Back to Frameworks

FATF Recommendation 16 - Payment Transparency (Travel Rule)

Global (FATF members and FSRB members; transposed by national law)
vR.16 and INR.16 as revised June 2025, in the FATF Recommendations updated October 2025; virtual asset travel rule via INR.15 paragraph 7(b) (2019); implementation of the revision expected by end of 2030
7 domains
31 controls

FATF Recommendation 16 (Wire Transfers) was extended to Virtual Asset Service Providers (VASPs) in October 2018 + June 2019 (R.15 + Interpretive Note to R.15 + the FATF October 2018 Public Statement) operationalising the TRAVEL RULE for virtual asset transfers. The 2024 FATF Targeted Update on Virtual Assets + VASPs (R.15 / R.16) refined implementation expectations. CORE REQUIREMENTS: VASPs must obtain + hold + transmit required originator and beneficiary information for virtual asset transfers; the de minimis threshold is set at USD/EUR 1,000 (lower than for traditional wire transfers); information includes originator name + originator account number / wallet identifier + originator address or national identity number / customer identification number / date and place of birth + beneficiary name + beneficiary account number / wallet identifier. The recipient VASP must conduct counterparty VASP due diligence (CVDD) to determine that the counterparty VASP is licensed/registered + has appropriate AML/CFT controls + risk-rates the counterparty + applies enhanced measures where appropriate. The 'SUNRISE PROBLEM' refers to cross-jurisdictional implementation gaps where some jurisdictions have transposed FATF R.16 for VASPs but others have not - leaving VASPs in compliant jurisdictions transferring to or receiving from VASPs in non-compliant jurisdictions facing ambiguity. UNHOSTED WALLET TRANSFERS (transfers to or from self-hosted / non-custodial wallets) raise additional risks; the 2024 FATF Targeted Update reinforced that VASPs should apply risk-based + enhanced measures + collect originator information for outbound transfers to unhosted wallets + assess incoming transfers from unhosted wallets. EU implementation via Transfer of Funds Regulation (TFR) (Regulation (EU) 2023/1113) + complementing the MiCA + AMLR. US implementation via FinCEN 31 CFR 1010.410(f) (Travel Rule) covering CVCs (Convertible Virtual Currencies). UK implementation via the Money Laundering, Terrorist Financing and Transfer of Funds (Information on the Payer) Regulations 2017. Travel Rule technical infrastructure includes the InterVASP Messaging Standard (IVMS101) for data exchange + multiple competing networks (TRP, TRUST, Sygna Bridge, OpenVASP, Notabene, Sumsub Travel Rule). Travel Rule compliance is a precondition for VASP licensing in most jurisdictions + a barrier to market access for non-compliant VASPs.

Verified

FATF Recommendation 16 - Payment Transparency (Travel Rule) is a compliance framework from Global (FATF members and FSRB members; transposed by national law) with 7 domains and 31 controls that map to 77 other frameworks. The largest domains are Exceptions and differentiated requirements (INR.16 paragraphs 13 to 19) – FATF Recommendation 16 - Payment Transparency (Travel Rule) (7 controls), Information requirements for cross-border and domestic payments (INR.16 paragraphs 4 to 12) – FATF Recommendation 16 - Payment Transparency (Travel Rule) (7 controls), Beneficiary financial institution and MVTS providers (INR.16 paragraphs 28 to 32) – FATF Recommendation 16 - Payment Transparency (Travel Rule) (5 controls). Every control below carries what it requires and what an assessor expects to see.

Maintained by Gerard BlokdykControl text last updated

Framework summaries on this platform are AI-assisted interpretations for educational and compliance planning purposes. They do not reproduce or replace the official standards. Refer to the authoritative source for the definitive text. Framework names and trademarks belong to their respective organisations.

