The model of BaaS in Brazil has undergone a a structural change with the new regulations for Banking as a Service from the Central Bank.
Joint Resolution No. 16/2025 redefines how companies can operate financial services, making it clear who can carry out, who can distribute and which structures are permitted within the financial regulated system.
For companies that operate or distribute financial products through third-party banking infrastructure, ignoring these changes is not an option. Understanding what is changing, why it is changing, and what needs to be reorganized is the starting point for any operation that wants to remain relevant and compliant with the law.
At the same time, this regulatory change reveals a structural transformation of a broader nature within the financial system.
Before the infrastructure, there is a key aspect: the regulatory framework for the operation.
Technology and infrastructure serve as enablers, ensuring execution, traceability, and governance, but they do not replace the need for compliance and adherence to financial system regulations.
This article, based on concrete data from the new standard and on the stance of Infratech regarding tokenization BLOCKBR, explores in depth what this regulatory shift means in practice.
What is Banking as a Service (BaaS) in Brazil?
Banking as a Service is a model in which a financial institution authorized by the Bankmakes available its regulatory and technological infrastructure so that a16> other companies, financial or non-financial, offer products and services banking to the end customer. In practice, this means that a retailer, an e-commerce platform or a technology company can may offer a digital account, a card, credit or means of payment without having to become a bank.
This model has become firmly established in Brazil over the past decade as one of the main drivers of the digital financial market’s expansion. The logic is simple: companies with a large customer base but without a financial license have begun to access the banking infrastructure of regulated partners to deliver financial products integrated into their own user journey.
The expansion of the model for BaaS also brought a new structural challenge to the market: how to ensure that financial transactions distributed by different companies continue to operate within the standards of security and governance required by the national financial system.
The answer to this challenge necessarily depends on the quality of the infrastructure used to connect these operations to the regulated environment.

The evolution of fintechs and embedded finance
The BaaS model has evolved in Brazil alongside the rise of fintech, open finance, and digital infrastructure. This rapid growth has driven innovation, but it has also exposed regulatory gaps that are now being addressed by the Central Bank.
Why have non-financial companies started offering banking services?
The answer lies in the combination of consumer demand, proprietary data, and revenue opportunities. Companies with large customer bases realized they had something that traditional banks took years to build: relationships and context. By incorporating financial services into their operations, these companies have managed to increase customer lifetime value, reduce friction in the purchasing journey, and create new sources of revenue.
Retailers, digital platforms, and technology companies have come to view BaaS not as an add-on product, but as a strategic component of their business. The problem is that this expansion has, in many cases, taken place without clear definitions of operational and regulatory responsibilities among the parties.
How did BaaS work before regulation?
The decision by the Central Bank to framework the regulation of Banking as a Service is not is a reaction in response to a specific situation, but a structural move by the Central Bank to raise the standard of security, governance and traceability of financial digital transactions.
The rapid growth of digital financial platforms
In recent years, the number of payment institutions authorized by the Central Bank has grown significantly, accompanied by the proliferation of BaaS models that did not always operate with the same clarity regarding roles and responsibilities. At the same time, the volume of transactions conducted outside the traditional banking system has increased significantly, expanding the scope of exposure to operational and regulatory risks.
While this growth was positive for competition and financial inclusion, it also gave rise to a variety of contractual arrangements and operational structures that made it difficult for the regulator to exercise effective oversight. The Central Bank came to the conclusion that, with competition sufficiently established, it was time to raise standards of security and transparency.
Operational risks and regulatory gaps identified in the market
In addition to the sector’s organic growth, specific incidents have accelerated the need for regulation. Security breaches on digital platforms, liquidity issues at smaller institutions, accounting irregularities, and the misuse of financial structures for unauthorized purposes have drawn the regulator’s attention.
Among the practices identified as problematic were the use of pooled accounts by unregulated firms to hold client funds, a lack of clarity regarding which institution was the regulatory authority for the operation, and the creation of BaaS chains in which a service provider outsourced financial services to a third party—the so-called “BaaS of BaaS.”
This shows how regulatory tolerance is in the financial market, these practices signal exactly the limits that the Central Bank decided to address in an explicit manner.
What changes with Central Bank Resolution No. 16/2025?
Joint Resolution No. 16/2025 is the primary regulatory instrument governing the provision of services under the BaaS model in Brazil. Published in November 2025, it consolidates the Central Bank’s previously stated positions and establishes objective parameters regarding how this model should operate, who may assume each role, and which practices are expressly prohibited.
The regulation of Banking as a Service is linked to other relevant regulatory instruments, such as the authorization rules for Payment Institutions and Joint Resolution No. 14/2025, which revised the calculation method for the minimum capital required for the establishment and operation of financial institutions and other entities authorized by the Central Bank. Together, these rules form a new framework for the embedded finance market in Brazil.

