A general counsel told "we comply with the Travel Rule" should ask a narrower question: which Travel Rule, in which jurisdiction, above what amount, and supervised by whom. FATF sets one international standard, but it lands in national law as materially different regimes, and a law existing in a counterparty's jurisdiction is not the same fact as that counterparty being held to it.

Proof of Talk Paris 2026 put the tension on the programme as "Privacy and Compliance: Two Sides of the Same Coin", on the Taostats Stage on 2 June 2026, 12:30 to 13:05. The panel was James Smith, Co-Founder and CSO of Elliptic; Jody Mettler, Chief Operating Officer and President of BitGo Bank & Trust, N.A., BitGo; Jens Hachmeister, Managing Director at Deutsche Börse Group; and Dr Saj Khoshroo, Chief Legal Officer of Midnight Foundation. Nicola Massella, Partner at Storm, moderated. The confidentiality side of that pairing is covered in our piece on blockchain privacy for regulated finance. This piece covers the compliance obligation: what the Travel Rule requires of a virtual asset service provider, where national texts depart from the FATF standard, and where a compliant sender still cannot get a compliant answer back.

What the FATF standard asks for

The Travel Rule is not a virtual-asset invention. FATF Recommendation 16 has long governed wire transfers: a payer's institution obtains originator information and passes it, with the payment, to the beneficiary's institution. FATF amended Recommendation 15 in October 2018 to bring virtual assets and VASPs within scope, and adopted the Interpretive Note to Recommendation 15 in June 2019. In FATF's own words, the Travel Rule "applies the FATF's payment transparency requirements (FATF Recommendation 16) to the VA context", requiring VASPs and financial institutions "to obtain, hold, and transmit specific originator and beneficiary information immediately and securely".

The standard lets countries apply a de minimis threshold of USD/EUR 1,000. Above it, the full set travels: the originator's name, account number or wallet address, and one of a physical address, national identity number, customer identification number, or date and place of birth, plus the beneficiary's name and account number or wallet address. Below it, names and account or wallet references are still expected. Whether a country uses that threshold, and where it sets its own, is where the regimes part company.

Four regimes compared

European Union

Regulation (EU) 2023/1113, the recast Transfer of Funds Regulation, extended the wire-transfer rules to crypto-asset transfers and has applied since 30 December 2024. It declines the de minimis option for crypto: its text states that transfers of crypto-assets "should be subject to the same requirements regardless of their amount and of whether they are domestic or cross-border transfers", while a EUR 1,000 threshold survives for ordinary transfers of funds. It also sets a specific duty for self-hosted addresses. Under Article 14(5), for a transfer of more than EUR 1,000 to a self-hosted address, the originator's crypto-asset service provider "shall take adequate measures to assess whether that address is owned or controlled by the originator". Article 16(2) places the mirror duty on the beneficiary's provider for transfers from a self-hosted address.

United States

FinCEN's Funds Travel Rule, at 31 CFR 1010.410(f), applies to a transmittal of funds of $3,000 or more. FinCEN's May 2019 guidance, FIN-2019-G001, stated that it "does not establish any new regulatory expectations or requirements"; it applied existing rules to convertible virtual currency, concluding that CVC transactions "qualify as transmittals of funds, and thus may fall within the Funds Travel Rule" at "$3,000 or more (or its equivalent in CVC)". In October 2020 FinCEN and the Federal Reserve Board proposed cutting the threshold to $250 for transfers that begin or end outside the United States, and writing CVC explicitly into the rule. That was a proposal. It has not been finalised, and $3,000 remains the operative threshold.

United Kingdom

Part 7A of the Money Laundering, Terrorist Financing and Transfer of Funds (Information on the Payer) Regulations 2017 has applied to cryptoasset transfers since 1 September 2023. Under regulation 64C, every transfer between cryptoasset businesses carries the names of originator and beneficiary and their account numbers or a unique transaction identifier. Where the transfer is not wholly within the UK and is worth the equivalent of £800 or more, fuller originator information must accompany it as well. That £800 figure replaced a EUR 1,000 threshold on 30 June 2026, under the Money Laundering and Terrorist Financing (Amendment) Regulations 2026. For transfers wholly within the UK, the fuller information must be provided within three working days if the beneficiary's business asks for it. The FCA's statement of expectations asks firms to "take all reasonable steps and exercise all due diligence" to comply. Where a counterparty cannot receive the data, the firm "must still collect and verify the information" and "should store that information before making the cryptoasset transfer".

Singapore

MAS Notice PSN02 requires a digital payment token service provider sending a value transfer to include the originator's and beneficiary's names and account or transaction reference numbers, whatever the amount. Above S$1,500, it must also include the originator's address, national identity number, or date and place of birth.

