Wolfsberg Response to FATF R.16 Consultation
August 3rd, 2026
Ms. Violaine Clerc
Executive Secretary
Financial Action Task Force (FATF)
2 Rue André Pascal 75116
Paris, France
RE: Public Consultation on Recommendation 16 Guidance on Payment Transparency
Dear Ms Clerc,
The Wolfsberg Group (“the Group”) appreciates the opportunity to provide comments on the Financial Action Task Force’s (the FATF’s) public consultation on the draft Recommendation 16 (R.16) Payment Transparency Guidance, supporting the revised R.16 adopted in June 2025.
We are grateful for the collaborative approach FATF has taken in developing this Guidance, including engagement with the private sector to shape practical, implementable guidance to uphold high standards of payment transparency while remaining proportionate, risk-based and grounded in operational reality. As one of the private sector partners working with the FATF in shaping this Guidance, we have seen first-hand the value of this partnership reflected in the draft Guidance. We encourage FATF to continue its commitment to an open and constructive dialogue with the private sector as the Guidance is finalised and implementation is underway.
We welcome the Guidance’s intent to stay principles-based and resilient to innovation in payment models. In particular, we support the Guidance’s emphasis on:
clarity on the start and end of the payment chain (including that it starts at the payment instruction), and on the respective roles of ordering, intermediary and beneficiary FIs, with obligations applied according to each FI’s role; and
“same activity, same risk, same rules”, ensuring obligations follow the activity rather than the type or label of the entity performing it or the form of value that the payment or value transfer takes;
a risk-based approach, focusing on effective risk outcomes. We are particularly encouraged to see this principle reflected in the holistic ongoing monitoring approach (alignment of beneficiary checks);
the important caution that “Enforcing compliance beyond what R.16 prescribes may give rise to costs… and pose financial exclusion risks without improving effectiveness”; this is particularly relevant given the significant implementation investment already required to deliver the revised R.16 changes.
The Group, however, believes that there are several elements of the draft Guidance that would benefit from refinement to support globally consistent, proportionate implementation and to avoid unnecessary friction, cost, and exclusion risk that could run counter to G20 objectives. Our key recommendations are set out below. Proposed texts for these recommendations, together with additional enhancements and clarification suggestions, are provided in the Annex.
Implementation timeline (end-2030) The Group acknowledges FATF’s intent in setting a clear end-2030 timeline for full implementation. A defined date can be an effective mechanism to drive pace, prioritisation and consistency across jurisdictions, and to avoid open-ended transition arrangements that may dilute the effectiveness of R.16. However, the Group considers it important that the Guidance recognise that achieving end-to-end compliance outcomes is not solely within the control of individual financial institutions; it depends on coordinated, market-wide changes across payment market infrastructures (PMIs), scheme rulebooks, card networks, messaging standards, cross-border interoperability arrangements and “last mile” domestic rails, alongside extensive testing and migration cycles. These dependencies are particularly acute for cross-border payments, where timelines can be shaped by the slowest-moving component in the chain including where legacy messaging standards constrain the ability to carry or transmit additional data elements (e.g., ISO 8583).
Without explicit recognition of phased implementation approaches, there is a risk that the end-2030 expectation is interpreted as requiring uniform, simultaneous delivery across all products, corridors and infrastructures, regardless of ecosystem readiness. This could lead to inconsistent supervisory outcomes, unnecessary friction in payment flows, and the adoption of workarounds that increase cost and complexity without materially improving effectiveness, potentially also increasing financial exclusion risk.
