Boldrails
Compliance · Crypto

The Travel Rule for crypto businesses: thresholds, data and jurisdictions

Claude IgrowAuthorClaude IgrowAugust 5, 202612 min read
An abstract arc of connected institutional nodes with data ribbons travelling between them, three nodes lit in gold, representing one transfer-information rule implemented unevenly across jurisdictions

The crypto Travel Rule applies to transfers of any size in most major regimes, and the EUR 1,000 figure almost every guide leads with governs a different obligation entirely.

Key takeaways
  • Four regulators, one structure. The United Kingdom, the European Union, Singapore and Switzerland each set the core obligation without a transfer-value gate. I checked each against the regulator's own binding text rather than against a secondary summary, and they agree.
  • United Kingdom. Under regulations 64A to 64H of the Money Laundering Regulations 2017, the value figure is a customer-due-diligence trigger and not the Travel Rule threshold. It was the EUR 1,000 equivalent and became a flat £800 on 30 June 2026 under SI 2026/621. The transfer-information duty itself started on 1 September 2023.
  • European Union. Regulation (EU) 2023/1113 Article 14 requires full originator and beneficiary information with no de minimis, and recital 27 grants no exemption for domestic low-value crypto-asset transfers.
  • Singapore. MAS Notice PSN02 paragraph 13.4 requires the originator's and beneficiary's names plus an account number or reference on transfers at or below S$1,500.
  • Switzerland. FINMA Guidance 02/2019 gives “no relief from anti-money laundering rules is provided compared to traditional payment transactions”, and requires firms to verify that clients own the wallets they use.
  • The Philippines is the exception that proves the rule. BSP Circular No. 1108 sets a real PHP 50,000 gate. A genuine value gate is now the minority position, not the norm.
  • The $3,000 you have read about is a wire threshold under 31 CFR 1010.410(f), and the $10,000 Currency Transaction Report is a separate cash-reporting filing. Neither is the crypto Travel Rule.

This article is general information about other businesses' regulatory obligations. It is not financial or legal advice.

4 of 4
Regulators with no transfer-value gate
The UK, the EU, Singapore and Switzerland each set the core obligation without one. Checked against each regulator's own binding text, 5 August 2026.
1 Sept 2023
UK transfer-information duty began
UK cryptoasset businesses had to collect, verify and share transfer information from that date, per the FCA.
No de minimis
EU threshold on the core duty
Regulation (EU) 2023/1113 Article 14, with recital 27 granting no exemption for domestic low-value crypto-asset transfers.
S$1,500
Singapore: data required at or below it
MAS Notice PSN02 paragraph 13.4 requires originator and beneficiary name plus account or reference on transfers at or below that level, so it sizes the data set rather than gating the rule.
PHP 50,000
A genuine value gate, and the minority position
BSP Circular No. 1108 sets a real Philippine threshold. Most major regimes set none at all.
USD 3,000
A wire threshold, not a crypto one
The Bank Secrecy Act funds rule under 31 CFR 1010.410(f) applies to transmittals of funds, and predates virtual assets entirely.

What is the crypto Travel Rule?

The crypto Travel Rule requires a business that transfers crypto-assets for a customer to collect and verify identifying information about the sender and the recipient, pass it to the business on the other side of the transfer, and keep a record of it. The name comes from the idea that the customer information travels alongside the value.

The standard originates with the Financial Action Task Force, the intergovernmental body that sets anti-money-laundering and counter-terrorist-financing standards. FATF Recommendation 16 had applied to wire transfers for years. In June 2019 FATF extended it to virtual assets and virtual-asset service providers. That is the moment the obligation reached crypto businesses.

FATF recommendations are not law in themselves. Everything difficult about this topic follows from that. They bind a business only once a jurisdiction writes them into its own rules, and jurisdictions have done that at different times, in different instruments, with different scopes. The Financial Conduct Authority puts the duty in three verbs for UK firms: collect, verify and share. Which transfers those verbs attach to is a question you answer per market, not once.

