Financial Action Task Force (FATF) revised Recommendation 16 in June 2025 to strengthen payment transparency, improve the consistency of originator and beneficiary information, and introduce measures to prevent payments from being sent to unintended recipients.
In June 2026, FATF published draft guidance explaining how financial institutions could implement these requirements. The related public consultation closed on 21 August 2026, so the final guidance and consultation results are yet to be published.
Nevertheless, the revised Recommendation and draft guidance already highlight several practical issues that compliance and operational-risk teams should begin considering. These include more structured data, beneficiary-alignment controls and greater payment transparency.
For CASPs, the challenge is not simply to update a Travel Rule policy. It is to implement these controls without creating transaction delays, data-protection risks or operational vulnerabilities.
This is where the FATF Recommendation 16 and the EU’s DORA intersect. While DORA compliance is only mandatory for European CASPs, the principles are relevant for responsible VASPs globally.
Travel Rule compliance relies on technology that collects sensitive personal data, communicates with counterparties and may perform checks before a transaction is completed. If this technology becomes unavailable, processes data incorrectly or creates bottlenecks, the impact can go beyond compliance and disrupt the entire transaction flow.
So, what should compliance and operational-risk teams pay attention to?
1. Prepare for beneficiary-alignment controls
Under the revised Recommendation 16, beneficiary financial institutions will need to take measures to reduce the risk of payments being sent to unintended recipients.
These measures may include transaction-level checks, broader risk-based monitoring or pre-validation mechanisms involving both institutions.
Crypto service providers will need to define how these checks should be performed and what should happen when information is missing, does not match or cannot be verified in time. Although FATF does not prescribe a single technical workflow, automated rules can help process straightforward cases while sending incomplete or potentially misdirected transactions for further review.
Other than the FATF guidance, paying more attention to the verification of payees also makes sense for crypto PSPs – unlike users depositing or withdrawing funds from their exchange accounts, stablecoin payments need to replicate controls familiar from the fiat space
2. Build for data standardization
The revised Recommendation 16 moves towards more structured originator and beneficiary information, using established messaging standards such as ISO 20022 where appropriate. It also introduces more consistent information requirements and identifiers such as LEIs for legal entities, where available.
Companies should assess whether their internal systems and technology providers can adapt to these requirements and exchange information reliably across different networks and legacy systems.
3. Balance transparency with privacy
Collecting and sharing more personal information also creates greater data-protection responsibilities.
Cross-border Travel Rule messaging must take into account GDPR requirements, data minimization, secure storage and restrictions on international data transfers.
Compliance teams should understand where personal data is processed, how long it is retained, which parties can access it and what safeguards apply when it crosses borders.
4. Treat operational resilience as part of Travel Rule compliance
Under DORA, European CASPs must manage ICT risks and dependencies on third-party technology providers. This makes the reliability, security and recoverability of Travel Rule infrastructure an important part of vendor assessment.
Availability, incident response, business continuity, data integrity and information security should therefore be considered alongside regulatory functionality.
The revised Recommendation does not prescribe a single technical process. The main challenge for compliance teams will be translating its requirements into practical and proportionate controls that improve payment transparency without creating unnecessary delays or operational risks.
Sources: