EST · MMXXVI
Home/Jurisdictions/El Salvador/AML/cft policy drafting in El Salvador: Legal Requirements for Businesses
Compliance, AML & Travel Rule

AML/cft policy drafting in El Salvador: Legal Requirements for Businesses

Aml/cft policy drafting in El Salvador. Cross-border digital-asset legal counsel for business – licensing, disputes and structuring. Talk to OBOLUS.

El Salvador sits at an unusual crossroads for digital-asset compliance. It was the first sovereign state to adopt bitcoin as legal tender under its Bitcoin Law (the legislative regime enacted in 2021), and its subsequent Digital Assets Issuance Law extended a formal regulatory perimeter to a wider class of virtual assets. Any business operating within that perimeter – whether a domestic exchange, a cross-border payments processor or an inbound operator establishing a local presence – must maintain a written AML/CFT policy (an anti-money-laundering and countering-the-financing-of-terrorism program) that satisfies the Banco Central de Reserva de El Salvador (BCR) and the Superintendencia del Sistema Financiero (SSF). Operating without one, or with a policy that cannot survive supervisory scrutiny, exposes the business to enforcement action, frozen correspondent rails and loss of registration.

The regulated basis is the Digital Assets Issuance Law and the country's AML/CFT framework, which aligns in principle with FATF Recommendation 15 on virtual assets. The BCR and SSF jointly supervise registered digital-asset providers. Getting the policy right from the outset – not retrofitting it when an examiner visits – is the decisive variable.

This page walks through the regulated perimeter, the specific policy requirements the supervisors expect, the cross-border complications for internationally active operators, the process for building a compliant program and the decision point at which outside counsel adds disproportionate value.

Who Needs an AML/CFT Policy in El Salvador?

Any digital asset service provider (DASP) operating under the Digital Assets Issuance Law is required to maintain a formal AML/CFT program as a condition of its registration. The scope is broader than many inbound operators assume. Custody, exchange, transfer and issuance activities each trigger the obligation independently. A foreign firm that onboards Salvadoran residents, even from an offshore entity, should obtain a legal opinion on whether its activity pattern crosses the jurisdictional threshold before it concludes that no local compliance program is needed.

The SSF expects the program to be documented, board-approved and operationally live – not a template filed at registration and then ignored. In our practice, the most common enforcement vulnerability we see is a policy that was adequate at filing but was never updated to reflect product changes, new counterparty types or evolving FATF guidance on virtual assets.

The practical scope of "who is covered" also extends to correspondent relationships. A payment processor that routes transactions through a Salvadoran-registered entity for bitcoin settlement may find that the SSF treats it as a regulated participant regardless of where the corporate parent sits. The Digital Assets Issuance Law and the SSF's supervisory mandate jointly determine the perimeter, and that perimeter follows the activity, not the domicile of the entity.

For a scoped assessment of whether your business model triggers a local AML/CFT obligation in El Salvador, contact OBOLUS at info@oboluslaw.com. The process above describes the standard path. Your facts – the entity structure, the user base and the transaction flows – change the analysis. Map your options.

The Regulatory Framework: BCR, SSF and FATF Alignment

El Salvador's AML/CFT architecture sits on two pillars: domestic legislation implementing FATF standards and sector-specific digital-asset regulation administered by the BCR and SSF. FATF's Recommendation 15 requires jurisdictions to regulate VASPs for AML/CFT purposes, and El Salvador's framework reflects that obligation. The supervisory body with day-to-day oversight of digital-asset AML compliance is the SSF, which has published guidance on the minimum content it expects in a registered provider's written program.

The BCR retains policy-setting authority, including the ability to issue implementing regulations that elaborate on the statutory requirements. In our cross-border practice, we have seen the gap between the statute and the implementing regulations trip up operators who read only the primary legislation. The SSF's expectations on risk-appetite statements, customer due diligence (CDD) tiers and transaction-monitoring calibration go beyond what the statute's text alone makes apparent.

FATF Recommendation 15 specifically addresses virtual assets and virtual asset service providers, requiring risk-based supervision, registration or licensing, and AML/CFT program standards consistent with those applied to conventional financial institutions. El Salvador's framework adopts this approach. An operator whose program satisfies MiCA-level CASP obligations in the EU or MAS Payment Services Act requirements in Singapore will find the structural logic familiar – but the local implementing rules and the SSF's supervisory style require a jurisdiction-specific read.

One practical asymmetry matters: El Salvador is not yet a FATF member. It participates as an observer and has committed to implementing FATF standards, but the domestic regime is still maturing. The SSF has demonstrated a willingness to issue corrective notices and to suspend registrations, but the enforcement density is lower than in a FATF-member jurisdiction. That is not a reason for a thinner program – it is a reason to build ahead of the curve, because the supervisory environment is tightening.

