The EU implements the FATF Travel Rule through Regulation (EU) 2023/1113, the Transfer of Funds Regulation. It has applied since 30 December 2024, it binds payment service providers and crypto-asset service providers directly in every member state, and it removes the amount threshold entirely for transfers of crypto-assets.
Key takeaways
- Regulation (EU) 2023/1113 was adopted on 31 May 2023 and has applied since 30 December 2024, the same date the crypto-asset service provider regime under MiCA began to bite.
- Crypto-asset transfers carry no minimum amount. The EUR 1 000 figures in the regulation apply to the reduced data set on funds transfers leaving the Union and to self-hosted address verification.
- Article 14(5) requires the originator's provider to assess ownership or control of a self-hosted address for transfers above EUR 1 000.
- Article 8 for funds and Article 16 for crypto-assets require documented procedures for whether to execute, reject, return or suspend an incomplete transfer.
- The EBA Travel Rule Guidelines, EBA/GL/2024/11 of 4 July 2024, set the supervisory expectation on detection, intermediaries, self-hosted addresses and direct debits.
What does Regulation (EU) 2023/1113 require, and since when?
It requires that specified information about the payer and the payee, or the originator and the beneficiary, accompanies a transfer through the whole chain, and that each provider in that chain can produce it. Regulation (EU) 2023/1113 is a recast of the 2015 wire transfer regulation, extended to crypto-assets, and it applies from 30 December 2024.
Because it is a regulation rather than a directive, there is no national transposition step and no member state variation to reconcile. That is the opposite of the position under the AML directives, where the same article can read differently in two national laws.
Records must be retained for five years, and penalties for breach are set and applied by the competent authority in each member state. The regulation is the EU's answer to FATF Recommendation 16, and it goes beyond the FATF baseline on thresholds.
Which transfers are in scope, and which are not?
Scope follows the provider, not the customer. A transfer is caught where a payment service provider or crypto-asset service provider established in the Union sits on either end, or acts as an intermediary in the chain.
| Transfer type | In scope | Threshold that matters |
|---|---|---|
| Funds transfer within the Union | Yes | Reduced data set permitted, full information on request within three working days |
| Funds transfer to or from outside the Union | Yes | Reduced data set below EUR 1 000 where the transfer is not linked to others |
| Crypto-asset transfer between two providers | Yes | None, regardless of amount and of whether it is domestic or cross border |
| Crypto-asset transfer to a self-hosted address | Yes | Ownership assessment above EUR 1 000 under Article 14(5) |
| Person to person crypto transfer with no provider involved | No | Not applicable |
Card payments, e-money instruments and mobile payments used purely to pay for goods or services fall outside the transfer rules where the instrument number travels with the transaction, and cash withdrawals from a payer's own account are excluded. A firm that assumes every payment product is in scope will over-engineer its controls; a firm that assumes crypto has a floor will under-engineer them.
What data must travel with a transfer of funds?
Article 4 sets the base list for the payer's provider: the payer's name, payment account number, and address, official personal document number, customer identification number or date and place of birth, plus the payee's name and payment account number. Where the transfer is not made from a payment account, a unique transaction identifier replaces the account number.
Article 5 relaxes this inside the Union. A transfer between two providers established in the Union may carry the payment account numbers alone, provided the payer's provider can supply the full data set to the payee's provider on request within three working days.
Article 6 handles transfers to outside the Union. Below EUR 1 000, and where the transfer is not linked to others that together exceed that figure, a reduced set of names and account numbers is permitted without verification, unless there are grounds for suspicion.
What data must travel with a crypto-asset transfer?
Article 14 sets a longer list, and no threshold applies to it. The originator's provider must send the originator's name, the distributed ledger address where the transfer is registered on a network using distributed ledger technology, the crypto-asset account number where one exists, and the originator's address including country, official personal document number and customer identification number, or the date and place of birth. A legal entity identifier or equivalent official identifier travels where one is available and the message format has a field for it.
| Data point | Funds transfer, Article 4 | Crypto-asset transfer, Article 14 |
|---|---|---|
| Originator or payer name | Required | Required |
| Account number or distributed ledger address | Payment account number or unique transaction identifier | Distributed ledger address and account number where one exists |
| Identifying data | Address, document number, customer number or date and place of birth | Address, document number and customer number, or date and place of birth |
| Beneficiary or payee data | Name and payment account number | Name, distributed ledger address and account number |
| Minimum amount | EUR 1 000 relevance outside the Union | None |
The practical consequence is that onboarding must capture the union of both lists, in structured fields. A name held as free text cannot be transmitted reliably or screened cleanly at the receiving end.
