2026-07-16

Added · Updated

Regulation of Virtual Asset Service Providers (VASPs)

The Superintendent of Financial Services adopted Resolution SSF No. 2026-444 to incorporate Title VII Ter into the Securities Market Regulations, establishing a regulatory framework for virtual asset service providers (VASPs). The resolution defines VASPs as legal entities providing services such as exchange, transfer, or custody of virtual assets and requires prior authorization from the regulator. It mandates specific organizational structures, prudential requirements, consumer protection measures, cybersecurity standards, and anti-money laundering protocols for these entities.

Banco Central del Uruguay logo

Uruguay

Banco Central del Uruguay

Click to view thumbnail

1 Montevideo, July 16, 2026 Ref: SECURITIES MARKET REGULATIONS - Regulation of Virtual Asset Service Providers (VASPs). The market is informed that the Superintendent of Financial Services adopted Resolution SSF No. 2026-444 on July 10, 2026. 2025-50-1-02290 Diagonal Fabini 777 - C.P. 11100 - Tel.: (598 2) 1967 - Montevideo, Uruguay - www.bcu.gub.uy JUAN PEDRO CANTERA Superintendent of Financial Services CIRCULAR NO. 2507

SUPERINTENDENCY OF FINANCIAL SERVICES – RESOLUTION SUPERINTENDENCY OF FINANCIAL SERVICES VISTO: The initiative included by the Superintendent of Financial Services in the Annual Regulatory Plan defined for the years 2025 and 2026 with the objective of regulating the activity of virtual asset service providers. RESULTING: I) That Article 1 of Law No. 20.345 of September 19, 2024 modified letter H) of Article 37 of Law No. 16.696 of March 30, 1995 (Organic Charter of the Central Bank of Uruguay) incorporating as a new entity part of the financial system the providers of services on virtual assets, among which are those that are defined as financial by the banking regulation. II) That said Article 1 provided that the Superintendent of Financial Services will also regulate and control the activity of those entities that provide virtual asset buy/sell services included in the definition adopted for this purpose by the Central Bank of Uruguay. III) That in this framework, the Superintendent of Financial Services drafted a regulatory project that was put out for public consultation by supervised institutions and the general public on August 21, 2025, granting a period to formulate comments that expired on September 19, 2025. IV) That comments were received from the following institutions: Banco de la República Oriental del Uruguay, Blockchain Chamber of Uruguay, Uruguayan Fintech Chamber, Digital Currencies Governance Group, Ferrere Law Firm, Marcelo Birenbaum, Minos Uruguay, Nexchange, Binance, Pala Blockchain, Ripio Uruguay and UFEX Stock Exchange S.A. V) That on December 16, 2025, Law No. 20.446 was promulgated which through Article 693 introduced modifications to said Article 37 of Law No. 16.696, in the wording given by Article 1° of Law No. 20.345. VI) That the modification redefined the scope of these supervised entities eliminating the distinction between those providers that provide services on virtual assets defined as financial by the banking regulation (letter H) and those entities that provide buy/sell services on non-financial virtual assets (numeral III), leaving all virtual asset service providers included under letter H) of said Article 37, generally. VII) That, in accordance with what is established in the referred Law and considering the comments received in the public consultation, a new regulatory proposal was elaborated that establishes the regulatory framework for the operation of virtual asset service providers, considering in this category those legal entities that, habitually and professionally, provide one or more of the following services: a) exchange between virtual assets and fiat currencies; b) exchange between one or more virtual assets; c) transfer of virtual assets; d) custody, administration or other means that allow control over virtual assets; e) participation and provision of financial services related to the offer or sale of virtual assets by an issuer, for example, through platforms and/or mobile applications. VIII) That, while the regulatory and supervisory focus of this new figure centers both on consumer protection and on the prevention of money laundering, terrorist financing and the financing of the proliferation of weapons of mass destruction, the proposal establishes the conditions for its authorization and withdrawal, sets prudential requirements and specific guidelines to guarantee technological security and the proper functioning of operating systems, determines the conditions for customer relations, stipulates transparency rules and corporate governance practices, establishes rules for the prevention of money laundering, terrorist financing and the financing of the proliferation of weapons of mass destruction, provides information requirements and imposes a sanctioning regime. IX) That the projected regulation expressly excludes from its scope of application mere participation in the development of a computer program – without actively involving oneself in the provision of the service – and those activities that are carried out using book-entry securities with decentralized registration, electronic money or any other representation of assets whose issuance, registration, negotiation or settlement is provided for in special laws or regulations. X) That the modifications introduced motivated the need to carry out a second public consultation on March 16, 2026, granting interested parties a period to formulate comments that expired on April 13, 2026. XI) That in this instance comments were received from the following institutions: Blockchain Chamber of Uruguay (CBU), Uruguayan Fintech Chamber (CUF), Digital Currencies Governance Group (DCGG), Ripio Uruguay, Minos Uruguay (Minos) and Belo App (Belo). CONSIDERING: I) That the need has been evidenced to have a robust regulatory framework that – attending international standards – provides legal certainty to the virtual asset industry, establishing prudential requirements, information provision and cybersecurity requirements, as well as those related to consumer protection and to the prevention of money laundering, terrorist financing and the financing of the proliferation of weapons of mass destruction. II) That the projected regulatory framework seeks to favor technological innovation and fair competition among the different actors in the market guaranteeing, at the same time, the protection of those who operate with these virtual assets and ensuring the mitigation of risks. III) That, given the high volatility of this type of asset, which can generate significant gains in short periods of time, as well as the loss of a large part or even the total amounts involved, it is indispensable to establish an adequate information system so that those who operate with them are aware of the risks they represent. IV) That it is also essential to guarantee technological security and the proper functioning of operating systems, especially providing for their rapid recovery from incidents and vulnerabilities and allowing services to be provided effectively and smoothly preserving the confidence of consumers and the market. V) That it is recognized that the provisions established in this regulation constitute an initial framework that may be adapted and complemented based on the advances registered in the sector and the experience in the application of this rule. VI) That, based on this, it is foreseen that the dynamics and growth of this sector will import the need to review and, if necessary, periodically update the provisions contained in this regulation, in order to guarantee effective, efficient, equitable and adaptable regulation to the changes and challenges that arise in the field of operation of virtual asset service providers. VII) That the comments received from the industry contributed elements that allowed improving the original proposal, corroborating the value that the consultation process has for the regulator. ATTENTIVE: To what is disposed in Articles 37 and 38 of Law No. 16.696 of March 30, 1995 in the wording given by Articles 693 and 694 of Law No. 20.446 of December 16, 2025, respectively and the proceedings in file 2025-50-1-02290. THE SUPERINTENDENT OF FINANCIAL SERVICES RESOLVES:

  1. INCORPORATE into Book I - AUTHORIZATIONS AND REGISTERS of the Securities Market Regulations Title VII Ter - VIRTUAL ASSET SERVICE PROVIDERS.
  2. INCORPORATE into Title VII Ter - VIRTUAL ASSET SERVICE PROVIDERS of Book I - AUTHORIZATIONS AND REGISTERS of the Securities Market Regulations CHAPTER I – DEFINITIONS AND APPLICABLE REGIME, which will contain the following articles: ARTICLE 127.22 (VIRTUAL ASSET SERVICE PROVIDERS). Virtual asset service providers are considered those legal entities that, habitually and professionally, provide one or more of the following services: a. exchange between virtual assets and fiat currencies; b. exchange between one or more virtual assets; c. transfer of virtual assets; d. custody, administration or other means that allow control over virtual assets; e. participation and provision of financial services related to the offer or sale of virtual assets by an issuer, for example, through platforms and/or mobile applications. These activities will also be considered included when carried out through protocols that allow them to be performed directly between users through smart contracts. Providers will require prior authorization from the Superintendent of Financial Services to function, and must communicate which of the activities established in letters a. to e. they will effectively develop. If, after the granting of the authorization, they decide to incorporate a new activity, they must communicate this to the aforementioned Superintendent with at least 10 (ten) days' notice before the start of the corresponding activity. In the case of the services referred to in letter d., they must also comply with what is provided in Article 151.1.8. The following will not be considered within the activities that require the request for authorization as a virtual asset service provider:
  • mere participation in the development of a computer program without actively involving oneself in the provision of the service;
  • activities that are carried out using book-entry securities with decentralized registration, electronic money or any other representation of assets whose issuance, registration, negotiation or settlement is provided for in special laws or regulations, governing for these cases the specific regulations in the matter.
  • the provision of services through which non-fungible virtual assets are used exclusively, except that said assets are used as a means of payment, investment instrument, or digital representation of a security. ARTICLE 127.23 (LEGAL NATURE). Virtual asset service providers must organize themselves as commercial societies under any of the social types provided for in Law No. 16.060 of September 4, 1989, its amendments and concordant laws, in Law No. 19.820 of September 18, 2019 and its amendments, or as branches of societies constituted abroad. ARTICLE 127.24 (PRINCIPLES OF ACTION). Virtual asset service providers, in the development of the activities referred to in Article 127.22, must:
  • act with loyalty and commercial ethics;
  • adhere to the good practices established in Article 208.2 and to the ethics principles set forth in Article 250;
  • formalize their relationship with clients through contracts in the terms of Article 208.10 when providing the services referred to in letters d. or e. of Article 127.22;
  • obtain – regarding each of their clients – the information that allows elaborating the profile that best adapts to their objectives and needs, according to what is provided in Article 213.2., when providing administration services or other means that allow control over virtual assets.
  • refrain from offering virtual assets, services, tools or mechanisms designed to hinder the identification of the origin and destination of transactions, to the detriment of financial traceability and anti-money laundering policies, terrorist financing and the financing of the proliferation of weapons of mass destruction. ARTICLE 127.25 (PROHIBITED OPERATIONS). Virtual asset service providers may not: a. carry out, with virtual assets, any activity that implies financial intermediation in the terms of Decree-Law No. 15.322 of September 17, 1982 and amendments. b. dispose of or make use of the virtual assets they custodian or administer, without express authorization from the client.
  1. INCORPORATE into Title VII Ter - VIRTUAL ASSET SERVICE PROVIDERS of Book I - AUTHORIZATIONS AND REGISTERS of the Securities Market Regulations CHAPTER II – AUTHORIZATION TO FUNCTION, which will contain the following articles: ARTICLE 127.26 (AUTHORIZATION). For the purposes of granting the prior authorization to function referred to in Article 127.22, the Superintendent of Financial Services will take into account reasons of legality, opportunity and convenience. The person exercising effective control must satisfy the following conditions:
  2. must not be linked to activities that could generate a conflict of interest with the activity intended to be developed.
  3. have seniority and reputation in the businesses developed by the institution. In the case of legal entities, it will be valued that no significant organic or inorganic growth (by acquisitions) has occurred in the immediate past. In case the person exercising effective control is a financial institution or, if not, is part of an economic group which is integrated by some financial institution, the following conditions must also be met:
  4. have implemented policies and procedures to prevent being used in money laundering, terrorist financing and the financing of the proliferation of weapons of mass destruction.
  5. their country of origin must belong to the Financial Action Task Force (FATF) or other similar regional bodies.
  6. there must be a Memorandum of Understanding between the supervisor of origin of the person exercising effective control and the Superintendent of Financial Services or, failing that, a degree of collaboration that the latter considers satisfactory between both supervisors.
  7. consolidated supervision must be exercised by the supervisor of the country. Likewise, the following will be valued:
  8. the policies to prevent being used in money laundering, terrorist financing and the financing of the proliferation of weapons of mass destruction of the country of origin of the financial institution exercising effective control.
  9. its risk rating, which must have been granted by a recognized international rating agency. In case the person exercising effective control has its share package atomized in such a way that no shareholder owns more than 5% (five percent) of it, the competent body for decision-making must be identified. In this case, the following will also be valued:
  10. the manner in which this takes decisions.
  11. the information established in Article 127.29 regarding the members of said body. ARTICLE 127.27 (MINIMUM INFORMATION REQUIRED). The application for authorization to function as a virtual asset service provider must be accompanied by the following information: a. Company name, indicating trade name, fictitious name – if applicable – real and constituted domicile and domicile of each of the dependencies, if any, telephone, email address, website, registration number in the Single Tax Register of the General Directorate of Taxes and in the corresponding social security body. b. Statutes or social contract. c. Identifying data of the legal representatives of the society (full name, nationality, identity document and domicile). d. List of partners or shareholders and persons exercising effective control of the group, identifying data, capital to be contributed and percentage of participation, accompanied by the information requested in Article 127.28. e. List of senior personnel according to the definition established in Article 143, accompanied by the information required by Article 127.29. f. List of members of the economic group to which the society belongs, according to the definition established in Article 142, including description of the activities developed by them, operational and commercial links with the provider, as well as detail of their websites, if any. g. Accounting statements corresponding to the last closed exercise formulated according to adequate accounting standards in Uruguay with Compilation Report, duly signed and with the corresponding professional stamps. h. Sworn declaration of the legitimate origin of the capital, subscribed by each shareholder, in the terms of Article 310.33, manual of the integral system to prevent being used in money laundering, terrorist financing and the financing of the proliferation of weapons of mass destruction and designation of the Compliance Officer, in the terms established in Book III. i. Accreditation that the managers, executives and senior personnel of the provider have the training required in Article 214.1. j. Detailed description of the activity to be developed (indicating whether it will be oriented to residents, non-residents or both) as well as the procedures established to carry out its activities, of the organizational infrastructure (with description of tasks and positions). k. Defined safeguard policy, business continuity plan and disaster recovery plan. l. Detail of the computer systems that will be used for the development of its activities, according to what is provided in Chapter VI of this Title. A description of the operating platforms that will be used must be presented, specifying whether they are national or foreign. In the latter case, the following information must be presented:
  • control body of said platforms;
  • operational and security control procedures available;
  • model contracts to be signed with the owners of said platforms m. Model contracts to be signed with clients. n. Description of third-party services that are essential for the company's entry into operation. When it comes to services provided by third parties located outside the country or in the country, but the service is provided totally or partially in or from abroad, the contract to be signed with the outsourced company and the risk assessment provided in numeral 1) of Article 127.40 must be presented. o. Code of Good Practices, according to what is provided by Article 208.4. p. Code of Ethics, according to what is provided in Article 252. q. For those virtual asset service providers that provide the services referred to in letter d. of Article 127.22, accreditation of the integration of the minimum equity referred to in Article 151.1.8. This integration will be accredited by presenting the accounting statements referred to the close of the month prior to the start of activities as a provider, formulated according to adequate accounting standards in Uruguay, with Compilation Report. In case it is necessary to make new capital contributions, the following must be presented:
  • detail of the capital contributed
  • sworn declaration of the legitimate origin of the capital, in the terms of Article 310.33
  • authenticated copy of the resolution adopted by the Assembly of partners or shareholders in which the new capital contribution was resolved. r. Accreditation of the constitution of real guarantees in favor of the Central Bank of Uruguay, for eventual obligations that it might assume with said Body or with third parties in the exercise of its RR-SSF-2026-444 Date: 07/10/2026 16:00:25 CIRCULAR NO. 2507

activity, as referred to in Article 151.1.9, as well as a deposit at the Central Bank of Uruguay under the terms of Article 151.1.11.

If deemed necessary, the Superintendency of Financial Services may request additional information beyond that indicated above, with the formalities it deems appropriate.

No application will be processed if it is not accompanied by all the documentation required by the preceding letters a. through o. To grant the authorization, it will be required to have demonstrated compliance with the preceding letters p. (if applicable) and q.

If the company is organized as a branch of a society incorporated abroad, it must include, in addition to what is established above, the following:

  1. Capital to be assigned to the branch.
  2. Note by which the supervisory bodies of the parent company establish that they have no objections to the installation of a branch in Uruguay and the type of supervision exercised, clarifying whether it is consolidated supervision.
  3. Certified copy of the resolution of the competent social authority where the decision to open the branch in Uruguay is recorded, the indication of the place where it will establish its domicile in Uruguay, the designation of the person or persons who will administer or represent it, and the determination of the capital to be assigned to the branch.
  4. Certificate of definitive registration in the Commercial Registry under the terms of Article 193 of Law 16.060 of September 4, 1989, and publications.
  5. Report and financial statements corresponding to the last 3 (three) closed economic years, with an external auditor's report from the society incorporated abroad of which it is a branch.

TRANSITIONAL PROVISION: Virtual asset service providers may apply for authorization to operate starting from September 1, 2026.

As for those already in activity, they will have from September 1, 2026, to March 31, 2027, to apply for the aforementioned authorization to operate. These companies may continue to operate while the application is being processed.

ARTICLE 127.28 (INFORMATION ON PARTNERS OR SHAREHOLDERS).

When applying for authorization to operate, virtual asset service providers must inform the name of their direct partners or shareholders and the persons who exercise control of the society, attaching the following information and documentation:

RR-SSF-2026-444 Date: 10/07/2026 16:00:25 CIRCULAR N°2507

I. Natural Persons:

a. The same information required for senior management by Article 127.29. b. Documentation that demonstrates compliance with items 1. and 2. of Article 127.26, as applicable.

II. Legal Entities:

a. Statutes or social contract. b. When dealing with foreign institutions: b.1 Sworn declaration of the foreign institution, with notarized certification of signature and representation, explicitly stating the control and supervisory bodies of the country of origin that have jurisdiction over the shareholder society. b.2 Certificate issued by the competent authority of the country of origin or a notarial certificate that demonstrates that the shareholder society is legally incorporated and that, in accordance with the legislation of said country, there are no restrictions or prohibitions for such societies to participate as partners, founders, or shareholders of other societies incorporated or to be incorporated in the country or abroad. In said certificate, the tax or registry number of the foreign legal entity must be stated. c. Original duly signed or certified copy of the annual report and financial statements corresponding to the last closed economic year, with an external auditor's report. d. Risk rating granted by a rating agency, if it has one. e. List of partners or shareholders, identification data and percentage of participation, detailing the shareholder chain up to identifying the legal subject that exercises effective control of the group and indicating the identification document number of each shareholder. It will not be admitted that in that chain there are societies whose shares are bearer shares and transferable by simple delivery. f. Original duly signed or certified copy of the Trustee's report corresponding to the last balance sheet, if it exists. g. Documentation that demonstrates compliance with items 1. through 10. of Article 127.26, as applicable.

