← Regulations / Laos / Operating Models / Remote VASP

Remote VASP serving residents in Laos

Foreign-incorporated entity that offers exchange, custody, or transfer services to residents of a jurisdiction without establishing a local entity or office.

Conditional AI-Generated · Unreviewed

Remote VASP is conditionally permitted in Laos with a local entity, subject to AML obligations and high licensing burden.

Verdict Details

Permitted
conditional
Local entity required
Yes
Licensing burden
High
Last updated
2026-07-13

AML Obligations

  • CDD: Obtain and verify identity (name, DOB, nationality, address, ID document for individuals; legal name, registered address, registration number, articles, directors for legal entities)
  • Beneficial ownership: Identify and take reasonable measures to verify beneficial owner(s)
  • Purpose and nature of business relationship: Understand and document intended nature of relationship
  • Ongoing monitoring: Scrutinize transactions throughout the relationship for consistency with customer risk profile
  • Risk-based approach: Apply EDD for PEPs, high-risk jurisdictions, complex/unusual transactions
  • Travel Rule: Expected to collect and transmit originator/beneficiary info for VA transfers above threshold (though specific local threshold not yet defined)
  • Suspicious transaction reporting: Report any transaction (regardless of amount) known, suspected, or with reasonable grounds of ML/TF to the FIU
  • No tipping-off: Prohibited from disclosing to customer or third parties that an STR has been or will be submitted
  • Timeliness: Reports to FIU must be submitted promptly upon suspicion
  • Record-keeping: Maintain CDD docs, transaction records, STR copies for minimum 5 years after relationship ends or transaction date

Key Restrictions

  • Must obtain a license via the government's digital asset sandbox program (joint committee of Ministry of Technology & Communications, Ministry of Finance, and Bank of Laos)
  • Must be an approved participant in the pilot/sandbox — broad public-facing crypto services are otherwise prohibited
  • No non-resident licensing path exists; licensing requires demonstrating technical capability, financial soundness, and AML/CFT compliance locally
  • Cross-border service to residents without local sandbox participation constitutes unlicensed activity subject to enforcement
  • Cryptocurrencies are not recognized as legal tender or regulated financial products in Laos

Key Risks

  • High enforcement risk for unlicensed remote VASPs — BOL has issued repeated public warnings against crypto use and Laos treats unlicensed crypto activity as operating outside authorized financial systems
  • Regulatory framework for VAs and VASPs is still classified as insufficient by FATF standards; AML/CFT obligations for VASPs are not yet comprehensively defined in law
  • The sandbox pilot program appears to have limited public update — continuation or expansion is uncertain, creating ambiguity for licensed operators
  • General public prohibition on crypto trading/exchange means any remote VASP serving residents faces legal exposure regardless of licensing status
  • Government has shown willingness to ban/warn, then selectively permit only state-favored projects (mining for energy monetization), not foreign remote exchanges

Evidence

This verdict synthesizes the following facts. Each fact links to its primary source(s).

licensing 40% confidence

Law on Anti-Money Laundering and Combating the Financing of Terrorism (Law No. 67/NA, dated 17 November 2022): This is the foundational AML/CFT law in Laos, superseding previous versions. It establishes the general obligations for reporting entities, including financial institutions, and covers key aspects of AML/CFT compliance.

licensing 40% confidence

Instruction on the Management and Supervision of Virtual Assets (Instruction No. 001/BOL, dated 28 January 2022): Issued by the Bank of Lao PDR, this instruction is highly specific to the pilot program for virtual assets. It outlines the regulatory framework, licensing requirements, and ongoing obligations (including AML/KYC) for entities authorized to engage in virtual asset activities (mining, trading platforms, exchanges, etc.). It designates authorized VASPs as reporting entities for AML/CFT purposes.

licensing 40% confidence

Regulatory Approach: Restrictive / Partial Ban (for the public) with Controlled Exceptions.

licensing 40% confidence

Bank of Lao PDR (BOL): The BOL is the central bank and the primary financial regulator in Laos. It is responsible for issuing licenses/authorizations for VASPs under the pilot program, developing specific regulations (like Instruction No. 001/BOL), and conducting ongoing supervision and examinations to ensure compliance with AML/CFT and other prudential requirements.

licensing 40% confidence

Financial Intelligence Unit (FIU) of Laos: Operating under the Bank of Lao PDR, the FIU is the central agency for receiving, analyzing, and disseminating suspicious transaction reports to law enforcement agencies.

custody 60% confidence

A General Prohibition with Exceptions: Initial stances were restrictive. However, a significant development was the Prime Minister's Order No. 001/PMO, which allowed for a controlled experiment.

custody 60% confidence

The "Sandbox" Approach: The government initiated a pilot program or "sandbox" allowing a limited number of companies to mine and trade cryptocurrencies under strict supervision. This means that any entity engaging in activities that would involve custody must be part of this approved sandbox.

custody 60% confidence

Prime Minister's Order No. 001/PMO concerning the management of cryptocurrencies and digital assets (2021): This Order effectively lifted a prior ban on crypto activities, allowing the Ministry of Technology and Communications, the Bank of Laos, and the Ministry of Finance to permit and manage the mining and trading of digital assets by selected companies within a controlled environment.

custody 60% confidence

No specific "custodial license" exists. Instead, entities wishing to provide any form of digital asset service that involves holding client funds (even if implicitly, like an exchange) must apply for and obtain a license to participate in the government's digital asset sandbox program.

custody 60% confidence

This licensing is issued by a joint committee involving the Ministry of Technology and Communications, the Ministry of Finance, and the Bank of Laos. The criteria for obtaining such a license are likely stringent and include demonstrating technical capability, financial soundness, and compliance with general AML/CFT principles.

