>_ Analyst Engineering

Funds Transfer Regulation (EU) 2023/1113: The Travel Rule in pacs.008

Written by Ahmed at Analyst Engineering, a Senior Technical Business Analyst with 10+ years in banking and payments delivery.

Cover for a guide to the EU Funds Transfer Regulation, showing payer and payee information mapped onto the Debtor and Creditor blocks of a pacs.008.

Key takeaways

  • Regulation (EU) 2023/1113 has applied since 30 December 2024 and replaced Regulation (EU) 2015/847. It requires the payer's bank to send the payer's name, account number, address with country (or the listed alternatives), and LEI where the format has a field, plus the payee's name, account number, and LEI, with every transfer of funds in any currency.
  • Inside the Union the minimum that must travel is lighter: the account numbers of payer and payee, without prejudice to SEPA rules. The full set must be produced within three working days on request, for transfers above EUR 1,000.
  • The payee's bank and every intermediary must detect missing, incomplete, and meaningless information and inadmissible characters, then decide on a risk basis to reject, suspend, or execute and request the data. Intermediaries must keep all payer and payee information with the transfer, which makes truncation a regulatory defect.
  • The same regulation brought crypto-asset transfers into scope from 30 December 2024, with no de minimis threshold for the accompanying information, and with specific duties for transfers to and from self-hosted addresses above EUR 1,000.
  • FATF adopted a revised Recommendation 16 on 18 June 2025: standardised name, address, and date of birth for cross-border peer-to-peer payments above USD or EUR 1,000, clearer responsibilities along the chain, and required tools against fraud and error. The changes come into effect by the end of 2030.

Regulation (EU) 2023/1113, the EU Funds Transfer Regulation or travel rule, requires every transfer of funds touching an EU payment service provider to carry the payer’s name, account number, address with country (or the listed alternatives), and LEI where a field exists, plus the payee’s name, account number, and LEI. In a pacs.008 that is Dbtr, DbtrAcct, Dbtr/PstlAdr, Dbtr/Id, Cdtr, and CdtrAcct. The payee’s bank and every intermediary must detect what is missing or meaningless and decide to reject, suspend, or request it.

The travel rule is the regulation that turns ISO 20022 data quality into a legal obligation. Before it, a cross-border payment arriving with NAME UNKNOWN in the debtor name was an operational nuisance. Under it, that payment is a transfer with missing information that your bank must detect, decide on, and possibly report, and the counterparty that keeps sending them is one you may have to restrict.

This belongs to the field-by-field track of The ISO 20022 Reference, next to sanctions screening, because both controls read the same party blocks for different reasons.

What is Regulation (EU) 2023/1113, and when did it start?

It is the recast EU regulation on information accompanying transfers of funds and certain crypto-assets. It was published in the Official Journal on 9 June 2023, applies from 30 December 2024, and repealed Regulation (EU) 2015/847 from that date. Practitioners often call it FTR, or FTR3 in EPC documents.

Scope, from Article 2:

  • Transfers of funds in any currency sent or received by a payment service provider or intermediary established in the Union. Credit transfers, direct debits, money remittances, and transfers made with cards or phones are all “transfers of funds”.
  • Transfers of crypto-assets where the crypto-asset service provider (CASP) of the originator or beneficiary has its registered office in the Union.

Exclusions that matter for requirements:

  • A card, e-money instrument, or phone used exclusively to pay for goods or services, with the card or device number accompanying the transfer. Person-to-person transfers made with those instruments are back in scope.
  • Cash withdrawal from the payer’s own account.
  • Transfers to a public authority for taxes, fines, or levies within a Member State.
  • Transfers where both payer and payee are payment service providers acting on their own behalf.

What information must accompany a transfer of funds?

Article 4 sets the full set. The payer’s bank must not execute the transfer until it complies, and must verify the payer information against a reliable and independent source (satisfied where customer due diligence already verified it).

