FINTRAC Travel Rule: requirements for Canadian regulated firms
The Travel Rule is the part of the PCMLTFA that requires originator and beneficiary information to travel with a wire transfer or virtual currency transfer. This is the plain-English requirements explainer for Canadian MSBs, PSPs, and crypto firms.
The "Travel Rule" is the requirement that specific information about the originator and the beneficiary of a transfer must "travel" with the payment along the entire chain that handles it. In Canada, it is grounded in the PCMLTFA and FINTRAC regulations, and it applies to two transfer types most regulated firms now handle: international electronic funds transfers (EFTs) and virtual currency transfers. The international standard behind it is FATF Recommendation 16.
This article is the definitive requirements explainer. If you are looking for the most common failure modes we see in the field (especially on the crypto side), read the companion piece, Crypto and the Travel Rule: where Canadian VASPs are getting it wrong.
Who is covered by the Travel Rule in Canada?
Three categories of reporting entity have direct Travel Rule obligations under FINTRAC:
- Money services businesses (MSBs) and foreign MSBs that initiate, receive, or transmit international EFTs.
- Financial entities (banks, credit unions) handling international EFTs.
- Money services businesses (including VASPs) that send or receive virtual currency transfers on behalf of a client.
Payment service providers (PSPs) become subject to overlapping Travel Rule-equivalent obligations through the Retail Payment Activities Act framework and, where they qualify as MSBs, through the PCMLTFA itself. The two regimes are not identical, but the information-flow expectations converge.
What information has to travel with the transfer?
For both international EFTs and virtual currency transfers, the regulations require the originator and the beneficiary to be identified, and for that identifying information to be transmitted with the transfer. The minimum data set is:
- Originator (the sender): name, account number (or unique transaction reference), and address.
- Beneficiary (the recipient): name, and account number (or unique reference).
- Transfer details: amount, currency, and date.
For virtual currency transfers, the address fields become the wallet addresses (or equivalent identifiers), and the "account number" obligation maps to the unique transaction reference (hash). The information must be transmitted on or before the transfer settles, and it must be retained on file for at least five years.
What are the Travel Rule thresholds?
The Travel Rule applies at and above the following thresholds, in Canadian dollars or equivalent:
- International EFTs: CAD $1,000 and above.
- Virtual currency transfers: CAD $1,000 and above.
Two important nuances. First, the thresholds apply to single transactions and to multiple related transactions that aggregate to the threshold (the "24-hour rule" for combined transactions). Second, the reporting obligations that sit alongside the Travel Rule (the EFT Report at CAD $10,000 and the Large Virtual Currency Transaction Report (LVCTR) at CAD $10,000) are separate filings with their own thresholds. Travel Rule information has to be captured below the reporting threshold even if you are not filing a report.
How does the Travel Rule interact with STRs, LCTRs, EFTRs, and LVCTRs?
The Travel Rule is an information-flow obligation. The reporting obligations are separate filings. Both depend on having the underlying data captured cleanly. Practically:
- A Suspicious Transaction Report (STR) can be triggered by any transaction at any value, including ones below the Travel Rule threshold. The originator and beneficiary information you captured to satisfy the Travel Rule feeds directly into the STR.
- A Large Cash Transaction Report (LCTR) sits alongside, for cash deposits or receipts at CAD $10,000 and above. Not Travel Rule, but adjacent.
- An Electronic Funds Transfer Report (EFTR) is filed for international EFTs at CAD $10,000 and above, in or out. The same originator and beneficiary fields populate the report.
- A Large Virtual Currency Transaction Report (LVCTR) is filed for virtual currency receipts at CAD $10,000 and above. The Travel Rule data is the spine of this report.
Building the Travel Rule capture once, in the system of record, is what makes the four reports come out clean. Building it separately for each report is what makes them come out inconsistent, which is the deficiency examiners find most often.
How is Travel Rule information transmitted between VASPs?
The transmission half of the Travel Rule is the operationally hardest part, especially for crypto. The originator VASP has the originator information; the beneficiary VASP needs to receive it. Canada accepts the use of compliant counterparty messaging protocols (such as IVMS 101-aligned protocols like TRP, OpenVASP, and TRISA) provided the information that ends up captured matches the regulatory minimum. Where the counterparty is unhosted (a self-custodied wallet), FINTRAC expects the regulated entity to conduct due diligence on the customer and on the destination wallet, not to rely on counterparty messaging that does not exist.
How long must Travel Rule records be retained?
Whether you filed a report or not, you must retain the originator and beneficiary information, plus the transaction details, for at least five years from the date of the transfer. The records must be retrievable in a reasonable time on request from FINTRAC. "In a reasonable time" in practice means hours to days, not weeks, and not "we will need to go ask the vendor".
How does BriteBase handle the Travel Rule?
The BriteBase screening platform screens originators and beneficiaries against sanctions, PEP, and adverse-media lists in real time, ties every match and disposition to the customer of record, and keeps the audit-ready case history a Travel Rule examination will ask for.
FAQ
What is the Travel Rule in Canada?
