The Travel Rule for crypto businesses: thresholds, data and jurisdictions

The crypto Travel Rule applies to transfers of any size in most major regimes, and the EUR 1,000 figure almost every guide leads with governs a different obligation entirely.
- Four regulators, one structure. The United Kingdom, the European Union, Singapore and Switzerland each set the core obligation without a transfer-value gate. I checked each against the regulator's own binding text rather than against a secondary summary, and they agree.
- United Kingdom. Under regulations 64A to 64H of the Money Laundering Regulations 2017, the value figure is a customer-due-diligence trigger and not the Travel Rule threshold. It was the EUR 1,000 equivalent and became a flat £800 on 30 June 2026 under SI 2026/621. The transfer-information duty itself started on 1 September 2023.
- European Union. Regulation (EU) 2023/1113 Article 14 requires full originator and beneficiary information with no de minimis, and recital 27 grants no exemption for domestic low-value crypto-asset transfers.
- Singapore. MAS Notice PSN02 paragraph 13.4 requires the originator's and beneficiary's names plus an account number or reference on transfers at or below S$1,500.
- Switzerland. FINMA Guidance 02/2019 gives “no relief from anti-money laundering rules is provided compared to traditional payment transactions”, and requires firms to verify that clients own the wallets they use.
- The Philippines is the exception that proves the rule. BSP Circular No. 1108 sets a real PHP 50,000 gate. A genuine value gate is now the minority position, not the norm.
- The $3,000 you have read about is a wire threshold under 31 CFR 1010.410(f), and the $10,000 Currency Transaction Report is a separate cash-reporting filing. Neither is the crypto Travel Rule.
This article is general information about other businesses' regulatory obligations. It is not financial or legal advice.
What is the crypto Travel Rule?
The standard originates with the Financial Action Task Force, the intergovernmental body that sets anti-money-laundering and counter-terrorist-financing standards. FATF Recommendation 16 had applied to wire transfers for years. In June 2019 FATF extended it to virtual assets and virtual-asset service providers. That is the moment the obligation reached crypto businesses.
FATF recommendations are not law in themselves. Everything difficult about this topic follows from that. They bind a business only once a jurisdiction writes them into its own rules, and jurisdictions have done that at different times, in different instruments, with different scopes. The Financial Conduct Authority puts the duty in three verbs for UK firms: collect, verify and share. Which transfers those verbs attach to is a question you answer per market, not once.
Which businesses does the Travel Rule apply to?
The same business has a different legal name in every rulebook. The name tells you which rulebook to read:
- VASP, virtual-asset service provider, in FATF's standards.
- CASP, crypto-asset service provider, in Regulation (EU) 2023/1113.
- Cryptoasset exchange provider and custodian wallet provider, both defined terms in the Money Laundering Regulations 2017 in the UK.
- Money services business in United States practice under the Bank Secrecy Act.
- Digital payment token service provider in Singapore, under the Payment Services Act.
One animal, five names. The obligation then splits by the role you play in a given transfer. The ordering institution sends the customer information. The beneficiary institution receives it and checks whether anything required is missing. An intermediary that sits between the two passes it along. A single business is routinely all three across different transfers on the same day. So build the controls per role, not per company.
Which jurisdictions apply the Travel Rule, and at what threshold?
I went looking for this table and could not find it anywhere, so I built it: nine regimes compared across what the threshold figure actually gates, in one table. That distinction is the one almost every published explainer collapses into a single number.