RR-SSF-2026-444 Date: 10/07/2026 16:00:25 CIRCULAR N°2507

If deemed necessary, the Superintendency of Financial Services may request additional information beyond that indicated above.

ARTICLE 127.29 (PERSONAL AND PROFESSIONAL BACKGROUND).

The application for authorization must be accompanied by the identification data (full name, date of birth, home address, email address, phone number, and proof of identity documentation issued by the country of which they are a natural citizen and by the country of which they are a resident, if applicable) and position to be held of each of the members of the senior management, attaching in addition the following information and documentation:

a. Curriculum vitae, which must include a detail of the level of education, training courses, and work experience. It must also include the necessary information to verify the provided background. b. Sworn declaration regarding their financial situation, indicating assets, rights, and bank and non-bank debts and the existence of liens on them. The date of the sworn declaration cannot be older than 3 (three) months. This declaration must be accompanied by a notarial certification of the holder's signature. c. Sworn declaration with notarized certification of the holder's signature, detailing:

i. The name, registered office, and business activity of the companies to which he has been or is linked, in a salaried or honorary capacity, as a partner or shareholder, director, executive, trustee, auditor, or in senior management, executive, or advisory positions, whether this situation is direct or indirect, through natural or legal persons of any nature. In particular, it must be stated whether any of the companies to which he has been linked has gone bankrupt, even if it occurred within the year following his separation.

ii. If he has been sentenced to pay damages in civil lawsuits initiated against him, as a consequence of his labor and professional activity, and if he has pending processes in this matter.

iii. If he has been sanctioned or is being subject to investigation or disciplinary procedures by supervisory and/or financial regulatory or self-regulatory bodies.

iv. If he is a university professional, if he is or was affiliated with any college or professional association, indicating the name of the institution and the period of affiliation. Likewise, he must declare that his license to practice his profession has not been revoked, as well as if he has received sanctions from the competent authority for violating norms or codes of ethics of professional associations.

RR-SSF-2026-444 Date: 10/07/2026 16:00:25 CIRCULAR N°2507

v. If he is subject to any criminal judicial process or has received any conviction in criminal proceedings.

vi. Not being included in the causes of disqualification mentioned in Article 23 of Decree-Law No. 15.322 of September 17, 1982, in the wording given by Article 2 of Law No. 16.327 of November 11, 1992.

d. Certificate of Judicial Background issued by the Ministry of the Interior. In the case of natural persons who reside or have resided abroad, certificates of an equivalent nature issued by the competent authority of the country where they reside and those where they have resided in the last 5 (five) years must be presented.

If deemed necessary, the Superintendency of Financial Services may request additional information beyond that indicated above.

ARTICLE 127.30 (DEPENDENCIES IN THE COUNTRY).

In the case of virtual asset service providers that use physical premises, these must be perfectly identified in such a way as not to give rise to confusion regarding the development of activities unrelated to those detailed in Article 127.22, and equipped with the necessary means for an effective execution of transactions.

Likewise, providers must comply with the security standards established by the General Directorate of Business Auditing (DIGEFE), dependent on the Ministry of the Interior, and keep the certificate of definitive or provisional authorization available to the Superintendency of Financial Services.

Those who use automated terminals must also observe the maximum transaction amount set forth in Article 127.32.

They must notify the Superintendency of Financial Services of the opening of new dependencies installed in the country, as well as the relocation of the main domicile or of said dependencies, with a notice of no less than 10 (ten) business days. If within said period the Superintendency of Financial Services does not raise observations, they will be authorized to proceed with the opening or relocation. In said communication, the date of opening and location of the dependency, telephone numbers, email address, website, and days, hours, and channels for public attention will be informed.

In the case of the closure of dependencies in the country, the virtual asset service provider must notify the Superintendency of Financial Services with a notice of no less than 10 (ten) business days.

RR-SSF-2026-444 Date: 10/07/2026 16:00:25 CIRCULAR N°2507

For these purposes, a dependency is considered the place other than the main domicile, where some or all of the activities permitted to virtual asset service providers are developed.

ARTICLE 127.31 (DEPENDENCIES AND ACTIVITY ABROAD).

Virtual asset service providers that use physical premises abroad must notify their opening to the Superintendency of Financial Services with a notice of no less than 30 (thirty) business days. If within said period the aforementioned Superintendency does not raise observations, they will be authorized to proceed with the opening.

In said communication, the following information must be presented:

i. Location of the dependency; ii. Telephone numbers, email address, website, and days, hours, and channels for public attention; iii. Detailed description of the activity to be developed and its insertion in the company's strategy; iv. Legal report on the regulations governing the receiving country for the installation of the provider's dependencies; v. Certified and legalized copy of the documentation that demonstrates the procedures carried out before the supervisory body of the country where the dependency will be installed.

The Superintendency of Financial Services may request additional documentation and information beyond that indicated above when it deems appropriate, in order to adopt a reasoned decision on the opening of a dependency abroad, in which case the aforementioned period will be suspended.

In the case of the closure of dependencies abroad, the virtual asset service provider must notify the Superintendency of Financial Services with a notice of no less than 10 (ten) business days.

Modifications to the information presented must be communicated to the Superintendency within a maximum period of 10 (ten) business days from when they occurred.

ARTICLE 127.32 (USE OF AUTOMATED TERMINALS).

Institutions that operate exclusively through automated terminals must apply for authorization to the Superintendency of Financial Services as virtual asset service providers.

When these terminals are located in premises belonging to other institutions supervised by the Central Bank of Uruguay, they must be clearly identified in order to avoid confusion among clients regarding who is providing the service.

RR-SSF-2026-444 Date: 10/07/2026 16:00:25 CIRCULAR N°2507

In all cases, providers must comply with the security standards established by the General Directorate of Business Auditing (DIGEFE), dependent on the Ministry of the Interior, and keep the certificate of definitive or provisional authorization available to the Superintendency of Financial Services.

Likewise, they must comply with the regulations on anti-money laundering, terrorist financing, and financing of the proliferation of weapons of mass destruction set forth in Book III.

Virtual asset service providers must additionally comply with the consumer protection standards established in Book IV, as well as the provisions on transparency and market conduct required in Book V.

Transactions carried out through these terminals will be subject to a maximum daily amount per client of US$ 1000 (one thousand United States dollars) or its equivalent in other currencies.

The Superintendency of Financial Services may issue specific instructions for operations through automated terminals.

ARTICLE 127.33 (HOURS AND CHANNELS FOR PUBLIC ATTENTION).

Virtual asset service providers will freely establish the days, hours, and channels for public attention.

Without prejudice to what is provided in Article 310.40, they must publicly disclose the days, hours, and channels for public attention established, as well as publicly communicate any modification to said attention regime.

ARTICLE 127.34 (SEPARATION OF OWN AND CLIENT FUNDS).

Virtual asset service providers must maintain independent bank accounts or electronic money instruments to guarantee an adequate separation of their assets' movements and those of their clients.

Client funds cannot remain in their possession for more than 48 hours. This period may be longer if there are specific instructions for it and that do not distort the operation.

ARTICLE 127.35 (SEPARATION OF OWN AND CLIENT VIRTUAL ASSETS).

Virtual asset service providers that provide the services referred to in letter d. of Article 127.22 must guarantee a clear separation between their own virtual assets and those of their clients.

This separation must be clearly recorded, individualized, and kept updated in their records.

RR-SSF-2026-444 Date: 10/07/2026 16:00:25 CIRCULAR N°2507

ARTICLE 127.36 (START OF ACTIVITIES).

Once the authorization to operate is granted, the start of activities of virtual asset service providers will be conditioned on the presentation of the following documentation:

a. Planned date of start of activities, indicating days, hours, and channels for public attention. b. Proof demonstrating that the virtual asset service provider has opened independent bank accounts or electronic money instruments and custody for the movements of their assets and those of their clients. c. In case of modification or expansion of the senior management list presented previously, they must provide the information and documentation required by Article 127.29 for those persons not presented in a timely manner. d. Approval of operational regulations by the competent body. e. Identification of the person responsible for logical and physical security, indicating the position they hold in the organizational chart and their functional dependency. f. Auditor's report on the implemented computer systems, which will comprise - at a minimum - the control of operation, security, and service continuity, the inalterability of recorded information, and backup procedures, mentioning the quantity and location (local or external storage sites) of the projected backup media.

  1. INCORPORATE into Title VII TER - VIRTUAL ASSET SERVICE PROVIDERS of Book I - AUTHORIZATIONS AND REGISTERS of the Compilation of Securities Market Rules CHAPTER III – ISSUANCE AND TRANSFER OF SHARES OR PROVISIONAL SHARE CERTIFICATES OR SOCIAL QUOTAS, which will contain the following article:

ARTICLE 127.37 (AUTHORIZATION TO ISSUE OR TRANSFER SHARES OR PROVISIONAL SHARE CERTIFICATES OR SOCIAL QUOTAS).

Virtual asset service providers must request prior authorization from the Superintendency of Financial Services to issue or transfer shares or provisional certificates, when organized as joint-stock companies; or to transfer social quotas, when organized as personal societies.

In analyzing these applications, the resolutions of the aforementioned Superintendency will be based on reasons of legality, opportunity, and convenience, considering for the transfer of social control what is provided in Article 127.26.

The application must be presented supplying the following information:

RR-SSF-2026-444 Date: 10/07/2026 16:00:25 CIRCULAR N°2507

  1. Certified copy of the minutes of the meeting of the social body that resolves to issue shares or provisional certificates or transfer social parts.
  2. When it concerns an issuance or transfer to a new shareholder or partner:

a. Amount of capital to be contributed or to be paid by the new shareholder or partner. b. Information on direct partners or shareholders and persons who exercise control of the society, required by Article 127.28. c. The sworn declaration of the legitimate origin of the capital, under the terms of Article 310.33.

  1. When it concerns an issuance or transfer to someone who already holds the status of shareholder or partner:

a. Amount of capital to be contributed or to be paid by the shareholder or partner. b. The sworn declaration of the legitimate origin of the capital, under the terms of Article 310.33.

If the authorized issuance or transfer of shares or social quotas is not effected within 90 (ninety) calendar days, counted from the date of notification, the corresponding authorization will automatically lose validity.

Those issuances of shares, provisional certificates, or social quotas that do not modify the participation of each of the partners or shareholders in the capital of the society are authorized, and must inform under the terms established by Articles 310.21 or 310.33, as applicable to a capitalization of equity items or to new contributions from partners or shareholders, respectively. Items whose final destination is a result that cannot yet be recognized under the applicable accounting standards cannot be capitalized.

In cases where any shareholder who increases their participation results in a total participation of less than 15% (fifteen percent) of the share capital and provided that control or significant influence is not configured, as provided in the appropriate accounting standards for commercial societies, prior notice to the Superintendency of Financial Services will be sufficient, understanding that authorization is conferred if no objections are raised within 10 (ten) business days following. In said notice, the information required in this article must be supplied.

In all cases, the effectuation of the respective issuances or transfers will be reported to the Superintendency of Financial Services within 10 (ten) business days following the date of occurrence.

RR-SSF-2026-444 Date: 10/07/2026 16:00:25 CIRCULAR N°2507

In the case of the death of a shareholder or partner, such fact must be reported, and within 30 (thirty) days following the date of occurrence, the following documentation must be presented:

a. Testimony of the death certificate. b. Notarial certificate detailing the persons with hereditary rights.

For the purpose of granting non-objection, the Superintendency of Financial Services will evaluate whether the new shareholder or partners meet the required requirements. In this regard, the initiation of the succession process must be demonstrated, and the information of the presumed heirs required by the regulations for partners or shareholders must be presented within a period of 90 (ninety) days following the date of the death.

Once the succession process is finalized, a certified copy of the Certificate of Results of the Succession Proceedings must be presented within a period of 10 (ten) business days, and in case of any variations regarding the persons with hereditary rights previously informed, the corresponding information must be presented.

  1. INCORPORATE into Title VII TER - VIRTUAL ASSET SERVICE PROVIDERS of Book I - AUTHORIZATIONS AND REGISTERS of the Compilation of Securities Market Rules CHAPTER IV – EXTERNAL AUDITORS, which will contain the following article:

ARTICLE 127.38 (AUTHORIZATION FOR THE HIRING OF EXTERNAL AUDITORS).

Virtual asset service providers must request prior authorization from the Superintendency of Financial Services for the hiring of external auditors and external audit firms referred to in Article 151.1.12.

The external auditor or external audit firm to be hired must have the adequate organization and knowledge regarding the size and specificity of the business of the company to be audited, as well as experience in auditing the financial sector.

For the purpose of granting authorization, the Superintendency of Financial Services will evaluate compliance with the mentioned requirements, for which information regarding the professionals involved in the audit proposal and their professional experience, as well as any other information that allows for verification, must be presented.

Furthermore, the aforementioned Superintendency will value the background of the tasks that the external auditor or external audit firm has developed for supervised entities.

The application for authorization must be presented with a minimum advance of 30 (thirty) days from the date of hiring. After the period of 30 (thirty) days following the application has passed without observations, the providers will be authorized to hire the external auditor or firm

RR-SSF-2026-444 Date: 10/07/2026 16:00:25 CIRCULAR N°2507

of external auditors proposed. This period shall be suspended if the Financial Services Superintendence requests additional information.

  1. INCORPORATE into Title VII TER - VIRTUAL ASSET SERVICE PROVIDERS of Book I - AUTHORIZATIONS AND REGISTERS of the Compilation of Securities Market Regulations CHAPTER V – OUTSOURCING OF SERVICES, which shall contain the following articles:

ARTICLE 127.39 (OUTSOURCING OF SERVICES).

Virtual asset service providers must previously notify the Financial Services Superintendence of the contracting of third parties to provide services that are so inherent to their business that, when performed by their own departments, they are subject to the regulatory and control powers of said Superintendence, in accordance with the instructions to be issued.

Companies providing the outsourced services shall be subject, with respect to those activities, to the same regulations that govern when they are performed by the controlled entities, except for those of a sanctioning nature.

Outsourcing does not imply in any case exemption or limitation of the liability that the law or regulations impose on institutions for non-compliance with their obligations.

Client acceptance may not be outsourced.

Virtual asset service providers must have established written policies and procedures that allow for the effective identification, measurement, control, and monitoring of risks - both present and future - associated with outsourcing agreements entered into.

In particular, they must evaluate the emerging risks of outsourcing multiple activities to the same provider.

ARTICLE 127.40 (REQUIREMENTS FOR OUTSOURCING OF SERVICES).

Virtual asset service providers must comply with the following requirements for outsourcing of services:

  1. Sign a contract with the outsourced company that must contain, at a minimum, the following clauses:

a) Identification of the contracting parties, their representatives, and legal domiciles.

b) Object of the contract, indicating the services to be outsourced in detail, their scope, and the minimum service levels and conditions established by the contracting institution.

When the contracted services involve data processing, the location from which such processing, maintenance, and backups are provided must be identified.

c) Liability of the institution for services provided by the contracted third party.

d) Commitments regarding confidentiality and data protection, which shall not be conditioned to a termination date.

When the contracted services involve data processing, the obligation of the service provider –upon termination of the contract– to transfer or offer tools that allow the transfer of data to whom the supervised institution disposes and its elimination once availability and integrity are confirmed at the destination, must be incorporated.

e) Conditions and protocols that ensure the continuity of the services provided.

f) Right to perform audits or evaluations, without any restriction whatsoever, by the Financial Services Superintendence and the contracting institution, either directly or through independent audits.

Unrestricted access to data and all technical documentation and information related to the services provided must be provided. Such unrestricted access shall not be subject to prior notice and must also be provided –if applicable– to the person responsible for the intervention, resolution, or liquidation process.

In cases where the service is provided abroad and the contract between the parties and/or the contracts with subcontracted companies by the third party providing services to the supervised institution –if any– do not contemplate the foregoing, the institution must have read-only, exclusive, and unrestricted (technical or administrative) access to the service and externally processed data, usable at all times from the institution's offices by Financial Services Superintendence officials.

g) Procedures to obtain the necessary information for the service to continue being provided in any situation that might prevent the third party from continuing to fulfill the contracted service.

The obligation of the provider to inform the supervised institution about any event that could significantly affect the provision of the service must be included.

h) Obligation of the provider –as long as the substantive obligations of the supervised institution are exercised under the contract, including payment obligations– to continue providing the service when the institution is undergoing intervention, resolution, or liquidation.

i) Grounds for termination, among which the instruction to cease the provision of services through the outsourced company by the Financial Services Superintendence must be included.

If the contract between the supervised institution and the third party providing services does not include this instruction within the termination clauses, the institution must accept the liability that may eventually arise in the event that said Superintendence instructs the termination of the outsourcing.

The detailed requirements in the preceding letters, except for letter c), shall also be enforceable against contracts with companies subcontracted by the outsourced company, if any.

If deemed necessary, the Financial Services Superintendence may require modifications to both the contracts with the outsourced company and those with subcontracted companies.

  1. Have a report stating the evaluation of risks associated with outsourcing, including the valuation of its impact on operational risks, operational resilience, and information security, as well as the evaluation of the financial and technical solvency of the contracted third parties and subcontractors, if any, as well as aspects related to legal risks to which the information subject to secrecy is exposed, in accordance with Uruguayan legislation. This report must be updated periodically based on the result of the risk assessment performed.

  2. Bear the costs incurred by the Financial Services Superintendence for supervision activities abroad of outsourced services.

  3. Communicate any subsequent change to the scope or conditions of the outsourcing.

In the case of outsourcing involving data processing, in addition to what is provided in items 1) to 4) above, they must consider what is provided in Articles 127.41 and 127.42.

With respect to the contracting of correspondent services, in addition to what is provided in items 1) to 4) above, they must consider what is provided in Articles 127.43 to 127.43.5.

The outsourcing of due diligence procedures shall be governed, in addition to what is provided in items 1) to 4) above, by what is provided in Article 198.

Those outsourcings performed with institutions that are subject to regulation and supervision by the Central Bank of Uruguay regarding the outsourced activity shall only comply with what is provided in item 1).

If applicable, institutions must register the databases and authorizations for the international transfer of personal data with the Regulatory and Control Unit for Personal Data of the Agency for Electronic Government and Society of Information and Knowledge.

The Financial Services Superintendence may establish that the outsourcing of certain services is not subject to the requirements described above.

ARTICLE 127.41 (OUTSOURCING OF DATA PROCESSING).

