The Travel Rule is the requirement that data on who pays and who receives travels along the chain together with a transfer of money or cryptoassets. The sender's bank or crypto exchange collects that information and passes it to the next link; the receiving side checks it for completeness and decides whether to credit the funds. That is where the questions on a withdrawal screen come from: who owns the wallet, what the recipient is called, which exchange holds the recipient's account.
Concept
The FATF regulates data transmission on transfers through two linked blocks. Recommendation 16 applies to wire transfers by banks and payment providers. Recommendation 15 and its Interpretive Note extend the corresponding requirements to virtual asset service providers by cross-reference to R.16. How the organisation itself works and adopts its standards is covered in the article on the FATF.
In June 2025 the FATF adopted the revised R.16. The explanatory note says it plainly: VASPs are not brought within the scope of R.16, the requirements continue to apply to them indirectly via R.15, and INR.15 will be updated "if necessary" to keep the cross-reference current. The R.16 revision did not change INR.15 automatically, so the data sets and implementation timelines for bank and crypto transfers can diverge. An operator running both types of business has to maintain separate data schemas and track the later INR.15 update.
The point of the rule is traceability. Without accompanying data, a transfer at the end of the chain looks like a credit from "some bank" or "some address", and neither sanctions screening of the recipient nor an FIU investigation can reconstruct whose money it is. With the data, each link sees both parties and is answerable for not losing them. For a licensed firm this means a duty to collect, transmit, check and retain. For the client it means a few extra fields in the transfer form and a delay if the fields do not match. How this fits into the wider control framework is set out in the compliance stack article.
The key parameters of the regime as at September 2026 are set out below.
| Rule | FATF Recommendation 16 (wire transfers), R.15 and INR.15 (virtual assets); in the EU — Regulation (EU) 2023/1113 |
|---|---|
| Who is caught | Banks and payment providers under R.16; virtual asset service providers indirectly, through R.15 |
| Threshold | FATF benchmark — de minimis up to USD/EUR 1,000; no crypto threshold in the EU, USD 3,000 in the US |
| Data set | Above the threshold: originator — name, account number or reference, address or identifier; beneficiary — name, account, country and town |
| Implementation deadline | Revised R.16 — end-2030; INR.15 is updated separately, with no date attached |
| Liability | Cannot be delegated: a third-party Travel Rule solution does not relieve the VASP itself |
| Status as at | 23.09.2026: the FATF consultation on R.16 guidance closed on 21.08.2026, the final guidance not yet published |
Where the Rule Comes From: From SWIFT Wires to VASPs
Wire transfers: Special Recommendation VII and R.16
The banking version of the rule is much older than the crypto one. It emerged from the FATF's special recommendations on terrorist financing: Special Recommendation VII required banks and money remitters to include "accurate and meaningful originator information" in transfers and to keep that information with the payment throughout the chain. In February 2012 the FATF merged the 40 Recommendations and the nine Special Recommendations into a single standard, and the wire transfer rule became Recommendation 16.
The logic has not changed since: the ordering institution collects and verifies originator data, the intermediary institution may not strip it, and the beneficiary institution must notice when data is missing and decide what to do with the payment. In the EU the construction lived until the end of 2024 in Regulation (EU) 2015/847; in the US it sits in the funds transfer rule with a USD 3,000 threshold, in place since 1996.
2018–2019: the same duties for VASPs
In October 2018 the FATF added the concepts of virtual asset and virtual asset service provider to R.15 and the glossary, and in June 2019 it adopted the Interpretive Note to R.15. Paragraph 7(b) of INR.15 is the crypto Travel Rule: the originating VASP obtains and holds accurate originator information and the required beneficiary information, submits it to the beneficiary VASP and makes it available to authorities on request; the beneficiary VASP obtains and holds the originator information and accurate information on its own customer. For occasional transactions the standard permits a USD/EUR 1,000 de minimis.
Transposing the banking model onto a blockchain proved harder technically than legally. In a bank payment the data rides inside the message. A blockchain transaction has no field for a name, so the data had to travel through a separate channel — which is where the market for Travel Rule compliance tools described below comes from.
