Most exchanges got the policy right. Embedding Travel Rule controls into transaction infrastructure at volume is where the industry’s focus is now.
Regulators are not waiting. The EU’s Transfer of Funds Regulation has applied to every crypto transfer, regardless of amount, since December 2024. In June 2025, FATF revised Recommendation 16 which broadened it from wire transfers to all payment and value transfers, and standardized the data fields required. Jurisdictions have until 2030 to transpose it.. And enforcement, once predictable in its absence, is now active across Europe, Singapore, and Hong Kong with the UAE’s framework in place and supervisory expectations tightening.
The question for compliance teams has shifted from “does this apply to us?” to “can our infrastructure actually run this at volume?”
This article addresses the second question. It draws on what we observe at the wallet and transaction layer when exchanges and payment firms operationalise Travel Rule compliance across regulated markets.
What the Travel Rule Requires: The Essentials
The Travel Rule is rooted in FATF Recommendation 16, which requires financial institutions to pass originator and beneficiary information alongside fund transfers. Applied to virtual assets, this means:
- The originating VASP must collect and transmit the sender’s name, account identifier (wallet address), and in some jurisdictions, physical address or national identification details.
- The beneficiary VASP must receive, verify, and retain this information before making funds available to the recipient.
- This obligation applies to qualifying transactions above defined thresholds, which vary by jurisdiction.
Threshold variations matter. The EU TFR applies to all CASP-to-CASP transfers with no minimum. Singapore’s MAS framework applies from SGD 1,500, VARA (Dubai) and ADGM (Abu Dhabi) apply from AED 3,500. The US Funds Transfer Rule applies from USD 3,000. A multi-jurisdictional exchange operating across even three of these regions must reconcile different thresholds, data field requirements, and timing obligations simultaneously.
This is not a paperwork exercise. At transaction volume, it is an infrastructure requirement.
Where Travel Rule Implementation Breaks Down
The regulation is reasonably clear. The implementation is not. These are the operational gaps that catch exchanges and payment firms off guard.
1. Counterparty VASP Identification
Before a VASP can send Travel Rule data, it needs to know whether the receiving address belongs to a regulated VASP or a self-hosted wallet. This process, called VASP attribution, sounds straightforward. It is not.
There is no universal VASP registry. Commercial blockchain analytics providers maintain databases of known exchange addresses, but coverage is incomplete, especially for smaller regional VASPs. When a receiving address cannot be attributed, the sending VASP faces a compliance gap: it cannot execute a proper data handshake with a counterparty it cannot identify.
At high volume, unresolved attribution piles up fast.
2. The Sunrise Problem
The sunrise problem refers to the uneven pace of Travel Rule adoption across jurisdictions. A VASP operating in Singapore or the EU may send Travel Rule data to a counterparty in a jurisdiction that has not yet implemented the rule. That counterparty has no obligation to receive or process the data, and often no technical capability to do so.
This creates a practical dilemma: do you block the transfer, proceed without receiving confirmation, or document a good-faith effort and proceed? Different jurisdictions answer this differently. Many compliance teams are operating without clear internal policy on this question.
FATF’s June 2025 Targeted Update acknowledged the problem and pressed jurisdictions to accelerate implementation. The gap is closing, but it remains a live operational risk for any exchange with global transaction flows.
3. Unhosted Wallet Transactions
When a transfer involves a self-hosted wallet on one end, there is no VASP counterparty to exchange data with. The obligation shifts: the VASP must use reasonable measures to determine who controls the wallet and assess whether the transaction pattern suggests higher risk.
What counts as “reasonable measures” varies by jurisdiction. MAS expects documented risk assessment. The EU TFR requires specific information collection for transfers above EUR 1,000 to or from unhosted wallets. VARA’s framework requires enhanced due diligence in certain cases.
Handling this consistently at scale, without blocking every unhosted wallet transfer for manual review, requires automated risk scoring at the wallet level, not manual case-by-case assessment.
4. Protocol Fragmentation
Travel Rule data exchange runs across competing messaging protocols: TRUST (used by major US exchanges), Sygna Bridge, VerifyVASP, Notabene, and OpenVASP, among others. There is no universal protocol. A sending VASP on one network may not have a direct connection to the receiving VASP’s preferred protocol.