Data processing is understood as the execution of any action on data that achieves a transformation in them, including the change of medium in which they are supported.

Data and software backup procedures must satisfy the conditions of Article 255.2 and guarantee that the technological infrastructure and systems to be used for communication, storage, and processing of data offer sufficient security to satisfy the conditions established in Article 255.6, as well as to permanently safeguard the operational continuity described in Article 255.8.

In cases where clients receive information processed by the third party, the latter must be identified by the institution by any means, indicating corporate name and domicile.

When the computer system or platform used is shared with other entities, it must allow for the clear identification of operations, data, and any other information inherent to the supervised entity.

ARTICLE 127.42 (ADDITIONAL REQUIREMENTS FOR DATA PROCESSING IN OR FROM OUTSIDE THE COUNTRY).

When data processing is provided by a third party located abroad or in the country, but the service is provided wholly or partially in or from abroad, institutions must evaluate the existing legal and regulatory requirements in the host jurisdiction as well as potential political, economic, and social conditions or other events that could conspire against the provider's ability to satisfactorily fulfill agreed obligations.

These aspects must be verified both at the time of initial provider selection and at the time of any contract renewals.

The third party must have an operational model and equipment such that online access to all information from terminals installed in the supervised company is possible at all times.

With regard to information backup abroad, one of the copies referred to in Article 255.2 must be physically located in Uruguay and remain accessible to Financial Services Superintendence officials within a timeframe not greater than that fixed by said Superintendence based on the location of the processing.

It will be admitted that a copy is not located in Uruguay when institutions implement and make available a physical space with the necessary technological infrastructure to allow total, continuous, and permanent access and control of all data processed outside the country, as well as their backups and the keys necessary for access and eventual decryption. This unified access point must be located in the country, in the headquarters or some department of the institution, and concentrate all accesses, regardless of locations, providers, and nature of services provided from abroad. Institutions must inform the Financial Services Superintendence of the location assigned to the point.

At least once a year, formal and duly documented tests must be performed that, for each of the persons designated according to the procedures defined by the institution and for each of the services available at the unified point, ensure access, consultation, download, and export of information.

The operational continuity plan and the disaster recovery plan, if applicable, must be adjusted and tested with successful results within a period not greater than 60 calendar days from the start of the processing activity and subsequently, at least once a year. The Financial Services Superintendence may order that these tests be performed under its supervision.

ARTICLE 127.43 (SERVICES PROVIDED THROUGH FINANCIAL CORRESPONDENTS OR ADMINISTRATORS OF FINANCIAL CORRESPONDENTS).

Virtual asset service providers may provide their clients the services referred to in letters a. to c. of Article 127.22 through financial correspondents or administrators of financial correspondents, in accordance with the definitions established in Articles 35.6 and 35.7 of the Compilation of Regulations and Control of the Financial System.

The Financial Services Superintendence may authorize the provision of other services, under the conditions it determines.

The premises of financial correspondents must comply with what is established in Article 35.15 of the Compilation of Regulations and Control of the Financial System.

The computer technology processes to be used by financial correspondents to carry out operations on behalf of the contracting providers must satisfy what is provided in Article 35.16 of said Compilation.

Operations carried out at such correspondents must be documented in accordance with what is established in Article 35.17 of said Compilation.

ARTICLE 127.43.1 (REQUIREMENTS FOR THE CONTRACTING OF FINANCIAL CORRESPONDENTS).

The provision of services through a financial correspondent or administrator of correspondents must comply with the conditions referred to in Article 127.40, and the service provision must be recorded in a contract to be signed with the financial correspondent or administrator of correspondents.

The aforementioned contract must contain, at a minimum, the clauses referred to in Article 127.40 and those established below:

  • In the case of contracting an administrator of correspondents, requirements regarding selection, control, and termination of financial correspondents contracted by the administrator.

  • Mechanisms for compensation between the parties and procedures regarding the fund flow resulting from contracted services.

  • Sanctions applicable in case of non-compliance by the financial correspondent or administrator of correspondents with the obligations established in the correspondent contract.

The inclusion of clauses in the contract stipulating the requirement of exclusivity in the provision of correspondent services by the correspondent with respect to a specific institution will not be admitted.

The contracts to be signed between the administrator of correspondents and the correspondents with which it contracts must contain the minimum clauses referred to above.

ARTICLE 127.43.2 (OBLIGATIONS OF CONTRACTING PROVIDERS OF CORRESPONDENT SERVICES).

Virtual asset service providers must, with respect to the correspondents or administrators of correspondents contracted:

  1. Maintain at all times, vis-à-vis clients, full responsibility for the services provided through them.

  2. Provide the policies, procedures, and operational manuals for the provision of contracted services, including those corresponding to the prevention of money laundering, terrorist financing, and financing of the proliferation of weapons of mass destruction, and control their use.

  3. Ensure that the correspondent or administrator of correspondents has the necessary funds for the development of the agreed operations and establish deadlines for the delivery of debtor balances to the contracting institution.

  4. Train them adequately to develop the contracted services appropriately.

  5. Perform adequate monitoring of executed transactions and carry out control of compliance with current regulations related to their activity.

  6. Have policies and procedures to evaluate risks associated with operations to be carried out through the financial correspondent or administrator of correspondents and measures to mitigate them.

  7. Verify that they comply with all obligations established in the regulations.

For the provision of the services detailed below, in addition, they must:

a. Services mentioned in letters a. and b. of Article 127.22:

a.1 Establish the quotes at which operations must be carried out.

a.2 Make available to their financial correspondents a real-time computer system that enables the possibility of incorporating prior controls to transactions and allows online monitoring and centralized recording of the flow of transactions carried out through them, as well as the performance of controls and validations to detect unusual or suspicious operations.

b. Services mentioned in letter c. of Article 127.22:

b.1 Install electronic devices connected online with the contracting provider, allowing correct authentication of the client or the person carrying out the transaction and the performance of operations in real time.

ARTICLE 127.43.3 (OBLIGATIONS OF FINANCIAL CORRESPONDENTS).

Financial correspondents must:

a. Use the policies, procedures, and operational manuals provided by contracting providers for the provision of services, including those corresponding to the prevention of money laundering, terrorist financing, and financing of the proliferation of weapons of mass destruction and user protection of financial services.

b. Maintain separate cash boxes for the performance of the services mentioned in letters a. to c. of Article 127.22.

c. Maintain separate accounting for their activity as a financial correspondent and comply, at all times, with the other requirements established in the conditions for the contracting of services.

d. Comply with all banking regulations related to the activity to be developed in their capacity as a financial correspondent.

e. Provide the information requested by the contracting provider or their external auditors.

f. Provide the information required by the Financial Services Superintendence for the fulfillment of its functions.

g. Keep confidential the information received regarding the contracting provider, being prohibited from revealing or disclosing the circumstances or details they have known about its business.

ARTICLE 127.43.4 (OBLIGATIONS OF ADMINISTRATORS OF CORRESPONDENTS).

Administrators of correspondents must adhere to what is provided in Article 35.13 of the Compilation of Regulations and Control of the Financial System.

ARTICLE 127.43.5 (PROHIBITIONS OF FINANCIAL CORRESPONDENTS OR ADMINISTRATORS OF CORRESPONDENTS).

Financial correspondents or administrators of correspondents may not:

a. Make decisions regarding clients or regarding the procedures for the provision of services, which shall fall upon the contracting providers of correspondent services.

b. Charge commissions to the provider's clients for the provision of services provided for in the contract.

c. Use the contracting provider's client database for their own benefit or that of third parties.

d. Operate when a communication failure occurs that prevents transactions from being carried out online with the contracting provider, when this condition is required for the provision of the service.

e. In the case of correspondents, subcontract the provision of correspondent services.

  1. INCORPORATE into Title VII TER - VIRTUAL ASSET SERVICE PROVIDERS of Book I - AUTHORIZATIONS AND REGISTERS of the Compilation of Securities Market Regulations CHAPTER VI – INFORMATION SECURITY, which shall contain the following articles:

ARTICLE 127.44 (COMPUTER SYSTEMS).

Virtual asset service providers must implement and maintain secure computer systems, with a high level of quality and cybersecurity in accordance with national and international parameters and consistent with their business model, volume of operations, as well as the number and type of clients.

When operating through virtual asset trading platforms, they must implement measures that ensure integrity is maintained on said platforms, abuses in trading are prevented, and actions implying manipulation are avoided.

Computer systems must have the capacity to detect potential incidents or security breaches. Likewise, they must have infrastructure that allows continuing essential functions, restoring critical systems after a cyberattack, and reducing the systemic risk that would be generated by an interruption in their activity.

ARTICLE 127.45 (INFORMATION SECURITY POLICIES AND PROCEDURES).

Virtual asset service providers must have information security policies and procedures approved by their highest governing body, which must be updated - at a minimum - annually.

Such policies and procedures must contemplate - at a minimum - the following aspects:

  • The description of the technical and operational systems and procedures used for the custody of private cryptographic keys, as well as for granting or revoking access to them, in the case of providers providing the services referred to in letter d. of Article 127.22.

  • The periodic training of their personnel in the matter.

  • The management of environmental conditions for the secure location of equipment.

  • The risk assessment in cybersecurity matters that allows the identification of threats and timely response to them, as well as the formulation of technical and operational guidelines for the resilience of systems linked to the operation and custody of virtual assets.

  • the periodic internal evaluation, as well as the carrying out of independent audits in accordance with the provisions of Article 127.47.

  • the mechanisms to identify potential weaknesses in their computer systems, which allow detecting those critical processes and operations of their infrastructure that must be protected prioritarily against cyber threats.

ARTICLE 127.46 (INFORMATION SECURITY OFFICER). Virtual asset service providers shall appoint an information security officer, who must ensure the governance and management of information assets - both physical and digital - preserving their availability, integrity, confidentiality, authenticity, and reliability.

Such officer shall be included in the category of senior personnel referred to in Article 143 and must have adequate competence in the subject matter and maintain functional and budgetary independence from the entity's information technology area.

ARTICLE 127.47 (ANNUAL SYSTEM AUDIT). The computer systems used by virtual asset service providers must have an annual system audit that will comprise - at a minimum - the control of operation, activities, security, and service continuity, the unalterability of recorded information, backup procedures, and other requirements demanded in this Chapter.

The annual system audit report must be signed by independent professionals experts in the subject matter, who may be national or foreign.

  1. INCORPORATE into Title VII TER - VIRTUAL ASSET SERVICE PROVIDERS of Book I - AUTHORIZATIONS AND REGISTERS of the Compilation of Securities Market Regulations CHAPTER VII – WITHDRAWAL OF AUTHORIZATION TO OPERATE, which will contain the following articles:

ARTICLE 127.48 (APPLICATION FOR WITHDRAWAL OF AUTHORIZATION TO OPERATE). The decision to cease activities by virtual asset service providers must be reported to the Superintendence of Financial Services with a 15 (fifteen) business days advance notice, attaching an authenticated copy of the minutes of the meeting of the corporate body that resolved the cessation, in which the cessation date and the reasons leading to such determination must be recorded.

Likewise, the place and person who - during the term established in Article 255.7 - will be responsible for the safeguarding of the information and documentation referred to in Articles 255.2 and 255.3 must be informed, and the minimum requirements for safeguarding established in Article 255.6 must be met. The designated person must ensure that all information and documentation will be available in time, form, and conditions to be processed when required by the Superintendence of Financial Services, immediately informing the latter of any circumstance that might prevent them from fulfilling this mission in the future.

From the date of cessation of activities, and having complied with the submission of the information indicated above, the virtual asset service provider will be exempt from submitting information corresponding to periods subsequent to that date. However, they must comply with the submission of information corresponding to periods finalized prior to the cessation date.

For the withdrawal of the authorization to operate, the following information must also be presented: a. Certificate of having initiated the liquidation procedure of the company before the relevant state bodies, or in the case of commercial companies that will dedicate themselves to other activities, a certificate that the process of reforming the statutes or social contract has been initiated to modify the name and corporate purpose, and other corresponding procedures. b. Individual financial statements as of the date of cessation of activities, accompanied by a compilation report, duly signed and with the corresponding professional stamps. c. Report from legal advisors indicating the existence or not of pending litigation or contingencies as of the date of cessation of activities. d. External Auditor's Report indicating that the virtual asset service provider does not hold - as of the date of cessation of activities - funds or virtual assets in custody that belong to its clients or third parties, and that it has informed them of the data of the institution to which the balances and custodies have been transferred.

Upon presentation of the information and documentation mentioned in the previous points to the satisfaction of the Superintendence of Financial Services, the guarantee and deposit constituted by the provider will be returned, in accordance with the provisions of Articles 151.1.9 and 151.1.11. For these purposes, virtual asset service providers must provide the account number and the financial institution to which the corresponding transfer will be made.

If deemed necessary, the Superintendence of Financial Services may request additional information to that indicated above.

ARTICLE 127.49 (AUTHORIZED ACTIVITIES UPON CESSATION). Upon ceasing their activities, and during the process of withdrawal of the authorization to operate, virtual asset service providers:

  1. May only carry out movements for the purpose of canceling pending liquidation transactions and may only carry out those activities strictly necessary for the liquidation of the company or, in the case of companies that will dedicate themselves to other activities, for the reform of the statutes or social contract and other corresponding procedures.

  2. Must disable the website or operational platform and eliminate all advertising that identifies the company as a virtual asset service provider, as well as any other reference to the provision of permitted services.

  3. SUBSTITUTE in Title X - DEFINITIONS of Book I - AUTHORIZATIONS AND REGISTERS of the Compilation of Securities Market Regulations Articles 142 and 143 with the following:

ARTICLE 142 (ECONOMIC GROUP). For the determination of the economic group or group, the definition established in Article 271 of the Compilation of Regulations and Control of the Financial System and Communications that regulate it will be applicable.

ARTICLE 143 (SENIOR PERSONNEL). Senior personnel are considered for the purposes of the provisions of this Compilation to: a. Persons who hold positions of directors or administrators, trustees, or are members of Fiscal Commissions, Audit Committees, or other commissions delegated by the Board of Directors or administrative body, as well as attorneys-in-fact or legal representatives of the company. b. Persons who hold the positions or fulfill the functions of general manager, deputy general manager, managers, internal auditor, general accountant, compliance officer, information regime officer, data, software, and documentation safeguarding officer, information security officer, and fiduciary activity officer in the case of general fiduciaries. c. Persons who, holding positions or maintaining a permanent relationship with the institutions, advise the direction or administration body.

  1. INCORPORATE into Book II - STABILITY AND SOLVENCY of the Compilation of Securities Market Regulations Title II QUATER - VIRTUAL ASSET SERVICE PROVIDERS.

  2. INCORPORATE into Title II QUATER - VIRTUAL ASSET SERVICE PROVIDERS of Book II - STABILITY AND SOLVENCY of the Compilation of Securities Market Regulations Chapter I - EQUITY, GUARANTEES, AND DEPOSITS, which will contain the following articles:

ARTICLE 151.1.8 (MINIMUM EQUITY). Virtual asset service providers that provide the services referred to in letter d. of Article 127.22 must permanently maintain a minimum equity of no less than UI 1,000,000 (one million indexed units).

The minimum equity must be maintained throughout the duration of the provider's activity, even during the time required for the procedure referred to in Article 127.48 as long as it holds client funds or virtual assets in its name.

For the purpose of complying with the minimum equity, balances arising from the statement of financial position will have deducted from them balances with controlling, controlled, and affiliated companies, and debtor balances of directors' and partners' accounts.

ARTICLE 151.1.9 (GUARANTEES). Virtual asset service providers must constitute and maintain, permanently, a guarantee in favor of the Central Bank of Uruguay for an amount of no less than UI 600,000 (six hundred thousand indexed units) for any obligations they might assume with said Bank or with third parties in the exercise of their activity as providers.

Such guarantees may consist of: a) Pledge on a deposit denominated in indexed units, constituted at the Central Bank of Uruguay; b) Pledge on national tradable public securities, denominated in indexed units, deposited at the Central Bank of Uruguay. For these purposes, the securities will be computed at their nominal value.

The selected guarantee modality or modalities cannot be substituted before the year of their constitution or any subsequent replacement. Furthermore, in case the constituted guarantee comprises one or more national tradable public securities, they cannot be substituted by other securities within a one-year period.

The constituted guarantees will be maintained:

  • until the year following the loss of the status of virtual asset service provider, at a minimum, or while it maintains client fund or virtual asset custodies in its name, if applicable;
  • until judicial actions filed against it are resolved by a final judgment.

ARTICLE 151.1.10 (ADJUSTMENT OF GUARANTEE DEFICIT). The guarantee deficit must be remedied within 8 (eight) business days of its occurrence, in which case it will not be considered a breach. Upon expiration of said term, the provisions of Article 366 will apply.

ARTICLE 151.1.11 (AVAILABILITY AT THE CENTRAL BANK OF URUGUAY). Virtual asset service providers must constitute and maintain a demand deposit at the Central Bank of Uruguay, denominated in indexed units, for an amount of no less than UI 50,000 (fifty thousand indexed units), for the purpose of meeting obligations with said Institution.

Each time a debit is made, the provider will have a term of 5 (five) business days counted from the notification to reconstitute said deposit to the required level.

The constituted deposit will be released, totally or partially, when the respective provider has definitively ceased activity, provided it is proven that the provider has fulfilled its obligations with the Central Bank of Uruguay.

  1. INCORPORATE into Title II QUATER - VIRTUAL ASSET SERVICE PROVIDERS of Book II - STABILITY AND SOLVENCY of the Compilation of Securities Market Regulations Chapter II - EXTERNAL AUDITORS AND INDEPENDENT PROFESSIONALS AUTHORIZED TO ISSUE REPORTS ON MONEY LAUNDERING, TERRORISM FINANCING, AND FINANCING OF THE PROLIFERATION OF WEAPONS OF MASS DESTRUCTION, which will contain the following article:

ARTICLE 151.1.12 (HIRING OF EXTERNAL AUDITOR AND INDEPENDENT PROFESSIONALS AUTHORIZED TO ISSUE REPORTS ON PREVENTION OF MONEY LAUNDERING, TERRORISM FINANCING, AND FINANCING OF THE PROLIFERATION OF WEAPONS OF MASS DESTRUCTION). Virtual asset service providers must hire an external auditor or external audit firm and an independent professional or independent professional firm authorized to issue reports on the prevention of money laundering, terrorism financing, and financing of the proliferation of weapons of mass destruction, who must be registered in the Registers referred to in Articles 143.1 and 143.9, as applicable, for the performance of the reports required by the regulations.

