← Regulations / Laos / Operating Models / Crypto ATM

Crypto ATM / kiosk operator in Laos

Physical kiosks that exchange cash for crypto (and sometimes vice versa). High-cash AML risk profile.

Conditional AI-Generated · Unreviewed

Crypto ATM is conditionally permitted in Laos with a local entity, subject to AML obligations and high licensing burden.

Verdict Details

Permitted
conditional
Local entity required
Yes
Licensing burden
High
Last updated
2026-07-13

AML Obligations

  • CDD required: obtain and verify identity using reliable source documents (full name, DOB, nationality, address, official ID) for all customers.
  • Beneficial ownership identification and verification required for legal entity customers.
  • Ongoing monitoring of business relationships and transactions to ensure consistency with customer knowledge and risk profile.
  • Risk-based approach: Enhanced Due Diligence (EDD) required for higher-risk customers (PEPs, high-risk jurisdictions, unusual transactions).
  • Suspicious Transaction Reports (STRs) must be filed with the FIU promptly — reporting threshold applies to ANY transaction that triggers suspicion, regardless of amount.
  • No tipping-off prohibition applies to all VASPs and employees.
  • Travel Rule obligations expected for virtual asset transfers above a threshold (not yet defined locally; FATF standard typically ~USD/EUR 1,000).
  • Record-keeping: customer identification records, transaction records, and STR records must be retained for minimum 5 years.
  • Cash-specific: As a cash-intensive operation, AML obligations under Law No. 67/NA (2022) apply via the VASP pilot framework.

Key Restrictions

  • Crypto ATM / kiosk operations are not open to the public at large — the general public is largely prohibited from engaging in cryptocurrency trading/exchange activities per BOL warnings.
  • Operation is only possible under the highly restrictive VASP pilot program (Instruction No. 001/BOL), which is limited to state-controlled or authorized entities.
  • The BOL has repeatedly warned the public that cryptocurrencies are not legal tender and pose significant risks — operating a public-facing ATM kiosk would conflict with this official stance.
  • Cash-in/cash-out functionality at a kiosk likely falls under the 'exchange' prohibition for general businesses unless specifically authorized under the pilot.
  • Local entity incorporation is required — only BOL-licensed entities under the pilot program may operate.

Key Risks

  • High enforcement risk: The BOL has actively warned the public against crypto use, and operating a crypto ATM would directly contradict official regulatory communications.
  • Regulatory ambiguity: The VASP framework (Instruction No. 001/BOL) does not clearly contemplate physical kiosk/ATM operations; no specific kiosk or money-transmitter license category exists.
  • FATF compliance gap: Laos is rated as deficient on VASP AML/CFT coverage (APG 2022 report), meaning operators may face sudden regulatory changes or retroactive enforcement.
  • Cash-transaction reporting threshold (e.g. structured reporting for cash > ~$10k equivalent) is not clearly specified for crypto kiosks in Lao law — creates compliance uncertainty.
  • Public perception & scam risk: Government media has actively warned about crypto investment scams, associating the space with fraud — any visible ATM would attract scrutiny.
  • No clear licensing pathway exists for a standalone crypto ATM business — the pilot program has historically been limited to large government-favored mining/trading projects.
  • Reputational risk given that the Lao government's crypto pilot was primarily designed for state revenue generation, not retail public access.

Evidence

This verdict synthesizes the following facts. Each fact links to its primary source(s).

licensing 40% confidence

Law on Anti-Money Laundering and Combating the Financing of Terrorism (Law No. 67/NA, dated 17 November 2022): This is the foundational AML/CFT law in Laos, superseding previous versions. It establishes the general obligations for reporting entities, including financial institutions, and covers key aspects of AML/CFT compliance.

licensing 40% confidence

Decree on the Implementation of the Law on Anti-Money Laundering and Combating the Financing of Terrorism (Decree No. 37/GOV, dated 10 February 2020): This decree provides detailed guidance and procedures for implementing the provisions of the AML/CFT Law.

