EST · MMXXVI
Home/Jurisdictions/Brazil/MLRO and compliance officer function in Brazil
Compliance, AML & Travel Rule

MLRO and compliance officer function in Brazil

Mlro and compliance officer function in Brazil. Cross-border digital-asset legal counsel for business – licensing, disputes and structuring. Talk to OBOLUS.

Brazil has moved from informal tolerance to active supervision of virtual-asset service providers, and the compliance function is now the operational centre of that regime. Under the Brazilian framework for virtual assets – anchored in the Virtual Assets Act and supervised by the Banco Central do Brasil (BCB) – every licensed VASP (virtual asset service provider) must maintain a designated Money Laundering Reporting Officer (MLRO) and an adequate compliance programme as a condition of authorisation. Failure to do so does not merely invite a regulatory penalty; it exposes the business to frozen payment rails, banking termination and potential criminal liability for its senior officers. This page sets out what the function requires, how it interacts with Brazil's AML and Travel Rule (the obligation to pass originator and beneficiary data with a transfer) obligations, and where cross-border complexity concentrates the legal risk.

What the Brazilian regime requires from a licensed VASP

Brazil's Virtual Assets Act created the legal basis for a federal licensing regime, with the Banco Central do Brasil designated as the primary supervisor for VASP activities including exchange, custody, transfer and brokerage of virtual assets. The BCB has issued complementary regulations that embed anti-money-laundering obligations directly into the licensing conditions. COAF (Conselho de Controle de Atividades Financeiras) – Brazil's financial intelligence unit – receives suspicious transaction reports (STRs) from VASPs and coordinates with the BCB on supervisory enforcement. Under the applicable VASP provisions, a firm that processes virtual-asset transactions is expected to maintain an internal control structure that mirrors, in substance, what the BCB requires of regulated financial institutions.

The compliance function sits at the intersection of three regulatory demands: BCB licensing conditions, COAF reporting obligations, and the rules issued by Brazil's AML authority under the framework aligned with FATF Recommendation 15 on virtual assets. All three point to the same outcome: a named, qualified individual must own the AML/CFT programme, report suspicious activity independently, and answer directly to the board or senior management.

In our cross-border practice, the businesses that struggle most at licensing stage are those that treated compliance as a document-production exercise rather than an embedded function. The BCB's supervisory focus in recent examinations has been on governance – specifically, whether the MLRO has real authority and real resources, or whether the role exists only on an organisational chart.

Who must serve as MLRO and what that role entails

The MLRO role in a Brazilian-licensed VASP requires a natural person – typically a senior officer or a dedicated compliance director – with sufficient seniority to challenge business decisions and sufficient independence to report to regulators without operational interference. The BCB's applicable provisions do not mandate a specific professional credential, but they do require that the responsible officer have demonstrable knowledge of AML/CFT regulation and the firm's product risk profile.

The MLRO's core functions run across four operational domains. First, policy ownership: the MLRO must maintain a written AML/CFT programme that is approved by senior management and reviewed at intervals the regulator considers reasonable. Second, suspicious activity reporting: STRs flow to COAF through a designated reporting channel; the MLRO authorises each submission and is personally accountable for timeliness. Third, training: every employee with customer-facing or transaction-monitoring duties must receive documented AML training, and the MLRO owns the training calendar. Fourth, board-level escalation: the MLRO must have a direct line to the board – or, for a branch or subsidiary structure, to the local governing body – that the BCB can verify in an examination.

Where the structure is a Brazilian subsidiary of a foreign group, the MLRO must be resident or at minimum accessible to Brazilian supervisors. A group compliance officer sitting in another jurisdiction does not satisfy the BCB's expectation of a locally accountable function. We regularly advise groups that have attempted a shared-service model across Latin America; in almost every case the structure required a dedicated local officer once the BCB's examination framework was applied.

For a scoped assessment of your compliance governance structure before you apply for BCB authorisation, contact OBOLUS at info@oboluslaw.com. The process above describes the standard path. Your facts – the entity type, the user base, the product set – change the analysis. Map your options.

How the KYC framework operates for Brazilian VASPs

Brazil's KYC framework (know-your-customer obligations) for VASPs mirrors the tiered customer due diligence (CDD) model applied to financial institutions, adapted to the velocity and pseudonymity of on-chain activity. The BCB's applicable regime requires VASPs to identify and verify every customer before the first transaction, maintain records for a minimum period set by the AML framework, and apply enhanced due diligence (EDD) to customers or transactions that present elevated risk indicators.

Practically, a Brazilian VASP must collect government-issued identification, verify it against authoritative sources, screen the customer against PEP (politically exposed person) lists and sanctions lists, and assess the source of funds for higher-risk profiles. The MLRO sets the risk-appetite thresholds that determine when a customer moves from standard CDD to EDD. Those thresholds must be documented and defensible; a regulator examining a firm for the first time will pull a sample of EDD files and test whether the escalation logic was applied consistently.