June 2025: the R.16 revision
The FATF Plenary approved the changes in June 2025, published on 18 June, naming as its aims a standardised data set for cross-border payments and protection against fraud. The revision reorganised the interpretive note by transaction type in place of entity type, aligned originator-side and beneficiary-side obligations symmetrically, and added fraud to the list of key predicate offences. The data set for a cross-border transfer now looks like this.
| Amount | Originator | Beneficiary |
|---|---|---|
| Above USD/EUR 1,000 | Name (verified by the originator's bank); account or reference; address or national ID, customer ID or date of birth; for legal persons — BIC, LEI or another identifier | Name; account number or reference; country and town in place of a full address |
| Up to USD/EUR 1,000 | Name and account number or reference, without verification | Name and account number or reference |
The set was simultaneously softened for financial inclusion: country and town are acceptable for the originator without a standardised postal format, the year of birth suffices where the full date is unavailable, and national identification numbers and customer IDs of natural persons are no longer mandatory fields. Fewer mandatory fields do not lower the bar on accuracy, structure and usability for identification. A truncated name, a placeholder, an unstructured address line or a mismatch between what was sent and what was received can each be treated as a control weakness even on a lawful payment.
The FATF expects most or all of the new requirements to be in effect by the end of 2030 (para. 59 of the note); the annex to the assessment methodology appeared in October 2025, and the current edition of the Recommendations is marked "Updated October 2025". Draft guidance went to public consultation on 24 June 2026; the comment window closed on 21 August 2026. The consultation agenda covers four themes:
- misdirected payments and alignment checks;
- financial inclusion;
- digital wallets and mobile money;
- the balance between R.16 and data protection requirements.
The final guidance may refine the practical requirements. National implementation will proceed at different speeds, and for lagging segments the FATF has kept the option of setting tailored deadlines through a new public-private Payments Advisory Group (para. 60).
Mechanics: What Happens Between Two VASPs
A single crypto transfer from an EU exchange to an exchange in another country goes through five steps. The order is dictated by the rule itself: the data has to reach the recipient before or at the moment of crediting, otherwise there is nothing to check.
- The originating VASP gathers its customer's data (already held from CDD) and asks the customer for the beneficiary's details: name, wallet address, sometimes the name of the receiving exchange.
- From the address it works out where the transfer is going: to another VASP's wallet or to a self-hosted address. A counterparty VASP is put through due diligence — is it licensed, can it receive the data, is it in a high-risk jurisdiction.
- The data goes to the counterparty over a secure channel — under the TFR "in advance of, or simultaneously or concurrently with" the transaction itself, under INR.15 "immediately and securely".
- The beneficiary VASP checks what arrived: are all fields present, are they meaningful, does the beneficiary name match its customer.
- It then credits the asset, returns or rejects the transfer, or holds it until the missing data arrives.
Which fields travel
For crypto transfers in the EU the field set is laid down in Article 14 TFR and goes beyond the FATF minimum: the European legislator required the originator's address, document number and customer ID together.
| Party | Mandatory fields (EU, Art. 14 TFR) | Comment |
|---|---|---|
| Originator | Name; DLT address and crypto-asset account number (where one exists); address including country, official personal document number and customer ID, or date and place of birth; LEI for legal persons | Accuracy verified by the originating VASP |
| Beneficiary | Name; DLT address; crypto-asset account number (where one exists); LEI for legal persons | As stated by the originating customer; checked by the beneficiary VASP |
Technically the fields are packaged according to the IVMS101 data model, maintained since 2020 by an industry working group; the current version is IVMS101.2023.
Counterparty due diligence
Before sending personal data, a VASP has to understand whom it is sending it to. The FATF Best Practices on Travel Rule Supervision (June 2025) name a weak grasp of counterparty VASP due diligence as one cause of ineffective risk assessment. In the EU the duty has a direct legal anchor: Article 38 TFR inserted Article 19a into Directive 2015/849 on correspondent relationships with a respondent CASP from a third country.
The measures under Article 19a are close to banking correspondent KYC:
- determine whether the respondent is authorised or registered;
- gather information on its business, reputation and ownership;
- assess its AML/CFT controls and the quality of its supervision;
- obtain senior management approval before the relationship begins;
- document the respective responsibilities of each party.
The banking equivalent is covered in the article on correspondent banking and safeguarding. The weakest link is global: 57% of jurisdictions (49 of 85) confine domestic VASPs to licensed, registered or compliant foreign counterparties, 22 of them require both a licence and Travel Rule compliance, and only 9 impose no restriction at all — while no global register of licensed VASPs exists. The working toolkit: "equivalent jurisdiction" lists (Japan publishes one annually), network provider directories, the firm's own counterparty KYB, and documented reasonable steps for sunrise cases.
