Hong Kong, Singapore, Dubai and Malaysia all regulate virtual-asset transfers, but they do not implement the VASP Travel Rule in the same way. A platform can finish licensing work and ship its product, yet still be unable to operate a compliant transfer corridor if its identity-data, counterparty and evidence controls are incomplete.

For a founder or regulated growth team, Travel Rule compliance in APAC therefore needs to be designed before the first customer transfer. It is part of the operating model, not a feature to add after launch.

We call our approach Structure Over Scale. Build the control model and evidence chain first, then add volume. This guide gives founders a four market comparison table and a rollout checklist.

Key takeaways

  • Travel Rule controls require regulated firms to obtain, hold and transmit specified originator and beneficiary information, with the exact field set and threshold determined by the applicable local rule.
  • Hong Kong requires immediate and secure submission before or when a transfer is conducted. HKD 8,000 is the full-information threshold, and unhosted-wallet ownership or control must be assessed on a risk-sensitive basis.
  • Singapore's MAS Notice PSN02 uses SGD 1,500 as the boundary: transfers at or below that amount carry a limited data set; transfers above it require fuller originator information.
  • VARA's rulebook specifies an AED 3,500 trigger and counterparty due diligence, while Malaysia's current SC guideline sets transfer data requirements without a de minimis threshold and requires seven-year record retention.
  • A configurable control plane can map KYC/KYB data to an interoperable payload, apply corridor rules and preserve the evidence behind each transfer decision.

What the VASP Travel Rule Actually Is (and Why Crypto Makes It Harder)

The Travel Rule began as a banking wire control. FATF Recommendation 16 asked banks to attach sender and receiver details to cross border payments so investigators could follow the money. In 2019 FATF extended that logic to virtual assets.

FATF Recommendation 16 in one paragraph

FATF Recommendation 16 requires a VASP making a covered transfer to obtain, hold and securely transmit specified originator and beneficiary information. FATF agreed revisions in June 2025, but countries are expected to implement the revised standard by the end of 2030. The revision adds the beneficiary's country and town, and allows the originator's year of birth as a fallback where the full date of birth is unavailable; it should not be presented as an already-universal 2026 field set. Read FATF's Recommendation 16 explanatory note and Virtual Assets standards page.

What data must travel: originator and beneficiary fields plus IVMS101

A covered transfer carries originator and beneficiary identity data. The exact fields depend on the local rule and the transfer amount, but commonly include names, account or transaction references and, for the originator, an address, official identifier or birth information. IVMS101 is an industry messaging data standard that helps counterparties exchange this information in a consistent structure.

Crypto makes this harder. Transfers settle on chain in seconds and cannot be reversed, so checks finish before broadcast. Wallets are pseudo anonymous, so proving control of a destination is hard. The two ends are often different companies in different countries under different regulators.

The threshold myth

Many founders assume there is one global line, usually USD/EUR 1,000, below which no information is required. FATF allows countries to adopt a de minimis threshold at that level, subject to a limited data set, but local implementation controls the actual obligation. Singapore draws the boundary at SGD 1,500; Hong Kong uses HKD 8,000 for the fuller data set; VARA specifies AED 3,500; and Malaysia's current SC guideline does not state a de minimis threshold in its digital-asset transfer provisions. A multi-market engine therefore needs corridor-specific rules rather than one global switch.

The 4 Obligations on Every Qualifying Transfer

Across the four regimes reviewed here, implementation can be organised into four control areas. We group them under our Evidence before expansion framework: do not add volume until each control is provable on demand. Each one builds on the cross-border KYC/KYB due diligence you already run at onboarding.

1. Data obligation. Collect the required originator and beneficiary fields and keep them accurate. This is where most launches stall, because the data lives in your KYC/KYB system, not in your transfer engine.

2. Screening obligation. Screen every party against sanctions, PEP, and adverse media lists. High risk transfers need enhanced review before they move. Teams that want manageable alert volume without missing real risk often pair this step with AML alert triage and noise reduction, so investigators see the cases that matter.

3. Pre-transaction obligation. In several markets you must finish Travel Rule checks before broadcasting, because blockchain finality means you cannot recall it. Hong Kong makes this explicit: the ordering VASP submits required information immediately and securely, before or at the moment of transfer.