Framework Domains (7)

Beneficiary financial institution and MVTS providers (INR.16 paragraphs 28 to 32) – FATF Recommendation 16 - Payment Transparency (Travel Rule)

5 controls
Controls in the Beneficiary financial institution and MVTS providers (INR.16 paragraphs 28 to 32) – FATF Recommendation 16 - Payment Transparency (Travel Rule) domain of FATF Recommendation 16 - Payment Transparency (Travel Rule)5 controls
CodeTitle
fatf-recommendation-16-payment-transparency-travel-rule::INR16.28INR16.28 Beneficiary institution: reasonable measures to identify missing information
fatf-recommendation-16-payment-transparency-travel-rule::INR16.29INR16.29 Beneficiary institution: verification of beneficiary identity above the threshold
fatf-recommendation-16-payment-transparency-travel-rule::INR16.30INR16.30 Beneficiary institution: detecting misdirected payments through alignment checks
fatf-recommendation-16-payment-transparency-travel-rule::INR16.31INR16.31 Beneficiary institution: risk-based policies on execution, rejection or suspension
fatf-recommendation-16-payment-transparency-travel-rule::INR16.32INR16.32 Money or value transfer service providers

Exceptions and differentiated requirements (INR.16 paragraphs 13 to 19) – FATF Recommendation 16 - Payment Transparency (Travel Rule)

7 controls
Controls in the Exceptions and differentiated requirements (INR.16 paragraphs 13 to 19) – FATF Recommendation 16 - Payment Transparency (Travel Rule) domain of FATF Recommendation 16 - Payment Transparency (Travel Rule)7 controls
CodeTitle
fatf-recommendation-16-payment-transparency-travel-rule::INR16.13INR16.13 No information required for institution-to-institution transfers
fatf-recommendation-16-payment-transparency-travel-rule::INR16.14INR16.14 Net settlements and their underlying transactions
fatf-recommendation-16-payment-transparency-travel-rule::INR16.15INR16.15 Batch transfers from a single originator
fatf-recommendation-16-payment-transparency-travel-rule::INR16.16INR16.16 Card payments for goods and services
fatf-recommendation-16-payment-transparency-travel-rule::INR16.17INR16.17 Card used for other transfers
fatf-recommendation-16-payment-transparency-travel-rule::INR16.18INR16.18 Domestic cash withdrawals
fatf-recommendation-16-payment-transparency-travel-rule::INR16.19INR16.19 Cross-border cash withdrawals

Information requirements for cross-border and domestic payments (INR.16 paragraphs 4 to 12) – FATF Recommendation 16 - Payment Transparency (Travel Rule)

7 controls
Controls in the Information requirements for cross-border and domestic payments (INR.16 paragraphs 4 to 12) – FATF Recommendation 16 - Payment Transparency (Travel Rule) domain of FATF Recommendation 16 - Payment Transparency (Travel Rule)7 controls
CodeTitle
fatf-recommendation-16-payment-transparency-travel-rule::INR16.10INR16.10 Domestic transfers below the de minimis threshold
fatf-recommendation-16-payment-transparency-travel-rule::INR16.11INR16.11 Domestic transfers above the threshold: full information or availability by other means
fatf-recommendation-16-payment-transparency-travel-rule::INR16.12INR16.12 Originator information within three business days; immediate production for law enforcement
fatf-recommendation-16-payment-transparency-travel-rule::INR16.4INR16.4 Structured information sufficient to identify originator and beneficiary
fatf-recommendation-16-payment-transparency-travel-rule::INR16.7INR16.7 Servicing institutions and their countries identifiable; no disguised account numbers
fatf-recommendation-16-payment-transparency-travel-rule::INR16.8INR16.8 Cross-border transfers below the de minimis threshold
fatf-recommendation-16-payment-transparency-travel-rule::INR16.9INR16.9 Cross-border transfers above the threshold: the full information set

Intermediary financial institution (INR.16 paragraphs 24 to 27) – FATF Recommendation 16 - Payment Transparency (Travel Rule)

