[codicts-css-switcher id=”346″]

Global Law Experts Logo
sbp rule 1-2026 panama

Our Expert in Panama

SBP Rule 1‑2026 (panama): Compliance Officer, MLRO and Fintech Governance Explained

By Global Law Experts
– posted 2 hours ago

Who this guide is for: founders, COOs, heads of compliance, MLRO candidates and in‑house counsel at fintechs and VASPs operating or seeking to operate in Panama. It sets out the actionable steps that would be required to meet the staffing and governance obligations of Panama’s emerging 2026 supervisory framework.

SBP Rule 1-2026 Panama has emerged as a focal point in the compliance conversation for fintechs, virtual asset service providers (VASPs) and payment institutions that fall, or may fall, under the oversight of the Superintendencia de Bancos de Panamá (SBP). The measure is associated with a broader tightening of anti-money-laundering (AML) and counter-terrorist-financing (CTF) governance, including minimum expectations for the appointment of a Compliance Officer and a Money Laundering Reporting Officer (MLRO).

For firms already operating in Panama, and for those preparing licence applications this year, the practical questions are urgent: who must be appointed, can any of these functions be outsourced, and how do the anticipated obligations sit alongside the draft Ley Marco Integral de Tecnologías Financieras (Draft Law No. 314) and the reporting duties owed to Panama’s financial intelligence unit, the Unidad de Análisis Financiero (UAF)? Because both the rule and the draft law are recent and evolving, firms should verify the exact status and text of any instrument directly with the SBP before relying on it. This guide addresses these questions and provides a six-month implementation checklist you can act on today.

TL;DR compliance actions:

  • Confirm whether your entity falls within SBP supervision and therefore within scope of the applicable governance requirements.
  • Appoint (or confirm the appointment of) a Compliance Officer and MLRO with clear reporting lines to the board.
  • Review any outsourcing or group-officer arrangement against regulator expectations on local accountability.
  • Update AML/CTF policies, escalation procedures and the suspicious-transaction reporting workflow that feeds the UAF.
  • Track the progress of Draft Law No. 314 and prepare for anticipated expansion of governance obligations.

What is SBP Rule 1‑2026 and who does it apply to?

SBP Rule 1-2026 Panama is understood to be a supervisory instrument associated with the Superintendencia de Bancos de Panamá aimed at strengthening the AML/CTF governance framework applicable to regulated financial entities. Its central purpose is to raise the operational baseline for how supervised firms identify, manage and report money-laundering and terrorist-financing risk, moving the conversation from written policies to demonstrable, accountable governance roles. Because the exact scope and status of the instrument may be subject to change, firms should locate and read the current published text on the SBP website.

The measure is directed at entities that fall within the SBP’s supervisory perimeter. In practice this includes licensed banks and other entities the SBP supervises, and may extend to fintechs, payment institutions and virtual asset service providers to the extent the SBP exercises oversight over them. The scope question is not academic: whether your business is caught determines whether the appointment, reporting and outsourcing obligations discussed below are mandatory or merely best practice. Founders should confirm their classification early, because the governance build-out described in this guide takes months, not weeks.

Key definitions

Understanding scope depends on how the applicable rules and the surrounding Panamanian framework define the key terms:

  • FinTech. Technology-enabled providers of financial services, payments, lending, wallets and related activities, where the underlying activity brings the firm within a regulated category.
  • VASP. A virtual asset service provider, consistent with the internationally recognised FATF definition, covering exchange, transfer, safekeeping and related services for virtual assets.
  • Payment institution. An entity providing payment services, which may sit within SBP supervision and therefore within the associated governance obligations depending on its licensing and activities.

Effective dates, transitional provisions and enforcement approach

Firms must confirm the effective date and any transitional windows directly from the published text on the SBP site, because these determine hard deadlines for appointments and policy updates. Where a rule of this type provides transitional periods, they are typically used by supervised entities to complete appointments, adopt board-approved policies and remediate gaps identified in a readiness assessment. The likely practical effect, industry observers expect, is a phased supervisory posture in which the SBP first assesses whether the required governance roles exist and function before escalating to sanction for substantive failings. Treat any transitional period as a compliance runway, not a reason to delay.

