Travel Rule Requirements for VASPs: What a Regulator Asks You to Produce

September 21, 2026

Travel Rule for VASPs in practice: thresholds by jurisdiction, unhosted wallets, non-compliant counterparties and what examiners ask to see.

Nataly Medici
Nataly Medici
Managing Partner and CEO

Most compliance officers do not discover their Travel Rule gaps in a policy review. They discover them when an examiner picks thirty transfers from last March and asks a simple question: show me what you sent, what you received, and what you did when something was missing.

That is where Travel Rule requirements stop being a regulatory summary and become an evidence problem. Nearly every licensed platform can describe the rule. Far fewer can reconstruct a single transfer from end to end, with timestamps, decisions and the name of the person who made them.

This guide is written from that seat. It covers what has to travel and when, where the thresholds sit, what to do with unhosted wallets and with counterparties that ignore the rule, what an examiner asks you to put on the table, and where your software stops and your own liability begins.

The rule in one paragraph

When a bank sends a wire, a packet of data travels with the money: who is sending, from which account, to whom, to which account. The United States has required this since 1996, and the requirement took its name from that idea: the information travels with the transfer. The FATF Travel Rule extends the same logic to virtual assets. Virtual assets were brought into the FATF standards in 2018–2019 through Recommendation 15, while the data-transmission mechanism itself lives in FATF Recommendation 16, the standard that has governed wire transfers for two decades. A blockchain shows addresses, not people. The rule closes the gap by keeping addresses on-chain and moving names separately, through a channel between the originating and beneficiary VASPs.

One point matters before anything else. The rule binds intermediaries, not users. A person holding their own keys is not a VASP. The moment a regulated platform sits on either end of a transfer, that platform owns the obligation, and with it the burden of proof.

Travel Rule requirements: what must travel, and at what moment

Under the FATF Travel Rule, the originating VASP must obtain, hold and transmit originator and beneficiary information immediately and securely, before or at the same time as the transfer settles. Not the next day. Not in a monthly batch.

Above the FATF threshold of USD/EUR 1,000, the originator data set is the customer's name, the account or wallet identifier, and either a physical address, a national identity number, a customer identification number, or date and place of birth. The beneficiary data set is the name and the account or wallet identifier. The originator information must be accurate and verified. The beneficiary information comes from your customer and is not something you can verify on your own.

Below the threshold the obligation does not disappear. The names of originator and beneficiary and their wallet identifiers still have to be collected and transmitted. What falls away is the duty to verify them. That detail catches out teams that configure their systems to skip small transfers entirely.

The beneficiary VASP has its own side of the obligation. It must receive and hold the originator and beneficiary information, check it for obvious gaps, and decide what to do with the transfer when something is missing. Examiners test both directions. A platform that sends flawless messages but credits incomplete incoming transfers without review has failed half of its Travel Rule requirements.

The rule is also moving, but not in a straight line for crypto. On 18 June 2025, FATF revised Recommendation 16 to clarify responsibilities along the payment chain and to tighten transparency for cross-border payments above USD/EUR 1,000, with implementation expected by the end of 2030. FATF has been explicit that these changes reach VASPs only indirectly, through Recommendation 15, which decides how Recommendation 16 applies to virtual assets. So the revision does not by itself change the data set a VASP must send. What it changes for crypto will depend on how FATF and national regulators carry it across, and that is the step to watch rather than assume.

How far implementation has actually gone is measured in FATF's seventh Targeted Update, published on 16 July 2026. Of the 109 jurisdictions that answered the relevant question, 91, or 83%, have passed Travel Rule legislation, up from 73% a year earlier. Yet 55 of those 91 have not issued a single supervisory finding, directive or enforcement action on it. The law exists almost everywhere. Supervision exists in roughly 40% of the places where the law does.

The Travel Rule threshold by jurisdiction

FATF sets the baseline. More than 90 legislatures have written their own versions of it, and the gap between one standard and many laws is exactly where operations break. What follows is the operating picture for the regimes our clients deal with most often. Always check the current text before relying on a figure: thresholds are amended, and conversion into local currency is part of your obligation.

The FATF travel rule threshold, set through FATF Recommendation 16 as applied to virtual assets, is USD/EUR 1,000. It is a recommendation, not a law, and it binds you only through the national rule that copies it.

