Sanctions screening for virtual-asset businesses operating in or into Brazil is a mandatory, regulator-enforced obligation – not an optional compliance enhancement. Brazil's primary digital-asset supervisory authority, the Banco Central do Brasil (BCB), took formal responsibility for virtual asset service provider (VASP) oversight following the enactment of the country's dedicated crypto regulatory regime. Under that regime, any entity providing virtual-asset services to Brazilian residents must maintain a documented sanctions screening program that meets BCB expectations, satisfies Conselho de Controle de Atividades Financeiras (COAF) anti-money-laundering requirements, and aligns with FATF Recommendation 15 on virtual assets. The stakes are concrete: a screening failure can trigger BCB enforcement, close correspondent-banking relationships, and expose cross-border transfers to seizure by foreign authorities acting on shared intelligence.
This page maps the regulated basis for sanctions screening in Brazil, the practical program elements BCB and COAF expect, the cross-border complications facing inbound operators, and the decision points that determine whether a foreign VASP can serve Brazilian clients from an offshore structure or must seek a local authorization.
What is the regulated basis for sanctions screening in Brazil?
Brazil's crypto regulatory regime – built around the Virtual Assets Act and implemented through BCB normative instructions – places sanctions screening squarely within the broader AML/CFT framework that financial institutions and VASPs must follow. The BCB issues binding normative instructions that set out the specific screening, monitoring and reporting obligations applicable to virtual-asset businesses. COAF, Brazil's financial intelligence unit, receives suspicious-transaction reports from VASPs and coordinates with BCB on enforcement referrals. Together these two bodies form the supervisory axis that every VASP serving Brazilian users must satisfy.
FATF Recommendation 15 anchors the international baseline. Brazil is a FATF member, and its domestic implementing measures track FATF's expectation that VASPs screen counterparties against applicable sanctions lists, apply enhanced due diligence to high-risk transactions, and maintain records sufficient to reconstruct transaction flows on request. The BCB has made clear that "applicable sanctions lists" includes not only Brazil's own COAF-maintained lists but also internationally recognized designations where Brazilian operators have cross-border exposure.
In our practice, one of the earliest structural questions for a foreign VASP entering Brazil is which list set the operator must screen against. A crypto exchange licensed in Europe under MiCA, for example, may already screen against EU and OFAC lists. Brazilian BCB expectations add a domestic layer – COAF's own list plus any designations issued under Brazilian law – creating a multi-list obligation that a single upstream screening vendor may not cover without configuration.
Which operators must maintain a sanctions screening program in Brazil?
Any entity that provides virtual-asset services to persons or businesses resident in Brazil must maintain a BCB-compliant sanctions screening program, regardless of where the entity is domiciled. The Virtual Assets Act applies on the basis of service delivery to Brazilian users, not solely on the basis of the operator's place of incorporation. This extraterritorial reach is consistent with how Brazil's financial-services laws have long applied to offshore entities providing financial products to Brazilian residents.
The categories of service that trigger the obligation span exchange, custody, transfer, issuance and intermediation of virtual assets. A foreign custodian holding digital assets for Brazilian clients, a stablecoin issuer whose tokens circulate in the Brazilian market, and a centralized exchange onboarding Brazilian retail users are each within scope. An entity serving only non-Brazilian institutional counterparties through a wholly foreign infrastructure may fall outside the direct BCB licensing perimeter, but it will still face sanctions exposure through correspondent banking and SWIFT-linked payment rails that are themselves subject to OFAC and EU screening.
The cross-border reality is this: even where an operator concludes it has no BCB filing obligation, the banking infrastructure supporting its Brazilian-user flows will apply its own screening. A US correspondent bank processing dollar settlements will screen against OFAC. A European payment processor will screen against EU designations. An operator that passes BCB screening but trips a correspondent-bank filter faces the same disruption as one that ignores BCB requirements entirely. Compliance must be built for the whole stack, not just the regulator facing the end-user.
For a scoped assessment of your Brazil exposure, contact OBOLUS at info@oboluslaw.com. The process above describes the standard path. Your facts – the entity type, the user base, the banking relationships, the token categories – change the analysis materially.
What does a BCB-compliant sanctions screening program require?
