During May 6-10, 2019, the FATF (Financial Action Task Force) held a private sector consultation on new AML policies related to “virtual assets” and “virtual asset service providers.” Representatives including regulators, financial intelligence units, financial institutions, and even a few blockchain companies provided both regulatory and industry insights on the proposed changes. As a regtech firm for fintechs, the iComply team provided a unique voice at the plenary, advocating on behalf of our clients and users. 

The FATF is the global oversight body for AML regulators around the world. In short, they regulate the regulators. The new FATF recommendations (specifically, 15 and 16) will impact how regulators define virtual assets, regulate virtual asset service providers, and enforce transaction-level audit trails. 

While the new FATF recommendations cover a much broader set of regulations, there are three key areas that will have the greatest impact on blockchain or cryptocurrency powered fintechs.

  • The definition of “Virtual Assets” casts the net widely, covering nearly all fungible, purchasable, and tradable digital assets. The regulations of virtual assets will be viewed in the same way cash is today. Non-fungible assets, such as ERC721 tokens, in certain use cases, may present opportunities to avoid being caught under the virtual assets definition.
  • The definition of “Virtual Asset Service Providers” (VASPs) encompasses any individual or corporation that holds virtual assets or the private keys to virtual assets on behalf of another party. Entities operating within the scope of a VASP today will need to review their core activities, such as promotion, distribution, custody, transfer, exchange, etc., for new reporting obligations. Interestingly, these new regulations may also drive the industry towards fully non-custodial Dex technology which was excluded from the policy discussions.
  • Recommendation 15.7(b) was by far the most controversial and highly contested policy discussed at the event. While the requirements of R.15.7(b) may be easily solved with a wide variety of technologies, adopting any standard will require global industry collaboration; the primary solutions presented during the meetings present massive risk and liability in the areas of privacy and identity regulations  in addition to questions of power, control, privacy, and the use of personal information.

R.15.7(b) attempts to “copy and paste” funds-transfer regulation onto the transfers of digital assets. This would require any virtual asset service provider to report the beneficiary and originator of any virtual asset transferregardless of size or jurisdictionthrough a database or data framework shared between the regulators and the market.

Aside from the new regulatory proposals, the plenary’s discussion focused on a much larger conversation: who determines the balance among privacy, digital identity, and market integrity regulations?

Some countries, such as the United States and Japan, showcased their own solutions for a centralized global data repository as presented by Verasign and Softbank, respectively. Here is a screenshot from one proposed solution, an “Equifax for virtual asset transactions”.

Big Data, Privacy, and Market Surveillance

Technically speaking, the ability to create a single, globally-centralized database housing the name, account number, home address, all wallet addresses, and the transaction number of every virtual transaction ever created is not difficult…until you get into the specifics of who has the power to control and access this data. 

More challenging than simply creating a global data repository is gaining market adoption. The virtual asset (a.k.a. cryptocurrency) industry has had difficulty with this to date. Threats of blockchain forks, or competitions over which chain best reflects the original vision of Satoshi Nakamoto, have created a fledgling industry full of tribal feudalism. 

Furthermore, establishing policies, best practices, or open source standards for maintaining the records of beneficial ownership and source of wealth for every cryptocurrency transaction opens a Pandora’s Box of questions regarding privacy, consent, GDPR, PIPA, and geopolitical power struggles. 

From cybersecurity, privacy, and data protection perspectives, handing over the power and control of both the identity and transactions of all public blockchains to a small handful of major corporations seems flawed from the start. While these honeypots of data are easy to create, they pose significant threats and potential harm to the trust and integrity of decentralized financial markets globally. 

 

Shared Standards and Interoperability

Luckily decentralized technology such as blockchain also presents viable solutions ─ many of which are already in use in the market today. Applied correctly, public blockchain technology can do a significantly better job of protecting the rights and privacy of a user while meeting AML obligations ─ provided the blockchain industry can agree on and implement a shared standard in time.

Simply using a public blockchain doesn’t prevent the ultimate aggregation of power and control if it is not done in an open, transparent, and decentralized manner. Solutions such as iComply’s Wallet Ownership Verification already address one part of the problem. Decentralized or self-sovereign identity solutions could solve other pieces, but they still leave significant gaps to fill.

All in all, the viability of public blockchains in regulated finance will come down to whether the industry can agree to establish and adopt standards for consent, privacy, and data sharing. As a leading regtech provider, and the only digital identity or asset tokenization solution invited to the FATF plenary, we at iComply considered it our duty to help raise awareness of the need for balanced regulations and enforcement policies that take a more holistic view of compliance; for example, how do we balance the requirements of R.15.7(b) with the requirements of MIFID, GDPR, or PIPA? 

Despite the challenges they present, these shifts in the regulatory fabric of global digital finance also present a number of exciting opportunities for the industry.

  • Early Adopters who successfully implement the new requirements stand to gain market share and increased scalability, while their late-to-the-game competitors struggle to catch up. Since the dawn of the computer, advancements in technology have created new regulatory problems to tackle; and adopting a shared standard for interoperability has proven highly effective. Stock exchanges globally run on the FIX protocol, identity standards are benchmarked against the FIDO protocol, and the first 200 correspondent banks to adopt SWIFT set the global standard. While there remains much debate whether these new regulations are over-reaching, it is unlikely that this will reverse these new changes before the industry implements solutions.

