EST · MMXXVI
Home/Jurisdictions/Brazil/Travel rule compliance program in Brazil
Compliance, AML & Travel Rule

Travel rule compliance program in Brazil

Travel rule compliance program in Brazil. Cross-border digital-asset legal counsel for business – licensing, disputes and structuring. Talk to OBOLUS.

For a virtual asset service provider with Brazilian users, the compliance question is not theoretical. Brazil has enacted a dedicated crypto-asset regulatory statute, brought exchanges and custodians inside the supervisory perimeter of the Banco Central do Brasil (BCB), and aligned its Travel Rule – the obligation to pass originator and beneficiary data alongside a virtual asset transfer – with the global standard set by the Financial Action Task Force (FATF) Recommendation 15. Firms that fail to build a compliant program before BCB supervisors come calling face frozen correspondent-banking rails, reputational damage with local payment partners, and exposure to administrative penalties. This page explains what the Travel Rule requires in Brazil, how to build a compliant program, and where the cross-border complications arise for an operator whose entity sits outside the country.

Brazil's digital-asset regulatory regime is anchored in a federal statute enacted in late 2022 and subsequently regulated by presidential decree, which designated the Banco Central do Brasil as the competent authority for virtual asset service providers (VASPs) – any entity that professionally intermediates the exchange, transfer, custody or issuance of virtual assets. The BCB published its VASP authorisation framework in 2023, establishing that firms must obtain BCB authorisation before operating commercially and must comply with the anti-money laundering obligations issued under Brazil's AML statute, the Lei de Lavagem de Dinheiro. The financial-intelligence unit, the Conselho de Controle de Atividades Financeiras (COAF), remains the body to which suspicious-activity reports are filed. Both the BCB and COAF therefore sit in every domestic compliance program.

The Travel Rule overlay comes from COAF normative guidance that transposes the FATF standard into the Brazilian operational environment. A VASP conducting a virtual asset transfer above the applicable threshold must collect, hold and transmit originator data – full name, account identifier and, for wire-equivalents, address – and beneficiary data to the receiving VASP before or at the moment of the transfer. The obligation applies to both legs: a Brazilian firm sending to a foreign counterpart must push the data; a Brazilian firm receiving from a foreign counterpart must receive and validate it.

The cross-border dimension matters immediately. An exchange incorporated in, say, the Cayman Islands but serving Brazilian retail users may still be subject to BCB requirements if it qualifies as habitually operating in Brazil. Regulators have shown an increasing willingness to apply substance-over-form analysis. Before assuming that a non-Brazilian entity is outside the perimeter, the structure warrants careful review.

For a scoped assessment of whether your entity is captured by the BCB VASP regime, contact OBOLUS at info@oboluslaw.com. The process above describes the standard path. Your facts – the entity, the user base, the banking – change the analysis.

What exactly does the Travel Rule demand of a Brazilian VASP?

A Brazilian VASP subject to the Travel Rule must build a data-capture and data-transmission infrastructure that covers four operational layers: originator identification, beneficiary identification, inter-VASP transmission, and inbound-data screening.

On the originator side, the VASP must hold the account-holder's verified legal name, the account or wallet identifier used, and – for transactions that meet the wire-transfer analogy – a physical address or national-identification number. This information is collected at onboarding as part of the KYC (know-your-customer) process and refreshed in line with the firm's customer-due-diligence cycle.

On the transmission side, the data must accompany the transfer message. Brazil's BCB guidance follows the FATF model: the information travels with the transaction, not in a separate report filed after the fact. For domestic transfers between two BCB-authorised VASPs, the transmission channel is part of the bilateral settlement infrastructure. For cross-border transfers, the receiving VASP is often in a jurisdiction that has its own Travel Rule implementation – the EU under MiCA and the associated FATF-aligned AML regime, Singapore under the MAS Payment Services Act, the United Kingdom under FCA rules, or the United States under FinCEN guidance. A Brazilian VASP sending funds abroad must therefore understand not only its own obligations but whether the counterpart VASP is Travel-Rule-capable and whether a compliant data-sharing protocol is in place.

Inbound screening is equally demanding. A Brazilian VASP receiving a transfer must validate the originator data against its own KYC records and against COAF/OFAC/UN sanctions lists. Transfers where originator data is absent, inconsistent, or relates to a sanctioned party must be held, escalated to the MLRO (money-laundering reporting officer), and in most cases refused or returned.