How are self-hosted addresses treated?
Article 14(5) is the operative provision on the sending side. Where a transfer to a self-hosted address exceeds EUR 1 000, the originator's crypto-asset service provider must take adequate measures to assess whether that address is owned or controlled by the originator. Below that amount the obligation is risk based rather than automatic.
Article 16(2) covers the receiving side. Where crypto-assets arrive from a self-hosted address, the beneficiary's provider must obtain and hold the Article 14(1) and (2) information and ensure the transfer can be individually identified.
Assessment in practice means a signed message from the private key, a satisfactory micro-transfer from the address, or an equivalent technical method recorded against the customer file. Accepting the customer's assertion that the address is theirs is the control most often found missing at inspection, and it is the one an examiner can test in minutes against the transaction monitoring record.
What must a provider do when information is missing?
Missing-information handling is a named obligation with four permitted outcomes, not a matter of operational preference. Article 8 applies it to the payee's payment service provider for funds transfers, and Article 16 to the beneficiary's crypto-asset service provider.
| Outcome | When it fits |
|---|---|
| Execute and request the missing data | Known counterparty with a good record and a low-risk transfer |
| Suspend | Data expected from the counterparty within a defined window |
| Return | Counterparty cannot supply the required information at all |
| Reject | Transfer that should not have been accepted on the information available |
Whichever outcome is chosen, the decision and its reason belong on file. Repeated failures by the same counterparty must be treated as a pattern rather than a series of one-offs, considered for suspicious transaction reporting, and capable of ending in restriction or termination of the relationship. A provider that silently executes every incomplete transfer has no procedure, whatever its policy document says.
What do the EBA Travel Rule Guidelines add?
The regulation states the obligation; the guidelines state the supervisory expectation. EBA/GL/2024/11 was published on 4 July 2024 and has applied since 30 December 2024, alongside the regulation itself.
They cover four things a compliance function has to build rather than assert: detection mechanisms that identify missing or incomplete originator and beneficiary information rather than relying on a downstream complaint, procedures for managing a transfer that lacks required information, technical means of identifying and verifying the party behind a self-hosted address, and the treatment of direct debits, where the payment flow runs in the opposite direction to the mandate.
They also address intermediary providers, which is the point most often overlooked. An intermediary that strips or truncates fields on the way through breaks the chain for everyone downstream, and the full guidelines text sets out what it must preserve.
How does the TFR fit with MiCA and the 2024 AML package?
The Transfer of Funds Regulation was timed to the crypto-asset service provider regime, which is why both landed on 30 December 2024. An authorised provider therefore acquires travel rule obligations and prudential obligations at the same moment, and a firm that obtained authorisation without building the messaging capability is exposed on day one.
From 10 July 2027 the preventive rulebook changes underneath it. Regulation (EU) 2024/1624 replaces the national transpositions of Directive (EU) 2015/849 with directly applicable customer due diligence rules, and the travel rule obligations continue to sit on top of them.
Sanctions come from the third instrument. Article 55 of Directive (EU) 2024/1640 requires maximum pecuniary sanctions of at least EUR 10 000 000 or 10 per cent of total annual turnover for a credit or financial institution that is a legal person, and at least EUR 5 000 000 for a natural person.
Where does the EU regime differ from the FATF baseline?
FATF Recommendation 16 leaves each country to set a de minimis threshold, and most have kept one for conventional payments. The EU removed it for crypto-asset transfers entirely, so a EUR 20 transfer between two European providers carries the same data obligation as a EUR 2 000 000 one.
The second difference is the enforcement route. A regulation applies uniformly on a fixed date, so there is no transposition gap between member states of the kind that produces the sunrise problem within a single bloc. The gap remains at the external border, where an EU provider sends to a counterparty in a jurisdiction that has not yet implemented.
For the comparative position across the United States, the United Kingdom, Singapore and Australia, see our guide to the FATF Travel Rule. For how these obligations sit within a wider exchange programme, see KYC for crypto AML and CTF compliance, our crypto sector page, and the jurisdictions and regulation collection.



