Travel Rule & EU Transfer of Funds Regulation (TFR) Compliance
Regulatory and AML/CFT advisory for businesses subject to EU requirements on information accompanying transfers of funds and crypto-assets under Regulation (EU) 2023/1113.
Support for PSPs, payment and e-money institutions, CASPs and relevant FinTech businesses — from regulatory assessment and policies to governance, transfer controls, remediation and ongoing compliance.
TFR
Reg. (EU) 2023/1113 applies from 30 Dec 2024
Funds
PSPs & intermediary payment providers
Crypto
CASPs & intermediary CASPs
FATF R.16
International payment transparency standard
Two sides of the EU Travel Rule
Transfers of Funds and Crypto-Assets Under the TFR.
Regulation (EU) 2023/1113 sets rules on information accompanying transfers of funds and transfers of crypto-assets for AML/CFT purposes. The Regulation applies where the relevant PSP or CASP nexus falls within its EU scope.
For payments, the framework addresses payer and payee information, verification, missing or incomplete data and intermediary PSP responsibilities. For crypto-assets, it addresses originator and beneficiary information, CASP-to-CASP transfers, self-hosted addresses and procedures for incomplete information.
FinTech businesses should not assume that every product is subject to the same rule. The correct starting point is to map the regulated entity, transaction flow, asset type and role of each provider in the transfer.
Transfers of funds — key areas
→Payer and payee information requirements
→Verification requirements and applicable thresholds
→Detection of missing or incomplete information
→Intermediary PSP responsibilities
Crypto-asset transfers — key areas
→Originator and beneficiary information
→Counterparty CASP controls
→Self-hosted address requirements
→Transfer handling, escalation and AML/CFT integration
Who may be in scope
Who May Need Travel Rule & TFR Support?
Applicability depends on the regulated activity and transaction flow. The TFR is relevant across both payment and crypto-asset transfer chains.
Payment service providers and intermediary PSPs
Payment institutions and electronic money institutions acting as PSPs
Crypto-asset service providers and intermediary CASPs
Crypto exchanges, custodial platforms and transfer providers
FinTech businesses combining payment and crypto functionality
Cross-border financial businesses entering or operating in the EU
Regulatory framework
EU Travel Rule — Key Regulatory Frameworks.
The EU framework covers payment transparency and crypto-asset transfers within one Regulation, supported by EBA guidance and wider FATF standards.
EU — TFR
Regulation (EU) 2023/1113
Applies from 30 December 2024
Covers transfers of funds in any currency within its scope
Covers in-scope transfers of crypto-assets involving CASPs
Sets information, verification and transfer-handling requirements
Includes specific rules for self-hosted addresses
Directly applicable EU law
EBA
Travel Rule Guidelines
Apply to PSPs and intermediary PSPs
Apply to CASPs and intermediary CASPs
Address missing or incomplete information
Set procedures for handling affected transfers
Support consistent application across the EU
Applicable from 30 December 2024
FATF — R.16
International Payment Transparency Standard
International standard underpinning the Travel Rule concept
Addresses transparency in transfers and payment messages
Travel Rule terminology is widely used for virtual assets
Recommendation 16 was revised by FATF in June 2025
Regulatory, governance and AML/CFT support for payment and crypto transfer models — without positioning the engagement as technical implementation.
01
Travel Rule & TFR Gap Assessment
A structured review of the existing or proposed framework against applicable TFR requirements and the actual operating model.
Regulatory perimeter and applicability analysis
Payment and crypto transaction-flow review
Information and verification requirements
Missing-information and escalation procedures
Governance and responsibility mapping
Gap prioritisation and remediation roadmap
02
Travel Rule Policies & Procedures
Development, review or remediation of policies and operational procedures for in-scope transfers of funds and crypto-assets.
TFR policy and governance framework
Payment-transfer procedures
Crypto-transfer procedures
Missing and incomplete information handling
Transfer rejection, suspension and escalation rules
Record-keeping and management oversight
03
Payment, Counterparty & Self-Hosted Controls
Compliance control design for payment transfer chains and crypto transfers involving other CASPs or self-hosted addresses.
Payer, payee, originator and beneficiary controls
Intermediary transfer procedures
Counterparty CASP risk framework
Self-hosted address procedures
Ownership or control assessment requirements
Sanctions and AML/CFT integration
04
Travel Rule Remediation & Ongoing Compliance
Support where weaknesses are identified through internal review, audit, supervisory engagement, licensing work or partner due diligence.
Remediation planning and tracking
Policy and procedure updates
Governance and control enhancement
Implementation review from a compliance perspective
Periodic effectiveness review
Regulatory change assessment
Payments, FinTech & crypto
Travel Rule Compliance Across Payment and Crypto Business Models.
The EU Travel Rule should not be treated as a crypto-only requirement. Regulation (EU) 2023/1113 governs information accompanying both transfers of funds and certain crypto-asset transfers.
For payment businesses, the analysis may involve PSP or intermediary PSP responsibilities, payer and payee information and verification. For crypto businesses, it may involve CASP responsibilities, originator and beneficiary information, self-hosted addresses and counterparty CASP controls.
Hybrid FinTech models
One customer journey can contain different regulatory legs.
A product may combine fiat payments, electronic money, crypto-assets, conversion and payout. Each leg should be mapped separately to identify the regulated entity, asset, transfer type and applicable information requirements.
Transaction-flow analysis before control design.
Implementation challenges
Common Travel Rule & TFR Compliance Challenges.
