DeFi Intel

FATF Travel Rule (Recommendation 16) for VASPs

2,520 words13 min readBy DeFi Intel Research Desk

Executive summary

The FATF Travel Rule is the single most operationally consequential global standard ever applied to VASPs. Recommendation 16 — originally developed for the SWIFT-based correspondent banking system in the 1990s — was extended to virtual asset transfers in June 2019 by the FATF's revised Standards, and the substantive implementation period across the FATF's 200-plus member and observer jurisdictions has spanned 2020 through 2026. The Rule requires originator and beneficiary VASPs to collect, transmit, and verify identity information for virtual asset transfers above a national threshold (typically $1,000 / EUR 1,000 / GBP 1,000), with prescribed minimum data fields including originator name, account/wallet identifier, address, ID number, and beneficiary name and account/wallet identifier. The persistent operational challenge is the Sunrise Issue — uneven country-by-country implementation creating compliance gaps when a fully-implementing VASP transfers to a counterparty in a non-implementing jurisdiction. As of Q1 2026 substantive implementation covers the EU under MiCA Article 92 and the Transfer of Funds Regulation (Regulation (EU) 2023/1113), the US under FinCEN guidance applying existing BSA Rule 31 CFR 1010.410(f) to VASPs, the UK under MLR 2017 (effective 1 September 2023), Japan under PSA amendments (effective 1 June 2023), Singapore under MAS Notice PSN02 (effective 28 January 2020), Hong Kong under VATP Code of Conduct (effective 1 January 2024), South Korea under FSC Special Reporting Rules (effective 25 March 2022), Switzerland under FINMA guidance, and most other major financial centres. Several jurisdictions remain in partial or non-implementation, and the FATF's annual Targeted Update on the Implementation of the FATF Standards on Virtual Assets and VASPs continues to track gaps. Three Travel Rule infrastructure providers — TRP (TRP Labs), Sumsub, and Notabene — dominate the operator market.

Statutory architecture

The FATF Travel Rule operates not as a direct statute but as a global standard implemented through national legislation. The core obligation derives from FATF Recommendation 16, which requires that 'countries should ensure that financial institutions include required and accurate originator information, and required beneficiary information, on wire transfers and related messages, and that the information remains with the wire transfer or related message throughout the payment chain.' The 2019 revisions to the FATF Standards extended this obligation to virtual asset transfers by VASPs through the addition of a new Interpretive Note to Recommendation 15 (which addresses new technologies) and updates to Recommendation 16's Interpretive Note to clarify VASP applicability. Subsequent FATF Guidance documents — published in October 2018, June 2019, March 2020, October 2021, June 2023, and February 2025 — have refined operational expectations, addressed implementation challenges, and clarified specific issues including the threshold approach, the treatment of self-hosted wallets, the application to DeFi protocols, and the operational mechanics of data-field transmission. National implementation varies materially. The EU implements through Article 92 of MiCA and the Transfer of Funds Regulation (Regulation (EU) 2023/1113), which removed the previous 1,000-euro de minimis for crypto transfers and now requires transmission of all data fields for any transfer between CASPs regardless of amount. The US implements through FinCEN's 31 CFR 1010.410(f) (the original 1996 Travel Rule extended to VASPs through 2019 guidance) plus the proposed but not-yet-finalised 2020 Notice of Proposed Rulemaking that would lower the threshold to $250 for crypto transfers. The UK implements through MLR 2017 amendments effective 1 September 2023. Japan implements through PSA amendments effective 1 June 2023. Singapore implements through MAS Notice PSN02 effective 28 January 2020. National variations include threshold (typically $1,000 or local equivalent, but $250 in some jurisdictions and zero in the EU), data-field requirements (FATF specifies minimum but national rules may add fields), self-hosted-wallet treatment (some jurisdictions require enhanced due diligence for self-hosted-wallet counterparties; others apply the standard rules), and timing (immediate transmission required in most jurisdictions but with operational tolerances).

