Assumptions this note depends on
- The note describes the international standard and common implementation patterns. It is not a statement of the law in any jurisdiction and is not legal advice.
- Thresholds, formats and supervisory expectations differ by jurisdiction and change; check the rules that apply to you.
- Written from the operator’s perspective: what a compliance function has to build and evidence.
The obligation in one paragraph
When a regulated provider transfers virtual assets on behalf of a customer, originator and beneficiary information must travel with the transfer to the receiving provider, immediately and securely. The requirement is an extension to virtual assets of a rule that has applied to wire transfers for decades, which is why it is called the Travel Rule.
The operative words in practice are "immediately" and "to the receiving provider". The information cannot be reconstructed later on request, and it has to reach a counterparty rather than merely be retained.
What a programme has to be able to do
Implemented end to end, the obligation decomposes into five capabilities:
- Identify whether the counterparty is a regulated provider or an unhosted wallet.
- Discover how that provider can receive data, across incompatible messaging protocols.
- Transmit the required fields securely, in a schema the recipient can parse.
- Receive, validate and act on inbound information, including on mismatches.
- Evidence all of the above to an examiner, per transfer, after the fact.
The counterparty problem
Discovery is the part that surprises teams. Determining that a destination address belongs to a specific regulated provider is inference, not fact, and providers implement different messaging protocols that do not automatically interoperate. The result is a routing problem before any compliance question is reached.
Where the counterparty cannot receive the data, the programme needs a documented decision: send and record the failure, hold, or decline. Supervisors are generally less interested in which policy you chose than in whether it is written down, applied consistently and evidenced.
Unhosted wallets and the open questions
Transfers to and from wallets with no provider on the other side remain the least settled area. Approaches range from additional customer verification, to address-ownership proofs, to enhanced monitoring — and expectations differ materially by jurisdiction.
For a programme being built now, the defensible position is a documented risk-based approach: state what you do, why, on what evidence, and how you review it. An examiner can disagree with a reasoned policy. An unreasoned one is harder to defend.
Sources
- 01Recommendation 16 and its Interpretive NoteFinancial Action Task Force
- 02Updated Guidance for a Risk-Based Approach to Virtual Assets and VASPsFinancial Action Task Force
- 03Regulation (EU) 2023/1113 on information accompanying transfers of funds and certain crypto-assetsOfficial Journal of the European Union
Cited by title and publisher rather than by link, so a moved page cannot turn a citation into a dead end.
Educational disclaimer
Ledgerworks Institute provides educational content and learning tools only. Nothing on this platform constitutes financial advice, an investment recommendation, or a guarantee of any outcome. Cryptocurrency and digital-asset markets carry substantial risk, including the total loss of capital. Conduct your own research and consult a qualified, licensed professional before making any financial decision.
