
The Crypto Travel Rule requires covered virtual asset service providers to collect, retain, verify, and securely transmit specified information about the sender and recipient of certain crypto transfers.
For crypto exchanges, custodial wallet providers, payment platforms, brokers, and other regulated crypto businesses, compliance involves more than sending a message between two institutions. It depends on reliable customer data, counterparty identification, sanctions screening, transaction monitoring, exception handling, secure data exchange, and an audit trail that explains each transfer decision.
Global adoption continues to expand. In July 2026, the Financial Action Task Force reported that 83% of surveyed jurisdictions had passed legislation implementing the Travel Rule, compared with 73% in 2025. FATF also warned that practical implementation, supervision, and enforcement remained inconsistent.
This guide explains who the rule affects, what information must be exchanged, how requirements differ across jurisdictions, and how crypto businesses can build Travel Rule-aware compliance workflows.
Crypto Travel Rule key takeaways
- FATF establishes the international standard, but individual jurisdictions implement it through local laws and regulations.
- The Travel Rule generally requires information about the originator and beneficiary of a covered crypto transfer.
- Thresholds, verification requirements, data fields, and self-hosted wallet rules differ by jurisdiction.
- A crypto business may need to determine whether a destination belongs to another regulated provider or a self-hosted wallet.
- Travel Rule compliance relies on KYC, KYB, AML screening, transaction monitoring, counterparty checks, and recordkeeping.
- A third-party messaging or compliance vendor can support the process, but the regulated business remains responsible for meeting its obligations.
What is the Crypto Travel Rule?
The Crypto Travel Rule is an anti-money laundering and counter-terrorist financing requirement that applies to certain virtual asset transfers.
Under the FATF framework, an originating VASP must obtain and hold required information about the originator and beneficiary. Where another covered institution is involved, the originating VASP must submit the required information immediately and securely to the beneficiary VASP or financial institution.
The beneficiary institution must obtain and hold the required originator information and accurate information about its beneficiary customer.
The information does not have to be written onto the blockchain. It can be transmitted through a separate secure communication channel, provided it remains connected to the relevant transfer and is available when required.
Why is it called the Travel Rule?
The term comes from traditional payment regulation, where identifying information is expected to accompany a funds transfer through the payment chain.
FATF updated its virtual asset standards in 2019 to apply relevant AML and CTF measures to virtual assets and VASPs. Its 2021 guidance provided additional direction on Travel Rule implementation, peer-to-peer transfers, stablecoins, VASP registration, and supervisory cooperation.
FATF recommendations are not national laws
FATF does not directly license or regulate individual crypto businesses.
Its recommendations create an international standard that countries are expected to implement through legislation, regulations, supervisory guidance, licensing requirements, and enforcement.
This means there is no single, globally uniform Crypto Travel Rule. A crypto business must assess the requirements of the jurisdictions connected to:
- its legal entities
- its licences and registrations
- its customers
- its originating VASP
- its beneficiary VASP
- the transfer route
- the relevant wallet
- the service being provided
FATF revised Recommendation 16 in June 2025 to clarify responsibilities within payment chains, increase consistency in cross-border payment data, and introduce tools intended to reduce fraud and payment errors. Countries are expected to be ready to implement the revised requirements by the end of 2030.
Why was the Crypto Travel Rule introduced?
A public blockchain may reveal wallet addresses, transaction values, timestamps, and asset movements, but a wallet address does not inherently identify the person or business controlling it.
This creates a gap between transaction visibility and identity visibility.
The Travel Rule is intended to help regulated institutions and authorities:
- identify parties connected to qualifying transfers
- detect missing or inconsistent customer information
- conduct sanctions and watchlist screening
- assess counterparty institutions
- investigate suspicious transfers
- preserve evidence for regulatory inquiries
- reduce the use of regulated crypto services for money laundering, terrorist financing, fraud, and sanctions evasion
The Travel Rule does not replace customer due diligence or blockchain analytics. It adds originator, beneficiary, and counterparty information to the broader AML control environment.
