The Travel Rule: Origins, Requirements, and Implementation Challenges for VASPs

By Safeheron Team
|
The Travel Rule: Origins, Requirements, and Implementation Challenges for VASPs

Key Takeaways

For institutions, the Travel Rule is a hard gate on licence applications, banking relationships, and exchange integrations. It also sits directly on top of sanctions screening — the single area carrying the highest risk of regulatory penalty.

Implementation, however, is anything but simple. The sunrise issue, counterparty identification and due diligence, data protection, the tension between sanctions screening and data accuracy, divergent cross-border requirements, and protocol interoperability are all live problems.

This article traces the Travel Rule from its origins to its present form, and closes with a practical compliance checklist for VASPs.


As licensing regimes come into force across jurisdictions, Travel Rule compliance has in all likelihood made its way onto the to-do list of most virtual asset service providers (VASPs). It may arrive as a precondition for a licence application, as a checkpoint in a banking partner’s due diligence, or as an overseas exchange suddenly asking you to send a data message before a transfer can go through.

With that in mind, the Safeheron compliance team has put together a systematic overview of the Travel Rule.

Note: this article is intended as general educational content and does not constitute legal advice.

Where the Travel Rule Came From

The Travel Rule did not originate in crypto. It was first issued in 1996 by the Financial Crimes Enforcement Network (FinCEN), a bureau of the U.S. Department of the Treasury, as a rule under the Bank Secrecy Act (BSA). The logic behind it is plain: when a funds transfer of USD 10,000 or more involves more than one financial institution, the first institution must pass certain information about that transfer along to the next. The information travels with the money — hence the name.

The information chain under the original (fiat) Travel Rule:

  • Originator (USD 10,000 and above) provides: name, address, transaction amount, date, payment instructions, beneficiary name, beneficiary address, beneficiary account number
  • Originating institution: collects the above information
  • Beneficiary institution: receives the transaction and the accompanying information
  • Beneficiary: receives the funds

In Advisory Issue 7, published in January 1997, FinCEN explained that “the funds transfer rules are designed to help law enforcement agencies detect, investigate and prosecute money laundering and other financial crimes by preserving an information trail about persons sending and receiving funds through funds transfer systems.” In other words, the Travel Rule is not, at its core, about restricting transactions; it is about ensuring that the movement of funds leaves behind a traceable record of identity.

FATF Brings the Travel Rule Into Digital Assets

In 2019, the Financial Action Task Force (FATF) updated and extended its Recommendations to cover virtual assets (VAs) and virtual asset service providers (VASPs).

FATF Recommendation 15 (R15)

The revision to R15 clarifies that the proliferation financing risk assessment and mitigation requirements apply to virtual asset activities and virtual asset service providers. Under R15, a VASP must:

  • Be licensed or registered
  • Be subject to anti-money laundering and counter-terrorist financing (AML/CTF) regulation
  • Be subject to effective monitoring or supervision

FATF Recommendation 16 (R16)

R16 sets out the obligation to obtain, hold, and submit the required originator and beneficiary information associated with virtual asset transfers, in order to:

  • Identify and report suspicious transactions
  • Take freezing actions
  • Prohibit transactions with designated persons and entities

What the Travel Rule Is Trying to Solve

From a regulator’s point of view, the Travel Rule serves several purposes: (1) preventing money laundering; (2) avoiding the inadvertent facilitation of sanctioned transactions; (3) countering terrorist financing; (4) improving transparency and trust; and (5) strengthening accountability.

For VASPs, Travel Rule compliance also moves crypto transactions from a world in which the counterparty is invisible to one in which the counterparty can be seen.

Before the Travel Rule, VASPs had almost no visibility into their transaction counterparties and could transact with suspicious parties without knowing it. Since then, VASPs have been able to run a risk assessment on every counterparty, and can transact safely with trusted counterparties with greater confidence.

The Travel Rule is not only a compliance burden. It is, more than that, the first counterparty identity infrastructure the industry has ever had — you can finally find out who actually operates the address on the other side of a transaction.

What a Compliant Travel Rule Transfer Looks Like

Suppose X holds an account at VASP 1 and wants to send ETH to Y’s account at VASP 2. Every step below has to be completed before the transaction is initiated.

