Skip to content
← Dossiers

Regulatory analysis · Switzerland

Switzerland's crypto travel rule, and the proof it demands

August 2026·CH · EU · UK
FINMATravel ruleUnhosted walletsSupervisionSwitzerland

Regulatory analysis · Switzerland

This dossier is about the travel rule — the requirement that identifying information travels with a payment — and specifically about how Switzerland applies it to transfers of crypto. Switzerland applies it more strictly than any other jurisdiction, and the practical shape of that strictness is easiest to see through a transaction.

Suppose you hold an account with a Swiss crypto institution and you want to send coins to a friend's private wallet. In the EU or the UK that transfer will ordinarily proceed. In Switzerland it will ordinarily be refused, unless the institution has first identified your friend, established who ultimately owns the assets behind the wallet, and satisfied itself by technical means that your friend genuinely controls the address you are sending to. Put plainly: before it will release your coins to someone who is not its customer, the Swiss institution must do to that person substantially what it did to you when you opened your account.

That requirement was set out by FINMA in a three-page notice, Guidance 02/2019 of 26 August 2019 — the 02/2019 guidance in what follows. It remains in force and nothing has replaced it.

What the 02/2019 guidance does not do is explain what would count as proof. It requires wallet ownership to be "proven using suitable technical means" and leaves the phrase undefined. The answer to the question every compliance officer actually has — which checks satisfy FINMA — has been supplied piecemeal in FINMA's annual reports for 2020 and 2022, and has never been consolidated anywhere.

This dossier therefore does three things. It establishes whether the 02/2019 guidance still stands, and on what evidence. It assembles, for the first time in one table, the six verification methods FINMA has said it accepts. And it asks why a requirement of this weight has never been written into the ordinance it is read out of, when FINMA revised that ordinance in May 2026 and used the same instrument to codify a different supervisory practice.

In summary

  • The requirement. A Swiss institution may transfer crypto to or from an external wallet only where it can establish who controls that wallet. Where the wallet belongs to its own customer, it must prove the customer's control. Where it belongs to anyone else, it must additionally run full customer due diligence on that third party, including beneficial ownership.
  • Where it comes from. The 02/2019 guidance, which derives the requirement from Article 10 of FINMA's Anti-Money Laundering Ordinance — the provision carrying the travel rule into Swiss law. Article 10 concerns information accompanying payment orders and does not mention wallets at all.
  • Whether it is still current. It is. No later guidance and no circular has replaced it, and the ordinance beneath it has not been amended since 1 January 2023.
  • What is missing from it. The methods that discharge it. Six are recognised; every one of them was announced in an annual report rather than in the guidance, an ordinance or a circular.

What the 02/2019 guidance requires

An external wallet, in FINMA's usage, is any wallet the supervised institution does not itself control — the customer's own, or a third party's. The question the guidance answers is when a Swiss institution may send coins to one, or accept coins from one.

Its answer, in the guidance itself:

"As long as an institution supervised by FINMA is not able to send and receive the information required in payment transactions, such transactions are only permitted from and to external wallets if these belong to one of the institution's own customers. Their ownership of the external wallet must be proven using suitable technical means."

And where the wallet belongs to somebody else:

"A transfer from or to an external wallet belonging to a third party is only possible if, as for a client relationship, the supervised institution has first verified the identity of the third party, established the identity of the beneficial owner and proven the third party's ownership of the external wallet using suitable technical means."

Three things make this stricter than anywhere else.

  1. There is no minimum amount. The duty bites on one franc.
  2. The word is proven. Not assessed. Not checked on a risk basis. Proven.
  3. A friend's wallet is harder, not easier. Sending to a third party means full customer checks on someone who is not your customer.

FINMA says outright that this goes beyond the global standard: "Unlike the FATF standards, Article 10 AMLO-FINMA does not provide for any exception for payments involving unregulated wallet providers."

How far beyond the standard — stated precisely

FATF's position on transfers to private wallets is set out in its October 2021 guidance on virtual assets, and it is worth quoting because it is often described loosely, including in an earlier version of this dossier.

At paragraph 179 FATF distinguishes three cases: a traditional wire transfer, a transfer between two obliged entities, and "a VA transfer between a VASP and a non-obliged entity (i.e., an unhosted wallet)". Its conclusion is explicit — "The full requirements of Recommendation 16 apply to (a) and (b) but not (c)."

