PRACTICAL CONSIDERATIONS (Introduction).*

### Box 1. Digital ID

### Box 1. Digital ID

### Screening and targeted financial sanctions
- VASPs, like financial institutions (FIs) and DNFBPs, are required to implement measures to prevent funds or other assets being made available, directly or indirectly, to or for the benefit of, any person or entity on designated lists.
- All transactions must be screened against designated lists to prevent such actors from gaining access to the financial system.
- Screening controls should:
  - detect positive matches;
  - enable the capability to freeze the account and/or stop the transaction immediately; and
  - provide mechanisms to report matches to the relevant authorities and file a suspicious transaction report (per the requirements of the national framework).
- Total anonymity interferes with effective implementation of targeted financial sanctions; total anonymity is therefore not an option for VASPs.
- While a threshold for conducting CDD on occasional transactions may exist, such a threshold is not applicable in the context of targeted financial sanctions screening: all transactions must be screened.
- The names of the originator and beneficiary of transactions must be obtained in all instances to carry out sanctions screening effectively; additional verifying information (for example, proof of identity documentation, information, or data) must also be obtained to verify the accuracy of the names collected.

### Record-keeping and digital ledger technology (DLT)
- Information on customers and their transactions must remain available to competent authorities if and when necessary; VASPs should maintain that information like other reporting entities.
- DLT can act as an immutable ledger and, if properly maintained, can hold capabilities to record comprehensive information along with a trail to trace all transactions.
- Reliance solely on DLT is not sufficient. VASPs must “connect the dots” and link transaction information on the DLT to the relevant customer/beneficiary.
- The information available and level of accessibility depend on the specific DLT being utilized; VASPs should thoroughly understand the technology and implement compensatory controls where necessary to enable linkage of transactions to customers/beneficiaries.

### Wire transfer rules and the “travel rule”
- Preventing and detecting ML/TF/PF requires VASPs to know who the originator and beneficiary of a transaction are; some information must “travel” with the VA similar to how it accompanies a wire transfer—commonly called the “travel rule.”
- When transferring VAs, VASPs must obtain, hold, and transmit required originator and beneficiary information.
- Challenges for VASPs include implementing secure mechanisms for information transfer and ensuring required information accompanies transfers in “real time.”
- Various technologies and tools could enable compliance with aspects of the travel rule, but currently there are not sufficient technological solutions that enable VASPs to comply with all aspects of the travel rule in a holistic, instantaneous, and secure manner.
- Work is underway and a few initiatives are being developed that could potentially assist VASPs (for example, interVASP’s IVMS-101 Messaging Standard has potential to assist by operating as a universal common language between VASPs).
- Absent a global solution (akin to the SWIFT messaging system in the banking sector), ensuring interoperability of different systems is a key challenge.
- Note: discussions are underway, including in the context of the public consultation held by the FATF on what these obligations entail in the context of the transfer of VAs and the potential data protection and privacy complications; the revised “Guidance for a Risk-Based Approach to Virtual Assets and Virtual Asset Service Providers” (forthcoming) will provide further clarification.

### Monitoring and reporting of suspicious transactions
- Careful monitoring of customer behavior and transactions is key to identifying potential suspicious activity.
- VASPs should implement a robust system for monitoring and detection of ML/TF activity with sophistication commensurate to the size and scale of their activities and exposure to ML/TF risk.
- Systems should include VA ML/TF red flag indicators based on ML/TF typologies associated with VA activities; typologies often involve multiple red flags that, in aggregate, may lead to suspicion.
- VASPs should report suspicious transactions to the FIU via timely reporting mechanisms; jurisdictions must determine which FIU should receive reports for VASPs operating across multiple physical jurisdictions.
- A suspicious transaction report (STR) should contain all relevant details: customer(s) information; date(s) of transaction(s); rationale supporting the suspicion; and all other relevant information.
- FIUs should consider whether additional VA-specific information (for instance, device identifiers, VA wallet addresses, and transaction hashes) is required and whether reporting mechanisms/forms need updating to facilitate submissions by VASPs.
- New technologies such as artificial intelligence (AI) and machine learning can enhance detection of suspicious activity by handling large quantities of information and identifying patterns, but:
  - FIUs and supervisors should monitor evolution of these technologies;
  - VASPs and supervisors must ensure solutions are challenged/assessed continuously to remain fit for purpose;
  - AI solutions recognize known suspicious patterns and must be enriched continuously to keep up with new patterns or schemes;
  - caution is required to avoid overreliance on technology;
  - VASPs must maintain adequate in-house knowledge of such tools at commencement and on an ongoing basis;
  - VASPs must identify and assess ML/TF risks arising from use of new or developing technologies.