The method matters more than the rows here. Every cell is sourced to a regulator's own instrument or a statute, checked against that instrument on 5 August 2026. And where I could not reach a primary source, the jurisdiction is named below the table with nothing filled in, rather than filled from someone else's summary. This table is sourced, not exhaustive.
| Jurisdiction | What the figure actually gates | Self-hosted wallets | Regulator | Instrument | In force |
|---|---|---|---|---|---|
| FATF (global baseline) | USD/EUR 1,000 recommended as a de minimis: below it a reduced data set still travels | National discretion | FATF | Recommendation 16, extended to virtual assets | June 2019 |
| European Union | Nothing. No de minimis on the core obligation. EUR 1,000 triggers a separate self-hosted ownership assessment | Assess ownership above EUR 1,000 (Art 14(5), 16(2)) | European Commission, EBA | Regulation (EU) 2023/1113, Art 14, recital 27 | From the date of application of Regulation (EU) 2023/1114 (recital 64) |
| United Kingdom | Customer due diligence. £800 (originally the EUR 1,000 equivalent, replaced from 30 June 2026) triggers CDD, not the Travel Rule | “Unhosted wallet transfer” is a defined in-scope transfer type | FCA | MLRs 2017 regs 64A to 64H, inserted by SI 2022/860; threshold substituted by SI 2026/621 | 1 September 2023 |
| United States | A wire threshold. USD 3,000 applies to transmittals of funds under the Bank Secrecy Act; there is no separate crypto Travel Rule statute | Not separately specified | FinCEN | 31 CFR 1010.410(f) | BSA funds rule, pre-dates virtual assets |
| Singapore | The size of the data set. S$1,500 changes how much information is required, not whether the rule applies | Verification required | MAS | Notice PSN02, para 13.4 | Notice dated 2 April 2024, last revised 30 June 2025 |
| Switzerland | Nothing. No Travel Rule threshold appears in FINMA's own material | Wallet-ownership verification required | FINMA | Guidance 02/2019, under the Anti-Money Laundering Act | 2019 |
| Philippines | The rule itself. PHP 50,000 or more is a genuine value gate | Not separately specified | BSP | Circular No. 1108 | 2021 |
| Australia | Nothing. No minimum threshold | Per AUSTRAC guidance | AUSTRAC | AML/CTF travel-rule obligations for virtual-asset transfers, under the AML/CTF Act 2006 | 1 July 2026 |
| Hong Kong | Not the core obligation. No value gate on whether the duty applies | Verification required | SFC | AMLO (Cap. 615) and the SFC AML/CFT Guideline | 1 June 2023 |
Every row cites the regulator's own instrument or the statute, checked 5 August 2026. Regimes in this area commence every quarter, so confirm a row against its own regulator before relying on it.
What this table does not claim. Five jurisdictions are deliberately left unfilled, each for its own reason, so you can audit the gap rather than trust it. Canada: FINTRAC's virtual-currency transfer guidance page did not resolve when I fetched it. No Canadian threshold is published here. Brazil: a phased framework is widely reported under a 2025 Banco Central resolution, but I could not retrieve the resolution itself, so no dates are published. Nigeria: an obligation is reported under the 2022 money-laundering act and securities-commission rules, again without a retrievable primary. Vietnam: no obligation was identified in any source, and absence of evidence is not a published finding. Nothing is asserted. Taiwan: news outlets reported a domestic-transfer rule and a figure in the days before this was written, on news authority only, and a news report is not an instrument.
Read this alongside the markets and methods we cover, because the two answer different halves of the same question: which rules attach to a transfer, and where the transfer can actually land.
Is there a single Travel Rule threshold?
A de minimis is not an on/off switch. FATF recommends USD/EUR 1,000 as a de minimis for virtual-asset transfers. Below it, a reduced data set still travels: the names of the originator and beneficiary and an account number or wallet address, which need not be verified unless something is suspicious. The common reading is that below the threshold nothing happens. Nothing happening is not one of the options.
Most major regimes set no threshold on the core obligation. The EU, the UK, Singapore, Hong Kong, Switzerland and Australia apply it to transfers of any size. Across the most comprehensive published jurisdiction survey I could find, the 76-jurisdiction table maintained by the compliance-software vendor Sumsub, the phrase “no transaction threshold” or its “no threshold” variant appears 59 times against 8 instances of a USD 1,000 (or equivalent) threshold. I counted that myself over that survey's 76 rows on 5 August 2026. It is a count of one published survey rather than a regulator's figure, and I am reporting it as such. The direction is not ambiguous.
