EST · MMXXVI
Home/Jurisdictions/Eu Mica/Travel rule compliance program in European Union (MiCA)
Compliance, AML & Travel Rule

Travel rule compliance program in European Union (MiCA)

Travel rule compliance program in European Union (MiCA). Cross-border digital-asset legal counsel for business – licensing, disputes and structuring. Talk to OB

A payments company operating a CASP (crypto-asset service provider) authorised under MiCA (the Markets in Crypto-Assets Regulation) faces an immediate compliance reality: every transfer of virtual assets above the applicable threshold must carry verified originator and beneficiary data. That obligation – known as the Travel Rule (the requirement to transmit identifying information alongside a virtual-asset transfer) – is now enforceable across the EU and EEA under the supervision of ESMA and national competent authorities. Firms that built their programs around pre-MiCA AML registrations are discovering that the new regime demands materially more than a name-and-address check. This page sets out what a compliant Travel Rule compliance program looks like under MiCA, how regulators are testing it, and where the cross-border complications arise for inbound operators.

What does the Travel Rule require under MiCA?

Under MiCA and the directly applicable EU Transfer of Funds Regulation (TFR) as extended to crypto-assets, a CASP must collect, verify, and transmit a defined set of originator and beneficiary data with every virtual-asset transfer – regardless of whether the counterpart institution is inside or outside the EU. The obligation applies to the sending CASP, the receiving CASP, and to any intermediary in the chain. Failure at any node breaks the compliance record for the entire transfer.

The data set required on the originator side includes full legal name, account identifier (typically a blockchain address or internal account reference), and – above the relevant threshold – a physical address or national identification number. Beneficiary data requirements mirror this structure. ESMA and the European Banking Authority have issued joint guidance on how the obligation interacts with pseudonymous blockchain addresses, a technically complex area that earlier EU AML frameworks did not contemplate.

The threshold above which the full data set is mandatory varies by the nature of the transfer and whether counterpart identification has been completed. Below that threshold, a lighter data set applies – but it does not disappear. Firms sometimes assume that small-value transfers fall entirely outside the regime. They do not; a reduced data obligation is not a zero obligation, and regulators have cited this misreading in enforcement correspondence.

One dimension that catches inbound operators by surprise is the unhosted-wallet rule: transfers to or from a wallet not held at a regulated CASP trigger additional due-diligence requirements rather than exemption. A program that addresses only inter-CASP transfers is structurally incomplete under the MiCA framework.

To map your firm's specific data-transmission obligations under the EU Travel Rule regime, contact OBOLUS at info@oboluslaw.com. The analysis above describes the standard path. Your entity structure, the user base you serve, and the transfer corridors you operate across will change the compliance architecture significantly.

Who is caught by the MiCA Travel Rule – and who is not?

Any CASP authorised under MiCA that initiates, intermediates or receives a virtual-asset transfer is subject to the Travel Rule obligation. That covers exchanges, custodians, transfer-and-settlement service providers, and – where their activity involves moving assets between accounts – lending and staking platforms. The authorisation itself is not the gateway to the obligation: a firm providing services into the EU without a CASP authorisation is still subject to the rule as a matter of EU law, though its primary exposure in that case is the unlicensed-activity risk.

Certain categories are excluded or treated differently. Pure peer-to-peer transfers with no CASP involvement fall outside the regulated perimeter, as do transfers between a CASP and its own wallets (subject to proper internal record-keeping). NFT platforms and DeFi protocols occupy a contested space: MiCA expressly carves out fully decentralised arrangements without an intermediary, but national competent authorities have signalled that they will look at substance over label. A platform that controls smart-contract keys or operates an order-routing layer is unlikely to sustain a decentralised-protocol exemption.

For an inbound operator – a firm licensed in Singapore under the MAS Payment Services Act, for example, or registered in the BVI under the VASP Act 2022 – the Travel Rule obligation arises on the EU side of every transfer involving an EU-authorised counterpart. The non-EU firm does not hold a CASP licence, but its EU counterpart must satisfy itself that the incoming transfer carries compliant data. In practice, this means that non-EU CASPs serving EU-regulated correspondents need Travel Rule-compliant messaging infrastructure or they will find transfer relationships terminated.