### Supervision and monitoring of VASPs’ AML/CFT compliance
- Effective AML/CFT implementation requires close cooperation among supervisors, competent authorities, and the private sector.
- Supervisors should:
  - work with competent authorities and the private sector to understand ML/TF/PF risks and help VASPs understand their risks;
  - clearly communicate regulatory expectations and provide guidance and feedback via ongoing dialogue and VASP-specific AML/CFT guidance;
  - collaborate and share information where multiple supervisors oversee VASPs to ensure coordinated and consistent supervision.
- Apply a risk-based approach to AML/CFT supervision informed by a thorough understanding of ML, TF, and PF risks posed by the VASP sector and by entity-level risk assessments.
- Supervisors may:
  - distribute supervisory returns requesting information on business models and AML/CFT systems and controls;
  - use FIU and law enforcement inputs, data on interbank settlements related to VASPs, crypto asset blockchain explorers, and public information to inform risk understanding.
- Inherent risk assessments should consider four main groups of factors: customers; products and services; geographic regions; and delivery channels (including higher-risk factors such as foreign PEPs).
- Supervisors should capture major ML/TF/PF risks faced by VASPs, including risks associated with products with enhanced anonymous features (for example, internet protocol anonymizers, mixers and tumblers) or links to multiple jurisdictions.
- Supervisory strategies should target higher-risk VASPs with enhanced offsite and onsite engagement, more frequent and in-depth inspections, closer offsite monitoring, and thematic inspections.
- Inspection modalities for VASPs may differ from traditional FIs; many tests may need to be conducted remotely and depend on technological solutions employed.
- Supervisors may engage third-party experts where necessary to assess business models, complex systems, and IT solutions.
- Supervisors should ensure VASPs maintain adequate oversight of RegTech solutions (for example, blockchain analytic software) and verify regular testing, renewal, and updates; tests of oversight should be case-by-case and challenge VASPs to demonstrate how they meet AML/CFT requirements.
- Supervisors need necessary resources, skills, and capabilities, which may require investment in training, personnel, and tools.
- Noncompliance should be met with dissuasive, proportionate, and effective sanctions; where warranted, consider suspension or revocation of license or removal from registration and sanctioning of directors and senior managers.
- Supervisors must understand VASP business models and AML/CFT internal controls to identify accountable individuals—a more complex task in contexts with fewer human interventions, such as smart contracts.
- Supervisors should consider publicizing enforcement results and alerting foreign counterparts given cross-border operations of many VASPs.

### Regulatory and supervisory cooperation
- The cross-border and online nature of VA activities makes international cooperation key for effective regulation and supervision of VASPs.
- Specific VASPs may be subject to AML/CFT frameworks of multiple jurisdictions, notably in the context of so-called global stablecoins.
- At licensing/registration, regulators may consult foreign counterparts who have authorized or rejected a VASP application to understand its regulatory history and overseas activities.
- Establishing AML/CFT supervisory colleges can facilitate information sharing and exchange among supervisors of VASPs operating in multiple jurisdictions.
- Sharing knowledge and experiences among jurisdictions enhances capacity to understand and mitigate ML/TF/PF risks in the sector.

