Digital-asset businesses operating in or through Panama face a compliance question that cuts across legal regimes: how does sanctions screening (the systematic checking of counterparties against designated-persons lists) interact with Panama's anti-money-laundering framework, and what does that mean for a VASP (virtual asset service provider) serving a cross-border client book? The answer matters not just for the Panamanian regulator but for every correspondent bank, payment rail and institutional partner the firm relies on. A program that works on paper but fails on implementation is a frozen account or a supervisory enforcement notice waiting to materialize.
Panama has layered its digital-asset compliance expectations onto an existing AML/CFT architecture that predates crypto by decades. Under the legislation that brought VASPs into the regulated perimeter, providers of virtual-asset services are treated as subject entities for AML/CFT purposes, placing them alongside banks, casinos and trust companies in the supervisory regime administered by the Superintendency of Banks of Panama (SBP) and, in certain activity categories, the Superintendencia del Mercado de Valores (SMV). FATF's Recommendation 15, which extends the standard AML obligations to virtual assets and their service providers, sits behind both frameworks. Understanding which obligations attach, and in what sequence, is the first decision a new entrant must make.
This page addresses the regulated basis for sanctions screening in Panama, the operational program a compliant VASP must maintain, how the cross-border reality of a digital-asset business complicates that program, and the practical considerations any inbound operator should work through before the first transaction clears.
What Is the Regulated Perimeter for Crypto AML in Panama?
Panama's primary AML statute – as amended to incorporate FATF Recommendation 15 – defines the category of obligated entities broadly enough to capture any enterprise that habitually exchanges, transfers, administers or custody digital assets on behalf of third parties. This is the functional test: the regulator looks at what the business does, not what it calls itself. A business that provides exchange, custody, transfer or brokerage services in virtual assets is a subject entity regardless of where it is formally incorporated, if it has operational presence or serves clients in Panama.
The SBP is the primary prudential and AML supervisor for entities that hold a financial license or conduct activities requiring one in the Panamanian banking and payments environment. The SMV has a parallel competence where digital assets are structured or marketed as securities. Both regulators expect a written sanctions-screening policy as a component of the broader AML/CFT program. The policy must address, at minimum: which lists are screened, at what frequency, how matches are escalated, and the recordkeeping chain that demonstrates the program is running.
In our regulatory practice, we consistently see new entrants underestimate this last element. The written policy is not the compliance program; it is the first document the regulator requests when it wants to see the compliance program. The operational evidence – screening logs, match-review records, training attestations, testing results – must exist independently and be retrievable on short notice.
Consult OBOLUS before your first transaction clears. The regulated perimeter question is a threshold issue: getting the answer wrong determines everything that follows. To have a preliminary conversation about your entity structure and activity scope in Panama, write to info@oboluslaw.com.
Which Sanctions Lists Must a Panama-Based VASP Screen Against?
A Panama-based VASP must screen against the official lists published by the Panamanian government – including those maintained by the Unidad de Análisis Financiero (UAF), Panama's financial intelligence unit – but that minimum is rarely sufficient in practice. The operational reality of digital-asset businesses is that their banking partners, stablecoin infrastructure and institutional clients impose separate screening requirements that track US and EU designations.
This creates a layered obligation. The UAF list incorporates United Nations Security Council consolidated designations, so that baseline is non-negotiable. US OFAC designations – and in particular the SDN (Specially Designated Nationals) list – are effectively mandatory for any VASP that processes US-dollar-denominated stablecoins, holds a US correspondent banking relationship, or whose clients include US persons. OFAC's secondary-sanctions exposure extends to non-US entities that facilitate transactions involving designated parties, irrespective of the entity's own national jurisdiction.
EU designations under the Common Foreign and Security Policy become relevant when the business uses Euro-denominated payment rails, has EU institutional clients, or employs staff in EU member states. Where the VASP also provides services into the UK market, the FCA's designated-persons framework runs in parallel.
The practical consequence: a Panama-incorporated exchange serving a global client book must maintain a multi-list screening matrix, reviewed and updated on a defined cycle, with automated tooling sufficient to catch additions between update cycles. A single, infrequently-refreshed list is a material gap that correspondent banks will identify on their own periodic reviews.
How Does the KYC Framework Support Sanctions Screening?