The numbers readers have seen usually govern something else. This one is better proved from the instruments than asserted:
- In the UK, the Money Laundering Regulations 2017 require a firm to apply customer due diligence measures where the transfer is equal to or exceeds the equivalent in cryptoassets of £800 in value (a figure originally set at the EUR 1,000 equivalent and substituted with the flat £800 figure from 30 June 2026 by the Money Laundering and Terrorist Financing (Amendment) Regulations 2026, SI 2026/621). That is a due-diligence trigger sitting next to the transfer-information duty, not the trigger for it.
- Singapore's MAS Notice PSN02 paragraph 13.4 requires the originator's name and account or reference and the beneficiary's name and account or reference on a value transfer at or below S$1,500. A requirement that applies below a figure cannot be gated by it. The notice sits in MAS's own notice register alongside the guidelines issued with it.
- In Switzerland, FINMA Guidance 02/2019 applies the existing information-transmission provisions to blockchain payments technology-neutrally, with no relief compared with traditional payment transactions.
- The EU's EUR 1,000 figure in Regulation (EU) 2023/1113 sits in Article 14(5) and Article 16(2), where it triggers an assessment of whether a self-hosted address is owned or controlled by the customer. The core information duty in Article 14 has no threshold at all.
What this means
How does the crypto Travel Rule differ from the $3,000 wire rule and the $10,000 CTR?
| Obligation | Trigger | What it actually is |
|---|---|---|
| BSA funds Travel Rule | Transmittals of funds of USD 3,000 or more | A recordkeeping and information-transmittal duty on financial institutions, under 31 CFR 1010.410(f) |
| Crypto Travel Rule | Virtual-asset transfers; the threshold varies by jurisdiction and is often zero | The FATF-derived duty on virtual-asset businesses to send, receive and keep customer information |
| Currency Transaction Report | Cash transactions above USD 10,000 by one customer in a single day | A report filed with FinCEN, not a data-sharing duty at all |
A given transaction can trigger both, either or neither. The failure mode I see most often is a programme calibrated to the $10,000 CTR figure, on the assumption that it is the number that matters. That leaves the transfer-information duty unscoped at every value below it.
To be straight about the United States: there is no separate US crypto Travel Rule statute. The Bank Secrecy Act obligation reaches businesses dealing in convertible virtual currency, and the FinCEN advisory that established the funds travel rule long pre-dates them. That is why the US row in the table above records a wire threshold and not a crypto one.
What information has to travel with a transfer?
Drawn from FATF Recommendation 16 and, for the UK field list, Part 7A of the MLRs:
Originator
- Full name
- Account number, or a unique transaction reference where no account exists
- One of: physical address, national identity number, or customer identification number (with date and place of birth where the jurisdiction requires it)
- The originating wallet address, for virtual-asset transfers
Beneficiary
- Full name
- Account number or equivalent reference
- The beneficiary wallet address
So what format does all of that travel in? No statute says. IVMS101 is the interVASP messaging data model that has become the de facto industry standard, and effectively every Travel Rule messaging protocol either uses it or has committed to supporting it. No regulator mandates it. If you are choosing a protocol, its IVMS101 support is the interoperability question, not a compliance one.
Jurisdictions also differ on how much is required for domestic transfers versus cross-border ones. The field list is a floor set by your own regulator, not a global constant. The UK sector guidance in JMLSG Annex 22-I is the most detailed working example I know of.
What do you do when the other side's country has no Travel Rule?
The FCA has published its expectations as a procedure, and it works as one regardless of where you are supervised:
- Before sending to a jurisdiction without the rule, take all reasonable steps to establish whether the receiving firm can accept the required information.
- If it cannot, still collect and verify the information, and store it before making the transfer.
- On the receive side, when a transfer arrives with missing or incomplete information, make a risk-based assessment, considering the countries you operate in and the status of the rule there, before making the assets available to the beneficiary.
