Centralized exchange in Uruguay
Order-book exchange that takes custody of user assets and matches trades between users.
CEX is conditionally permitted in Uruguay with a local entity, subject to AML obligations and medium licensing burden.
Verdict Details
- Permitted
- conditional
- Local entity required
- Yes
- Licensing burden
- Medium
- Last updated
- 2026-07-13
AML Obligations
- Register with the UIAF (Unidad de Información y Análisis Financiero) as an obligated subject under AML/CFT law (Ley N° 19.574, Decreto N° 379/020).
- Conduct Customer Due Diligence (CDD): identify and verify customer identity (KYC), beneficial owners, purpose and nature of business relationship.
- Apply Enhanced Due Diligence (EDD) for high-risk customers (PEPs, clients from high-risk jurisdictions, complex/unusual transactions, new technologies/products).
- Implement ongoing transaction monitoring and periodic customer information updates.
- Report suspicious transactions (SARs) to SEGPRE (the FIU) without delay, regardless of amount — no minimum threshold.
- Maintain records of customer identification, transactions, and AML/CFT analysis for at least five years.
- Establish internal policies, procedures, and controls to prevent ML/TF.
- Comply with 'no tipping-off' prohibition regarding SAR filings.
- If the exchange handles fiat deposits/withdrawals or offers payment services in fiat, it likely also needs BCU authorization as a Payment Service Provider (PSP) or Electronic Payment Institution (IPE), with higher capital requirements.
Key Restrictions
- A purely virtual-asset exchange (no fiat rails) requires only UIAF AML/CFT registration — no BCU financial license for the core exchange activity.
- If the exchange offers fiat deposits/withdrawals or interest-bearing fiat accounts, it must obtain BCU authorization as a Payment Service Provider / Electronic Payment Institution (IPE).
- No specific minimum capital requirement for UIAF registration; capital requirements apply only if BCU authorization (IPE/PSP) is triggered.
- Virtual assets are not legal tender in Uruguay — the BCU has clarified they do not fall under the traditional financial intermediation framework.
- If the exchange issues regulated financial instruments or acts as a payment institution for fiat, BCU authorization becomes mandatory in addition to UIAF registration.
Key Risks
- Regulatory ambiguity: the specific VASP regulatory framework is still under development (BCU proposed regulations in 2021, work is ongoing) — obligations could change.
- If fiat on/off-ramps are offered without proper BCU authorization, the operator faces enforcement risk for unlicensed financial activity.
- The UIAF can investigate and refer AML/CFT violations for prosecution; penalties vary by severity and could be significant.
- Travel rule obligations (FATF Recommendation 16) are not explicitly detailed in the provided facts — operators should verify specific virtual asset transfer requirements with the UIAF.
- No publicly known crypto-specific enforcement precedents exist, but the BCU's 2021 communication establishes the baseline for future enforcement action.
Evidence
This verdict synthesizes the following facts. Each fact links to its primary source(s).
BCU Stance: The BCU has issued communications clarifying its position. While it acknowledges virtual assets, it has explicitly stated that they are not considered legal tender in Uruguay and virtual asset activities generally do not fall under the traditional financial intermediation framework (e.g., banking law) unless they involve activities that would traditionally require BCU authorization (e.g., taking public deposits, issuing e-money as a payment institution). The BCU monitors the sector and indicates the possibility of future, more specific regulation.
UIAF Role: The UIAF is the key authority for AML/CFT oversight of VASPs. VASPs are required to register with the UIAF and comply with AML/CFT regulations.
Requirement: Registration with the UIAF is mandatory for virtual asset exchanges operating in Uruguay. They are considered "obligated subjects" under AML/CFT law.
Nature: This is an AML/CFT registration, not a financial license from the BCU to operate an exchange per se.
BCU Consideration: If an exchange offers services that cross into traditional financial activities (e.g., offering interest-bearing accounts in fiat, acting as a payment institution for fiat, issuing regulated financial instruments), it would likely require specific authorization from the BCU in addition to UIAF registration.
For UIAF Registration (VASPs): There is no specific minimum capital requirement directly tied to UIAF AML/CFT registration for VASPs.
For BCU Authorization (e.g., IPEs/PSPs): If an entity's activities fall under the BCU's existing regulatory framework for financial institutions (like Payment Service Providers or Electronic Payment Institutions), then significant minimum capital requirements apply. These are determined by BCU regulations for those specific activities and can be substantial (e.g., tens of thousands to hundreds of thousands of USD equivalent, depending on the scope of activities).
