Brazil • Virtual-asset services

Brazil VASP authorisation under the BCB framework.

Build or transition a Brazil-facing crypto operation with the governance, controls, client-asset safeguards, compliance programme, and evidence structure expected under the formal virtual-asset regime.

Supervisory authorityBanco Central do Brasil
Framework effective2 February 2026
Core classificationsIntermediary, custodian, broker
Delivery modelPrivate, scope-led engagement
Who this is for

Crypto businesses serving Brazil or building a Brazilian operating base.

The route depends on what the platform actually does, not simply whether it describes itself as an exchange, wallet, broker, OTC desk, or payment product.

01

Exchange & intermediation

Fiat-to-crypto, crypto-to-crypto, matching, execution, order routing, OTC, and platform-mediated transactions.

02

Custody & wallet services

Safekeeping, administration, key management, wallet infrastructure, withdrawals, deposits, and client-asset controls.

03

Brokerage & distribution

Client-facing purchase and sale models, brokerage structures, liquidity access, and execution through counterparties.

04

Stablecoin & cross-border models

BRL-linked flows, international transfers, fiat-referenced tokens, treasury movement, and potential foreign-exchange perimeter issues.

05

Existing operators

Businesses already active in Brazil that require a gap assessment, remediation plan, governance upgrades, and transition support.

Regulatory architecture

What the Brazil VASP build needs to address.

The final requirements depend on the authorised activities and risk profile. The following pillars should be designed as one operating system.

G

Governance & suitability

Clear decision rights, accountable management, controller and leadership suitability, conflicts management, committees, and documented oversight.

R

Risk & internal controls

Enterprise risk assessment, control ownership, operational-risk methodology, testing, escalation, reporting, and audit readiness.

A

AML/CTF framework

Customer risk scoring, KYC/KYB, beneficial ownership, sanctions and PEP controls, monitoring, investigations, reporting, and retention.

C

Client-asset safeguards

Segregation, custody architecture, wallet governance, reconciliations, withdrawal controls, reserve evidence, and insolvency-aware processes.

T

Technology & security

Cybersecurity, privileged access, key management, outsourcing, incident response, resilience, logging, recovery, and change management.

F

Financial robustness

Capital planning, financial projections, liquidity assumptions, safeguarding costs, operating budgets, and sustainable resourcing.

Project scope

From modality mapping to an evidence-backed authorisation file.

We tailor the workstream to a new entrant, an international group localising its model, or an incumbent transitioning into the new regime.

Activity and perimeter memorandum

  • Service and modality mapping
  • Customer and jurisdiction analysis
  • Stablecoin and FX touchpoints
  • Custody and asset-flow assessment
  • Adjacent regulatory dependencies

Entity and governance package

  • Brazilian entity workstream
  • Foreign shareholder documentation
  • Ownership and control records
  • Management role architecture
  • Governance policies and registers

Compliance and control framework

  • AML/KYC policy suite
  • Risk-assessment methodology
  • Monitoring and escalation procedures
  • Client-asset safeguard design
  • Technology and outsourcing controls

Application and implementation support

  • Operating-plan preparation
  • Document and evidence checklist
  • Authority-facing workflow coordination
  • Remediation and response support
  • Post-authorisation continuity plan
VASP delivery sequence

A structured five-stage engagement.

Model mapping

Define the services, classification, users, assets, counterparties, custody arrangement, and BRL or cross-border exposure.

Entity, ownership & governance

Build the corporate and governance architecture, assign accountable roles, and map local operational requirements.

Compliance & safeguards

Develop the AML/CTF stack, client-asset controls, monitoring framework, technology controls, and incident procedures.

Authorisation evidence pack

Prepare policies, procedures, registers, business descriptions, financial assumptions, and supporting evidence.

Implementation or transition

Support partner onboarding, operational remediation, internal adoption, and ongoing regulatory continuity.

Frequently asked questions

Brazil VASP questions.

A business providing virtual-asset services in Brazil generally needs to assess the BCB authorisation framework. The outcome depends on the actual services, client-facing activity, location, and operating structure.

The current framework distinguishes intermediary, custodian, and virtual-asset broker classifications. A platform may need to map more than one function depending on its service architecture.

Yes. Fiat-referenced tokens, international transfers, on/off-ramps, and BRL settlement may create additional foreign-exchange and reporting considerations alongside the VASP authorisation analysis.

International ownership can be structured, subject to Brazilian corporate, documentation, governance, beneficial-ownership, management, and regulatory requirements.

Yes. The engagement can begin with a gap assessment covering activities, governance, compliance, client assets, technology, records, and transition priorities.

Brazil VASP

Turn your operating model into a defensible authorisation plan.

Share the services, customer regions, current status, stablecoin use, custody model, and target launch structure. We will map the next steps privately.