4. Record-keeping obligation. Store the transfer record, the data exchanged and the decisions made in a form a regulator can inspect. Malaysia's SC guideline, for example, requires relevant records to be retained for at least seven years.

A founder who can show these four obligations as connected, timestamped evidence has the foundation for an audit ready operation.

APAC at a Glance: Travel Rule by Market

This table is the fastest way to see how the four markets diverge. Keep it open while you read the per market sections below.

MarketPrimary sourceInformation triggerLower-value treatmentUnhosted / self-hosted approachCounterparty due diligenceOperational note
FATF referenceRecommendation 16Countries may permit USD/EUR 1,000 de minimisLimited required data still appliesLocal implementation controlsRisk-based treatment under applicable rulesReference standard, not a single global threshold
Hong KongSFC AML/CFT Guideline, Chapter 12Full information at HKD 8,000 or aboveLimited required fields below HKD 8,000Take reasonable measures to ascertain ownership or control on a risk-sensitive basisDue diligence before relying on a counterparty institutionImmediate submission applies from 1 Jan 2024
SingaporeMAS Notice PSN02, paragraph 13Full information above SGD 1,500Names and account / unique transaction references at SGD 1,500 or belowApply risk-based mitigation under MAS guidanceIdentify and assess the counterparty institutionMatch the exact PSN02 amount boundary in code
DubaiVARA Compliance and Risk Management Rulebook, Section GObtain and hold specified information above AED 3,500; transmission follows applicable Federal AML-CFT lawCheck current Federal requirements for the transfer typeAddress risks arising from unhosted walletsRisk-based due diligence before transactingConfirm both current VARA and Federal requirements
MalaysiaSC Guidelines on Prevention of Money Laundering and Terrorism FinancingCurrent digital-asset transfer provisions state the full data requirements without a de minimis thresholdNo separate lower-value field tier statedNo dedicated self-hosted-wallet section in the current guidelineIdentify and conduct due diligence on the counterparty VASPRetain relevant records for at least 7 years

The comparison is operationally important because the amount boundary, field set and unhosted-wallet treatment vary. A VASP operating across these corridors should not hard-code one rule and assume it fits every market.

Hong Kong (SFC) Travel Rule: Immediate Submission Since 1 Jan 2024

Hong Kong enforced the crypto Travel Rule early through the Anti Money Laundering and Counter Terrorist Financing Ordinance (AMLO, Cap. 615). Licensed platforms must comply with section 13A of Schedule 2 to the AMLO, which applies FATF R.16 to virtual asset transfers. Guidance sits in Chapter 12 of the SFC's AML/CFT Guideline (see the SFC VATP licensing page).

Licensing scope

A centralised virtual-asset trading platform that carries on business in Hong Kong, or actively markets its services to Hong Kong investors, falls within the SFC licensing regime. Scope should be assessed against the business model and marketing activity rather than reduced to the claim that every overseas VASP serving any Hong Kong customer needs the same licence.

Threshold HKD 8,000

Transfers at or above HKD 8,000 (roughly USD 1,000) require the full field set. Below that line, a limited set applies, but basic identity still travels.

Pre-transaction obligation and unhosted wallet ownership verification

Hong Kong requires the ordering institution to submit required information to the beneficiary institution immediately and securely, before or when the transfer is conducted. For an unhosted wallet, the platform must take reasonable measures to ascertain ownership or control on a risk-sensitive basis. The SFC notes that a customer's declaration alone is insufficient and gives measures such as a micropayment test or message signing as examples.

What the SFC looks at

Examiners pull a few sampled transfers and ask for the trail. If the log doesn't close, the policy on paper won't save you.

Illustrative control failure (composite). A newly licensed VASP has strong customer KYC but no enforceable method for assessing control of unhosted destination wallets. When a sample transfer is reviewed, the team can produce names and account references but no ownership or control evidence. The launch has to pause while the check and its audit log are added. This is a composite operating scenario, not a report of a specific SFC enforcement case.

Singapore (MAS) Travel Rule: SGD 1,500 and the Guiding Factors

Singapore implemented the Travel Rule through MAS Notice PSN02. The operative text is paragraph 13 of PSN02, effective 28 January 2020. One caution: PSN03 governs suspicious-activity and fraud reporting, not the Travel Rule. Do not cite it as your Travel Rule basis.