IVMS 101 provides a data format standard, but protocol fragmentation means even a well-structured data package may not reach its intended recipient without an intermediary or integration layer.
At scale, this adds latency, integration complexity, and potential compliance gaps when data transfers fail silently.
5. Data Quality and Audit Trail
Regulators are increasingly auditing not just whether Travel Rule data was exchanged, but whether the exchange is documented, the data fields were complete, and the screening that accompanied the transfer was timestamped and retrievable.
Incomplete data, especially missing originator address fields or unverified beneficiary identifiers, creates audit exposure even when both parties acted in good faith.
What Good Travel Rule Implementation Looks Like at the Transaction Layer
Exchanges and payment firms that have operational Travel Rule compliance well share some consistent infrastructure characteristics. These are not vendor recommendations. They are the patterns we observe from the custody and wallet infrastructure layer.
Automated trigger at transaction initiation. Post-settlement compliance gaps cannot be undone they can only be reported. Embedding the Travel Rule check at the point of transaction initiation, before signing and broadcast, means the control actually prevents the exposure rather than documenting it after the fact.
Protocol-agnostic data exchange. Building a direct integration to one protocol locks you to your counterparties choices, not your own. A middleware layer connected to TRUST, Sygna, Notabene, and others simultaneously means counterparty discovery succeeds regardless of which network the beneficiary VASP uses, without your team managing a separate integration for each.
Wallet-level risk scoring for unhosted addresses. Without automated scoring, every unhosted wallet transfer becomes a manual review candidate and at volume, that either creates a bottleneck or gets skipped. Risk scores derived from on-chain history, high-risk cluster exposure, and transaction velocity let the system triage automatically, so compliance staff focus on flows that actually warrant attention.
Timestamped, retrievable audit trail. A policy document won’t satisfy regulators anymore. They want the record; what data you sent, who you sent it to, what came back, and whether sanctions screening ran at the same time. If that’s not captured automatically and retrievably, it’s not an audit trail. It’s a gap.
Clear internal policy on sunrise transactions. FATF’s June 2025 review found that most firms hadn’t documented their position on sunrise transactions at all. That means when a regulator asks how you handle them, the honest answer is “it depends on who’s on shift.” That’s not a compliance posture. A one-page policy, board-signed and on file, closes that gap entirely.
What Regulated Markets in APAC and MENA Expect
Institutions operating in regulated environments across APAC and MENA face specific expectations worth noting.
In Singapore, MAS expects Travel Rule compliance to be embedded in a VASP’s AML/CFT framework from the outset of licensing, not added later. The focus in supervisory reviews has shifted from documentation to operational evidence: can the system actually execute the data exchange, and is the audit trail retrievable?
In Dubai, VARA’s licensing requirements include explicit Travel Rule obligations for all licensed VASPs, with data exchange tested during the authorisation process. The approach is similar in ADGM, where AML controls are assessed as part of the authorisation file.
Across these markets, the pattern is consistent: compliance that exists on paper but cannot be demonstrated in a live supervisory review does not count.
Travel Rule Compliance as Infrastructure, Not Process
The firms getting Travel Rule compliance right in 2026 have stopped treating it as a process their compliance team manages manually and started treating it as infrastructure their systems run automatically.
That distinction matters because:
- Transaction volumes are not compatible with manual Travel Rule checks.
- Regulatory expectations have shifted from documented policy to demonstrated operational control.
- Multi-jurisdictional complexity, across different thresholds, protocols, and unhosted wallet rules, requires system-level handling.
Compliance teams that inherited Travel Rule as a checkbox item face a real challenge. The operational bar is now higher than most initial implementations anticipated.
Shilpa Sharma
Global Compliance Manager
Shilpa is a Global Compliance Manager at Liminal, with over seven years of experience across fintech compliance, financial crime, and AML. Before Liminal, she managed surveillance and compliance functions at Groww and worked as a Senior AML Consultant at Protiviti. She holds a Certified Anti-Money Laundering Expert (CAME) credential and specializes in global regulatory strategy, risk assessment, and compliance process automation.