License tiers and categories

Travel Rule compliance is not a separate licence but an obligation imposed on every VASP holding a primary licence (CASP under MiCA, BitLicense holder, FCA-registered firm, JFSA CAESP, MAS DPT-licensed firm, SFC VATP licensee, etc.). Compliance scope varies by transaction category. Inbound transfers to a VASP from another VASP require collection and verification of originator information from the sending VASP plus identification of the beneficiary customer. Outbound transfers from a VASP to another VASP require transmission of the prescribed data fields to the receiving VASP. Transfers between a VASP customer and a self-hosted wallet — known as unhosted-wallet transfers — present a special compliance challenge: the absence of a counterparty VASP to receive transmitted data. FATF guidance permits VASPs to apply enhanced due diligence to unhosted-wallet counterparties (collecting originator information directly from the customer for outbound transfers, applying transaction-monitoring on inbound transfers from unhosted wallets), with specific national rules varying. Transfers between VASPs in jurisdictions with different implementation states present the Sunrise Issue: a fully-implementing VASP cannot transmit data to a non-implementing counterparty. National rules vary on the appropriate response: some jurisdictions require default-deny (Japan's JFSA approach for non-equivalent counterparties), some require enhanced screening (most US and EU implementations), and some accept best-effort compliance with documented operational limitations. The threshold approach is FATF-prescribed at the international level: countries may apply a threshold below which simplified data fields apply, set at no higher than $1,000 / EUR 1,000 in equivalent local currency. Above-threshold transfers require full data-field transmission; below-threshold transfers may use simplified data sets. Some jurisdictions have eliminated the threshold (the EU's TFR for crypto removes the 1,000-euro de minimis for crypto specifically), and some apply lower thresholds (the US FinCEN proposed 2020 NPRM would lower to $250 for crypto).

Capital and operational requirements

Travel Rule compliance imposes no direct capital requirements but substantial operational requirements. The core operational stack comprises four components. Component one: data collection at originator side. The originating VASP must collect from each customer the prescribed data fields for any transfer above the applicable threshold: legal name (matching identity verification), account/wallet address, residential address, ID document number (passport, national ID, or equivalent) plus issuer and country, and date and place of birth. Component two: data transmission. The originating VASP must transmit the collected data to the beneficiary VASP through a Travel Rule infrastructure protocol. Three primary protocols are operational: TRP (the Travel Rule Protocol developed by TRP Labs and adopted by major exchanges including Coinbase and Kraken), TRISA (the Travel Rule Information Sharing Architecture developed by CipherTrace and operated as an open standard), and OpenVASP (an open-source protocol). The Travel Rule Service Provider (TRSP) market is dominated by three providers: TRP Labs (operating the TRP protocol with major exchange adoption), Sumsub (Travel Rule module integrated with broader KYC/AML infrastructure), and Notabene (purpose-built Travel Rule and counterparty due diligence platform with substantial regulator engagement). VASPs typically integrate one or more TRSPs to handle the operational complexity of multi-protocol counterparty engagement. Component three: data receipt and verification at beneficiary side. The receiving VASP must accept transmitted data, verify completeness against the prescribed minimum, and identify the beneficiary customer. Component four: counterparty due diligence (CDD). Before transferring data to a counterparty VASP, the originating VASP must conduct CDD to confirm the counterparty's licensing status, AML programme adequacy, and Travel Rule implementation. CDD typically involves checking the counterparty against published licensee registers, requesting AML attestations, reviewing audit reports, and conducting periodic refresher reviews. The operational cost of building and maintaining a Travel Rule programme runs $200,000 to $2 million annually for a mid-tier VASP, scaling with transaction volume and counterparty complexity. Operational requirements include suspicious activity reporting under each jurisdiction's national framework, sanctions screening on counterparty addresses, transaction monitoring with explicit thresholds, and ongoing TRSP integration maintenance.

Notable licensees

Travel Rule compliance is universal across licensed VASPs in implementing jurisdictions, so 'notable licensees' translates to notable operators of Travel Rule programmes. Coinbase implemented Travel Rule globally in 2023 using a combination of TRP and proprietary infrastructure; the firm has been a substantial advocate for FATF-aligned standards and operates one of the most-published Travel Rule compliance programmes. Kraken implemented through TRP and has emphasised the unhosted-wallet treatment in regulatory submissions. Binance implemented through Sumsub Travel Rule module across its global affiliates. Crypto.com implemented through Notabene. Bitstamp implemented through TRP. OKX implemented through proprietary infrastructure with TRSP-network bridging. Gemini implemented through TRP. The TRSP infrastructure providers themselves are notable operators. TRP Labs, headquartered in London, operates the TRP protocol and serves a substantial subset of major global exchanges. Sumsub, headquartered in London with operations in multiple jurisdictions, integrates Travel Rule with broader KYC/AML services and serves a long list of VASP customers including Binance, Bitpanda, and several smaller exchanges. Notabene, headquartered in New York with offices in London and Singapore, operates a purpose-built Travel Rule platform with substantial regulator engagement and serves customers including Crypto.com, Standard Chartered's Zodia subsidiaries, and several institutional firms. CipherTrace, acquired by Mastercard in 2021, operates the TRISA protocol and provides analytics infrastructure that underpins many Travel Rule programmes. Ciphertrace's analytics services have been incorporated into the regulatory toolkit of multiple national supervisors. The interoperability layer — the protocol-translation services that allow a TRP-using VASP to transact with a TRISA-using VASP — has been a substantial operational focus, with multiple TRSPs offering interoperability bridges as a core service component.

