加密货币“旅行规则”合规实务指南
加密货币 旅行规则合规 不仅仅是转账前填写的一份表格。它是一个将实体分类、客户与交易对手身份识别、制裁控制、安全数据交换、异常处理以及证据保留连接起来的运营模式。您所需要的结果很简单:每一笔纳入范围的转账都应具备可抗辩的决策轨迹,无论该交易是被放行、暂停、拒绝还是升级处理。.
对于虚拟资产服务提供商、银行和加密货币中介机构而言,实际上面临的挑战是:规则虽源自全球,但却是在本地实施。金融行动特别工作组(FATF)提供了国际标准。各项国家法律(包括欧盟《资金转移条例》(TFR)和英国监管框架)则确立了企业实际必须遵循的操作规则。因此,一个可靠的合规计划应从适用于该笔转账的更严格规则着手,而不是采用单一的全球门槛。.
重要提示:本指南属于通用业务运营信息,而非法律意见。贵司的法律与合规团队应将各项业务流程与适用于贵司实体、客户及交易对手的法律、牌照及监管期望进行逐一对照。.
主要收获
- 将旅行规则视为端到端控制:信息交换只是流程的一部分。分类、筛选、决策、记录保存和报告必须与其紧密相连。.
- 不要将 1,000 美元/欧元视为普遍豁免:FATF 在其虚拟资产框架中使用了 1,000 美元/欧元的指定门槛,但地方规则可能更严。欧盟关于 CASP 之间转账的 TFR 义务并非基于普遍的微量豁免。.
- 明确发起方和受益方角色:发起虚拟资产服务提供商(VASP)负责准确收集和传输信息。受益 VASP 必须检查传入信息、应用本地验证规则并控制不完整的转账。.
- 建立对手方能力登记册:应对牌照状态、管辖权、协议支持、制裁暴露、数据质量历史以及升级联系人进行记录并持续审查。.
- 将数据标准与传输通道分离开来:IVMS101风格的数据结构可以提高互操作性,但您的团队仍然必须验证交易对手、加密、确认信息、错误以及审计证据。.
- 为证据而设计,而非仅仅为了完成:交接应产生已收集数据、筛选结果、审批、消息、确认、异常情况和最终处理结果的完整追踪记录。.
- 使用本文作为基础,制定一份涵盖治理、数据字段、控制措施、交易对手、集成测试和审计就绪性的内部检查清单。行动号召 (CTA):申请 投资玻璃 演示如何讨论一个可配置的合规工作流。.

图1. 一个实用的旅行规则(Travel Rule)流程。关键控制点是决策关卡:数据不全或风险不可接受必须导致有记录的升级处理,而不是未作记录的变通做法。.
加密货币的旅行规则合规性:FATF 的使命与第 16 号建议是什么?
FATF是反洗钱领域的国际标准制定机构洗钱, ,打击恐怖主义融资和打击扩散融资。其建议旨在供各国通过国内法律和监管措施实施,因此不能替代对每个相关司法管辖区规则手册的查阅。.
加密货币旅行规则介于FATF关于虚拟资产和虚拟资产服务提供商(或称VASPs)的框架之间。FATF的虚拟资产材料规定,VASPs应采取可比拟金融机构的预防措施,包括 客户尽职调查, ,记录保存以及可疑交易报告。它还要求他们在进行虚拟资产转账时获取、保存并安全传输汇款人和收款人的信息。.
建议16(在此语境下通常被称为“旅行规则”)涉及支付透明度。对于虚拟资产,该解释性框架要求发起方VASP获取并保存所需且准确的发起方信息以及所需的收款方信息,将其提交给收款方VASP或对手方,并在收到请求时提供给主管当局。收款方VASP必须获取并保存所需的发起方信息以及所需且准确的收款方信息。.
FATF 最近的更新有哪些变化?
建议第16号在2025年的修订使支付透明度标准得以现代化,但其实施时间表至关重要。金融行动特别工作组(FATF)在2025年6的全会上同意了这些修改,包括明确支付链中各方的责任、针对某些超过1,000美元/欧元的跨境支付设定标准化的信息要求,以及能够减少欺诈和错误的工具。FATF表示,这些修订后的标准将在2030年底前生效。.
您的“旅行规则”项目应记录该区别。现行的虚拟资产要求现在必须根据地方法律付诸实施。2025年支付透明度修订版是一项重要的前瞻性调研输入,特别是对于同时运营支付服务的集团而言,但它们不应被误传为在每个司法管辖区都立即生效的新的加密货币特定要求。.
FATF最新的虚拟资产实施更新也表明了为什么运营成熟度至关重要。同样的更新强调了围绕离岸VASP、托管钱包活动、稳定币、去中心化金融以及有效监管的持续问题。.
“FATF标准的有效实施已刻不容缓,”FATF主席吉尔斯·汤普森(Giles Thomson)在发布2026年7月更新时表示。他呼吁采取更强的预防措施、开展跨境合作,并建立能够跟上不断演变的犯罪手法的保障机制。.
基准美元/欧元 1,000 的门槛:这意味着什么,又没意味着什么
USD/EUR 1,000 是 FATF 的基准,但这并不意味着普遍允许省略该金额以下的控制措施。FATF 关于虚拟资产的解释性备忘录将 USD/EUR 1,000 设定为临时交易的指定门槛,超过此门槛时,虚拟资产服务提供商 (VASP) 必须开展客户尽职调查。更广泛的“旅行规则”要求、基于风险的控制、制裁限制以及国内规则依然重要。.
