Trackers
Trackers

AML & KYC in Brazil: 2026 Update

Brazil operates one of Latin America';s most developed anti-money laundering and know-your-customer frameworks, anchored by a robust legislative base and active regulatory enforcement. The country';s AML & KYC Brazil regime applies across banking, capital markets, insurance, fintechs, real estate, and a growing list of designated non-financial businesses and professions. For international founders, investors, and compliance officers entering the Brazilian market, understanding the current rules is not optional - it is a prerequisite for operating legally and avoiding significant penalties. This guide covers the legal foundations, the competent authorities, customer due diligence requirements, recent regulatory updates, and the practical obligations that businesses must meet.

Legal foundations of AML & KYC in Brazil

Brazil';s primary AML statute is Law No. 9,613 of 1998, commonly known as the Anti-Money Laundering Law. It was substantially reformed by Law No. 12,683 of 2012, which expanded the list of predicate offences to include all crimes, removed the previous closed list, and strengthened the obligations of reporting entities. The law criminalises the concealment, conversion, or transfer of assets derived from any criminal activity, and establishes a framework of administrative and criminal penalties.

Complementing the AML Law is Law No. 13,260 of 2016, which addresses terrorist financing, and Law No. 13,810 of 2019, which governs the freezing of assets linked to UN Security Council sanctions lists. Together, these statutes form the legislative backbone of Brazil';s financial crime prevention architecture.

Brazil is a member of the Financial Action Task Force (FATF) and of GAFILAT, the regional FATF-style body for Latin America. The country underwent a mutual evaluation in recent years, and the resulting recommendations have driven a series of regulatory updates across multiple sectors. Compliance with FATF standards is a live and evolving obligation, not a one-time exercise.

Competent authorities and their roles

Several regulators share responsibility for AML & KYC oversight in Brazil, each covering a distinct segment of the regulated sector.

The Council for Financial Activities Control, known by its Portuguese acronym COAF, is the country';s financial intelligence unit. COAF receives suspicious transaction reports, analyses financial intelligence, and shares information with law enforcement and other authorities. It operates under the supervision of the Banco Central do Brasil (BCB) following a recent institutional reorganisation.

The Banco Central do Brasil supervises banks, payment institutions, fintechs, and other financial institutions. It issues its own AML regulations, most notably Resolution BCB No. 44 of 2021 and subsequent amendments, which set out detailed customer due diligence, record-keeping, and internal controls requirements for the entities it supervises.

The Securities and Exchange Commission of Brazil, the CVM, regulates capital markets participants including brokers, asset managers, and investment funds. CVM Resolution No. 50 of 2021 consolidated and updated AML obligations for the securities sector, aligning them more closely with FATF standards.

The Superintendence of Private Insurance, SUSEP, covers insurance companies and brokers. The Federal Revenue Service, Receita Federal, oversees certain designated non-financial businesses. Each regulator publishes its own normative acts, and regulated entities must identify which authority governs their specific activities.

Customer due diligence requirements

Customer due diligence, or CDD, is the operational core of any AML & KYC Brazil compliance programme. Brazilian regulations require regulated entities to identify and verify the identity of customers before establishing a business relationship or carrying out occasional transactions above defined thresholds.

For individual customers, identification requires full name, CPF (the Brazilian individual taxpayer number), date of birth, address, and the nature of the business relationship. For legal entities, the requirements extend to the CNPJ (corporate taxpayer number), articles of incorporation, and - critically - identification of the ultimate beneficial owner (UBO). Brazilian rules define the UBO as any natural person who, directly or indirectly, holds or controls more than 25% of the share capital, or who exercises effective control over the entity.

Enhanced due diligence applies in higher-risk situations. These include:

  • Customers classified as politically exposed persons (PEPs) and their close associates
  • Transactions involving jurisdictions identified as high-risk by FATF
  • Complex or unusually large transactions with no apparent economic rationale
  • Customers from sectors historically associated with financial crime

Simplified due diligence may apply to lower-risk customers and products, but regulated entities must document their risk-based rationale. A common mistake among foreign-owned businesses entering Brazil is applying the CDD standards of their home jurisdiction rather than the specific Brazilian requirements, which can differ materially in scope and documentation.

Ongoing monitoring and suspicious transaction reporting

Identification at onboarding is only the starting point. Brazilian regulations impose a continuous monitoring obligation. Regulated entities must maintain up-to-date customer records, monitor transactions against the customer';s expected profile, and flag anomalies for further review.

Suspicious transaction reports (STRs) must be filed with COAF when a regulated entity identifies transactions or attempted transactions that suggest money laundering, terrorist financing, or related offences. The reporting obligation is unconditional - there is no de minimis threshold for STRs. Entities must also file cash transaction reports (CTRs) for cash operations above the threshold set by their specific regulator, which for banks is currently set at a level requiring reporting of significant cash movements.

The reporting obligation is confidential. Brazilian law prohibits tipping off the customer that a report has been filed. Failure to report, or deliberate delay, can result in administrative penalties and, in serious cases, criminal liability for the compliance officer or senior management responsible.

In practice, regulated entities should consider building automated transaction monitoring systems calibrated to their specific customer base and product mix. Many underestimate the operational investment required to maintain a credible monitoring programme, particularly as transaction volumes grow.

