Back to Frameworks

FATF Recommendation 16 - Virtual Asset Travel Rule

International (FATF — 40 members)
v2019 (updated 2024)
7 domains
13 controls

FATF Recommendation 16 (Wire Transfers) was extended to Virtual Asset Service Providers (VASPs) in October 2018 + June 2019 (R.15 + Interpretive Note to R.15 + the FATF October 2018 Public Statement) operationalising the TRAVEL RULE for virtual asset transfers. The 2024 FATF Targeted Update on Virtual Assets + VASPs (R.15 / R.16) refined implementation expectations. CORE REQUIREMENTS: VASPs must obtain + hold + transmit required originator and beneficiary information for virtual asset transfers; the de minimis threshold is set at USD/EUR 1,000 (lower than for traditional wire transfers); information includes originator name + originator account number / wallet identifier + originator address or national identity number / customer identification number / date and place of birth + beneficiary name + beneficiary account number / wallet identifier. The recipient VASP must conduct counterparty VASP due diligence (CVDD) to determine that the counterparty VASP is licensed/registered + has appropriate AML/CFT controls + risk-rates the counterparty + applies enhanced measures where appropriate. The 'SUNRISE PROBLEM' refers to cross-jurisdictional implementation gaps where some jurisdictions have transposed FATF R.16 for VASPs but others have not - leaving VASPs in compliant jurisdictions transferring to or receiving from VASPs in non-compliant jurisdictions facing ambiguity. UNHOSTED WALLET TRANSFERS (transfers to or from self-hosted / non-custodial wallets) raise additional risks; the 2024 FATF Targeted Update reinforced that VASPs should apply risk-based + enhanced measures + collect originator information for outbound transfers to unhosted wallets + assess incoming transfers from unhosted wallets. EU implementation via Transfer of Funds Regulation (TFR) (Regulation (EU) 2023/1113) + complementing the MiCA + AMLR. US implementation via FinCEN 31 CFR 1010.410(f) (Travel Rule) covering CVCs (Convertible Virtual Currencies). UK implementation via the Money Laundering, Terrorist Financing and Transfer of Funds (Information on the Payer) Regulations 2017. Travel Rule technical infrastructure includes the InterVASP Messaging Standard (IVMS101) for data exchange + multiple competing networks (TRP, TRUST, Sygna Bridge, OpenVASP, Notabene, Sumsub Travel Rule). Travel Rule compliance is a precondition for VASP licensing in most jurisdictions + a barrier to market access for non-compliant VASPs.

Unverified

Framework summaries on this platform are AI-assisted interpretations for educational and compliance planning purposes. They do not reproduce or replace the official standards. Refer to the authoritative source for the definitive text. Framework names and trademarks belong to their respective organisations.

Framework Domains (7)

R.16 VATR: Counterparty VASP Due Diligence and Sanctions Screening

2 controls
Controls in the R.16 VATR: Counterparty VASP Due Diligence and Sanctions Screening domain of FATF Recommendation 16 - Virtual Asset Travel Rule2 controls
CodeTitle
R.16-VATR.CVDDCounterparty VASP Due Diligence (CVDD)
R.16-VATR.SanctionsSanctions screening of Travel Rule data

R.16 VATR: Record Retention, Audit, Training and Status

3 controls
Controls in the R.16 VATR: Record Retention, Audit, Training and Status domain of FATF Recommendation 16 - Virtual Asset Travel Rule3 controls
CodeTitle
R.16-VATR.GovernanceGovernance, training and independent testing
R.16-VATR.RecordRecord retention for Travel Rule data (FATF R.11 + R.16)
R.16-VATR.StatusFATF R.16 Virtual Asset Travel Rule - corpus status, 2024 update + implementation pipeline

R.16 VATR: Required Originator and Beneficiary Information

2 controls
Controls in the R.16 VATR: Required Originator and Beneficiary Information domain of FATF Recommendation 16 - Virtual Asset Travel Rule2 controls
CodeTitle
R.16-VATR.BeneficiaryBeneficiary information requirements
R.16-VATR.OriginatorOriginator information requirements

R.16 VATR: Scope, Applicability and Governance

1 controls
Controls in the R.16 VATR: Scope, Applicability and Governance domain of FATF Recommendation 16 - Virtual Asset Travel Rule1 controls
CodeTitle
R.16-VATR.ScopeScope and applicability of Travel Rule to VASPs (R.16 + Interpretive Note to R.15/R.16)

