Regulatory analysis · EU, UK, Switzerland
Three regimes share the name "travel ruleThe requirement that sender and recipient identity data accompany crypto transfers between providers (FATF Recommendation 16).". None of the three shares a threshold with either of the others, and the numbers that look comparable — €1,000, £800, CHF 1,000 — each answer a different question. A compliance team that maps one onto another will get the wrong answer in both directions.
Below: what each text actually requires, where the three diverge, and why the binding constraint is not the legislation.
What the three thresholds are not
The three figures look like local variants of one number. They are not. Set each against the question it answers.
€1,000, in the EU, appears in the second subparagraph of Article 14(5) of Regulation (EU) 2023/1113. It does not govern what information travels. It governs whether a crypto-asset service provider must go looking behind a self-hosted address:
"Without prejudice to specific risk mitigating measures taken in accordance with Article 19b of Directive (EU) 2015/849, in the case of a transfer of an amount exceeding EUR 1 000 to a self-hosted address, the crypto-asset service provider of the originator shall take adequate measures to assess whether that address is owned or controlled by the originator."
Below €1,000 the first subparagraph still bites: obtain and hold the full Article 14(1) and (2) data set, and ensure the transfer can be individually identified. Article 16(2) mirrors both subparagraphs for inbound transfers.
£800, in the UK, appears in regulation 64C(4) of the Money Laundering Regulations 2017. It governs whether the fuller originator data set must accompany a transfer — and only where at least one business in the chain is not carrying on business in the United Kingdom in respect of the transaction. The basic data set under 64C(5) travels on every inter-cryptoasset business transfer, at any value.
CHF 1,000, in Switzerland, appears in Article 51a(1) of the FINMA Anti-Money Laundering Ordinance. It is not a travel-rule threshold at all. It governs whether a financial intermediary must identify the contracting party to a virtual-currency transaction that is neither a money or value transfer nor attached to a continuing business relationship. The article sits in Chapter 1a of the ordinance — Identifizierung der Vertragspartei, identification of the contracting party — not in the provisions on payment orders. The Swiss travel ruleThe requirement that sender and recipient identity data accompany crypto transfers between providers (FATF Recommendation 16). proper is Article 10, and Article 10 has no threshold.
The conflation is not confined to vendor commentary. FATFThe Financial Action Task Force — the inter-governmental body, created by the G7 in 1989, whose Recommendations set the global anti-money-laundering standard. Not a law-maker: its power runs through peer review and its lists.'s own Best Practices on Travel Rule Supervision of June 2025 describes Switzerland as having moved "to strengthen its regulatory framework by further clarifying Travel RuleThe requirement that sender and recipient identity data accompany crypto transfers between providers (FATF Recommendation 16). requirements", the first of which is that "the EUR/USD/CHF 1000 threshold applies to not only individual transactions, but also to transactions that 'appear to be linked'". All three limbs of that passage map onto Article 51a and nothing else — including the third, which FATF renders in the language of identification: "The FI must always identify the contracting party if there are suspicions of possible money laundering or terrorist financing." That is Article 51a(3). What the passage describes as a clarification of the travel rule is a customer due diligence trigger.
The European Union
Regulation (EU) 2023/1113 recast the 2015 wire-transfer regulation and extended it to crypto-assets. It has applied since 30 December 2024 (Article 40).
The EU regime is two documents, not one. The Regulation, in the EBA's own words, "does not set out in detail what payment service providers …, intermediary PSPs …, crypto-asset service providers …, and intermediary CASPs … should do in order to comply with it": it mandates the EBA to say. EBA/GL/2024/11, the Travel RuleThe requirement that sender and recipient identity data accompany crypto transfers between providers (FATF Recommendation 16). Guidelines, apply from the same day as the Regulation and repeal the 2017 joint guidelines. They are issued under Article 16 of Regulation (EU) No 1093/2010: competent authorities and financial institutions "must make every effort to comply", and each authority must tell the EBA whether it complies or give reasons for not doing so. So the operative expectation in a Member State is the Regulation, the Guidelines, and whatever that State's authority has notified. Everything the Guidelines say below is a should, and is written here as one.