  1. INCORPORATE into Title II QUATER - VIRTUAL ASSET SERVICE PROVIDERS of Book II - STABILITY AND SOLVENCY of the Compilation of Securities Market Regulations Chapter III - CORPORATE GOVERNANCE, which will contain the following article:

ARTICLE 151.1.13 (CORPORATE GOVERNANCE PRACTICES). Virtual asset service providers must implement corporate governance practices, in order to ensure:

  • the ethical and professional competence of the highest management bodies and senior personnel,
  • a balanced structure, with a clear definition of roles and responsibilities, according to the volume and complexity of the entity's operations, and
  • reliable internal control systems.

Likewise, they must adopt a code of ethics, which must be duly communicated and applied by all personnel and published on the website, as well as verify compliance with the regulations on insider information referred to in Articles 246.1 and following.

  1. RENAME in Book III - PROTECTION OF THE FINANCIAL SYSTEM AGAINST ILLEGAL ACTIVITIES of the Compilation of Securities Market Regulations Title I - PREVENTION OF THE USE OF SECURITIES INTERMEDIARIES AND INVESTMENT FUND MANAGEMENT COMPANIES FOR MONEY LAUNDERING, TERRORISM FINANCING, AND FINANCING OF THE PROLIFERATION OF WEAPONS OF MASS DESTRUCTION, which will be renamed PREVENTION OF THE USE OF SECURITIES INTERMEDIARIES, INVESTMENT FUND MANAGEMENT COMPANIES, AND VIRTUAL ASSET SERVICE PROVIDERS FOR MONEY LAUNDERING, TERRORISM FINANCING, AND FINANCING OF THE PROLIFERATION OF WEAPONS OF MASS DESTRUCTION.

  2. SUBSTITUTE in Chapter I - COMPREHENSIVE SYSTEM FOR THE PREVENTION OF MONEY LAUNDERING, TERRORISM FINANCING, AND FINANCING OF THE PROLIFERATION OF WEAPONS OF MASS DESTRUCTION of Title I - PREVENTION OF THE USE OF SECURITIES INTERMEDIARIES, INVESTMENT FUND MANAGEMENT COMPANIES, AND VIRTUAL ASSET SERVICE PROVIDERS FOR MONEY LAUNDERING, TERRORISM FINANCING, AND FINANCING OF THE PROLIFERATION OF WEAPONS OF MASS DESTRUCTION of Book III - PROTECTION OF THE FINANCIAL SYSTEM AGAINST ILLEGAL ACTIVITIES of the Compilation of Securities Market Regulations Articles 185, 186, and 187 with the following:

ARTICLE 185 (COMPREHENSIVE SYSTEM FOR THE PREVENTION OF MONEY LAUNDERING, TERRORISM FINANCING, AND FINANCING OF THE PROLIFERATION OF WEAPONS OF MASS DESTRUCTION). Securities intermediaries, investment fund management companies, and virtual asset service providers must implement a comprehensive system to prevent being used in money laundering, terrorism financing, and financing of the proliferation of weapons of mass destruction in accordance with the provisions of the following articles.

Its application must extend to the entire organization, including its branches and subsidiaries, in the country and abroad. In such cases, institutions must verify that their branches or subsidiaries abroad adequately apply all prevention and control measures provided by said comprehensive system. When the minimum requirements in matters of prevention of money laundering, terrorism financing, and financing of the proliferation of weapons of mass destruction of the host country of the branch or subsidiary are less strict than those of our country, institutions must ensure that these implement the requirements of our country, to the extent permitted by the regulations of the host country. If said country does not allow its implementation, institutions must apply appropriate additional measures to manage money laundering, terrorism financing, and financing of the proliferation of weapons of mass destruction risks and inform the Financial Information and Analysis Unit.

The management of institutions must show total commitment to the functioning of the preventive system, establishing appropriate policies and procedures and ensuring their effectiveness.

Financial fiduciaries will be subject to the provisions of this Book to the extent that they constitute themselves as investment fund management companies.

Financial intermediation institutions will be governed by the provisions of the Compilation of Regulations and Control of the Financial System.

ARTICLE 186 (COMPONENTS OF THE SYSTEM). The system required by Article 185 must include the following elements: a. Policies and procedures for the administration of money laundering, terrorism financing, and financing of the proliferation of weapons of mass destruction risk, which allow preventing, detecting, and reporting to competent authorities transactions that may be related to said crimes.

For these purposes, securities intermediaries, investment fund management companies, and virtual asset service providers must: i. identify risk factors (products, services, clients, geographic zones, and distribution channels) associated with their different lines of activity; ii. evaluate their possibilities of occurrence and impact; iii. implement adequate control measures to mitigate the different types and levels of identified risk; iv. permanently monitor the results of applied controls and their degree of effectiveness, to detect those operations that result unusual or suspicious and correct existing deficiencies in the risk management process, and v. document the risk assessments performed in such a way as to be able to demonstrate their bases, keep them updated, and have appropriate mechanisms to supply information regarding said risk assessment when required. b. Policies and procedures regarding personnel that procure: i. A high level of integrity. Aspects such as personal, labor, and patrimonial backgrounds must be considered, which enable evaluating the justification of significant changes in their patrimonial situation or consumption habits. ii. Permanent training that allows them to know the regulations in the matter, recognize operations that may be related to money laundering, terrorism financing, and financing of the proliferation of weapons of mass destruction, and the manner of proceeding in each situation. c. A Compliance Officer who will be responsible for the implementation, monitoring, and control of the adequate functioning of the system, promoting the permanent updating of the policies and procedures applied by the institution. Additionally, they will be the official who serves as a link with competent bodies. They will also be responsible for adequately documenting the risk assessment performed by the institution and the control procedures established to mitigate them, preserving information on controls, operation analysis, and other activities developed by the members of the area under their charge.

ARTICLE 187 (CODE OF CONDUCT). Securities intermediaries, investment fund management companies, and virtual asset service providers must adopt a code of conduct, approved by their highest executive body with notification to their owners, which reflects the institutional commitment assumed for the purpose of avoiding the use of the market for money laundering, terrorism financing, and financing of the proliferation of weapons of mass destruction, and in which the ethical and professional norms that, in general, govern their actions in the matter are exposed.

This commitment will extend, in the case of investment fund administrators, to the funds and trusts they administer. In the case of securities intermediaries, the aforementioned code must also be approved by the Stock Exchange that groups them, if applicable. The code of conduct must be duly communicated and applied by all personnel. To this end, the provisions contained in Articles 252 to 253.1 apply.

  1. SUBSTITUTE in Chapter II - POLICIES AND PROCEDURES FOR DUE DILIGENCE REGARDING CLIENTS of Title I - PREVENTION OF THE USE OF SECURITIES INTERMEDIARIES, INVESTMENT FUND ADMINISTRATOR COMPANIES AND VIRTUAL ASSET SERVICE PROVIDERS FOR MONEY LAUNDERING, TERRORISM FINANCING AND FINANCING OF THE PROLIFERATION OF WEAPONS OF MASS DESTRUCTION of Book III - PROTECTION OF THE FINANCIAL SYSTEM AGAINST ILLEGAL ACTIVITIES of the Compilation of Securities Market Regulations Articles 189, 190, 190.1, 190.2, 191, 191.1, 192, 193, 194, 196, 197, 197.1, 198.2, 198.3, 199, 200 and 201 with the following:

ARTICLE 189 (DUE DILIGENCE POLICIES AND PROCEDURES). Securities intermediaries, investment fund administrators, and virtual asset service providers must define due diligence policies and procedures that must be applied to all new clients and also to existing clients, allowing them to obtain adequate knowledge of them, as well as the beneficial owner, paying special attention to the volume and nature of the business or other economic activities developed by the clients. When investment fund administrators act in a fiduciary capacity, clients will be understood not only as the quota holders, settlors, and beneficiaries of the trusts they administer but also as all those persons from whom they receive funds for said trusts. Institutions will not establish business relationships nor execute operations when they cannot apply the aforementioned due diligence procedures. When this possibility is appreciated during the course of the business relationship, the institutions will terminate it, proceeding to consider the appropriateness of filing a suspicious transaction report with the Financial Information and Analysis Unit in accordance with the regulations in this matter. The policies and procedures defined by the institution must contain, at a minimum:

RR-SSF-2026-444 Date: 10/07/2026 16:00:25 CIRCULAR N°2507

a. Reasonable measures to obtain, verify, register, update, and preserve information regarding the true identity of the client, as well as the person in whose benefit an account is opened or a transaction is carried out. b. Procedures to obtain, verify, register, update, and preserve information regarding the economic activity developed by the client, which allow adequate justification of the source of the funds managed. c. Clear client acceptance rules, defined based on risk factors such as: country of origin, level of political exposure, type of business or activity, related persons, type of product required, volume of operations, etc., which contemplate special analysis mechanisms and more rigorous approval requirements for higher-risk client categories. d. Transaction monitoring systems that allow detecting unusual or suspicious patterns in client behavior. The policies and procedures to be applied must consider the client's risk category and those special situations requiring intensified due diligence. Likewise, the policies and procedures may provide that, in exceptional cases, institutions do not complete due diligence when they notice that doing so would alert the client, reporting such situation to the Financial Information and Analysis Unit immediately.

ARTICLE 190 (CLIENT IDENTIFICATION). Securities intermediaries, investment fund administrators, and virtual asset service providers may not process transactions without the proper identification of their clients, whether occasional or habitual. To this end, they must collect information to establish and register the identity of their clients, as well as the purpose and nature of the business relationship, by effective means. A definitive relationship must not be established until their identity has been satisfactorily verified, in accordance with what is established in Article 190.1.

ARTICLE 190.1 (CLIENT IDENTITY VERIFICATION PROCEDURES). Securities intermediaries, investment fund administrators, and virtual asset service providers must implement the procedures they deem most effective to verify the identity of their clients before establishing a definitive relationship with them, for which they must consider the result of the risk assessment performed. RR-SSF-2026-444 Date: 10/07/2026 16:00:25 CIRCULAR N°2507

These procedures must contemplate personal contact in the following cases: a) Clients who carry out an economic activity This definition includes natural and legal persons who carry out commercial, industrial, agricultural, financial, professional, etc., activities. When it concerns clients whose annual transactions, according to their activity profile, reach amounts exceeding USD 1,500,000 (one million five hundred thousand US dollars) or its equivalent in other currencies, or carry out transactions for said amount during a calendar year, the client's identity must be verified through personal contact with the holder, representative, or attorney-in-fact, carried out by the institution or by third parties within the framework of what is provided in Article 198. In the case of clients who, without meeting the condition established in the preceding paragraph, their annual transactions reach - according to their activity profile - amounts exceeding USD 120,000 (one hundred twenty thousand US dollars) or its equivalent in other currencies, or carry out transactions for said amount during a calendar year, the aforementioned verification may also be carried out by another local or foreign financial entity registered with the supervisory body of its country to carry out financial activities, or by a notary or whoever performs this function abroad, obtaining the corresponding certification that such contact was made. b) Clients who do not carry out an economic activity This definition includes natural and legal persons not included in letter a), including companies used as investment vehicles, companies whose main or only function is to own or administer the ownership of other companies or corporations, trusts, among others. When it concerns clients whose annual transactions, according to their activity profile, reach amounts exceeding USD 500,000 (five hundred thousand US dollars) or its equivalent in other currencies, in the case of non-residents, or amounts exceeding USD 1,000,000 (one million US dollars) or its equivalent in other currencies, in the case of residents, or carry out transactions for said amount - as applicable - during a calendar year, the client's identity must be verified through personal contact with any of the beneficial owners, carried out by the institution or by third parties within the framework of what is provided in Article 198, and it must be recorded that such contact was maintained in the copy of the identification document used as a means of verification. RR-SSF-2026-444 Date: 10/07/2026 16:00:25 CIRCULAR N°2507

In the case of clients who, without meeting the condition established in the preceding paragraph, their annual transactions reach - according to their activity profile - amounts exceeding USD 120,000 (one hundred twenty thousand US dollars) or its equivalent in other currencies, or carry out transactions for said amount during a calendar year, the aforementioned verification may also be carried out by another local or foreign financial entity registered with the supervisory body of its country to carry out financial activities, or by a notary or whoever performs this function abroad, obtaining the corresponding certification that such contact was made. When investment fund administrator companies act in a fiduciary capacity, the requirement for identity verification through personal contact will extend at least to the settlors and beneficiaries of the trusts they administer. In all cases, when it concerns natural persons (residents and non-residents), personal contact with the client may be fulfilled through:

  • Physical presence of the client before the institution or the third parties mentioned in the preceding paragraphs.
  • The use of a process that allows remote verification of the client's identity, in accordance with the instructions to be issued.
  • The validation of the client's digital identity or advanced electronic signature, provided by providers within the framework of Law No. 18.600 of September 21, 2009, and its amendments and regulatory provisions, in accordance with the instructions to be issued. The term client includes the holder, representative, attorney-in-fact, or beneficial owner, as applicable. For the purpose of determining the thresholds established above, the total amount to be deposited or deposited into the account will be considered, and in the case of transactions not associated with an account, their accumulated volume excluding those related to another operation, such as a currency purchase followed by a transfer. Client identity verification procedures may be applied after the commercial relationship has begun whenever it is necessary not to interrupt the normal course of activity. A maximum period of 60 (sixty) days counted from the start of the link or from when the conditions enumerated above are met will be available, during which period more intense monitoring of the client's transactions must be performed.

ARTICLE 190.2 (IDENTIFICATION AND VERIFICATION OF BENEFICIAL OWNER IDENTITY). Securities intermediaries, investment fund administrators, and virtual asset service providers must collect information to establish and register the identity of the beneficial owner by effective means, as well as verify their identity. Identity verification procedures must consider the result of the risk assessment performed and contemplate personal contact when what is established in Article 190.1 is met. The obligation to identify the beneficial owner is exempted when it concerns clients whose equity participation titles are traded through national stock exchanges or internationally recognized stock exchanges, or are owned, directly or indirectly, by companies whose participation titles meet the aforementioned requirement, provided that such titles are available for immediate sale or acquisition in the referred markets. This exception applies only with respect to titles that are traded on the stock exchange. The beneficial owner will be understood as natural persons who, directly or indirectly, own at least 15% (fifteen percent) of the capital or its equivalent, or of the voting rights, or who by other means exercise final control over an entity, considered such a legal entity, a trust, an investment fund, or any other patrimony of allocation or legal structure. Likewise, natural persons who provide funds to carry out an operation or in whose representation an operation is carried out will be considered beneficial owners. Final control will be understood as that exercised directly or indirectly through a chain of ownership or through any other means of control. In the case of trusts, the obligation established in the first paragraph will extend to natural persons who meet any of the conditions set forth in paragraphs three to five regarding the settlor, trustee, and beneficiary. Additionally, when it concerns persons who habitually manage third-party funds, what is provided in Article 197 will be taken into account.

ARTICLE 191 (MINIMUM INFORMATION). Securities intermediaries, investment fund administrators, and virtual asset service providers must maintain the Client Register which will contain all the Client Files, which must include as a minimum, the following data: i. Habitual Clients

  1. Natural Persons a) full name and surname b) date and place of birth c) copy of the identity document or confirmation of its consultation or verification by some official information source RR-SSF-2026-444 Date: 10/07/2026 16:00:25 CIRCULAR N°2507

d) registration number in the Single Tax Registry or in the corresponding tax authority e) marital status (if married or in a union concubinaria recognized judicially, name and identity document number of the spouse or partner) f) address and telephone number g) profession, trade, or main activity h) income volume It must be expressly stated whether the client is acting on their own behalf or on behalf of a third party, and in the latter case, obtain the aforementioned data regarding the beneficial owner. Likewise, the aforementioned data must be obtained regarding: a. all account holders b. attorneys-in-fact and authorized persons to operate on behalf of the client before the institution, with the exception of what is provided in letter g). With respect to the data on the income volume of the aforementioned persons, as well as the beneficial owner, it will be requested when these constitute a source of the account's income or of the funds managed by the client. 2) Legal Persons a) denomination b) date of incorporation c) address and telephone number d) registration number in the Single Tax Registry or in the corresponding tax authority e) documentation accrediting the incorporation in the form of the respective entity and its current authorities and representatives f) main activity g) income volume h) ownership and control structure of the company, establishing who its shareholders or owners are and noting who is the beneficial owner or controller of the company, if it is another person different from the aforementioned ones. The identification of shareholders or owners will correspond whenever they own a percentage of the capital greater than 15% (fifteen percent). i) confirmation of registration in the Register of Beneficial Owners (Law No. 19.484 of January 5, 2017) The data referred to in numeral 1) must also be obtained regarding the beneficial owner. Likewise, the aforementioned data must be obtained for natural persons acting on behalf of the legal person client, as well as for attorneys-in-fact and authorized persons to operate on their behalf before the institution, with the exception of what is provided in letter g). With respect to the data on the income volume of the aforementioned natural persons, as well as the beneficial owner, it will be requested when these constitute a source of the account's income or of the funds managed by the client. ii. Occasional Clients For those clients who carry out occasional transactions, including custody transfers, for an individual or accumulated amount less than USD 15,000 (fifteen thousand US dollars) or its equivalent in other currencies, the following information will be requested:

  1. Natural Persons a) full name and surname b) copy of the identity document or confirmation of its consultation or verification by some official information source c) address and telephone number
  2. Legal Persons a) denomination b) address and telephone number c) registration number in the Single Tax Registry, if such registration applies d) identification of the natural person carrying out the operation under the terms provided in the previous numeral 1), accrediting their quality of representative. For those clients who carry out transactions with virtual assets, the aforementioned threshold will be USD 1,000 (one thousand US dollars) or its equivalent in other currencies. TRANSITIONAL PROVISION: Virtual asset service providers that are in activity will have the following deadlines to comply with what is provided in this article regarding existing clients at the date of entry into force of the regulation: Client Type Deadline Higher risk clients 1 year Clients who operate by significant amounts 1 year Medium risk clients 1 year Lower risk clients 2 years

ARTICLE 191.1 (UPDATE OF CLIENT INFORMATION). Securities intermediaries, investment fund administrators, and virtual asset service providers must establish procedures that allow the update of the information they possess about their clients. These procedures must contemplate, among others, the periodic review of client information within the minimum timeframes indicated below: Client Type Minimum Update Deadline Higher risk clients 1 year Clients who operate by significant amounts 2 years Medium risk clients 3 years For lower risk clients, the procedures must contemplate the update of information when monitoring systems detect unusual or suspicious patterns in client behavior.

