Panama sits at the intersection of Latin American capital flows and global digital-asset activity, making it an attractive domicile for crypto businesses serving clients across the Americas. Yet operators consistently underestimate what Panamanian law actually demands on the transaction monitoring front — and enforcement attention is rising. Any VASP (virtual asset service provider) operating through or from Panama must build and operate a documented transaction monitoring program that satisfies the country's AML/CFT framework, or risk enforcement action, frozen correspondent banking relationships, and exclusion from regulated counterparties. This page sets out the legal basis, the practical setup process, the cross-border complications, and the decision point for businesses building or auditing a monitoring program in Panama today.
What is the legal basis for transaction monitoring in Panama?
Panama's AML/CFT obligations for digital-asset businesses rest on a civil-law statute regime that incorporates FATF Recommendation 15 (on virtual assets) and the broader FATF framework into national law through legislation administered by the Unidad de Análisis Financiero (UAF), Panama's Financial Intelligence Unit. The UAF supervises reporting entities, receives suspicious transaction reports, and sets minimum standards for monitoring programs. Separately, the Superintendencia de Bancos de Panamá (SBP) and sector-specific regulators interact where a business touches payment flows or holds client funds. Together, these bodies define the perimeter that a crypto operator must satisfy.
The applicable regime requires all covered entities — including those dealing in virtual assets — to implement risk-based controls for customer due diligence, transaction screening, and the generation of suspicious activity reports. Panama adopted legal changes aligned to FATF's 2019 revised guidance on virtual assets, meaning that exchanges, custodians, and transfer services operating in or from Panama fall within the supervised perimeter. The specific provisions do not need citing by article number; what matters operationally is that the obligation is broad and includes on-chain activity as well as fiat on/off ramps.
The UAF is the central AML supervisory authority for virtual-asset businesses in Panama. Firms must register with or notify the UAF before commencing regulated activity, designate a Money Laundering Reporting Officer (MLRO), and maintain records sufficient to reconstruct any transaction on demand.
In our practice, we see a recurring pattern: a founder incorporates a Panamanian entity, opens it for business, and treats the AML policy document as a box-ticking exercise. The UAF's supervisory posture has shifted. Regulators now examine the calibration of monitoring rules, the quality of STR filings, and the competence of the designated MLRO — not just the existence of a written policy.
For a scoped assessment of your Panama compliance posture, contact OBOLUS at info@oboluslaw.com. The process above describes the standard path. Your facts — the entity structure, the user base geography, the banking — change the analysis materially. Map your options
What does a compliant transaction monitoring program require?
A compliant transaction monitoring program in Panama requires, at minimum, a risk-based customer due diligence framework, automated or documented manual screening against sanctions lists, threshold-based transaction alert rules, an escalation and investigation workflow, and a reporting channel to the UAF. Each element must be documented, tested, and reviewed on a defined cycle. The word "program" is deliberate — a checklist is not a program.
The practical components break down as follows.
Customer risk scoring is the foundation. Each customer is assigned a risk tier based on jurisdictional exposure, product type, transaction volume, and source-of-funds indicators. Higher-risk customers require enhanced due diligence and more sensitive alert thresholds. The risk methodology must be written, approved at the senior-management level, and updated when the business model or customer mix changes.
Alert rule calibration is where most early-stage operators fail. A monitoring system that generates hundreds of false positives per day is not a compliant program — it is an alert fatigue machine. Regulators expect evidence that rules have been tuned against the actual transaction population, with documented rationale for thresholds chosen. For a crypto exchange, this means separate rule sets for spot trading, stablecoin transfers, withdrawals to self-custodied wallets, and high-value OTC flows.
Sanctions screening must run in real time or as close to it as the product architecture permits. Panama-based firms face exposure to OFAC (US Office of Foreign Assets Control) designations in addition to UN and domestic lists, because correspondent banking relationships with US institutions depend on clean OFAC compliance. A firm that processes a transaction involving a sanctioned address — even unknowingly — can lose its banking relationship the same week.
Suspicious transaction reporting to the UAF must be timely. The applicable regime sets a filing window after identification; the specific deadline is governed by current UAF regulation and should be verified against the live instrument. Internal escalation from the front-line analyst to the MLRO, and from the MLRO to the UAF, must be documented with timestamps.
Record retention obligations apply to both the underlying transaction data and the monitoring records themselves. The retention period under Panamanian law extends for a period consistent with FATF standards; confirm the precise term with current regulation before you commit to a data architecture.
How does the Travel Rule interact with a Panama setup?
