Brazil has emerged as one of Latin America's most active digital-asset markets, and its anti-money laundering regime has kept pace. For any business operating a virtual asset service provider (VASP) function in or into Brazil – whether an exchange, custodian, payment facilitator or token issuer – the question is not whether an AML/CFT policy is required, but how demanding the requirement has become and what a deficient policy costs. Operating without adequate controls risks enforcement action, frozen correspondent-banking rails and reputational damage that closes doors well beyond Brazil's borders.
Brazil's primary VASP supervision now sits with the Banco Central do Brasil (BCB), which assumed authority over crypto-asset service providers following the enactment of the Virtual Assets Act. The BCB's AML/CFT expectations draw directly on FATF Recommendation 15 and its guidance on virtual assets, meaning the framework is internationally legible but locally enforced. This page maps the regulated basis, the drafting obligations, the Travel Rule interaction, and the cross-border reality any inbound operator must manage.
What is the regulated basis for AML/CFT obligations in Brazil?
Brazil's AML/CFT regime for virtual assets rests on the country's principal anti-money laundering law – the framework sometimes called the AML Law – together with the BCB's normative instructions and the Financial Activities Control Council (COAF) rules that govern suspicious-transaction reporting. The BCB formally became the licensing and supervisory authority for VASPs under the Virtual Assets Act, which entered into force and delegated rulemaking authority to the central bank. That delegation placed Brazilian VASP supervision within a regulated financial-institution paradigm, not a lighter registration track.
Separately, COAF retains jurisdiction over suspicious-activity and unusual-transaction reporting. A VASP in Brazil therefore has a dual reporting chain: prudential and AML supervision through the BCB, and financial-intelligence reporting to COAF. Both bodies coordinate under the broader National Anti-Money Laundering Strategy, which aligns Brazil's posture to the FATF Recommendations, including the digital-asset-specific guidance that FATF updated to address DeFi, NFT marketplaces and unhosted wallets.
For an inbound operator – a firm licensed elsewhere seeking to serve Brazilian users or transact in reais-denominated rails – the BCB's regulatory perimeter extends to the economic substance of the activity, not solely to the place of incorporation. An offshore-licensed entity that actively onboards Brazilian clients, settles in Brazilian reais or maintains a commercial presence in Brazil will generally need to engage the BCB's VASP authorisation process and adopt a Brazil-specific AML/CFT policy.
For a scoped review of whether your current structure triggers BCB registration obligations, contact OBOLUS at info@oboluslaw.com. The analysis turns on entity structure, user base and banking layer – factors that vary significantly across operator profiles.
What must a Brazil-compliant AML/CFT policy contain?
A Brazil-compliant AML/CFT policy must address, at minimum, customer due diligence, risk classification, transaction monitoring, suspicious-activity reporting, record-keeping, sanctions screening and the Travel Rule – and it must be proportionate to the specific risk profile of the VASP's product and client base. The BCB's normative framework for VASPs incorporates the standard components expected of regulated financial institutions, adapted for the characteristics of virtual assets: pseudonymous wallets, cross-chain settlement and the speed at which funds can move across borders.
The core policy components break down as follows.
Customer due diligence (CDD) and enhanced due diligence (EDD). Brazilian requirements follow the risk-based approach endorsed by FATF. Standard CDD applies at onboarding and at periodic review intervals. EDD applies to politically exposed persons (PEPs), high-risk geographies, complex ownership structures and transactions above defined thresholds. The BCB expects VASPs to document their CDD methodology, not merely list the information collected.
Risk classification matrix. The policy must set out how the VASP classifies clients and products on a low-to-high risk scale, with explicit criteria. Regulators reviewing AML programs look first at whether the risk matrix is genuinely calibrated to the business – a custodian holding institutional balances has a different risk profile than a retail exchange processing high-frequency micro-transactions.
Transaction monitoring. The BCB expects automated or systematic monitoring with defined alert thresholds, case management processes and documented escalation paths. For crypto VASPs, this means on-chain analytics tools should be integrated into the monitoring program. In our cross-border practice, we regularly advise clients that a monitoring system built for fiat payments will not satisfy regulators when applied without adaptation to blockchain-native flows.
