Regulation

FATF Travel Rule for Crypto: What It Requires

The Travel Rule requires the virtual asset provider handling a transfer to identify both parties involved.

Equipo Soulbit9 min read
Share
Regulation

A company that already cleared KYB to operate with virtual assets tends to assume its compliance exposure ends there. It does not. Every virtual asset transfer above a minimum threshold triggers a separate obligation that has nothing to do with whether the account is already open: identify the originator and the beneficiary, and send that data along with the payment, transfer by transfer. That obligation has a name in the international anti-money-laundering standard: the Travel Rule.

At Soulbit Academy we cover this rule because, alongside KYB, it is the compliance topic that generates the most questions among companies that start collecting or paying in stablecoins. The Travel Rule does not replace KYB, it complements it. KYB verifies who your company is before the account opens; the Travel Rule decides what information travels attached to each transfer once the account is already operating. If you are looking for what documents a platform requests when opening an account, that guide is what is KYB and why your business needs it. This article covers the other half of compliance: the part that happens on every payment.

What the FATF Travel Rule Requires

The Travel Rule requires the virtual asset provider sending a transfer to identify the originator and the beneficiary, and pass that data to the provider receiving it. The name comes from the fact that the information "travels" with the payment itself, not just the sender's internal record.

FATF, the Financial Action Task Force, has required this transparency for traditional wire transfers for over a decade under its Recommendation 16. In 2019 it extended that same logic to virtual assets through the Interpretive Note to Recommendation 15. That note requires virtual asset service providers (VASPs) to apply the Recommendation 16 standard to transfers between them. FATF's official summary of Recommendation 15's scope is published on its virtual assets page.

Why did FATF treat this as a priority separate from other anti-money-laundering obligations?

Because a virtual asset transfer, unlike a bank wire, can move between two providers without either one automatically seeing who is on the other end. FATF identified that gap as an open channel for separating an illicit fund's origin from its final destination. The Travel Rule closes that gap by requiring identification to travel with the money, rather than staying isolated at each end.

A VASP, in FATF's own definition, is any business that conducts one or more of a set of activities on behalf of a customer: exchanging virtual assets for fiat or other virtual assets, transferring virtual assets, safekeeping or administering them, or participating in the issuance or sale of one. A custodial exchange, a custody provider, and a stablecoin-based payments platform can all fall under that definition depending on the specific service performed. What matters for your company is simpler: whichever provider executes your transfer is the one carrying the Travel Rule obligation for that transaction, not your finance team.

The Travel Rule Threshold for Virtual Assets: USD/EUR 1,000

FATF recommends a de minimis threshold of USD/EUR 1,000 to trigger the full set of data required on a virtual asset transfer. Below that figure, the obligation still exists but is reduced; at or above it, it becomes complete.

Transfer levelWhat the VASP must transmitExample
Below USD/EUR 1,000Originator's and beneficiary's names, plus an account number or wallet address, or a unique transaction referenceSending 300 USDC: full name of both parties and the destination wallet
At or above USD/EUR 1,000Plus an address or country and city, and the originator's date of birth for an individual, or a business identifier for a legal entitySending 5,000 USDC: the originator's date of birth and the beneficiary's country are added
Threshold set by each countryUSD/EUR 1,000 is FATF's minimum recommendation; each jurisdiction can tighten itThe European Union applies no threshold at all: it requires full data from the first euro transferred
Table 1. What information the FATF Travel Rule requires depending on the size of a virtual asset transfer, as of August 2026.

The threshold is a floor, not a ceiling. The European Union chose to apply no threshold at all for its crypto-asset service providers: it requires the full data set from the first unit transferred, a tightening worth keeping in mind if your company collects or pays European counterparties.

Whose Obligation Is It: The VASP, Not Your Company

The obligation to identify, transmit, and retain the data on every transfer sits with the VASP executing it, not with the company ordering or receiving the payment.

Does my company have to do anything different every time it sends a stablecoin payment?

Not directly. What your company provides is complete information during KYB onboarding, and correct beneficiary details on each payment instruction: name, and destination wallet or account.