Sunrise and interoperability
The sunrise problem, as defined in the FATF Best Practices (Box 2.1), is "the uneven adoption of the Travel Rule across jurisdictions, arising from delays and/or inconsistent standards" — named the single largest obstacle. By 2026 the legislative gap is nearly closed: the seventh Targeted Update of 16 July 2026 records the Travel Rule in force in 83% of jurisdictions (91 of 109) against 73% a year earlier, with 11 more in progress — 93% in total; among the 69 materially important jurisdictions (roughly 97% of global VA trading volume) adoption reaches 94%.
Sunrise and interoperability are legally distinct problems. Under sunrise, the counterparty sits in a jurisdiction without a Travel Rule and is under no duty to exchange personal data; the answer is documented best efforts. Under interoperability, the counterparty is compliant and willing but runs an incompatible solution; the answer is direct protocol integration or the expensive route of supporting several networks at once. The second is now the dominant one. The FATF states expressly that its standards do not require interoperability between tools (para. 20 of the Best Practices), while acknowledging that its absence creates friction.
Compliance tools and interoperability
IVMS101 describes which fields are sent and in what format; how they reach the counterparty depends on the Travel Rule compliance tool, and the FATF does not prescribe any particular one. Its best practices on Travel Rule supervision of June 2025 note that many VASPs achieve sufficient compliance by running several tools at once, which brings data-interoperability problems of its own, and that some tools have gaps or deficiencies that complicate compliance; interoperability should therefore weigh in the choice, so that a VASP reaches more counterparties with fewer tools (para. 20). Singapore went further and, as the FATF records, commissioned independent evaluations of Travel Rule solution providers against R.16 and technology and cybersecurity requirements, including whether they support industry messaging standards. The choice follows the operator's corridors: a tool that does not reach the operator's main counterparties is of little use however many members it has.
When data is missing: reject, return or hold
The most practical question in the regime is what the recipient does when the data is incomplete. In the EU the answer is in Article 17 TFR: on a risk-sensitive basis the beneficiary CASP either rejects the transfer or returns the crypto-assets to the originator's account, or requests the missing information before making the assets available to its customer. Where a counterparty repeatedly fails to send data, the CASP issues warnings and sets deadlines, then rejects future transfers, restricts or terminates the relationship, and reports the failures to the competent authority.
The regulation is supplemented by the Travel Rule Guidelines EBA/GL/2024/11 of 4 July 2024: "missing" information covers both an empty field and meaningless content — random characters, a title with no name, inadmissible characters; the window to chase missing data is 3 business days intra-Union, 5 from outside and up to 7 for complex intermediary chains. The EBA also states that missing or inadmissible information does not in itself give rise to suspicion of money laundering and calls for a holistic risk assessment.
Other jurisdictions answer the same question in a similar way, with different degrees of rigidity.
| Jurisdiction | Rule | Outcome on incomplete data |
|---|---|---|
| EU | TFR, Art. 17 | Reject or return; or request the data before crediting |
| UK | MLR 2017, reg. 64G(4) | The asset is not made available to the beneficiary until the requested information is received |
| UAE | Cabinet Resolution No. 134 of 2025, Art. 30 | Risk-based policy of the beneficiary institution: execute, reject or suspend |
A hold is therefore a normal outcome, and the client experiences it as a "stuck" transfer.
Self-hosted wallets: ownership of the address is tested
The EU tests something narrow. Articles 14(5) and 16(2) TFR require a CASP, when sending to or receiving from a self-hosted address above EUR 1,000, to take adequate measures to assess whether the address is owned or controlled by its own customer. Recital 39 states expressly that a CASP is in principle under no obligation to verify information about the user of a self-hosted address: what is checked is the customer's ownership of the address, and the counterparty's identity stays outside the check. This was a compromise against the European Parliament's far harsher opening position.
The EBA lists five groups of sufficient methods:
- unattended verification — demonstrating the address under remote onboarding rules;
- attended verification — a check involving a member of staff;
- a Satoshi test — sending a predetermined minimal amount from the address being checked;
- signing a specified message with the key corresponding to the address;
- other reliable technical means.
Whitelisting after verification is permitted, subject to monitoring for changes in ownership and risk, and the indicators of linked transactions are set out separately (one payer and one payee over a short period, multiple payees, multiple accounts of the same person) — with "short period" left to the institution's own assessment. The FATF Best Practices (para. 15) require party data to be collected even on transfers to unhosted wallets.