在实际操作中,应将金额作为规则引擎中的一个字段使用,而不是唯一字段。涉及受制裁钱包指标、高风险司法管辖区、新发现的对手方VASP、重复关联转账或托管钱包的小额转账,可能需要加强审查。相反,仅凭金额门槛无法替代持续的尽职调查、筛查或可疑活动评估。.
专业提示:配置您的策略,使引擎能够对价值、关联转账聚合、地理位置、钱包类型、交易对手状态、客户风险和交易类型进行综合评估。保存每次做出决策时所使用的规则版本。.
金融机构与加密货币旅行规则
金融机构应将加密货币“旅行规则”(Travel Rule)视为基于风险的金融犯罪项目中的一项可溯源性控制措施,因为它有助于更广泛的金融系统打击洗钱和恐怖主义融资。这使得利用缺乏完整身份信息的转账渠道变得更加困难,并有助于企业将区块链交易与其背后的各方、机构及相关决策联系起来。这种可溯源性支持预防和调查工作,包括打击洗钱以及应对洗钱和恐怖主义融资风险的努力。.
控制的理由不仅限于洗钱。FATF的2026年更新指出了日益关联的风险,涉及有组织诈骗、网络盗窃、制裁规避、稳定币、非托管钱包以及跨境洗钱。这些威胁需要一种能够在不造成不受控制的数据暴露的情况下共享关键信息的运营模式。.
为什么制裁筛选属于转账工作流程
制裁管控需要成为转账时决策的一部分,而不是独立的定期行动。FATF虚拟资产框架将第16项建议的要求与针对指定个人和实体的监控、冻结行动及禁令结合适用。欧盟《资金转移条例》(TFR)同样要求制定内部政策、程序和管控措施以支持限制性措施。.
设计良好的工作流程会对客户、可识别的受益人、相关的钱包地址、受益人虚拟资产服务商(VASP)、相关的法人实体以及适用的地理指标进行筛查。它还会保存筛查提供商、搜索的名单、时间戳、匹配逻辑、分析人员的处置意见和批准记录。这为放行转账或采取适当行动创造了可辩护的依据。.
这就是互联系统发挥作用的地方。. InvestGlass 操作风险管理工作流 能够帮助团队将筛查警报、异常案例、审批人及其整改措施与底层客户和转账记录关联起来,而无需将证据分散在收件箱和电子表格中。.
跨境合规是一个编排问题
跨境转移必须满足转出机构、接收机构和相关司法管辖区的要求,同时保留清晰的审计线索。不同的定义、门槛、实施日期和数据处理期望会产生运营摩擦。这种不均衡的采用通常被称为日出问题。恰当的应对方式是采用考虑当地法规的辖区感知决策矩阵以及有记录的交易对手政策,而不是非正式的逐案假设。.
例如,即使海外交易对手方尚无法接收所选的“旅行规则”信息,发送机构也可能需要保留并核实信息。英国金融行为监管局(FCA)期望英国的加密资产企业采取合理步骤并进行尽职调查,然后根据其他司法管辖区是否已实施“旅行规则”来调整其流程。.
资产服务提供商、VASPs及其涵盖范围
适用范围始于您的组织所开展的活动,而非其营销材料上印制的标签。FATF使用“VASP”一词来指代从事受监管的虚拟资产活动的业务。广泛的类别包括:虚拟资产与法定货币之间的兑换、一种或多种形式虚拟资产之间的兑换、虚拟资产的转移、虚拟资产或能够控制虚拟资产的工具的保管或管理、以及参与或提供与发行人发售或出售虚拟资产相关的金融服务。.
因此,即便某个企业自称为交易所、经纪商、托管机构、钱包提供商、数字资产平台、场外交易(OTC)服务台、支付公司、银行或技术提供商,它也可能属于监管范围内。法律分析取决于具体的业务活动、司法管辖区以及谁在控制转移或客户关系。金融行动特别工作组(FATF)还期望各国对虚拟资产服务提供商(VASP)进行许可或注册,并基于风险敏感原则对其进行监管。.
框架还是市场 | 常见受监管实体标签 | 运营 implication的翻译可以根据具体语境选择: 业务影响 / 运营影响 / 对运营的影响 |
FATF全球标准 | VASP | 确定您的业务是否从事受监管的虚拟资产活动并必须实施反洗钱/打击资助恐怖主义(AML/CFT)合规管控。. |
欧洲联盟 | 加密资产服务提供商,即 CASP | 应用欧盟资金转移条例(TFR)的转让信息控制,并评估MiCA授权、过渡期状态及国家监管。. |
英国 | 加密资产业务 | 在洗钱防范框架下应用英国旅游规则(Travel Rule)的期望,包括跨境风险处理。. |
您的组策略 | 范围内的传输算子 | 建立一个中立的内部分类,适用于发起、接收、控制或中介相关转账的任何法律实体。. |
如何分类您的实体状态
在设计技术集成之前,请创建一个实体与活动清单。列出每个集团法律实体、其注册和运营司法管辖区、提供的服务,, 服务的客户, ,牌照或注册状态、钱包控制模式、外部交易对手方以及转账角色。随后询问谁接受客户指令、谁控制钱包或账户、谁发送资产、谁接收资产以及谁可以暂停转账。.
记录法律结论、保单持有人、所依赖的建议或来源、审查日期以及受影响的具体工作流。每当推出新产品、钱包架构发生变化、进入新市场或第三方开始执行转移步骤时,都要重复此项工作。这比假设软件供应商、网络参与者或品牌关联方自动在范围之外更为可靠。.