What Must an AML/CFT Policy Contain?

A compliant AML/CFT policy for a Salvadoran digital-asset provider must address, at minimum, six substantive areas that the SSF expects to verify on examination.

First, a risk assessment: a documented evaluation of the business's inherent money-laundering and terrorist-financing risks, segmented by customer type, product, delivery channel and geography. For a DASP, geographic risk is particularly material – the BCR and SSF will expect the firm to have assessed risks arising from transactions with high-risk jurisdictions as defined by FATF.

Second, customer due diligence (CDD) and enhanced due diligence (EDD) procedures. The policy must specify the identity verification steps applied at onboarding, the triggers for enhanced scrutiny (politically exposed persons, high-risk geographies, large or unusual transactions) and the documentation the firm retains. Blockchain-specific considerations – whether the firm accepts transfers from unhosted wallets, how it handles counterparty wallet screening – belong in this section.

Third, transaction monitoring: the rules engine or typology-based approach the firm uses to detect suspicious activity, the escalation path from alert to investigation to suspicious transaction report (STR), and the record of calibration reviews. The SSF expects evidence that the monitoring logic is appropriate to the firm's specific product mix – not a generic ruleset copied from a retail bank.

Fourth, Travel Rule compliance procedures. Under the applicable VASP provisions aligned with FATF Recommendation 16, originator and beneficiary information must accompany virtual asset transfers above the applicable threshold. The Travel Rule obligation applies to every covered transfer, and the policy must specify how the firm collects, transmits and verifies that data, including what it does when a counterpart VASP cannot or will not provide the required information.

Fifth, sanctions screening: real-time or near-real-time screening against OFAC, UN Security Council and other applicable sanctions lists, with documented escalation procedures for matches.

Sixth, governance and training: the MLRO (Money Laundering Reporting Officer) designation, the internal audit or independent review cycle, and the training program for staff with AML/CFT responsibilities.

The SSF does not prescribe the exact format of a policy, but it does expect each of these areas to be addressed in a document that a non-specialist examiner can follow. In our practice, overly technical policies that read well to a compliance engineer but poorly to a regulatory examiner generate unnecessary supervisory friction.

How Does the Travel Rule Apply to El Salvador-Based VASPs?

The Travel Rule (the FATF requirement that originator and beneficiary information travel with a virtual asset transfer) applies to DASPs registered in El Salvador in the same way it applies to VASPs in other FATF-aligned regimes. The specific data fields required – originator's name, account number or wallet address, and transaction reference, along with equivalent beneficiary data – mirror the FATF standard.

The practical challenge is bilateral. A Salvadoran-registered DASP sending a transfer to a counterpart VASP in a MiCA-compliant EU jurisdiction, or to a MAS-licensed DPT provider in Singapore, must ensure its Travel Rule messaging solution is interoperable with the recipient's. Where the recipient VASP is in a jurisdiction that has not yet implemented the Travel Rule, the sending firm must decide how to handle the information gap – the policy must specify the firm's approach, whether that is holding the transfer, applying enhanced due diligence or another documented procedure.

FATF's Recommendation 16 sets the originator and beneficiary information standard that applies to covered transfers. El Salvador's implementing regime adopts this standard. Operators we advise regularly discover that their policy says the right things about the Travel Rule but their operational workflow – the actual messaging between their system and the counterpart VASP's – does not deliver on the policy's promise. The gap between a written commitment and an operational capability is precisely what an SSF examiner will test.

For cross-border operators, the Travel Rule intersects with sanctions screening in a non-obvious way. A transfer that satisfies the Travel Rule data requirement but involves a sanctioned address or a jurisdiction under an OFAC blocking programme must be stopped regardless. The policy must sequence these checks correctly.

Cross-Border Interaction: Banking and Tax

For a business registered in El Salvador, the AML/CFT policy is not an isolated compliance document. It is the foundation of every banking relationship the firm needs to operate. Correspondent banks that clear US-dollar transactions – the dominant settlement currency in El Salvador, which is a dollarized economy – will require evidence of a live, board-approved AML/CFT program before they open or maintain an account for a DASP.

We have seen Salvadoran-registered digital-asset businesses lose banking access not because their policy was substantively wrong but because it was not presented in the form a US correspondent bank's compliance team expected. The framing matters: a policy that emphasizes local regulatory compliance without explicitly mapping to FATF standards and FinCEN expectations will not satisfy a US correspondent's due diligence checklist. FinCEN's BSA/AML requirements are the lens through which a US correspondent bank evaluates the policy of a foreign digital-asset counterpart.

