
Travel Rule Switzerland: data, thresholds and the unhosted-wallet duty
What the FATF travel rule requires
The FATF travel rule requires a VASP to collect identifying information on the originator and the beneficiary of every virtual-asset transfer and pass that data to the counterparty institution alongside the transaction, mirroring the wire-transfer obligation that already applied to banks.
The originator side means the sending VASP holds the name and account reference of its client and forwards it. The beneficiary side means the receiving VASP captures the same for the recipient and retains it. The requirement is symmetric: both institutions in the chain carry duties, and neither can simply process the movement of value without attaching the identifying data. The FATF's stated purpose is to prevent anonymous flows through the crypto system and to give financial intelligence units the traceability they have long had for bank wires.
For Swiss purposes, a VASP is not a formal legal category but a shorthand for the activity described in detail in our guide to what is a VASP. The substantive obligation falls on anyone who qualifies as a financial intermediary under the Anti-Money Laundering Act (AMLA, SR 955.0) by reason of exchanging, transferring or holding virtual assets commercially. The travel rule is one layer of that broader AML framework, sitting alongside client identification, beneficial-ownership establishment and transaction monitoring.
Switzerland's threshold: art. 51a AMLO-FINMA
Art. 51a of the FINMA Anti-Money Laundering Ordinance (AMLO-FINMA) is the provision that sets the Swiss identification threshold for virtual-asset transfers at CHF 1,000, as of July 2026. That figure entered into force on 1 January 2021 and was a deliberate reduction from the CHF 5,000 level that had applied before, reflecting FINMA's view that crypto carries a higher inherent money-laundering risk than ordinary cash-like instruments.
At or above CHF 1,000, a Swiss VASP must do three things. First, it must identify the contracting party on its own side, ensuring the client is known and the relationship is documented. Second, it must collect originator and beneficiary data and forward it to the counterparty institution with the transfer. Third, it must retain records in a form that can be retrieved on supervisory demand. These are concurrent obligations, not a sequence the provider can pick and choose from.
The comparison with the FATF's own guidance is instructive. The international baseline references a USD / EUR 1,000 equivalent, but the FATF framing is a guideline and leaves room for national discretion. Switzerland exercised that discretion by anchoring the threshold in CHF and choosing a level that, given exchange rates, sits in the same range as the international figure but reflects the local currency. More importantly, Switzerland added obligations that the FATF baseline does not itself impose, most visibly the unhosted-wallet verification described below.
For a custodial business, the CHF 1,000 threshold is somewhat academic: a firm that holds client assets runs full onboarding from the moment a relationship starts, regardless of initial transaction size. The threshold bites most sharply on occasional, non-custodial or exchange-only activity where a one-off conversion can cross the line and trigger data-forwarding obligations the operator must be technically ready to meet.
Data that must travel with a transfer
The core of the travel rule is the data set that must move alongside the transaction. The table below sets out the Swiss requirements against the FATF baseline, drawn from FINMA's published supervisory materials (as of July 2026).
| Requirement | Switzerland | FATF baseline |
|---|---|---|
| Identification threshold | CHF 1,000 (Art. 51a AMLO-FINMA, from 1 Jan 2021) | USD/EUR 1,000 guideline |
| Originator data | Name and account/wallet reference of sending client; forwarded to receiving VASP | Originator name and account number |
| Beneficiary data | Name and account/wallet reference of receiving client; retained by receiving VASP | Beneficiary name and account number |
| External-wallet control | Client must demonstrate ownership or power of disposal (FINMA Guidance 02/2019) | Not generally required |
| Beneficial ownership | Identify the natural person behind the client | Identify the natural person behind the client |
| Record retention | Mandatory; available on supervisory demand | Mandatory |
The rows where Switzerland diverges from the baseline are the identification threshold (set in CHF rather than as a soft guideline) and, most significantly, the external-wallet control requirement. Every other element reflects the FATF standard. Where the table says "name and account/wallet reference," that is the FATF-standard minimum for wire-transfer-equivalent data applied to virtual assets; the FINMA framework expects at least this, with enhanced detail where the risk profile of the transfer or the client warrants it.
