top of page

The Supervisor's Playbook: What FATF's New Manual Signals

  • Writer: Elizabeth Travis
    Elizabeth Travis
  • Jul 24
  • 8 min read

Stack of black binders or books on a wooden table, with white page edges, in a blurred warm-toned café or library setting

The travel rule has been legislated almost everywhere. The FATF has now written down how it will be enforced


For years, one question hung over Recommendation 16 (R16): would regulators ever move from writing the rule to enforcing it? The Financial Action Task Force (FATF) answered it quietly. On 26 June 2025, alongside its sixth targeted update on virtual assets, the FATF published its Best Practices on Travel Rule Supervision, catalogued as FATF/PDG(2025)18. The targeted update supplied the familiar diagnosis: adoption has raced far ahead of supervision. The manual is the prescription, and it has drawn less attention than it deserves. It is the first FATF document devoted specifically to how the travel rule is supervised, setting out in operational detail what a competent inspection actually looks like.


The distinction matters more than it appears. A manual written to instruct supervisors is, read from the other side of the desk, a preview for the supervised. The questions a regulator is told to ask are the questions a firm will one day have to answer. The FATF has now written them down.


Enforcement was never the first move


The manual opens by dismantling a comfortable assumption. A low number of enforcement actions, the FATF cautions, does not signal regulatory tolerance. It may reflect supervisors concentrating their early efforts on educating firms rather than sanctioning them, or working with firms to remediate shortcomings caught at licensing rather than punishing failures after the event. The quiet years were not idle years. They were preparation.


Firms that read the absence of fines as leniency have misread the sequence. Education precedes enforcement; it does not replace it. The remediation conversations, thematic reviews and supervisory returns the FATF describes are how a regulator assembles the evidence base that makes later enforcement defensible. The grace period was a supervisor sharpening its instruments in plain sight of a sector that assumed it was being left alone. The FATF is blunt that this phase is closing: it records a growing body of enforcement examples in jurisdictions with more mature supervision. This is not tolerance giving way to crackdown. It is groundwork giving way to consequence.


The examination starts before the licence


The most striking theme in the manual is how far supervision now reaches back into licensing itself. The old model licensed a firm on its documentation and tested reality only if something later went wrong. The new model inverts that. It tests reality first.


In the Bahamas, applicants may be required to attend a meeting with the supervisor to demonstrate their operational capabilities and technological solutions, including their ability to comply with the travel rule, following an off-site review of their policies. Compliance is not asserted on paper and confirmed at leisure. It is demonstrated, live, as a condition of entry. Elsewhere the manual describes pre-licensing on-site visits built around walk-through discussions, in which applicants must evidence not only their travel rule controls but their enhanced measures for higher-risk scenarios such as transfers to unhosted wallets. The FATF is candid about what these walk-throughs expose. The common deficiencies it lists are a poor grasp of the requirements, an unwillingness or inability to put adequate measures in place, and, most tellingly, no awareness of the limitations of the very tools the applicant has chosen. That last failing is the quiet one. A firm that does not understand where its chosen solution falls short cannot compensate for the gap, and the supervisor now expects it to have done exactly that before it opens for business.


Kazakhstan runs a variation on the same principle. Within the Astana International Financial Centre, virtual asset service providers (VASPs) pass through the Astana Financial Services Authority's regulatory sandbox, each assigned a dedicated case officer who evaluates the firm's anti-money laundering (AML) controls, travel rule provisions included, before the business goes live. The sandbox is not a courtesy. It is a controlled environment in which a supervisor watches a firm's controls behave under conditions close to the real thing, and forms a view before any customer money is at stake. Singapore engaged directly with compliance tool providers to understand the technology on the market and calibrate its expectations before firms were left to implement alone, categorising VASPs by risk on the strength of what it learned. Three jurisdictions, three methods, one conviction: the burden of proof belongs at the front of the relationship, not the back. The implication for firms is stark. The audit does not begin when an examiner arrives. It begins at the application.


Transparency is becoming a supervisory instrument


The manual is equally clear that enforcement, when it comes, is meant to be seen. It points to Japan, where the Financial Services Agency publishes summaries of its supervisory actions when it orders remediation, suspends business or revokes a licence. The rationale is deliberate: other firms study the published failings and check their own systems against them. One enforcement action becomes a signal to the entire sector.


This breaks with the private, bilateral tradition of much financial supervision, and it changes the calculus for every firm in a market that adopts it. A weakness found in a competitor is no longer a confidential problem safely belonging to someone else. It is a published account of exactly what a supervisor treats as failure, and an implicit instruction to fix the same weakness before an examiner finds it. The manual's endorsement of thematic and multi-firm reviews sharpens the point further.