ARTICLE 192 (PRESERVATION OF INFORMATION). Securities intermediaries, investment fund administrators, and virtual asset service providers must preserve the records of all operations carried out with their clients or for their clients, as well as all information obtained in the due diligence process, for a minimum period of 5 (five) years after the end of the commercial relationship, in accordance with what is provided in Article 21 of Law No. 19.574 of December 20, 2017.

ARTICLE 193 (CLIENT ACTIVITY PROFILE). Securities intermediaries, investment fund administrators, and virtual asset service providers must determine the activity profile of their clients for the purpose of adequately monitoring their transactions.

ARTICLE 194 (INTENSIFIED DUE DILIGENCE PROCEDURES). Securities intermediaries, investment fund administrators, and virtual asset service providers must apply intensified due diligence procedures for client categories, commercial relationships, or operations considered higher risk, in accordance with what arises from the risk assessment performed by the institution. However, the following will be considered higher risk: a) commercial relationships and operations with non-resident clients coming from countries that do not comply with international standards in matters of money laundering, terrorism financing, and financing of the proliferation of weapons of mass destruction. b) transactions by those persons who link with the entity through operations where personal contact is not habitual under the terms provided in Article 190.1, such as in the case of clients who carry out operations through operational modalities that, using new or developing technologies, could favor client anonymity. c) politically exposed persons from abroad, as well as their family members and close associates. d) all those operations that are carried out under unusual circumstances according to the customs and practices of the respective activity. In application of intensified due diligence procedures, institutions must: i. obtain the approval of the main hierarchical levels of the institution when establishing or continuing a relationship with this type of client. ii. prepare a detailed report in which all elements considered to elaborate their activity profile will be explicit. The report must be adequately backed by documentation that allows establishing the patrimonial, economic, and financial situation or justifying the origin of the funds managed by the client. To this end, accounting statements with a Public Accountant's report, tax returns, responsibility statements, profit distribution minutes, sales contracts, or other documentation that allows complying with the aforementioned must be available. However, in all cases, copies of sworn declarations or equivalent documentation presented to the corresponding tax administration must be available. This requirement is exempted when it concerns referencing, advisory, and portfolio management services provided to non-resident clients of foreign financial institutions that are subject to regulation and supervision, provided that:

  • they do not receive from said clients - under any title - sums of money, securities, or precious metals,

  • the institutions ensure that the presentation of the referenced documentation is not a requirement established by the financial regulator of the foreign financial institution in its money laundering, terrorism financing, and financing of the proliferation of weapons of mass destruction prevention regulations, and RR-SSF-2026-444 Date: 10/07/2026 16:00:25 CIRCULAR N°2507

  • Obtain a certificate issued by the Tax Administration or a letter issued by a professional or the client's representatives indicating that they are up to date with their tax obligations. In the case of persons included in item c) whose annual transactions, according to their activity profile, reach amounts less than US$ 120,000 (one hundred twenty thousand US dollars) or its equivalent in other currencies, or carry out transactions up to said amount during a calendar year, only the documentation that allows establishing the patrimonial, economic and financial situation or justifying the origin of the funds managed by the client will be required. For the purpose of determining said threshold, the total amount to be deposited or deposited into the account will be considered, and in the case of transactions not associated with an account, their accumulated volume excluding those related to another operation, such as a currency purchase-sale followed by a transfer. iii. increase the frequency of updating client information, in accordance with what is provided in Article 191.1. iv. carry out more intense monitoring of the commercial relationship, increasing the quantity and frequency of controls applied. For those clients who operate by significant amounts, compliance with items ii. and iii. must also be met. The threshold to determine those clients who operate by significant amounts will be defined by each institution considering elements such as: i. the maintenance of funds under management greater than a determined amount; ii. wholesale client who enters extraordinary funds into their account or processes transactions for amounts greater than a minimum value established for a determined period, regardless of the activity profile that had been assigned to them; iii. retail client who proposes to carry out a transaction that exceeds an established amount.

ARTICLE 196 (POLITICALLY EXPOSED PERSONS). A "politically exposed person" is understood to be a person who holds or has held in the last 5 (five) years important public functions in the country or abroad, such as: Heads of State or Government, high-ranking politicians, high-ranking government, judicial or military officials, representatives and RR-SSF-2026-444 Date: 10/07/2026 16:00:25 CIRCULAR N°2507

senators of the Legislative Power, prominent leaders of political parties, directors and high executives of state-owned companies and other public entities. Politically exposed persons are also understood to be those persons who hold or have held in the last 5 (five) years a high-ranking function in an international organization, such as: senior management members, directors, deputy directors, board members or equivalent functions. Securities intermediaries, investment fund administrators and virtual asset service providers must have procedures that allow them to determine when a client or beneficial owner is a politically exposed person, a family member or close associate of a politically exposed person. In the case of having clients who are local politically exposed persons of low and medium risk, in addition to executing the due diligence procedures provided for in Article 189, institutions must carry out more intense monitoring of the commercial relationship, increasing the quantity and frequency of controls applied. The due diligence intensified procedures provided for in items i. to iv. of Article 194 will apply to foreign politically exposed persons. Likewise, said procedures must be applied to local politically exposed persons in which the institution has identified a higher-risk commercial relationship.

ARTICLE 197 (ACCOUNTS OPENED OR TRANSACTIONS RELATED TO NATURAL OR LEGAL PERSONS WHO HANDLE THIRD-PARTY FUNDS). Clients who handle third-party funds coming from or related to the development of professional, financial, commercial or savings activities are considered included in this provision, such as: • Purchase-sale, construction, promotion, investment or administration of real estate. • Purchase-sale of commercial establishments. • Administration or custody of money, bank accounts, securities or other assets. • Investments or financial transactions in general, including payment and collection services. • Creation, operation or administration of legal entities or other legal institutes. • Foreign trade operations, including intermediation operations, in which payments or collections are made on behalf of third parties. • Livestock sale and consignment operations. RR-SSF-2026-444 Date: 10/07/2026 16:00:25 CIRCULAR N°2507

Transactions or accounts that involve third-party funds solely for professional fees or commissions of the holder are exempted. Securities intermediaries, investment fund administrators and virtual asset service providers must have effective procedures to detect all accounts opened or transactions processed by natural or legal persons who habitually handle third-party funds, and carry out adequate monitoring of their operations. In those cases where institutions consider it necessary based on the risk assessment performed, they must identify the beneficial owner of the transactions and obtain information on the origin of the funds. At a minimum, they must observe the principles set out below, depending on the type of client in question: a) Clients subject to financial regulation and supervision Institutions will apply to these clients the due diligence procedures referred to in item c), with the exception of the following cases: i. when it concerns transactions related to foreign correspondent financial institutions operating under the terms of Article 197.1; ii. when it concerns transactions related to national or foreign financial institutions whose policies and procedures for the prevention and control of money laundering, terrorist financing and the financing of the proliferation of weapons of mass destruction have been favorably evaluated by the institution. b) Clients subject to regulation and supervision of the National Secretariat against Money Laundering and Terrorist Financing Institutions will apply to these clients the due diligence procedures referred to in item c), except when any of the activities mentioned in this article are carried out with a non-financial obligated subject under the terms of Law No. 19.574 of December 20, 2017, whose policies and procedures for the prevention and control of money laundering, terrorist financing and the financing of the proliferation of weapons of mass destruction have been favorably evaluated by the institution. c) Other clients RR-SSF-2026-444 Date: 10/07/2026 16:00:25 CIRCULAR N°2507

The activity of these clients will be considered as higher risk and intensified due diligence procedures will apply in the following cases: i. Clients who carry out transactions for amounts greater than US$ 600,000 (six hundred thousand US dollars) or its equivalent in other currencies, in a calendar year. For these purposes, the total amount deposited into the account will be considered, and in the case of transactions not associated with an account, their accumulated volume excluding those related to another operation. The procedures to monitor the client's activity must allow the institution to also monitor the accumulated operations of the third party whose funds are managed by the client and identify possible structuring. The beneficial owner of all operations greater than US$ 50,000 (fifty thousand US dollars) or its equivalent in other currencies must be identified, or, failing that, define alternative procedures that make it possible to identify them, such as the receipt of periodic reports, in which the client declares the amounts of transactions carried out in a determined period, for each of the different beneficial owners of the operations. The identification of the beneficial owner must be carried out - at a minimum - with the full name and surname, copy of the identity document and address, or by means of a copy of the supporting documentation of the transaction that originates the funds when these data arise from it. Once a client exceeds the established threshold of US$ 600,000 (six hundred thousand US dollars) or its equivalent in other currencies, the intensified due diligence procedures will begin to be applied immediately. From the following calendar year, these procedures must be applied from the beginning of the period, except in those cases where the institution can establish on reasonable grounds that the threshold was exceeded as a result of punctual operations and that this is not the expected profile of the account. ii. Clients who carry out financial transactions for amounts greater than US$ 100,000 (one hundred thousand US dollars) or its equivalent in other currencies, even if the accumulated operation does not reach the threshold mentioned in item i). Institutions must identify the beneficial owners in the manner indicated. RR-SSF-2026-444 Date: 10/07/2026 16:00:25 CIRCULAR N°2507

In addition to what is established in items i) and ii), and depending on the amounts operated by each identified beneficial owner and the risk associated with their operation, the institution must define information and documentation requirements to determine the background and economic activity developed by the third party whose funds are managed by the client, as well as the origin of said funds. Notwithstanding what is established in the preceding items a) and b):

  • the procedures must contemplate the requirement of information on the client and the origin of the funds in the case of operations that - due to their amount, country of origin or other conditions - present some characteristic of high risk in the judgment of the institution.
  • when securities intermediaries, investment fund administrators and virtual asset service providers receive money in cash, precious metals or other monetary instruments from abroad that do not come from financial intermediation institutions operating under the terms of Article 197.1, they must carry out - in all cases - a special examination of said transactions to determine the beneficial owner of the operation and the legitimate origin of the received funds. Regardless of the type of client in question, when they refuse to provide information on the beneficiaries of any transaction, or on the origin of the managed funds, the institution must examine it in detail to determine if it constitutes an unusual or suspicious transaction that must be reported to the Financial Information and Analysis Unit. Likewise, in case this situation recurs, the commercial relationship with this client must be restricted or terminated.

ARTICLE 197.1 (CORRESPONDENT FINANCIAL INSTITUTIONS). Securities intermediaries and virtual asset service providers must apply special due diligence procedures when establishing correspondent relationships with foreign financial institutions, under operational conditions that enable them to maintain accounts or carry out transactions for their own clients through the local institution. To this end, institutions must:

  1. Obtain sufficient information on said foreign institutions to know: a) the nature of their business, the reputation of the institution, management, main activities and where they are located; b) purpose of the account or transaction; c) regulation and supervision in their country, including whether it has been subject or not to an investigation on money laundering, terrorist financing and the financing of the proliferation of weapons of mass destruction or a regulatory action.
  2. Evaluate the policies and procedures of the foreign institution, including the controls implemented, to prevent being used for money laundering, terrorist financing and the financing of the proliferation of weapons of mass destruction, among others.
  3. Understand and document the respective responsibilities of each entity.
  4. Obtain the approval of the main hierarchical levels of the institution when establishing the correspondent relationship. The foreign financial institutions referred to in this article must be authorized operators of the foreign banking, exchange, insurance, securities, remittance or other formal financial markets, be subject to regulation and supervision and have customer acceptance and knowledge policies that have been favorably evaluated by the local institution. Business relationships must not be established with financial institutions constituted in jurisdictions that do not require physical presence nor establish correspondent relationships with foreign financial institutions, when these allow their accounts to be used by this type of institutions.

ARTICLE 198.2 (IDENTIFICATION OF THE HOLDER OR ORDERER IN VIRTUAL ASSET TRANSFERS ISSUED BY VIRTUAL ASSET SERVICE PROVIDERS). Virtual asset service providers that originate virtual asset transfers - domestic or with abroad - must include, in the message itself that instructs the transfer, precise and significant information regarding the holder or orderer, including - at a minimum - information on: A. Natural Person:

  • full name
  • home address
  • date and place of birth
  • identity card or identification number
  • account number and type (when it is used to process the transaction) or virtual asset wallet address, as applicable. In case of no account, the reference code that has a function equivalent to the account number.
  • date of the transfer
  • transaction identifier that allows its tracking
  • type and quantity of each virtual asset transferred
  • exchange rates used and their source RR-SSF-2026-444 Date: 10/07/2026 16:00:25 CIRCULAR N°2507

B. Legal Person:

  • company name (trade name and trade name if applicable)
  • Unique Tax Registry number of the General Tax Directorate and the Social Security Bank
  • real and constituted address
  • natural person who represents it in the transaction, proceeding to verify the information on their identity and representation
  • account number and type (when it is used to process the transaction) or virtual asset wallet address, as applicable. In case of no account, the reference code that has a function equivalent to the account number.
  • date of the transfer
  • transaction identifier that allows its tracking
  • type and quantity of each virtual asset transferred
  • exchange rates used and their source The prior consent of the client will be obtained. If the client does not grant the requested authorization, the provider must not process the operation. Virtual asset service providers must also adequately identify the beneficiaries of the issued transfers, recording in the message itself identical information to that required for the holder or orderer. In the case of domestic transfers for amounts less than or equal to US$ 1,000 (one thousand US dollars) or its equivalent in other currencies, the message may include only the account number of the orderer and beneficiary, provided that the originating institution can track the transaction and complete the information at the request of the beneficiary institution or competent authorities within a maximum period of 48 (forty-eight) business hours. Virtual asset service providers must not process transfers if they do not have all the data required previously. For the purposes of this article, virtual asset transfers comprise domestic and foreign transfers, received and issued by virtual asset service providers, being the counterparty another virtual asset service provider and regardless of the operational modality used for its execution. TRANSITIONAL PROVISION: Virtual asset service providers will have until December 31, 2027 to adapt their systems to what is provided for in this article. RR-SSF-2026-444 Date: 10/07/2026 16:00:25 CIRCULAR N°2507

ARTICLE 198.3 (IDENTIFICATION OF THE HOLDER OR ORDERER IN VIRTUAL ASSET TRANSFERS RECEIVED BY VIRTUAL ASSET SERVICE PROVIDERS). Virtual asset service providers that receive virtual asset transfers - domestic or from abroad - must have effective procedures that allow obtaining precise and significant information regarding the holder or orderer, including - at a minimum - information on: A. Natural Person:

  • full name

  • home address

  • date and place of birth

  • identity card or identification number

  • account number and type (when it is used to process the transaction) or virtual asset wallet address, as applicable. In case of no account, the reference code that has a function equivalent to the account number.

  • date of receipt

  • transaction identifier that allows its tracking

  • type and quantity of each virtual asset received

  • date of the remittance

  • exchange rates used for the remittance and their origin

  • if the remittance is in virtual currency: type and quantity of each currency involved in the remittance

  • if the remittance is not in virtual currency: type of remittance and its value, if it differs from the amount of virtual currency received

  • proof of virtual currency exchange transaction with respect to each virtual currency exchange transaction. B. Legal Person:

  • company name (trade name and trade name if applicable)

  • Unique Tax Registry number of the General Tax Directorate and the Social Security Bank

  • real and constituted address

  • natural person who represents it in the transaction, proceeding to verify the information on their identity and representation

  • account number and type (when it is used to process the transaction) or virtual asset wallet address, as applicable. In case of no account, the reference code that has a function equivalent to the account number.

  • date of receipt

  • transaction identifier that allows its tracking

  • type and quantity of each virtual asset received

  • date of the remittance

  • exchange rates used for the remittance and their origin

  • if the remittance is in virtual currency: type and quantity of each currency involved in the remittance RR-SSF-2026-444 Date: 10/07/2026 16:00:25 CIRCULAR N°2507

  • if the remittance is not in virtual currency: type of remittance and its value, if it differs from the amount of virtual currency received

  • proof of virtual currency exchange transaction with respect to each virtual currency exchange transaction. They must also carry out a detailed examination of said transfers to determine if they constitute an unusual or suspicious transaction that must be reported to the Financial Information and Analysis Unit. The receiving provider must consider the convenience of restricting or terminating their business relationship with those virtual asset service providers that do not comply with the standards in matters of identification of the orderers of the transfers. Virtual asset service providers must also adequately identify the beneficiaries of the received transfers, recording in the message itself identical information to that required for the holder or orderer. When it comes to domestic transfers for amounts less than or equal to US$ 1,000 (one thousand US dollars) or its equivalent in other currencies, the information may include only the account number of the orderer and beneficiary, provided that the receiving institution can track the transaction and complete the information at the request of the beneficiary institution or competent authorities within a maximum period of 48 (forty-eight) business hours. Virtual asset service providers must not receive transfers if they do not have all the data required previously.

ARTICLE 199 (CONFIDENTIALITY). Securities intermediaries, investment fund administrators and virtual asset service providers may not make known to the persons involved or to third parties, the actions or reports that they carry out or produce in compliance with their duty to inform or in response to a request for information that has been made to them by the Financial Information and Analysis Unit.

ARTICLE 200 (EXAMINATION OF OPERATIONS). Securities intermediaries, investment fund administrators and virtual asset service providers must pay attention to those transactions that result unusual or complex or of great magnitude and leave written record of: i. the controls and verifications they carry out to determine their background and purposes, and ii. the conclusions of the examination performed, in which the elements that were taken into account to confirm or discard the unusual nature of the operation will be specified. They must also leave a record of the controls carried out to determine the existence of goods or transactions that may be RR-SSF-2026-444 Date: 10/07/2026 16:00:25 CIRCULAR N°2507

linked to persons or organizations related to terrorist activities indicated in Article 203. All information mentioned in this article shall be kept available to the Central Bank of Uruguay and the entity's external auditor.

