Pakistan flag and regulation clipboard on grey background

Pakistan's Travel Rule: What VASPs Need to Know

28 Sept, 2026

TL;DR

  • The Travel Rule applies to virtual asset transfers meeting or exceeding the PKR equivalent of USD 1,000.
  • Licensees must obtain, verify where required, and transmit or make available accurate originator and beneficiary information.
  • Required information includes names, account numbers or wallet addresses, and other identifiers where applicable.
  • Licensees must conduct risk-based due diligence on counterparty VASPs before establishing material transfer relationships and review this due diligence annually.
  • Licensees must maintain controls for incomplete or unreliable counterparty information, threshold evasion, and anonymity-enhancing technologies.
  • Specific controls apply to transfers involving self-hosted wallets, including wallet verification, sanctions screening, transaction monitoring and risk-based restrictions.


Understanding the Regulatory Obligations for Virtual Asset Service Providers

Pakistan has introduced its first comprehensive legal framework for virtual assets through the Virtual Assets Act, 2026.

The framework establishes requirements for Virtual Asset Service Providers (VASPs) and other regulated entities, with a strong focus on anti-money laundering (AML), counter-terrorist financing (CFT) and counter-proliferation financing (CPF) requirements.

These requirements include customer due diligence, transaction monitoring, record-keeping, sanctions screening, data security and Travel Rule compliance.

Pakistan's framework requires Licensees to comply with the Travel Rule and applicable requirements under the Federal AML-CFT Laws, including requirements implementing FATF Recommendation 16 and its Interpretive Note.


Scope of the Travel Rule in Pakistan

The framework applies to any VASP that carries out a virtual asset service in or from Pakistan. It also applies to Issuers that offer, originate or distribute a virtual asset on their own behalf in or from Pakistan.

It is important to distinguish between a VASP and a Licensee. Under Pakistan's virtual asset framework, a VASP is a person that, as a business, provides one or more virtual asset services to third parties on a professional basis. A Licensee is an entity that has obtained a licence under the Pakistani regulatory framework.

The Travel Rule applies to virtual asset transfers meeting or exceeding the threshold of the PKR equivalent of USD 1,000.

For transfers at or above this threshold, Licensees must obtain, verify where required, and transmit or make available the required and accurate originator and beneficiary information.


Required Travel Rule Data

For transfers meeting or exceeding the applicable threshold, the required information includes:

  • Originator's full name;
  • Originator's account number, virtual asset wallet address or another unique transaction identifier;
  • Additional identifiers required under applicable law, which may include an address, national identification number, customer identification number, or date and place of birth;
  • Beneficiary's name; and
  • Beneficiary's account number, virtual asset wallet address or another unique transaction identifier.

The framework therefore requires Licensees to have processes and systems capable of collecting, validating and transmitting Travel Rule information alongside the virtual asset transfer.


Obligations of Virtual Asset Service Providers

Licensees have a range of obligations supporting Travel Rule compliance and broader AML/CFT/CPF requirements. These obligations extend beyond the exchange of Travel Rule information and include counterparty due diligence, risk-based controls, transaction integrity, monitoring and the handling of transfers by both originator and beneficiary VASPs.


Counterparty Due Diligence and Risk-Based Controls

Before establishing a material relationship for virtual asset transfers with a counterparty VASP in another jurisdiction, Licensees must conduct risk-based due diligence on the counterparty's Travel Rule and AML/CFT controls. This due diligence must be reviewed annually and whenever heightened risk indicators arise. Licensees must also assess whether counterparties have appropriate controls in place to support compliant virtual asset transfers.

Licensees must maintain controls addressing risks associated with deposits and withdrawals where counterparty information is incomplete, unavailable or unreliable; transactions or patterns designed to evade thresholds or information requirements; and anonymity-enhancing features or services, where applicable.

These controls form part of the broader AML/CFT/CPF framework, which also covers customer due diligence, transaction monitoring, record-keeping, suspicious activity reporting and sanctions screening.


Transaction Integrity, Accuracy and Monitoring

Licensees must establish controls to ensure the integrity and accuracy of transfers and settlements. These include pre-execution validation of transfer instructions, verification of destination details, including wallet addresses and account identifiers, reconciliation between internal records and on-chain or account balances, and error-prevention measures appropriate to the business model.

