← Regulations / Peru / Operating Models / Remote VASP

Remote VASP serving residents in Peru

Foreign-incorporated entity that offers exchange, custody, or transfer services to residents of a jurisdiction without establishing a local entity or office.

Conditional AI-Generated · Unreviewed

Remote VASP is conditionally permitted in Peru without local incorporation, subject to AML obligations and low licensing burden.

Verdict Details

Permitted
conditional
Local entity required
No
Licensing burden
Low
Last updated
2026-07-13

AML Obligations

  • VASPs are explicitly designated as obliged entities under Resolución SBS N° 893-2019, requiring implementation of an AML/CFT compliance program, appointment of a compliance officer, and reporting to UIF-Perú.
  • Customer Due Diligence (CDD): Must obtain and verify identity for individuals (national ID/passport, full name, date of birth, address, nationality) and legal entities (legal name, form, address, directors, beneficial owners).
  • Beneficial ownership identification and verification is required.
  • Enhanced Due Diligence (EDD) required for PEPs, high-risk jurisdictions, high-value virtual asset transactions, and transactions with unusual patterns.
  • Ongoing monitoring of business relationships and transactions for unusual or suspicious patterns.
  • Suspicious Transaction Reports (ROS) must be filed with UIF-Perú.
  • Record-keeping of transactions and customer data required.
  • Risk assessment and internal controls (policies, procedures, training programs) must be established.
  • Foreign entities serving residents remotely must still comply with these AML obligations if they are deemed obliged subjects under Peruvian law.

Key Restrictions

  • No specific VASP licensing regime exists — no dedicated crypto exchange, custody, or payment processor license is required.
  • If services involve fiat-to-crypto or crypto-to-fiat conversions, they may be deemed financial intermediation or money transmission, potentially triggering traditional financial regulation (e.g., EEDE licensing by SBS).
  • If custody services evolve to offer interest-bearing accounts or lending, they may require traditional financial licenses from SBS.
  • VASPs are not explicitly listed as 'obligated subjects' under the main AML/CTF law (Ley N° 27693), but Resolución SBS N° 893-2019 designates them as obliged entities for AML/CFT purposes.
  • General company law applies for formation — no specific capital requirements for VASPs unless deemed a traditional financial institution.
  • FATF Recommendation 15 obligations apply as Peru is a member of GAFILAT/FATF-LAC.

Key Risks

  • Regulatory ambiguity: No specific VASP licensing regime exists, creating uncertainty about whether a foreign remote VASP needs to register or obtain any specific authorization before serving residents.
  • Risk of SBS scrutiny: If fiat conversion services are deemed money transmission or financial intermediation, the operator could face enforcement for operating without a required financial license.
  • UIF-Perú AML enforcement: While VASPs are designated obliged entities under SBS Resolution, the lack of explicit inclusion in the primary AML law creates legal ambiguity and potential enforcement risk.
  • No local entity requirement means no 'safe harbor' for foreign operators — the regulator could theoretically pursue unlicensed cross-border activity.
  • FATF pressure: Peru's GAFILAT membership means increasing regulatory attention on VASPs is likely, raising the risk of future regulatory changes or enforcement actions against unregistered operators.

Evidence

This verdict synthesizes the following facts. Each fact links to its primary source(s).

licensing 60% confidence

No specific Licensing Regime for VASPs: There is no dedicated law requiring crypto exchanges, custody providers, or crypto-focused payment processors to obtain a specific "virtual asset license" from a regulatory body like the Superintendencia de Banca, Seguros y AFP (SBS) or the Banco Central de Reserva del Perú (BCRP).

licensing 60% confidence

AML/CTF Obligations for Existing "Obligated Subjects": The primary regulatory interaction for entities dealing with virtual assets comes from the Unidad de Inteligencia Financiera del Perú (UIF-Perú), which oversees AML/CTF compliance. Existing "obligated subjects" (sujetos obligados) under the AML/CTF framework (like banks, financial institutions, payment service providers dealing with fiat, and money transmitters) are expected to manage risks associated with virtual assets if they engage with them.

licensing 60% confidence

However, if an exchange facilitates fiat-to-crypto or crypto-to-fiat conversions, or offers services that could be interpreted as financial intermediation or money transmission under existing laws, there's a risk they might be expected to comply with some aspects of financial regulation, particularly AML/CTF.

licensing 60% confidence

If custody services evolve to offer interest-bearing accounts, lending, or other financial products using virtual assets, they could potentially attract scrutiny from the SBS and might be deemed to require traditional financial licenses.

