All four routes require both parties' names and account or reference numbers; Singapore and Hong Kong send them to the receiving provider. Only the step-up differs: Singapore above S$1,500, Hong Kong at HK$8,000. The EU's EUR 1 000 is a wallet-ownership check, not a transfer threshold. Switzerland is the outlier: without a reliable channel, a supervised firm may transact only with its own verified customers' wallets.
The threshold decides the step-up, not whether the rule applies
If you already know the travel rule exists, the question that matters is narrower: which version binds you, and what do you have to build before you file? This page answers both for the four routes an applicant chooses between. The annual side is covered in keeping a crypto licence; the company side in local substance requirements. All regulatory documents cited were retrieved on 9 October 2026.
Sending information with a transfer is one of the obligations that begin once you hold the licence. What else starts then -- banking, card programmes, what has to be notified -- is in after the licence. If the regulated activity you fall under is not settled yet, start with choosing a licence.
Key takeaways
- Below S$1,500 and below HK$8,000 four items still have to be obtained and recorded.
- The threshold decides the step-up, not whether the rule applies: above it you add the originator's address, ID number, or date and place of birth.
- The EU's EUR 1 000 line sits on the self-hosted address ownership check. The EUR 1 000 linked-transfer threshold is in the regulation's transfer-of-funds articles.
- Switzerland has no exception for unregulated wallet providers, and the Swiss self-regulatory route is CryptoLicense's largest practice by revenue.
Which version of the travel rule actually binds you?
Four routes, four texts. Switzerland's obligation is Article 10 of the FINMA Anti-Money Laundering Ordinance: client and beneficiary information must be transmitted with payment orders. The EU's is Regulation (EU) 2023/1113, applying since 30 December 2024 alongside MiCA, with the EBA's Travel Rule Guidelines. Singapore's is the value-transfer part of MAS Notice PSN02. Hong Kong's is the virtual asset transfer rule in the SFC's AML/CFT guideline.
Two practical points before the comparison. In Singapore and Hong Kong the information goes to the beneficiary institution at the other end, not the regulator, which sees it on request. And FINMA does not require it to travel on the blockchain: transmission can take place over other communication channels.
The four routes: what travels at the bottom tier, where the step-up sits, and what happens with a private wallet
| Route | Bottom tier | Step-up threshold | Private / external wallet |
|---|---|---|---|
| Switzerland: self-regulatory body members and licensed institutions | Client and beneficiary information transmitted with the payment order (no amount tiers in the guidance) | None stated | While the channel is unreliable: external wallets only if they belong to the institution's own customers, with ownership proven by suitable technical means |
| EU: crypto-asset service providers | Name, address and LEI or alternative identifier fields, to the EBA's field-level standards | None for the information between providers: the same requirements apply regardless of amount, domestic or cross-border | Above EUR 1 000, assess whether the address is owned or controlled by your customer; below it, still obtain and hold the information on the address |
| Singapore: payment services licensees (digital payment tokens) | Four items: both names, both account or unique transaction reference numbers (para 13.5 lets the domestic leg to an intermediary institution carry only the reference number and the beneficiary's details, provided it traces back to both parties and all four are supplied on request and to the beneficiary institution) | Above S$1,500: identify and verify the originator, and add address, unique ID number, or date and place of birth or registration | No separate self-hosted clause in the notice; if the requirements cannot be met, the transfer must not be executed at all |
| Hong Kong: virtual asset service providers | Four items below HK$8,000: both names, both account or unique reference numbers | At HK$8,000 and above: five items, adding the originator's address, customer identification number or ID document number | A dedicated unhosted-wallet clause: obtain and record both sides' information before sending or receiving; the address/ID item is excused below HK$8,000 |
The EU regulation says which information must be transmitted but not in detail, which is why the EBA had to publish standards for the name, address and identifier fields. If your vendor's message format predates those guidelines, the fields are where the gap will be. The regulation's own EUR 1 000 linked-transfer threshold sits in the transfer-of-funds articles (2(5)(c), 5(2), 6(2), 7(3)). Scope questions, meaning which services you trigger in the first place, are in which CASP services you trigger, and the vocabulary in the glossary.
Is there an amount below which nothing has to travel?
No. This is the most common planning error, and it comes from reading a FATF-style threshold as an exemption. Hong Kong below HK$8,000 still requires four items obtained and recorded, and Singapore at or below S$1,500 requires the same four. Crossing the line adds the identifying detail: Singapore adds identity verification of the originator plus an address, unique identification number, or date and place of birth; Hong Kong moves from four items to five.
Hong Kong then uses the same HK$8,000 line a second time, for record-keeping: an occasional transaction that is a virtual asset transfer at or above that amount attracts the heavier retention requirement. And in the unhosted-wallet clause the same figure appears a third time, as the point below which the originator's address, identification number or date and place of birth need not be obtained. One number doing three jobs, worth modelling once rather than three times.
What happens when the other end is a private wallet?
This is where the routes genuinely diverge, and where product design gets decided. In the EU the ownership test is conditional on amount: above EUR 1 000 the CASP must assess whether the self-hosted address is owned or controlled by its customer, and the EBA requires at least one of five listed verification methods, two of which are:
- Signed message. Ask the customer to digitally sign a specific message with the key corresponding to that address.
