Skip to content
Clav

BCB Resolution 520: a guide to VASP regulation and Banco Central authorization in Brazil

What BCB Resolution 520/2025 requires from crypto exchanges and virtual asset service providers in Brazil: SPSAV types, Banco Central authorization, asset segregation, custody and the 2026 deadlines.

Eduardo de Paiva Gomes

BCB Resolution 520, of 10 November 2025, is the core of crypto regulation in Brazil. It sets who may provide virtual asset services in the country, in which forms, and which governance, security and customer protection rules each provider has to follow. If your company runs an exchange, a crypto custody business or a brokerage serving Brazil, this is the resolution that tells you what must be in place to get authorized by the Banco Central do Brasil (BCB).

This guide summarizes the official text and cites the article behind each rule, as a starting point for teams preparing an authorization application or reviewing their operation. The regulations are published in Portuguese; the quotes below are our translation.

What BCB Resolution 520 is

Its summary is short:

Governs the incorporation and operation of virtual asset service provider companies and the provision of virtual asset services by other institutions authorized to operate by the Banco Central do Brasil.

It implements Law 14,478/2022, Brazil’s legal framework for virtual assets, and Decree 11,563/2023, which gave the Banco Central the power to regulate and supervise the sector. It was published in the Official Gazette (DOU) on 11 November 2025 and took effect on 2 February 2026 (art. 92).

Resolution 520 came out together with two others, each covering part of the subject:

RegulationWhat it governs
BCB Resolution 519/2025Authorization processes for FX brokers, CTVMs, DTVMs and virtual asset service provider companies
BCB Resolution 520/2025Incorporation and operation of providers, and conduct rules
BCB Resolution 521/2025Bringing virtual asset operations into the FX market and foreign capital rules

Normative instructions detailing the procedures followed. The map below shows how the pieces fit together.

How BCB Resolution 520 relates to the other regulations of the sector

What an SPSAV is

The resolution uses SPSAV for the virtual asset service provider company (sociedade prestadora de serviços de ativos virtuais). Under art. 4, SPSAVs are “institutions authorized to operate by the Banco Central do Brasil that provide virtual asset services on behalf of third parties”. The broader term PSAV, the Brazilian equivalent of VASP, also covers already authorized institutions such as banks and brokers when they work with virtual assets (art. 2, XII).

An SPSAV picks one of three types:

The three SPSAV types, arts. 4 to 10

Intermediaries and custodians cannot take on activities of the other type (art. 4, § 2). A company that wants to offer both has to be a virtual asset broker, whose corporate purpose is precisely intermediation and custody (art. 10).

Art. 12 also bars every SPSAV from three things: lending to customers, raising funds from the public (except by issuing shares) and holding stakes in other financial institutions.

Banks and brokers can provide the service too

The SPSAV is not the only way in. Art. 20 allows commercial, FX, investment and multiple banks, Caixa Econômica Federal, securities brokers (CTVMs), securities distributors (DTVMs) and FX brokers to provide intermediation and custody. FX brokers are limited to intermediation.

These institutions do not apply for a new authorization. They file a formal notice with the Banco Central, together with a technical certification issued by a qualified independent firm (arts. 21 and 22). The requirements for that certification are in BCB Normative Instruction 701.

Which path each type of company follows under BCB Resolution 520

Requirements to set up an SPSAV

Art. 14 requires the SPSAV to be a limited liability company or a corporation and to have at least three officers accountable to the Banco Central. They answer for running the business, anti-money laundering, internal controls and compliance, risk and capital management, and the cybersecurity policy and incident response plan. One officer may hold more than one of these roles as long as there is no conflict of interest.

Other incorporation rules:

  • the company name must include “Sociedade Prestadora de Serviços de Ativos Virtuais” (art. 15);
  • the governance policy must be reviewed every two years (art. 16);
  • capital is paid in cash, in full, at once (art. 18).

The authorization application follows the process in BCB Resolution 519. Among other things, it requires financial capacity of the controlling shareholders, lawful origin of funds, an unblemished reputation, adequate technology infrastructure and compliance with minimum capital requirements. Resolution 519 also rules out a coworking space or virtual office as headquarters. The documents for the application are listed in BCB Normative Instruction 704, which BCB NI 739 amended to add a reasonable assurance report on AML/CFT.

Asset segregation and proof of reserves

  • Customers’ money is held in individual payment or deposit accounts (art. 28).
  • Customers’ virtual assets are kept in wallets separate from the provider’s own wallets (art. 29).
  • The segregation policy must include proof of reserves and an independent audit “on a biennial basis, with a reasonable level of assurance”, with the report published on the provider’s website (art. 30, § 1).
  • The provider may keep its own assets in customer wallets only for liquidity, up to 5% of total customer assets (art. 30).
  • Using customer assets in the provider’s own operations is prohibited, except for staking with the express consent of qualified or professional investors (art. 31).