ARTICLE 201 (GUIDELINES FOR SUSPICIOUS OR UNUSUAL TRANSACTIONS). The Financial Information and Analysis Unit shall issue guidelines for transactions that help detect suspicious patterns in the behavior of clients of subjects obligated to report. Securities intermediaries, investment fund administrators, and virtual asset service providers shall disseminate the content of these guidelines among their personnel to alert them regarding the potential risk of money laundering, terrorist financing, and the financing of the proliferation of weapons of mass destruction associated with the transactions described therein.

  1. SUBSTITUTE in Chapter III - VERIFICATION OF LISTS, PREVENTIVE FREEZING AND REPORTING of Title I - PREVENTION OF THE USE OF SECURITIES INTERMEDIARIES, INVESTMENT FUND ADMINISTRATORS AND VIRTUAL ASSET SERVICE PROVIDERS FOR MONEY LAUNDERING, TERRORIST FINANCING AND FINANCING OF THE PROLIFERATION OF WEAPONS OF MASS DESTRUCTION of Book III - PROTECTION OF THE FINANCIAL SYSTEM AGAINST ILLEGAL ACTIVITIES of the Compilation of Securities Market Regulations articles 202, 203, 204.2 and 205 with the following:

ARTICLE 202 (OBLIGATION TO REPORT SUSPICIOUS OR UNUSUAL OPERATIONS). Securities intermediaries, investment fund administrators, and virtual asset service providers shall be obligated to report to the Financial Information and Analysis Unit transactions, whether carried out or not, that, in the usages and customs of the respective activity, appear unusual, present themselves without evident economic or legal justification, or are posed with unusual or unjustified complexity, as well as financial transactions involving assets regarding which there are suspicions of illicit origin, for the purpose of preventing the crime of money laundering, terrorist financing, and the financing of the proliferation of weapons of mass destruction. In the latter case, the obligation to report extends even to those operations that - even involving assets of lawful origin - are suspected of being linked to natural or legal persons included in said crime or destined to finance any terrorist activity. The information shall be communicated immediately upon being qualified as such, even if the operations have not been effectively RR-SSF-2026-444 Date: 10/07/2026 16:00:25 CIRCULAR N°2507

concretized by the institution, either because the client desisted from carrying it out or because the institution resolved not to process it. The communication shall be carried out in accordance with the instructions issued by the Financial Information and Analysis Unit for these purposes.

ARTICLE 203 (OBLIGATION TO VERIFY LISTS, PREVENTIVE FREEZING AND REPORTING). Securities intermediaries, investment fund administrators, and virtual asset service providers shall permanently control and verify: A. Lists of individuals or entities associated with terrorist organizations, compiled by the United Nations Organization pursuant to Resolutions of the Security Council of said Organization. B. Lists of individuals or entities linked to the financing of the proliferation of weapons of mass destruction, compiled pursuant to Resolutions of the Security Council of the United Nations Organization. C. Designations of natural or legal persons or entities, pursuant to Resolution S/RES/1373 of the Security Council of the United Nations Organization. D. The roster of persons declared terrorists by final national or foreign judicial resolution. If there is a match of natural or legal persons or entities with the names or identification data arising from said lists or designations, securities intermediaries, investment fund administrators, and virtual asset service providers shall proceed to the immediate and without delay preventive freezing of the funds and other financial assets or economic resources of said persons or entities, and also prevent the entry of funds available to them. Likewise, securities intermediaries, investment fund administrators, and virtual asset service providers shall immediately report to the Financial Information and Analysis Unit of the Central Bank of Uruguay that they have carried out a preventive freeze, in accordance with instructions that will be issued.

ARTICLE 204.2 (REPORT OF FINANCIAL TRANSACTIONS - VIRTUAL ASSET SERVICE PROVIDERS AND VIRTUAL ASSET SERVICE PROVIDERS). Virtual asset service providers shall provide the Financial Information and Analysis Unit with information about natural or legal persons who carry out the following transactions: i. receipt of cash from clients for amounts greater than US$ 10,000 (ten thousand USA dollars) or its equivalent in other currencies. RR-SSF-2026-444 Date: 10/07/2026 16:00:25 CIRCULAR N°2507

ii. cash withdrawals from clients for amounts greater than US$ 10,000 (ten thousand USA dollars) or its equivalent in other currencies. iii. receipt of funds (both from clients and from third parties for the clients) via local or foreign drafts and transfers, for amounts greater than US$ 1,000 (one thousand USA dollars) or its equivalent in other currencies, regardless of the operational modality used for its execution. iv. delivery of funds (whether to clients or to third parties on behalf of the clients) via local or foreign drafts and transfers, for amounts greater than US$ 1,000 (one thousand USA dollars) or its equivalent in other currencies, regardless of the operational modality used for its execution. In the operations covered by items i. and ii., information regarding transactions for amounts below the defined threshold must also be communicated when the sum of operations carried out in a specific account exceeds US$ 10,000 (ten thousand USA dollars) or its equivalent in other currencies, during the course of a calendar month. The communication of information about the natural or legal persons carrying out the transactions covered by the preceding items shall be carried out in accordance with the instructions that will be issued.

ARTICLE 205 (INTERNAL REPORT OF SUSPICIOUS OR UNUSUAL TRANSACTIONS). Securities intermediaries, investment fund administrators, and virtual asset service providers shall implement and make known to their personnel internal procedures that ensure that all transactions that may be considered suspicious or unusual are brought to the attention of the Compliance Officer. The channels for reporting suspicious operations must be clearly established in writing and communicated to all personnel.

  1. SUBSTITUTE in Chapter IV - OTHER PROVISIONS of Title I - PREVENTION OF THE USE OF SECURITIES INTERMEDIARIES, INVESTMENT FUND ADMINISTRATORS AND VIRTUAL ASSET SERVICE PROVIDERS FOR MONEY LAUNDERING, TERRORIST FINANCING AND FINANCING OF THE PROLIFERATION OF WEAPONS OF MASS DESTRUCTION of Book III - PROTECTION OF THE FINANCIAL SYSTEM AGAINST ILLEGAL ACTIVITIES of the Compilation of Securities Market Regulations article 206 with the following:

ARTICLE 206 (TRANSPORT OF VALUES ACROSS BORDERS). Securities intermediaries, investment fund administrators, and virtual asset service providers that transport cash, precious metals, or other monetary instruments across the border for an amount greater than US$ 10,000 (ten thousand USA dollars) or its equivalent in other currencies, shall communicate this to the Central Bank of Uruguay in accordance with the instructions that will be issued.

  1. SUBSTITUTE in Chapter I - GENERAL PRINCIPLES of Title I - RELATIONSHIP WITH CLIENTS of Book IV - PROTECTION OF THE USER OF FINANCIAL SERVICES of the Compilation of Securities Market Regulations article 208.1 with the following:

ARTICLE 208.1 (SCOPE OF APPLICATION). The articles contained in this chapter are applicable to companies administering crowdfunding platforms, securities intermediaries, investment advisors, portfolio managers, virtual asset service providers, and investment fund administrators, unless the supervised institution to which it applies is specified in the article itself.

  1. SUBSTITUTE in Chapter II – CODE OF GOOD PRACTICES of Title I - RELATIONSHIP WITH CLIENTS of Book IV - PROTECTION OF THE USER OF FINANCIAL SERVICES of the Compilation of Securities Market Regulations article 208.3 with the following:

ARTICLE 208.3 (SCOPE OF APPLICATION). The articles contained in this Chapter are applicable to companies administering crowdfunding platforms, securities intermediaries, investment advisors, portfolio managers, virtual asset service providers, and investment fund administrators, unless the supervised institution to which it applies is specified in the article itself.

  1. SUBSTITUTE in Chapter III – CLAIMS ATTENTION of Title I - RELATIONSHIP WITH CLIENTS of Book IV - PROTECTION OF THE USER OF FINANCIAL SERVICES of the Compilation of Securities Market Regulations article 208.7 with the following:

ARTICLE 208.7 (SCOPE OF APPLICATION). The articles contained in this Chapter are applicable to companies administering crowdfunding platforms, securities intermediaries, investment advisors, portfolio managers, virtual asset service providers, and investment fund administrators, unless the supervised institution to which it applies is specified in the article itself.

  1. RENAME Chapter IV - SERVICES PROVIDED BY SECURITIES INTERMEDIARIES, INVESTMENT ADVISORS AND PORTFOLIO MANAGERS of Title I - RELATIONSHIP WITH CLIENTS of Book IV - PROTECTION OF THE USER OF FINANCIAL SERVICES of the Compilation of Securities Market Regulations, which shall be renamed Chapter IV - SERVICES PROVIDED BY SECURITIES INTERMEDIARIES, INVESTMENT ADVISORS, PORTFOLIO MANAGERS AND VIRTUAL ASSET SERVICE PROVIDERS. RR-SSF-2026-444 Date: 10/07/2026 16:00:25 CIRCULAR N°2507

  2. SUBSTITUTE in Chapter IV - SERVICES PROVIDED BY SECURITIES INTERMEDIARIES, INVESTMENT ADVISORS, PORTFOLIO MANAGERS AND VIRTUAL ASSET SERVICE PROVIDERS of Title I - RELATIONSHIP WITH CLIENTS of Book IV - PROTECTION OF THE USER OF FINANCIAL SERVICES of the Compilation of Securities Market Regulations article 208.10 with the following:

ARTICLE 208.10 (CONTRACTS). The services provided by securities intermediaries, investment advisors, portfolio managers, and virtual asset service providers that provide the services referred to in letters d. or e. of article 127.22 shall be preceded by the signing of a written contract in which the responsibilities assumed by each of the parties are clearly delimited, and in particular in the case of securities intermediaries, the provisions of article 209 shall be recorded. In order routing activities, the contract shall provide for the existence of powers of attorney granted by clients for the routing of orders on their behalf and representation to securities intermediaries. In portfolio management activities, the existence of a management power granted by the client shall be provided for, which will allow making decisions regarding their investments and ordering operations to securities intermediaries on their behalf and representation. Operations shall be settled between client accounts, and the powers granted shall in no case include authority to make disbursements or transfers of funds or securities to third parties. For the purposes of said powers, the autonomy of will of the parties shall prevail, provided that through them the securities intermediary, investment advisor, or portfolio manager is not authorized to carry out activities unrelated to what is stipulated in articles 62, 124.1, or 127.8, respectively. Furthermore, in the case where the products offered in advisory and portfolio management activities are limited to those provided by a specific entity of the country or abroad with which business is conducted exclusively, this circumstance shall be specified in the contract. With regard to the provision of services on virtual assets referred to in letters d. and e. of article 127.22, the contract shall contain - at a minimum - the following elements: i. the modality of the service provided and a description of it ii. the custody policy, if applicable iii. the commissions, expenses, and charges applied iv. the applicable jurisdiction Contracts and the various information that the institution provides to its clients shall always be in Spanish. When the client is a resident of a country whose official language is different from Spanish, it is admitted that the contract be drafted in another language. Furthermore, they shall be drafted in such a way as to facilitate their reading; in particular, easily legible characters, clear language, titles and subtitles, bold and underlined letters, and adequate layout in terms of styles, spacing, and any other characteristic that facilitates comprehension shall be used. The typographic characters used in standard form contracts shall in no case be less than 10 points in size. The signing of a written contract is not required for the provision of referencing services to other institutions. It is also not required for the case of investment advisory services provided to clients of an institution abroad within the framework of a contract celebrated with said institution, provided that this assumes responsibility for the provision of the service. TRANSITIONAL PROVISION: Virtual asset service providers that provide the services referred to in letters d. or e. of article 127.22 and are in operation shall have until December 31, 2027, to comply with the modifications established regarding existing clients at the date of its entry into force.

  1. INCORPORATE in Chapter IV - SERVICES PROVIDED BY SECURITIES INTERMEDIARIES, INVESTMENT ADVISORS, PORTFOLIO MANAGERS AND VIRTUAL ASSET SERVICE PROVIDERS of Title I - RELATIONSHIP WITH CLIENTS of Book IV - PROTECTION OF THE USER OF FINANCIAL SERVICES of the Compilation of Securities Market Regulations the following articles:

ARTICLE 211.2 (INFORMATION TO CLIENTS - VIRTUAL ASSET SERVICE PROVIDERS). Virtual asset service providers shall provide their clients with clear, sufficient, truthful, and timely information regarding the characteristics and risks of virtual assets, so as to allow them to make informed decisions. Under no circumstances shall significant informational elements be hidden, nor shall inaccurate references or expressions susceptible of generating error, deception, or confusion in clients regarding any characteristic of the products and services involved be employed. Virtual asset service providers shall make available to clients the Communication in which the authorization to operate issued by the Superintendency of Financial Services is recorded. RR-SSF-2026-444 Date: 10/07/2026 16:00:25 CIRCULAR N°2507

Likewise, they shall provide on their website or on the platforms where they offer services to their clients, at a minimum, the following information: a) The business model applied, including the conditions and terms of the service, hours, and any other relevant information, when carrying out operations or at the time of contracting the service. In the case where the services offered are limited to those provided by a specific entity of the country or abroad, this circumstance shall be specified to the client, indicating the name of said entity. b) The specification of costs that the client will incur in the different types of operations offered, indicating concept (charges, expenses, commissions, fees, and other applicable amounts), amount, billing periodicity, and whether each is mandatory or optional, indicating the conditions for modification, the means, and the deadline that will be used for prior notice to the client. In the case of exchange of virtual assets from the provider's own portfolio, the client shall be informed of the price differential applied in relation to the reference price of the instrument. This differential may be expressed in absolute or percentage terms. In cases where the virtual asset service provider uses or operates through automated terminals, a sign with the commissions and other charges imposed by the operator of said terminals shall appear - in a clearly visible place, indicating the exact amount and the reason for the charge. If not, said sign may contain a notice indicating that said commissions and charges can be consulted on the screen or via a toll-free phone number on the terminal. Whenever the service requested by the client implies any commission or any type of charge imposed or passed on to the client by the operator, a message on the screen indicating the amount shall be provided, allowing - at no cost to the client - to desist from carrying out said operation. c) Receipts of any operation carried out on behalf and order of the client within or outside any asset trading market, which shall be issued upon the mere request of the client. d) The nature and risks associated with carrying out operations with virtual assets, warning that users will assume the risk of total or partial loss of capital or funds associated with said assets or their change in value. To this effect, the virtual asset service provider shall obtain, by the means it deems pertinent, a declaration stating that the client has taken knowledge of the existing risks. RR-SSF-2026-444 Date: 10/07/2026 16:00:25 CIRCULAR N°2507

ARTICLE 211.2.1 (INFORMATION AVAILABLE TO THE PUBLIC IN CONTRACTING INSTITUTIONS OF CORRESPONDENCE SERVICES). Virtual asset service providers shall make available to the public on their website or in their premises, if applicable, the following updated information regarding financial correspondents hired directly and those hired by correspondent administrators:

  • Legal name and denomination.
  • Address, telephone, fax, email address, and website.
  • Hours of operation.

ARTICLE 211.2.2 (INFORMATION AVAILABLE TO CLIENTS IN THE PREMISES OF FINANCIAL CORRESPONDENTS). Financial correspondents shall make the following information available to the institution's clients in their premises: a. Correspondence services provided, indicating the contracting virtual asset service provider and the services provided on their behalf, and must inform:

  • Limits per person, per type of transaction, per number of operations, or others, as well as the other conditions for the provision of said services.
  • Addresses of the nearest branches of the contracting provider.
  • Available channels for receiving claims.
  • Public service hours. b. That the contracting virtual asset service provider is fully responsible before clients for the services provided through the financial correspondent. c. Any other information that must be available to clients in accordance with the provisions of this Book.

ARTICLE 211.3 (OFFER OF VIRTUAL ASSETS). Virtual asset service providers that provide the services referred to in letter e. of article 127.22 may only offer their clients virtual assets that contain general information in the "white paper" or prospectuses with relevant information about the issuer and the project, which shall be published or linked on the website, must be easily accessible, and available at all times in Spanish or English.

ARTICLE 211.4 (DELIVERY OF ACCOUNT STATEMENTS TO CLIENTS - VIRTUAL ASSET SERVICE PROVIDERS). Virtual asset service providers that provide the services referred to in letter d. of article 127.22 shall make available to their clients information regarding the transactions carried out, the rate RR-SSF-2026-444 Date: 10/07/2026 16:00:25 CIRCULAR N°2507

of the weighted average performance of the client's portfolio where applicable and the commissions applied in each of them. The provider must electronically send or facilitate, when the client so requests, a statement of position of the virtual assets registered in the name of said client. The statement of position will identify the virtual assets in question, their balance, their value, and the operations carried out during the considered period. The delivery modality of the same must be defined by the client in writing, as well as its periodicity, which must be at least annual. Notwithstanding the foregoing, the provider must provide the client who expressly requests it with the information regarding said reporting at any time.

ARTICLE 213.2 (CLIENT PROFILE - VIRTUAL ASSET SERVICE PROVIDERS). Virtual asset service providers that provide administration services or other means that allow control over virtual assets must determine the categories in which they will classify each of their clients, based on the degree of risk, sophistication, and knowledge of each of them, with the purpose of identifying the different products and operations consistent with said categories. To this end, they will consider, among others, the following personal circumstances of the client: • investor's age; • investment time horizon; • investment objectives; • volume of income received; • risk tolerance; • financial knowledge that facilitates the client's understanding of the instruments in which they will invest; • desired profitability; • previous experience in investment matters (nature, frequency, and volume of investments made by the client in the instrument in which they intend to invest). Based on the preceding elements, a specific investment profile will be assigned to the clients. In the event that the client or potential client does not provide the requested information, they must be warned that such decision prevents determining whether the intended service is suitable for them. Each of these profiles must contain definitions regarding the type and terms of the assets in which to invest, investment limits, level of risk tolerance, among others.

RR-SSF-2026-444 Date: 10/07/2026 16:00:25 CIRCULAR N°2507

Once the profile is assigned to the client, it must be notified, and their consent must be obtained through previously agreed means and the corresponding record must be kept. Procedures must be established that allow ensuring that the services provided correspond to the profiles, as well as to resolve those situations in which the client decides to deviate from the initially established profile, obtaining their consent through previously agreed means and keeping the corresponding record.

ARTICLE 214.1 (PERSONNEL TRAINING - VIRTUAL ASSET SERVICE PROVIDERS). Virtual asset service providers must adopt the necessary measures so that managers, executives, and senior staff have adequate training for the prudent and diligent performance of their functions, considering also what is required in section ii. of letter b. of article 186. The compliance with this requirement must be duly documented.

