Travel Rule Compliance for Crypto Firms: The Gap That Gets You
By the Legal Cyber Academy editorial team ·
The Financial Action Task Force adopted its Recommendation 16 — the Travel Rule — for virtual asset service providers (VASPs) in June 2019. As of 2026-09-21, more than 60 jurisdictions have enacted domestic legislation or binding regulatory guidance that applies the rule to crypto transfers above a threshold, typically the equivalent of USD 1,000. Yet cross-border enforcement remains fragmented, and the compliance gaps that remain open are precisely the ones regulators in the United States, European Union, and Singapore are actively examining.
What the Travel Rule Actually Requires
At its core, the Travel Rule requires the sending VASP to collect and transmit specific identifying information about the originator and the beneficiary to the receiving VASP — before or at the time of the transfer. The required originator data includes the customer's name, account number, and, depending on jurisdiction, address or national identity number. The receiving VASP must hold that data and make it available to competent authorities on request.
In the United States, the Bank Secrecy Act's existing Travel Rule — codified at 31 C.F.R. § 103.33 — has applied to banks since 1996. FinCEN extended its application to money services businesses, including certain crypto exchanges, through subsequent rulemaking. FinCEN's October 2020 proposed rule (85 Fed. Reg. 83840) sought to lower the reporting threshold for cryptocurrency transactions to USD 250 for cross-border transfers and impose stricter CDD requirements for transactions involving unhosted wallets. As of 2026-09-21, that rulemaking has not been finalized in its original form, but FinCEN has continued to enforce the existing threshold using the MSB framework, and the unhosted-wallet question remains open rulemaking.
In the EU, the Transfer of Funds Regulation — Regulation (EU) 2023/1113, which replaced the prior 2015 regulation — extended Travel Rule obligations to all crypto-asset service providers (CASPs) licensed under MiCA, with no minimum transfer threshold. That regulation came into force in 2023 and its Travel Rule provisions apply in full as of 2026-09-21.
The Sunrise Problem Is Not Over
The single most litigated operational gap in Travel Rule compliance has been the sunrise problem: a sending VASP in a jurisdiction with a live Travel Rule obligation transmits required data to a receiving VASP in a jurisdiction where no equivalent rule yet exists, and the receiver has no infrastructure to accept or store that data. Conversely, a compliant receiver asks for data that a sender in a lighter-touch jurisdiction is not yet required to collect.
Industry bodies including the Global Digital Finance Travel Rule Working Group and the Joint Working Group on inter-VASP messaging standards (JWGVAMS) have produced technical standards — most notably the IVMS101 data standard — to enable machine-readable transmission. Using IVMS101 does not solve the legal sunrise problem; it solves the data-format problem. A VASP that transmits IVMS101-formatted data to a counterparty that ignores it has not satisfied its compliance obligation, even though its technology worked.
Practically, this means compliance teams cannot treat "we send the data" as equivalent to "we comply." You need to document counterparty due diligence: does the receiving VASP have the regulatory obligation and the technical infrastructure to receive, hold, and report the data? If not, the transaction may need to be paused, the counterparty relationship reviewed, or the transfer declined.
Unhosted Wallets: The Open Question
Transfers to or from unhosted (self-custodied) wallets present a structural compliance challenge that no jurisdiction has fully resolved as of 2026-09-21. There is no counterparty VASP to receive originator data. The EU's Transfer of Funds Regulation requires CASPs to collect beneficiary or originator information for transfers involving unhosted wallets and to apply enhanced due diligence for transfers above EUR 1,000. FinCEN's 2020 proposed rule targeted the same gap; its final form remains uncertain.
For compliance teams and their legal counsel, the practical answer right now is:
- Map every unhosted-wallet transfer above your jurisdiction's reporting threshold.
- Document the CDD steps taken to identify the wallet's beneficial owner, even if the data cannot be "transmitted" in the traditional sense.
