AML/CTF value transfers and the travel rule explained

Businesses that transfer money, property or virtual assets for customers may need to collect, verify and share information about the people involved in the transfer.

These obligations are commonly known as the travel rule. They apply across a chain of businesses that accepts the transfer instruction, passes on the transfer information and makes the value available to the recipient.

The rules are not limited to banks or international money transfers. Depending on the service, they can apply to financial institutions, remittance providers, virtual asset service providers and other businesses involved in transferring value.

This explainer covers what a transfer of value is, the institutions in a value transfer chain, the information that must travel with a transfer and the additional requirements for virtual assets.

What is a transfer of value?

A transfer of value is broadly a transfer of money, virtual assets or other property from one person to another.

The concept is not limited to the physical movement of an asset. It can include transactions, messages and arrangements that have substantially the same effect as moving value between people.

A transfer of value does not include a transfer of physical currency or other tangible property. Other exclusions can also apply, including to some transfers of securities or derivatives and certain administrative payment services.

For example, a business may provide administrative services that help an employer make salary, benefit, salary-sacrifice or superannuation payments. Subject to the applicable conditions, those payments may fall outside the value-transfer framework.

The substance of the arrangement matters. A business should look at who gives the instruction, who controls the value, how it reaches the recipient and which entities process the transfer.

What is the travel rule?

The travel rule requires specified information about a value transfer to pass between the businesses involved in completing it.

Its purpose is to make the payer, payee and path of a transfer visible to those businesses. That information helps them identify and manage money laundering, terrorism financing and proliferation financing risk.

The information can also help law enforcement and other authorities trace funds or assets through a payment chain.

The precise obligation depends on the role a business performs. One business may need to collect and verify the information. Another may need to check that it has received the information. A third may need to preserve and pass the information to the next institution.

Every new instruction from a payer can start a new value transfer chain. If a customer receives funds into an account and later instructs the institution to send them elsewhere, the second transfer does not simply continue the first chain.

Who is involved in a value transfer chain?

A value transfer chain can include three types of institution:

1.      the ordering institution;

2.      one or more intermediary institutions; and

3.      the beneficiary institution.

A single business can perform more than one role. The roles should be assessed for each transfer rather than assigned permanently according to the general nature of the business.

Understanding your role is the first compliance step. The obligations of ordering, intermediary and beneficiary institutions are different.

What is an ordering institution?

An ordering institution accepts an instruction to transfer value on behalf of the payer as part of carrying on a business.

The payer’s instruction may be written, spoken or given through a digital channel. It may also be implicit under a standing arrangement, such as a direct debit authority.

A business may be acting as an ordering institution if it:

  • receives the value to be transferred from the payer;

  • holds that value in an account or virtual asset wallet;

  • has authority to transfer value held by another institution;

  • transfers value under an arrangement with the payer; or

  • arranges an offsetting transaction with the institution serving the payee.

The transfer instruction is different from the transfer message. The instruction tells the ordering institution what the payer wants done. The transfer message carries the required information through the value transfer chain.

What must an ordering institution do?

An ordering institution must generally collect specified information about the payer and payee before it sends the transfer message or otherwise gives effect to the transfer.

It will usually need to:

  • collect the required payer information;

  • verify the required payer information;

  • collect the payee’s full name;

  • identify the source and destination of the transfer;

  • pass the required information to the next institution in the chain;

  • provide specified information when another institution in the chain requests it; and

  • retain sufficient records to reconstruct the transfer.

Some of this information may already have been collected and verified through customer due diligence. The ordering institution should confirm that the information is complete, current and suitable for the transfer rather than assuming that an existing customer record is enough.

The information should be sent before, or at the same time as, the transfer is completed where the transfer message does not itself move the value.

What is payer information?

Payer information identifies the person who instructs the transfer.

It generally includes the payer’s full name together with one or more additional identifiers. Depending on the transfer, that may include:

  • a customer identification number;

  • another unique identifier;

  • the payer’s date and place of birth; or

  • a full residential or business address.

A post office box will not generally be enough where an address is required.

Alternative information standards may apply as global travel rule requirements change. Reporting entities need to make sure their systems use a permitted information set and treat the payer and payee information consistently.

What is tracing information?

Tracing information allows institutions to identify the source and destination of the transferred value.

Depending on the transfer, this may include:

  • account details;

  • virtual asset wallet details;

  • a wallet address; or

  • a unique transaction reference number.

For a transfer from or to a bank account, the information should identify the relevant account. For a transfer involving a custodial virtual asset wallet, it should identify the customer’s holdings within that wallet.

If a self-hosted wallet is involved, the wallet address may form part of the tracing information.

Tracing information matters because names alone do not show where value originated or where it was delivered. The information should let an institution and, if necessary, an authority reconstruct the path of the transfer.

