El Salvador's Bitcoin Law (the 2021 statute that recognised bitcoin as legal tender) and the subsequent Digital Assets Issuance Law established a regulated environment in which virtual asset service providers must satisfy know-your-customer and anti-money-laundering obligations before onboarding any user. The primary supervisory authority is the Comisión Nacional de Activos Digitales (CNAD), which administers the licensing, AML programme review and ongoing compliance expectations for digital-asset businesses operating in or from El Salvador. For an inbound operator, the KYC and onboarding framework is not optional colour – it is a hard condition of the licence and of the banking relationship that sustains the business.
Operators we advise frequently underestimate how much the El Salvador regime borrows from the FATF Recommendations (the global anti-money-laundering standards set by the Financial Action Task Force), including the Travel Rule (the obligation to transmit originator and beneficiary identification data alongside a virtual-asset transfer). The regime does not exist in isolation: a VASP licensed in El Salvador that serves users in the European Union, the United Kingdom or Singapore will also face the AML and KYC expectations of those jurisdictions. The cross-border compliance stack matters from day one. This page sets out the regulated basis, the practical onboarding requirements, the Travel Rule posture, the interaction with banking and tax, and the decision points an operator must work through before committing to the structure.
What is the regulatory basis for KYC in El Salvador?
The CNAD holds supervisory authority over digital-asset service providers under El Salvador's digital-assets legal regime, and it has aligned its AML/KYC expectations with the FATF framework, including Recommendation 15, which addresses virtual assets and virtual-asset service providers. Any entity conducting exchange, transfer, custody or issuance of digital assets for third parties requires a CNAD licence or registration – and an approved AML/CFT programme is a precondition, not a post-licence addition.
The AML/CFT programme must cover customer due diligence (CDD), enhanced due diligence (EDD) for higher-risk customers, ongoing transaction monitoring, suspicious transaction reporting to the relevant financial intelligence unit, and recordkeeping. These are not El Salvador novelties. They reflect the standard FATF structure that a well-run compliance operation in any major jurisdiction would recognise. What matters for the inbound operator is the specific documentation that CNAD reviewers expect to see when they assess whether the programme is genuine and proportionate.
In our cross-border practice, we see operators assume that a FATF-aligned AML policy from another jurisdiction will pass CNAD review without local adaptation. That assumption has cost firms significant time. Regulators in leading hubs increasingly expect a programme that names local obligations explicitly, identifies the Salvadoran risk environment in the business-wide risk assessment, and designates a responsible officer who can be reached by the local authority.
CNAD supervises the programme lifecycle – from pre-licensing review through periodic audit. Gaps identified at licensing stage must be resolved before the licence issues, not remediated afterwards.Who must comply with the El Salvador KYC regime?
Any business that qualifies as a virtual-asset service provider under El Salvador's digital-assets legislation – and that is not merely a retail user – falls within the CNAD's supervisory perimeter. The relevant categories include exchange operators (fiat-to-crypto and crypto-to-crypto), custodians holding digital assets for third parties, transfer and remittance services using digital assets, and issuers of digital assets offered to the public in El Salvador.
The test is functional, not formal. A business incorporated in Panama that offers exchange services to Salvadoran residents through a mobile application is engaging in regulated activity in El Salvador. The CNAD's jurisdictional reach extends to the conduct, not merely to the registered address. This is consistent with how MAS in Singapore, the FCA in the United Kingdom and VARA in Dubai each define their perimeters – by reference to the activity and the users, not purely by entity location.
For groups with a multi-entity structure – say, a Cayman holding company, a BVI operating entity and a Salvadoran-facing front end – each layer requires analysis. The entity that touches the Salvadoran user is the one that faces CNAD obligations. Allied counsel in the relevant jurisdiction can confirm the precise perimeter application for non-standard structures.
Operating without a CNAD licence or with an inadequate AML programme risks enforcement action, suspension of the licence, closure of local banking facilities and reputational consequences that affect operations in other jurisdictions. We regularly advise operators who have already launched and are now seeking to regularise – that path is more expensive and more uncertain than building correctly from the outset.
To map your compliance and licensing obligations before you commit to the El Salvador structure, contact OBOLUS at info@oboluslaw.com. The process above describes the standard path. Your facts – the entity, the user base, the banking – change the analysis. Map your options
What does a compliant KYC programme require in practice?