- Build escalation procedures for transfers where ownership cannot be verified — your policy should specify whether the transfer is declined, delayed, or filed with an STR/SAR.
What Enforcement Has Actually Looked Like
FinCEN's civil money penalty against Bittrex, Inc. — announced in October 2022 — included failures related to BSA obligations, not the Travel Rule specifically. The case nonetheless illustrates FinCEN's willingness to pursue mid-size exchanges, not only global platforms, for systemic compliance failures. The NYDFS has used its BitLicense regime under 23 N.Y.C.R.R. Part 200 to impose conditions on licensees related to transaction monitoring and sanctions screening, which intersect with Travel Rule infrastructure requirements.
In the EU, national competent authorities under MiCA have begun examining CASP Travel Rule compliance as part of initial licensing reviews, meaning firms seeking a MiCA license in 2025 and 2026 faced Travel Rule readiness as a threshold question, not an afterthought.
Building a Defensible Compliance Program
Legal counsel advising VASPs or CASPs should push their clients toward a compliance architecture that addresses three distinct layers:
1. Counterparty due diligence. Before onboarding a VASP relationship, verify the counterparty's regulatory status, jurisdiction, IVMS101 capability, and published Travel Rule policy. Document this in your vendor management file.
2. Transaction-level data collection. Your onboarding flow must collect the data the Travel Rule requires before a transfer is initiated — not after a flag is raised. Retrofitting KYC into a live transfer is not compliant.
3. Recordkeeping and retrieval. Both FinCEN's rules under 31 C.F.R. Part 1010 and the EU's Transfer of Funds Regulation require that Travel Rule data be retrievable and producible to competent authorities. Test your retrieval capability periodically and document the test.
For firms operating across jurisdictions — holding a BitLicense and a MiCA registration simultaneously, for example — the applicable rules may impose different thresholds, different data fields, and different retention periods. A single global policy will almost certainly under-serve one jurisdiction. Jurisdiction-specific annexes are the practical answer.
If your practice or compliance function extends into the anti-money laundering dimensions of crypto transfers, the intersection with smart contracts and DeFi raises a separate but related set of questions — the Risky Business: Cryptocurrency, Money Laundering, and Smart Contracts course covers how AML obligations apply where there is no obvious VASP intermediary to bear the compliance burden.
When the Rule Hits Litigation
Travel Rule failures surface in litigation in two ways: as part of a government enforcement action, and as evidence in private disputes about whether a transfer was processed in accordance with applicable law. In the latter context, counsel should understand that a VASP's own Travel Rule policy — if it promises a compliance standard the firm did not actually meet — can become a breach of contract or negligence exhibit. Draft those policies carefully, and audit against them.
Go deeper — courses on this
Blockchain LawPremiumRisky Business: Cryptocurrency, Money Laundering, and Smart Contracts
This two-part course covers how cryptocurrency is used for money laundering, including its three stages…
FreeBlockchain LawOn the Money: Central Bank Digital Currency Explained
This seminar introduces central bank digital currencies (CBDCs) to a broad professional audience…
Daniel B. Garrie · 1h 4m
Cyber IncidentsCounsel's How To: Advising the Board on Cyber Incident Response Planning
Panelists explain the board's role in cybersecurity oversight and what that looks like in practice…
Daniel B. Garrie
Keep reading
- DeFi Protocols Under the Bank Secrecy Act: The Compliance ReckoningFinCEN's 2023 proposed rulemaking on convertible virtual currency mixing signals that DeFi protocols face real BSA obligations. Here is what…
- GDPR Fines for AI Training Data: The Enforcement Gap Closing FastEuropean regulators are targeting how companies collect and use personal data to train AI models. Here is what that means for your complianc…
- Q&A: Cybersecurity ComplianceQ1: Why is cybersecurity compliance so important for law firms? A1: Law firms handle highly sensitive information, including personal data,…
Get the next one by email
Plain-English analysis of the law-and-technology developments that change how you advise. No more than monthly, and you can leave whenever you like.