4 controls
Controls in the Intermediary financial institution (INR.16 paragraphs 24 to 27) – FATF Recommendation 16 - Payment Transparency (Travel Rule) domain of FATF Recommendation 16 - Payment Transparency (Travel Rule)4 controls
CodeTitle
fatf-recommendation-16-payment-transparency-travel-rule::INR16.24INR16.24 Intermediary institution: information retained with the transfer
fatf-recommendation-16-payment-transparency-travel-rule::INR16.25INR16.25 Intermediary institution: five-year record where technical limits prevent pass-through
fatf-recommendation-16-payment-transparency-travel-rule::INR16.26INR16.26 Intermediary institution: reasonable measures to identify missing information
fatf-recommendation-16-payment-transparency-travel-rule::INR16.27INR16.27 Intermediary institution: risk-based policies on execution, rejection or suspension

Ordering financial institution (INR.16 paragraphs 20 to 23) – FATF Recommendation 16 - Payment Transparency (Travel Rule)

4 controls
Controls in the Ordering financial institution (INR.16 paragraphs 20 to 23) – FATF Recommendation 16 - Payment Transparency (Travel Rule) domain of FATF Recommendation 16 - Payment Transparency (Travel Rule)4 controls
CodeTitle
fatf-recommendation-16-payment-transparency-travel-rule::INR16.20INR16.20 Ordering institution: required and accurate originator information above the threshold
fatf-recommendation-16-payment-transparency-travel-rule::INR16.21INR16.21 Ordering institution: names and account or reference numbers below the threshold
fatf-recommendation-16-payment-transparency-travel-rule::INR16.22INR16.22 Ordering institution: retention of originator and beneficiary information
fatf-recommendation-16-payment-transparency-travel-rule::INR16.23INR16.23 Ordering institution: no execution of non-compliant transfers

Screening, freezing and monitoring under Recommendation 16 – FATF Recommendation 16 - Payment Transparency (Travel Rule)

2 controls
Controls in the Screening, freezing and monitoring under Recommendation 16 – FATF Recommendation 16 - Payment Transparency (Travel Rule) domain of FATF Recommendation 16 - Payment Transparency (Travel Rule)2 controls
CodeTitle
fatf-recommendation-16-payment-transparency-travel-rule::R16-MONR16-MON Monitoring for transfers lacking required information
fatf-recommendation-16-payment-transparency-travel-rule::R16-TFSR16-TFS Freezing action and prohibited transactions with designated persons in the payment chain

Virtual asset transfers (INR.15 paragraph 7(b)) – FATF Recommendation 16 - Payment Transparency (Travel Rule)

2 controls
Controls in the Virtual asset transfers (INR.15 paragraph 7(b)) – FATF Recommendation 16 - Payment Transparency (Travel Rule) domain of FATF Recommendation 16 - Payment Transparency (Travel Rule)2 controls
CodeTitle
fatf-recommendation-16-payment-transparency-travel-rule::INR15.7b-BENINR15.7b-BEN Beneficiary VASP: obtain and hold information and apply the other R.16 duties
fatf-recommendation-16-payment-transparency-travel-rule::INR15.7b-ORIGINR15.7b-ORIG Originating VASP: obtain, hold and submit originator and beneficiary information

Your Compliance Coverage

If you comply with FATF Recommendation 16 - Payment Transparency (Travel Rule), you already cover:

Maps to 77 other frameworks

44 total controls
Pakistan Personal Data Protection Bill 2023
2 source controls mapped|2 target controls covered
5%
UAE Virtual Asset Regulatory Authority (VARA) Regulations
2 source controls mapped|3 target controls covered
5%
ISO/IEC 29147:2018
2 source controls mapped|3 target controls covered
5%
US Automated Commercial Environment (ACE) - CBP Trade Data Requirements
1 source controls mapped|1 target controls covered
2%
UK Defence Standard 05-138 - Cyber Security for Defence Suppliers
1 source controls mapped|1 target controls covered
2%
W3C Verifiable Credentials (VC) Data Model 2.0
1 source controls mapped|1 target controls covered
2%
Vietnam Law on Cybersecurity (No. 24/2018/QH14)
1 source controls mapped|2 target controls covered
2%
Vermont Artificial Intelligence and Consumer Data Act (AICDA)
1 source controls mapped|1 target controls covered
2%
USMCA Chapter 19 - Digital Trade (United States-Mexico-Canada Agreement)
1 source controls mapped|1 target controls covered
2%
US Gramm-Leach-Bliley Act (GLBA) - Higher Education Safeguards Rule
1 source controls mapped|2 target controls covered
2%
TEFCA - Trusted Exchange Framework and Common Agreement
1 source controls mapped|1 target controls covered
2%
SWIFT CSCF
1 source controls mapped|1 target controls covered
2%
Regulation on the European Health Data Space (EHDS)
1 source controls mapped|1 target controls covered
2%
Protective Security Policy Framework (PSPF) Release 2024
1 source controls mapped|1 target controls covered
2%
Privacy Act 1988 (Australia)
1 source controls mapped|1 target controls covered
2%
PCAOB AS 2201 - Audit of Internal Control Over Financial Reporting (ICFR)
1 source controls mapped|4 target controls covered
2%
OWASP DevSecOps Maturity Model (DSOMM)
1 source controls mapped|2 target controls covered
2%
OWASP ASVS
1 source controls mapped|1 target controls covered
2%
MITRE D3FEND
1 source controls mapped|1 target controls covered
2%
Ley Orgánica de Protección de Datos Personales (LOPDP)
1 source controls mapped|1 target controls covered
2%
Law No. 172-13 on the Protection of Personal Data
1 source controls mapped|1 target controls covered
2%
South Korea PIPA
1 source controls mapped|1 target controls covered
2%
India DPDP Act
1 source controls mapped|1 target controls covered
2%
India CERT-In Cyber Security Directions 2022
1 source controls mapped|1 target controls covered
2%
India Account Aggregator Framework (RBI)
1 source controls mapped|1 target controls covered
2%
ICH E6(R3) - Good Clinical Practice
1 source controls mapped|1 target controls covered
2%
ICAO Annex 17 - Aviation Security (AVSEC)
1 source controls mapped|1 target controls covered
2%
HKMA Cyber Resilience Assessment Framework (C-RAF)
1 source controls mapped|1 target controls covered
2%
ISO/IEC 27004:2016
1 source controls mapped|3 target controls covered
2%
ASIS SPC.1-2009 - Organizational Resilience Standard
1 source controls mapped|2 target controls covered
2%
2%
Annex 11 to EU GMP - Computerised Systems
1 source controls mapped|4 target controls covered
2%
ISO 19011
1 source controls mapped|2 target controls covered
2%
ISO/IEC 27400:2022
1 source controls mapped|2 target controls covered
2%
ISO/IEC 27011:2024