为了业务执行,一个 专为加密货币经纪商设计的CRM 可以保留 客户生命周期 将数据、交易上下文、合规任务与审批紧密相连。它不能取代法律分类或旅行规则网络,但它可以成为您的团队记录每项结论的可控环境。.
发起人和受益人的角色与义务
发起方虚拟资产服务提供商(VASP)负责收集和传输所需的转移信息,而受益方 VASP 必须验证到达的信息并实施其自身的本地控制措施。双方都需要明确的权责归属,因为技术上成功的区块链转移并不证明合规信息是完整、准确或经过适当处理的。.
发起方是发出转账指令的个人或实体。受益人是指定的收款人。在虚拟资产服务提供商(VASP)对VASP的转账中,发起方VASP服务于发起人,受益方VASP服务于受益人。在某些流程中,中介服务提供商也可能负有确保信息在整个转账链中保持可用的职责。.
信息类别 | 发起方 VASP 责任 | 受益方 VASP 责任 |
发起方身份 | 收集所需的身份数据,在当地法规要求的地方进行验证,并在发布前确保其准确无误。. | 接收、评估完整性并连同移交记录一起保存。. |
受益人身份 | 从发起方收集所需的受益人信息,并通过安全通道进行传输。. | 根据适用的制度要求,在提供资产之前,核实受益人信息或身份。. |
钱包或账户参考 | 将正确的分布式账本地址或账户引用与消息和转账关联起来。. | 确认收到的参考信息可以与受益人或转账指示进行核对。. |
筛查与风险审查 | 在放款前审查交易方、对手方和钱包上下文,然后将异常情况升级处理。. | 在入账或释放款项之前,审查并复核收到的汇款、受益人以及任何相关的风险指标。. |
缺少信息 | 填补数据空白,记录外联情况,并根据政策要求暂停或拒绝。. | 应用有案可稽的执行、暂挂、拒绝或退回决策流程,包括对重复失败的升级处理。. |
最小数据模型:使用结构化字段,而非自由文本
您的数据模型应将身份、账户、地址、管辖区、验证和消息状态字段分离开来。FATF的框架指的是建议16或其虚拟资产等效项中规定的必需的发起人和受益人信息。在适用规则允许的情况下,实际基准通常包括发起人的姓名和账户或钱包参考信息,外加地址、国民身份或客户标识符,或者出生日期和地点。受益人基准通常包括姓名和账户或钱包参考信息。.
不要将钱包地址等同于经过验证的自然人或法人实体。该地址是一个技术目标参考。 身份验证, ,所有权或控制权评估与客户记录是各自独立的控制措施。欧盟《资金转移条例》(TFR)摘要明确提到了姓名、分布式账本地址以及加密资产账号,这说明了为什么机构必须同时对身份和账本引用进行建模。.
发起方 VASP 操作
发起方虚拟资产服务提供商(VASP)在完成一系列有据可查的收集、验证、筛选和安全传输步骤之前,不应放行属于监管范围内的转账。该系列步骤需要能够快速执行,同时也必须留存可供审核人员事后理解的证据。.
1. 在转账前收集所需的汇款人字段
首先从客户记录中检索已验证的客户数据,而不是要求用户每次重新输入。如果记录陈旧、与指令不符或对于接收司法管辖区而言不充分,则要求进行确认或刷新。在批准交易之前,在结构化字段中收集受益人详细信息,并验证钱包地址格式、网络、资产和账户信息。.
使用 InvestGlass KYC 和 KYB 工作流 将入职数据与后续的转移控制对齐。当身份和实体数据被捕获在可重复使用的受控记录中时,交易工作流可以引用经过验证的来源,而不是创建冲突的副本。.
2. 筛选发起人、受益人、钱包和交易对手
筛查的实施时间既要足够接近执行环节以便识别新的限制,又不能过于滞后,以免运营团队没有时间处理真正的命中。您的政策应明确界定名单来源、匹配规则、人工审核期望、升级路径以及决策权限。如果使用了区块链分析或钱包风险工具,应将分析结果及理由连同合规案例一并存档。.
专业提示:遭遇制裁、高风险钱包暴露或不良交易对手信号时,应建立结构化案件并要求给出明确的处理结果。绝对不允许分析师在未作记录的聊天消息或电子邮件串中清除异常。.
3. 将数据安全地传输至受益方 VASP
旅行守则并不要求将个人数据直接嵌入区块链。FATF 明确指出,这些信息不必直接附加到虚拟资产转账中。请使用安全的链外消息通道,该通道需具备身份验证的对手方、传输加密、访问控制、消息完整性检查以及接收凭证。.
在广播或发布之前,确保消息与账本划转能够通过共同的交易标识符、划转参考号或钱包映射进行核对。记录消息发送的时间、是否已送达、受益人是否已确认以及划转是否随后已释放。.
InvestGlass 旅行规则工作流 旨在围绕数据请求、客户记录、审批和凭证来组织运营活动。该运营层可以通过确保相关审查和审计流程与客户关系保持紧密相连,来对专业消息网络形成补充。.
受益人 VASP 操作
受益方虚拟资产服务提供商(VASP)应在使加密资产可用之前,验证随附或随后发送至的转账信息,然后保留其决策的证据。接收数据并不等于接受数据。您的合规项目需要针对完整性、一致性、制裁以及本地身份要求进行有记录的审查。.
