Our Expert in Panama
No results available
Who this guide is for: founders, COOs, heads of compliance, MLRO candidates and in‑house counsel at fintechs and VASPs operating or seeking to operate in Panama. It sets out the actionable steps that would be required to meet the staffing and governance obligations of Panama’s emerging 2026 supervisory framework.
SBP Rule 1-2026 Panama has emerged as a focal point in the compliance conversation for fintechs, virtual asset service providers (VASPs) and payment institutions that fall, or may fall, under the oversight of the Superintendencia de Bancos de Panamá (SBP). The measure is associated with a broader tightening of anti-money-laundering (AML) and counter-terrorist-financing (CTF) governance, including minimum expectations for the appointment of a Compliance Officer and a Money Laundering Reporting Officer (MLRO).
For firms already operating in Panama, and for those preparing licence applications this year, the practical questions are urgent: who must be appointed, can any of these functions be outsourced, and how do the anticipated obligations sit alongside the draft Ley Marco Integral de Tecnologías Financieras (Draft Law No. 314) and the reporting duties owed to Panama’s financial intelligence unit, the Unidad de Análisis Financiero (UAF)? Because both the rule and the draft law are recent and evolving, firms should verify the exact status and text of any instrument directly with the SBP before relying on it. This guide addresses these questions and provides a six-month implementation checklist you can act on today.
TL;DR compliance actions:
SBP Rule 1-2026 Panama is understood to be a supervisory instrument associated with the Superintendencia de Bancos de Panamá aimed at strengthening the AML/CTF governance framework applicable to regulated financial entities. Its central purpose is to raise the operational baseline for how supervised firms identify, manage and report money-laundering and terrorist-financing risk, moving the conversation from written policies to demonstrable, accountable governance roles. Because the exact scope and status of the instrument may be subject to change, firms should locate and read the current published text on the SBP website.
The measure is directed at entities that fall within the SBP’s supervisory perimeter. In practice this includes licensed banks and other entities the SBP supervises, and may extend to fintechs, payment institutions and virtual asset service providers to the extent the SBP exercises oversight over them. The scope question is not academic: whether your business is caught determines whether the appointment, reporting and outsourcing obligations discussed below are mandatory or merely best practice. Founders should confirm their classification early, because the governance build-out described in this guide takes months, not weeks.
Understanding scope depends on how the applicable rules and the surrounding Panamanian framework define the key terms:
Firms must confirm the effective date and any transitional windows directly from the published text on the SBP site, because these determine hard deadlines for appointments and policy updates. Where a rule of this type provides transitional periods, they are typically used by supervised entities to complete appointments, adopt board-approved policies and remediate gaps identified in a readiness assessment. The likely practical effect, industry observers expect, is a phased supervisory posture in which the SBP first assesses whether the required governance roles exist and function before escalating to sanction for substantive failings. Treat any transitional period as a compliance runway, not a reason to delay.
The heart of a governance-focused rule of this kind is accountability. Supervised fintechs and VASPs should expect to appoint a Compliance Officer and an MLRO (or an equivalent role where the two functions are combined in a smaller organisation), each with a defined mandate, sufficient seniority and a reporting line that reaches the board. The overriding principle is independence: the individuals responsible for detecting and reporting financial crime must be able to escalate concerns without commercial interference.
The Compliance Officer owns the firm’s regulatory compliance framework. Typical functions include maintaining the AML/CTF policy suite, overseeing the risk assessment, coordinating regulatory reporting and acting as the primary point of contact with the SBP.
A workable job-spec for a Panama fintech Compliance Officer includes:
The MLRO is the individual accountable for the detection, investigation and reporting of suspicious activity to the UAF. The MLRO role should be genuinely independent, adequately resourced and able to escalate directly to the board.
Core MLRO duties include:
Governance accountability does not stop at the officer level. The board retains ultimate responsibility for the firm’s financial-crime risk appetite and the adequacy of its controls. In a compliant fintech, the board approves the AML/CTF policy, receives regular reporting from the Compliance Officer and MLRO, ensures the functions are adequately resourced, and documents its oversight in minutes that a supervisor can inspect. Segregation of duties is essential: the individuals who own revenue must not also own the controls that constrain it. Where a single senior individual carries both compliance and MLRO responsibilities in a smaller firm, the board should document why that arrangement is proportionate and how conflicts are managed.
