Skip to content
← Back to the list

Crypto Travel Rule Compliance Checklist for Exchange Operators

Crypto Travel Rule Compliance Checklist for Exchange Operators

Your withdraw rail can freeze the day a counterparty asks for originator data you never stored. The crypto travel rule requires regulated platforms (VASPs) to collect, hold, and send sender and recipient details with qualifying transfers – like a wire memo that travels with the payment. Use this checklist to map corridors, pick a messaging path, lock fields and thresholds, wire deposit and withdrawal ops, then run go-live and first-30-days controls.

Summary: Map which products and corridors trigger Travel Rule under FATF, FinCEN, and EU TFR. Choose native protocol, vendor hub, or hybrid for reachability. Ship an IVMS101-class field pack, jurisdiction thresholds, and self-hosted wallet checks. Wire checks into withdraw/deposit UX with a silent-counterparty playbook, then audit retention and match-rate KPIs for 30 days.

SERP pages explain FATF Recommendation 16 or sell hubs; operators need a printable sequence. Plain terms: a VASP is a virtual asset service provider (exchange, custodian, broker); originator is the sender; beneficiary is the recipient; IVMS101 is a shared field layout, not a transport wire. Not legal advice. Broader legal stack: crypto exchange compliance checklist for founders – this guide stays on Travel Rule messaging and ops.

Map when Travel Rule applies to your products and corridors

Travel Rule thresholds comparison: FATF USD/EUR 1,000, FinCEN $3,000 CVC, EU TFR all-amount CASP with self-hosted checks over €1,000

Start with a corridor map, not a vendor demo. List paths where value leaves or enters custody: spot withdrawals, deposits from another VASP, custody moves that look like customer transfers, and P2P if you are the VASP in the middle. Mark self-hosted (unhosted) wallets separately – EU rules often add ownership checks.

Three planning clusters (reconfirm locally):

  • FATF baseline: full info generally above USD/EUR 1,000; below – names + wallet/account unless ML/TF suspicion
  • US FinCEN / FIN-2019-G001: CVC at or above $3,000; info before or at transfer; messaging need not share the chain rail
  • EU TFR (EU) 2023/1113 from 30 Dec 2024: CASP crypto transfers in-scope at all amounts; over €1,000 with a self-hosted address – assess/verify customer ownership or control

In practice: use the strictest rule per corridor. License shopping stays in crypto exchange license jurisdiction (MiCA / VARA).

  1. Inventory products: spot withdraw, deposit, custody transfer, P2P if VASP-touching.
  2. Tag each corridor hosted-to-hosted vs hosted-to-self-hosted.
  3. Assign FATF / US / EU-TFR (or local) rule set per corridor.
  4. Flag sunrise risk: peers that cannot yet receive Travel Rule messages.
  5. Freeze a one-page applicability matrix before any protocol vendor call.

Important: Software hooks are not a license. Travel Rule tooling supports compliance; it does not replace registration or the AML program in the AML software modules guide.

Compare messaging paths: native VASP protocol vs vendor hub vs hybrid

Messaging path comparison table: native protocol vs vendor hub vs hybrid for Travel Rule reachability, cost, and fit

Choose how messages move between VASPs. Native means you integrate protocols yourself (TRP, OpenVASP, TRISA, and similar). A vendor hub abstracts multi-protocol reachability behind one API. Hybrid keeps a primary path plus a fallback hub.

Criteria Native protocol Vendor hub Hybrid
Reachability Same-stack peers only Broad multi-protocol reach Primary + hub fallback
Build cost Higher eng, own stack Lower eng, vendor fees Medium eng, dual ops
When it fits Few corridors, strong in-house Fast go-live, many peers Scale + control, mixed peers

IVMS101 is the field model; protocols and hubs are transport. Do not lock one vendor as mandatory. Ask white-label providers who owns TR integration, audit logs, and data residency – see white label vs build a crypto exchange.

Recommendation: Default to hub or hybrid for first corridors unless eng already runs a multi-protocol stack. Document discovery timeouts and the ops response when discovery fails.

Lock data fields, thresholds, and beneficiary verification

Dark checklist UI: IVMS101 fields, jurisdiction thresholds, and beneficiary verification

Build a field pack before UX mocks. Originator fields (regime-dependent): name, account or wallet, plus address or national ID / date and place of birth. Beneficiary fields usually start with name plus account or wallet. Keep the pack IVMS101-compatible.

Criteria FATF baseline US FinCEN EU TFR (CASP)
Threshold USD/EUR 1,000 full info above $3,000 CVC (Funds Travel Rule) All amounts CASP to CASP
Self-hosted Risk-based / local law Confirm with counsel Over €1,000 ownership check
Retention Confirm local (often multi-year) Plan ~5 years (confirm MSB) 5 years (+ optional +5)

Confirm non-primary corridors with counsel before hardcoding thresholds. Plan retention at least 5 years (then align locally). Screen payloads against sanctions at the same release decision. Missing info needs a written procedure: request, delay, refuse, or restrict.

