The Financial Action Task Force (FATF) Travel Rule has reached 85 of 163 jurisdictions with passed legislation in 2026 — up from 65 a year earlier — but the binding compliance risk for crypto exchanges, custodians, and brokers is not coverage; it is the “sunrise gap” between jurisdictions that have laws on the books and those that actively enforce them, with roughly 59% of in-scope jurisdictions yet to issue any Travel Rule enforcement action.
The Travel Rule has been the most consequential cross-border crypto-compliance requirement of the post-2019 era, and the 2026 picture is now clearer than at any point since FATF’s revised Recommendation 15 took hold. The FATF’s own targeted update shows 85 jurisdictions out of 163 with passed Travel Rule legislation for virtual assets and service providers (VASPs), with another 14 actively working toward implementation — material progress against the prior cycle’s 65 jurisdictions. The European Union’s Transfer of Funds Regulation (TFR) took effect in December 2024 with no transaction threshold, the United Kingdom has enforced its version through the Financial Conduct Authority (FCA) since September 2023, and the United States operates the rule under the Bank Secrecy Act (BSA) with a USD 3,000 floor. On 18 June 2025, the FATF agreed to a significant revision of Recommendation 16 at its June 2025 Plenary, with the revised requirements coming into effect by the end of 2030. This Deep Dive walks through the rule, how four major regimes compare, the live enforcement context, and what compliance teams should do now.
Key Facts:
• 85 of 163 jurisdictions have passed Travel Rule legislation for virtual assets in 2026, up from 65 in the prior cycle; 14 more actively working — 21 Analytics summary of FATF Targeted Update
• Roughly 59% of jurisdictions with Travel Rule laws have not yet issued supervisory findings, directives, or enforcement actions tied to the rule — FATF 2025 Targeted Update
• EU’s Transfer of Funds Regulation (TFR) took effect December 2024, with no de minimis transaction threshold — Sumsub
• United States operates the Travel Rule under the Bank Secrecy Act with a USD 3,000 threshold — Sumsub
• Singapore’s Monetary Authority (MAS) requires all Digital Payment Token (DPT) service providers to comply with the Travel Rule — Sumsub
• FATF revised Recommendation 16 on 18 June 2025; revised requirements come into effect by end of 2030 — Mayer Brown client memo
• FATF Best Practices on Travel Rule Supervision were issued June 26, 2026 — FATF
Methodology and sources
This analysis rests on the FATF’s own 2025 Targeted Update on Implementation of the FATF Standards on Virtual Assets and VASPs, the June 2026 FATF Best Practices on Travel Rule Supervision, public statements from FATF President Elisa de Anda Madrazo (in office 2024–2026), and the Mayer Brown client memo on the June 2025 Recommendation 16 revisions. Jurisdictional snapshots draw on EU Regulation 2023/1113 (TFR), UK Financial Conduct Authority guidance from September 2023, US Bank Secrecy Act regulations, Monetary Authority of Singapore (MAS) Notice PSN02, and Japan Virtual Currency Exchange Association (JVCEA) guidance. The window is May 2025 through May 2026. Two caveats apply: the FATF Targeted Update is self-reported by jurisdictions and therefore over-counts paper compliance versus operational supervision, and the June 2025 Recommendation 16 revisions take effect by end-2030, meaning much of the implementation backdrop will keep moving across multiple consultation cycles.
What the rule actually requires
The Travel Rule, derived from FATF Recommendation 15 and the corresponding interpretive note, requires Virtual Asset Service Providers (VASPs) that send or receive a covered transaction above a defined threshold to collect and transmit specified originator and beneficiary information alongside the transaction. The required data set generally includes the originator’s and beneficiary’s name, account number, and physical or wallet address, and the rule extends to “unhosted wallet” (non-custodial) counterparty data in jurisdictions that have adopted the FATF’s interpretive notes in full. In practical terms, the requirement turns every cross-border crypto transfer above the threshold into a data-sharing transaction in parallel to the on-chain transaction itself.
The mechanical issue is interoperability. The Travel Rule does not specify a single technical standard for the data exchange, which has produced a fragmented vendor ecosystem (TRP, TRISA, OpenVASP, Sumsub-style integrators, native APIs from exchanges) and the well-documented “sunrise issue”: VASPs in compliant jurisdictions must exchange data with counterparts whose jurisdiction has not yet implemented, leaving them either to refuse the transaction, complete it on a best-effort basis, or fall back to manual reconciliation. The June 2026 FATF Best Practices document on supervision tries to harmonise expectations, but it does not solve the technical interoperability gap. The picture mirrors what we documented when the GENIUS Act and MiCA July 2026 stablecoin regimes split into divergent rulebooks — different jurisdictions adopt the standard, then diverge on the details that actually drive operational cost.
