GIIF Clarifies Travel Rule Obligations: Technical Verification Required for Unhosted Wallets
The General Inspector of Financial Information (GIIF) has published Communication No. 113 concerning the application of the Travel Rule, i.e. the information requirements accompanying transfers of funds and certain crypto-assets under Regulation (EU) 2023/1113, known as the Transfer of Funds Regulation (TFR). The Communication is addressed primarily to:
- payment service providers (PSPs);
- intermediary payment service providers (IPSPs);
- crypto-asset service providers (CASPs);
- intermediary crypto-asset service providers(ICASPs).
Technical Verification of Unhosted Wallets and TFR Breach Reporting under GIIF Guidance
GIIF has clarified how obliged institutions should apply the guidelines of the European Banking Authority (EBA) concerning the Travel Rule. The most important practical point concerns transfers involving unhosted addresses, i.e. crypto-asset wallet addresses managed directly by the customer.
An obliged institution should verify whether the customer actually controls such an address. GIIF indicates that acceptable verification methods may include technical solutions, such as signing a test message with a private key, using a micro-transfer, or applying advanced blockchain analytics tools.

At the same time, GIIF has clearly indicated what should not be treated as sufficient. A customer’s mere declaration that they control a wallet is not an acceptable solution. Screenshots from a computer or mobile application used to operate the wallet are also insufficient. Therefore, any entity that has so far relied on this type of evidence will need to change its approach.
The Communication also clarifies the rules for reporting TFR breaches to GIIF. The mere occurrence of circumstances indicating a breach of the TFR, without other risk factors and without conclusions drawn by the obliged institution on the basis of information and documents collected as part of customer due diligence measures, should not in itself constitute grounds for filing a suspicious transaction report.
The obliged institution should first carry out a comprehensive risk assessment to determine whether breaches of the TFR information requirements, such as attempts to circumvent thresholds or lack of cooperation by another provider, may justify filing a report concerning a suspicious transaction or suspicious circumstances.
In practice, a breach of the TFR information requirements should first be analysed as a transaction carried out in an unusual manner. This means that the obliged institution should clarify the circumstances of the transaction, apply customer due diligence measures, assess the business relationship with the customer, the purpose of the transaction, the source of the assets involved, and whether the transaction is consistent with the customer’s profile and assigned AML/CFT risk.
Only if the analysis confirms a suspicion of money laundering or terrorist financing should the obliged institution file a notification with GIIF. Such a notification will also need to indicate the link with the TFR breach. GIIF has announced that a dedicated field will be added in the goAML system to mark this circumstance.
Travel Rule Procedures: Key Compliance Checks After the GIIF Communication
Entities subject to the TFR should first check whether their Travel Rule procedures provide for actual technical verification of control over unhosted addresses. If the current process relies on customer declarations, screenshots or declarations submitted through a form, it should be changed.

Following the GIIF Communication, entities should check in particular:
- whether the AML/CFT procedure or a separate TFR procedure describes how unhosted addresses are verified;
- whether the transaction system allows the entity to collect and retain evidence of technical control over the address;
- whether the process for handling missing TFR data does not result in automatic reporting of every case to GIIF;
- whether the AML team is able to distinguish a formal TFR breach from a situation that actually gives rise to suspicion of money laundering or terrorist financing;
- whether the procedure provides for the analysis of unusual transactions, the application of appropriate customer due diligence measures and proper documentation of conclusions;
- whether the rules for returning funds in the case of a rejected transfer ensure that the funds are returned to an address actually controlled by the originator of the transfer;
- whether the organisation has taken into account the new form in the SIGIIF system used to inform GIIF about the failure to provide information required under the TFR.
Risks of Non-Compliance with the Travel Rule: Supervisory Scrutiny, Reporting Failures and AML/CFT Liability
The main risk concerns supervisory inspections. If an obliged institution cannot demonstrate that it actually verifies the customer’s control over an unhosted address, the supervisory authority may challenge the effectiveness of the Travel Rule procedure and, more broadly, the manner in which the institution performs its AML/CFT obligations.
Relying solely on customer declarations or screenshots will be particularly risky, given that GIIF has expressly stated that such methods are not acceptable.
The second risk concerns reporting. Automatically reporting every TFR breach to GIIF may indicate the absence of proper risk analysis. Conversely, failing to report a case where a TFR breach is accompanied by other risk factors may be assessed as improper performance of AML/CFT obligations.
In practice, obliged institutions should be ready to show the authority not only the procedure itself, but also evidence that it is actually applied: internal documentation, including analytical notes, compliance/AMLRO decisions, documentation explaining the unusual transaction, and the rationale for why a report to GIIF was or was not required in a given case.
Our Support in Adapting Travel Rule Procedures
GIIF Communication No. 113 confirms that entities subject to the Travel Rule should technically verify customer control over unhosted wallets and should not rely solely on customer declarations or screenshots.
The guidance also underlines that TFR breaches should be assessed on a risk-based basis before filing a suspicious transaction report. PSPs, CASPs and other obliged institutions should now review their Travel Rule, AML/CFT and transaction monitoring procedures to ensure they meet GIIF and EBA expectations.
Need to update your Travel Rule procedures after the latest GIIF Communication? Our team can help you review your current process, design technical wallet verification rules and align your AML/CFT reporting framework with GIIF and EBA expectations. Contact us to discuss how we can support your organisation.