AML/CTF supervision is becoming increasingly operational and data-driven. Recent developments show regulators focusing not only on whether businesses have AML policies in place, but on whether those frameworks work in practice: whether customer risk is properly assessed, suspicious activity is identified and reported, transaction monitoring is effective, and new business models such as DeFi are subject to appropriate controls.
This month’s RegRally highlights the developments most relevant to financial institutions, CASPs, fintechs and other obliged entities operating in Lithuania and across the EU.
This month at a glance
- Virtual assets: FATF identifies continuing gaps in Travel Rule implementation, VASP supervision and risk mitigation, while highlighting stablecoins, unhosted wallets and offshore VASPs as growing risk areas.
- DeFi: FATF takes a functional approach to determining when supposedly decentralised arrangements fall within AML/CFT requirements.
- EU reporting: AMLA is developing a harmonised EU format for suspicious transaction reporting and transaction data, potentially replacing fragmented national reporting approaches.
- Ongoing monitoring: AMLA is preparing horizontal guidance on customer information updates and ongoing monitoring applicable across obliged entities.
- Lithuania: FNTT’s 2025 inspections show that deficiencies in CDD, record keeping, internal controls, employee training and suspicious transaction reporting remain key enforcement risks.
Quick Navigation
- FATF identifies continuing gaps in VASP supervision and highlights emerging virtual asset risks
- FATF warns that DeFi is increasingly exposed to money laundering and other financial crime risks
- AMLA moves towards a harmonised EU format for suspicious transaction reporting
- AMLA develops EU-wide guidance on ongoing monitoring of business relationships
- FNTT enforcement data shows where Lithuanian AML controls continue to fail
FATF identifies continuing gaps in VASP supervision and highlights emerging virtual asset risks
Date: 16 July 2026 | Source: Financial Action Task Force (FATF)
Link
What happened?
FATF published its seventh targeted update on the implementation of Recommendation 15 concerning virtual assets and virtual asset service providers (VASPs).
The report identifies continued global progress in implementing the Travel Rule: 83% of surveyed jurisdictions have now passed Travel Rule legislation, compared with 73% in 2025.
At the same time, significant implementation gaps remain. These include translating risk assessments into effective mitigation measures, operationalising licensing and registration frameworks, identifying persons conducting VASP activities, and ensuring effective risk-based supervision and enforcement.
FATF also highlights emerging risks involving the use of virtual assets for organised fraud and money laundering, with particular attention to stablecoins, peer-to-peer transactions involving unhosted wallets and offshore VASPs.
Why does it matter for businesses?
The report reinforces that virtual asset businesses are moving into a more mature supervisory environment. Having a Travel Rule solution or VASP licence is not, by itself, sufficient: supervisors are increasingly likely to assess whether the underlying risk assessment and controls actually address the relevant typologies.
For CASPs, exposure to stablecoins, unhosted wallets, P2P transfers and offshore counterparties should therefore be reflected in the business-wide ML/TF risk assessment and corresponding controls.
Recommended actions
CASPs should:
- benchmark Travel Rule implementation against the FATF’s identified implementation gaps;
- review whether stablecoin, unhosted-wallet and offshore-VASP risks are adequately reflected in the ML/TF risk assessment;
- test whether enhanced due diligence and transaction-monitoring controls respond to the relevant virtual asset typologies;
- assess whether existing controls remain appropriate as the business expands into new virtual asset products or transaction models.
FATF warns that DeFi is increasingly exposed to money laundering and other financial crime risks
Date: 21 July 2026 | Source: Financial Action Task Force (FATF)
Link
What happened?
FATF published a targeted report on regulatory challenges arising from decentralised finance (DeFi).
The report identifies permissionless access, automated smart-contract execution, cross-border reach and pseudonymity as factors that can increase exposure to fraud, ransomware, professional money laundering and proliferation financing.
