Unhosted (self-hosted / non-custodial) wallet transfers: virtual asset transfers between a VASP-controlled customer wallet + an unhosted wallet controlled by an individual or entity not registered/licensed as a VASP raise specific risks. The 2024 FATF Targeted Update reinforced risk-based measures: (a) for OUTBOUND transfers to unhosted wallets - VASPs should obtain originator information + apply risk-based + enhanced measures + retain records; the VASP may apply additional verification of the customer's ownership / control of the unhosted wallet (e.g. via Address Ownership Proof Protocol AOPP + Satoshi Test) where risk warrants; (b) for INBOUND transfers from unhosted wallets - VASPs should obtain beneficiary information + apply risk-based + enhanced measures + assess source of funds where appropriate. Some jurisdictions impose stricter requirements (e.g. EU TFR requires that unhosted wallet transfers above EUR 1,000 be subject to enhanced due diligence; UK FCA guidance applies similar risk-based measures). The 2024 FATF Targeted Update emphasized PROPORTIONALITY + AVOIDED ABSOLUTE PROHIBITION of unhosted wallet interactions while reinforcing risk-based controls.
This control maps to 175 controls across 83 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.
Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected.
The graph holds this control, the 175 it maps to, and the evidence behind each claim, over MCP and REST.