1. 接收并验证传入的发起方数据
根据报文模式和您的司法管辖区规则验证必填字段。检查报文是否与传入转账相关、发送方交易对手是否被认可、其发送方身份是否与注册的交易对手档案相符,以及数据是否在内部保持一致。具有有效技术签名的报文仍然可能包含不足或不合理的客户数据。.
设定客观的缺陷代码,例如缺失发起方名称、地址格式无效、未注册的交易对手、钱包不匹配以及无回执。这些代码使趋势监控成为可能,并为您的交易对手管理团队提供讨论反复出现的问题的依据。.
2. 根据当地规则验证受益人身份
接收机构应当了解受益人是现有的已验证客户、新入职的个人、需要进行KYB(了解您的企业)审查的实体,还是连接至托管钱包的地址。当当地法律或风险要求时,请验证或更新受益人信息。欧盟《资金转移条例》(TFR)摘要规定,受益人加密资产服务提供商(CASP)在向受益人提供加密资产之前,需验证受益人信息的准确性。.
The appropriate evidence may include a current customer record, cryptographic proof, a signed message, a micro-transfer or other risk-appropriate wallet-control process. The method should be proportionate and approved by your legal and privacy teams. Do not choose a verification approach solely because it is convenient for a particular counterparty.
3. 保留转移记录以便审计
A reviewer should be able to move from a blockchain transaction to the client record, message payload, counterparty file, screening decision, approval and final disposition without reconstructing events manually. EU TFR requires relevant originator and beneficiary information to be retained for five years, with a possible extension of a further five years where a Member State decides.
Retention should also support data minimisation, role-based access, lawful cross-border transfers of personal data, deletion controls and legal holds. Compliance evidence needs to be available to authorised staff and authorities, but it should not become an unmanaged repository of sensitive data.
FATF 旅行规则要求和门槛
The most robust operating rule is to apply the required data set and verification standard for the transfer’s applicable jurisdiction, then document why that rule was selected. The global FATF framework establishes the minimum direction. It does not prevent a jurisdiction from imposing broader or stricter requirements.
Control point | FATF-oriented baseline | Operational design response |
Customer due diligence threshold | USD/EUR 1,000 is the designated threshold for occasional virtual-asset transactions requiring CDD. | Treat the threshold as one rule condition. Do not use it to bypass sanctions, suspicious-activity or local Travel Rule obligations. |
Originator information | Obtain and hold required, accurate originator information and transmit it to the beneficiary VASP or counterparty. | Maintain a structured source-of-truth record with verification status, timestamp and permitted data variants. |
Beneficiary information | Obtain required beneficiary information, and beneficiary VASPs hold required, accurate beneficiary information. | Capture beneficiary identity and wallet or account details separately, then validate against the receiving relationship. |
Freezing and prohibited transfers | Monitoring, freezing and prohibited-person controls continue to apply. | Integrate sanctions decisioning before release and at receipt, with an auditable escalation path. |
Linked transfers | A risk-based programme must look beyond a single transfer’s face value. | Aggregate linked instructions by customer, beneficiary, wallet, counterparty, timing, asset and behavioural pattern. |
阈值以上验证与关联传输聚合
When a transaction is at or above the applicable threshold, verification must be planned before the transfer clock starts. Your system should identify the trigger early, route it to the required verification and prevent release if the evidence is missing or inconsistent. The exact verification requirement and threshold depends on the local regime, customer status and risk classification.
Aggregation is equally important. A sequence of transfers can be related by the same customer, beneficiary, wallet, counterparty, purpose, asset, time period or instruction pattern. Define the aggregation logic in policy, set a review window and preserve the evidence showing why a set of transfers was or was not treated as linked. This is a central control against structuring and threshold evasion.
跨境传输的阈值和数据字段
Cross-border teams should maintain a configurable rules matrix rather than hard-code one global threshold or data template. FATF, the EU and the UK illustrate why: the international baseline, directly applicable EU regulation and national UK approach cannot be reduced to one simple value test. Singapore is another useful example for virtual currency 和 va transfers, because its Travel Rule threshold for digital payment tokens is SGD 1,500.
场景 | Practical data expectation | Key caution |
|---|---|---|
Below FATF USD/EUR 1,000 baseline | A reduced approach may be available under the applicable implementation, but capture sufficient identity, wallet and risk data to support screening and investigation. | Below threshold does not mean below risk. Apply local law and your risk rules. |
At or above FATF USD/EUR 1,000 baseline | Use the complete required originator and beneficiary dataset, including names and account or wallet references plus the applicable originator identity locator. | Validate the correct data variant before sending. Do not rely on unstructured notes. |
EU CASP-to-CASP transfer | Include originator and beneficiary information, such as names, distributed-ledger addresses and crypto-asset account numbers, according to TFR requirements. | Do not assume a general de minimis value exemption for CASP-to-CASP transfers. |
EU transfer involving a self-hosted address over EUR 1,000 | Apply the TFR ownership-or-control verification assessment for the relevant self-hosted address. | The check concerns control or ownership of an address, not merely that an address was supplied. |
UK cross-border transfer | Collect, verify and share information as required, while adapting to the receiving jurisdiction’s Travel Rule implementation status. | If the counterparty cannot receive the information, preserve the UK firm’s collection and verification evidence before sending. |
Singapore transfer involving digital payment tokens at or above SGD 1,500 | Apply the full Travel Rule dataset required under Singapore’s implementation for digital payment tokens. | Use the Singapore threshold, not a generic global baseline, when determining required data. |
为什么包含钱包地址至关重要
Every in-scope virtual-asset message needs a reliable link to the blockchain transfer. The distributed-ledger address, crypto-asset account number, transaction hash, network and asset reference are not optional implementation details. They enable reconciliation between a Travel Rule message and the on-chain movement, support screening, and give investigators a path from a transaction to a customer and counterparty record.