One of the most frequent questions is whether the compliance and MLRO functions can be outsourced or discharged by a group officer sitting outside Panama. The short answer is that outsourcing of tasks is generally possible, but the accountability cannot be exported. Regulators across mature AML regimes expect a locally accountable person and resist sole reliance on a distant group officer who lacks day-to-day visibility of the Panamanian business.
Practical do’s and don’ts:
Whoever holds the accountable role must satisfy fit-and-proper standards, and supervisors typically favour an individual with genuine presence in, and knowledge of, the Panamanian market. Where a firm relies on a group function, it should be prepared to demonstrate how that officer maintains real oversight of local risks, local customers and local regulatory expectations. Sole reliance on an offshore officer with no local presence is the arrangement most likely to attract regulatory pushback.
Where any part of the function is outsourced, the service-level agreement should be treated as a control document, not a procurement formality. It should specify monitoring cadence, turnaround times for alert investigation, escalation triggers, reporting templates, audit and inspection rights, data-access guarantees, and the provider’s obligation to cooperate with the SBP and UAF. Oversight KPIs, alert clearance times, report conversion rates, backlog levels and quality-review scores, give the board and the accountable officer the evidence needed to show the arrangement works in practice. This is consistent with FATF guidance, which permits reliance on third parties for AML functions only where the regulated entity retains ultimate responsibility.
The governance requirements do not operate in isolation. They sit within a shifting legislative landscape and alongside standing obligations owed to the UAF. Firms building a governance framework this year should design it to accommodate both current requirements and the direction of travel signalled by Draft Law No. 314.
Draft Law No. 314, the proposed Ley Marco Integral de Tecnologías Financieras, has been introduced in the Asamblea Nacional and is widely expected to formalise and potentially expand the licensing and governance obligations applicable to fintechs and VASPs. Because the draft is not yet enacted, its final scope should be treated as anticipated regulatory expectation rather than settled law. Firms should monitor the official legislative portal for the current text and status. The likely practical effect, early indications suggest, is that a broader set of entity classes will be drawn into formal supervision, reinforcing rather than replacing the governance roles associated with the current supervisory framework.
Building a robust MLRO and Compliance Officer structure now is therefore a sensible hedge against a more demanding statutory regime.
The UAF is Panama’s financial intelligence unit and the recipient of suspicious transaction reports. Under the country’s AML framework, supervised entities must conduct customer due diligence, monitor transactions, file suspicious transaction reports where suspicion arises and retain records for the periods prescribed in law and UAF guidance. Firms should confirm the exact reporting timelines, thresholds and reporting-form requirements from current UAF and SBP guidance rather than relying on generic figures, and should build these directly into the MLRO’s workflow. The Compliance Officer’s programme and the MLRO’s reporting function are the two operational engines that discharge these UAF duties.
The most effective way to manage overlapping obligations is a single compliance calendar that reconciles SBP governance requirements with UAF reporting duties. That calendar should capture board reporting dates, policy-review cycles, independent testing, staff training refreshers, reporting obligations and any periodic returns owed to the SBP. A unified calendar prevents the common failure mode where a firm satisfies one regulator’s expectations while quietly breaching another’s timeline.
The following month-by-month plan gives founders and COOs a realistic path to compliance. Larger firms may compress it; smaller firms should not over-extend it, because supervisory patience during a transitional period is finite.
Prioritise the documents that a supervisor will ask for first: the board-approved AML/CTF policy, the enterprise-wide risk assessment, the escalation and reporting procedure, the RACI matrix showing who owns each control, and the outsourcing register with associated SLAs. These artefacts are the evidence base that demonstrates your governance is real rather than nominal.
