Brazil KYC & AML compliance checklist
A practical, source-linked checklist for implementing KYC, KYB and AML requirements in Brazil.

Direct answer
What does the Brazil compliance checklist cover?
The Brazil checklist translates primary KYC, KYB and AML rules into 11 control areas and 44 implementation checks. It identifies the relevant authorities, customer and beneficial-owner controls, reporting duties, recordkeeping expectations and evidence teams should retain.
Key regulatory facts
- National FIU
- Conselho de Controle de Atividades Financeiras (Coaf)
- Core AML law
- Law 9,613 of 3 March 1998, as amended
- Suspicious reporting
- To Coaf through Siscoaf; statutory and sector timing applies, commonly within 24 hours or by the next business day after the reporting decision
- Cash reporting
- Sector-specific; BCB Circular 3,978 requires specified cash reports from R$50,000
- Retention
- Five-year statutory minimum; ten years for core records under BCB Circular 3,978
- BCB beneficial-owner parameter
- A risk-based percentage set in policy, not above 25%, plus control analysis
- CNPJ beneficial owner
- Natural person with more than 25% capital or voting rights, or other preponderant control, under current IN RFB 2,119/2022
- Privacy authority
- Autoridade Nacional de Protecao de Dados (ANPD)
- Virtual assets
- BCB authorization regime under Resolutions 519 and 520; operating rule effective 2 February 2026 with transition for existing providers
- FATF status
- FATF/GAFILAT member; not on FATF public lists reviewed 1 August 2026
Implementation detail
Brazil compliance requirements and actions
Open each control area to review the requirement, recommended implementation action, evidence to retain and the primary-source citation used by the research team.
01Scope, authorities and licensingStart with the legal entity, exact activity and supervisor. Brazil's AML perimeter is activity-based and the operating licence does not follow from AML registration alone.4 items+
Persons and entities in Law 9,613 article 9 are subject to customer identification, records, controls and reporting, under rules issued by their competent supervisor.
- Implementation action
- Map every product and legal entity to article 9 and the current BCB, CVM, Susep, Previc, professional-council or Coaf rule before onboarding.
- Evidence to retain
- Perimeter memo, product inventory, legal-entity map, supervisor confirmation and current-rule register.
- Primary citation
- Law 9,613/1998 arts. 9-11 and 14
BCB-authorized institutions must implement Circular 3,978's risk-based AML/CFT policy, procedures and controls.
- Implementation action
- Translate the Circular into approved ownership, roles, risk assessment, CDD, monitoring, reporting, training and effectiveness testing.
- Evidence to retain
- Authorization, board-approved policy, procedures, risk assessment, system configuration and testing.
- Primary citation
- BCB Circular 3,978/2020 arts. 1-10 and 62-65
Persons without another sector supervisor that fall under Coaf competence must register and follow Coaf's applicable resolutions, including Resolution 36's proportional framework.
- Implementation action
- Confirm direct-Coaf supervision, register in Siscoaf when required and document any proportional dispensation relied upon.
- Evidence to retain
- Scope analysis, Coaf registration, applicable resolution, dispensation rationale and portal access list.
- Primary citation
- Law 9,613/1998 arts. 10(IV) and 14(1); Coaf Resolution 36/2021
Payment and virtual-asset activities may require prior BCB authorization independently of AML duties.
- Implementation action
- Gate launch on a written classification under Law 12,865, BCB Resolutions 80/81 and, for virtual assets, Law 14,478 and BCB Resolutions 519/520.
- Evidence to retain
- Regulatory classification, application or authorization, transition analysis, conditions and launch approval.
- Primary citation
- Law 12,865/2013 arts. 6 and 9; BCB Resolutions 80/2021, 81/2021, 519/2025 and 520/2025
02Governance and risk assessmentGovernance must be proportionate to the business and demonstrably control customers, products, channels, jurisdictions, employees and partners.4 items+
BCB-regulated institutions must maintain a board-approved AML/CFT policy compatible with their risk profile and group operations.
- Implementation action
- Assign accountable senior management, approve the policy, cover domestic and foreign units and record exceptions and remediation.
