Blokchain Basics
•
9
min read

FATF vs EU AML Rules for Crypto Payments

How FATF standards differ from binding EU AML Travel Rule duties for crypto payments, and what to check before sending funds.

FATF sets standards; EU law sets binding duties for covered crypto payments. Before sending funds, I’d check the provider’s legal status, destination wallet, and ability to send the required transfer data - not just its claim of “FATF compliance.”

As of October 3, 2026, the EU crypto Travel Rule already applies. Small payments are not automatically exempt, and the EU’s €1,000 self-hosted wallet check is separate from transfer-data duties. <u>There’s no reason to wait for the July 10, 2027 AML changes.</u>

Quick Comparison

Check FATF standards Current EU rules
Legal force and provider oversight Countries implement standards through local law. Binding rules apply to covered CASPs; authorization needs a separate check.
Transfer data and thresholds Local law sets duties and may use a $1,000 or €1,000 threshold. Required data applies without a general small-payment exemption.
Self-hosted wallets Controls depend on risk and local law. Transfers exceeding €1,000 trigger a customer ownership-or-control assessment.
Missing data Local rules determine the response. Providers use risk-based procedures to request data, suspend, or reject transfers.
Customer checks, reporting, and records Duties arise through domestic law. Applicable EU and national duties apply alongside transfer-data rules.
Cross-border routes Requirements differ by country. Foreign rules do not remove an EU provider’s duties.

My pre-payment checklist is simple: verify the provider and wallet, confirm the secure data route, and keep the invoice, approval, and transaction records. Travel Rule checks do not replace sanctions checks or suspicious activity reporting.

FATF vs EU Crypto AML: Rules Before You Pay

FATF vs EU Crypto AML: Rules Before You Pay

FATF standards for crypto transfers

FATF sets the global baseline, while EU rules impose binding duties. FATF Recommendation 15 requires countries to license or register virtual asset service providers and supervise their AML/CFT controls. Its Interpretive Note applies Recommendation 16 to virtual-asset transfers.

The Travel Rule requires providers to collect, keep, and transmit required sender and recipient information. Providers must also conduct customer checks, monitor activity, apply enhanced checks to higher-risk activity, and report suspicious activity. FATF standards take effect through local implementation - not publication alone. Publishing a standard does not create a direct duty for businesses.

For crypto payments, that difference determines which rules providers must follow.

Issue FATF standards EU framework
Legal authority and implementation International recommendations implemented through domestic law. Binding EU rules: Regulation (EU) 2023/1113 sets transfer-data duties; MiCA governs authorization, alongside national AML laws.
Covered providers VASPs and relevant financial institutions involved in virtual-asset transfers. Crypto-asset service providers (CASPs) and intermediary CASPs within the applicable EU rules.
Supervision National authorities oversee compliance and enforcement. Competent authorities oversee authorization and AML compliance; EBA guidance supports consistent transfer-data procedures.

These differences affect how much transfer data providers must collect and what they must do when information is missing.

EU transfer data and AML duties

Regulation (EU) 2023/1113 covers crypto transfers when the originator’s or beneficiary’s CASP - or an intermediary CASP - has its registered office in the EU. It does not automatically cover direct transfers made without a CASP.

Under the EBA Travel Rule Guidelines, providers must detect missing or incomplete transfer information. They must then take risk-based steps to request the data, suspend the transfer, or reject it.

Separate AML duties require customer and ultimate beneficial owner checks, monitoring, recordkeeping, and reporting suspicions to the relevant Financial Intelligence Unit (FIU) without tipping off customers. Sanctions screening and asset-freezing duties come from separate rules. Travel Rule compliance does not replace them.

Current rules and changes in 2027

The date that matters for current compliance is today - not 2027.

As of October 3, 2026, Regulation (EU) 2023/1113 and the EBA guidelines already apply to covered transfers. The 2027 AML framework does not postpone those duties. Check the legal entity, its authorized services, and its status in the relevant authority’s records.

Transfer data, wallet checks, and risk controls

Once the scope is set, providers need to know what to verify before a transfer moves. FATF sets a risk-based baseline; EU law makes some of those requirements binding in the EU. Travel Rule data, wallet ownership or control, and suspicious reporting are separate checks. Passing one does not satisfy the others.

Travel Rule data and value thresholds

FATF’s $1,000 or €1,000 threshold is an option for national lawmakers, not a worldwide exemption. EU providers must collect the prescribed transfer information even for small payments.

Transfer value or condition FATF baseline, subject to local implementation Current EU duty
Below the applicable FATF threshold Collect the originator’s and beneficiary’s names, wallet addresses or account identifiers, and originator location information, subject to local law. Collect and retain the required originator and beneficiary information. There is no general small-transfer exemption.
At or above the applicable threshold Obtain, hold, and transmit the full required originator and beneficiary information, and apply verification controls. Apply EU information requirements and preserve an individual transaction record.
Suspicious or related transfers Review the combined pattern rather than each transfer alone, and escalate when suspicion exists. Apply monitoring and other AML checks. Artificial splitting does not remove information duties.

If beneficiary data is incomplete, hold or reject the transfer and document the reason.

Self-hosted wallet ownership and control

The EU’s €1,000 ownership-or-control check does not exempt smaller transfers from data collection. Nor does it automatically prohibit self-hosted wallets. FATF calls for controls proportionate to the wallet and transaction risk.

