Crypto travel rule 101

What Is the Crypto Travel Rule?

Table of Contents

Key facts

  • What it is: FATF Recommendation 16, applied to virtual assets since June 2019.

  • Who must comply: virtual asset service providers (VASPs), including exchanges, custodians, brokers, and banks or payment firms that transfer crypto for customers.

  • What it requires: sending originator and beneficiary information with each covered transfer, and screening the counterparty.

  • Threshold: the FATF recommends USD/EUR 1,000. The EU has no threshold, and the US uses USD 3,000. See thresholds by country

  • Data standard: IVMS101

  • Adoption: 83% of jurisdictions surveyed by the FATF had Travel Rule laws in force as of July 2026.

Last updated October 6, 2026. Reviewed by Notabene's regulatory team

What Is the Crypto Travel Rule, and Why Is It Important?

The Crypto Travel Rule requires virtual asset service providers (VASPs) to collect, verify, and share the sender's and recipient's identifying information when they transfer crypto for a customer. The Financial Action Task Force (FATF) extended the rule to virtual assets in 2019, and most countries apply it above USD/EUR 1,000.

The rule comes from FATF Recommendation 16, the same standard that has governed bank wire transfers for decades. Its purpose is to keep illicit funds from moving anonymously between financial institutions and to give compliance teams the data they need for sanctions screening. Learn more about the FATF

Different countries use different terms for the businesses it covers. The EU calls them crypto-asset service providers (CASPs), and the US treats them as money services businesses (MSBs). Banks that offer crypto custody or transfers fall under the same obligations for that activity. Learn more about who counts as a VASP

Businesses that skip it risk regulatory action and rejected transfers from compliant counterparties. Customers feel it too: exchanges may ask who you are sending to, or ask you to prove you own a self-hosted wallet.

‍

What are the FATF Travel Rule Requirements?

The FATF Travel Rule requires financial institutions and VASPs to send identifying information about the originator and beneficiary along with a transfer, keep records of it, and screen it. Here are the key requirements:

Key requirements for traditional financial institutions:

  1. Information Collection:
    • Originator Information:
      • Name
      • Account number (or unique reference number if no account exists),
      • Physical address
      • National identity number,
        Customer identification number, or date and place of birth.
    • Beneficiary Information:
      • Name
      • Account number (or unique reference number).
  2. Information Transmission
    • The collected information must be transmitted to the receiving financial institution along with the transfer of funds.
  3. Record Keeping
    • Financial institutions must keep records of the information collected and transmitted for a minimum period (typically five years).
  4. Compliance and Reporting:
    • Institutions must have policies and procedures in place to comply with the Travel Rule.
    • Any suspicious transactions must be reported to relevant authorities.

Key requirements for virtual asset service providers (VASPs, aka CASPs, or MSBs):

  1. Information Collection and Transmission:
    • Similar requirements as traditional financial institutions, collecting and transmitting originator and beneficiary information for virtual asset transfers.
  2. Record Keeping:
    • Maintain records of the information collected and transmitted for a specified period.
  3. Compliance Programs:
    • Implement effective compliance programs to adhere to the Travel Rule requirements, including risk-based measures to identify and mitigate risks.

Who does the Travel Rule apply to?

It applies to any business that transfers virtual assets on behalf of a customer: centralized exchanges, custodians, brokers, OTC desks, payment providers, and banks offering crypto services. Most jurisdictions also apply it to stablecoin transfers. It does not apply to individuals sending from their own self-hosted wallets, though a VASP on the other side of that transfer has its own obligations.

‍

To learn more about Travel Rule implementation worldwide, visit our Travel Rule Requirements by Jurisdiction page.

What is the Travel Rule threshold?

The FATF recommends applying the Travel Rule to virtual asset transfers of USD/EUR 1,000 or more. Countries can set a lower threshold, and several apply it to every transfer. Linked transactions that add up to the threshold count as one.

Travel Rule thresholds by jurisdiction

Jurisdiction

Threshold

Regulator

European Union

None (all transfers)

National authorities, EBA guidelines

United States

USD 3,000

FinCEN

United Kingdom

All transfers; full data at EUR 1,000 cross-border

FCA

Singapore

SGD 1,500

MAS

Switzerland

CHF 1,000

FINMA

Canada

CAD 1,000

FINTRAC

Hong Kong

HKD 8,000

SFC / HKMA

South Korea

KRW 1,000,000

FSC

Japan

None (all transfers)

FSA

Australia

None (all transfers)

AUSTRAC

Thresholds are taken from Notabene's jurisdiction pages. See all 100+ jurisdictions

Threshold amount for traditional financial institutions

  • Threshold Amount: The Travel Rule applies to wire transfers and other similar payment methods when the amount is USD 1,000 or more (or the equivalent in other currencies).
  • Aggregated Transactions: If multiple smaller transactions that appear to be linked total USD 1,000 or more, the Travel Rule requirements apply.

