You've read the interpretive notes. Your legal team signed off on the policy. But somewhere between FATF Recommendation 15 and your actual compliance program, a myth took root, and it's creating gaps that regulators will find.
These myths persist because FATF's standards for virtual assets evolved faster than most compliance frameworks could absorb. The 2019 clarifications on Virtual Asset Service Providers introduced obligations that don't map cleanly to traditional financial institution rules, and the industry filled the gaps with assumptions. Some of those assumptions are wrong.
Here's what VASPs still get wrong about FATF compliance, and what the standards actually require.
Myth 1: The Travel Rule Only Applies When You're Sending Crypto
Reality: You're obligated when you're the originating VASP and when you're the beneficiary VASP.
FATF Recommendation 16 (the Travel Rule) requires you to obtain, hold, and transmit originator and beneficiary information for virtual asset transfers. That's a two-sided obligation. If you're receiving a transfer on behalf of a customer, you must obtain the required information from the sending VASP and verify that the beneficiary information is accurate.
Many VASPs built systems that capture and transmit data when their customers send funds, but they don't validate incoming transfers properly. That's half a compliance program. When a customer receives crypto, you need to confirm the counterparty VASP provided the originator's name, account number (or wallet address), and physical address, plus your customer's information. If the data's missing or incomplete, you're required to reject the transfer or file a Suspicious Activity Report, not just accept it and hope for the best.
Regulators don't just review your outbound transaction logs; they sample incoming transfers and ask why you accepted funds with incomplete Travel Rule data.
Myth 2: If You're Not Custodying Assets, You're Not a VASP
Reality: FATF's definition of a VASP includes non-custodial services if you're conducting covered activities for or on behalf of customers.
FATF defines VASPs as entities that conduct transfer of virtual assets, exchange between virtual and fiat currencies, exchange between virtual asset types, or participation in financial services related to virtual assets. The key phrase is "for or on behalf of another person." Custody isn't the trigger, facilitation is.
If you operate a platform that enables peer-to-peer trades and you're involved in the transaction flow (even as an intermediary matching orders or holding funds in escrow), you're likely a VASP under FATF's framework. If you provide wallet software but never touch the private keys, you're probably not, but the line isn't about custody, it's about whether you're conducting a covered activity as a service.
This myth creates risk when companies assume they're exempt because they're "non-custodial," but they're still executing transfers or exchanges on behalf of users. FATF's guidance is function-based, not label-based.
Myth 3: You Can Rely on Blockchain Analytics to Satisfy Customer Due Diligence
Reality: Blockchain analytics is a risk assessment tool, not a substitute for CDD.
FATF requires VASPs to conduct Customer Due Diligence (CDD), that means identifying and verifying the customer's identity using reliable, independent source documents or information. Blockchain analytics can tell you a wallet has interacted with a mixing service or a sanctioned address, but it can't verify who controls the wallet or confirm the customer's identity.
You still need to collect name, date of birth, address, and identification documents for natural persons, and registration details for legal entities. You still need to verify that information against independent sources. You still need to understand the nature and purpose of the business relationship.
Blockchain analytics belongs in your transaction monitoring and risk rating processes. It helps you detect suspicious patterns, assess counterparty risk, and assign customer risk ratings. But it doesn't replace the foundational CDD requirement to know who your customer actually is. Regulators expect both: verified identity information and transaction behavior analysis.
Myth 4: FATF Standards Are Recommendations, So You Have Flexibility
Reality: FATF Recommendations become legally binding when your jurisdiction implements them into national law.
FATF is a standard-setting body, not a regulator. It issues Recommendations, currently 40 of them, that member countries commit to implement. Once a country enacts those standards into domestic legislation (through AML acts, virtual asset regulations, or licensing rules), they're no longer optional. They're law.
In the U.S., FinCEN's 2019 guidance on virtual currencies and the BSA/AML framework incorporate FATF's standards. In the EU, the Fifth Anti-Money Laundering Directive (5AMLD) and the forthcoming Markets in Crypto-Assets Regulation (MiCA) reflect FATF's requirements. In Singapore, the Payment Services Act codifies them.
When you see "FATF Recommendation 15," understand that it's shorthand for the actual enforceable rule in your jurisdiction. You don't get to treat it as aspirational. Your regulator will assess you against the implemented version, and they'll reference FATF's interpretive notes and guidance when they evaluate your program.
Myth 5: Small VASPs Get a Pass on Full FATF Compliance
Reality: FATF standards apply to all VASPs; jurisdictions may set thresholds, but you're not automatically exempt.
There's no materiality waiver in FATF Recommendation 15. The standards apply to VASPs regardless of transaction volume or customer count. Some jurisdictions create registration thresholds or tiered licensing (where smaller operators face lighter requirements), but that's a national policy choice, not a FATF exemption.
If you're operating below a registration threshold, you're not exempt from AML/CFT obligations; you're just not required to register. You still can't facilitate money laundering or terrorist financing. You're still subject to general criminal law. And if your jurisdiction later lowers the threshold or you cross it through growth, you'll need a compliant program immediately.
More important: even if you're technically below a threshold, regulators can pursue enforcement if you're involved in suspicious activity. Being small doesn't mean being invisible.
What to Do Instead
Start with FATF Recommendation 15 and the 2021 updated guidance on virtual assets and VASPs. Read the interpretive note, it's more specific than the Recommendation itself. Then map those requirements to your jurisdiction's implementing regulations.
Build your CDD process around identity verification first, then layer in blockchain analytics for transaction monitoring and risk rating. Don't reverse the order.
For Travel Rule compliance, implement technical solutions that handle both origination and beneficiary obligations. Test your system with incomplete incoming data to confirm it rejects or escalates properly.
If you're uncertain whether your business model makes you a VASP, apply the functional test: are you conducting transfers, exchanges, or safekeeping of virtual assets for or on behalf of another person? If yes, you're likely covered. Get a legal opinion based on your specific activities and jurisdiction, not on industry assumptions.
Finally, treat FATF guidance updates as compliance triggers. When FATF publishes new interpretive notes or revised standards, your program needs to reflect them within the timeframe your jurisdiction sets for implementation, usually 12 months or less.
The myths persist because they're convenient. The reality is less flexible, but it's also clearer than most VASPs assume.



