Crypto Travel Rule

    Crypto Travel Rule compliance for VASPs and CASPs.

    Ship originator and beneficiary data with every virtual-asset transfer without breaking your withdrawal UX. ComplianceSuite normalises IVMS 101 across TRP, TRISA, Sygna Bridge, Notabene and OpenVASP, keeps a live directory of 2,500+ counterparty VASPs, verifies unhosted wallets, and screens every address against sanctions and blockchain analytics — aligned to EU MiCA/TFR (Reg. 2023/1113), FATF R.16, FinCEN, UK MLR, MAS PSN02 and JFSA.

    • IVMS 101 over every major protocol
    • 2,500+ VASP directory
    • Unhosted-wallet verification (Satoshi Test, AOPP)
    • Sanctions + blockchain-analytics inline

    Definition

    What is the Crypto Travel Rule?

    The Crypto Travel Rule extends the traditional wire-transfer travel rule to virtual-asset transfers between VASPs. Under FATF Recommendation 16 (extended to VAs in 2019, re-affirmed 2024), the originator VASP must transmit — and the beneficiary VASP must obtain — specified originator and beneficiary information alongside any virtual-asset transfer above the applicable threshold.

    In the EU, Regulation 2023/1113 (TFR), in force from 30 December 2024, sets the threshold at €0 — every crypto-asset transfer between CASPs is in scope. For transfers ≥€1,000 to unhosted wallets, the TFR additionally requires the CASP to verify that the destination wallet is controlled by its own customer.

    Related: Crypto compliance, sanctions screening, transaction monitoring and the AML glossary.

    Capabilities

    What's included.

    IVMS 101 across every protocol

    TRP, TRISA, Sygna Bridge, Notabene, VerifyVASP, OpenVASP — one API, one canonical schema, full interoperability.

    Counterparty VASP directory

    Real-time directory of 2,500+ VASPs with regulatory status, licence, jurisdiction and travel-rule support. Auto-route to their preferred protocol.

    Unhosted-wallet verification

    Satoshi Test, AOPP, in-app signature. Captures verification evidence for the EU TFR ≥€1,000 threshold.

    Sanctions on wallet addresses

    OFAC SDN wallet-address list, EU/UN, UK OFSI, plus commercial blockchain-analytics risk score. Block or hold in real time.

    Jurisdiction-specific rules

    Per-jurisdiction thresholds, data requirements, exemptions — configurable per CASP/VASP legal entity in a multi-jurisdiction group.

    Full case & audit trail

    Every travel-rule message, screening decision, verification evidence and counterparty exchange logged, immutable, exportable.

    How it works

    Four steps to a compliant transfer.

    1. Collect at initiation

    Customer initiates a crypto withdrawal → ComplianceSuite prompts for beneficiary VASP, wallet address, and — where required — beneficiary name. Originator data pulled from KYC file.

    2. Route via counterparty protocol

    Look up beneficiary VASP in the directory → route the IVMS 101 payload over their supported protocol (TRP, TRISA, Sygna, Notabene). Unknown/unregulated → enhanced review.

    3. Screen & verify

    Wallet address checked against sanctions lists and blockchain-analytics risk score. For unhosted wallets ≥€1,000 → address-ownership verification (Satoshi Test / AOPP).

    4. Execute, log, monitor

    Transfer released on clean decision. Full message exchange, screening result, verification evidence logged immutably. Post-transaction feeds monitoring for structuring and unhosted-wallet aggregation.

    Example transfers

    Three transfer scenarios, three compliant outcomes.

    TypeScenarioAction
    Hosted-to-hosted (EU)€5,000 BTC transfer from an EU CASP to Coinbase IrelandIVMS 101 payload sent over TRP; Coinbase acknowledges within seconds. Sanctions clean. Transfer released. Total added latency: <2s.
    Hosted-to-unhosted (EU)€8,000 ETH transfer from an EU CASP to a customer's self-hosted MetaMask walletTFR requires address-ownership verification. Customer signs a challenge in MetaMask; signature verified against the destination address. Verification stored in case file. Transfer released.
    Cross-border to unregulated VASP$12,000 USDT to a small offshore exchange not listed in the VASP directoryCounterparty flagged as unregulated. Case escalated to L2 compliance. Enhanced beneficiary information requested. If unresolved within 24h, transfer rejected with customer notification.