Threshold Amount for VASPs, aka CASPs, aka MSBs

  • Threshold Amount: For virtual asset transactions, the FATF recommends a threshold of USD 1,000 (or EUR 1,000).
  • Aggregated Transactions: Similar to traditional financial institutions, if smaller virtual asset transactions that appear to be linked total USD 1,000 or more, the Travel Rule requirements must be followed.

Information required when threshold is met

When the threshold is met, the following information must be collected and transmitted:

Originator Information:

  1. Name
  2. Account number (or unique transaction reference)
  3. Address, national identity number, customer identification number, or date and place of birth

Beneficiary Information:

  1. Name
  2. Account number (or unique transaction reference)

Key Points

  • Due Diligence: Even for transactions below the threshold, financial institutions and VASPs should conduct due diligence if there are suspicions of money laundering or terrorist financing.
  • Regulatory Variations: Different jurisdictions may have varying implementations and additional requirements, so it's important to be aware of local regulations.

Example Scenarios

  • Single Transaction: A single wire transfer of USD 1,200 would require the collection and transmission of the specified information.
  • Multiple Linked Transactions: Multiple transactions of USD 300 each, sent in quick succession and appearing to be linked, would also trigger the Travel Rule if their total exceeds USD 1,000.

The Travel Rule threshold ensures that significant transactions are monitored for compliance with anti-money laundering (AML) and counter-terrorism financing (CTF) regulations, contributing to global financial transparency and security.

‍

What's changed since 2024?

  • EU Travel Rule in force: the Transfer of Funds Regulation has applied to every crypto transfer by EU CASPs since December 30, 2024, with no threshold. How the first six months went

  • MiCA authorization: the MiCA transition periods have ended, and the grandfathering window never exempted anyone from the TFR. What's next with MiCA

  • Recommendation 16 revised: in June 2025 the FATF finalized changes that move R16 from wire transfers to payment transparency, add beneficiary country and town as required fields, and require beneficiary institutions to check that names match. What the R16 revision means

  • Adoption up, enforcement lagging: the FATF's July 2026 update found 83% of surveyed jurisdictions (91 of 109) have Travel Rule laws in force, but 60% of those have not taken a single supervisory or enforcement action. Our takeaways from the FATF update

  • US stablecoins: the GENIUS Act, signed in July 2025, created a federal framework for payment stablecoin issuers. In April 2026, FinCEN and OFAC proposed the AML/CFT and sanctions programs those issuers must run. What it requires of your compliance stack

  • Self-hosted wallets: the EU requires CASPs to verify that a customer owns a self-hosted wallet for transfers over EUR 1,000. Self-hosted wallet rules under the TFR

Where did the Travel Rule come from?

In a publication published in January 1996, the Financial Crimes Enforcement Network (FinCEN) Advisory presented the original Travel Rule:

A Bank Secrecy Act (BSA) rule [31 CFR 103.33(g)]—often called the “Travel Rule”—requires all financial institutions to pass on certain information to the next financial institution, in certain funds transmittals involving more than one financial institution. (FinCEN 1997)

In June 2019, the FATF extended its Recommendations, including the Travel Rule, to virtual assets and VASPs. It followed with updated guidance in October 2021 that clarified how VASPs should handle counterparty due diligence, self-hosted wallets, and stablecoins. Read the FATF Recommendations

What is a Travel Rule data transfer? 

All Travel Rule-regulated transactions must be accompanied by the originator's and beneficiary's personally identifiable information (PII). At Notabene, we call these messages Travel Rule data transfers. They travel between VASPs, separately from the blockchain transaction itself, through Travel Rule messaging protocols

Is there a standard for data included in Travel Rule data transfers?

Naturally, a few questions arise when dealing with the exchange of customer PII:

  • What information should be exchanged?
  • In what format?
  • What happens when a VASP receives customer names formatted with different character sets than their systems are accustomed to?

The IVMS101 messaging standard, created by the Joint Working Group on interVASP Messaging Standards (interVASP n.d.), defines a standardized customer record data model for transmitting originator and beneficiary information. The FATF and critical regulators such as FinCEN, the Monetary Authority of Singapore (MAS), the United Kingdom’s Financial Conduct Authority (FCA), and Japan’s Financial Services Agency (JFSA) were kept informed during the development of IVMS101. 

On May 6th, 2020, IVMS101 was commended for adoption at an InterVASP closing plenary. Today, nearly every Travel Rule messaging protocol uses IVMS101.

Requesting workflow using IVMS 101

To request a transfer, there must be a workflow that enables exchange of information and ultimately authorizes a transfer.