A BCB-compliant screening program for a VASP consists of several interlocking elements that the regulator expects to see documented, tested and operational before the business onboards Brazilian users at scale. The core requirements track the FATF-aligned AML framework that BCB normative instructions impose on all regulated financial entities.
First, list coverage and update frequency. The program must screen against COAF's domestic lists and any supplementary lists specified by BCB in its normative instructions, with update cadence sufficient to capture new designations before the next transaction cycle. In practice this means automated list ingestion rather than manual refresh, because the interval between a designation and an attempted transaction can be measured in minutes in the digital-asset environment.
Second, KYC framework integration. Screening is not a standalone process; it is a gate within the broader customer due-diligence lifecycle. A match at onboarding stops account opening. A retroactive match against an existing customer triggers enhanced review, possible account restriction, and a COAF suspicious-transaction report. The program must document the escalation path and the decision authority for each scenario.
Third, transaction monitoring. BCB expects VASPs to apply ongoing monitoring to detect patterns consistent with sanctions evasion – structuring, layering through multiple wallet addresses, rapid conversion between asset types. The Travel Rule (the obligation to pass originator and beneficiary data alongside a virtual-asset transfer) is part of this layer: a transaction that arrives without the required counterparty data is itself a red flag requiring enhanced review.
Fourth, record retention. BCB normative instructions specify minimum retention periods for customer identification records, transaction data and screening-decision logs. These records must be accessible to BCB and COAF on request, typically within defined response windows.
Fifth, an MLRO (money-laundering reporting officer) or equivalent responsible-person designation. The program must have a named officer with clear authority to file reports, make escalation decisions and interface with BCB and COAF. For a foreign entity operating into Brazil, determining where this officer must be located – and whether a local representative satisfies the requirement – is a structural decision that has direct implications for how the entity organizes its cross-border operations.
How should an inbound operator structure its Brazil screening approach?
An inbound operator – a foreign VASP entering the Brazilian market – faces a layered compliance build: its home-jurisdiction AML/CFT requirements plus the BCB/COAF layer plus the correspondent-banking screening expectations of the payment rails it uses. Getting this sequence right matters, because a program designed solely around a European MiCA CASP authorization or a MAS digital payment token licence will not, by default, cover Brazil's domestic list requirements.
The practical sequencing looks like this. Before onboarding Brazilian users, the operator should map: (1) whether its current screening vendor covers COAF lists and any BCB-specified supplementary lists; (2) whether the MLRO or equivalent function meets BCB's responsible-person expectations; (3) whether the Travel Rule implementation covers Brazilian-counterparty transfers at the applicable data threshold; and (4) whether correspondent banks supporting Brazilian-peso settlement or BRL-denominated stablecoin flows impose additional screening layers.
In a recent compliance structuring matter, a digital-asset exchange already licensed in a leading EU jurisdiction sought to expand services to Brazilian users. The operator assumed its existing MiCA-aligned program was sufficient. On review, we identified three gaps: COAF list coverage was absent from the vendor configuration, the Travel Rule threshold applied by the operator did not align with BCB normative instruction parameters, and the designated MLRO was located in a time zone that made timely COAF report submission structurally difficult. Addressing these gaps before launch avoided what would have been a reportable compliance failure within the first transaction cycle.
Decision matrix by operator profile:
Profile A – Foreign exchange with an existing MiCA CASP authorization: Brazil service delivery triggers BCB screening overlay. The operator should extend its existing AML program rather than build standalone, but vendor configuration, MLRO designation and COAF reporting procedures all require Brazil-specific documentation. Timeline to compliance readiness typically runs several weeks, depending on vendor flexibility.
Profile B – Foreign custodian holding Brazilian-resident client assets: BCB may require local authorization in addition to screening compliance, depending on the nature of the custody service and the client classification. Screening obligations attach from first client onboarding, irrespective of whether authorization proceedings are complete. The operator should treat interim compliance as a live obligation, not a post-authorization task.
Profile C – Token issuer distributing to Brazilian retail users: The combination of BCB VASP oversight, COAF AML reporting and Brazil's consumer-protection regime for digital-asset disclosures creates a multi-authority compliance stack. Sanctions screening is the AML/CFT layer; the operator also faces disclosure and suitability obligations that interact with how screening data is used at onboarding.
