Home  /  News  /  Compliance & AML
Compliance & AMLMay 17, 2026

The Travel Rule and Crypto Gambling: What Regulators Expect

Crypto gambling operators face mounting Travel Rule pressure. Learn what regulators and banking partners now require and how to build compliant processes.

The Travel Rule and Crypto Gambling: What Regulators Expect

For crypto gambling operators, the Financial Action Task Force Travel Rule has moved from a theoretical compliance concern to an active enforcement priority. Regulators across the EU, UK, and key licensing jurisdictions are now asking hard questions about how operators identify the originators and beneficiaries of virtual asset transfers, and banking partners are demanding documented answers before they will maintain correspondent relationships.

What the Travel Rule Actually Requires

The Travel Rule, originally FATF Recommendation 16, obligates virtual asset service providers to collect, verify, and transmit specific identifying information alongside any virtual asset transfer above a defined threshold. In most jurisdictions that threshold sits at the equivalent of EUR 1,000, though some regulators apply it to all transfers regardless of value. The required data typically includes the originator's full name, account number or wallet address, and physical address or national identity number, plus the beneficiary's name and wallet address.

For a crypto gambling operator, this means that every on-chain deposit and withdrawal is not simply a technical transaction. It is a regulated data transfer that must carry a verifiable identity trail from sender to recipient and back.

Where Operators Are Currently Falling Short

The most common compliance gaps OnlineShine observes when operators approach us for AML reviews include the following:

  • Accepting deposits from unhosted or self-custodied wallets without applying counterparty due diligence
  • No Travel Rule messaging protocol in place, meaning the operator cannot send or receive the required originator and beneficiary data
  • KYC data collected at onboarding that does not map cleanly onto Travel Rule data fields, creating reporting gaps
  • Withdrawal flows that release funds before Travel Rule data has been confirmed by the receiving VASP
  • Incomplete audit trails, so that compliance teams cannot reconstruct a transaction's full identity chain for a regulator or banking partner on request

What Regulators Are Looking for in Practice

Supervisory examinations in 2025 and into 2026 have made the regulator's expectations clearer. Authorities want to see a documented Travel Rule policy that names the chosen compliance protocol, whether IVMS 101 data standard via solutions such as Notabene, Sygna, or TRP, and explains how the operator handles sunrise-period exceptions when a counterpart VASP cannot yet receive structured data.

Regulators also expect operators to screen counterpart VASPs before transacting with them, verifying that the receiving or sending entity is itself a licensed, supervised entity. Sending Travel Rule data to an unlicensed counterpart does not satisfy the obligation; it compounds the risk.

Transaction monitoring rules must be calibrated to flag unhosted wallet activity specifically, not just apply generic thresholds. Examiners increasingly review monitoring logic during inspections, not just SAR or STR filing rates.

What Banking Partners Demand

Crypto gambling operators that maintain fiat banking relationships face a parallel set of requirements from their banking partners, who are themselves subject to correspondent banking due diligence rules. A bank providing payment infrastructure to a crypto gambling operator will typically require the following:

  • A written Travel Rule compliance policy with named ownership and a review schedule
  • Evidence of a deployed Travel Rule solution with documented counterpart VASP coverage rates
  • Quarterly or semi-annual compliance reporting, often including transaction volume data by wallet type
  • Escalation procedures for transactions that cannot be matched to a licensed counterpart VASP

Banks are losing tolerance for vague assurances. Operators that cannot produce structured evidence of Travel Rule compliance are finding that account reviews are becoming account terminations.

Building a Defensible Compliance Framework

Operators need to treat Travel Rule compliance as an operational system, not a policy document. That means integrating a Travel Rule messaging solution at the platform level so that data exchange is automatic and logged, not a manual exception process. It also means aligning KYC data collection with IVMS 101 field requirements from the point of player registration, so that the compliance team is not retrofitting identity data after the fact.

A compliant Travel Rule program is one that a regulator or banking partner can audit end-to-end on short notice. If the audit trail exists only in theory, it does not exist in practice.

Unhosted wallet transactions require a separate risk assessment and, in many licensing frameworks, enhanced due diligence that must be documented case by case. Operators should establish clear internal rules about which unhosted wallet flows are permitted, at what value limits, and with what additional verification steps.

For operators building or reviewing their crypto compliance stack, the Travel Rule is no longer a back-burner issue. It is the compliance question regulators ask first and banking partners ask before extending or renewing any relationship.

FAQ

Frequently asked questions

What is the Travel Rule and why does it apply to crypto gambling operators?

The Travel Rule, derived from FATF Recommendation 16, requires virtual asset service providers to collect and transmit identifying information about the originator and beneficiary of any virtual asset transfer above a defined threshold, typically EUR 1,000. Crypto gambling operators qualify as VASPs in most licensing and regulatory frameworks because they send and receive virtual assets on behalf of players. This means they are legally obligated to implement Travel Rule data exchange processes and cannot treat crypto deposits or withdrawals as anonymous technical events.

Which data fields must a crypto gambling operator collect and transmit under the Travel Rule?

The required data set follows the IVMS 101 standard and generally includes the originator's full legal name, wallet address or account identifier, and either a physical address, national identity number, or date and place of birth. On the beneficiary side, operators must capture the recipient's name and wallet address. The exact fields vary slightly by jurisdiction, but operators should design their KYC and withdrawal flows to collect all IVMS 101 fields at registration so that Travel Rule messages can be generated automatically for each transaction.

How should a crypto gambling operator handle transfers from unhosted or self-custodied wallets?

Transfers from unhosted wallets present a specific compliance challenge because there is no counterpart VASP to exchange Travel Rule data with. Regulators generally require operators to apply enhanced due diligence to unhosted wallet transactions, documenting the player's ownership of the wallet through methods such as micro-deposit verification or signed message proof. Many licensing frameworks also require a separate risk assessment for unhosted wallet activity, and some impose lower value thresholds before enhanced checks are triggered. Operators should have a written unhosted wallet policy that sets out permitted transaction limits and the required verification steps.

What do banking partners typically require from a crypto gambling operator to demonstrate Travel Rule compliance?

Banking partners providing fiat infrastructure to crypto gambling operators typically require a written Travel Rule compliance policy with documented ownership, evidence of a deployed Travel Rule messaging solution with stated counterpart VASP coverage rates, and regular compliance reporting that includes transaction volume breakdowns by wallet type. Banks also expect to see clear escalation procedures for transactions where a counterpart VASP cannot be identified or is unlicensed. Operators that cannot provide structured, auditable evidence of these controls are increasingly facing account reviews or terminations.

Keep reading

Related articles

Show us one brand.
We will find the leaks.

Book a 30-minute teardown. We walk through one of your brands and show you exactly where revenue, retention or compliance is slipping, no obligation.