Panama sits at a cross-border inflection point for digital-asset businesses. The country has historically attracted international holding structures, yet its anti-money laundering (AML) regime has undergone material tightening in recent years under sustained pressure from the Financial Action Task Force (FATF) and correspondent banking partners. For a crypto exchange, custodian or token-issuer operating through a Panamanian entity — or simply onboarding users from the region — the KYC and onboarding framework in Panama is now a live compliance obligation, not a planning footnote. This page maps the regulated basis, the practical onboarding process, the cross-border interaction with banking and tax, and the decision points a business must resolve before it goes live.
The Regulated Basis for KYC in Panama
Panama's AML compliance obligations for businesses handling digital assets flow from its core financial-crime prevention statute and the supervisory mandate of the Superintendencia de Bancos de Panamá (SBP), the Superintendencia del Mercado de Valores (SMV) and, for money-transmission and payment activities, the Ministerio de Comercio e Industrias (MICI). Panama does not yet operate a bespoke crypto-asset service-provider regime equivalent to MiCA in the European Union or the VARA rulebook in Dubai. Instead, digital-asset businesses are assessed against existing AML/CFT (combating the financing of terrorism) provisions where their activities fall within a regulated category — money transmission, securities dealing or financial intermediation.
The FATF placed Panama on its "grey list" of jurisdictions under increased monitoring in 2019 and again in 2023, citing deficiencies in beneficial-ownership transparency and in the supervision of designated non-financial businesses and professions (DNFBPs). That grey-list status has a direct practical consequence: correspondent banks treat Panamanian-domiciled entities with heightened scrutiny, and a crypto firm operating through Panama faces a steeper due-diligence burden from its banking partners than an equivalent entity in Singapore or a MiCA-passported EU hub.
In our cross-border practice, we regularly advise clients who discover this differential only after their first account-opening rejection. The grey-list context is not a dealbreaker, but it recalibrates the KYC framework a business must build — both to satisfy local regulators and to maintain access to the dollar-clearing infrastructure that any serious digital-asset operation depends on.
Who is a reporting entity in Panama? The applicable regime covers financial intermediaries and, by extension, businesses that transfer, exchange or custody value. A virtual-asset service provider (VASP) — any entity carrying out exchange, transfer, custody or related services with digital assets — that is incorporated in Panama, or that solicits Panamanian-resident customers, is expected to apply customer due-diligence standards consistent with FATF Recommendation 15. The legal obligation attaches to the activity, not to whether a dedicated crypto licence has been issued.
CTA #1 — The regime described above sets the standard path. Your facts — the entity's activity type, its user base and the banking partners you need — change the analysis materially. Map your options with OBOLUS.
What Does the KYC Onboarding Framework Actually Require?
A Panamanian reporting entity must apply a risk-based customer due-diligence (CDD) process before establishing a business relationship or executing a transaction above applicable thresholds. In practice, this means four things for a digital-asset business.
First, identity verification. The business must collect and verify the legal identity of every customer — full name, date of birth, nationality, residential address and an official identity document. For corporate customers, the chain of beneficial ownership must be traced to the natural person or persons who ultimately own or control the entity, applying a threshold consistent with FATF standards. Beneficial-ownership data must be current; reliance on stale corporate documents is a recurrent finding in supervisory reviews.
Second, purpose and nature of the relationship. The onboarding questionnaire must establish why the customer is opening an account, the expected volume and source of funds, and the categories of assets or services involved. For a crypto exchange, this means asking about the customer's prior trading activity, funding sources and expected counterparties — not just collecting a passport scan.
Third, sanctions and PEP screening. Every customer — individual and corporate — must be screened against consolidated sanctions lists (OFAC, UN, EU) and checked for politically exposed person (PEP) status. A PEP designation triggers enhanced due diligence (EDD): a more detailed source-of-wealth inquiry, senior-management sign-off and more frequent periodic review. In the digital-asset context, a PEP who funds an account in stablecoins rather than wire transfer receives the same EDD treatment — the instrument does not reduce the obligation.