- Evidence to retain
- Approval minutes, accountable-officer appointment, group mapping, exception register and attestations.
- Primary citation
- BCB Circular 3,978/2020 arts. 2-7
An internal risk assessment must evaluate customer, institution, operation, transaction, product, service, employee, partner and third-party categories.
- Implementation action
- Score inherent risk, control effectiveness and residual risk; refresh at least biennially for the BCB perimeter and after material change.
- Evidence to retain
- Methodology, datasets, model validation, biennial approval, change triggers and residual-risk acceptance.
- Primary citation
- BCB Circular 3,978/2020 arts. 10-16
Policies must be communicated, supported by training and evaluated for effectiveness.
- Implementation action
- Train role-based populations, test knowledge and complete the annual effectiveness evaluation within the regulatory timetable.
- Evidence to retain
- Training plan, attendance, assessments, annual evaluation report, management response and closure tracking.
- Primary citation
- BCB Circular 3,978/2020 arts. 3(V), 7 and 62-65
Outsourcing does not transfer the regulated entity's accountability or regulator-access duties.
- Implementation action
- Risk-assess vendors, contract for security, audit and access rights, validate models and maintain an executable exit plan.
- Evidence to retain
- Due diligence, contract, data-flow map, service tests, audit results, incidents and exit test.
- Primary citation
- BCB Circular 3,978/2020 arts. 3-7 and 60-61; Coaf Resolution 36/2021
03Natural-person KYC and representativesIdentity evidence must be reliable, current and sufficient to understand who acts, for whom and with what authority.4 items+
Obliged persons must identify customers and maintain current records under supervisor rules.
- Implementation action
- Collect and verify legal name, CPF or official identifier, date of birth, address and risk-relevant occupation or activity using reliable independent evidence.
- Evidence to retain
- Identity record, document or authoritative lookup, verification result, timestamps and refresh history.
- Primary citation
- Law 9,613/1998 art. 10(I); BCB Circular 3,978/2020 arts. 16-19
Representatives and agents must be identified and their authority verified.
- Implementation action
- Verify each representative to natural-person standard, validate the mandate against current corporate or legal evidence and set expiry controls.
- Evidence to retain
- Representative identity, power or mandate, registry check, authority scope, expiry and revocation monitoring.
- Primary citation
- BCB Circular 3,978/2020 arts. 16-18 and 24
Customer qualification must capture information compatible with the relationship and risk.
- Implementation action
- Establish occupation, income or revenue, purpose, expected activity, source of funds where risk requires and update on risk-sensitive triggers.
- Evidence to retain
- Profile, expected-activity baseline, corroboration, risk rating, review schedule and trigger events.
- Primary citation
- BCB Circular 3,978/2020 arts. 18-20
The institution must authenticate remote customers and manage fraud and impersonation risk without weakening AML controls.
- Implementation action
- Layer document, device, biometric or database checks according to risk, test liveness where used and route discrepancies for human review.
- Evidence to retain
- Channel assessment, verification logs, biometric justification, fraud signals, reviewer decision and model testing.
- Primary citation
- BCB Circular 3,978/2020 arts. 16-20; LGPD arts. 6, 11 and 46
04KYB, registries and beneficial ownershipCorporate registration, CNPJ beneficial-owner filing and AML beneficial-owner identification are related but separate controls.4 items+
A legal-entity customer must be identified, qualified and represented through valid constituent and registry information.
- Implementation action
- Verify CNPJ status, legal name, address, activity, legal form, directors and representatives against RFB and the competent commercial registry.
- Evidence to retain
- CNPJ proof, registry extract, constitutional documents, director list, representative authority and reconciliation log.
- Primary citation
- Law 9,613/1998 art. 10(I); BCB Circular 3,978/2020 arts. 16-20
BCB institutions must identify the ownership chain to the beneficial owner and use a policy-defined participation reference no higher than 25%, while also considering control.
- Implementation action
- Trace direct and indirect ownership, voting and other control to natural persons; document the fallback and any impossibility to verify.