Appointment requirements, Compliance Officer and MLRO

The heart of a governance-focused rule of this kind is accountability. Supervised fintechs and VASPs should expect to appoint a Compliance Officer and an MLRO (or an equivalent role where the two functions are combined in a smaller organisation), each with a defined mandate, sufficient seniority and a reporting line that reaches the board. The overriding principle is independence: the individuals responsible for detecting and reporting financial crime must be able to escalate concerns without commercial interference.

Compliance Officer, functions, recommended profile and hiring checklist

The Compliance Officer owns the firm’s regulatory compliance framework. Typical functions include maintaining the AML/CTF policy suite, overseeing the risk assessment, coordinating regulatory reporting and acting as the primary point of contact with the SBP.

A workable job-spec for a Panama fintech Compliance Officer includes:

  • Mandate. Design, maintain and test the AML/CTF compliance programme across all products and channels.
  • Reporting line. Direct access to the board or a board committee, with day-to-day liaison to the CEO.
  • Profile. Demonstrable AML/CTF experience, familiarity with SBP and UAF expectations, and standing to challenge senior management.
  • Authority. Power to require information across the business, commission independent testing and halt onboarding where risk is unmanaged.
  • Fit-and-proper. Clean regulatory and criminal record, relevant qualifications and no unmanaged conflicts of interest.

MLRO, duties, reporting processes, independence and escalation

The MLRO is the individual accountable for the detection, investigation and reporting of suspicious activity to the UAF. The MLRO role should be genuinely independent, adequately resourced and able to escalate directly to the board.

Core MLRO duties include:

  • Suspicious transaction reporting. Receive internal alerts, investigate, and file suspicious transaction reports with the UAF where thresholds and indicators are met.
  • Transaction monitoring oversight. Own the monitoring rules, tuning and alert-handling framework.
  • Recordkeeping. Maintain complete investigation and reporting records for the retention periods required by Panamanian law and UAF guidance.
  • Escalation. Report material risks and reporting statistics to the board on a defined cadence.
  • Independence. Freedom from commercial targets that could compromise reporting decisions.

Board oversight and required board/committee responsibilities

Governance accountability does not stop at the officer level. The board retains ultimate responsibility for the firm’s financial-crime risk appetite and the adequacy of its controls. In a compliant fintech, the board approves the AML/CTF policy, receives regular reporting from the Compliance Officer and MLRO, ensures the functions are adequately resourced, and documents its oversight in minutes that a supervisor can inspect. Segregation of duties is essential: the individuals who own revenue must not also own the controls that constrain it. Where a single senior individual carries both compliance and MLRO responsibilities in a smaller firm, the board should document why that arrangement is proportionate and how conflicts are managed.

Outsourcing, shared functions and group officers, regulator expectations

One of the most frequent questions is whether the compliance and MLRO functions can be outsourced or discharged by a group officer sitting outside Panama. The short answer is that outsourcing of tasks is generally possible, but the accountability cannot be exported. Regulators across mature AML regimes expect a locally accountable person and resist sole reliance on a distant group officer who lacks day-to-day visibility of the Panamanian business.

Can the MLRO or compliance function be outsourced?

Practical do’s and don’ts:

  • Do outsource discrete, resource-intensive tasks, such as transaction-monitoring alert triage or independent testing, under a robust contract.
  • Do retain a named, locally accountable officer who owns the reporting relationship with the SBP and UAF.
  • Don’t treat a group MLRO in another jurisdiction as a substitute for local accountability without SBP comfort.
  • Don’t outsource the ultimate decision to file (or not file) a suspicious transaction report without a clear, documented governance chain back to a responsible local person.

Fit‑and‑proper and local residency considerations

Whoever holds the accountable role must satisfy fit-and-proper standards, and supervisors typically favour an individual with genuine presence in, and knowledge of, the Panamanian market. Where a firm relies on a group function, it should be prepared to demonstrate how that officer maintains real oversight of local risks, local customers and local regulatory expectations. Sole reliance on an offshore officer with no local presence is the arrangement most likely to attract regulatory pushback.