The hardest issues usually arise at the boundary between regulation, transaction flows, AML/CFT controls and cross-border operations.
01
Regulatory Perimeter
Determining which payment or crypto transaction flows fall within the TFR and which entity carries the relevant obligation.
02
Hybrid FinTech Models
Payment, e-money and crypto functionality may sit in one customer journey but engage different regulatory requirements.
03
Missing Information
Defining consistent procedures for transfers where required payer, payee, originator or beneficiary information is incomplete.
04
Cross-Border Transfers
Managing transactions involving jurisdictions that apply different Travel Rule or payment-transparency standards.
05
Counterparty & Self-Hosted Risk
Applying proportionate controls to counterparty CASPs and crypto transfers involving self-hosted addresses.
06
AML/CFT Integration
Ensuring Travel Rule controls work with sanctions, transaction monitoring, customer risk and escalation processes.
When businesses reach out
When Travel Rule Support Becomes Critical.
Travel Rule issues often surface during product launch, licensing, partner due diligence, audit or supervisory review.
Launching a Payment or Crypto Product
Map the regulatory perimeter and information requirements before transactions go live.
Licensing or Authorisation
Align TFR policies, governance and operational controls with the regulated business model.
Banking & Counterparty Due Diligence
Provide credible evidence of Travel Rule governance and transfer-control design to regulated partners.
Audit, Review or Remediation
Address gaps in documentation, control design, responsibilities or implementation before they become supervisory issues.
EU regulatory context
Travel Rule Requirements in the EU.
Transfers of funds
PSPs and intermediary PSPs
The TFR applies to transfers of funds in any currency sent or received by a PSP or intermediary PSP established in the Union, subject to the Regulation's scope and exclusions. Requirements cover payer and payee information, verification, missing information and transfer handling.
Regulation (EU) 2023/1113 · Articles 1–13
Crypto-asset transfers
CASPs and intermediary CASPs
For crypto-assets, the Regulation applies to in-scope transfers where a CASP is involved. Person-to-person transfers carried out without CASP involvement are excluded. Transfers to or from self-hosted addresses remain in scope where a CASP is involved.
Regulation (EU) 2023/1113 · Articles 14–21
Why LEX ARTA
Regulatory-Led, Cross-Sector Travel Rule Support.
A compliance approach built around the legal perimeter, actual transaction flow and wider AML/CFT framework.
Payments + Crypto Perspective
The TFR is analysed across both transfers of funds and crypto-assets rather than as a crypto-only requirement.
Regulatory-Led Analysis
The work starts with the applicable perimeter, regulated entity, business model and transaction flow.
AML/CFT Integration
Travel Rule controls are aligned with sanctions, transaction monitoring, CDD/EDD, escalation and governance.
Cross-Border Focus
EU requirements are considered together with the practical issues created by international payment and crypto transfers.
Frequently asked questions
EU Travel Rule & TFR — FAQ.
Is the Travel Rule only for crypto?
+
No. Regulation (EU) 2023/1113 covers both transfers of funds and transfers of crypto-assets within its scope. It imposes requirements on relevant payment service providers and crypto-asset service providers involved in those transfers.
Who is subject to the EU Travel Rule?
+
The Regulation applies to in-scope transfers involving payment service providers, intermediary payment service providers, crypto-asset service providers and intermediary CASPs established or registered in the Union, subject to the Regulation's scope and exclusions.
Does the Travel Rule apply to FinTech companies?
+
Not automatically. Applicability depends on the activities performed, regulatory status and transaction flow. A FinTech business may fall within the TFR where it acts as, or operates through, an in-scope PSP, intermediary PSP, CASP or intermediary CASP.
When did Regulation (EU) 2023/1113 become applicable?
+
Regulation (EU) 2023/1113 applies from 30 December 2024. The EBA Travel Rule Guidelines also apply from 30 December 2024.
Does the EU Travel Rule have a EUR 1,000 threshold?
+
There is no general EUR 1,000 threshold excluding lower-value crypto-asset transfers from the TFR. The EUR 1,000 threshold is relevant to specific verification requirements, including adequate measures to assess ownership or control of a self-hosted address in certain crypto-asset transfers, and to certain verification rules for transfers of funds.
How does the TFR apply to self-hosted addresses?
+
Where a CASP is involved in a transfer to or from a self-hosted address, the TFR establishes information and identification requirements. For a transfer exceeding EUR 1,000, the relevant CASP must take adequate measures to assess whether the self-hosted address is owned or controlled by its client.
What happens when required Travel Rule information is missing?
+
PSPs and CASPs must maintain effective procedures to detect missing or incomplete information and determine the appropriate treatment of the transfer, including risk-based decisions and follow-up measures required by the Regulation and EBA Guidelines.
Is Travel Rule compliance relevant to MiCA-authorised CASPs?
+
Yes. CASPs that perform in-scope crypto-asset transfers must comply with Regulation (EU) 2023/1113 alongside the broader regulatory framework applicable to their crypto-asset services, including MiCA where relevant.
Whether you operate in payments, FinTech, crypto or a hybrid model, the starting point is a clear view of how Regulation (EU) 2023/1113 applies to the actual transaction flow. We support regulatory assessment, policies, governance, controls and remediation.
This website uses cookies and third-party services (including Google Fonts) that may process personal data. By continuing, you consent to our Cookie Policy and Privacy Policy, in accordance with the EU GDPR.
Get in Touch
Discuss Travel Rule Requirements
BOOK A CONSULTATION
Tell us about your matter.
Share the business context, jurisdiction and support you need. We will reply with a practical next step.