Set side by side: the EU requires full information at any amount; the UK and Singapore require basic information on every transfer and fuller information above £800 and S$1,500 respectively; the US rule starts at $3,000. A programme built only to the FATF standard would under-deliver in the EU and, since June 2026, in the UK. It would also misread Washington if it treated the 2020 proposal as law.

The unhosted wallet problem

The Travel Rule's mechanism, one regulated institution passing data to another, assumes a beneficiary institution exists. A transfer to a self-custodied wallet has none. FATF's July 2026 Targeted Update lists "risks arising from P2P transactions through unhosted wallets" among emerging and increasing risks, alongside industrialised fraud, stablecoin misuse, offshore VASPs outside effective supervision, and DeFi. It notes that P2P transfers "occur directly between parties without involvement of a regulated intermediary". It also recommends that VASPs "strengthen the monitoring of transactions involving unhosted wallets by applying enhanced due diligence measures for higher-risk wallet activity".

National answers differ. The EU's Articles 14(5) and 16(2) impose a defined duty to assess ownership or control above EUR 1,000. That is weaker than a counterparty's KYC on its own customer, since the provider is assessing a claim about a wallet it does not control, but it has a threshold and a trigger. The UK's regulation 64G takes a risk-based route instead. A business "may request" information from its own customer, having regard to its risk assessment, and "must not make the cryptoasset available to the beneficiary" if requested information does not arrive. It contains no ownership-verification duty. The US Travel Rule, framed around transmittals between financial institutions, has no equivalent provision.

The sunrise problem, in FATF's numbers

Compliance vendors such as Notabene call it the "sunrise issue": a sending VASP's obligation exists from the day its own jurisdiction's law takes effect, whether or not the receiving VASP's jurisdiction has an equivalent rule yet. FATF's July 2026 update supplies the numbers.

  • 83% of responding jurisdictions (91 of 109) had passed legislation implementing the Travel Rule, up from 73% (85 of 117) in 2025. A further 11 of 109 reported being in the process of implementing it, against 14 of 117 in 2025.
  • As of April 2026, 149 jurisdictions had been assessed against Recommendation 15. 34% (51) were rated largely compliant, up from 29% in 2025. 43% (64) were partially compliant, down from 50%. 22% (33) were non-compliant, and only one jurisdiction was fully compliant.

The more consequential figure sits inside the first. Of the 91 jurisdictions with Travel Rule legislation, 55 "have not yet issued findings or directives or taken enforcement or other supervisory actions against VASPs focused on Travel Rule compliance". FATF suggests this "likely reflects that many jurisdictions have only recently enacted Travel Rule legislation". Either way, a law on the books and a supervised obligation are separate facts. A sending VASP assessing a counterparty cannot infer the second from the first.

Sanctions screening and chain analytics sit alongside the rule

Three obligations share infrastructure but rest on different legal bases. The Travel Rule is an information duty: a transfer triggers it, and sending accurate data to the counterparty discharges it. Sanctions regimes, such as OFAC's SDN list and the UK and EU asset-freeze regimes, prohibit dealings with designated persons whatever the transfer size and whether or not a counterparty's jurisdiction has a Travel Rule. Chain analytics is neither a legal duty nor a source of originator information. It is the tooling that helps a VASP judge whether an address belongs to a supervised counterparty, a self-hosted wallet, or something it should not touch.

FATF's July 2026 recommendations to VASPs treat them together. They call for AML/CFT controls "including KYC, wallet screening, blacklisting, and, where appropriate, whitelisting mechanisms as well as freezing and blocking capabilities". They ask VASPs to "detect rapid transfer of VAs using transactions monitoring and blockchain analytics tools", and to "detect accounts used by oVASPs that misrepresent themselves as retail users". None of that substitutes for the Travel Rule. An analytics tool can flag that an address clusters with a sanctioned entity, but it cannot supply an originator's date of birth that the sending institution never collected.

What the texts settle

None of this is legal advice. Four points follow from the primary texts. There is no single global threshold: the EU has none for crypto, the UK moved to £800 in June 2026, Singapore uses S$1,500, and the US applies $3,000, with its $250 cross-border figure still an unfinished 2020 proposal. "Legislated" and "supervised" are different facts about a counterparty jurisdiction; by FATF's count, 55 of the 91 jurisdictions with a Travel Rule law had yet to take any Travel Rule supervisory or enforcement action. Self-hosted wallets are treated differently in each regime, from the EU's defined ownership assessment to the UK's risk-based requests. And sanctions screening and the Travel Rule have different triggers, so discharging one does not discharge the other.

For where the wider 2026 regulatory picture stands, see our review of what regulators actually permitted in 2026. The full Paris 2026 programme this panel sat within is on the agenda.