News
JERSEY
JFSC
news image Published on : 22/09/2026

Progress on the Jersey VASPs Travel Rule, but interoperability and the “sunrise” problem still bite

The Jersey Financial Services Commission (JFSC) published industry feedback on 14 September 2026, based on its 2025 supervisory engagement with a sample of virtual asset service providers (VASPs).

The work followed an earlier assessment in 2024, after the Travel Rule was brought into Jersey legislation.

Primary JFSC pages:

This article is a single reading of that feedback, plus the interoperability analysis that the same findings require.

  • The official pages above are the documents to verify.

  • Related JFSC material from 2024–2025 is cited where it shows what has actually changed.

What has improved

Implementation is better than in 2024. Firms now have policies, procedures and controls in place, and Travel Rule requirements are more often embedded in daily operations. VASPs generally understood their obligations and could explain how they meet them.

That is a genuine shift from the 2024 bitesize feedback, when the JFSC still found gaps in documented in-scope and out-of-scope assessments, procedures for jurisdictions without the Travel Rule, and understanding of intermediary VASP models.

What still does not work cleanly

The JFSC is explicit: remaining problems mainly reflect wider virtual-asset market structure and uneven adoption abroad, not a uniquely Jersey failure. Two themes dominate. They are related. They are not the same.

1. Interoperability

Different Travel Rule solutions are in use across the sector, particularly where those solutions do not work together. Choice of provider often depends on where the firm operates, local market adoption, what counterparties use, cost and scalability.

The JFSC observed that:

  • Travel Rule solutions do not always interact seamlessly

  • Compatibility problems push firms onto manual processes

  • Delays in information-sharing can delay funds being made available to customers

Firms responded by:

  • Periodically assessing jurisdictions, counterparties and customers, and whether extra solutions are needed

  • Adopting solutions matched to size, business model, volumes and customer profile, and reviewing them

  • Applying risk-based procedures and documenting why a transaction proceeds or is rejected

  • Considering jurisdiction, customer and VASP profiles where information cannot be exchanged automatically

Interoperability is not sunrise. Sunrise is: the counterparty is not legally or operationally ready to exchange data. Interoperability is: both sides are ready, but the systems still cannot pass the data. Mixing the two lets a firm blame “the rest of the world” for what is often a vendor and architecture choice.

FATF does not require tools to interoperate. It does say lack of interoperability creates friction and can reduce a VASP’s ability to comply. It does not accept that friction as a reason to send value without the required information.

Travel Rule compliance is a stack. Each layer can fail on its own.

Counterparty discovery. The originating VASP sees a blockchain address, not an institution. There is still no exhaustive, reliable way to identify from the address alone which VASP, if any, controls it. FATF has said so. If discovery fails, firms often treat the destination as an unhosted wallet. That is a compliance error, not a protocol error. FATF has published that failure mode.

Messaging protocol. Competing protocols include TRP, TRISA, Sygna Bridge, CODE/CodeVASP, GTR, TRUST, Veriscope and vendor-native meshes. Some are open; some are closed consortia. IVMS101 is a common data model, not a common network. Sharing a schema does not mean two systems can route, authenticate or confirm a message.

Vendor product. Pairwise bridges exist (TRISA–TRP, TRISA–Sygna, multi-protocol gateways). Coverage is still incomplete, asset lists differ, and “live” on a marketing page is not a confirmed message on a live withdrawal. The UK FCA required a firm to add a second tool because the first neither covered listed tokens nor interoperated adequately. That example is in FATF’s 2025 supervisory best-practice paper.

Legal payload. Thresholds and required fields still differ (EU Transfer of Funds Regulation / MiCA: generally no de minimis for CASPs; US FinCEN still uses a higher threshold for many comparable transfers; other jurisdictions sit in between). A technical handshake can still fail a legal completeness check.

Timing. On-chain settlement is fast. Travel Rule exchange is often slower, especially when fallback is email, a portal or a manual request. That is why the JFSC saw delays in making funds available.

Solution choice follows geography, counterparties, cost and scale. That is rational. It still produces islands. Incompatible tools force manual exchange. Manual work does not scale, is hard to evidence, and is where data quality and timing fail. Delayed information-sharing is an AML issue, a conduct issue and an operational-resilience issue.

FATF notes that many VASPs buy reach by running several tools at once. That helps coverage. It creates a second problem: reconciling data, policies and audit trails between the firm’s own tools. Multi-homing is a workaround, not a standard.

Closed networks make this worse. If the destination VASP sits only on a consortium you have not joined, the tool may report “no VASP found”. Treating that as unhosted is a known supervisory finding.

The Jersey responses are sensible as far as they go. They are not sufficient if left vague.

Periodic counterparty review is not the same as discovering the VASP on this transaction. Directories go stale. A quarterly scan will not catch a new destination wallet on a Friday afternoon.

“Appropriate to size and business model” can become an excuse for thin coverage. A small Jersey VASP on one regional protocol will systematically fail into another protocol cluster. Size does not change the legal duty to transmit data when the rule applies.

Risk-based proceed-or-reject needs a written standard. If two similar transfers get opposite outcomes because officers judged “manual effort too high”, that is inconsistent application of the Wire Transfer Regulations, not proportionality.

Manual fallback is a control only if it is tested: how long a request takes; what happens if there is no reply; whether the asset is held, returned or released; who signs off; whether the decision is on file. Interoperability failures generate the same extra cost the JFSC already noted on the sunrise side — more often, with counterparties who should have been reachable.