Who must comply with the Crypto Travel Rule?
The rule generally applies to businesses that fall within a jurisdiction's definition of a:
- virtual asset service provider
- crypto-asset service provider
- digital payment token service provider
- money services business
- money transmitter
- financial institution
- other regulated payment or transfer provider
Depending on local law, in-scope businesses may include:
- centralized crypto exchanges
- custodial wallet providers
- crypto payment processors
- digital asset brokers and dealers
- crypto custodians
- over-the-counter trading desks
- stablecoin service providers
- platforms transferring crypto on behalf of customers
- businesses exchanging crypto for fiat currency
- businesses exchanging one virtual asset for another
Classification is based on the activities performed, not only on the terminology a company uses to describe itself.
A service described as decentralized, non-custodial, peer-to-peer, or software-only may still fall within a regulatory definition when identifiable people or companies control the service, facilitate transfers, or conduct covered activities as a business.
At the same time, being classified as a VASP does not mean every activity automatically triggers the Travel Rule. Applicability may depend on:
- the service being provided
- whether the transfer is made for a customer
- the parties involved
- the relevant jurisdictions
- the value of the transfer
- whether another regulated institution is involved
- whether a self-hosted wallet is involved
- whether a local exemption applies
Crypto businesses should document these variables in a jurisdiction-specific applicability matrix.
When does the Crypto Travel Rule apply?
A Travel Rule assessment should take place before a covered crypto transfer is released.
VASP-to-VASP transfers
The clearest use case is a transfer from the customer of one VASP to the customer of another VASP.
The originating VASP generally:
- identifies and verifies its customer
- obtains the required beneficiary information
- identifies and assesses the receiving institution
- screens relevant parties and risk indicators
- transmits the required information securely
The beneficiary VASP generally:
- receives the Travel Rule information
- checks whether required fields are present
- verifies or compares relevant information
- performs applicable sanctions and risk checks
- approves, holds, rejects, returns, or escalates the transfer
Transfers involving intermediary institutions
Some transfers involve one or more intermediary institutions between the originating and beneficiary providers.
An intermediary may be required to:
- preserve information received with the transfer
- pass the information to the next institution
- monitor for missing fields
- avoid removing or altering required information
- follow risk-based procedures for incomplete transfers
- retain appropriate records
The revised FATF Recommendation 16 clarifies where a payment chain begins and how responsibilities are allocated among ordering, intermediary, and beneficiary institutions.
Transfers involving self-hosted wallets
A self-hosted wallet is controlled directly by its user rather than by a custodial provider.
A direct transfer between two private users, without a VASP or another obliged entity, is generally treated as a peer-to-peer transaction under the FATF framework. FATF obligations are primarily directed at regulated intermediaries rather than private individuals.
The position changes when a regulated business participates on one side of the transfer.
Depending on local law and the level of risk, the VASP may need to:
- collect originator or beneficiary information from its customer
- determine whether the external address is self-hosted
- assess who owns or controls the address
- screen the customer and relevant wallet
- perform transaction monitoring
- apply enhanced due diligence
- retain the information and decision record
A self-hosted wallet should not automatically be treated as suspicious. The business should apply a documented, risk-based procedure.
Domestic and cross-border transfers
Travel Rule obligations can apply to both domestic and cross-border transfers.
A transfer that appears domestic to the customer may still involve a foreign VASP, legal entity, group company, infrastructure provider, or regulatory jurisdiction.
The applicable rule should be determined using legal and operational facts, not only the customer's location or the language of the product interface.
What is the Crypto Travel Rule threshold?
The FATF framework allows jurisdictions to adopt a de minimis threshold of USD/EUR 1,000 for virtual asset transfers.
For transfers below this threshold, FATF guidance states that jurisdictions may require a reduced set of information, including:
- The originator’s name
- The beneficiary’s name
- The wallet address of each party or a unique transaction reference
According to FATF guidance, this information does not generally need to be verified unless suspicious circumstances are present.
