← Regulations / Timor-Leste / Operating Models / Crypto ATM

Crypto ATM / kiosk operator in Timor-Leste

Physical kiosks that exchange cash for crypto (and sometimes vice versa). High-cash AML risk profile.

Conditional AI-Generated · Unreviewed

Crypto ATM is conditionally permitted in Timor-Leste with a local entity, subject to AML obligations and low licensing burden.

Verdict Details

Permitted
conditional
Local entity required
Yes
Licensing burden
Low
Last updated
2026-07-13

AML Obligations

  • General AML/CFT obligations under Law No. 2/2011 and Law No. 3/2011 apply (the foundational AML/CFT framework).
  • Customer Due Diligence (CDD) required: identify and verify individuals (name, DOB, nationality, address, government-issued ID) and legal entities (company name, legal form, proof of existence, beneficial owners >25%).
  • Ongoing transaction monitoring required to detect suspicious activity.
  • Enhanced Due Diligence (EDD) mandatory for PEPs, high-risk geographic locations, complex/unusually large transactions, and non-face-to-face business relationships.
  • Suspicious Transaction Reports (STRs) must be filed with the Unidade de Informação Financeira (UIF) — no minimum threshold; report any transaction with reasonable grounds for suspicion of ML/FT.
  • 'No tipping-off' rule applies — cannot disclose STR submission to customer or third parties.
  • Record-keeping: CDD records and transaction records must be retained for at least 5 years after end of business relationship or transaction date.
  • Cash-transaction reporting: No specific cash transaction reporting threshold identified in provided facts; general STR obligation applies regardless of value for suspicious transactions.

Key Restrictions

  • No crypto-specific license or registration regime exists — operator cannot obtain a tailored crypto license.
  • If activities blur with traditional financial services (e.g., holding fiat deposits, facilitating fiat-to-fiat transfers), a BCTL financial license may be required, which carries significant capital requirements.
  • Operator must comply with general business registration / company incorporation laws, requiring a registered office and local representation.
  • BCTL has publicly warned about crypto risks — operating in this space carries heightened regulatory scrutiny risk despite absence of specific prohibitions.
  • No specific kiosk/money-transmitter license category exists; regulatory status of cash-for-crypto kiosks is legally ambiguous.

Key Risks

  • High AML enforcement risk: cash-intensive crypto kiosk model is inherently high-risk under FATF standards, and Timor-Leste's general AML laws apply with no safe harbor for crypto-specific compliance gaps.
  • Regulatory ambiguity: no specific VASP or kiosk license means operator is in a grey zone — BCTL could issue enforcement action or new regulations at any time.
  • Banking risk: local banks may refuse to provide services to a cash-to-crypto kiosk operator due to uncertainty and perceived ML risk.
  • No specific cash-reporting threshold identified — operator lacks clear guidance on CTR obligations, increasing compliance uncertainty.
  • Resource-constrained enforcement: while enforcement is currently low-priority, a high-profile cash-crypto business could attract attention disproportionate to overall market size.

Evidence

This verdict synthesizes the following facts. Each fact links to its primary source(s).

licensing 40% confidence

Lack of Specific Regulation is Not the Same as Legality or Full Freedom: While there are no crypto-specific licenses, any entity operating within Timor-Leste would still be subject to general business laws, tax laws, and potentially, if their activities could be interpreted as traditional financial services, existing financial sector legislation overseen by the Banco Central de Timor-Leste (BCTL).

licensing 40% confidence

AML/CFT Obligations: Even without specific VASP regulation, Timor-Leste, as a member of the international community, is subject to the recommendations of the Financial Action Task Force (FATF). Its existing Anti-Money Laundering (AML) and Counter-Financing of Terrorism (CFT) laws (such as Law No. 2/2011 on the Prevention and Combat of Money Laundering and Financing of Terrorism, and any subsequent updates) would apply to financial institutions and designated non-financial businesses and professions (DNFBPs). The BCTL and other relevant authorities would expect any entity involved in financial transactions, even those involving virtual assets, to have robust AML/KYC controls in place to prevent illicit activities.

licensing 40% confidence

No specific licenses are currently required for crypto-specific activities.

licensing 40% confidence

If a service provider's activities blur the lines with traditional financial services (e.g., holding fiat currency deposits, facilitating fiat-to-fiat transfers through crypto, or providing lending services in fiat backed by crypto), they might inadvertently fall under existing financial services laws and require a license as a financial institution, payment service provider, or money service business from the BCTL. However, for pure crypto-to-crypto activities or non-custodial wallets, there is no direct precedent or requirement.

