FATF Recommendation 16: Travel Rule, 2025 Revision, and Crypto

FATF Recommendation 16 is the global standard that requires financial institutions to attach verified sender and recipient information to electronic payments so authorities can trace funds through the system. Often called the wire transfer rule, it applies to both cross-border and domestic transfers and now covers cryptocurrency movements as well. The Financial Action Task Force revised the standard at its June 2025 Plenary to catch up with fintechs, digital wallets, and virtual assets, and countries have until the end of 2030 to bring their laws into line.1Financial Action Task Force. FATF Updates Standards on Recommendation 16 on Payment Transparency

What the Rule Covers

Recommendation 16 applies to any electronic payment carried out through a financial institution on behalf of a sender. A cross-border transfer is one where the sending and receiving institutions sit in different countries. A domestic transfer stays within one nation’s borders, and it is still in scope because laundered money can move through purely internal channels before leaving a jurisdiction.

Banks are the obvious targets, but the rule reaches any entity that facilitates electronic fund movements. The 2025 revision explicitly acknowledges that fintechs and digital payment platforms now perform functions once handled only by banks, and cryptocurrency exchanges and other virtual asset service providers are within scope too.1Financial Action Task Force. FATF Updates Standards on Recommendation 16 on Payment Transparency

One boundary matters here: card-based purchases of goods and services remain exempt from the full requirements. The 2025 update narrowed the definition of what counts as such a purchase to prevent misuse of that carve-out, but ordinary retail card transactions still sit outside the wire transfer regime.

What Information Must Travel With a Transfer

Every wire transfer must carry identifying details about both sender and recipient. How much depends on whether the payment crosses a border and whether it exceeds a de minimis threshold.

Cross-Border Transfers Above USD/EUR 1,000

For cross-border payments above USD/EUR 1,000, the revised standard requires the sender’s full name, address, and date of birth. The recipient must be identified by name and account number. That information is drawn from the customer’s Know Your Customer profile, built when the account was opened, and embedded into the payment message so it moves alongside the funds.1Financial Action Task Force. FATF Updates Standards on Recommendation 16 on Payment Transparency

Transfers Below the Threshold

Countries may set a de minimis threshold of up to USD/EUR 1,000. Below it, the requirements shrink. For cross-border transfers under the threshold, institutions need only include the name and account number, or a unique transfer reference, for both sender and recipient. For domestic transfers below the threshold, the requirement drops further to just the sender’s name and account number. In both cases the data does not have to be independently verified unless the institution suspects money laundering or terrorist financing.

Responsibilities Along the Payment Chain

A single transfer often passes through several institutions before reaching the recipient. Recommendation 16 assigns distinct obligations at each stage.

The Ordering Institution

The institution that accepts the payment instruction from the customer bears primary responsibility for collecting and attaching the required identifying information. Under the 2025 revision, this is the point where the payment chain officially begins. If the ordering institution fails to include the necessary details, every institution downstream inherits a problem it cannot easily fix.1Financial Action Task Force. FATF Updates Standards on Recommendation 16 on Payment Transparency

Intermediary Institutions

Institutions sitting in the middle of the chain must keep sender and recipient information intact as the transfer passes through. They cannot strip or alter the identifying data. Where technical limitations prevent the information from staying with a related domestic leg of a cross-border transfer, the intermediary must retain a record of everything it received for at least five years. Intermediaries are also expected to flag transfers arriving without the required information and to maintain risk-based policies for deciding whether to process, reject, or suspend them.2Financial Action Task Force. The FATF Recommendations

The Beneficiary Institution

The institution receiving the funds on the recipient’s behalf must verify that the incoming information matches the recipient’s identity. When data is missing or incomplete, the beneficiary institution can reject the transfer outright, hold the funds while requesting the missing details from the sender, or process the transfer subject to a risk assessment. Repeated failures by a counterpart institution to include proper information can lead to the termination of the correspondent relationship entirely. This is where the system’s enforcement really lives, because no financial institution wants to lose its ability to receive international payments.