- Evidence to retain
- Ownership chart, calculations, control analysis, source documents, beneficial-owner verification and exception approval.
- Primary citation
- BCB Circular 3,978/2020 arts. 24-26
The CNPJ regime separately defines and requires reporting of beneficial owners for covered entities; current IN RFB 2,119 includes more-than-25% ownership or voting rights and other preponderant control.
- Implementation action
- Determine CNPJ filing scope, submit or update the e-BEF within the current timetable and do not substitute the tax filing for AML verification.
- Evidence to retain
- Scope analysis, e-BEF submission, signatures, receipt, annual confirmation and change log.
- Primary citation
- IN RFB 2,119/2022 arts. 53-57, as amended by IN RFB 2,290/2025
Complex structures, trusts, nominees and unexplained ownership require deeper verification and may justify declining or exiting the relationship.
- Implementation action
- Obtain the complete chain, trust roles and economic rationale; resolve bearer, nominee or opaque-jurisdiction risks before approval.
- Evidence to retain
- Structure documents, trust instrument or extracts, role identities, rationale, EDD decision and escalation outcome.
- Primary citation
- BCB Circular 3,978/2020 arts. 24-26 and 39-41; IN RFB 2,119/2022 arts. 53-54
05PEPs, EDD and onboarding decisionsPEP status is a risk factor requiring specific approval and diligence, not an automatic prohibition.4 items+
BCB-regulated institutions must identify Brazilian and foreign PEPs and relevant representatives, family members and close associates under the current rule.
- Implementation action
- Screen at onboarding and periodically, capture the basis and dates, and apply the required post-office lookback.
- Evidence to retain
- Screening result, role source, relationship mapping, dates, disposition and refresh log.
- Primary citation
- BCB Circular 3,978/2020 arts. 27-30
BCB-regulated institutions must adopt controls compatible with PEP status, reflect that status in the customer risk classification, and have a person holding a position or function hierarchically above the relationship authorizer evaluate whether to begin or maintain the relationship.
- Implementation action
- Document the risk rationale and higher-level evaluation, and apply enhanced measures, including source-of-funds or source-of-wealth checks, where justified by risk.
- Evidence to retain
- PEP risk file, higher-level evaluation, wealth or funds evidence where required, monitoring scenario and periodic review.
- Primary citation
- BCB Circular 3,978/2020 arts. 19 and 27-29
Higher-risk customers, products, channels and jurisdictions require enhanced due diligence; lower-risk measures require a documented basis.
- Implementation action
- Define objective escalation and simplification criteria linked to the internal risk assessment and prohibit simplification where suspicion exists.
- Evidence to retain
- Risk rules, EDD or simplified-DD rationale, approvals, test samples and monitoring linkage.
- Primary citation
- BCB Circular 3,978/2020 arts. 10-16 and 39-41; Coaf Resolution 36/2021
Material identity, ownership or purpose doubts must be resolved before relying on the relationship.
- Implementation action
- Pause restricted activity, request reliable corroboration, escalate unresolved cases and assess reporting without tipping off.
- Evidence to retain
- Exception case, requests, response, restriction log, decision, report assessment and exit record.
- Primary citation
- Law 9,613/1998 arts. 10-11; BCB Circular 3,978/2020 arts. 16-20 and 43-48
06Monitoring, suspicious reporting and confidentialityMonitoring must cover completed and attempted activity and preserve the distinction between automated cash reports and suspicion-based communications.4 items+
BCB institutions must select and analyze atypical operations and situations using criteria compatible with their risk assessment.
- Implementation action
- Monitor customer behaviour against the expected profile, aggregate related activity and document the analysis whether or not it results in a report.
- Evidence to retain
- Alert logic, alert history, investigation record, data lineage, decision and quality review.
- Primary citation
- BCB Circular 3,978/2020 arts. 38-47
The analysis period for a selected event may not exceed 45 days under BCB Circular 3,978, and a reportable conclusion must be sent to Coaf by the next business day.
- Implementation action
- Start the regulatory clock at selection, control aging, record the decision time and transmit through Siscoaf by the next business day.