If a prior compliance build stalled or a banking relationship was closed, a structured review can identify the root cause. Write to OBOLUS at info@oboluslaw.com or message t.me/oboluslaw.
How does the Travel Rule apply to virtual-asset transfers in Brazil?
The Travel Rule – the obligation to pass originator and beneficiary identification data alongside a virtual-asset transfer – applies in Brazil as part of the BCB/COAF AML framework, consistent with FATF's Recommendation 16 as applied to virtual assets. VASPs transmitting or receiving virtual assets on behalf of Brazilian-resident customers must collect, verify and transmit the required counterparty data at the applicable threshold set by BCB normative instructions.
In practice, Travel Rule compliance for a Brazil-facing VASP involves three operational decisions. The first is technical: the operator must select or build a messaging protocol capable of transmitting originator and beneficiary data in a format that the receiving VASP can process. The leading interoperability solutions – sector-developed messaging protocols – vary in their coverage of Brazilian VASPs, and an operator should verify counterparty readiness before assuming symmetric compliance across all transfer pairs.
The second is jurisdictional: where a transfer crosses into or out of Brazil, the operator must apply the higher of the Brazilian threshold and any threshold imposed by the foreign jurisdiction's Travel Rule regime. MiCA's Travel Rule implementation, for example, applies to all transfers regardless of amount – a zero-threshold rule that is more demanding than some other jurisdictions' de-minimis provisions. A VASP operating under both MiCA and BCB supervision must satisfy both simultaneously.
The third is the unhosted-wallet question. Transfers to or from unhosted wallets – wallets not held at a regulated VASP – require enhanced due-diligence procedures that BCB expects to be documented in the operator's AML policy. The standard approach involves collecting self-certification of ownership, applying transaction monitoring to detect structuring, and escalating anomalies to the MLRO for disposition. BCB's expectations on unhosted-wallet treatment align broadly with the FATF guidance issued on the topic, but the specific documentation thresholds are set by normative instruction rather than by FATF directly.
How do banking and tax obligations interact with sanctions screening in Brazil?
Sanctions screening compliance and Brazilian banking access are closely linked. The BCB licenses and supervises both traditional banks and VASPs, which means a VASP's compliance standing with BCB directly affects its ability to maintain BRL-denominated bank accounts and access the PIX instant-payment system. A VASP whose sanctions screening program is found deficient during a BCB examination risks not only regulatory sanction but also the revocation of access to the payment infrastructure that BRL settlement depends on.
For foreign VASPs, the banking interaction is primarily through correspondent relationships. A foreign operator settling BRL-denominated transactions through a Brazilian correspondent bank will find that the correspondent applies its own screening layer – typically covering OFAC, EU and UN lists as a minimum, with some correspondents applying additional proprietary risk filters. The correspondent's screen and the VASP's own screen can produce divergent outcomes: the VASP clears a transaction; the correspondent flags it. The result is a failed settlement that the VASP cannot explain to the client without disclosing the correspondent's filter criteria, which the correspondent will generally not share.
On the tax side, Brazil's Receita Federal (the federal tax authority) requires VASPs and Brazilian-resident holders of virtual assets to report holdings and transactions above defined thresholds. While tax reporting and sanctions screening are distinct obligations, they share an underlying data architecture: both require accurate identification of the counterparty, transaction value and asset type. A VASP that builds its sanctions screening data infrastructure carefully will have much of the raw material needed for tax-reporting compliance as well. The converse is equally true: an operator that under-invests in counterparty identification at onboarding will face compounding compliance failures across both the AML and tax reporting channels.
Exchange-rate exposure is also relevant for operators holding BRL balances. Sanctions-related account restrictions can freeze BRL balances at a moment of unfavorable exchange-rate movement. Operators should factor this into their treasury management alongside the compliance design.
A common assumption: an offshore licence is enough to serve Brazilian users
A persistent assumption among digital-asset operators entering Latin American markets is that a single offshore VASP licence – typically from a well-regarded Caribbean or European jurisdiction – is sufficient to serve clients globally, including Brazilian residents. This assumption is incorrect and, in our experience, is one of the most common causes of enforcement exposure for operators who have otherwise invested seriously in compliance.