Suspicious-activity reporting to COAF. Brazil imposes mandatory reporting of unusual transactions (Relatório de Operações Suspeitas – ROS) to COAF within defined timeframes. The policy must specify the trigger criteria, the internal escalation chain and the reporting officer's authority.
Record-keeping. Transaction records, CDD files and monitoring decisions must be retained for a period that the BCB's normative instructions specify – qualitatively described here as a multi-year retention window consistent with the FATF standard. The policy must state retention periods and the format in which records are held.
Sanctions and PEP screening. Brazil maintains national sanctions lists administered by COAF and the Ministry of Foreign Affairs, alongside the expectation that internationally active VASPs will screen against OFAC, UN and EU consolidated lists. The screening methodology and update frequency must be documented.
How does the Travel Rule apply to Brazilian VASPs?
The Travel Rule – the obligation under FATF Recommendation 16 to pass originator and beneficiary identifying information alongside a virtual-asset transfer – applies in Brazil through the BCB's normative framework and aligns with the threshold and data-field approach that FATF prescribes for VASPs. Compliance requires both outbound transmission of required data when your VASP originates a transfer and inbound verification procedures when your VASP receives one.
In practice, Travel Rule compliance for a Brazilian VASP involves three interconnected steps. First, the firm must identify which of its transfer flows are in-scope – typically peer VASP-to-VASP transfers above the applicable threshold, with unhosted-wallet transfers subject to a separate risk-based analysis. Second, it must integrate a Travel Rule messaging solution capable of transmitting the required data fields to counterpart VASPs, including those in foreign jurisdictions where the counterpart may be using a different protocol. Third, the policy must document the procedure for what happens when a transfer arrives without Travel Rule data – the so-called "sunrise problem" – and when a counterpart VASP is unresponsive or located in a non-compliant jurisdiction.
The cross-border dimension is acute. A Brazilian exchange routing transfers through correspondent accounts in the United States or the European Union will encounter Travel Rule obligations under those jurisdictions' regimes as well – FinCEN's rules in the US, and the requirements that MiCA's AML package applies across the EU. A single-jurisdiction policy is therefore structurally insufficient for any VASP with international transaction flows. We have seen Brazilian operators build technically compliant local policies that nevertheless fail when tested by a US correspondent bank applying its own Travel Rule expectations.
Who is responsible: the MLRO role and governance requirements?
Brazilian regulation requires VASPs to designate a responsible officer for AML/CFT compliance – a role functionally equivalent to the Money Laundering Reporting Officer (MLRO) used in common-law jurisdictions. The BCB's normative framework specifies that this officer must have sufficient authority within the organization to implement the policy, access all relevant business lines and report independently to senior management.
For smaller or founder-led businesses, the instinct is to assign the MLRO role informally to an existing officer without documenting the authority, the reporting line or the resource allocation. Regulators in leading hubs – and the BCB follows this pattern – treat the governance structure of the AML program as a primary examination focus. An undocumented or under-resourced MLRO role is treated as a substantive deficiency, not a formality.
For inbound operators, the BCB may require the designated officer to be locally resident or locally reachable for supervisory contact. This creates a practical staffing consideration for foreign firms entering the market through a subsidiary. In our practice, we advise clients to resolve the MLRO question before the application stage, because a change of nominated officer after filing typically extends the review period.
To map the governance and staffing obligations before you commit to the Brazilian market, write to OBOLUS at info@oboluslaw.com. A prior application that stalled on the MLRO question can often be restarted with a structural adjustment rather than a full redesign.
How do tax and banking interact with AML compliance in Brazil?
AML policy drafting in Brazil cannot be treated in isolation from the tax and banking stack – a lesson that operators entering the market frequently learn at cost. The BCB's VASP authorisation process and the ongoing AML supervision sit alongside the Receita Federal's (Brazilian Federal Revenue Service) reporting requirements for virtual-asset transactions, which impose disclosure obligations on exchanges and on certain end-users. A VASP that is AML-compliant but fails to integrate the Receita Federal's reporting framework into its client communication and data architecture will face a separate compliance gap.