From there the spectrum runs from a check at any amount to no requirement at all.
| Jurisdiction | Self-hosted / unhosted |
|---|---|
| FATF (standard) | Party data collected even for transfers to unhosted addresses; measures are risk-based |
| EU | Above EUR 1,000 — "adequate measures" to assess whether the address belongs to the customer (Arts. 14(5) and 16(2)); the address user's identity is not verified (recital 39) |
| US | No requirement |
| UK | reg. 64G: risk-based information request, £800 threshold; if the information is not obtained, the asset must not be made available to the beneficiary |
| Switzerland | Verification of power of disposal over an external wallet at any amount, including third-party wallets; Satoshi test or signed message |
| Singapore | Non-custodial sits outside the Travel Rule perimeter, but EDD and proof of address ownership are required |
| Hong Kong | Ownership verified before the transfer and periodically for whitelisted addresses; cryptographic signature |
| UAE (Dubai) | VARA requires firms to take account of the risks of transfers involving unhosted wallets |
| Japan | Data collection and risk assessment for self-hosted transactions |
| South Korea | From February 2027: transfers to overseas exchanges outside the low-risk list and to personal wallets only where sender and recipient are the same person; high-risk destinations barred |
| Canada | No specific non-custodial requirements |
A Swiss detail that is often confused: the Travel Rule itself carries no threshold, and the 30-day window in Art. 51a AMLO-FINMA (in force since 1 January 2023) concerns the CHF 1,000 identification threshold for exchanging virtual currency for cash, counted across linked transactions. Singapore's PSN02 puts non-custodial outside the Travel Rule perimeter but keeps EDD.
Where the FATF moves next is open. The targeted report on stablecoins and unhosted wallets of 3 March 2026 introduces no new standards: it records more than 250 stablecoins with capitalisation above USD 300bn by mid-2025, finds that they accounted for 84% of illicit virtual-asset transaction volume in 2025, and recommends requiring issuers to hold freeze/burn and allow/deny-list capability — while leaving the obligation to transmit party data with CASPs. The same gap shows in P2P: 88% of surveyed jurisdictions (58 of 66) treat such transfers as high risk, but only 23% (31 of 133) collect market metrics.
The Banking Rail: R.16 and ISO 20022
For an ordinary SWIFT payment the Travel Rule has existed for a long time, and the 2025 revision changes above all the quality of the data. The explanatory note to R.16 (para. 4) calls for accompanying information to be structured, to the extent possible, in accordance with the standards of the system used, "such as ISO 20022". In banking this coincided with a technical migration.
Swift ended the coexistence period between MT and ISO 20022 for cross-border payments on 22 November 2025: after that date MT103 and MT202 payment instructions are no longer delivered on FIN. The next step is November 2026, when fully unstructured addresses in CBPR+ cease to be supported: a structured or hybrid address is required, with town and country in dedicated fields at a minimum. By Swift's estimate around 65% of messages still carry unstructured addresses, and Swift itself links the change to R.16. The FATF requirement of "beneficiary country and town" and the minimum hybrid ISO 20022 address match almost word for word.
The second innovation is alignment checks. The beneficiary institution must apply at least one measure (para. 30 of the note): matching the name and account number in the message against its own customer data, holistic monitoring for anomalous accounts and activity, or pre-validation such as Confirmation of Payee where both banks take part. Card payments for goods and services remain outside the rule provided the card number accompanies the transfer, but a person-to-person transfer by card is covered by R.16.
Fiat thresholds by jurisdiction are set out below; they do not coincide with the crypto ones.
| Jurisdiction | Rule | Fiat threshold |
|---|---|---|
| FATF | R.16 as revised in June 2025 | USD/EUR 1,000 (below it, names and account numbers without verification) |
| EU | Regulation (EU) 2023/1113, Arts. 4–6 | EUR 1,000; intra-Union below that, account numbers suffice |
| US | 31 CFR 1010.410(e), (f) | USD 3,000 |
| UK | Retained Regulation (EU) 2015/847 | EUR 1,000 in the text of the regulation |
| Hong Kong | AMLO, Sch. 2, s. 12 | HKD 8,000 |
| UAE | Cabinet Resolution No. 134 of 2025, Arts. 28–31 | AED 3,500 (below it, data travels unverified) |
The practical conclusion for a bank and its client is the same: from November 2026 a single-line beneficiary address ceases to be supported in CBPR+ regardless of amount, and such a payment risks getting stuck at the correspondent or the beneficiary bank.