What does a compliant Travel Rule program look like in practice?

A compliant Travel Rule compliance program under MiCA is not a single policy document; it is an integrated operational system with four interconnected layers. Building only one or two layers – the most common gap we see in firms transitioning from pre-MiCA registrations – leaves a program that will not survive a regulatory review.

The first layer is data collection and verification at origination. Before a transfer is initiated, the sending CASP must have completed KYC on the originator to the standard required by the applicable AML regime, recorded the relevant identifiers, and structured that data in a format capable of transmission. Many firms collect the right data during onboarding but store it in a format incompatible with their transfer-messaging infrastructure – creating a gap between the KYC framework and the Travel Rule execution layer.

The second layer is the transmission mechanism. Data must travel with the transfer, not alongside it in a separate communication. Several Travel Rule solution providers operate interoperable messaging protocols in the EU market. The firm must select a protocol, integrate it into its core transfer system, and establish counterpart connectivity. Where a counterpart CASP is not on the same protocol, the sending firm must have a documented escalation procedure – including a decision rule on whether to proceed, pause or decline the transfer.

The third layer is transaction monitoring and screening. Incoming and outgoing transfers must be screened against sanctions lists (including EU consolidated sanctions and OFAC designations where the firm has US-facing activity), and monitored for typologies associated with layering and structuring. The monitoring program must be calibrated to the firm's specific asset classes and transfer corridors – a one-size-fits-all rule set drawn from traditional banking will miss crypto-specific patterns.

The fourth layer is the governance and escalation structure, which includes a designated MLRO (Money Laundering Reporting Officer), documented escalation paths, a suspicious-transaction reporting process, and a periodic testing and review cycle. Regulators across the EU – particularly the Bank of Lithuania and the MFSA in Malta, which supervise a significant share of CASPs authorised under the pre-MiCA EU regime – have made governance deficiencies a priority in supervisory reviews.

Who carries the compliance mandate – and what does an MLRO need to know?

The MLRO role under the MiCA-aligned AML regime carries personal accountability: the individual is responsible for overseeing the firm's AML and Travel Rule compliance, filing suspicious-transaction reports, and being the named point of contact for the national competent authority. Appointing a token MLRO – someone holding the title without the authority, budget or operational access – is a well-documented failure mode that regulators treat as a governance finding, not a minor procedural gap.

The MLRO must understand virtual-asset mechanics at a functional level. An officer who cannot read a blockchain explorer, distinguish between a custodial and non-custodial transfer, or identify the indicators of mixer usage will not be able to make defensible escalation decisions. In our cross-border practice, we regularly advise firms whose MLRO appointments were challenged during regulatory review because the individual lacked documented crypto-specific training and had no practical familiarity with the firm's transfer infrastructure.

For firms operating across multiple EU member states under a CASP passport, the MLRO question has an additional dimension: the home-state competent authority supervises the AML program, but host-state authorities retain concurrent rights to request information and take supervisory action. The MLRO must be positioned to respond to both, and the compliance program must be documented in a form that a non-home-state regulator can assess without a full re-brief.

In a recent matter, a mid-size crypto exchange expanding from a Baltic member state into Western European markets discovered that its host-state regulator had a materially different expectation on unhosted-wallet due diligence than the home-state authority. We structured an overlay policy that satisfied both supervisory frameworks without requiring the firm to operate dual compliance programs – preserving the operational efficiency of the passport while closing the gap.

How do regulators audit MiCA Travel Rule compliance programs?

National competent authorities across the EU are moving from registration-era light-touch supervision to structured, risk-based audits of CASP compliance programs. The audit process typically unfolds in two phases: a document request and a follow-up examination, which may be desk-based or on-site.