  1. Publish the IVMS101 field matrix per corridor cluster.
  2. Encode threshold logic separately from UX copy.
  3. Define beneficiary verification on outbound rails.
  4. Add EU self-hosted ownership checks above €1,000 where TFR applies.
  5. Document missing-info request/delay/refuse SOP.

Popular mistake: one global form that ignores EU all-amount CASP crypto transfers while assuming the US $3,000 line everywhere.

Wire Travel Rule into deposit and withdrawal ops without killing UX

Compliance messaging and the chain rail can be different systems (FinCEN FIN-2019-G001). Design Travel Rule as a gate with clear states, not a silent hang.

  1. Collect originator fields once in KYC; ask only for delta data at withdraw.
  2. Resolve the counterparty VASP before broadcasting when policy requires pre-transfer messaging.
  3. Show async states: pending discovery, pending response, ready, failed.
  4. On deposit from another VASP, accept inbound data, match the credited account, queue exceptions.
  5. Attach sanctions screening to the same release decision.
  6. Document sunrise / no-response playbook: delay, request info, refuse, or restrict; for EU, escalate repeated missing-info failures toward competent authority notice.

Never leave “waiting forever” as the default. Turnkey stacks such as White Label Exchange should expose TR hooks, audit logs, and Monitoring Services in the contract – still diligence the integration yourself.

In practice: Test unhappy paths first – unreachable VASP, partial IVMS payload, self-hosted address above €1,000 – before marketing “Travel Rule ready.”

Run go-live controls, audit trail, and first 30 days monitoring

Soft-launch a small corridor set before opening every chain and country.

Before public corridors

  • Applicability matrix signed by compliance and ops
  • Messaging path, credentials, and data residency documented
  • Field/threshold pack in staging with sample IVMS101 payloads
  • Withdraw/deposit exception queues staffed; retention controls live
  • Silent-counterparty and repeated-failure procedures written

First 30 days KPIs

  • Match rate and timeout rate (discovery/response past SLA)
  • Manual review queue age; self-hosted ownership checks above €1,000 (EU)
  • Weekly sample audit: random transfers vs stored payloads

What next: freeze the corridor map, pick messaging path, ship the field pack, wire UX fail states, soft-launch, then watch KPIs. For branded exchange infrastructure with compliance-oriented monitoring, review White Label Exchange and guides on the blog – counsel remains the final gate.

Material verified: White Label Exchange Editorial.
Data reliability: Thresholds and dates checked against FATF VA/VASP guidance, FinCEN Funds Travel Q&A / FIN-2019-G001, and the official EU TFR summary ((EU) 2023/1113) as of August 2026. Ahrefs (US) for keyword clusters. Not legal advice.

Frequently asked questions

What is the Travel Rule in crypto?

FATF Recommendation 16 for virtual asset transfers: VASPs obtain, hold, and transmit originator and beneficiary information with qualifying transfers under local law (FinCEN, EU TFR, and peers). Map corridors to the local rule before buying software.

What does the Travel Rule require of VASPs?

Identify in-scope transfers, verify customer data, discover the counterparty when required, send or receive an IVMS101-class payload, retain records, screen as required, and escalate missing data under written policy.

What is the Travel Rule threshold (FATF vs US vs EU)?

FATF commonly cites USD/EUR 1,000 for full accurate information. US FinCEN uses $3,000 for covered CVC transmittals. EU TFR treats CASP crypto transfers as in-scope at all amounts in practice, with self-hosted ownership checks above €1,000. Use the strictest applicable corridor.

How does FATF Travel Rule differ from FinCEN Travel Rule?

FATF sets the global standard language; FinCEN is the US BSA implementation with a $3,000 trigger for money transmitters including convertible virtual currency under FIN-2019-G001. US plus EU users means more than one threshold on the rails.

Do white label exchanges include Travel Rule?

Ask for TR hooks: API or hub support, IVMS-class payloads, audit logs, and who owns configuration. Software is not a license. Confirm Monitoring / compliance modules in the contract, then complete the corridor checklist above.

How do self-hosted wallets work under Travel Rule?

Rules are risk-based and local. Under EU TFR, for transfers over €1,000 involving a self-hosted address, the CASP must assess or verify customer ownership or control. Build that check into withdraw and deposit flows.

What if the counterparty VASP does not respond?

Follow documented policy: delay, request information, refuse, or restrict the relationship. Under EU practice, repeated failures can require notice to the competent authority – log every attempt.