Which businesses does the Travel Rule apply to?

It binds businesses that hold or move crypto-assets on someone else's behalf. If a customer's assets pass through your control, you are in scope. If you are an individual moving your own crypto between wallets you control, you are not.

The same business has a different legal name in every rulebook. The name tells you which rulebook to read:

  • VASP, virtual-asset service provider, in FATF's standards.
  • CASP, crypto-asset service provider, in Regulation (EU) 2023/1113.
  • Cryptoasset exchange provider and custodian wallet provider, both defined terms in the Money Laundering Regulations 2017 in the UK.
  • Money services business in United States practice under the Bank Secrecy Act.
  • Digital payment token service provider in Singapore, under the Payment Services Act.

One animal, five names. The obligation then splits by the role you play in a given transfer. The ordering institution sends the customer information. The beneficiary institution receives it and checks whether anything required is missing. An intermediary that sits between the two passes it along. A single business is routinely all three across different transfers on the same day. So build the controls per role, not per company.

Which jurisdictions apply the Travel Rule, and at what threshold?

I went looking for this table and could not find it anywhere, so I built it: nine regimes compared across what the threshold figure actually gates, in one table. That distinction is the one almost every published explainer collapses into a single number.

The method matters more than the rows here. Every cell is sourced to a regulator's own instrument or a statute, checked against that instrument on 5 August 2026. And where I could not reach a primary source, the jurisdiction is named below the table with nothing filled in, rather than filled from someone else's summary. This table is sourced, not exhaustive.

Crypto Travel Rule regimes by jurisdiction, classified by what the threshold figure actually gates
JurisdictionWhat the figure actually gatesSelf-hosted walletsRegulatorInstrumentIn force
FATF (global baseline)USD/EUR 1,000 recommended as a de minimis: below it a reduced data set still travelsNational discretionFATFRecommendation 16, extended to virtual assetsJune 2019
European UnionNothing. No de minimis on the core obligation. EUR 1,000 triggers a separate self-hosted ownership assessmentAssess ownership above EUR 1,000 (Art 14(5), 16(2))European Commission, EBARegulation (EU) 2023/1113, Art 14, recital 27From the date of application of Regulation (EU) 2023/1114 (recital 64)
United KingdomCustomer due diligence. £800 (originally the EUR 1,000 equivalent, replaced from 30 June 2026) triggers CDD, not the Travel Rule“Unhosted wallet transfer” is a defined in-scope transfer typeFCAMLRs 2017 regs 64A to 64H, inserted by SI 2022/860; threshold substituted by SI 2026/6211 September 2023
United StatesA wire threshold. USD 3,000 applies to transmittals of funds under the Bank Secrecy Act; there is no separate crypto Travel Rule statuteNot separately specifiedFinCEN31 CFR 1010.410(f)BSA funds rule, pre-dates virtual assets
SingaporeThe size of the data set. S$1,500 changes how much information is required, not whether the rule appliesVerification requiredMASNotice PSN02, para 13.4Notice dated 2 April 2024, last revised 30 June 2025
SwitzerlandNothing. No Travel Rule threshold appears in FINMA's own materialWallet-ownership verification requiredFINMAGuidance 02/2019, under the Anti-Money Laundering Act2019
PhilippinesThe rule itself. PHP 50,000 or more is a genuine value gateNot separately specifiedBSPCircular No. 11082021
AustraliaNothing. No minimum thresholdPer AUSTRAC guidanceAUSTRACAML/CTF travel-rule obligations for virtual-asset transfers, under the AML/CTF Act 20061 July 2026
Hong KongNot the core obligation. No value gate on whether the duty appliesVerification requiredSFCAMLO (Cap. 615) and the SFC AML/CFT Guideline1 June 2023

Every row cites the regulator's own instrument or the statute, checked 5 August 2026. Regimes in this area commence every quarter, so confirm a row against its own regulator before relying on it.

