TFR regulation: what it requires and where compliance teams feel it

25 September 2026

Since 30 December 2024, the EU’s Transfer of Funds Regulation (TFR) requires each transfer of funds or crypto-assets in scope to carry information on who sends it and who receives it. This article sets out what the rules require, article by article, and where they create work for compliance teams.

TFR regulation

💡 Key takeaways

  • The TFR regulation, Regulation (EU) 2023/1113, has applied since 30 December 2024 and requires every transfer of funds or crypto-assets in scope to carry information on the sender and the recipient.
  • For transfers of funds, EUR 1,000 is the dividing line: above it, the full information and its verification apply, and transfers that appear to be linked count together.
  • Crypto-asset transfers carry the information regardless of amount, including the distributed ledger addresses of both parties.
  • The receiving institution needs risk-based procedures for transfers with missing information, and must report counterparties that repeatedly fail to its competent authority.
  • Where customer due diligence has already verified the customer's identity, verification is deemed done, so the quality of the KYC file largely determines the extra workload.

What is the TFR regulation?

The TFR regulation is the EU rulebook that sets out which information on the sender and the recipient must accompany a transfer of funds or crypto-assets, so that the transfer can be traced for anti-money laundering and counter-terrorist financing purposes (Art. 1). It is the EU's implementation of the "travel rule" in FATF Recommendations 15 and 16 (recital 6): the data travels with the payment, from the institution that sends it to the institution that receives it.

The current text, Regulation (EU) 2023/1113, entered into force on 29 June 2023 and has applied since 30 December 2024. It replaced Regulation (EU) 2015/847 and extended the travel rule from payments to crypto-asset transfers.

Where the TFR regulation fits in the EU framework

The TFR regulation is part of the EU AML package. The regulation it replaced only covered transfers of funds, meaning banknotes and coins, scriptural money and electronic money (recital 3). Together with the MiCA regulation, it now forms one of the pillars of crypto-asset regulation in Europe.

The TFR regulation was incorporated into the EEA Agreement in February 2025 and has applied there since 24 June 2025, so it covers Norway, Iceland and Liechtenstein as well. The rules may still change: the Commission had to review the TFR regulation within 12 months after the AML Regulation entered into force in July 2024, with a view to aligning the two (Art. 37(1)).

What information must travel with a transfer

Payment service providers and crypto-asset service providers must ensure that each transfer in scope carries information on both parties:

  • On the payer: name, payment account number, and address including the country, official personal document number and customer identification number, or alternatively date and place of birth, plus the LEI where available (Art. 4(1)).
  • On the payee: name, payment account number and, where available, the LEI (Art. 4(2)).
  • For crypto-assets: comparable information on the originator and the beneficiary, including their distributed ledger addresses, for every transfer regardless of amount (Art. 14, recital 30).

Some transfers fall outside the TFR regulation, such as card or e-money payments used only for goods or services, cash withdrawals from the payer’s own account and tax payments to a public authority within a Member State (Art. 2).

The EUR 1,000 threshold explained

For transfers of funds, the TFR uses EUR 1,000 to separate smaller transfers from larger ones. Above that amount, the full information applies and both institutions must check that it is accurate. At EUR 1,000 or less, a lighter regime applies, so that small payments are not slowed down or pushed outside the regulated system (recital 29). Transfers that appear to be linked count together, so splitting an amount does not avoid the full regime. Crypto-asset transfers have no threshold at all.

In practice, for transfers of funds:

  • Within the EU, a transfer only needs to carry the account numbers of the payer and the payee. If the payee's institution or an intermediary asks, the payer's institution must respond within three working days: with the full information for transfers above EUR 1,000, and with at least the names and account numbers for transfers of EUR 1,000 or less (Art. 5(1) and 5(2)).
  • For transfers of EUR 1,000 or less to outside the EU, the names and account numbers of both parties are sufficient (Art. 6(2)).
  • Above EUR 1,000, the payer's institution must verify the payer's information before sending the transfer, and the payee's institution must verify the payee's information before crediting the account (Art. 4(4), 7(3)).
  • At EUR 1,000 or less, neither institution needs to verify, unless the funds are received or paid out in cash or anonymous electronic money, or there are reasonable grounds to suspect money laundering or terrorist financing (Art. 5(3), 6(2), 7(4)).

Where the customer's identity has already been verified through customer due diligence, verification is deemed to have taken place (Art. 4(5), 7(5)). More on what that means for the KYC, AML and CDD process below.

Where compliance teams feel the TFR regulation

The rules themselves are short. The operational work sits in a handful of places.

  • Missing information. The payee’s institution needs effective risk-based procedures to decide whether to execute, reject or suspend a transfer that lacks the required information, and must then reject it or request the information (Art. 8(1)). Missing or incomplete information must also be taken into account when assessing whether a transfer is suspicious and should be reported to the FIU (Art. 9).
  • Counterparties that repeatedly fail. Where another payment service provider repeatedly fails to send the required information, the payee’s institution must take steps, which may start with warnings and deadlines, and can go as far as rejecting future transfers or restricting or ending the business relationship. It must report the failure, and the steps taken, to its competent authority (Art. 8(2)). Intermediaries and crypto-asset service providers have the same obligation (Art. 12(2), 17(2)).
  • Linked transfers. Transfers that appear to be linked count together for the EUR 1,000 threshold (Art. 5(2), 6(2), 7(3)), so an amount split into smaller transfers can still require full information and verification.
  • The KYC file. Because verification can be deemed done through customer due diligence, the KYC file carries much of the weight. In practice, this means the quality and completeness of client data largely determine how much extra verification work the TFR regulation creates.
  • Records. Information on both parties must be kept for five years, after which personal data must be deleted unless national law provides otherwise (Art. 26).

Sanctions are set at national level and are published (Art. 28 to 30). Subject to national law, they can also apply to members of the management body (Art. 28(2)). Failing to implement effective risk-based procedures is one of the breaches for which Member States must provide minimum sanctions (Art. 29(c)).

Harmoney orchestrates the whole counterparty lifecycle, from onboarding to continuous monitoring, in one auditable flow. Human-in-the-loop, audit-ready, always in control. Want to see how that works for your AML and risk assessment processes? Talk to us or explore the Harmoney platform, or stay in touch via our newsletter ⬇️.

This site is protected by reCAPTCHA and the Google Privacy Policy and Terms of Service apply.

Frequently asked questions

What is the TFR regulation?

The TFR regulation, Regulation (EU) 2023/1113, is the EU regulation on information accompanying transfers of funds and certain crypto-assets. It requires payment service providers and crypto-asset service providers to send, check and retain information on the sender and the recipient of each transfer, to prevent money laundering and terrorist financing (Art. 1, 26).

When did the TFR regulation start to apply?

It entered into force on 29 June 2023 and has applied since 30 December 2024. From that date, it replaced Regulation (EU) 2015/847.

Is there a minimum amount for crypto-asset transfers?

No. The information requirements apply to every crypto-asset transfer, regardless of amount. The EUR 1,000 threshold only plays a role for self-hosted wallets, where transfers above that amount require the provider to assess whether the wallet is owned or controlled by its customer (Art. 14(5), 16(2)).

What happens when a transfer arrives with missing information?

For transfers of funds, the receiving institution decides on a risk-sensitive basis whether to execute, reject or suspend the transfer, and must either reject it or request the missing information. For crypto-assets, it can also return the transfer. Repeated failures by the same counterparty must be escalated and reported to the competent authority (Art. 8, 12, 17).

Questions about the TFR regulation and your KYC processes? Reach out to us.

Latest articles