On the banking side, correspondent banks and Brazilian domestic banks applying their own AML programs will conduct due diligence on a VASP's AML policy before opening or maintaining accounts. A policy that was adequate at account opening may not satisfy a bank's enhanced review the following year if the BCB has updated its normative framework or if the bank has received updated FATF guidance on high-risk indicators for crypto businesses. We have seen VASP operators lose banking access not because of any regulatory breach, but because their AML policy documentation was not current or sufficiently specific to satisfy the bank's internal VASP risk appetite.
The tax dimension adds a layer of data-sharing. Where a VASP's transaction monitoring system flags a reportable transaction, there is an intersection between the COAF report and the data that may be subject to automatic exchange under Brazil's international tax information-exchange commitments. Operators should ensure their AML and tax reporting processes are designed to interact, not to run in parallel silos.
What is the process for an inbound operator drafting a Brazil-compliant AML policy?
For an overseas VASP seeking to establish a compliant AML/CFT program for Brazilian operations, the process typically follows a sequential path: gap analysis against the BCB's normative requirements, policy drafting and board adoption, technology integration (CDD tools, transaction monitoring, Travel Rule solution), MLRO appointment and governance documentation, and then BCB submission as part of the broader VASP authorisation file.
The gap analysis stage is the most consequential. An operator that maps an existing EU MiCA-compliant or MAS-compliant policy against the BCB's requirements will typically find that the framework elements overlap significantly, but that specific local requirements – COAF reporting procedures, Brazilian PEP list integration, reais-threshold calibration – require policy amendments rather than a wholesale redraft. The timeline from gap analysis to a policy ready for BCB submission is typically a matter of weeks for a well-prepared operator with existing AML infrastructure, and longer where systems need to be built.
The BCB's review of VASP applications includes a qualitative assessment of the AML/CFT policy. A policy that is detailed, internally consistent and demonstrably calibrated to the specific risk profile of the applicant's business will progress more smoothly than a generic template. In our practice, we have seen applications pause at the AML review stage where the policy described monitoring thresholds that bore no relationship to the actual transaction volumes and client demographics of the business.
A recent cross-border matter illustrates the stakes. A payments company seeking to operate a digital-asset settlement corridor between Brazil and a major European jurisdiction had an EU-compliant AML policy in place. In the course of preparing the BCB authorisation file, we identified that the Travel Rule procedure referenced an inter-VASP messaging protocol that was not supported by the firm's technology stack and that COAF reporting timelines in the policy were copied from the EU regime without adjustment. A targeted amendment and a technology integration review resolved both issues before submission, avoiding a material deficiency finding during BCB review.
Which operator profile needs which level of AML policy?
The depth and complexity of the required AML/CFT program varies by operator profile. A structured view helps businesses allocate drafting resources appropriately.
A retail virtual-asset exchange onboarding Brazilian consumers directly requires the most comprehensive program: full CDD and EDD procedures, automated transaction monitoring calibrated to retail behavior patterns, COAF reporting infrastructure, Travel Rule compliance across the full wallet-to-wallet transfer perimeter, and a locally present or locally reachable MLRO. The BCB will scrutinize this profile most closely. Timeline from engagement to a policy ready for BCB submission typically runs several weeks; if technology systems need to be procured, the timeline extends accordingly.
An institutional-only custodian servicing professional counterparties in Brazil can calibrate its CDD program to a smaller, higher-due-diligence client base. The risk matrix will differ, monitoring thresholds will be set at higher transaction values, and the Travel Rule analysis will focus on institution-to-institution transfers rather than retail wallet flows. The program is no less rigorous in principle, but the surface area is narrower. Timeline is broadly comparable.
A foreign-incorporated VASP routing Brazilian reais through a Brazilian correspondent bank without a local entity faces a different question: whether the BCB's perimeter reaches the activity at all, and what a correspondent bank will require by way of AML documentation before clearing. Even without a Brazilian licence obligation, the banking layer will demand a policy that satisfies BCB norms. Failure to produce one typically results in account refusal or closure. This is the profile where we most frequently see operators assume that an offshore licence resolves the problem – it does not, because the bank's AML standards are driven by BCB expectations regardless of where the VASP is incorporated.
What are the most common AML policy mistakes Brazilian VASPs make?
In our practice advising digital-asset businesses across the major regulatory hubs, the Brazil-specific mistakes fall into a recognizable pattern.
