Uruguay -- AML/CFT Compliance Regulatory Overview
Methodology
AI-generated synthesis from web search results.
Limitations
- AI-generated content -- not reviewed by human expert
- Source URLs not independently verified
Research Status
This article is based on verified primary sources but does not yet cover all required dimensions. Research is ongoing as of 2026-08-18. Known gaps:
- Licensing
- Tax
RESEARCH: Uruguay AML
Executive Summary
Crypto activities in Uruguay are not explicitly legalized or prohibited, but the country's regulatory framework primarily targets traditional financial services, extending to emerging digital assets through the lens of existing Anti-Money Laundering (AML) and Know-Your-Customer (KYC) obligations. The Anti-Money Laundering Secretariat (AMLS), under Law 19,355 (December 2015), oversees compliance for financial institutions and designated non-financial businesses and professions (DNFBPs), including those potentially involved in crypto transactions. No specific licenses for crypto service providers have been issued, nor is there clear guidance on crypto tax treatment. Practically, entities offering crypto-related services must comply with existing AML/KYC rules applicable to banks, exchanges, and fintechs. The regulatory landscape remains evolving, with gaps that could expose participants to compliance risks.
Regulatory Framework
- Regulatory Bodies:
- Anti-Money Laundering Secretariat (AMLS) – responsible for AML/CFT supervision.
- Financial Intelligence Unit (UIAF) – within the Central Bank of Uruguay, handles financial intelligence and AML reporting.
- Central Bank of Uruguay – issues licensing and supervises financial institutions.
- Primary Legislation:
- Law 19,355 (December 2015) – enhances supervisory and enforcement豆绿tegrated strategy against terrorism, submitted to Parliament? This seems to be a misstep; need to confirm if it's relevant to crypto or just terrorism.
- International Membership: Uruguay is a member of GAFILAT (Financial Action Task Force of Latin America), with its mutual evaluation available at GAFILAT Evaluation.
- Status: AML/CFT framework is FATF-style but not specifically crypto-focused.
Licensing Requirements
- Who Needs a License: Financial institutions and DNFBPs, including potential crypto exchanges or wallets, must be licensed by the Central Bank of Uruguay Sammy and must comply with the AMLS.
- Capital Requirements: Not specified for crypto-specific licenses; existing capital requirements for banks are not provided in the sources.
- Application Process: Background investigations of principals are required for offshore banks; no specific crypto license process is outlined.
- Timeline & Structural Requirements: N/A for crypto; general processes involve compliance with the 2015 law and staffing expansion to supervise 20,000 entities.
- Entities Licensed: No specific mention of crypto licensees; only generic financial entities are mentioned.
AML/KYC Requirements
- CDD & EDD: Required for all obligated entities, including those in the crypto space, per the AMLS.
- SRT Reporting: STRs are required; 290 reported in Jan–Oct 2015.
- Record Retention: Not detailed in sources; typical for financial sectors.
- Beneficial Ownership & PEP Screening: Required for all covered entities, including potential crypto service providers.
Enforcement Actions
- Penalties/Fines: Specific crypto penalties not mentioned; general AML enforcement includes fines and asset freezes.
- Criminal Cases: No specific crypto-related enforcement cases cited; general AML prosecutions/convictions noted (e.g., 51 prosecutions, 7 convictions in Jan–Jul 2015).
Tax Treatment
- Status: No specific tax guidance for virtual assets is issued in the provided sources. The 2014 financial inclusion law mandates electronic payments but does not address crypto gains or VAT on crypto.
Key Gaps & Risks
- Missing Crypto-Specific Rules: No dedicated law or regulation for digital currencies; existing AML/KYC obligations are applied generically.
- Proliferation of Criminal Organizations: Risk due to porous borders and presence of Colombian, Mexican, and Russian criminal groups.
- Dollarized Economy: High reliance on USD may channel illicit funds through formal and informal channels.
- Licensing Gaps: No clear licensing path for crypto exchanges or wallet providers, leaving a regulatory blind spot.
Sources
- Uruguay - State.gov [S1]
- Uruguay - State.gov [S2]
- GAFILAT Evaluation [S3]
Source Data
Exchange between virtual assets and fiat currencies.
Exchange between one or more forms of virtual assets.