Use validation rules that prevent asset and network confusion. An address that is syntactically valid can still be incorrect for the asset, network, beneficiary relationship or instruction. Build a four-eyes review or customer confirmation process for higher-risk transfers and address changes.
跨境汇款与资金监管
Determine which funds- or crypto-transfer regulation applies before you choose the workflow, data set and decision rights. A multi-jurisdictional group should identify the sender’s location, recipient location, booking entity, service-provider locations, customer residency, transfer path, wallet type, asset, value and counterparty. That data enables legal counsel to map the controlling rules and teams to configure the correct operational path.
For EU-facing firms, TFR extends transfer-information requirements to crypto-assets and applies from 30 December 2024. It is linked to the broader MiCA framework, which sets uniform EU market rules for crypto-assets and establishes authorisation and supervisory arrangements for CASPs.
实施跨境管制,切勿混淆支付与加密货币规则
Do not copy a banking payment control into crypto operations without testing whether the law and technology support it. FATF’s revised Recommendation 16 includes requirements to use tools that protect against fraud and error, such as verification of recipients’ banking information, as part of its future payment-transparency updates. Those changes come into effect by the end of 2030.
A crypto firm can still use recipient-confirmation controls today as good risk management, for example by checking the beneficiary customer record, validating wallet ownership where required, confirming address changes or applying a cooling-off review for anomalous transfers. However, label the control accurately. Do not state that a bank-style confirmation-of-payee obligation automatically applies to all virtual-asset transfers.
使用更严格的规则策略来协调冲突的阈值
Your rules engine should compare: the sending entity’s home rule, the receiving entity’s rule, the customer’s status, the counterparty jurisdiction, the wallet type and the group’s risk appetite. Where requirements differ, a well-governed policy may apply the stricter applicable requirement or route the case for legal review. The policy must identify its legal basis and avoid creating unnecessary data collection where it is not lawful or proportionate.
针对交易对手的尽职调查与强化尽职调查
Counterparty due diligence is the control that turns an anonymous endpoint into a risk-assessed VASP relationship. Before a high-risk or recurring VASP-to-VASP relationship is permitted, establish who the counterparty is, where it is regulated, what services it performs, how it authenticates participants, which Travel Rule protocol it supports and how it handles exceptions.
FATF’s 2026 update identifies persistent challenges in identifying entities that perform VASP activity, controlling offshore VASPs and turning legal frameworks into effective supervision. These findings support a conservative, evidence-led approach to counterparty onboarding and periodic review.
VASP对VASP尽职调查步骤
Due-diligence step | Evidence to request or verify | Ongoing control |
Legal identity and licensing | Legal name, registration identifier, registered address, ownership information, licence or registration details, regulator and relevant permissions. | Refresh against regulator registers and counterparty attestations on a risk-based schedule. |
Service and jurisdiction profile | Services, customer markets, booking entities, wallet model, use of agents, sanctions exposure and high-risk geographies. | Reassess when products, countries, ownership or transfer volumes change. |
Technical capability | Protocol support, schema version, encryption, authentication, message acknowledgement, error handling and fallback process. | Run periodic conformance tests and monitor failed exchanges. |
Compliance operating model | AML/CFT contacts, escalation contacts, sanctions and suspicious-activity process, data-retention approach and audit rights where appropriate. | Record incidents, data-quality scores, remediation commitments and repeated failures. |
Trust decision | Risk score, documented rationale, approver, permitted transfer types and transaction limits. | Review trust status at least annually and immediately after material events. |
Pro tip: Store counterparty evidence in a single controlled file, with a visible expiry date and workflow owner. A one-time spreadsheet assessment will not support a dependable cross-border operation.
如何遵守旅行规则:合规步骤
A compliance programme succeeds when legal requirements become specific owners, system rules, operational playbooks and testable evidence. The following sequence provides a practical implementation route that works for a VASP, crypto broker, bank with digital-asset services or group operating across several jurisdictions.
1.Map legal obligations by operating jurisdiction: Build an inventory of entities, licences, customer locations, transfer types, wallet models and counterparties. Record the legal source, effective date, threshold, data fields, verification rule, retention period and supervisor.
2.Implement KYC data collection flows: Capture the source fields required for originators and beneficiaries at onboarding and refresh them at the point of transfer when necessary. Use controlled field formats, evidence references and consent or privacy notices.
3.Implement KYB onboarding workflows: Identify legal entities, beneficial ownership, authorised signatories, business purpose, licences and expected activity. This is vital where the originator or beneficiary is a corporate client or financial intermediary.
4.Integrate Travel Rule messaging protocols: Select a secure, interoperable channel, define message-status controls and map the data model to the customer master record. Test messages with each significant counterparty before go-live.
5.Perform sanctions screening at transfer time: Screen customer, beneficiary, wallet, counterparty and relevant geographic information. Establish clear stop, escalation, review and release permissions.
6.Establish recordkeeping and retention schedules: Make the data, message payload, screening result, approval and outcome retrievable as a single case. Apply local retention, privacy and legal-hold policies.