ARTICLE 214.2 (AUTHENTICATION METHODOLOGIES). Virtual asset service providers must establish measures that reasonably guarantee the security of the system made available to their clients to operate, which include authentication methodologies associated with the risks of the different types of transactions and access levels to ensure that the operations carried out in it are those carried out by authorized persons. Notwithstanding the foregoing, transfers to third parties that are carried out remotely will require as a minimum a double factor of authentication. Likewise, they must establish monitoring and control measures that allow detecting irregular events linked to the use of the instrument or the system in which they operate, including changes and attempts to change passwords, personal identification numbers, address, phone, and contact email, means established to receive communications, among others. Such system must safeguard, at a minimum: · dates and times of operations; · content of messages; · identification of operators, senders, and receivers; · accounts and amounts involved; · user authentication mechanism used in the operation; · identification of the terminal from which the operation was performed; and · whether the operation was carried out in person or remotely. Additionally, they must ensure the correct functioning of the system, and the continuous provision of the service, under normal circumstances.

ARTICLE 214.3 (ENHANCED CLIENT AUTHENTICATION). For the application of the double factor of authentication referred to in article 214.2, at least two factors of distinct categories (knowledge, possession, and inherence) must be combined.

RR-SSF-2026-444 Date: 10/07/2026 16:00:25 CIRCULAR N°2507

  1. SUBSTITUTE in Section II - ADVERTISING CARRIED OUT BY SUPERVISED INSTITUTIONS of Chapter I - ADVERTISING of Title I - TRANSPARENCY of Book V - TRANSPARENCY AND MARKET CONDUCT of the Compilation of Securities Market Regulations article 226.1 with the following:

ARTICLE 226.1 (ADVERTISING). Stock exchanges, securities intermediaries, investment advisors, portfolio managers, virtual asset service providers, investment fund management companies, financial trustees, securities depositories, rating agencies, and companies managing crowdfunding platforms may only carry out advertising from the date of authorization or registration, as applicable, by the Superintendence of Financial Services. All advertising that institutions carry out by any means must be clear, truthful, and not induce errors or confusion. According to article 24 of Law No. 17.250 of August 11, 2000, any misleading advertising is prohibited. Misleading advertising is understood as any modality of information or communication contained in advertising messages that is wholly or partially false, or in any other way, even by omission of essential data, capable of inducing the consumer to error regarding the nature, quantity, origin, price, of the products and services.

  1. SUBSTITUTE in Chapter IV - INSIDER INFORMATION of Title I - TRANSPARENCY of Book V - TRANSPARENCY AND MARKET CONDUCT of the Compilation of Securities Market Regulations articles 246.2, 246.4, and 246.6 with the following:

ARTICLE 246.2 (MISUSE OF INSIDER INFORMATION). The actions defined below constitute misuse of insider information: i. Revealing or confiding insider information before it is disclosed to the market. ii. Recommending the execution of operations with securities on which insider information is held. iii. Acquiring or disposing of - for oneself or for third parties, directly or indirectly - securities or assets on which insider information is possessed. iv. In general, making use of insider information directly or indirectly, for one's own benefit or that of third parties. Entities, the persons listed below, and in general, any person who by reason of their position or role possesses insider information, must abstain from carrying out the actions detailed in the preceding paragraph: a. Directors, administrators, managers, and liquidators of the issuer.

RR-SSF-2026-444 Date: 10/07/2026 16:00:25 CIRCULAR N°2507

b. The persons indicated in the preceding letter a., who perform tasks in the controlling company or in controlled companies. c. The external auditor or senior staff of the external audit firm of the issuer. d. Partners, administrators, managers, and qualified technicians of rating agencies that rate the issuer or the securities issued by it. e. Professionals who provide services to the issuer on a permanent or temporary basis, to the extent that the nature of their services allows them access to such information. f. Senior staff of securities intermediaries, investment fund management companies, investment advisors, portfolio managers, and virtual asset service providers, members of the Board or similar body, and persons assigned to the direction of securities operations of specialized investors, as well as professionals who provide services to them under the terms of the preceding letter e. g. Natural persons authorized to enter orders on behalf of securities intermediaries and specialized investors. h. Senior staff of stock exchanges and companies managing crowdfunding platforms on which the security is registered for trading.

ARTICLE 246.4 (PREVENTION OF THE FLOW OF INSIDER INFORMATION). Stock exchanges, companies managing crowdfunding platforms, securities intermediaries, investment advisors, portfolio managers, specialized investors, investment fund management companies, and virtual asset service providers must implement policies, procedures, and control mechanisms to prevent and control the flow of insider information in order to promote: a. The identification of insider information generated by the entity or to which it may have access in relation to issuers and their securities. b. The control of the custody, archiving, access, reproduction, and distribution of insider information. In the case of securities intermediaries, investment advisors, portfolio managers, specialized investors, investment fund management companies, and virtual asset service providers that provide the services referred to in letter d. of article 127.22, said control must include the definition of a system to prevent investment decisions that are made directly or advised to clients from being influenced by knowledge of insider information.

RR-SSF-2026-444 Date: 10/07/2026 16:00:25 CIRCULAR N°2507

c. That insider information is communicated only to those persons (internal and external) who must know it, with prior warning that it is information of this nature subject to the prohibitions referred to in article 246.2. d. The detection of operations that give rise to suspicion of being based on the misuse of insider information. To this end, they must consider, among other factors, the abnormal evolution of contracted volumes and negotiated prices, compared to past periods.

ARTICLE 246.6 (INTERNAL PROCEDURES AND PROTECTION FOR MAKING REPORTS). Issuers, stock exchanges, companies managing crowdfunding platforms, securities intermediaries, investment advisors, portfolio managers, specialized investors, virtual asset service providers, and investment fund management companies must establish procedures to guarantee the making of reports on the use of insider information and market manipulation in a confidential manner and independent of the hierarchical chain, and provide adequate protection to employees who make reports, from any negative consequence, direct or indirect, resulting from their upright conduct.

  1. SUBSTITUTE in Chapter II - CODE OF ETHICS of Title II - MARKET CONDUCT of Book V - TRANSPARENCY AND MARKET CONDUCT of the Compilation of Securities Market Regulations article 249 with the following:

ARTICLE 249 (SCOPE OF APPLICATION). The articles contained in this chapter are applicable to stock exchanges, companies managing crowdfunding platforms, securities intermediaries, investment advisors, portfolio managers, virtual asset service providers, investment fund management companies, financial trustees, securities depositories, and rating agencies.

  1. SUBSTITUTE in Part I - GENERAL PROVISIONS of Book VI - INFORMATION AND DOCUMENTATION of the Compilation of Securities Market Regulations articles 255.1, 255.2, 255.3, 255.4, 255.7, 255.8, 255.9, 255.10, and 256 with the following:

ARTICLE 255.1 (RESPONSIBLE FOR THE INFORMATION REGIME). Stock exchanges, companies managing crowdfunding platforms, securities intermediaries, investment advisors, portfolio managers, virtual asset service providers, investment fund management companies, and securities depositories must appoint a responsible person for the compliance of information requirements, who must ensure the execution of controls that allow an adequate level of quality of the information sent. This official will be included in the category of senior staff referred to in article 143 and must be resident in the country.

RR-SSF-2026-444 Date: 10/07/2026 16:00:25 CIRCULAR N°2507

ARTICLE 255.2 (SAFEGUARDING OF INFORMATION). Stock exchanges, companies managing crowdfunding platforms, securities intermediaries, investment advisors, portfolio managers, virtual asset service providers, investment fund management companies, general and financial trustees, securities depositories, and rating agencies must implement data and software safeguarding procedures, such that it is possible to reconstruct the information emitted to the Central Bank of Uruguay, the accounting records, and each of the movements that give rise to them -to such a degree of detail that it allows the identification of accounts and movements in the items of the financial statements-, as well as any other data, including emails, instant messaging, and any other form of electronic messaging, that is considered relevant in the reconstruction of operations for the purposes of the Central Bank of Uruguay or for judicial requirements. Likewise, they must safeguard the keys that allow the decryption of the data. The storage formats will be established - in each case - by the Superintendence of Financial Services. The aforementioned procedures must include, as a minimum, a daily backup and must provide for the generation of at least 2 (two) backup copies, one of which must be stored at a reasonable distance from the processing center, in a building different from the same. The data, the keys, and their mentioned copies must not be exposed to the possibility that a single risk event is capable of affecting them simultaneously. Incremental backup is admitted, that is, a backup that contemplates only the changes since the last backup performed, provided that the recovery procedures allow the complete restoration of the information for any day. Likewise, they must have procedures that allow the recovery of all backed-up information. At least once a year, formal and duly documented tests of recovery and integrity of data backups must be carried out, which must ensure the institution's capacity to recover all backed-up information.

ARTICLE 255.3 (SAFEGUARDING OF DOCUMENTATION). Stock exchanges, companies managing crowdfunding platforms, securities intermediaries, investment advisors, portfolio managers, virtual asset service providers, investment fund management companies, general and financial trustees, securities depositories, and rating agencies must implement procedures for safeguarding all documentation issued supporting their management.

RR-SSF-2026-444 Date: 10/07/2026 16:00:25 CIRCULAR N°2507

ARTICLE 255.4 (INTEGRITY OF RECORDS). The records that, in compliance with current regulations, are kept by stock exchanges, companies managing crowdfunding platforms, securities intermediaries, investment advisors, portfolio managers, investment fund management companies, general and financial trustees, securities depositories, rating agencies, and virtual asset service providers must satisfy the integrity requirement, for which they may be prepared in: a. Any electronic storage medium for documents, which has security measures that ensure confidentiality and availability; b. Paper, through sequentially numbered sheets. In both cases, measures must be adopted that guarantee the physical safeguarding of the records and access only to authorized persons.

ARTICLE 255.7 (RETENTION PERIODS). The original corporate books or the information supports containing their reproduction must be preserved until the fulfillment of the 20 (twenty) year term determined by article 80 of the Commercial Code. This term will be counted from the last entry or from the date on which they were extended or reproduced, as applicable, all without prejudice to the terms required by tax, labor, corporate, or other regulations. The information and documentation referred to in articles 255.2 and 255.3 of issuers of securities, stock exchanges, companies managing crowdfunding platforms, securities intermediaries, investment advisors, portfolio managers, virtual asset service providers, investment fund management companies, general and financial trustees, securities depositories, and rating agencies must be maintained for a period of no less than 10 (ten) years. All this information and documentation must be available in time, form, and conditions to be processed.

ARTICLE 255.8 (OPERATIONAL CONTINUITY PLAN). Stock exchanges, companies managing crowdfunding platforms, securities intermediaries, investment advisors, portfolio managers, virtual asset service providers, investment fund management companies, general and financial trustees, securities depositories, and rating agencies must have a documented plan that ensures the continuity of operations in case of any event that affects facilities, equipment, data, software, or the provision of outsourced services, making normal operations impossible.

RR-SSF-2026-444 Date: 10/07/2026 16:00:25 CIRCULAR N°2507

The aforementioned plan must be permanently updated. Tests - formal and duly documented - of its effectiveness must be carried out, as a minimum, 1 (one) time per year.

ARTICLE 255.9 (CONSERVATION OF DOCUMENTS). Stock exchanges, companies managing crowdfunding platforms, securities intermediaries, investment advisors, portfolio managers, virtual asset service providers, investment fund management companies, general and financial trustees, securities depositories, and rating agencies may, under their exclusive responsibility, opt for the procedures they deem most convenient for the conservation, storage, or archiving of the documentation issued and of the information obtained or prepared in compliance with client due diligence procedures. Notwithstanding the foregoing, the technology to be applied will be valid to the extent that the requirements established in article 255.6 are satisfied. Any original documentation whose reproduction is admitted and that has been carried out according to what is established in this regime, prior to its physical destruction, must be made available to the interested parties through reliable notification for a term of 6 (six) months counted from said notification. Generic notification carried out through publication in the Official Diary and in another newspaper of the largest national circulation is admitted as a reliable means of notification.

ARTICLE 255.10 (REPRODUCTION OF DOCUMENTS). Stock exchanges, companies managing crowdfunding platforms, securities intermediaries, investment advisors, portfolio managers, virtual asset service providers, investment fund management companies, general and financial trustees, securities depositories, and rating agencies may conserve, in substitution of the originals and to the extent that legal provisions do not oppose it, photographs, microfilming, or digitized reproductions of the documents and receipts linked to their operations. The technology to be used will be valid whenever adequate methods of certification of authenticity of the reproduced copies in the information supports used are established and the requirements established in article 255.6 are satisfied. When proceeding to the destruction of files - always that it does not refer to operations or matters that are active or pending - procedures must be employed that prevent the identification of their content. In a book kept especially for these purposes, an act must be drawn up signed by the responsible person for the reproduction and by the head of the department to which the documentation to be reproduced and/or destroyed belongs.

RR-SSF-2026-444 Date: 10/07/2026 16:00:25 CIRCULAR N°2507

ARTICLE 256 (RESOLUTIONS OF THE BOARD OF DIRECTORS OF THE CENTRAL BANK OF URUGUAY OR THE SUPERINTENDENCY OF EMERGING FINANCIAL SERVICES ARISING FROM SUPERVISORY OR AUDIT ACTS).

Issuers of public offering securities, stock exchanges, companies administering crowdfunding platforms, securities intermediaries, investment advisors, portfolio managers, virtual asset service providers, investment fund management companies, general and financial trustees, securities depositories, and risk rating agencies must transcribe in the minutes book of their governing body, within 90 (ninety) days following notification or within the period indicated in the resolution itself, the resolutions adopted by the Board of Directors of the Central Bank of Uruguay or the Superintendency of Financial Services, referring to each institution specifically emerging from acts of supervision or audit of compliance with legal and regulatory norms and specific instructions.

Likewise, they must record in said book the fines liquidated by the institution itself, within 90 (ninety) days following their liquidation. This requirement shall not apply to institutions that do not have the legal obligation to keep social books.

  1. INCORPORATE into Book VI - INFORMATION AND DOCUMENTATION of the Compilation of Norms of the Securities Market Part VI TER - VIRTUAL ASSET SERVICE PROVIDERS.

  2. INCORPORATE into Part VI TER - VIRTUAL ASSET SERVICE PROVIDERS of Book VI - INFORMATION AND DOCUMENTATION of the Compilation of Norms of the Securities Market Title I - INFORMATION REGIME.

  3. INCORPORATE into Title I - INFORMATION REGIME of Part VI TER - VIRTUAL ASSET SERVICE PROVIDERS of Book VI - INFORMATION AND DOCUMENTATION of the Compilation of Norms of the Securities Market Chapter I - GENERAL PROVISIONS, which shall contain the following article:

ARTICLE 310.17 (UPDATE OF PRESENTED INFORMATION).

Any modification that occurs regarding the information presented by virtual asset service providers must be communicated to the Superintendency of Financial Services within 5 (five) business days of occurrence, except in those cases where a specific deadline is assigned.

  1. INCORPORATE into Title I - INFORMATION REGIME of Part VI TER - VIRTUAL ASSET SERVICE PROVIDERS of Book VI - INFORMATION AND DOCUMENTATION of the Compilation of Norms of the Securities Market Chapter II - ACCOUNTING AND FINANCIAL STATEMENTS, which shall contain the following articles:

RR-SSF-2026-444 Date: 10/07/2026 16:00:25 CIRCULAR No. 2507

ARTICLE 310.18 (APPLICABLE REGIME).

Virtual asset service providers must prepare their financial statements applying the appropriate accounting standards in Uruguay.

ARTICLE 310.19 (FISCAL YEAR END DATE).

Virtual asset service providers shall have as the end date of the fiscal year December 31 of each year.

ARTICLE 310.20 (ACCOUNTING AND MANAGEMENT INFORMATION).

Virtual asset service providers must present, within a period of 4 (four) months counted from the end of each fiscal year, the following information:

a. Authenticated copy of the Annual Report prepared by the Board of Directors or governing body of the company on the management of corporate affairs and performance in the last period, according to the minimum content established in Article 92 of Law No. 16.060 of September 4, 1989, duly signed.

b. Original duly signed or authenticated copy of the Auditor's Report or oversight body, if applicable.

c. Annual consolidated financial statements of the group to which the provider belongs, accompanied by External Audit Report, duly signed and with corresponding professional stamps.

In cases where consolidation does not apply, a sworn declaration indicating the reasons why the provider does not prepare Consolidated Financial Statements must be presented.

d. Annual individual financial statements, accompanied by External Audit Report, duly signed and with corresponding professional stamps.

e. Authenticated copy of the Shareholders or Partners Meeting Minutes approving the Financial Statements, duly signed.

f. Sworn declaration indicating the market value of assets under custody and administration at the end of the fiscal year, if applicable.

Audit Reports must be signed by a professional or firm of professionals registered in the Register of Auditors of the Central Bank of Uruguay.

Failure to present the information on time and in due form will result in the application of the daily fine established in Article 358.

The verification of errors in the presented information will also result in the application of said daily fine, from the moment of its notification.

RR-SSF-2026-444 Date: 10/07/2026 16:00:25 CIRCULAR No. 2507

ARTICLE 310.21 (INFORMATION ON CAPITALIZATION OF EQUITY ITEMS).

Virtual asset service providers must inform the Superintendency of Financial Services about the capitalization of equity items arising both from the application of legal norms and from resolutions of the Shareholders or Partners Assembly, within 5 (five) business days following its occurrence, supplying the following documentation:

a. Authenticated copy of the resolution adopted by the Shareholders or Partners Assembly.

b. Funded certification by a public accountant of the corresponding accounting registration.

c. The necessary information for the update of the Register of partners or shareholders referred to in Article 310.30.

ARTICLE 310.22 (INFORMATION ON NON-CAPITALIZED CONTRIBUTIONS).

Virtual asset service providers must inform the Superintendency of Financial Services, within a period of 5 (five) business days following each imputation of the "Contributions to Capitalize" account, the amount of resources irrevocably affected for the purpose of capitalization and the date on which such resources became available to them, accompanying notarized testimony of the Assembly minutes from which the decision to increase capital arises.

ARTICLE 310.23 (INFORMATION ON MINIMUM EQUITY).

Virtual asset service providers providing the services referred to in letter d. of Article 127.22 must prepare monthly information on the amount and composition of their minimum equity, according to the instructions to be issued.