What is a beneficiary institution?

A beneficiary institution makes the transferred value available to the payee as part of carrying on a business.

It may do this by:

  • paying the value directly to the payee;

  • depositing it into an account held for the payee;

  • crediting a custodial virtual asset wallet;

  • arranging for another institution to make the value available; or

  • completing an offsetting arrangement with the ordering institution.

The beneficiary institution is not simply any business that receives a message. Its role is linked to making the transferred value available to the person who is meant to receive it.

What must a beneficiary institution do?

A beneficiary institution must take reasonable steps to monitor whether it has received the required transfer information.

Depending on the type of transfer, it may need to monitor for:

  • payer information;

  • the payee’s full name;

  • tracing information; or

  • information specific to the payment method, such as a card number.

The beneficiary institution may also need to check whether information about the payee is accurate.

If required information is missing or inaccurate, the institution must respond according to its anti-money laundering and counter-terrorism financing program. That response may include refusing to make the value available, requesting further information or taking another risk-based action.

The right response will depend on the nature of the deficiency, the risks involved and whether the problem can be corrected. The decision and reasons should be recorded.

What is an intermediary institution?

An intermediary institution receives a transfer message and passes it to another intermediary institution or the beneficiary institution.

It sits between the businesses serving the payer and payee. It may not have a direct relationship with either customer, but it still has an important part in preserving the information attached to the transfer.

An intermediary institution must generally:

  • monitor whether it has received the required information;

  • respond to missing information according to its AML/CTF policies;

  • pass the required information to the next institution;

  • provide information to another institution in the chain when requested; and

  • keep records of the transfer and its decisions.

An intermediary should not strip information from a transfer message simply because its own system does not use the information. Its systems must be able to preserve and transmit the data required for the next institution to meet its obligations.

What happens if transfer information is missing?

Missing or inaccurate information is not merely a data-quality problem. It can prevent another institution from identifying the parties, tracing the transfer or assessing the financial crime risk.

A beneficiary or intermediary institution should have procedures that explain:

  • how missing information is detected;

  • when staff must request further information;

  • when a transfer must be stopped or rejected;

  • what other risk-based action may be taken;

  • who makes the decision;

  • when the matter must be escalated; and

  • how the decision and reasons are recorded.

A single technical failure may require a different response from repeated missing information from the same institution.

Patterns matter. Repeated incomplete messages may indicate that an upstream provider has weak controls or cannot supply the information required by the Australian regime. That can affect whether the relationship should continue and whether suspicious matter reporting should be considered.

Do the same rules apply to every transfer?

No. The information requirements can vary according to the type of transaction and the system used.

Modified requirements may apply to:

  • domestic transfers processed through specified Australian payment systems;

  • batches containing multiple transfers;

  • merchant payments and refunds;

  • automated teller machine transactions;

  • some international transfers received through domestic payment systems; and

  • transfers involving self-hosted virtual asset wallets.

For example, a card number may be the relevant information for some merchant payments or automated teller machine withdrawals. A domestic transfer through an established payment system may require different information to a cross-border transfer.

Reporting entities should not build one undifferentiated travel rule process. Their systems need to recognise the transaction type and apply the correct information standard.

What is a merchant payment?

A merchant payment is generally a transfer of money to a merchant resulting from the payer’s use of a credit, debit or stored-value card issued by the ordering institution.

The beneficiary institution initiates the transfer and pays, or becomes liable to pay, the merchant. A refund of that payment may receive similar treatment.

Some standard collection and verification requirements are modified for merchant payments. This reflects the structure of card payment systems, but it does not remove the need for appropriate records and transaction monitoring.

A payment does not become a merchant payment simply because a business receives it. The card, merchant and payment-processing features must satisfy the applicable definition.

How do the rules apply to virtual asset transfers?

Virtual asset transfers are subject to the general travel rule and additional requirements concerning wallets and the institutions controlling them.

Before accepting an instruction to transfer a virtual asset, an ordering institution must conduct due diligence to determine whether the destination is:

  • a self-hosted wallet controlled by the payee;

  • a custodial wallet controlled by a licensed or registered provider;

  • a custodial wallet controlled by a provider that is not required to be licensed or registered; or

  • a custodial wallet controlled by a provider that is required to be licensed or registered but is not.

A similar assessment applies to a beneficiary institution receiving a transfer. It needs to understand whether the sending wallet is self-hosted or controlled by a regulated custodial provider.

A transfer must not proceed in some circumstances involving an unlicensed or unregistered custodial provider that is required to hold that status.

These checks require more than recording a wallet address. The institution needs a reasonable basis for its conclusion and should retain evidence of the wallet assessment and any licensing or registration check.

For more information, see our AML/CTF regulation of virtual assets explainer.

