← Regulations / Uruguay / Operating Models / Custodial SaaS

Custodial wallet / SaaS in Uruguay

Hosted wallet provider that holds keys on behalf of end users, often white-labeled to businesses (custody as a service).

Conditional AI-Generated · Unreviewed

Custodial SaaS is conditionally permitted in Uruguay with a local entity, subject to AML obligations and medium licensing burden.

Verdict Details

Permitted
conditional
Local entity required
Yes
Licensing burden
Medium
Last updated
2026-07-13

AML Obligations

  • UIAF registration as an obligated subject under Decreto N° 379/020 (AML/CFT registration, not a financial license)
  • Customer Due Diligence (CDD): KYC for individuals (full name, DOB, nationality, ID number, address); for legal entities (legal name, registration number, legal form, address, directors, ownership/control structure, UBOs)
  • Beneficial ownership identification and verification (reasonable measures to identify individuals owning/controlling > a certain percentage)
  • Purpose and intended nature of business relationship assessment
  • Source of Funds and Source of Wealth (SoF/SoW) measures for high-risk customers/transactions
  • Ongoing monitoring of business relationships and transactions for consistency with customer risk profile
  • Enhanced Due Diligence (EDD) for PEPs, high-risk jurisdictions, complex/unusual transactions, and transactions involving new technologies
  • Suspicious Activity Reporting (SARs) to SEGPRE (Uruguay's FIU) — any suspected transaction regardless of amount, with no-tipping-off prohibition
  • Record-keeping for at least 5 years (customer ID data, transaction records, AML analysis and decision records)
  • Internal controls: risk-based AML/CFT program, internal policies, procedures, and controls
  • If the SaaS provider also handles fiat payment processing, BCU authorization as PSP/IPE is additionally required with higher AML obligations

Key Restrictions

  • Custodial wallet / SaaS provider must register with the UIAF as a VASP obligated subject — this is an AML/CFT registration, not a financial license
  • Purely virtual asset custody is not currently under BCU licensing, but if the provider also offers regulated financial services or manages client funds in a way that falls under existing financial laws, BCU authorization would also be required
  • If processing payments involving fiat currency (e.g., facilitating fiat deposits/withdrawals), BCU authorization as a Payment Service Provider (PSP) or Electronic Payment Institution (IPE) is additionally required
  • No specific minimum capital requirement for UIAF registration as a VASP, but significant capital requirements apply if BCU authorization (PSP/IPE) is needed
  • White-label clients who are themselves VASPs may need separate UIAF registration depending on their activities — AML obligations may attach at both the SaaS level and the client level

Key Risks

  • Regulatory framework for VASPs is still developing — the BCU announced a proposal in 2021 but specific crypto regulation is not yet finalized, creating ambiguity
  • The BCU has warned that virtual assets are not legal tender and has signaled future regulation — operators face risk of regulatory change mid-operation
  • Enforcement is primarily through existing AML/CFT rules (UIAF monitoring), with limited publicly known crypto-specific enforcement cases, making the enforcement landscape uncertain
  • If the SaaS provider is structured to avoid being the direct counterparty to end users, the UIAF may still view the provider as an obligated subject under the 'safekeeping and/or administration of virtual assets' definition
  • Reputational and operational risk if the white-label client fails AML compliance — the SaaS provider may face regulatory scrutiny as the custodian of assets

Evidence

This verdict synthesizes the following facts. Each fact links to its primary source(s).

licensing 60% confidence

BCU Stance: The BCU has issued communications clarifying its position. While it acknowledges virtual assets, it has explicitly stated that they are not considered legal tender in Uruguay and virtual asset activities generally do not fall under the traditional financial intermediation framework (e.g., banking law) unless they involve activities that would traditionally require BCU authorization (e.g., taking public deposits, issuing e-money as a payment institution). The BCU monitors the sector and indicates the possibility of future, more specific regulation.

licensing 60% confidence

UIAF Role: The UIAF is the key authority for AML/CFT oversight of VASPs. VASPs are required to register with the UIAF and comply with AML/CFT regulations.

licensing 60% confidence

Requirement: Registration with the UIAF is mandatory for virtual asset exchanges operating in Uruguay. They are considered "obligated subjects" under AML/CFT law.

licensing 60% confidence

Nature: This is an AML/CFT registration, not a financial license from the BCU to operate an exchange per se.

licensing 60% confidence

BCU Consideration: If an exchange offers services that cross into traditional financial activities (e.g., offering interest-bearing accounts in fiat, acting as a payment institution for fiat, issuing regulated financial instruments), it would likely require specific authorization from the BCU in addition to UIAF registration.

licensing 100% confidence

Nature: Similar to exchanges, this is an AML/CFT registration.

