cyberx_
back to indexCompliance & Regulation4 min read

Virtual asset regulation: what changes for compliance

The meaningful shift isn't a new line item on the checklist. It's where the burden sits: what used to be "there was no way to know" becomes "there was a duty to know."

Robert F.
In this article

Much of the debate around virtual asset regulation in Brazil centers on deadlines and on who needs authorization. That's the administrative side, and it matters — but it isn't where the risk lives.

The risk lies in a quiet shift of burden. While the sector was a grey area, "we had no way of knowing where those funds came from" was an explanation. With a defined regime and a designated supervisor, the same sentence stops being an explanation and becomes an admission of control failure.

The turn, in three moves

1. Legal definition. Lei nº 14.478/2022, in force since June 2023, defined what qualifies as a virtual asset and what qualifies as a virtual asset service provider, pulling the sector out of legal informality.

2. Designation of the supervisor. Decreto nº 11.563/2023 assigned the Banco Central the authority to regulate, authorize and supervise service providers — without disturbing the CVM's jurisdiction over what constitutes a security.

3. Concrete rulemaking. In November 2025 the Banco Central published Resoluções BCB nº 519, 520 and 521, effective as of February 2, 2026. They set out who may operate and under what requirements, and bring part of virtual asset activity within the scope of the foreign exchange market.

Taken separately, each step is bureaucratic. Together they produce an effect none of them produces alone: an expected standard of conduct now exists. And where there is an expected standard, the absence of a control stops being a circumstance and becomes non-compliance.

What changes in practice

From declaring to demonstrating. A written policy, annual training and a compliance statement were always the floor. What is now demanded is evidence of application: what the control flagged, what was done about the flag, and why that decision was taken. A control without an audit trail is, for supervisory purposes, a control that never happened.

Know your customer — and your customer's counterparty. Identifying the account holder answers who is operating the account. It says nothing about where the funds came from. With virtual assets, that second question is answerable — the ledger is public — and that is precisely why the answer becomes enforceable.

Data is no longer optional. With part of these operations classified as foreign exchange activity, reporting them to the Banco Central has been mandatory since May 4, 2026. The structural consequence is what matters for compliance: the gap is no longer invisible. When data should have been reported and wasn't, it shows.

Authorization is a gate, not a stamp. The application requirements include fit-and-proper standards for controlling shareholders, minimum capital, and conformity with rules on risk management, cybersecurity and anti-money laundering. Whoever enters the regime accepts being measured against them continuously.

The blind spot

Almost every virtual asset compliance program is built on a screening tool — address in, risk score out. It's necessary, and it's where most programs stop.

What screening does well is answer questions about the address. What it doesn't do is answer questions about the structure: who sits behind it, what other entities share the same behavior, whether that flow has surfaced before under a different name. A clean address and a problematic counterparty coexist without contradiction — and that is exactly where supervisors ask what was done beyond checking the list.

Scale is the other blind spot. Virtual asset transaction volume is incompatible with manual review, and alerts nobody can work through produce the worst outcome of all: the institution knew, documented that it knew, and did nothing. From a liability standpoint, that is worse than never having generated the alert.

What to do before you're asked

  • Map actual exposure, including indirect exposure — clients whose activity involves virtual assets without it appearing in onboarding records
  • Test the audit trail: pick an old alert and try to reconstruct the decision from the record alone. If you can't, the problem already exists today
  • Define escalation criteria — what goes to deep-dive review, who decides, within what timeframe
  • Build deep-dive capacity, in-house or external, for cases screening can't resolve. An alert with nowhere to go becomes an ignored alert
  • Check where your counterparties stand against the authorization deadline, which closes on October 30, 2026 for firms already operating

In one sentence

The regulation doesn't ask for more paperwork. It asks that, when the question comes, an answer exists — and that the answer was recorded before the question was asked.


CyberX works in digital intelligence applied to investigation — OSINT, on-chain tracing and fraud prevention. This content is informational and does not constitute legal advice.

About the author

Robert F.

Robert F. is the founder of CyberX, a digital intelligence operation applied to investigation, based in Brazil with cross-border reach.

He works in OSINT, on-chain tracing and antifraud for legal teams, corporate compliance, banking antifraud and public authorities.

In CyberX publications we write about what can be said in public — fraud and scam typologies, digital threats, on-chain tracing, regulation, and what separates an investigation from a database lookup. Never about ongoing cases, matters under judicial secrecy, clients, or operational detail that would compromise an investigation in progress.

Tags

[AML/CFT][Virtual assets][Central Bank][KYC]

Share