Six steps for the originating VASP (VASP 1)

  1. Verify X’s information
  2. Collect Y’s name
  3. Run sanctions screening on Y
  4. Conduct due diligence on VASP 2
  5. Decide whether to accept or reject the transaction
  6. Transmit the information to VASP 2

Seven steps for the beneficiary VASP (VASP 2)

  1. Verify Y’s information
  2. Confirm ownership of the blockchain address used to receive the Travel Rule data transmission
  3. Confirm that the wallet address does in fact belong to Y
  4. Receive and review X’s information
  5. Run sanctions screening on X
  6. Conduct due diligence on VASP 1
  7. Decide whether to accept or reject the transaction

It is worth noting that this is a two-way process, not simply a matter of the originator sending data and the beneficiary receiving it. Both sides must complete customer verification, sanctions screening, and due diligence on the counterparty institution, and each retains the right to reject the transaction.

What Data Has to Be Transmitted

A Travel Rule data transmission typically needs to include:

  • The asset to be transferred (for example, ETH)
  • The amount of the asset to be transferred
Originator (sending customer)Beneficiary (receiving customer)
NameName
Account number or blockchain addressAccount number or blockchain address
Physical address; orIdentity document number (e.g., national ID number, passport number); orDate and place of birth

Note: specific field requirements vary by jurisdiction. The table above reflects the common minimum set under the FATF standard.

The Main Challenges in Implementing the Travel Rule

1. The Sunrise Issue

Because countries are legislating the Travel Rule at different speeds, the industry has settled on a vivid metaphor: the Travel Rule is like the sun, rising at different times in different parts of the world. Some jurisdictions have completed legislation and begun enforcement, some are still drafting, and some have done nothing at all. That leaves VASPs at very uneven stages of compliance, and it creates a series of practical problems for those already compliant.

This transitional period of unsynchronised global implementation is known as the sunrise period, and the difficulties it produces are known as the sunrise issue. In practice, they take three main forms:

Being unable to meet the obligation to send

When the beneficiary VASP is not subject to the Travel Rule and cannot be reached, the originating VASP has no way to fulfil its obligation to transmit information.

Being unable to meet the obligation to receive information alongside a deposit

When the originating VASP is not subject to the Travel Rule and does not send the required information with the funds, the beneficiary VASP has no option but to return them — with a direct cost to user experience and transaction volume.

Being unable to conduct effective sanctions screening and risk management on counterparty customers

An uncooperative VASP means counterparty information that cannot be verified. If a non-compliant VASP does not respond, or the Travel Rule message is missing, the compliant VASP lacks the information it needs to confirm the identity of the counterparty’s end customer. That severely undermines the effectiveness of the sanctions screening process — and sanctions screening is precisely where the risk of regulatory penalty is highest.

FATF’s position on the sunrise period

Phase one: mitigation measures for the transition

“Regardless of the regulation in a certain country, a VASP may implement robust control measures to comply with the travel rule requirements. Examples include VASPs restricting VA transfers to within their customer base (i.e., internal transfers of VAs within the same VASP), only allowing confirmed first-party transfers outside of their customer base (i.e., the originator and the beneficiary are confirmed to be the same person) and enhanced monitoring of transactions.” (FATF, Updated Guidance, 2021, p. 64, para. 201)

Phase two: pushing for full and rapid implementation

“Until all VASPs are required to implement the Travel Rule, VASPs operating in or from jurisdictions with Travel Rule obligations will continue to face challenges executing all covered transactions in a compliant manner.” (FATF, Virtual Assets: Targeted Update on Implementation of the FATF Standards on VAs and VASPs, June 2023, para. 20)

2. Identifying and Conducting Due Diligence on Counterparty VASPs

Accurately identifying the entity that controls the counterparty wallet determines which set of requirements applies. The distinctions that have to be drawn include:

  •  Whether the wallet is hosted by another VASP or financial institution, or is self-custodied
  • Whether a self-custodied wallet is controlled by an individual or by a service or entity — gaming platforms, e-commerce sites, mining pools, liquidity pools, faucet sites, smart contracts, and so on
  • Whether the counterparty sits in the same jurisdiction or in a third country

3. Data Protection Considerations

The Travel Rule requires the transmission of personally identifiable information, which creates an inherent tension with data protection laws such as the GDPR. FATF allows some room here: where a VASP has reasonable grounds to believe that a counterparty VASP will not handle user information securely, alternative procedures should be available to it, including the possibility of not sending that information; equally, where the VASP considers the AML/CFT risk to be acceptable, it may still proceed with the transfer. (FATF, Updated Guidance, 2021, p. 85, para. 291)

4. Effective Sanctions Screening vs. Data Accuracy Requirements

Paragraph 182(d) of the FATF Updated Guidance (2021, p. 58) provides that the required information an ordering institution must obtain and hold includes the name of the beneficiary — that is, the person the originator identifies as the recipient of the virtual asset transfer. The ordering institution is not required to verify that name for accuracy, but it should review it for suspicious transaction report (STR) monitoring and sanctions screening purposes.