Two providers are involved in any relevant transfer. The originating VASP, the one sending the payment, has to identify its ordering customer, attach that customer's data to the transfer message, and transmit it before or alongside the movement of the asset. The beneficiary VASP, the one receiving the payment, has to verify that the information arrived complete, retain it, and hold the transfer for review if something does not add up. Your company depends on which of the two providers it uses; the operational work of the Travel Rule happens between them.

The Sunrise Issue: What Happens if the Other Side Is Not Ready

The sunrise issue is the gap between providers that already comply with the Travel Rule and providers that cannot yet process that data, and it is the most common friction on a transfer between countries with uneven frameworks.

What happens if the VASP receiving the payment is not prepared to accept that data?

It happens either because their jurisdiction does not require it yet or because their technical infrastructure is not ready. The transfer rarely disappears; it is almost always held for manual review while the originating provider confirms the beneficiary's identity through another channel, which adds hours or days to settlement. In stricter cases, the originating VASP may choose not to execute the payment until that verification is resolved.

For a treasury paying suppliers or collecting from clients across several countries, the sunrise issue is a practical reason not to assume every virtual asset transfer settles in minutes. A stablecoin's speed solves the infrastructure side; compliance at both ends of the transfer determines whether that speed actually reaches the counterparty without friction.

The practical mitigation is documentation, not a workaround. Keeping the invoice, the contract, and the wallet address on file for every payment gives your own team the same information a VASP would need to resolve a held transfer quickly, whether the delay comes from a sunrise issue or from a routine compliance check on the receiving end. A finance team that can produce that paper trail in minutes turns a multi-day hold into a same-day one.

Where Travel Rule Implementation Actually Stands in 2026

As of July 2026, 83% of the 109 jurisdictions FATF surveyed already had Travel Rule legislation in force for virtual assets, up from 73% a year earlier. That legislative progress, however, has not yet translated into the same level of enforcement.

Indicator (July 2026)FigureWhat it means
Jurisdictions with the Travel Rule in force83% (91 of 109)Up from 73% recorded a year earlier
Jurisdictions with the Travel Rule in force or in progress93% (102 of 109)Only 7 of the 109 surveyed jurisdictions report no progress at all
Jurisdictions with at least one supervisory or enforcement action on Travel Rule compliance40% (36 of 91)6 out of 10 jurisdictions with a law in place have not yet audited it
Table 2. Global implementation status of the crypto Travel Rule, per FATF's seventh targeted update on virtual assets and VASPs, published July 2026. Source: FATF.

FATF's own targeted update describes this gap as the sector's central risk right now: most countries have passed the law, but few have shown they enforce it in practice. For a company, that means a counterparty's jurisdiction having a Travel Rule law on the books does not guarantee its provider is actually being audited on real compliance.

The US and EU Angle: FinCEN's Threshold and MiCA's No-Threshold Rule

A US or European company paying suppliers or contractors in Latin America sits on the stricter side of this framework, and it is worth knowing exactly how strict.

In the United States, the underlying Travel Rule, codified as the Funds Transfer Rule at 31 CFR 1010.410(e), has applied to cross-border transfers above USD 3,000 for decades. FinCEN's 2019 guidance (FIN-2019-G001) confirmed that this rule already covers convertible virtual currency, so a US-based VASP handling an international stablecoin payment above that amount must collect and transmit the same originator and beneficiary data required for a wire transfer. In 2020, FinCEN and the Federal Reserve jointly proposed lowering that international threshold to USD 250 specifically for funds transfers, a change that would bring US practice much closer to FATF's own USD 1,000 recommendation, as recorded in the official Federal Register notice. As of 2026, that proposal is still pending; it has not been finalized, and the USD 3,000 threshold remains in effect.

What should a US company paying a Latin American supplier in stablecoins actually check?

Two things, both about the receiving side. First, whether the beneficiary's VASP in Colombia, Mexico, or elsewhere in the region already operates under Travel Rule legislation in force, a status that varies sharply by country and is mapped in the LATAM crypto regulation landscape for 2026; the FATF gap described above means a law on paper is not proof of real compliance either. Second, whether that provider can actually receive and act on the identifying data your own VASP sends, to avoid the sunrise issue described earlier turning into a delayed payroll or a delayed supplier payment.