Fourth, ongoing monitoring. KYC is not a one-time gate. The applicable regime requires transaction monitoring calibrated to the customer's risk profile, periodic refresh of customer data, and prompt escalation of unusual activity to the compliance function. Operators we advise routinely underinvest in the ongoing-monitoring layer, treating onboarding as the whole of the program — that miscalibration is the most common gap a supervisory review surfaces.
How Does the FATF Travel Rule Apply to Panama-Based VASPs?
The Travel Rule — the obligation, derived from FATF Recommendation 16, to pass originator and beneficiary data alongside a virtual-asset transfer — applies to VASPs operating in Panama in the same way it applies across FATF-member regimes. Panama's position as a FATF member means its reporting entities are expected to implement Travel Rule transmission when they send or receive virtual-asset transfers above the applicable threshold.
In practice, this requires a Panama-based VASP to identify its counterparty VASP before executing a transfer, exchange originator and beneficiary information through an interoperable messaging protocol, and retain that data for the required record-keeping period. The challenge in Panama — and in many emerging-market FATF-compliant regimes — is that the local supervisory guidance on Travel Rule implementation is less developed than the equivalent guidance from ESMA under MiCA or from MAS under Singapore's Payment Services Act. The framework principle is clear; the operational detail requires careful legal analysis of the current regulatory position.
A cross-border angle that matters here: a Panama entity sending USDT to a counterparty VASP in a MiCA jurisdiction will be assessed by the receiving VASP against that receiving regime's Travel Rule requirements — which may be more prescriptive. A Panama-based VASP must therefore build outbound Travel Rule compliance to the highest standard demanded by its counterparty network, not merely to the domestic minimum.
What Does the Onboarding Process Look Like in Practice?
For a digital-asset business establishing a compliant onboarding program in Panama, the process follows a broadly sequential structure, though the timeline depends on the complexity of the customer segments and the technology choices made.
The first stage is program design. The business maps its customer types — retail users, corporate counterparties, institutional depositors — against a risk matrix. Each category receives a tiered due-diligence standard: simplified CDD for lower-risk profiles (where permitted), standard CDD for the baseline, and EDD for high-risk categories including PEPs, customers from high-risk jurisdictions and customers with complex beneficial-ownership structures.
The second stage is policy documentation. Panama's applicable supervisory expectations require a written AML/CFT program — covering customer risk rating, onboarding procedures, transaction monitoring rules, escalation protocols, training obligations and record-keeping standards. In our practice, we have seen programs that are technically complete on paper but operationally disconnected: the procedures say one thing, the system does another. A gap between written policy and live implementation is a material supervisory finding.
The third stage is technology integration. The business selects and configures KYC tooling (identity verification, liveness detection, document authentication) and a transaction monitoring system calibrated to the risk appetite set in the policy. Blockchain analytics — tools that score on-chain addresses against known illicit-activity clusters — are increasingly expected as part of the monitoring stack for crypto-specific VASPs, even where the local guidance does not yet mandate a specific tool.
The fourth stage is the appointment of a compliance officer — typically referred to as the MLRO (money-laundering reporting officer) — with the authority and independence to file suspicious-activity reports and to escalate to senior management. The MLRO role carries personal accountability in most FATF-aligned regimes; Panama is not an exception.
Depending on the business's activity type and the supervisory body involved, a program review or registration step may also be required before the business goes live. Timelines vary by activity and regulator; completing this stage typically takes a matter of weeks from submission of a complete file.
The Cross-Border Reality: Banking and Tax Interaction
For a digital-asset business in Panama, the KYC program is not just a regulatory obligation — it is a prerequisite for banking access. Correspondent banks serving Panamanian financial institutions apply their own enhanced due-diligence standards, and a crypto firm that cannot demonstrate a credible, documented AML program will not open or maintain a USD correspondent account.
The grey-list context amplifies this. Banks in the United States, Europe and Asia-Pacific that clear dollar transactions for Panamanian entities are themselves supervised by regulators — the Federal Reserve, the FCA, MAS — who expect them to manage their correspondent-banking risk rigorously. A weak KYC program at the Panamanian entity level becomes a derisking event at the correspondent level. In our cross-border practice, we have seen clients lose banking access not because their program was absent, but because it was not documented and evidenced to the standard a correspondent bank's compliance team needed to see.
