Financial Crime Insights: The FATF Travel Rule Is Two Years Overdue at Most VASPs. Here’s Why That’s Dangerous.

The FATF Travel Rule Is Two Years Overdue at Most VASPs — Here’s Why That’s Dangerous

The Financial Action Task Force first extended Recommendation 16 — the so-called “Travel Rule” — to virtual asset service providers in June 2019. Six years later, FATF’s own data tells a sobering story: roughly 75% of jurisdictions have not fully implemented the rule, and the majority of VASPs worldwide still cannot transmit originator and beneficiary data in a compliant, interoperable way. What was designed as the cornerstone of crypto AML has become the single largest compliance gap in the global digital-asset ecosystem.

For senior compliance professionals, this isn’t merely a regulatory curiosity. It’s an operational and strategic risk that touches every wire, every counterparty relationship, and every supervisory examination. This article breaks down why implementation has stalled, what the real-world consequences look like, and what compliance leaders should be doing right now.

 

 

1. The Global State of Travel Rule Implementation — By the Numbers

FATF’s 2023 Targeted Update pulled no punches: the Travel Rule remains the area of weakest compliance across the entire virtual-asset regulatory landscape. Consider the current reality:

~75%
Jurisdictions Not Fully Compliant
6 yrs
Since FATF Extended R.16 to VASPs
<30%
VASPs With Interoperable Solutions

These numbers mean that for every compliant transfer a licensed VASP sends, there’s a strong probability the counterparty on the other end either cannot receive the data, doesn’t know what to do with it, or isn’t even licensed in the first place. That asymmetry is where the danger lives.

⚠️ Risk Alert

A VASP that processes transfers without verifiable counterparty Travel Rule compliance is effectively operating with a blind spot equivalent to a bank clearing SWIFT messages with no originator information. Regulators — from VARA to the FCA — are increasingly treating this as a sanctionable failure, not a teething issue.

2. A Brief Regulatory Timeline — How We Got Here

Understanding the current gap requires understanding how slowly — and unevenly — the regulatory framework has matured:

 

June 2019 — FATF Extends R.16

FATF updates its guidance to include VASPs under the Travel Rule, requiring originator/beneficiary data transmission for transfers above the $1,000/€1,000 threshold. Industry scrambles to understand implications.

 

2020–2021 — IVMS101 Developed

The InterVASP Messaging Standard (IVMS101) is created through the FATF TREIN working group, establishing a common data format. Adoption is voluntary and patchy. UAE’s first mutual evaluation flags the Travel Rule as a critical gap.

 

2022–2023 — Key Jurisdictions Act

UAE enacts Cabinet Resolution No. 111 (2022); UK amends MLRs; both mandate IVMS101 and set enforcement dates. VARA sunrise period ends December 2023. FCA makes it clear: inability to receive data is no defence.

 

2024–2025 — Enforcement Ramps Up

VARA includes Travel Rule checks in all on-site inspections. Wolfsberg Group recommends banks refuse to process crypto payments from non-compliant VASPs. The compliance gap becomes a market access issue.

3. Why Implementation Has Stalled — The Real Obstacles

It’s easy to blame industry inertia, but the Travel Rule presents genuinely novel challenges that have no clean parallel in traditional finance:

The Counterparty Identification Problem

In the SWIFT world, every bank has a BIC. In the crypto ecosystem, there is no universal registry of licensed VASPs. When a VASP receives an inbound transfer from a blockchain address, it often cannot determine whether the originating entity is a licensed VASP (requiring Travel Rule data exchange), an unhosted private wallet (requiring enhanced due diligence), or an unlicensed money service business (requiring rejection or escalation).

Interoperability Fragmentation

Multiple Travel Rule solution providers have emerged — Notabene, Sygna, TRP by 21 Analytics, Shyft, among others — but they don’t all interoperate seamlessly. A VASP using one protocol may not be able to exchange data with a counterparty on another, creating digital islands of compliance.

Jurisdictional Threshold Mismatches

As the comparison below illustrates, even jurisdictions that have implemented the rule don’t always agree on the basics:

Dimension 🇦🇪 UAE (VARA / CBUAE) 🇬🇧 UK (FCA)
Threshold AED 3,500 (~USD 1,000) No de minimis — ALL transfers
Effective Date Q4 2023 (sunrise ended Dec 2023) September 2023
Data Standard IVMS101 mandated IVMS101 mandated
Unhosted Wallets Enhanced due diligence; guidance pending EDD required; JMLSG guidance issued
Enforcement Approach Assessed in all on-site exams No defence for inability to receive data

A VASP operating in both jurisdictions must engineer its compliance systems for the stricter standard (UK’s no-threshold approach) while managing the operational nuances of each regime. This regulatory divergence increases cost, complexity, and the risk of inadvertent non-compliance.

“The Travel Rule is not a technology problem. It’s a coordination problem. We have the messaging standard. What we lack is universal adoption and the political will to enforce it consistently.”— Senior FATF Delegate, 2024 Plenary

 

 

4. Why the Compliance Gap Is Genuinely Dangerous

Some in the industry treat Travel Rule non-compliance as a “soft” risk — regulators are still learning crypto, enforcement is inconsistent, and no one has been shut down solely for a Travel Rule failure yet. That calculus is rapidly changing for three reasons:

 
Now Enrolling

Master AML, AI & Financial Crime Compliance

CAMS-aligned, practitioner-led courses built for compliance professionals who want to stay ahead of the technology reshaping their profession.

Explore Courses →

 

4.1 — Correspondent Banking De-Risking

The Wolfsberg Group’s recommendation that correspondent banks refuse to process crypto-related payments from non-compliant VASPs is a commercial death sentence. Without fiat on- and off-ramps, a VASP cannot function. Banks are already asking for Travel Rule compliance attestations during account reviews, and CBUAE’s AML/CFT standards (Article 8) require banks to verify Travel Rule data before processing crypto-to-fiat conversions.

