FATF Recommendation 16 - Virtual Asset Travel Rule
R.16 VATR: Unhosted Wallet Transfers and Risk-Based Measures

FATF Recommendation 16 - Virtual Asset Travel Rule VATR.Unhosted: Unhosted (self-hosted / non-custodial) wallet transfers - 2024 Targeted Update

Unhosted (self-hosted / non-custodial) wallet transfers: virtual asset transfers between a VASP-controlled customer wallet + an unhosted wallet controlled by an individual or entity not registered/licensed as a VASP raise specific risks. The 2024 FATF Targeted Update reinforced risk-based measures: (a) for OUTBOUND transfers to unhosted wallets - VASPs should obtain originator information + apply risk-based + enhanced measures + retain records; the VASP may apply additional verification of the customer's ownership / control of the unhosted wallet (e.g. via Address Ownership Proof Protocol AOPP + Satoshi Test) where risk warrants; (b) for INBOUND transfers from unhosted wallets - VASPs should obtain beneficiary information + apply risk-based + enhanced measures + assess source of funds where appropriate. Some jurisdictions impose stricter requirements (e.g. EU TFR requires that unhosted wallet transfers above EUR 1,000 be subject to enhanced due diligence; UK FCA guidance applies similar risk-based measures). The 2024 FATF Targeted Update emphasized PROPORTIONALITY + AVOIDED ABSOLUTE PROHIBITION of unhosted wallet interactions while reinforcing risk-based controls.

Maintained by Gerard BlokdykControl text last updated

What else in your programme already covers this

This control maps to 175 controls across 83 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.

ISO/IEC 29134:2023 · 5 controls

ISO/IEC 27014:2020 · 4 controls

ISO/IEC 29147:2018 · 4 controls

  • ASTWO-1 Audit Planning, Scaling, Risk Assessment, and Integration
  • ASTWO-3 Entity-Level Controls and Period-End Financial Reporting Process
  • ASTWO-7 Deficiency Evaluation, Material Weakness, and Communication
  • ASTWO-8 ICFR Opinion, Basis, Definition, Limitations, Combined vs Separate Reports
  • 1.2 Operating System Privileged Account Control
  • 1.3 Virtualisation Platform Protection
  • 3.3 Configure Data Access Control Lists

BSI IT-Grundschutz · 3 controls

  • BSI-13 Risk assessment procedures
  • BSI-15 Security categorization
  • BSI-17 Continuous monitoring strategy

ISO/IEC 27004:2016 · 3 controls

ISO/IEC 27011:2024 · 3 controls

ISO/IEC 27400:2022 · 3 controls

ISO/IEC 29100:2024 · 3 controls

ISO/IEC 30111:2019 · 3 controls

  • CH-FADP-21 Data protection impact assessments
  • FADP-5 Definitions (Article 5)
  • FADP-7 Data Protection Impact Assessment (Articles 9-10)

API 1164 · 2 controls

  • 4.3.1 Risk Assessment and Impact Analysis
  • 4.4.1 Resources, Roles, Responsibility, and Authority
  • AT-DSG-2 Section 2 - Scope and application
  • AT-DSG-8 Section 22 - Functions and powers of the DPA
  • BB-DPA-2 Section 2 - Interpretation
  • BB-DPA-20 Sections 50-60 - Registration and Responsibilities
  • DA-1 Enterprise Data Architecture
  • DIQ-2 Data Quality Management
  • 6.5 Preparing and Distributing Audit Report
  • 6.7 Conducting Audit Follow-up

ISO 19011 · 2 controls

  • 6.5 Preparing and Distributing Audit Report
  • 6.7 Conducting Audit Follow-up

ISO/IEC 27031:2011 · 2 controls

  • 3.11 Encrypt Sensitive Data at Rest
  • 3.3 Configure Data Access Control Lists
  • NISTSP34-1 Contingency Planning Policy, Programme, and Plan Coordination
  • NISTSP34-2 Business Impact Analysis (BIA): Critical Resources, Recovery Priorities
  • DSOMM-1 Culture, Organization, Education, and Governance
  • DSOMM-2 Implementation Practices, Secure Coding, and Threat Modelling
  • PAKPDPB-7 NCPDP, Registration, Records, Processor Contracts, DPO
  • PAKPDPB-8 Enforcement, Penalties, Complaints, Retention, Training
  • 2.4.4 Hazard Analysis and Risk Assessment
  • 2.7.2 Food Fraud Plan
  • C1 Organizational Boundary
  • C3 Scope 1 and 2 Coverage
  • CRM-1 AML/CFT Compliance
  • CRM-4 Business Risk Assessment
  • CPS230-11 Identification, Assessment and Management of Operational Risk

Bahrain PDPL · 1 control

  • CPG-6.B Supply Chain Incident Reporting

COBIT 2019 · 1 control

FedRAMP High · 1 control

  • CA-9 Internal System Connections

FedRAMP Moderate · 1 control

  • CA-9 Internal System Connections

ISO 31000:2018 · 1 control

  • 6.7 Conducting Audit Follow-up

ISO/IEC 27007:2020 · 1 control

India DPDP Act · 1 control

MITRE D3FEND · 1 control

  • CA-9 Internal System Connections
  • CA-9 Internal System Connections
  • CA-9 Internal System Connections

OWASP ASVS · 1 control

  • OWASPASVS-1 Architecture, Design and Threat Modelling (V1)

PCI DSS 4.0 · 1 control

  • 2.2.2 Vendor default accounts are managed as follows: • If the vendor default account(s) will be used, the default password is changed per Requirement 8.3.6. • If the vendor default account(s) will not be used,
  • AUPRV-6 Sensitive Information, PIA, Privacy by Design, Children
  • PSPF24-1 Security Culture, Governance, Risk Management
  • EHDSREG-1 Mandatory Requirements for EHR Systems (Articles 14-29)

SWIFT CSCF · 1 control

  • SWIFTCSCF-1 Restrict Internet Access and Protect Critical Systems (Objective 1)

South Korea PIPA · 1 control

  • TEFCAREC-1 Common Agreement Conformance and Onboarding
  • W3CVCDM-1 Three-Party Ecosystem (Issuer, Holder, Verifier)

Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected.

Query this from an agent

The graph holds this control, the 175 it maps to, and the evidence behind each claim, over MCP and REST.