7.Define escalation for incomplete or suspicious data: Decide who can request clarification, suspend, reject, return, report or terminate a counterparty relationship. Measure the time to resolution and repeated-failure rate.
Build a one-page matrix listing entity, transfer type, origin and destination, threshold, data fields, verification, sanctions, retention, protocol and exception owner. CTA: Speak with InvestGlass about configuring compliant data-capture and approval workflows.
说明性操作场景:数据缺失的入站传输
A beneficiary CASP receives a transfer that can be linked to an incoming wallet address, but the originator message lacks a usable name and the sender is not in the approved counterparty register. The case should not be resolved by simply crediting the recipient and asking questions later.
A controlled workflow records the transfer, identifies the missing fields, checks counterparty identity and jurisdiction, screens available information, requests clarification, evaluates the customer and wallet risk, then documents whether the assets are suspended, returned, released or reported. This scenario is illustrative, not a claim about a particular customer result. Its purpose is to show the type of audit-ready reasoning a regulator or internal auditor should be able to follow.
针对资产服务提供商和 VASP 的旅行规则协议与技术集成
Technical integration should be designed as a control system, not a file-transfer project. A protocol can carry data, but your compliance programme still needs an authoritative data source, user access controls, validation, counterparty authentication, status monitoring, exception workflows and immutable evidence.
评估 IVMS101 兼容性
IVMS101 is an industry data model for structuring originator and beneficiary information exchanged between VASPs. The interVASP standards body describes it as a common language for this required data, and its current documentation includes scope, data principles, data types and character-set handling. It can reduce bilateral field-mapping effort and improve interoperability, but it is not a legal safe harbour and it does not itself decide whether your data collection, verification or privacy basis is sufficient. Evaluate the data version, supported entity types, character sets, identifiers, address handling, beneficiary account mapping and validation tooling.
Ask each protocol provider and counterparty to document which schema version it supports, which fields are mandatory, what data transformations it performs, how it flags validation errors and how it handles unsupported fields. Retain the mapping specification and test evidence. This is particularly important if the same client record feeds several networks or counterparties.
选择互操作协议和安全消息传输
Interoperability is an operational requirement because your counterparties will not all use the same network. Select a solution that can authenticate counterparties, encrypt messages in transit, attach or reconcile a transfer reference, acknowledge receipt, support secure exception communication and provide evidence that can be exported for audit. Agree the fallback method in advance, including its approval threshold and data-security controls.
Transport security should include strong encryption, certificate or key lifecycle management, authenticated endpoints, least-privilege access, environment separation, rate limiting, monitoring and incident response. Keep production credentials outside local spreadsheets or personal mailboxes. A message containing sensitive personal data deserves the same disciplined security treatment as other regulated customer data.
在投产前测试端到端交互
Test normal, failed and unusual scenarios. Include valid individual and legal-entity payloads, missing originator data, wallet mismatch, unsupported assets, duplicate messages, delayed acknowledgements, sanctions escalation, counterparty downtime, cancellation, return and audit export. Require a named business owner to sign off that the system response matches the policy.
InvestGlass 数字入职 can support the upstream collection of accurate, reusable identity and entity data. The Travel Rule process is strongest when data quality is designed into onboarding rather than repaired under transfer-time pressure.
跨境互操作性与FATF指南
A practical cross-border strategy combines protocol mapping with a risk-based fallback procedure. FATF has repeatedly emphasised that uneven implementation and limited interoperability create real operational challenges. Its updates also point to the importance of private-sector solutions that work across protocols and jurisdictions.
Maintain a counterparty protocol map with at least these fields: legal entity, regulator, licence status, Travel Rule implementation jurisdiction, supported protocol, data schema, authentication method, operational contacts, service hours, message success rate, last test date, error categories and fallback option. Assign an owner who reviews material changes and documents the result.
If a counterparty is not ready to receive a message, do not improvise over consumer chat, unencrypted email or unapproved file-sharing services. Apply the legally appropriate fallback process, record why it was used, secure the data and set a time-bound remediation step. The UK FCA’s expectations are instructive: when sending to a jurisdiction without the Travel Rule, a UK firm still needs to collect and verify the required information and store it before making the transfer if the receiving firm cannot receive it.
欧盟实施与资金转移条例
EU firms need a TFR-specific operating model, because Regulation (EU) 2023/1113 applies directly and is more prescriptive than a generic threshold-based approach. The regulation extends transfer-information requirements to certain crypto-asset transfers and works alongside the MiCA authorisation and supervisory landscape.
TFR零门槛对加密资产服务提供商(CASP)的影响
The EU TFR summary explains that an originator CASP ensures that transfers are accompanied by originator and beneficiary details, including names, distributed-ledger addresses and crypto-asset account numbers. The beneficiary CASP checks whether required information is included with or follows the transfer, and it must have a process for incomplete information. This means CASP-to-CASP controls should not rely on a general value-based exemption.
Build a TFR transfer path that starts with the CASP classification and the parties’ relationship, then selects the required data. Your system should know when a transaction is person-to-person without CASP involvement, as those transfers are outside the regulation’s scope, and when an in-scope CASP is involved in either side of the transfer.
MiCA 授权与交易对手身份
MiCA provides the EU’s uniform framework for crypto-assets that are not regulated under existing financial-services legislation, including authorisation and supervision requirements for crypto-asset service providers. ESMA maintains a register that includes authorised CASPs and non-compliant entities, although operational teams should also verify national supervisory information and the exact legal status of the relevant entity.