Thresholds and Rules by Jurisdiction
The crypto Travel Rule thresholds and their start dates, across the FATF standard and ten jurisdictions.
| Jurisdiction | Rule | Crypto threshold | In force since |
|---|---|---|---|
| FATF (standard) | INR.15 §7(b) | USD/EUR 1,000 | June 2019 |
| EU | TFR 2023/1113, Arts. 14–17 | 0 — no threshold (recital 30) | 30.12.2024 |
| US | 31 CFR 1010.410(f) | USD 3,000 (CVC treated as "money" under 2019 FinCEN guidance) | Threshold unchanged since 1996 |
| UK | MLR 2017, Part 7A | Basic set at any amount; extended set from £800 | 01.09.2023; £800 — from 30.06.2026 |
| Switzerland | FINMA Guidance 02/2019 | CHF 0 — all transfers | 26.08.2019 |
| Singapore | MAS Notice PSN02 | SGD 1,500; below it, names and account numbers | 28.01.2020 |
| Hong Kong | AMLO, Sch. 2, s. 13A; SFC AML Guideline | HKD 8,000; below it, names and account numbers | 01.06.2023 |
| UAE (Dubai) | VARA Compliance and Risk Management Rulebook | Above AED 3,500 | Current version from 19.06.2025 |
| Japan | — | No de minimis | 01.06.2023 |
| South Korea | Decree amendments, Cabinet decision of 11.08.2026 | KRW 1,000,000 → 0 | Zero threshold — six months after promulgation, February 2027 |
| Canada | PCMLTFR | CAD 1,000 (plus separate reporting at CAD 10,000) | 01.06.2021 (transition period to 31.03.2022) |
Requirements for transfers to self-hosted wallets in the same jurisdictions are set out above, in the mechanics section.
EU: a zero threshold by legislative choice
The EU has set a zero de minimis threshold for crypto transfers. Regulation (EU) 2023/1113 has applied since 30 December 2024 in step with MiCA, and it carries no de minimis for crypto transfers: recital 30 requires the same data set irrespective of amount. That is the European legislator's own choice, since the FATF permits a threshold up to USD/EUR 1,000. How the regulation relates to the new AML regime is covered in the article on the EU AML package.
US: USD 3,000 and a withdrawn proposal
The US is the principal outlier. The threshold in 31 CFR 1010.410 remains USD 3,000 and has not moved since 1996. The joint FinCEN–Federal Reserve NPRM of 27 October 2020 (85 FR 68005) proposed lowering it to USD 250 for transfers beginning or ending outside the US and expressly bringing convertible virtual currency into the definition of "money".
That proposal is dead: in the Unified Agenda, RIN 1506-AB41 sits under Completed Actions marked "Withdrawn 04/16/2025" — even though a substantial share of 2025–2026 industry commentary still describes it as pending. The US is assessed partially compliant with R.16; the detail sits on the MSB and FinCEN page, with the Canadian perimeter on the map of financial licences by jurisdiction.
UK: Part 7A and the £800 threshold
The UK quietly tightened its threshold in June 2026. MLR 2017 Part 7A has applied since 1 September 2023: reg. 64C(5) requires the parties' names, firm names and account numbers or unique transaction identifiers at any amount, while the extended set — customer ID, address, document number, date and place of birth — was triggered at "1,000 euros". SI 2026/621 replaced that wording with £800 in both reg. 64C(4) and reg. 64G(1)(b) with effect from 30 June 2026. The instrument was made on 9 June 2026 and comes into force 21 days later; it redenominates every euro figure in the MLR at once.
| Euro figure | After SI 2026/621 |
|---|---|
| 15,000 euros | £12,000 |
| 10,000 euros | £10,000 |
| 2,000 euros | £2,000 |
| 1,000 euros | £800 |
For crypto that conversion is not neutral: £800 is roughly EUR 930, so the threshold fell. The amendment is buried in regs 32–33 of an instrument carrying dozens of MLR changes; the wider UK perimeter is covered in the analysis of the FCA and Bank of England crypto regime.
UAE: two tiers of regulation
In the UAE the Travel Rule operates on two tiers. The federal Cabinet Resolution No. 134 of 2025 — the executive regulations to Federal Decree-Law No. 10 of 2025, issued on 29 October and in force since 14 December 2025 — sets an AED 3,500 threshold for international wire transfers (Art. 28) and the duties of intermediary and beneficiary institutions (Arts. 29–30). The threshold governs verification: from AED 3,500 the bank checks the accuracy of the originator data, while below it the data accompanies the transfer unverified unless there is suspicion.
Article 36 of the same regulations extends these rules to VASPs: data is transmitted "immediately and securely", with a minimum of the originator's name, account or wallet address and address, and the beneficiary's name and account or wallet. In Dubai, the VARA rules require that data to be obtained before initiating any transfer with an equivalent value above AED 3,500 and refer expressly to INR.15.