Safekeeping and/or administration of virtual assets or instruments enabling control over virtual assets.
Participation in and provision of financial services related to an issuer’s offer and/or sale of a virtual asset.
AML/CFT Law 19,574 (2017): This is the primary AML/CFT law in Uruguay, establishing obligations for various reporting entities.
Reference: Law 19,574 - Prevención y Combate del Lavado de Activos y el Financiamiento del Terrorismo (Official Spanish Text)
Law 19,996 (2021): This law further strengthens the AML/CFT framework and explicitly includes virtual assets (defined broadly as "property") within the scope of illicit activities covered by the AML/CFT regime. It designates VASPs as obligated subjects for AML/CFT purposes.
Reference: Law 19,996 - Modificaciones a la Ley N° 19.574, de 20 de diciembre de 2017 (Official Spanish Text)
BCU Circular No. 2,427 (2022): The BCU clarified that virtual assets and related activities require supervision, aligning VASPs with existing financial intermediaries in terms of AML/CFT obligations. It explicitly states that entities offering virtual asset services must apply CDD, risk management, and report suspicious transactions to SENACLAFT.
Reference: Comunicación No. 2022/247 - Marco de Supervisión de Activos Virtuales (Official Spanish Text)
SENACLAFT Guidelines: SENACLAFT, as Uruguay's Financial Intelligence Unit (FIU), issues specific guidelines and recommendations for reporting entities, including those handling virtual assets, regarding their AML/CFT obligations, which encompass targeted financial sanctions.
Implementation: Uruguay implements UN sanctions through national decrees. These decrees mandate the freezing of assets and prohibition of transactions with individuals and entities designated by the UN Security Council.
Decree 379/014 (2014): Establishes the procedures for the implementation of UN Security Council resolutions related to the freezing of assets associated with terrorism and proliferation.
Reference: Decreto 379/014 - Medidas relativas a la prevención del lavado de activos y el financiamiento del terrorismo y la proliferación de armas de destrucción masiva (Official Spanish Text)
Decree 208/022 (2022): Updates and strengthens the regulatory framework for TFS, aligning with FATF recommendations and addressing virtual assets. It explicitly requires reporting entities (including VASPs) to check their client lists against the UN sanctions lists immediately upon their publication.
Reference: Decreto 208/022 - Marco Regulatorio de Sanciones Financieras Dirigidas (Official Spanish Text)
Sanctioned Entity Screening: VASPs must screen all customers (during onboarding and ongoing), beneficial owners, and transactions against the UN Consolidated Sanctions List, which includes:
ISIL (Da'esh) & Al-Qaida Sanctions List
DPRK (North Korea) Sanctions List
Other country-specific sanctions regimes (e.g., Libya, Mali, Somalia, Yemen, etc.)
Asset Freezing: Immediately freeze any virtual assets or funds belonging to or controlled by sanctioned individuals or entities.
Reporting: Report any matches or frozen assets to SENACLAFT without delay.
Deal with U.S. Persons or Entities: This includes U.S. citizens, permanent residents, entities organized under U.S. law, or persons/entities located in the U.S.
Utilize U.S. Dollar-Denominated Transactions or U.S. Financial Infrastructure: Many crypto exchanges and financial services providers rely on U.S. correspondent banking relationships or process transactions in USD. Non-compliance can lead to de-risking by financial partners or direct OFAC enforcement.
Have a Nexus to the U.S. or EU: This could include servers located in these jurisdictions, U.S./EU investors, employees, or significant business operations.
Engage in Activities within the U.S. or EU Financial System: Any transaction that touches the U.S. or EU financial system, even indirectly, could fall under their jurisdiction.
Proactive Screening: Best practice dictates that VASPs in Uruguay screen against OFAC's Specially Designated Nationals (SDN) and Blocked Persons List, other OFAC sanctions lists (e.g., SSI, CAPTA), and the EU Consolidated List of persons, groups, and entities subject to EU financial sanctions.
Prohibited Transactions: Prohibit any direct or indirect transactions involving sanctioned individuals, entities, or jurisdictions as designated by OFAC or the EU.
Risk Management: Implement robust risk-based compliance programs that account for the potential impact of OFAC and EU sanctions on their operations and client base.
Perform Customer Due Diligence (CDD): Identify and verify the identity of their customers and beneficial owners.