Risk Assessment: Develop and implement a robust, risk-based AML/CFT program.
Customer Due Diligence (CDD):
Identify and verify the identity of customers (KYC - Know Your Customer).
Identify beneficial owners.
Understand the purpose and nature of the business relationship.
Ongoing monitoring of transactions and relationships.
Enhanced Due Diligence (EDD) for high-risk customers or transactions.
Suspicious Activity Reporting (SARs): Report suspicious transactions to the UIAF without delay.
Record-Keeping: Maintain records of customer identification, transactions, and AML/CFT analysis for at least five years.
Internal Controls: Establish internal policies, procedures, and controls to prevent money laundering and terrorist financing.
Ley N° 19.574 (Integral Law Against Money Laundering and Terrorism Financing), dated December 20, 2017: This is the cornerstone legislation that established the general AML/CFT regime, identified obligated subjects, and set out the core requirements for prevention, detection, and punishment of money laundering and terrorism financing.
Decreto N° 379/020 (Regulation of Non-Financial Obligated Subjects and Activities Regulated by Law N° 19.574), dated December 23, 2020: This crucial decree explicitly includes "providers of virtual asset services" (proveedores de servicios de activos virtuales) as obligated subjects (sujetos obligados) under the AML/CFT framework. This brought VASPs directly under the regulatory scope, requiring them to comply with the same AML/CFT obligations as traditional financial institutions and other designated non-financial businesses and professions (DNFBPs).
Exchange between virtual assets and fiat currencies.
Exchange between one or more forms of virtual assets.
Transfer of virtual assets.
Safekeeping and/or administration of virtual assets or instruments enabling control over virtual assets.
Identification and Verification:
Beneficial Ownership: Identify and take reasonable measures to verify the identity of the beneficial owner(s) behind any legal entity, trust, or other legal arrangement. This involves understanding the control structure and identifying individuals who ultimately own or control more than a certain percentage (e.g., 25%) of the entity.
Enhanced Due Diligence (EDD): Apply EDD measures for high-risk customers, relationships, or transactions. This includes, but is not limited to:
Politically Exposed Persons (PEPs).
Clients from high-risk jurisdictions.
What to Report: Any transaction, attempted transaction, or operation, regardless of the amount, that the VASP suspects or has reasonable grounds to suspect is related to money laundering, terrorism financing, or underlying criminal activity.
No Tipping-Off: VASPs and their employees are prohibited from disclosing to the customer or third parties that a suspicious transaction report has been or will be submitted, or that an investigation is being conducted.
Customer Identification Data: All documents and information obtained during the CDD process (e.g., copies of identification documents, corporate registration documents, beneficial ownership information).
Transaction Data: Records of all transactions, including amounts, currencies, dates, types of virtual assets, parties involved (originator and beneficiary information), and any other relevant details.
Analysis and Decision-Making: Records of the analysis undertaken for suspicious activity and the decisions made regarding reporting or non-reporting.
Issuing warnings and general guidance: Advising the public on risks and clarifying that virtual assets are not legal tender.
Developing a regulatory framework: The BCU presented a preliminary proposal for regulating Virtual Asset Service Providers (VASPs) in 2021, and work is ongoing.
Applying existing AML/CFT rules: Emphasizing that entities dealing with virtual assets are subject to existing anti-money laundering and counter-terrorist financing (AML/CFT) regulations, even without specific crypto legislation.
BCU Communication (Comunicación No. 2021/200): https://www.bcu.gub.uy/Comunicados/comunicado200211.pdf
Verdict Attribution
- Source:
- AI-Generated · Unreviewed
- AI synthesized:
- 2026-07-13 (deepseek-chat)
- Last updated:
- 2026-07-13
- Confidence:
- medium
This verdict was produced by an AI model from the underlying facts. Confirm with counsel before relying on it for material decisions.
Conditional — a centralized exchange can operate in Uruguay with mandatory UIAF AML/CFT registration (no BCU financial license for pure crypto activities), but must seek additional BCU authorization as a Payment Service Provider if it also handles fiat on/off-ramps or offers regulated financial services.
Questions this verdict aims to answer
- What exchange / VASP license applies?
- What custody segregation rules apply to user assets?
- What market-conduct and listing rules apply?
- What travel-rule obligations apply on withdrawals?