Custodial wallet / SaaS in Uruguay
Hosted wallet provider that holds keys on behalf of end users, often white-labeled to businesses (custody as a service).
Custodial SaaS is conditionally permitted in Uruguay with a local entity, subject to AML obligations and medium licensing burden.
Verdict Details
- Permitted
- conditional
- Local entity required
- Yes
- Licensing burden
- Medium
- Last updated
- 2026-07-13
AML Obligations
- UIAF registration as an obligated subject under Decreto N° 379/020 (AML/CFT registration, not a financial license)
- Customer Due Diligence (CDD): KYC for individuals (full name, DOB, nationality, ID number, address); for legal entities (legal name, registration number, legal form, address, directors, ownership/control structure, UBOs)
- Beneficial ownership identification and verification (reasonable measures to identify individuals owning/controlling > a certain percentage)
- Purpose and intended nature of business relationship assessment
- Source of Funds and Source of Wealth (SoF/SoW) measures for high-risk customers/transactions
- Ongoing monitoring of business relationships and transactions for consistency with customer risk profile
- Enhanced Due Diligence (EDD) for PEPs, high-risk jurisdictions, complex/unusual transactions, and transactions involving new technologies
- Suspicious Activity Reporting (SARs) to SEGPRE (Uruguay's FIU) — any suspected transaction regardless of amount, with no-tipping-off prohibition
- Record-keeping for at least 5 years (customer ID data, transaction records, AML analysis and decision records)
- Internal controls: risk-based AML/CFT program, internal policies, procedures, and controls
- If the SaaS provider also handles fiat payment processing, BCU authorization as PSP/IPE is additionally required with higher AML obligations
Key Restrictions
- Custodial wallet / SaaS provider must register with the UIAF as a VASP obligated subject — this is an AML/CFT registration, not a financial license
- Purely virtual asset custody is not currently under BCU licensing, but if the provider also offers regulated financial services or manages client funds in a way that falls under existing financial laws, BCU authorization would also be required
- If processing payments involving fiat currency (e.g., facilitating fiat deposits/withdrawals), BCU authorization as a Payment Service Provider (PSP) or Electronic Payment Institution (IPE) is additionally required
- No specific minimum capital requirement for UIAF registration as a VASP, but significant capital requirements apply if BCU authorization (PSP/IPE) is needed
- White-label clients who are themselves VASPs may need separate UIAF registration depending on their activities — AML obligations may attach at both the SaaS level and the client level
Key Risks
- Regulatory framework for VASPs is still developing — the BCU announced a proposal in 2021 but specific crypto regulation is not yet finalized, creating ambiguity
- The BCU has warned that virtual assets are not legal tender and has signaled future regulation — operators face risk of regulatory change mid-operation
- Enforcement is primarily through existing AML/CFT rules (UIAF monitoring), with limited publicly known crypto-specific enforcement cases, making the enforcement landscape uncertain
- If the SaaS provider is structured to avoid being the direct counterparty to end users, the UIAF may still view the provider as an obligated subject under the 'safekeeping and/or administration of virtual assets' definition
- Reputational and operational risk if the white-label client fails AML compliance — the SaaS provider may face regulatory scrutiny as the custodian of assets
Evidence
This verdict synthesizes the following facts. Each fact links to its primary source(s).
BCU Stance: The BCU has issued communications clarifying its position. While it acknowledges virtual assets, it has explicitly stated that they are not considered legal tender in Uruguay and virtual asset activities generally do not fall under the traditional financial intermediation framework (e.g., banking law) unless they involve activities that would traditionally require BCU authorization (e.g., taking public deposits, issuing e-money as a payment institution). The BCU monitors the sector and indicates the possibility of future, more specific regulation.
UIAF Role: The UIAF is the key authority for AML/CFT oversight of VASPs. VASPs are required to register with the UIAF and comply with AML/CFT regulations.
Requirement: Registration with the UIAF is mandatory for virtual asset exchanges operating in Uruguay. They are considered "obligated subjects" under AML/CFT law.
Nature: This is an AML/CFT registration, not a financial license from the BCU to operate an exchange per se.
BCU Consideration: If an exchange offers services that cross into traditional financial activities (e.g., offering interest-bearing accounts in fiat, acting as a payment institution for fiat, issuing regulated financial instruments), it would likely require specific authorization from the BCU in addition to UIAF registration.
Nature: Similar to exchanges, this is an AML/CFT registration.