| Jurisdiction / Regulator | Status / date | Threshold | Key requirement | Penalty / sanction |
|---|---|---|---|---|
| EU (ESMA, EBA, national CAs under TFR) | Transfer of Funds Regulation in force from December 2024 | None (no de minimis) | Full Travel Rule data on every crypto transfer; CASP-to-CASP and CASP-to-unhosted-wallet rules | National CA enforcement; MiCA-style penalties under member-state implementing laws |
| UK (FCA) | Enforced under the Money Laundering Regulations since September 2023 | None (no de minimis) | FCA-supervised cryptoasset firms must collect/transmit Travel Rule data; sunrise-issue mitigation guidance | FCA Final Notices; unlimited civil penalties under the MLRs |
| US (FinCEN under BSA) | Long-standing BSA Recordkeeping & Travel Rules | USD 3,000 | Money services businesses (MSBs) including convertible-virtual-currency exchanges retain and transmit specified data above threshold | FinCEN civil money penalties; criminal referral under 31 U.S.C. §§5318/5322 |
| Singapore (MAS) | Notice PSN02 in force; all DPT providers in scope | None for DPT providers | All Digital Payment Token service providers must comply; cross-border counterparty due diligence | MAS supervisory actions; potential licence variation/withdrawal |
| Japan (JVCEA / FSA) | Crypto Travel Rule guidance in force since 2022 | None | Member exchanges apply to all customer-requested crypto transactions; KYC and counterparty data sharing | JVCEA disciplinary action; JFSA business-improvement orders |
Sources: Sumsub jurisdictional summary, FATF 2025 Targeted Update, EU Regulation 2023/1113, FCA MLRs guidance, FinCEN BSA recordkeeping rules, MAS Notice PSN02, JVCEA guidance. Last updated: May 24, 2026.
How the jurisdictions diverge
The most consequential divergence is the threshold. The EU’s TFR applies to every covered transfer, with no de minimis carve-out; the United States retains a USD 3,000 floor under the BSA; Singapore and Japan apply the rule to all in-scope crypto transactions. That single difference reshapes operational scope for global firms: a single exchange operating in the EU and the US must build to a no-threshold regime for the European book and a $3,000-threshold regime for the American book, with separate compliance pipelines for each. The second divergence is supervisory intensity. The FATF Targeted Update flags that roughly 59% of jurisdictions with passed laws have not issued any specific Travel Rule enforcement action, meaning the on-paper coverage map dramatically overstates the operational risk in practice — except where it doesn’t, and where it doesn’t is the FCA’s perimeter and the FinCEN MSB perimeter, both of which have produced fines.
The “sunrise issue” is the practical consequence. When a compliant EU CASP sends a transfer to a counterpart in a non-implementing jurisdiction, neither the originator nor the beneficiary side can reliably exchange Travel Rule data, and the compliant firm must decide whether to complete the transaction with caveats, hold it for manual review, or refuse it outright. As FATF President Elisa de Anda Madrazo framed the structural risk:
“The risks of virtual assets for money laundering and terrorist financing are no longer an emerging risk. Today, it is a real, substantive risk with growing impact.”
— Elisa de Anda Madrazo, President, Financial Action Task Force (FATF) (AML Intelligence)
Enforcement and live litigation context
Two enforcement vectors dominate. First, FinCEN’s track record under the BSA: the agency has used the recordkeeping and Travel Rule provisions as the foundation for several multi-hundred-million-dollar settlements over the past three years, with the typical pattern being missing or incomplete Travel Rule transmissions discovered in the context of broader AML programme failures. Second, the FCA: the UK perimeter has produced enforcement notices against MLR-registered cryptoasset firms specifically for Travel Rule gaps and for inadequate sunrise-issue mitigation. The CFTC’s parallel work on commodities-side jurisdiction over event contracts, covered in our analysis of how the CFTC’s grip on sports event contracts faces a circuit split, is structurally separate from Travel Rule enforcement but does affect which US agency is the relevant supervisor for hybrid asset categories. On the EU side, the same operational-resilience perimeter that we covered when DORA’s 19-provider critical-ICT oversight regime tightened in May 2026 determines which Travel Rule vendors face cross-cutting EU supervision, and the consolidated MiCA chapter on CASP authorisation governs the licensing perimeter where these obligations attach.
The enforcement picture is unbalanced. With 59% of in-scope jurisdictions yet to act, the operational risk concentrates in the FCA, FinCEN, MAS and BaFin perimeters. As the FATF President put it on enforcement gaps:
“it becomes a loophole to the extent that jurisdictions will not implement the standards of the FATF and in particular, the travel rules.”