R.16 VATR: Sunrise Problem, Cross-Border and Intermediary Handling

2 controls
Controls in the R.16 VATR: Sunrise Problem, Cross-Border and Intermediary Handling domain of FATF Recommendation 16 - Virtual Asset Travel Rule2 controls
CodeTitle
R.16-VATR.CrossBorderCross-border transfer controls + intermediary VASP handling
R.16-VATR.SunriseSproblemSunrise Problem - cross-jurisdictional implementation gaps

R.16 VATR: Technical Infrastructure (IVMS101) and Data Quality

2 controls
Controls in the R.16 VATR: Technical Infrastructure (IVMS101) and Data Quality domain of FATF Recommendation 16 - Virtual Asset Travel Rule2 controls
CodeTitle
R.16-VATR.DataQualityData accuracy, validation and quality assurance
R.16-VATR.IVMS101InterVASP Messaging Standard (IVMS101) and Travel Rule technical infrastructure

R.16 VATR: Unhosted Wallet Transfers and Risk-Based Measures

1 controls
Controls in the R.16 VATR: Unhosted Wallet Transfers and Risk-Based Measures domain of FATF Recommendation 16 - Virtual Asset Travel Rule1 controls
CodeTitle
R.16-VATR.UnhostedUnhosted (self-hosted / non-custodial) wallet transfers - 2024 Targeted Update

Your Compliance Coverage

If you comply with FATF Recommendation 16 - Virtual Asset Travel Rule, you already cover:

Maps to 88 other frameworks

13 total controls
Pakistan Personal Data Protection Bill 2023
2 source controls mapped|2 target controls covered
15%
15%
NIST AI Risk Management Framework (AI RMF 1.0)
2 source controls mapped|5 target controls covered
15%
15%
ISO/IEC 29147:2018
2 source controls mapped|5 target controls covered
15%
UK Defence Standard 05-138 - Cyber Security for Defence Suppliers
1 source controls mapped|1 target controls covered
8%
W3C Verifiable Credentials (VC) Data Model 2.0
1 source controls mapped|1 target controls covered
8%
Vietnam Law on Cybersecurity (No. 24/2018/QH14)
1 source controls mapped|2 target controls covered
8%
Vermont Artificial Intelligence and Consumer Data Act (AICDA)
1 source controls mapped|1 target controls covered
8%
USMCA Chapter 19 - Digital Trade (United States-Mexico-Canada Agreement)
1 source controls mapped|1 target controls covered
8%
US Gramm-Leach-Bliley Act (GLBA) - Higher Education Safeguards Rule
1 source controls mapped|2 target controls covered
8%
TEFCA - Trusted Exchange Framework and Common Agreement
1 source controls mapped|1 target controls covered
8%
SWIFT CSCF
1 source controls mapped|1 target controls covered
8%
Regulation on the European Health Data Space (EHDS)
1 source controls mapped|1 target controls covered
8%
Protective Security Policy Framework (PSPF) Release 2024
1 source controls mapped|1 target controls covered
8%
Privacy Act 1988 (Australia)
1 source controls mapped|1 target controls covered
8%
PCAOB AS 2201 - Audit of Internal Control Over Financial Reporting (ICFR)
1 source controls mapped|4 target controls covered
8%
OWASP DevSecOps Maturity Model (DSOMM)
1 source controls mapped|2 target controls covered
8%
OWASP ASVS
1 source controls mapped|1 target controls covered
8%
MITRE D3FEND
1 source controls mapped|1 target controls covered
8%
Ley Orgánica de Protección de Datos Personales (LOPDP)
1 source controls mapped|1 target controls covered
8%
Law No. 172-13 on the Protection of Personal Data
1 source controls mapped|1 target controls covered
8%
South Korea PIPA
1 source controls mapped|1 target controls covered
8%
India DPDP Act
1 source controls mapped|1 target controls covered
8%
India CERT-In Cyber Security Directions 2022
1 source controls mapped|1 target controls covered
8%
India Account Aggregator Framework (RBI)
1 source controls mapped|1 target controls covered
8%
ICH E6(R3) - Good Clinical Practice
1 source controls mapped|1 target controls covered
8%
ICAO Annex 17 - Aviation Security (AVSEC)
1 source controls mapped|1 target controls covered
8%
HKMA Cyber Resilience Assessment Framework (C-RAF)
1 source controls mapped|1 target controls covered
8%
21 CFR Part 58 - Good Laboratory Practice (GLP)
1 source controls mapped|2 target controls covered
8%
ISO/IEC 27004:2016
1 source controls mapped|3 target controls covered
8%
ASIS SPC.1-2009 - Organizational Resilience Standard
1 source controls mapped|2 target controls covered
8%
APPI
1 source controls mapped|1 target controls covered
8%
Annex 11 to EU GMP - Computerised Systems
1 source controls mapped|4 target controls covered
8%
ISO/IEC 29115:2023 - Entity Authentication Assurance Framework
1 source controls mapped|1 target controls covered
8%
ISO/IEC 30111:2019
1 source controls mapped|3 target controls covered
8%
Azure Security Benchmark
1 source controls mapped|2 target controls covered
8%
ISO 19011
1 source controls mapped|3 target controls covered
8%
8%
ISO 31000:2018
1 source controls mapped|1 target controls covered
8%
ISO/IEC 29100:2024
1 source controls mapped|3 target controls covered
8%
ISO/IEC 27400:2022
1 source controls mapped|3 target controls covered
8%
ISO/IEC 27011:2024
1 source controls mapped|3 target controls covered
8%
ISO/IEC 29134:2023
1 source controls mapped|5 target controls covered
8%
ISO/IEC 27014:2020
1 source controls mapped|4 target controls covered
8%
BSI IT-Grundschutz
1 source controls mapped|3 target controls covered
8%
ISO/IEC 27557:2022 - Organisational Privacy Risk Management
1 source controls mapped|6 target controls covered
8%
BRCGS Global Standard for Food Safety Issue 9
1 source controls mapped|3 target controls covered
8%
Austria Data Protection Act (Datenschutzgesetz, DSG, amended 2018)
1 source controls mapped|2 target controls covered
8%
ISO 20000-1
1 source controls mapped|2 target controls covered
8%
ISO 13485
1 source controls mapped|1 target controls covered
8%
ISO 13485:2016
1 source controls mapped|1 target controls covered
8%
ISO 9001:2015
1 source controls mapped|2 target controls covered
8%
ISO/IEC 23837 - Security Requirements for Quantum Key Distribution
1 source controls mapped|3 target controls covered
8%
NIST SP 800-171A Rev 3 - Assessing CUI Security Requirements
1 source controls mapped|2 target controls covered
8%
COBIT 2019
1 source controls mapped|1 target controls covered
8%
ISO/IEC 38500:2024 - Governance of IT
1 source controls mapped|3 target controls covered
8%
AML/CTF Act 2006 (Australia)
1 source controls mapped|1 target controls covered
8%
DAMA-DMBOK2 - Data Management Body of Knowledge (2nd Edition)
1 source controls mapped|2 target controls covered
8%
FBI CJIS Security Policy
1 source controls mapped|1 target controls covered
8%
Barbados Data Protection Act 2019
1 source controls mapped|2 target controls covered
8%
APRA CPS 230 Operational Risk Management
1 source controls mapped|1 target controls covered
8%
Illinois Biometric Information Privacy Act (BIPA)
1 source controls mapped|3 target controls covered
8%
AWS Well-Architected Security Pillar
1 source controls mapped|2 target controls covered
8%
ISO/IEC 27007:2020
1 source controls mapped|1 target controls covered
8%
AS9100D:2016 - Quality Management Systems for Aviation, Space, and Defence
1 source controls mapped|1 target controls covered
8%
ISO 14001
1 source controls mapped|1 target controls covered
8%
ISO 45001:2018
1 source controls mapped|1 target controls covered
8%
ISO/IEC 27031:2011
1 source controls mapped|2 target controls covered
8%
IEC 62351 - Power Systems Communication Security
1 source controls mapped|1 target controls covered
8%
21 CFR Part 211 - Current Good Manufacturing Practice
1 source controls mapped|1 target controls covered
8%
API 1164
1 source controls mapped|2 target controls covered
8%
CISA Cross-Sector Cybersecurity Performance Goals (CPG) 2.0
1 source controls mapped|1 target controls covered
8%
FedRAMP High
1 source controls mapped|1 target controls covered
8%
NIST SP 800-53 Revision 5.1 HIGH
1 source controls mapped|1 target controls covered
8%
FedRAMP Moderate
1 source controls mapped|1 target controls covered
8%
NIST SP 800-53 Rev 5 MODERATE
1 source controls mapped|1 target controls covered
8%
NIST SP 800-53 Rev 5 LOW
1 source controls mapped|1 target controls covered
8%
APRA CPS 234
1 source controls mapped|1 target controls covered
8%
Azerbaijan Law on Personal Data (2010)
1 source controls mapped|1 target controls covered
8%
IEC 60601-1 - Medical Electrical Equipment Safety
1 source controls mapped|2 target controls covered
8%
ISO/IEC 27050 - Electronic Discovery (Parts 1-4)
1 source controls mapped|1 target controls covered
8%
Bahrain PDPL
1 source controls mapped|1 target controls covered
8%

Frequently Asked Questions

What is FATF Recommendation 16 - Virtual Asset Travel Rule?