How paragraph 13 works

PSN02 applies to digital payment token value transfers. At SGD 1,500 or below, the ordering institution must include the originator's and beneficiary's names and the relevant account or unique transaction references. Above SGD 1,500, the fuller originator information applies, including an address and an official identifier or date and place of birth. The equality boundary matters: the wider tier begins above, not at, SGD 1,500.

Self-hosted wallet enhanced due diligence

MAS guidance expects a DPT provider to assess and mitigate the risks of transfers involving unhosted wallets or unregulated counterparties. The control should be risk-based and documented; describing enhanced due diligence as mandatory for every self-hosted transfer would overstate the rule.

The MAS Guiding Factors

MAS materials emphasise coverage, interoperability, counterparty due diligence and timely transmission when firms evaluate Travel Rule controls. Use these factors as a procurement and implementation checklist, and verify the operative requirements against MAS Notice PSN02 and its supporting guidelines.

Dubai (VARA) Travel Rule: Federal Baseline Plus Rulebook

Dubai built its virtual-asset regime on Law No. 4 of 2022, which created VARA. VARA's Compliance and Risk Management Rulebook addresses the FATF Travel Rule in Part III, Section G, alongside the Federal AML-CFT laws that govern the underlying information requirements.

AED 3,500 trigger and the Federal baseline

VARA requires VASPs, before transfers exceeding AED 3,500, to obtain and hold the specified originator and beneficiary information. The rulebook also requires compliance with applicable Federal AML-CFT laws, which control the detailed transmission obligations. Teams should therefore avoid coding the AED 3,500 figure as a complete exemption below that amount; the transaction type, suspicion indicators and current Federal requirements still need to be evaluated.

Counterparty VASP due diligence

Before transacting with a counterparty VASP, a Dubai VASP must conduct risk-based due diligence on that institution and assess the counterparty's ability to protect confidential information. This institution-level assessment is separate from wallet-owner checks and should be documented and refreshed on a risk-based cycle.

Unhosted wallets and documented decision paths

VARA requires VASPs to address the risks arising from transactions involving unhosted wallets and from the sunrise problem. The public rulebook does not prescribe one universal reject, delay or return sequence, so those states should be framed as an operator's documented control response rather than quoted as a regulator mandate. Review the current G. FATF Travel Rule section before go-live.

Malaysia (SC) Travel Rule: No De Minimis Tier Stated, 7-Year Retention

Malaysia regulates digital-asset exchange operators within the Securities Commission Malaysia (SC) framework. The SC's current AML/CFT guideline contains dedicated digital-asset transfer provisions covering both domestic and cross-border transfers.

No de minimis, full field set every time

The current SC guideline states the full originator and beneficiary data requirements without setting a de minimis threshold in that section. For the originator, this includes name, account or unique transaction reference, address and an official identifier or date and place of birth. Beneficiary data includes the name and account or unique transaction reference. The information must be submitted immediately and securely.

Address instead of place of birth

The SC rule permits alternative originator identifiers within the prescribed set, so the payload mapping should use the verified data actually collected by the Malaysian onboarding process. A team copying a Singapore or Hong Kong data model should test the Malaysian mapping rather than assume that every field is captured in the same way.

Self-hosted wallets: document the treatment

The current SC guideline does not set out a dedicated section for self-hosted wallets. That is not a reason to leave the risk untreated. A VASP should document how it identifies, screens, escalates and records non-custodial transfers, and confirm the position against current SC or Bank Negara Malaysia material before launch. The SC guideline also requires counterparty VASP identification and due diligence before information is transmitted. Review the current SC AML/CFT guideline.

Implementing the Travel Rule: Payload Mapping and Counterparty Confirmation

This is where the playbook turns operational. The four obligations are policy. Payload mapping and counterparty confirmation are engineering — and for most teams this is the hardest 20% of Travel Rule compliance APAC.

Mapping KYC/KYB fields to IVMS101

Most teams already hold the Travel Rule data in their KYC/KYB system. The gap is mapping those fields to IVMS101 originator and beneficiary structures. A frequent failure is storing a date of birth in a free text field that does not serialize, so the beneficiary VASP rejects the transfer. Define the mapping once and test it per market.

Founders who want to see a configurable mapping layer can review our Travel Rule API and the travel-rule configuration for APAC corridors we ship as part of the UWAY stack.

