Regulated virtual asset service providers operate under a compliance clock that started ticking the moment FATF Recommendation 15 extended the Travel Rule – the obligation to pass originator and beneficiary identification data alongside every qualifying transfer – to virtual asset businesses. As supervisory bodies from ESMA under MiCA to VARA in Dubai and MAS in Singapore sharpen their examination playbooks, the gap between a paper policy and a genuinely defensible AML program has become the single most common reason a licence application stalls or a correspondent banking relationship collapses. Operating without a complete, evidence-ready compliance structure risks enforcement action, frozen payment rails and the loss of banking – consequences that arrive faster in digital assets than in any other regulated sector.
A Travel Rule compliance program for a regulated entity is not a checkbox exercise. It is a layered legal and operational architecture that connects your KYC framework (the policies governing customer due diligence), your transaction monitoring system, your counterparty VASP screening process and your Travel Rule data-transmission mechanism into a single auditable whole. This page sets out the regulated basis, the program components, the cross-border realities and the decision matrix operators need before they engage counsel or a compliance vendor.
The Regulated Basis: Why the Travel Rule Has Real Teeth Now
The Travel Rule carries enforceable weight in every major licensing jurisdiction because it is a direct expression of FATF Recommendation 15, which national legislators and regulators have transposed into their domestic VASP or CASP regimes. Under MiCA, the EU's Transfer of Funds Regulation (TFR) extension to crypto-assets requires originator and beneficiary information to travel with every transfer regardless of value. MAS under the Payment Services Act imposes the same obligation on Digital Payment Token service providers. VARA in Dubai builds Travel Rule compliance into its activity-specific rulebooks. The FCA in the United Kingdom enforces the rule through the Money Laundering Regulations. Across all of these regimes, the obligation is structural: it cannot be satisfied by a vendor subscription alone.
In our cross-border practice, we see a consistent pattern. Firms that entered regulated markets between 2020 and 2023 adopted compliance programs built for the prior, lighter-touch AML registration model. Regulators in the leading hubs now expect something materially different: a program that is jurisdiction-specific, senior-accountable, technically implemented and regularly tested. The delta between those two standards is where enforcement risk lives.
The cross-border dimension intensifies the problem. A VASP licensed in one jurisdiction and serving users in another operates under the originating jurisdiction's Travel Rule threshold and data format requirements – but also under the receiving jurisdiction's rules when its counterparty VASP is domiciled abroad. Where those rules diverge, the obligation defaults to the stricter standard. No single vendor protocol resolves that conflict; legal analysis must.
What a Defensible Program Actually Contains
A complete Travel Rule compliance program for a regulated entity has six interdependent components; a weakness in any one exposes the others to audit criticism.
First, policy architecture. The AML/CFT policy suite must reflect the specific activities licensed, the jurisdictions of operation and the user base. A custody-only entity faces different exposure than a full-service exchange. Policies that copy a template from a foreign jurisdiction without localization fail at the first supervisory review.
Second, the KYC framework – the customer identification, verification and risk-rating procedures – must be calibrated to the business model. Institutional counterparties, retail users and nested VASPs each require a distinct due diligence track. The framework must address enhanced due diligence triggers and document the risk appetite in writing.
Third, transaction monitoring: the rules-based and, increasingly, analytics-based systems that flag suspicious activity in real time. Regulators now expect the monitoring logic to address both fiat on/off-ramp flows and on-chain activity. A monitoring system that covers only the fiat leg is, in the view of most supervisors, incomplete.
Fourth, Travel Rule data collection and transmission. The firm must be able to collect originator and beneficiary data at the point of transaction, screen the counterparty VASP for licensing status and sanctions exposure, and transmit the data through a compliant protocol. Where the counterparty VASP cannot receive Travel Rule data – the so-called sunrise problem – the firm must have a documented policy for managing those transfers, including the option to decline.
