The Travel Rule requires the institution sending a payment or virtual asset transfer to pass the originator's and the beneficiary's identifying details to the receiving institution, and to hold them on record. FATF sets the standard in Recommendation 16. Each jurisdiction then sets its own threshold, its own data fields and its own start date.
Key takeaways
- The United States still applies a USD 3,000 threshold under 31 CFR 1010.410(f). The 2020 joint proposal to cut the cross-border figure to USD 250 was never finalised.
- The European Union applies no minimum amount at all to crypto-asset transfers. Recital 30 of Regulation (EU) 2023/1113 makes the obligation amount-neutral, and the regulation has applied since 30 December 2024.
- The UK switched on cryptoasset transfer obligations on 1 September 2023 through regulations 64A to 64H of the Money Laundering Regulations 2017.
- Australia's travel rule commenced on 31 March 2026, with newly registrable virtual asset services deferred to 1 July 2026 and self-hosted wallet reporting deferred to 31 March 2029.
- Singapore sets its data cut at S$1,500, above which the originator's address, national identity number or date and place of birth must also travel.
What data must accompany a transfer under the Travel Rule?
The required fields are similar everywhere, but they are set by national law rather than by FATF directly. In the United States, 31 CFR 1010.410(f) obliges the transmittor's financial institution to include the transmittor's name and account number, the transmittor's address, the amount, the execution date, the identity of the recipient's financial institution, the recipient's name, address and account number as received, and either the name and address or a numerical identifier of the transmittor's own institution.
The European Union's list is close but not identical. Article 14 of Regulation (EU) 2023/1113 requires the originator's name, distributed ledger address, account number, address including country, official personal document number and customer identification number for crypto-asset transfers.
Two consequences follow for anyone operating across borders. The union of the fields, not the intersection, is what your onboarding must collect. And the data has to be structured, because a receiving institution screening a free-text name string cannot reliably tell a match from a near miss.
Which thresholds and commencement dates apply by jurisdiction?
Thresholds are the single biggest source of implementation error, because teams assume a global figure exists. It does not. The table below sets out the position in five reachable regimes as at August 2026.
| Jurisdiction | Instrument | Threshold | Applied from |
|---|---|---|---|
| United States | 31 CFR 1010.410(f) | USD 3,000 or more | 1996 for funds transfers; extended to convertible virtual currency by FinCEN guidance in May 2019 |
| European Union | Regulation (EU) 2023/1113 | No minimum for crypto-asset transfers; EUR 1,000 for simplified data on funds transfers | 30 December 2024, alongside the EBA Travel Rule Guidelines |
| United Kingdom | Part 7A, MLRs 2017, regs 64A to 64H | No minimum for cryptoasset transfers | 1 September 2023 |
| Singapore | MAS Notice PSN02 | All value transfers; expanded data set above S$1,500 | In force, last revised 30 June 2025 |
| Australia | AML/CTF Act value transfer obligations | All transfers of money, virtual assets or property | 31 March 2026, deferred to 1 July 2026 for new registrable virtual asset services |
The pattern worth noting is directional. Conventional payments kept their monetary thresholds, while the crypto obligations were written without one in the EU, the UK and Australia. A firm that runs both rails cannot apply one rule set to both.
Why is the United States still on a USD 3,000 threshold?
Because the proposal to change it stalled. On 27 October 2020 FinCEN and the Federal Reserve Board published a joint notice of proposed rulemaking that would have cut the recordkeeping and travel rule threshold to USD 250 for transfers beginning or ending outside the United States, and would have clarified that the rules cover convertible virtual currency.
That proposal has not been finalised. As of August 2026 the operative figure remains USD 3,000, and treating USD 250 as live is a live compliance error in the other direction: it produces over-collection without a legal basis in the US, while offering no protection in the EU where there is no floor at all.
The virtual currency point was settled separately. FinCEN's May 2019 guidance confirmed that the funds transfer and travel rules apply to transmittals of convertible virtual currency by money transmitters, so a US exchange has been in scope for seven years without any change to the underlying regulation.
What does the sunrise issue actually cost a VASP?
The sunrise issue is the gap created when jurisdictions commence at different dates. A UK business has been obliged to transmit originator data since 1 September 2023. An Australian counterparty offering a newly registrable virtual asset service had no equivalent obligation until 1 July 2026. For nearly three years the UK sender had a legal duty to send data that its counterparty had no duty, no protocol and sometimes no lawful basis to receive.