What does apply to (c) is set out at paragraphs 204 and 295. FATF "does not expect that VASPs and FIs, when originating a VA transfer, to submit the required information to individuals who are not obliged entities"; instead the firm "should obtain the required originator and beneficiary information from their customer", because it cannot obtain it from another VASP. At 296 it adds that VASPs "should collect data on their unhosted wallet transfers, and monitor and assess that information" against their risk appetite.

And at paragraph 297 FATF lists what a VASP may choose to do beyond that. One of the options is "studying the feasibility of accepting transactions only from/to VASPs and other obliged entities, and/or unhosted wallets that the VASP has assessed to be reliable."

Read that sentence next to the Swiss requirement. What FATF offered in 2021 as an option a firm might consider, FINMA had already made compulsory in 2019 — and made compulsory in a stronger form, because FATF's word is assessed and FINMA's is proven.

So the accurate statement of the gap is narrower than "FATF says nothing", and more useful. FATF requires a firm to collect information about the transfer from its own customer, to monitor, and to manage the risk. No FATF instrument requires a firm to establish who controls the receiving address. Switzerland requires exactly that, at any value, and requires full customer due diligence on a third party before it will pay one.

Why it matters

For a firm, this is the provision that stops a payment going out. The clearest way to see the divergence is to run the same instruction through all three regimes: a customer asks to transfer about £2,000 to a wallet belonging to a friend.

What the firm must doDoes the transfer go?
EUAbove EUR 1,000, assess whether the address belongs to its own customer. A friend's wallet falls outside that articleUsually yes
UKMay ask for information, having weighed four listed factors. It may lawfully not askUsually yes
SwitzerlandIdentify the friend, establish the beneficial owner, and prove the friend controls the walletFor ordinary retail, no

For an investigator or a claimant, the same rule reads the other way round. A Swiss firm that may only pay an address it has proved someone controls must be holding, for every address it ever touched: a named and checked customer, the address itself, and a document tying the two together. That is a better attribution record than the EU or the UK regime produces. The strictest rule creates the best evidence.

Is it still in force? Four checks

A guidance note seven years old, in a field that has changed as fast as this one, cannot simply be assumed to be current — and until 24 August 2026 nobody in this practice had tested the assumption. Three of its own research notes rested on the 02/2019 guidance without asking whether it still stood. Four checks were run, and all four point the same way.

CheckResult
Still on FINMA's published list of guidance?Yes — 59 documents listed, the 02/2019 guidance among them, dated 26.08.2019
Replaced by later guidance?No. The four later crypto guidances cover staking, stablecoins, accounting disclosure and custody. Guidance 01/2026 on custody was read in full and never mentions wallets, transfers or 02/2019
Replaced by a circular?No. FINMA's register of current circulars contains nothing on wallets, crypto transfers or the travel rule
Has the ordinance beneath it changed?No. Fedlex publishes AMLO-FINMA as consolidated to 1 January 2023. Article 10 is unchanged
Qualified in any other FINMA publication?No. Every annual report from 2020 to 2025 was read, as were the Risk Monitors for 2024 and 2025. The 2023 report and both Risk Monitors return nothing on wallets; the 2025 Risk Monitor calls crypto-sector money-laundering risk elevated but cross-refers to Guidance 06/2024 on stablecoins, not to 02/2019

One caution, because it cuts against a quick answer. FINMA's list has no status column. Nothing on it is marked current, revised or withdrawn. The neighbouring archive holds the 64 newsletters FINMA stopped issuing in 2014 — an old format, not a bin for cancelled rules. So being on the list proves FINMA still publishes 02/2019. It does not, by itself, prove the rule still bites.

What proves that is FINMA saying so, repeatedly, in its annual reports — and inspecting for it as recently as 2024.

The rule grew, and it grew somewhere odd

Here is the whole life of the rule in one place.

WhenWhat happenedWhere it was said
26 Aug 2019The requirement is published. Own-customer wallets only; ownership "proven using suitable technical means"; full checks for a third party's walletGuidance 02/2019
2020FINMA restates the rule, adds the condition "as long as there is no technical solution", and names the first accepted methods: micro-payment, signed message, whitelisting after the first check, and a screenshot where the other side runs pooled walletsAnnual Report 2020, pp. 43–44
2021FINMA and the SROs discuss how to implement the travel rule "in conformity with FINMA Guidance 02/2019". A sixth audit module is added for crypto firmsAnnual Report 2021
2022Two more methods accepted: time-boxing, and logging into the wallet in front of the firm's staffAnnual Report 2022, p. 38
2024Travel-rule risk is given as the reason for targeted on-site inspections at selected SROs. 203 crypto firms sit under SRO supervision; 88 are inactiveAnnual Report 2024
2025Nothing. Across 94 pages, the words wallet, travel, VASP and 02/2019 do not appear onceAnnual Report 2025
12 May 2026FINMA opens a consultation to revise the ordinance. It does not touch the external-wallet requirementDraft amending ordinance and explanatory report

Every addition is in an annual report. An annual report is an account of what a public body did last year. It is not a rule. A firm asking "what must I do?" must read a 2019 notice, then four annual reports, and assemble the answer itself.