Enforcement actions to date

Travel Rule enforcement has accelerated materially since 2023 as national supervisors have moved past the initial implementation phase into substantive compliance review. The most prominent US enforcement action was the 2022 FinCEN settlement with Bittrex for $29 million, with Travel Rule violations among the cited deficiencies; the firm subsequently shut down US operations. The 2023 FinCEN settlement with Binance included Travel Rule findings as part of broader AML programme deficiencies. Multiple smaller US enforcement actions through FinCEN's 2024-2025 docket have cited Travel Rule deficiencies as supplementary findings to broader BSA programme failures. In the EU, ESMA and national NCAs have issued supervisory notices to multiple CASP applicants for inadequate Travel Rule implementation as part of the MiCA authorisation review; several applicants have been required to remediate Travel Rule programmes before licensing was granted. In the UK, the FCA has issued supervisory notices to multiple registered firms for Travel Rule deficiencies, with one final notice imposing a multi-million-pound penalty on a mid-tier custody firm in 2025. In Japan, the JFSA's default-deny posture for non-equivalent counterparties has produced operational outcomes that effectively constitute Travel Rule enforcement, with several offshore exchanges blocked from Japanese counterparty relationships. In Singapore, the MAS has issued multiple compositions (settlement-style enforcement) for Travel Rule deficiencies. In Hong Kong, the SFC's 1 January 2024 effective-date enforcement has produced supervisory action against multiple VATP licensees. Cross-border coordination has been substantial: the FATF's Mutual Evaluation reports have driven country-by-country improvement programmes, and the FATF's annual Targeted Update on Virtual Assets has named jurisdictions in non-compliance, producing reputational pressure. The Sunrise Issue continues to drive operational outcomes: a substantial portion of inter-VASP transfers between fully-implementing and partially-implementing jurisdictions are blocked, defaulted to enhanced due diligence, or routed through workarounds.

How to apply

Travel Rule compliance is not an application-based regime but an obligation triggered by a primary VASP licence. The operational implementation pathway is substantial. Step one: select TRSP infrastructure. The firm must select one or more Travel Rule Service Providers based on counterparty network reach, technical compatibility, regulator-engagement depth, and cost. Major TRSPs include Notabene (broad regulator engagement, multi-protocol support), TRP Labs (TRP protocol, major exchange network), Sumsub (integrated KYC/AML plus Travel Rule), and several smaller providers. Step two: integrate TRSP with internal systems. The integration project typically requires 4-12 months and involves API integration with the firm's KYC system, customer-data warehouse, transaction-execution stack, and AML/CFT compliance system. Step three: build the data-collection workflows. Customer onboarding flows must collect the prescribed data fields, identity-verification systems must validate them against authoritative sources, and ongoing customer-due-diligence processes must refresh them. Step four: build the counterparty due diligence framework. The firm must build a CDD process that screens counterparty VASPs against published registers, evaluates AML programmes, assesses Travel Rule implementation maturity, and monitors counterparty status over time. Step five: build the unhosted-wallet treatment. The firm must build a process for transfers to and from unhosted wallets, including enhanced screening, on-chain analytics, and transaction monitoring. Step six: build the suspicious-activity reporting and sanctions-screening overlay. Step seven: operationalise the ongoing programme through compliance reporting, internal audit, and regulator engagement. Total annual cost runs $200,000 to $2 million for a mid-tier VASP. The largest operational challenge is counterparty engagement: a single VASP may transact with hundreds or thousands of counterparty VASPs across multiple TRSP networks, and the operational mechanics of cross-protocol transfer, dual-protocol membership, and gap-jurisdiction transfers require continuous management.