If you are establishing a regulated business in Brazil and need to design a compliant AML & KYC framework from the ground up, contact info@vlolawfirm.com. We can help structure the setup correctly the first time.

Internal controls, training, and record-keeping

Brazilian AML regulations require regulated entities to maintain a formal internal controls structure. For entities supervised by the BCB, Resolution BCB No. 44 sets out specific requirements for the compliance function, including the appointment of a designated AML officer (the "diretor responsável"), internal policies and procedures, periodic risk assessments, and an independent audit function.

The AML officer must be a member of senior management and is personally accountable to the regulator. This is a non-obvious requirement for foreign groups that assume a compliance function can be outsourced entirely to a third party. The designated officer must be formally registered with the relevant regulator and must have sufficient authority within the organisation to act on compliance findings.

Training is mandatory. All staff who interact with customers or handle transactions must receive AML and KYC training appropriate to their role. Training records must be maintained and made available to regulators on request.

Record-keeping obligations require that customer identification documents, transaction records, and STR documentation be retained for a minimum of five years from the end of the business relationship or the date of the transaction. Some categories of records must be kept for longer periods. Records must be retrievable within a reasonable timeframe if requested by COAF, the BCB, the CVM, or law enforcement.

A practical scenario: a foreign asset manager establishing a Brazilian subsidiary will need to appoint a local AML officer, draft Portuguese-language policies aligned with CVM Resolution No. 50, implement a transaction monitoring system, and register the officer with the CVM before commencing operations. Attempting to run the Brazilian entity on a global policy document without local adaptation is a common and costly mistake.

Recent regulatory updates and upcoming changes

Brazil';s AML & KYC framework has been actively updated in recent years, driven by FATF mutual evaluation recommendations and domestic policy priorities.

The BCB has progressively tightened requirements for payment institutions and fintechs, recognising that the rapid growth of Brazil';s digital financial sector created new channels for financial crime. Fintechs are now subject to substantially the same CDD and monitoring obligations as traditional banks, with limited exceptions for lower-risk business models.

The CVM updated its AML framework for the securities sector, consolidating previous rules and introducing clearer guidance on risk-based approaches, UBO identification, and the treatment of investment funds with complex ownership structures. Asset managers and fund administrators have had to invest significantly in updating their onboarding and monitoring processes.

COAF has expanded its analytical capacity and increased the volume of intelligence reports shared with the Federal Police and the Public Prosecutor';s Office. Enforcement actions resulting from COAF intelligence have become more frequent, and the penalties imposed - which can include fines, suspension of operations, and disqualification of officers - have increased in severity.

Brazil has also made progress in implementing beneficial ownership transparency requirements. The Federal Revenue Service has expanded the scope of entities required to disclose UBO information in the CNPJ registration system, and cross-referencing between the CNPJ database and COAF intelligence is now a standard enforcement tool.

A second practical scenario: an international trading company with a Brazilian subsidiary that has historically treated its local compliance programme as a formality will face increasing scrutiny. Regulators are now conducting thematic inspections focused on UBO identification and the quality of transaction monitoring, not merely the existence of a written policy.

FAQ

What entities are subject to AML & KYC obligations in Brazil?

The scope of regulated entities in Brazil is broad and continues to expand. It covers financial institutions, payment institutions, fintechs, securities brokers and asset managers, insurance companies, real estate agents and developers, lawyers and accountants when carrying out certain activities, dealers in high-value goods, and factoring companies, among others. The specific regulator and the applicable normative act depend on the sector. Foreign-owned entities operating in Brazil through a local subsidiary or branch are subject to Brazilian rules in full, regardless of the AML standards applied by their parent group in other jurisdictions.

How long does it take to implement a compliant AML programme for a new Brazilian entity?

The timeline varies significantly depending on the entity type, the complexity of the business model, and the regulator involved. For a fintech or payment institution supervised by the BCB, the process of drafting policies, appointing and registering the AML officer, implementing transaction monitoring, and training staff typically takes several months from the decision to launch. Entities that underestimate this timeline risk commencing operations without a compliant framework in place, which exposes the AML officer and senior management to personal liability. Engaging specialist legal and compliance advisers early in the process materially reduces the risk of delay.

What are the penalties for non-compliance with AML rules in Brazil?

Administrative penalties under the AML Law and sector-specific regulations can be substantial. They include warnings, fines calculated as a percentage of the transaction or a fixed amount, suspension of operations, cancellation of licences, and disqualification of officers from holding management positions in regulated entities. Criminal liability for money laundering carries prison sentences under the AML Law. Regulators have demonstrated a willingness to impose the full range of sanctions, including personal penalties against compliance officers and directors. The reputational consequences of a public enforcement action in Brazil can also affect a group';s ability to operate in other markets.

Conclusion

Brazil';s AML & KYC framework is comprehensive, actively enforced, and continuing to evolve in line with FATF standards. Regulated entities - whether domestic or foreign-owned - must maintain robust customer due diligence, ongoing monitoring, timely suspicious transaction reporting, and a properly resourced internal controls function. The cost of non-compliance, in financial penalties and reputational damage, significantly exceeds the investment required to build a credible programme.

VLO Law Firms advises international clients on AML & KYC matters in Brazil. We can assist with regulatory mapping, policy drafting, AML officer registration, and ongoing compliance support. To request a consultation, contact: info@vlolawfirm.com