EST · MMXXVI
Home/Jurisdictions/El Salvador/MLRO and compliance officer function in El Salvador
Compliance, AML & Travel Rule

MLRO and compliance officer function in El Salvador

Mlro and compliance officer function in El Salvador. Cross-border digital-asset legal counsel for business – licensing, disputes and structuring. Talk to OBOLUS

El Salvador occupies a singular position in the global digital-asset environment. It was the first country to make Bitcoin legal tender and has since built a dedicated Digital Asset Service Provider (DASP) regime that imposes specific AML/CFT obligations – including a named Money Laundering Reporting Officer (MLRO) and a compliance officer function – on every licensed entity. For any business operating under that regime, getting those functions right is not optional: deficiencies in the compliance structure are one of the leading reasons the Salvadoran regulator initiates supervisory action against licensed DASPs.

This page sets out the regulated basis for the MLRO and compliance officer roles in El Salvador, how those functions interact with the Travel Rule (the obligation to transmit originator and beneficiary data alongside a transfer), the cross-border reality for businesses that also hold licences in other hubs, and the decision points that a general counsel or founder should resolve before going live.

What is the regulated basis for AML compliance in El Salvador?

El Salvador's anti-money laundering obligations for digital-asset businesses flow from the Bitcoin Law and its implementing regulation, together with the country's core AML/CFT statute, which applies to DASPs in the same way it applies to traditional financial institutions. The primary supervisory body for DASPs is the Comisión Nacional de Activos Digitales (CNAD), which was established specifically to regulate the digital-asset sector. CNAD derives its supervisory authority from the Digital Assets Issuance Law and the DASP framework, and it applies FATF Recommendation 15 standards as the baseline for virtual-asset oversight.

Under that regime, every licensed DASP is required to implement an AML/CFT program that meets standards aligned with FATF's Recommendations, including a customer due diligence framework, ongoing transaction monitoring, suspicious activity reporting, and – critically – a designated MLRO and a compliance function with clear authority and resources. Those are not administrative checkboxes. In our cross-border practice, we see regulators treat an under-resourced compliance function as a structural risk finding, not a minor gap.

El Salvador also sits within the broader FATF framework. As a member of GAFILAT (the FATF-style regional body for Latin America and the Caribbean), the country's supervisory approach to DASPs is subject to mutual evaluation cycles that directly shape how CNAD interprets and enforces its compliance expectations.

What must the MLRO function do in a Salvadoran DASP?

The MLRO is the designated individual responsible for receiving, assessing and filing suspicious transaction reports with the Financial Intelligence Unit – the Unidad de Investigación Financiera (UIF) – and for ensuring that the DASP's AML/CFT program is operative and current. The role carries personal responsibility. That is a deliberate design feature common to FATF-aligned jurisdictions: attaching individual accountability concentrates attention on the quality of the compliance function.

In practice, the MLRO must be:

  • a natural person, not a corporate entity;
  • senior enough within the organisation to have genuine authority over compliance decisions;
  • accessible to the regulator and the UIF on demand;
  • resident or reachable within a time zone and schedule that supports timely suspicious-activity reporting.

Operators we advise routinely underestimate the last point. A DASP licensed in El Salvador and operated from Europe or North America must ensure the MLRO function can respond to a UIF inquiry or a regulatory request within a timeframe consistent with the local regime – not on a 12-hour delay. Where the beneficial owner group manages multiple jurisdictions, we work through a responsibility matrix that assigns the MLRO function per licence, with clear escalation lines between them.

The compliance officer function is related but distinct. Where a smaller DASP may combine the two roles in a single individual, a larger exchange or custodian will typically separate them: the MLRO owns the STR pipeline and the relationship with the UIF; the compliance officer owns the program design, the KYC framework (the policies and procedures for knowing your customer), the training calendar and the board-level reporting. CNAD expects both functions to be documented in the DASP's internal governance framework.

For a scoped assessment of your MLRO and compliance officer structure in El Salvador, contact OBOLUS at info@oboluslaw.com. The process above describes the standard path. Your facts – the entity type, the user base, the holding structure – will change the analysis. Map your options.

How does the KYC and transaction monitoring program work?

A functional KYC framework under El Salvador's DASP regime requires the business to collect and verify customer identity at onboarding, apply risk-based enhanced due diligence for higher-risk counterparties, and maintain records in a form that is accessible for regulatory inspection. The specifics of what "verify" means – document types, liveness checks, source-of-funds enquiries – are calibrated by the customer's risk profile and the value of the relationship.

