The travel rule is being rewritten for every cross-border payment, not just crypto
FATF agreed revisions to Recommendation 16 in June 2025. From the point countries implement, a peer-to-peer cross-border payment above USD/EUR 1,000 carries name, address and date of birth.
FATF agreed revisions to Recommendation 16 in June 2025. From the point countries implement, a peer-to-peer cross-border payment above USD/EUR 1,000 carries name, address and date of birth. The guidance consultation closed on 21 August 2026.
The short version
- FATF describes Recommendation 16 as "also referred to as the 'Travel Rule' in the context of virtual assets". The standard covers cross-border payments generally, and the revisions were made for the whole payments landscape.
- Standardised requirements apply to peer-to-peer cross-border payments over that threshold: name, address and date of birth accompany the payment message.
- "The payment chain is considered to start with the financial institution which receives an instruction from the customer", which fixes who is responsible for the information being right.
- The revised standard requires use of technologies protecting against fraud and error, "such as verification of recipients' banking information".
- Card transactions for the purchase of goods or services remain outside full R.16 requirements, though the scope of "purchase of goods and services" has been clarified.
- After the October 2025 Plenary, FATF published an Annex IV to its assessment methodology setting out how compliance with the revised R.16 will be assessed in mutual evaluations.
Most people who say travel rule mean crypto, and the rule was never only about crypto
The Financial Action Task Force, the intergovernmental body that sets global anti-money laundering standards, revised Recommendation 16 in June 2025. In its own words it is "also referred to as the 'Travel Rule' in the context of virtual assets". That framing is the source of a persistent misunderstanding, because the recommendation has always governed wire transfers.
The rule's idea is simple. When money moves, information about who sent it and who receives it should move with it, so that an investigator following a payment does not lose the thread at a border. Crypto firms met it late and loudly, which is why the phrase attached itself to virtual assets, but banks and payment firms have lived under it for years.
On 18 June 2025 FATF agreed a set of revisions at its Plenary. The stated reason was that the payment landscape had changed underneath the standard. As FATF puts it, "many different actors, such as fin-techs and digital payment systems, are now performing tasks that only a few, traditional banks, did in the past".
So this is a rewrite of the rule for everyone who moves money across a border, and the identity content of it is the part worth a compliance team's attention.
Four changes, and the second one is an identity requirement
FATF's announcement of 18 June 2025 sets out four changes to Recommendation 16. They cover who is responsible in the payment chain, what information must accompany a payment, what anti-fraud tooling firms must deploy, and how card transactions are treated. The second is the one that reaches back into onboarding.
Responsibility. Under the revised standard "the payment chain is considered to start with the financial institution which receives an instruction from the customer". That settles a question that used to produce finger-pointing: when information is missing or altered somewhere along a chain of intermediaries, the starting point is now defined.
Information. FATF is "applying standardised requirements on what information should accompany the payment messages for peer-to-peer cross-border payments above USD/EUR 1,000". The fields are name, address and date of birth. FATF's rationale is efficiency as much as transparency: standardising the payload simplifies requirements for the private sector while making it clearer who is sending and receiving money.
Anti-fraud tooling. The revised standard requires firms to "make use of new technologies that protect against fraud and error, such as verification of recipients' banking information". FATF notes that such technologies "are already in place in parts of the world", which is a reference to confirmation-of-payee style checks.
Cards. Transactions using a credit, debit or prepaid card "for the purchase of goods or services continue to be exempt from full R.16 requirements", with clarification of what counts as a purchase of goods and services.
Two earlier public consultations, gathering "more than 300 responses", fed into the June 2025 package, and FATF frames the whole exercise as supporting the G20 roadmap for cross-border payments that are "faster, cheaper, more transparent and more inclusive".
The deadline is 2030 and the grading method already exists
FATF states that the changes to Recommendation 16 "will come into effect by the end of 2030", and that all countries are expected to be ready by then. That is a long runway by regulatory standards, and it is the reason this can look like a problem for later. The assessment machinery says otherwise.
