← Regulations / Costa Rica / Operating Models / DeFi frontend

DeFi protocol frontend in Costa Rica

Operates a web frontend or aggregator that interacts with permissionless smart contracts on behalf of users. May or may not screen users / restrict regions.

Conditional AI-Generated · Unreviewed

DeFi frontend is conditionally permitted in Costa Rica with a local entity, subject to AML obligations and medium licensing burden.

Verdict Details

Permitted
conditional
Local entity required
Yes
Licensing burden
Medium
Last updated
2026-07-13

AML Obligations

  • Law 10.363 (Ley de Regulación de Proveedores de Servicios de Activos Virtuales) brings VASPs under Law 7786 AML/CFT scope, though operational regulations via SUGEF 2-2024 remain pending — meaning the AML framework is legally established but not yet fully implementable
  • If deemed an 'obligated subject', must implement comprehensive AML/KYC program including customer identification (KYC), ongoing monitoring, suspicious transaction identification and reporting
  • Customer KYC must collect: physical residential address, national ID/passport number, contact info, and for legal entities: corporate name, proof of incorporation, registered office, tax ID (cédula jurídica), directors/partners, beneficial owners (≥25% ownership), nature of business
  • Enhanced Due Diligence (EDD) required for high-risk clients, including PEPs, cross-border relationships, and complex/unusual transactions; must verify source of funds/wealth for such clients
  • Risk-Based Approach (RBA) required — CDD measures must be calibrated to customer risk profile
  • Suspicious Transaction Reports (STRs) must be filed with the Unidad de Inteligencia Financiera del Instituto Costarricense sobre Drogas (UIAD — Costa Rica's FIU) for any transaction where funds are suspected to be proceeds of crime or terrorist financing
  • No tipping-off prohibition applies regarding STR filings
  • Appointment of a designated AML Compliance Officer required
  • Must conduct a comprehensive money laundering risk assessment
  • Internal controls, policies, procedures, and employee training programs required
  • If processing fiat currency payments (even if crypto-related): operator would fall under existing payment service provider regulations and AML/CFT laws as obligated subjects
  • Pure crypto-to-crypto transactions remain a grey area as VASPs not yet explicitly classified as 'obligated subjects' under Law 7786; proposed amendment Expediente 22.837 remains pending with procedural setbacks

Key Restrictions

  • Virtual assets are not legal tender in Costa Rica and are not regulated by SUGEF unless they fall under existing regulated activities (SUGEF Circular SGF-0036-2021)
  • Law 10.363 established the legal framework for VASPs but the key implementing regulation (SUGEF 2-2024) remains pending — so formal registration may not yet be practically possible
  • If the DeFi frontend takes custody of user assets or controls private keys on behalf of users, it would likely be classified as a custody provider and fall under obligated-subject AML requirements
  • If purely facilitating crypto-to-crypto transactions without fiat conversion, the activity sits in a regulatory grey area — not explicitly covered but global trend is toward bringing such services under AML/CFT scrutiny
  • If the frontend processes fiat payments (e.g., on-ramp/off-ramp), it would likely need compliance with general financial service regulations, potentially including higher capital requirements and specific operational licenses from SUGEF
  • Local incorporation is required for any company operating and generating income in Costa Rica under standard corporate law, with a local registered office and legal representative

Key Risks

  • Regulatory ambiguity: DeFi frontends are not explicitly addressed in Costa Rican law; whether the frontend is 'providing services' as a VASP depends on degree of control over smart contracts and user funds, creating significant classification risk
  • Pending legislation (Expediente 22.837) that would explicitly classify VASPs as obligated subjects has faced procedural setbacks — the regulatory goalposts may shift if/when it passes or if SUGEF 2-2024 is finalized
  • SUGEF and BCCR have consistently warned that virtual assets are not regulated and carry significant risks — operating in this environment carries enforcement exposure if authorities later determine the frontend falls within regulated activity
  • If the DeFi frontend takes fees (e.g., swap fees, interface fees), this increases the likelihood of being classified as providing a regulated service, especially if fees are in fiat or involve fiat conversion
  • Criminal enforcement exposure: OIJ has investigated crypto-related fraud and money laundering cases; a frontend that does not geofence or screen users could attract criminal liability if used for illicit purposes
  • No specific VASP licensing pathway exists yet — operators cannot achieve formal regulatory compliance, creating a 'comply without a framework' dilemma