Such information will be presented to the Superintendency of Financial Services annually, together with the financial statements referred to in Article 310.20.

ARTICLE 310.24 (EQUITY RECOMPOSITION OR ADJUSTMENT PLAN).

Virtual asset service providers providing the services referred to in letter d. of Article 127.22 and presenting situations of insufficient minimum equity must inform the causes that provoke them and present a plan that allows regularizing them within a reasonably brief period.

This information must be presented to the Superintendency of Financial Services within 10 (ten) business days following the end of the month in which the insufficiency was recorded.

Virtual asset service providers providing the services referred to in letter d. of Article 127.22 and presenting situations of insufficient minimum equity must inform the causes that the

RR-SSF-2026-444 Date: 10/07/2026 16:00:25 CIRCULAR No. 2507

provoke them and present a plan that allows regularizing them within a reasonably brief period.

This information must be presented to the Superintendency of Financial Services within 10 (ten) business days following the end of the month in which the insufficiency was recorded.

  1. INCORPORATE into Title I - INFORMATION REGIME of Part VI TER - VIRTUAL ASSET SERVICE PROVIDERS of Book VI - INFORMATION AND DOCUMENTATION of the Compilation of Norms of the Securities Market Chapter III - EXTERNAL AUDITORS, which shall contain the following articles:

ARTICLE 310.25 (EXTERNAL AUDITOR REPORTS).

Virtual asset service providers must present to the Superintendency of Financial Services, following the format established by it, an annual report issued by external auditors that evaluates the policies and procedures referred to in Article 186.

An opinion must be issued regarding the suitability and functioning of the policies and procedures adopted by the institution to prevent being used for money laundering, terrorist financing, and financing of proliferation of weapons of mass destruction, indicating materially significant deficiencies or omissions, recommendations issued to overcome them, and corrective measures adopted.

The report referred to in this article must be presented within the first 4 (four) months following the end of the fiscal year to which it refers.

ARTICLE 310.26 (ANNUAL REPORT OF INFORMATION SYSTEMS).

Virtual asset service providers must present to the Superintendency of Financial Services the report corresponding to the annual audit of information systems referred to in Article 127.47, within the first 4 (four) months following the end of the fiscal year.

  1. INCORPORATE into Title I - INFORMATION REGIME of Part VI TER - VIRTUAL ASSET SERVICE PROVIDERS of Book VI - INFORMATION AND DOCUMENTATION of the Compilation of Norms of the Securities Market Chapter IV - SENIOR PERSONNEL AND SHAREHOLDERS, which shall contain the following articles:

ARTICLE 310.27 (INFORMATION ON SENIOR PERSONNEL).

Virtual asset service providers must provide to the Superintendency of Financial Services, according to the instructions to be issued, the following information on persons included in the category of senior personnel:

a. Position to be held.

b. Identifying data of the person.

RR-SSF-2026-444 Date: 10/07/2026 16:00:25 CIRCULAR No. 2507

ARTICLE 310.28 (COMPLEMENTARY INFORMATION ON SENIOR PERSONNEL).

Virtual asset service providers must request from persons who make up the category of senior personnel, information that allows them to evaluate their moral, professional, and technical suitability. Such information, at a minimum, must include that established in Article 127.29.

This information, together with the evaluation of the records contained therein, must be available to the Superintendency of Financial Services, according to instructions to be issued, and kept in the manner provided in Articles 255.2 and 255.3, during the period established in Article 255.7. With respect to the information provided in letter d. of Article 127.29, the certificate of request for judicial background check must be kept available.

Whenever modifications occur to the facts recorded in the sworn declarations required by letter c. of Article 127.29, the persons referred to must formulate a new declaration. Likewise, the evaluation of the aforementioned records must be updated.

ARTICLE 310.29 (MODIFICATIONS TO THE LIST OF SENIOR PERSONNEL).

The incorporations, dismissals, or modifications of senior personnel of virtual asset service providers must be informed to the Superintendency of Financial Services within a maximum period of 5 (five) business days of occurrence, and in the case of appointments, be accompanied by the information requested by Article 310.27.

ARTICLE 310.30 (REGISTER OF PARTNERS OR SHAREHOLDERS).

The Central Bank of Uruguay will keep the register of partners or shareholders of virtual asset service providers, which shall have a public character.

With respect to direct partners or shareholders, what is provided in Articles 127.37 and 310.21 shall apply.

Regarding indirect shareholders, changes must be informed to the Superintendency of Financial Services, within 10 (ten) business days following their occurrence, accompanied by:

  1. In the case of changes in the shareholder chain: the sworn declaration required by letter e. of numeral II. of Article 127.28.

  2. In the case of change of the subject exercising control: the information required in Article 127.28.

The Superintendency of Financial Services may request additional information to that indicated above.

RR-SSF-2026-444 Date: 10/07/2026 16:00:25 CIRCULAR No. 2507

ARTICLE 310.31 (PATRIMONIAL INFORMATION AND SIGNIFICANT FACTS REGARDING PARTNERS OR SHAREHOLDERS).

Virtual asset service providers must obtain annually the following information from their direct partners or shareholders who hold a participation equal to or greater than 15% (fifteen percent) of the capital and from the subject exercising effective control:

  1. Natural persons: sworn declaration on their patrimonial situation with indication of assets, rights, and banking and non-banking debts, and the existence of encumbrances affecting them. The date of the sworn declaration cannot be older than 3 (three) months.

Such declaration must be accompanied by notarized certification of the signature of the holder.

  1. Legal entities: financial statements corresponding to the last closed fiscal year with external auditor's opinion, provided they do not belong to the public sector, nor are they institutions supervised by the Central Bank of Uruguay.

The aforementioned information must:

  • be obtained within a period of 5 (five) months counted from December 31 of each year and refer to the last closed financial statement during the previous calendar year.

  • be kept safeguarded at the domicile of the virtual asset service provider available to the Superintendency of Financial Services.

A declaration must be presented before said Superintendency indicating that the required information has been obtained from all persons included and that it is available to the Superintendency of Financial Services or that its shareholders are from the public sector or are institutions supervised by the Central Bank of Uruguay.

Such declaration must be presented within a period of 5 (five) months counted from December 31 of each year.

Additionally, they must inform the Superintendency of Financial Services, within a period of 2 (two) business days following occurrence or knowledge thereof, any significant change that could negatively affect the patrimonial situation or suitability:

i. of the direct partner or shareholder who holds a participation equal to or greater than 15% (fifteen percent) of the capital; or

ii. of the subject exercising effective control, provided they do not belong to the public sector nor are institutions supervised by the Central Bank of Uruguay.

RR-SSF-2026-444 Date: 10/07/2026 16:00:25 CIRCULAR No. 2507

  1. INCORPORATE into Title I - INFORMATION REGIME of Part VI TER - VIRTUAL ASSET SERVICE PROVIDERS of Book VI - INFORMATION AND DOCUMENTATION of the Compilation of Norms of the Securities Market Chapter V - PREVENTION OF MONEY LAUNDERING, TERRORIST FINANCING, AND FINANCING OF PROLIFERATION OF WEAPONS OF MASS DESTRUCTION, which shall contain the following articles:

ARTICLE 310.32 (DESIGNATION OF COMPLIANCE OFFICER).

Virtual asset service providers must inform the Superintendency of Financial Services of the name of the official to whom functions corresponding to the Compliance Officer have been assigned within 5 (five) business days following their designation.

Modifications to such designation must also be informed within the same period counted from the date of occurrence.

ARTICLE 310.33 (SWORN DECLARATION OF LEGITIMATE ORIGIN OF CAPITAL).

Whenever shares are transferred or funds contributions are made to equity, virtual asset service providers must inform the Superintendency of Financial Services within 5 (five) business days following their occurrence.

For these purposes, a sworn declaration with notarized certification of the holder's signature must be presented in which the legitimate origin of the contributed funds is justified, the amount of the contribution is indicated, the source of the funds is stated, and supporting documentation is attached.

If deemed necessary, the Superintendency of Financial Services may request additional information for such justification.

ARTICLE 310.34 (INFORMATION ON TRANSACTIONS AND SERVICES).

Virtual asset service providers must provide annual information on transactions and services, grouped according to risk factors for money laundering, terrorist financing, and financing of proliferation of weapons of mass destruction.

The aforementioned information will be presented to the Financial Information and Analysis Unit, according to the instructions to be issued, within 30 (thirty) days following the end of the fiscal year to which it refers.

ARTICLE 310.35 (REPORTING OF CLIENT ACCOUNTS).

Virtual asset service providers providing the services referred to in letter d. of Article 127.22 must inform the Superintendency of Financial Services of the opening and closing of custody accounts or others linked to clients, including data of holders, attorneys-in-fact, and authorized persons to operate on behalf of the client before the institution.

RR-SSF-2026-444 Date: 10/07/2026 16:00:25 CIRCULAR No. 2507

The information will be provided within 5 (five) business days following the date on which the account is opened or closed or the modification of persons linked to the account occurs, according to the instructions to be issued.

  1. INCORPORATE into Title I - INFORMATION REGIME of Part VI TER - VIRTUAL ASSET SERVICE PROVIDERS of Book VI - INFORMATION AND DOCUMENTATION of the Compilation of Norms of the Securities Market Chapter VI - RELEVANT EVENTS, which shall contain the following article:

ARTICLE 310.36 (INFORMATION ON RELEVANT EVENTS).

Virtual asset service providers must inform the Superintendency of Financial Services of any relevant event or special situation that could affect the development of their activity or the situation of funds and virtual assets administered, both own and those of clients, immediately upon occurrence or when it comes to their knowledge, without exceeding the next business day.

The general provisions on relevant events contained in this Compilation shall apply, as appropriate.

  1. INCORPORATE into Title I - INFORMATION REGIME of Part VI TER - VIRTUAL ASSET SERVICE PROVIDERS of Book VI - INFORMATION AND DOCUMENTATION of the Compilation of Norms of the Securities Market Chapter VII - INSIDER INFORMATION, which shall contain the following articles:

ARTICLE 310.37 (INFORMATION ON MISUSE OF INSIDER INFORMATION).

Virtual asset service providers must inform the Superintendency of Financial Services immediately upon occurrence or when it comes to their knowledge, without exceeding the next business day, facts that constitute reasonable grounds to suspect that misuse of insider information has occurred.

ARTICLE 310.38 (INFORMATION ON MARKET MANIPULATION).

Virtual asset service providers must inform the Superintendency of Financial Services immediately upon occurrence or when it comes to their knowledge, without exceeding the next business day, facts that constitute reasonable grounds to suspect that market manipulation has occurred.

  1. INCORPORATE into Title I - INFORMATION REGIME of Part VI TER - VIRTUAL ASSET SERVICE PROVIDERS of Book VI - INFORMATION AND DOCUMENTATION of the Compilation of Norms of the Securities Market Chapter VIII - OTHER INFORMATIONS, which shall contain the following articles:

RR-SSF-2026-444 Date: 10/07/2026 16:00:25 CIRCULAR No. 2507

ARTICLE 310.39 (INFORMATION ON THE PERSON RESPONSIBLE FOR HANDLING CLAIMS). Virtual Asset Service Providers shall inform the Superintendence of Financial Services of the name of the official assigned the responsibilities corresponding to the handling of customer claims referred to in Article 208.8, within 5 (five) business days following their appointment. Likewise, the position held, their position in the institution's organizational chart, if applicable, and contact details shall be reported. Modifications to such appointment shall also be reported within the same timeframe, counted from the date the change occurred.

ARTICLE 310.40 (INFORMATION ON DAYS AND HOURS OF PUBLIC SERVICE). Virtual Asset Service Providers shall inform the Superintendence of Financial Services of the days, hours, and channels for public service. They shall also report modifications with a 3 (three) business day advance notice.

ARTICLE 310.41 (INFORMATION ON OUTSOURCING OF SERVICES). Virtual Asset Service Providers shall provide the Superintendence of Financial Services, in accordance with instructions to be issued, information on outsourced services contracted. Such information shall be submitted within 10 (ten) business days of the contract being signed.

ARTICLE 310.42 (INFORMATION ON OPERATIONAL RISK INDICATORS). Virtual Asset Service Providers shall provide information on their operational risk indicators semi-annually, according to instructions to be issued. Such information shall be submitted to the Superintendence of Financial Services within the first 15 (fifteen) business days following the reported period.

  1. INCORPORATE in Part VI TER - VIRTUAL ASSET SERVICE PROVIDERS of Book VI - INFORMATION AND DOCUMENTATION of the Compilation of Securities Market Regulations Title II - RECORDS, which shall include the following article:

ARTICLE 310.43 (RECORDS). Virtual Asset Service Providers shall keep the following Records, in accordance with the specifications to be established by the Superintendence of Financial Services: a. Customer Register b. Register of orders received from customers c. Operations Register d. Operational Risk Events Register

Virtual Asset Service Providers that provide the services referred to in letter d. of Article 127.22 shall, in addition, keep a Register of open positions per customer.

  1. SUBSTITUTE in Title I - GENERAL REGIME of Book VII - SANCTIONING AND PROCEDURAL REGIME of the Compilation of Securities Market Regulations Article 351 with the following:

ARTICLE 351 (REGIME). Entities controlled by the Central Bank of Uruguay that infringe legal or regulatory norms, or the general norms and particular instructions in the matter issued by the Central Bank of Uruguay, shall be subject to the following sanctions: a. Issuers:

  1. Observation
  2. Warning
  3. Fine
  4. Suspension or cancellation of the listing of securities
  5. Suspension or cancellation of the authorization to make a public offering b. Financial Intermediation Institutions:
  6. Observation
  7. Warning
  8. Fine
  9. Suspension or cancellation of their activities related to the Securities Market c. Stock Exchanges, Stockbrokers, Securities Agents, Investment Fund Management Companies, Custody Companies, Securities Clearing and Settlement Companies, Collective Financing Platform Management Companies, and Virtual Asset Service Providers:
  10. Observation
  11. Warning
  12. Fine
  13. Suspension or cancellation of activities d. Investment Advisors, Portfolio Managers, and General Trustees:
  14. Observation
  15. Warning
  16. Fine
  17. Suspension or cancellation of activities related to the securities market e. Risk Rating Agencies:
  18. Observation
  19. Warning
  20. Fine
  21. Suspension or cancellation of their registration in the Securities Market Register f. State-Owned Companies: Institutions included in Article 25 of Law No. 17.555 of September 18, 2002, shall be subject to the following sanctions:
  22. Observation
  23. Warning

Without prejudice to the foregoing, non-compliance incidents shall be communicated to the Executive Power. The determination of the fines established in this Book does not preclude the exercise of the powers of the Central Bank of Uruguay to opt, with due justification, to apply this sanction or any other established in this article, as well as to reduce or increase its amount, if the gravity of the situation so requires. In such a case, the circumstances that motivated the non-compliance, the nature of the infringement committed, and generally, the factual and legal considerations applicable in each case shall be valued.

  1. SUBSTITUTE in Title II – SANCTIONS APPLICABLE TO ALL INSTITUTIONS of Book VII - SANCTIONING AND PROCEDURAL REGIME of the Compilation of Securities Market Regulations Articles 373, 374, and 374.1 with the following:

ARTICLE 373 (NON-COMPLIANCE WITH THE SYSTEM ESTABLISHED TO PREVENT MONEY LAUNDERING, TERRORISM FINANCING, AND FINANCING OF THE PROLIFERATION OF WEAPONS OF MASS DESTRUCTION). Securities intermediaries, investment fund management companies, collective financing platform management companies, and virtual asset service providers that do not comply with the comprehensive system to prevent being used in money laundering, terrorism financing, and financing of the proliferation of weapons of mass destruction, shall be sanctioned with a fine equivalent to 50 (fifty) times that established in Article 357 of this Compilation.

ARTICLE 374 (DETECTION OF MONEY LAUNDERING, TERRORISM FINANCING, AND FINANCING OF THE PROLIFERATION OF WEAPONS OF MASS DESTRUCTION ACTIVITIES). Securities intermediaries, investment fund management companies, collective financing platform management companies, and virtual asset service providers whose non-compliance with the comprehensive system to prevent being used in money laundering, terrorism financing, and financing of the proliferation of weapons of mass destruction has enabled the completion of such activities, shall be sanctioned with a fine equivalent to 150 (one hundred fifty) times that established in Article 357 of this Compilation.

ARTICLE 374.1 (FINE FOR NON-COMPLIANCE WITH OUTSOURCING NORMS). Institutions that fail to comply with norms on outsourcing of services shall be sanctioned with a fine not less than 2 (two) nor more than 130 (one hundred thirty) times that established in Article 357.

  1. INCORPORATE in Book VII - SANCTIONING AND PROCEDURAL REGIME of the Compilation of Securities Market Regulations Title VI BIS - VIRTUAL ASSET SERVICE PROVIDERS – OTHER SANCTIONS, which shall include the following articles:

ARTICLE 383.2 (NON-COMPLIANCE WITH THE RESPONSIBILITIES OF THE VIRTUAL ASSET SERVICE PROVIDER). Virtual Asset Service Providers that fail to comply with the responsibilities corresponding to the provision of services shall be sanctioned with a fine equivalent to 100 (one hundred) times that established in Article 357.

ARTICLE 383.3 (SANCTIONS FOR DELAYS OR OMISSIONS IN THE RESPONSES OF THE CLAIMS HANDLING SERVICE). Infringements to the timeframes established in Article 208.9 shall be sanctioned with the fine provided in Article 358, with a maximum of 30 (thirty) days of daily fine. In the event that the response to the customer does not justify the institution's actions regarding each claimed point, the minimum fine established in Article 357 shall be applied.

ARTICLE 383.4 (SANCTION FOR FAILURE TO RESTORE NET WORTH). Virtual Asset Service Providers that provide the services referred to in letter d. of Article 127.22 and that do not comply with net worth restoration within a maximum period of 90 (ninety) days from when the situation of insufficiency in minimum net worth referred to in Article 151.1.8 arises, may be subject to suspension of activities.

  1. TRANSITIONAL PROVISION: Virtual Asset Service Providers shall have until June 30, 2027, to comply with the provisions contained in this resolution, unless a different timeframe is established in the article itself.

  2. COMMUNICATE the resolution via Circular. JUAN PEDRO CANTERA Superintendent of Financial Services

More like this from BCU

BCU published 1 document in the last 30 days. We email you each new one the day it's published.

Share