The unhosted-wallet duty under FINMA Guidance 02/2019
FINMA Guidance 02/2019 requires a Swiss VASP to verify that its client owns or controls any external wallet before sending assets to or accepting assets from that address, a step the FATF baseline does not impose. An unhosted wallet is any wallet not held with the VASP itself: a hardware wallet, a software wallet under the client's own control, or a wallet held with a third-party custodian not involved in the current transfer.
The verification requirement is technical in nature. FINMA accepts proof methods that reliably establish private-key control. Two approaches appear in the supervisory discussion and are referenced in the firm's materials on VASP AML Travel Rule. One is a small test transaction sent from the external wallet to an address the VASP controls, proving the client can initiate a transaction from that wallet. The other is a cryptographic signed message from the wallet's private key, demonstrating control without moving any value. Either method creates a verifiable audit trail that satisfies the supervisory requirement.
The rationale is straightforward: without this duty, a VASP could receive crypto from an unknown external source or send to an arbitrary address without knowing whether its client has any connection to the wallet at the other end. In FINMA's view, that gap is exactly the kind of anonymous channel the travel rule exists to close. The guidance does not provide a blanket risk-based opt-out for established clients or well-known addresses. The verification must happen.
Operationally, this is the element that requires the most attention at product design stage. The verification flow has to be embedded in the user interface at the point where a client adds or confirms an external withdrawal address. Teams that design a custody or exchange product for another jurisdiction and then try to add the verification step after the fact typically find it requires significant product re-engineering. Building for the Swiss rule from the outset is simpler than retrofitting it after an SRO audit raises the finding.
Handling counterparty VASPs and data exchange across borders
A Swiss VASP must collect and forward originator and beneficiary data on every qualifying transfer regardless of where the counterparty institution is located, and cannot rely on the absence of compatible Travel Rule infrastructure on the other side to skip that obligation. Most transfers involve a counterparty institution, sometimes a fellow Swiss firm, often one based in another jurisdiction. The data exchange the travel rule requires depends on both parties having the technical means to send and receive it, and supervisory requirements have not been adopted at the same pace across every jurisdiction.
Switzerland's position is clear: the CHF 1,000 duty and the data-forwarding obligation apply to the Swiss provider regardless of where the counterparty is. A Swiss VASP cannot invoke the absence of a compatible system on the other side as grounds to simply skip the data collection and forwarding steps. Where the counterparty does not yet have Travel Rule infrastructure, general risk-based AML principles require the Swiss firm to assess whether to proceed, hold or decline the transfer and to document that assessment; the absence of compatible infrastructure on the other side does not remove that obligation.
In practice, this means the compliance and product teams must maintain a view of which counterparty VASPs have Travel Rule capability, what protocol they support, and what the firm's policy is for transfers to those that do not. That policy needs to be written, risk-based and auditable, because it is the kind of operational question an SRO auditor or FINMA examiner will ask when reviewing the Travel Rule implementation. The Swiss AML obligations that apply to all financial intermediaries include the record-keeping and governance structure that backs this up.
When the travel rule does not apply
The travel rule's data-forwarding duty under Art. 51a AMLO-FINMA does not apply below the CHF 1,000 threshold for occasional transactions, to transfers between accounts at the same institution, or to activity that does not amount to financial intermediation under AMLA. Knowing where those limits sit is as important as knowing the obligations, because operating outside the perimeter does not trigger the same requirements.
Transfers below CHF 1,000 (occasional transactions). Art. 51a AMLO-FINMA ties the full data-forwarding duty to transfers at or above CHF 1,000 for occasional transactions. A transfer of CHF 800 in a non-custodial context does not trigger the same requirement. The caveat is that any custodial business runs full onboarding from the first transaction regardless of amount, so the threshold matters mainly at the non-custodial, exchange or occasional-use end of the product spectrum.
