Myanmar Passes Crypto Scam Bill: Life Sentences and What It Means for Compliance Teams
Myanmar's combined parliament, the Pyidaungsu Hluttaw, has passed an anti-online scam bill that would impose prison sentences ranging from ten years to life for those convicted of running crypto scams or operating online scam centres. For accounting firms, auditors, and CFOs with any exposure to Southeast Asian digital asset flows, this legislation signals a sharp escalation in the country's enforcement posture and raises a fresh set of AML, counterparty risk, and crypto accounting software considerations that cannot be ignored.
What the Legislation Actually Says
The bill was passed by the Pyidaungsu Hluttaw on Tuesday after resolving differences between the versions previously approved by Myanmar's two chambers. The state-run Global New Light of Myanmar reported the passage, though at the time of publication neither presidential assent nor an effective date had been confirmed. The final amended text was not immediately available, meaning some precise wording of the crypto-related provisions could not be independently verified.
Core Penalty Structure
Based on the draft provisions reported before passage, the penalty framework operates on two tiers:
- Crypto scams and operating scam centres: prison terms of ten years to life imprisonment.
- Violence, torture, unlawful arrest or detention used to coerce people into participating in online scams: sentences of ten years to life, or capital punishment where the conduct results in death.
Lower House MP Aye Chan, cited in a Straits Times report referencing Agence France-Presse, confirmed that the final version retained the death-penalty provision and that there were no significant changes to the draft's core clauses.
What Remains Unconfirmed
Two material details are still outstanding. First, the bill had not yet received presidential assent as of the reporting date, so it is not yet in force. Second, the exact statutory definition of "crypto scam" in the final text has not been published, which means the precise perimeter of criminal liability for activities touching digital assets remains to be confirmed. Compliance teams should treat the penalty ranges cited here as reflecting the draft; they should monitor official Myanmar government publications for the enacted text.
Why Myanmar Matters for Regional Crypto Compliance
Myanmar has spent several years at the centre of international reporting on industrial-scale cyber fraud. Parts of the country, particularly areas outside central government control, became known as operational hubs for large scam compounds that recruited or trafficked workers and targeted victims globally. The crypto element is significant: many of these operations used digital assets to receive proceeds, move funds across borders, and obscure the trail available to investigators.
The FATF Dimension
The Financial Action Task Force has consistently flagged gaps in VASP oversight across Southeast Asia. Myanmar has historically had limited formal AML infrastructure for virtual assets. Legislation that criminalises crypto scam activity at the statutory level is, in principle, a precondition for effective prosecution and international cooperation on asset recovery. However, the gap between legislation and enforcement capacity is a separate question, and one that FATF's own reporting has identified as the central challenge across the region. Our earlier analysis of how the FATF enforcement gap affects VASP oversight across the region sets out why legislative adoption alone rarely translates immediately into improved compliance outcomes.
ASEAN-Wide Regulatory Momentum
Myanmar's bill does not exist in isolation. Across ASEAN, regulators have been moving to formalise crypto oversight, extend licensing requirements, and tighten AML obligations on exchanges and intermediaries. The broader question of ASEAN crypto licence passporting and what it means for compliance teams is directly relevant here: as national frameworks become more codified, the pressure on regional counterparties to demonstrate clean compliance histories will intensify. A jurisdiction that criminalises scam activity with life sentences is also, implicitly, one that will eventually generate enforcement referrals to partner regulators.
AML and Counterparty Risk Implications
For accounting firms advising clients with digital asset exposure, and for CFOs running treasury or payment operations that touch Southeast Asian counterparties, this development has several practical angles worth working through.
Counterparty and Transaction Screening
The passage of the bill does not automatically change the sanctions or FATF grey-list status of Myanmar, but it does reinforce the case for treating any transaction flow that touches Myanmar-linked addresses or entities with heightened scrutiny. Firms that rely on crypto bookkeeping software or digital asset accounting software to categorise inflows and outflows need to ensure that their on-chain screening layer is capturing Myanmar-associated counterparties accurately. The legislative development is a trigger for revisiting risk appetite statements and counterparty due diligence procedures, particularly for exchanges or OTC desks with regional operations.
Proceeds of Crime and Asset Recovery Risk
A key risk for firms that unknowingly process funds linked to Myanmar scam operations is proceeds-of-crime exposure. If the new law is eventually enforced and generates prosecutions, international asset recovery requests could follow. Accounting firms conducting audits of clients with high-volume crypto transaction flows should document their screening methodology with sufficient granularity to demonstrate that reasonable steps were taken to identify and reject tainted funds. This is not a Myanmar-specific requirement; it is a standard AML obligation that this development makes more urgent to act on.