Fifth, the sanctions and adverse media screening layer. Travel Rule data is only useful if it connects to a live screening system. A transfer passing clean through KYC can still breach sanctions obligations if the underlying wallet address is designated. The screening feed must be current and the match-review workflow must be senior-accountable.
Sixth, governance: the appointment and empowerment of a MLRO (Money Laundering Reporting Officer), board-level sign-off on the policy suite, a training calendar and a documented testing cycle. Regulators audit governance evidence as a proxy for culture. A program that exists only in PDFs without board minutes, training records and test results is legally insufficient.
To begin mapping where your current program has gaps, contact OBOLUS at info@oboluslaw.com. The process above describes the standard architecture. Your entity structure, licence category and user geography change the analysis materially.
What Goes Wrong: The Five Recurring Failures
The most consequential Travel Rule compliance failures share a short list of root causes, and in our practice we encounter them with enough regularity to treat them as a diagnostic checklist.
Failure one: treating the Travel Rule as a data-transfer problem, not a legal obligation. Vendors sell Travel Rule transmission protocols. Transmission is necessary but not sufficient. The legal obligation is to perform the underlying due diligence, to make a documented risk decision and to escalate where the counterparty VASP cannot be verified. A firm that transmits data without performing that verification has implemented the technical layer and missed the legal layer entirely.
Failure two: threshold confusion across jurisdictions. The data-sharing threshold – the transfer value above which Travel Rule obligations attach – varies by jurisdiction and, in some regimes, is set at zero for transfers between unhosted wallets. An operator running a multi-jurisdictional book must map each jurisdiction's threshold separately and programme the monitoring logic accordingly. A single global threshold calibrated to the most permissive standard will breach the rules of the strictest.
Failure three: no unhosted-wallet policy. Transfers to or from self-custodied wallets sit in a regulatory grey zone that is narrowing fast. MiCA's TFR extension and MAS guidance both impose identification and verification obligations on unhosted-wallet transfers above the applicable threshold. A firm with no unhosted-wallet policy, or a policy that defers the question, will fail a targeted examination on this point.
Failure four: the MLRO in name only. Regulators require an MLRO who has genuine authority, adequate resource and direct board access. An MLRO who doubles as the CFO, has no compliance headcount beneath them and cannot demonstrate a reporting line to the board is a regulatory liability, not a compliance officer.
Failure five: static programs. A compliance program built in year one and not materially updated is, by year three, almost certainly out of compliance. Regulatory guidance evolves. Transaction typologies change. A program must be tested, documented as tested, and updated on a defined cycle.
The Cross-Border Reality: One Program Is Never Enough
A single offshore licence does not satisfy the Travel Rule obligations of every jurisdiction in which a VASP serves clients – and this remains one of the most damaging assumptions we encounter when advising operators at the bottom of the funnel. The obligation follows the transaction, not the entity's domicile.
A VASP licensed under the BVI FSC VASP Act and serving users in Singapore must satisfy MAS's Travel Rule standards for those Singapore-user transactions. The same firm serving EU users must comply with the TFR as applied under MiCA. The BVI licence does not substitute for either. What it does is provide a credible licensing home; what it does not do is export its compliance standards to every jurisdiction the firm touches.
In practice, this means the compliance program must be architected at two levels. The base layer is the domestic program required by the licensing jurisdiction. The overlay is the set of additional obligations triggered by the jurisdiction of users, counterparty VASPs and correspondent banks. For most regulated entities operating across more than two significant markets, those overlay obligations materially expand the program beyond what the base-layer regulator requires.
Banking is the lever. Correspondent banks and EMI partners are, effectively, a second compliance regulator. They conduct their own Travel Rule audits on VASP clients and will close accounts where the program does not meet their internal standards – which are frequently stricter than the licensing regime's minimum. We map the licence, AML and banking stack together, because a firm that passes its licensing examination but fails its bank's due diligence has solved the wrong problem.