Sanctions screening in isolation does not constitute an AML program. The KYC framework (know-your-customer identity and risk-assessment procedures) and transaction monitoring (automated or manual review of activity against behavioral typologies) are the operational backbone on which screening sits. In Panama's regulated environment, these are distinct but interdependent requirements: a VASP must know enough about its customer to screen effectively, and it must monitor enough of the transaction pattern to catch evasion techniques.
CDD (customer due diligence) under the applicable Panamanian AML provisions requires the VASP to identify and verify the beneficial owner of the account – not just the nominal holder. For corporate clients, the chain of ownership must be traced to the natural person(s) exercising ultimate control. Enhanced due diligence applies where the risk profile of the customer or the transaction suggests elevated exposure: PEPs (politically exposed persons), high-risk jurisdictions, unusual transaction structures or counterparties in sectors with known AML typologies.
Transaction monitoring in the crypto context carries a technical dimension that has no analogue in traditional banking: the blockchain record is public, pseudonymous and immutable. A competent monitoring program integrates on-chain analytics – using forensic tools that attribute addresses to known entities, flag exposure to sanctioned addresses and score the risk of transaction paths – alongside the traditional behavioral-analytics layer. Regulators in the leading hubs increasingly expect on-chain analytics to be part of the documented methodology, not an optional add-on.
We regularly advise clients on the design of monitoring programs that satisfy Panamanian regulatory expectations while also meeting the due-diligence standards of institutional counterparties operating under US, EU and UK regimes. The intersection is where most compliance failures occur: a program designed only for the local regulator will routinely fall short of what a correspondent bank's compliance team requires.
Does the Travel Rule Apply to Crypto Transactions in Panama?
The Travel Rule – the obligation under FATF Recommendation 16 to pass originator and beneficiary data with each virtual-asset transfer – applies in principle to Panamanian VASPs under the FATF-aligned AML framework. The rule requires that when a VASP sends a virtual-asset transfer above a defined threshold, it must transmit identifying information about the sending customer and the intended recipient to the receiving VASP, and the receiving VASP must verify and retain that information.
Implementation specifics – including the precise threshold, the technical protocol required and the timeline for full enforcement – are matters that should be confirmed against the current supervisory guidance in force at the time of application. The direction of travel is clear: Panama, like other FATF member and observer jurisdictions, is expected to bring its implementation into alignment with the revised FATF standards. A VASP setting up operations now should build Travel Rule compliance into the infrastructure architecture from the outset, rather than retrofitting it after launch.
The cross-border complexity of Travel Rule compliance deserves emphasis. A Panama-based VASP transacting with counterpart VASPs in the EU is subject to MiCA's Travel Rule provisions from the EU side of the transaction, even if Panama's own Travel Rule enforcement has not yet caught up to the same technical standard. The EU-based VASP will decline or flag transactions from a counterpart that cannot demonstrate a compliant data-transfer capability. The result is effective market exclusion – not through regulatory action but through the operational choices of better-resourced counterparts.
In our cross-border practice, we have seen this dynamic play out in markets that moved to FATF alignment later than their institutional trading partners. The solution is to build to the higher standard from day one. The marginal cost of an additional Travel Rule protocol integration at launch is a fraction of the cost of being excluded from interbank and inter-VASP settlement flows after the fact.
Who Must Serve as MLRO, and What Does the Role Require?
Every regulated VASP in Panama must designate a Money Laundering Reporting Officer (MLRO) – the individual responsible for receiving internal suspicion reports, making filings to the UAF, maintaining the AML program and acting as the primary point of contact for the regulator on AML matters. This is not an honorary or administrative title. The MLRO carries personal regulatory exposure if the program is deficient, if reports are not filed when the threshold is met, or if records are not maintained.
Under Panama's AML framework, the MLRO must have sufficient seniority and independence to challenge business decisions that create compliance risk. In smaller VASPs, the MLRO role is often held by a senior operational officer; in larger firms, it is a dedicated compliance function. The regulator expects the MLRO to demonstrate genuine knowledge of the firm's products, client base and the specific risk typologies associated with digital-asset activity.
For an inbound operator that does not already have a qualified Panamanian compliance officer, the appointment of the MLRO is a critical pre-launch step. Some operators use an outsourced or fractional MLRO arrangement in the early stage, subject to regulator acceptance. The acceptability of that arrangement depends on the scope of activity, the firm's risk profile and the specific supervisory expectations of the SBP or SMV for the relevant license category.