Small fintechs can often combine the Compliance Officer and MLRO roles in one senior hire, provided conflicts are managed and documented and the applicable rules permit it, and can complete the build within four to six months. Medium firms should separate the roles and add dedicated monitoring resource, targeting six months. Large firms and established VASPs typically need a full second-line function, a board committee and independent assurance, and should treat six months as the minimum for a defensible framework.
| Factor | In‑house MLRO | Outsourced MLRO | Recommended mitigant |
|---|---|---|---|
| Regulatory acceptance | Strong, local accountability is clear | Variable, sole reliance may draw pushback | Retain a named local accountable officer |
| Control over investigations | High, direct oversight of cases | Lower, dependent on provider process | Contractual investigation standards and review rights |
| Cost | Higher fixed cost of a senior hire | Potentially lower and scalable | Match model to transaction volume and risk |
| Continuity / availability | Key-person risk on leave or exit | Provider covers absence | Documented deputy and succession plan |
| Fit-and-proper | Directly assessable by the firm and SBP | Relies on provider’s vetting | Verify provider personnel credentials |
| Data access | Full internal access | Requires secure data-sharing | Data-access guarantees and security controls in SLA |
| Management oversight | Embedded in governance | Needs deliberate oversight structure | Board reporting on outsourced KPIs |
| SLA enforcement | Not applicable | Depends on contract quality | Audit rights, KPIs and termination triggers |
A downloadable one-page checklist, “SBP Rule 1‑2026 MLRO & Compliance Officer Checklist,” accompanies this guide for teams working through the build.
Supervisory attention under the emerging framework is likely to concentrate on the areas where firms most often fall short. Industry observers expect the SBP and UAF to focus on recordkeeping lapses, inadequate or late suspicious transaction reporting, weak transaction-monitoring calibration, and insufficient oversight of outsourced AML functions, the last being a recurring theme in international AML assessments. International assessments of Panama’s AML/CFT regime have historically emphasised the importance of effective supervision and credible enforcement, which reinforces the direction of the current reforms.
Where gaps are identified, the recommended engagement playbook is straightforward: acknowledge the issue promptly, present a clear remediation plan with owners and deadlines, demonstrate board-level oversight of the fix, and evidence the improved control in operation. Regulators generally respond better to a candid, well-governed remediation than to defensiveness. Maintaining an audit-ready evidence trail, policies, minutes, reporting logs and testing results, is the single most valuable protection when the SBP or UAF comes to call. Applicable penalties should be confirmed against the current SBP rules and Panamanian AML legislation, as they vary by breach and entity type.
The following copy-pasteable snippets help teams stand up documentation quickly. Adapt them to your risk profile and confirm each obligation against the current SBP and UAF texts.
MLRO job-spec bullets:
Compliance Officer job-spec bullets:
Key outsourced-MLRO SLA clauses:
The emerging SBP governance requirements associated with Rule 1-2026 mark a decisive shift from paper policies to accountable governance for fintechs, payment institutions and VASPs under SBP supervision. The firms that fare best in 2026 will be those that appoint a credible Compliance Officer and MLRO now, keep local accountability firmly in Panama even where tasks are outsourced, integrate UAF reporting into a single compliance calendar, and prepare for the broader obligations anticipated under Draft Law No. 314. Use the six-month checklist and the templates in this guide to build a defensible framework, and confirm every prescriptive detail against the current SBP and UAF sources.
For a tailored compliance review, licensing strategy or an outsourcing assessment, Global Law Experts can connect you with specialist Panamanian FinTech counsel. For related reading, see our Panama Fintech Law, Practical Roadmap, our overview for Fintech Lawyers Panama 2026, licensing, SBP Rule 1‑2026, bank access & AML, and the Global Law Experts FinTech practice area.
This article was produced by Global Law Experts. For specialist advice on this topic, contact Viktor Juskin at LegalBison, a member of the Global Law Experts network.
posted 5 minutes ago
posted 26 minutes ago
posted 39 minutes ago
posted 1 hour ago
posted 3 hours ago
posted 4 hours ago
posted 4 hours ago
posted 4 hours ago
posted 5 hours ago
posted 5 hours ago
posted 6 hours ago
posted 6 hours ago
No results available
Find the right Legal Expert for your business
Send welcome message