On the tax side, a Panama entity operating a digital-asset business must assess its territorial-tax position carefully. Panama operates a territorial tax system: income derived from sources outside Panama is generally exempt from Panamanian income tax. However, the characterization of income as foreign-source versus domestic-source requires analysis, particularly where the business has employees, servers or customer-facing operations in Panama. A structure that generates Panamanian-source income without the corresponding compliance and tax-registration posture creates both tax and AML risk — the two are correlated in supervisory review.
Additionally, a Panama-domiciled VASP with users in MiCA jurisdictions, Singapore or Hong Kong will be subject to the outbound regulatory expectations of those regimes. The local KYC framework in Panama sets the floor; the most demanding regime in the customer base often sets the ceiling.
CTA #2 — If a prior application stalled or a banking relationship closed, a second read of the program structure can surface the reason and the route forward. Write to OBOLUS at info@oboluslaw.com.
What Are the Most Common KYC Compliance Mistakes in Panama?
Operators entering Panama with a digital-asset structure make a predictable set of errors. Each is correctable, but each also represents a window of enforcement or banking exposure while it persists.
The first is treating the offshore structure as a compliance substitute. A Panama entity held through a BVI holding company does not inherit a KYC program from the holding layer. The regulated activity triggers the obligation at the entity level performing the activity.
The second is beneficial-ownership opacity. Panama's corporate legislation has historically permitted nominee arrangements and bearer-share structures. FATF grey-listing drove material reform. A VASP that still relies on nominee directors without documented, current beneficial-ownership records will fail a supervisory review and will not satisfy a correspondent bank's enhanced due-diligence inquiry.
The third — and the most consequential for crypto-specific businesses — is the absence of blockchain analytics in the transaction monitoring stack. A sanctions-list check at onboarding does not detect a customer who subsequently receives funds from a mixer or a sanctioned exchange. The AML obligation is ongoing; the tooling must match that ongoing nature.
The fourth is MLRO appointment without authority. An MLRO who is also the CEO, or who reports to the revenue function, lacks the structural independence the role demands. Regulators and correspondent banks both look at reporting lines when assessing program credibility.
A Practical Illustration
In a recent compliance structuring matter, a payments company incorporated in Panama sought correspondent-banking access for a stablecoin settlement product. Its existing KYC documentation covered individual user onboarding but lacked a corporate-counterparty CDD procedure and had no Travel Rule transmission protocol. We reviewed the program, redesigned the onboarding questionnaire for institutional counterparties, produced a Travel Rule policy aligned to FATF Recommendation 16, and rebuilt the MLRO reporting structure with documented sign-off authority. The correspondent bank's compliance review concluded favorably, and the account was opened in a leading financial center. The work was completed across a single quarter.
A Common Assumption: One Offshore Licence Covers Global Onboarding
A common assumption among businesses structuring through Panama is that a single licence or registration in one jurisdiction provides sufficient regulatory cover to onboard users worldwide. That assumption does not hold. The country where users are located typically imposes its own licensing, onboarding and data-handling obligations on the entity serving those users — regardless of where the entity is domiciled. A Panama entity onboarding EU residents is visible to national competent authorities under MiCA. The same entity onboarding Singaporean residents is visible to MAS. The local KYC program must be built to the highest standard encountered across the full user-base geography, and the legal-entity structure must be mapped to the activity in each jurisdiction. In our practice, we map the licence stack across operating, custody and payment layers before a client commits to a structure.
The Decision Point: Is Panama the Right Compliance Jurisdiction?
Panama offers genuine advantages for certain digital-asset structures: territorial tax treatment, a sophisticated corporate law system, access to Panama City's financial infrastructure, and proximity to Latin American user bases. For businesses whose primary activity is holding, treasury management or cross-border payments with a Latin American focus, Panama can be a defensible domicile when paired with a properly constructed AML program.
