TL;DR: Crypto Travel Rule compliance means a VASP must obtain, hold, and transmit originator and beneficiary information to the counterparty VASP before or at the time a virtual asset transfer settles. The rule comes from FATF Recommendation 16, extended to VASPs in June 2019, and in the United States from 31 CFR 1010.410(f), which FinCEN applies to convertible virtual currency at $3,000. According to the FATF's July 2026 targeted update, 83 percent of surveyed jurisdictions have legislated the Travel Rule, up from 73 percent a year earlier, but thresholds, data fields, and enforcement differ enough that a firm has to run one policy per corridor.
Where the Travel Rule Comes From
The Travel Rule predates crypto by more than two decades. FATF Recommendation 16 requires originator and beneficiary information to accompany wire transfers, and the US version has been codified since 1996 at 31 CFR 1010.410(f). In June 2019 the FATF amended the Interpretive Note to Recommendation 15 so the same obligations apply to VASPs; the crypto Travel Rule technically lives in INR.15 by cross-reference to R.16.
The US did not need new legislation. FinCEN's May 2019 guidance, FIN-2019-G001, reasoned that because a transmittal order involving CVC is an instruction to pay a determinable amount of money, CVC transactions are transmittals of funds, and a money transmitter handling one of $3,000 or more must comply. Substituting a pseudonym for the transmittor's name does not satisfy the rule. The EU implemented its version through Regulation (EU) 2023/1113, the recast Transfer of Funds Regulation, applying from 30 December 2024; the UK inserted Part 7A into the Money Laundering Regulations 2017 from 1 September 2023.
What Has to Travel
The core data set is consistent across regimes even where thresholds are not. Under the FATF standard, the originating VASP transmits the originator's name, the account number or wallet address used for the transfer, and one further identifier: physical address, national identity number, customer identification number, or date and place of birth. For the beneficiary, only name and account number or wallet address are required, and each VASP verifies only its own customer's data.
The EU is more prescriptive. Article 14 of Regulation 2023/1113 requires the originator's name, distributed ledger address, and address including country, official document number, and customer identification number, or alternatively date and place of birth, plus the LEI where available, and prohibits executing a transfer before the article is fully complied with. The UK splits the set: Regulation 64C requires names and account numbers on every transfer regardless of amount, and the extended originator identifiers only above a threshold or on request from a UK beneficiary firm.
The information must be submitted before or concurrently with the transfer, not after settlement, and it does not travel on-chain: both FinCEN's 2019 guidance and Article 14(4) of the EU regulation say the data need not ride with the value itself. That separate rail is where the interoperability problem comes from.
Thresholds Are Where the Regimes Diverge
One FATF standard produced four thresholds, and the gaps between them drive most of the policy complexity.
The US figure deserves a note, because much commentary still calls a lower threshold pending. In 2020 FinCEN and the Federal Reserve proposed cutting it to $250 for transfers that begin or end outside the United States. The Unified Agenda entry for RIN 1506-AB41 lists that proposal as withdrawn on 16 April 2025, so the operative US threshold is $3,000. The EU's zero threshold is deliberate: Recital 27 of Regulation 2023/1113 says that because crypto transfers are borderless, no low-value exemption should apply.
The Sunrise Problem Has Not Set
The sunrise problem is the FATF's term for uneven adoption: a VASP where the rule is live sends to a counterparty where it is not, and the required data has nowhere to land. The FATF's June 2025 Best Practices on Travel Rule Supervision calls it the single largest obstacle to effective implementation.
The FATF's June 2025 targeted update found that 85 of 117 responding jurisdictions permitting VASPs, or 73 percent, had passed Travel Rule legislation, but 59 percent of those, 50 jurisdictions, had taken no enforcement or supervisory action on it. The July 2026 update lifted the legislation figure to 83 percent with 11 more in progress, while stressing that many have yet to translate law into supervision.
The FCA's August 2023 statement shows how a supervisor expects firms to live with this. When sending to a jurisdiction without the Travel Rule, a UK firm must establish whether the counterparty can receive the information, and if it cannot, must still collect, verify, and store the data before transferring. When receiving incomplete information, the firm makes a risk-based decision on releasing the assets, and it stays responsible even when using a third-party supplier.
Self-Hosted Wallets
Transfers to and from self-hosted wallets have no counterparty VASP, so there is no one to message, but regulators have not treated that as an exemption. The FATF's 2021 updated guidance says VASPs should still collect originator and beneficiary information for transfers between a customer and an unhosted wallet and apply risk-based mitigation, while pure peer-to-peer transfers sit outside the AML/CFT perimeter.
