Crypto, Blockchain & MiCA

Travel Rule Switzerland: data, thresholds and the unhosted-wallet duty

The travel rule in Switzerland requires that identifying information on the originator and beneficiary accompanies every virtual-asset transfer at or above CHF 1,000, the threshold fixed by Art. 51a of the FINMA Anti-Money Laundering Ordinance (AMLO-FINMA), which entered into force on 1 January 2021. Switzerland goes further than the FATF baseline: FINMA Guidance 02/2019 adds an unhosted-wallet verification duty, requiring a VASP to confirm that its client controls any external address before sending to or receiving from it. The rule carries no exemption for self-custodied wallets and binds all Swiss financial intermediaries in the virtual-asset space.

What the FATF travel rule requires

The FATF travel rule requires a VASP to collect identifying information on the originator and the beneficiary of every virtual-asset transfer and pass that data to the counterparty institution alongside the transaction, mirroring the wire-transfer obligation that already applied to banks.

The originator side means the sending VASP holds the name and account reference of its client and forwards it. The beneficiary side means the receiving VASP captures the same for the recipient and retains it. The requirement is symmetric: both institutions in the chain carry duties, and neither can simply process the movement of value without attaching the identifying data. The FATF's stated purpose is to prevent anonymous flows through the crypto system and to give financial intelligence units the traceability they have long had for bank wires.

For Swiss purposes, a VASP is not a formal legal category but a shorthand for the activity described in detail in our guide to what is a VASP. The substantive obligation falls on anyone who qualifies as a financial intermediary under the Anti-Money Laundering Act (AMLA, SR 955.0) by reason of exchanging, transferring or holding virtual assets commercially. The travel rule is one layer of that broader AML framework, sitting alongside client identification, beneficial-ownership establishment and transaction monitoring.

Switzerland's threshold: art. 51a AMLO-FINMA

Art. 51a of the FINMA Anti-Money Laundering Ordinance (AMLO-FINMA) is the provision that sets the Swiss identification threshold for virtual-asset transfers at CHF 1,000, as of July 2026. That figure entered into force on 1 January 2021 and was a deliberate reduction from the CHF 5,000 level that had applied before, reflecting FINMA's view that crypto carries a higher inherent money-laundering risk than ordinary cash-like instruments.

At or above CHF 1,000, a Swiss VASP must do three things. First, it must identify the contracting party on its own side, ensuring the client is known and the relationship is documented. Second, it must collect originator and beneficiary data and forward it to the counterparty institution with the transfer. Third, it must retain records in a form that can be retrieved on supervisory demand. These are concurrent obligations, not a sequence the provider can pick and choose from.

The comparison with the FATF's own guidance is instructive. The international baseline references a USD / EUR 1,000 equivalent, but the FATF framing is a guideline and leaves room for national discretion. Switzerland exercised that discretion by anchoring the threshold in CHF and choosing a level that, given exchange rates, sits in the same range as the international figure but reflects the local currency. More importantly, Switzerland added obligations that the FATF baseline does not itself impose, most visibly the unhosted-wallet verification described below.

For a custodial business, the CHF 1,000 threshold is somewhat academic: a firm that holds client assets runs full onboarding from the moment a relationship starts, regardless of initial transaction size. The threshold bites most sharply on occasional, non-custodial or exchange-only activity where a one-off conversion can cross the line and trigger data-forwarding obligations the operator must be technically ready to meet.

Data that must travel with a transfer

The core of the travel rule is the data set that must move alongside the transaction. The table below sets out the Swiss requirements against the FATF baseline, drawn from FINMA's published supervisory materials (as of July 2026).

