Centralized exchange in Laos
Order-book exchange that takes custody of user assets and matches trades between users.
CEX is conditionally permitted in Laos with a local entity, subject to AML obligations and high licensing burden.
Verdict Details
- Permitted
- conditional
- Local entity required
- Yes
- Licensing burden
- High
- Last updated
- 2026-07-13
AML Obligations
- Customer identification and verification using reliable, independent source documents (full name, DOB, nationality, address, ID details for individuals; legal name, registered address, registration number, articles, director details for legal entities) per Instruction No. 001/BOL and AML/CFT Law No. 67/NA
- Beneficial ownership identification and verification for all customers, including legal entities and arrangements
- Understand purpose and intended nature of business relationship
- Ongoing transaction monitoring consistent with customer knowledge and risk profile
- Risk-based approach: Enhanced Due Diligence (EDD) for PEPs, high-risk jurisdictions, complex/unusual transactions
- Travel Rule (FATF Rec. 16) expected — collect and transmit originator/beneficiary info for virtual asset transfers; threshold not yet locally defined but international standard (USD/EUR 1,000) anticipated
- Suspicious Transaction Reports (STRs) to the FIU for any transaction (regardless of amount) that the VASP knows/suspects involves ML/TF
- No tipping-off prohibition
- Timely reporting to FIU upon suspicion formed
- Record-keeping: CDD documents, transaction records (amount, currency, date, type, parties), STR copies — minimum 5-year retention
Key Restrictions
- Must obtain a license under the government's digital asset sandbox program (pilot program) — there is no general license for public-facing centralized exchanges
- Licensing is issued by a joint committee of Ministry of Technology and Communications, Ministry of Finance, and Bank of Lao PDR
- Cryptocurrencies are not legal tender in Laos; the BOL has issued repeated warnings against general public use
- The sandbox program is limited, experimental, and has largely targeted state-controlled or government-approved entities (e.g., mining projects to monetize surplus energy)
- No specific custodial license exists — custody is covered only under the sandbox authorization
- No specific cold-storage, insurance/bonding, or qualified-custodian requirements are publicly mandated — best practices expected but not codified
Key Risks
- Extreme regulatory ambiguity — VASPs are not yet comprehensively defined or supervised under the AML/CFT framework, creating legal uncertainty for any exchange operation
- APG mutual evaluation reports (2022) highlight ongoing deficiencies in Laos's coverage of VAs/VASPs, meaning Laos is under pressure from FATF to tighten regulation, creating unstable rule environment
- No specific Travel Rule threshold, technical standards, or penalties exist for VASPs — operators face a compliance vacuum with unclear exposure
- Public-facing exchange activity is operationally discouraged by BOL warnings; enforcement risk from the general prohibition stance is material
- Sandbox project transparency is low — few public updates on continuation or expansion of pilot program
- Potential for sudden regulatory reversal: the government has oscillated between prohibition (prior to 2021) and limited pilot (post-2021)
Evidence
This verdict synthesizes the following facts. Each fact links to its primary source(s).
Law on Anti-Money Laundering and Combating the Financing of Terrorism (Law No. 67/NA, dated 17 November 2022): This is the foundational AML/CFT law in Laos, superseding previous versions. It establishes the general obligations for reporting entities, including financial institutions, and covers key aspects of AML/CFT compliance.
Decree on the Implementation of the Law on Anti-Money Laundering and Combating the Financing of Terrorism (Decree No. 37/GOV, dated 10 February 2020): This decree provides detailed guidance and procedures for implementing the provisions of the AML/CFT Law.
Instruction on the Management and Supervision of Virtual Assets (Instruction No. 001/BOL, dated 28 January 2022): Issued by the Bank of Lao PDR, this instruction is highly specific to the pilot program for virtual assets. It outlines the regulatory framework, licensing requirements, and ongoing obligations (including AML/KYC) for entities authorized to engage in virtual asset activities (mining, trading platforms, exchanges, etc.). It designates authorized VASPs as reporting entities for AML/CFT purposes.
Obtain and verify the identity of the customer (individual or legal entity) using reliable, independent source documents, data, or information. For individuals, this includes full name, date of birth, nationality, residential address, and official identification document details (e.g., passport, national ID card).
For legal entities, this includes legal name, registered address, registration number, articles of association, and details of directors/senior management.
Beneficial Ownership: Identify and take reasonable measures to verify the identity of the beneficial owner(s) of the customer, including for legal entities and arrangements.
Purpose and Nature of Relationship: Understand and, where appropriate, obtain information on the purpose and intended nature of the business relationship or transaction.
Ongoing Monitoring: Conduct ongoing monitoring of the business relationship, including scrutiny of transactions undertaken throughout the course of that relationship to ensure that the transactions are consistent with the VASP's knowledge of the customer, their business, and risk profile.
Risk-Based Approach: Apply a risk-based approach to CDD, meaning enhanced due diligence (EDD) must be applied to higher-risk customers, business relationships, or transactions (e.g., politically exposed persons (PEPs), customers from high-risk jurisdictions, complex or unusual transactions, or transactions involving high-value virtual assets). Simplified due diligence (SDD) may be applied in lower-risk situations.
