Crypto-funded debit card in Uruguay
A card program where customer fiat balances are funded from crypto holdings, typically through an off-ramp at point of sale or top-up.
Crypto debit card is conditionally permitted in Uruguay with a local entity, subject to AML obligations and high licensing burden.
Verdict Details
- Permitted
- conditional
- Local entity required
- Yes
- Licensing burden
- High
- Last updated
- 2026-07-13
AML Obligations
- Register with UIAF as a VASP obligated subject under AML/CFT law (Decreto N° 379/020)
- Implement a risk-based AML/CFT program per Ley N° 19.574
- Perform CDD for all cardholders: verify name, DOB, nationality, ID number, address, and contact details
- For legal entity customers: verify legal name, registration number, legal form, address, directors, ownership structure, and UBOs
- Identify beneficial owners and take reasonable measures to verify identity
- Understand purpose and intended nature of the business relationship
- Collect source of funds / source of wealth for high-risk customers or transactions
- Perform ongoing transaction monitoring to detect suspicious activity
- Apply Enhanced Due Diligence (EDD) for PEPs, high-risk jurisdictions, complex transactions, and new technologies
- Report suspicious transactions (SARs) to SEGPRE (Uruguay's FIU) without delay — no minimum reporting threshold
- Maintain customer identification and transaction records for at least 5 years
- Establish internal AML/CFT policies, procedures, and controls
- No tipping-off: prohibited from disclosing SAR submission or investigation to customers
Key Restrictions
- If processing fiat currency (customer fiat balances funded from crypto off-ramp), BCU authorization as a Payment Service Provider (PSP) or Electronic Payment Institution (IPE) is likely required in addition to UIAF registration
- The crypto-to-fiat conversion leg is regulated — exchange between virtual assets and fiat currencies is a defined VASP activity under Decreto N° 379/020
- A partner bank or BIN sponsor arrangement in Uruguay is needed, but no specific local framework for crypto-funded card programs exists — must operate via a BCU-licensed PSP/IPE for the fiat payment component
- Virtual assets are NOT legal tender in Uruguay per BCU communication No. 2021/200
- If the service is purely crypto-to-crypto (no fiat leg), only UIAF registration is required; but a crypto-funded debit card by definition involves fiat, triggering BCU licensing
Key Risks
- Regulatory ambiguity: no specific crypto-debit-card framework exists — operators must piece together BCU PSP/IPE licensing + UIAF VASP registration
- BCU has warned about risks of virtual assets and is still developing a formal VASP regulatory framework (proposal since 2021) — framework may change
- If operator fails to obtain BCU authorization for the fiat payment component, it faces enforcement action for unauthorized financial intermediation
- UIAF enforcement history on crypto firms is not widely publicized — uncertain enforcement intensity
- FATF Mutual Evaluation Report (2019) sets context but is outdated; expectations may have shifted
Evidence
This verdict synthesizes the following facts. Each fact links to its primary source(s).
BCU Stance: The BCU has issued communications clarifying its position. While it acknowledges virtual assets, it has explicitly stated that they are not considered legal tender in Uruguay and virtual asset activities generally do not fall under the traditional financial intermediation framework (e.g., banking law) unless they involve activities that would traditionally require BCU authorization (e.g., taking public deposits, issuing e-money as a payment institution). The BCU monitors the sector and indicates the possibility of future, more specific regulation.
UIAF Role: The UIAF is the key authority for AML/CFT oversight of VASPs. VASPs are required to register with the UIAF and comply with AML/CFT regulations.
Requirement: Registration with the UIAF is mandatory for virtual asset exchanges operating in Uruguay. They are considered "obligated subjects" under AML/CFT law.
BCU Consideration: If an exchange offers services that cross into traditional financial activities (e.g., offering interest-bearing accounts in fiat, acting as a payment institution for fiat, issuing regulated financial instruments), it would likely require specific authorization from the BCU in addition to UIAF registration.
If processing payments involving Fiat Currency (e.g., facilitating fiat deposits/withdrawals, enabling merchants to accept crypto but receive fiat):
Requirement: Likely fall under the VASP definition and require registration with the UIAF for AML/CFT purposes.
Requirement: This might require BCU authorization as a Payment Service Provider (PSP) or Electronic Payment Institution (Institución de Pagos Electrónicos - IPE), in addition to UIAF registration if they also handle virtual assets.
Nature: This is a full financial license from the BCU, which involves more stringent capital, operational, and regulatory compliance requirements. The BCU regulates these entities under its general framework for payment services.
Risk Assessment: Develop and implement a robust, risk-based AML/CFT program.