- Evidence to retain
- Selection timestamp, analysis log, decision, Siscoaf receipt and late-case escalation.
- Primary citation
- BCB Circular 3,978/2020 arts. 43 and 48
Law 9,613 requires covered proposals or transactions to be reported to Coaf within 24 hours under the applicable supervisor instructions and prohibits tipping off.
- Implementation action
- Map the exact sector trigger and clock, file confidentially and restrict knowledge of the report to authorized personnel.
- Evidence to retain
- Sector-rule mapping, decision log, filing receipt, access log, confidentiality control and customer-communication review.
- Primary citation
- Law 9,613/1998 art. 11(II)-(III)
A non-occurrence declaration is required at the frequency and through the route specified by the relevant supervisor.
- Implementation action
- Calendar the applicable annual or sector period, validate that no reportable case was omitted and retain the acknowledgement.
- Evidence to retain
- Population reconciliation, officer sign-off, declaration and submission receipt.
- Primary citation
- Law 9,613/1998 art. 11(III); Coaf Resolution 41/2022 arts. 28-29
07Cash, payments, wires and agentsObjective reporting thresholds and payment authorization rules are sector-specific and must not be treated as universal customer limits.4 items+
BCB institutions must report specified cash deposits, withdrawals and provisions of R$50,000 or more to Coaf under Circular 3,978.
- Implementation action
- Detect single and linked qualifying events, capture the required payer, beneficiary, owner and purpose fields and report within the rule's timetable.
- Evidence to retain
- Threshold logic, cash record, party data, purpose, report file and Siscoaf receipt.
- Primary citation
- BCB Circular 3,978/2020 arts. 49-51
Transaction records must identify the parties, amount, date and other information required by the competent authority, including aggregated monthly operations above its fixed limit; BCB transfer records must include the required originator and beneficiary information.
- Implementation action
- Preserve originator, beneficiary, instrument, account, timestamp and linked-transaction data in reconstructable form.
- Evidence to retain
- Transaction record, aggregation output, message fields, exception queue and reconciliation.
- Primary citation
- Law 9,613/1998 art. 10(II)-(III); BCB Circular 3,978/2020 art. 30
Payment institutions must operate only within their permitted modality and obtain BCB authorization when required by the current Resolutions 80 and 81 framework.
- Implementation action
- Classify issuance, acquiring, initiation and account functions; confirm current authorization status and conditions before launch or material change.
- Evidence to retain
- Product classification, authorization, corporate-object check, regulatory correspondence and launch gate.
- Primary citation
- Law 12,865/2013 arts. 6 and 9; BCB Resolutions 80/2021 and 81/2021
Use of correspondents, agents or technology providers does not remove customer, monitoring, reporting or record duties.
- Implementation action
- Apply due diligence, contractual controls, training, monitoring and data-access requirements to every distribution or processing partner.
- Evidence to retain
- Partner file, contract, training, transaction oversight, incidents, audits and termination plan.
- Primary citation
- Law 9,613/1998 arts. 10-11; BCB Circular 3,978/2020 arts. 3-7 and 60-61
08Targeted financial sanctionsUN Security Council measures apply immediately and the statutory standard of without delay means immediately or within hours.4 items+
UN Security Council sanctions resolutions and committee designations have immediate enforceability in Brazil.
- Implementation action
- Screen customers, beneficial owners, representatives and transactions against the current UN list at onboarding, continuously and on list updates.
- Evidence to retain
- List source, update timestamps, screening logs, match rules and coverage tests.
- Primary citation
- Law 13,810/2019 arts. 2(V), 3 and 6-8
A person in Brazil must not make assets available to a designated person or entity, directly or indirectly.
- Implementation action
- Block release and movement of confirmed-match assets immediately, including indirect availability, while preserving funds and audit data.
- Evidence to retain
- Match analysis, freeze timestamp, asset inventory, blocked transactions and control-room log.
- Primary citation
- Law 13,810/2019 arts. 2, 5-8
Law 13,810 requires obliged persons to implement applicable UN asset-freezing measures without delay and without prior notice to the sanctioned person, in the form prescribed by their supervisor. Asset freezes and attempted transfers involving sanctioned persons must be communicated to the Ministry of Justice and Public Security, the relevant supervisor and Coaf.