Key Finding
In seven of the nine rows above, the number you were told about is not the thing that decides whether the rule bites.

What this table does not claim. Five jurisdictions are deliberately left unfilled, each for its own reason, so you can audit the gap rather than trust it. Canada: FINTRAC's virtual-currency transfer guidance page did not resolve when I fetched it. No Canadian threshold is published here. Brazil: a phased framework is widely reported under a 2025 Banco Central resolution, but I could not retrieve the resolution itself, so no dates are published. Nigeria: an obligation is reported under the 2022 money-laundering act and securities-commission rules, again without a retrievable primary. Vietnam: no obligation was identified in any source, and absence of evidence is not a published finding. Nothing is asserted. Taiwan: news outlets reported a domestic-transfer rule and a figure in the days before this was written, on news authority only, and a news report is not an instrument.

Read this alongside the markets and methods we cover, because the two answer different halves of the same question: which rules attach to a transfer, and where the transfer can actually land.

Is there a single Travel Rule threshold?

No, and the more useful answer is that most of the figures in circulation are not Travel Rule thresholds at all. There are three separate distinctions hiding behind one word, and getting them the wrong way round is how a compliance programme ends up under-scoped.

A de minimis is not an on/off switch. FATF recommends USD/EUR 1,000 as a de minimis for virtual-asset transfers. Below it, a reduced data set still travels: the names of the originator and beneficiary and an account number or wallet address, which need not be verified unless something is suspicious. The common reading is that below the threshold nothing happens. Nothing happening is not one of the options.

Most major regimes set no threshold on the core obligation. The EU, the UK, Singapore, Hong Kong, Switzerland and Australia apply it to transfers of any size. Across the most comprehensive published jurisdiction survey I could find, the 76-jurisdiction table maintained by the compliance-software vendor Sumsub, the phrase “no transaction threshold” or its “no threshold” variant appears 59 times against 8 instances of a USD 1,000 (or equivalent) threshold. I counted that myself over that survey's 76 rows on 5 August 2026. It is a count of one published survey rather than a regulator's figure, and I am reporting it as such. The direction is not ambiguous.

The numbers readers have seen usually govern something else. This one is better proved from the instruments than asserted:

  • In the UK, the Money Laundering Regulations 2017 require a firm to apply customer due diligence measures where the transfer is equal to or exceeds the equivalent in cryptoassets of £800 in value (a figure originally set at the EUR 1,000 equivalent and substituted with the flat £800 figure from 30 June 2026 by the Money Laundering and Terrorist Financing (Amendment) Regulations 2026, SI 2026/621). That is a due-diligence trigger sitting next to the transfer-information duty, not the trigger for it.
  • Singapore's MAS Notice PSN02 paragraph 13.4 requires the originator's name and account or reference and the beneficiary's name and account or reference on a value transfer at or below S$1,500. A requirement that applies below a figure cannot be gated by it. The notice sits in MAS's own notice register alongside the guidelines issued with it.
  • In Switzerland, FINMA Guidance 02/2019 applies the existing information-transmission provisions to blockchain payments technology-neutrally, with no relief compared with traditional payment transactions.
  • The EU's EUR 1,000 figure in Regulation (EU) 2023/1113 sits in Article 14(5) and Article 16(2), where it triggers an assessment of whether a self-hosted address is owned or controlled by the customer. The core information duty in Article 14 has no threshold at all.

What this means

The top-ranking explainers on this subject disagree with each other on Singapore and on Switzerland, and one of them publishes a Philippine threshold the BSP's own circular contradicts. I am not interested in scoring points off them. The consequence is what matters, and it is singular and expensive: a control set scoped to “we only need to do this above X” is under-scoped in all four of the jurisdictions above.

How does the crypto Travel Rule differ from the $3,000 wire rule and the $10,000 CTR?