The European Union runs a zero threshold travel rule. Regulation (EU) 2023/1113, the Transfer of Funds Regulation, applies from 30 December 2024 and requires the full data set on every crypto-asset transfer between CASPs, regardless of value. A EUR 15 transfer and a EUR 15 million transfer carry the same information. The most common mistake in client conversations is to look for this inside MiCA. There is no Travel Rule in MiCA. MiCA governs authorisation; the TFR governs the data. Two regulations, two supervisory lenses, and two separate ways to fail an inspection. So when someone asks about the EU travel rule threshold under MiCA, the precise answer is zero, and it comes from the TFR.

The United Kingdom has applied its own Travel Rule since 1 September 2023. Full information is required for transfers of £800 or more, with a reduced data set below that, and a specific expectation that firms handle transfers from jurisdictions without the rule on a risk-based basis. The threshold was originally set in euros, at EUR 1,000; the 2026 amendment to the Money Laundering Regulations replaced it with the sterling figure in regulations 64C and 64G. If your UK entity still runs a EUR 1,000 rule, it is working to a number that no longer exists.

The United States applies the oldest regime, and the highest threshold among the major ones. The FinCEN travel rule sits in 31 CFR 1010.410(f), the Bank Secrecy Act travel rule for transmittals of funds, with a threshold of USD 3,000. In 2019 FinCEN confirmed that it applies to convertible virtual currency and to the businesses that transmit it. In October 2020, FinCEN and the Federal Reserve proposed cutting the threshold to USD 250 for transfers that begin or end outside the United States. At the time of writing that proposal has not been finalised, so the operative figure remains USD 3,000. Plan for the lower number anyway: if it lands, the US moves from the most permissive major threshold to one of the tightest.

The United Arab Emirates now has a federal floor. Federal Decree-Law No. 10 of 2025 took effect on 14 October 2025, and its executive regulations, Cabinet Resolution No. 134 of 2025, on 14 December 2025. VASPs regulated by VARA, by the FSRA in ADGM or by the DFSA in DIFC must collect and transmit originator and beneficiary information on transfers at or above AED 3,500. The federal figure is a floor, not a ceiling. ADGM goes further: its FSRA treats virtual asset transfers as wire transfers and applies the rule with no threshold at all. A licence in Abu Dhabi and a licence in Dubai therefore mean different operating thresholds inside one country. In Dubai, VARA's Compliance and Risk Management Rulebook also requires counterparty due diligence, a defined treatment of self-custodial wallets and a documented approach to the sunrise issue, and it expects firms to demonstrate that their controls work, both at licensing and on request. VASP travel rule compliance in Dubai is not a post-licensing project. It is part of the entry ticket.

Singapore applies the rule to digital payment token transfers at SGD 1,500. Hong Kong sets HKD 8,000. South Korea applies KRW 1 million. Switzerland has chosen no threshold at all, much like the EU.

Three operational consequences follow from this picture. First, your system must convert every transfer into the local currency of each applicable regime, and the conversion method must be written down, because an examiner will ask which rate you used and when. Second, a route between two regimes is handled by each side under its own rules. A US platform sending USD 2,000 to an EU platform may transmit nothing under US law, while the EU receiver is obliged to detect the missing data and decide whether to credit, suspend or return the funds. Third, a single group with licences in several places will run several thresholds at once, and your policy must say which one applies to which entity.

Transfers to and from an unhosted wallet

An unhosted wallet has no VASP on the other side. There is no counterparty to send the message to, so the obligation changes shape rather than disappearing.

For outgoing transfers, you still collect the beneficiary information from your own customer and hold it. For incoming transfers, you obtain the originator information from your customer. What you cannot do is treat the absence of a counterparty as the absence of a requirement.

The EU goes further than the FATF baseline. For transfers of more than EUR 1,000 to or from a self-hosted wallet owned or controlled by your own customer, the CASP must take adequate measures to verify that ownership or control. Self-hosted wallets are not banned. They are made accountable. In practice, verification means a signed message from the wallet, a small test transfer, or another method your policy describes and your records prove.

Most regulators, including VARA, also expect such transfers to be risk-assessed: screened through blockchain analytics, flagged for enhanced due diligence where the pattern warrants it, and restricted when the risk cannot be managed. The examiner's question here is not whether you allow such transfers. It is how you decided, per transfer, and where that decision is recorded.