Cybersecurity and AML/CFT

Art. 48 calls for identity and access control, continuous monitoring, vulnerability testing and review by independent analysts, smart contracts included. Art. 49 requires multiple or segmented private keys to be stored in different places.

For anti-money laundering, the provider must monitor sanctions lists and sanctioned wallet addresses (art. 34) and know its customers, partners and outsourced providers (art. 47). Art. 44 sets the travel rule: on transfers, the provider passes the sender’s and recipient’s data to the receiving institution. Rollout happens in stages, and compliance is mandatory from 2 February 2028 (art. 89).

Art. 90 prohibits mechanisms that make it harder to detect crimes, naming mixers, tumblers and bots as examples.

Virtual asset custody

For custodians, the resolution sets out:

  • a custody contract with minimum content, including the use of hot, warm and cold wallets, and an independent audit at least once a year (art. 73);
  • a redundancy mechanism managed in Brazil, with access for the Banco Central (art. 76);
  • stress tests at least once a year, with records kept for five years (art. 82);
  • notice to the Banco Central 90 days before offering staking (art. 82, § 5);
  • rules for using a custodian abroad, which must be authorized and supervised in its own country and have a legal representative in Brazil (art. 83).

Customer protection

Resolution 520 also sets conduct rules toward customers:

  • state whether there is insurance or a guarantee fund, making clear that the FGC deposit guarantee does not apply (arts. 53 and 68);
  • assess the customer’s risk profile and collect a risk acknowledgment when an operation does not fit it (arts. 58 and 59);
  • keep a support channel with the option of a human agent (art. 60);
  • charge fees only for intermediation and custody, disclosed before charging (arts. 61 to 63);
  • explain the security measures and risks when a customer chooses self-custody (art. 57, § 2).

For asset listing, the provider needs a technical committee and a listing and delisting policy (art. 64). Art. 65, § 3, bans offering stablecoins whose reserve asset controls are run by algorithms.

BCB Resolution 520 deadlines for providers already operating

BCB Resolution 520 dates

A company that was already providing virtual asset services when the resolution took effect has 270 days to apply for authorization (art. 88, I), a period that ends on 30 October 2026. In the application it must show that it already complies with the rules on risk management, cybersecurity and cloud contracting, AML, enforcement of sanctions under Law 13,810/2019 and accounting under the Cosif standard (art. 88, II).

Companies that file on time may keep operating until the Banco Central decides, without taking on another type in the meantime (art. 88, § 6). Companies that do not file must stop providing the services within 30 days after the deadline (art. 88, § 7).

From filing until phase 1 is concluded, the provider sends the Banco Central customer data for the national customer registry (CCS), balances and custody positions, proof of reserves and the total allocated to staking (art. 88, III). BCB Resolution 589/2026 adjusted this obligation as of 1 January 2027.

Resolution 589 also changed the date in art. 91. From 6 November 2026, banks, payment institutions and other authorized institutions may not carry out or enable virtual asset market operations with providers that are not authorized to operate in Brazil. In practice, an unauthorized exchange loses access to its banking partners.

Frequently asked questions

Does every crypto exchange need Banco Central authorization?

Yes, if it provides in Brazil the intermediation or custody services covered by the resolution. It has to be an authorized SPSAV or one of the art. 20 institutions that filed the formal notice. A foreign entity that was already operating in Brazil must transfer its operations and customers to one of them within 270 days (art. 23).

What is the deadline to apply for authorization as a VASP?

For companies already operating on 2 February 2026, it is 270 days from that date, until 30 October 2026 (art. 88, I). Companies starting later need authorization before they begin operating (art. 19).

What is the minimum capital for an SPSAV?

BCB Resolution 520 does not set the amounts. BCB Resolution 519 requires compliance with the “minimum capital and equity requirements set out in the regulations in force”, and the figures are in those regulations.

Does Resolution 520 ban transfers to self-custody wallets?

No. It requires the provider to explain the risks when a customer chooses self-custody (art. 57, § 2). The duty to identify the owner of a self-custody wallet came with BCB Resolution 521, in art. 76-A of Resolution 277, and is covered in our article on self-custody wallet verification.

How Clav helps

Clav has BCB Resolution 520 mapped as a compliance framework, with the requirements organized into controls and the evidence each one calls for. The team tracks what is still missing for the authorization application and keeps the history of every submission.

Sources (in Portuguese)