The FATF Travel Rule Is Two Years Overdue at Most VASPs — Here’s Why That’s Dangerous
The Financial Action Task Force first extended Recommendation 16 — the so-called “Travel Rule” — to virtual asset service providers in June 2019. Six years later, FATF’s own data tells a sobering story: roughly 75% of jurisdictions have not fully implemented the rule, and the majority of VASPs worldwide still cannot transmit originator and beneficiary data in a compliant, interoperable way. What was designed as the cornerstone of crypto AML has become the single largest compliance gap in the global digital-asset ecosystem.
For senior compliance professionals, this isn’t merely a regulatory curiosity. It’s an operational and strategic risk that touches every wire, every counterparty relationship, and every supervisory examination. This article breaks down why implementation has stalled, what the real-world consequences look like, and what compliance leaders should be doing right now.
◆
1. The Global State of Travel Rule Implementation — By the Numbers
FATF’s 2023 Targeted Update pulled no punches: the Travel Rule remains the area of weakest compliance across the entire virtual-asset regulatory landscape. Consider the current reality:
These numbers mean that for every compliant transfer a licensed VASP sends, there’s a strong probability the counterparty on the other end either cannot receive the data, doesn’t know what to do with it, or isn’t even licensed in the first place. That asymmetry is where the danger lives.
A VASP that processes transfers without verifiable counterparty Travel Rule compliance is effectively operating with a blind spot equivalent to a bank clearing SWIFT messages with no originator information. Regulators — from VARA to the FCA — are increasingly treating this as a sanctionable failure, not a teething issue.
2. A Brief Regulatory Timeline — How We Got Here
Understanding the current gap requires understanding how slowly — and unevenly — the regulatory framework has matured:
June 2019 — FATF Extends R.16
FATF updates its guidance to include VASPs under the Travel Rule, requiring originator/beneficiary data transmission for transfers above the $1,000/€1,000 threshold. Industry scrambles to understand implications.
2020–2021 — IVMS101 Developed
The InterVASP Messaging Standard (IVMS101) is created through the FATF TREIN working group, establishing a common data format. Adoption is voluntary and patchy. UAE’s first mutual evaluation flags the Travel Rule as a critical gap.
2022–2023 — Key Jurisdictions Act
UAE enacts Cabinet Resolution No. 111 (2022); UK amends MLRs; both mandate IVMS101 and set enforcement dates. VARA sunrise period ends December 2023. FCA makes it clear: inability to receive data is no defence.
2024–2025 — Enforcement Ramps Up
VARA includes Travel Rule checks in all on-site inspections. Wolfsberg Group recommends banks refuse to process crypto payments from non-compliant VASPs. The compliance gap becomes a market access issue.
3. Why Implementation Has Stalled — The Real Obstacles
It’s easy to blame industry inertia, but the Travel Rule presents genuinely novel challenges that have no clean parallel in traditional finance:
The Counterparty Identification Problem
In the SWIFT world, every bank has a BIC. In the crypto ecosystem, there is no universal registry of licensed VASPs. When a VASP receives an inbound transfer from a blockchain address, it often cannot determine whether the originating entity is a licensed VASP (requiring Travel Rule data exchange), an unhosted private wallet (requiring enhanced due diligence), or an unlicensed money service business (requiring rejection or escalation).
Interoperability Fragmentation
Multiple Travel Rule solution providers have emerged — Notabene, Sygna, TRP by 21 Analytics, Shyft, among others — but they don’t all interoperate seamlessly. A VASP using one protocol may not be able to exchange data with a counterparty on another, creating digital islands of compliance.
Jurisdictional Threshold Mismatches
As the comparison below illustrates, even jurisdictions that have implemented the rule don’t always agree on the basics:
A VASP operating in both jurisdictions must engineer its compliance systems for the stricter standard (UK’s no-threshold approach) while managing the operational nuances of each regime. This regulatory divergence increases cost, complexity, and the risk of inadvertent non-compliance.
