Funds transfer information under Regulation (EU) 2023/1113 — the intra-EU shortcut and the three-day clock
Inside the Union a credit transfer only has to carry two account numbers. The full payer and payee dataset has to be produced on request — within three working days. Regulation (EU) 2023/1113 is best known for the crypto travel rule, but its first chapters govern ordinary transfers of funds, and they work on a different logic: a reduced intra-Union dataset, a three-working-day retrieval duty, a EUR 1,000 dividing line for verification, and a repeat-offender ladder that ends in terminating a correspondent relationship. This walks through the payer-side and payee-side obligations and the numbers that separate them.
1. What the payer’s PSP must attach
Article 4 sets the full dataset. The payer’s payment service provider must ensure that transfers of funds are accompanied by the following information on the payer: the name; the payment account number; the address including the name of the country, official personal document number and customer identification number, or alternatively the date and place of birth; and — subject to the existence of the necessary field in the relevant payments message format, and where provided by the payer — the current LEI or, in its absence, any available equivalent official identifier.
On the payee side Article 4(2) requires the name, the payment account number, and the same conditional LEI field. Where the transfer is not made to or from a payment account, Article 4(3) substitutes a unique transaction identifier for the account number.
Article 4(4) requires the payer’s PSP to verify the accuracy of the payer information before transferring funds, on the basis of documents, data or information obtained from a reliable and independent source. Article 4(5) deems that verification to have taken place where the payer’s identity has been verified under Article 13 of Directive (EU) 2015/849 and the information retained under Article 40 of that directive, or where Article 14(5) of that directive applies to the payer — so ordinary customer due diligence discharges it, provided the retention side is in order.
2. Inside the Union: two numbers, then three working days
Article 5(1) is the derogation that shapes European payment infrastructure. Where all payment service providers in the payment chain are established in the Union, transfers need only be accompanied by at least the payment account number of both payer and payee — or the unique transaction identifier where Article 4(3) applies — without prejudice to the information requirements in Regulation (EU) No 260/2012.
The information does not disappear; it becomes retrievable on demand. Article 5(2) requires the payer’s PSP, within three working days of receiving a request from the payee’s PSP or an intermediary PSP, to make available:
- for transfers exceeding EUR 1,000 — whether in a single transaction or in several transactions which appear to be linked — the full Article 4 information on the payer or the payee;
- for transfers not exceeding EUR 1,000 that do not appear to be linked to other transfers which together exceed EUR 1,000 — at least the names of payer and payee and their payment account numbers, or the unique transaction identifier.
Article 5(3) then relaxes verification for that second category: the payer’s PSP need not verify the payer information unless it has received the funds in cash or in anonymous electronic money, or has reasonable grounds for suspecting money laundering or terrorist financing.
The three-working-day clock is the operational obligation firms underestimate. It is a service-level commitment to other PSPs, enforced by regulation, and it requires the full dataset to be retrievable per transaction — including the linkage logic that determines whether a sub-EUR 1,000 transfer sits inside a linked set.
3. Leaving the Union, and batch files
Article 6(1) handles batch processing. For a batch file transfer from a single payer where the payees’ PSPs are established outside the Union, Article 4(1) does not apply to the individual transfers bundled inside it — provided the batch file itself contains the Article 4(1), (2) and (3) information, that information has been verified under Article 4(4) and (5), and the individual transfers carry the payer’s payment account number or the unique transaction identifier.
Article 6(2) mirrors the small-value treatment outbound: where the payee’s PSP is established outside the Union, transfers not exceeding EUR 1,000 that do not appear to be linked to others exceeding that figure need carry only the names of payer and payee and their account numbers or the unique transaction identifier — with the same cash, anonymous-e-money and suspicion carve-outs to the verification relief.
| Scenario | What must accompany the transfer | Verification of payer data |
|---|---|---|
| All PSPs in the Union | Account numbers of payer and payee (or unique transaction identifier) | Full Article 4 data on request within 3 working days; verification relaxed below EUR 1,000 unless cash, anonymous e-money or suspicion |
| Payee’s PSP outside the Union, above EUR 1,000 | Full Article 4(1) and (2) dataset | Required before transfer |
| Payee’s PSP outside the Union, at or below EUR 1,000 and unlinked | Names and account numbers, or unique transaction identifier | Not required unless cash, anonymous e-money or suspicion |
| Batch file to outside the Union | Full dataset on the batch file, verified; account number or unique transaction identifier on each individual transfer | Required at batch level |
4. The payee’s PSP: detection, then verification
Article 7(1) requires the payee’s PSP to implement effective procedures to detect whether the payer and payee information fields in the messaging or payment and settlement system have been filled in using characters or inputs admissible in accordance with the conventions of that system. This is a syntactic control — a field stuffed with placeholder text or invalid characters is a detectable defect independent of whether the field is populated.
Article 7(2) then requires effective procedures, including where appropriate monitoring after or during the transfers, to detect whether information is missing — with a different dataset depending on where the payer’s PSP sits: the Article 5 information where it is established in the Union; the Article 4(1)(a), (b) and (c) and Article 4(2)(a) and (b) information where it is established outside the Union; and the same for a batch file transfer from outside the Union.
