D1 Sanctions
Sanctions is not yet covered for this jurisdiction in this report.
Uruguay's AML/CFT regime rests on Laws 17,835, 18,494 and 19,355, with a bearer-share identification registry under Law 18,930 (2012) run by the Banco Central.
Sanctions is not yet covered for this jurisdiction in this report.
Beneficial Ownership is not yet covered for this jurisdiction in this report.
Enabler Jurisdictions is not yet covered for this jurisdiction in this report.
Conflict Finance is not yet covered for this jurisdiction in this report.
Uruguay has finalised the first comprehensive authorisation regime for virtual-asset service providers in its history. Banco Central del Uruguay, through its Superintendencia de Servicios Financieros, has completed Resolution SSF No. 2026-444, adding Title VII-TER to the Compilation of Securities Market Regulations and operationalising the authority granted under Ley N degrees 20.345. The core requirement is that legal entities providing virtual-asset services on a regular and professional basis, where the BCU deems the underlying assets financial instruments, must obtain BCU authorisation before operating in Uruguay. Critically, the application dossier for that authorisation embeds AML/CFT compliance-programme documentation as a governance precondition, meaning the licensing gate and the compliance-architecture gate are, in practice, a single gate.
The transitional mechanics deserve particular attention from a financial-integrity perspective, because they allocate continuity risk asymmetrically. Existing VASP operators may apply for authorisation during a window running from 1 September 2026 through 31 March 2027, and may continue operating while their application undergoes BCU review. New entrants face a stricter standard: authorisation must be secured before any operation commences. This creates a two-track system in which the compliance runway available to an operator depends entirely on whether it was already active in the market before the regime crystallised. From a typology perspective, the design has the practical effect of pulling a population of previously informal or lightly-regulated virtual-asset businesses into a formal compliance-documentation regime over an eighteen-month period, which is itself the kind of structural absorption that FATF-aligned jurisdictions are increasingly expected to demonstrate.
The evidentiary picture here is strong but not complete. The primary legal basis, Ley N degrees 20.345, is confirmed via a Tier-1 IMPO source at Confirmed confidence, and the substance of the authorisation requirement and the transitional application window both trace to that same primary legislative source. The claim that existing operators may continue trading pending review, however, rests at Probable confidence, corroborated only through law-firm commentary from Ferrere rather than through independent retrieval of the full resolution text. This is a genuine, flagged sourcing gap rather than a substantive doubt about the underlying policy, and it should be read as such: the direction and shape of the transitional regime is not in serious question, but the precise operative language of Resolution SSF No. 2026-444 has not yet been directly examined this cycle.
Read against the standing AML/CTF backdrop, this development is best understood as a sectoral tightening rather than a whole-regime shift. Uruguay's national AML/CFT strategy, approved in July 2025, and its FATF/GAFILAT standing (not grey-listed, most recent mutual evaluation on-site visit in May 2019) remain unchanged; what has changed is that a previously unregulated or ambiguously-regulated sector, virtual assets, has now been folded into a documented compliance-governance requirement. The enablement lens applies here too: the prior absence of any VASP-specific authorisation regime was itself a gap, and its closure is the material fact, independent of any enforcement action taken against a named entity.
The period between the opening of the application window and its close on 31 March 2027 is the operative test window. Existing operators will need to build out corporate governance and AML/CFT documentation to a standard that, per available assessment, has generally lagged among unregulated regional firms in this sector; the degree to which incumbents can meet that bar within an eighteen-month runway is the first practical question the regime poses. A second and closely related question is how the BCU exercises its discretionary authority to deem an asset a financial instrument for purposes of triggering the authorisation requirement, since that discretionary threshold is the hinge on which the entire regime's scope turns, and it was not itself the subject of confirmed sourcing this cycle. Firms and counterparties operating in or with Uruguay's virtual-asset sector should expect the transitional period to generate the clearest evidence yet of whether the architecture, once operational rather than merely announced, functions as a genuine compliance uplift or surfaces gaps between statutory intent and supervisory capacity.
Compliance Technology & Active Defence is not yet covered for this jurisdiction in this report.
Uruguay's standing AML/CTF regime saw no material this-cycle delta at the whole-of-economy level, but the sectoral tightening captured under the crypto/digital-assets finding this cycle is itself an AML/CTF-relevant development and is best read through that lens as well. The Banco Central del Uruguay approved a new National Strategy for Combating Money Laundering in July 2025, per IMF Country Report No. 25/287, and Uruguay's financial-intelligence and AML coordination body, SENACLAFT, published its most recent politically-exposed-persons list update in February 2025. Both of these are standing-regime facts rather than developments dated to this cycle, and they establish the institutional base against which the new virtual-asset authorisation layer, finalised via Resolution SSF No. 2026-444 under Ley N degrees 20.345, should be assessed.
Uruguay's multilateral standing remains stable and favourable relative to jurisdictions under active FATF or GAFILAT pressure. It is not on the FATF grey list, and its most recent GAFILAT mutual evaluation on-site visit took place 6 to 17 May 2019, a report that covered AML/CFT matters comprehensively across all categories of designated non-financial businesses and professions. No new mutual evaluation cycle or grey-list designation activity was identified this cycle, and the absence of such activity is itself a stable, structural fact worth stating plainly rather than passing over in silence: Uruguay's baseline AML/CTF architecture has not moved, even as its sectoral crypto oversight has moved materially.