“The Travel Rule is not a technology problem. It’s a coordination problem. We have the messaging standard. What we lack is universal adoption and the political will to enforce it consistently.”— Senior FATF Delegate, 2024 Plenary
◆
4. Why the Compliance Gap Is Genuinely Dangerous
Some in the industry treat Travel Rule non-compliance as a “soft” risk — regulators are still learning crypto, enforcement is inconsistent, and no one has been shut down solely for a Travel Rule failure yet. That calculus is rapidly changing for three reasons:
4.1 — Correspondent Banking De-Risking
The Wolfsberg Group’s recommendation that correspondent banks refuse to process crypto-related payments from non-compliant VASPs is a commercial death sentence. Without fiat on- and off-ramps, a VASP cannot function. Banks are already asking for Travel Rule compliance attestations during account reviews, and CBUAE’s AML/CFT standards (Article 8) require banks to verify Travel Rule data before processing crypto-to-fiat conversions.
4.2 — Regulatory Enforcement Escalation
VARA now assesses Travel Rule implementation in every on-site inspection. The FCA’s supervisory statement explicitly removes the “sunrise period” defence. These aren’t future threats — they’re current examination criteria. Non-compliance doesn’t just trigger a remediation letter; it triggers enforcement action.
4.3 — Sanctions Evasion Exposure
Without Travel Rule data, a VASP has no systematic way to screen the originator or beneficiary of an inbound transfer against sanctions lists. You’re essentially flying blind. One sanctioned-party transaction that could have been caught with proper data exchange can result in penalties that dwarf the cost of implementing a Travel Rule solution.
The Travel Rule isn’t just about data transmission — it’s the mechanism through which VASPs perform counterparty due diligence. Without it, the entire AML/CFT framework for virtual assets collapses at the point of transfer, precisely where illicit funds move between jurisdictions.
5. What Compliance Leaders Should Do Now — A Practical Roadmap
If your Travel Rule programme is still in pilot, partially deployed, or — candidly — non-existent, here is a prioritised action plan:
Map every VASP-to-VASP and VASP-to-unhosted-wallet transfer by jurisdiction, volume, and counterparty type. Identify your highest-risk corridors — these are your priority implementation targets.
Evaluate providers on interoperability (how many counterparty VASPs are reachable), IVMS101 native support, and integration with your existing transaction monitoring and sanctions screening stack.
Develop a methodology to assess whether a counterparty is a licensed VASP, an unlicensed entity, or an unhosted wallet. Document your determination logic — regulators will ask for it.
Decide — and document — what happens when a counterparty VASP cannot receive or provide Travel Rule data. Options range from blocking the transfer to applying enhanced due diligence with additional verification steps. Ambiguity here is an examination finding waiting to happen.
Travel Rule non-compliance is a material regulatory risk. Ensure your board and senior management receive a clear assessment of current gaps, remediation timelines, and residual risk. This is no longer an “IT project” — it’s a governance obligation.
Treat your Travel Rule solution as critical compliance infrastructure — on par with your transaction monitoring system and sanctions screening engine. Budget, staff, and govern it accordingly. Firms that bolt it on as an afterthought consistently fail regulatory inspections.
◆
6. Frequently Asked Questions
Conclusion: The Window for Graceful Compliance Is Closing
The crypto industry has had six years to implement the Travel Rule. Regulators have moved from guidance to enforcement. Banks are conditioning access on compliance attestations. The Wolfsberg Group is explicitly recommending payment refusal for non-compliant VASPs. The argument that “the ecosystem isn’t ready” is no longer a shield — it’s an admission of unmanaged risk.
For compliance leaders, the path forward is clear: treat Travel Rule implementation as an urgent, board-level priority. Audit your current state, select an interoperable solution, build your counterparty VASP due diligence framework, and document every policy decision. The VASPs that solve this first won’t just avoid enforcement — they’ll become the trusted counterparties that the rest of the ecosystem needs to do business with.
The Travel Rule isn’t coming. It’s here. The only question is whether your firm will be ready when the examiner arrives — or when your correspondent bank calls.
Need Expert AML/CFT & RegTech Guidance?
17+ years across FATF, CBUAE, VARA & NRB. Visit our website for consultancy services tailored to your organization.
“Your compliance programme looks good on paper.
But will it survive a regulatory examination?”
