US Travel Rule: Thresholds, Crypto Transfers, and Penalties

The US Travel Rule is a Bank Secrecy Act regulation that requires financial institutions to collect, retain, and pass along specific identifying information about the sender and recipient whenever they process a funds transfer of $3,000 or more.1Financial Crimes Enforcement Network. Funds Travel Regulations: Questions and Answers The point is to keep an identity trail attached to money as it moves between institutions, so investigators can trace the origin of suspicious funds no matter how many intermediaries handle the transfer. It applies to banks, credit unions, brokers, money services businesses, casinos above a revenue threshold, and cryptocurrency platforms.

What Information Must Travel With the Transfer

Under 31 CFR 1010.410(f), the sender’s financial institution has to include the following in every transmittal order of $3,000 or more at the time it goes out:2eCFR. 31 CFR 1010.410 – Records To Be Made and Retained by Financial Institutions

  • The sender’s name, and account number if the transfer is drawn from an account
  • The sender’s address
  • The exact dollar amount of the transfer
  • The execution date
  • The recipient’s financial institution
  • The recipient’s name, address, and account number or other identifier, to the extent the sending institution has that information
  • The transmittor’s own financial institution, identified by name and address or by a numerical identifier

Any intermediary institution that touches the transfer along the way has to forward all of that same information in its own transmittal order.2eCFR. 31 CFR 1010.410 – Records To Be Made and Retained by Financial Institutions By the time the funds reach the receiving bank, the entire identity trail should be intact.

Who Has to Comply

The definition of “financial institution” for these purposes is broad. Under 31 CFR 1010.100(t), it covers banks, brokers and dealers in securities, money services businesses, casinos with more than $1 million in gross annual gaming revenue, and card clubs meeting that same revenue threshold.3eCFR. 31 CFR 1010.100 – General Definitions Credit unions fall inside the BSA definition of “bank.” Money services businesses include money transmitters and currency exchangers, which is why services like Western Union and MoneyGram are on the hook.

Each institution’s obligations depend on where it sits in the chain. The transmittor’s institution originates the transfer and carries the heaviest data-collection load. Intermediaries relay the transfer and must pass along whatever they received. The recipient’s institution accepts the transfer at the end. If any link drops the information, the chain breaks.

The $3,000 Threshold and What’s Exempt

The rule triggers at $3,000. Any transmittal of funds equal to or greater than that amount, domestic or international, requires the identifying information described above.1Financial Crimes Enforcement Network. Funds Travel Regulations: Questions and Answers The threshold covers the foreign-currency equivalent for cross-border transfers. FinCEN proposed in 2020 to drop the threshold to $250 for transfers beginning or ending outside the United States, but that proposal was never finalized, and the $3,000 figure still governs both domestic and international transfers.4Federal Register. Threshold for the Requirement To Collect, Retain, and Transmit Information on Funds Transfers and Transmittals of Funds That Begin or End Outside the United States

Several categories of transactions fall outside the rule entirely:

  • Consumer electronic transfers governed by the Electronic Fund Transfer Act, including ACH, ATM, and point-of-sale transactions5FFIEC BSA/AML InfoBase. Funds Transfers Recordkeeping – Section: Travel Rule Requirement
  • Transfers where the sender and recipient are the same person and both use the same bank
  • Transfers where either party is a federal, state, or local government entity6Financial Crimes Enforcement Network. Funds Travel Regulations: Questions and Answers
  • Transfers where the sender or recipient is itself a bank, a wholly owned domestic subsidiary of a US-chartered bank, a broker-dealer in securities, or a wholly owned domestic subsidiary of a broker-dealer

Consumer payment systems and government transfers already sit under separate regulatory schemes, which is why they’re carved out here. The Travel Rule targets the commercial wire transfer system, where large sums move institution to institution.