South Korea: the threshold goes
South Korea is abolishing its domestic threshold: under the Cabinet decision of 11 August 2026 the KRW 1,000,000 floor disappears six months after promulgation of the amended decree, i.e. in February 2027; from the same date, transfers to overseas exchanges outside the low-risk list and to personal wallets are allowed only where sender and recipient are the same person, and high-risk destinations are barred outright. Alongside the EU, Switzerland and Japan, that makes a fourth major market with no de minimis for crypto transfers.
What happens to the TFR on 9 July 2027
One fork, now resolved. EUR-Lex metadata for Regulation (EU) 2023/1113 does show 9 July 2027 — precisely one day before AMLR starts to apply and CASPs become obliged entities under it. But the annotation on that date carries the code FIN/VAL/PART: a partial end of validity, tied to Article 38 and to a partial implicit repeal (AI/PAR) by Directive (EU) 2024/1640. Article 38 is precisely the provision that inserted the counterparty CASP due diligence rule into Directive 2015/849, and from July 2027 the old directive gives way to the new AML package. The same metadata still records the regulation as in force, so the TFR is not repealed wholesale on that date.
Privacy: The Mandatory Guidelines That Do Not Exist
Article 25 TFR subjects the processing to the GDPR, prohibits further incompatible processing and expressly bars commercial use, and requires Article 13 GDPR information to be given before the business relationship is established; the Article 26 retention period is five years. Article 25(4) obliges the EDPB to issue guidelines on transfers of personal data to third countries in the crypto-transfer context. Twenty months after the regulation began to apply, no such document appears in the EDPB register.
The practical consequence: the legal basis for the transmission is Article 6(1)(c) GDPR (legal obligation), but everything runs into Chapter V — most VASP jurisdictions have no adequacy decision. The market holds together on five supports:
- SCCs with the counterparty CASP;
- transfer impact assessments;
- field minimisation;
- encryption;
- the pattern of "first confirm the address belongs to a regulated counterparty able to receive the data, then send the PII".
Relying on the Article 49(1)(d) derogation for a continuous flow is fragile: the EDPB insists Chapter V derogations must be occasional, and the Travel Rule is systematic by definition. This is the most exposed point in the European regime, and the FATF acknowledges the conflict — the balance between R.16 and data protection is on the June 2026 consultation agenda.
Supervision and Enforcement
Legislative coverage runs ahead of both supervision and technical compliance — the same Targeted Update data shows it.
| Indicator | Value |
|---|---|
| No finding, direction or enforcement action at all | 60% of jurisdictions with a law in force (55 of 91) |
| Meet criterion R.15.9 (preventive measures including the Travel Rule) | 13 of 149 jurisdictions |
| R.15 technical compliance as at April 2026 | compliant — one; largely compliant — 34% (51 of 149) |
| R.15 partially and non-compliant | 43% and 22% |
| Licensing required | 73% (95 of 130) |
| Licensing actually performed | 58% (76 of 130) — down from 65% |
| Prohibit VASPs | 23% (33 of 144) in 2026 against 11% in 2023 |
A correction for anyone reading progress charts: a prohibition counts as a risk response even though the Travel Rule is simply unnecessary in such a jurisdiction. Offshore VASPs are a separate risk: per the FATF's March 2026 report only 46% of jurisdictions regulate on an activity basis, and 44% (50 of 114) licence domestic providers only.
Pure "Travel-Rule-only" penalties barely exist: the rule appears as a component of broader AML cases.
| Case | Penalty | Authority | Date |
|---|---|---|---|
| OKX | USD 505m | DOJ resolution | 24.02.2025 |
| KuCoin | USD 300m | DOJ, guilty plea | 27.01.2025 |
| Paxos | USD 48.5m | NYDFS | 06.08.2025 |
| Cryptomus | CAD 176.96m | FINTRAC | 22.10.2025 |
| Upbit | KRW 35.2bn (about USD 25m) | KoFIU | November 2025 |
The FINTRAC penalty was for failing to file large virtual currency transfer reports, and the Korean case is closest to the genre: Upbit was fined for roughly 5.3 million breaches of customer verification duties. The second format is a direction without a monetary penalty: the FCA required a firm to onboard an additional Travel Rule solution and remediate historic non-compliant transactions.