How Does Sanctions Screening Interact With Banking Access in Panama?
Panama's banking sector applies its own AML and sanctions-screening standards to VASP clients, and those standards are in many cases more demanding than the minimum statutory requirement. Panamanian banks, particularly those with US correspondent relationships, operate under the shadow of US regulatory expectations – including OFAC compliance and Bank Secrecy Act standards as applied through correspondent-bank agreements. A VASP that satisfies the SBP's AML requirements but cannot demonstrate OFAC-grade screening will find that the practical question of banking access remains unresolved.
This is the point at which the Panamanian compliance question intersects with what amounts to a global banking-access question. A VASP's banking relationship is not determined solely by the domestic regulator. The correspondent bank's own compliance function will conduct periodic reviews of the VASP's program; deficiencies in sanctions screening, transaction monitoring or Travel Rule capability are grounds for account closure on commercial, not regulatory, terms.
Operators we advise on Panamanian entry routinely face this dynamic: the regulatory approval is achievable, but the banking relationship – and the stable, institutional-grade payment rails it represents – requires a compliance standard that tracks US expectations even for a firm that has no US clients and no US operations. Building the compliance architecture to that standard from the outset is significantly cheaper than remediation after an account is closed.
If your compliance program has already been questioned by a banking partner, a structural review can identify the gap and the route back. Write to info@oboluslaw.com to discuss a scoped assessment.
How Do Multi-Jurisdiction Operations Change the Compliance Design?
For a VASP that uses Panama as one layer of a multi-jurisdiction structure – with the operating entity in one hub, custody in a second, and payment processing in a third – sanctions screening cannot be designed as a single-jurisdiction program. Each entity in the structure attracts the AML and screening obligations of its own regulator; but the transaction flow runs across all of them, and a gap in any layer exposes the whole structure.
The minimum architecture for a multi-entity VASP group is a group-wide sanctions policy that sets the standard at the most demanding regime in the group, with local addenda that address jurisdiction-specific procedural requirements. The group policy covers list selection, screening frequency, escalation chain, recordkeeping format and testing cadence. Local addenda address the specific filing obligations, threshold levels and supervisor-reporting timelines applicable in each jurisdiction.
Where Panama sits alongside a MiCA-regulated EU entity, the EU entity's obligations under the applicable MiCA provisions and the associated AML Regulation will set the effective group standard for screening and Travel Rule compliance. The Panama entity operates under that group policy, with its own local supplement addressing UAF filing and Panamanian recordkeeping requirements.
In a recent matter, a multi-entity digital-asset group had built separate compliance programs for each of its operating jurisdictions. Each program satisfied the local regulator. But the group had no consolidated sanctions list, no cross-entity escalation protocol and no mechanism for flagging a counterparty flagged in one jurisdiction to the screening function in another. We designed a group AML architecture that consolidated the list matrix, centralized the escalation record and built a cross-entity notification protocol – and the group passed a subsequent correspondent-bank review without remediation requests.
What Must an Inbound Operator Establish Before Going Live in Panama?
For a business entering the Panamanian digital-asset market, the compliance setup sequence is a pre-launch obligation, not a post-launch task. The following is the operational framework a compliant VASP should have in place before the first customer transaction is processed.
The first step is entity registration and regulatory notification: confirming which supervisory body – SBP or SMV – has jurisdiction over the specific activity and completing the applicable registration or licensing process. The MLRO designation and the written AML policy are typically components of the registration package, not separate submissions.
The second step is the sanctions-list matrix: documenting which lists are screened, at what frequency, through what tooling, and by whom. The matrix must account for the lists required by the Panamanian regime and the lists required by the firm's banking partners and institutional counterparties.
The third step is the KYC and CDD framework: onboarding procedures, identity verification tooling, beneficial-ownership documentation requirements, risk-rating methodology and EDD triggers. This must be tested against the actual client population before launch – the risk-rating methodology calibrated to the firm's own business model, not a generic template.
The fourth step is on-chain analytics integration: selecting and deploying a blockchain forensics tool, calibrating the alert thresholds, and establishing the review workflow for triggered alerts. The tool selection should be documented and the rationale defensible to the regulator.
The fifth step is Travel Rule protocol selection: identifying the technical solution for transmitting originator/beneficiary data in virtual-asset transfers, testing it against the counterpart VASPs the firm expects to transact with, and documenting the solution in the AML policy.