Payload structure and encryption

The payload carries personal data, so it should be protected in transit and kept off-chain. A transaction or account reference lets the beneficiary VASP link the identity data to the transfer. Protocols may use public-key infrastructure or transport-level encryption. Document the method, access controls and evidence retained, because an examiner may ask how personal data was protected and how the payload remained linked to the transaction. Our Travel Rule API reference explains the private-preview contract and current technical conventions.

Counterparty identification and confirmation

Before sending personal data to another VASP, identify the institution, assess its regulatory status and security posture where required, and record the result. This is the sunrise problem in miniature. A configured counterparty readiness workflow can support the review, but the regulated firm remains responsible for the decision. If the counterparty is identifiable but not yet Travel Rule ready, use a documented path rather than an indefinite transfer hold.

Illustrative sunrise scenario (composite). A Singapore DPT provider receives an outbound request to a genuine counterparty VASP whose Travel Rule endpoint is not answering confirmation requests. The provider's workflow holds the transfer, records the reason and routes the case for review instead of broadcasting without the required control. This is a composite implementation scenario, not a report of a specific MAS examination or enforcement case.

Handling unreachable or non compliant counterparties

Build four responses: repair, hold, reject, return. Repair means asking for missing data and retrying. Hold means pausing while you chase confirmation. Reject means refusing because the counterparty fails due diligence. Return means sending funds back when a transfer cannot be completed lawfully. Mapping these states to clear policies gives auditors a defensible log.

The Sunrise Problem and Self-Hosted / Cross-Chain Edge Cases

APAC's asynchronous adoption

The sunrise problem is the gap between markets, counterparties and technical networks that implement Travel Rule controls at different speeds. Your engine must handle that asymmetry without treating every cross-border flow as identical. The cross-border KYC/KYB coverage gaps guide explains how to structure the underlying customer evidence across markets.

Self-hosted wallet EDD playbook

For non-custodial destinations, screen the wallet, assess the customer's purpose and risk, and decide whether further ownership or control evidence is required. Hong Kong expressly requires reasonable measures to ascertain ownership or control on a risk-sensitive basis; Singapore and Dubai require risk treatment; the current Malaysian guideline has no dedicated self-hosted-wallet section. Apply the strictest applicable requirement across the corridor and document why the chosen control is proportionate.

Cross-chain attribution

When a transfer spans bridges or chains, attribution can break. The Travel Rule data references the transaction, but the on chain path may hop networks. Document how you trace a transfer across bridges and keep the payload linked to every leg.

Evidence, Audit and Audit-Ready: Tying Travel Rule to Your KYC/CDD Chain

What regulators want to see

Examiners want timestamped logs: when data was collected, sent, confirmed, and what decision was made. A Travel Rule log that doesn't link back to the customer's KYC file is a loose end. The name on the payload has to be the same name you verified at onboarding, or the examiner treats the transfer as unverified.

Linking Travel Rule records to cross-border KYC/KYB due diligence

The Travel Rule is one link in a longer chain. The identity you send should connect to the cross-border KYC/KYB due diligence you performed at onboarding. When a transfer flags, your investigator should open one case and see the KYC, the screening hit from your AML Sentinel alert triage layer, and the Travel Rule payload together. That connected view is what we mean by audit ready.

Structure Over Scale

Stand up the control model and evidence chain before you chase volume. A VASP that onboards at scale on a weak foundation multiplies its remediation burden. Establishing the controls first does not make an examination automatic, but it makes the evidence easier to retrieve, explain and defend.

A Practical APAC Travel Rule Rollout Checklist

Use this as your launch control sheet. Each box should close before the next stage.

Before you go live

  • Map your KYC/KYB fields to IVMS101 for all four markets.
  • Configure the amount logic precisely: full information at HKD 8,000 or above in Hong Kong; the fuller tier above SGD 1,500 in Singapore; VARA's above-AED 3,500 rule together with current Federal requirements; and the full Malaysian field set without a stated de minimis tier in the current SC guideline.
  • Define below threshold and above threshold field sets for each market.
  • Build risk-based unhosted-wallet logic, including ownership or control evidence where the applicable rule requires it.
  • Choose and document your encryption and transmission method.

