Launching a VASP means navigating Travel Rule compliance from day one. Unlike many regulatory requirements that scale with maturity, the Travel Rule applies from your first qualifying transfer. There is no grace period.
This checklist covers every step a new VASP needs to take to build a Travel Rule compliance programme that satisfies regulators, protects your licence, and scales with your operations.
Before you begin: understanding the scope
The FATF Travel Rule requires VASPs to collect, transmit, and store originator and beneficiary information for qualifying virtual asset transfers. "Qualifying" depends on the jurisdiction — thresholds range from zero (every transfer) to USD 3,000, with most jurisdictions trending toward lower thresholds or no threshold at all.
Your compliance programme must account for every jurisdiction in which you operate, every jurisdiction your counterparties operate in, and every jurisdiction your customers reside in. This is not a single-jurisdiction exercise.
Step 1: Confirm your regulatory registration
Before processing any transfers, confirm that your VASP is properly registered or licensed in every jurisdiction where you operate.
- Identify your primary regulator based on your principal place of business (e.g., MAS in Singapore, FCA in the UK, AUSTRAC in Australia, FinCEN in the US)
- Complete VASP registration with the relevant authority. In many jurisdictions, operating as a VASP without registration is a criminal offence.
- Obtain any required licences — some jurisdictions require specific licences beyond basic registration (e.g., Hong Kong's SFC licence, Dubai's VARA licence)
- Register as a reporting entity for AML/CTF purposes, which is typically a prerequisite for Travel Rule compliance
- Document your registration status and keep copies of all licences, approvals, and correspondence with regulators
This step is non-negotiable. You cannot build a compliant Travel Rule programme on an unregistered VASP.
Step 2: Map your jurisdictional obligations
Travel Rule requirements differ by jurisdiction. Your compliance programme must reflect the specific rules that apply to your operations.
- List every jurisdiction where you hold a licence, have customers, or process transfers
- Document the Travel Rule threshold for each jurisdiction (e.g., EUR 0 in the EU, SGD 1,500 in Singapore, USD 3,000 in the US)
- Identify the required data fields for each jurisdiction — while FATF provides a baseline, jurisdictions may require additional fields
- Note any jurisdiction-specific rules such as enhanced due diligence for unhosted wallets, sanctions screening requirements, or specific protocol mandates
- Establish a process for monitoring regulatory changes — thresholds and requirements change regularly, and your programme must adapt
This mapping exercise becomes the foundation of your screening rules and SOPs.
Step 3: Build your KYC data collection process
Travel Rule compliance starts with having the right data. You cannot transmit originator information you have not collected.
- Collect full originator data at onboarding: name, account number or wallet address, physical address (or national identity number, or date and place of birth)
- Verify originator identity using reliable, independent sources — this is a regulatory requirement in most jurisdictions, not an optional enhancement
- Implement ongoing monitoring to ensure customer data remains current and accurate
- Design your data collection forms to capture all fields required by your most demanding jurisdiction — it is easier to collect everything upfront than to chase missing data later
- Store KYC data securely with appropriate access controls, encryption, and retention policies (most jurisdictions require five to seven years of retention)
- Plan for data quality issues — incomplete or inaccurate originator data is one of the most common Travel Rule audit findings
Your KYC process should be designed with Travel Rule compliance in mind from the start, not retrofitted later.
Step 4: Establish counterparty identification and due diligence
The Travel Rule requires you to know who you are sending data to, not just who your customer is.
- Build a counterparty VASP database that tracks the name, registration status, jurisdiction, and supported protocols of every VASP you exchange transfers with
- Verify counterparty registration status — transmitting Travel Rule data to an unregistered entity creates its own compliance risk
- Assess counterparty compliance capability — can they receive and process Travel Rule data in a format your system supports?
- Define your approach to unhosted wallets — transfers to or from wallets not associated with a VASP may require enhanced due diligence depending on jurisdiction
- Establish a process for onboarding new counterparties including due diligence checks and protocol compatibility testing
- Document your counterparty risk assessment criteria and review counterparty status regularly (at minimum annually)
Counterparty identification is an area where many new VASPs underinvest. Regulators increasingly expect documented due diligence on the VASPs you interact with.
Step 5: Select and integrate Travel Rule protocols
Travel Rule data must be transmitted using standardised protocols. You need to select, integrate, and test at least one.
- Evaluate available protocols: TRP (Travel Rule Protocol), TRISA, OpenVASP, and Sygna Bridge are the most widely adopted
- Consider multi-protocol support — your counterparties may use different protocols, and supporting multiple protocols maximises your counterparty reach
- Integrate your chosen protocol(s) with your transfer processing system so that Travel Rule screening occurs automatically, not as a manual step
- Test protocol connectivity with counterparty VASPs before going live — a protocol integration that has not been tested with real counterparties is not complete
- Implement fallback procedures for cases where protocol-based transmission fails (e.g., counterparty system downtime)
- Document your protocol selection rationale — auditors will ask why you chose your protocol(s) and how you assessed their reliability
Protocol selection is a technical decision with compliance implications. Choose based on counterparty coverage, reliability, and regulatory acceptance in your jurisdictions.
Step 6: Write and encode your SOPs
Standard Operating Procedures are the backbone of your compliance programme. They document how your team handles Travel Rule requirements day-to-day.