- Implementation action
- Maintain a tested escalation path to legal, the Ministry, supervisor and Coaf without delaying the freeze.
- Evidence to retain
- Escalation matrix, notifications, receipts, timestamps, legal assessment and follow-up.
- Primary citation
- Law 13,810/2019 arts. 9 and 11
False positives, delisting and permitted-access cases require controlled legal handling rather than unilateral release.
- Implementation action
- Verify identifiers, document the disposition and release or allow access only under the applicable official decision or procedure.
- Evidence to retain
- Identifier comparison, legal decision, authority communication, release approval and customer notice review.
- Primary citation
- Law 13,810/2019 arts. 14-18 and 27-32
09Records, audit and regulator accessRetention starts from the legally specified event and must support prompt reconstruction and production.4 items+
Law 9,613 sets a minimum five-year period from account closure or transaction completion, extendable by the competent authority.
- Implementation action
- Attach the correct closure or completion trigger to each record class and apply longer sector periods where required.
- Evidence to retain
- Retention schedule, trigger fields, legal holds, disposal approvals and deletion logs.
- Primary citation
- Law 9,613/1998 art. 10(2)
BCB Circular 3,978 requires core customer, beneficial-owner, transaction, analysis and communication records to be retained for ten years under its specified triggers.
- Implementation action
- Map each Circular record to its ten-year trigger and make archived evidence searchable and readable.
- Evidence to retain
- Record map, immutable archive, retrieval test, access log and disposal control.
- Primary citation
- BCB Circular 3,978/2020 art. 67
Obliged persons must answer lawful Coaf and supervisor requests in the form and period specified while preserving secrecy.
- Implementation action
- Authenticate requests, collect responsive records, quality-check production and log secure delivery.
- Evidence to retain
- Request, authority check, collection log, production set, approval and receipt.
- Primary citation
- Law 9,613/1998 art. 10(V); BCB Circular 3,978/2020 arts. 60-61
Effectiveness testing must identify weaknesses and drive documented remediation.
- Implementation action
- Independently sample onboarding, ownership, PEP, monitoring, reporting, sanctions and retention controls and verify closure.
- Evidence to retain
- Scope, independence record, samples, findings, action owners, deadlines and closure testing.
- Primary citation
- BCB Circular 3,978/2020 arts. 62-65; Coaf Resolution 36/2021
10Privacy, biometrics and international transfersAML processing must be reconciled with LGPD purpose, necessity, transparency, security and data-subject rights.4 items+
LGPD applies to covered personal-data processing and requires a documented legal basis, purpose limitation, necessity, transparency and accountability.
- Implementation action
- Map every KYC field and processing purpose to an LGPD basis, minimize collection and document statutory-obligation processing separately from consent.
- Evidence to retain
- Data inventory, purpose and basis register, notice, minimization review and rights procedure.
- Primary citation
- LGPD, Law 13,709/2018 arts. 3, 6-7 and 37
Biometric data linked to a natural person is sensitive personal data and must satisfy article 11's stricter grounds and safeguards.
- Implementation action
- Complete a necessity and proportionality assessment, restrict biometric templates, test bias and spoofing controls and provide a safe exception route.
- Evidence to retain
- Sensitive-data basis, assessment, template architecture, access logs, test results and alternative process.
- Primary citation
- LGPD arts. 5(II), 11 and 46
Where a security incident may cause relevant risk or damage to data subjects, the controller must notify ANPD and affected data subjects within three business days, unless specific legislation establishes another period.
- Implementation action
- Record the controller-awareness timestamp, assess relevant risk or damage, and submit the required ANPD and data-subject communications within three business days.
- Evidence to retain
- Security plan, incident register, awareness timestamp, impact assessment, ANPD and data-subject notices, receipts and remediation.
- Primary citation
- LGPD art. 48; Resolution CD/ANPD 15/2024 arts. 6 and 9
International transfers require an LGPD article 33 mechanism and compliance with ANPD Resolution 19/2024, including standard clauses where used.