Tax interaction is a separate layer. El Salvador's bitcoin legal-tender status has implications for how bitcoin transactions are characterized for income and VAT purposes under domestic law. A DASP whose policy treats bitcoin receipts as a foreign-currency equivalent for AML record-keeping purposes needs to ensure that characterization is consistent with its tax reporting. Operators we advise are careful to align the AML team's transaction records with the tax team's revenue recognition – inconsistencies between the two create exposure in a combined regulatory and tax examination.

For inbound operators establishing a Salvadoran presence while maintaining operations in the EU, Singapore or the UAE, the cross-border interaction is more complex. The local policy must satisfy the SSF, but the group's consolidated AML policy – which may be governed by MiCA/ESMA standards, MAS requirements or VARA rulebooks – must also be consistent with it. Where the group policy is more demanding than the local minimum, the local entity should adopt the higher standard; where local law requires something the group policy does not address, a local addendum is needed.

To map the compliance, banking and tax stack for your El Salvador build before you commit capital, write to info@oboluslaw.com. If a prior banking relationship was lost or an account was closed, a second read of the policy can surface the structural gap and the route back. Map your options.

The Drafting Process: Steps, Timeline and Common Mistakes

Building a compliant AML/CFT policy for a Salvadoran DASP is a sequential process that typically runs across several weeks, depending on the complexity of the business model and the availability of internal subject-matter input.

The first step is a business-line risk assessment. Before drafting the first word of a policy, the legal team needs to understand the full range of customer types, transaction patterns, product features and geographic exposures the firm operates with. This is not a formality – the SSF expects the risk assessment to be specific to the firm, not generic. In our experience, operators who skip or rush this step produce policies that are internally inconsistent: the risk appetite statement says "medium risk" but the CDD procedures describe a "low risk" workflow.

The second step is policy architecture: deciding which elements belong in the master policy document, which belong in a separate procedures manual and which belong in product-specific annexes. This is particularly important for a DASP with multiple product lines, because the transaction-monitoring rules for a peer-to-peer bitcoin exchange are materially different from those for a stablecoin custody service.

The third step is drafting, review by the designated MLRO, and board approval. El Salvador's supervisors expect the board to have formally adopted the policy, not simply been informed of it. The board minutes should reflect substantive engagement – questions asked, scope confirmed, approval recorded.

The fourth step is operational implementation: loading the policy's CDD requirements into the onboarding workflow, configuring the transaction-monitoring ruleset, establishing the Travel Rule messaging capability and training staff. A policy that is not operationally implemented is a liability, not an asset. The SSF can ask for evidence that procedures work in practice.

Common mistakes we see: first, importing a policy template from another jurisdiction without localizing it to El Salvador's specific supervisory expectations; second, failing to include a documented escalation matrix for STRs; third, treating Travel Rule compliance as a technology problem rather than a legal and operational one, with the result that the technology is in place but the legal obligations on when to hold a transfer are not properly codified; fourth, neglecting to schedule the first annual review, so the policy is current at launch but stale by the time of first examination.

A micro-matter from our recent practice illustrates the drafting gap: a payments company expanding from Europe sought BCR and SSF registration to route bitcoin settlement through El Salvador. Its EU-facing policy was MiCA-aligned and substantively strong. In the process of localising it, we identified that its Travel Rule procedures did not address the "sunrise issue" – the firm's policy assumed all counterpart VASPs would also be Travel Rule-compliant, which is not the case in several markets where its users were concentrated. We built a hold-and-review workflow for non-compliant counterpart transfers, documented it as an annex and the registration proceeded without a remediation request from the SSF.

Decision Matrix: Which Operator Profile Needs What

Different business profiles call for materially different policy architectures. Understanding which profile fits your business shapes the drafting scope before a single clause is written.

A domestic exchange or payments processor registered solely in El Salvador, serving retail users, needs a full standalone policy covering the six substantive areas above, calibrated to a retail-user risk profile. The Travel Rule and STR workflows are the high-examination-priority areas for this profile. The indicative drafting and implementation timeline is several weeks, assuming the risk assessment is completed first. The key risk is under-calibrated transaction monitoring that generates either too many false positives (creating operational friction) or too few alerts (a supervisory red flag).

An inbound operator with a group compliance program – for example, a MiCA-licensed CASP adding El Salvador as a deployment jurisdiction – needs a local policy addendum and a gap analysis against the group program. The drafting scope is narrower, but the cross-border interaction work (banking, group governance, Travel Rule interoperability) is substantial. The timeline may be shorter for the policy document itself, but the operational implementation often takes longer because it involves group IT systems. The key risk is a group policy that is silent on the SSF's specific STR reporting procedures or that uses different customer-risk-rating categories than the BCR expects.