Scope for crypto-assets is registered-office based. Article 2(1) catches transfers of crypto-assets, including those executed through crypto-ATMs, where the crypto-asset service provider or intermediary provider of either the originator or the beneficiary has its registered office in the Union. Two exclusions, both in the third subparagraph of Article 2(4): transfers where both parties are crypto-asset service providers acting on their own behalf, and person-to-person transfers carried out without any provider involved.
Article 14(1) and (2) set the data that must accompany every transfer. On the originator: name; distributed ledger address where the transfer is registered on a DLT network, together with the crypto-asset account number where such an account exists and is used to process the transaction; the account number alone where the transfer is not registered on a DLT network; address including country, official personal document number and customer identification number, or alternatively date and place of birth; and the LEI where the message format has a field for it and the originator has provided it. On the beneficiary: name, distributed ledger address and account number on the same conditions, and the LEI on the same condition again.
There is no de minimis. The €1,000 figures in Articles 5 and 6 apply to transfers of funds, not crypto-assets, and the crypto chapter contains no equivalent — the only monetary figure anywhere in Chapter III is the one in Articles 14(5) and 16(2), and it attaches to the ownership assessment, not to the data.
Nor is there any intra-Union derogation. Article 5 lets payment service providers inside the Union send account numbers alone, and supply the full Article 4 set within three working days on request above €1,000, or names and account numbers below it. Chapter III gives crypto-asset service providers nothing of the kind. The only relief in the crypto chapter is Article 15, for batch file transfers, and that is structural rather than geographic.
On timing, Article 14(4) requires the information to be submitted "in advance of, or simultaneously or concurrently with, the transfer of crypto-assets", securely and consistently with the GDPR — and expressly does not require it to be attached to or included in the transfer itself. The channel is left open; the sequence is not.
The EBA sets an earlier outer edge. Its Travel RuleThe requirement that sender and recipient identity data accompany crypto transfers between providers (FATF Recommendation 16). Guidelines, EBA/GL/2024/11, say the originator's crypto-asset service provider and any intermediary provider should transmit the information "immediately and securely and no later than the initiation of the blockchain transaction" — initiation being a point before the transfer completes.
The consequences are hard-edged. Article 14(8): the originator's provider "shall not allow for the initiation, or execute any transfer, of crypto-assets before ensuring full compliance". Article 17(1) requires the beneficiary's provider to hold risk-based procedures "for determining whether to execute, reject, return or suspend" a transfer lacking complete information, and, once it becomes aware that information is missing or incomplete, to reject or return, or else request the missing information before releasing the assets. Where a counterparty repeatedly fails, Article 17(2) offers two routes: graduated steps, which "may initially include" warnings and deadlines before rejection, restriction or termination — or going directly to rejection of future transfers, restriction, or termination of the relationship. Either way the failure and the steps taken are reported to the competent authority.
The Regulation fixes no numeric period for any of that — Article 17(1) says only "without undue delay". The Guidelines supply the numbers. A request for missing information should carry a reasonable deadline, not exceeding three working days within the Union or five working days for a transfer received from outside it, running from the day the gap is identified; a longer deadline of up to seven days — days, not working days — may be set where the chain involves more than two parties, or where at least one of the providers in it is based outside the EU. A repeatedly failing counterparty should be reported to the competent authority "without undue delay, and no later than three months" after identification, "regardless of the reasons given … or their location in the Union or outside".
And beneath Article 17(1)'s four-way discretion the Guidelines press hard in one case. A provider that executes despite missing information should document why — "however, where the payer, payee, originator or beneficiary cannot be unambiguously identified due to missing or incomplete information, or information provided using inadmissible characters, the PSP, IPSP, CASP or ICASP should not execute the transfer". The discretion is the Regulation's and survives; a provider that executes in that case is departing from its supervisor's stated expectation and will have to say why.
The United Kingdom
Part 7A of the Money Laundering, Terrorist Financing and Transfer of Funds (Information on the Payer) Regulations 2017 has bound UK cryptoasset businesses since 1 September 2023.
The architecture differs from the EU's in three respects.
It carves the population by chain, not by value alone. Regulation 64C(3) applies where every cryptoasset business executing the transfer, intermediaries included, is carrying on business in the United Kingdom in respect of the transaction. Where it applies, only the 64C(5) data set accompanies the transfer — names, registered or trading name for a firm, account numbers or a unique transaction identifier — and the fuller 64C(6) data set on the originator is supplied within three working days if the beneficiary's business asks for it. Where 64C(3) does not apply, 64C(4) requires the fuller set to accompany transfers at or above the threshold, aggregated with any linked transfer.