Swiss VASP travel rule requirements versus the FATF baseline, as of July 2026.
Requirement Switzerland FATF baseline
Identification threshold CHF 1,000 (Art. 51a AMLO-FINMA, from 1 Jan 2021) USD/EUR 1,000 guideline
Originator data Name and account/wallet reference of sending client; forwarded to receiving VASP Originator name and account number
Beneficiary data Name and account/wallet reference of receiving client; retained by receiving VASP Beneficiary name and account number
External-wallet control Client must demonstrate ownership or power of disposal (FINMA Guidance 02/2019) Not generally required
Beneficial ownership Identify the natural person behind the client Identify the natural person behind the client
Record retention Mandatory; available on supervisory demand Mandatory

The rows where Switzerland diverges from the baseline are the identification threshold (set in CHF rather than as a soft guideline) and, most significantly, the external-wallet control requirement. Every other element reflects the FATF standard. Where the table says "name and account/wallet reference," that is the FATF-standard minimum for wire-transfer-equivalent data applied to virtual assets; the FINMA framework expects at least this, with enhanced detail where the risk profile of the transfer or the client warrants it.

The unhosted-wallet duty under FINMA Guidance 02/2019

FINMA Guidance 02/2019 requires a Swiss VASP to verify that its client owns or controls any external wallet before sending assets to or accepting assets from that address, a step the FATF baseline does not impose. An unhosted wallet is any wallet not held with the VASP itself: a hardware wallet, a software wallet under the client's own control, or a wallet held with a third-party custodian not involved in the current transfer.

The verification requirement is technical in nature. FINMA accepts proof methods that reliably establish private-key control. Two approaches appear in the supervisory discussion and are referenced in the firm's materials on VASP AML Travel Rule. One is a small test transaction sent from the external wallet to an address the VASP controls, proving the client can initiate a transaction from that wallet. The other is a cryptographic signed message from the wallet's private key, demonstrating control without moving any value. Either method creates a verifiable audit trail that satisfies the supervisory requirement.

The rationale is straightforward: without this duty, a VASP could receive crypto from an unknown external source or send to an arbitrary address without knowing whether its client has any connection to the wallet at the other end. In FINMA's view, that gap is exactly the kind of anonymous channel the travel rule exists to close. The guidance does not provide a blanket risk-based opt-out for established clients or well-known addresses. The verification must happen.

Operationally, this is the element that requires the most attention at product design stage. The verification flow has to be embedded in the user interface at the point where a client adds or confirms an external withdrawal address. Teams that design a custody or exchange product for another jurisdiction and then try to add the verification step after the fact typically find it requires significant product re-engineering. Building for the Swiss rule from the outset is simpler than retrofitting it after an SRO audit raises the finding.

Handling counterparty VASPs and data exchange across borders

A Swiss VASP must collect and forward originator and beneficiary data on every qualifying transfer regardless of where the counterparty institution is located, and cannot rely on the absence of compatible Travel Rule infrastructure on the other side to skip that obligation. Most transfers involve a counterparty institution, sometimes a fellow Swiss firm, often one based in another jurisdiction. The data exchange the travel rule requires depends on both parties having the technical means to send and receive it, and supervisory requirements have not been adopted at the same pace across every jurisdiction.

Switzerland's position is clear: the CHF 1,000 duty and the data-forwarding obligation apply to the Swiss provider regardless of where the counterparty is. A Swiss VASP cannot invoke the absence of a compatible system on the other side as grounds to simply skip the data collection and forwarding steps. Where the counterparty does not yet have Travel Rule infrastructure, general risk-based AML principles require the Swiss firm to assess whether to proceed, hold or decline the transfer and to document that assessment; the absence of compatible infrastructure on the other side does not remove that obligation.

In practice, this means the compliance and product teams must maintain a view of which counterparty VASPs have Travel Rule capability, what protocol they support, and what the firm's policy is for transfers to those that do not. That policy needs to be written, risk-based and auditable, because it is the kind of operational question an SRO auditor or FINMA examiner will ask when reviewing the Travel Rule implementation. The Swiss AML obligations that apply to all financial intermediaries include the record-keeping and governance structure that backs this up.

When the travel rule does not apply

The travel rule's data-forwarding duty under Art. 51a AMLO-FINMA does not apply below the CHF 1,000 threshold for occasional transactions, to transfers between accounts at the same institution, or to activity that does not amount to financial intermediation under AMLA. Knowing where those limits sit is as important as knowing the obligations, because operating outside the perimeter does not trigger the same requirements.