Implementation of the FATF Standards for qualifying DeFi arrangements remains limited: almost 93% of reporting jurisdictions have not yet implemented the Standards in this area.
Importantly, FATF takes a functional approach to determining whether a DeFi arrangement falls within Recommendation 15. A business or person may be subject to AML/CFT requirements where it exercises sufficient control or influence, even where the arrangement is presented as decentralised.
FATF identifies indicators of potential control both on-chain and off-chain, including governance token concentration, administrative privileges, control over upgrades, economic benefits and influence over development or infrastructure.
Why does it matter for businesses?
The report challenges the assumption that describing a product or protocol as “decentralised” automatically places it outside the AML/CFT framework.
This is particularly relevant to CASPs, financial institutions and technology businesses interacting with DeFi protocols. The regulatory analysis may need to focus on who actually controls or influences the arrangement, rather than how the protocol is marketed or structured.
FATF also states that financial institutions and VASPs should apply relevant AML/CFT controls when interacting with qualifying DeFi arrangements and refrain from interacting where compliance cannot be achieved.
Recommended actions
Businesses interacting with DeFi should:
- document an assessment of the actual control and influence exercised over each relevant arrangement;
- consider FATF’s on-chain and off-chain indicators when determining whether a DeFi arrangement falls within Recommendation 15;
- assess the adequacy of CDD, transaction monitoring and other AML/CFT controls applicable to the relationship;
- identify exposure to chain-hopping, cross-chain bridges, decentralised exchanges and mixers;
- avoid entering into or maintaining relationships where required AML/CFT controls cannot be effectively implemented.
For CASPs and financial institutions, DeFi exposure should also be reflected in the business-wide ML/TF risk assessment.
AMLA moves towards a harmonised EU format for suspicious transaction reporting
Date: 2 July 2026 | Source: Anti-Money Laundering Authority (AMLA)
Link
What happened?
AMLA launched a public consultation on draft implementing technical standards establishing a common EU format for reporting suspicions and providing transaction records to Financial Intelligence Units (FIUs).
The proposed framework would introduce a harmonised set of data points for suspicious transaction reporting across the EU, replacing the fragmented national reporting formats currently used by obliged entities.
A public hearing is scheduled for 9 September 2026, while written consultation responses remain possible.
Why does it matter for businesses?
A common EU reporting format could materially change how compliance teams prepare and submit suspicious transaction reports, particularly for businesses operating across several EU jurisdictions.
For Lithuanian and Latvian businesses, the change may require adjustments to existing reporting processes and the data collected for national FIU reporting.
The impact will be particularly relevant to fintechs, financial institutions and other businesses operating cross-border, where differences between national reporting requirements currently create operational complexity.
Recommended actions
Compliance teams should:
- compare existing STR reporting processes with the proposed EU data points;
- identify information currently collected in national systems that may not map easily to the proposed format;
- assess whether existing transaction-monitoring and case-management systems can produce the required information;
- consider submitting consultation feedback where the proposed requirements create significant operational or proportionality concerns.
Businesses operating across multiple EU jurisdictions should begin considering the implications for their reporting architecture rather than waiting until implementation.
AMLA develops EU-wide guidance on ongoing monitoring of business relationships
Date: 2 July 2026 | Source: Anti-Money Laundering Authority (AMLA)
Link
What happened?
AMLA held a public hearing on its draft guidelines for the ongoing monitoring of business relationships, attracting more than 1,200 stakeholders from the financial and non-financial sectors.
The draft guidance addresses customer information updates and the monitoring of transactions and activities. As horizontal guidance, it is intended to apply across obliged entities, with proportionality and the risk-based approach embedded throughout.
The written consultation remains open until 3 September 2026.
Why does it matter for businesses?
Ongoing monitoring is one area where AML frameworks often become operationally inconsistent: customer information may be updated at fixed time intervals without sufficient regard to changes in customer risk, while transaction monitoring may operate separately from KYC refresh processes.