Transaction monitoring is the live counterpart to onboarding KYC. A DASP is expected to maintain systems that flag unusual patterns: transaction volumes inconsistent with the customer's declared profile, structuring behavior, rapid movement of funds across wallets, or counterparty relationships with sanctioned addresses. Blockchain analytics tools have become a de facto element of a defensible transaction monitoring program; CNAD supervisory guidance reflects the expectation that on-chain activity is monitored, not just fiat rails.

The UIF receives suspicious transaction reports (STRs) from licensed DASPs. The threshold for filing is not certainty of a crime – it is suspicion. Failure to file when suspicion arises is an independent compliance breach, regardless of whether the underlying activity turns out to be criminal. In our practice, we draft the STR policy as a standalone document within the compliance manual, with escalation triggers, time limits and a clear decision record.

How does the Travel Rule apply to El Salvador DASPs?

The Travel Rule – derived from FATF Recommendation 16 and its Guidance for Virtual Assets – requires a DASP to pass originator and beneficiary information alongside any qualifying virtual-asset transfer, whether the transfer is outbound to another VASP or inbound from one. El Salvador's AML framework incorporates this obligation as part of the DASP regime, consistent with GAFILAT and FATF expectations.

For a Salvadoran DASP sending or receiving transfers to or from counterparts in MiCA-regulated jurisdictions, Singapore, Hong Kong, or the United Kingdom, the Travel Rule creates a bilateral compliance question: both sides of the transfer must exchange the required data, and both must have a compliant mechanism to do so. The data fields typically required include the originator's name, account identifier and address (or other identifying information), and equivalent beneficiary data.

Several practical issues arise at the point of implementation. First, the counterpart VASP must be identifiable and willing to exchange data – the "sunrise problem" (the asymmetry between jurisdictions that have implemented the Travel Rule and those that have not) is not fully resolved at the global level. Second, the data exchange must occur within the transaction flow, which requires technical integration. Third, the data must be stored securely and made available to the regulator on request.

Operators we advise in El Salvador typically implement Travel Rule compliance through one of the established VASP-to-VASP messaging protocols. The choice of protocol affects interoperability with counterparty VASPs in other hubs – a point that has direct consequences for a DASP that routes a significant proportion of its volume through major exchange corridors.

How does the Salvadoran MLRO function interact with other jurisdictions?

For a business that holds a DASP authorisation in El Salvador alongside licences in, for example, a MiCA-authorised EU jurisdiction or under the MAS Payment Services Act in Singapore, the MLRO function becomes a multi-layered structure. Each licence typically requires a named MLRO satisfying that jurisdiction's residency, seniority and qualification standards. Those standards are not identical.

The cross-border reality is that AML policies drafted for one jurisdiction may not satisfy another. A KYC framework designed for CNAD will not automatically meet FCA expectations in the United Kingdom, nor the FSRA's requirements in ADGM. We regularly advise groups that operate across three or four jurisdictions to build a tiered compliance architecture: a group-level AML policy that sets the floor, and jurisdiction-specific addenda that address local requirements in detail.

Banking is the other dimension. A Salvadoran DASP that relies on a correspondent banking relationship in the United States or Europe will find that its banking counterpart applies its own AML standards – which are calibrated to FinCEN requirements in the US or EBA guidelines in the EU. Deficiencies in the DASP's compliance documentation can cause a bank to restrict or terminate the account, even where CNAD is satisfied. We map the AML requirements of the bank, the DASP regulator and any secondary jurisdiction as a single exercise, not three separate ones.

If your compliance architecture spans multiple jurisdictions and you need a second read before a regulatory review, write to OBOLUS at info@oboluslaw.com. If a prior application stalled or a banking relationship was restricted, a structured review can surface the gap and the path forward. Map your options.

How does this work in a real cross-border situation?

In a recent compliance matter, a payments business licensed in El Salvador as a DASP and operating remittance corridors into North America encountered a Travel Rule implementation problem: its US correspondent bank required evidence of a compliant VASP-to-VASP data exchange protocol as a condition of maintaining the fiat settlement account. The DASP had an AML manual and an MLRO in place, but its Travel Rule documentation was written in general terms and did not demonstrate a live, tested protocol. We restructured the compliance documentation – separating the policy statement from the operational procedure, documenting the protocol selection rationale, and preparing a testing log – and assisted the MLRO in presenting the revised program to the bank's compliance team. The account relationship was preserved.

What are the most common compliance mistakes Salvadoran DASPs make?

The most consequential error is treating the MLRO appointment as a formality rather than a substantive function. Naming an individual on a licence application without giving that person the authority, budget and access to do the job produces a paper compliance structure that fails at the first real test – whether that test is a UIF inquiry, a CNAD supervisory visit or a banking due diligence review.