The six checks FINMA accepts

FINMA has never published this table. It is assembled from the 2020 and 2022 reports, and the 2022 report points back to the 2020 one for the earlier entries.

MethodWhat the customer doesFirst said
Micro-payment (the satoshi test)Sends a tiny agreed amount, at an agreed time2020
Signed messageUses the wallet's key to sign a text the firm asks for. No money moves2020
WhitelistingPasses the check once. The address is then trusted for later transfers, re-checked at intervals the firm sets2020
ScreenshotWhere the other side runs an omnibus wallet and nothing else works: sends a picture of the transaction they announced2020
Time-boxingSends an agreed amount to an address the firm supplies, inside a short window the firm sets2022
Wallet login in front of staffLogs in while an employee watches. Must be properly documented2022

Set that list against the word proven and the distance is plain. A screenshot is a picture. Whitelisting means the check may be years old by the time it matters. The strictest wallet standard in the world is, in its softest corner, a photograph and a promise.

That is not a criticism of the firms. FINMA allowed the screenshot precisely because the other methods do not work against a pooled wallet, and something is better than nothing. It is a caution for anyone relying on a Swiss "verified" flag as evidence. The flag records that a method was run. It does not record what the method proved.

What kind of document is this?

This is the part that decides how much weight the rule can carry.

Swiss financial rules come in layers. An Act is passed by Parliament. An ordinance is made under an Act and binds. A FINMA circular explains how FINMA will apply the law, and binds FINMA itself. FINMA guidance sits below all of those.

FINMA says so itself. On its own page for these notices:

"Die FINMA-Aufsichtsmitteilung ist im Unterschied zu FINMA-Verordnungen und FINMA-Rundschreiben kein Regulierungsinstrument, sondern dient der reibungslosen Anwendung von Vorschriften in der Praxis. Sie ist auf den Taterfolg, nicht auf die Rechtswirkung ausgerichtet."

In English: FINMA guidance, unlike FINMA ordinances and FINMA circulars, is not a regulatory instrument. It serves the smooth application of rules in practice. It is aimed at practical effect, not legal effect. (FINMA's own English version puts it more strongly still: guidance "does not have legal impact". The German is the authentic text, and it says slightly less.)

So where does the binding duty come from? FINMA points to Article 10 AMLO-FINMA, headed Angaben bei Zahlungsaufträgen — information on payment orders. Read it and it is an ordinary travel-rule provision: send the payer's name, account number and address, and the payee's name and account number. Search the whole ordinance and the German words for wallet, power of disposal and ownership appear zero times.

The rule is therefore an inference. FINMA reads a duty to make information travel, notes that no compliant system exists to carry it for crypto, and concludes that a firm may only send to wallets it has proved its customer controls.

That inference has been publicly questioned since the month it appeared. Writing in September 2019, Jeremy Bacharach — then a doctoral researcher at the University of Geneva's banking and finance law centre — argued that Article 10 does not support the third-party identification duty: "Die angeführte Rechtsgrundlage stellt aus unserer Sicht keine solche Verpflichtung dar"in our view the legal basis cited imposes no such obligation. (Crypto Valley Journal, 25 September 2019.)

What a court has said

No court has ruled on the 02/2019 guidance. A full-text query of entscheidsuche.ch — which indexes the Federal Supreme Court, the Federal Administrative Court, the Federal Criminal Court and the cantonal courts — returns no decision citing it, and no decision construing Article 10 AMLO-FINMA since 2019. The single decision on that article, BVGer B-2091/2014, predates the guidance by four years.

A court has, however, decided what a FINMA guidance is. In a criminal judgment of 2 December 2021, SK.2021.17, the Federal Criminal Court convicted the head of an ICO issuer of acting as a financial intermediary without authorisation. The defendant had argued that applying FINMA's ICO guidance to conduct predating it would offend the principle of legality. The court answered, at E. 2.4.2:

"Im Unterschied zu FINMA-Verordnungen und FINMA-Rundschreiben stellen Aufsichtsmitteilungen und Wegleitungen gerade keine Regulierungsinstrumente dar, sondern dienen der reibungslosen Anwendung von Vorschriften in der Praxis. Sie sind auf den Taterfolg und nicht auf die Rechtswirkung ausgerichtet (Art. 7 Abs. 1 FINMAG …)."

