Insights
Canada’s Travel Rule in 2026: A Practical Compliance Guide for Virtual Asset Service Providers
The Travel Rule Is Here — And FINTRAC Is Watching
For virtual asset service providers (VASPs) operating in Canada, the Financial Action Task Force’s Recommendation 16 — commonly known as the Travel Rule — is no longer a theoretical compliance concern. Through amendments to the Proceeds of Crime (Money Laundering) and Terrorist Financing Act (PCMLTFA) and its supporting regulations, Canada has incorporated Travel Rule obligations into law, and FINTRAC’s enforcement activity in 2025 and 2026 signals that regulators are actively scrutinizing whether businesses have built the systems and policies to comply.
If your business sends or receives virtual currency on behalf of clients — whether you are a crypto exchange, OTC desk, custodian, or payment processor — understanding exactly what is required, and where the practical friction lies, is essential to operating without regulatory interruption.
What the Travel Rule Actually Requires
At its core, the Travel Rule obligates a VASP (or money services business dealing in virtual currency, in Canadian regulatory terminology) to collect, verify, and transmit specific information about the parties to a virtual asset transfer when the transaction meets or exceeds the prescribed threshold. Under Canada’s PCMLTFA regulations, this threshold is CAD $1,000 — including transactions that are part of a series clearly related to one another.
The required data elements break down as follows:
- Originator information — legal name, account number (e.g. wallet address or client account ID), and geographic address
- Beneficiary information — legal name and account number (wallet address or account identifier at the receiving institution)
This information must travel with the transaction — sent by the originating VASP to the beneficiary VASP before or simultaneously with the virtual asset transfer. The receiving institution must, in turn, retain that data and make it available to FINTRAC upon request. Records must be kept for a minimum of five years.
Importantly, these obligations apply whether you are the sending party, the receiving party, or acting as an intermediary. Each leg of the transaction chain carries distinct obligations under the regulations.
Three Practical Challenges Every VASP Faces
1. Counterparty Identification: Regulated VASP or Unhosted Wallet?
One of the most operationally complex questions is determining who sits on the other side of a transaction. When a client sends virtual currency to an external address, your compliance team must assess whether that address belongs to another regulated VASP or to an unhosted (self-custodied) wallet.
For transfers to another regulated VASP, you can use a Travel Rule messaging protocol to transmit originator data and receive beneficiary confirmation. For unhosted wallets, the situation is more nuanced: FINTRAC guidance requires enhanced due diligence and controls, and some institutions apply transaction limits or additional ownership verification (commonly called a proof-of-ownership check) before processing.
Developing a clear written unhosted wallet policy — one that sets out your risk-based thresholds, acceptable verification methods, and escalation procedures — is a foundational step that many VASPs still lack.
2. Choosing a Travel Rule Technical Solution
The PCMLTFA regulations specify what must be transmitted but not how. There is no single mandated technical standard globally, which means Canadian VASPs must choose from a fragmented ecosystem of interoperability protocols — including IVMS 101 data standards, OpenVASP, the Travel Rule Protocol (TRP), and platforms such as Notabene, Sygna Bridge, and Shyft Network.
Selecting a protocol that your counterparties also support is critical. A Travel Rule message sent via one protocol cannot be received by an institution using an incompatible system, creating operational breakdowns that can hold up settlement or trigger compliance flags. Before committing to a vendor, map out which protocols your most frequent counterparty institutions use, and ensure your chosen solution supports multiple standards or can bridge between them.
3. The Sunrise Problem: International Counterparties with No Equivalent Obligations
Canada has implemented the Travel Rule. Many jurisdictions have not — or have implemented it on a different timeline with different thresholds. When you send virtual assets to a VASP in a jurisdiction that has not enacted equivalent requirements, that counterparty may be unwilling or technically unable to receive and acknowledge your Travel Rule data.
FINTRAC’s risk-based approach requires you to document your efforts: attempt to transmit the information, record the outcome, and apply appropriate compensating controls (such as enhanced monitoring or transaction holds) where counterparty compliance cannot be confirmed. Simply abandoning Travel Rule obligations because a foreign counterparty is unresponsive is not a defensible position in an examination.
Practical Steps to Build a Compliant Travel Rule Program
- Confirm your MSB registration. All Canadian VASPs are required to register as money services businesses with FINTRAC. Operating without registration — or with a lapsed registration — exposes your business to significant penalties, including public notices of violation.
- Conduct a transaction flow audit. Map every inbound and outbound virtual currency flow. Identify which corridors exceed the CAD $1,000 threshold and classify counterparties as regulated VASPs, unhosted wallets, or unknown addresses.
- Select and integrate a Travel Rule solution. Procure a platform that supports the IVMS 101 data standard at minimum, evaluate counterparty network coverage, and test end-to-end data exchange before going live.
- Draft an unhosted wallet policy. Define how your firm identifies, verifies, and limits transactions to unhosted wallets, including the due diligence steps required for higher-value transfers.
- Update your AML compliance program. Your written AML/CFT policies must reflect Travel Rule procedures. This includes staff training, record-keeping protocols, and procedures for handling exceptions where counterparty data cannot be obtained.
- Prepare for FINTRAC examinations. Be able to demonstrate, through logs and documented procedures, that your Travel Rule transmission process functions on every qualifying transaction — not just in policy on paper.
The Stakes: Why This Matters Now
FINTRAC has signalled through its published compliance assessments and administrative monetary penalties that the virtual currency sector remains a priority focus. Penalties for PCMLTFA violations can reach into the millions of dollars, and repeated or wilful non-compliance can result in criminal referrals. Beyond regulatory risk, Travel Rule failures can also damage counterparty relationships: regulated exchanges and custodians increasingly refuse to process incoming transfers that arrive without compliant originator data, effectively freezing your clients’ assets.
In an environment where institutional adoption of digital assets is accelerating, being a Travel Rule-compliant counterparty is increasingly a prerequisite for accessing major liquidity venues and banking relationships.
Getting Compliant Without the Overwhelm
Travel Rule compliance touches technology, legal, operations, and client experience simultaneously — which is why many VASPs struggle to build a coherent program without external support. A structured gap assessment, followed by a phased implementation plan, is usually the most efficient path: identify what you have, determine what is missing, and build toward a defensible, auditable compliance posture.
Need guidance? Reach out to our team — no pressure, no jargon.