aml 40% confidence

No, not comprehensively. While Laos has a general AML/CFT law, its framework for VAs and VASPs is still considered insufficient by international standards. The FATF Travel Rule (which stems from FATF Recommendation 15 and its Interpretive Note) requires countries to regulate VASPs for AML/CFT purposes, including implementing obligations to collect and transmit originator and beneficiary information for virtual asset transfers. Laos has yet to establish this comprehensive regulatory regime.

aml 40% confidence

Which VASPs are Covered:

aml 40% confidence

Therefore, there isn't a clear list of "covered VASPs" that are currently subject to Travel Rule obligations. Any entities dealing with virtual assets operate in a largely unregulated or ambiguous legal environment concerning AML/CFT specifically for virtual assets.

enforcement 60% confidence

Issuing Official Warnings and Prohibitions: The BOL has repeatedly reminded the public and financial institutions that cryptocurrencies are not legal tender and pose significant risks.

enforcement 60% confidence

Entity Targeted: The general public, financial institutions, and potentially anyone engaging in cryptocurrency activities. Violation Type: Engaging in activities with unrecognized digital assets, not being compliant with existing financial regulations, operating outside authorized financial systems. The BOL views cryptocurrencies as speculative assets that are not legal tender and pose risks like money laundering, fraud, and financial instability. Penalty Amount: Not applicable to warnings; potential penalties for actual illegal operations would fall under existing financial or criminal laws, not specific crypto regulations.

enforcement 60% confidence

A Brief Experiment with Authorized Mining (and subsequent cooling): There was a period in late 2021 where the Lao government approved a pilot project for a few companies to mine and trade cryptocurrencies, primarily to generate revenue for the state. However, this was a government initiative, not an enforcement action, and the enthusiasm seems to have significantly cooled since.

enforcement 70% confidence

Legal Basis: This stance stems from the BOL's mandate to maintain monetary stability, control the national currency (Lao Kip - LAK), and regulate the payment system under the Law on the Bank of the Lao PDR and the Law on Payment Systems.

licensing 40% confidence

Identification and Verification:

licensing 40% confidence

Obtain and verify the identity of the customer (individual or legal entity) using reliable, independent source documents, data, or information. For individuals, this includes full name, date of birth, nationality, residential address, and official identification document details (e.g., passport, national ID card).

licensing 40% confidence

For legal entities, this includes legal name, registered address, registration number, articles of association, and details of directors/senior management.

licensing 40% confidence

Beneficial Ownership: Identify and take reasonable measures to verify the identity of the beneficial owner(s) of the customer, including for legal entities and arrangements.

licensing 40% confidence

Purpose and Nature of Relationship: Understand and, where appropriate, obtain information on the purpose and intended nature of the business relationship or transaction.

licensing 40% confidence

Ongoing Monitoring: Conduct ongoing monitoring of the business relationship, including scrutiny of transactions undertaken throughout the course of that relationship to ensure that the transactions are consistent with the VASP's knowledge of the customer, their business, and risk profile.

licensing 40% confidence

Risk-Based Approach: Apply a risk-based approach to CDD, meaning enhanced due diligence (EDD) must be applied to higher-risk customers, business relationships, or transactions (e.g., politically exposed persons (PEPs), customers from high-risk jurisdictions, complex or unusual transactions, or transactions involving high-value virtual assets). Simplified due diligence (SDD) may be applied in lower-risk situations.

licensing 40% confidence

"Travel Rule" (FATF Recommendation 16): While specific detailed local regulations on the "Travel Rule" for VASPs may be further developed, authorized VASPs are generally expected to collect and transmit required originator and beneficiary information for virtual asset transfers above a certain threshold, in line with FATF recommendations, especially when transacting with other VASPs.

licensing 40% confidence

Reporting Obligation: Any transaction (regardless of amount) that the VASP knows, suspects, or has reasonable grounds to suspect involves money laundering, financing of terrorism, or other illicit activities, must be reported.

licensing 40% confidence

No Tipping-Off: VASPs and their employees are prohibited from disclosing to the customer or third parties that a suspicious transaction report has been or will be submitted.

licensing 40% confidence

Timeliness: Reports must be submitted to the FIU promptly, as soon as the suspicion is formed.

licensing 40% confidence

Customer Identification Records: All documents and information obtained during the CDD process, including copies of identification documents, beneficial ownership information, and risk assessments.

licensing 40% confidence

Transaction Records: Records of all transactions, including the amount, currency (both fiat and virtual asset), date, type of transaction, and the parties involved (originator and beneficiary information).

licensing 40% confidence

STR Records: Copies of all suspicious transaction reports submitted to the FIU and any internal analysis leading to those reports.

licensing 40% confidence

Retention Period: Records must generally be kept for a minimum of five (5) years after the business relationship has ended or after the date of the transaction.

Verdict Attribution

Source:
AI-Generated · Unreviewed
AI synthesized:
2026-07-13 (deepseek-chat)
Last updated:
2026-07-13
Confidence:
medium

This verdict was produced by an AI model from the underlying facts. Confirm with counsel before relying on it for material decisions.

Conditional — a non-resident remote VASP may not serve Laos residents without joining the government's digital asset sandbox program, which requires a local license from a joint committee (MTC/MOF/BOL), and the broader public remains subject to a de facto prohibition on crypto trading, with high enforcement risk for unlicensed cross-border operators.

Questions this verdict aims to answer

  • May a non-resident provider serve residents from abroad?
  • Does cross-border service trigger licensing, registration, or AML obligations?
  • What enforcement risk exists for unlicensed remote operators?