In English: unlike FINMA ordinances and FINMA circulars, supervisory notices and guides are precisely not regulatory instruments; they serve the smooth application of rules in practice. They are aimed at practical effect, not legal effect.

So the proposition is no longer FINMA's description of itself. A federal court has adopted it, and grounded it in Article 7(1) FINMASA.

Three qualifications, because the case does not decide this one.

  • It concerns a different notice — Guidance 04/2017 on initial coin offerings. The court states the proposition about the category, which is why it travels, but no court has applied it to the external-wallet requirement.
  • The defendant was convicted anyway, and the reason matters here. The court held that the guidance did not need to bind, because the duty was already in the Act: the obligation to affiliate to an SRO is expressly in Article 14(1) of the Anti-Money Laundering Act. That is precisely where the external-wallet requirement differs. Article 10 AMLO-FINMA does not mention wallets. A court asked the same question about the 02/2019 guidance would have to find the duty in Article 10 first, and the words are not there.
  • Guidance still bites, through culpability rather than through law. The court treated the defendant's knowledge of the 04/2017 notice, and FINMA having drawn it to his attention, as making his mistake of law "leicht vermeidbar" — easily avoidable. He was convicted, and sentenced to 120 day-fines of CHF 440 suspended, a fine of CHF 13,200 and costs, with the judgment executed by the Federal Department of Finance rather than by FINMA.

That last point is the practical answer to "is FINMA guidance binding?". Not as a rule. Very much as evidence of what you knew.

The 2026 revision, and the thing it left out

On 12 May 2026 FINMA opened a consultation on changing AMLO-FINMA. It closed on 9 June 2026. The target date for the new text is 1 January 2027. As at 24 August 2026 no results report had appeared, so everything below is about a draft.

FINMA gave three reasons for the revision. One of them is "dem Bedarf nach punktueller Kodifizierung der aktuell geltenden Aufsichtspraxis"the need to write current supervisory practice into the rules, point by point. The timetable is driven by the FATF's next inspection of Switzerland, expected May to July 2027; FINMA shortened the consultation to under a month so the changes would be in force before the inspectors arrive.

So: a rewrite, explicitly to codify practice, explicitly before an international examination.

It did two things worth putting side by side.

The first is a codification. New Article 9b writes down an expectation FINMA had been enforcing through practice and had, in its own words, "mehrfach öffentlich kommuniziert"communicated publicly several times — in its annual reports for 2021 and 2023. The reason given: "dem Bedürfnis nach Rechtssicherheit sowie dem Anliegen der FATF"the need for legal certainty, and the FATF's concern.

The second is a deletion. Article 10(3) is repealed. That paragraph let a firm use the reduced data set for domestic payments for goods and services where full compliance was "aus technischen Gründen nicht möglich"not possible for technical reasons. FINMA explains that it existed to treat payments to and from Liechtenstein as domestic, and that the QR-code changeover of 1 July 2020 made it pointless. It also records that the paragraph "war jedoch nicht mit den FATF-Recommendations vereinbar"was not compatible with the FATF Recommendations.

The external-wallet requirement appears nowhere. Searched right through, the draft and its seventeen-page explanatory report never use the words 51a, virtuell, Wallet, Verfügungsmacht, Blockchain or DLT.

Set the three facts together and the question asks itself. FINMA had a codification vehicle open. It had a stated reason — legal certainty. It had an international examination coming. It had a worked example, in the same instrument, of writing down a practice it had announced through annual reports. And it left its strictest crypto requirement exactly where it was.

There is also a smaller point with a longer reach. Article 10(3) is the only place in Article 10 that excuses a firm because something is technically impossible. The 02/2019 guidance rests on exactly that idea — the rule applies "as long as" a firm cannot send and receive the required information. On its face the repeal does not touch crypto: Article 10(3) is about domestic payments for goods and services. But from 1 January 2027, if the draft is adopted, the article the external-wallet requirement is read out of will contain no technical-impossibility exemption at all.

The other side of the argument

A Swiss supervisor would say this makes far too much of where a document sits.