Brazil's Virtual Assets Act and BCB normative instructions apply on the basis of service delivery to Brazilian users, not on the basis of where the operator holds its primary licence. An operator licensed in the Cayman Islands under CIMA's VASP regime, or in BVI under the VASP Act 2022, or even in the EU under MiCA, that actively markets to and onboards Brazilian-resident users is within the BCB's supervisory perimeter for the Brazilian-resident portion of its business. The offshore licence is not a Brazilian licence and does not substitute for BCB screening and AML obligations.
The practical consequence is a two-track compliance obligation: the operator must maintain the offshore programme required by its primary licensing jurisdiction and a Brazil-specific AML/CFT overlay that satisfies BCB and COAF requirements. For many operators, the most efficient structure is to extend the primary programme by adding Brazil-specific list coverage, MLRO designation provisions and COAF-reporting workflows, rather than building a standalone Brazilian programme. This extension approach is operationally cleaner, but it requires the operator to have a primary programme sufficiently well documented and vendor-configured that extension is feasible without rebuilding from scratch.
We map the licence, banking and tax stack for your build before you commit. To pressure-test your structure, message OBOLUS via t.me/oboluslaw or write to info@oboluslaw.com.
Related at OBOLUS
Related at OBOLUS
- AML and Travel Rule compliance for digital-asset businesses – full-spectrum AML/CFT counsel across licensing jurisdictions and transfer regimes.
- The Travel Rule for digital assets: a legal guide – a definitive guide to originator and beneficiary data obligations across key jurisdictions.
- DAO legal wrapper in the United Kingdom – structuring decentralized organizations under English law for cross-border operations.
FAQ
What does the Travel Rule require from a VASP?
The Travel Rule requires a VASP (virtual asset service provider) to collect, verify and transmit originator and beneficiary identification data alongside every qualifying virtual-asset transfer. Under FATF Recommendation 16 as applied to virtual assets, this obligation applies at a transfer threshold that each jurisdiction sets by domestic regulation. Brazil's BCB normative instructions specify the applicable threshold and the data fields required. Receiving VASPs must also verify the data and apply it in their transaction-monitoring and sanctions-screening processes. Transfers arriving without the required data are a red flag requiring enhanced review.
Who must act as MLRO for a crypto firm?
A money-laundering reporting officer (MLRO) is the named individual with authority to file suspicious-transaction reports, make escalation decisions and interface with the regulator and financial intelligence unit. For a VASP operating in or into Brazil, BCB normative instructions require an identifiable responsible officer. Whether that officer must be physically located in Brazil – or whether a foreign-resident officer with clear reporting lines to COAF satisfies the requirement – depends on the operator's BCB authorisation structure. For inbound foreign operators, the MLRO designation is an early structural decision, not an afterthought, because it affects the legal entity and reporting architecture.
How do regulators audit crypto AML programs?
BCB and COAF audit VASP AML programs through a combination of supervisory examinations, data requests and suspicious-transaction-report analysis. An examination typically reviews the written AML policy, screening-vendor configuration, list-coverage documentation, sample transaction files and escalation records. BCB may also request evidence of staff training and of periodic program reviews. Operators should maintain documentation in a form that can be produced on short notice. A program that exists in practice but is not documented is treated as a deficient program. External independent reviews, conducted before an examination, regularly identify documentation gaps that internal teams miss.
OBOLUS is an independent digital-asset law boutique acting only for businesses. We advise exchanges, custodians, token issuers and funds on licensing across 70+ jurisdictions, on disputes and on-chain asset recovery across 25+ forums, and on the tax, banking and compliance that sit around them. Digital assets are the entirety of our practice, and we act only for businesses – not retail clients. We map the licence, compliance and payment stack across operating, custody and payment layers before you commit. To discuss your situation, contact info@oboluslaw.com.
By Victor Olsen, Regulatory & Compliance Analyst – specialising in AML/CFT program design and sanctions-screening obligations for digital-asset businesses across Latin America and the EU.
This publication is general information about the law and does not constitute legal advice. It is not a substitute for advice tailored to your circumstances. OBOLUS accepts no liability for action taken or not taken on the basis of this material. For advice on your situation, contact info@oboluslaw.com.