BCU Consideration: Purely virtual asset custody is not currently under BCU licensing. However, if the custody provider also offers regulated financial services or manages client funds in a way that falls under existing financial laws, BCU authorization would be required.
If processing payments exclusively in Virtual Assets (e.g., crypto-to-crypto payments, or facilitating payments where the merchant receives crypto directly):
Requirement: Likely fall under the VASP definition and require registration with the UIAF for AML/CFT purposes.
If processing payments involving Fiat Currency (e.g., facilitating fiat deposits/withdrawals, enabling merchants to accept crypto but receive fiat):
Requirement: This might require BCU authorization as a Payment Service Provider (PSP) or Electronic Payment Institution (Institución de Pagos Electrónicos - IPE), in addition to UIAF registration if they also handle virtual assets.
For UIAF Registration (VASPs): There is no specific minimum capital requirement directly tied to UIAF AML/CFT registration for VASPs.
For BCU Authorization (e.g., IPEs/PSPs): If an entity's activities fall under the BCU's existing regulatory framework for financial institutions (like Payment Service Providers or Electronic Payment Institutions), then significant minimum capital requirements apply. These are determined by BCU regulations for those specific activities and can be substantial (e.g., tens of thousands to hundreds of thousands of USD equivalent, depending on the scope of activities).
Risk Assessment: Develop and implement a robust, risk-based AML/CFT program.
Customer Due Diligence (CDD):
Identify and verify the identity of customers (KYC - Know Your Customer).
Identify beneficial owners.
Understand the purpose and nature of the business relationship.
Ongoing monitoring of transactions and relationships.
Enhanced Due Diligence (EDD) for high-risk customers or transactions.
Suspicious Activity Reporting (SARs): Report suspicious transactions to the UIAF without delay.
Record-Keeping: Maintain records of customer identification, transactions, and AML/CFT analysis for at least five years.
Internal Controls: Establish internal policies, procedures, and controls to prevent money laundering and terrorist financing.
Ley N° 19.574 (Integral Law Against Money Laundering and Terrorism Financing), dated December 20, 2017: This is the cornerstone legislation that established the general AML/CFT regime, identified obligated subjects, and set out the core requirements for prevention, detection, and punishment of money laundering and terrorism financing.
Decreto N° 379/020 (Regulation of Non-Financial Obligated Subjects and Activities Regulated by Law N° 19.574), dated December 23, 2020: This crucial decree explicitly includes "providers of virtual asset services" (proveedores de servicios de activos virtuales) as obligated subjects (sujetos obligados) under the AML/CFT framework. This brought VASPs directly under the regulatory scope, requiring them to comply with the same AML/CFT obligations as traditional financial institutions and other designated non-financial businesses and professions (DNFBPs).
Exchange between virtual assets and fiat currencies.
Exchange between one or more forms of virtual assets.
Transfer of virtual assets.
Safekeeping and/or administration of virtual assets or instruments enabling control over virtual assets.
Participation in and provision of financial services related to an issuer’s offer and/or sale of a virtual asset.
Identification and Verification:
For Individuals: Obtain and verify the client's full name, date of birth, nationality, identification number (e.g., national ID, passport), address, and other relevant contact details.
For Legal Entities: Obtain and verify the legal name, registration number, legal form, address of the registered office, names of directors and senior management, and the ownership and control structure (including ultimate beneficial owners - UBOs).
Beneficial Ownership: Identify and take reasonable measures to verify the identity of the beneficial owner(s) behind any legal entity, trust, or other legal arrangement. This involves understanding the control structure and identifying individuals who ultimately own or control more than a certain percentage (e.g., 25%) of the entity.
Purpose and Intended Nature of the Business Relationship: Understand the purpose and intended nature of the business relationship or occasional transaction.
Source of Funds and Source of Wealth (SoF/SoW): Especially for high-risk customers or transactions, VASPs must take reasonable measures to establish the source of funds or source of wealth involved.
Ongoing Monitoring: Continuously monitor the business relationship and transactions to ensure they are consistent with the VASP's knowledge of the customer, their business, and risk profile. This includes reviewing transactions for suspicious activity and updating customer information periodically.
Enhanced Due Diligence (EDD): Apply EDD measures for high-risk customers, relationships, or transactions. This includes, but is not limited to:
Politically Exposed Persons (PEPs).
Clients from high-risk jurisdictions.
Complex or unusual transactions or structures.