Recommended SLA and oversight KPIs

Where any part of the function is outsourced, the service-level agreement should be treated as a control document, not a procurement formality. It should specify monitoring cadence, turnaround times for alert investigation, escalation triggers, reporting templates, audit and inspection rights, data-access guarantees, and the provider’s obligation to cooperate with the SBP and UAF. Oversight KPIs, alert clearance times, report conversion rates, backlog levels and quality-review scores, give the board and the accountable officer the evidence needed to show the arrangement works in practice. This is consistent with FATF guidance, which permits reliance on third parties for AML functions only where the regulated entity retains ultimate responsibility.

Interaction with Draft Law No. 314 and UAF AML obligations

The governance requirements do not operate in isolation. They sit within a shifting legislative landscape and alongside standing obligations owed to the UAF. Firms building a governance framework this year should design it to accommodate both current requirements and the direction of travel signalled by Draft Law No. 314.

Draft Law No. 314, anticipated changes affecting governance and staffing

Draft Law No. 314, the proposed Ley Marco Integral de Tecnologías Financieras, has been introduced in the Asamblea Nacional and is widely expected to formalise and potentially expand the licensing and governance obligations applicable to fintechs and VASPs. Because the draft is not yet enacted, its final scope should be treated as anticipated regulatory expectation rather than settled law. Firms should monitor the official legislative portal for the current text and status. The likely practical effect, early indications suggest, is that a broader set of entity classes will be drawn into formal supervision, reinforcing rather than replacing the governance roles associated with the current supervisory framework.

Building a robust MLRO and Compliance Officer structure now is therefore a sensible hedge against a more demanding statutory regime.

UAF obligations: suspicious transaction reports, KYC and recordkeeping

The UAF is Panama’s financial intelligence unit and the recipient of suspicious transaction reports. Under the country’s AML framework, supervised entities must conduct customer due diligence, monitor transactions, file suspicious transaction reports where suspicion arises and retain records for the periods prescribed in law and UAF guidance. Firms should confirm the exact reporting timelines, thresholds and reporting-form requirements from current UAF and SBP guidance rather than relying on generic figures, and should build these directly into the MLRO’s workflow. The Compliance Officer’s programme and the MLRO’s reporting function are the two operational engines that discharge these UAF duties.

Practical reconciliation: a combined SBP + UAF compliance calendar

The most effective way to manage overlapping obligations is a single compliance calendar that reconciles SBP governance requirements with UAF reporting duties. That calendar should capture board reporting dates, policy-review cycles, independent testing, staff training refreshers, reporting obligations and any periodic returns owed to the SBP. A unified calendar prevents the common failure mode where a firm satisfies one regulator’s expectations while quietly breaching another’s timeline.

Practical implementation, a six‑month checklist

The following month-by-month plan gives founders and COOs a realistic path to compliance. Larger firms may compress it; smaller firms should not over-extend it, because supervisory patience during a transitional period is finite.

  • Months 1–2: Confirm regulatory classification and scope; secure board approval for the AML/CTF governance framework; appoint (or confirm) the Compliance Officer and MLRO; complete fit-and-proper checks.
  • Month 3: Adopt board-approved policies, the enterprise risk assessment and a documented escalation and RACI matrix.
  • Month 4: Stand up or tune transaction monitoring; finalise the reporting workflow feeding the UAF; complete any outsourcing due diligence and sign control-grade SLAs.
  • Month 5: Deliver staff and board training; run a live reporting dry-run and independent testing of key controls.
  • Month 6: Conduct a readiness self-assessment against the applicable SBP requirements; remediate residual gaps; establish the ongoing reporting cadence.

Governance documents to prioritise

Prioritise the documents that a supervisor will ask for first: the board-approved AML/CTF policy, the enterprise-wide risk assessment, the escalation and reporting procedure, the RACI matrix showing who owns each control, and the outsourcing register with associated SLAs. These artefacts are the evidence base that demonstrates your governance is real rather than nominal.