The EU went furthest. Under Articles 14(5) and 16(2) of Regulation 2023/1113, a CASP must obtain and hold originator and beneficiary information for transfers to or from a self-hosted address, and above EUR 1,000 must take adequate measures to assess whether the address is owned or controlled by its client. Recital 39 clarifies that the CASP need not verify the identity of the self-hosted address user, so the test is ownership, not third-party identity; firms satisfy it with signed messages, micro-deposits, or third-party attestation. The US has no equivalent rule in force; FinCEN's December 2020 unhosted wallet proposal has not been finalized.
Protocols, Directories, and IVMS 101
Because Travel Rule data moves off-chain, the industry built the rail. The data layer is IVMS 101, the interVASP Messaging Standard released in May 2020 by a joint working group of more than 130 technical experts and updated in 2024, which defines the fields and datatypes so two VASPs on different software can parse the same message. The transport layer is fragmented: the Travel Rule Protocol, TRISA, OpenVASP, and commercial networks such as Notabene, Sygna, and VerifyVASP all carry IVMS 101 payloads, and none reaches every counterparty. That imposes two requirements: counterparty discovery, so the originating VASP knows before a withdrawal whether the destination is a VASP and which protocols it supports; and multi-protocol reach, since most production VASPs connect to more than one network. Firms evaluating crypto compliance software should treat protocol coverage and directory quality as first-order criteria.
Where the Travel Rule Meets Sanctions and Monitoring
The Travel Rule is a data-collection rule whose purpose is downstream. The FATF's supervision guidance describes payment transparency as what underpins financial investigations and compliance with targeted financial sanctions. The names that arrive through a Travel Rule message are what the beneficiary VASP screens, so the Travel Rule and sanctions screening workflows cannot be separate systems making separate decisions: a listed name or a wallet address matching an OFAC designation has to be held before the assets are released. Missing data is itself a signal. Article 18 of the EU regulation makes incomplete originator information a factor in assessing suspicion, and many sanctions evasion red flags, including nested accounts at offshore VASPs, surface first as Travel Rule anomalies.
What the Compliance Team Actually Runs
A Travel Rule program is four recurring processes.
The volume is in the exceptions, not the automated message exchange: unmatched counterparties, incomplete payloads, screening hits on inbound names, and over-threshold self-hosted transfers needing ownership evidence. Firms building this inside a broader crypto AML compliance program, or extending it to stablecoin transfers under the same $3,000 rule, find the exception queue grows faster than the transfer count.
Where Sphinx Fits
Sphinx's agents work that exception queue. For crypto firms, that means performing counterparty VASP due diligence against the same registries, licensing databases, and sanctions lists an analyst would use, reviewing Travel Rule alerts where inbound data is missing or a name has hit, and producing a documented case file with the reasoning behind each hold, request, release, or rejection, inside the firm's existing tools. Judgment stays with the firm: terminating a counterparty, setting risk appetite for sunrise jurisdictions, and deciding when anomalies constitute reportable suspicion are decisions a compliance officer owns.
Frequently Asked Questions
What is the Travel Rule threshold for crypto in the United States?
$3,000, or its equivalent in convertible virtual currency, under 31 CFR 1010.410(f), as confirmed by FinCEN's 2019 guidance. A 2020 proposal to lower it to $250 for cross-border transfers was withdrawn in April 2025.
Does the EU Travel Rule have a minimum transaction amount?
No. Regulation (EU) 2023/1113 requires the full originator and beneficiary data set on every transfer between crypto-asset service providers regardless of value. The EUR 1,000 figure applies only to self-hosted address transfers, above which the CASP must assess whether its client controls the address.
What is the sunrise problem in Travel Rule compliance?
The sunrise problem is the gap created when the Travel Rule is in force in one jurisdiction but not the counterparty's, so a compliant VASP has no one to exchange data with. The FATF's 2025 update found 59 percent of jurisdictions with Travel Rule legislation had taken no enforcement action.
Do Travel Rule requirements apply to transfers to self-hosted wallets?
Partly. The FATF's 2021 guidance says VASPs should still collect originator and beneficiary information. In the EU, a CASP must hold that information for every self-hosted transfer and, above EUR 1,000, assess whether its own client controls the address. The US has no equivalent rule in force.
What is IVMS 101?
IVMS 101 is the interVASP Messaging Standard, a data model released in May 2020 that defines how originator and beneficiary information is structured so different VASPs and Travel Rule networks can exchange it consistently. It is a data model, not a transport protocol; networks such as TRP, TRISA, and OpenVASP carry it.

.png)