If information cannot move, liquidity cannot move cleanly. Customers see held withdrawals. Firms then face a commercial incentive to release funds before data arrives. That incentive is the real risk. “The protocols don’t talk” will not impress a supervisor if value was released anyway.

There is still no SWIFT equivalent for VASP-to-VASP identity data. Vendor claims of “largest network” or “five protocols” are marketing metrics. They do not prove that your top twenty counterparties confirm messages before settlement. Demand success rate, median time-to-confirm, assets supported and fail reasons for your corridors.

2. Cross-border implementation (the sunrise issue)

Travel Rule legislation is more widespread, but jurisdictions still differ in supervisory maturity, enforcement and operational readiness. Firms still meet counterparties that cannot operationalise the exchange even where a statute exists.

The JFSC observed that:

  • Information requirements and implementation still differ across jurisdictions

  • The ability of some counterparties to exchange the required information remains inconsistent

Firms responded by:

  • Tracking how far jurisdictions and counterparties have actually implemented the rule, and the associated risks

  • Applying a risk-based approach at the point of transaction, including enhanced scrutiny, mitigation or avoidance

  • Using approved-counterparty and whitelist arrangements where originator and beneficiary information is already available

  • Carrying out reviews and risk assessments where information cannot be obtained — work the JFSC recognises consumes extra resource

Legislation is spreading faster than operational, interoperable compliance. That explains friction. It does not excuse weak Jersey controls.

Application of the requirements is still muddled

Some senior managers treated ordinary onboarding and customer due diligence as enough for Travel Rule purposes, with little distinction between the two. Others interpreted the rule differently for certain transaction types, including intermediary VASP models. The JFSC flags a training need.

Firms responded by embedding Travel Rule work in business risk assessments, compliance monitoring and transaction processing, and by reviewing policies, procedures and training against JFSC guidance.

The Commission says it will keep working with firms on business models and in-scope transactions, and will publish further guidance. It last updated the Travel Rule guidance note on 14 November 2025 (first issued 5 February 2024). That update added detail on intermediary VASPs and restated the expectation that Jersey remain among the more advanced implementers.

A critical reading

Progress since 2024 is real if the sample is representative. The published feedback does not give sample size, selection method or how many firms still rely on manual workarounds. “Improved across the sector” is a supervisory judgement, not a census.

The remaining issues are structural:

  • Protocol fragmentation and vendor lock-in will keep producing manual work and delayed payouts until tools interoperate or a dominant path wins.

  • Sunrise is not a footnote. A ready Jersey VASP can still fail to obtain data from a counterparty in a jurisdiction that has a statute and little operational capacity.

  • Treating CDD files as Travel Rule transmission is a governance failure. Boards should treat that as a training and oversight finding.

  • Extra reviews cost money. Smaller VASPs feel it first. “Risk-based” must not mean inconsistent.

Jersey’s legal hook remains the EU Legislation (Information Accompanying Transfers of Funds) (Jersey) Regulations 2017 (the Wire Transfer Regulations), extended to VASPs from 1 September 2023. The guidance note is the practical statement of expectations. Read the 14 September 2026 feedback against that note, not instead of it.

What a serious Jersey VASP should test

Map flows, not vendors.

  • For each material corridor: destination jurisdiction, typical counterparty tools, protocol path, confirmation rate, fallback, hold or release rule.

  • Prove discovery: how hosted VASP wallets are distinguished from unhosted before Travel Rule messaging is skipped.

  • Prove reconciliation if more than one solution is in use.

  • Prove that senior management do not treat CDD as a substitute for per-transfer originator and beneficiary transmission.

  • Treat interoperability failure as an operational incident when it delays customer funds or forces a policy override.

The November 2025 guidance already expected a functioning solution that can be demonstrated. The 2026 feedback shows demonstration now includes what happens when that solution cannot reach the other side.

Sources

JFSC — this update

JFSC — Travel Rule framework and earlier feedback

International and industry context

Vendor pages describe their own networks. Use them to understand market structure. Do not treat claimed VASP counts as proof that your counterparties are reachable.

JERSEY JFSC

The Team

Meet the team of industry experts behind Comsure

Find out more

Latest News

Keep up to date with the very latest news from Comsure

Find out more

Gallery

View our latest imagery from our news and work

Find out more

News Disclaimer

As well as owning and publishing Comsure's copyrighted works, Comsure wishes to use the copyright-protected works of others. To do so, Comsure is applying for exemptions in the UK copyright law. There are certain very specific situations where Comsure is permitted to do so without seeking permission from the owner. These exemptions are in the copyright sections of the Copyright, Designs and Patents Act 1988 (as amended)[www.gov.UK/government/publications/copyright-acts-and-related-laws]. Many situations allow for Comsure to apply for exemptions. These include 1] Non-commercial research and private study, 2] Criticism, review and reporting of current events, 3] the copying of works in any medium as long as the use is to illustrate a point. 4] no posting is for commercial purposes [payment]. (for a full list of exemptions, please read here www.gov.uk/guidance/exceptions-to-copyright]. Concerning the exceptions, Comsure will acknowledge the work of the source author by providing a link to the source material. Comsure claims no ownership of non-Comsure content. The non-Comsure articles posted on the Comsure website are deemed important, relevant, and newsworthy to a Comsure audience (e.g. regulated financial services and professional firms [DNFSBs]). Comsure does not wish to take any credit for the publication, and the publication can be read in full in its original form if you click the articles link that always accompanies the news item. Also, Comsure does not seek any payment for highlighting these important articles. If you want any article removed, Comsure will automatically do so on a reasonable request if you email info@comsuregroup.com.  

Archived News

To find our older articles, please click here.

View archive