The direction of travel is clear. From 10 July 2027, Article 79 of the EU Anti-Money Laundering Regulation, Regulation (EU) 2024/1624, prohibits CASPs from keeping anonymous crypto-asset accounts or any account that allows the anonymisation of the holder or of transactions, including through anonymity-enhancing coins. Operators who still treat these flows as a grey zone have less than a year to close it.

When the counterparty does not comply

This is the question the product pages skip, and the one examiners ask most often: what did you do when the other side sent nothing, sent garbage, or never answered?

Start with the sunrise issue. FATF uses the term for the uneven timing of implementation: some jurisdictions switched the rule on earlier than others, so a compliant VASP regularly deals with counterparties that have no obligation yet. The FATF figures add a second layer. Many counterparties now have the obligation on paper but no supervisor checking it. From the desk of a compliance officer at a compliant firm, the two situations look identical: an incoming transfer with empty fields, and the cost of the gap landing on the firm that takes the rule seriously.

The sunrise issue does not suspend your obligation. The regulatory expectation, stated plainly in the EU framework and echoed by VARA and the UK, is a documented, risk-based response in four steps.

First, counterparty VASP due diligence before the first transfer. Identify the counterparty, confirm whether it is licensed or registered, understand which Travel Rule regime applies to it, and assess whether it can receive and protect the data. This file should exist before the money moves, not be built after the examiner asks.

Second, a defined treatment for incomplete incoming transfers. Your policy should state whether you reject, suspend while requesting the missing data, or credit and follow up, and on what risk criteria. The EU TFR requires the beneficiary CASP to have exactly such procedures.

Third, escalation for repeat offenders. Under the TFR, a counterparty that repeatedly fails to provide required information must first be warned and given a deadline, and then restricted or cut off, with the failure reported to your competent authority. Even outside the EU, this sequence is what a reasonable supervisor expects to see.

Fourth, a link to suspicious activity reporting. Missing or inconsistent information is one factor in deciding whether a transfer is suspicious. The file should show that the question was asked.

Counterparty VASP due diligence is not a one-time onboarding step. Counterparties lose licences, change jurisdictions and degrade. Your register needs review dates, and those dates need to be met.

What a regulator asks you to produce

This is the section to keep open during an inspection. Examiners rarely ask whether your travel rule compliance is in place. They ask you to prove it, document by document and transfer by transfer. FATF's own guidance on Travel Rule supervision describes the same approach: supervisors test implementation through sampling, not through policy statements.

Expect to be asked for the following.

A Travel Rule policy and procedures, approved by the board or senior management, naming the regimes that apply to each licensed entity, the thresholds, the data set and the owner of each process.

A threshold and conversion methodology: which exchange rate source you use, at what moment the value is calculated, and how you prevent a large transfer from being split into small ones to stay under the line.

A data map showing which onboarding field feeds which message field. This is where most failures begin. A platform can transmit messages flawlessly and still send empty address fields, because its KYC process captured a passport scan and a selfie but never recorded a verified address. Examiners have learned to look here first.

Transmission and receipt logs for the sampled transfers, with timestamps, the originator and beneficiary information sent and received, the counterparty identified and the settlement time. The examiner will check that information travelled before or at the same time as the transfer, not after.

An exception log: every incomplete or failed exchange, the decision taken, who took it, when, and on what grounds. An empty exception log is not reassuring. It suggests exceptions are not being recorded.

Counterparty VASP due diligence files and a counterparty register with risk ratings and review dates.

Unhosted wallet evidence: the ownership or control verification for transfers above the applicable threshold, and the risk decision for each flagged transfer.

Sanctions screening results for originator and beneficiary names received through the Travel Rule, not only for your own customers. Under US sanctions law, OFAC applies strict civil liability: a penalty can follow even where you did not know the other party was sanctioned.

Links to suspicious activity reports where Travel Rule gaps contributed to the decision.

Record retention and retrieval. FATF requires records to be kept for at least five years, and national regimes set their own periods, which can be longer. The practical test is retrieval speed: can you produce a complete record for a transfer from three years ago on request, without reconstructing it by hand?