For businesses onboarding institutional counterparties – exchanges, OTC desks, corporate treasury accounts – the KYC framework extends to beneficial ownership identification. Brazil's AML provisions track FATF guidance in requiring ultimate beneficial owner disclosure to a specified percentage threshold; the exact figure is set by the applicable BCB rules and should be confirmed against current legislation.

What transaction monitoring must look like in practice

Effective transaction monitoring in a VASP context requires both on-chain analytics and fiat-side monitoring. A Brazilian VASP that converts virtual assets to Brazilian reais – the overwhelming majority of retail-facing businesses – operates at a junction where blockchain forensics and traditional banking surveillance must be integrated. The MLRO is responsible for ensuring that the monitoring programme covers both channels and that alerts generated by either are reviewed and resolved within a documented timeframe.

The BCB's supervisory posture increasingly reflects the FATF expectation that VASPs deploy risk-based transaction monitoring, not rule-based filtering alone. That means the firm must be able to demonstrate that its monitoring thresholds are calibrated to its actual customer risk profile, not simply set at a fixed BRL amount and left unchanged. Firms that rely on out-of-the-box monitoring parameters without periodic calibration have faced BCB feedback requiring corrective action within defined remediation windows.

In a recent compliance advisory matter, a payments business operating across Brazil and a neighbouring jurisdiction had deployed a single monitoring ruleset for both markets. We identified that the Brazilian ruleset failed to capture a category of structured transfers the BCB had flagged in published typologies guidance. The MLRO had not received the typologies update because the group compliance team was based offshore. We restructured the escalation path so that Brazilian typology updates flowed directly to the local MLRO, and the remediation was completed before the scheduled BCB examination.

How the Travel Rule applies to Brazilian VASPs

The Travel Rule obligation – requiring a VASP to pass originator and beneficiary data alongside a virtual-asset transfer – applies to Brazilian-licensed VASPs under the BCB's applicable VASP provisions, consistent with FATF Recommendation 15. The rule creates a bilateral data-exchange obligation: the originating VASP must transmit the required customer information before or simultaneously with the transaction, and the beneficiary VASP must receive and screen it.

The MLRO is operationally accountable for Travel Rule compliance, which means the firm must have a technical solution capable of transmitting and receiving structured counterparty data, a policy for handling transactions where the beneficiary VASP is unhosted or non-responsive, and a documented risk approach for transactions below any applicable de-minimis threshold set by Brazilian rules. The specific data threshold and de-minimis treatment should be confirmed against current BCB guidance, as the figures are subject to regulatory update.

The cross-border dimension here is acute. A Brazilian VASP sending a transfer to a counterparty in a jurisdiction that has not yet implemented the Travel Rule – a significant portion of global VASP traffic – faces an asymmetric obligation. It must send the data; the counterpart may not be equipped to receive it. The MLRO must have a written policy for this scenario that the BCB considers risk-appropriate, typically involving enhanced monitoring of unhosted wallet flows and documented counterparty due diligence for cross-border sends above threshold.

The cross-border banking and tax interaction

The compliance function does not operate in isolation from the banking and tax environment. A Brazilian VASP maintaining correspondent banking relationships must satisfy its banking partners' AML expectations in addition to the BCB's supervisory requirements. Banks in Brazil – and those abroad that process BRL-denominated settlements – conduct periodic compliance reviews of their VASP clients, and the MLRO's programme is a primary document in those reviews.

Operating without the right licence risks enforcement, frozen payment rails and lost banking. We have seen this pattern repeatedly: a firm that delayed BCB authorisation continued operating through an unlicensed entity, and the banking counterpart – responding to its own regulator's guidance on unregistered VASPs – terminated the account. Restoring banking access after a termination event is a significantly longer process than obtaining it the first time, because banks apply heightened scrutiny to previously terminated counterparties.

On the tax side, Brazil's Receita Federal (the federal revenue authority) requires VASPs to report customer transaction data on a monthly basis under a specific reporting obligation for virtual-asset transactions. The MLRO and the firm's tax compliance function must coordinate on this obligation, because the data sets overlap. An MLRO who is unaware of the Receita Federal reporting requirement may inadvertently create a discrepancy between AML records and tax filings – a discrepancy that is visible to both the BCB and the Receita Federal in a joint examination.

For groups structured with a Brazilian operating entity and an offshore holding or custody layer, the MLRO must understand how the intercompany flows are characterised. A transfer from the Brazilian entity to an offshore custodian may trigger both AML reporting and foreign-exchange reporting obligations. The compliance programme must map those flows and assign ownership of each reporting obligation explicitly.

If a prior application stalled or banking access was lost, a second read can surface the structural reason and the route back. To map the licence, banking and compliance stack for your Brazil build, write to info@oboluslaw.com. Map your options.

The compliance failures that recur in Brazilian VASP examinations

The most common structural weakness we identify when reviewing a Brazilian VASP's compliance programme is the absence of a documented risk assessment that is specific to the firm's actual product and customer profile. A generic AML policy imported from a European or US group compliance library rarely maps to the BCB's expectations for a Brazilian-market business, particularly on the treatment of virtual-asset-to-cash conversions, peer-to-peer exchange activity, and the elevated exposure to politically exposed persons in an emerging-market context.