A compliant KYC programme under the El Salvador regime must address customer identification and verification, beneficial ownership identification for legal-entity customers, risk classification, ongoing monitoring and periodic review. Each element has a documentation expectation that CNAD reviewers will test at licensing stage and during supervision cycles.
Customer identification requires collecting government-issued identity documents and verifying them against independent sources. For natural persons, this typically means a national ID or passport, a proof of address and – for higher transaction volumes – a source-of-funds declaration. For legal entities, the programme must identify beneficial owners down to the individual level, following a threshold consistent with FATF guidance. The specific threshold applicable in El Salvador should be confirmed against current CNAD guidance, as it may be adjusted.
Risk classification drives the rest of the programme. A customer assessed as higher risk – for example, a politically exposed person (PEP), a customer from a FATF-listed jurisdiction or a business with opaque ownership – triggers EDD. EDD means deeper source-of-wealth inquiry, senior management sign-off on onboarding, and more frequent periodic review. The risk appetite documented in the business-wide risk assessment determines where the line sits, and the CNAD will assess whether the line is drawn sensibly given the operator's business model.
Transaction monitoring is an automated and a manual function. The automated layer flags transactions against rule-based parameters – velocity, counterparty risk, geographic risk, amount thresholds. The manual layer reviews the alerts that the automated system generates, escalates genuine suspicion to the MLRO (money-laundering reporting officer) and, where warranted, files a suspicious transaction report (STR). The monitoring ruleset must be calibrated to the actual product risk, not copied from a generic template.
Recordkeeping obligations require that identity records and transaction records be retained for a minimum period specified under Salvadoran law. Operators should build their data architecture with this retention requirement in mind, particularly where records are held on infrastructure outside El Salvador.
How does the Travel Rule apply to VASPs in El Salvador?
El Salvador has aligned its Travel Rule expectations with FATF Recommendation 16, which requires a VASP transmitting a virtual-asset transfer to pass originator and beneficiary identifying information to the receiving VASP or financial institution. The obligation applies at or above the applicable threshold, which should be confirmed against current CNAD guidance because FATF-member jurisdictions set their own de-minimis levels within the FATF framework.
In practice, Travel Rule compliance requires the sending VASP to collect, verify and transmit the full name, account number (or wallet address) and physical address – or a national identity number or date and place of birth – of the originator, together with the full name and account/wallet of the beneficiary. The receiving VASP must be able to receive that data and must screen it. Neither party is released from its own AML obligations merely because the other has complied.
The operational challenge for a Salvadoran-licensed VASP is the counterparty gap. The Travel Rule only functions if the counterparty VASP is both identifiable and equipped to receive the data in a compatible format. Where the counterparty is in a jurisdiction that has not yet implemented the Travel Rule, or where the transfer goes to an unhosted wallet, the operator must apply its own policy for handling those situations – typically involving enhanced monitoring or, in high-risk cases, declining the transfer.
We have seen operators build technically capable Travel Rule messaging systems but fail on the policy side: no documented procedure for unhosted wallets, no counterparty VASP due-diligence process and no escalation path for non-responsive counterparties. CNAD reviewers examine the policy as closely as the technical infrastructure. Both must be in place.
For a Salvadoran VASP serving users in the EU, the MiCA regime and the EU's Transfer of Funds Regulation impose their own Travel Rule parameters. The Salvadoran programme must be designed with those parallel obligations in mind. A Travel Rule solution that satisfies CNAD but leaves EU counterparties unable to receive compliant data is not a solution at all.
How does the KYC framework interact with banking and tax?
Banking is the pressure point where compliance failures become commercially fatal. Correspondent banks and local settlement banks in El Salvador – as in any jurisdiction – conduct their own KYC on the VASPs they serve. A VASP that cannot demonstrate a functioning AML programme, CNAD supervision and Travel Rule capability will not retain a banking relationship, regardless of licence status. Banking due diligence on crypto clients has intensified across the region, and operators without a clean compliance posture find themselves excluded from rails they need to function.
The interaction runs both ways. The bank's own AML team will ask to see the VASP's policies, its most recent independent audit, its STR filing record (volume, not content) and its sanctions screening configuration. Operators we advise build their AML programme with the bank's due-diligence questionnaire in mind from the outset – not as an afterthought when the account application is already in review.