"Travel Rule" (FATF Recommendation 16): While specific detailed local regulations on the "Travel Rule" for VASPs may be further developed, authorized VASPs are generally expected to collect and transmit required originator and beneficiary information for virtual asset transfers above a certain threshold, in line with FATF recommendations, especially when transacting with other VASPs.
Reporting Obligation: Any transaction (regardless of amount) that the VASP knows, suspects, or has reasonable grounds to suspect involves money laundering, financing of terrorism, or other illicit activities, must be reported.
No Tipping-Off: VASPs and their employees are prohibited from disclosing to the customer or third parties that a suspicious transaction report has been or will be submitted.
Timeliness: Reports must be submitted to the FIU promptly, as soon as the suspicion is formed.
Customer Identification Records: All documents and information obtained during the CDD process, including copies of identification documents, beneficial ownership information, and risk assessments.
Transaction Records: Records of all transactions, including the amount, currency (both fiat and virtual asset), date, type of transaction, and the parties involved (originator and beneficiary information).
STR Records: Copies of all suspicious transaction reports submitted to the FIU and any internal analysis leading to those reports.
Retention Period: Records must generally be kept for a minimum of five (5) years after the business relationship has ended or after the date of the transaction.
Bank of Lao PDR (BOL): The BOL is the central bank and the primary financial regulator in Laos. It is responsible for issuing licenses/authorizations for VASPs under the pilot program, developing specific regulations (like Instruction No. 001/BOL), and conducting ongoing supervision and examinations to ensure compliance with AML/CFT and other prudential requirements.
Financial Intelligence Unit (FIU) of Laos: Operating under the Bank of Lao PDR, the FIU is the central agency for receiving, analyzing, and disseminating suspicious transaction reports to law enforcement agencies.
The FIU's information is integrated within the BOL structure.
Regulatory Approach: Restrictive / Partial Ban (for the public) with Controlled Exceptions.
For the general public and most businesses, engaging in cryptocurrency trading, exchanges, or financial services is largely prohibited or highly discouraged due to the Bank of the Lao PDR's warnings and notices.
However, the government has, at times, indicated an openness to pilot projects for specific, state-controlled uses, particularly in areas like cryptocurrency mining to monetize surplus energy, but these are exceptions and not indicative of a liberalization for the broader market.
A General Prohibition with Exceptions: Initial stances were restrictive. However, a significant development was the Prime Minister's Order No. 001/PMO, which allowed for a controlled experiment.
The "Sandbox" Approach: The government initiated a pilot program or "sandbox" allowing a limited number of companies to mine and trade cryptocurrencies under strict supervision. This means that any entity engaging in activities that would involve custody must be part of this approved sandbox.
Prime Minister's Order No. 001/PMO concerning the management of cryptocurrencies and digital assets (2021): This Order effectively lifted a prior ban on crypto activities, allowing the Ministry of Technology and Communications, the Bank of Laos, and the Ministry of Finance to permit and manage the mining and trading of digital assets by selected companies within a controlled environment.
No specific "custodial license" exists. Instead, entities wishing to provide any form of digital asset service that involves holding client funds (even if implicitly, like an exchange) must apply for and obtain a license to participate in the government's digital asset sandbox program.
This licensing is issued by a joint committee involving the Ministry of Technology and Communications, the Ministry of Finance, and the Bank of Laos. The criteria for obtaining such a license are likely stringent and include demonstrating technical capability, financial soundness, and compliance with general AML/CFT principles.
No specific rules are publicly mandated. While financial best practices and general Anti-Money Laundering/Combating the Financing of Terrorism (AML/CFT) principles would strongly suggest the segregation of client assets from the firm's operational assets, there are no explicit legal requirements for this specifically for digital asset custodians in Laos at present. Any requirements would be ad-hoc conditions imposed during the sandbox licensing process.
No specific insurance or bonding requirements for digital asset custody are publicly mandated. General business insurance would be expected for any licensed entity, but crypto-specific insurance or bonding is not a known regulatory requirement.
No specific cold storage mandates are publicly known. While the use of cold storage for the majority of digital assets is a standard industry best practice for security, it is not a specific regulatory requirement in Laos. Security protocols would likely be reviewed as part of the sandbox licensing application, but without prescriptive mandates.
No definition of a "qualified custodian" exists in Laotian law in the context of digital assets. This concept is typically found in more mature financial markets with established securities laws (e.g., the SEC in the U.S.).
Bank of Laos (BOL): The central bank, responsible for monetary policy and financial stability. It has previously issued warnings regarding crypto risks.
Ministry of Finance (MOF): Involved in fiscal policy and potentially taxation of digital asset activities.
Ministry of Technology and Communications (MTC): Plays a role in overseeing the technological aspects of digital assets and the sandbox.
Financial Intelligence Unit (FIU): Responsible for AML/CFT oversight, and any licensed digital asset entity would fall under their purview for reporting suspicious transactions.