Transaction-monitoring rules overlay the Travel Rule. BCB and COAF expect automated monitoring calibrated to the firm's risk appetite and customer profile: velocity alerts, unusual jurisdiction patterns, structuring detection, and PEP (politically exposed person) flags. The monitoring outputs feed the MLRO's suspicious-activity review queue, which drives COAF reporting timelines.

How do you build a Travel Rule compliance program in Brazil?

Building a compliant program follows a sequential process: regulatory scoping, structural design, system implementation, policy drafting, staff training, and audit-readiness. Each step has a cross-border dimension that operators frequently underestimate.

Step 1 – Regulatory scoping. Determine whether the entity is within the BCB VASP perimeter and which activity categories apply. Exchange, custody and payment functions carry different risk profiles and trigger different rule-sets. An operator that combines exchange and custody must address both.

Step 2 – Risk assessment. Under BCB and COAF expectations, the compliance program begins with a written risk assessment that maps the customer base, the products offered, the jurisdictions of counterpart VASPs, and the delivery channels. The risk assessment is not a one-time document: it is updated when the product or customer profile changes materially.

Step 3 – KYC framework design. The firm's KYC framework – the policies and procedures for customer identification, verification and monitoring – must be documented, approved by the board or equivalent governance body, and operationalised in the onboarding flow. Brazilian AML rules require enhanced due diligence for PEPs, for high-risk jurisdictions, and for transactions above certain thresholds. The thresholds themselves are set by COAF regulation and should be tracked as they evolve.

Step 4 – Travel Rule data infrastructure. The firm must select and integrate a Travel Rule messaging protocol. The market-standard tools – interoperability solutions that connect VASPs and allow structured data exchange – are recognised in the major hubs. A Brazilian VASP transacting with EU-based counterparts must be capable of receiving and processing data in the format those counterparts use, which means the Travel Rule system must support the relevant messaging standards.

Step 5 – Transaction monitoring calibration. The monitoring system should be calibrated using the risk assessment as its base. Rules and thresholds must be documented, tested and reviewed at defined intervals. Alert-handling procedures, escalation matrices and COAF SAR-filing workflows must be written into the operational manual.

Step 6 – MLRO appointment and training. A designated MLRO – a natural person with authority and independence – must be appointed and their role documented. Brazilian AML governance expects the MLRO to have direct reporting access to senior management and to maintain a log of decisions made on suspicious-activity referrals.

Step 7 – Independent audit. BCB and COAF expect periodic independent review of the AML/CFT program. The frequency and scope of audits vary by the firm's risk category, but the expectation of an audit trail – documented findings, management responses, remediation timelines – is consistent across the regime.

In our cross-border practice, we consistently see operators underestimate the time required for steps 3 and 4. KYC framework design and Travel Rule system integration typically take longer than the authorisation paperwork itself, particularly where the firm serves both Brazilian and foreign users and must reconcile BCB requirements with those of the users' home jurisdictions.

How does the Brazilian Travel Rule interact with foreign regimes?

The cross-border interaction between Brazil's Travel Rule and the rules of counterpart jurisdictions is the central operational challenge for any exchange that routes international transfers. Under FATF Recommendation 15, the Travel Rule is intended to be reciprocal: both sending and receiving VASPs must be capable of handling the data. In practice, the level of implementation differs widely across jurisdictions.

For transfers to EU-based VASPs, the applicable regime on the EU side is the Transfer of Funds Regulation (TFR) as updated to cover crypto-asset transfers, now aligned with MiCA. EU VASPs are required to capture and transmit Travel Rule data on all transfers regardless of amount. A Brazilian VASP sending to an EU counterpart should confirm that the counterpart is MiCA-authorised or transitioning under the relevant member state's MiCA implementation timetable and that it operates a compatible Travel Rule system.

For transfers to the United Kingdom, the FCA's MLR registration and the UK Travel Rule implementation apply. The UK Travel Rule follows a phased threshold approach. A Brazilian VASP with significant UK-bound transfer volume will need to map that flow against the UK rules and confirm counterpart capability.

For transfers to Singapore, the MAS Payment Services Act licensing regime and the MAS Travel Rule notice apply. Singapore VASPs are supervised by MAS, and counterpart due diligence is expected on both sides.

The most common gap we encounter in practice is not legal: it is operational. Two legally compliant VASPs – one Brazilian, one foreign – fail to exchange Travel Rule data because their messaging systems are not interoperable. The compliance failure that results is real even though the law on both sides is sound. Resolving that gap requires either a shared protocol or a bilateral data-sharing agreement.