PartyRequired informationCondition
PayerNameAlways
PayerPayment account numberOr a unique transaction identifier if no account
PayerAddress including country, official personal document number and customer identification number, or alternatively date and place of birthAlways
PayerCurrent LEI, or an equivalent official identifierWhere the message format has the field and the payer provided it
PayeeNameAlways
PayeePayment account numberOr a unique transaction identifier if no account
PayeeCurrent LEI, or an equivalent official identifierWhere the format has the field and the payer provided it

The payer address row is the one programmes argue about. The EBA guidelines treat its items as alternatives to be combined, chosen not only on availability but on the set that “best provides for an unambiguous identification” of the payer. Get compliance to write down which combination your bank sends for natural persons and for legal persons, then build to that decision.

Two lighter regimes sit on top:

Inside the Union (Article 5). Where every payment service provider in the chain is established in the Union, the transfer needs at least the payment account numbers of payer and payee, without prejudice to SEPA requirements. On request from the payee’s bank or an intermediary, the payer’s bank must provide the full Article 4 information within three working days for transfers above EUR 1,000 (single or linked), or at least names and account numbers below that.

To outside the Union (Article 6). Transfers not exceeding EUR 1,000 that do not appear linked to others need at least the names and account numbers of payer and payee. Above that, the full set travels. Batch files to payees outside the Union can carry the full payer information once at batch level.

How does that map to pacs.008 fields?

The regulation is format neutral, so the mapping is your bank’s decision. This is the one I start from, for pacs.008.001.08 as used in SEPA and CBPR+:

Regulation itempacs.008 element
Payer nameCdtTrfTxInf/Dbtr/Nm
Payer accountDbtrAcct/Id/IBAN (or Othr/Id)
Payer address and countryDbtr/PstlAdr with StrtNm, BldgNb, PstCd, TwnNm, Ctry
Official personal document numberDbtr/Id/PrvtId/Othr/Id with SchmeNm/Cd such as NIDN or CCPT
Customer identification numberDbtr/Id/PrvtId/Othr/Id with SchmeNm/Cd = CUST
Date and place of birthDbtr/Id/PrvtId/DtAndPlcOfBirth (BirthDt, CityOfBirth, CtryOfBirth)
Payer LEIDbtr/Id/OrgId/LEI
Payee name, account, LEICdtr/Nm, CdtrAcct/Id/IBAN, Cdtr/Id/OrgId/LEI
Unique transaction identifierPmtId/UETR where the rail uses it, otherwise the scheme’s transaction reference
<Dbtr>
  <Nm>Anna Kowalska</Nm>
  <PstlAdr>
    <StrtNm>ul. Marszalkowska</StrtNm>
    <BldgNb>84</BldgNb>
    <PstCd>00-514</PstCd>
    <TwnNm>Warszawa</TwnNm>
    <Ctry>PL</Ctry>
  </PstlAdr>
  <Id>
    <PrvtId>
      <DtAndPlcOfBirth>
        <BirthDt>1984-03-12</BirthDt>
        <CityOfBirth>Krakow</CityOfBirth>
        <CtryOfBirth>PL</CtryOfBirth>
      </DtAndPlcOfBirth>
    </PrvtId>
  </Id>
</Dbtr>
<DbtrAcct><Id><IBAN>PL61109010140000071219812874</IBAN></Id></DbtrAcct>

Three mapping traps:

  • The payer is the account holder. The regulation defines the payer as the person who holds the payment account and allows the transfer. In a payment factory, that is Dbtr, not UltmtDbtr. Screening still reads the ultimate parties; the travel rule information goes on the debtor.
  • The address order of priority. The EBA guidelines list address components in priority order: country, postal code, city, state or province and municipality, street name, building number or name. A post office box or virtual address does not meet the requirement. That aligns with structured and hybrid addresses, covered in structured addresses.
  • The EPC rulebooks are moving towards this. Among the accepted changes for the 2028 SEPA Direct Debit rulebooks are usage rule changes on organisation and private identification to align further with the regulation. If your SEPA mapping of Id was “leave it empty”, plan for that changing.

How the identifiers themselves behave across a chain is in ISO 20022 identifiers.

What must the payee’s bank and intermediaries do?

Detect, decide, follow up, and remember. These obligations are where the system requirements are.

Detect (Articles 7 and 11). The payee’s bank and every intermediary must have effective procedures to detect whether the payer and payee fields were filled with characters admissible under the conventions of the system used, and whether required information is missing. Above EUR 1,000, the payee’s bank must verify the payee information before crediting the account.