Activity that is not a business service. The FATF framework and Switzerland's AMLA both target activity carried on commercially for or on behalf of third parties. An individual who transfers their own crypto between wallets they control, without acting as a business or providing services to others, is not a VASP and does not carry travel rule duties. The rule follows the intermediary, not the asset itself.
Transfers between accounts at the same institution. Where both the originator and beneficiary hold accounts at the same VASP, the institution has already identified both parties and the inter-account movement does not require the same external data-forwarding step. The identification and record-keeping obligations still apply, but the data does not need to travel to a counterparty because there is none.
Activity that does not qualify as financial intermediation. Some crypto-adjacent activities, depending on how they are structured, do not amount to financial intermediation under AMLA. In those cases, the AML framework, including the travel rule, does not apply in the same way. Whether a specific model falls inside or outside that boundary is a subordination question that requires a concrete analysis of what the business actually does, for whom, and on whose balance sheet the assets sit. Assumptions in either direction carry risk.
The compliance flow a Swiss VASP implements
Assembling the travel rule into a working compliance system means connecting several distinct components: the onboarding and KYC process that identifies clients at or before the CHF 1,000 threshold; the data collection layer that captures originator and beneficiary information for each transfer; the forwarding mechanism that passes the data to the counterparty VASP in a usable format; and the external-wallet verification flow that runs before any unhosted withdrawal address is added or confirmed.
The verification step is the most product-sensitive. It must sit in the user interface at the moment the client wants to use an external wallet address, not as a back-office check after the fact. When the client adds a new withdrawal address, the system requests the proof of control, captures the result, records it with a timestamp, and ties it to the client record. Only then does the address become available for use. If the proof of control cannot be obtained, the address is not approved and the transfer does not proceed. That sequencing is the operational expression of what FINMA Guidance 02/2019 requires.
Alongside the verification, the firm needs a policy for counterparty VASP data exchange, a monitoring system that watches for Travel Rule failures or incomplete data in incoming transfers, and an escalation path that connects anomalies to the compliance officer and, where warranted, to the Money Laundering Reporting Office Switzerland under Art. 9 AMLA. The travel rule does not operate in isolation from the rest of the AML framework; it feeds into the transaction-monitoring alerts and the broader suspicious-activity assessment.
In our advisory work, we structure this as an integrated compliance flow rather than a series of separate policies. The threshold, the data fields, the wallet verification and the counterparty protocol are all designed as a single system, aligned with the SRO or FINMA supervision the business operates under. For firms building for Switzerland from the outset, getting the design right before onboarding the first client is materially cheaper than correcting it after the first audit cycle. The full scope of what the framework involves, and how we build it, is set out in our VASP AML Travel Rule.
Key figures at a glance
- CHF 1,000: travel rule identification threshold (Art. 51a AMLO-FINMA, in force 1 January 2021).
- CHF 5,000: the previous threshold, applicable before 1 January 2021.
- FINMA Guidance 02/2019: source of the unhosted-wallet verification duty.
- Art. 9 AMLA: the reporting obligation to MROS for suspicious activity.
- AMLA SR 955.0: the parent statute classifying crypto businesses as financial intermediaries.
Frequently asked questions.
01What is the FATF travel rule for crypto?
02What is the travel rule threshold in Switzerland?
03Which statute implements the travel rule in Switzerland?
04What data must travel with a crypto transfer in Switzerland?
05What is the unhosted-wallet verification requirement in Switzerland?
06When did the CHF 1,000 travel rule threshold enter into force?
07How does the travel rule work when the receiving VASP is abroad?
08Does the travel rule apply below CHF 1,000?
09Can a signed message satisfy the unhosted-wallet verification?
10What is FINMA Guidance 02/2019?
Read more in our knowledge base.


MiCA vs Switzerland

Token classification
Discuss your matter.
A thirty-minute confidential conversation, in any of our five working languages. No fee, no obligation, no boilerplate.