Three different obligations get called the travel rule, and only one of them is about crypto. They come from the same statute in the United States, which is why they blur, and they have different triggers, different subjects and different mechanics.
The three obligations readers most often conflate
ObligationTriggerWhat it actually is
BSA funds Travel RuleTransmittals of funds of USD 3,000 or moreA recordkeeping and information-transmittal duty on financial institutions, under 31 CFR 1010.410(f)
Crypto Travel RuleVirtual-asset transfers; the threshold varies by jurisdiction and is often zeroThe FATF-derived duty on virtual-asset businesses to send, receive and keep customer information
Currency Transaction ReportCash transactions above USD 10,000 by one customer in a single dayA report filed with FinCEN, not a data-sharing duty at all

A given transaction can trigger both, either or neither. The failure mode I see most often is a programme calibrated to the $10,000 CTR figure, on the assumption that it is the number that matters. That leaves the transfer-information duty unscoped at every value below it.

To be straight about the United States: there is no separate US crypto Travel Rule statute. The Bank Secrecy Act obligation reaches businesses dealing in convertible virtual currency, and the FinCEN advisory that established the funds travel rule long pre-dates them. That is why the US row in the table above records a wire threshold and not a crypto one.

What information has to travel with a transfer?

Two paired sets of fields, one for each side of the transfer: the originator's identifying details and the beneficiary's, plus the wallet addresses on both ends for virtual-asset transfers.

Drawn from FATF Recommendation 16 and, for the UK field list, Part 7A of the MLRs:

Originator

  • Full name
  • Account number, or a unique transaction reference where no account exists
  • One of: physical address, national identity number, or customer identification number (with date and place of birth where the jurisdiction requires it)
  • The originating wallet address, for virtual-asset transfers

Beneficiary

  • Full name
  • Account number or equivalent reference
  • The beneficiary wallet address

So what format does all of that travel in? No statute says. IVMS101 is the interVASP messaging data model that has become the de facto industry standard, and effectively every Travel Rule messaging protocol either uses it or has committed to supporting it. No regulator mandates it. If you are choosing a protocol, its IVMS101 support is the interoperability question, not a compliance one.

Jurisdictions also differ on how much is required for domestic transfers versus cross-border ones. The field list is a floor set by your own regulator, not a global constant. The UK sector guidance in JMLSG Annex 22-I is the most detailed working example I know of.

What do you do when the other side's country has no Travel Rule?

This is the sunrise problem. The sun comes up at different times in different places, so a rule that needs both businesses to implement it will spend years with only one side ready. Four of the five best-ranking pages on this topic name the problem. None of them tells you what to do about it. A regulator does.

The FCA has published its expectations as a procedure, and it works as one regardless of where you are supervised:

  1. Before sending to a jurisdiction without the rule, take all reasonable steps to establish whether the receiving firm can accept the required information.
  2. If it cannot, still collect and verify the information, and store it before making the transfer.
  3. On the receive side, when a transfer arrives with missing or incomplete information, make a risk-based assessment, considering the countries you operate in and the status of the rule there, before making the assets available to the beneficiary.
  4. Regularly review the implementation status of the rule in other jurisdictions and adapt your processes.

The same statement records the root cause, citing FATF: in June 2023 FATF highlighted the challenges arising from delays in adoption and different timelines for enforcement of the Travel Rule across jurisdictions. Read that as a standing condition rather than a transitional one. No deadline fixes it, because there is no single deadline to hit.

Then the sentence with the largest commercial consequence here, in the FCA's own words: firms “remain responsible for achieving compliance with the Travel Rule, even when using third-party suppliers.” Buying a vendor moves the work. It does not move the liability.

How are transfers to self-custody wallets treated?

It depends on the jurisdiction, and this is where regimes diverge most. Two mirror-image misconceptions are both wrong: a transfer to a self-custody wallet is not automatically out of scope, and it is not automatically in scope either.