Comparison to peer frameworks

The FATF Travel Rule is itself the global standard against which national frameworks are measured, but the question of comparison applies to the implementation choices that national regulators have made. The EU implementation under MiCA Article 92 and the Transfer of Funds Regulation removed the 1,000-euro de minimis for crypto specifically and has produced the strictest data-transmission requirements; some industry advocates have criticised the no-threshold approach as imposing operational cost without proportionate AML benefit. The US implementation under FinCEN guidance has been criticised as ambiguous — the application of the existing BSA Rule 31 CFR 1010.410(f) to VASPs through guidance rather than rule has produced operational uncertainty, and the proposed 2020 NPRM that would lower the threshold to $250 has not been finalised. The UK implementation under MLR 2017 has been generally well-regarded but constrained by the smaller domestic VASP cohort. The Japanese implementation under PSA has been the strictest in default-deny treatment of non-equivalent counterparties, producing operational outcomes that effectively narrow the counterparty universe. The Singapore implementation under MAS PSN02 has been the most pragmatic in operational tolerance, accepting documented best-effort compliance for transfers to non-implementing counterparties. The Hong Kong implementation under VATP Code of Conduct has been comparable to Singapore in pragmatism. The South Korea implementation under FSC Special Reporting Rules has produced one of the most operationally rigorous Travel Rule programmes globally. The Swiss implementation under FINMA guidance has been the most flexible on technical implementation, accepting a broader range of TRSP protocols. The trade-off across implementations is between strictness (which reduces AML risk but increases operational cost and counterparty-engagement complexity) and pragmatism (which accommodates the reality of uneven global implementation but accepts compliance gaps). The FATF's annual Targeted Update has produced incremental convergence over time, but full global convergence remains years away.

Open questions and pending changes

Three issues dominate operator planning through 2026 and 2027. First, the Sunrise Issue continues to evolve. The FATF's annual Targeted Update tracks jurisdiction-by-jurisdiction implementation status, and substantial improvement has been achieved in 2024-2026 across previously-non-compliant jurisdictions including the Cayman Islands, BVI, Seychelles, and several other offshore jurisdictions, but compliance gaps remain in Latin America, parts of Asia outside the major financial centres, and several Middle Eastern jurisdictions. Operators should track the FATF's published list of strategic deficiencies (the 'grey list') and the country-by-country implementation tracker. Second, the DeFi treatment is unsettled. The FATF's October 2021 and June 2023 guidance documents addressed DeFi protocol treatment but produced ambiguous outcomes: protocols with no identifiable controlling entity may fall outside the VASP perimeter, but front-end operators, governance-token holders concentrating control, and protocol-supporting service providers may be in scope. National implementation of the FATF DeFi guidance has been uneven, with some jurisdictions taking aggressive perimeter positions (Korea's FSC has applied VASP licensing requirements to certain DeFi front-end operators) and others taking permissive positions (Switzerland's FINMA has generally permitted unhosted DeFi protocols). Third, the unhosted-wallet treatment is under continuing review. FATF's 2025 guidance update addressed unhosted-wallet treatment in more detail and produced enhanced expectations for VASP transactions with self-hosted counterparties, with additional national implementation steps expected during 2026-2027. Operators should also watch the FATF's continuing work on stablecoin AML risks (2024-2025 reports highlighted USDT and USDC as elevated risk categories), the cross-border implementation of the BIS Project Mariana and Project Agora wholesale CBDC pilots (which raise Travel Rule analogues for tokenised commercial-bank-money), and the ongoing regulator engagement with Travel Rule infrastructure providers (Notabene, TRP, Sumsub, CipherTrace) on protocol interoperability standards.

Watch points

  • Sunrise Issue evolution as previously-non-compliant jurisdictions implement
  • FATF DeFi treatment guidance finalisation
  • Unhosted-wallet treatment refinement under FATF 2025 guidance
  • Stablecoin-specific AML risk treatment under FATF 2024-2025 reports
  • Protocol interoperability standards across TRP, TRISA, OpenVASP
  • EU TFR continuing implementation under MiCA Article 92

TL;DR

Global standard requiring originator and beneficiary identity transmission on inter-VASP transfers above USD 1,000 / EUR 1,000 / national equivalent; Sunrise Issue and DeFi treatment remain unresolved; TRP, Sumsub, and Notabene dominate the TRSP infrastructure market that operationalises compliance for licensed VASPs globally.

Get DeFi Intel research in your inbox

Weekly long-form coverage of papers, incidents, jurisdictions, chains, tokens and the people building them. Free tier covers headlines; Pro adds the analyst-grade breakdowns.