The Client's View: Why an Exchange Asks for Recipient Details
Beneficiary data on every withdrawal
The sending exchange must transmit the recipient's name and wallet address, and in the EU the crypto-asset account number where one exists. It takes the name from the customer, which is why the withdrawal form asks who the funds are going to and on which platform the recipient holds an account: the answer determines where, and over which protocol, the data goes. The EU has no crypto threshold, so EUR 20 is handled exactly like EUR 20,000 — a choice by the European legislator that the FATF standard does not require. A EUR 50 crypto transfer carries more data obligations than a EUR 900 intra-Union SEPA payment.
The customer's data goes to the counterparty CASP, including into countries with no adequacy decision; commercial use is prohibited, retention is five years, and processing information must be provided before the relationship starts. What a regulated intermediary collects and why is covered in AML/KYC for the private client.
Withdrawing to one's own wallet
In the EU, above EUR 1,000 the exchange must satisfy itself that the address belongs to the customer — hence the request to sign a message or run a Satoshi test; Switzerland does this at any amount, the UK on a risk basis from £800, Korea will from February 2027 allow personal-wallet transfers only to oneself, and the US requires no check. After verification the address usually goes onto a whitelist, and repeat withdrawals proceed without a signature until the exchange sees a change in ownership or risk. How this interacts with holding structures is covered in crypto for private wealth, and for large off-exchange deals in the article on OTC.
Why a payment is stuck
A "stuck" transfer is usually Article 17 TFR plus the EBA chase windows: 3 business days intra-Union, 5 from outside, up to 7 in a complex chain. There are four typical causes:
- the recipient's name in the form does not match their KYC at the receiving exchange;
- the sending and receiving exchanges sit on incompatible Travel Rule networks;
- the address is recognised as self-hosted and ownership has not been proved;
- in a bank payment, the beneficiary address is written as a single line or the name does not match the account in the alignment check.
A refusal is not always justified: a formal gap in the fields does not in itself give rise to suspicion, and that EBA position is usable in a complaint.
Structuring below a threshold reads plainly: the EBA requires linked transfers to be identified, UK reg. 64C(4) counts them together towards the £800, and in Switzerland the Travel Rule has no threshold at all. Travel Rule data is kept for five years and used in sanctions screening of counterparties. Tax exchange on customers' crypto transactions runs as a separate stream under CARF, though it rests on the same KYC.
A Matrix of Corridors for the Operator
One stack has to carry three mismatched thresholds: zero in the EU, roughly a thousand under FATF logic and across most of Asia, USD 3,000 in the US. From February 2027 the Korean zero is added, Dubai applies AED 3,500, and the UK runs a hybrid — a basic set at any amount plus an extended set from £800. The June 2026 UK change is a trap of its own: systems with the threshold hard-coded in euros with auto-conversion will misfire in both directions.
Liability cannot be delegated: both the FCA and Hong Kong's SFC state that using a third-party Travel Rule solution does not relieve the VASP — which makes vendor due diligence a control in its own right. For a supervisor and a correspondent bank the natural metrics are the same: the share of inbound transfers without data, chase turnaround, what happens to held transfers, and how repeat-offender counterparties end up on a restricted list.
Three items belong in the plan now: data validation alongside transmission; a GDPR perimeter built without waiting for the EDPB guidelines; and vendor selection based on the overlap between the provider's coverage and the operator's actual corridors, since a headline count of connected VASPs says little. The roadmap: November 2026 — the end of unstructured addresses on SWIFT; February 2027 — the Korean zero; July 2027 — AMLR and the reshaping of the European regime; January 2028 — direct AMLA supervision of some forty high-risk cross-border obliged entities; end-2030 — the revised R.16 on the banking rail. An operator working under someone else's licence still owns this matrix — the model itself is set out in the guide to the CASP licence.
Calendar: What Happens When
The key dates of the regime, from SR VII becoming R.16 to the implementation deadline for the revised R.16; national start dates are in the threshold table above.
