top of page
fnlogo.png

Brazil Introduces 24-Hour Review Period for High-Risk Cryptocurrency Transfers

  • Aug 12
  • 6 min read

Brazil is introducing a new safeguard for cryptocurrency transactions that will require regulated institutions to delay certain outbound virtual asset transfers for 24 hours before allowing them to proceed. The measure, adopted by the Central Bank of Brazil, is designed to give financial institutions additional time to identify potentially fraudulent or illicit transactions before digital assets leave their control and are transferred to foreign platforms or privately controlled wallets. The new requirements will take effect on 1 January 2027.


Brazil Introduces 24-Hour Review Period for High-Risk Cryptocurrency Transfers

The measure forms part of a broader expansion of Brazil's fraud-prevention framework to cover virtual asset services. Under the new rules, institutions providing cryptocurrency-related services, as well as certain other regulated entities processing payments connected to those services, will be required to apply the additional review period in specified circumstances. The framework also covers virtual asset service providers operating under transitional arrangements, preventing firms in the process of adapting to the country's regulatory requirements from falling outside the new controls.


The 24-hour requirement will generally apply to transfers involving virtual asset businesses located outside Brazil and to transfers involving self-custodied wallets. These destinations present particular challenges for financial crime monitoring because once assets leave a regulated Brazilian institution, they can potentially be moved rapidly across additional platforms, jurisdictions or blockchain addresses without the originating institution having practical control over their subsequent movement.


A transaction will automatically fall within the new precautionary mechanism when its value exceeds the equivalent of US$10,000. Importantly, the threshold is not assessed solely on an individual transaction. Transfers made by the same customer during a single day can be aggregated, meaning that a customer cannot necessarily avoid the review requirement simply by dividing a large transaction into multiple smaller transfers.


The rules also establish a broader risk-based trigger. Even where a transfer falls below the US$10,000 threshold, an institution may be required to retain the transaction for review if its internal risk-management framework identifies circumstances warranting further examination. The assessment is expected to consider factors including the customer's risk profile, the nature of the transaction or service, the counterparty and the jurisdiction associated with the recipient.


The new mechanism reflects the speed at which cryptocurrency can move through the financial system. Traditional banking transactions may provide institutions with opportunities to identify unusual activity before funds are settled or transferred internationally. Cryptocurrency transactions, by contrast, can often be executed within minutes, after which assets may be transferred repeatedly between wallets or exchanges. A mandatory review period creates an additional opportunity to investigate suspicious activity before that point is reached.


Particular attention is likely to be required where newly deposited funds are followed almost immediately by an outbound cryptocurrency transfer. Rapid movement does not automatically indicate criminal activity, as legitimate customers may have valid reasons for moving digital assets quickly. However, high transaction velocity can also be associated with layering, account misuse, pass-through activity and attempts to move funds beyond the reach of the institution's controls.


The new framework does not treat every transaction subject to the 24-hour period as suspicious. The retention mechanism is precautionary and does not constitute an asset freeze, confiscation or determination that the customer's funds represent proceeds of crime. Instead, the purpose is to create sufficient time for the institution to assess the transaction and determine whether it should ultimately proceed or be rejected.


During the review period, institutions can examine whether the transaction is consistent with the customer's established profile, expected activity and stated purpose. They may also consider the source of funds, previous account behaviour, the identity and risk profile of the counterparty, the destination jurisdiction and the relationship between recently received funds and the proposed transfer.


The rules expressly cover stablecoins as part of the relevant virtual asset services. This is significant because stablecoins can facilitate rapid transfers of value while maintaining a relatively stable price compared with more volatile cryptocurrencies. Their inclusion ensures that customers cannot avoid the safeguards simply by using digital assets linked to fiat currencies rather than traditional cryptocurrencies.