Customer Due Diligence (CDD):
Suspicious Activity Reporting (SARs): Report suspicious transactions to the UIAF without delay.
Record-Keeping: Maintain records of customer identification, transactions, and AML/CFT analysis for at least five years.
Internal Controls: Establish internal policies, procedures, and controls to prevent money laundering and terrorist financing.
Ley N° 19.574 (Integral Law Against Money Laundering and Terrorism Financing), dated December 20, 2017: This is the cornerstone legislation that established the general AML/CFT regime, identified obligated subjects, and set out the core requirements for prevention, detection, and punishment of money laundering and terrorism financing.
Decreto N° 379/020 (Regulation of Non-Financial Obligated Subjects and Activities Regulated by Law N° 19.574), dated December 23, 2020: This crucial decree explicitly includes "providers of virtual asset services" (proveedores de servicios de activos virtuales) as obligated subjects (sujetos obligados) under the AML/CFT framework. This brought VASPs directly under the regulatory scope, requiring them to comply with the same AML/CFT obligations as traditional financial institutions and other designated non-financial businesses and professions (DNFBPs).
Exchange between virtual assets and fiat currencies.
Identification and Verification:
Beneficial Ownership: Identify and take reasonable measures to verify the identity of the beneficial owner(s) behind any legal entity, trust, or other legal arrangement. This involves understanding the control structure and identifying individuals who ultimately own or control more than a certain percentage (e.g., 25%) of the entity.
Source of Funds and Source of Wealth (SoF/SoW): Especially for high-risk customers or transactions, VASPs must take reasonable measures to establish the source of funds or source of wealth involved.
Ongoing Monitoring: Continuously monitor the business relationship and transactions to ensure they are consistent with the VASP's knowledge of the customer, their business, and risk profile. This includes reviewing transactions for suspicious activity and updating customer information periodically.
Enhanced Due Diligence (EDD): Apply EDD measures for high-risk customers, relationships, or transactions. This includes, but is not limited to:
What to Report: Any transaction, attempted transaction, or operation, regardless of the amount, that the VASP suspects or has reasonable grounds to suspect is related to money laundering, terrorism financing, or underlying criminal activity.
To Whom: Reports must be submitted to the Secretaría Nacional para la Lucha contra el Lavado de Activos y el Financiamiento del Terrorismo (SEGPRE), Uruguay's FIU.
No Tipping-Off: VASPs and their employees are prohibited from disclosing to the customer or third parties that a suspicious transaction report has been or will be submitted, or that an investigation is being conducted.
Customer Identification Data: All documents and information obtained during the CDD process (e.g., copies of identification documents, corporate registration documents, beneficial ownership information).
Transaction Data: Records of all transactions, including amounts, currencies, dates, types of virtual assets, parties involved (originator and beneficiary information), and any other relevant details.
BCU Communication (Comunicación No. 2021/200): https://www.bcu.gub.uy/Comunicados/comunicado200211.pdf
Regulator Name: Banco Central del Uruguay (BCU)
Regulator Name: Unidad de Información y Análisis Financiero (UIAF - Financial Information and Analysis Unit, part of the BCU)
FATF Mutual Evaluation Report for Uruguay (mentions UIAF's role in VAs, though specific enforcement data is limited publicly): https://www.fatf-gafi.org/content/dam/fatf-gafi/mer/MER-Uruguay-2019.pdf (While 2019, it sets the context for ongoing obligations)
Outcome: Established the BCU's initial position on virtual assets, clarified that they are not legal tender, warned about risks, and reiterated that existing AML/CFT obligations apply to entities dealing with VAs. It also announced the start of a regulatory framework development process. This communication serves as a foundational "warning" and "guidance" for the market.
Verdict Attribution
- Source:
- AI-Generated · Unreviewed
- AI synthesized:
- 2026-07-13 (deepseek-chat)
- Last updated:
- 2026-07-13
- Confidence:
- medium
This verdict was produced by an AI model from the underlying facts. Confirm with counsel before relying on it for material decisions.
Conditional — a crypto-funded debit card in Uruguay requires dual licensing: UIAF VASP registration (AML/CFT) for the crypto-to-fiat exchange, plus BCU authorization as a Payment Service Provider (PSP) or Electronic Payment Institution (IPE) for the fiat payment/issuance leg, with full KYC/AML/CDD obligations under Ley N° 19.574 and Decreto N° 379/020.
Questions this verdict aims to answer
- What e-money / payment-institution license is required?
- How is the crypto-to-fiat conversion regulated?
- What KYC and AML obligations apply to cardholders?
- What partner-bank or BIN-sponsor arrangements are required?