The Travel Rule is no longer primarily a legislative gap. According to FATF’s seventh targeted update, published in July 2026, 91 of 109 surveyed jurisdictions now have Travel Rule legislation in force. However, 55 of those 91 jurisdictions (60%) had not yet issued findings or directives or taken enforcement or other supervisory action against VASPs specifically focused on Travel Rule compliance.
For VASPs and crypto exchanges, the message is clear: the regulatory framework is increasingly in place, while many jurisdictions are still building the supervisory capacity to test whether firms comply in practice. This article breaks down the six operational areas that a travel rule compliance audit may cover, explains what “good” looks like in each and offers practical steps to address common compliance gaps.
A note on FATF standards and national law: FATF Recommendations establish international AML/CFT standards but do not themselves operate as directly applicable law in every jurisdiction. Specific Travel Rule obligations, thresholds, data fields, sanctions requirements and retention periods depend on the applicable national or regional legal framework.
| Compliance area | Key requirement | Why it matters |
| Onboarding-to-transfer data integrity | CIP/CDD records match originator and beneficiary fields in travel rule messages | Material or unexplained mismatches may require investigation and depending on the circumstances and applicable law, may contribute to a suspicious transaction reporting decision |
| Counterparty VASP due diligence | Risk-based assessment of every counterparty VASP before exchanging travel rule data | FATF guidance expects VASPs to assess counterparties before sharing customer data. Recent enforcement developments underscore the importance of identifying exposure to illicit counterparties |
| Unhosted wallet procedures | Documented process for transfers involving wallets not controlled by a VASP or other obliged intermediary | Jurisdictions differ sharply on requirements, creating compliance risk for cross-border operators |
| Sanctions screening integration | Screening originator and beneficiary data against applicable sanctions lists before transfer completion | Travel rule data provides the fields needed for effective screening, but only if workflows are connected |
| Exception handling and escalation | Clear policies for incomplete data, failed transmissions and rejected transfers | Supervisors may look for documented decision trails, not just successful messages |
| Record retention and audit trail | Retention of all travel rule messages, screening results and exception records for the period required by applicable law | Without retrievable records, firms cannot demonstrate compliance after the fact |
Why the travel rule compliance audit landscape is shifting now
Three developments have moved the Travel Rule from a checkbox exercise to a genuine supervisory priority.
First, legislative adoption has reached critical mass. FATF’s 2026 data shows that 83% of surveyed jurisdictions have Travel Rule laws in force, up from 73% a year earlier. Among the 69 jurisdictions representing 97% of the global virtual asset market, 94% have rules either enacted or in development.
Second, FATF strengthened Recommendation 16 in June 2025, which applies in the virtual-asset context through Recommendation 15 and its Interpretive Note, to increase transparency for cross-border payments. Countries are expected to implement the revised standard by the end of 2030. For VASPs already subject to the Travel Rule, the changes reinforce the importance of maintaining accurate, complete and retrievable originator and beneficiary information. Specific legal requirements will depend on the jurisdiction in which the VASP operates. (For a broader overview, see our earlier guide on global crypto Travel Rule compliance.)
Third, enforcement has started in earnest. On 9 September 2026, OFAC designated Xinbi Guarantee as a significant transnational criminal organization operating through Telegram, facilitating scams, trafficking and money laundering. OFAC reported that the marketplace had processed more than USD 24 billion in digital assets and fiat currency since around 2022, with transactions reportedly settled primarily in USDT on TRON. The DOJ simultaneously restrained approximately USD 52 million in cryptocurrency and identified wallets associated with the network. The action underscores the importance of integrating sanctions screening, blockchain analytics and counterparty due diligence into VASP transfer controls.
Onboarding-to-transfer data integrity
A key area of travel rule compliance audit testing is the consistency between a customer’s onboarding records and the originator or beneficiary information transmitted with a transfer. A customer opens an account with one version of their name, address or identifier, but the travel rule message contains a different version. Sometimes the discrepancy is minor: a middle name omitted or a transliteration difference. Other times it is material. Either way, it signals weak data governance.
To address this, VASPs should ensure that their customer identification program feeds directly into the travel rule messaging workflow. Avoid manual re-entry of customer data when constructing messages. Implement validation checks that flag discrepancies between CDD records and outgoing transfer data before sending the message. Run periodic sample testing, with sample size and frequency determined by transaction volume, risk and the firm’s audit methodology. For smaller VASPs, a monthly sample of 20 to 30 transfers may provide a practical starting point.
Counterparty VASP due diligence
Sending a travel rule message to a counterparty VASP is not enough. FATF guidance expects VASPs to conduct risk-based due diligence on counterparties before transmitting required customer information.
FATF’s best practices guidance on Travel Rule supervision (June 2025) highlights counterparty due diligence as a core supervisory expectation, building on FATF’s 2021 Updated Guidance for a Risk-Based Approach to VAs and VASPs. As part of its risk-based due diligence, a firm should assess the counterparty’s licensing or registration status where applicable and confirm that it has the capability to receive and process travel rule data. For higher-risk counterparties, enhanced checks should include reviewing the counterparty’s sanctions screening practices, assessing its exposure to high-risk jurisdictions and checking for regulatory action.
The Xinbi Guarantee designation illustrates the importance of identifying exposure to sanctioned and illicit counterparties. Xinbi operated as a Telegram-based marketplace connecting scam syndicates with vendors of stolen personal data and AI deepfake tools. The designation and identification of associated cryptocurrency wallets demonstrate the operational reach of sanctions enforcement in digital assets.