Verification on the receiving side is split at the same figure. Under Article 7(3), for transfers exceeding EUR 1,000 — single or apparently linked — the payee’s PSP must verify the accuracy of the payee information before crediting the payee’s payment account or making the funds available, on the basis of documents, data or information from a reliable and independent source, without prejudice to Articles 83 and 84 of Directive (EU) 2015/2366. Under Article 7(4), below that figure and unlinked, verification is not required unless the PSP effects pay-out in cash or anonymous electronic money or has reasonable grounds for suspicion. Article 7(5) deems verification done where the payee’s identity was verified under Article 13 of the AML directive with retention under Article 40, or where Article 14(5) applies.
5. Missing information: reject, request, or escalate
Article 8(1) requires the payee’s PSP to implement effective risk-based procedures, including procedures on the risk-sensitive basis referred to in Article 13 of the AML directive, for determining whether to execute, reject or suspend a transfer lacking complete payer and payee information, and for taking appropriate follow-up action.
Where the PSP becomes aware on receipt that the required information is missing, incomplete, or not filled in using admissible characters, it must, on a risk-sensitive basis, either reject the transfer or request the required information before or after crediting the payee’s account or making the funds available. Both branches are available; what is not available is doing neither.
Facts: a firm receives inbound transfers from a non-EU correspondent where the payer address field is systematically populated with the correspondent’s own head-office address. Values are mostly under EUR 1,000. Operations treats the field as present and processes normally.
What the rule says: Article 7(2)(b) requires detection of missing Article 4(1)(c) information for transfers where the payer’s PSP is outside the Union, and Article 7(1) requires detection of fields not filled in according to system conventions. A constant, obviously non-specific address is the pattern those procedures exist to find, and Article 8(1) then requires a risk-based reject-or-request decision.
What the practitioner does: builds a pattern control rather than a presence control — the same address across unrelated payers is the signal — and takes the Article 8(2) route below rather than absorbing the defect indefinitely.
Article 8(2) is the escalation ladder, and it contains the duty most correspondent policies omit. Where a payment service provider repeatedly fails to provide the required information, the payee’s PSP must either take steps that may initially include issuing warnings and setting deadlines before proceeding to rejection, restriction or termination, or directly reject any future transfers from that PSP, or restrict or terminate the business relationship with it. And then: the payee’s PSP shall report that failure, and the steps taken, to the competent authority responsible for monitoring compliance with AML/CFT provisions.
That report is a duty owed to the supervisor about another PSP’s conduct, and it is separate from any suspicious transaction report. Article 9 handles the FIU side: the payee’s PSP must take missing or incomplete information into account as a factor when assessing whether a transfer or related transaction is suspicious and reportable to the FIU. Two different filings, two different triggers.
Facts: after repeated warnings, a correspondent still sends transfers without complete payer data. The firm restricts the relationship and closes the file internally.
What the rule says: restriction is a permitted response under Article 8(2)(b), but the paragraph also requires the failure and the steps taken to be reported to the competent AML/CFT authority. Closing the file internally satisfies half the obligation.
What the practitioner does: wires the report into the same workflow as the restriction decision, so the supervisory notification cannot be forgotten once the commercial problem is solved — and keeps the Article 9 suspicion assessment as a separate step rather than treating the two as alternatives.
6. FAQ
What must accompany an intra-EU credit transfer?
At least the payment account numbers of payer and payee, or a unique transaction identifier where the transfer is not to or from a payment account — provided every PSP in the chain is established in the Union.
How quickly must the full information be provided on request?
Within three working days of receiving a request from the payee’s PSP or an intermediary PSP, under Article 5(2).
What does the EUR 1,000 figure do?
It divides the datasets and the verification duties. Above it — including several transactions that appear linked — the full Article 4 information and verification apply. At or below it and unlinked, a reduced dataset applies and verification is not required unless there is cash, anonymous electronic money, or suspicion.
Is the LEI mandatory?
It is conditional: required subject to the existence of the necessary field in the relevant payments message format and where the payer provided it to its PSP. It is the field implementations most often skip because it is not absolute.
Can we credit the account and then ask for missing data?
Yes, on a risk-sensitive basis. Article 8(1) permits requesting the required information before or after crediting, as an alternative to rejecting the transfer.
Do we have to report a counterparty that keeps sending incomplete data?
Yes. Article 8(2) requires the failure and the steps taken to be reported to the competent authority responsible for AML/CFT compliance — a duty distinct from any FIU report under Article 9.
7. What to do, today
- Test the three-working-day retrieval end to end. It is a regulated response time, and it needs the linkage logic for sub-EUR 1,000 sets, not just a per-transaction lookup.
- Implement Article 4(6) as a block, not a warning: outbound transfers must not execute before full compliance, subject to the Article 5 and 6 derogations.
- Add pattern controls to field-presence controls. A populated field that is identical across unrelated payers is what Article 7(1) and 7(2) are aimed at.
- Wire the Article 8(2) supervisory report into the counterparty-restriction workflow, so it fires when the commercial decision is taken.
- Keep the Article 9 suspicion assessment separate — missing information is a factor in the suspicion analysis, not a substitute for it.
- Check batch-file structure against Article 6(1): full verified dataset on the file, account number or unique transaction identifier on every individual transfer inside it.
Related: The crypto travel rule under the same regulation · Sanctions screening in instant payments · Verification of Payee under the IPR · The EU AML package — AMLR, AMLD6 and AMLA


