← Regulations / Laos / Operating Models / DeFi frontend

DeFi protocol frontend in Laos

Operates a web frontend or aggregator that interacts with permissionless smart contracts on behalf of users. May or may not screen users / restrict regions.

Conditional AI-Generated · Unreviewed

DeFi frontend is conditionally permitted in Laos with a local entity, subject to AML obligations and high licensing burden.

Verdict Details

Permitted
conditional
Local entity required
Yes
Licensing burden
High
Last updated
2026-07-13

AML Obligations

  • CDD required under Law No. 67/NA — must obtain and verify identity (name, DOB, nationality, address, official ID) for individuals and legal entities (legal name, registered address, registration number, articles, directors)
  • Beneficial ownership identification and verification required
  • Ongoing monitoring of business relationships and transactions
  • Risk-based approach required — EDD for PEPs, high-risk jurisdictions, complex/unusual transactions
  • Travel Rule (FATF Rec. 16) expected — collect and transmit originator/beneficiary info for VA transfers (threshold not yet defined in Laos)
  • Suspicious Transaction Reporting to the FIU — any transaction suspected of ML/TF must be reported promptly, regardless of amount
  • No tipping-off prohibition
  • Record-keeping: customer identification docs, transaction records, STR copies — minimum 5 years retention

Key Restrictions

  • DeFi frontend likely constitutes a VASP activity under BOL Instruction No. 001/BOL pilot program scope
  • Only entities licensed under the government's digital asset sandbox program may operate — general public is prohibited from engaging in crypto trading/exchange services
  • Must apply to a joint committee of MTC, MOF, and BOL for sandbox participation — criteria are stringent
  • Fee-taking (commission/fees from user transactions) likely classifies the frontend as a regulated VASP engaging in exchange/trading services
  • Geofencing Laos residents is practically required since unlicensed crypto services to the public are prohibited and BOL has issued repeated warnings
  • No comprehensive VA/VASP legal framework yet exists — operator would be subject to an experimental sandbox regime

Key Risks

  • High regulatory ambiguity — Laos does not yet comprehensively define VAs or VASPs under AML law, creating enforcement uncertainty
  • BOL has repeatedly issued public warnings that crypto is not legal tender and that engaging in crypto activities poses risks — enforcement actions against unlicensed operators are possible
  • The sandbox pilot program is experimental; its continuation and scope changes are unpredictable
  • FATF has identified Laos as deficient in VA/VASP AML/CFT coverage (APG 3rd Enhanced Follow-Up Report 2022) — the regime may change rapidly
  • Public-facing frontends risk being targeted by enforcement as operating outside authorized financial systems
  • No specific custodial, insurance, or technical requirements exist — operator bears all security risk without regulatory clarity

Evidence

This verdict synthesizes the following facts. Each fact links to its primary source(s).

licensing 40% confidence

Instruction on the Management and Supervision of Virtual Assets (Instruction No. 001/BOL, dated 28 January 2022): Issued by the Bank of Lao PDR, this instruction is highly specific to the pilot program for virtual assets. It outlines the regulatory framework, licensing requirements, and ongoing obligations (including AML/KYC) for entities authorized to engage in virtual asset activities (mining, trading platforms, exchanges, etc.). It designates authorized VASPs as reporting entities for AML/CFT purposes.

licensing 40% confidence

Regulatory Approach: Restrictive / Partial Ban (for the public) with Controlled Exceptions.

licensing 40% confidence

For the general public and most businesses, engaging in cryptocurrency trading, exchanges, or financial services is largely prohibited or highly discouraged due to the Bank of the Lao PDR's warnings and notices.

licensing 40% confidence

Law on Anti-Money Laundering and Combating the Financing of Terrorism (Law No. 67/NA, dated 17 November 2022): This is the foundational AML/CFT law in Laos, superseding previous versions. It establishes the general obligations for reporting entities, including financial institutions, and covers key aspects of AML/CFT compliance.

licensing 40% confidence

Identification and Verification:

licensing 40% confidence

Obtain and verify the identity of the customer (individual or legal entity) using reliable, independent source documents, data, or information. For individuals, this includes full name, date of birth, nationality, residential address, and official identification document details (e.g., passport, national ID card).

licensing 40% confidence

For legal entities, this includes legal name, registered address, registration number, articles of association, and details of directors/senior management.

licensing 40% confidence

Beneficial Ownership: Identify and take reasonable measures to verify the identity of the beneficial owner(s) of the customer, including for legal entities and arrangements.

licensing 40% confidence

Purpose and Nature of Relationship: Understand and, where appropriate, obtain information on the purpose and intended nature of the business relationship or transaction.

licensing 40% confidence

Ongoing Monitoring: Conduct ongoing monitoring of the business relationship, including scrutiny of transactions undertaken throughout the course of that relationship to ensure that the transactions are consistent with the VASP's knowledge of the customer, their business, and risk profile.

licensing 40% confidence

Risk-Based Approach: Apply a risk-based approach to CDD, meaning enhanced due diligence (EDD) must be applied to higher-risk customers, business relationships, or transactions (e.g., politically exposed persons (PEPs), customers from high-risk jurisdictions, complex or unusual transactions, or transactions involving high-value virtual assets). Simplified due diligence (SDD) may be applied in lower-risk situations.

licensing 40% confidence

"Travel Rule" (FATF Recommendation 16): While specific detailed local regulations on the "Travel Rule" for VASPs may be further developed, authorized VASPs are generally expected to collect and transmit required originator and beneficiary information for virtual asset transfers above a certain threshold, in line with FATF recommendations, especially when transacting with other VASPs.

