Stablecoin Payments

Travel Rule Compliance for Crypto: A Complete Guide for VASPs and CASPs (2026)

James Carter
Business Finance Writer

Understand the FATF Travel Rule for virtual assets: thresholds by jurisdiction, data requirements, transmission protocols, operational challenges, and how PhotonPay achieves compliant cross-border transfers.

2026.07.14 06:30:22 · 5minute(s)
The Travel Rule is one of the most consequential anti-money-laundering (AML) obligations in the virtual asset industry. Rooted in FATF Recommendation 16 and extended to crypto in 2019, it requires virtual asset service providers (VASPs) to collect and transmit originator and beneficiary information alongside qualifying transfers. This guide explains what the Travel Rule is, who it applies to, exactly what data must be shared, how thresholds differ sharply by jurisdiction, the protocols used to transmit data, the operational challenges firms face, and the 2026 FATF updates that are reshaping the landscape.

What Is the Travel Rule?

The Travel Rule is FATF Recommendation 16 (R.16) applied to virtual asset transfers. It was originally designed for traditional bank wire transfers under the Bank Secrecy Act framework. In June 2019, the Financial Action Task Force (FATF) published guidance extending the Travel Rule to virtual assets, placing crypto transfers under the same "traveling information" principle that governs correspondent banking.
The core principle is simple but demanding: when a VASP executes a qualifying transfer, it must collect identifying information about the originator and the beneficiary, and transmit that information to the counterparty VASP at or before the point of transfer. As the industry saying goes — "the information travels with the value."
Crucially, the rule applies to activity, not to a label. A business does not escape the obligation by calling itself a "protocol" or a "wallet." If it performs the regulated activity of sending or receiving value on behalf of customers, it is in scope.

Who Must Comply?

The Travel Rule applies to a broad set of regulated entities, known by different names across regimes:
  • VASPs — the term used by FATF and most jurisdictions (Virtual Asset Service Providers)
  • CASPs — the EU term (Crypto-Asset Service Providers), defined under MiCA
  • MSBs — the US term (Money Services Businesses), registered with FinCEN
Concrete examples include centralized exchanges, custodial wallets, fiat on-ramps and off-ramps, brokers, and OTC desks. If you custody customer funds or facilitate transfers on their behalf, the Travel Rule almost certainly applies to you.

Data Requirements: What Must Travel

The data that must travel depends on whether the transfer is above or below the applicable threshold.

Above Threshold (e.g., USD/EUR 1,000 FATF default)

  • Originator: full name, account/wallet identifier, and physical address OR national identity number / date and place of birth
  • Beneficiary: full name and account/wallet identifier

Below Threshold

  • Originator and beneficiary names plus a wallet address or unique transaction reference
  • No identity verification is strictly required at the low-value tier in most regimes
The intent is proportionate: small transfers carry lighter obligations, while larger transfers require robust identification to support law enforcement traceability.

Thresholds by Jurisdiction: They Differ Sharply

One of the most common compliance errors is assuming a single global threshold. There is no uniform rule — and the differences are stark.
Regime
Threshold
Notes
FATF global
USD/EUR 1,000
Recommendation, not law
US FinCEN
USD 3,000
BSA Travel Rule, 31 CFR 1010.410
EU TFR
ZERO (no de-minimis)
Regulation 2023/1113, applies to all transfers
Canada FINTRAC
CAD 1,000
UK FCA
GBP 1,000 (aligned with FATF)
South Korea
KRW 1,000,000
UAE
AED 3,500
The EU's Transfer of Funds Regulation (TFR) is the most aggressive: it applies a zero de-minimis threshold, meaning every single crypto transfer — regardless of size — must carry Travel Rule data. A VASP operating in both the US and the EU must therefore apply two completely different rule sets to the same customer flow.

How Is the Data Transmitted?

