Travel Rule Deadline Looms: U.S. VASPs Must Comply with FATF's Recommendation 16
The FATF's Recommendation 16, which was extended to virtual assets in 2019, requires U.S. virtual asset service providers (VASPs) to collect and transmit identifying information about both the sender and recipient before a transaction settles.
This rule is also known as the Travel Rule, and it sits at the intersection of anti-money laundering law, data privacy, and real-time payment infrastructure. The binding enforcement touchpoint for U.S. compliance leads is the Bank Secrecy Act (BSA) and FinCEN's recordkeeping rules.
The core obligations under the Travel Rule are to collect full originator and beneficiary information before or at the time of transfer, verify that information against reliable sources, transmit the data to the receiving VASP simultaneously with or before the transfer, retain records for a minimum of five years, and screen both parties against sanctions lists.
The U.S. threshold for compliance is $3,000, which is higher than the FATF baseline of $1,000. The EU, however, has moved faster and adopted a zero-threshold approach, requiring crypto asset service providers to accompany every transfer with full originator and beneficiary data regardless of amount.
U.S. VASPs must meet the zero-threshold standard for transactions involving EU counterparties, even if domestic rules are lower. Compliance teams should monitor FinCEN rulemaking dockets on Regulations for updates on threshold proposals and public comments.