In other words, a VASP does not have to vouch for the authenticity of the beneficiary name, yet must use it to run sanctions screening. There is a subtle tension in this: counterparty data has to drive sanctions screening, while its accuracy need not be verified — and the effectiveness of sanctions screening depends precisely on that accuracy.

5. Divergent Requirements in Cross-Border Transactions

VASPs tend to design their processes around the requirements of their own jurisdiction, but the rules applying to the counterparty may be stricter, or simply different: different thresholds, different mandatory fields, different treatment of self-custodied wallets.

6. Protocols and Interoperability

Multiple Travel Rule transmission protocols and solutions exist in the market. If your counterparty is on a different system, the message never arrives. On this point FATF has addressed the private sector directly, calling on it to “improve the interoperability of their Travel Rule compliance tools globally, whether through technological advancements that allow interoperability between tools or by developing relationships that permit transactions to be made through a chain of interoperable tools.” (FATF, Virtual Assets: Targeted Update on Implementation of the FATF Standards on VAs and VASPs, June 2023, p. 5)

The practical implication is that when a VASP evaluates Travel Rule solutions, the question of how many counterparties a solution covers and whether it can interoperate with other protocols usually carries more weight than any single product’s feature list.

A Compliance Action Checklist for VASPs

  1. Determine your scope: map the jurisdictions where your entities are licensed or operating, and confirm the local Travel Rule’s effective date, threshold amount, and mandatory fields for each.
  2. Take stock of your data capability: confirm whether you can currently obtain and produce structured required information for both originator and beneficiary before a transaction is initiated.
  3. Design the pre-transaction workflow: embed customer information verification, sanctions screening of counterparty customers, counterparty VASP due diligence, and address ownership confirmation into the pre-transaction stage of both withdrawal and deposit flows.
  4. Solve counterparty identification: build an explainable, auditable method for determining whether a target address is a hosted or a self-custodied wallet, and define the handling path for each.
  5. Set a sunrise period policy: define clear rules for handling non-compliant or unresponsive counterparties (allow, restrict, or return), write them into your internal policies, and keep a record of the decisions made.
  6. Make interoperability your first selection criterion: assess the size of the counterparty network a solution covers and its ability to interoperate across protocols.
  7. Address data protection in parallel: complete a lawful basis assessment for transmitting personal information, and add the counterparty’s data security capability to your due diligence checklist.
  8. Roll out in phases: start with internal and first-party transfers, then expand gradually to full third-party transfers, calibrating user experience as you go.

The Safeheron compliance team will continue its research and publish professional compliance content. To discuss any of this further, please get in touch with Safeheron.

References

  • FinCEN, Advisory Issue 7, “Funds ‘Travel’ Regulations: Questions & Answers,” January 1997 (relating to 31 CFR 103.33(g), effective 28 May 1996)
  • FATF, “Updated Guidance for a Risk-Based Approach to Virtual Assets and Virtual Asset Service Providers,” October 2021 (pages cited: 17, 24, 27, 58, 62, 64, 85, 109)
  • FATF, “Virtual Assets: Targeted Update on Implementation of the FATF Standards on VAs and VASPs,” June 2023 (paragraphs cited: 16, 20; p. 5)
  • FATF, Recommendation 15 and Recommendation 16, and their Interpretive Notes
  • FATF virtual asset guidance series, June 2019 to June 2023
  • T. Adrian, D. He, A. Narain, “Global Crypto Regulation Should be Comprehensive, Consistent, and Coordinated,” IMF, 9 December 2021
  • U.S. Department of the Treasury, Office of Foreign Assets Control (OFAC) sanctions actions: Garantex (April 2022) and Tornado Cash (August 2022); FinCEN and U.S. Department of Justice actions against Bitzlato (January 2023)
Book a Demo
Leave your details and a Safeheron expert will get back to you shortly.
SHARE THIS ARTICLE
联系我们