DeFi protocol frontend in Peru
Operates a web frontend or aggregator that interacts with permissionless smart contracts on behalf of users. May or may not screen users / restrict regions.
DeFi frontend is conditionally permitted in Peru without local incorporation, subject to AML obligations and low licensing burden.
Verdict Details
- Permitted
- conditional
- Local entity required
- No
- Licensing burden
- Low
- Last updated
- 2026-07-13
AML Obligations
- VASPs (including DeFi frontends that facilitate crypto-to-fiat conversions) are designated as obliged entities under Resolución SBS N° 893-2019 and must implement an AML/CFT compliance program. (pe.aml.resolucin-sbs-n-893-2019-and)
- Must appoint a compliance officer and report to the UIF-Perú. (pe.aml.what-it-means-for-vasps)
- Customer Due Diligence (CDD) required: obtain and verify identity of individuals (national ID, passport) and legal entities (articles of incorporation, business registration). (pe.aml.identification-and-verification, pe.aml.individuals-obtain-and-verify-identity, pe.aml.legal-entities-obtain-and-verify)
- Beneficial ownership identification required. (pe.aml.beneficial-ownership-identify-and-verify)
- Ongoing transaction monitoring for unusual or suspicious patterns. (pe.aml.ongoing-monitoring-continuously-monitor-the)
- Enhanced Due Diligence (EDD) required for high-risk customers, PEPs, high-risk jurisdictions, and significant-value transactions. (pe.aml.enhanced-due-diligence-edd-required, pe.aml.customers-from-high-risk-jurisdictions, pe.aml.politically-exposed-persons-peps-and)
- Suspicious Transaction Reports (ROS) must be filed with the UIF-Perú. (pe.licensing.reporting-suspicious-transactions-ros-reporting)
- Record-keeping of transactions and customer data required. (pe.licensing.record-keeping-maintaining-records-of-transactions)
- Must conduct a comprehensive AML risk assessment and establish internal policies, procedures, and training programs. (pe.licensing.risk-assessment-conducting-a-comprehensive, pe.licensing.internal-controls-establishing-internal-policies)
Key Restrictions
- If the frontend facilitates crypto-to-fiat or fiat-to-crypto conversions, it may be deemed a financial intermediation or money transmission activity and could become subject to SBS regulations applicable to Electronic Money Issuing Companies (EEDEs) or other traditional financial licenses. (pe.licensing.if-they-facilitate-crypto-to-fiat-or, pe.licensing.however-if-an-exchange-facilitates)
- No specific crypto license exists, so the frontend operates under general commercial law as a regular company — but this creates legal uncertainty. (pe.licensing.they-typically-operate-under-general)
- If the frontend offers services resembling traditional payment services or money transfers in fiat, heightened regulatory scrutiny applies. (pe.licensing.if-they-facilitate-crypto-to-fiat-or)
- Geofencing/region-restriction obligations are not explicitly codified, but VASPs must identify and verify customers per CDD requirements, implying KYC-based access controls are expected. (pe.licensing.customer-due-diligence-cdd-implementing)
Key Risks
- Regulatory ambiguity: VASPs are not explicitly listed as 'obligated subjects' in the foundational AML law (Ley N° 27693) — the designation comes via SBS resolution (Resolución SBS N° 893-2019), which could be challenged or inconsistently enforced. (pe.licensing.while-vasps-are-not-explicitly)
- DeFi frontends that do not take fees or control smart contracts may argue they are 'non-custodial' software providers and not VASPs — this argument has not been tested in Peru. (pe.licensing.no-specific-licensing-regime-for)
- If fee-taking is structured as a service fee for facilitating transactions (especially fiat on/off ramps), it increases the risk of classification as a regulated financial intermediary. (pe.licensing.if-they-facilitate-crypto-to-fiat-or)
- No existing enforcement precedent specifically targeting DeFi frontends in Peru; unclear how UIF-Perú or SBS would treat a non-custodial interface. (pe.licensing.no-specific-licensing-regime-for)
- If the frontend enables lending, interest-bearing products, or staking rewards, it could attract SBS scrutiny requiring traditional financial licenses with significant capital requirements. (pe.licensing.if-custody-services-evolve-to, pe.licensing.if-a-vasp-were-to)
Evidence
This verdict synthesizes the following facts. Each fact links to its primary source(s).