No, not comprehensively. While Laos has a general AML/CFT law, its framework for VAs and VASPs is still considered insufficient by international standards. The FATF Travel Rule (which stems from FATF Recommendation 15 and its Interpretive Note) requires countries to regulate VASPs for AML/CFT purposes, including implementing obligations to collect and transmit originator and beneficiary information for virtual asset transfers. Laos has yet to establish this comprehensive regulatory regime.
As the comprehensive regulatory framework for VASPs and the Travel Rule is not yet in place, there is no specific effective date for its implementation in Laos. The initial steps involve defining VAs and VASPs, bringing them under the regulatory scope, and then prescribing the specific Travel Rule obligations.
Given the absence of a comprehensive framework for the Travel Rule, no specific threshold amounts have been defined for VASP transactions in Laos related to the Travel Rule. The FATF standard typically applies to transactions above a certain threshold (e.g., USD/EUR 1,000) for cross-border transfers and sometimes lower for domestic.
This is the primary challenge. Laos's existing AML/CFT framework, while aiming to combat financial crime, does not yet comprehensively define Virtual Assets (VAs) or Virtual Asset Service Providers (VASPs) to bring them under direct AML/CFT supervision as required by FATF Recommendation 15 and its Interpretive Note.
Therefore, there isn't a clear list of "covered VASPs" that are currently subject to Travel Rule obligations. Any entities dealing with virtual assets operate in a largely unregulated or ambiguous legal environment concerning AML/CFT specifically for virtual assets.
While Laos has penalties for general AML/CFT non-compliance under its primary Law on Anti-Money Laundering and Counter-Terrorism Financing, these would apply to entities already covered by the existing framework (e.g., banks, financial institutions, certain designated non-financial businesses and professions).
Since VASPs are not yet comprehensively defined or brought under this regulatory umbrella for virtual asset-specific AML/CFT obligations, there are no specific penalties defined for non-compliance with the Travel Rule by VASPs.
Law on Anti-Money Laundering and Counter-Terrorism Financing (No. 55/NA, dated 26 December 2014, amended): This is Laos's primary AML/CFT legislation. While it provides the general framework, its scope regarding virtual assets and VASPs is currently not comprehensive enough to implement the Travel Rule.
APG Mutual Evaluation Reports for Laos: These reports provide the most authoritative public assessment of Laos's compliance with FATF Recommendations.
The APG 3rd Enhanced Follow-Up Report on Lao PDR (2022), for instance, highlights the ongoing deficiencies in addressing Virtual Assets and VASPs, noting that the country still needs to revise its legal and regulatory framework to ensure VAs and VASPs are adequately covered.
Issuing Official Warnings and Prohibitions: The BOL has repeatedly reminded the public and financial institutions that cryptocurrencies are not legal tender and pose significant risks.
A Brief Experiment with Authorized Mining (and subsequent cooling): There was a period in late 2021 where the Lao government approved a pilot project for a few companies to mine and trade cryptocurrencies, primarily to generate revenue for the state. However, this was a government initiative, not an enforcement action, and the enthusiasm seems to have significantly cooled since.
Regulator Name: Bank of the Lao PDR (BOL)
Entity Targeted: The general public, financial institutions, and potentially anyone engaging in cryptocurrency activities. Violation Type: Engaging in activities with unrecognized digital assets, not being compliant with existing financial regulations, operating outside authorized financial systems. The BOL views cryptocurrencies as speculative assets that are not legal tender and pose risks like money laundering, fraud, and financial instability. Penalty Amount: Not applicable to warnings; potential penalties for actual illegal operations would fall under existing financial or criminal laws, not specific crypto regulations.
Date: Warnings have been issued periodically, with renewed emphasis in recent years. Key periods include late 2021 when global crypto interest surged, and ongoing reminders.
Outcome: Reinforcement of the official position that cryptocurrencies are not recognized as legal tender or regulated financial products in Laos. Discouragement of public participation.
Legal Basis: This stance stems from the BOL's mandate to maintain monetary stability, control the national currency (Lao Kip - LAK), and regulate the payment system under the Law on the Bank of the Lao PDR and the Law on Payment Systems.
Verdict Attribution
- Source:
- AI-Generated · Unreviewed
- AI synthesized:
- 2026-07-13 (deepseek-chat)
- Last updated:
- 2026-07-13
- Confidence:
- medium
This verdict was produced by an AI model from the underlying facts. Confirm with counsel before relying on it for material decisions.
Conditional — a centralized exchange is permitted in Laos only if it obtains a license under the government's restrictive digital asset sandbox program, which requires a local entity, joint-committee approval (BOL, MTC, MOF), and compliance with AML/CFT obligations (CDD, ongoing monitoring, STRs, Travel Rule expectations); the broader public is warned against crypto use, and the regulatory framework for VASPs remains incomplete.
Questions this verdict aims to answer
- What exchange / VASP license applies?
- What custody segregation rules apply to user assets?
- What market-conduct and listing rules apply?
- What travel-rule obligations apply on withdrawals?