licensing 40% confidence

Reporting Obligation: Any transaction (regardless of amount) that the VASP knows, suspects, or has reasonable grounds to suspect involves money laundering, financing of terrorism, or other illicit activities, must be reported.

licensing 40% confidence

No Tipping-Off: VASPs and their employees are prohibited from disclosing to the customer or third parties that a suspicious transaction report has been or will be submitted.

licensing 40% confidence

Timeliness: Reports must be submitted to the FIU promptly, as soon as the suspicion is formed.

licensing 40% confidence

Customer Identification Records: All documents and information obtained during the CDD process, including copies of identification documents, beneficial ownership information, and risk assessments.

licensing 40% confidence

Transaction Records: Records of all transactions, including the amount, currency (both fiat and virtual asset), date, type of transaction, and the parties involved (originator and beneficiary information).

licensing 40% confidence

STR Records: Copies of all suspicious transaction reports submitted to the FIU and any internal analysis leading to those reports.

licensing 40% confidence

Retention Period: Records must generally be kept for a minimum of five (5) years after the business relationship has ended or after the date of the transaction.

licensing 40% confidence

Bank of Lao PDR (BOL): The BOL is the central bank and the primary financial regulator in Laos. It is responsible for issuing licenses/authorizations for VASPs under the pilot program, developing specific regulations (like Instruction No. 001/BOL), and conducting ongoing supervision and examinations to ensure compliance with AML/CFT and other prudential requirements.

licensing 40% confidence

Financial Intelligence Unit (FIU) of Laos: Operating under the Bank of Lao PDR, the FIU is the central agency for receiving, analyzing, and disseminating suspicious transaction reports to law enforcement agencies.

custody 60% confidence

A General Prohibition with Exceptions: Initial stances were restrictive. However, a significant development was the Prime Minister's Order No. 001/PMO, which allowed for a controlled experiment.

custody 60% confidence

The "Sandbox" Approach: The government initiated a pilot program or "sandbox" allowing a limited number of companies to mine and trade cryptocurrencies under strict supervision. This means that any entity engaging in activities that would involve custody must be part of this approved sandbox.

custody 60% confidence

Prime Minister's Order No. 001/PMO concerning the management of cryptocurrencies and digital assets (2021): This Order effectively lifted a prior ban on crypto activities, allowing the Ministry of Technology and Communications, the Bank of Laos, and the Ministry of Finance to permit and manage the mining and trading of digital assets by selected companies within a controlled environment.

custody 60% confidence

No specific "custodial license" exists. Instead, entities wishing to provide any form of digital asset service that involves holding client funds (even if implicitly, like an exchange) must apply for and obtain a license to participate in the government's digital asset sandbox program.

custody 60% confidence

This licensing is issued by a joint committee involving the Ministry of Technology and Communications, the Ministry of Finance, and the Bank of Laos. The criteria for obtaining such a license are likely stringent and include demonstrating technical capability, financial soundness, and compliance with general AML/CFT principles.

enforcement 60% confidence

Issuing Official Warnings and Prohibitions: The BOL has repeatedly reminded the public and financial institutions that cryptocurrencies are not legal tender and pose significant risks.

enforcement 60% confidence

Outcome: Reinforcement of the official position that cryptocurrencies are not recognized as legal tender or regulated financial products in Laos. Discouragement of public participation.

aml 40% confidence

No, not comprehensively. While Laos has a general AML/CFT law, its framework for VAs and VASPs is still considered insufficient by international standards. The FATF Travel Rule (which stems from FATF Recommendation 15 and its Interpretive Note) requires countries to regulate VASPs for AML/CFT purposes, including implementing obligations to collect and transmit originator and beneficiary information for virtual asset transfers. Laos has yet to establish this comprehensive regulatory regime.

aml 40% confidence

Which VASPs are Covered:

aml 40% confidence

This is the primary challenge. Laos's existing AML/CFT framework, while aiming to combat financial crime, does not yet comprehensively define Virtual Assets (VAs) or Virtual Asset Service Providers (VASPs) to bring them under direct AML/CFT supervision as required by FATF Recommendation 15 and its Interpretive Note.

aml 40% confidence

Therefore, there isn't a clear list of "covered VASPs" that are currently subject to Travel Rule obligations. Any entities dealing with virtual assets operate in a largely unregulated or ambiguous legal environment concerning AML/CFT specifically for virtual assets.

aml 40% confidence

APG Mutual Evaluation Reports for Laos: These reports provide the most authoritative public assessment of Laos's compliance with FATF Recommendations.

Verdict Attribution

Source:
AI-Generated · Unreviewed
AI synthesized:
2026-07-13 (deepseek-chat)
Last updated:
2026-07-13
Confidence:
low

This verdict was produced by an AI model from the underlying facts. Confirm with counsel before relying on it for material decisions.

Conditional — a DeFi protocol frontend is likely a regulated activity requiring sandbox licensing under BOL Instruction No. 001/BOL and Prime Minister's Order No. 001/PMO, but the legal framework for VAs/VASPs is still insufficiently developed, creating significant ambiguity; fee-taking would strengthen classification as a regulated VASP.

Questions this verdict aims to answer

  • Is operating the frontend a regulated activity even if the protocol is decentralized?
  • What geofencing or KYC obligations apply?
  • Does fee-taking change classification?