Crypto & the Travel Rule
The Travel Rule is the application of FATF Recommendation 16 to virtual assets: when value moves between Virtual Asset Service Providers (VASPs), the originating provider must collect and transmit identifying information about the sender (originator) and recipient (beneficiary), and the receiving provider must obtain and check it. FATF extended the standard to virtual assets in June 2019, and jurisdictions including the UK and EU have since made it law. It exists to stop crypto being used to move criminal funds anonymously.
The Travel Rule derives from FATF Recommendation 16 (originally for wire transfers), extended to virtual assets and VASPs in June 2019.
It applies to transfers at or above a USD/EUR 1,000 threshold; below that, reduced information may be required.
The originating VASP must send the originator's name, account/wallet identifier and address (or date of birth and a customer/ID number), plus the beneficiary's name and wallet identifier.
The beneficiary VASP must receive and verify this data and apply risk-based controls when information is missing or the counterparty cannot be confirmed.
The 'sunrise problem' - jurisdictions adopting the rule at different times - and transfers to/from unhosted (self-custody) wallets create practical compliance gaps.
In the UK the Travel Rule has applied since 1 September 2023 under the Money Laundering and Terrorist Financing (Amendment) (No. 2) Regulations 2022, with FCA expectations published for firms.
The EU implemented equivalent rules via the recast Transfer of Funds Regulation, in force from late 2024.
The Travel Rule bites on crypto casinos and any operator that accepts cryptoasset deposits or withdrawals through a VASP relationship, meaning originator/beneficiary information must accompany qualifying transfers. It reinforces the need for source-of-funds and sanctions screening on crypto flows, and heightens counterparty risk where deposits arrive from non-compliant exchanges or self-custody wallets.
Reference, not advice. This is a teaching summary of the AML framework — not legal advice, and not an operational compliance procedure. Confirm requirements against the primary regulator and your own counsel.