The USD/EUR 1,000 threshold is not a universal global exemption.
Depending on the jurisdiction, rules may:
- apply regardless of transaction value
- require reduced information below a threshold
- require additional information above a threshold
- impose a different local-currency threshold
- aggregate linked transactions
- distinguish between existing and occasional customers
- apply separate rules to self-hosted wallets
A crypto business should configure its threshold logic by jurisdiction, transfer type, customer relationship, counterparty, and applicable regulation.
What information must accompany a crypto transfer?
Under the FATF framework, commonly required information includes:
Local laws may require additional information such as:
- date of birth
- place of birth
- residential address
- registered business address
- national identity number
- legal entity identifier
- transaction amount
- asset type
- transaction reference
- sending and receiving institution details
- purpose of transfer
- wallet ownership or control information
A receiving VASP should not assume that every field received from another institution has been independently verified.
Its workflow should establish:
- which institution collected the information
- which fields were verified
- whether the message is complete
- whether the data matches the customer and transfer
- whether the counterparty institution is acceptable
- whether sanctions or other risks are present
How Crypto Travel Rule compliance works
A practical workflow can be organized into eight stages.
1. The customer initiates the transfer
2. The system determines the applicable rule
3. The counterparty type is identified
4. Existing KYC and KYB data is checked
5. The customer, counterparty, wallet, and transaction are screened
6. Required information is exchanged securely
7. The transfer is approved, held, rejected, or escalated
8. The decision is recorded
Crypto Travel Rule requirements by jurisdiction
The following table provides a high-level comparison and is not a substitute for jurisdiction-specific legal advice.
Regulatory positions last verified on July 31, 2026.
European Union
Regulation (EU) 2023/1113 applies information requirements to covered transfers of crypto-assets involving EU crypto-asset service providers.
The framework does not include a general minimum-value exemption for covered crypto transfers.
For a transfer to or from a self-hosted address exceeding EUR 1,000, the CASP must assess whether the address is owned or controlled by its customer. The regulation also requires risk-based procedures for handling incomplete originator or beneficiary information.
United Kingdom
UK Travel Rule requirements took effect on September 1, 2023.
The Financial Conduct Authority expects cryptoasset businesses to collect, verify, and share required information, take reasonable steps, and conduct appropriate due diligence.
A regulated business remains responsible for compliance when it uses a third-party technology supplier. When a counterparty jurisdiction has not implemented the rule, the UK firm should still collect and verify the required information and make a risk-based decision about whether to proceed.
United States
The current US federal Funds Travel Rule applies to qualifying transmittals of funds of USD 3,000 or more.
Required information can include the transmittor's name, address, account number where applicable, transfer amount, execution date, recipient institution, and available recipient information.
FinCEN guidance states that a transmittal involving convertible virtual currency may qualify as a transmittal of funds and may therefore trigger the Funds Travel Rule. The business must first determine whether its activity makes it a covered money transmitter or financial institution.
Canada
Canada applies Travel Rule requirements to covered electronic funds and virtual currency transfers. Money services businesses have specific FINTRAC obligations in this area.
Separate FINTRAC rules require identity verification in specified circumstances involving virtual currency transfers or remittances of CAD 1,000 or more. Certain transaction records are also required at that level.
The CAD 1,000 amount should not be confused with the CAD 10,000 large virtual currency transaction reporting threshold.
Singapore
Singapore applies value-transfer information requirements to covered digital payment token service providers under MAS Notice PSN02.
The current notice was revised on June 30, 2025. Requirements depend on whether the service provider acts as an ordering, intermediary, or beneficiary institution within the value-transfer chain.
Crypto businesses operating in Singapore should map the current notice to their licence, service type, customer relationship, transfer role, and transaction flow.
Switzerland
FINMA applies Swiss payment-information requirements to blockchain transactions using a technology-neutral approach.
FINMA has stated that financial intermediaries must transmit client and beneficiary information for covered blockchain payments and apply controls to external wallets. Its published supervisory approach includes verifying the client's power of disposal over an external wallet using appropriate technical means.