Evidence

This verdict synthesizes the following facts. Each fact links to its primary source(s).

licensing 90% confidence

Superintendencia General de Entidades Financieras (SUGEF): The General Superintendency of Financial Institutions. SUGEF is responsible for supervising financial entities and enforcing AML/CFT regulations for many obligated subjects.

licensing 85% confidence

Virtual asset service providers in Costa Rica are not yet explicitly classified as 'obligated subjects' under Law 7786; the proposed amendment (Expediente 22.837) that would explicitly include them remains pending and has faced procedural setbacks.

licensing 90% confidence

Registration: With SUGEF as an "obligated subject" (if the activity falls under their scope) or potentially with the Financial Intelligence Unit (Unidad de Inteligencia Financiera - UIF) depending on the exact classification.

licensing 90% confidence

Full AML/KYC Program: Implementation of robust Know Your Customer (KYC), Customer Due Diligence (CDD), Enhanced Due Diligence (EDD), and Transaction Monitoring policies and procedures.

licensing 100% confidence

Reporting: Obligation to report suspicious transactions (SARs/STRs) to the UIF.

licensing 60% confidence

Status: If the custody provider holds virtual assets on behalf of clients and/or provides services that enable the transfer or exchange of these assets, they would likely also fall under the "obligated subject" category, especially if they control the private keys for clients.

licensing 60% confidence

Requirements: Similar to exchanges – full AML/KYC program, AML officer, reporting, record-keeping, risk assessment.

licensing 60% confidence

If processing fiat currency payments (even if crypto-related): They would likely fall under existing payment service provider regulations and certainly under AML/CFT laws as obligated subjects.

licensing 60% confidence

If purely crypto-to-crypto transactions (e.g., facilitating payments in crypto without fiat conversion): This remains a grey area in many jurisdictions without specific VASP licensing. However, the global trend is to bring such services under AML/CFT scrutiny if they involve value transfer and could be used for illicit purposes. SUGEF's interpretation would be key.

licensing 80% confidence

Local Presence: Generally, any company operating and generating income in Costa Rica needs to be incorporated locally and have a local registered office and local representation (e.g., a local legal representative). This is standard corporate law, not crypto-specific. For AML purposes, having a local AML officer is also typical.

aml 100% confidence

Law No. 7786, "Law on Narcotics, Psychotropic Substances, Drugs of Unauthorized Use, Related Activities, Money Laundering and Financing of Terrorism" (Ley sobre Estupefacientes, Sustancias Psicotrópicas, Drogas de Uso No Autorizado, Actividades Conexas, Legitimación de Capitales y Financiamiento al Terrorismo), as amended. This is Costa Rica's foundational AML/CFT law.

aml 100% confidence

Law No. 10.363, "Law on the Regulation of Virtual Asset Service Providers" (Ley de Regulación de Proveedores de Servicios de Activos Virtuales). This law established the legal framework for VASPs, bringing them under Law 7786's AML/CFT scope. However, the operational AML/CFT obligations and registration mandate became enforceable only after SUGEF's implementing regulation (SUGEF 2-2024) came into effect on November 16, 2024.

aml 100% confidence

Regulations issued by SUGEF: While Law 10.363 sets the legal framework, the Superintendent General of Financial Entities (SUGEF) is responsible for developing specific regulations. The key implementing regulation, SUGEF 2-2024 ("Reglamento para la Inscripción y Supervisión de los Proveedores de Servicios de Activos Virtuales"), was issued and became effective on November 16, 2024. It details registration, CDD, transaction monitoring, STR, and record-keeping requirements for VASPs.

aml 100% confidence

Identification and Verification of Customer Identity:

aml 100% confidence

Physical residential address

aml 100% confidence

Identification number (e.g., national ID card, passport number)

aml 100% confidence

Contact information (e.g., phone number, email address)

aml 100% confidence

Source of funds/wealth (as part of Enhanced Due Diligence (EDD) for high-risk clients, which may include scrutiny of large transactions as a contributing factor to the risk assessment).

aml 100% confidence

Verification through reliable, independent source documents, data, or information (e.g., government-issued ID, utility bills).