The document phase covers the AML policy and procedures manual, the risk assessment (firm-level and product-level), the MLRO appointment and reporting lines, the transaction monitoring system configuration, evidence of staff training, and – specifically for Travel Rule compliance – records of data transmission for a sample of transfers. Regulators have increasingly requested the technical logs from Travel Rule messaging protocols, not just the policy documents that describe how they should work.

ESMA has signalled that it expects national competent authorities to converge on a common supervisory standard for Travel Rule implementation, with particular focus on unhosted-wallet controls and the treatment of transfers from non-EU CASPs. Firms that cannot demonstrate that incoming transfers from non-EU counterparts triggered appropriate due diligence – including a documented decision on whether the counterpart's AML regime is equivalent – are likely to receive a remediation notice.

The follow-up examination focuses on governance: regulators interview the MLRO, test the escalation decision-making process with hypothetical scenarios, and assess whether the compliance function has the authority and resources to act independently. A compliance program that exists on paper but that the business routinely overrides – accepting high-risk transfers at commercial pressure – is treated as a systemic failure, not an isolated incident.

Cross-border banking adds a practical dimension. The correspondent banks holding the CASP's fiat settlement accounts typically conduct their own periodic AML reviews of the CASP's compliance program. A regulatory finding on Travel Rule compliance often triggers a banking review within weeks. Firms that maintain compliant programs and can produce clean regulatory correspondence preserve their banking relationships; those that cannot frequently find account closure notices arriving alongside the regulatory remediation timeline.

If your compliance program is due for review or you are preparing for a regulatory examination, write to OBOLUS at info@oboluslaw.com. A prior application that stalled or a supervisory query that went unanswered has a known route back – but the window for managing it narrows once formal proceedings are opened.

How does the Travel Rule interact with cross-border banking and tax obligations?

The Travel Rule compliance program does not operate in isolation: it sits inside a broader compliance architecture that includes banking relationships, tax reporting, and – for firms operating across multiple jurisdictions – the interaction between EU MiCA obligations and non-EU regulatory regimes. Getting the compliance program right in Brussels or Frankfurt and wrong in Singapore or the BVI creates the same enforcement exposure as getting it wrong in both.

On the banking side, EU correspondent banks and payment processors require CASP clients to demonstrate a functioning Travel Rule program before extending or maintaining fiat settlement access. The bank's internal AML team will typically request the firm's AML policy, evidence of MLRO appointment, and – increasingly – a summary of Travel Rule protocol coverage and unhosted-wallet controls. A CASP that can produce these documents proactively, with a clear narrative on how the compliance program maps to the MiCA regime, shortens the bank's review cycle materially.

On the tax side, the EU's DAC8 regime – which extends automatic exchange of information to crypto-asset transactions – operates on a data set that overlaps significantly with Travel Rule originator and beneficiary information. Firms that have built clean Travel Rule data infrastructure are better positioned to satisfy DAC8 reporting obligations than firms whose data is incomplete or held in incompatible formats. We advise firms to design the data architecture once, to the highest applicable standard, and apply it across both regulatory regimes.

For firms with a non-EU parent or subsidiary structure, the interaction between MiCA's Travel Rule obligations and the rules of the non-EU jurisdiction matters. The FATF Recommendation 15 framework, which underlies Travel Rule obligations across most major hubs, sets a common baseline – but implementation details differ. A CASP authorised in the EU and sending transfers to a counterpart in a jurisdiction where the Travel Rule threshold or data-set requirement differs must apply the higher standard, or risk a compliance gap at the receiving end. We map these interactions routinely for operators who sit between two or more regulatory environments.

What are the most common mistakes in MiCA Travel Rule programs?

The most common structural failure is treating the Travel Rule as a data-collection obligation rather than a data-transmission obligation. A firm that collects all the right originator and beneficiary information but stores it in its CRM, rather than transmitting it via a compatible protocol at the moment of transfer, has not complied. The regulator's test is whether the data traveled with the funds – not whether the data exists somewhere in the firm's systems.