FINMA has restated the 02/2019 guidance in four annual reports. It discussed implementation with the SROs. It built an audit module for it. In 2024 it sent inspectors into SROs because of travel-rule risk. A rule that is supervised, audited and inspected for seven years is an operative rule, whatever shelf its text is on. And a firm that told FINMA its published reading of Article 10 was merely guidance, and therefore optional, would be making an argument it might win in theory and lose in every way that matters — FINMA licenses, inspects, and under FINMASA can strip authorisation.

That is right as advice. Comply.

It is incomplete as analysis, for two reasons that survive it. The duties are scattered and unconsolidated — five documents over six years, never published as a set. And the codification point stands on its own facts: FINMA did codify a comparable practice in 2026, for stated reasons that apply at least as strongly here, and did not codify this one.

Reading for practitioners

If you are a firm. The status point is not an escape route. A federal court has said FINMA guidance is not a regulatory instrument, and in the same judgment treated knowledge of the guidance as making a mistake of law inexcusable. Departing from it is a decision to be defended on the ordinance, not a free option. Do not treat the 02/2019 guidance as the specification. Read the 2020 and 2022 annual reports as well, because that is where the accepted methods live. Document which method you used and when. If you rely on whitelisting, record the re-check interval you set and why — FINMA leaves that interval to you, which is discretion you will be asked to justify.

If you are checking a Swiss counterparty. Ask which supervisor it answers to. Firms outside a banking licence are supervised by one of the eleven FINMA-recognised SROs, not by FINMA: AOOS, ARIF, OAD FCT, PolyReg, SRO SLV, SRO SAV/SNV, SRO-SVV, SRO SVIG, SO-FIT, SRO-Treuhand Suisse and VQF. FINMA's own list is here. The external-wallet requirement reaches SRO-supervised firms through their SRO's rulebook, not directly.

If you are asking a Swiss firm for records. The wallet-ownership artefact is the document worth naming in a request: the signed message, the micro-payment, the time-boxed transfer, the screenshot. Ask which method, on what date, and when it was last repeated. "Verified" on a file is not a date.

If you are advising on what happens next. Two dates. The revised ordinance is targeted at 1 January 2027 and remains a draft. The FATF inspection is expected between May and July 2027. If the external-wallet requirement is going to be written into the ordinance, the run-up to that inspection is when it would happen.

Dotted-underlined terms carry hover definitions; the full list is in the glossary. For how the two Swiss supervisory channels differ, and why FATF's rule against self-regulatory supervision did not stop Switzerland using one, see Supervised by whom. For the same travel-rule question across three jurisdictions, see Three travel rules.

Key takeaways

  • The 02/2019 guidance is still in force. Nothing has replaced it and the ordinance beneath it is unchanged since 1 January 2023.
  • The rule has been qualified four times, entirely in annual reports — which is where the six accepted verification methods live. FINMA has never published them as a list.
  • FINMA states that its guidance is not a regulatory instrument and is aimed at practical effect, not legal effect. The binding provision, Article 10 AMLO-FINMA, never mentions wallets.
  • The May 2026 revision codified a different practice for legal certainty ahead of the 2027 FATF inspection, and left the external-wallet requirement alone.
  • No court has ever cited the 02/2019 guidance. One has held that FINMA guidance is not a regulatory instrument at all — and convicted the defendant anyway, because that duty was in the Act. This one is not.
  • A Swiss "verified" flag records that a method was run — it does not record what the method proved. One accepted method is a screenshot.

Sources

FINMA — the rule and its qualifications

Law

The 2026 revision

Courts

  • Bundesstrafgericht, SK.2021.17, 2 December 2021 — E. 2.4.2 on the status of FINMA supervisory notices
  • Swiss court corpus queried through entscheidsuche.ch, 24 August 2026 — no decision cites the 02/2019 guidance

Standard and commentary


Sourcing note, 24 August 2026. The section How far beyond the standard was added after FATF's October 2021 guidance was obtained and read in full. It is worth saying why, because the practice's own working note had until then described FATF's treatment of private wallets as amounting to the parenthesis "(if any)" in the Interpretive Note to Recommendation 15. That is true of the Recommendations themselves and understates the position once the guidance is in view: paragraphs 179, 203–204 and 295–297 address unhosted-wallet transfers at length, and paragraph 297 floats the very restriction Switzerland had already imposed. The conclusion is unchanged and better supported — no FATF instrument requires a firm to establish who controls the receiving address — but the shorter formulation would have overstated the silence, and it has been retired before it reached this page.


Research and analysis, not legal advice. Positions stated as at 24 August 2026; the AMLO-FINMA revision was a draft on that date. The information provided is for research and educational purposes only and does not constitute legal advice.

Working on a matter this touches?

Start a conversation