For businesses requiring a regulated VASP licence that is recognized cross-border — a passport into the EU, regulatory equivalence under MiCA, or recognized-exchange status in Hong Kong — Panama does not yet offer that credential. The grey-list status adds a correspondent-banking friction layer. Businesses in those profiles should assess a MiCA-authorized jurisdiction in the EU (including Lithuania or Malta during the MiCA transition), the VARA regime in Dubai, or MAS in Singapore as primary licensing hubs, potentially with a Panama entity serving a supplementary treasury or holding function.
Profile A: a Latin American payments company primarily clearing USDC between regional business counterparties, with no EU or APAC retail users — Panama, structured correctly, can be a viable primary domicile with a well-documented AML program and a strong MLRO appointment.
Profile B: a crypto exchange seeking passportable EU access with a Panama holding layer — the Panama entity serves a structural function, but the regulated operating entity must sit in a MiCA-authorized jurisdiction. The KYC program must meet both the Panamanian baseline and the CASP authorization standard.
Profile C: a stablecoin issuer requiring reserve and ART/EMT compliance — Panama does not provide the issuer authorization framework that MiCA requires. The issuer authorization must be sought in an EU member state; the Panama entity may remain as a treasury vehicle.
In each case, the KYC and onboarding program is not a standalone deliverable — it is part of a licensing, banking and tax architecture that must be designed as one coherent mandate.
Related at OBOLUS
- AML and Travel Rule compliance for digital-asset businesses – full-service compliance structuring across licensing and operational layers
- AML/CFT policy drafting in Singapore – MAS-aligned program design for Payment Services Act licensees
- Economic substance for licensed VASPs in El Salvador – substance requirements for Chivo-adjacent and Bitcoin-law structures
FAQ
What does the Travel Rule require from a VASP?
The Travel Rule requires a VASP sending a virtual-asset transfer to collect and transmit originator and beneficiary information — full name, account identifier and, where available, address data — to the receiving VASP before or simultaneously with the transfer. The obligation applies to transfers above the applicable threshold set by the supervising jurisdiction. VASPs must also verify that counterparty institutions are themselves subject to AML supervision before transmitting. Record-keeping of transmitted data is required for the period specified in the applicable regime.
Who must act as MLRO for a crypto firm?
A money-laundering reporting officer (MLRO) must be a sufficiently senior individual with documented authority to file suspicious-activity reports, access all relevant transaction and customer data, and escalate findings to the board without interference from commercial functions. In Panama and in most FATF-aligned regimes, the MLRO role carries personal accountability. The individual must be named in the written AML program, have appropriate compliance experience, and report to governance — not to the revenue or operations function.
How do regulators audit crypto AML programs?
Supervisors typically review the written AML program for completeness, then test whether the documented procedures match actual operational practice — checking sample onboarding files, transaction-monitoring alert logs, MLRO escalation records and training attendance. For crypto-specific firms, regulators increasingly expect evidence of blockchain analytics integration and Travel Rule message logs. A program that is complete on paper but lacks operational evidence — no alert disposals, no EDD files, no MLRO sign-off records — will generate material findings regardless of how well the policy document reads.
OBOLUS is an independent digital-asset law boutique acting only for businesses. We advise exchanges, custodians, token issuers and funds on licensing across 70+ jurisdictions, on disputes and on-chain asset recovery across 25+ forums, and on the tax, banking and compliance structures that sit around them. Digital assets are the whole of our practice. We structure licensing, banking and tax as one mandate rather than three disconnected workstreams — mapping the licence stack across operating, custody and payment layers before you commit. To discuss your situation, contact info@oboluslaw.com or message us at t.me/oboluslaw.
By Victor Olsen, Regulatory & Compliance Analyst — specializing in AML program design, FATF-aligned KYC frameworks and cross-border VASP compliance structuring for digital-asset businesses.
This publication is general information about the law and does not constitute legal advice. It is not a substitute for advice tailored to your circumstances. OBOLUS accepts no liability for action taken or not taken on the basis of this material. For advice on your situation, contact info@oboluslaw.com.