Back
From paper to practice: Why VASPs cannot afford to wait on Travel Rule
Published on 2026-08-09
From paper to practice: Why VASPs cannot afford to wait on Travel Rule

Summary

  • 83% of jurisdictions have Travel Rule laws, but 60% may not have active enforcement yet.
  • FATF flagged four structural gaps: sunrise issue, tool interoperability, supervisory capacity, and unhosted wallets.
  • Six concrete steps VASPs should take now: audit compliance, ensure tool interoperability, build due diligence for unhosted wallets, train staff, document a risk-based approach, and ensure data protection treatment.
  • The tools and enforcement playbook already exist — the question is whether VASPs are ready.

The numbers tell a clear story. According to FATF's 7th Targeted Update published in July 2026, 83% of 109 surveyed jurisdictions have now passed Travel Rule legislation, an improvement from 73% in 2025. Despite this progress, 60% of those jurisdictions with Travel Rule laws have not taken enforcement or supervisory action against VASPs.

That gap, between having a law and enforcing it, is temporary. And should not be a reason for VASPs to wait. Rather, it is a window to get your house in order before enforcement arrives at your door.

Where we are

For context: The revised FATF Recommendation 15 (2019) is the framework that brings VASPs into the global AML/CFT regime. It requires jurisdictions to license or register VASPs, apply preventive measures like customer due diligence, and conduct risk-based supervision. Recommendation 16, commonly known as the Travel Rule, is the framework that obliges VASPs and financial institutions to obtain, hold, and transmit originator and beneficiary information immediately and securely when transferring virtual assets.

Since 2019, implementation of R.15 across the FATF Global Network has been lagging. In particular, the Travel Rule has been even slower, initially held back by technical constraints and lack of regulatory capacity.

But the landscape has shifted. Several compliance tools now exist. The EU's MiCAR and revised Transfer of Funds Regulation have driven a surge in implementation in the region. The FATF Global Network is moving from "pass the law" to "make it work."

The challenge is no longer whether the rules exist. It is whether the industry is ready for them.

What's holding implementation back

FATF has identified four structural gaps slowing Travel Rule implementation globally:

The sunrise issue: inconsistent global adoption means compliant VASPs may face friction when transacting with counterparties in certain other jurisdictions. 57% of compliant jurisdictions appear to be restricting VASPs from transacting with certain other foreign VASPs.

Tool interoperability: FATF does not mandate specific compliance tools, and a lack of interoperability between different providers creates friction. Some tools suffer from technical deficiencies, including failing to transmit data simultaneously with the transfer.

Supervisory capacity: VASP supervision is still emerging in most jurisdictions. Regulators lack technical expertise, and understanding of risks is misaligned between regulators and the private sector.

Unhosted wallets: peer-to-peer transfers between self-hosted wallets lack obliged intermediaries, creating ML/TF risks that fall outside the Travel Rule's direct scope. Jurisdictions are increasingly requiring VASPs to apply mitigating measures for any transfers to and from self-hosted wallets.

These are real challenges. But they are not reasons for VASPs to delay action to comply with the Travel Rule.

What VASPs should actually do

Based on FATF's findings and supervisory guidance, below are six concrete steps VASPs should consider today:

  1. Audit your actual compliance posture
    Do you truly transmit originator and beneficiary data with every qualifying transfer, or do you have a tool that claims compliance but does not execute in practice? Map your transaction flows against R.16 requirements and identify where data is missing, delayed, or incomplete. Many VASPs discover during regulatory inspections that their compliance is theoretical — the tool exists, but it is not configured correctly, does not cover all transaction types, or has gaps in data transmission.
  2. Ensure your Travel Rule tool is interoperable
    Can you send and receive Travel Rule messages across different providers, not just within your own system? Interoperability is the number one technical gap FATF flagged. If your tool only works seamlessly with one provider, you have a compliance gap — because your counterparties use different tools.

    The industry has moved past the question of "do you have a Travel Rule solution?" to "does your solution actually talk to everyone else's?" Ensure your provider supports and has tested interoperability across the major compliance tool providers.

    GTR Bridge interoperability with CODE, Sumsub, and Sygna

    GTR addressed this early with Bridge announcements in Q1 2024 establishing interoperability with CODE, Sumsub, and Sygna, and is actively working on new connections to further close the interoperability gap.

  3. Build enhanced due diligence for unhosted wallet transfers
    FATF highlights unhosted wallet activity as a growing risk. In many jurisdictions, VASPs are already required to implement mitigating measures: collecting counterparty information, verifying wallet ownership, and flagging suspicious transfer patterns. If your compliance framework treats unhosted wallet transfers the same as any other transaction, you are under-supervising a risk area that FATF has explicitly flagged.

    Incorporate tools such as GTR's Wallet Verify and build processes for enhanced due diligence on these transfers now, before your regulator asks why you have not done it yet.

    GTR Wallet Verify proves unhosted wallet ownership in seconds
  4. Invest in staff training and compliance capacity
    FATF flagged capacity and training gaps on both the regulator side and the private sector side. It is important for your compliance team to understand the Travel Rule requirements not just at a policy level but operationally — how data flows, where gaps occur, what to do when a counterparty does not respond with required information, how to handle failed transmissions.
  5. Document your risk-based approach
    Regulators want to see that you have assessed your risks and designed your compliance program around them. A documented risk assessment that drives your compliance decisions is what separates "trying" from "compliant" in a supervisor's eyes. It is key to document the risks you have identified, the decisions you have made, and the rationale behind them.
  6. Treat data protection as part of your Travel Rule program, not an afterthought
    Ensure your Travel Rule implementation is also compliant with applicable data protection obligations. Travel Rule information involves personal data that must be handled lawfully, minimised, transmitted securely, and retained only as long as required. A Travel Rule program that is legally compliant but data-protection non-compliant is still a regulatory risk.

The bottom line

The standard is set and the tools exist. The laws are in place in 83% of jurisdictions, and more are coming. The jurisdictions that have not enforced yet are not going to stay that way. FATF published its Best Practices on Travel Rule Supervision in June 2025 — a document written for regulators that essentially serves as an enforcement playbook.

The question for VASPs is no longer whether the Travel Rule is coming. It is whether you are truly ready when your regulator moves.