KYC and AML Requirements for Crypto in Brazil (BACEN & CVM)
Complete guide to KYC and AML compliance for cryptocurrency exchanges and virtual asset service providers in Brazil under BACEN, CVM, and the Marco Legal das Criptomoedas.
Brazil's Crypto Regulatory Framework
Brazil locked in its status as Latin America's largest crypto market after President Lula signed the Marco Legal das Criptomoedas (Law 14,478/2022) in December 2022. The statute created a formal legal regime for virtual asset service providers (VASPs). It introduced licensing duties and named the Banco Central do Brasil (BACEN) as the primary regulator for crypto assets used as payment instruments.
The law took effect in June 2023. Brazil moved from a previously unregulated crypto setting to one with defined compliance duties, KYC and AML among them.
Key Regulatory Bodies
BACEN (Banco Central do Brasil)
BACEN was named the main regulator for virtual asset service providers. It licenses crypto exchanges, sets operational standards, and enforces anti-money laundering rules. Secondary regulations that put the Marco Legal into practice have been under active development at BACEN.
CVM (Comissao de Valores Mobiliarios)
The CVM, Brazil's securities regulator, keeps authority over crypto assets that qualify as securities tokens. A token that represents an investment contract, equity stake, or debt instrument sits under CVM jurisdiction and must meet securities registration and disclosure rules. Which body oversees a given token — BACEN or CVM — turns on that token's nature and function.
COAF (Conselho de Controle de Atividades Financeiras)
COAF is Brazil's financial intelligence unit, the counterpart to the UIF in other Latin American jurisdictions. Every VASP must report suspicious transactions to COAF and keep transaction monitoring systems in working order. COAF reviews financial intelligence and passes relevant material to law enforcement agencies.
KYC Requirements for Crypto Companies in Brazil
Under the Marco Legal and BACEN's implementing regulations, crypto exchanges and VASPs must run full customer identification programs.
Individual Customer Verification
- CPF (Cadastro de Pessoas Fisicas): Brazil's individual taxpayer identification number is mandatory for every customer.
- Government-issued ID: RG (Registro Geral), CNH (driver's license), or passport.
- Proof of address: Utility bill, bank statement, or similar document dated within 90 days.
- Biometric verification: Increasingly required for remote onboarding, especially for higher-value accounts.
- Source of funds: Required for transactions that exceed defined thresholds.
Legal Entity Verification
For corporate customers, VASPs must verify:
- CNPJ (Cadastro Nacional da Pessoa Juridica) registration
- Articles of incorporation and current corporate bylaws
- Identification of all beneficial owners holding 25% or more
- Proof of legal representation and signing authority
Enhanced Due Diligence
Higher-risk customers — PEPs, non-resident individuals, and entities from high-risk jurisdictions — trigger enhanced due diligence. That means extra documentation, senior management approval, and more frequent account reviews.
Joinble's AI-powered identity verification compresses these steps for Brazilian crypto platforms. CPF validation, Brazilian document checks, and biometric matching run in a single automated flow. For the basics, see our guide on what is KYC.
AML Compliance Under Brazilian Law
Brazil's AML regime for crypto rests on the Marco Legal and on the broader Law 9,613/1998 (Anti-Money Laundering Law), as amended. Core duties include:
Transaction Monitoring
VASPs must run automated systems that flag suspicious patterns, among them:
- Structuring (splitting large transactions into smaller ones to stay under thresholds)
- Rapid movement of funds through multiple wallets
- Transactions with sanctioned jurisdictions or wallets
- Activity that does not match the customer's declared profile
Suspicious Activity Reporting
Every suspicious transaction must be reported to COAF through the SISCOAF electronic system. Urgent matters must be filed within 24 hours. VASPs must not tell the customer that a report has been filed (the tipping-off prohibition).
Record Keeping
Customer identification records and transaction data must be kept for at least five years from the date of the transaction or the end of the business relationship, whichever is later.
Travel Rule Compliance
Brazil is rolling out the FATF Travel Rule in stages. VASPs must share originator and beneficiary information for crypto transfers above defined thresholds. Meeting that duty needs technical infrastructure that can send and receive this data securely between institutions.
LGPD and Data Protection Considerations
Brazil's Lei Geral de Protecao de Dados (LGPD) places extra duties on crypto companies that collect KYC data. AML compliance and data protection have to be balanced with care:
- Legal basis for processing: Collecting KYC data is justified under the legal obligation basis, yet data minimization still applies.
- Data retention limits: AML laws require five-year retention. LGPD says data must not be kept longer than necessary. Firms need clear retention policies.
- Customer rights: Data subjects keep rights of access, correction, and information about how their data is processed, including inside compliance workflows.
- Security requirements: LGPD requires technical and organizational measures that protect personal data, including encryption, access controls, and incident response plans.