licensing 40% confidence

Instruction on the Management and Supervision of Virtual Assets (Instruction No. 001/BOL, dated 28 January 2022): Issued by the Bank of Lao PDR, this instruction is highly specific to the pilot program for virtual assets. It outlines the regulatory framework, licensing requirements, and ongoing obligations (including AML/KYC) for entities authorized to engage in virtual asset activities (mining, trading platforms, exchanges, etc.). It designates authorized VASPs as reporting entities for AML/CFT purposes.

licensing 40% confidence

Identification and Verification:

licensing 40% confidence

Obtain and verify the identity of the customer (individual or legal entity) using reliable, independent source documents, data, or information. For individuals, this includes full name, date of birth, nationality, residential address, and official identification document details (e.g., passport, national ID card).

licensing 40% confidence

For legal entities, this includes legal name, registered address, registration number, articles of association, and details of directors/senior management.

licensing 40% confidence

Beneficial Ownership: Identify and take reasonable measures to verify the identity of the beneficial owner(s) of the customer, including for legal entities and arrangements.

licensing 40% confidence

Purpose and Nature of Relationship: Understand and, where appropriate, obtain information on the purpose and intended nature of the business relationship or transaction.

licensing 40% confidence

Ongoing Monitoring: Conduct ongoing monitoring of the business relationship, including scrutiny of transactions undertaken throughout the course of that relationship to ensure that the transactions are consistent with the VASP's knowledge of the customer, their business, and risk profile.

licensing 40% confidence

Risk-Based Approach: Apply a risk-based approach to CDD, meaning enhanced due diligence (EDD) must be applied to higher-risk customers, business relationships, or transactions (e.g., politically exposed persons (PEPs), customers from high-risk jurisdictions, complex or unusual transactions, or transactions involving high-value virtual assets). Simplified due diligence (SDD) may be applied in lower-risk situations.

licensing 40% confidence

"Travel Rule" (FATF Recommendation 16): While specific detailed local regulations on the "Travel Rule" for VASPs may be further developed, authorized VASPs are generally expected to collect and transmit required originator and beneficiary information for virtual asset transfers above a certain threshold, in line with FATF recommendations, especially when transacting with other VASPs.

licensing 40% confidence

Reporting Obligation: Any transaction (regardless of amount) that the VASP knows, suspects, or has reasonable grounds to suspect involves money laundering, financing of terrorism, or other illicit activities, must be reported.

licensing 40% confidence

No Tipping-Off: VASPs and their employees are prohibited from disclosing to the customer or third parties that a suspicious transaction report has been or will be submitted.

licensing 40% confidence

Timeliness: Reports must be submitted to the FIU promptly, as soon as the suspicion is formed.

licensing 40% confidence

Customer Identification Records: All documents and information obtained during the CDD process, including copies of identification documents, beneficial ownership information, and risk assessments.

licensing 40% confidence

Transaction Records: Records of all transactions, including the amount, currency (both fiat and virtual asset), date, type of transaction, and the parties involved (originator and beneficiary information).

licensing 40% confidence

STR Records: Copies of all suspicious transaction reports submitted to the FIU and any internal analysis leading to those reports.

licensing 40% confidence

Retention Period: Records must generally be kept for a minimum of five (5) years after the business relationship has ended or after the date of the transaction.

licensing 40% confidence

Bank of Lao PDR (BOL): The BOL is the central bank and the primary financial regulator in Laos. It is responsible for issuing licenses/authorizations for VASPs under the pilot program, developing specific regulations (like Instruction No. 001/BOL), and conducting ongoing supervision and examinations to ensure compliance with AML/CFT and other prudential requirements.

licensing 40% confidence

Financial Intelligence Unit (FIU) of Laos: Operating under the Bank of Lao PDR, the FIU is the central agency for receiving, analyzing, and disseminating suspicious transaction reports to law enforcement agencies.

licensing 40% confidence

Regulatory Approach: Restrictive / Partial Ban (for the public) with Controlled Exceptions.

licensing 40% confidence

For the general public and most businesses, engaging in cryptocurrency trading, exchanges, or financial services is largely prohibited or highly discouraged due to the Bank of the Lao PDR's warnings and notices.

licensing 40% confidence

However, the government has, at times, indicated an openness to pilot projects for specific, state-controlled uses, particularly in areas like cryptocurrency mining to monetize surplus energy, but these are exceptions and not indicative of a liberalization for the broader market.