FATF Recommendation 16 - Virtual Asset Travel Rule is a compliance framework from International (FATF — 40 members) with 7 domains and 13 controls. FATF Recommendation 16 (Wire Transfers) was extended to Virtual Asset Service Providers (VASPs) in October 2018 + June 2019 (R.15 + Interpretive Note to R.15 + the FATF October 2018 Public Statement) operationalising the TRAVEL RULE for virtual asset transfers. The 2024 FATF Targeted Update on Virtual Assets + VASPs (R.15 / R.16) refined implementation expectations. CORE REQUIREMENTS: VASPs must obtain + hold + transmit required originator and beneficiary information for virtual asset transfers; the de minimis threshold is set at USD/EUR 1,000 (lower than for traditional wire transfers); information includes originator name + originator account number / wallet identifier + originator address or national identity number / customer identification number / date and place of birth + beneficiary name + beneficiary account number / wallet identifier. The recipient VASP must conduct counterparty VASP due diligence (CVDD) to determine that the counterparty VASP is licensed/registered + has appropriate AML/CFT controls + risk-rates the counterparty + applies enhanced measures where appropriate. The 'SUNRISE PROBLEM' refers to cross-jurisdictional implementation gaps where some jurisdictions have transposed FATF R.16 for VASPs but others have not - leaving VASPs in compliant jurisdictions transferring to or receiving from VASPs in non-compliant jurisdictions facing ambiguity. UNHOSTED WALLET TRANSFERS (transfers to or from self-hosted / non-custodial wallets) raise additional risks; the 2024 FATF Targeted Update reinforced that VASPs should apply risk-based + enhanced measures + collect originator information for outbound transfers to unhosted wallets + assess incoming transfers from unhosted wallets. EU implementation via Transfer of Funds Regulation (TFR) (Regulation (EU) 2023/1113) + complementing the MiCA + AMLR. US implementation via FinCEN 31 CFR 1010.410(f) (Travel Rule) covering CVCs (Convertible Virtual Currencies). UK implementation via the Money Laundering, Terrorist Financing and Transfer of Funds (Information on the Payer) Regulations 2017. Travel Rule technical infrastructure includes the InterVASP Messaging Standard (IVMS101) for data exchange + multiple competing networks (TRP, TRUST, Sygna Bridge, OpenVASP, Notabene, Sumsub Travel Rule). Travel Rule compliance is a precondition for VASP licensing in most jurisdictions + a barrier to market access for non-compliant VASPs. It is used by organisations to establish and maintain compliance with industry standards and regulatory requirements.

How many controls does FATF Recommendation 16 - Virtual Asset Travel Rule have?

FATF Recommendation 16 - Virtual Asset Travel Rule has 13 controls organised across 7 domains. The largest domains are R.16 VATR: Record Retention, Audit, Training and Status (3 controls), R.16 VATR: Counterparty VASP Due Diligence and Sanctions Screening (2 controls), R.16 VATR: Required Originator and Beneficiary Information (2 controls). Each control defines specific requirements that organisations must implement to achieve compliance.

What frameworks does FATF Recommendation 16 - Virtual Asset Travel Rule map to?

FATF Recommendation 16 - Virtual Asset Travel Rule maps to 88 other compliance frameworks. The top mapping partners are Pakistan Personal Data Protection Bill 2023 (15% coverage), Italy Personal Data Protection Code (Legislative Decree No. 196/2003, amended 2018) (15% coverage), Federal Decree-Law No. 45 of 2021 on the Protection of Personal Data (UAE PDPL) (15% coverage). Use our comparison tool to explore control-level mappings between frameworks.

How do I get started with FATF Recommendation 16 - Virtual Asset Travel Rule compliance?

Start your FATF Recommendation 16 - Virtual Asset Travel Rule compliance journey by running a self-assessment on our platform to identify your current compliance posture. Our AI advisory can answer specific questions about FATF Recommendation 16 - Virtual Asset Travel Rule requirements, and cross-framework mapping helps you leverage existing controls from other frameworks you may already comply with. Create a free account to access all 13 controls and track your progress.

Start Your Compliance Journey

Create a free account to run self-assessments, get AI advisory, and track your compliance progress across 700 frameworks.

Get Started Free →

Free forever — no credit card required