The Travel Rule is the PCMLTFA requirement that specific information about the originator and the beneficiary of a transfer must travel with the payment along the entire chain that handles it. In Canada it is grounded in the PCMLTFA and FINTRAC regulations, and the international standard behind it is FATF Recommendation 16. It applies to the two transfer types most regulated firms now handle: international electronic funds transfers and virtual currency transfers, at CAD $1,000 and above. It is an information-flow obligation rather than a report, so the identifying data has to be transmitted on or before the transfer settles and retained on file, distinct from the separate reports that sit alongside it. The point is that the originator and beneficiary can always be identified as value moves, which is what lets an investigator, or an examiner, reconstruct who sent and received a transfer after the fact.
Who has to comply with the FINTRAC Travel Rule?
Three categories of reporting entity have direct Travel Rule obligations under FINTRAC. Money services businesses and foreign MSBs that initiate, receive, or transmit international electronic funds transfers are covered, as are financial entities such as banks and credit unions handling those transfers. The third category is money services businesses, including VASPs, that send or receive virtual currency transfers on behalf of a client. Payment service providers sit slightly apart: they become subject to overlapping Travel Rule-equivalent obligations through the Retail Payment Activities Act framework, and where they also qualify as MSBs, through the PCMLTFA itself. The two regimes are not identical, but their information-flow expectations converge, so a PSP that moves value generally cannot treat itself as out of scope. The common thread is that any firm initiating, transmitting, or receiving covered transfers on a client's behalf carries the obligation to make the required information travel with them.
What is the Travel Rule threshold for virtual currency transfers in Canada?
CAD $1,000, or its equivalent in another currency. The same threshold applies to international electronic funds transfers, so both covered transfer types share the CAD $1,000 line. Two nuances matter. First, the threshold applies not only to single transactions but to multiple related transactions that aggregate to it, the 24-hour rule for combined transactions, so a series of smaller transfers cannot be used to stay below the line. Second, the CAD $1,000 Travel Rule threshold is separate from the CAD $10,000 reporting thresholds that sit alongside it, the EFT Report and the Large Virtual Currency Transaction Report. That means Travel Rule information has to be captured below the CAD $10,000 reporting threshold even when you are not filing a report. Treating the two thresholds as one is a common mistake; the information-flow obligation begins at CAD $1,000, well before any reporting obligation is triggered.
What originator information has to be captured under the Travel Rule?
At minimum, three fields for the originator: their name, their account number or a unique transaction reference, and their address. For virtual currency transfers the address field becomes the wallet address or equivalent identifier, and the account-number obligation maps to the unique transaction reference, which is the transaction hash. The beneficiary side requires the same identifying data: name and account number or unique reference. On top of the party details, the transfer itself has to carry the amount, the currency, and the date. All of it must be transmitted on or before the transfer settles, not reconstructed afterward, and retained on file for at least five years from the date of the transfer. Capturing this minimum data set cleanly at the point of the transfer is what lets the same information later populate the EFT Report or the Large Virtual Currency Transaction Report without having to be gathered a second time.
How long do I have to keep Travel Rule records?
At least five years from the date of the transfer. That retention obligation applies whether or not you filed a report on the transaction: the originator and beneficiary information, plus the transaction details, has to be kept for the full period regardless. Retention alone is not the whole standard, though. The records must also be retrievable in a reasonable time on request from FINTRAC, and in practice a reasonable time means hours to days, not weeks, and certainly not "we will need to go ask the vendor". That retrieval expectation is why storing Travel Rule data in a system you do not control, or across disconnected spreadsheets, is a real weakness even when the data technically exists. Keeping the information in a system of record you can query directly is what turns a five-year archive into records you can actually produce when an examiner asks for them within the window they expect.
How does the Travel Rule interact with LVCTRs and EFTRs?
The Travel Rule is an information-flow obligation, while the LVCTR and the EFTR are separate filings, each triggered at CAD $10,000 and above. The Electronic Funds Transfer Report covers international EFTs at that threshold, in or out, and the Large Virtual Currency Transaction Report covers virtual currency receipts at CAD $10,000 and above. The connection is that both reports are populated by the same originator and beneficiary fields you captured to satisfy the Travel Rule, so the Travel Rule data is effectively the spine of each report. Building that capture once, in the system of record, is what makes the reports come out clean and consistent; building it separately for each filing is what makes them come out inconsistent, which is the deficiency examiners find most often. A Suspicious Transaction Report can also draw on the same captured data, since an STR can be triggered at any value, including below the Travel Rule threshold.
What does FINTRAC expect for transfers to unhosted wallets?
Where the counterparty is an unhosted, self-custodied wallet, there is no other VASP on the far side to exchange messaging with, so the transmission half of the Travel Rule cannot be satisfied through a counterparty protocol. In that situation FINTRAC expects the regulated entity to conduct due diligence on the customer and on the destination wallet, rather than to rely on counterparty messaging that does not exist. Reliance on messaging that is not there is not an acceptable substitute for the underlying obligation to know who is sending and receiving the value. For hosted counterparties, Canada accepts compliant messaging protocols such as IVMS 101-aligned TRP, OpenVASP, and TRISA, provided the information that ends up captured matches the regulatory minimum. But the protocol is only a means of transmission; where no counterparty exists to transmit to, the obligation falls back on the firm's own diligence, and that diligence has to be documented like any other decision.
Sources
Reading is useful. A conversation is faster.
Book a platform demo and we will walk you through real-time sanctions, PEP, and adverse-media screening and the data coverage that fits your firm.
Book a call