On tax, El Salvador's 2023 tax reform eliminated income tax on foreign-sourced income from digital assets, which has drawn attention from operators structuring for efficiency. The tax position interacts with the KYC and compliance picture because it affects the entity structure – where the operating entity sits, where revenue is booked and, therefore, which jurisdiction's VASP supervision applies to which activity. A structure that is tax-efficient but creates a compliance gap in the operating layer is not a good structure. We map the licence, banking and tax stack together, not in sequence.
For groups with investors or beneficial owners in the United States, FATCA reporting obligations attach regardless of where the entity is licensed. For EU-connected investors, DAC8 (the EU's crypto-asset reporting directive for tax authorities) and the OECD's Crypto-Asset Reporting Framework (CARF) will increasingly require information exchange across borders. The Salvadoran licence does not shelter the group from those obligations.
What are the cross-border onboarding considerations?
A VASP licensed in El Salvador that onboards customers in multiple jurisdictions is not operating under a single KYC regime – it is operating under several simultaneously. The El Salvador/CNAD regime sets the floor for the local programme. The jurisdiction of each user may impose its own standard, and the more restrictive standard governs that customer relationship.
A common mistake is to design the KYC programme to the Salvadoran standard only and then scale it globally. That works until a user in Germany, the UAE or the UK triggers an obligation that the Salvadoran programme does not cover. Under MiCA, EU customers of a non-EU VASP may generate obligations under the EU regime depending on how the service is structured. Under the FCA's rules, marketing a crypto product to UK persons without registration creates criminal liability – regardless of where the VASP is licensed.
In a recent compliance restructuring matter, a digital-asset exchange licensed in a Central American jurisdiction had onboarded users across Latin America, Europe and Southeast Asia using a single KYC template calibrated to the home regime. When its EU banking partner conducted a de-risking review, the bank identified the gap and suspended settlement services. We were engaged to rebuild the programme in layers: a core FATF-aligned baseline, jurisdiction-specific overlays for the EU and Singapore user cohorts, and a Travel Rule infrastructure capable of messaging counterparts in multiple formats. The banking relationship was restored. The rebuild took several months and was materially more expensive than building correctly at launch.
The cross-border onboarding reality means that geographic restriction controls – blocking IP ranges, geo-fencing app stores, inserting residency confirmations in onboarding flows – are a first line of defence but not a complete answer. Users misrepresent their location. The KYC programme must catch the discrepancy at the identity-document verification stage. Regulators in leading hubs, including ESMA's guidance to NCAs under MiCA, have been explicit that passive geo-restriction does not discharge the operator's compliance duty.
Which operator profile fits El Salvador, and what are the key risks?
El Salvador suits a specific set of operator profiles – and not every business model is a good fit. The following assessment covers the most common scenarios we encounter.
Profile A – the remittance-focused operator. A business whose core model is bitcoin or stablecoin remittance to and from El Salvador has strong product-market fit with the regime. The legal-tender status of bitcoin, the Chivo wallet infrastructure and the CNAD's familiarity with remittance use cases make the licensing path relatively direct. The key risk is the cross-border AML layer: remittance corridors to the United States and to parts of Central America carry elevated sanctions and money-laundering risk, and the VASP's transaction-monitoring configuration must reflect that.
Profile B – the exchange operator seeking an EU or US user base. An operator that wants the El Salvador licence as a primary licence while serving EU or US users will encounter the MiCA and FCA/SEC/FinCEN perimeters almost immediately. The Salvadoran licence does not passport into the EU. The operator needs either a CASP authorisation from an EU national competent authority, FCA registration for UK activity, or a deliberate geographic restriction with genuine enforcement. Timeline for adding an EU CASP layer runs to many months after the Salvadoran licence issues.
Profile C – the token issuer. An issuer using El Salvador as the legal seat for a digital-asset issuance must comply with the Digital Assets Issuance Law's whitepaper-equivalent obligations and with the CNAD's investor-protection expectations. The KYC obligation falls on the issuer if it deals directly with investors; if it uses an intermediary, the intermediary's programme must meet the same standard. Cross-border securities law exposure – particularly for US persons – requires a separate analysis by allied counsel in the relevant jurisdiction.
Across all profiles, the single most common structural error we see is treating the CNAD licence as a compliance certificate rather than a starting point. The licence confirms that the programme met the standard at authorisation. Ongoing compliance – monitoring, STRs, Travel Rule, periodic review and response to CNAD supervisory queries – is the operational reality that the business must sustain from day one.