The Group recommends that the Guidance explicitly endorse a phased, risk-based implementation approach to the end-2030 deadline, including prioritisation of higher-risk areas and the use of interim measures where full end-to-end transmission is not yet feasible due to ecosystem dependencies, with supervisory expectations calibrated accordingly. (suggested draft wording in Appendix)
Ecosystem accountability / supervisory calibration: The Guidance appropriately notes that “technical service providers and payment market infrastructure operators are not obliged entities under R.16” while recognising that “PMI design and rulebooks are therefore necessary enablers of FI compliance with R.16”. We recommend the Guidance to more explicitly reflect that end-to-end outcomes depend on the wider ecosystem (including PMIs, card network schemes, message standards, mapping practices and “last-mile” infrastructures), so that supervisory assessments focus on reasonable, proportionate controls within an FI’s direct control, consistent with the Guidance’s intent to be risk-based and outcomes-focused. particularly during the transition period where infrastructure capability may constrain end-to-end transmission.
Virtual accounts. We support improving transparency in virtual account models. However, we recommend targeted refinement to paragraphs 163(1) and 163(2) to avoid ambiguity and unintended market outcomes. First, paragraph 163(1) should clarify who the “FI issuing virtual account numbers” is. In many models, the FI servicing the master account does not issue the virtual account number to underlying payers and has no relationship with the master account holder’s underlying customers; virtual account numbers are often allocated and distributed by the FI’s customer (e.g., a corporate/merchant acquirer). Without clarification, expectations (including invoice/payment-instruction disclosures) may be misapplied. We also recommend recognising established constraints (e.g., undisclosed factoring) by qualifying invoice/instruction disclosure expectations with “to the extent possible”. Second, we strongly recommend removing the “redirection to a different FI” option in paragraph 163(2). In practice, inter-FI redirection is operationally unviable in many models, erodes the legitimate benefits of a virtual account offering, risks being misread as endorsed product design, and does not address the upstream transparency challenge (i.e., upstream parties may still not know the relevant servicing FI/jurisdiction at the point they need to perform controls). Third, we recommend adding a footnote to paragraph 163(2)(ii) to clarify that the expectation on the issuing FI servicing the master account holder is limited to data collection (not KYCC/ID&V) on the identity of the VA assignees; and not to create an unintentional KYCC/ID&V obligation on issuing FIs on their customers’ customers i.e. virtual account users.
PMI rulebooks (permitted use cases): Building on Chapter 4.6 and paragraph 120, we recommend FATF be more explicit that PMI rulebooks should clearly state whether cross-border flows are permitted and how payment parties and intermediated flows should be represented in the scheme message format. Lack of explicit rulebook clarity can drive inconsistent implementation and supervisory outcomes, particularly where a scheme permits cross-border flows that its current infrastructure cannot yet support in a manner consistent with revised R.16 data requirements. In those scenarios, the Guidance should reinforce PMI-led progressive enhancement (with appropriate oversight engagement) while keeping FIs accountable for compliance within their role and the information they originate, receive or control.
Beneficiary legal person identifiers (LEI/BIC): The Group supports improving interoperability and data quality, including the increased use of standardised identifiers where available. However, we do not consider it proportionate or outcomes-effective to imply an expectation that ordering FIs actively collect beneficiary identifiers (e.g., by routinely asking originators whether beneficiaries “hold” an LEI/BIC). An implied “active collection” expectation could increase cost and friction without a commensurate improvement in effectiveness because: (1) where ordering FIs are not required to verify beneficiary information, LEI/BIC details provided by originators may be incomplete or inaccurate, limiting its practical utility for risk mitigation, alignment of beneficiary checks and creating data-quality issues; and (2) treating “where this exists” as a de facto collection obligation may introduce customer journey friction and inconsistent implementation across jurisdictions, increasing cost and exclusion risk without improving effectiveness. A “where provided (and supported by message format)” approach better aligns with effective outcomes, avoids avoidable friction and consistent with established implementation practice for example, Article 4(2)(c) of the EU Funds Transfer Regulation.
The above highlights the Group’s overarching comments on R.16 Guidance, while the next section provides specific paragraph-by-paragraph comments and suggested drafting language are set out in the Annex.