A closely related error is incomplete counterpart connectivity. Travel Rule messaging protocols are only useful if the counterpart CASP is also connected. Firms often implement a protocol, test it with a handful of major exchange counterparts, and consider the obligation satisfied. The gaps appear when a transfer is directed to a smaller CASP, a newly authorised platform, or a non-EU institution that is not yet on the same messaging network. A compliant program must document what the firm does in these gap cases – which may include holding the transfer, requesting the data by alternative means, or declining the transaction.

A common assumption in the market is that a single offshore CASP licence – for example, a registration in a low-requirement jurisdiction – provides a compliant basis for serving EU clients with EU Travel Rule exposure. It does not. The Travel Rule obligation under MiCA attaches to the EU side of the transfer, not to the licence status of the non-EU counterpart. A firm without a CASP authorisation serving EU-based users faces both unlicensed-activity exposure and, indirectly, causes its EU counterparts a compliance problem they will resolve by terminating the relationship.

Governance failures – an MLRO with insufficient authority, a transaction-monitoring system that was configured at onboarding and never recalibrated, a risk assessment that has not been updated since the firm launched new products – are the most frequently cited findings in supervisory correspondence we have reviewed. Each is correctable, but correction takes time. Firms that address these proactively, before a regulatory audit, are in a materially stronger position than those that begin remediation under supervisory pressure.

Related at OBOLUS:

FAQ

What does the Travel Rule require from a VASP?

The Travel Rule requires a CASP or VASP to collect, verify, and transmit identifying information about the originator and beneficiary of a virtual-asset transfer at the point the transfer is executed. Under the EU's extended Transfer of Funds Regulation as applied through MiCA, this includes full legal name, account identifier, and – above the applicable threshold – address or identification number. The obligation applies to sending, receiving and intermediary institutions. Transfers to unhosted wallets trigger enhanced due diligence, not exemption.

Who must act as MLRO for a crypto firm?

Under the MiCA-aligned AML regime, the MLRO must be a named individual with sufficient seniority, authority and operational access to oversee the firm's AML and Travel Rule compliance program, make suspicious-transaction filing decisions, and serve as the named regulatory contact. The role cannot be delegated to an external consultant without the national competent authority's acceptance of that arrangement. The MLRO must have documented crypto-specific knowledge – generic AML credentials without virtual-asset familiarity are increasingly treated as a governance deficiency.

How do regulators audit crypto AML programs?

Regulators typically begin with a structured document request: AML policy, firm-level risk assessment, MLRO appointment records, transaction-monitoring system configuration, staff training evidence, and Travel Rule transmission logs for a transfer sample. A follow-up examination tests governance – MLRO interviews, escalation scenario testing, and a review of whether the compliance function operates independently of commercial pressure. ESMA has signalled convergence on a common supervisory standard across member-state competent authorities, with particular focus on unhosted-wallet controls and non-EU counterpart due diligence.

OBOLUS is an independent digital-asset law boutique acting only for businesses. We advise exchanges, custodians, token issuers and funds on licensing across 70+ jurisdictions, on disputes and on-chain asset recovery across 25+ forums, and on the tax, banking and compliance that sit around them. We map the licence, AML and Travel Rule stack across operating, custody and payment layers before you commit to a structure. Digital assets are the whole of our practice. To discuss your situation, contact info@oboluslaw.com or message us at t.me/oboluslaw.

By Victor Olsen, Regulatory & Compliance Analyst – specialising in MiCA CASP authorisation, AML program design and Travel Rule implementation for EU-facing digital-asset businesses.

This publication is general information about the law and does not constitute legal advice. It is not a substitute for advice tailored to your circumstances. OBOLUS accepts no liability for action taken or not taken on the basis of this material. For advice on your situation, contact info@oboluslaw.com.

Tell us the task — we'll map your options in 30 minutes.

Fixed-fee packages with defined scope and SLAs. The first call is free and under NDA. Business clients only.

Map your optionsinfo@oboluslaw.com · t.me/oboluslaw · reply < 2 hours