Unlike traditional banking, which relies on a single universal messaging network (SWIFT), crypto has no single mandated protocol. Instead, several competing standards have emerged:
  • TRISA (built on OpenVASP)
  • Sygna Bridge
  • Notabene
  • Elliptic
The data must be transmitted before or at the same time as the transaction — never after. This creates a timing challenge: a compliant transfer requires the counterparty's identity to be resolved in real time before the value moves on-chain.
There is also a persistent data-security tension. VASPs must share personal data to comply with AML rules while simultaneously respecting privacy laws such as the EU's GDPR. Encrypting data in transit, minimizing what is shared, and limiting retention are all part of a defensible compliance design.

Key Operational Challenges

Interoperability Between Protocols

With multiple protocols in use, a VASP on TRISA may need to exchange data with a counterparty on Sygna or Notabene. Gateways and translation layers are essential, but friction remains.

Self-Hosted Wallet Verification

When a transfer goes to a self-hosted (non-custodial) wallet, the EU requires the VASP to verify that the customer owns or controls that wallet above €1,000. This "ownership attestation" is technically and operationally demanding.

Counterparty Due Diligence

VASPs must perform due diligence on foreign counterparties to ensure they are also regulated and compliant. Sending data to an unregulated counterparty can itself create regulatory exposure.

The "Sunrise Issue"

As of January 2026, roughly 85 of 117 FATF jurisdictions have enacted Travel Rule legislation — but holdouts remain. When one side of a transfer is in a compliant jurisdiction and the other is not, the originating VASP faces difficult decisions about whether and how to proceed.

Structuring Detection

Bad actors attempt to evade thresholds by breaking large transfers into many smaller ones ("structuring"). VASPs must deploy monitoring to detect and report patterns indicative of threshold evasion.

FATF 2026 Updates: The Scope Is Expanding

The FATF's 2026 updates signal stronger, broader enforcement:
  • Expanded scope: intermediaries that perform value-routing or key management can now themselves be classified as VASPs.
  • DeFi in scope: Decentralized finance protocols fall under the Travel Rule when they exercise control, custody, or hold administrative keys.
  • Richer data and retention: Supervisors expect more complete data capture and longer, clearer retention practices.
  • Stronger enforcement: National supervisors are issuing clearer enforcement signals, raising the cost of non-compliance.

PhotonPay's Travel Rule Implementation

✅ Cross-Border AML & Travel Rule

  • PhotonPay natively supports Travel Rule compliance across all regulated jurisdictions
  • Integrated with AI-driven fraud prevention
  • Covers all VASP-to-VASP transfers in its network

FAQ

What is the Travel Rule in simple terms?

The Travel Rule requires crypto businesses (VASPs/CASPs/MSBs) to collect and send customer identifying information alongside qualifying transfers, so that originator and beneficiary data "travels with the value" and remains available to law enforcement.

Does the Travel Rule apply to small transfers?

It depends on the jurisdiction. The FATF default and several regimes apply a threshold (e.g., USD 1,000), below which only names plus a wallet address or reference are needed. The EU is the major exception: its TFR applies a zero threshold, so all transfers are covered.

How do VASPs send Travel Rule data if there is no SWIFT for crypto?

VASPs use competing protocols such as TRISA, Sygna Bridge, Notabene, and Elliptic. Data must be exchanged before or at the time of the on-chain transaction, requiring real-time counterparty resolution.

Are self-hosted wallets exempt?

No. Above the EU's €1,000 threshold, a VASP must verify that its customer owns or controls a self-hosted wallet. Other jurisdictions address self-hosted wallets through risk-based controls rather than a hard verification rule.

Conclusion

The Travel Rule is no longer optional for any serious virtual asset business. With thresholds that vary from zero (EU) to USD 3,000 (US) and a fragmented protocol landscape, compliance demands both technical infrastructure and regulatory clarity. The 2026 FATF updates only raise the stakes, pulling intermediaries and even some DeFi actors into scope. For VASPs and CASPs building cross-border operations, partnering with a provider that natively supports Travel Rule compliance across all regulated jurisdictions — and layers AI-driven fraud prevention on top — is the most resilient path forward. PhotonPay's implementation delivers exactly that: native, multi-jurisdiction Travel Rule coverage with integrated screening across its entire VASP-to-VASP network.

Power Your Global Growth with PhotonPay