The Travel Rule (the FATF obligation to pass originator and beneficiary identifying information with every qualifying virtual-asset transfer) applies to Panama-registered VASPs by operation of the FATF-aligned national framework. In practice, this means that a VASP in Panama must collect, screen, and transmit counterparty data on outgoing transfers above the applicable threshold, and must receive and screen that data on incoming transfers.
The cross-border tension here is acute. Panama-based firms often send and receive transfers from counterparty VASPs in jurisdictions that have implemented the Travel Rule differently — or not yet at all. A VASP in Panama that routinely receives transfers from a jurisdiction where Travel Rule implementation is incomplete faces a compliance gap: it cannot verify the originator data because none was sent. The firm's monitoring program must document how it handles that gap. Accepting unaccompanied transfers without a remediation protocol is a supervisory risk.
Technology solutions exist — interoperability protocols such as TRISA and OpenVASP, as well as commercial Travel Rule compliance platforms — but selecting and integrating the right tool requires a prior legal analysis of which transfers fall within scope. The de-minimis threshold, the treatment of unhosted-wallet transfers, and the interaction with correspondent-bank wire requirements all vary. Panama's implementation of the Travel Rule should be read alongside the SBP's expectations for any fiat leg of the transaction.
In our cross-border practice, we regularly advise clients whose monitoring programs were built for one jurisdiction and then deployed across multiple entities without adjustment. A Travel Rule solution that works for a Singapore-licensed entity does not automatically satisfy Panama's UAF or the correspondent bank's own AML requirements. The two must be mapped in parallel.
Who must act as MLRO, and what does the role demand?
Every supervised entity in Panama must designate a qualified MLRO who is resident or sufficiently accessible to the supervisory authority, holds appropriate competence in AML/CFT, and bears formal accountability for the entity's reporting obligations. The MLRO is not a nominal compliance figurehead — in Panama, as in most FATF-aligned jurisdictions, the MLRO is personally accountable for the quality and timeliness of suspicious transaction reports.
For a crypto firm, the MLRO must understand both the legal obligations and the technical reality of on-chain transactions. A traditional banking compliance officer without crypto-specific training will struggle to assess whether a cluster of wallet-to-wallet transfers constitutes a suspicious pattern or a routine arbitrage workflow. We have seen firms appoint MLROs who were unaware of chain-analysis tools, unable to read a blockchain explorer output, or unfamiliar with common mixer/obfuscation typologies. That is a supervisory liability.
The MLRO must also manage the internal reporting culture. Employees who identify suspicious activity must know how to escalate it, and there must be no organizational pressure — implicit or explicit — to suppress a report because a customer is high-revenue. The UAF expects documented evidence of internal reports received, investigated, and resolved or escalated.
For early-stage firms that cannot yet justify a full-time MLRO, a contracted interim or fractional MLRO can satisfy the formal requirement — but the arrangement must be properly documented, the individual must have genuine authority, and the retainer must survive scrutiny from the UAF. A nominal appointment that functions as a compliance letterhead will not.
How does the Panama banking environment interact with AML compliance?
Panama's correspondent banking relationships are a central practical constraint for crypto businesses. The country's history of financial secrecy, combined with its presence on various international grey and watch lists at different points in time, has made Panamanian banks — and the US correspondent banks that support them — acutely sensitive to crypto-related AML risk. A crypto firm that cannot demonstrate a mature monitoring program will find it difficult to open or retain a bank account in Panama.
This is not merely a domestic issue. Panamanian banks rely on US correspondent relationships to clear USD transactions. A VASP that a Panamanian bank perceives as a de-risking liability will be offboarded — not for a specific regulatory violation, but for the bank's own risk appetite. The result is operational: no banking, no business.
The practical implication is that the monitoring program must satisfy two audiences simultaneously — the UAF's supervisory expectations and the bank's own AML questionnaire. These are not identical. A bank's due diligence questionnaire will ask about the firm's customer jurisdictions, the proportion of unhosted-wallet transfers in total volume, the chain-analysis vendor used, and the MLRO's credentials. A UAF examination will focus on policy documentation, STR filings, and record completeness. A well-designed program satisfies both — but only if it was built with both in mind.
We regularly advise clients who built their program for the regulator and then lost their bank account because the bank's questionnaire revealed gaps the UAF had not yet examined. The solution is to treat banking compliance and regulatory compliance as a single workstream from day one.
If a prior compliance build stalled or your correspondent banking relationship is at risk, write to OBOLUS at info@oboluslaw.com. A second read can surface the structural reason and the route back. Map your options
What is the setup process for an inbound operator?