- Document your transfer screening process step by step: how transfers are flagged, who reviews them, what information is checked, and how decisions are recorded
- Define escalation procedures for transfers that cannot be processed automatically (e.g., incomplete counterparty data, flagged jurisdictions, transfers above enhanced due diligence thresholds)
- Specify roles and responsibilities — who owns Travel Rule compliance? Who reviews flagged transfers? Who approves exceptions?
- Include decision trees for common scenarios: transfers below threshold, transfers above threshold, transfers to unhosted wallets, transfers involving high-risk jurisdictions
- Set response time requirements — how quickly must Travel Rule data be transmitted? Most jurisdictions require transmission before or at the time of the transfer
- Plan for SOP reviews — schedule regular reviews (at minimum quarterly) to ensure SOPs reflect current regulations and actual practice
- Encode SOPs where possible — SOPs that exist only as documents are prone to drift from actual practice. Where you can, build your SOP logic into your compliance systems
The gap between documented SOPs and actual practice is one of the most common audit findings. Write SOPs that reflect reality, not aspiration.
Step 7: Test your compliance system
Before processing live transfers, test your entire compliance workflow end to end.
- Run test transfers through every scenario in your decision trees: below threshold, above threshold, known counterparty, unknown counterparty, unhosted wallet, multiple jurisdictions
- Verify data completeness — confirm that every required field is populated and transmitted correctly for each jurisdiction
- Test protocol connectivity with your actual counterparty VASPs, not just in a sandbox environment
- Simulate failure scenarios — what happens when a counterparty system is down? When data is incomplete? When a transfer triggers multiple jurisdiction rules?
- Review audit trail output — confirm that every screening decision, flag, and action is logged with timestamps, user identifiers, and decision rationale
- Conduct a mock audit — walk through your compliance programme as an auditor would, checking records, SOPs, training logs, and transfer samples
- Document test results and remediate any gaps before going live
Testing is not a one-time exercise. Schedule regular compliance tests (at minimum semi-annually) after go-live.
Step 8: Train your team
Your compliance programme is only as strong as the people operating it.
- Train all relevant staff on Travel Rule requirements, your SOPs, and the compliance tools they will use
- Provide jurisdiction-specific training for staff handling transfers in jurisdictions with unique requirements
- Include practical exercises — have staff process sample transfers and identify compliance issues
- Document all training including dates, attendees, topics covered, and assessment results
- Schedule refresher training at regular intervals and whenever SOPs or regulations change
- Ensure senior management understands Travel Rule requirements and their oversight responsibilities
Training records are a standard audit check. If you cannot demonstrate that your staff were trained, regulators will question whether your programme is effective.
Step 9: Go live with monitoring in place
When you begin processing live transfers, active monitoring is essential.
- Monitor compliance rates in real time — what percentage of qualifying transfers are being screened and transmitted correctly?
- Track flagged transfers and resolution times — are flagged transfers being resolved promptly or building up in a queue?
- Review exception reports daily during the first weeks of operation, then at a frequency that matches your transfer volume
- Set up automated alerts for compliance failures: missed screenings, incomplete data transmissions, protocol errors
- Establish a reporting cadence for compliance metrics — weekly for the first quarter, then monthly
- Have a clear process for handling compliance failures discovered post-transfer, including retrospective screening and filing of suspicious transfer reports if required
The first 90 days of live operation are critical. Most compliance gaps surface in this period, and addressing them quickly demonstrates regulatory good faith.
Step 10: Build ongoing compliance operations
Travel Rule compliance is not a project with a completion date. It is an ongoing operational requirement.
- Conduct regular internal audits of your Travel Rule programme (at minimum quarterly)
- Monitor regulatory changes across all jurisdictions you operate in — thresholds, data requirements, and protocol mandates change regularly
- Update SOPs whenever regulations change or internal processes evolve
- Review and update your counterparty database at least annually
- Maintain your compliance technology — protocol updates, system patches, and performance optimisation are ongoing requirements
- Prepare for external audits by maintaining organised, accessible records at all times
- Report compliance metrics to the board at regular intervals — regulatory scrutiny increasingly extends to board-level oversight
The VASPs that maintain strong compliance programmes treat it as a core operational function, not a box-ticking exercise.
Common mistakes new VASPs make
Based on patterns from regulatory enforcement actions and audit findings, here are the mistakes to avoid:
- Applying a single threshold globally instead of jurisdiction-specific thresholds
- Collecting originator data but not transmitting it to the counterparty VASP
- Treating Travel Rule compliance as a batch process instead of real-time screening
- Writing SOPs that do not reflect actual practice — the document says one thing, the team does another
- Neglecting counterparty due diligence — knowing your customer is not enough; you must also know your counterparty
- Failing to test before go-live — assumptions about system behaviour do not survive contact with real transfers
- Not monitoring after go-live — compliance gaps that go undetected become audit findings
Getting started
Building a Travel Rule compliance programme from scratch is a significant undertaking, but it is not optional. Every step in this checklist addresses a specific regulatory requirement that auditors will assess.
The VASPs that succeed are the ones that build compliance into their operations from day one rather than retrofitting it after a regulatory finding.
Cogentic provides Travel Rule compliance infrastructure for VASPs, covering 45+ jurisdictions with automated screening, counterparty identification, SOP mapping, and audit-ready reporting. If you are building your compliance programme and want to see how automation can accelerate the process, book a demo to speak with our team.