Travel Rule & AML

the rule that follows the money

2 min readRegulation & PolicyLast updated:

Editorial illustration: the FATF Travel Rule and crypto anti-money-laundering compliance

Key facts

FATFRecommendation 16
Origin
VASPsexchanges, custodians
Applies to
Identity datasent with the transfer
Requires
Self-custodywallets with no firm behind them
Hard case

The single rule that did most to change how crypto actually works. Banks have had to send the sender's identity with every wire for decades. Applying that to a technology built for pseudonymous transfer was never going to be tidy.

Of all the rules imposed on crypto, the Travel Rule has changed day-to-day operations most. It is not a crypto invention: it comes from banking, where information about a payer must travel alongside a wire transfer so that law enforcement can follow money across institutions. The Financial Action Task Force extended it to cryptoassets, and implementing it on a technology designed for pseudonymous transfer has been awkward from the start.

What it requires

When a customer sends cryptoassets from one regulated firm to another, the sending firm must transmit identifying information about the sender, and often the recipient, to the receiving firm. Name, account reference and, depending on the jurisdiction, address or date of birth. The receiving firm is expected to check that the information is complete and to act if it is missing or looks wrong.

FATF sets the standard, and roughly 200 jurisdictions have committed to implementing it. The European Union’s Transfer of Funds Regulation applies it alongside MiCA, and other major markets have their own versions with differing thresholds.

Why it is difficult

The blockchain carries the value but not the paperwork. A transaction records addresses and amounts, with no field for a customer’s name, so the identity information has to travel over a separate channel between firms. That requires the sending firm to know which firm controls the receiving address, and to have a way of talking to it. Neither is guaranteed.

The industry’s response has been a set of competing messaging protocols and networks that firms join in order to exchange the data. Interoperability between them remains imperfect, which means a transfer between two compliant firms on different systems can still fail to complete cleanly.

The genuinely unresolved case is self-custody. If a customer withdraws to a wallet they control themselves, there is no firm at the other end to receive the information. Jurisdictions differ sharply here: some require additional verification that the customer owns the destination wallet, others accept a declaration, and the practical result is that withdrawal experiences vary enormously depending on where a user lives.

What it means in practice

The rule is the reason exchanges ask who owns a destination address, why withdrawals to unfamiliar addresses are sometimes delayed, and why proving ownership of a wallet has become routine. It is also why blockchain analytics has grown into a substantial industry: firms need to know whether an address has a history that makes a transfer risky.

Where it stands

Implementation remains uneven, and FATF has repeatedly noted that many jurisdictions are behind. The tension underneath is unchanged: a rule written for a system with identified account holders at both ends, applied to one that was deliberately built to work without them.