Customers must be informed when a transaction is retained under the new mechanism. The notification is expected to make clear that the measure is precautionary and specify the applicable retention period. This requirement is intended to distinguish a temporary compliance review from an unexplained restriction on the customer's ability to access or use assets.


Institutions will also have to make a clear decision following the review. Once the prescribed period has expired, the transaction must either be released or rejected. The framework therefore does not permit institutions to leave a transaction indefinitely unresolved under the 24-hour mechanism, although separate regulatory or legal measures may apply if the review identifies evidence requiring further action.


The rules provide some flexibility by allowing institutions to release a transaction before the full 24-hour period has elapsed. However, an early release must be supported by a reasoned decision that takes into account the relevant customer, transaction, counterparty and jurisdictional risks. The decision and the reasoning behind it must be documented and made available to the Central Bank when required.


This exception is likely to create an important governance requirement for cryptocurrency businesses and financial institutions. Firms will need to establish clear internal procedures determining who can approve an early release, what information must be reviewed and what level of evidence is required. Repeatedly releasing transactions early without sufficient justification could undermine the effectiveness of the broader control and expose the institution to supervisory criticism.


The documentation requirements are therefore likely to become a significant part of implementation. Institutions should be able to demonstrate what information was considered, which risk indicators were assessed, who authorised the decision and why the transaction was considered sufficiently low-risk to proceed. Generic records indicating that no concerns were identified may not be sufficient where the regulatory framework requires a reasoned assessment.


The Central Bank also retains the ability to strengthen the restrictions where it identifies weaknesses or non-compliance. This can include extending the retention period beyond 24 hours, applying the mechanism to transactions below the standard monetary threshold or restricting an institution's ability to release transactions early. These powers give the measure a broader supervisory dimension beyond individual customer transactions.


The new requirements do not replace Brazil's existing anti-money laundering and counter-terrorist financing obligations. Customer due diligence, transaction monitoring, sanctions screening, suspicious transaction reporting and other financial crime controls will continue to apply independently. Completing the 24-hour review does not mean that an institution has satisfied its wider AML/CFT responsibilities.


For compliance teams, the practical challenge will be making effective use of the additional time. A delay by itself will not prevent financial crime if institutions lack the information or analytical capabilities required to assess the transaction. Businesses will therefore need reliable customer data, effective transaction monitoring, blockchain analytics, counterparty intelligence and clearly defined escalation procedures.


The aggregation requirement may also require changes to transaction-monitoring systems. Institutions will need to identify related transfers made by the same customer during a single day rather than assessing each instruction independently. This could be particularly important where customers attempt to divide transfers into smaller amounts around the US$10,000 threshold.


Cyprus Company Formation

Lower-value transactions will also require attention where risk-based criteria apply. Repeated deposits followed by immediate transfers, unexplained movements to foreign entities, sudden transfers to self-custodied wallets and transaction activity inconsistent with a customer's established profile may all warrant additional examination. None of these factors independently establishes criminal conduct, but they can contribute to a broader risk assessment.


The Brazilian approach reflects a growing regulatory focus on the speed and portability of digital assets. Rather than attempting to prevent all cryptocurrency transfers, the new framework introduces an intervention point at a particularly sensitive stage: the moment when recently received assets are about to leave the regulated environment.


The effectiveness of the measure will ultimately depend on how institutions implement it. If the 24-hour period is treated simply as an administrative waiting period, its value as a financial crime control will be limited. If institutions use the additional time to conduct structured risk assessments and investigate unusual behaviour, it could provide an important additional layer of protection against fraud, money laundering and other forms of illicit financial activity.


From January 2027, cryptocurrency businesses operating within the scope of the Brazilian framework will therefore need to ensure that their systems, policies and governance arrangements are capable of applying the new requirements consistently. The changes represent a significant development in Brazil's approach to virtual asset regulation and signal a move towards greater scrutiny of rapid cross-border and self-custodied cryptocurrency transfers.

By fLEXI tEAM

Comments


bottom of page