Your counterparty due-diligence workflow should therefore record the legal entity and authorisation basis rather than relying on a brand name. A group may have different licensed, transitional or unauthorised entities depending on the Member State and time period. Status should feed the counterparty risk score and transfer-permission rules.
自托管钱包所有权或控制权验证
TFR is particularly important for self-hosted addresses. The EU summary says an originator CASP verifies whether a self-hosted address is owned or controlled by the originator for transfers over EUR 1,000. A beneficiary CASP similarly assesses ownership or control of a self-hosted address for incoming transfers over EUR 1,000.
Create a procedure that specifies when a wallet-control check is triggered, which evidence methods are acceptable, how evidence is securely retained and who can approve exceptions. Test the method against user experience, fraud risk, privacy and operational resilience. A visual display of an address is not, by itself, proof of control.
记录保存、报告和可审计性
Auditability is achieved when the full lifecycle of a transfer can be reconstructed quickly and accurately. Recordkeeping should connect transfer data to the customer, beneficiary, counterparty, message, screening, decision, documents, timestamps and all relevant communications. The EU TFR retention baseline is five years, with a possible further five-year extension by a Member State.
Build a transfer evidence pack with these core components:
•Transfer record: Blockchain transaction identifier, asset, network, amount, time, source and destination references.
•Party information: Originator and beneficiary identity fields, verification status, customer references and relationship data.
•Counterparty record: Legal entity, licence status, jurisdiction, protocol, risk rating and operational contacts.
•Control evidence: Sanctions and wallet screening results, risk score, reviewer notes, approvals, holds and release or rejection decision.
•Message evidence: Structured payload, delivery status, acknowledgement, amendments, errors, fallback route and reconciliation result.
•Reporting evidence: Suspicious-activity trigger, investigation file, decision, approved report or no-report rationale, and authority communication reference where applicable.
Automate the creation of review cases and evidence packs, but retain human accountability for suspicious-activity reporting decisions. An alert can identify a pattern and a workflow can route it to an investigator. It should not be presented as a system that autonomously decides whether a legal reporting obligation has been met.

风险管理、监控与持续改进
A Travel Rule programme needs metrics that reveal data quality, counterparty reliability and risk-control performance. Track missing-field rates, validation failures, message delivery success, acknowledgement latency, transfer holds, sanctions-alert outcomes, linked-transfer alerts, self-hosted-wallet checks, counterparty exceptions, repeat defects and time to close cases.
Use dashboards for operational management, not only monthly governance reporting. A sudden rise in message errors from one counterparty may indicate a protocol change. A rising manual-review rate for a particular jurisdiction could indicate a customer-data issue, a new typology or an unclear local rule. These signals should lead to root-cause analysis and documented remediation.
FATF’s 2026 update reports significant continuing gaps in licensing, registration, effective supervision and offshore VASP risk management. In other words, a programme cannot become static merely because its first integration is live.
一个实用的持续改进循环
Review cadence | What to review | Expected output |
Daily or intraday | Queue age, sanctions and wallet alerts, message failures, missing data and held transfers. | Prioritised case management and documented dispositions. |
每月 | Data-quality rates, top defect codes, counterparty failures, exception volumes and screening outcomes. | Control report, root-cause actions and counterparty remediation. |
季刊 | Jurisdiction matrix, protocol changes, counterparty licences, risk appetite and policy exceptions. | Updated rules configuration, management approval and training notices. |
Annually and on trigger | Legal inventory, enterprise risk assessment, retention rules, business continuity and independent assurance. | Formal policy review, control testing and board or committee reporting. |
For teams seeking a connected operating view, InvestGlass can help organise client data, counterparty due diligence, workflow approvals, exceptions and evidence around the transfer process. The appropriate product architecture depends on your technology stack and local regulatory obligations, so implementation should begin with a documented requirements and integration assessment rather than a claim of automatic compliance.
附录:合规资源与后续步骤
为期90天的实施路线图
An effective programme can be built in stages, provided that each stage has a clear owner, acceptance criteria and residual-risk decision. The following milestones are a starting point for project planning.
Period | Milestone | Deliverables |
Days 1 to 30 | Establish scope and governance | Entity map, legal-jurisdiction matrix, transfer inventory, risk assessment, accountable executive, policy gap analysis and data inventory. |
Days 31 to 60 | Design controls and counterparties | Data dictionary, screening design, counterparty due-diligence pack, protocol selection, exception playbook, privacy review and retention schedule. |
Days 61 to 90 | Integrate, test and deploy | Configured workflows, UAT evidence, counterparty tests, training completion, go-live approval, monitoring dashboard and post-launch review plan. |
管辖权要求矩阵:最少列数
Your central matrix should include country or region, legal source, effective date, entity label, in-scope transfers, threshold, originator fields, beneficiary fields, verification requirements, self-hosted-wallet conditions, sanctions controls, reporting route, retention period, protocol requirements, data-transfer restrictions, counterparty policy and source owner. Link each row to the underlying official source and the date it was last reviewed.
合规与运营团队培训
Training should be role-specific. Compliance staff need scenario practice for sanctions hits, suspicious patterns, counterparty escalation, reporting decisions and regulatory requests. Operations staff need step-by-step execution for data exceptions, wallet checks, message failures, approval routing and customer communications.
Use live examples, test evidence retrieval and update training whenever a rule, protocol, product or counterparty process changes. Require an attestation that staff understand their authority limits. A clear escalation is far safer than an employee improvising a decision under time pressure.