Sample timelines for small, medium and large fintechs

Small fintechs can often combine the Compliance Officer and MLRO roles in one senior hire, provided conflicts are managed and documented and the applicable rules permit it, and can complete the build within four to six months. Medium firms should separate the roles and add dedicated monitoring resource, targeting six months. Large firms and established VASPs typically need a full second-line function, a board committee and independent assurance, and should treat six months as the minimum for a defensible framework.

In‑house MLRO vs outsourced MLRO, trade-offs

Factor In‑house MLRO Outsourced MLRO Recommended mitigant
Regulatory acceptance Strong, local accountability is clear Variable, sole reliance may draw pushback Retain a named local accountable officer
Control over investigations High, direct oversight of cases Lower, dependent on provider process Contractual investigation standards and review rights
Cost Higher fixed cost of a senior hire Potentially lower and scalable Match model to transaction volume and risk
Continuity / availability Key-person risk on leave or exit Provider covers absence Documented deputy and succession plan
Fit-and-proper Directly assessable by the firm and SBP Relies on provider’s vetting Verify provider personnel credentials
Data access Full internal access Requires secure data-sharing Data-access guarantees and security controls in SLA
Management oversight Embedded in governance Needs deliberate oversight structure Board reporting on outsourced KPIs
SLA enforcement Not applicable Depends on contract quality Audit rights, KPIs and termination triggers

A downloadable one-page checklist, “SBP Rule 1‑2026 MLRO & Compliance Officer Checklist,” accompanies this guide for teams working through the build.

Enforcement risk, penalties and regulator engagement

Supervisory attention under the emerging framework is likely to concentrate on the areas where firms most often fall short. Industry observers expect the SBP and UAF to focus on recordkeeping lapses, inadequate or late suspicious transaction reporting, weak transaction-monitoring calibration, and insufficient oversight of outsourced AML functions, the last being a recurring theme in international AML assessments. International assessments of Panama’s AML/CFT regime have historically emphasised the importance of effective supervision and credible enforcement, which reinforces the direction of the current reforms.

Where gaps are identified, the recommended engagement playbook is straightforward: acknowledge the issue promptly, present a clear remediation plan with owners and deadlines, demonstrate board-level oversight of the fix, and evidence the improved control in operation. Regulators generally respond better to a candid, well-governed remediation than to defensiveness. Maintaining an audit-ready evidence trail, policies, minutes, reporting logs and testing results, is the single most valuable protection when the SBP or UAF comes to call. Applicable penalties should be confirmed against the current SBP rules and Panamanian AML legislation, as they vary by breach and entity type.

Templates and job‑spec snippets

The following copy-pasteable snippets help teams stand up documentation quickly. Adapt them to your risk profile and confirm each obligation against the current SBP and UAF texts.

MLRO job-spec bullets:

  • Own the end-to-end suspicious transaction reporting process and file reports with the UAF.
  • Oversee transaction-monitoring rules, tuning and alert investigation.
  • Report reporting statistics and material risks to the board on a defined cadence.
  • Maintain investigation and reporting records for the required retention period.
  • Operate with documented independence from commercial targets.

Compliance Officer job-spec bullets:

  • Maintain and test the AML/CTF policy suite and enterprise risk assessment.
  • Act as primary liaison with the SBP.
  • Coordinate staff and board training.
  • Report programme effectiveness to the board.

Key outsourced-MLRO SLA clauses:

  • Named local accountable officer and defined escalation chain.
  • Investigation turnaround times and monitoring cadence.
  • Audit, inspection and regulator-cooperation rights.
  • Data-access, security and confidentiality guarantees.
  • KPIs, quality-review standards and termination triggers.