aml 40% confidence

No, not comprehensively. While Laos has a general AML/CFT law, its framework for VAs and VASPs is still considered insufficient by international standards. The FATF Travel Rule (which stems from FATF Recommendation 15 and its Interpretive Note) requires countries to regulate VASPs for AML/CFT purposes, including implementing obligations to collect and transmit originator and beneficiary information for virtual asset transfers. Laos has yet to establish this comprehensive regulatory regime.

aml 40% confidence

As the comprehensive regulatory framework for VASPs and the Travel Rule is not yet in place, there is no specific effective date for its implementation in Laos. The initial steps involve defining VAs and VASPs, bringing them under the regulatory scope, and then prescribing the specific Travel Rule obligations.

aml 40% confidence

Which VASPs are Covered:

aml 40% confidence

This is the primary challenge. Laos's existing AML/CFT framework, while aiming to combat financial crime, does not yet comprehensively define Virtual Assets (VAs) or Virtual Asset Service Providers (VASPs) to bring them under direct AML/CFT supervision as required by FATF Recommendation 15 and its Interpretive Note.

aml 40% confidence

Therefore, there isn't a clear list of "covered VASPs" that are currently subject to Travel Rule obligations. Any entities dealing with virtual assets operate in a largely unregulated or ambiguous legal environment concerning AML/CFT specifically for virtual assets.

aml 40% confidence

APG Mutual Evaluation Reports for Laos: These reports provide the most authoritative public assessment of Laos's compliance with FATF Recommendations.

aml 40% confidence

The APG 3rd Enhanced Follow-Up Report on Lao PDR (2022), for instance, highlights the ongoing deficiencies in addressing Virtual Assets and VASPs, noting that the country still needs to revise its legal and regulatory framework to ensure VAs and VASPs are adequately covered.

enforcement 60% confidence

Issuing Official Warnings and Prohibitions: The BOL has repeatedly reminded the public and financial institutions that cryptocurrencies are not legal tender and pose significant risks.

enforcement 60% confidence

A Brief Experiment with Authorized Mining (and subsequent cooling): There was a period in late 2021 where the Lao government approved a pilot project for a few companies to mine and trade cryptocurrencies, primarily to generate revenue for the state. However, this was a government initiative, not an enforcement action, and the enthusiasm seems to have significantly cooled since.

enforcement 60% confidence

Entity Targeted: The general public, financial institutions, and potentially anyone engaging in cryptocurrency activities. Violation Type: Engaging in activities with unrecognized digital assets, not being compliant with existing financial regulations, operating outside authorized financial systems. The BOL views cryptocurrencies as speculative assets that are not legal tender and pose risks like money laundering, fraud, and financial instability. Penalty Amount: Not applicable to warnings; potential penalties for actual illegal operations would fall under existing financial or criminal laws, not specific crypto regulations.

enforcement 60% confidence

Outcome: Reinforcement of the official position that cryptocurrencies are not recognized as legal tender or regulated financial products in Laos. Discouragement of public participation.

enforcement 70% confidence

Legal Basis: This stance stems from the BOL's mandate to maintain monetary stability, control the national currency (Lao Kip - LAK), and regulate the payment system under the Law on the Bank of the Lao PDR and the Law on Payment Systems.

Verdict Attribution

Source:
AI-Generated · Unreviewed
AI synthesized:
2026-07-13 (deepseek-chat)
Last updated:
2026-07-13
Confidence:
low

This verdict was produced by an AI model from the underlying facts. Confirm with counsel before relying on it for material decisions.

Conditional — a crypto ATM/kiosk operator is theoretically possible only under the Bank of Lao PDR's restrictive VASP pilot program (Instruction No. 001/BOL), but the legal framework does not explicitly address kiosk/ATM operations, the general public is broadly prohibited from crypto trading, and no specific money-transmitter or kiosk license exists — making practical viability very low.

Questions this verdict aims to answer

  • What money-transmitter / kiosk-specific license is required?
  • What cash-transaction reporting thresholds apply?
  • What enhanced-KYC obligations attach to cash-in / cash-out?