A common assumption is that a single offshore licence is enough to serve clients globally. It is not. A DASP licensed only in El Salvador and offering services to users in EU member states, Singapore or the United Kingdom is operating in those jurisdictions' regulatory perimeters without authorisation. Each of those regimes – MiCA, the MAS Payment Services Act, FCA registration – has its own compliance, MLRO and Travel Rule requirements. Serving a global user base without mapping that exposure is a material risk that compliance documentation alone cannot cure.

Other recurring issues include: a KYC framework that is not risk-stratified (treating all customers identically regardless of transaction volume or geography); transaction monitoring that covers fiat rails but not on-chain activity; and STR policies that set a de facto certainty threshold when the legal standard is suspicion. Each of these can be identified and corrected before a supervisory cycle begins – but only if the compliance function has the mandate and the resources to do so.

Self-assessment: is your MLRO function ready for a CNAD review?

A compliance officer preparing for a CNAD supervisory visit, a bank due diligence request, or an expansion into a second jurisdiction should be able to confirm the following with documented evidence:

  • The MLRO is a named natural person with a documented mandate, direct board access and an allocated budget.
  • The KYC framework is risk-stratified, documented and applied consistently across all onboarding channels.
  • Transaction monitoring covers both fiat and on-chain activity, with written escalation procedures.
  • The STR policy sets a suspicion – not certainty – threshold, with a decision record for every assessed transaction.
  • Travel Rule implementation is documented at the operational level, not just the policy level, with a tested protocol and a counterparty due diligence procedure for unhosted wallets.
  • The compliance program has been reviewed and updated within the past twelve months, with board sign-off recorded.
  • If the DASP operates in additional jurisdictions, group-level and local-level policies are clearly delineated.

Where one or more of those items cannot be confirmed, the gap creates exposure – to CNAD, to banking counterparts, and to the individual MLRO personally. We map the licence stack, the compliance architecture and the banking relationship as one mandate before a client goes live or faces a review.

Related at OBOLUS

FAQ

What does the Travel Rule require from a VASP?

The Travel Rule, derived from FATF Recommendation 16, requires a VASP to collect and transmit originator and beneficiary information alongside a qualifying virtual-asset transfer. Both the sending and receiving VASP must exchange specified data fields – typically name, account identifier and address or other identifying information. The obligation applies regardless of whether the counterpart is in the same jurisdiction or a different one. Non-compliance is an AML breach independent of the underlying transaction's character.

Who must act as MLRO for a crypto firm?

Under FATF-aligned regimes, including El Salvador's DASP framework, the MLRO must be a named natural person with genuine seniority and authority within the organisation. They are responsible for receiving and assessing internal suspicion reports, filing STRs with the financial intelligence unit, and maintaining the AML program. The role cannot be delegated to a corporate entity. Where a firm holds licences in multiple jurisdictions, each licence typically requires its own designated MLRO meeting that jurisdiction's specific standards.

How do regulators audit crypto AML programs?

Regulators typically audit AML programs through a combination of document review and interview. Supervisors examine the written AML policy, KYC onboarding records, transaction monitoring logs, STR decision records and Travel Rule implementation documentation. They also interview the MLRO and compliance officer directly. A program that exists only on paper – without operational records, training logs and tested procedures – will not survive scrutiny. In our practice, regulators in leading FATF-aligned jurisdictions have moved toward risk-based, thematic reviews that focus on the quality of judgment, not only completeness of documentation.

OBOLUS is an independent digital-asset law boutique acting only for businesses. We advise exchanges, custodians, token issuers and funds on licensing across 70+ jurisdictions, on disputes and on-chain asset recovery across 25+ forums, and on the compliance, AML and banking structures that sit around them. We map the licence stack, the MLRO function and the Travel Rule architecture as one mandate rather than three disconnected workstreams – so that a supervisory review or a banking due diligence request does not expose a gap that was preventable. To discuss your compliance structure, contact info@oboluslaw.com.

By Victor Olsen, Regulatory & Compliance Analyst – specialising in AML/CFT program design, MLRO function structuring and Travel Rule implementation for digital-asset businesses across Latin America and multi-jurisdictional groups.

This publication is general information about the law and does not constitute legal advice. It is not a substitute for advice tailored to your circumstances. OBOLUS accepts no liability for action taken or not taken on the basis of this material. For advice on your situation, contact info@oboluslaw.com.

Tell us the task — we'll map your options in 30 minutes.

Fixed-fee packages with defined scope and SLAs. The first call is free and under NDA. Business clients only.

Map your optionsinfo@oboluslaw.com · t.me/oboluslaw · reply < 2 hours