The forthcoming AMLA guidance may therefore influence how businesses structure customer reviews, trigger events, conduct transaction monitoring, and perform periodic KYC refreshes.
Recommended actions
Obliged entities should:
- review current KYC refresh procedures against the draft AMLA approach;
- assess whether customer reviews are sufficiently risk-based rather than driven solely by fixed review cycles;
- identify trigger events that should result in an earlier review of customer information;
- assess whether transaction monitoring outcomes feed effectively into customer-risk reassessment;
- Consider submitting consultation responses by 3 September 2026, where the proposed approach creates significant operational challenges.
Fintechs and other business models with large or rapidly changing customer populations should pay particular attention to the proportionality of ongoing monitoring requirements.
FNTT enforcement data shows where Lithuanian AML controls continue to fail
Date: 16 July 2026 | Source: Financial Crime Investigation Service (FNTT)
FNTT published the 2025 activity report of its Money Laundering Prevention Board.
During 2025, FNTT conducted 20 inspections of obliged entities and imposed measures on 11 companies. Fines ranged from €2,435 to €771,400, with total fines reaching approximately €1.46 million.
The most common deficiencies concerned:
- customer identification and verification;
- record keeping;
- internal policies and control procedures;
- appointment and training of responsible employees;
- reporting requirements for transactions of €15,000 or more;
- suspicious transaction reporting;
- examination of complex, unusually large or unusually structured transactions.
Why does it matter for businesses?
This is one of the most useful indicators of current AML enforcement priorities in Lithuania because it shows the areas where deficiencies are actually identified during inspections.
The findings also demonstrate that enforcement risk does not necessarily arise from sophisticated money laundering schemes. Basic weaknesses in CDD, documentation, governance, training and escalation processes remain significant.
For obliged entities, the practical question is whether the AML framework would withstand an inspection today — not whether the required policies formally exist.
Recommended actions
Lithuanian obliged entities should test their AML framework against the FNTT’s identified enforcement areas, including:
- customer identification and verification;
- customer and business relationship risk assessment;
- record keeping and audit trails;
- internal AML policies and controls;
- appointment, competence and training of responsible employees;
- suspicious transaction identification and escalation;
- reporting of transactions subject to mandatory reporting requirements;
- assessment of complex, unusually large or unusually structured transactions.
Businesses should ensure that evidence of these controls is readily available and inspection-ready, rather than relying solely on written policies.
What businesses should take from this month’s developments
The direction of AML/CTF supervision is becoming clear: regulators are moving from formal requirements towards demonstrable effectiveness.
For virtual asset businesses, this means demonstrating that emerging risks — including stablecoins, unhosted wallets, and DeFi — are reflected in the risk assessment and control framework.
For traditional financial institutions and other obliged entities, the same principle applies to CDD, transaction monitoring, suspicious transaction reporting, ongoing KYC and internal governance.
The FNTT’s Lithuanian enforcement data is particularly clear: weaknesses in fundamental AML controls can still lead to significant financial penalties.
Businesses should therefore assess not only whether their AML framework is documented, but whether it would withstand a regulatory inspection, a complex customer-risk scenario or a suspicious transaction requiring rapid escalation and reporting.
Need assistance?
ECOVIS ProventusLaw advises financial institutions, fintechs, CASPs and other obliged entities on AML/CTF compliance, including:
- AML/CTF regulatory assessments and gap analysis;
- business-wide ML/TF risk assessments;
- AML policies, internal controls and procedures;
- customer due diligence and enhanced due diligence frameworks;
- transaction monitoring and suspicious transaction reporting;
- AML governance, MLRO responsibilities and employee training;
- CASP and virtual asset AML/CTF requirements;
- regulatory inspections and remediation of identified deficiencies.
If your organisation is preparing for increased AMLA or national supervisory scrutiny, our team can help assess whether your AML framework is not only documented but operationally effective and ready for regulatory review.
LT
RU
CN
DE