A token issuer subject to the Digital Assets Issuance Law needs an AML/CFT policy that addresses issuer-specific risks: secondary-market trading it does not directly control, wallet screening at the point of token distribution and post-issuance holder-transfer monitoring. The policy architecture is different from an exchange or payments processor, and the Travel Rule analysis – which applies to transfers of the issued token once it is treated as a virtual asset under the law – requires specific drafting attention.

For all three profiles, the banking interaction is the forcing function. No policy, no correspondent account. No correspondent account, no US-dollar clearing. The sequencing is: policy first, banking second, operations third.

Self-Assessment Checklist Before You File

Before submitting a registration application that includes an AML/CFT policy, an operator should be able to confirm each of the following points.

  • The risk assessment is specific to the firm's actual product mix and customer geography – not a generic DASP template.
  • CDD and EDD procedures specify the exact documentation collected, the storage format and the retention period.
  • Transaction-monitoring rules are documented, calibrated to the firm's specific transaction patterns and reviewed at least annually.
  • The Travel Rule workflow addresses both compliant and non-compliant counterpart VASPs, with a documented hold-and-review procedure for the latter.
  • Sanctions screening covers OFAC, UN Security Council and, where applicable, EU consolidated lists – and runs on transfer initiation, not batch-end-of-day.
  • The MLRO is named, qualified and has a documented escalation path for STRs to the SSF.
  • The board has formally adopted the policy by resolution, with minutes reflecting substantive review.
  • The policy has been operationally implemented: staff trained, systems configured, first review date calendared.

If any of these points cannot be confirmed, the policy is not ready for submission – or for examination.

Related at OBOLUS

FAQ

What does the Travel Rule require from a VASP?

The Travel Rule, derived from FATF Recommendation 16, requires a virtual asset service provider to collect and transmit originator and beneficiary information with every covered virtual asset transfer. Required data includes the originator's name, account identifier or wallet address, and a transaction reference, along with equivalent beneficiary information. The sending VASP must also verify the accuracy of originator data it transmits. Where the receiving VASP cannot accept Travel Rule data, the sender must have a documented procedure for handling the transfer – which may include holding it pending confirmation or declining it.

Who must act as MLRO for a crypto firm?

The MLRO (Money Laundering Reporting Officer) must be a senior individual with sufficient authority, independence and operational knowledge to fulfil the role effectively. El Salvador's supervisors expect the MLRO to be named in the policy, reachable by the regulator and responsible for all STR filings with the SSF. For a small DASP, the MLRO is often a co-founder or a senior compliance officer. For a larger operator or an inbound group entity, the local MLRO must have genuine decision-making authority over local compliance matters – a nominal appointment will not satisfy supervisory expectations.

How do regulators audit crypto AML programs?

The SSF typically examines an AML/CFT program by requesting the written policy and procedures, the risk assessment, samples of CDD files, transaction-monitoring alert logs with disposition records, STR filing history and evidence of staff training. Examiners look for consistency: does the policy say one thing and the records show another? Common findings include transaction-monitoring thresholds that do not match the documented risk appetite, CDD files missing key documentation and Travel Rule logs that show transfers sent without required data. A program that is both well-drafted and operationally implemented will withstand this scrutiny.

OBOLUS is an independent digital-asset law boutique acting only for businesses. We advise exchanges, custodians, token issuers and funds on licensing across 70+ jurisdictions, on disputes and on-chain asset recovery across 25+ forums, and on the compliance, AML and Travel Rule programs that sit around every regulated activity. We map the licence stack across operating, custody and payment layers before you commit. Our disputes team coordinates freezing relief and on-chain tracing across leading common-law forums. Digital assets are the whole of our practice. To discuss your situation, contact info@oboluslaw.com.

By Victor Olsen, Regulatory & Compliance Analyst – specialising in AML/CFT program design and supervisory engagement for digital-asset businesses across emerging and established regulatory regimes.

This publication is general information about the law and does not constitute legal advice. It is not a substitute for advice tailored to your circumstances. OBOLUS accepts no liability for action taken or not taken on the basis of this material. For advice on your situation, contact info@oboluslaw.com.

Tell us the task — we'll map your options in 30 minutes.

Fixed-fee packages with defined scope and SLAs. The first call is free and under NDA. Business clients only.

Map your optionsinfo@oboluslaw.com · t.me/oboluslaw · reply < 2 hours