licensing 100% confidence

BCU Consideration: Purely virtual asset custody is not currently under BCU licensing. However, if the custody provider also offers regulated financial services or manages client funds in a way that falls under existing financial laws, BCU authorization would be required.

licensing 60% confidence

If processing payments exclusively in Virtual Assets (e.g., crypto-to-crypto payments, or facilitating payments where the merchant receives crypto directly):

licensing 100% confidence

Requirement: Likely fall under the VASP definition and require registration with the UIAF for AML/CFT purposes.

licensing 60% confidence

If processing payments involving Fiat Currency (e.g., facilitating fiat deposits/withdrawals, enabling merchants to accept crypto but receive fiat):

licensing 100% confidence

Requirement: This might require BCU authorization as a Payment Service Provider (PSP) or Electronic Payment Institution (Institución de Pagos Electrónicos - IPE), in addition to UIAF registration if they also handle virtual assets.

licensing 100% confidence

For UIAF Registration (VASPs): There is no specific minimum capital requirement directly tied to UIAF AML/CFT registration for VASPs.

licensing 100% confidence

For BCU Authorization (e.g., IPEs/PSPs): If an entity's activities fall under the BCU's existing regulatory framework for financial institutions (like Payment Service Providers or Electronic Payment Institutions), then significant minimum capital requirements apply. These are determined by BCU regulations for those specific activities and can be substantial (e.g., tens of thousands to hundreds of thousands of USD equivalent, depending on the scope of activities).

licensing 60% confidence

Risk Assessment: Develop and implement a robust, risk-based AML/CFT program.

licensing 60% confidence

Identify and verify the identity of customers (KYC - Know Your Customer).

licensing 60% confidence

Understand the purpose and nature of the business relationship.

licensing 60% confidence

Ongoing monitoring of transactions and relationships.

licensing 60% confidence

Enhanced Due Diligence (EDD) for high-risk customers or transactions.

licensing 60% confidence

Suspicious Activity Reporting (SARs): Report suspicious transactions to the UIAF without delay.

licensing 60% confidence

Record-Keeping: Maintain records of customer identification, transactions, and AML/CFT analysis for at least five years.

licensing 60% confidence

Internal Controls: Establish internal policies, procedures, and controls to prevent money laundering and terrorist financing.

aml 60% confidence

Ley N° 19.574 (Integral Law Against Money Laundering and Terrorism Financing), dated December 20, 2017: This is the cornerstone legislation that established the general AML/CFT regime, identified obligated subjects, and set out the core requirements for prevention, detection, and punishment of money laundering and terrorism financing.

aml 60% confidence

Decreto N° 379/020 (Regulation of Non-Financial Obligated Subjects and Activities Regulated by Law N° 19.574), dated December 23, 2020: This crucial decree explicitly includes "providers of virtual asset services" (proveedores de servicios de activos virtuales) as obligated subjects (sujetos obligados) under the AML/CFT framework. This brought VASPs directly under the regulatory scope, requiring them to comply with the same AML/CFT obligations as traditional financial institutions and other designated non-financial businesses and professions (DNFBPs).

aml 60% confidence

Safekeeping and/or administration of virtual assets or instruments enabling control over virtual assets.

aml 60% confidence

Participation in and provision of financial services related to an issuer’s offer and/or sale of a virtual asset.

aml 60% confidence

For Individuals: Obtain and verify the client's full name, date of birth, nationality, identification number (e.g., national ID, passport), address, and other relevant contact details.

aml 60% confidence

For Legal Entities: Obtain and verify the legal name, registration number, legal form, address of the registered office, names of directors and senior management, and the ownership and control structure (including ultimate beneficial owners - UBOs).

aml 60% confidence

Beneficial Ownership: Identify and take reasonable measures to verify the identity of the beneficial owner(s) behind any legal entity, trust, or other legal arrangement. This involves understanding the control structure and identifying individuals who ultimately own or control more than a certain percentage (e.g., 25%) of the entity.

aml 60% confidence

Purpose and Intended Nature of the Business Relationship: Understand the purpose and intended nature of the business relationship or occasional transaction.

aml 60% confidence

Source of Funds and Source of Wealth (SoF/SoW): Especially for high-risk customers or transactions, VASPs must take reasonable measures to establish the source of funds or source of wealth involved.

aml 60% confidence

Ongoing Monitoring: Continuously monitor the business relationship and transactions to ensure they are consistent with the VASP's knowledge of the customer, their business, and risk profile. This includes reviewing transactions for suspicious activity and updating customer information periodically.

aml 60% confidence

Enhanced Due Diligence (EDD): Apply EDD measures for high-risk customers, relationships, or transactions. This includes, but is not limited to:

aml 60% confidence

Transactions involving new technologies or products where the ML/TF risks are higher.