Ongoing Monitoring: Continuously monitor customer transactions and relationships for any suspicious activity or changes in sanctions status.
Sanctions Screening: Screen all new and existing clients, as well as the counterparties to transactions, against applicable sanctions lists (UN, OFAC, EU as appropriate) using reliable screening software.
Record Keeping: Maintain records of all CDD, monitoring, and screening activities.
UN: North Korea (DPRK), Iran (proliferation-related).
OFAC: Cuba, Iran, North Korea, Syria, Venezuela (certain sectors/entities), parts of Ukraine (Crimea, Donetsk, Luhansk regions).
EU: Similar to OFAC, with specific focus on North Korea, Iran, Syria, Russia (post-invasion of Ukraine), Belarus.
SENACLAFT Role: SENACLAFT is responsible for disseminating updated consolidated lists of individuals and entities subject to targeted financial sanctions (primarily derived from UN lists) to reporting entities in Uruguay. While SENACLAFT doesn't create new independent lists distinct from UN ones, it ensures their timely and effective national implementation.
The Central Bank (BCU) or SENACLAFT can impose substantial administrative fines on VASPs for deficiencies in their compliance programs, failure to report suspicious transactions, or failure to implement sanctions screening. Fines can be significant, calculated as a percentage of gross income or a fixed amount.
Individuals and entities involved in facilitating money laundering, terrorist financing, or proliferation financing can face criminal prosecution, leading to imprisonment and confiscation of assets.
Sanctions evasion, particularly concerning UN-mandated prohibitions, can be treated as an underlying predicate offense for money laundering or financing of terrorism.
Violations can severely damage a VASP's reputation, leading to loss of customers, banking relationships, and investor confidence.
Financial institutions (both traditional and crypto-native) may terminate services to VASPs perceived as high-risk or non-compliant with international sanctions, making it difficult for them to operate.
Develop a Robust AML/CFT & Sanctions Compliance Program: This includes written policies and procedures, risk assessments, internal controls, and independent audits.
Implement Comprehensive CDD: Identify and verify all customers and beneficial owners.
Conduct Sanctions Screening: Screen all customers and counterparties against the UN Consolidated Sanctions List, OFAC SDN List, and EU Consolidated List.
Monitor Transactions: Continuously monitor transactions for red flags indicative of sanctions evasion, money laundering, or terrorist financing.
Train Staff: Provide regular and comprehensive training to all relevant staff on AML/CFT and sanctions compliance requirements.
Report Suspicious Activity: File suspicious activity reports (SARs) with SENACLAFT promptly when required.
Stay Updated: Monitor updates from the BCU, SENACLAFT, UN, OFAC, and EU regarding sanctions lists and regulatory guidance.
Law N° 19.996 – Ley de Fomento a la Innovación Financiera (Financial Innovation Promotion Law): Enacted in 2021, this law establishes a regulatory sandbox (Espacio de Innovación Financiera) to test new technologies and business models, and mandates the BCU to classify "digital assets."
Link to Law N° 19.996 (Spanish, parliamentary site)
Decreto N° 360/011 (Regulation of Electronic Money Services): Defines electronic money and outlines the requirements for Electronic Money Issuers (EMIs).
Link to Decreto N° 360/011 (Spanish, official)
Comunicación N° 2013/058 del BCU (Regulations for Payment Service Providers – PSPs): Further details the licensing and operational requirements for PSPs that issue electronic money.
Link to Comunicación N° 2013/058 (Spanish, BCU site)
BCU's View: The BCU has been cautious, stating that while some crypto assets could potentially function as a form of electronic money, they generally do not meet the stringent regulatory, prudential, and consumer protection standards required for financial services.
Law N° 18.627 (Ley del Mercado de Valores – Securities Market Law): Regulates public offerings of securities.
Link to Law N° 18.627 (Spanish, parliamentary site)
Law N° 16.749 (Ley de Sociedades Administradoras de Fondos de Inversión – Investment Fund Management Companies Law): Could apply if the stablecoin represents units in a fund.
Link to Law N° 16.749 (Spanish, parliamentary site)
Regulator: The Superintendencia de Servicios Financieros (SSF) within the BCU supervises the securities market.