If a prior application stalled or an existing programme has drawn a regulatory query, a second read can surface the structural reason and the route forward. Contact OBOLUS at info@oboluslaw.com or message us via t.me/oboluslaw. Map your options
Self-assessment: is your KYC programme ready for El Salvador?
Before submitting a CNAD application – or before onboarding the first Salvadoran user under an existing licence – an operator should be able to answer yes to each of the following questions. A no is a gap that must be closed, not a risk to accept.
- Does the business-wide risk assessment identify El Salvador's specific risk environment, including the remittance corridor risk, the PEP population relevant to the business and the product-specific risk factors?
- Is there a designated MLRO with authority to file STRs, access transaction records and escalate to senior management?
- Does the CDD procedure cover both natural-person and legal-entity customers, including beneficial-ownership identification to the applicable threshold?
- Is there a documented EDD procedure for PEPs, high-risk jurisdictions and unusual corporate structures?
- Is the transaction-monitoring ruleset calibrated to the actual product and user risk, not to a generic template?
- Does the Travel Rule procedure cover both outbound and inbound transfers, address unhosted wallets and include a counterparty VASP due-diligence process?
- Has the programme been independently reviewed within the past twelve months, and is the review documented in a format that a CNAD examiner can assess?
- Is there a training log showing that all relevant staff received AML/KYC training appropriate to their role?
Operators who cannot answer yes to all eight questions are carrying compliance risk that is visible to the CNAD, to banking partners and – in the event of a regulatory incident – to law enforcement. The cost of fixing gaps before licensing is a fraction of the cost of fixing them under a remediation order.
Related at OBOLUS
- AML and Travel Rule compliance for digital-asset businesses – end-to-end programme design, MLRO support and regulatory review across major hubs
- VASP business risk assessment in Lithuania – how the EU MiCA transition affects your risk-assessment obligations in a leading EU licensing hub
- Custody arrangements for funds: the compliance burden in practice – safeguarding, segregation and the AML layer that sits around a custody structure
FAQ
What does the Travel Rule require from a VASP?
The Travel Rule, drawn from FATF Recommendation 16, requires a sending VASP to transmit identifying information about the originator and beneficiary to the receiving VASP or financial institution alongside a virtual-asset transfer. The data typically includes the originator's full name, account or wallet identifier, and physical address or national identity reference, together with the beneficiary's name and account identifier. The obligation applies at or above the applicable threshold, which varies by jurisdiction. Both sending and receiving VASPs carry independent compliance duties.
Who must act as MLRO for a crypto firm?
A money-laundering reporting officer (MLRO) is a designated individual within the business who holds authority to receive internal suspicion reports, make external suspicious-transaction filings to the relevant financial intelligence unit, and act as the primary point of contact for the regulator on AML matters. Most FATF-aligned regimes – including El Salvador's CNAD framework – require the MLRO to be a senior employee with genuine authority and access to transaction data. The role cannot be outsourced in its entirety; accountability must sit with a named individual inside the firm.
How do regulators audit crypto AML programs?
Regulators typically audit a digital-asset firm's AML programme through a combination of document review, transaction testing and interviews with key personnel. Examiners will request the business-wide risk assessment, CDD and EDD policies, transaction-monitoring rules and alert-disposition logs, STR filing records, training documentation and independent audit reports. They will also test a sample of onboarded customer files against the stated CDD standard. Gaps between the written policy and actual practice are the most common finding – and the most damaging, because they suggest the programme is a document rather than an operational reality.
OBOLUS is an independent digital-asset law boutique acting only for businesses. We advise exchanges, custodians, token issuers and funds on licensing across 70+ jurisdictions, on disputes and on-chain asset recovery across 25+ forums, and on the tax, banking and compliance that sit around them. We map the licence stack across operating, custody and payment layers before you commit – so that the structure you build is the structure that works under regulatory scrutiny. We advise crypto exchanges, custodians, token issuers and funds across more than seventy licensing jurisdictions. Digital assets are the whole of our practice. To discuss your situation, contact info@oboluslaw.com.
By Victor Olsen, Regulatory & Compliance Analyst – specialising in AML programme design, VASP supervision and the cross-border compliance obligations of digital-asset businesses across Central America and the major licensing hubs.
This publication is general information about the law and does not constitute legal advice. It is not a substitute for advice tailored to your circumstances. OBOLUS accepts no liability for action taken or not taken on the basis of this material. For advice on your situation, contact info@oboluslaw.com.