Recordkeeping and Identity Verification

Transmitting the information is only half the requirement. The sender’s institution also has to retain a record of the sender’s name, address, transfer amount, execution date, and the recipient’s financial institution, along with whatever recipient details it collected.2eCFR. 31 CFR 1010.410 – Records To Be Made and Retained by Financial Institutions If the sender is not an established customer, the institution must verify the person’s identity in person using government-issued ID and record the ID type, number, and the person’s taxpayer identification number.

Records have to be kept for at least five years.7FFIEC BSA/AML InfoBase. Appendix P – BSA Record Retention Requirements Banks also have to maintain written procedures for verifying customer identities under their Customer Identification Program obligations.8eCFR. 31 CFR 1020.220 – Customer Identification Program Requirements for Banks

How the Rule Applies to Cryptocurrency

FinCEN’s 2019 guidance confirmed that money transmitters dealing in convertible virtual currencies are subject to the same BSA rules as any other money transmitter, including the Travel Rule.9Financial Crimes Enforcement Network. FinCEN Guidance FIN-2019-G001 – Application of FinCENs Regulations to Certain Business Models Involving Convertible Virtual Currencies A regulated crypto exchange processing a transfer of $3,000 or more has to collect and pass along the same sender and recipient information that a bank would attach to a wire.

The challenge is that blockchains don’t have built-in fields for identity data the way SWIFT and Fedwire messages do. Exchanges have addressed this by using off-chain messaging systems to send the required information to the receiving platform in parallel with the on-chain transaction. Platforms that can’t implement a compliant system risk losing the ability to operate as money transmitters in the United States.

Transfers Involving Unhosted Wallets

Self-custodied wallets sit outside any regulated institution, which complicates the transmit side of the rule. FinCEN proposed a rule in late 2020 that would have imposed specific requirements on banks and money services businesses for transactions involving unhosted wallets, with a $10,000 reporting threshold and a $3,000 recordkeeping threshold, but it was never finalized.10Financial Crimes Enforcement Network. Requirements for Certain Transactions Involving Convertible Virtual Currency or Digital Assets The general recordkeeping rule still applies: when a customer sends $3,000 or more from a licensed exchange to an unhosted wallet, the exchange has to collect and keep the sender’s information. It just has no counterparty institution to transmit that information to.

Structuring and Penalties

Breaking a large transfer into smaller amounts specifically to stay under BSA reporting thresholds is a federal crime called structuring. Under 31 USC 5324, structuring carries up to five years in prison. If it’s part of a broader pattern of illegal activity involving more than $100,000 in a 12-month period, the maximum doubles to 10 years.11Office of the Law Revision Counsel. 31 USC 5324 – Structuring Transactions To Evade Reporting Requirement Prohibited Institutions that spot patterns suggesting structuring are expected to file a Suspicious Activity Report when the transaction involves at least $5,000 and there’s reasonable suspicion of evasion. Certainty isn’t required.

For the institution itself, the civil penalty structure under 31 USC 5321 scales with intent. Negligent violations can draw up to $500 per violation, subject to annual inflation adjustments. Willful violations can run to the greater of the transaction amount (capped at $100,000) or $25,000 per violation.12Office of the Law Revision Counsel. 31 USC 5321 – Civil Penalties FinCEN enforcement actions against institutions with systemic failures frequently settle for figures well into the millions, along with mandatory remediation, independent compliance monitors, and continued reporting.13Financial Crimes Enforcement Network. Enforcement Actions Individual partners, directors, officers, and employees who willfully participate in violations face the same penalty structure the institution does.

How the US Rule Compares Internationally

The Financial Action Task Force sets a parallel global standard through its Recommendation 16. In June 2025, FATF updated the recommendation to standardize cross-border peer-to-peer payment requirements, setting a threshold of $1,000 (or €1,000) above which the sender’s name, address, and date of birth must accompany the payment.14FATF. FATF Updates Standards on Recommendation 16 on Payment Transparency The US $3,000 figure is higher than both the FATF standard and the thresholds many other jurisdictions apply, so institutions handling cross-border transfers often have to comply with a stricter foreign threshold even when the US number wouldn’t be triggered. Programs built for international operations typically default to the lowest applicable threshold.