Transfer direction Information collection Ownership or control assessment Risk measures
Customer sends through a CASP to a self-hosted address Collect and hold originator and beneficiary information, and identify the transfer individually. For amounts exceeding €1,000, assess whether the sending customer controls the destination address. Use a signed message, a small verification transaction, a wallet connection check, or another documented method. Investigate unresolved risks.
Self-hosted address sends to a CASP customer Collect and hold originator and beneficiary information, and identify the transfer individually. For amounts exceeding €1,000, assess whether the receiving customer controls the sending address. Review the source of funds, wallet history, and relevant risk indicators.
Direct wallet-to-wallet transfers fall outside this rule until a CASP is involved. Outside this EU transfer-information regulation. No CASP ownership-assessment duty under this regulation. -

These checks run alongside broader AML monitoring and reporting.

Customer checks, reporting, and penalties

Wallet checks do not replace customer due diligence or suspicious reporting. Amount alone does not establish suspicion. False beneficiary details, an unexplained source of funds, repeated threshold-splitting, or other unusual patterns can matter more than payment size. Record why an alert was cleared or escalated, and report when the legal suspicion standard is met.

Control FATF standard Applicable EU or national duty Provider action
Customer and UBO Identify and verify customers and relevant beneficial owners. Follow applicable customer due diligence requirements. Verify the business, its ultimate owners, and the payment purpose.
Enhanced due diligence and monitoring Apply stronger checks to higher risks and monitor activity. Apply relevant enhanced checks and ongoing monitoring. Investigate unusual patterns and inconsistent funding evidence.
Suspicious reporting Report suspicions under domestic implementation. Report to the relevant FIU and observe tipping-off restrictions. Preserve evidence and document the reporting decision.
Retention Maintain records under implemented standards. Follow applicable transfer-record and national AML retention rules. Retain transfer data, verification evidence, alerts, and missing-data correspondence.
Supervision and penalties National authorities enforce local law, not FATF itself. Competent authorities apply supervisory measures and penalties. Details vary by member state. Map controls to local duties and fix gaps promptly.

Cross-border checks and choosing a provider

EU obligations still apply, even when a foreign provider follows different FATF-based local rules. Overseas laws may differ on start dates, provider definitions, and required fields. Providers may also use data formats or secure channels that don’t work together. Weaker foreign rules do not remove an EU CASP’s obligations.

The main check is whether the receiving provider can accept the required data and route it securely.

Stage FATF-based local requirements EU duties Provider actions
Before transfer Local law sets the required information and effective dates. Covered transfers involving an EU CASP or intermediary CASP fall under Regulation (EU) 2023/1113. Confirm that the receiving provider accepts the required fields and secure transmission channel.
During transmission Local rules govern secure transmission of originator and beneficiary data. Apply transfer-data requirements and procedures for missing or incomplete information. Match the transaction ID to the off-chain data message. Resolve format mismatches before release, limit data access, and follow applicable privacy rules.
After settlement Reporting and retention duties depend on local implementation. Applicable EU and national monitoring, reporting, and recordkeeping duties continue. Preserve the transaction-data link, review unresolved alerts, and document any suspension, rejection, or return.

EU business payments to overseas suppliers

For supplier payments, check whether the provider can receive both the payment and the required data without delay.

Before paying an overseas supplier, confirm the supplier, destination wallet, and secure data path: the EU CASP must transmit required information even when the receiving provider applies different local rules.

Provider authorization and payment records

Once you’ve confirmed the route, check the provider, records, and payment file before funding.

Use this pre-funding checklist:

  • Confirm the provider’s legal entity and verify that it can legally serve the route and transmit required transfer data.
  • Confirm the destination wallet and review wallet-risk findings.
  • Keep the invoice, internal approval, provider confirmation, transaction hash, and exception correspondence.

Conclusion: what to check before paying

FATF sets the baseline; EU law makes the rules binding for covered crypto payments. Suspicious activity reporting is mandatory when the legal threshold is met under the applicable domestic rule.

What matters isn't which framework sounds stricter. It's whether the payment route can meet the required checks. Use a provider authorized for that route, and expect identity and transfer-data checks. Small payments aren't automatically exempt from EU Travel Rule requirements. Before paying, check the destination’s rules and how the provider handles missing data if a transfer is held or rejected.

Follow current rules; don't wait for future reforms. Current guidance and provider instructions matter more than future reform dates. Check the relevant national authority’s current guidance and your provider’s instructions. Proceed only if the cross-border route supports the required data flow and controls.

FAQs

How can I verify a crypto provider’s EU authorization?

Check the European Securities and Markets Authority’s (ESMA) official interim MiCA register to confirm that the provider is listed as an authorized Crypto-Asset Service Provider (CASP).

Then review the provider’s website for its licenses, registrations with national financial supervision authorities, and regulatory details. Give preference to providers that clearly explain how they comply with regulations. This transparency is a key indicator of adherence to EU standards.

What if I’m paying someone else’s self-hosted wallet?

Requirements vary by transfer amount and jurisdiction. Under EU rules, transfers of more than €1,000 from a regulated platform to a self-hosted wallet require proof that you own or control the wallet. This usually involves signing a message.

Direct peer-to-peer transfers between individuals using self-hosted wallets remain legal and don’t require KYC checks. Transfers through regulated platforms must follow the Travel Rule, which requires collecting sender and recipient information.

How is my Travel Rule data protected abroad?

When you send cryptocurrency abroad, legal safeguards and security measures help protect your Travel Rule data. EU-regulated platforms like Kryptonim must follow GDPR privacy and security requirements.

For transfers outside the European Economic Area, platforms use legal safeguards such as Standard Contractual Clauses, Binding Corporate Rules, and adequacy decisions. Encryption and pseudonymization add protection by reducing risks when data moves between countries.

Related Blog Posts