An inbound operator establishing transaction monitoring in Panama follows a structured sequence: legal analysis of the applicable perimeter, UAF registration, policy drafting, technology selection, MLRO appointment, staff training, and a testing cycle before go-live.
The first step is confirming that the Panama entity is within scope. Not every entity that touches crypto is a supervised VASP under Panamanian law. The determination turns on the nature of the services provided, the location of the customers, and whether the Panamanian entity is the operating entity or merely a holding structure. This analysis must precede any other step — an operator who registers with the UAF when they did not need to may create a supervisory relationship without the corresponding benefit. Conversely, an operator who should register and does not is exposed to enforcement.
Once scope is confirmed, UAF registration proceeds. The timeline for this step is governed by current UAF processing capacity and the completeness of the application; write qualitatively that it typically takes a matter of weeks, but allow for administrative back-and-forth. The registration package will include entity documentation, a description of business activities, identification of the beneficial owners, and details of the designated MLRO.
Policy drafting follows registration. The AML/CFT policy, the transaction monitoring procedures, the escalation matrix, and the STR filing protocol are the core documents. These must be tailored to the actual business — a copy-pasted policy from another jurisdiction will fail on internal consistency. A policy that references a "front-office team" that does not exist in the org chart, or monitoring thresholds calibrated for a different product, is a supervisory red flag.
Technology selection for monitoring depends on transaction volume and product type. A low-volume OTC desk can operate a defensible program with manual controls and a licensed chain-analysis subscription. An exchange processing thousands of transactions per day requires a purpose-built transaction monitoring system with automated alert generation and case management. The firm's legal counsel should be involved in vendor selection, because the choice of tool affects the audit trail and the firm's ability to demonstrate compliance in a supervisory examination.
Staff training, a documented testing cycle, and a sign-off by the MLRO close the setup phase. The monitoring program is then a live obligation — it must be reviewed and updated as the customer base, product set, and regulatory environment evolve.
A Recent Cross-Border Compliance Matter
In a recent engagement, a payments-focused digital-asset firm incorporated in Panama came to us after its primary bank issued a de-risking notice. The firm had a UAF registration and a written AML policy, but its transaction monitoring rules had never been calibrated against its actual transaction data, and its MLRO had no documented training in on-chain analytics. We conducted a gap analysis across the monitoring program, the MLRO competency framework, and the bank's AML questionnaire requirements. We restructured the monitoring rule set, supported the appointment of an interim MLRO with crypto-specific credentials, and prepared a remediation letter to the bank documenting the steps taken. The bank reconsidered its de-risking decision. The matter illustrated a pattern we see often: compliance paperwork that satisfies a registration requirement but fails at the operational layer when examined by a counterparty with real AML leverage.
Which operator profile needs what level of monitoring infrastructure?
The appropriate monitoring infrastructure for a Panama-based digital-asset business depends on the operator profile — the nature of the service, the customer geography, the transaction volume, and the cross-border licensing stack.
Profile A — early-stage or low-volume operator: A firm processing a modest transaction volume, with a defined customer base in one or two jurisdictions, and no unhosted-wallet exposure, can build a compliant program around a manual-review workflow, a licensed chain-analysis tool, a documented risk methodology, and a part-time or fractional MLRO. The key risk for this profile is under-documentation — decisions are made informally, but the UAF expects a paper trail. Timeline to a defensible program: typically a matter of weeks from engagement, assuming the legal perimeter analysis is clean.
Profile B — mid-market exchange or custodian: A firm processing significant daily volume across multiple customer jurisdictions, with exposure to both hosted and unhosted wallets, needs an automated monitoring platform, a full-time MLRO with crypto-specific credentials, a Travel Rule compliance solution, and a documented calibration history for alert rules. Banking relationships will require a mature AML questionnaire response and, in some cases, an independent compliance review. Timeline to a defensible program: longer, reflecting system integration and calibration. Key risk: alert fatigue from poorly tuned rules, which creates supervisory liability even when genuine suspicious activity is filed correctly.
Profile C — multi-entity cross-border structure: A group with a Panama operating entity alongside licensed entities in other jurisdictions — a MiCA-authorized CASP in the EU, a MAS-licensed DPT service in Singapore, or a VARA-regulated entity in Dubai — must reconcile the monitoring program with each jurisdiction's requirements. Panama's UAF obligations do not automatically satisfy ESMA's expectations, VARA's rulebooks, or MAS's Payment Services Act regime. A group-level monitoring policy with jurisdiction-specific annexes is the minimum viable approach. This profile requires legal coordination across allied counsel in each relevant jurisdiction. Key risk: assuming that a group policy built for the most demanding jurisdiction satisfies all others — it usually does not, on the details.