The EBA guidelines make “missing” broader than empty. Information counts as missing if it is meaningless or incomplete, and at minimum the following are meaningless:

  • strings of random or illogical characters, such as xxxxx or ABCDEFG
  • titles without a name, such as Mrs
  • incoherent designations, such as An Other or My Customer

Banks that keep a list of such terms must review it periodically. That list is a requirement artifact with an owner.

Decide (Articles 8 and 12). On a risk-sensitive basis, reject the transfer, or request the missing information before or after crediting the payee (or, for an intermediary, before or after forwarding it). When rejecting, the guidelines say the prior bank in the chain should be told the transfer was rejected because of missing information. In ISO 20022 that is a pacs.002 reject, and the external codes RR01 (missing debtor account or identification), RR02 (missing debtor name or address), RR03 (missing creditor name or address), and RR04 (regulatory reason) exist for exactly this. Reason code handling is in ISO 20022 reason codes.

Follow up. When requesting information, the guidelines set a deadline of no more than three working days for transfers within the Union and five working days for transfers from outside, extendable to seven where the chain is long. A counterparty that repeatedly fails to provide information gets warnings and deadlines, then rejection of future transfers or restriction of the relationship, and the failure is reported to the competent authority. The guidelines expect quantitative criteria (the percentage of incomplete transfers and of unanswered requests per counterparty) and a report within three months of identifying a repeatedly failing provider.

Remember (Articles 10 and 26). Intermediaries must retain all payer and payee information received with the transfer. Banks of the payer and payee keep records for five years. And missing information is a factor in assessing whether a transfer is suspicious, though the guidelines are explicit that missing information alone does not create suspicion.

Article 10 is the clause to quote at a migration programme. An intermediary that drops a structured address, cuts a 140-character name to 35, or loses the Id block on a hop through a legacy system is failing to keep information with the transfer. Data truncation stops being a data quality topic and becomes a compliance one.

The method for turning a regulation like this into traceable requirements is in From Vague BR to Functional Requirements, and the payments domain behind it is in Break Into Banking.

How do direct debits fit?

Awkwardly, because the payer’s bank does not originate the transfer. The EBA guidelines resolve it: in a direct debit, the payee’s bank sends the payer and payee information to the payer’s bank as part of the collection. The payee’s bank takes on the Article 4 to 6 obligations and verifies the payee information before sending; the payer’s bank takes on the detection and decision obligations and verifies the payer information before debiting. For SEPA Direct Debit that means the pacs.003 debtor and creditor blocks carry the travel rule data, and the debtor bank’s missing-information handling becomes a reject or return. The scheme side is covered in SEPA Direct Debit for analysts.

What changed for crypto-assets?

The same regulation brought crypto-asset transfers into scope from 30 December 2024, under Articles 14 to 22.

  • The originator’s CASP must send the originator’s name, distributed ledger address and crypto-asset account number where used, address with country or the listed alternatives, and LEI where available, plus the beneficiary’s name, distributed ledger address or account number, and LEI.
  • The information does not have to be attached to the on-chain transfer, but must be submitted in advance of, or simultaneously with, it, securely.
  • There is no de minimis threshold for the information on crypto transfers, unlike the EUR 1,000 thresholds for funds.
  • For self-hosted addresses, the CASP must obtain and hold the information, and for transfers above EUR 1,000 assess whether the address is owned or controlled by its own customer.
  • A beneficiary CASP that finds information missing may reject the transfer or return the crypto-assets, or request the information before making them available.

For a bank analyst, the practical overlap is electronic money tokens, which the regulation treats as crypto-assets, and any product that moves value between bank accounts and crypto accounts.

What did FATF change in Recommendation 16 in June 2025?

The EU regulation implements FATF Recommendation 16, so the FATF revision is the next change on the horizon. On 18 June 2025 FATF published changes to Recommendation 16 on payment transparency, agreed at its June 2025 plenary. FATF’s summary of the changes:

  • Responsibilities in the chain. Who includes the information and who keeps it unchanged is clarified, and the payment chain starts with the institution that receives the customer’s instruction.
  • Standardised information. Cross-border peer-to-peer payments above USD or EUR 1,000 carry standardised information: name, address, date of birth.
  • Tools against fraud and error. Institutions must use technology such as verification of the recipient’s banking information. In the EU, Verification of Payee already does this for euro credit transfers.
  • Card transactions. Card purchases of goods and services stay exempt from the full requirements, with a clarified definition of what counts as a purchase.