What if travel rule information cannot be transmitted securely?

Virtual asset systems do not always allow the required customer information to be embedded in the blockchain transaction.

The travel rule information may therefore need to be transmitted through a separate secure channel.

An ordering institution may face circumstances where the receiving institution cannot accept the information securely or may not protect its confidentiality. The applicable rules can permit the information not to be passed in limited circumstances, but the ordering institution must have reasonable grounds for its conclusion and keep a record of its reasons.

A beneficiary institution may also face a transfer where another institution could not transmit the information securely. Any exception must be supported by a proper risk assessment and controls addressing the risks of accepting the transfer.

Technical inconvenience is not enough. The institution needs evidence of the security or confidentiality problem and a documented response.

Are any value transfers exempt?

A number of exemptions and modified requirements apply. Depending on the circumstances, these can include:

  • transfers reasonably incidental to another service;

  • specified transfers through foreign permanent establishments;

  • transfers between financial institutions acting on their own behalf;

  • some payments processed through the SWIFT system;

  • certain transfers initiated by cheque;

  • merchant payments and refunds;

  • transfers involving some pre-commencement or previously verified customers; and

  • transfers to self-hosted virtual asset wallets.

Each exemption has conditions. A business should not apply one based only on a brief description of the payment.

The incidental service exemption, for example, does not apply in the same way to every institution or service. International transfers, currency exchange, gambling and virtual asset services can require separate analysis.

Record why an exemption applies. That reasoning may later be needed to explain why information was not collected, verified or passed on.

How should travel rule requirements appear in an AML/CTF program?

An AML/CTF program should explain how the reporting entity identifies its role and applies the correct requirements to each transfer.

The policies should cover:

  • how a transfer of value is identified;

  • how the entity determines whether it is acting as an ordering, intermediary or beneficiary institution;

  • what information must be collected, verified, monitored and passed on;

  • how transfer information is transmitted securely;

  • how requests from other institutions are handled;

  • how missing or inaccurate information is detected;

  • when a transfer must be stopped, rejected or escalated;

  • how virtual asset wallets and providers are assessed;

  • when an exemption applies; and

  • what records must be retained.

The process must also work in the systems used to complete transfers. A policy cannot cure a payment platform that drops required information or cannot place a hold on an incomplete transfer.

What should you do?

  • Map your transfer services. Identify every service that moves money, virtual assets or property for customers, including services described internally as payments, settlement, custody, remittance or withdrawals.

  • Assign roles by transaction. Determine when you act as an ordering, intermediary or beneficiary institution. Do not rely only on your general business classification.

  • Map the required data. Identify where payer, payee and tracing information is collected, verified, stored and transmitted.

  • Test system capability. Confirm that payment and messaging systems preserve the required information and can stop or hold transfers when information is missing.

  • Set rules for incomplete messages. Give staff clear criteria for requesting information, rejecting a transfer, taking another risk-based action and escalating repeated failures.

  • Prepare for information requests. Establish a process for finding and providing transfer information promptly to another institution in the chain.

  • Review third-party arrangements. Check whether payment processors, technology providers and correspondent institutions support your travel rule obligations.

  • Assess virtual asset wallets. Document how you distinguish self-hosted wallets from custodial wallets and verify the status of custodial providers.

  • Test completed transfers. Sample different transaction types and trace the required information from the payer’s instruction to the value received by the payee.

The bottom line

The travel rule is an information chain that runs beside the transfer of value.

Each institution must understand its place in that chain and deal properly with the information it collects, receives or passes on. A failure by one institution can leave the next unable to identify the parties, trace the asset or assess the risk.

Start by mapping the transfer. Then map the information.

Need help with AML/CTF value transfers?

Dwyer Harris assists reporting entities to assess, document and implement their AML/CTF obligations for transfers of value.

We can help you:

  • identify the value transfer services your business provides;

  • determine when you act as an ordering, intermediary or beneficiary institution;

  • assess the information requirements applying to different transfer types;

  • draft or review your travel rule policies and procedures;

  • review processes for missing or inaccurate transfer information;

  • assess exemptions and modified requirements;

  • review virtual asset wallet due diligence and transfer controls;

  • assess payment, messaging and third-party service arrangements;

  • test selected transfers and supporting records;

  • conduct a post-implementation review of new travel rule processes; and

  • update your AML/CTF program following a service, system or regulatory change.

Our focus is on controls that meet the legal requirements, give staff clear instructions and work with the systems used to complete the transfer.

Get in touch with Dwyer Harris if you need help assessing or implementing the AML/CTF requirements that apply to your value transfers.

This article provides general information only and is not legal advice.

Previous
Previous

How does AML/CTF apply to legal professional privilege?

Next
Next

How does Australia’s AML/CTF regime regulate virtual assets?