The most frequent error is importing a policy from another jurisdiction without localizing it. A MiCA-compliant CASP policy and a BCB-compliant VASP policy share a common FATF skeleton, but the COAF reporting obligations, the PEP definitions, the specific data-field requirements for Brazilian national identity documents and the reais-threshold calibration differ. A policy that names the wrong reporting authority or references EU-specific thresholds will be identified immediately in a BCB review.
The second common mistake is treating the AML policy as a one-time filing rather than a living compliance document. The BCB updates its normative framework, FATF revises its guidance on virtual assets, and COAF refines its typology notices. A policy that was adequate at the point of BCB authorisation may be materially deficient twelve months later. Operators should build a policy maintenance calendar into their compliance governance from the outset.
A third error relates to the unhosted-wallet procedure. Many operators draft a robust VASP-to-VASP Travel Rule procedure and then include a one-line placeholder for unhosted wallet interactions. The BCB's risk-based expectations, following FATF guidance, require a more substantive approach: documented risk criteria, a defined EDD trigger for high-value unhosted-wallet interactions, and a record of how the decision was made in each case.
A common assumption in the market is that a single offshore VASP licence covers global operations, including Brazil. It does not. The BCB's perimeter test focuses on economic substance and client relationship, not the place of the VASP's incorporation. An operator that routes services to Brazilian users without BCB authorisation – and without a BCB-compliant AML policy – is exposed to enforcement risk under Brazilian law and to banking termination under the correspondent bank's AML standards.
Related at OBOLUS
- AML/CFT and Travel Rule Compliance for Digital-Asset Businesses – our practice overview covering the full compliance lifecycle for VASPs across jurisdictions.
- How to Draft an AML/CFT Policy for a VASP – a step-by-step guide to policy structure, content requirements and common drafting errors.
- Licence Renewal and Variation for Established Operators – managing AML policy updates as part of renewal filings and material-change notifications.
FAQ
What does the Travel Rule require from a VASP?
The Travel Rule, derived from FATF Recommendation 16, requires a VASP that originates a virtual-asset transfer to transmit specified originator and beneficiary identifying information to the receiving VASP alongside the transaction. In Brazil, the BCB's normative framework incorporates this obligation. VASPs must also implement inbound verification procedures – screening data received from originating VASPs and applying a risk-based procedure when data is absent or incomplete. The specific data fields and applicable thresholds follow FATF guidance, interpreted through BCB rules.
Who must act as MLRO for a crypto firm?
Brazilian regulation requires VASPs to designate a responsible officer for AML/CFT compliance with sufficient internal authority to implement the program across all business lines and to report independently to senior management. For foreign-incorporated VASPs operating in Brazil, the BCB may require local accessibility for supervisory contact. The MLRO's authority, reporting line and resource allocation must be formally documented. An informally assigned or under-resourced officer constitutes a substantive program deficiency, not merely a formality, and will typically be identified during BCB review.
How do regulators audit crypto AML programs?
The BCB assesses AML/CFT programs through a combination of initial authorisation review, periodic supervisory engagement and targeted examinations. Examiners typically focus on whether the risk classification matrix is genuinely calibrated to the VASP's product and client profile, whether transaction monitoring alert thresholds are proportionate and documented, whether COAF reporting pipelines are operational, and whether Travel Rule procedures are implemented in the technology stack – not merely described in the policy. COAF may separately conduct financial-intelligence reviews focused on the quality and timeliness of suspicious-activity reporting.
OBOLUS is an independent digital-asset law boutique acting only for businesses. We advise exchanges, custodians, token issuers and funds on licensing across 70+ jurisdictions, on disputes and on-chain asset recovery across 25+ forums, and on the tax, banking and compliance that sit around them. Digital assets are the entirety of our practice, and we act only for businesses. We map the licence, banking and compliance stack across operating, custody and payment layers before you commit to a market – so that the structure you build is the structure that works. To discuss your Brazil AML/CFT requirements, contact info@oboluslaw.com.
By Victor Olsen, Regulatory & Compliance Analyst – specialising in AML/CFT regime analysis and VASP compliance program development across Latin American and European regulatory environments.
This publication is general information about the law and does not constitute legal advice. It is not a substitute for advice tailored to your circumstances. OBOLUS accepts no liability for action taken or not taken on the basis of this material. For advice on your situation, contact info@oboluslaw.com.