1 source controls mapped|2 target controls covered
2%
ISO/IEC 29134:2023
1 source controls mapped|3 target controls covered
2%
ISO/IEC 27014:2020
1 source controls mapped|2 target controls covered
2%
ISO/IEC 30111:2019
1 source controls mapped|1 target controls covered
2%
BSI IT-Grundschutz
1 source controls mapped|3 target controls covered
2%
SQF Code Edition 9 - Safe Quality Food
1 source controls mapped|2 target controls covered
2%
ISO/IEC 27557:2022 - Organisational Privacy Risk Management
1 source controls mapped|3 target controls covered
2%
Austria Data Protection Act (Datenschutzgesetz, DSG, amended 2018)
1 source controls mapped|2 target controls covered
2%
COBIT 2019
1 source controls mapped|1 target controls covered
2%
ISO/IEC 38500:2024 - Governance of IT
1 source controls mapped|3 target controls covered
2%
Science Based Targets Initiative (SBTi) - Net-Zero Standard
1 source controls mapped|2 target controls covered
2%
PCI DSS 4.0
1 source controls mapped|1 target controls covered
2%
AML/CTF Act 2006 (Australia)
1 source controls mapped|1 target controls covered
2%
DAMA-DMBOK2 - Data Management Body of Knowledge (2nd Edition)
1 source controls mapped|2 target controls covered
2%
US Foreign Corrupt Practices Act (FCPA)
1 source controls mapped|1 target controls covered
2%
FBI CJIS Security Policy
1 source controls mapped|1 target controls covered
2%
Barbados Data Protection Act 2019
1 source controls mapped|2 target controls covered
2%
APRA CPS 230 Operational Risk Management
1 source controls mapped|1 target controls covered
2%
ISO/IEC 29100:2024
1 source controls mapped|1 target controls covered
2%
Illinois Biometric Information Privacy Act (BIPA)
1 source controls mapped|1 target controls covered
2%
Switzerland New Federal Act on Data Protection (nFADP/nDSG, 2023)
1 source controls mapped|3 target controls covered
2%
ISO/IEC 27007:2020
1 source controls mapped|1 target controls covered
2%
US Consumer Product Safety Commission (CPSC) - Connected Product Safety
1 source controls mapped|1 target controls covered
2%
ISO/IEC 27031:2011
1 source controls mapped|2 target controls covered
2%
IEC 62351 - Power Systems Communication Security
1 source controls mapped|1 target controls covered
2%
DFARS 252.204-7012 - Safeguarding Covered Defense Information
1 source controls mapped|1 target controls covered
2%
API 1164
1 source controls mapped|2 target controls covered
2%
CISA Cross-Sector Cybersecurity Performance Goals (CPG) 2.0
1 source controls mapped|1 target controls covered
2%
Connecticut Data Privacy Act (CTDPA)
1 source controls mapped|1 target controls covered
2%
FedRAMP High
1 source controls mapped|1 target controls covered
2%
NIST SP 800-53 Revision 5.1 HIGH
1 source controls mapped|1 target controls covered
2%
FedRAMP Moderate
1 source controls mapped|1 target controls covered
2%
NIST SP 800-53 Rev 5 MODERATE
1 source controls mapped|1 target controls covered
2%
NIST SP 800-53 Rev 5 LOW
1 source controls mapped|1 target controls covered
2%
Azerbaijan Law on Personal Data (2010)
1 source controls mapped|1 target controls covered
2%
IEC 60601-1 - Medical Electrical Equipment Safety
1 source controls mapped|2 target controls covered
2%
Bahrain PDPL
1 source controls mapped|1 target controls covered
2%