- Implementation action
- Map every cross-border transfer, select and implement the valid mechanism, update contracts and notices and control onward transfers.
- Evidence to retain
- Transfer register, assessment, contract or standard clauses, notice, vendor diligence and onward-transfer controls.
- Primary citation
- LGPD arts. 33-36; Resolution CD/ANPD 19/2024
11Virtual assets and launch evidenceBrazil now has an operative BCB virtual-asset regime. Existing-provider transition and other financial, securities and exchange rules must be assessed separately.4 items+
Virtual-asset services within Law 14,478 and BCB Resolution 520 may be provided only by an authorized SPSAV or another institution expressly permitted by the BCB framework.
- Implementation action
- Classify each exchange, transfer, custody or financial service, identify any CVM or exchange overlay and obtain the required BCB authorization before operating outside a valid transition.
- Evidence to retain
- Service map, asset classification, legal opinion, application or authorization, restrictions and launch approval.
- Primary citation
- Law 14,478/2022 arts. 3-9; Decree 11,563/2023; BCB Resolution 520/2025 arts. 1-20
An SPSAV carrying on an activity listed in articles 7 or 9 when Resolution BCB 520 entered into force on 2 February 2026 must apply for authorization within 270 days of that date and comply with article 88's transitional conditions and information duties.
- Implementation action
- Calculate the exact deadline, preserve evidence of pre-existing activity, submit under Resolution 519 and track every transition milestone and prudential commencement.
- Evidence to retain
- Transition memo, activity evidence, application receipt, BCB correspondence, milestone tracker and contingency plan.
- Primary citation
- BCB Resolution 520/2025 art. 88; BCB Resolution 519/2025; IN BCB 713/2026
SPSAVs must apply the BCB AML/CFT/CPF framework and maintain governance, customer-protection, security, records and asset-segregation controls.
- Implementation action
- Extend Circular 3,978 controls to virtual-asset data, wallets and counterparties; implement segregation, reconciliation and independent assurance required by Resolution 520.
- Evidence to retain
- AML mapping, wallet screening, travel-data design, segregation policy, reconciliations, proof-of-reserves method and audit.
- Primary citation
- BCB Resolution 520/2025 arts. 29-30 and 85-92; BCB Circular 3,978/2020
A production launch must demonstrate that licensing, KYC/KYB, monitoring, reporting, sanctions, privacy, records and incident controls work end to end.
- Implementation action
- Run controlled dry tests without sending fictional reports to Coaf or BCB, close defects and obtain legal, compliance, privacy, security and product sign-off.
- Evidence to retain
- Completed checklist, source register, test scripts and results, defect closure, approvals and monitoring ownership.
- Primary citation
- Law 9,613/1998 arts. 9-12; BCB Circular 3,978/2020; LGPD arts. 6-7 and 46
Primary-source register
25 sources used for this checklist
Use these links to verify the underlying legislation, regulator guidance, reporting procedures and international status statements.