Supervisors increasingly examine the sector, not merely the firm. Common weaknesses are now systemic risks, addressed at scale. The logic is efficient and, for firms, exacting: a deficiency identified once can be pursued across every firm that shares it, without a fresh investigation each time. Watching your own controls is no longer enough. The published failings of your peers have become part of the record you are expected to have read.


The uncomfortable question of who is at fault


There is a tension here the manual does not resolve, and firms should meet it honestly. The FATF accepts that travel rule tools carry gaps and deficiencies, and that interoperability between competing protocols remains unsolved. It records the sunrise issue plainly: until every jurisdiction implements the rule, firms in compliant jurisdictions will keep meeting transactions they cannot complete compliantly, because the counterparty has no obligation to reciprocate. A firm can do everything asked of it and still be unable to close the loop.


This is the genuine grievance of the well-run firm, and it is not imaginary. The infrastructure is immature, the protocols do not always speak to one another, and a conscientious originator can find its carefully collected data with nowhere to go. The supervisory answer, however, is unsentimental.

The manual treats tool deficiencies and interoperability gaps as challenges to be managed, not as defences, and it commends supervisors who publish firms' failings precisely so the rest of the sector can check its own systems against them. Imperfect infrastructure is a mitigating context, not an excuse. The obligation is to show a defensible, risk-based response to the gaps, documented and deliberate, not to treat the gaps as licence to do nothing. Transmit to an unregulated counterparty without due diligence, or leave a known tool limitation unaddressed, and no amount of systemic immaturity will spare you. Operational realism cuts both ways. The supervisor accepts the environment is imperfect. It expects the firm to have engineered around that imperfection, not sheltered behind it.


From control existence to control effectiveness


Read whole, the manual describes one decisive migration: from checking that controls exist to testing whether they work. Live demonstrations, dedicated case officers, thematic and multi-firm reviews, supervisory returns, published enforcement summaries. Every instrument probes operational reality rather than documentary comfort. A firm can hold a travel rule solution, connect it to a recognised protocol and generate an immaculate audit trail, and still fail every test the FATF describes if the data is incomplete, the counterparty unverified, or no accountable individual reviews what the system produces.


The distinction is not rhetorical. It decides what a firm should be building. Procuring a compliant tool satisfies control existence. Demonstrating, on demand, that the tool ingests accurate originator and beneficiary data, screens counterparties in real time and feeds its output to a named, accountable officer satisfies control effectiveness. These are not the same investment, and they are rarely the same cost. The first can be bought from a vendor. The second has to be built into how a firm operates, governed and owned by someone who can answer for it. The manual is a catalogue of the methods supervisors will use to tell the two apart. It rewards the firm that can show its controls working. It exposes the firm that can only show its controls were bought.


Implications for firms


The practical consequence is simple. Prepare for the standard the manual describes, not the one your home regulator applies today. Supervisory expectations converge upward, never downward, and the FATF has just handed every lagging authority a ready-made template assembled from the jurisdictions furthest ahead. A supervisor that has never run a travel rule inspection now has worked examples from the Bahamas, Japan, Singapore and Kazakhstan to copy. The distance between the most demanding regime and the least will close, and it will close in one direction. A firm calibrated to a lenient home supervisor is not compliant so much as fortunate, and its good fortune has an expiry date.


Three questions follow from the manual, and a firm should answer them before an examiner does. Can it demonstrate its travel rule capability live, against real transfer flows, rather than describe it in a policy? Is its originator and beneficiary data accurate and verified, or merely present and correctly formatted? And is there a named individual accountable for the decisions the system produces, so the audit trail rests on human governance rather than protocol output alone? A firm that can answer all three has little to fear from the methods the manual describes. A firm that cannot has been told, in advance and in detail, where it will be found wanting. These are not speculative concerns raised out of caution. They are the questions the manual's methods are built to answer, drawn from regulators already asking them.


Conclusion


The travel rule spent a decade as a rule on paper. The FATF's supervision manual is the moment the paper began to acquire teeth, not through a wave of fines but through the patient construction of a method almost any jurisdiction can now adopt. It reads less like guidance than a rehearsal script. The firms that treat it that way will recognise the questions when they are finally put; the firms that dismiss it will meet those same questions cold, in a room with an examiner. Legislation was always the easy part. Supervision was always the real test. The FATF has published the exam paper. The only question left is who has revised.


Could your firm demonstrate its travel rule controls live, the way the FATF now expects a supervisor to ask?


We help payments firms, banks and VASPs move from documented compliance to demonstrable compliance, rehearsing travel rule controls against the supervisory methods the FATF now commends rather than the paper assurances regulators have stopped accepting.


Our work tests control effectiveness across the full transfer chain, from data quality at origination to counterparty verification and accountable governance, and it treats the imperfect infrastructure firms must operate within as a problem to be engineered around, not an excuse to lean on.


To rehearse the examination before a regulator sets it, contact us.

bottom of page