— Elisa de Anda Madrazo, President, Financial Action Task Force (FATF) (AML Intelligence)
What this means for exchanges, brokers, and compliance teams
For VASPs operating across multiple jurisdictions, the operational map should be redrawn against the supervisory-intensity reality rather than the legislative coverage map. Build compliance for the lowest-threshold regime in scope (EU’s no-floor) and treat the BSA $3,000 floor as a sub-pipeline rather than the default. For broker-dealers and prime-brokerage businesses moving into crypto via a regulated wrapper — the pathway opened by the FINRA-cleared Securitize Markets template covered in our deep dive on how the SEC tokenized-stocks exemption stops at digital twins, not synthetics — the Travel Rule attaches to any covered transfer that the broker-dealer’s affiliated MSB initiates or receives, with the same originator/beneficiary data set. Custodians and clearing members should map vendor dependencies (TRP, TRISA, OpenVASP) against any DORA-style critical-ICT oversight that catches their providers. Asset managers and fund administrators should treat the June 2025 Recommendation 16 revisions as a multi-year build, not a 2026 deadline, but should already be aligning internal data taxonomies to the revised data set.
Legal and compliance teams should also flag the sunrise issue directly to risk committees: the binding question for many cross-border transactions is not “do we comply” but “does our counterparty’s regime allow them to comply,” which sits outside the firm’s control and produces operational risk that should be priced into transfer-corridor policies and not just AML budgets. The same MiCA-era harmonisation question raised in our coverage of how MiCA’s July 1 cliff and the UK’s CP26/13 pulled the crypto rulebooks apart applies to Travel Rule operations: harmonisation is the goal, divergence is the present.
What’s next — the forward view
Three workstreams will determine the picture into 2027 and beyond. First, the implementation of the June 2025 Recommendation 16 revisions, which extend Travel Rule-style transparency to specific funds transfers with a 2030 effective date — the long lead time gives firms room to absorb the cost, but the early-adopter regimes will set the pattern. Second, the FATF’s next Targeted Update, expected through 2026: the headline number to watch is whether the share of in-scope jurisdictions producing enforcement actions rises from the current 41% (the inverse of the 59% lag). Third, the EU operational perimeter — TFR enforcement is in its second year and is likely to surface its first wave of public CASP notices through 2026, which will reset the perceived compliance baseline globally. Until those signals print, the 85-jurisdiction milestone is a paper marker, not an operational one.
TL;DR
FATF Travel Rule coverage reached 85 of 163 jurisdictions in 2026 (up from 65), but roughly 59% of jurisdictions with passed laws have yet to issue a Travel Rule enforcement action, concentrating real operational risk in the FCA, FinCEN, MAS and EU TFR perimeters. The EU runs no de minimis threshold from December 2024; the US retains a USD 3,000 BSA floor; Singapore and Japan apply to all in-scope crypto transactions. The June 2025 Recommendation 16 revisions take effect by end-2030 and reshape the data set firms must collect. Compliance teams should build to the lowest-threshold regime in scope and treat the sunrise issue as a transfer-corridor question, not just an AML question.
FAQ
What is the FATF Travel Rule?
It is the obligation, derived from FATF Recommendation 15 and the related interpretive notes, for Virtual Asset Service Providers to collect and transmit specified originator and beneficiary information on covered crypto transfers above a threshold. In 2026, 85 of 163 jurisdictions had passed legislation implementing the rule, up from 65 a year earlier.
Why does the EU threshold differ from the US one?
The EU’s Transfer of Funds Regulation, in force from December 2024, applies to every covered transfer with no de minimis carve-out. The US implements the Travel Rule under the Bank Secrecy Act with a USD 3,000 threshold. A global firm operating in both jurisdictions must build to the lower European bar for its European book.
What is the “sunrise issue”?
It is the operational problem that arises when a VASP in a jurisdiction that has implemented the Travel Rule transacts with a counterparty in a jurisdiction that has not. Neither side can fully exchange Travel Rule data; the compliant firm must hold, complete with caveats, or refuse the transaction.
How do the FATF June 2025 revisions affect compliance?
The Recommendation 16 revisions agreed on 18 June 2025 extend Travel Rule-style transparency to specified funds transfers and revise the required data set. They take effect by end-2030, giving firms a multi-year build window but signalling the direction of cross-border-payment AML compliance.
What should compliance teams do now?
Build to the lowest-threshold regime in scope (the EU’s no-floor TFR is the operative bar for any firm with European customers), map vendor dependencies against DORA-style oversight, document sunrise-issue mitigation policies, and align internal data taxonomies to the revised Recommendation 16 data set even though the binding deadline is 2030.
This article is informational analysis only and does not constitute legal, regulatory, tax, or investment advice. Regulatory frameworks change frequently and interpretation depends on facts and circumstances; primary documents and official regulator guidance always supersede summaries. Firms should consult qualified legal counsel and their relevant supervisory authority before taking any action based on the analysis above.