FATF says the changes come into effect by the end of 2030, and in October 2025 it published an assessment methodology annex for how compliance will be evaluated. Treat it as a dependency: the EU will need to align its own rules, and the EPC has already started aligning rulebook usage rules. Current as of October 2026.

What test cases does the travel rule need?

Derive them from the articles, not from the schema. A starting set:

#ScenarioExpected result
1Outbound to a non-EU bank, EUR 1,000.01, full payer dataExecuted with name, account, address, and identifiers in Dbtr
2Outbound to a non-EU bank, EUR 1,000.00, unlinkedNames and accounts suffice
3Three linked outbound transfers of EUR 400 to the same non-EU payeeTreated as above EUR 1,000: full set
4Intra-EU transfer with accounts onlyExecuted
5Request from a payee bank for an intra-EU transfer of EUR 5,000Full payer data provided within three working days
6Inbound from outside the EU, Dbtr/PstlAdr absent and no alternativeDetected as missing; reject or request per policy
7Inbound with debtor name xxxxxDetected as meaningless
8Inbound with debtor name Mrs onlyDetected as meaningless
9Inbound with debtor name My CustomerDetected as meaningless
10Inbound with characters inadmissible on the railBlocked by validation and flagged for manual review
11Reject for missing debtor name or addresspacs.002 with RR02 to the prior bank
12Information requested, no answer in three working days (intra-EU)Follow-up action per policy
13Counterparty exceeds the repeated-failure thresholdWarning issued; escalation path triggered and logged
14Intermediary hop through a system with a 35-character name limitDefect: information not retained with the transfer
15Structured address in, hybrid or flattened address outDefect unless all components survive
16Legal entity payer with an LEI on fileDbtr/Id/OrgId/LEI populated
17Payment factory: treasury centre debtor, subsidiary ultimate debtorTravel rule data on Dbtr; both parties screened
18Joint account payerNames of all holders, or the initiating holder where the format limits it
19Card purchase of goodsOut of scope; no travel rule check
20Person-to-person transfer via cardIn scope
21Crypto transfer to a self-hosted address, EUR 1,500Ownership or control assessment recorded
22Inbound SEPA Direct Debit missing debtor nameDebtor bank rejects or requests per policy

Rows 14 and 15 are the ones that find real defects, because they test the platform rather than the payment. Run them through every hop in your chain, and use the field-level discipline from pacs.008 test cases to assert each element by XPath rather than by eye.

The takeaway

Regulation (EU) 2023/1113 has applied since 30 December 2024. It makes the debtor and creditor blocks of every pacs.008 a legal artifact: name, account, address with country or the listed alternatives, and LEI where a field exists, with a lighter account-number minimum inside the Union and EUR 1,000 thresholds for verification and for transfers leaving it. The payee’s bank and every intermediary must detect what is missing or meaningless, decide to reject or request, follow up within days, and escalate counterparties that keep failing.

For analysts, three requirements follow. Map each item to a specific element and get compliance to sign the address combination. Make sure no hop drops what it received, because that is an Article 10 breach. And put the 2030 FATF changes on the roadmap now. The rest of the field-by-field track is on The ISO 20022 Reference.

Ahmed is a Senior Technical Business Analyst with 10+ years in banking and payments. He builds practical guides and tools for analysts at The Tech BA Toolkit.

Tags: Regulation, Travel Rule, ISO 20022, Payments, AML, Compliance

About the author

Analyst Engineering is written by Ahmed, a Senior Technical Business Analyst with 10+ years of banking and payments delivery experience: ISO 20022 and SWIFT messaging, payments API integration, Kafka event validation, and production support. Every article comes from real delivery work, and each one is reviewed and updated as tools and standards change.

Go deeper on this

Not ready to buy? The free downloads are a no-cost place to start, and every article here stays free.

Free account

Practice on the Labs, keep your progress

A free account, no password: an email link signs you in. It saves your steps and self-assessments on the Labs, shows your missions on a dashboard, unlocks the solutions, and, if you tick the box, sends you new missions and articles when they ship.

Your email is used to sign you in. Nothing else, unless you ask. Privacy.