As ever, the Group is grateful for the opportunity to comment and remains at the FATF’s disposal should further discussion on any of the points be helpful as the Guidance is finalised.
Yours sincerely,
Ned Conway
Executive Secretary
The Wolfsberg Group
Annex – Specific responses and suggested revised text (red for edits)
A1. Implementation timeline (para 24) – explicitly support phased implementation and interim solutions
Comment: The Group supports the end-2030 objective, but recommends the Guidance explicitly recognise that jurisdictions may implement in phases and use interim measures where end-to-end delivery depends on ecosystem readiness.
Suggested revised text (para 24):
“Para. 24: FATF expects full implementation of all the revised requirements by the end of 2030. FATF expects the revised Recommendation 16 requirements to be incorporated into local laws by end-2030. FATF also recognises that full compliance with R.16 requirements may be achieved in phases and on a risk-based basis, as determined by each jurisdiction, including prioritisation of higher-risk areas and the application of interim measures, as appropriate.”
A2. Ecosystem accountability / supervisory calibration (Chapter 2.4 – after para 24)
Comment: End-to-end outcomes may depend on PMIs, schemes, message standards and “last mile” rails. During transition, supervisory expectations should focus on reasonable controls within an FI’s role and control.
Suggested revised text (Chapter 2.4, after para 24):
“Para 24. Competent authorities should recognise that end-to-end payment transparency transmission and preservation of required information may depend on the capabilities and governance choices of PMIs, card network schemes, and other ecosystem participants that are not obliged entities under Recommendation 16. During the transition period, competent authorities should calibrate assessments accordingly and focus on reasonable, proportionate and risk-based controls within an FI’s direct control.”
A3. Virtual account numbers (paras 163(1) and 163(2), 163(2)(ii))
A3.1 Clarify who the “FI issuing virtual account numbers” is (para 163(1))
Comment: Paragraph 163(1) refers to the “FI issuing virtual account numbers” and places expectations on that party to ensure relevant information is disclosed in invoices or payment instructions. In practice, there is a risk of inconsistent interpretation of who the “issuing FI” is:
In many virtual account/vIBAN models, the bank servicing the master account does not “issue” the virtual account number to underlying payers and has no relationship with the master account holder’s underlying customers (who receive the virtual accounts and generate invoices/payment instructions).
The entity that allocates and distributes virtual account numbers to underlying customers is frequently the FI’s customer (e.g., a corporate/platform/merchant acquirer), rather than the bank.
Without clarification, jurisdictions and supervisors could misapply expectations by placing requirements on the master-account servicing bank that it cannot practically deliver (e.g., requiring invoice/payment-instruction disclosures by parties it cannot contract with.
In addition, where paragraph 163(1) expects customers to disclose the “true account owner” in invoices or payment instructions, the Group recommends recognising established business constraints (e.g., undisclosed factoring arrangements) where such disclosure may not be feasible without disrupting legitimate and entrenched business models.
Suggested revised text (para 163(1)):
“Para 163 (1): “.. The FI that is issuing virtual accounts should require its customers to disclose the relevant information, such as the true account owner and the FI servicing the master account, in their invoices or payment instructions. Where a virtual account number is assigned to an end user by an FI other than the FI servicing the master account, the assigning FI should be responsible for requiring its customer to disclose the relevant information, to the extent possible, in invoices or payment instructions. The FI servicing the master account should apply appropriate measures in relation to the parties and information flows within its control, including contractual arrangements where necessary.”
A3.2 Remove “redirection to a different FI” option (para 163(2)) and add a clarifying footnote in para 163(2)(ii) on “identifying of virtual account user”
Comment: The Group strongly recommends that FATF remove the “redirection” option in paragraph 163(2). While we understand the intent to avoid third parties being misled as to the servicing institution and jurisdiction, the proposed approach is not a practical or an outcomes-effective solution in many real-world operating models and risks undermining legitimate use of virtual accounts. The Group further recommends FATF to add a clarifying footnote in para 163(2)(ii) on the phrasing “identifying virtual account user” to avoid creating an unintentional KYCC/ID&V obligation on issuing FIs on their customers’ customers i.e. virtual account users.