The European side of this is already stricter than the US in one specific way: the EU applies no minimum threshold at all for crypto-asset service providers under its markets-in-crypto-assets framework, a point we detail in MiCA in 2026: what a LATAM company should know to operate with Europe. A European client paying a Latin American exporter, or the reverse, should expect full identifying data on every transfer regardless of size. The broader anti-money-laundering treatment that stablecoin issuers themselves face in the US, separate from what VASPs owe under the Travel Rule, is covered in the GENIUS Act and what changes for Latin American companies.

This matters most for the payment types that move most often between these two regions: recurring contractor payments and one-off supplier invoices. A US company paying international contractors in USDC, the case we walk through in how to pay international contractors in USDC, sends transfers that individually may sit well above the FATF USD/EUR 1,000 threshold and above the US domestic USD 3,000 mark alike. Each of those payments already carries full originator and beneficiary data under both frameworks; the open question is only whether the contractor's own VASP on the receiving end can process it without a manual hold.

What Soulbit's V1 Actually Delivers Today

Soulbit is a payments and treasury rail in stablecoins for businesses. Before operating, every company completes a KYB verification that confirms its legal registration, its representatives, and its beneficial owners, the process described in the KYB guide linked above. On top of that, every transaction goes through on-chain AML/KYT monitoring, which analyzes the origin and destination of funds on the blockchain.

This article does not claim that Soulbit operates a specific Travel Rule messaging protocol with every counterparty provider: that capability depends on the compliance infrastructure of each VASP involved in a transfer and varies transaction by transaction, as the sunrise issue section above describes. What is consistent in the V1 is the foundation any Travel Rule compliance is built on: complete company identification through KYB and traceability of every transaction through AML/KYT monitoring. Soulbit does not offer cards, yield on balances, a native token, or a native mobile app, and its local banking rail exists today only in Colombia.

For a company paying or collecting across several countries, the practical takeaway is this: verifying who your counterparty is does not end at onboarding KYB. Every relevant transfer depends on two providers, not just one, doing their part of the identification.

Frequently asked questions

What is the FATF Travel Rule for crypto?

It is the requirement that the virtual asset provider sending a transfer identify the originator and the beneficiary, and pass that data to the receiving provider. FATF (Financial Action Task Force) set it out in the Interpretive Note to Recommendation 15, which extends to virtual assets the same logic Recommendation 16 already applies to traditional wire transfers.

What is the threshold that triggers the crypto Travel Rule?

FATF recommends a de minimis threshold of USD/EUR 1,000. Below it, the provider only needs both parties' names and an account or wallet reference. At or above it, the provider must also transmit an address or country and, for an individual originator, a date of birth. Jurisdictions can set a stricter threshold; the European Union, for example, applies none at all.

Does my company have to comply with the Travel Rule directly?

Not directly. The obligation to identify, transmit, and retain the data sits with the virtual asset service provider (VASP) executing the transfer, not with the company ordering or receiving the payment. Your company's role is to supply accurate information during KYB onboarding and complete beneficiary details on each payment instruction.

What is the Travel Rule 'sunrise issue'?

It is the industry term for the gap between providers that already comply with the Travel Rule and providers that cannot yet receive that data, because their jurisdiction has not required it or their systems are not ready. When that happens, a transfer between the two can be held for manual review or, in some cases, rejected.

Is the Travel Rule already enforced in the United States?

The underlying rule has applied to convertible virtual currency since FinCEN's 2019 guidance, at the existing USD 3,000 threshold for cross-border funds transfers under the Bank Secrecy Act. A 2020 proposal to lower that threshold to USD 250 for international transfers remains pending; as of 2026 it has not been finalized.

Want your company to add stablecoins to its operations?

Join the Soulbit waitlist and start paying payroll, collecting and managing treasury without SWIFT.

Join the waitlist

Related articles

Regulation

Mexico Stablecoin Regulation: the AVE Bill Explained

Mexico's Senate is reviewing a bill that would regulate peso-referenced stablecoins for the first time. It has not passed. Here is what it would change.

11 min read
Mexico Stablecoin Regulation: the AVE Bill Explained
Regulation

Colombia's Foreign Exchange Regime: A Guide for Companies

A US or Brazilian company invoicing a Colombian buyer, lending to a Colombian subsidiary, or investing in a Colombian company is dealing with Colombia's exchange control regime, whether it names it or not.

11 min read
Colombia's Foreign Exchange Regime: A Guide for Companies