Moreover, documented procedures for failed, delayed, erroneous and disputed transfers must be maintained. These procedures must cover identification and escalation, timely communication with affected clients and counterparties, remediation and, where appropriate, compensation arrangements.

A Licensee must not process a transfer instruction where available information creates a material concern that the destination is invalid, incomplete or inconsistent with the client's instruction, or otherwise presents a material risk of error, fraud, sanctions breach or loss, unless the issue is first resolved.

As part of these controls, Licensees must implement transaction monitoring systems capable of detecting suspicious patterns and unusual activities. Where suspicious transactions or activities are identified, they must be reported to the Financial Monitoring Unit (FMU) in accordance with the applicable AML/CFT framework


Self-hosted Wallets 

Pakistan's framework specifically requires Licensees to establish and maintain controls governing transfers involving external wallets, including self-hosted wallets.

These controls may cover:

  • Wallet verification;
  • Sanctions screening;
  • Travel Rule compliance;
  • Transaction monitoring;
  • Source and destination checks; and
  • Risk-based restrictions.

Licensees must apply risk-based controls to transfers involving self-hosted wallets and other non-obliged persons, in line with relevant FATF Standards and guidance. Transfers involving self-hosted, unverified or non-compliant wallets may only proceed where they meet the controls, conditions, restrictions or approvals set by the Authority.

The Authority may also restrict or prohibit transfers involving self-hosted wallets, privacy-enhancing technologies, anonymising protocols, mixers, cross-chain bridges or other arrangements that reduce regulatory visibility, AML/CFT/CPF compliance or transaction traceability.


21 Analytics and Pakistan’s Travel Rule 

21 Analytics helps Pakistani VASPs meet Travel Rule requirements by addressing key compliance challenges around interoperability, counterparty due diligence, data control and transfers involving self-hosted wallets.

Through native connectivity to TRUST, which connects a broad network of VASPs and major exchanges, as well as alternatives such as TRP, 21 Travel Rule enables Pakistani VASPs to exchange the required originator and beneficiary information with counterparties across different Travel Rule ecosystems. 

The solution also supports Pakistan’s counterparty due diligence requirements through automated VASP discovery and counterparty information, helping VASPs assess whether counterparties have appropriate Travel Rule and AML/CFT controls in place before establishing a material relationship.

For transfers where required information is incomplete, unavailable or unreliable, 21 Travel Rule provides the controls needed to identify and manage non-compliant transfers before they proceed. Combined with transaction monitoring and risk-based compliance workflows, this helps VASPs address the risks associated with incomplete Travel Rule information and potentially suspicious transactions.

Pakistan’s framework also requires Licensees to apply risk-based controls to transfers involving self-hosted wallets and other non-obliged persons. 21 Travel Rule supports self-hosted wallet verification through the AOPP Portal.

As an on-premises solution, 21 Travel Rule allows Pakistani VASPs to retain control over sensitive Travel Rule information within their own infrastructure. Peer-to-peer data exchange means 21 Analytics does not need to host or access customer Travel Rule data, supporting data control, security and governance requirements while reducing reliance on centralised data storage.

Together, these capabilities provide Pakistani VASPs with the infrastructure to manage Travel Rule information, assess counterparties, handle self-hosted wallet transfers and maintain risk-based controls in line with Pakistan’s virtual asset regulatory framework.

Become Travel Rule Compliant with 21 Analytics

Request a Demo


Further Reading 

Pakistan Virtual Asset Services Regulations, 2026 (S.R.O. 1419(I)/2026)

Pakistan Virtual Asset Regulatory Authority Notification (S.R.O. 1420(I)/2026)

The Virtual Assets Act, 2026

Pakistan Federal AML-CFT Laws

Pakistan’s Travel Rule Summary

Info Circle Outlined Icon

Disclaimer

This material is provided for educational and informational purposes only and is not intended to be a substitute for professional advice or detailed research.

Written by:
About Nicole
Content & Social Media Manager
With an Honours in English Linguistics, Nicole started her career as an educator before transitioning to education management and curriculum development.  Thereafter, she moved to crypto writing - uniting her passion for education with crypto to educate the ecosystem on the Travel Rule.
X
Trust Graphic

New: TRUST Network

Transact with Coinbase, Kraken, Gemini and others.