The threshold moved this summer. The sum in 64C(4) is now £800, substituted with effect from 30 June 2026 by regulation 32 of the Money Laundering and Terrorist Financing (Amendment) Regulations 2026, S.I. 2026/621; regulation 33 makes the same substitution in 64G(1)(b). The sum it replaced was €1,000 — the figure JMLSG's sectoral guidance was still working to in its December 2025 update, which instructs firms to take the value at initiation and convert it into euros, and to use a euro trading pair or a conversionThe tort of treating someone else's goods as your own. Yuen v Li (2026) held it does not extend to crypto. through pairs that exist. Screening logic still expressed in euros is now applying a figure that has been superseded.
And £800 is not an arithmetic conversion — it is a deliberate one. The instrument's own Explanatory Note says it replaces euro references with sterling "on a 1:1 basis (for example, 10,000 euros becomes £10,000), except where to do so would risk failing to meet the recommendations … set by the Financial Action Task Force". The same policy appears at paragraph 5.6 of the explanatory memorandum.
The Note does not say which conversionsThe tort of treating someone else's goods as your own. Yuen v Li (2026) held it does not extend to crypto. are the exceptions. It gives a parenthetical list of the provisions that convert — and that list mixes both kinds, so it cannot be read as naming the exceptions: regulation 10(b) is in it and turns 1,000 euros into £1,000, while regulation 32 is in it and turns the same 1,000 euros into £800. The exceptions have to be identified from the figures themselves, and across the whole instrument only two are discounted: 1,000 euros to £800 in regulations 32 and 33, and 15,000 euros to £12,000 in regulation 14(b). Both are FATFThe Financial Action Task Force — the inter-governmental body, created by the G7 in 1989, whose Recommendations set the global anti-money-laundering standard. Not a law-maker: its power runs through peer review and its lists.-derived — 1,000 is the occasional-transaction threshold for virtual-asset service providers at INR.15 §7(a), 15,000 the threshold for financial institutions under R.10 — and everything else converts at par.
The reason is arithmetic. A one-to-one £1,000 would be worth more than the 1,000 euros it replaced, so it would catch fewer transfers than the FATFThe Financial Action Task Force — the inter-governmental body, created by the G7 in 1989, whose Recommendations set the global anti-money-laundering standard. Not a law-maker: its power runs through peer review and its lists. baseline. £800 restores the level. On this threshold the redenomination was done to hold the UK against the FATF standard, not to move away from it — which is worth knowing before reading the change as Brexit divergence. The most telling detail is that the same 1,000-euro figure went to £1,000 in one regulation and £800 in another, in a single instrument, on the same day: the difference is that one of them answers to FATF and the other does not.
Unhosted wallets are handled by permission, not obligation. Part 7A imposes no accompanying-information duty at all on an unhosted walletA wallet controlled directly by its user rather than by an exchange. transfer. Regulation 64G(1) says a cryptoasset business involved in one "may request" information from its customer — the 64C(5) data it does not already hold, and, at or above £800 where its customer is the beneficiary, the 64C(6) data on the originator. Whether to ask is governed by 64G(2), which directs the business to its own risk assessments under regulations 18(1) and 18A(1), and by the factors in 64G(3). The compulsion sits one paragraph later, in 64G(4): if the business asks and does not receive, it "must not make the cryptoasset available to the beneficiary".
Set against Article 14(5) of the EU regulation — obtain and hold the full data set for every self-hosted transfer regardless of value, and assess ownership above €1,000 — the UK's front end is materially lighter. Its back end is not: 64G(4) is an absolute bar once a request goes unanswered, and the EU regulation contains no equivalent.
The response to missing information is softer too. Regulation 64D(2) requires the beneficiary's business to request what is missing and to "consider" both making enquiries into discrepancies and delaying release, against the EU's requirement to reject, return or obtain before release. Repeated failure by a counterparty is reported to the FCA under 64D(5), and by intermediaries under 64E(5). Regulation 64H requires a full and prompt response to written law-enforcement requests.