Training records for the staff who handle exceptions, management information showing that senior management sees Travel Rule performance, and independent testing or internal audit reports on the process.

A vendor oversight file, if part of the process is outsourced: the contract, the service levels, the testing you performed and the incidents you escalated.

One more document is worth preparing even though nobody lists it: a written walkthrough of three sample transfers, one outgoing, one incoming with missing data, one to a customer's own wallet, showing each step and each record. It is the fastest way to find your own gaps before the examiner does.

Where your provider's job ends and yours begins

The Travel Rule is transport. AML is decisions. The first can be bought. The second cannot.

A Travel Rule solution typically does the following well: it formats messages in the IVMS101 data standard, discovers and identifies the counterparty VASP, transmits and receives data securely, applies the threshold you configured, and keeps a log of each exchange. Those are real functions, and a good solution will also flag transfers to wallets with no VASP behind them and integrate with your transaction monitoring and sanctions screening.

What remains yours is everything that requires judgement. The quality of the data you feed in. The threshold policy and the conversion method. The decision to credit, suspend or return an incomplete transfer. Counterparty VASP due diligence and the decision to cut a counterparty off. Sanctions and suspicious activity decisions. Retention, retrieval and governance. A regulator will accept that you outsourced a task. It will not accept that you outsourced the responsibility.

That is the honest boundary of AML travel rule obligations. You can transmit data perfectly and still fail an inspection, because nobody acted on what arrived. And you can run strong AML and still be cited, because the data never travelled. Supervisors test both halves, and a clean vendor dashboard proves only the first.

The consequences are rising, particularly for individuals. In the UAE, Federal Decree-Law No. 10 of 2025 introduced personal liability for senior managers and compliance officers who fail to prevent violations. In the US, civil penalties under the Bank Secrecy Act are assessed per violation, and for continuing violations each day can count separately. And before any regulator acts, the market usually does: counterparties that take crypto travel rule compliance seriously stop accepting transfers from platforms that do not.

FAQ

What is the Travel Rule in crypto?

It is the obligation for VASPs to collect, transmit and keep originator and beneficiary details alongside a transfer of virtual assets, so that the people behind blockchain addresses are known to both platforms. It comes from FATF Recommendation 16 and binds your firm through national law, such as the Transfer of Funds Regulation in the EU or the Bank Secrecy Act in the US. The rest of this guide is about proving you apply it.

Does the rule apply to transfers below the threshold?

Under the FATF standard, yes, in reduced form: names and wallet identifiers of both parties still travel, only verification is dropped. Several regimes, including the EU, Switzerland and ADGM, apply the rule with no threshold at all.

Is the Travel Rule part of MiCA?

It sits in a separate act. In the EU, MiCA covers authorisation of CASPs, while Travel Rule obligations come from Regulation (EU) 2023/1113. Both are examined, and a firm can pass one and fail the other.

Do we need Travel Rule data for a transfer to a self-hosted wallet?

There is no counterparty to send it to, but you still collect and keep the information from your own customer. In the EU, transfers above EUR 1,000 to or from a wallet your customer owns or controls also require verification of that ownership or control.

How long must Travel Rule records be kept?

At least five years under the FATF standard. National regimes can require longer, so the retention period in your policy should follow the strictest rule that applies to each licensed entity, and your records should be retrievable on request, not reconstructed.

Does a Travel Rule solution make us compliant?

It covers transmission, formatting and logging. The decisions stay with you: data quality, thresholds, treatment of incomplete transfers, counterparty due diligence, sanctions and reporting. An examiner assesses both.

In short

Travel Rule requirements are easy to describe and hard to evidence. The firms that pass inspections are not the ones with the most expensive tooling. That is what VASP travel rule compliance looks like from the examiner's side of the table: the firms that pass can pick any transfer from their history and show, in one sitting, what travelled, what arrived, what was missing, who decided and why.

If you are preparing for a licensing application or a supervisory review and want to test your Travel Rule file against these requirements, book a call with our team.

Connect with our experts

Get full clarity on licensing, compliance and structuring before you spend time and budget on the wrong move.

Book a Free Call

Ready to build a structure that actually works?

Whether you are launching a fintech company, applying for a license, entering the UAE, issuing a token or preparing for regulatory review — we can help you choose the right path before costly mistakes happen.

Book a Free Call