Australia
Australia's expanded virtual asset Travel Rule obligations took effect on July 1, 2026.
AUSTRAC distinguishes between:
- ordering institutions
- intermediary institutions
- beneficiary institutions
For non-incidental virtual asset transfers, VASPs may be subject to the rule for both domestic and international transfers. AUSTRAC also provides role-specific requirements for collecting, passing on, monitoring, and retaining payer, payee, and tracing information.
What happens with self-hosted or unhosted wallets?
A self-hosted wallet does not automatically become a VASP merely because it sends or receives crypto.
However, when a regulated business interacts with the wallet, it may still need to establish:
- who controls the address
- whether the wallet belongs to its customer or another person
- the identity of the beneficiary
- the purpose of the transfer
- whether the wallet has high-risk exposure
- whether enhanced due diligence is appropriate
- whether the transaction should be approved, held, rejected, or reported
Potential wallet ownership or control checks include:
- customer declarations
- cryptographic message signing
- micro-transactions
- wallet connection
- screenshots or supporting evidence
- prior verified use of the address
- device and account context
- manual review
No single method is appropriate for every wallet, network, customer, or jurisdiction.
A low-risk transfer to a previously verified address may justify a different procedure from a first-time transfer to an address linked to elevated-risk activity.
The business should define when ownership evidence is required and avoid applying intrusive checks without a documented legal or risk basis.
How KYC, KYB, AML, and KYT support Travel Rule compliance
Travel Rule messaging is one component of the broader compliance model.
A platform that collects only a name and identity document at onboarding may later discover that it lacks:
- a verified address
- the customer's place of birth
- a current business representative
- beneficial ownership information
- information required for a specific jurisdiction
Effective Travel Rule compliance depends on the quality of the underlying customer data, the consistency of risk decisions, and the business's ability to reconstruct how each transfer was assessed.
How Identomat supports Travel Rule-aware workflows
Identomat helps crypto businesses build the identity, screening, monitoring, and risk-management foundation needed for Travel Rule-aware operations.
Identity and document verification
Identomat supports identity document verification, biometric face matching, and liveness checks.
These controls help establish a more reliable customer record before the user begins initiating crypto transfers. Identomat also positions consistent decisions and reviewable verification logs as part of its KYC onboarding workflow.
Customer information and CDD questionnaires
Configurable KYC and CDD questionnaires can collect structured customer information and make responses available within a review workflow.
This supports risk assessment, decision documentation, and audit trails without relying on unstructured emails or disconnected documents.
KYB and beneficial-owner checks
Identomat supports company information collection, business verification, and individual KYC checks for owners or representatives.
KYC and KYB cases can be managed through connected workflows with audit trails and compliance controls.
AML screening and ongoing monitoring
Identomat supports screening against sanctions lists, PEP databases, adverse media sources, and other watchlists.
Identomat’s AML monitoring solution includes configurable matching thresholds, automated alerts, and ongoing rescreening.
KYT and transaction monitoring
Identomat's KYT and transaction monitoring functionality evaluates transaction activity using configurable rules and risk logic.
The product also connects transaction information with customer context, case management, investigation workflows, and audit records.
Configurable risk logic
Travel Rule procedures vary by jurisdiction, threshold, customer type, counterparty, and wallet type.
Identomat's crypto industry offering describes Travel Rule-aware workflow design, threshold-based escalation, and clearer audit trails for VASP environments.
Build a Travel Rule-aware compliance workflow
Travel Rule readiness begins before a customer sends crypto.
A regulated crypto business needs:
- accurate customer and beneficiary information
- jurisdiction-specific rules
- counterparty assessment
- sanctions screening
- transaction monitoring
- exception management
- secure information exchange
- an audit trail supporting the final decision
Identomat helps crypto exchanges, custodial wallet providers, payment platforms, brokers, OTC providers, and other VASPs connect KYC, KYB, AML screening, risk assessment, and transaction monitoring within one configurable compliance workflow.