FATF leaves national regulators significant discretion here, and they have used it differently. Three patterns run through the instruments:

  • Verification on all such transfers. Singapore, Hong Kong and Switzerland, where FINMA requires firms to verify their clients' ownership of the wallets used.
  • An assessment above a value. The EU, where Article 14(5) and Article 16(2) require the provider to assess whether an address above EUR 1,000 is owned or controlled by its customer.
  • A defined in-scope transfer type with no separate value test. That is the UK: “unhosted wallet transfer” is a defined term, and regulation 64A brings such transfers into scope.

The operational point is easy to miss. There is no institution on the far side to receive a message, so the duty stops being about message-passing and becomes about proving your own customer controls the destination address. That is a different technical problem, solved with signed messages or micro-transfers rather than a Travel Rule protocol. And it is the one that catches teams out after they have already bought messaging software.

What does the Travel Rule change about your payouts, on-ramp and settlement?

Every explainer in this category stops at “here is the rule” and pivots to a product. The part nobody writes down is what the rule does to a live money flow.

Four changes, in the order they tend to bite:

  1. Batch payouts are assessed transfer by transfer.A single disbursement run is not one event for these purposes. One run can contain transfers that fall under different jurisdictions' rules, and a per-run control does not catch that.
  2. The off-ramp leg inherits the obligation. Moving crypto to a counterparty before fiat settlement is itself a transfer. Incomplete information on the receive side can hold those funds, which makes this a settlement-timing problem and not only a compliance one. That is the connection to crypto-to-fiat settlement that gets missed.
  3. Counterparty due diligence becomes a precondition, not a periodic review. You need to know whether the destination is a custodial business or a self-custody wallet before you send, because the answer changes what you owe. For high-risk OTC settlement flows, that check sits in the transaction path.
  4. Outsourcing the mechanics does not move the responsibility, in the FCA's own words above. Vendor selection is a controls decision.

For what it changes about month-end evidence and forecasting, the same held-transfer risk shows up in on-chain treasury operations.

Where Boldrails sits in this: we hold the necessary licences required in the markets we serve, and we settle crypto to fiat and disburse payouts directly rather than routing you to a third party, so the transfer-information workflow sits inside the settlement flow rather than bolted alongside it. What that buys you is a shorter answer to “why is this payout held”. Everything above about your own obligations stays your own; our crypto OTC desk does not absorb it, and no provider's can.

Talk to us about your settlement and payout flows, and where transfer-information requirements land in them.

What happens if a business does not comply?

Consequences escalate, and they start long before a fine. Supervisors have a ladder, and in most regimes it runs in roughly the order below.
  • A direction to correct deficient policies, systems or records
  • A required remediation programme
  • Heightened supervisory scrutiny and reporting
  • Administrative or financial penalties
  • Restrictions on particular services or products
  • Suspension, restriction or withdrawal of a licence or registration
  • Civil or criminal consequences where national law provides for them, including liability for directors and senior management

The honest calibration, which the vendor pages tend to skip: criminal prosecutions specifically for Travel Rule breach remain rare, and enforcement so far has mostly been penalties, remediation orders and licence restrictions. That reflects how young the obligation is, since FATF only extended Recommendation 16 to virtual assets in 2019. It is not evidence of built-in leniency, and both the FCA and FinCEN publish their actions as they come.

The consequence operators actually feel first is none of the above. It is commercial. A business that cannot send or receive transfer information cleanly becomes an expensive counterparty, and counterparties and banks withdraw quietly and quickly. That is usually what closes a business, not the penalty, and it is why business banking for crypto companies and high-risk business bank accounts are harder to hold than to open.

Frequently asked questions

FATF recommends USD/EUR 1,000 as a de minimis rather than an on/off switch: below it a reduced, unverified data set still travels. Many major regimes, including the EU, the UK, Singapore, Hong Kong, Switzerland and Australia, set no threshold at all on the core obligation. Check your own jurisdiction in the table above rather than relying on a global figure.