No specific Licensing Regime for VASPs: There is no dedicated law requiring crypto exchanges, custody providers, or crypto-focused payment processors to obtain a specific "virtual asset license" from a regulatory body like the Superintendencia de Banca, Seguros y AFP (SBS) or the Banco Central de Reserva del Perú (BCRP).
AML/CTF Obligations for Existing "Obligated Subjects": The primary regulatory interaction for entities dealing with virtual assets comes from the Unidad de Inteligencia Financiera del Perú (UIF-Perú), which oversees AML/CTF compliance. Existing "obligated subjects" (sujetos obligados) under the AML/CTF framework (like banks, financial institutions, payment service providers dealing with fiat, and money transmitters) are expected to manage risks associated with virtual assets if they engage with them.
No specific crypto exchange license is required.
They typically operate under general commercial law, registering as a regular company in Peru.
However, if an exchange facilitates fiat-to-crypto or crypto-to-fiat conversions, or offers services that could be interpreted as financial intermediation or money transmission under existing laws, there's a risk they might be expected to comply with some aspects of financial regulation, particularly AML/CTF.
If they facilitate crypto-to-fiat or fiat-to-crypto payments, or if their services resemble traditional payment services (e.g., money transfers in fiat), they might be subject to the regulations applicable to Electronic Money Issuing Companies (Empresas Emisoras de Dinero Electrónico - EEDEs) or other payment service providers, which are regulated by the SBS. However, the direct application to pure-play crypto firms is often unclear.
AML/KYC (Anti-Money Laundering/Know Your Customer): This is the most relevant area.
While VASPs are not explicitly listed as "obligated subjects" in the current AML/CTF law, the UIF-Perú encourages all entities engaged in activities susceptible to money laundering (including new technologies) to implement robust AML/KYC practices.
Customer Due Diligence (CDD): Implementing KYC procedures to identify and verify customers (natural persons and legal entities).
Reporting Suspicious Transactions (ROS): Reporting any suspicious activity to the UIF-Perú.
Record-Keeping: Maintaining records of transactions and customer data.
Risk Assessment: Conducting a comprehensive risk assessment of money laundering and terrorist financing risks.
Internal Controls: Establishing internal policies, procedures, and training programs.
Resolución SBS N° 893-2019 (and its preceding/subsequent modifications):
What it means for VASPs: VASPs are now required to implement an AML/CFT compliance program, appoint a compliance officer, and report to the UIF-Perú.
Individuals: Obtain and verify identity using reliable independent source documents (e.g., national ID, passport). This includes full name, date of birth, place of birth, nationality, address, and national identification number.
Legal Entities: Obtain and verify legal name, legal form, address of main place of business, names of directors/partners, legal representative, and evidence of legal existence (e.g., articles of incorporation, business registration).
Beneficial Ownership: Identify and verify the natural person(s) who ultimately own or control the customer, or on whose behalf a transaction is being conducted.
Ongoing Monitoring: Continuously monitor the business relationship and transactions to ensure they are consistent with the VASP's knowledge of the customer, their business, and risk profile. This includes monitoring for unusual or suspicious transaction patterns.
Enhanced Due Diligence (EDD): Required for higher-risk customers, business relationships, or transactions. This includes:
Politically Exposed Persons (PEPs) and their family members/close associates.
If a VASP were to be deemed a traditional financial institution (e.g., an EEDE), then significant capital requirements mandated by the SBS would apply.
If custody services evolve to offer interest-bearing accounts, lending, or other financial products using virtual assets, they could potentially attract scrutiny from the SBS and might be deemed to require traditional financial licenses.
Verdict Attribution
- Source:
- AI-Generated · Unreviewed
- AI synthesized:
- 2026-07-13 (deepseek-chat)
- Last updated:
- 2026-07-13
- Confidence:
- low
This verdict was produced by an AI model from the underlying facts. Confirm with counsel before relying on it for material decisions.
Conditional — A DeFi protocol frontend operating in Peru is not subject to a specific crypto licensing regime but is likely classified as a VASP under Resolución SBS N° 893-2019 for AML/CTF purposes, requiring KYC, transaction monitoring, and suspicious activity reporting to UIF-Perú; fee-taking or fiat conversion increases the risk of being deemed a regulated financial intermediary requiring SBS licensing.
Questions this verdict aims to answer
- Is operating the frontend a regulated activity even if the protocol is decentralized?
- What geofencing or KYC obligations apply?
- Does fee-taking change classification?