Conclusion and next steps

The emerging SBP governance requirements associated with Rule 1-2026 mark a decisive shift from paper policies to accountable governance for fintechs, payment institutions and VASPs under SBP supervision. The firms that fare best in 2026 will be those that appoint a credible Compliance Officer and MLRO now, keep local accountability firmly in Panama even where tasks are outsourced, integrate UAF reporting into a single compliance calendar, and prepare for the broader obligations anticipated under Draft Law No. 314. Use the six-month checklist and the templates in this guide to build a defensible framework, and confirm every prescriptive detail against the current SBP and UAF sources.

For a tailored compliance review, licensing strategy or an outsourcing assessment, Global Law Experts can connect you with specialist Panamanian FinTech counsel. For related reading, see our Panama Fintech Law, Practical Roadmap, our overview for Fintech Lawyers Panama 2026, licensing, SBP Rule 1‑2026, bank access & AML, and the Global Law Experts FinTech practice area.

Need Legal Advice?

This article was produced by Global Law Experts. For specialist advice on this topic, contact Viktor Juskin at LegalBison, a member of the Global Law Experts network.

Sources

  1. Superintendencia de Bancos de Panamá (SBP)
  2. Unidad de Análisis Financiero (UAF), Panama Financial Intelligence Unit
  3. Asamblea Nacional de Panamá, Official legislative portal
  4. Financial Action Task Force (FATF), VASP and MLRO guidance
  5. International Monetary Fund (IMF), Panama AML/CFT country reports

FAQs

What entities must comply with SBP Rule 1‑2026 Panama?
The applicable governance requirements are directed at entities within the SBP’s supervisory perimeter, which includes licensed banks and other supervised entities, and may extend to fintechs, payment institutions and VASPs where the SBP exercises oversight. Firms should confirm their classification against the published text on the Superintendencia de Bancos de Panamá website, because scope determines whether the appointment and reporting obligations are mandatory.
Supervised fintechs and VASPs should expect to appoint an MLRO (or an equivalent role where functions are combined in a smaller firm) with genuine independence and a reporting line to the board. Confirm the precise appointment obligation in the current SBP text; where the rule is silent on a detail, FATF guidance on MLRO independence and minimum functions represents the applicable best practice.
Discrete tasks can be outsourced or supported at group level, but accountability cannot be exported. Regulators generally expect a locally accountable officer and resist sole reliance on a distant group officer. FATF guidance permits reliance on third parties only where the regulated entity retains ultimate responsibility, which in practice means retaining a named, locally accountable person for Panama.
Both roles require relevant AML/CTF experience, a clean regulatory and criminal record, adequate seniority to challenge management, and no unmanaged conflicts of interest. Verify the specific fit-and-proper criteria against the SBP text; FATF standards on competent, independent AML functions inform the underlying expectation.
The MLRO investigates internal alerts and files suspicious transaction reports with the UAF where suspicion arises, using the current UAF forms and within the timelines and thresholds set out in UAF and SBP guidance. Build this workflow into the MLRO function so that the SBP governance obligations and the UAF reporting duties are satisfied through a single, documented process.
Travel Rule expectations for VASP data-sharing derive from FATF standards and are an emerging supervisory focus. Firms should treat originator and beneficiary information-sharing as an anticipated requirement and design controls accordingly, confirming the current position against Panamanian legislation and SBP guidance.
Supervisory focus is expected to fall on recordkeeping lapses, late or inadequate reports, weak monitoring and poor oversight of outsourcing. Confirm applicable penalties from current SBP rules and Panamanian AML legislation, and maintain an audit-ready evidence trail so that any remediation can be presented credibly to the SBP and UAF.

Find the right Legal Expert for your business

The premier guide to leading legal professionals throughout the world

Specialism
Country
Practice Area
LAWYERS RECOGNIZED
0
EVALUATIONS OF LAWYERS BY THEIR PEERS
0 m+
PRACTICE AREAS
0
COUNTRIES AROUND THE WORLD
0
Lawyer Profile Page - Lead Capture
GLE-Logo-White
Lawyer Profile Page - Lead Capture

SBP Rule 1‑2026 (panama): Compliance Officer, MLRO and Fintech Governance Explained

Send welcome message

Custom Message