In Practice: Rebuilding a Program Under Regulatory Pressure
In a recent matter, a regulated exchange operating under a European CASP authorisation received a supervisory letter citing material deficiencies in its Travel Rule data-collection process and its unhosted-wallet policy. The firm had a compliant-on-paper policy suite but had not implemented the unhosted-wallet verification workflow in its onboarding system, and its MLRO had no documented authority matrix. We conducted a gap analysis against the applicable MiCA requirements and the firm's banking partner's own compliance standards, rebuilt the unhosted-wallet policy and the counterparty VASP screening workflow, and worked with the MLRO to document the authority structure and the board reporting line. The supervisory review concluded without further escalation. The firm's banking relationship was preserved. The resolution took a matter of weeks, not months, because the gap analysis identified the precise deficiencies rather than requiring a full program rebuild.
Decision Matrix: Which Program Architecture Fits Your Profile
Not every regulated entity needs the same program depth. The right architecture depends on three variables: licence category, geographic footprint and transaction volume profile.
Profile A – single-jurisdiction exchange, retail focus, moderate volume. The priority is a complete base-layer program: KYC framework, transaction monitoring calibrated to retail typologies, a functioning Travel Rule transmission protocol and a qualified MLRO. The unhosted-wallet policy is a near-term priority given the direction of regulatory guidance. Timeline to a defensible program: typically measured in weeks from a clean gap analysis. Key risk: underestimating the monitoring build, which takes longer than the policy drafting.
Profile B – multi-jurisdiction operator, institutional and retail mix. Base-layer plus overlay architecture is required from day one. The KYC framework must have distinct tracks for institutional counterparties and nested VASPs. Transaction monitoring must cover both fiat and on-chain legs. Travel Rule data must be reconciled across the threshold and format rules of each active jurisdiction. The MLRO function almost certainly requires dedicated headcount. Timeline: materially longer; the overlay analysis drives the project. Key risk: building the base-layer program in isolation and discovering the overlay obligations after the banking onboarding.
Profile C – licensed custodian, no retail execution. Travel Rule obligations are narrower but not absent. Custody transfers above the applicable threshold still require originator and beneficiary data. The KYC framework is typically more intensive at onboarding and less continuous. The MLRO function can often be shared with a sister entity if the governance documentation supports it. Key risk: assuming custody is low-risk from an AML perspective; in-scope assets can be large and the underlying beneficiaries complex.
Profile D – early-stage entity pre-licence, planning ahead. Building the compliance program in parallel with the licence application is materially more efficient than retrofitting it after authorisation. Regulators in most flagship hubs now expect a complete draft program at the point of application. A program built for the licence application also accelerates the banking onboarding. Key risk: over-engineering the program for a business model that will evolve; the program must be proportionate to actual current operations while demonstrating scalability.
If a prior compliance review identified deficiencies, or if a supervisory letter has been received, contact OBOLUS now at info@oboluslaw.com. A second-read gap analysis can surface the structural issue and the route to resolution.
A Common Assumption Worth Addressing Directly
A common assumption among operators entering regulated markets is that Travel Rule compliance is primarily a technical problem – one that a vendor subscription resolves. This underestimates the legal exposure by a significant margin.
The vendor provides the transmission infrastructure. The law requires the firm to perform the underlying due diligence, to document the risk decision, to maintain the counterparty VASP screening record and to retain that record in a form the regulator can audit. A firm that has deployed a Travel Rule protocol but has not built the surrounding legal architecture – the KYC framework, the MLRO authority structure, the board-sign-off cycle – has satisfied the technical obligation while remaining legally exposed on the substantive one.
We have also seen the inverse: a firm with excellent internal policies that has not deployed a functioning Travel Rule transmission protocol. In that case, the legal framework is sound but the operational implementation is missing. Both failures produce the same supervisory outcome. The program is only defensible when the legal and technical layers are aligned and documented together.