- Law 9,613/1998 - current consolidated AML lawPresidencia da Republica · Primary legislation
- Coaf duties for obliged personsConselho de Controle de Atividades Financeiras · Official FIU guidance
- Coaf Resolution 36/2021Conselho de Controle de Atividades Financeiras · Primary regulatory instrument
- Coaf Resolution 41/2022Conselho de Controle de Atividades Financeiras · Primary regulatory instrument
- Siscoaf reporting systemConselho de Controle de Atividades Financeiras · Official reporting channel
- BCB Circular 3,978/2020 - current compiled textBanco Central do Brasil · Primary regulatory instrument
- Law 13,810/2019 - UN sanctions implementationPresidencia da Republica · Primary legislation
- UN Security Council Consolidated ListUnited Nations Security Council · Official sanctions list
- IN RFB 2,119/2022 - current annotated CNPJ and beneficial-owner ruleReceita Federal do Brasil · Primary regulatory instrument
- e-BEF beneficial-owner manual v2.0, April 2026Receita Federal do Brasil · Current official registry guidance
- CNPJ consultation serviceReceita Federal do Brasil · Official company register
- Law 12,865/2013 - payment arrangements and institutionsPresidencia da Republica · Primary legislation
- BCB Resolution 80/2021 - payment institutionsBanco Central do Brasil · Primary regulatory instrument
- BCB Resolution 81/2021 - payment authorizationBanco Central do Brasil · Primary regulatory instrument
- Law 14,478/2022 - virtual-asset servicesPresidencia da Republica · Primary legislation
- Decree 11,563/2023 - BCB virtual-asset authorityPresidencia da Republica · Primary decree
- BCB Resolution 519/2025 - SPSAV authorizationBanco Central do Brasil · Primary regulatory instrument
- BCB Resolution 520/2025 - SPSAV operationBanco Central do Brasil · Primary regulatory instrument
- IN BCB 713/2026 - existing SPSAV transition reportingBanco Central do Brasil · Primary regulatory instrument
- LGPD - Law 13,709/2018Presidencia da Republica · Primary legislation
- ANPD international data-transfer regulationAutoridade Nacional de Protecao de Dados · Primary regulatory instrument
- ANPD security-incident communication regulation and official guidanceAutoridade Nacional de Protecao de Dados · Official regulator guidance
- FATF Brazil country and assessment pageFinancial Action Task Force · Official international assessment
- FATF jurisdictions under increased monitoring, 19 June 2026Financial Action Task Force · Official current-status source
- FATF high-risk jurisdictions subject to a call for action, 19 June 2026Financial Action Task Force · Official current-status source
Direct answers
Brazil KYC, KYB and AML questions
Who receives suspicious transaction reports in Brazil?+
Coaf is Brazil's FIU. Obliged persons submit through Siscoaf or the route prescribed by their sector supervisor.
What is the suspicious-reporting deadline?+
Apply the exact sector rule. Law 9,613 uses a 24-hour requirement for covered proposals or transactions; BCB Circular 3,978 requires a report by the next business day after the institution decides to communicate, following an analysis period capped at 45 days.
Is there a universal cash-report threshold?+
No. Threshold reports are sector-specific. BCB Circular 3,978 requires specified cash reports from R$50,000, but other supervisors may define different events and fields.
What beneficial-owner threshold applies?+
The test depends on purpose. BCB institutions set a risk-based reference percentage not above 25% and must consider control. The separate current CNPJ rule uses more than 25% capital or voting rights or other preponderant control for covered entities.
How long are AML records retained?+
Law 9,613 establishes a five-year minimum from account closure or transaction completion and allows extension. BCB Circular 3,978 requires ten years for its principal customer, ownership, transaction, analysis and reporting records under specified triggers.
Are UN sanctions immediately effective?+
Yes. Law 13,810 makes applicable UN Security Council measures immediately enforceable and defines without delay as immediately or within hours.
Does a payment company need BCB authorization?+
Often yes, depending on the modality and current transition. Classify the service under Law 12,865 and the current BCB Resolutions 80 and 81 before operating.
Are virtual-asset providers regulated?+
Yes. Law 14,478 and BCB Resolutions 519 and 520 establish authorization and operating rules. Resolution 520 took effect on 2 February 2026 and includes a 270-day application transition for providers already operating on that date.
Can AML data be processed without LGPD controls?+
No. A legal obligation can support necessary processing, but purpose, necessity, security, transparency, rights handling and transfer controls remain relevant; biometrics receive sensitive-data protection.
Is Brazil on a FATF public list?+
Brazil was not named on the FATF increased-monitoring or call-for-action lists reviewed 1 August 2026. Its FATF/GAFILAT mutual-evaluation findings should still inform country and control risk.
Research and review method
VOVE ID Compliance Research maps the regulatory perimeter, translates obligations into operational controls, links each material claim to a source and records the date and version of every review.
General regulatory information, not legal advice, an authorization decision or a substitute for the operative Portuguese text, sector rules, official reporting manuals or regulator instructions. Reviewed 1 August 2026. Confirm the entity, activity, customer, transaction, reporting route, threshold, transitional status and later developments with qualified Brazilian counsel and the competent authority before launch.