Client Advisory Obligations
Firms advising clients who operate in or near Myanmar, whether in payments, remittances, or digital asset exchange services, should proactively revisit the AML risk assessment for those clients. The combination of a new criminal statute with severe penalties and an unresolved enforcement infrastructure creates an asymmetric risk environment: the legal framework is hardening faster than the on-the-ground capacity to implement it cleanly. That gap can generate compliance failures for counterparties who assume that legislative inaction is the same as regulatory tolerance.
Accounting and Reporting Considerations
From a financial reporting perspective, the bill raises a narrower but still relevant question for CFOs preparing accounts under IFRS or local standards where digital assets are held on the balance sheet or where clients include crypto-facing businesses in the region.
Contingent Liability and Disclosure
Where a firm or its clients have material transaction exposure to counterparties that could plausibly fall within the scope of Myanmar's new criminal provisions, finance teams should assess whether a contingent liability disclosure is warranted under IAS 37 or equivalent. The threshold is low: if there is a possible obligation whose existence will be confirmed only by future events, and those events are not wholly within the entity's control, disclosure is typically required even if the probability of crystallisation is assessed as less than fifty percent.
Going Concern and Operational Risk Flags
For crypto-facing businesses that derive a meaningful share of transaction volume from Southeast Asian markets where scam-adjacent activity is elevated, auditors should consider whether the tightening regulatory environment, including the Myanmar legislation, represents a material operational risk that warrants a going concern assessment or at least a risk factor discussion in management commentary.
Crypto Accounting Software and Audit Trails
One practical consequence of enforcement-focused legislation like this is that regulators and prosecutors will increasingly demand transaction-level audit trails when investigating whether a business knowingly or negligently processed scam proceeds. Firms using crypto accounting software that provides wallet-level attribution, transaction categorisation, and chain-of-custody documentation are better positioned to respond to such requests. Teams that rely on spreadsheet-based ledgers or incomplete exchange exports will struggle to reconstruct the evidence trail that a regulator, liquidator, or prosecutor would require.
What Compliance Teams Should Do Now
Given that the bill has not yet received presidential assent and the final statutory text has not been published, the immediate priority is monitoring rather than reactive restructuring. However, several preparatory steps are worth taking now.
Near-Term Actions
- Track the enacted text: watch for the official published version of the law, which may contain definitional changes from the draft, particularly around what constitutes a "crypto scam" for statutory purposes.
- Review counterparty screening lists: assess whether your on-chain and off-chain screening covers Myanmar-linked entities with sufficient granularity, including OTC desks, exchanges, and payment processors operating in the border regions.
- Update risk assessments: for clients with Southeast Asian digital asset exposure, refresh the AML risk assessment to reflect the legislative development and document the rationale for any risk rating changes.
- Engage legal counsel on proceeds-of-crime exposure: if any transaction flows involve counterparties that could plausibly be associated with scam centre activity, obtain written legal advice on the exposure before the law comes into force.
- Audit trail readiness: confirm that your crypto accounting software or digital asset accounting software generates the transaction-level documentation that would support a regulatory inquiry or audit.
Frequently Asked Questions
Is the Myanmar anti-scam bill now in force?
Not yet as of the reporting date. The Pyidaungsu Hluttaw passed the bill, but presidential assent had not been confirmed and no effective date had been announced. Compliance teams should monitor the Global New Light of Myanmar and official government publications for confirmation.
Does this law affect firms based outside Myanmar?
Directly, no. The criminal penalties apply to conduct within Myanmar's jurisdiction. Indirectly, yes: firms that process transactions linked to Myanmar-based scam operations face AML and proceeds-of-crime exposure under their own jurisdiction's laws, regardless of where the underlying crime occurred.
What is the definition of a crypto scam under the new law?
The final enacted text was not publicly available at the time of publication, so the precise statutory definition has not been independently confirmed. The draft provisions targeted crypto scams and the operation of online scam centres. Firms should await the published law before drawing definitive conclusions about scope.
How should auditors treat contingent liabilities linked to Myanmar transaction exposure?
Under IAS 37, where there is a possible obligation whose existence depends on future events not wholly within the entity's control, disclosure is generally required. Auditors should assess whether any material transaction flows with Myanmar-linked counterparties meet this threshold and document their reasoning accordingly.
Does Myanmar's bill change its FATF status?
Legislative adoption is one factor FATF considers, but it is not sufficient on its own. FATF also assesses the effectiveness of implementation and enforcement. The bill's passage may be noted positively in future FATF evaluations, but it does not automatically alter Myanmar's current standing. Firms should continue to apply the risk classification that reflects Myanmar's existing FATF status until an official update is issued.
Source: Cointelegraph