     If you are interested in contributing to this conversation, contact us.

  • Payment Services and Virtual Asset Exchanges will see several major changes to how they operate, with significant variations in reporting requirements or regulatory oversight by jurisdiction. This gets even more complex where an exchange is engaged in the issuance of utility or security tokens. The silver lining to these businesses is that compliance with these new regulatory requirements is one of the final technological hurdles for blockchain-powered exchanges and payments businesses to enter into the more lucrative institutional markets. 

 

  • OTC Brokers and Trading Desks, including individuals facilitating OTC transactions, will be impacted significantly by the new compliance requirements these regulations will have on daily operations. However, in our conversations with iComply clients and partners who operate in the OTC market, the adoption of technology to meet regulatory requirements presents a larger opportunity, as the disclosure of beneficiary and originator data on an OTC transaction will remove significant instances of fraud, lost deals, and shady OTC agents throughout the industry as a whole. 

While the new regulations will see some variations as each jurisdiction begins implementing these AML requirements, iComply is dedicated to supporting our clients and partners as we navigate these changes.

Many fintech businesses now have questions about how these new regulations may impact their compliance program, competitive position, or ability to scale their business in the face of these new requirements. 

Click here to speak with an iComply representative if your business is interested in joining the discussion of virtual asset regulation, or if you have questions on how your business can best position itself to achieve compliance in an evolving regulatory landscape.

About iComply Investor Services Inc.
iComply Investor Services Inc. (iComply) is Regtech for Fintech, an award-winning software company focused on reducing regulatory friction in the digital finance. With powerful data, verification, tokenization solutions, iComply helps companies overcome the cost, complexity, and risks of multi-jurisdictional compliance in order to effectively access new markets. Learn more: iComplyIS.com

2025 Outlook: Data Privacy and Security in KYB, KYC, AML Compliance
2025 Outlook: Data Privacy and Security in KYB, KYC, AML Compliance

In today’s rapidly changing digital landscape, data privacy and security are more crucial than ever for compliance teams. As regulations tighten and cyber threats evolve, businesses must prioritize innovative solutions. Enter edge computing, a game-changer for KYC,...

Vaidyanathan Chandrashekhar

Vaidyanathan Chandrashekhar

Advisors

“Chandy,” is a technology and risk expert with executive experience at Boston Consulting Group, Citi, and PwC. With over two decades in financial services, digital transformation, and enterprise risk, he advises iComply on scalable compliance infrastructure for global markets.
Thomas Linder

Thomas Linder

Advisors

Thomas is a global tax and compliance expert with deep specialization in digital assets, blockchain, and tokenization. As a partner at MME Legal | Tax | Compliance, he advises iComply on regulatory strategy, cross-border compliance, and digital finance innovation.
Thomas Hardjono

Thomas Hardjono

Advisors

Thomas is a renowned identity and cybersecurity expert, serving as CTO of Connection Science at MIT. With deep expertise in decentralized identity, zero trust, and secure data exchange, he advises iComply on cutting-edge technology and privacy-first compliance architecture.
Rodney Dobson

Rodney Dobson

Advisors

Rodney is the former President of ADP Canada and international executive with over two decades of leadership in global HR and enterprise technology. He advises iComply with deep expertise in international service delivery, M&A, and scaling high-growth operations across regulated markets.
Praveen Mandal

Praveen Mandal

Advisors

Praveen is a serial entrepreneur and technology innovator, known for leadership roles at Lucent Bell Labs, ChargePoint, and the Stanford Linear Accelerator. He advises iComply on advanced computing, scalable infrastructure, and the intersection of AI, energy, and compliance tech.
Paul Childerhose

Paul Childerhose

Advisors

Paul is a Canadian RegTech leader and founder of Maple Peak Group, with extensive experience in financial services compliance, AML, and digital transformation. He advises iComply on regulatory alignment, operational strategy, and scaling compliance programs in complex markets.
John Engle

John Engle

Advisors

John is a seasoned business executive with senior leadership experience at CIBC, UBS, and Accenture. With deep expertise in investment banking, private equity, and digital transformation, he advises iComply on strategic growth, partnerships, and global market expansion.
Jeff Bandman

Jeff Bandman

Advisors

Jeff is a former CFTC official and globally recognized expert in financial regulation, fintech, and digital assets. As founder of Bandman Advisors, he brings deep insight into regulatory policy, market infrastructure, and innovation to guide iComply’s global compliance strategy.
Greg Pearlman

Greg Pearlman

Advisors

Greg is a seasoned investment banker with over 35 years of experience, including leadership roles at BMO Capital Markets, Morgan Stanley, and Citigroup. Greg brings deep expertise in financial strategy and growth to support iComply's expansion in the RegTech sector.
Deven Sharma

Deven Sharma

Advisors

Deven is the former President of S&P and a globally respected authority in risk, data, and capital markets. With decades of leadership across financial services and tech, he advises iComply on strategic growth, governance, and the future of trusted data in AML compliance.