### Conclusion and forward actions
- The 2018 and 2019 changes to FATF standards constitute major progress by clarifying regulation and supervision of VASPs and reducing regulatory arbitrage.
- Subjecting VASPs to measures similar to those applicable to FIs and DNFBPs encourages fair treatment of new virtual actors and increases VASPs’ interaction with the traditional financial sector; several VASPs have indicated benefits of implementing sound AML/CFT systems outweigh costs, notably by reassuring banks.
- Implementation remains challenging and uneven; emergence of global stablecoins may increase supervisory challenges (for example, more VASPs to supervise, greater business volume, greater market scale).
- Jurisdictions should ensure VASPs are subject to appropriate AML/CFT measures and that supervisors have know-how, powers, and resources to monitor compliance effectively.
- The international AML/CFT community should continue to monitor financial integrity risks related to VAs, ensure standards remain appropriate, assist jurisdictions in implementation, and address issues from uneven implementation and multiplicity of regulatory frameworks.
- The FATF has committed to issue more guidance (for example, on stablecoins, anonymous peer-to-peer transactions, the “travel rule,” and red flags for potential ML/TF); promote understanding of VA-specific ML/TF/PF risks; engage with the private sector; enhance international cooperation among VASP supervisors; and periodically take stock of implementation of standards on VA and VASP globally.
- IMF staff is committed to assist members through relevant workstreams, including capacity development activities, to strengthen financial integrity in the VA space.

*International Monetary Fund | October 2021*

### Annex 1. FATF Standards Related to

### Annex 1. FATF Standards Related to VAs and VASPs

### FATF Recommendation 15 and Interpretive Note
- Recommendation 15 “New Technologies,” second paragraph:
  - “To manage and mitigate the risks emerging from virtual assets, countries should ensure that virtual asset service providers are regulated for [anti–money laundering/combating the financing of terrorism] AML/CFT purposes, and licensed or registered and subject to effective systems for monitoring and ensuring compliance with the relevant measures called for in the FATF Recommendations.”
- Interpretive Note to Recommendation 15 highlights:
  - Countries should consider virtual assets as “property,” “proceeds,” “funds,” “funds or other assets,” or other “corresponding value” for the purposes of applying the FATF Recommendations and apply relevant measures to virtual assets and VASPs.
  - In accordance with Recommendation 1, countries should identify, assess, and understand ML/TF risks emerging from virtual asset activities and VASP operations and apply a risk-based approach proportionate to identified risks. Countries should require VASPs to identify, assess, and take effective action to mitigate their ML/TF risks.

### Licensing, Supervision, and Sanctions
- Licensing/registration requirements:
  - VASPs should be required to be licensed or registered. At a minimum, VASPs should be required to be licensed or registered in the jurisdiction(s) where they are created. In cases where the VASP is a natural person, they should be required to be licensed or registered in the jurisdiction where their place of business is located.
  - Jurisdictions may also require VASPs that offer products and/or services to customers in, or conduct operations from, their jurisdiction to be licensed or registered in this jurisdiction.
  - Competent authorities should take necessary legal or regulatory measures to prevent criminals or their associates from holding, or being the beneficial owner of, a significant or controlling interest, or holding a management function in, a VASP.
  - Countries should take action to identify natural or legal persons that carry out VASP activities without the requisite license or registration and apply appropriate sanctions.
- Interaction with existing financial institution licensing:
  - A country need not impose a separate licensing or registration system with respect to natural or legal persons already licensed or registered as financial institutions (as defined by the FATF Recommendations) within that country, which, under such license or registration, are permitted to perform VASP activities and which are already subject to the full range of applicable obligations under the FATF Recommendations.
- Supervision and monitoring:
  - Countries should ensure that VASPs are subject to adequate regulation and supervision or monitoring for AML/CFT and are effectively implementing relevant FATF Recommendations.
  - VASPs should be subject to effective systems for monitoring and ensuring compliance with national AML/CFT requirements.
  - VASPs should be supervised or monitored by a competent authority (not a [self-regulatory body] SRB), which should conduct risk-based supervision or monitoring.
  - Supervisors should have adequate powers to supervise or monitor and ensure compliance by VASPs with requirements to combat money laundering and terrorist financing including the authority to conduct inspections, compel the production of information, and impose sanctions.
  - Supervisors should have powers to impose a range of disciplinary and financial sanctions, including the power to withdraw, restrict or suspend the VASP’s license or registration, where applicable.
- Sanctions:
  - Countries should ensure that there is a range of effective, proportionate, and dissuasive sanctions, whether criminal, civil, or administrative, available to deal with VASPs that fail to comply with AML/CFT requirements, in line with Recommendation 35.
  - Sanctions should be applicable not only to VASPs, but also to their directors and senior management.

