Moving beyond policy to production
Most VASPs have policy statements; fewer have reliable, automated data exchange. These are the
field‑tested lessons from teams that made the Travel Rule work at scale.
Top lessons
- Choose an interop path and document why (TRP/IVMS101/other).
- Screen Travel Rule data the same way you screen the transaction.
- Decide unhosted‑wallet policy—allow, restrict, or block with evidence.
- Handle sunrise gaps with counterparty attestations and tiered limits.
- Log exceptions as case records with analyst decisions.
- Encrypt & sign payloads; don’t send PII via ad‑hoc channels.
- Monitor deliverability (bounces/timeouts) as a compliance KPI.
- Prove control of sending/receiving addresses where feasible.
- Train support teams to handle Travel Rule‑related customer queries.
- Test fail‑safes—does the transfer halt when data is missing?
Outcome: aim for a weekly dashboard showing % transfers covered, exceptions, and
time‑to‑resolution by counterparty.