Transfers below CHF 1,000 (occasional transactions). Art. 51a AMLO-FINMA ties the full data-forwarding duty to transfers at or above CHF 1,000 for occasional transactions. A transfer of CHF 800 in a non-custodial context does not trigger the same requirement. The caveat is that any custodial business runs full onboarding from the first transaction regardless of amount, so the threshold matters mainly at the non-custodial, exchange or occasional-use end of the product spectrum.

Activity that is not a business service. The FATF framework and Switzerland's AMLA both target activity carried on commercially for or on behalf of third parties. An individual who transfers their own crypto between wallets they control, without acting as a business or providing services to others, is not a VASP and does not carry travel rule duties. The rule follows the intermediary, not the asset itself.

Transfers between accounts at the same institution. Where both the originator and beneficiary hold accounts at the same VASP, the institution has already identified both parties and the inter-account movement does not require the same external data-forwarding step. The identification and record-keeping obligations still apply, but the data does not need to travel to a counterparty because there is none.

Activity that does not qualify as financial intermediation. Some crypto-adjacent activities, depending on how they are structured, do not amount to financial intermediation under AMLA. In those cases, the AML framework, including the travel rule, does not apply in the same way. Whether a specific model falls inside or outside that boundary is a subordination question that requires a concrete analysis of what the business actually does, for whom, and on whose balance sheet the assets sit. Assumptions in either direction carry risk.

The compliance flow a Swiss VASP implements

Assembling the travel rule into a working compliance system means connecting several distinct components: the onboarding and KYC process that identifies clients at or before the CHF 1,000 threshold; the data collection layer that captures originator and beneficiary information for each transfer; the forwarding mechanism that passes the data to the counterparty VASP in a usable format; and the external-wallet verification flow that runs before any unhosted withdrawal address is added or confirmed.

The verification step is the most product-sensitive. It must sit in the user interface at the moment the client wants to use an external wallet address, not as a back-office check after the fact. When the client adds a new withdrawal address, the system requests the proof of control, captures the result, records it with a timestamp, and ties it to the client record. Only then does the address become available for use. If the proof of control cannot be obtained, the address is not approved and the transfer does not proceed. That sequencing is the operational expression of what FINMA Guidance 02/2019 requires.

Alongside the verification, the firm needs a policy for counterparty VASP data exchange, a monitoring system that watches for Travel Rule failures or incomplete data in incoming transfers, and an escalation path that connects anomalies to the compliance officer and, where warranted, to the Money Laundering Reporting Office Switzerland under Art. 9 AMLA. The travel rule does not operate in isolation from the rest of the AML framework; it feeds into the transaction-monitoring alerts and the broader suspicious-activity assessment.

In our advisory work, we structure this as an integrated compliance flow rather than a series of separate policies. The threshold, the data fields, the wallet verification and the counterparty protocol are all designed as a single system, aligned with the SRO or FINMA supervision the business operates under. For firms building for Switzerland from the outset, getting the design right before onboarding the first client is materially cheaper than correcting it after the first audit cycle. The full scope of what the framework involves, and how we build it, is set out in our VASP AML Travel Rule.

Key figures at a glance

  • CHF 1,000: travel rule identification threshold (Art. 51a AMLO-FINMA, in force 1 January 2021).
  • CHF 5,000: the previous threshold, applicable before 1 January 2021.
  • FINMA Guidance 02/2019: source of the unhosted-wallet verification duty.
  • Art. 9 AMLA: the reporting obligation to MROS for suspicious activity.
  • AMLA SR 955.0: the parent statute classifying crypto businesses as financial intermediaries.
FAQ

Frequently asked questions.