What are the most common monitoring failures in Panama?
The most common transaction monitoring failures we see in Panama-domiciled digital-asset businesses fall into a short, recurring list.
Treating registration as compliance. UAF registration is a precondition, not a compliance program. A firm that registers and then operates with an uncalibrated spreadsheet and a nominal MLRO is technically registered and practically non-compliant. The gap between the two is where enforcement risk lives.
Ignoring the bank's AML layer. As described above, the bank's AML expectations are distinct from the UAF's. A firm that satisfies one but not the other will find itself in the position of the client in our micro-matter — compliant on paper, de-banked in practice.
Static monitoring rules. A monitoring program built at launch and never updated is a liability. As the customer mix, transaction volume, and typology environment change, the rules must change with them. Regulators expect a documented review cycle — at least annually, and on any material change to the business model.
Weak STR culture. Under-reporting of suspicious transactions is a supervisory red flag. A firm that has operated for two years and filed zero STRs will attract scrutiny. The explanation may be legitimate — a clean customer base and a conservative risk appetite — but it must be documented and defensible.
No cross-border Travel Rule protocol. A firm that does not have a documented protocol for handling incoming transfers without originator data is exposed. The protocol does not need to be perfect, but it must exist, be implemented, and be reviewable.
A common assumption among founders building in Panama is that the country's regulatory environment is light-touch and that a basic compliance posture is sufficient. That assumption is increasingly wrong. FATF mutual evaluation pressure, correspondent-bank de-risking dynamics, and the growing sophistication of the UAF's supervisory function mean that the bar for a defensible program rises each year. Operators who built their compliance infrastructure two years ago and have not updated it are running on borrowed time.
Related at OBOLUS
- AML & Travel Rule compliance for digital-asset businesses – The full regulatory perimeter, from FATF to jurisdiction-specific obligations
- AML/CFT policy drafting for early-stage founders – Tailored policy documentation for firms at the pre-launch or early-registration stage
- Digital-asset counsel for venture funds – Legal support for funds with exposure to crypto assets across licensing, tax and structuring
FAQ
What does the Travel Rule require from a VASP?
The Travel Rule requires a VASP to collect, screen, and transmit identifying information about the originator and beneficiary of a qualifying virtual-asset transfer — including name, account identifier, and, depending on the jurisdiction's implementation, address or other verifying data. Panama's FATF-aligned framework applies this obligation to transfers above the applicable threshold. The receiving VASP must in turn screen the data received and hold it for the required retention period. Transfers where the counterparty VASP cannot or does not send this data require a documented handling protocol.
Who must act as MLRO for a crypto firm?
The MLRO must be a named individual with sufficient authority, competence, and independence to discharge the reporting function without organizational interference. For a Panama-registered digital-asset business, the MLRO must be accessible to the UAF and demonstrably qualified in AML/CFT — which, for a crypto firm, includes familiarity with on-chain transaction analysis and common virtual-asset typologies. A fractional or contracted MLRO can satisfy the formal requirement if the arrangement is properly documented and the individual holds genuine authority, not merely a title.
How do regulators audit crypto AML programs?
Regulators examining a crypto AML program typically request the written policies and procedures, the risk methodology, the alert rule configuration and calibration history, a sample of investigated alerts with disposition notes, the STR filing log, records of MLRO training and competency, and the customer due diligence files for a sample of high-risk accounts. For a Panamanian firm, the UAF may also examine the firm's correspondent-bank correspondence and any bank questionnaire responses. The examination tests whether the program was implemented, not merely documented.
OBOLUS is an independent digital-asset law boutique acting only for businesses. We advise exchanges, custodians, token issuers and funds on licensing across 70+ jurisdictions, on disputes and on-chain asset recovery across 25+ forums, and on the tax, banking and compliance that sit around them. Digital assets are the whole of our practice. We map the licence stack across operating, custody and payment layers before you commit — and we structure licensing, banking and tax as one mandate rather than three disconnected workstreams. To discuss your situation, contact info@oboluslaw.com.
By Victor Olsen, Regulatory & Compliance Analyst — specialising in AML/CFT program architecture and FATF-aligned compliance obligations for digital-asset businesses across Latin American and cross-border jurisdictions.
This publication is general information about the law and does not constitute legal advice. It is not a substitute for advice tailored to your circumstances. OBOLUS accepts no liability for action taken or not taken on the basis of this material. For advice on your situation, contact info@oboluslaw.com.