Switzerland
Article 10 of the FINMA Anti-Money Laundering Ordinance requires the ordering party's financial intermediary to transmit, with payment orders, the ordering party's name, account number and address, and the beneficiary's name and account number. Where there is no account number, a transaction reference. The address may be replaced by date and place of birth, customer number or national identity number. The intermediary must ensure the ordering-party data are accurate and complete and the beneficiary data complete. No threshold qualifies any of it.
Article 10(2) carries a domestic derogation closely parallel to the EU's for funds: for payment orders within Switzerland the intermediary may send the account number or reference alone, provided it can supply the remaining ordering-party data to the beneficiary's intermediary and to the Swiss authorities within three working days of a request. Article 10(3) extends that route to domestic payment orders for goods and services where compliance with paragraph 1 is technically impossible.
FINMA confirmed that Article 10 already reaches blockchain payments in Guidance 02/2019 of 26 August 2019, on the ground that the provision must be read technology-neutrally, and confirmed that the information need not travel on-chain. The same document takes a harder line on external wallets than the FATFThe Financial Action Task Force — the inter-governmental body, created by the G7 in 1989, whose Recommendations set the global anti-money-laundering standard. Not a law-maker: its power runs through peer review and its lists. standards, and says so in terms:
"Unlike the FATFThe Financial Action Task Force — the inter-governmental body, created by the G7 in 1989, whose Recommendations set the global anti-money-laundering standard. Not a law-maker: its power runs through peer review and its lists. standards, Article 10 AMLO-FINMA does not provide for any exception for payments involving unregulated wallet providers. Such an exception would favour unsupervised service providers and would result in supervised providers not being able to prevent problematic payments from being executed."
What follows is a conditional near-prohibition. So long as a supervised institution is unable to send and receive the required information, transfers to and from external wallets are permitted only where the wallet belongs to one of the institution's own customers, and that customer's ownership "must be proven using suitable technical means". Transactions between customers of the same institution remain permissible. A transfer to or from a third party's external wallet is possible only if the institution has verified the third party's identity, established the beneficial owner, and proven the third party's ownership of the wallet — the treatment of a customer relationship, applied to a counterparty.
For the customer's own wallet the EU is more prescriptive than the Regulation alone suggests, and in a way that helps. Where the ownership assessment is engaged, the Guidelines name five methods and say a provider should use at least one: unattended verification under the remote-onboarding guidelines, with the address displayed; attended verification under the same guidelines; sending a predefined amount set by the provider — "preferably the smallest denomination of a given crypto-asset" — to and from the address; requiring the customer to sign a specified message with the key for that address; or other technical means, so long as they allow a "reliable and secure assessment" and the provider is fully satisfied it knows who owns or controls the address. Where one method is not reliable enough on its own, a combination should be used. Once fully satisfied, the provider documents it and "may not need to re-apply the measures above to subsequent transactions from/to the same address" — whitelisting — subject to controls that remove the address when risk or control changes.
Switzerland says nothing either way about persistence. Guidance 02/2019 requires ownership to be "proven using suitable technical means" and is silent on whether that proof carries over to later transfers to the same address. The EU expressly permits the provider not to repeat the exercise; Switzerland is silent, which is not the same as saying no.
The third-party case is where the two are most often set against each other, and the contrast is real but narrower than it looks. Where the assessment establishes that the address belongs to a third person, the Guidelines allow the verification limb of Article 19a(1), point (a), of Directive 2015/849 to "be deemed to have taken place" on corroborating data "including but not limited to blockchain analytical data, third-party data, recognised authorities' data and publicly available information", or by other means where the provider is fully satisfied and can demonstrate that to its supervisor. Switzerland, for so long as the institution cannot send and receive travel-rule information, requires the third party's identity to be verified as for a client relationship, the beneficial owner established, and ownership proven technically.
The two provisions are not doing the same work, and it is worth being exact about why. Article 19a(1) offers four mitigating measures of which a provider applies at least one, so a provider may never reach the verification limb at all; and the deeming in the Guidelines follows from the above-€1,000 assessment, not from every third-party transfer. The Swiss requirement is a precondition on the transfer itself, and it lapses once the institution can transmit. What survives the comparison is narrower and still worth having: on the evidence that verification has happened, the EU will take chain analytics, and Switzerland has never said it will.