- Predefined-amount test. Send a predefined amount set by the CASP, preferably the smallest denomination of the asset, from and to the self-hosted address and the CASP's own account.
Two things sit outside that list of five. Whitelisting: once satisfied the address belongs to your customer, document it, and you may not need to re-apply the measures later. The EBA also expects controls to identify a change in the address's ML/TF risk or ownership, and removal from the whitelist when either changes. Third-party addresses are a different path: where the address belongs to a third person, a heavier verification route applies.
Hong Kong does not make the duty itself conditional on amount: the institution must obtain and record both sides' information before it sends to or receives from an unhosted wallet at all, and it should accept transfers only to or from unhosted wallets it has assessed to be reliable. Switzerland goes furthest. Even a fiat-to-crypto, crypto-to-fiat or crypto-to-crypto exchange that involves an external wallet requires proof of the customer's ownership of that wallet. Whether you are a custodian in the first place is a separate question, answered in when a wallet needs a custody licence.
Why is Switzerland the outlier?
Because Switzerland removed the exception everyone else kept. FINMA's guidance of 26 August 2019 states that, unlike the FATF standards, Article 10 of the ordinance provides no exception for payments involving unregulated wallet providers, because such an exception would favour unsupervised providers and leave supervised ones unable to stop problematic payments. The restriction that follows is stated in the regulator's own words:
"Institutions supervised by FINMA are only permitted to send cryptocurrencies or other tokens to external wallets belonging to their own customers whose identity has already been verified and are only allowed to receive cryptocurrencies or tokens from such customers."FINMA, press release, 26 August 2019
It is conditional, not a judgement about blockchains: the practice applies as long as information about the sender and recipient cannot be transmitted reliably in the respective payment system. The premise is factual: no system exists nationally or internationally, comparable to SWIFT for interbank transfers, that reliably transfers identification data for blockchain payments. FINMA's own characterisation: because it applies without the FATF exception for unregulated wallets, the practice is one of the most stringent in the world.
For anyone filing on the Swiss route, that clause ranks with capital and directors: it decides what your withdrawal feature looks like. The route itself is set out in the Swiss SRO application process.
Can you send when the counterparty will not send back?
Singapore answers it hardest: where the ordering institution cannot comply with the value-transfer requirements, it must not execute or arrange the transfer. Hong Kong's answer runs through screening: the relevant parties are screened against the current database before the virtual asset transfer is executed. Switzerland's restriction is itself the answer: while the channel is unreliable, the set of permissible counterparties narrows to the institution's own verified customers.
The EU acknowledged the same gap and bought time for it. Until 31 July 2025, CASPs whose messaging infrastructure had genuine technical limitations on data completeness were allowed to compensate with additional technical steps. That window has closed. What remains is a design question: your counterparty list, your transmission arrangement, and your written rule for an incomplete message all have to be explainable to a supervisor.
What this changes in the application file
Three decisions are cheaper before filing than after launch: how you identify the counterparty before a transfer, which ownership-verification method and whitelisting rule you adopt, and your written rule for not sending when the information is incomplete. The first two change the product; the third changes how long your compliance manual is.
- How you identify the counterparty, pre-transfer. The EU expects the assessment before initiation, with blockchain analytics and third-party data as acceptable means. That is a system capability, not a policy paragraph.
- Which ownership-verification method, and your whitelisting rule. Signed message, predefined-amount test, or a combination; when you re-verify; and what you do when the address belongs to a third person.
- Your written do not send rule. Singapore's text is that the transfer must not be executed where the requirements cannot be met. Writing that into the procedure is easier than explaining its absence.
Frequently asked questions
Does nothing have to travel with an EU crypto transfer under EUR 1 000?
That reads the threshold in the wrong place. The EBA applies EUR 1 000 to the self-hosted address ownership check, and the regulation's EUR 1 000 linked-transfer threshold sits in the transfer-of-funds articles (2(5)(c), 5(2), 6(2), 7(3)). Below EUR 1 000 the CASP must still obtain and hold the information on the self-hosted address.
Are the Singapore and Hong Kong bottom tiers the same?
The bottom tiers are near-identical; the step-ups are not. Both require four items below the line: both parties' names and both account or traceable reference numbers. The step-up sits at S$1,500 in Singapore and HK$8,000 in Hong Kong, where the requirement becomes five items including the originator's address, customer identification number or ID document number.
Can a Swiss-supervised firm let customers withdraw to their own wallets?
Yes, within a narrowed set. While the required payment information cannot be sent and received reliably, a supervised institution may transact only with external wallets belonging to its own already-verified customers, and must prove that ownership by suitable technical means. Where the wallet belongs to a third party, the institution must first verify that third party's identity, establish the beneficial owner, and prove the third party's ownership of the wallet.
This page describes the wording of public regulatory documents as at October 2026 and is not legal advice. No application can be guaranteed approval; authorisation is entirely at the regulator's discretion. CryptoLicense is the licensing-advisory brand of CL GLOBAL SDN BHD (1421939-T), which has served 100+ companies across 10+ jurisdictions; registration details are on the entity proof page, and route selection in choosing a licence.