After the October 2025 Plenary, FATF published an Annex IV to its assessment methodology "setting out how compliance with the revised Recommendation 16 will be assessed in FATF mutual evaluations". A mutual evaluation is the peer review in which one country's anti-money laundering regime is graded by others, and a poor result carries real consequences for a jurisdiction's standing.
The guidance layer arrived next. On 24 June 2026 FATF opened a consultation on draft guidance to support implementation, closing on Friday 21 August 2026. At the time of writing no outcome or results document has been published.
What FATF asked about tells you where the difficulty is expected. It sought views on detecting and preventing misdirected payments, "including by leveraging the three options for alignment checks foreseen in the revised Standard". It asked about implementation "that supports financial inclusion, including in lower-capacity jurisdictions". It also asked how the recommendation applies to "newer payment methods, such as digital wallets and mobile money", and how to meet data protection requirements at the same time.
I urge everyone with an interest to share their views, so that we can unleash the full potential of the strengthened Recommendation 16, which will better equip authorities and financial institutions to follow the money and disrupt harmful criminal activity.
Elisa de Anda Madrazo, President of the Financial Action Task Force. Statement of 24 June 2026
| Date | Rule | Status |
|---|---|---|
| 18 Jun 2025 | Revisions to Recommendation 16 agreed — Agreed at the FATF Plenary. Four changes covering payment chain responsibility, standardised information, anti-fraud tooling and card scope. | Passed |
| 28 Oct 2025 | Annex IV to the assessment methodology — Published after the October 2025 Plenary, setting out how compliance with the revised R.16 will be assessed in mutual evaluations. | Passed |
| 24 Jun 2026 | Consultation on draft implementation guidance — Views sought on misdirected payments, financial inclusion, digital wallets and mobile money, and data protection. | Passed |
| 21 Aug 2026 | Consultation closed — No outcome or results document published at the time of writing. | Closed |
| End 2030 | Countries expected to be ready — "The changes will come into effect by the end of 2030." National implementation dates are set by each jurisdiction. | Ahead |
What you collect at onboarding decides what you can put in a payment message
Recommendation 16, as revised in June 2025, asks for name, address and date of birth to travel with peer-to-peer cross-border payments above USD/EUR 1,000. A firm cannot put those fields in a message unless it holds them, holds them accurately, and holds them in a form that can be transmitted. That is an onboarding question answered years before the payment.
Address is the field most likely to cause trouble. Names and dates of birth come off an identity document; a current address usually does not, which is why a separate proof of address step exists at all. A customer file that was adequate for opening an account may not carry an address in a structured, current form.
The anti-fraud requirement points somewhere different. Verifying a recipient's banking information before sending is not customer due diligence; it is a payment-time check on the counterparty, closer in spirit to the confirmation-of-payee schemes already running in several markets. Firms will need to source it rather than build it out of their existing identity stack.
The proportionality question sits where FATF put it in its own consultation, which is unusual and worth noting. The body asked explicitly about "implementation that supports financial inclusion, including in lower-capacity jurisdictions", and invited input from emerging economies. A rule that attaches identity data to every cross-border payment above a threshold falls hardest on remittance corridors, and FATF has asked the question rather than left it to be raised.
None of this binds a firm today. FATF sets standards for countries; the obligation arrives through national implementation, on national timetables. Several markets are already moving, which is the pattern we traced across nine Asian jurisdictions rewriting their identity rules, and Ireland has committed to extending originator and beneficiary information to crypto transfers as part of implementing the EU package. The deadline that matters to you is your regulator's, not FATF's.
Key takeaways
Recommendation 16 is not a crypto rule.
FATF calls it the Travel Rule "in the context of virtual assets", but the standard governs cross-border payments generally and was revised for the whole payments landscape.
Three identity fields above USD/EUR 1,000.
Name, address and date of birth accompany peer-to-peer cross-border payments over the threshold.
Responsibility now has a starting point.
