Since 30 December 2024, the EU’s Transfer of Funds Regulation (TFR) requires each transfer of funds or crypto-assets in scope to carry information on who sends it and who receives it. This article sets out what the rules require, article by article, and where they create work for compliance teams.
The TFR regulation is the EU rulebook that sets out which information on the sender and the recipient must accompany a transfer of funds or crypto-assets, so that the transfer can be traced for anti-money laundering and counter-terrorist financing purposes (Art. 1). It is the EU's implementation of the "travel rule" in FATF Recommendations 15 and 16 (recital 6): the data travels with the payment, from the institution that sends it to the institution that receives it.
The current text, Regulation (EU) 2023/1113, entered into force on 29 June 2023 and has applied since 30 December 2024. It replaced Regulation (EU) 2015/847 and extended the travel rule from payments to crypto-asset transfers.
The TFR regulation is part of the EU AML package. The regulation it replaced only covered transfers of funds, meaning banknotes and coins, scriptural money and electronic money (recital 3). Together with the MiCA regulation, it now forms one of the pillars of crypto-asset regulation in Europe.
The TFR regulation was incorporated into the EEA Agreement in February 2025 and has applied there since 24 June 2025, so it covers Norway, Iceland and Liechtenstein as well. The rules may still change: the Commission had to review the TFR regulation within 12 months after the AML Regulation entered into force in July 2024, with a view to aligning the two (Art. 37(1)).
Payment service providers and crypto-asset service providers must ensure that each transfer in scope carries information on both parties:
Some transfers fall outside the TFR regulation, such as card or e-money payments used only for goods or services, cash withdrawals from the payer’s own account and tax payments to a public authority within a Member State (Art. 2).
For transfers of funds, the TFR uses EUR 1,000 to separate smaller transfers from larger ones. Above that amount, the full information applies and both institutions must check that it is accurate. At EUR 1,000 or less, a lighter regime applies, so that small payments are not slowed down or pushed outside the regulated system (recital 29). Transfers that appear to be linked count together, so splitting an amount does not avoid the full regime. Crypto-asset transfers have no threshold at all.
In practice, for transfers of funds:
Where the customer's identity has already been verified through customer due diligence, verification is deemed to have taken place (Art. 4(5), 7(5)). More on what that means for the KYC, AML and CDD process below.
The rules themselves are short. The operational work sits in a handful of places.
Sanctions are set at national level and are published (Art. 28 to 30). Subject to national law, they can also apply to members of the management body (Art. 28(2)). Failing to implement effective risk-based procedures is one of the breaches for which Member States must provide minimum sanctions (Art. 29(c)).
Harmoney orchestrates the whole counterparty lifecycle, from onboarding to continuous monitoring, in one auditable flow. Human-in-the-loop, audit-ready, always in control. Want to see how that works for your AML and risk assessment processes? Talk to us or explore the Harmoney platform, or stay in touch via our newsletter ⬇️.
The TFR regulation, Regulation (EU) 2023/1113, is the EU regulation on information accompanying transfers of funds and certain crypto-assets. It requires payment service providers and crypto-asset service providers to send, check and retain information on the sender and the recipient of each transfer, to prevent money laundering and terrorist financing (Art. 1, 26).
It entered into force on 29 June 2023 and has applied since 30 December 2024. From that date, it replaced Regulation (EU) 2015/847.
No. The information requirements apply to every crypto-asset transfer, regardless of amount. The EUR 1,000 threshold only plays a role for self-hosted wallets, where transfers above that amount require the provider to assess whether the wallet is owned or controlled by its customer (Art. 14(5), 16(2)).
For transfers of funds, the receiving institution decides on a risk-sensitive basis whether to execute, reject or suspend the transfer, and must either reject it or request the missing information. For crypto-assets, it can also return the transfer. Repeated failures by the same counterparty must be escalated and reported to the competent authority (Art. 8, 12, 17).
Questions about the TFR regulation and your KYC processes? Reach out to us.