Transactions involving new technologies or products where the ML/TF risks are higher.
What to Report: Any transaction, attempted transaction, or operation, regardless of the amount, that the VASP suspects or has reasonable grounds to suspect is related to money laundering, terrorism financing, or underlying criminal activity.
To Whom: Reports must be submitted to the Secretaría Nacional para la Lucha contra el Lavado de Activos y el Financiamiento del Terrorismo (SEGPRE), Uruguay's FIU.
No Tipping-Off: VASPs and their employees are prohibited from disclosing to the customer or third parties that a suspicious transaction report has been or will be submitted, or that an investigation is being conducted.
Customer Identification Data: All documents and information obtained during the CDD process (e.g., copies of identification documents, corporate registration documents, beneficial ownership information).
Transaction Data: Records of all transactions, including amounts, currencies, dates, types of virtual assets, parties involved (originator and beneficiary information), and any other relevant details.
Analysis and Decision-Making: Records of the analysis undertaken for suspicious activity and the decisions made regarding reporting or non-reporting.
Issuing warnings and general guidance: Advising the public on risks and clarifying that virtual assets are not legal tender.
Developing a regulatory framework: The BCU presented a preliminary proposal for regulating Virtual Asset Service Providers (VASPs) in 2021, and work is ongoing.
Applying existing AML/CFT rules: Emphasizing that entities dealing with virtual assets are subject to existing anti-money laundering and counter-terrorist financing (AML/CFT) regulations, even without specific crypto legislation.
Regulator Name: Banco Central del Uruguay (BCU)
Entity Targeted: All financial institutions, virtual asset service providers (VASPs), and the general public operating in the virtual asset space. Violation Type: Primarily aimed at preventing non-compliance with existing AML/CFT regulations and consumer protection issues arising from unregulated activities. Penalty Amount: Not applicable for a general communication.
Date: Issued November 29, 2021 (and subsequent communications).
Outcome: Established the BCU's initial position on virtual assets, clarified that they are not legal tender, warned about risks, and reiterated that existing AML/CFT obligations apply to entities dealing with VAs. It also announced the start of a regulatory framework development process. This communication serves as a foundational "warning" and "guidance" for the market.
Significance: This is the most significant official statement from the BCU regarding virtual assets, informing the market of its stance and future direction. Any future enforcement would directly reference these principles.
Regulator Name: Unidad de Información y Análisis Financiero (UIAF - Financial Information and Analysis Unit, part of the BCU)
Entity Targeted: Financial institutions, designated non-financial businesses and professions (DNFBPs), and potentially VASPs (under existing AML definitions). Violation Type: Non-compliance with anti-money laundering and counter-terrorist financing (AML/CFT) regulations. Penalty Amount: Varies depending on the severity of the non-compliance. Specific amounts for crypto-related cases are not publicly detailed for Uruguay.
Date: Ongoing (UIAF is continuously monitoring and enforcing AML/CFT).
Outcome: The UIAF's mandate includes monitoring and investigating suspicious transactions, including those involving virtual assets. While specific cases against crypto firms aren't widely publicized, the UIAF would be the body to investigate and refer for prosecution any AML/CFT violations in the crypto space. They issue guidelines and requirements that apply.
Significance: This represents the ongoing, fundamental enforcement mechanism for financial crimes, which includes the use of cryptocurrencies.
FATF Mutual Evaluation Report for Uruguay (mentions UIAF's role in VAs, though specific enforcement data is limited publicly): https://www.fatf-gafi.org/content/dam/fatf-gafi/mer/MER-Uruguay-2019.pdf (While 2019, it sets the context for ongoing obligations)
Verdict Attribution
- Source:
- AI-Generated · Unreviewed
- AI synthesized:
- 2026-07-13 (deepseek-chat)
- Last updated:
- 2026-07-13
- Confidence:
- medium
This verdict was produced by an AI model from the underlying facts. Confirm with counsel before relying on it for material decisions.
Conditional — a custodial wallet / SaaS provider may operate in Uruguay after registering with the UIAF as a VASP obligated subject under AML/CFT law (Decreto N° 379/020), with no BCU financial license required for pure crypto custody, but BCU authorization (PSP/IPE) is additionally needed if fiat payment processing is involved.
Questions this verdict aims to answer
- What custody license / qualified-custodian status applies?
- What segregation, insurance, and proof-of-reserves rules apply?
- What AML obligations attach to the SaaS vs the white-label client?