Per market

  • Hong Kong: enforce immediate submission before or when the transfer is conducted; take reasonable, risk-sensitive measures to ascertain unhosted-wallet ownership or control.
  • Singapore: implement the PSN02 paragraph 13 field tiers with the correct equality boundary; document the risk treatment for unhosted wallets and counterparties.
  • Dubai: perform counterparty VASP due diligence; address unhosted-wallet and sunrise risks; validate current VARA and Federal requirements before launch.
  • Malaysia: implement the full field set without relying on a de minimis tier; perform counterparty VASP due diligence; retain relevant records for at least seven years; document the self-hosted-wallet policy.

Per transaction

  • Identify and confirm the counterparty VASP before sending data.
  • Attach the correct field subset for the amount and market.
  • Encrypt the payload and link it to the transaction reference.
  • Apply repair, hold, reject, or return logic when the counterparty is unreachable or non compliant.

For audit

  • Keep timestamped logs of collection, transmission, confirmation, and decisions.
  • Store records for the longest applicable period (7 years for Malaysia).
  • Be able to open one case linking KYC, screening, and Travel Rule payload.
  • Run a periodic test of counterparty confirmation and self-hosted paths.

Tools and a Configurator Approach

Build versus buy

You can build Travel Rule plumbing in house. The risk is each market changes its rule and your team becomes a permanent regulator watch desk. Adopting a configurable layer shifts maintenance to a vendor while you keep accountability. Either way, the licensed VASP remains responsible.

What an APAC Travel Rule Configurator should do

A purpose built configurator manages four jobs: store per corridor thresholds and field subsets; map KYC/KYB data to IVMS101 and validate; identify and confirm counterparties through a directory; apply repair, hold, reject, return consistently. Our Travel Rule Configurator is built around these four for the HK, SG, Dubai, and Malaysia corridors.

Where UWAY fits

UWAY runs three products as one compliance plane. Compliance Quality Analysis scores your KYC/KYB data. AML Sentinel triages alerts and cuts noise. Travel Rule Configurator turns the four obligations into configurable, auditable behaviour. Together they express our method: evidence before expansion, structure over scale, audit ready from the first customer.

FAQ

What is the Travel Rule for a VASP? The Travel Rule is the FATF Recommendation 16 framework under which a VASP obtains, holds and securely transmits specified originator and beneficiary information for a covered virtual-asset transfer. Each institution must perform the checks assigned to it under the applicable local rule; not every participant verifies every field in the same way.

How do I comply with the Travel Rule as a VASP? Organise the implementation around four control areas: collect the required identity data, screen the parties, complete checks before broadcast where required, and keep timestamped records. Use an interoperable data structure such as IVMS101, identify and assess the counterparty VASP, and map each market's amount boundary and field set.

What is the Travel Rule threshold for crypto? There is no single global threshold. FATF allows a USD/EUR 1,000 de minimis threshold with a limited data set, but local rules differ. Hong Kong uses HKD 8,000 for the full-information tier; Singapore's fuller tier starts above SGD 1,500; VARA specifies obligations above AED 3,500 together with applicable Federal law; and Malaysia's current SC guideline states the data requirements without a de minimis tier.

Hong Kong versus Singapore Travel Rule: what is the difference? Hong Kong requires immediate and secure submission before or when the transfer is conducted, with HKD 8,000 as the full-information threshold and risk-sensitive measures to ascertain unhosted-wallet ownership or control. Singapore PSN02 uses a limited field set at SGD 1,500 or below and fuller originator information above that amount, supported by risk-based treatment for unhosted wallets and counterparties.

Does the Travel Rule apply to self-hosted wallets? It depends on the market and transaction. Hong Kong requires reasonable measures to ascertain ownership or control on a risk-sensitive basis. Singapore and Dubai expect risks involving unhosted wallets to be assessed and mitigated. The current Malaysian SC guideline has no dedicated self-hosted-wallet section, so firms should document their treatment and check current regulatory material before launch.

Conclusion

The Travel Rule is an operating dependency that founders often underestimate. Across these four markets, amount rules, field sets and unhosted-wallet treatments differ. The common implementation task is to know which rule applies, map the KYC/KYB data, assess counterparties and retain a defensible record of each decision.

To review the configurator approach for your own corridors, review the Travel Rule Configurator and read the cross-border KYC/KYB due diligence guide that connects transfer controls to the wider onboarding evidence chain. Structure over scale is the operating sequence: establish the controls and evidence first, then add volume.

For a focused comparison of the two regimes behind many APAC transfer corridors, see the Hong Kong vs Singapore KYC/KYB compliance map.