If classified as Electronic Money: Yes, EMIs in Uruguay are subject to strict reserve requirements. They must maintain backing (generally 1:1) for all electronic money issued, typically in highly liquid assets (e.g., segregated bank accounts, government bonds) to ensure full convertibility and redemption at par. The BCU would set specific rules for the quality and location of these reserves.
If classified as Securities: Reserve requirements would depend on the nature of the security. If it's a debt instrument, it would follow standard corporate finance rules; if it's a share in a fund, the fund's investment policies would dictate asset allocation.
If not E-Money or Security: Currently, there are no specific reserve requirements for stablecoins operating outside of these classifications, though this could change with new legislation.
If classified as Electronic Money: Yes, EMIs in Uruguay are subject to strict reserve requirements. They must maintain backing (generally 1:1) for all electronic money issued, typically in highly liquid assets (e.g., segregated bank accounts, government bonds) to ensure full convertibility and redemption at par. The BCU would set specific rules for the quality and location of these reserves.
If classified as Securities: Issuers offering stablecoins classified as securities to the public would need to register the offering with the SSF (within the BCU) and comply with securities market regulations. Intermediaries (brokers, exchanges) would also require specific licenses.
Regulatory Sandbox: Entities wishing to issue stablecoins under novel models can apply to the Financial Innovation Space (sandbox) established by Law N° 19.996. This allows for controlled testing with temporary, modified regulatory requirements, but still requires BCU authorization.
AML/CFT Registration: Even if not falling under the e-money or securities classifications for prudential purposes, entities dealing with stablecoins (e.g., exchanges, custodians) are typically considered "virtual asset service providers" (VASPs) and must register with the BCU and comply with AML/CFT regulations.
If classified as Electronic Money: Yes, EMIs in Uruguay are subject to strict reserve requirements. They must maintain backing (generally 1:1) for all electronic money issued, typically in highly liquid assets (e.g., segregated bank accounts, government bonds) to ensure full convertibility and redemption at par. The BCU would set specific rules for the quality and location of these reserves.
If classified as Securities: Redemption rights would be defined by the specific terms of the security (e.g., prospectus, bond covenants).
If not E-Money or Security: Currently, there are no specific reserve requirements for stablecoins operating outside of these classifications, though this could change with new legislation.
Given their inherent volatility and reliance on complex algorithms rather than full fiat collateral, they are highly unlikely to be classified as electronic money.
They could potentially be classified as securities if their design involves investment-like features or if they fail to maintain their peg, leading to speculative activity.
The BCU would likely view them as higher-risk digital assets, requiring careful scrutiny within the sandbox or under general consumer protection and financial stability considerations.
e-Peso Pilot Project (2017-2018): The BCU conducted a successful pilot program for a retail CBDC, the "e-Peso," making it one of the first countries to do so. The pilot demonstrated the technical feasibility of issuing a digital version of the Uruguayan peso for general use.
Link to BCU's information on the e-Peso pilot (Spanish)
Current Status: While the pilot concluded successfully, the BCU decided against full implementation of a retail CBDC at that time, stating that the project confirmed the technical feasibility but further analysis was needed regarding its real benefits, costs, and potential impact on the financial system.
Interaction with Private Stablecoins: If Uruguay were to launch a CBDC, it would likely serve as a safe and regulated digital alternative to private stablecoins, potentially limiting their widespread adoption as a primary means of payment. A CBDC would be a direct liability of the central bank, carrying no credit or liquidity risk, unlike private stablecoins. The BCU continues to monitor international developments and assess the implications of CBDCs for financial stability and monetary policy.
Law N° 19.574 (Ley Integral de Lavado de Activos – Comprehensive Anti-Money Laundering Law): Extends AML/CFT obligations to "virtual asset service providers" (VASPs).
Link to Law N° 19.574 (Spanish, parliamentary site)
BCU Regulations: The BCU issues specific circulars and communications detailing AML/CFT requirements for financial institutions and VASPs, including customer due diligence (CDD), record-keeping, and suspicious transaction reporting (STR).
Initial Framework: The foundational legislation bringing VASPs under the AML/CFT regime, Law No. 19.940 (Ley de Prevención de Lavado de Activos y Financiamiento del Terrorismo en el Sector de Activos Virtuales) and Decree No. 379/021, were published in 2021. These mandated the registration and supervision of VASPs by the BCU.