- Regularly review the implementation status of the rule in other jurisdictions and adapt your processes.
The same statement records the root cause, citing FATF: in June 2023 FATF highlighted the challenges arising from delays in adoption and different timelines for enforcement of the Travel Rule across jurisdictions. Read that as a standing condition rather than a transitional one. No deadline fixes it, because there is no single deadline to hit.
Then the sentence with the largest commercial consequence here, in the FCA's own words: firms “remain responsible for achieving compliance with the Travel Rule, even when using third-party suppliers.” Buying a vendor moves the work. It does not move the liability.
How are transfers to self-custody wallets treated?
FATF leaves national regulators significant discretion here, and they have used it differently. Three patterns run through the instruments:
- Verification on all such transfers. Singapore, Hong Kong and Switzerland, where FINMA requires firms to verify their clients' ownership of the wallets used.
- An assessment above a value. The EU, where Article 14(5) and Article 16(2) require the provider to assess whether an address above EUR 1,000 is owned or controlled by its customer.
- A defined in-scope transfer type with no separate value test. That is the UK: “unhosted wallet transfer” is a defined term, and regulation 64A brings such transfers into scope.
The operational point is easy to miss. There is no institution on the far side to receive a message, so the duty stops being about message-passing and becomes about proving your own customer controls the destination address. That is a different technical problem, solved with signed messages or micro-transfers rather than a Travel Rule protocol. And it is the one that catches teams out after they have already bought messaging software.
What does the Travel Rule change about your payouts, on-ramp and settlement?
Four changes, in the order they tend to bite:
- Batch payouts are assessed transfer by transfer.A single disbursement run is not one event for these purposes. One run can contain transfers that fall under different jurisdictions' rules, and a per-run control does not catch that.
- The off-ramp leg inherits the obligation. Moving crypto to a counterparty before fiat settlement is itself a transfer. Incomplete information on the receive side can hold those funds, which makes this a settlement-timing problem and not only a compliance one. That is the connection to crypto-to-fiat settlement that gets missed.
- Counterparty due diligence becomes a precondition, not a periodic review. You need to know whether the destination is a custodial business or a self-custody wallet before you send, because the answer changes what you owe. For high-risk OTC settlement flows, that check sits in the transaction path.
- Outsourcing the mechanics does not move the responsibility, in the FCA's own words above. Vendor selection is a controls decision.
For what it changes about month-end evidence and forecasting, the same held-transfer risk shows up in on-chain treasury operations.
Where Boldrails sits in this: we hold the necessary licences required in the markets we serve, and we settle crypto to fiat and disburse payouts directly rather than routing you to a third party, so the transfer-information workflow sits inside the settlement flow rather than bolted alongside it. What that buys you is a shorter answer to “why is this payout held”. Everything above about your own obligations stays your own; our crypto OTC desk does not absorb it, and no provider's can.
Talk to us about your settlement and payout flows, and where transfer-information requirements land in them.
What happens if a business does not comply?
- A direction to correct deficient policies, systems or records
- A required remediation programme
- Heightened supervisory scrutiny and reporting
- Administrative or financial penalties
- Restrictions on particular services or products
- Suspension, restriction or withdrawal of a licence or registration
- Civil or criminal consequences where national law provides for them, including liability for directors and senior management
The honest calibration, which the vendor pages tend to skip: criminal prosecutions specifically for Travel Rule breach remain rare, and enforcement so far has mostly been penalties, remediation orders and licence restrictions. That reflects how young the obligation is, since FATF only extended Recommendation 16 to virtual assets in 2019. It is not evidence of built-in leniency, and both the FCA and FinCEN publish their actions as they come.
The consequence operators actually feel first is none of the above. It is commercial. A business that cannot send or receive transfer information cleanly becomes an expensive counterparty, and counterparties and banks withdraw quietly and quickly. That is usually what closes a business, not the penalty, and it is why business banking for crypto companies and high-risk business bank accounts are harder to hold than to open.