Self-Assessment: Is Your Program Ready for Examination?
The following questions reflect the audit criteria applied by supervisors in the leading licensing jurisdictions. A "no" or "uncertain" answer on any item is a material risk indicator.
- Does your AML policy suite specifically address your licensed activities and the jurisdictions of your user base?
- Do you have a written counterparty VASP screening procedure that covers licensing status, sanctions exposure and Travel Rule capability?
- Is your unhosted-wallet policy documented, implemented in your onboarding system and tested?
- Does your transaction monitoring cover both fiat and on-chain transaction legs?
- Is your MLRO formally appointed, with a documented authority matrix, direct board access and adequate compliance resource?
- Has your compliance program been independently tested in the last twelve months, with the results documented and reported to the board?
- Do you have a documented Travel Rule threshold map for each active jurisdiction?
- Does your compliance program meet the standards of your correspondent bank or EMI partner – not just your licensing regulator?
If any of these questions surfaces uncertainty, the gap analysis is the right first step.
Related at OBOLUS
- AML and Travel Rule compliance for digital-asset businesses – the full practice overview covering the regulatory regime and our approach
- Transaction monitoring setup in South Africa – jurisdiction-specific guidance on AML monitoring obligations under the South African regime
- Travel Rule compliance program for early-stage founders – a streamlined program path for pre-licence and newly authorised entities
FAQ
What does the Travel Rule require from a VASP?
The Travel Rule requires a virtual asset service provider (VASP) to collect, verify and transmit originator and beneficiary identification data alongside every qualifying transfer. The obligation applies to both the originating and the beneficiary VASP. The data threshold above which the obligation attaches, and the required data fields, are set by the applicable domestic regime transposing FATF Recommendation 15 – and these vary by jurisdiction. Where the counterparty VASP cannot receive the data, the originating firm must have a documented policy for managing or declining the transfer.
Who must act as MLRO for a crypto firm?
A Money Laundering Reporting Officer (MLRO) must be a named, senior individual with formal authority to receive and assess internal suspicious activity reports, to file external reports with the financial intelligence unit and to access all relevant business lines. Most licensing regulators – including under MiCA, VARA, the FCA and MAS – require the MLRO to be approved or notified and to demonstrate independence from commercial operations. A compliance consultant can support the function but typically cannot substitute for an accountable senior individual who is employed by or formally engaged with the firm.
How do regulators audit crypto AML programs?
Regulators in the leading hubs conduct AML audits through a combination of desk-based document reviews and on-site examinations. They typically request the AML policy suite, the risk assessment, MLRO appointment records, training logs, a sample of CDD files and monitoring alerts, and Travel Rule transmission records for a defined transaction population. They test the gap between the written policy and the operational implementation. Firms that cannot produce current, complete records – not just the policy documents – are the ones that generate enforcement referrals. The audit standard has materially tightened since MiCA took effect across the EU.
OBOLUS is an independent digital-asset law boutique acting only for businesses. We advise exchanges, custodians, token issuers and funds on licensing across 70+ jurisdictions, on disputes and on-chain asset recovery across 25+ forums, and on the AML, Travel Rule and KYC compliance that connect those layers. Digital assets are the whole of our practice. We map the licence, compliance and banking stack before you commit – and we work alongside forensic partners to convert on-chain evidence into court-ready disclosure applications when recovery is needed. To discuss your compliance program, contact info@oboluslaw.com or reach us at t.me/oboluslaw.
By Victor Olsen, Regulatory & Compliance Analyst – specialising in AML program architecture, Travel Rule implementation and cross-border VASP compliance across the EU, UAE and Asia-Pacific licensing regimes.
This publication is general information about the law and does not constitute legal advice. It is not a substitute for advice tailored to your circumstances. OBOLUS accepts no liability for action taken or not taken on the basis of this material. For advice on your situation, contact info@oboluslaw.com.