    Regulatory coverage

    Travel-rule regimes ComplianceSuite ships with.

    RegimeScopeRequirement
    EU MiCA + TFR (Reg. 2023/1113)EU 27Crypto-asset transfers between CASPs in scope from €0. Originator + beneficiary data mandatory; unhosted-wallet verification for transfers ≥€1,000; applies from 30 Dec 2024.
    FATF Recommendation 16 (VA)Global standardVASPs must obtain, hold and transmit originator/beneficiary information for VA transfers above USD/EUR 1,000. Applies to intermediary and beneficiary VASPs.
    US FinCEN 31 CFR 1010.410(f)United StatesWire-transfer travel rule applied to VASPs. FinCEN 2023 clarification: convertible virtual currency transfers ≥$3,000 must include specified originator/beneficiary information.
    UK MLR 2017 (amended Sep 2023)United KingdomCrypto-asset transfers ≥£1,000 (or all cross-border transfers) require originator and beneficiary information; UK-to-UK simplified for hosted-to-hosted.
    MAS PSN02 §6SingaporeDPT service providers must comply with wire-transfer information requirements for digital-payment-token transfers regardless of value.
    JFSA Guidelines (FIEA/PSA)JapanCrypto-Asset Exchange Service Providers must comply with the FATF Travel Rule from 1 June 2023 for transfers ≥¥100,000.

    Frequently asked questions.

    What is the Crypto Travel Rule?

    The Crypto Travel Rule (FATF Recommendation 16, extended to virtual assets in 2019 and re-affirmed in 2024) requires Virtual Asset Service Providers (VASPs) to exchange originator and beneficiary information alongside virtual-asset transfers above a defined threshold — typically USD/EUR 1,000. It mirrors the wire-transfer travel rule (US 31 CFR 1010.410(f), EU Regulation 2015/847 / TFR).

    Which transfers are in scope?

    Virtual-asset transfers between VASPs (exchanges, custodians, brokers, hosted-wallet providers) above the de minimis threshold set by each jurisdiction. The EU MiCA / TFR (Reg. 2023/1113) sets the threshold at €0 — every crypto-asset transfer between CASPs is in scope, regardless of value.

    What data must travel with a transfer?

    Originator: name, account/wallet identifier, address (or ID number / customer ID / DOB + birthplace). Beneficiary: name and account/wallet identifier. For self-hosted (unhosted) wallets ≥€1,000, the EU TFR additionally requires the CASP to verify that the wallet is controlled by its customer.

    What protocols do you support?

    IVMS 101 data model over TRP (Travel Rule Protocol), TRISA, Sygna Bridge, Notabene, VerifyVASP and OpenVASP. ComplianceSuite normalises across protocols so you interoperate with any counterparty VASP regardless of their stack.

    How do you handle unhosted (self-hosted) wallets?

    Address-ownership verification via Satoshi Test (micro-transaction signing), AOPP where supported, or in-app signature. For transfers ≥€1,000 to unhosted wallets, the EU TFR requires enhanced measures — ComplianceSuite captures the verification evidence in the case file.

    What if the counterparty VASP is not on a travel-rule protocol?

    The originator VASP must still collect and hold the required data, and — under EU TFR Art. 16 — apply enhanced scrutiny before executing the transfer, potentially rejecting the transfer to non-compliant counterparties. ComplianceSuite scores counterparty VASPs by regulatory status and travel-rule support.

    Which jurisdictions have adopted the Travel Rule?

    As of 2025: EU (MiCA + TFR Reg. 2023/1113), US (FinCEN — clarified Aug 2023), UK (MLR 2017 amended Sep 2023), Singapore (MAS PSN02), Japan (JFSA), Hong Kong (SFC), South Korea (KoFIU), Switzerland (FINMA), UAE (VARA + SCA), Canada (FINTRAC). ComplianceSuite ships jurisdiction packs for each.

    How does this integrate with sanctions and blockchain analytics?

    Every travel-rule message is auto-screened against sanctions (OFAC SDN wallet-address list, EU/UN, UK OFSI) and enriched with blockchain-analytics risk score (Chainalysis, TRM Labs, Elliptic integrations). One case, one decision — no separate tools.

    Test the Travel Rule on your own withdrawal flow.

    We'll wire up TRP/TRISA/Notabene against a sandbox counterparty, run an unhosted-wallet verification, and show the full case file in one session.