Brazil VASP authorisation under the BCB framework.
Build or transition a Brazil-facing crypto operation with the governance, controls, client-asset safeguards, compliance programme, and evidence structure expected under the formal virtual-asset regime.
Crypto businesses serving Brazil or building a Brazilian operating base.
The route depends on what the platform actually does, not simply whether it describes itself as an exchange, wallet, broker, OTC desk, or payment product.
Exchange & intermediation
Fiat-to-crypto, crypto-to-crypto, matching, execution, order routing, OTC, and platform-mediated transactions.
Custody & wallet services
Safekeeping, administration, key management, wallet infrastructure, withdrawals, deposits, and client-asset controls.
Brokerage & distribution
Client-facing purchase and sale models, brokerage structures, liquidity access, and execution through counterparties.
Stablecoin & cross-border models
BRL-linked flows, international transfers, fiat-referenced tokens, treasury movement, and potential foreign-exchange perimeter issues.
Existing operators
Businesses already active in Brazil that require a gap assessment, remediation plan, governance upgrades, and transition support.
What the Brazil VASP build needs to address.
The final requirements depend on the authorised activities and risk profile. The following pillars should be designed as one operating system.
Governance & suitability
Clear decision rights, accountable management, controller and leadership suitability, conflicts management, committees, and documented oversight.
Risk & internal controls
Enterprise risk assessment, control ownership, operational-risk methodology, testing, escalation, reporting, and audit readiness.
AML/CTF framework
Customer risk scoring, KYC/KYB, beneficial ownership, sanctions and PEP controls, monitoring, investigations, reporting, and retention.
Client-asset safeguards
Segregation, custody architecture, wallet governance, reconciliations, withdrawal controls, reserve evidence, and insolvency-aware processes.
Technology & security
Cybersecurity, privileged access, key management, outsourcing, incident response, resilience, logging, recovery, and change management.
Financial robustness
Capital planning, financial projections, liquidity assumptions, safeguarding costs, operating budgets, and sustainable resourcing.
From modality mapping to an evidence-backed authorisation file.
We tailor the workstream to a new entrant, an international group localising its model, or an incumbent transitioning into the new regime.
Activity and perimeter memorandum
- Service and modality mapping
- Customer and jurisdiction analysis
- Stablecoin and FX touchpoints
- Custody and asset-flow assessment
- Adjacent regulatory dependencies
Entity and governance package
- Brazilian entity workstream
- Foreign shareholder documentation
- Ownership and control records
- Management role architecture
- Governance policies and registers
Compliance and control framework
- AML/KYC policy suite
- Risk-assessment methodology
- Monitoring and escalation procedures
- Client-asset safeguard design
- Technology and outsourcing controls
Application and implementation support
- Operating-plan preparation
- Document and evidence checklist
- Authority-facing workflow coordination
- Remediation and response support
- Post-authorisation continuity plan
A structured five-stage engagement.
Model mapping
Define the services, classification, users, assets, counterparties, custody arrangement, and BRL or cross-border exposure.
Entity, ownership & governance
Build the corporate and governance architecture, assign accountable roles, and map local operational requirements.
Compliance & safeguards
Develop the AML/CTF stack, client-asset controls, monitoring framework, technology controls, and incident procedures.
Authorisation evidence pack
Prepare policies, procedures, registers, business descriptions, financial assumptions, and supporting evidence.
Implementation or transition
Support partner onboarding, operational remediation, internal adoption, and ongoing regulatory continuity.
Brazil VASP questions.
A business providing virtual-asset services in Brazil generally needs to assess the BCB authorisation framework. The outcome depends on the actual services, client-facing activity, location, and operating structure.
The current framework distinguishes intermediary, custodian, and virtual-asset broker classifications. A platform may need to map more than one function depending on its service architecture.
Yes. Fiat-referenced tokens, international transfers, on/off-ramps, and BRL settlement may create additional foreign-exchange and reporting considerations alongside the VASP authorisation analysis.
International ownership can be structured, subject to Brazilian corporate, documentation, governance, beneficial-ownership, management, and regulatory requirements.
Yes. The engagement can begin with a gap assessment covering activities, governance, compliance, client assets, technology, records, and transition priorities.
Turn your operating model into a defensible authorisation plan.
Share the services, customer regions, current status, stablecoin use, custody model, and target launch structure. We will map the next steps privately.