It undermines the core premise and legitimate utility of virtual accounts
In common product designs, funds are held at the master account level; the virtual account number is a routing/reconciliation tool rather than a separate account where funds are held. Treating virtual accounts as “genuine accounts” with inter-FI redirection risks eroding legitimate benefits (e.g., reconciliation and collections) and adds complexity without clear transparency gains.
Redirection at the clearing/settlement layer is operationally unviable in many models
Attempting to dynamically route funds across different destination FIs would require significant changes to clearing and settlement arrangements and could introduce settlement delays, liquidity fragmentation and increased operational risk.
It risks being read as prescriptive market steering and is unlikely to be consistently adoptable
Given varied market models, language that implies “redirection” as an option may be misinterpreted by jurisdictions and supervisors as an endorsed operating model, despite the Guidance’s intent to remain non-prescriptive.
It does not solve the upstream transparency challenge
Even where a provider could “redirect”, that redirection is performed at the creditor-agent/provider stage and does not resolve the challenge that upstream actors may not know the relevant FI/jurisdiction at the time they conduct screening and monitoring. This could adversely affect upstream screening/monitoring outcomes.
Given the above, the Group believes the “redirection” option risks being ineffective, operationally unworkable, and misinterpreted as an endorsed product design and recommends it to be removed.
With regards to Paragraph 163(2)(ii) – “identifying the virtual account number user” The Group is concerned that the current wording (“identifying the virtual account number user, not only the master account holder”) could be misinterpreted by legislators or supervisors as introducing a broader KYCC/ID&V expectation in respect of virtual account users (“VA assignees”) who are not customers of the master account servicing FI. We do not believe FATF’s intent is to imply a KYCC/ID&V obligation on the issuing FI in relation to underlying virtual account assignees; rather, the intent is to ensure payment messages are populated accurately and that FIs in the payment chain and competent authorities have visibility, and able to distinguish who the master account holder (originator/beneficiary) and ultimate parties are. As such, the Group recommends adding a clarifying footnote to paragraph 163(2)(ii) to confirm that the expectation on the issuing FI servicing the master account holder is limited to data collection (not KYCC/ID&V) on the identity of the VA assignees.
Suggested revised text (para 163(2) – delete the “redirection” sentences):
“para 163 (2): Role of the FI issuing virtual accounts numbers in supporting payment transparency: One option is to treat the virtual account number as a genuine account with redirection capabilities, where the virtual account number redirects flows to a different financial institution than the one servicing the account where the funds are received. While this does not remove the risks attached to redirection, it ensures that third parties, including competent authorities, are not misled as to the servicing institution and jurisdiction applicable to the transaction. Where virtual account numbers are used, the FI issuing the virtual account numbers should implement appropriate controls to support payment transparency...”
Suggested footnote to para 163(2) (ii) “identifying the virtual account number user, not only the master account holder”:
“For the avoidance of doubt, ‘identifying’ the virtual account number user refers to the issuing FI to collect data from their customer i.e. master account holder, on the identity of the virtual account number user, it does not create a KYCC/ID&V obligation on the issuing FI for the virtual account users who are not their customers.”
A3.3 Minor amendment on Box 7: Case study 1 – Enhancing vIBAN transparency
Comment: The use case described in Box 7 does not fully accurately describe the status quo. The requirement applies to VIBANs in certain circumstances and not all. We recommend amending the text by inserting "in certain cases”.