A second recurring failure is the MLRO's lack of documented escalation authority. The BCB expects to see evidence that the MLRO can, in practice, pause a customer relationship or a product launch pending a compliance review. If the MLRO's authority is conditioned on commercial approval, the independence requirement is not met. This is a point regulators test in examination interviews, not just in document review.

Third, many firms underinvest in the ongoing training obligation. A training deck produced at licensing stage and never updated does not satisfy the BCB's expectation of a living programme. The MLRO must document not only that training was delivered but that it reflected current typologies, updated sanctions lists and any BCB guidance issued since the last training cycle.

A common assumption is that a single offshore AML licence is sufficient to cover Brazilian customer relationships. It is not. The BCB applies its regime to any entity that provides virtual-asset services to Brazilian residents, regardless of where the entity is incorporated. An offshore structure without a Brazilian authorisation – and without a locally accountable MLRO – is an enforcement target, not a compliance solution.

Which compliance structure fits which operator profile

The right compliance architecture depends on the operator's scale, product complexity and cross-border footprint. Three profiles dominate the inbound market.

Profile A – a standalone Brazilian exchange or brokerage: A dedicated in-house MLRO with full-time AML/CFT authority is the expected model. The MLRO should hold seniority at director level or above, report directly to the board, and have a budget line for monitoring tools and external counsel independent of the revenue business. Timeline from compliance programme build to BCB-ready submission is typically a matter of months; the exact period depends on the firm's existing documentation baseline.

Profile B – a foreign group with a Brazilian subsidiary: The group compliance framework must be localised for Brazil. This requires a locally appointed MLRO (not merely a group delegate), a Brazilian-specific risk assessment, a COAF reporting capability, and Travel Rule tooling that covers BRL-denominated flows. The MLRO may sit within the subsidiary or be shared with a regional hub, but must be accessible to the BCB and named in the BCB filing. Integration with the group's tax reporting to the Receita Federal requires a separate workstream.

Profile C – a fintech or payments business adding virtual-asset services to an existing licence: The existing compliance programme must be extended, not simply amended. The BCB treats virtual-asset activities as a distinct risk category requiring a dedicated risk assessment and potentially a separate supervisory engagement. The MLRO for the broader entity may absorb the VASP compliance function, but the programme must demonstrate that virtual-asset-specific risks are addressed with the same rigour as the existing regulated activities.

Related at OBOLUS

FAQ

What does the Travel Rule require from a VASP?

The Travel Rule requires a VASP to collect and transmit originator and beneficiary identifying information alongside a virtual-asset transfer. Under Brazil's applicable VASP provisions – aligned with FATF Recommendation 15 – the originating firm must send the data before or simultaneously with the transaction. The beneficiary VASP must receive and screen it. The MLRO is responsible for the firm's Travel Rule policy, including the treatment of transfers to non-compliant counterparties. The applicable data threshold should be confirmed against current BCB guidance.

Who must act as MLRO for a crypto firm?

Under the BCB's applicable VASP framework, the MLRO must be a named natural person with sufficient seniority to exercise independent AML authority. For a Brazilian subsidiary of a foreign group, the MLRO must be locally accessible and named in the BCB's supervisory records – a group compliance officer based offshore does not satisfy this requirement. The role requires documented escalation authority, a direct reporting line to the board or local governing body, and personal accountability for COAF suspicious transaction reporting.

How do regulators audit crypto AML programs?

The BCB conducts AML programme reviews through a combination of document examination and supervisory interviews. Examiners will review the firm's written risk assessment, customer due diligence files (including a sample of EDD cases), transaction monitoring calibration records, COAF reporting logs and MLRO training documentation. The examination tests not only whether a policy exists but whether it was applied consistently and updated to reflect current BCB typologies guidance. Firms that cannot produce contemporaneous evidence of monitoring decisions are the most frequent targets of BCB remediation requirements.

OBOLUS is an independent digital-asset law boutique acting only for businesses. We advise exchanges, custodians, token issuers and funds on licensing across 70+ jurisdictions, on disputes and on-chain asset recovery across 25+ forums, and on the tax, banking and compliance functions that sit around them. Digital assets are the whole of our practice. We map the licence stack across operating, custody and payment layers before you commit – and we advise crypto exchanges, custodians, token issuers and funds across more than seventy licensing jurisdictions. To discuss your compliance structure or MLRO appointment in Brazil, contact info@oboluslaw.com.

By Victor Olsen, Regulatory & Compliance Analyst – specialising in VASP AML/CFT programme design and cross-border compliance governance for digital-asset businesses.

This publication is general information about the law and does not constitute legal advice. It is not a substitute for advice tailored to your circumstances. OBOLUS accepts no liability for action taken or not taken on the basis of this material. For advice on your situation, contact info@oboluslaw.com.

Tell us the task — we'll map your options in 30 minutes.

Fixed-fee packages with defined scope and SLAs. The first call is free and under NDA. Business clients only.

Map your optionsinfo@oboluslaw.com · t.me/oboluslaw · reply < 2 hours