Banking interaction adds a further layer. A Brazilian VASP receiving foreign transfers through a correspondent bank will face AML inquiries from the correspondent bank that run in parallel with – and are independent of – the BCB/COAF obligations. Banks apply their own de-risking policies. Demonstrating a well-documented Travel Rule program to a correspondent bank is, in our experience, as important commercially as satisfying the regulator.

A cross-border Travel Rule matter in practice

In a recent compliance matter, a payments company with Brazilian and European user bases had built separate AML programs for each jurisdiction without reconciling them. The firm's Travel Rule system pushed data correctly for domestic transfers but failed to transmit originator information for cross-border flows because its protocol version was not supported by counterpart VASPs in the EU. When the firm's EU correspondent bank flagged a pattern of incomplete Travel Rule data and suspended inbound settlement rails, the commercial impact was immediate. We mapped the inter-VASP messaging gap, negotiated a transitional data-sharing arrangement with the counterpart VASPs, and assisted the firm in upgrading its protocol to restore settlement within a matter of weeks. The BCB authorisation file was updated to reflect the remediation. No enforcement action was taken.

What does BCB VASP authorisation require alongside compliance?

BCB authorisation and the AML/Travel Rule compliance program are not separate exercises: the authorisation file requires the applicant to demonstrate a compliant AML/CFT framework before a licence is granted. The authorisation application typically includes the risk assessment, the compliance manual, the MLRO appointment letter, the KYC procedures and the Travel Rule operational documentation. A firm that tries to complete the authorisation before its compliance infrastructure is built will encounter substantive questions from the BCB that delay approval.

The BCB's licensing categories distinguish between different VASP activities. A firm that exchanges, a firm that custodies and a firm that provides payment services will each have a different regulatory footprint. Some operators will require authorisation across more than one activity category. Each category carries its own capital expectation, operational requirement and supervisory intensity. The capital minimums and fee schedules are set by BCB regulation and should be confirmed directly against current BCB publications, as they are subject to revision.

For a firm domiciled outside Brazil, the cross-border structural question is whether to apply for BCB authorisation directly through a Brazilian subsidiary or to seek to operate under an exemption or carve-out. The available paths are fact-specific and depend on where the firm holds its assets, where its servers and decision-making are located, and where its clients are resident. Operators we advise routinely find that the structural question and the compliance question are inseparable: the entity that holds the licence must be the entity whose compliance program the BCB will inspect.

If a prior application stalled or a banking relationship was suspended, a second read of the structure can surface the root cause. Write to info@oboluslaw.com to request a review. If a prior application stalled or an account was closed, a second read can surface the structural reason and the route back.

What are the most common Travel Rule compliance mistakes in Brazil?

The most common compliance failures we see fall into five categories, each preventable with correct program design at the outset.

Treating the Travel Rule as a data-collection project rather than a data-transmission project. Collecting originator data at onboarding satisfies the KYC obligation. It does not satisfy the Travel Rule unless that data is transmitted to the receiving VASP in real time. The distinction is critical, and regulators audit for it specifically.

Relying on a single offshore licence. A common assumption is that an offshore VASP registration – in the BVI, Cayman or a non-Brazilian EU jurisdiction – is sufficient to serve Brazilian users without BCB authorisation. That assumption does not hold once a firm habitually targets Brazilian residents through a Brazilian-language platform, Brazilian payment rails, or a local banking relationship. The BCB's perimeter analysis is substance-based.

Failing to conduct counterpart VASP due diligence. Before routing a transfer to a foreign VASP, a Brazilian firm should verify that the counterpart holds an appropriate licence in its home jurisdiction, operates a Travel Rule-capable system, and is not on a sanctions list. Routing to an unlicensed or sanctioned counterpart exposes the sending firm regardless of its own compliance standing.

Appointing an MLRO without the required authority or independence. The MLRO role requires genuine decision-making power. Regulators look for reporting lines, documented decisions and evidence that the MLRO's referrals are taken seriously by management. A compliance officer who cannot escalate over a commercial objection is not a functional MLRO.

Static risk assessments. Brazil's VASP environment is evolving. New BCB guidance, new COAF typologies and new product lines at the firm all require the risk assessment to be revisited. A program built in year one that is never updated will produce alerts calibrated to a business that no longer exists.

Which operator profile needs what program?