01What is the FATF travel rule for crypto?
The FATF travel rule requires that identifying information on both the originator and the beneficiary of a virtual-asset transfer accompanies the transaction, in the same way it does for a wire transfer. It was introduced through FATF Recommendation 15 and applies to virtual asset service providers. The rule is designed to prevent anonymous movement of value through the crypto system and to make the chain of transfers traceable by supervisors and law enforcement.
02What is the travel rule threshold in Switzerland?
Switzerland sets the identification threshold for crypto at CHF 1,000 under Art. 51a AMLO-FINMA. This came into force on 1 January 2021, reduced from the earlier CHF 5,000. Any virtual-asset transfer at or above that value requires the sending VASP to collect and forward originator and beneficiary data. The threshold is deliberately lower than the general threshold for other cash-like dealings, reflecting FINMA's view of the heightened money-laundering risk in crypto transfers.
03Which statute implements the travel rule in Switzerland?
Art. 51a of the Anti-Money Laundering Ordinance of FINMA (AMLO-FINMA) is the implementing provision, setting the CHF 1,000 identification threshold for crypto from 1 January 2021. The parent statute is the Anti-Money Laundering Act (AMLA, SR 955.0), which classifies most crypto businesses as financial intermediaries. FINMA Guidance 02/2019 adds the external-wallet verification layer on top of the statutory base.
04What data must travel with a crypto transfer in Switzerland?
Originator and beneficiary information must accompany the transfer. The sending VASP forwards its client's identifying data to the receiving institution, and the receiving VASP does the same in reverse. The categories follow the FATF standard applied to virtual-asset transfers: name and account or wallet reference at a minimum, with enhanced detail for higher-risk cases. For transfers involving unhosted wallets, FINMA Guidance 02/2019 adds a wallet-control verification before the transfer is processed.
05What is the unhosted-wallet verification requirement in Switzerland?
FINMA Guidance 02/2019 requires a Swiss VASP to verify that its client actually owns or controls an external (unhosted) wallet before transferring assets to or from it. A technical method is accepted, such as a small test transaction sent from the wallet to the VASP, or a cryptographic signed message proving private-key control. This duty goes beyond the FATF baseline and must be built into the product's user flow from the outset, not added after the SRO audit begins.
06When did the CHF 1,000 travel rule threshold enter into force?
Art. 51a AMLO-FINMA, which set the CHF 1,000 identification threshold for crypto, entered into force on 1 January 2021. It replaced the earlier CHF 5,000 level. The reduction reflects FINMA's assessment of the heightened money-laundering risk associated with virtual-asset transfers and leaves almost no room for unidentified activity in a custodial or transfer business.
07How does the travel rule work when the receiving VASP is abroad?
The Swiss VASP must attempt to collect and forward originator and beneficiary data regardless of where the counterparty institution is located. General risk-based AML principles require the Swiss provider to assess whether to proceed, hold or decline the transfer and to document that assessment; the absence of compatible infrastructure on the counterparty side does not remove that obligation.
08Does the travel rule apply below CHF 1,000?
For occasional transactions, the full data-forwarding duty does not apply to amounts below CHF 1,000. However, a custodial relationship triggers full client onboarding and ongoing monitoring from the first transaction, regardless of the amount, so the threshold is practically relevant mainly for spot or non-custodial activity. A business that holds assets for clients cannot rely on the threshold to avoid identification obligations across all its activity.
09Can a signed message satisfy the unhosted-wallet verification?
Yes. FINMA Guidance 02/2019 accepts technical proof methods that demonstrate client control over an external wallet. A cryptographic signed message proving private-key control is one accepted approach. A small test transaction sent from the wallet to the VASP is another. The method must reliably establish that the client has control over the address in question, not merely knowledge of it.
10What is FINMA Guidance 02/2019?
FINMA Guidance 02/2019 sets out FINMA's supervisory expectations for virtual-asset service providers on the Travel Rule and the handling of external wallet addresses. It requires Swiss VASPs to verify a client's ownership or power of disposal over an unhosted wallet before sending or receiving assets, a step most other jurisdictions do not impose. It is the source of the unhosted-wallet verification duty that makes Switzerland's Travel Rule stricter than the international baseline.
Knowledge base

Read more in our knowledge base.

Show all

Discuss your matter.

A thirty-minute confidential conversation, in any of our five working languages. No fee, no obligation, no boilerplate.

Book a Meeting Maria will contact you shortly Schedule