The cost lands in three places. Sending teams accumulate a queue of transfers where the data was collected but never successfully delivered, which is a recordkeeping problem rather than a transmission one. Receiving teams get partial payloads in formats their systems do not parse. And both sides need a documented policy for what happens next.
The FCA addressed exactly this in its statement of expectations for UK cryptoasset businesses, which sets out how firms should behave when sending to, and receiving from, jurisdictions that have not yet implemented. The answer is not to stop transferring. It is to take the required data, assess the counterparty and record the decision.
How do you verify that the counterparty VASP is real and registered?
This is the obligation with no equivalent in correspondent banking, where a SWIFT BIC already identifies a supervised institution. A virtual asset transfer arrives from a wallet address that carries no registration status, no supervisor and no jurisdiction on its face.
Counterparty due diligence therefore has to resolve three separate questions before data is released: whether the receiving business is a real, identifiable legal entity; whether it holds the registration or authorisation its jurisdiction requires, such as FCA registration under the MLRs or a MiCA authorisation in the EU; and whether its own controls are good enough to be trusted with personal data about your customer.
Industry has built shared infrastructure to close part of this gap. The interVASP messaging standard IVMS101 gives the payload a common structure, and networks such as TRISA and OpenVASP handle authenticated exchange between members. None of them decides whether a counterparty is legitimate. That judgement stays with your firm, and it belongs in the same file as your sanctions and PEP screening evidence.
How are transfers to self-hosted wallets treated?
Self-hosted wallets are the hardest case, because there is no institution on the other side to receive anything. Regimes have converged on ownership verification rather than data transmission. Under Article 14(5) of Regulation (EU) 2023/1113, a crypto-asset service provider must verify that a self-hosted address is owned or controlled by its customer where the transfer exceeds EUR 1,000.
Australia took a different route on timing. AUSTRAC's transitional rules do not require reports of transfers of value involving unverified self-hosted virtual asset wallets until 31 March 2029 where the business already provided the relevant designated services, while expecting firms to begin planning system and policy changes now. Suspicious matter reporting still applies throughout.
Verification in practice means a signed message from the private key, a micro-transfer from the address, or a satisfactory equivalent recorded against the customer file. What it does not mean is accepting a customer's assertion that the address is theirs, which is the control most commonly found missing at inspection. Our crypto sector page covers where this sits in a wider exchange programme.
What should happen when originator information is missing or incomplete?
Missing-information handling is a named obligation, not an operational preference. Article 16 of Regulation (EU) 2023/1113 requires the beneficiary's crypto-asset service provider to run effective risk-based procedures for determining whether to execute, reject, return or suspend a transfer that lacks the required complete information.
The four outcomes are deliberately different. Executing while requesting the missing data suits a known counterparty with a good record, and suspending fits a case awaiting a response within a defined window. Returning suits a counterparty that cannot supply the data at all, while rejecting is reserved for a transfer you should not have accepted.
What ties them together is the escalation path. Repeated failures by one counterparty must be treated as a pattern, considered for suspicious activity reporting, and capable of ending in restriction or termination of the relationship. A firm that silently executes every incomplete transfer has no procedure, whatever its policy document says, and the transaction monitoring record is where an examiner will look for the evidence.
What changes to Recommendation 16 are coming before 2030?
FATF agreed revisions to Recommendation 16 in June 2025, aimed at payment transparency in cross-border payments generally rather than at virtual assets specifically. The revisions align the standard with structured message formats such as ISO 20022, tighten what counts as required originator and beneficiary information, and address the treatment of intermediary institutions. Global implementation is expected by the end of 2030.
Two practical implications follow for planning. Structured data becomes the assumption rather than an aspiration, which means free-text name and address fields will need remediation rather than reformatting. And the alignment between conventional payments and virtual asset transfers gets closer, so the two workstreams that most firms still run separately will converge.
The near-term dates are firmer than the 2030 horizon. Australian firms have travel rule obligations for new virtual asset services from 1 July 2026, enrolment and registration due by 29 July 2026, and self-hosted wallet reporting from 31 March 2029. Our guides to the EU Transfer of Funds Regulation, KYC for crypto and the wider jurisdictions and regulation collection cover the neighbouring obligations.