The depth and complexity of a Travel Rule compliance program in Brazil tracks closely with the operator's activity profile and user base. A simple decision-matrix in prose illustrates the key branching points.

Profile A – A Brazilian-incorporated exchange serving domestic users only. This operator is squarely within the BCB perimeter and requires full BCB authorisation, a BCB-compliant AML/CFT manual, COAF reporting infrastructure, and a domestic Travel Rule capability for peer-to-peer transfers between BCB-authorised VASPs. Cross-border obligations arise only when foreign users transact or when transfers route to foreign exchanges. Timeline to authorisation readiness – including compliance program buildout – typically runs to several months; the authorisation review itself adds further time that varies with the BCB's queue and the completeness of the application.

Profile B – A foreign-incorporated exchange with Brazilian users and Brazilian payment rails. This operator faces the threshold question of BCB perimeter capture first. If captured, it will need a Brazilian subsidiary, BCB authorisation and a full compliance program. The compliance program must reconcile BCB/COAF requirements with the home-jurisdiction requirements of the foreign entity's licensing regulator. The dual-compliance layer extends the build timeline and adds ongoing reporting obligations in both jurisdictions. This is the profile where legal counsel engagement at the structural design stage has the greatest impact on cost and speed.

Profile C – A custodian or payment gateway with no direct retail user relationship. A B2B-only operator may have a lighter KYC exposure on direct customer relationships but retains full Travel Rule obligations on transfers it processes. Transaction-monitoring calibration must reflect the indirect exposure through its institutional counterparts. BCB authorisation requirements apply if the operator qualifies as a VASP under the BCB regime.

About OBOLUS

OBOLUS is an independent digital-asset law boutique acting only for businesses. We advise exchanges, custodians, token issuers and funds on licensing across 70+ jurisdictions, on disputes and on-chain asset recovery across 25+ forums, and on the tax, banking and compliance programs that sit around them. Digital assets are the whole of our practice. We map the licence stack across operating, custody and payment layers before you commit – including the AML and Travel Rule infrastructure that regulators inspect at authorisation and audit. Our disputes team coordinates freezing relief and on-chain tracing across leading common-law forums when asset-recovery situations arise. To discuss your situation, contact info@oboluslaw.com.

FAQ

What does the Travel Rule require from a VASP?

The Travel Rule, derived from FATF Recommendation 15 and implemented in Brazil through BCB and COAF regulation, requires a virtual asset service provider to collect, hold and transmit originator and beneficiary identification data alongside a virtual asset transfer. The data must accompany the transfer in real time, not in a post-hoc report. Both the sending and the receiving VASP carry obligations. The specific data fields required – name, account identifier, address or national ID – follow the FATF wire-transfer analogy and are detailed in BCB and COAF normative guidance.

Who must act as MLRO for a crypto firm?

A BCB-authorised VASP must appoint a designated MLRO (money-laundering reporting officer) – a natural person, typically a senior compliance officer, who holds documented authority to make autonomous decisions on suspicious-activity referrals. The MLRO must have direct access to senior management or the board, maintain a decision log, and file reports to COAF within the prescribed timeframes. Regulators assess both the formal appointment and the practical authority of the MLRO. A compliance function without real escalation authority does not satisfy the requirement.

How do regulators audit crypto AML programs?

The BCB and COAF audit AML programs through a combination of authorisation-file review, periodic supervisory examinations and event-triggered inquiries. Examiners typically request the written risk assessment, the compliance manual, transaction-monitoring rule documentation, MLRO decision logs, SAR-filing records and evidence of staff training. A Travel Rule audit focuses specifically on data-transmission records: whether originator and beneficiary data was sent and received correctly, and how exceptions were handled. Firms with well-documented programs and clear audit trails consistently manage supervisory inquiries with less disruption than those relying on informal processes.

By Victor Olsen, Regulatory & Compliance Analyst – specialises in AML, Travel Rule implementation and VASP authorisation programs across Latin America and the EU.

This publication is general information about the law and does not constitute legal advice. It is not a substitute for advice tailored to your circumstances. OBOLUS accepts no liability for action taken or not taken on the basis of this material. For advice on your situation, contact info@oboluslaw.com.

Tell us the task — we'll map your options in 30 minutes.

Fixed-fee packages with defined scope and SLAs. The first call is free and under NDA. Business clients only.

Map your optionsinfo@oboluslaw.com · t.me/oboluslaw · reply < 2 hours