Minor amendment to Box 7: Case study 1 – Enhancing vIBAN transparency
Box 7: Case study 1 – Enhancing vIBAN transparency “Up until now, credit institutions in Germany must, in certain cases, promptly, accurately, and fully record every virtual IBAN that they issue to non-bank financial institutions in a database…”
A4. PMI rulebooks and scheme rules – be explicit on permitted use cases and message capture (para 117 / 119)
Comment: Building on Chapter 4.6.4, PMI rulebooks should be explicit about whether cross-border flows are permitted and how payment parties and intermediated flows should be represented in the scheme message format, including unsupported use cases. This should include the types of transactions which are not permitted to be channelled through the PMI and will be particularly important for those PMIs that have made the determination not to upgrade their infrastructure to carry any additional data required for a cross-border message. This would help calibrate supervisory expectations so responsibilities are aligned to what each party can control, with PMIs/card/messaging schemes accountable for infrastructure capability and rulebook clarity, and participating FIs remaining accountable for compliance within their role and the information they originate, receive, or control, thereby avoiding disproportionate outcomes driven by infrastructure constraints
Para 117 – explicit clarity on permitted cross-border use cases and message capture
“Para 117: PMI rulebooks and technical specifications are strongly encouraged to clearly define: the types of payments and transaction flow the infrastructure supports; data standards and message requirements (including how to populate gaps correctly); validation rules for participation; and how participating FIs can identify all FIs involved in a payment chain and their respective jurisdictions. insert: This should include clarity on whether cross-border payments or value transfers are permitted within the scheme and, where permitted, how relevant payment parties (e.g., Ultimate Originator or Beneficiary for Virtual Account payments) and intermediated flows should be captured in the applicable message format, including any use cases that are not supported. This gives participating FIs the clarity needed to use the infrastructure in an R.16-compliant manner and reduces ambiguity across the payment chain.”
Paragraph after 119 (tighten language)
“Para 119: If PMIs designed primarily for domestic payments are also used to route cross-border payments or value transfers, they should consider stating explicitly in their rulebooks that full R.16 requirements apply to those transactions. Where an FI or PMI knowingly routes cross-border payments or value transfers but does not support those requirements, competent authorities should consider whether supervisory or oversight engagement is appropriate insert: Where domestic payment infrastructures are used as part of a cross-border payment chain, financial institutions should not be expected to rely on the payment infrastructure itself to determine the cross-border nature of the transaction. Recommendation 16 compliance should instead be based on the information accompanying the payment throughout the payment chain. Where such cross-border use cases are permitted but the PMI cannot yet support end-to-end transmission of the required information, PMIs and competent authorities should consider appropriate oversight engagement and a progressive capability enhancement plan.”
A5. Beneficiary legal person identifiers (para 151) – avoid implying active collection
Comment: The Group supports use of legal entity identifiers where available but recommends avoiding an implied expectation that ordering FIs actively collect beneficiary identifiers (particularly where beneficiary info is not verified).
Suggested revised text (para 151 streamlined):
Para 151. “…The ordering FI must include the identifier for the originator where it reasonably ascertains that one exists, even if it has not been previously obtained by the ordering FI. The originator is primarily responsible for providing the beneficiary's information. Where the beneficiary's identifier has not been previously recorded, the ordering FI should ask the originator whether the beneficiary holds such an identifier. Where provided by the originator, the ordering FI should transmit the beneficiary’s identifier for legal persons. The ordering FI is not required to verify the accuracy of the beneficiary's information.”
A6. Strengthen core obligations of ordering FIs (para 77) – concise summary clarification
Comment: These obligations are addressed across the Guidance; we recommend adding a short summary clarification under paragraph 77 to draw together two foundational obligations underpinning effective payment transparency at initiation, without changing the principles-based nature of the Guidance.
Suggested revised text (para 77 – insert bullet and amend existing bullet):
“Para 77. The ordering FI is responsible for ensuring all required originator and beneficiary information is transmitted to the intermediary. Specifically, the ordering FI is responsible for ensuring that:
Appropriate customer due diligence (CDD) is applied, including identification and verification, for customers and, where applicable, non-customer users of origination services (e.g., occasional or walk-in transactions), in line with applicable requirements.]