常见问题
1. 什么是加密货币旅行规则?
The crypto Travel Rule is the application of financial-crime transfer-information requirements to relevant virtual-asset transfers. In practice, it requires in-scope providers to collect, hold and securely exchange specified originator and beneficiary information, subject to local implementation rules.
2. 旅行规则适用于每一笔加密货币转账吗?
No. Scope depends on the jurisdiction, the parties and whether a VASP or CASP is involved. FATF provides the global standard, while local law decides the binding implementation. For example, EU TFR excludes certain person-to-person crypto-asset transfers where no CASP is involved.
3. 1,000 美元/欧元是全球旅行规则(Travel Rule)的门槛吗?
It is an important FATF threshold, including the designated threshold for occasional virtual-asset transactions requiring CDD, but it is not a universal exemption from Travel Rule, sanctions or suspicious-activity controls. EU CASP-to-CASP obligations and other domestic regimes can be stricter.
4. 发起方 VASP 需要收集哪些信息?
The required fields depend on the governing regime, but a practical FATF-oriented model includes the originator’s name, wallet or account reference and an accepted identity locator, together with beneficiary name and wallet or account reference. Store data in structured fields and preserve the verification status.
5. 旅行规则数据会在区块链上传输吗?
Not necessarily. FATF says the information does not need to be attached directly to a virtual-asset transfer. Firms normally use secure off-chain messaging, with a reliable reference that links the message to the blockchain transaction.
6. VASP应如何处理不完整的旅行规则信息?
Use a documented exception process. Validate the missing or defective field, request clarification where appropriate, assess the customer, counterparty and transaction risk, then decide whether to execute, suspend, reject, return or escalate the transfer. The EU TFR framework specifically requires beneficiary CASPs to manage incomplete information.
7. 什么是 IVMS101?它是强制性的吗?
IVMS101 is an industry data model used to structure Travel Rule identity information for interoperability between providers. It can support efficient integration, but it does not replace legal analysis, counterparty due diligence, secure transport, screening or local data-protection obligations.
8. 公司应如何评估作为交易对手方的VASP?
Verify legal identity, licence or registration, supervisory jurisdiction, service model, sanctions exposure, protocol capability, data-security arrangements, compliance contacts and historic performance. Document the risk assessment, decision authority, permitted transfer types and periodic review date.
9. 欧盟对自托管钱包有哪些规定?
Under the EU TFR summary, an originator CASP verifies whether a self-hosted address is owned or controlled by the originator for transfers over EUR 1,000. A beneficiary CASP assesses ownership or control for qualifying incoming transfers. Configure the trigger and evidence method carefully.
10. InvestGlass 如何支持旅行规则(Travel Rule)的操作?
InvestGlass can help teams organise the client data, KYC and KYB evidence, jurisdiction-aware workflows, counterparty records, approvals, exceptions and audit trail that surround a Travel Rule process. It should be integrated with your selected messaging, screening and wallet-risk tools as part of a documented compliance architecture. Explore the InvestGlass Travel Rule solution.
使用 InvestGlass 构建可靠的旅行规则运营模式
Travel Rule compliance becomes manageable when you treat it as a controlled business process, not a stand-alone message. Start with the legal and entity map. Define the data, screening and counterparty controls. Make exceptions visible. Then connect every transfer to a complete audit trail.
InvestGlass helps regulated crypto teams bring the surrounding workflow together: 数字入职, KYC and KYB data, client relationships, counterparty review, approvals, exception cases and operational evidence. To explore a Swiss-主权 workflow for your Travel Rule operations, request an InvestGlass demo.
编者按方法与来源说明
This article was prepared by the InvestGlass Editorial Team using primary material from FATF, EUR-Lex, ESMA and the UK FCA, reviewed on 23 August 2026. It is designed to explain operational considerations for regulated firms and does not provide legal, regulatory, tax or sanctions advice for a specific organisation or transaction.
分发与更新计划
项目 | Recommended execution |
LinkedIn post | Lead with the message that USD/EUR 1,000 is not a universal Travel Rule exemption. Link to the article and offer the jurisdictional matrix as a discussion asset. |
Newsletter introduction | Explain that the difficult part of Travel Rule compliance is operational evidence across counterparty, data, screening and message workflows, then invite readers to assess their process maturity. |
Five short social-post angles | Cover threshold myths, self-hosted-wallet controls, counterparty due diligence, missing-data escalation, and EU TFR readiness. |
Sales enablement summary | Position InvestGlass as the controlled workflow layer around KYC, counterparty review, approvals and auditability, integrated with specialist Travel Rule transport and screening tools. |
Backlink outreach angle | Offer the article’s jurisdictional matrix and operational-flow figure to compliance, fintech and digital-asset risk publications as a concise implementation resource. |
Review date | 23 February 2027, or earlier if FATF, EU TFR guidance, MiCA supervisory materials or local Travel Rule rules change. |
Performance KPIs | Organic ranking for crypto Travel Rule terms, AI citation presence, click-through rate, engaged reading time, demo requests and compliance-checklist conversions. |
来源与延伸阅读
[3] FATF Recommendations, as amended June 2026
[4] FATF updates standards on Recommendation 16 on payment transparency
[9] EUR-Lex summary: information accompanying transfers of funds and certain crypto-assets
[10] ESMA: Markets in Crypto-Assets Regulation
[11] FCA: expectations for UK cryptoasset businesses complying with the Travel Rule