licensing 40% confidence

Neither a specific registration nor a licensing regime exists for VASPs.

licensing 40% confidence

Capital Requirements: No specific capital requirements for VASPs as there are no specific licenses. If a business were to seek a traditional financial license (e.g., as a payment service provider), then the BCTL's requirements for that specific license would apply, which include significant capital.

licensing 40% confidence

AML/KYC (Anti-Money Laundering/Know Your Customer): This is the most critical area. While specific VASP regulations are absent, any business engaging in financial activities, including those involving virtual assets, is strongly advised to implement robust AML/KYC procedures. This includes:

licensing 40% confidence

Customer due diligence (identifying and verifying customers).

licensing 40% confidence

Reporting suspicious transactions to the national Financial Intelligence Unit (FIU), likely housed within the Ministry of Finance or Central Bank.

licensing 40% confidence

The general AML/CFT laws of Timor-Leste (e.g., Law No. 2/2011) would be the guiding principles. Failure to comply with these general obligations could lead to criminal charges if illicit activities are facilitated.

licensing 40% confidence

Local Presence: No specific local presence requirements for VASPs given the lack of specific regulation. However, to operate any business in Timor-Leste, general company registration and business licensing laws would apply, which typically require a registered office and local representation.

licensing 40% confidence

Law No. 2/2011 on the Prevention and Combat of Money Laundering and Financing of Terrorism: This is Timor-Leste's primary AML/CFT law. While it likely does not explicitly mention "virtual assets" or "VASPs," its general provisions apply to entities engaged in financial activities and would be the basis for any enforcement action related to money laundering or terrorism financing through crypto. Finding the official, current version of this law online through a public government portal can be challenging for Timor-Leste. You may need to consult local legal resources.

aml 40% confidence

Law No. 3/2011 on Prevention and Combat of Money Laundering and Financing of Terrorism (Lei N.º 3/2011 de Prevenção e Combate ao Branqueamento de Capitais e ao Financiamento do Terrorismo): This is the foundational law that establishes the framework for AML/CFT in Timor-Leste. It defines money laundering and terrorist financing offenses, sets out reporting obligations for financial institutions and designated non-financial businesses and professions (DNFBPs), and establishes the Financial Intelligence Unit (FIU).

aml 40% confidence

Identification and Verification:

aml 40% confidence

Enhanced Due Diligence (EDD):

aml 40% confidence

Obligation to Report: VASPs are obligated to report to the Unidade de Informação Financeira (UIF) any transaction, regardless of its value, where they have reasonable grounds to suspect that:

aml 40% confidence

"No Tipping-Off" Rule: VASPs, their directors, officers, and employees are prohibited from disclosing to the customer or any third party that an STR has been or will be submitted to the UIF.

aml 40% confidence

Customer Identification Data: All records obtained through CDD procedures (e.g., copies of identification documents, verification data). These must be kept for at least five (5) years after the business relationship has ended.

aml 40% confidence

Transaction Records: All records relating to transactions (e.g., amounts, currencies, dates, parties involved, account numbers, virtual asset wallet addresses/transaction IDs). These must be kept for at least five (5) years from the date of the transaction.

enforcement 20% confidence

Issuing Warnings and Advisories: The BCTL has previously issued statements cautioning the public about the risks associated with cryptocurrencies, highlighting their volatile nature, lack of regulatory oversight, and potential for use in illicit activities. These are general advisories rather than enforcement actions against specific entities.

enforcement 20% confidence

Developing Regulatory Frameworks: Efforts are likely underway to understand and potentially regulate digital assets, but these processes often take time and resources.

enforcement 20% confidence

Prioritization: Enforcement efforts in smaller, developing economies often prioritize more traditional forms of financial crime due to limited resources and the nascent stage of crypto adoption.

Verdict Attribution

Source:
AI-Generated · Unreviewed
AI synthesized:
2026-07-13 (deepseek-chat)
Last updated:
2026-07-13
Confidence:
low

This verdict was produced by an AI model from the underlying facts. Confirm with counsel before relying on it for material decisions.

Conditional — Crypto ATM/kiosk operators can operate in Timor-Leste without a specific crypto license, but must comply with general AML/CFT laws (Law No. 2/2011 and Law No. 3/2011), register as a local business, and face significant legal ambiguity given the absence of a tailored regulatory framework for cash-to-crypto kiosk models.

Questions this verdict aims to answer

  • What money-transmitter / kiosk-specific license is required?
  • What cash-transaction reporting thresholds apply?
  • What enhanced-KYC obligations attach to cash-in / cash-out?