On this reading of the texts, Switzerland is the most restrictive of the three on self-hosted wallets, the EU next, and the UK the most permissive on the face of the provision — though the comparison is not clean, because each regime restricts a different thing. Switzerland conditions its restriction on the institution's technical capability. The EU imposes an unconditional obtain-and-hold and a threshold-gated ownership assessment by one of five named methods, and permits whitelisting thereafter. The UK makes the request optional and the withholding absolute. What the texts do not support is the familiar assumption that the Swiss position is the most accommodating.
Where the three diverge
| EU · Reg. 2023/1113 | UK · MLRs Part 7A | CH · AMLO-FINMA | |
|---|---|---|---|
| Data on every provider-to-provider transfer | Full Art. 14(1)–(2) set | 64C(5) basic set | Art. 10(1) set |
| Value threshold for the travelling data | None | £800, non-UK-only chains, for the fuller 64C(6) set | None |
| Domestic derogation | None | 64C(3), fuller set on request in 3 working days | Art. 10(2)–(3), remainder on request in 3 working days |
| Self-hosted / unhosted wallets | Obtain and hold full set always; assess ownership above €1,000 by at least one of five named methods, whitelisting permitted thereafter (Arts. 14(5), 16(2); GL ¶¶83–86); for a third party's address above €1,000, chain analytics may evidence the Art. 19a(1)(a) verification limb (GL ¶89) | No accompanying duty; may request (64G(1)–(2)); must withhold if asked and not received (64G(4)) | No exception to Art. 10; where the institution cannot transmit, ownership proof by technical means or the transfer is not permitted (Guidance 02/2019) |
| Timing | Advance, simultaneous or concurrent, and no later than initiation of the blockchain transaction; not required on-chain (Art. 14(4); GL ¶25) | Must accompany; no channel provision | With the payment order; not required on-chain |
| Missing information inbound | Execute, reject, return or suspend on risk-based procedures; reject, return or obtain before release — and should not execute where a party cannot be unambiguously identified for want of complete or admissible information (Art. 17(1); GL ¶64) | Request, and consider enquiries and delay (64D(2)) | Intermediary defines its own risk-based procedure (Art. 10(5)) |
| Counterparty failure | Graduated steps or direct rejection, restriction or termination; report to the competent authority without undue delay and no later than three months after identification (Art. 17(2); GL ¶74) | Report repeated failure to the FCA (64D(5), 64E(5)) | Supervisory audit, then measures and deadlines, then enforcement — per FATF's account of Swiss practice, Box 3.7 |
| The 1,000-ish figure governs | Ownership assessment for self-hosted addresses (€1,000) | The fuller data set on non-UK-only chains (£800) | Identification of the contracting party (CHF 1,000, Art. 51a) |
The constraint is supervision
FATFThe Financial Action Task Force — the inter-governmental body, created by the G7 in 1989, whose Recommendations set the global anti-money-laundering standard. Not a law-maker: its power runs through peer review and its lists.'s June 2025 Best Practices on Travel Rule Supervision reports the 2025 survey results: 85 of 163 responding jurisdictions had passed legislation implementing the travel ruleThe requirement that sender and recipient identity data accompany crypto transfers between providers (FATF Recommendation 16)., against 65 in 2024 and 35 in 2023, with a further 14 in the process. Of the 85, approximately half — 49, which the report puts at 57% — restrict domestic providers to counterparties that are licensed, travel-rule compliant, or otherwise risk-mitigated. Nine permit their providers to transact with foreign counterparties regardless of licensing status, travel-rule compliance or mitigation. Nine of the 99 implementing or implementing-soon jurisdictions are running phased strategies, which the report describes as including "setting higher transaction thresholds for when compliance is required" and grace periods during which expectations are "more flexible or temporarily waived".
Three cautions on those numbers. The Global Network is 205 jurisdictions; 163 responded, and non-responders are assumed not to have implemented. The report carries three different denominators — 163 for the survey base, 117 for Figure 1.1, which is limited to jurisdictions that have neither prohibited providers nor announced plans to, and, at paragraph 14, "99 out of 164" for the same implementing population that paragraph 8 puts at 99 of 163. And the count is of legislation passed, which is the thing the report goes on to say is not the constraint.
On enforcement it is candid:
"Due to a number of jurisdictions still being in the process of implementing supervisory regimes for VASPsVirtual-asset service provider — an exchange, custodian or similar business handling crypto for customers., and the persistence of the Sunrise Issue, enforcement cases are often more limited in number in the VA sector than in other sectors."