A common mistake at this stage is treating the compliance build as a box-checking exercise rather than an operational system. The SBP and correspondent bank reviewers look at whether the program is running, not merely whether it was written.
Does an Offshore Licence Satisfy Panama's Compliance Requirements?
A common assumption among operators entering the Latin American digital-asset market is that a licence obtained in a favorable offshore hub – BVI, Cayman or a European VASP registration – suffices for compliance purposes when the business serves Panamanian clients or operates infrastructure in Panama. That assumption is structurally incorrect and carries material risk.
A foreign licence demonstrates that the firm has satisfied another regulator's requirements. It does not satisfy Panamanian AML registration requirements, which attach to the activity conducted in or from Panama. If the firm has a Panamanian office, Panamanian employees, Panamanian customers or processes transactions routed through Panamanian banking infrastructure, the SBP's AML oversight applies. Operating without the required Panamanian AML registration while relying on a foreign licence exposes the firm to enforcement by the SBP, deregistration and – more immediately – account closure by Panamanian correspondent banks that apply a substance-over-form test to their VASP clients.
The multi-jurisdiction structure that best protects the business is one that maps each activity layer to the correct regulatory treatment in each jurisdiction where that layer operates. We map the licence stack across operating, custody and payment layers before you commit to a structure – so that the compliance program is designed for the actual regulatory exposure, not a simplified version of it.
Related at OBOLUS
- AML and Travel Rule compliance for digital-asset businesses – how we design and test compliant AML programs across 70+ jurisdictions.
- MLRO and compliance officer function in South Africa – the regulatory requirements for senior compliance roles in an emerging digital-asset market.
- Token issuance and offering rules in the United Kingdom – how FCA financial-promotion and token-classification rules interact with AML obligations at launch.
FAQ
What does the Travel Rule require from a VASP?
The Travel Rule – derived from FATF Recommendation 16 – requires a VASP to collect and transmit identifying information about the originator and beneficiary of a virtual-asset transfer to the receiving VASP when the transfer meets or exceeds the applicable threshold. The receiving VASP must verify and retain that information. The rule applies to transactions between VASPs, not to on-chain transfers to unhosted wallets, though those carry separate risk-management obligations. The precise threshold varies by jurisdiction and should be confirmed against current supervisory guidance.
Who must act as MLRO for a crypto firm?
A designated Money Laundering Reporting Officer (MLRO) is required in every regulated VASP across the major AML regimes. The MLRO must have sufficient seniority and independence to challenge business decisions that create compliance risk, must receive and assess internal suspicion reports, and is personally accountable for filings to the financial intelligence unit. In smaller firms the role may be combined with a senior operational function; in larger operations it is typically a dedicated compliance position with its own resourcing and authority.
How do regulators audit crypto AML programs?
Regulators typically audit a VASP's AML program through a combination of document review, process walkthrough and transaction-level testing. They request the written policy, the risk assessment, MLRO appointment evidence, training records, screening logs, alert-review documentation and UAF filing records. Transaction-level testing examines whether the monitoring system generates alerts consistent with the stated thresholds and whether those alerts are reviewed and resolved in the documented timeframe. Gaps between the written policy and the operational evidence are the most common finding – and the basis for remediation orders.
OBOLUS is an independent digital-asset law boutique acting only for businesses. We advise exchanges, custodians, token issuers and funds on licensing across 70+ jurisdictions, on disputes and on-chain asset recovery across 25+ forums, and on the AML, sanctions-screening and Travel Rule compliance that sit around them. Digital assets are the entirety of our practice. We map the licence stack across operating, custody and payment layers before you commit to a structure – so that the compliance program is designed for the actual regulatory exposure. Digital assets are the whole of our practice, and we act only for businesses. To discuss your situation, contact info@oboluslaw.com or message us at t.me/oboluslaw.
By Victor Olsen, Regulatory & Compliance Analyst – specialising in AML program design, sanctions-screening architecture and VASP regulatory compliance across Latin American and cross-border digital-asset operations.
This publication is general information about the law and does not constitute legal advice. It is not a substitute for advice tailored to your circumstances. OBOLUS accepts no liability for action taken or not taken on the basis of this material. For advice on your situation, contact info@oboluslaw.com.