Information should be structured to the extent possible in accordance with the relevant payment messaging standard.
Reasonable controls are implemented to ensure that the relevant information accompanying the outgoing payment messages properly reflects the end point of the payment chain as instructed by the originator so that it can be ascertained if the payment or value transfer is a cross-border or domestic transfer.”
A7. Possible misuse of net settlement arrangements (para 64)
Comment: Support the “no unbundling” clarification and add a short role-based statement for settlement-leg participants.
Suggested revised text (additional sentence to para 64):
“Similarly, FIs acting solely in the net or aggregated settlement leg should not be expected to assess and or verify whether upstream participants have correctly applied R.16 requirements, criteria or exemptions, nor to reconstruct customer-level information that they do not receive or control. Their obligations should be determined by their role in the payment chain and the information available to them.”
This addition would reinforce consistent role-based implementation, while preserving the underlying objective of preventing the misuse of net settlement arrangements.
A8. Batch transfers – linkage between payment message and batch file (para 70)
Comment: Clarify the need for reliable linkage, especially where the batch file is transmitted separately or via a different channel.
Suggested revised text (additional sentence to para 70):
“Where the batch file is transmitted separately from the payment message or through a different channel, FIs should ensure that the payment message and the batch file remain reliably linked through a unique reference or equivalent mechanism, so that the underlying individual transfers can be reconstructed and relevant information can be made available where required.”
This clarification would strengthen the effectiveness of the batch transfer flexibility while preserving the efficiency benefits described in paragraph 70.
A9. Technical limitations in PMIs (para 120) – role-based responsibility (“originate, receive or control”)
Comment: The current wording “from the beginning to the end of the payment chain” could be read as imposing end-to-end accountability on individual FIs for data loss or lack of traceability arising from PMI technical limitations that are outside the FI’s control. To support consistent and proportionate supervisory interpretation, we recommend clarifying that FI responsibility is role-based and linked to the information the FI originates, receives, or controls.
Suggested revised text (para 120 – replace second sentence):
“…However, FIs do remain responsible for collecting required information from the beginning to the end of payment chain, and for ensuring it can be made available upon request where end-to-end transmission is not yet feasible. However, FIs remain responsible, in accordance with their role in the payment chain, for collecting and retaining the required information and for transmitting the information they originate, receive or control; and to ensure it can be made available upon request where end-to-end transmission is not yet feasible due to PMI limitations.”
A10. Role of card networks (para 204) – consistency of expectations
Comment: For clarity and consistency of supervisory expectations, The Group recommends strengthening the language in paragraph 204 so it aligns with the Guidance’s treatment elsewhere (including the explicit reliance on card networks for information transmission for cross border cash withdrawals, Para. 213). In practice, it is more likely than not that the same information-sharing mechanism facilitated by the card network for cross-border cash withdrawal scenarios will be leveraged to provide issuer and acquirer information for card transactions more generally. A clearer statement of the expected role of schemes/networks would support consistent implementation and avoid under-weighting the enabling role played by networks in meeting the relevant transparency outcomes.
Suggested revised text (para 204 – amend sentence):
“It is expected that card schemes, or networks, will likely need to play a significant role in facilitating access to issuer and acquirer information…”
A11. Gap analyses between AML/CFT/CPF and DPP (para 248) – include payment regulation
Comment: Explicitly include payment services/payment regulation alongside AML/CFT/CPF and DPP to avoid conflicting domestic requirements.
Suggested revised text (para 248 – add sentence):
“…Gap analyses should also consider payment regulations to avoid inconsistent implementation requirements across AML/CFT/CPF, payment services and DPP frameworks.”
A12. Minor editorial amendment to Executive Summary (para 7):
Suggested revised text (para 7):
“Chapter 7 introduces a targeted regime for cross-border cash withdrawals. The cardholder's name