The payment chain starts with the institution that receives the customer's instruction.
Recipient verification becomes a requirement.
Firms must use technologies protecting against fraud and error, such as verification of recipients' banking information.
2030 is the readiness date, and grading is already defined.
An Annex IV to the assessment methodology published in October 2025 sets out how mutual evaluations will assess the revised standard.
Using Didit for Recommendation 16 readiness
The identity payload is the part of this that a verification provider touches. Name and date of birth come from the document, which ID Verification at $0.15 per check reads and validates. Where the document is chipped, NFC Reading at $0.15 per check takes them from signed data rather than a photographed page. Address is the field least likely to be sitting in a usable form already, and Proof of Address at $0.20 per check is what evidences it. For firms transmitting the messages themselves, Travel Rule runs at $0.02 per transaction and Transaction Monitoring at $0.02 per transaction. Current prices are on the pricing page.
Two limits are worth stating plainly. FATF sets standards for countries rather than obligations on firms, so nothing here binds you until your own jurisdiction implements it, and Didit cannot tell you which national rules apply to your licence. And the recipient-verification requirement is a payment-time check on a counterparty's banking details, which is not something we do; that capability sits with payment infrastructure providers rather than with identity verification.
Frequently asked questions
Is the FATF travel rule only about crypto?
No. The obligation is Recommendation 16, which FATF describes as "also referred to as the 'Travel Rule' in the context of virtual assets". It applies to cross-border payments generally, and the June 2025 revisions were made to keep pace with the whole payments landscape, including fintechs and digital payment systems.
What information must accompany a cross-border payment under the revised Recommendation 16?
For peer-to-peer cross-border payments above USD/EUR 1,000, FATF is applying standardised requirements covering name, address and date of birth. The aim is to simplify requirements for the private sector and make it clearer who is sending and receiving money.
When does the revised Recommendation 16 take effect?
FATF states that the changes will come into effect by the end of 2030, and that all countries are expected to be ready to implement them by then. FATF sets standards for countries, so the binding obligation on any individual firm arrives through its own jurisdiction's implementation.
What did the August 2026 FATF consultation cover?
Draft guidance to support implementation, open from 24 June to 21 August 2026. FATF sought views on detecting and preventing misdirected payments, implementation that supports financial inclusion in lower-capacity jurisdictions, how Recommendation 16 applies to newer payment methods such as digital wallets and mobile money, and meeting data protection requirements alongside it.
Will countries be assessed on the revised Recommendation 16?
Yes. Following the October 2025 FATF Plenary, an Annex IV to the FATF assessment methodology was published, setting out how compliance with the revised Recommendation 16 will be assessed in FATF mutual evaluations.
Related reading
- Asia is moving the cost of weak identity checks onto banks and platforms — Nine markets rewriting identity rules, several of them on travel rule thresholds.
- The stablecoin identity rule covers issuance and redemption — Where American identity duties attach in a payment chain.
Sources
- FATF updates Standards on Recommendation 16 on Payment Transparency — Financial Action Task Force · 18 June 2025, updated 28 October 2025 · the four changes and the 2030 date
- FATF launches public consultation on guidance to increase payment transparency — Financial Action Task Force · Paris, 24 June 2026 · closed 21 August 2026 · source of the de Anda Madrazo statement
- The FATF Recommendations — Financial Action Task Force · the standards themselves, including Recommendation 16 and its Interpretive Note
Who wrote this
Tuan Nguyen — Growth · Didit
Writes about identity verification, fraud and compliance at Didit.
Last reviewed 24 Aug 2026 against the sources above
Related articles
- The UK's first A7 alert describes a network built to pass identity checks
- A four-digit merchant code decided whether memecoin buyers faced KYC
- Korea let a crypto exchange pull government records for KYC instead of asking for documents
- FinCEN's Banque Misr proposal names one bank and 103 front companies
- All 400 wealth managers refresh KYC now, but 26% record no expected activity
- California is moving age checks from the website to the phone