4.2 — Regulatory Enforcement Escalation

VARA now assesses Travel Rule implementation in every on-site inspection. The FCA’s supervisory statement explicitly removes the “sunrise period” defence. These aren’t future threats — they’re current examination criteria. Non-compliance doesn’t just trigger a remediation letter; it triggers enforcement action.

4.3 — Sanctions Evasion Exposure

Without Travel Rule data, a VASP has no systematic way to screen the originator or beneficiary of an inbound transfer against sanctions lists. You’re essentially flying blind. One sanctioned-party transaction that could have been caught with proper data exchange can result in penalties that dwarf the cost of implementing a Travel Rule solution.

💡 Key Insight

The Travel Rule isn’t just about data transmission — it’s the mechanism through which VASPs perform counterparty due diligence. Without it, the entire AML/CFT framework for virtual assets collapses at the point of transfer, precisely where illicit funds move between jurisdictions.

5. What Compliance Leaders Should Do Now — A Practical Roadmap

If your Travel Rule programme is still in pilot, partially deployed, or — candidly — non-existent, here is a prioritised action plan:

1
Conduct a Transfer Volume Audit

Map every VASP-to-VASP and VASP-to-unhosted-wallet transfer by jurisdiction, volume, and counterparty type. Identify your highest-risk corridors — these are your priority implementation targets.

2
Select a Travel Rule Solution Provider

Evaluate providers on interoperability (how many counterparty VASPs are reachable), IVMS101 native support, and integration with your existing transaction monitoring and sanctions screening stack.

3
Build a Counterparty VASP Due Diligence Framework

Develop a methodology to assess whether a counterparty is a licensed VASP, an unlicensed entity, or an unhosted wallet. Document your determination logic — regulators will ask for it.

4
Define a Policy for Non-Compliant Counterparties

Decide — and document — what happens when a counterparty VASP cannot receive or provide Travel Rule data. Options range from blocking the transfer to applying enhanced due diligence with additional verification steps. Ambiguity here is an examination finding waiting to happen.

5
Report to the Board

Travel Rule non-compliance is a material regulatory risk. Ensure your board and senior management receive a clear assessment of current gaps, remediation timelines, and residual risk. This is no longer an “IT project” — it’s a governance obligation.

✅ Best Practice

Treat your Travel Rule solution as critical compliance infrastructure — on par with your transaction monitoring system and sanctions screening engine. Budget, staff, and govern it accordingly. Firms that bolt it on as an afterthought consistently fail regulatory inspections.

 

 

6. Frequently Asked Questions

❓ What is the FATF Travel Rule and why does it apply to VASPs?
FATF Recommendation 16 requires financial institutions — and, since 2019, virtual asset service providers — to obtain, hold, and transmit originator and beneficiary information when transferring funds or virtual assets. The rule exists to ensure that law enforcement can trace the flow of value across borders and identify the parties on both sides of a transaction. For VASPs, it applies to transfers at or above the $1,000/€1,000 threshold (though some jurisdictions, like the UK, apply it to all transfers regardless of amount).
❓ What is IVMS101 and why is it important?
IVMS101 (InterVASP Messaging Standard 101) is the global technical data standard for formatting and transmitting Travel Rule information between VASPs. Developed by the FATF TREIN working group, it standardises data fields such as originator name, account number, and beneficiary details into a common schema. Both the UAE (VARA) and UK (FCA) mandate IVMS101 as the required data format, making it the de facto global standard for Travel Rule compliance.
❓ What should a VASP do when the counterparty cannot receive Travel Rule data?
This is one of the most difficult operational questions. The FCA has stated explicitly that a firm’s inability to receive Travel Rule data is not a valid defence for processing a transfer. Best practice is to have a documented policy that either blocks the transaction, applies enhanced due diligence with manual data collection, or restricts the relationship to lower-risk transfer types. The key is that your approach must be risk-based, documented, and defensible during a supervisory examination.
❓ How does the Travel Rule apply to unhosted (self-custody) wallets?
Transfers to and from unhosted wallets don’t involve a counterparty VASP, so the standard VASP-to-VASP data exchange doesn’t apply. However, both UAE and UK regulators require enhanced due diligence (EDD) for these transfers. In the UK, the JMLSG’s 2023 crypto guidance provides detailed expectations, including ownership verification steps. In the UAE, VARA’s guidance on unhosted wallet EDD is still pending but the expectation of heightened scrutiny is already clear.

Conclusion: The Window for Graceful Compliance Is Closing

The crypto industry has had six years to implement the Travel Rule. Regulators have moved from guidance to enforcement. Banks are conditioning access on compliance attestations. The Wolfsberg Group is explicitly recommending payment refusal for non-compliant VASPs. The argument that “the ecosystem isn’t ready” is no longer a shield — it’s an admission of unmanaged risk.

For compliance leaders, the path forward is clear: treat Travel Rule implementation as an urgent, board-level priority. Audit your current state, select an interoperable solution, build your counterparty VASP due diligence framework, and document every policy decision. The VASPs that solve this first won’t just avoid enforcement — they’ll become the trusted counterparties that the rest of the ecosystem needs to do business with.

The Travel Rule isn’t coming. It’s here. The only question is whether your firm will be ready when the examiner arrives — or when your correspondent bank calls.

Compliance Advisory

Need Expert AML/CFT & RegTech Guidance?

17+ years across FATF, CBUAE, VARA & NRB. Visit our website for consultancy services tailored to your organization.

“Your compliance programme looks good on paper.
But will it survive a regulatory examination?”

Get Consultancy →

Leave a Reply

Your email address will not be published. Required fields are marked *