### Preventive Measures and Customer Due Diligence
- Application of Recommendations 10 to 21 to VASPs, with qualifications:
  - (a) R.10 – The occasional transactions designated threshold above which VASPs are required to conduct CDD is USD/EUR 1 000.
  - (b) R.16 – Countries should ensure that originating VASPs obtain and hold required and accurate originator information and required beneficiary information on virtual asset transfers, submit the above information to the beneficiary VASP or financial institution (if any) immediately and securely, and make it available on request to appropriate authorities.
    - Countries should ensure that beneficiary VASPs obtain and hold required originator information and required and accurate beneficiary information on virtual asset transfers and make it available on request to appropriate authorities.
    - Other requirements of R.16 (including monitoring of the availability of information and taking freezing action and prohibiting transactions with designated persons and entities) apply on the same basis as set out in R.16.
    - The same obligations apply to financial institutions when sending or receiving virtual asset transfers on behalf of a customer.
- Supervisory powers and obligations for VASPs to implement AML/CFT measures and make information available to authorities.

### International Cooperation
- Countries should rapidly, constructively, and effectively provide the widest possible range of international cooperation in relation to money laundering, predicate offences, and terrorist financing relating to virtual assets, on the basis set out in Recommendations 37–40.
- Supervisors of VASPs should exchange information promptly and constructively with their foreign counterparts, regardless of the supervisors’ nature or status and differences in the nomenclature or status of VASPs.

### Glossary
- Virtual Asset:
  - “A virtual asset is a digital representation of value that can be digitally traded, or transferred, and can be used for payment or investment purposes. Virtual assets do not include digital representations of fiat currencies, securities and other financial assets that are already covered elsewhere in the FATF Recommendations.”
- Virtual Asset Service Providers:
  - “Virtual asset service provider means any natural or legal person who is not covered elsewhere under the Recommendations, and as a business conducts one or more of the following activities or operations for or on behalf of another natural or legal person:
    - (i) exchange between virtual assets and fiat currencies;
    - (ii) exchange between one or more forms of virtual assets;
    - (iii) transfer of virtual assets;
    - (iv) safekeeping and/or administration of virtual assets or instruments enabling control over virtual assets; and
    - (v) participation in and provision of financial services related to an issuer’s offer and/or sale of virtual assets.”
  - Transfer in this context: “transfer means to conduct a transaction on behalf of another natural or legal person that moves a virtual asset from one virtual asset address or account to another.”

### Annex 2. ML/TF Red Flag Indicators
- FATF guidance:
  - The FATF published a list of virtual assets—red flag indicators. Countries should ensure these flags are incorporated (where applicable) into transaction monitoring systems.
  - VASPs should use the six categories highlighted in the report as a framework to identify additional red flags tailored to their activities and associated ML/TF risk:
    - Transactions
    - Transaction Patterns
    - Anonymity
    - Senders or Recipients
    - Source of Funds or Wealth
    - Geographical Risks
- US Financial Crimes Enforcement Network examples:
  - “A customer receives a series of deposits from disparate sources that, in aggregate, amount to nearly identical aggregate funds transfers to a known virtual currency exchange platform within a short period of time.”
  - “A customer’s transactions are initiated from non-trusted IP addresses, IP addresses from sanctioned countries, or IP addresses previously flagged as suspicious.”
  - “A customer provides identification or account credentials (for example, non-standard password, IP address, or flash cookies) shared by another account.”
  - “A common wallet address is shared between customers.”
  - “A customer initiates multiple rapid trades between multiple virtual currencies with no related purpose, which may be indicative of attempts to break the chain of custody on the respective blockchains or further obfuscate the transaction.”

*International Monetary Fund | October 2021*

---


_Source: https://www.imf.org/-/media/files/publications/ftn063/2021/english/ftnea2021003.pdf_
