AFAIK - there is no direct policy nat available, but you could try something. Try using a route map, with a nat statement using a pool of addresses - but the pool only have 1 address, something like:-
ip nat pool test1 x.x.x.x x.x.x.x netmask 255.255.255.255
ip nat inside source route-map test pool test1
access-list 101 permit ip host y.y.y.y host z.z.z.z
route-map test permit 10
match ip address 101
access-list 102 permit ip host x.x.x.x host z.z.z.z
crypto map vpntunnel
match address 102
x.x.x.x - translated IP address
y.y.y.y - original IP address
z.z.z.z - remote end IP address for VPN tunnel
HTH>