Firms should maintain a counterparty VASP register, recording each counterparty’s licensing status, jurisdiction, last review date and risk rating. Review the register periodically, with frequency determined by the firm’s risk-based framework. Update it when material events occur, such as a counterparty facing regulatory action or appearing on a sanctions list. For higher-risk counterparties, quarterly review may be appropriate.
Unhosted wallet procedures
Transfers involving unhosted or self-hosted wallets (wallets not controlled by a VASP or other obliged intermediary) present distinct challenges. Jurisdictions vary in their requirements. Within the scope of the EU Transfer of Funds Regulation, which came into force on 30 December 2024, CASPs must collect originator and beneficiary information for all virtual asset transfers, regardless of amount. For transfers exceeding EUR 1,000 involving a self-hosted address, the CASP must take the prescribed measures to assess whether the address is owned or controlled by the relevant customer.
Other jurisdictions apply lighter requirements or have not addressed unhosted wallets at all. FATF’s best practices document acknowledges this inconsistency, noting that “requirements for peer-to-peer transaction oversight” vary across jurisdictions.
In a travel rule compliance audit, firms need to demonstrate a documented, risk-based approach to unhosted wallet transfers. This includes a clear policy defining how the firm treats such transfers under each jurisdiction where it operates. It also includes a verification procedure for high-value transfers using appropriate measures, potentially including blockchain analytics, to assess wallet ownership or control. Retain records of each verification decision, including cases where the firm declined or escalated a transfer.
Sanctions screening integration
Travel rule data and sanctions screening should operate as a single workflow, not two separate processes. The originator and beneficiary information collected under the Travel Rule (name, address, identifier) provides important data fields for effective sanctions screening.
Yet many VASPs run travel rule messaging and sanctions screening on separate systems, with separate data inputs. The result is a dangerous gap: a travel rule message may be transmitted successfully while sanctions screening runs against a different data set. In some cases, screening only runs after the transfer has already been completed.
Supervisors may examine whether sanctions screening runs against the same originator and beneficiary data used in the travel rule message. Where sanctions screening applies, the firm should complete screening and any required review before releasing funds or completing the transfer. Ensure that screening covers the sanctions regimes applicable to the firm’s business, customers, counterparties and transaction corridors, which may include relevant UN, domestic, EU, UK and U.S. programs. Retain screening results alongside the corresponding travel rule message for the applicable retention period.
Exception handling and escalation
A compliance program reveals itself when something breaks. Supervisors may pay close attention to how VASPs handle exceptions: incomplete originator or beneficiary data from a counterparty, failed message transmissions, rejected transfers and cases where sanctions screening returns a potential match.
For each exception type, firms need a documented policy specifying the response. When a counterparty fails to provide required beneficiary information, does the firm hold the transfer, reject it or proceed with enhanced monitoring? Should a travel rule message fail to transmit, is the transfer paused until the message is successfully delivered? And when sanctions screening returns a potential match, who reviews it, what criteria guide the decision and where is the decision recorded?
The evidence trail matters more than the policy itself. An effective audit will typically sample exception cases and trace the decision from trigger to resolution. Log every step with a timestamp, the reviewer’s identity and the rationale for the decision. A compliance officer should review any manual workaround that bypasses the normal workflow.
Record retention and the five-year evidence trail
FATF Recommendation 11 establishes a minimum five-year record-keeping period for relevant transaction and CDD records. VASPs should retain travel rule messages, screening results, exception records and counterparty due diligence evidence for the period applicable law and the firm’s record-retention framework requires. Where applicable law prescribes a longer retention period, apply the longer period.
The practical challenge is not storage. It is retrievability. In a travel rule compliance audit, supervisors may request all travel rule messages for a specific customer, a specific counterparty or a specific date range. Firms need to demonstrate that they can retrieve these records promptly, cross-reference them against CDD records and present a coherent evidence trail for any given transfer.
Testing retrieval capability at least annually is a practical safeguard. Select a risk-based sample of historical transfers and attempt to reconstruct the full evidence trail for each: the customer’s CDD record, the travel rule message, the sanctions screening result and any exception records. For many firms, a sample of 50 to 100 transfers drawn from 12 and 24 months ago may provide a practical starting point. Document the results and note any gaps. Where records are incomplete, investigate and remediate the root cause.
What to do before your next audit
Preparing for a travel rule compliance audit does not require a full program overhaul. Firms can close most gaps with targeted improvements to existing processes.
Start with a data integrity review. Pull a sample of recent transfers and compare the originator and beneficiary fields in each travel rule message against the corresponding CDD records. Document every mismatch and fix the underlying data flow.
Then review your counterparty VASP register. Confirm that every active counterparty has a current risk assessment and that the register reflects recent enforcement actions.
Next, map your sanctions screening workflow against your travel rule messaging workflow. Confirm that both processes draw from the same data source and that screening completes before the transfer is completed.
Finally, run a record retrieval test. Select a risk-based sample of transfers from 12 and 24 months ago. Attempt to reconstruct the full evidence trail for each. Any unexplained retrieval failure should be treated as a compliance gap requiring investigation.
The Travel Rule has moved beyond legislation and increasingly into supervision. Firms that prepare now will be better positioned when auditors or supervisors test their Travel Rule controls. For tailored support with Travel Rule readiness assessments, counterparty due diligence frameworks or audit preparation, book a free consultation with Compliance7.
Related Compliance7 guides
- Core guide: Global Crypto Travel Rule Compliance: Regulatory Expectations for VASPs in 2026
- Core guide: VASP Compliance in India: What FIU-Registered Firms Still Get Wrong
- Related: AML Audits for Crypto Exchanges and VASPs: What Regulators Expect
This article is for informational purposes only and does not constitute legal or regulatory advice. For guidance specific to your business, consult a qualified compliance professional.