The analytically significant point for the three-pillar AML/CTF/CPF balance is that the newly-finalised VASP authorisation regime is the vehicle through which AML/CFT compliance obligations are now being extended to a sector that previously sat outside any dedicated authorisation gate. The authorisation dossier required of virtual-asset service providers under the new regime embeds AML/CFT compliance-programme documentation as a governance precondition of market access, meaning the standing national AML strategy now has a concrete sectoral implementation mechanism in the virtual-asset space that did not exist before this cycle. This is a case where the AML/CTF regime domain and the crypto/digital-assets domain converge on the same underlying regulatory instrument, viewed from two different analytical angles: one as market-access architecture, the other as compliance-governance extension.
Enablement-as-signal analysis is relevant here in its negative form: prior to this cycle, the absence of any VASP-specific AML/CFT authorisation requirement in Uruguay was itself a standing enablement condition, whether or not it was ever actively exploited. Its closure via Resolution SSF No. 2026-444 removes that structural gap, independent of whether any enforcement action or illicit-finance case had previously been attributable to it.
The standing AML/CTF architecture is unlikely to see further whole-of-economy change in the near term absent a new GAFILAT evaluation cycle, none of which was identified as scheduled this cycle. The more immediate development to watch sits at the sectoral level: how thoroughly the AML/CFT documentation requirements embedded in the new VASP authorisation regime are actually enforced during the transitional application window running through 31 March 2027 will be the practical test of whether this cycle's architectural finding translates into a genuine uplift in AML/CTF coverage of the virtual-asset sector, or remains, for now, a documentation requirement without an established supervisory track record.
Commercial Activity is not yet covered for this jurisdiction in this report.
Virtual-asset counterparties in Uruguay will now be subject to a formal AML/CFT compliance-documentation gate as part of BCU authorisation, extending the standing national AML strategy into a sector that previously lacked a dedicated authorisation requirement. SAR-relevant typology exposure via unregulated Uruguayan VASP counterparties should reduce over the transitional period through 31 March 2027 as the regime beds in.
Compliance functions with exposure to Uruguayan VASP counterparties should track the transitional application window (1 September 2026 to 31 March 2027) since counterparty status will shift from unregulated to formally authorised or under review during this period.
No material change for this persona this cycle
The finding is architectural: no enforcement action drives it, and its significance lies in the closure of a previously unregulated market segment for institutions with digital-asset counterparty exposure to Uruguay.
Technology and compliance-architecture teams supporting Uruguay-facing crypto operations should anticipate documentation and governance build requirements tied to the transitional window through 31 March 2027.
Exposure concentration risk tied to unregulated Uruguayan crypto counterparties should be reassessed as the transitional authorisation period progresses; the shift from unregulated to authorised status is a material change in counterparty risk profile.
No material change for this persona this cycle
Audit trails referencing the specifics of the transitional application window should note that the underlying finding is corroborated at Probable rather than Confirmed confidence pending direct retrieval of the primary resolution text.
Uruguay finalised a comprehensive VASP authorisation regime embedding AML/CFT compliance documentation as an authorisation precondition.
New BCU VASP authorisation regime creates a licensing and compliance-documentation gate for Uruguay-facing virtual-asset counterparties.
No material change this cycle.
Uruguay has closed a longstanding VASP authorisation gap, a structural rather than incident-driven development.
BCU's new authorisation regime requires AML/CFT compliance-programme documentation as a technical and governance precondition for VASP operation in Uruguay.
A previously unregulated Uruguayan VASP sector is being absorbed into a formal AML/CFT-linked authorisation regime.
No material change this cycle.
The operative text of BCU Resolution SSF No.
Illustrative scenario for analytical orientation only. As the EU AML Package matures, the shift from purely national AML supervision toward AMLA direct and indirect supervision of cross-border obliged entities, under the AMLA Regulation (Reg (EU) 2024/1620), alongside the directly-applicable AMLR (Reg 2024/1624) and per-Member-State 6AMLD transposition, could reshape how evasion typologies migrate across the EU-non-EU boundary. A jurisdiction such as Uruguay, which sits outside the EU AML Package direct perimeter but maintains an EU adequacy-adjacent posture in other regulatory domains, illustrates the kind of non-EEA node that a hybrid EU-level supervisory architecture might increasingly need to account for when tracing cross-border obliged-entity exposure, without this being read as any finding about Uruguay's actual regulatory status under that Package, which does not apply to it.
Illustrative scenario for analytical orientation only. Not compliance advice, not a prediction, and not a statement of observed fact.
| Tracker | Status | Note |
|---|---|---|
| T1 · Russian Sanctions-Evasion Architecture | stable | |
| T2 · EU AML Package / AMLA | stable | |
| T3 · FATF Grey List | stable | |
| T4 · Beneficial-Ownership Register Status | stable | |
| T5 · Crypto / VASP Regulatory Framework | material_change | |
| T6 · Sanctions Regime Divergence | stable |