It offers three readings of that scarcity: supervisors choosing engagement and education over enforcement in the early phase; supervisors "working with VASPsVirtual-asset service provider — an exchange, custodian or similar business handling crypto for customers. to remediate shortcomings, rather than at the point of taking enforcement action for ongoing or significant failures, which may have been identified and addressed at the licensing stage"; and that "the low number of enforcement actions may also reflect the challenges identified in this report with regards to Travel RuleThe requirement that sender and recipient identity data accompany crypto transfers between providers (FATF Recommendation 16). supervision". It does not choose between them, though it closes by noting a growing body of enforcement examples in jurisdictions with more mature frameworks.
What the published examples show is remediation rather than penalty. The FCA's case runs from multiple information requests in 2023, through segmentation of the registered population into high, medium and low risk, to intensive supervisory action against the highest tier including firm visits. The one travel-rule case described ends in an agreed remediation plan: integrate a second tool, write compliant policies, and remediate the non-compliant back book. A supervisory engagement a year later confirmed the work done, with "the only outstanding issues related to the Sunrise Issue". Switzerland's example begins with a criminal investigation into a drug-trafficking ring using a provider's crypto-ATM network and FINMA intervening through the self-regulatory body then responsible, to stop that provider's ATM exchange operations entirely; it goes on to describe the regulatory tightening that followed and a supervisory practice of regular audits, with measures and deadlines ordered on non-compliance and enforcement — in serious cases licence withdrawal or exclusion — where implementation does not follow.
FATFThe Financial Action Task Force — the inter-governmental body, created by the G7 in 1989, whose Recommendations set the global anti-money-laundering standard. Not a law-maker: its power runs through peer review and its lists. names the sunrise problem — uneven adoption, so that a compliant provider cannot complete a compliant transfer with a counterparty whose regulator does not require one — as "the single largest obstacle to effectively implementing the Travel RuleThe requirement that sender and recipient identity data accompany crypto transfers between providers (FATF Recommendation 16).", and says it will explore next steps. It also records that a revised Recommendation 16 and its interpretive note were adopted in June 2025, following consultations in 2024 and 2025, and that guidance on how the revised framework applies to virtual assets is still to come. Because Interpretive Note 15.7(b) applies R.16 to virtual-asset transfers by cross-reference, that revision reaches the crypto travel rule without amending anything that names it.
Key takeaways
- The three headline figures are not comparable. €1,000 governs ownership assessment for self-hosted addresses; £800 governs the fuller data set on chains that are not wholly UK; CHF 1,000 governs whether a customer is identified at all.
- None of the three sets a value below which a provider-to-provider transfer carries nothing.
- The EU is the only one of the three with no domestic derogation. A Union-only chain carries the same full data set as a transfer to a third country.
- The UK's threshold changed from €1,000 to £800 on 30 June 2026. Screening logic still expressed in euros is applying a superseded figure.
- The EU regime is two documents. Reading Regulation 2023/1113 without EBA/GL/2024/11 misses the transmission cut-off, the response clocks, the expectation that a transfer is not executed where a party cannot be identified, and the methods for verifying a self-hosted address. The Guidelines are shoulds, and both authorities and firms are told to make every effort to comply.
- On self-hosted wallets the texts do not support the usual assumption: Switzerland restricts most, the EU next, the UK least — though each restricts a different thing. On a third party's wallet above €1,000 the EU will take chain analytics as evidence that verification happened; the Swiss requirement to identify the third party as a client is a precondition on the transfer, and it lapses once the institution can transmit travel-rule data.
- FATFThe Financial Action Task Force — the inter-governmental body, created by the G7 in 1989, whose Recommendations set the global anti-money-laundering standard. Not a law-maker: its power runs through peer review and its lists. reports 85 of 163 responding jurisdictions with travel-rule legislation, and enforcement cases "more limited in number in the VA sector than in other sectors", without deciding whether that reflects supervisory choice or supervisory capacity.
Sources
European Union
- Regulation (EU) 2023/1113 of the European Parliament and of the Council of 31 May 2023 on information accompanying transfers of funds and certain crypto-assets and amending Directive (EU) 2015/849 (recast), OJ L 150/1, 9 June 2023 — Arts. 2, 3(20), 5, 6, 14, 15, 16, 17, 40. EUR-Lex · held as the Official Journal PDF; read 24 August 2026.