Exchanging Required Customer PII using IVMS 101

To exchange customer information through the industry-standard Travel Rule messaging protocol, it is essential to:

  • Verify that the recipient counterparty VASP is correct
  • Ensure the data doesn’t leak
  • Leverage several intermediary service providers

‍

How do VASPs decide which counterparties to trust?

One of the most significant problems in this space is knowing your counterparty VASP. Some questions you can ask to determine the trustworthiness of other VASPs and financial institutions (FIs) include:

  • Where are they incorporated?
  • Are they regulated?
  • What are their know-your-customer (KYC) policies?
  • Do they have a robust KYC/AML process? Which third-party services do they use for KYC/AML?
  • What are their data privacy rules (and which regulation ensures them)?
  • Who else trusts them?
  • How can I verify that a request belongs to them?
  • How can I verify I am sending a request to them (rather than an imposter)?

‍

A Risk-Based Approach to Trusting Correspondent VASPs

When implementing the Travel Rule, trust is imperative for VASP interaction. VASPs send their customers’ data and rely on their counterparties to do an excellent job KYC-ing their customers. While it is your counterparty’s responsibility to perform KYC on their customer, it is originator VASP’s responsibility to determine whether their counterparty’s KYC processes are robust.

The FATF recommends performing due diligence on counterparties like a bank would while creating a correspondent banking relationship.

FATF’s initial guidance states:

Recommendation 13 stipulates that countries should require FIs to apply certain other obligations in addition to performing normal CDD measures when they engage in cross-border correspondent relationships. Separate and apart from traditional FIs that may engage in covered VA activities and for which all of the measures of Recommendation 13 already apply, some other business relationships or covered VA activities in the VASP sector may have characteristics similar to cross-border correspondent banking relationships.

INR. 13 stipulates that for correspondent banking and other similar cross-border relationships, FIs should apply criteria (a) to (e) of Recommendation 13, in addition to performing normal CDD measures. “Other similar relationships” includes money or value transfer services (MVTS) when MVTS providers act as intermediaries for other MVTS providers or where an MVTS provider accesses banking or similar services through the account of another MVTS customer of the bank (see 2016 FATF Guidance on Correspondent Banking Relationships).
(FATF Initial Guidance, 2019, para. 105)

‍

The FATF emphasizes that VASPs should establish a rigorous due diligence process to choose which VASP they wish to engage with. Even after conducting successful due diligence, this information should be continuously integrated into the ongoing AML process for approving or denying transactions.

‍

FATF’s counterparty due diligence recommendations

FATF acknowledges that conducting counterparty VASP due diligence in a timely and secure manner is a challenge, and has provided guidance on how counterparty due diligence could be undertaken:

  • Perform due diligence on the counterparty VASP.
  • Know where their business is registered.
  • Know their licensing status with their local financial regulator.
  • Know the ultimate beneficial owners.
  • Establish whether any of the ultimate beneficial owners are politically exposed persons or on a sanctions list.
  • Investigate and approve of your counterparty’s KYC/AML processes.
  • Ensure that both parties understand their responsibilities with regard to the Travel Rule.
  • Approve the senior management of the VASP before accepting a relationship.

‍

As required by paragraph 6 of INR.15 countries should also have sanctions in place for VASPs and other obligated entities that engage in VA activities but don't meet their AML/CTF requirements. (FATF 2021, 108)

For a deeper look, read VASP due diligence: establishing trust in counterparty sanctions screening

How do I send Travel Rule data transfers with Notabene?

By signing up for Notabene’s VASP Network, clients are enrolled in Notabene’s free Sunrise Plan. Sunrise users can receive and respond to unlimited Travel Rule data transfers and send transfers up to USD 10,000.00 per month to any of their counterparties — regardless of which Travel Rule solution they use.

How does Notabene support VASP due diligence?

We have incorporated the industry-standard VASP due diligence questionnaire into our client Dashboard. 

Global Digital Finance, an industry association accelerating digital finance through adopting best practices and standards and engagement with regulators and policymakers, created a VASP-to-VASP due diligence questionnaire based on the Wolfsberg Correspondent Banking Due Diligence Questionnaire (CBDDQ.)

‍

due dilliegence crypto graphic

‍

If implemented as industry standard, the CBDDQ could facilitate Travel Rule compliance. Licensing and registration information on the 2,300+ regulated institutions in the Notabene network is available in Notabene's network directory

How to access the Due Diligence Questionnaire (DDQ)

  • Create a free Notabene account
  • Navigate to the ‘My Company’ tab.
  • Scroll down to ‘Counterparty Due Diligence.'
  • You can either ‘Complete, Edit, or View DDQ.’

Related reading

The Notabene certification program covers this topic and much more

⚖️ What is the Financial Task Force?

The Financial Action Task Force (FATF) is an intergovernmental policy-making body that sets international standards in the format of non-binding recommendations to prevent money laundering and terrorist financing.

