deepidv
Back to Minutes
MinuteAML · Europe · European Banking Authority (EBA) / BaFin

EU Crypto Travel Rule Enters Full Enforcement Mode

The Transfer of Funds Regulation applies to every crypto transfer with no minimum threshold, and supervisors have named Travel Rule implementation an examination priority for 2026.

Rosalie Chirip
Rosalie Chirip
Senior Editor at deepidv
Aug 14, 2026 · 1 min read

What Changed

On January 28, 2026, Germany's Federal Financial Supervisory Authority (BaFin) published its Risiken im Fokus 2026 report, naming crypto-asset service provider implementation of the Travel Rule an explicit examination priority and committing to at least 75 anti-money-laundering special audits during the year. The move activates the recast Transfer of Funds Regulation (TFR), in force since December 30, 2024 with no transitional grace period, which requires originator and beneficiary information to accompany every crypto-asset transfer regardless of value. That zero-threshold standard was set by the European Banking Authority (EBA) Travel Rule Guidelines of July 4, 2024. With BaFin now auditing against it, the regulation shifts from obligation to active supervisory enforcement.

Who It Affects

Crypto-asset service providers authorised under MiCA, intermediary CASPs, and the payment service providers that interface with them. Exchanges, custodians and transfer services handling cross-border and self-hosted-wallet transactions are squarely in scope. With the interim technical-limitation allowances long expired and supervisors like BaFin now auditing against the zero-threshold rule, the conversation shifts from whether firms have a Travel Rule solution to whether it withstands examination.

What to Do

Verify that your Travel Rule messaging captures complete originator and beneficiary data on every transfer, including low-value and self-hosted-wallet cases, and that missing-information procedures actually trigger. Reconcile Travel Rule data against your sanctions-screening and CDD records so an examiner sees one coherent audit trail. Test the counterparty due diligence you perform before transacting with other CASPs. Treat the 2026 audit cycle as the moment gaps become findings, not observations.

IntermediateMinuteCryptoAMLRegulatory ComplianceEU

What is deepidv?

Not everyone loves compliance — but we do. deepidv is the AI-native verification engine and agentic compliance suite built from scratch. No third-party APIs, no legacy stack. We verify users across 211+ countries in under 150 milliseconds.

Learn More

More Minutes