aml 60% confidence

What to Report: Any transaction, attempted transaction, or operation, regardless of the amount, that the VASP suspects or has reasonable grounds to suspect is related to money laundering, terrorism financing, or underlying criminal activity.

aml 60% confidence

To Whom: Reports must be submitted to the Secretaría Nacional para la Lucha contra el Lavado de Activos y el Financiamiento del Terrorismo (SEGPRE), Uruguay's FIU.

aml 60% confidence

No Tipping-Off: VASPs and their employees are prohibited from disclosing to the customer or third parties that a suspicious transaction report has been or will be submitted, or that an investigation is being conducted.

aml 60% confidence

Customer Identification Data: All documents and information obtained during the CDD process (e.g., copies of identification documents, corporate registration documents, beneficial ownership information).

aml 60% confidence

Transaction Data: Records of all transactions, including amounts, currencies, dates, types of virtual assets, parties involved (originator and beneficiary information), and any other relevant details.

aml 60% confidence

Analysis and Decision-Making: Records of the analysis undertaken for suspicious activity and the decisions made regarding reporting or non-reporting.

enforcement 60% confidence

Issuing warnings and general guidance: Advising the public on risks and clarifying that virtual assets are not legal tender.

enforcement 60% confidence

Developing a regulatory framework: The BCU presented a preliminary proposal for regulating Virtual Asset Service Providers (VASPs) in 2021, and work is ongoing.

enforcement 60% confidence

Applying existing AML/CFT rules: Emphasizing that entities dealing with virtual assets are subject to existing anti-money laundering and counter-terrorist financing (AML/CFT) regulations, even without specific crypto legislation.

enforcement 60% confidence

Entity Targeted: All financial institutions, virtual asset service providers (VASPs), and the general public operating in the virtual asset space. Violation Type: Primarily aimed at preventing non-compliance with existing AML/CFT regulations and consumer protection issues arising from unregulated activities. Penalty Amount: Not applicable for a general communication.

enforcement 60% confidence

Date: Issued November 29, 2021 (and subsequent communications).

enforcement 60% confidence

Outcome: Established the BCU's initial position on virtual assets, clarified that they are not legal tender, warned about risks, and reiterated that existing AML/CFT obligations apply to entities dealing with VAs. It also announced the start of a regulatory framework development process. This communication serves as a foundational "warning" and "guidance" for the market.

enforcement 60% confidence

Significance: This is the most significant official statement from the BCU regarding virtual assets, informing the market of its stance and future direction. Any future enforcement would directly reference these principles.

enforcement 60% confidence

Regulator Name: Unidad de Información y Análisis Financiero (UIAF - Financial Information and Analysis Unit, part of the BCU)

enforcement 60% confidence

Entity Targeted: Financial institutions, designated non-financial businesses and professions (DNFBPs), and potentially VASPs (under existing AML definitions). Violation Type: Non-compliance with anti-money laundering and counter-terrorist financing (AML/CFT) regulations. Penalty Amount: Varies depending on the severity of the non-compliance. Specific amounts for crypto-related cases are not publicly detailed for Uruguay.

enforcement 60% confidence

Date: Ongoing (UIAF is continuously monitoring and enforcing AML/CFT).

enforcement 60% confidence

Outcome: The UIAF's mandate includes monitoring and investigating suspicious transactions, including those involving virtual assets. While specific cases against crypto firms aren't widely publicized, the UIAF would be the body to investigate and refer for prosecution any AML/CFT violations in the crypto space. They issue guidelines and requirements that apply.

enforcement 60% confidence

Significance: This represents the ongoing, fundamental enforcement mechanism for financial crimes, which includes the use of cryptocurrencies.

enforcement 60% confidence

FATF Mutual Evaluation Report for Uruguay (mentions UIAF's role in VAs, though specific enforcement data is limited publicly): https://www.fatf-gafi.org/content/dam/fatf-gafi/mer/MER-Uruguay-2019.pdf (While 2019, it sets the context for ongoing obligations)

Verdict Attribution

Source:
AI-Generated · Unreviewed
AI synthesized:
2026-07-13 (deepseek-chat)
Last updated:
2026-07-13
Confidence:
medium

This verdict was produced by an AI model from the underlying facts. Confirm with counsel before relying on it for material decisions.

Conditional — a custodial wallet / SaaS provider may operate in Uruguay after registering with the UIAF as a VASP obligated subject under AML/CFT law (Decreto N° 379/020), with no BCU financial license required for pure crypto custody, but BCU authorization (PSP/IPE) is additionally needed if fiat payment processing is involved.

Questions this verdict aims to answer

  • What custody license / qualified-custodian status applies?
  • What segregation, insurance, and proof-of-reserves rules apply?
  • What AML obligations attach to the SaaS vs the white-label client?