| Date | Milestone |
|---|---|
| February 2012 | FATF: SR VII on wire transfers becomes Recommendation 16 |
| June 2019 | FATF: Interpretive Note to R.15, the Travel Rule for VASPs |
| 01.06.2023 | Hong Kong and Japan: Travel Rule in force |
| 01.09.2023 | UK: MLR 2017 Part 7A, the FCA statement, JMLSG guidance |
| 04.07.2024 | EU: EBA adopts the Travel Rule Guidelines (EBA/GL/2024/11) |
| 30.12.2024 | EU: TFR applies alongside MiCA; zero threshold for crypto |
| 16.04.2025 | US: the proposal to lower the threshold to USD 250 is formally withdrawn |
| 18.06.2025 | FATF: R.16 revision; in the same month, Best Practices on Travel Rule Supervision |
| 18.07.2025 | US: the GENIUS Act is signed — a federal stablecoin regime |
| October 2025 | FATF: Recommendations "Updated October 2025" plus the R.16 assessment methodology annex |
| 22.11.2025 | Swift: end of MT and ISO 20022 coexistence for cross-border payments |
| 03.03.2026 / 11.03.2026 | FATF: reports on stablecoins and unhosted wallets, then on offshore VASPs |
| 24.06.2026 – 21.08.2026 | FATF: public consultation on the draft R.16 guidance |
| 30.06.2026 | UK: SI 2026/621 — £800 threshold replaces "1,000 euros" |
| 16.07.2026 / 21.07.2026 | FATF: 7th Targeted Update on VAs/VASPs, then the targeted report on DeFi |
| November 2026 | Swift: unstructured addresses in CBPR+ no longer supported |
| February 2027 | Korea: zero Travel Rule threshold; personal-wallet transfers only to oneself |
| 10.07.2027 | EU: AMLR applies, CASPs become obliged entities; the day before, the TFR sees a partial end of validity for Art. 38, with the regulation otherwise remaining in force |
| January 2028 | AMLA begins direct supervision of high-risk cross-border obliged entities |
| End-2030 | FATF: implementation deadline for the revised R.16 on the banking rail |
Q/A
Did anything change for crypto after the June 2025 R.16 reform?
Legally, no. The FATF's explanatory note states expressly that VASPs are not brought within R.16's scope: the requirements reach them indirectly through R.15, and INR.15 will be updated "if necessary". The new field set — symmetry between the parties, country and town only for the beneficiary, year of birth instead of a full date, removal of mandatory national IDs — belongs to the banking rail. In practice, the supervisory logic that a field's mere presence is not enough and the data must be usable will reach crypto too.
Why does the EU ask for data even on a EUR 20 transfer?
Because the TFR (Reg. 2023/1113) contains no de minimis for crypto transfers: recital 30 requires the same data set regardless of amount, and the rule has applied since 30 December 2024. This is a European legislative choice; the FATF permits a threshold up to USD/EUR 1,000. The fiat side of the regulation keeps the EUR 1,000 threshold, producing the paradox in which a crypto transfer is regulated more tightly than a larger intra-Union SEPA payment.
Why does the exchange need the recipient's name when the transfer goes to the customer's own account on another exchange?
The sending exchange must transmit beneficiary data whoever the beneficiary is, and the receiving exchange matches that name against its customer. Where the names match, the transfer usually goes through without questions. A mismatch between the name entered and the KYC at the receiving end is a frequent cause of a hold.
What happens when a transfer is suspended over incomplete data?
Under Article 17 TFR the beneficiary CASP may reject the transfer or return the assets, or request what is missing before crediting; the EBA allows 3 business days intra-Union, 5 for inbound transfers from outside and up to 7 for a complex intermediary chain. In the UK, reg. 64G(4) MLR 2017 prohibits making the asset available until the information is obtained. The EBA nonetheless states that missing or inadmissible information does not in itself give rise to suspicion of money laundering — the basis of a complaint where the refusal rests solely on a formal gap in the fields.
Why does the bank want the recipient's town and country on an ordinary SWIFT payment?
The revised R.16 requires the beneficiary's name, account, country and town, and from November 2026 Swift stops supporting fully unstructured addresses in cross-border payments: town and country must sit in dedicated fields. A payment with a single-line address risks rejection or delay at the correspondent bank.
Can a withdrawal to a personal wallet in the EU go through without a signature or a Satoshi test?
Up to EUR 1,000 the ownership check under Article 14(5) TFR is not mandatory, although party data is still transmitted. Above EUR 1,000 the exchange must take adequate measures to satisfy itself that the address belongs to the customer; the EBA lists message signing, a Satoshi test, attended and unattended verification. A verified address can be whitelisted.
How real is the risk of a penalty specifically for the Travel Rule?
Low so far, though the profile is shifting. On the FATF's July 2026 data, 60% of jurisdictions with a law in force (55 of 91) have issued no finding or action, and only 13 of 149 meet criterion R.15.9. Pure Travel Rule fines barely exist: the rule appears as a component of broad AML cases (OKX, KuCoin, Cryptomus) or as a direction without a monetary penalty. The closest case in the genre is KoFIU's KRW 35.2bn fine on Upbit; the FCA precedent requiring remediation of historic transactions shows where supervision is heading.