Travel Rule Specifics: The BCU issued Circular No. 240/2021 (and subsequent amendments like Circular 245/2021 and 247/2021), which details the AML/CFT obligations for VASPs, including the Travel Rule. While the framework was in place in 2021, full compliance with the Travel Rule data transmission requirements for VASPs was generally expected to be in force by August 2022.
VASP-to-VASP Transfers: For virtual asset transfers between a Uruguayan VASP and another VASP (domestic or international), the Travel Rule applies to transactions equal to or exceeding USD 1,000 (or its equivalent in other currencies/virtual assets).
VASP-to-Unhosted Wallet Transfers: For transactions where a Uruguayan VASP sends or receives virtual assets to/from an unhosted (private, self-custodied) wallet:
If the transaction is equal to or exceeds USD 3,000 (or its equivalent), the VASP must collect the relevant information from its own customer (originator or beneficiary) as if it were a VASP-to-VASP transfer. The VASP must also assess the risks associated with unhosted wallets.
The FATF's updated guidance (2023) encourages all VASPs to manage the risks of unhosted wallets, even below thresholds.
Name (natural person) or legal name (legal entity).
National identity number (e.g., CI, Passport number, Tax ID).
Customer identification number (assigned by the VASP, if applicable).
This information must be transmitted securely and immediately along with the virtual asset transaction, or within a reasonable timeframe if immediate transmission is technically impossible.
VASPs are required to store this information for a period of five years, readily available to competent authorities.
While the BCU mandates the data points, it does not prescribe a specific technical solution or protocol (e.g., TRISA, Sygna, Travel Rule Protocol, etc.). VASPs are expected to adopt a solution that effectively enables them to comply with the information collection and transmission requirements.
Fines: Substantial monetary fines can be imposed, calculated based on the severity and recurrence of the infraction. Fines can range up to significant amounts (e.g., up to 20,000,000 Indexed Units – UI, which is a considerable sum).
Suspension of Operations: Temporary suspension of VASP activities.
Revocation of Registration/License: In severe or repeated cases of non-compliance, the BCU can revoke a VASP's registration, effectively barring them from operating in Uruguay.
Reputational Damage: Non-compliance can lead to public censure and damage to a VASP's reputation.
Criminal Charges: In cases involving money laundering or financing of terrorism, individuals and legal entities can face criminal prosecution, imprisonment, and asset forfeiture.
Law No. 19.940 (Ley de Prevención de Lavado de Activos y Financiamiento del Terrorismo en el Sector de Activos Virtuales): Establishes the legal framework for AML/CFT for VASPs.
Decree No. 379/021: Regulates Law 19.940, detailing definitions, scope, registration, and supervision.
BCU Circular No. 240/2021: Establishes specific AML/CFT obligations for VASPs, including the Travel Rule requirements.
BCU Circular No. 241/2021: Defines the registration process for VASPs with the BCU.
BCU Circular No. 245/2021 and 247/2021: Subsequent amendments that further clarify or modify aspects of Circular 240/2021. These are usually linked from the main BCU circulars page.
49 fact(s) collected but awaiting source verification. View in explorer →
References
This article was generated by local/granite4.1 .
Primary Sources
gafilat.org. (n.d.). GAFILAT Evaluation. Retrieved August 22, 2026, from http://www.gafilat.org/UserFiles/documentos/es/evaluaciones_mutuas/Uruguay_3era_Ronda_2009.pdf
2009-2017.state.gov. (n.d.). Uruguay - State.gov. Retrieved August 22, 2026, from https://2009-2017.state.gov/j/inl/rls/nrcrpt/2016/vol2/253439.htm
2009-2017.state.gov. (n.d.). Uruguay - State.gov. Retrieved August 22, 2026, from https://2009-2017.state.gov/j/inl/rls/nrcrpt/2015/supplemental/239335.htm
Secondary Sources
gub.uy. (n.d.). gub.uy. Retrieved April 22, 2026, from https://www.gub.uy/secretaria-nacional-lucha-lavado-activos-financiamiento-terrorismo/ es
bcu.gub.uy. (n.d.). bcu.gub.uy. Retrieved April 22, 2026, from https://www.bcu.gub.uy/ es
Edit History
This article is maintained by AI research workers and reviewed by human editors. Learn about our methodology →