licensing 60% confidence

If they facilitate crypto-to-fiat or fiat-to-crypto payments, or if their services resemble traditional payment services (e.g., money transfers in fiat), they might be subject to the regulations applicable to Electronic Money Issuing Companies (Empresas Emisoras de Dinero Electrónico - EEDEs) or other payment service providers, which are regulated by the SBS. However, the direct application to pure-play crypto firms is often unclear.

licensing 60% confidence

No specific capital requirements for VASPs. General company formation capital requirements apply based on the chosen legal entity type (e.g., S.A.C., S.A.A.).

licensing 60% confidence

If a VASP were to be deemed a traditional financial institution (e.g., an EEDE), then significant capital requirements mandated by the SBS would apply.

licensing 60% confidence

AML/KYC (Anti-Money Laundering/Know Your Customer): This is the most relevant area.

licensing 60% confidence

While VASPs are not explicitly listed as "obligated subjects" in the current AML/CTF law, the UIF-Perú encourages all entities engaged in activities susceptible to money laundering (including new technologies) to implement robust AML/KYC practices.

licensing 60% confidence

Customer Due Diligence (CDD): Implementing KYC procedures to identify and verify customers (natural persons and legal entities).

licensing 60% confidence

Reporting Suspicious Transactions (ROS): Reporting any suspicious activity to the UIF-Perú.

licensing 60% confidence

Risk Assessment: Conducting a comprehensive risk assessment of money laundering and terrorist financing risks.

licensing 60% confidence

Internal Controls: Establishing internal policies, procedures, and training programs.

licensing 60% confidence

Obligated Subjects: The primary law governing AML/CTF is Ley N° 27693, Ley que crea la Unidad de Inteligencia Financiera del Perú (UIF-Perú), and its regulatory norms. The list of "obligated subjects" (sujetos obligados) who must report to the UIF-Perú includes:

aml 40% confidence

Resolución SBS N° 893-2019 (and its preceding/subsequent modifications):

aml 40% confidence

What it means for VASPs: VASPs are now required to implement an AML/CFT compliance program, appoint a compliance officer, and report to the UIF-Perú.

aml 40% confidence

FATF Recommendations: As a member of the Financial Action Task Force of Latin America (GAFILAT/FATF-LAC), Peru is committed to implementing the FATF Recommendations. FATF Recommendation 15 specifically calls for countries to regulate and supervise VASPs for AML/CFT purposes, and to apply the FATF standards to them. Peru's regulatory moves reflect this commitment.

aml 40% confidence

Identification and Verification:

aml 40% confidence

Beneficial Ownership: Identify and verify the natural person(s) who ultimately own or control the customer, or on whose behalf a transaction is being conducted.

aml 40% confidence

Ongoing Monitoring: Continuously monitor the business relationship and transactions to ensure they are consistent with the VASP's knowledge of the customer, their business, and risk profile. This includes monitoring for unusual or suspicious transaction patterns.

aml 40% confidence

Enhanced Due Diligence (EDD): Required for higher-risk customers, business relationships, or transactions. This includes:

aml 40% confidence

Customers from high-risk jurisdictions.

aml 40% confidence

Politically Exposed Persons (PEPs) and their family members/close associates.

aml 40% confidence

Transactions involving significant amounts of virtual assets.

aml 40% confidence

Transactions with unusual patterns or no apparent economic or lawful purpose.

aml 40% confidence

Collecting additional information on the customer, beneficial owner, source of funds/wealth, and the reasons for the intended transactions.

aml 40% confidence

Obtaining senior management approval for establishing or continuing relationships with such customers.

aml 40% confidence

Simplified CDD: May be applied in situations of lower risk, provided the VASP has sufficient information to determine that the risk is low.

Verdict Attribution

Source:
AI-Generated · Unreviewed
AI synthesized:
2026-07-13 (deepseek-chat)
Last updated:
2026-07-13
Confidence:
medium

This verdict was produced by an AI model from the underlying facts. Confirm with counsel before relying on it for material decisions.

Conditional — a foreign remote VASP may serve Peruvian residents without a specific VASP license and without a local entity, but is subject to AML/CFT obligations as a designated obliged entity under Resolución SBS N° 893-2019 (CDD, EDD, suspicious transaction reporting to UIF-Perú, compliance officer), and faces heightened regulatory risk if fiat conversion services are deemed financial intermediation requiring traditional licensing.

Questions this verdict aims to answer

  • May a non-resident provider serve residents from abroad?
  • Does cross-border service trigger licensing, registration, or AML obligations?
  • What enforcement risk exists for unlicensed remote operators?