FATF Recommendations provide financial institutions with guidance that suggests a standardized line of operation without imposing any legal obligation on those to which it is addressed. 

🙌 Why is the Financial Action Task Force important?

The FATF plays an integral role in global efforts in combatting terrorist financing. It sets global standards to assist jurisdictions in implementing financial provisions of the United Nations Security Council resolutions on terrorism.

Additionally, the FATF evaluates countries’ ability to prevent, detect, investigate and prosecute the financing of terrorism. 

🤝 What are the advantages of being part of the Financial Action Task Force members? 

Financial Action Task Force members adopt the transparency of the financial system (making it easier to detect criminal activity) and give countries the capacity to successfully take action against money launderers and terrorist financiers. Over 200 jurisdictions worldwide have committed to FATF standards either as FATF members or as members of a FATF-style regional organization (FSRB).

📥 Why choose Notabene for FATF Crypto Travel Rule compliance?

Notabene's software, tools, and comprehensive data were created explicitly for helping crypto businesses comply with FATF’s recommendations.

Companies leverage our first-to-market FATF Travel Rule solution to identify virtual asset accounts, perform mandated VASP due diligence, and manage regulatory and counterparty risks from one holistic dashboard.

Frequently asked questions

What is the Travel Rule in crypto?

The crypto Travel Rule is FATF Recommendation 16 applied to virtual assets. It requires VASPs to send the sender's and recipient's identifying information with a crypto transfer, usually above USD/EUR 1,000, so the receiving VASP can screen it and keep records.

Who has to comply with the Travel Rule?

Any business that transfers crypto for customers: exchanges, custodians, brokers, OTC desks, payment providers, and banks offering crypto services. Individuals using their own self-hosted wallets are not obligated entities, but the VASP they transact with has obligations.

What is the Travel Rule threshold?

The FATF recommends USD/EUR 1,000. The EU, Japan, and Australia apply it to every transfer. The US threshold is USD 3,000 and Singapore's is SGD 1,500. Check the jurisdiction pages for each country's rule.

What information has to be shared?

For the originator: name, account number or transaction reference, and an address, ID number, customer number, or date and place of birth. For the beneficiary: name and account number or transaction reference. Some jurisdictions require more, and the 2025 R16 revisions add beneficiary country and town.

Does the Travel Rule apply to self-hosted wallets?

VASPs don't send Travel Rule data to a self-hosted wallet, but they must collect information about the wallet's owner. In the EU, transfers over EUR 1,000 to or from a customer's own wallet require proof that the customer controls it.

Does the Travel Rule apply to stablecoins?

Yes. The FATF treats stablecoins as virtual assets, so transfers between VASPs carry the same obligations. In the US, the GENIUS Act adds AML/CFT and sanctions program requirements for payment stablecoin issuers.

Does the Travel Rule apply to DeFi?

The rule applies to VASPs, not to software. A DeFi protocol with a person or company that controls or profits from it may be treated as a VASP under FATF guidance. Fully decentralized protocols generally fall outside it, though the VASPs that touch them do not.

What does the Travel Rule mean for crypto users?

When you withdraw to another exchange, you may be asked for the recipient's name and which platform they use. Sending to your own wallet, you may be asked to prove you own it. Transfers missing this information can be delayed or returned.

What happens if my counterparty isn't Travel Rule compliant?

This is the "sunrise issue." You still have to meet your own obligations, which may mean asking for missing data, holding the transfer, or returning it, based on your risk policy. In the EU, repeated failures by a counterparty must be reported to the regulator.

What are the penalties for not complying?

Penalties are set by each country and range from fines to license restrictions. Enforcement is uneven: the FATF found in 2026 that most jurisdictions with Travel Rule laws had not yet taken enforcement action, but it urged supervisors to start.

📥 Why choose Notabene for FATF Crypto Travel Rule compliance?

Notabene's software, tools, and comprehensive data were created explicitly for helping crypto businesses comply with FATF’s recommendations.

Companies leverage our first-to-market FATF Travel Rule solution to identify virtual asset accounts, perform mandated VASP due diligence, and manage regulatory and counterparty risks from one holistic dashboard.

Sunrise Plan

FREE | NO INTEGRATION REQUIRED

Start with the basics. Ease into Travel Rule compliance with our code-free, low-effort SafeTransact-Rise plan. Ramp up the full implementation when you're ready.

Learn more
Incoming TX
unlimited
OUTGOING TX
up to US$10k
DASHBOARD
full access
VASP NETWORK
full access

By clicking “Get started” you’re agreeing to sign up to Notabene’s SafeTransact-Rise plan

By clicking “Accept”, you agree to the storing of cookies on your device to enhance site navigation, analyze site usage, and assist in our marketing efforts. View our Privacy Policy for more information.