Joinble's platform is built with privacy by design. KYC collection for Brazilian crypto compliance can satisfy BACEN rules and LGPD duties at the same time.
Exchange Licensing and Operational Requirements
The Marco Legal requires every VASP operating in Brazil to obtain authorization from BACEN. Licensing duties include:
- Minimum capital requirements tied to the scope of services offered
- Demonstrated compliance infrastructure, including a designated compliance officer
- Technology systems able to support KYC, AML, and transaction monitoring
- Cybersecurity frameworks that meet BACEN standards
- Segregation of customer funds from operational funds
- Regular reporting to BACEN on operational metrics and compliance activity
Penalties for Non-Compliance
Operating without a license carries criminal penalties, including imprisonment of four to eight years plus fines. Licensed entities that breach KYC and AML rules face administrative sanctions, among them fines, operational restrictions, and license revocation.
Building a Compliant Crypto Operation in Brazil
Crypto firms that want to operate in Brazil on a compliant basis need a structured plan:
- Determine regulatory classification: Establish whether the tokens sit under BACEN or CVM jurisdiction.
- Apply for licensing: File a full application with BACEN that shows compliance readiness.
- Implement KYC technology: Deploy automated identity verification that supports Brazilian documents and biometric standards. Platforms such as Joinble's AI-powered verification can shorten this step.
- Build AML infrastructure: Put in place transaction monitoring, sanctions screening, and COAF reporting.
- Address LGPD compliance: Confirm that data processing meets LGPD alongside AML duties.
- Establish ongoing monitoring: Keep compliance current through regular reviews, staff training, and system updates.
For a full overview of KYC principles and practice, see our resource on what is KYC.
Frequently Asked Questions
What is the Marco Legal das Criptomoedas?
Law 14,478/2022, known as the Marco Legal das Criptomoedas, is Brazil's main statute regulating virtual asset service providers. It named BACEN as the principal regulator and created licensing, KYC, and AML duties for crypto companies operating in Brazil.
Which regulator oversees crypto in Brazil, BACEN or CVM?
BACEN regulates crypto assets used as payment instruments and oversees exchange licensing. The CVM regulates tokens that qualify as securities. The relevant regulator depends on the nature and function of the specific crypto asset.
What KYC documents do Brazilian crypto exchanges need to collect?
At a minimum, exchanges must collect the customer's CPF, a government-issued ID (RG, CNH, or passport), proof of address, and source of funds for larger transactions. Biometric verification is increasingly required for remote onboarding.
How does LGPD affect crypto KYC compliance in Brazil?
LGPD requires crypto companies to apply data minimization, keep clear retention policies, respect data subject rights, and put strong security measures in place. Collecting KYC data is legally justified under compliance duties, but processing must still follow LGPD principles.
What are the penalties for operating a crypto exchange without a license in Brazil?
Unlicensed operation can bring criminal penalties of four to eight years imprisonment plus fines. Administrative breaches by licensed entities can lead to fines, operational restrictions, and license revocation.
Does Brazil require crypto companies to comply with the FATF Travel Rule?
Brazil is rolling out the Travel Rule in stages. VASPs must share originator and beneficiary information for transfers above specified thresholds. Crypto companies should put technical infrastructure in place to support that duty.
Automate your compliance with AI Agents
Joinble's Agentic Identity platform reduces manual KYC reviews by up to 80%. Book a demo to see it in action.
Book a demoRelated compliance guides
KYC & AML Requirements for Crypto in Bahrain (CBB)
Comprehensive guide to KYC and AML compliance for cryptocurrency and digital asset companies in Bahrain, covering CBB crypto-asset regulations, licensing categories, sandbox framework, and travel rule implementation.
MiCA KYC Requirements for Crypto Exchanges in the EU
Definitive guide to MiCA KYC requirements for crypto exchanges operating in the European Union. Covers CASP authorization, Travel Rule compliance, asset-referenced token obligations, and identity verification standards for digital asset platforms.
KYC and AML Requirements for Crypto in the United States
An expert guide to KYC, AML, and BSA compliance for cryptocurrency businesses operating in the United States under FinCEN, SEC, and CFTC regulatory frameworks.
Related articles
Post-MiCA: What 80% Exit Means for Crypto KYC
After MiCA's July 2026 deadline eliminated 80% of EU crypto exchanges, licensed CASPs still face critical KYC gaps that regulators are closing in on.
ReportState of KYC in Crypto 2026: The Year Identity Became Autonomous
Annual report on the state of identity verification in the crypto sector. Data, trends, and the impact of MiCA, AI Agents, and real-world asset tokenization on KYC.
ComplianceUK FCA Crypto Gateway: KYC Compliance Checklist 2026
The FCA crypto authorisation gateway opens 30 September 2026. Firms have five months to apply. Here is what KYC compliance teams must prepare now.