AMLConsensus · course
Programme · Lesson 1.2
Section 1 · Lesson 1.2

FATF, VASPs and the Travel Rule: who regulates crypto and how

When an exchange asks you to state to whom and where you are sending your coins, it isn't just being fussy. Behind that requirement stands an international standard adopted by dozens of countries. Let's trace where the rules come from: what FATF is, why the notion of a VASP emerged, and how the Travel Rule is changing the everyday user experience.

What FATF is

FATF (the Financial Action Task Force) is an intergovernmental body created in 1989 by the G7 nations. Its mission is to develop global standards for combating money laundering and terrorist financing. FATF does not pass laws directly: it formulates 40 Recommendations, and member states then translate them into their own legislation.

Formally this is "soft law" — recommendations. But FATF has a powerful lever: its lists of jurisdictions. The "grey list" (increased monitoring) and the "black list" (countries with critical deficiencies) sharply worsen a country's access to the international financial system. Banks in other countries begin treating payments from there with suspicion, correspondent relationships are severed, investment becomes more expensive. So even nominally optional recommendations end up being implemented quite obligatorily.

Why this matters. The rules that cause your transaction to be checked on an exchange anywhere in the world all trace back to a single source. That is exactly why AML procedures at an exchange in the UAE, in the EU and in Singapore look so similar — they all implement the one FATF standard.

Recommendation 15 and extending the rules to crypto

For a long time cryptocurrencies lived outside the perimeter of these rules. That changed in 2018–2019, when FATF updated Recommendation 15 ("New Technologies") and issued separate guidance on virtual assets. The key point: virtual assets and the businesses that work with them must be subject to the same AML/CFT requirements as traditional financial institutions. That is how two new terms entered the regulatory vocabulary — VA (virtual asset) and VASP.

Who VASPs are

A VASP (Virtual Asset Service Provider) is any business that carries out crypto operations on behalf of clients. The category covers:

The crucial dividing line is custody. If a service controls your keys and disposes of the funds (an exchange holds your balance), it is a VASP with all the obligations of KYC and monitoring. If you use a non-custodial wallet (MetaMask, Trust Wallet), where the keys are yours alone, then the wallet itself is not a VASP. This boundary is the subject of constant regulatory dispute, especially around DeFi and decentralised exchanges.

VASP or not a VASP — a quick guide

The Travel Rule in practice

The part of the standard most tangible for the user is the Travel Rule, which comes from Recommendation 16. In traditional banking it has been in force for a long time: when money is transferred, information about the sender and recipient "travels" along with it. FATF extended this to crypto.

The essence: when one VASP sends virtual assets to another VASP above a threshold (FATF proposes a benchmark of USD/EUR 1,000, but countries set their own figures), the sending party is obliged to pass the receiving party the participants' details: the sender's name, their account number/address, the recipient's name, and sometimes an address and identifier. These data are transmitted not on the blockchain itself but over separate secure protocols between exchanges (for example, TRP, OpenVASP, and various providers' solutions).

Exchange A
sender + KYC
Travel Rule
party data
Exchange B
recipient

In parallel, the coin itself moves over the blockchain, while an "accompanying sheet" with the identification data travels over the secure channel. The receiving exchange checks who is named as the sender and assesses the risk.

What this means for exchange users

A few years ago, withdrawing crypto from an exchange was simple: paste an address, hit send. Today the Travel Rule is changing that experience, and here is exactly how.

  1. The "who are you sending to" question. The exchange asks whether the recipient address belongs to you or to a third party, and sometimes for the recipient's name and exchange.This is a direct consequence of the duty to pass the data along with the transfer.
  2. Verifying ownership of the address. To confirm that an external wallet is yours, the exchange may ask you to sign a message with your private key (a Satoshi test) or make a micro-transfer.
  3. Limits on withdrawals to non-custodial wallets. In some jurisdictions such withdrawals require additional address verification, and limits are lower without it.
  4. Delays and queries on inter-exchange transfers. If the Travel Rule data don't match, the receiving party may hold up the credit and request clarification.
Take note. Giving deliberately false information about the recipient (for example, that the wallet is yours when it belongs to someone else) is a bad idea. A mismatch between the Travel Rule data and the real picture on the blockchain is itself an alarm signal and grounds for a freeze.

The practical takeaway

So: FATF sets the rules, VASPs carry them out, and the Travel Rule is the mechanism you run into directly with every withdrawal. In the next lesson we move from the model of money laundering to the concrete tracing tools, risk scoring and the specifics of individual networks.

This material is for educational purposes and does not constitute legal advice.