aml 100% confidence

Legal name, legal nature or type of entity (naturaleza jurídica), and proof of incorporation/registration (copia certificada de la personería jurídica).

aml 80% confidence

Registered office address (domicilio o dirección física de la sede social).

aml 100% confidence

Corporate identification number (número de identificación), which in Costa Rica commonly serves as the tax identification number (cédula jurídica / Número de Identificación Tributaria).

aml 100% confidence

Names of directors, partners, and senior management.

aml 100% confidence

Identification of Beneficial Owners (BOs): VASPs must identify and verify the identity of all natural persons who ultimately own or control the legal entity (typically those holding 25% or more of shares or voting rights, or otherwise exercising control).

aml 100% confidence

Nature of business and purpose of the business relationship.

aml 100% confidence

Purpose and Intended Nature of the Business Relationship: Understanding why the customer wants to use the VASP's services.

aml 100% confidence

Ongoing Due Diligence:

aml 100% confidence

Regularly monitoring transactions to ensure they are consistent with the VASP's knowledge of the customer, their business, and risk profile.

aml 100% confidence

Keeping customer information, documents, and data up-to-date.

aml 100% confidence

Periodically reviewing the risk categorization of customers.

aml 100% confidence

Risk-Based Approach (RBA): VASPs must apply CDD measures on a risk-sensitive basis. This means applying enhanced due diligence (EDD) for higher-risk customers, transactions, or business relationships (e.g., Politically Exposed Persons (PEPs), cross-border correspondent relationships, complex/unusual transactions). Simplified due diligence (SDD) may be applied in specific lower-risk scenarios.

aml 100% confidence

Trigger: Any transaction, attempted transaction, or activity where the VASP suspects or has reasonable grounds to suspect that the funds or assets are proceeds of criminal activity (including money laundering) or are related to terrorist financing.

aml 100% confidence

Reporting Body: The report must be submitted to the Unidad de Inteligencia Financiera del Instituto Costarricense sobre Drogas (UIAD), which is Costa Rica's FIU.

aml 40% confidence

No Tipping Off: VASPs and their employees are prohibited from disclosing to the customer or any third party that an STR has been, or will be, filed.

enforcement 90% confidence

September 2021: SUGEF Circular SGF-0036-2021 reiterates that virtual assets are not legal tender and are not regulated by SUGEF unless they fall under existing regulated activities.

enforcement 80% confidence

January 2022: SUGEF continues to issue warnings regarding the risks of virtual assets.

enforcement 100% confidence

Outcome: SUGEF maintains that virtual assets are not regulated financial products or services under its supervision. Financial institutions are advised to exercise extreme caution when dealing with virtual assets and to ensure compliance with existing AML/CFT regulations if handling any related transactions. This means that if a bank facilitates transactions involving crypto, it must still comply with its existing AML obligations.

enforcement 90% confidence

November 2021: BCCR reiterates that cryptocurrencies are not legal tender in Costa Rica and highlights risks associated with their use.

enforcement 90% confidence

Costa Rica's regulatory stance on cryptocurrencies has evolved from mere cautionary statements to active legislative development, with Bill No. 22.837 on virtual assets advancing in the legislative assembly.

enforcement 90% confidence

Example (illustrative, not specific to last 3 years due to public data scarcity): News reports over the years have documented OIJ investigations into cybercrime and fraud where victims sent crypto to scammers, or where crypto was used to move illicit funds.

Verdict Attribution

Source:
AI-Generated · Unreviewed
AI synthesized:
2026-07-13 (deepseek-chat)
Last updated:
2026-07-13
Confidence:
low

This verdict was produced by an AI model from the underlying facts. Confirm with counsel before relying on it for material decisions.

Conditional — a DeFi protocol frontend operating in Costa Rica may be subject to AML/CFT obligations under Law 10.363 (if classified as a VASP/custody provider/fiat handler), but the regulatory framework remains incomplete (SUGEF 2-2024 pending), VASPs are not yet explicitly classified as obligated subjects, and pure crypto-to-crypto frontends without custody or fiat sit in a grey area; local incorporation is required under general corporate law, and fee-taking increases classification risk.

Questions this verdict aims to answer

  • Is operating the frontend a regulated activity even if the protocol is decentralized?
  • What geofencing or KYC obligations apply?
  • Does fee-taking change classification?