What FATF Is and Why It Matters
The Financial Action Task Force is the global standard-setter for anti-money-laundering and counter-terrorist-financing. It does not make law directly; instead, its 40 Recommendations are implemented by over 200 jurisdictions, and FATF evaluates how well each one complies. Falling short risks grey-listing — with serious consequences for a country's financial sector.
For crypto, FATF's influence is decisive: when FATF sets a standard for virtual assets, national regulators follow. That is exactly what happened with the Travel Rule.
Recommendation 16 — The Travel Rule
In 2019 FATF updated its guidance to apply Recommendation 16 — originally written for bank wire transfers — to virtual asset service providers (VASPs). The rule requires that, when a VASP sends a virtual-asset transfer, it obtains and transmits required originator and beneficiary information to the receiving VASP, and that both screen for sanctions and suspicious activity.
FATF sets a de minimis threshold of USD/EUR 1,000, below which a reduced data set may apply. This is a key difference from the EU regime, which removed the threshold for crypto entirely.
FATF Standard vs the EU's TFR
The EU implemented FATF's Travel Rule through the recast Transfer of Funds Regulation (EU) 2023/1113 — but went further in places:
| Aspect | FATF Rec. 16 | EU TFR 2023/1113 |
|---|---|---|
| Threshold | USD/EUR 1,000 | No threshold for crypto |
| Self-hosted wallets | Risk-based | Verification over €1,000 |
| Legal force | Standard (soft law) | Directly applicable regulation |
| Scope | VASPs | Authorised CASPs |
So an EU CASP must meet the stricter EU rules; a firm operating across borders must satisfy each jurisdiction's local implementation of the FATF baseline.
The Sunrise Problem
The Travel Rule only works if both the sending and receiving providers can exchange data. Because jurisdictions adopted the rule at different times, providers in "sunrise" countries (rule live) must transact with counterparties in jurisdictions where it is not yet enforced — the so-called sunrise problem.
The practical answer is a combination of interoperable Travel Rule messaging protocols, counterparty due diligence, and risk-based policies for transfers to providers that cannot yet receive Travel Rule data. EU CASPs need a documented stance on how they handle non-compliant counterparties.
How Jurisdictions Have Implemented It
Implementation varies, but the direction is uniform. The EU, United Kingdom, Switzerland, Singapore, Japan, Canada, and many others have enacted Travel Rule obligations, each with their own thresholds and self-hosted-wallet treatment. Some apply the FATF USD/EUR 1,000 threshold; the EU applies none. Firms passporting an EU licence still face local Travel Rule rules anywhere they serve customers outside the EU.
For businesses weighing where to base, this is one more reason the EU's harmonised regime under MiCA is attractive: one rulebook across 27 states.
What This Means for Your Business
Whether you call it the FATF Travel Rule or the EU TFR, the operational requirement is the same build: collect and transmit originator/beneficiary data, identify counterparties, verify self-hosted wallets where required, screen for sanctions, and document how you treat non-compliant counterparties. We integrate this into a CASP's wider AML programme so the global standard and the EU rules are satisfied together.