Blog

Jurisdictions & Regulation

The Travel Rule and the Transfer of Funds Regulation in the European Union

Regulation (EU) 2023/1113 in operational detail: what is in scope, the data required on payer and payee, self-hosted addresses, and missing-information handling.

The EU implements the FATF Travel Rule through Regulation (EU) 2023/1113, the Transfer of Funds Regulation. It has applied since 30 December 2024, it binds payment service providers and crypto-asset service providers directly in every member state, and it removes the amount threshold entirely for transfers of crypto-assets.

Key takeaways

  • Regulation (EU) 2023/1113 was adopted on 31 May 2023 and has applied since 30 December 2024, the same date the crypto-asset service provider regime under MiCA began to bite.
  • Crypto-asset transfers carry no minimum amount. The EUR 1 000 figures in the regulation apply to the reduced data set on funds transfers leaving the Union and to self-hosted address verification.
  • Article 14(5) requires the originator's provider to assess ownership or control of a self-hosted address for transfers above EUR 1 000.
  • Article 8 for funds and Article 16 for crypto-assets require documented procedures for whether to execute, reject, return or suspend an incomplete transfer.
  • The EBA Travel Rule Guidelines, EBA/GL/2024/11 of 4 July 2024, set the supervisory expectation on detection, intermediaries, self-hosted addresses and direct debits.

What does Regulation (EU) 2023/1113 require, and since when?

It requires that specified information about the payer and the payee, or the originator and the beneficiary, accompanies a transfer through the whole chain, and that each provider in that chain can produce it. Regulation (EU) 2023/1113 is a recast of the 2015 wire transfer regulation, extended to crypto-assets, and it applies from 30 December 2024.

Because it is a regulation rather than a directive, there is no national transposition step and no member state variation to reconcile. That is the opposite of the position under the AML directives, where the same article can read differently in two national laws.

Records must be retained for five years, and penalties for breach are set and applied by the competent authority in each member state. The regulation is the EU's answer to FATF Recommendation 16, and it goes beyond the FATF baseline on thresholds.

Which transfers are in scope, and which are not?

Scope follows the provider, not the customer. A transfer is caught where a payment service provider or crypto-asset service provider established in the Union sits on either end, or acts as an intermediary in the chain.

Transfer typeIn scopeThreshold that matters
Funds transfer within the UnionYesReduced data set permitted, full information on request within three working days
Funds transfer to or from outside the UnionYesReduced data set below EUR 1 000 where the transfer is not linked to others
Crypto-asset transfer between two providersYesNone, regardless of amount and of whether it is domestic or cross border
Crypto-asset transfer to a self-hosted addressYesOwnership assessment above EUR 1 000 under Article 14(5)
Person to person crypto transfer with no provider involvedNoNot applicable

Card payments, e-money instruments and mobile payments used purely to pay for goods or services fall outside the transfer rules where the instrument number travels with the transaction, and cash withdrawals from a payer's own account are excluded. A firm that assumes every payment product is in scope will over-engineer its controls; a firm that assumes crypto has a floor will under-engineer them.

What data must travel with a transfer of funds?

Article 4 sets the base list for the payer's provider: the payer's name, payment account number, and address, official personal document number, customer identification number or date and place of birth, plus the payee's name and payment account number. Where the transfer is not made from a payment account, a unique transaction identifier replaces the account number.

Article 5 relaxes this inside the Union. A transfer between two providers established in the Union may carry the payment account numbers alone, provided the payer's provider can supply the full data set to the payee's provider on request within three working days.

Article 6 handles transfers to outside the Union. Below EUR 1 000, and where the transfer is not linked to others that together exceed that figure, a reduced set of names and account numbers is permitted without verification, unless there are grounds for suspicion.

What data must travel with a crypto-asset transfer?

Article 14 sets a longer list, and no threshold applies to it. The originator's provider must send the originator's name, the distributed ledger address where the transfer is registered on a network using distributed ledger technology, the crypto-asset account number where one exists, and the originator's address including country, official personal document number and customer identification number, or the date and place of birth. A legal entity identifier or equivalent official identifier travels where one is available and the message format has a field for it.

Data pointFunds transfer, Article 4Crypto-asset transfer, Article 14
Originator or payer nameRequiredRequired
Account number or distributed ledger addressPayment account number or unique transaction identifierDistributed ledger address and account number where one exists
Identifying dataAddress, document number, customer number or date and place of birthAddress, document number and customer number, or date and place of birth
Beneficiary or payee dataName and payment account numberName, distributed ledger address and account number
Minimum amountEUR 1 000 relevance outside the UnionNone

The practical consequence is that onboarding must capture the union of both lists, in structured fields. A name held as free text cannot be transmitted reliably or screened cleanly at the receiving end.

How are self-hosted addresses treated?

Article 14(5) is the operative provision on the sending side. Where a transfer to a self-hosted address exceeds EUR 1 000, the originator's crypto-asset service provider must take adequate measures to assess whether that address is owned or controlled by the originator. Below that amount the obligation is risk based rather than automatic.

Article 16(2) covers the receiving side. Where crypto-assets arrive from a self-hosted address, the beneficiary's provider must obtain and hold the Article 14(1) and (2) information and ensure the transfer can be individually identified.