Coverage is not the same as your position

This page shows what FATF Recommendation 16 - Payment Transparency (Travel Rule) overlaps with in general. Where your organisation actually stands, against the standard you are going for and the certifications you already hold, is a different question. Same graph and the same recorded refutations, scoped to you rather than to a pair.

The Compliance Position Diagnostic, $5,000 fixed, ten business days

What is FATF Recommendation 16 - Payment Transparency (Travel Rule) and who does it apply to?

FATF Recommendation 16 - Payment Transparency (Travel Rule) is a compliance framework from Global (FATF members and FSRB members; transposed by national law) with 7 domains and 31 controls. FATF Recommendation 16 (Wire Transfers) was extended to Virtual Asset Service Providers (VASPs) in October 2018 + June 2019 (R.15 + Interpretive Note to R.15 + the FATF October 2018 Public Statement) operationalising the TRAVEL RULE for virtual asset transfers. The 2024 FATF Targeted Update on Virtual Assets + VASPs (R.15 / R.16) refined implementation expectations. CORE REQUIREMENTS: VASPs must obtain + hold + transmit required originator and beneficiary information for virtual asset transfers; the de minimis threshold is set at USD/EUR 1,000 (lower than for traditional wire transfers); information includes originator name + originator account number / wallet identifier + originator address or national identity number / customer identification number / date and place of birth + beneficiary name + beneficiary account number / wallet identifier. The recipient VASP must conduct counterparty VASP due diligence (CVDD) to determine that the counterparty VASP is licensed/registered + has appropriate AML/CFT controls + risk-rates the counterparty + applies enhanced measures where appropriate. The 'SUNRISE PROBLEM' refers to cross-jurisdictional implementation gaps where some jurisdictions have transposed FATF R.16 for VASPs but others have not - leaving VASPs in compliant jurisdictions transferring to or receiving from VASPs in non-compliant jurisdictions facing ambiguity. UNHOSTED WALLET TRANSFERS (transfers to or from self-hosted / non-custodial wallets) raise additional risks; the 2024 FATF Targeted Update reinforced that VASPs should apply risk-based + enhanced measures + collect originator information for outbound transfers to unhosted wallets + assess incoming transfers from unhosted wallets. EU implementation via Transfer of Funds Regulation (TFR) (Regulation (EU) 2023/1113) + complementing the MiCA + AMLR. US implementation via FinCEN 31 CFR 1010.410(f) (Travel Rule) covering CVCs (Convertible Virtual Currencies). UK implementation via the Money Laundering, Terrorist Financing and Transfer of Funds (Information on the Payer) Regulations 2017. Travel Rule technical infrastructure includes the InterVASP Messaging Standard (IVMS101) for data exchange + multiple competing networks (TRP, TRUST, Sygna Bridge, OpenVASP, Notabene, Sumsub Travel Rule). Travel Rule compliance is a precondition for VASP licensing in most jurisdictions + a barrier to market access for non-compliant VASPs. It is used by organisations to establish and maintain compliance with industry standards and regulatory requirements.

What does FATF Recommendation 16 - Payment Transparency (Travel Rule) actually require?

FATF Recommendation 16 - Payment Transparency (Travel Rule) has 31 controls organised across 7 domains. The largest domains are Exceptions and differentiated requirements (INR.16 paragraphs 13 to 19) – FATF Recommendation 16 - Payment Transparency (Travel Rule) (7 controls), Information requirements for cross-border and domestic payments (INR.16 paragraphs 4 to 12) – FATF Recommendation 16 - Payment Transparency (Travel Rule) (7 controls), Beneficiary financial institution and MVTS providers (INR.16 paragraphs 28 to 32) – FATF Recommendation 16 - Payment Transparency (Travel Rule) (5 controls). Each control defines specific requirements that organisations must implement to achieve compliance.

If I already comply with another framework, how much of FATF Recommendation 16 - Payment Transparency (Travel Rule) do I already cover?

FATF Recommendation 16 - Payment Transparency (Travel Rule) maps to 77 other compliance frameworks. The top mapping partners are Pakistan Personal Data Protection Bill 2023 (5% coverage), Italy Personal Data Protection Code (Legislative Decree No. 196/2003, amended 2018) (5% coverage), Federal Decree-Law No. 45 of 2021 on the Protection of Personal Data (UAE PDPL) (5% coverage). Use our comparison tool to explore control-level mappings between frameworks.

How do I implement FATF Recommendation 16 - Payment Transparency (Travel Rule)?

Start your FATF Recommendation 16 - Payment Transparency (Travel Rule) compliance journey by running a self-assessment on our platform to identify your current compliance posture. Our AI advisory can answer specific questions about FATF Recommendation 16 - Payment Transparency (Travel Rule) requirements, and cross-framework mapping helps you leverage existing controls from other frameworks you may already comply with. Create a free account to access all 31 controls and track your progress.

Start Your Compliance Journey

Create a free account to run self-assessments, get AI advisory, and track your compliance progress across 704 frameworks.

Get Started Free →

Free forever — no credit card required