- EBA, Guidelines on information requirements in relation to transfers of funds and certain crypto-assets transfers under Regulation (EU) 2023/1113 ('Travel RuleThe requirement that sender and recipient identity data accompany crypto transfers between providers (FATF Recommendation 16). Guidelines'), EBA/GL/2024/11, final report 4 July 2024, applying from 30 December 2024 — paras. 21–26, 35–41, 47–51, 56, 64, 74, 81–89. EBA · held; read 24 August 2026. Whether a given national authority complies is recorded in the EBA's compliance table, which this practice holds and read on 24 August 2026: as at the table's own update of 17 March 2026, 24 declarations record compliance and 12 record an intention to comply, several of the latter conditional on national legislation. Those are declarations, not a measurement of supervisory practice.
United Kingdom
- The Money Laundering, Terrorist Financing and Transfer of Funds (Information on the Payer) Regulations 2017, S.I. 2017/692, Part 7A, regs. 64A–64H. legislation.gov.uk · text held as generated 26 July 2026, stated to be up to date with all changes in force on or before that date. Part 7A inserted with effect from 1 September 2023 by S.I. 2022/860, regs. 1(3), 5(5).
- The Money Laundering and Terrorist Financing (Amendment) Regulations 2026, S.I. 2026/621, as made 9 June 2026 — regs. 1(2), 32 and 33. Regulation 32 reads: "In regulation 64C(4), for '1,000 euros' substitute '£800'." Regulation 33 is identical for 64G(1)(b). In force 30 June 2026, being 21 days after the day of making (reg. 1(2)). The conversionThe tort of treating someone else's goods as your own. Yuen v Li (2026) held it does not extend to crypto. policy — 1:1 except where that would risk failing to meet the FATFThe Financial Action Task Force — the inter-governmental body, created by the G7 in 1989, whose Recommendations set the global anti-money-laundering standard. Not a law-maker: its power runs through peer review and its lists. Recommendations — is in the Explanatory Note to the instrument, and more generally at paragraph 5.6 of the explanatory memorandum. The Note's parenthetical list of converting provisions does not distinguish the exceptions: it includes reg. 10(b), which converts 1,000 euros to £1,000, alongside reg. 32, which converts 1,000 euros to £800. Compare reg. 14(a)–(e), which converts 1,000 to £800 and 15,000 to £12,000 but 10,000 to £10,000 and 2,000 to £2,000. legislation.gov.uk · held; read 24 August 2026.
- JMLSG, Prevention of money laundering / combating terrorist financing: Guidance for the UK Financial Sector, Part II (sectoral), June 2023, updated December 2025 — Annex 22-I, Cryptoassets Transfers ('Travel Rule'), paras. 1, 13 and 45, for the valuation and conversionThe tort of treating someone else's goods as your own. Yuen v Li (2026) held it does not extend to crypto. method, and as the guidance firms were working to before the substitution. JMLSG · held; read 24 August 2026.
Switzerland
- Verordnung der Eidgenössischen Finanzmarktaufsicht über die Bekämpfung der Geldwäscherei und der Terrorismusfinanzierung im Finanzsektor (GwV-FINMA / AMLO-FINMA), SR 955.033.0 — Arts. 10, 51a, 52. Held in the German original, Stand 1 January 2023; read 24 August 2026. Fedlex
- FINMA Guidance 02/2019, Payments on the blockchain, 26 August 2019. FINMA
FATF
- FATFThe Financial Action Task Force — the inter-governmental body, created by the G7 in 1989, whose Recommendations set the global anti-money-laundering standard. Not a law-maker: its power runs through peer review and its lists. (2025), Best Practices on Travel Rule Supervision, FATF, Paris — paras. 8–11, 13–17, 39–40, 43–45; Figure 1.1 and footnote 6; Boxes 1.1, 2.1, 3.1, 3.7. fatf-gafi.org · held; read 24 August 2026.
Research and analysis, not legal advice · this piece compares the text of three regimes and does not assess any firm's compliance with any of them · positions stated as at 24 August 2026 · the UK sums in regs. 64C(4) and 64G(1)(b) changed on 30 June 2026, the Swiss ordinance is cited at Stand 1 January 2023, and FATF guidance on the revised Recommendation 16 as it applies to virtual assets had not been published at that date · check the instruments in force.