Assessment in practice means a signed message from the private key, a satisfactory micro-transfer from the address, or an equivalent technical method recorded against the customer file. Accepting the customer's assertion that the address is theirs is the control most often found missing at inspection, and it is the one an examiner can test in minutes against the transaction monitoring record.

What must a provider do when information is missing?

Missing-information handling is a named obligation with four permitted outcomes, not a matter of operational preference. Article 8 applies it to the payee's payment service provider for funds transfers, and Article 16 to the beneficiary's crypto-asset service provider.

OutcomeWhen it fits
Execute and request the missing dataKnown counterparty with a good record and a low-risk transfer
SuspendData expected from the counterparty within a defined window
ReturnCounterparty cannot supply the required information at all
RejectTransfer that should not have been accepted on the information available

Whichever outcome is chosen, the decision and its reason belong on file. Repeated failures by the same counterparty must be treated as a pattern rather than a series of one-offs, considered for suspicious transaction reporting, and capable of ending in restriction or termination of the relationship. A provider that silently executes every incomplete transfer has no procedure, whatever its policy document says.

What do the EBA Travel Rule Guidelines add?

The regulation states the obligation; the guidelines state the supervisory expectation. EBA/GL/2024/11 was published on 4 July 2024 and has applied since 30 December 2024, alongside the regulation itself.

They cover four things a compliance function has to build rather than assert: detection mechanisms that identify missing or incomplete originator and beneficiary information rather than relying on a downstream complaint, procedures for managing a transfer that lacks required information, technical means of identifying and verifying the party behind a self-hosted address, and the treatment of direct debits, where the payment flow runs in the opposite direction to the mandate.

They also address intermediary providers, which is the point most often overlooked. An intermediary that strips or truncates fields on the way through breaks the chain for everyone downstream, and the full guidelines text sets out what it must preserve.

How does the TFR fit with MiCA and the 2024 AML package?

The Transfer of Funds Regulation was timed to the crypto-asset service provider regime, which is why both landed on 30 December 2024. An authorised provider therefore acquires travel rule obligations and prudential obligations at the same moment, and a firm that obtained authorisation without building the messaging capability is exposed on day one.

From 10 July 2027 the preventive rulebook changes underneath it. Regulation (EU) 2024/1624 replaces the national transpositions of Directive (EU) 2015/849 with directly applicable customer due diligence rules, and the travel rule obligations continue to sit on top of them.

Sanctions come from the third instrument. Article 55 of Directive (EU) 2024/1640 requires maximum pecuniary sanctions of at least EUR 10 000 000 or 10 per cent of total annual turnover for a credit or financial institution that is a legal person, and at least EUR 5 000 000 for a natural person.

Where does the EU regime differ from the FATF baseline?

FATF Recommendation 16 leaves each country to set a de minimis threshold, and most have kept one for conventional payments. The EU removed it for crypto-asset transfers entirely, so a EUR 20 transfer between two European providers carries the same data obligation as a EUR 2 000 000 one.

The second difference is the enforcement route. A regulation applies uniformly on a fixed date, so there is no transposition gap between member states of the kind that produces the sunrise problem within a single bloc. The gap remains at the external border, where an EU provider sends to a counterparty in a jurisdiction that has not yet implemented.

For the comparative position across the United States, the United Kingdom, Singapore and Australia, see our guide to the FATF Travel Rule. For how these obligations sit within a wider exchange programme, see KYC for crypto AML and CTF compliance, our crypto sector page, and the jurisdictions and regulation collection.

FAQ

Common questions.

What is the Transfer of Funds Regulation?
Regulation (EU) 2023/1113 of 31 May 2023 on information accompanying transfers of funds and certain crypto-assets. It is the EU implementation of the FATF Travel Rule, it applies directly in every member state without national transposition, and it has applied since 30 December 2024.
Does the EU Travel Rule have a minimum transfer amount?
Not for crypto-asset transfers, which are in scope regardless of amount. Conventional transfers of funds keep two EUR 1 000 points, one for the reduced data set on transfers to outside the Union and one for the verification of self-hosted address ownership.
Who has to comply with Regulation (EU) 2023/1113?
Payment service providers and intermediary payment service providers for transfers of funds, and crypto-asset service providers and intermediary crypto-asset service providers for transfers of crypto-assets, where they are established in the Union or serve customers in it.
What must a provider do if originator information is missing?
Operate risk-based procedures to decide whether to execute, reject, return or suspend the transfer, ask the counterparty for the missing data, and record the decision. Repeated failures by the same counterparty must be escalated and can end in restricting or terminating the relationship.
How are transfers to self-hosted wallets handled under the EU rules?
Where a transfer to a self-hosted address exceeds EUR 1 000, Article 14(5) requires the originator's crypto-asset service provider to take adequate measures to assess whether the address is owned or controlled by its customer. Article 16(2) covers transfers received from a self-hosted address.
What are the EBA Travel Rule Guidelines?
EBA/GL/2024/11, published on 4 July 2024 and applying from 30 December 2024. They set out how payment service providers and crypto-asset service providers should detect missing information, handle incomplete transfers, and deal with self-hosted addresses and direct debits.

See MemberCheck against your own risk data.

Book a walkthrough with our compliance team and screen a real case in the first session.