What the June 2025 Revision Changed

The original Recommendation 16 was written when most cross-border payments passed through a handful of large correspondent banks using established messaging networks. By 2025, that world barely existed. Peer-to-peer payment apps, mobile money platforms, and cryptocurrency exchanges had created payment chains the old rules did not clearly address. The FATF’s June 2025 Plenary adopted a revision targeting four areas.1Financial Action Task Force. FATF Updates Standards on Recommendation 16 on Payment Transparency

  • Clearer responsibilities across the payment chain. The chain now officially starts at the institution that receives the customer’s instruction, with each stage’s obligations to include and preserve information spelled out.
  • Standardized information for cross-border payments. For peer-to-peer cross-border transfers above USD/EUR 1,000, the required data is explicitly name, address, and date of birth.
  • Fraud and error protection. Institutions will be required to use technology that verifies recipient banking details before processing a transfer, reducing the risk that money lands in the wrong account.
  • Narrower card carve-out. The exemption for credit, debit, and prepaid card purchases of goods and services continues, but its definition has been tightened to prevent abuse.

Countries have until the end of 2030 to implement the updated standard. Until then, the pre-revision version of Recommendation 16 remains the baseline against which mutual evaluations are conducted.1Financial Action Task Force. FATF Updates Standards on Recommendation 16 on Payment Transparency

The Travel Rule for Cryptocurrency

The same transparency requirements apply to cryptocurrency and other digital asset transfers, a framework commonly known as the Travel Rule. The FATF describes the June 2025 revision as encompassing the Travel Rule in the virtual asset context.1Financial Action Task Force. FATF Updates Standards on Recommendation 16 on Payment Transparency When a user sends cryptocurrency from one exchange to another, the sending exchange must share the sender’s and recipient’s identifying details with the receiving exchange, just as a bank would for a traditional wire.

Unhosted Wallets

Transfers to self-custodial wallets, where there is no counterparty institution to receive the identity data, are the hard case. The FATF’s position is that a virtual asset service provider must still collect the required sender and recipient information from its own customer when facilitating a transfer to an unhosted wallet. The difference is that there is no receiving institution to transmit the data to. Countries that allow these transfers are expected to assess the associated risks and apply proportionate safeguards, which in practice can include caps on amounts sent to self-custodial wallets, enhanced due diligence, proof of control over the destination wallet, and blockchain analytics on the receiving address.3Financial Action Task Force. Targeted Report on Stablecoins and Unhosted Wallets

How Countries Turn R16 Into Law

FATF Recommendations are not themselves laws. They are standards each member country translates into its own legal framework, which means specific thresholds and data requirements vary as long as they meet the minimum the FATF sets. The United States implements its version of the Travel Rule through the Bank Secrecy Act at a higher threshold of $3,000, requiring transmitting institutions to collect and include the sender’s name, address, and account number along with the recipient’s identifying details for any funds transfer at or above that amount.4eCFR. 31 CFR 1010.410

Other countries may set their thresholds at or below the FATF’s USD/EUR 1,000 ceiling, require additional data elements, or impose stricter obligations on particular types of institutions. Falling short of the FATF minimum exposes a country to negative findings during evaluations.

How Compliance Is Enforced

The FATF verifies compliance through mutual evaluations: peer reviews where assessors from other member countries examine whether a jurisdiction has both the legal framework and the practical effectiveness to enforce its anti-money-laundering standards. Each evaluation has two components. Technical compliance checks whether the country’s laws and regulations cover what the FATF requires. Effectiveness, which drives the on-site portion of the review, looks at whether those laws actually produce results. A complete evaluation takes up to 18 months, and assessment reports are presented at one of the three Plenary meetings the FATF holds each year.5Financial Action Task Force. Mutual Evaluations

A country with significant weaknesses may be placed on the FATF’s list of Jurisdictions Under Increased Monitoring, informally known as the grey list. Grey-listing means the country has committed to addressing specific deficiencies within agreed timeframes and faces heightened scrutiny. Countries that fail to engage with the FATF to resolve their deficiencies risk being designated as High-Risk Jurisdictions Subject to a Call for Action, the formal name for the black list.6National Treasury South Africa. What Does FATF Greylisting Mean For A Country

The economic consequences are what give the standard its bite. Banks and other regulated firms in compliant countries must apply enhanced due diligence to transactions involving listed jurisdictions, which raises compliance costs and often leads to de-risking, where institutions simply terminate relationships with clients in those countries rather than bear the expense. Grey-listed countries have shown measurable drops in foreign direct investment, portfolio inflows, and cross-border banking activity, and correspondent banking relationships frequently shrink or disappear. For smaller economies, losing access to international payment channels can cause serious domestic instability, which is precisely why the listing mechanism works as a compliance incentive.