The definition of the roles of the provider and customer of BaaS
One of the most significant advances of Joint Resolution No. 16/2025 is the clear definition of two distinct roles within the BaaS chain: the provider and the user.
The provider of BaaS is always a financial institution or a payment institution duly authorized by the Central Bank. It is the institution that holds the regulatory license, is responsible for compliance with the operation and provides its infrastructure so that third parties can distribute financial products to the end customer.
The customer of BaaS is the company, financial or non-financial company, which uses this infrastructure to offer financial services integrated into its own business. The borrower acts as a distributor, but not as a financial institution. This distinction is central to understanding the limits of what each party can and cannot do within this model.
Responsibilities institutional within the new regulation
The regulation makes clear that regulatory responsibility for the financial operation lies with the provider, the authorized institution. This means that, even though the end customer interacts primarily with the borrower’s interface, it is the institution provider that is responsible for compliance of the rules of the financial system, for the integrity of data and for the protection of customers’ assets.
This definition has important practical implications. The borrower cannot charge financial fees directly from clients as if it were a financial institution. It cannot hold in custody funds from clients in structures that are not authorized. And may not may not transfer the services that receives from the provider to a third party, creating a chain that is not supervised of financial distribution.
Governance, transparency, and operational control
In addition to defining roles, Joint Resolution No. 16/2025 imposes governance, due diligence, and operational control requirements on BaaS providers. The authorized institution must maintain clear policies for selecting and monitoring the borrowers with whom it operates, ensure that the distributed services comply with applicable regulations, and ensure that the end customer has transparency regarding which regulated institution is responsible for the transaction.
The regulation also requires formal contracts between service providers and clients that clearly establish each party’s responsibilities, operational limits, and control and reporting mechanisms. Informal structures or operational agreements without proper documentation will no longer be tolerated under this new framework.
Who can provide financial services using the BaaS model?
For those who were already operating in accordance with the best practices expected by the regulator, Joint Resolution No. 16/2025 represents more of a formalization than a major change. Well-structured models, with regulated partners, proper segregation of funds, and transparency for the end customer are likely to be minimally affected. The greatest impact falls on operations that relied on regulatory gray areas or creative interpretations of previous rules.
Which practices are now prohibited?
Companies acting as BaaS buyers will need to review their contracts with providers to ensure that roles are clearly defined and documented.
Structures in which the borrower performed functions that, in practice, were similar to those of a financial institution will need to be reorganized. This includes reviewing the custody of funds, eliminating financial fees charged by the borrower, and updating communications with end customers to make it clear which regulated institution is responsible for the transaction.
It is worth noting that the regulation establishes a transition period: existing BaaS contracts may be brought into compliance with the new rules by December 31, 2026. While this deadline exists, it should not be interpreted as an invitation to procrastinate. The sooner the structures are reviewed, the lower the risk of operational disruption or regulatory exposure during the transition period.
In addition, service providers will need to strengthen their due diligence processes regarding the borrowers with whom they do business, implementing continuous monitoring mechanisms and documented controls that demonstrate to the regulator that the BaaS chain is being effectively supervised.
Technological infrastructure as the foundation of the new financial architecture
The new regulations for Banking as a Service make it clear that operating under the model of BaaS within the requirements of the Central Bank is not merely a legal issue. It is, fundamentally, an issue of infrastructure.
The governance, traceability, due diligence, and transparency requirements set forth in Joint Resolution No. 16/2025 can only be met in a systematic and scalable manner if there is a robust technological foundation to support these operations.
Market infrastructure, in the context of digital assets and financial services distributed, goes far beyond mere technological systems in isolation.
It involves the integration of technology, legal governance, compliance mechanisms, connections with regulated institutions, and operational processes capable of ensuring traceability and control over every stage of the financial transaction.
This infrastructure is responsible for connecting different layers of the financial market, ranging from institutions authorized by the Central Bank to technology platforms a16> that distribute financial services to the end customer. Without this structured foundation, operations of BaaS tend to face operational limitations, regulatory risks, and scalability challenges.

Why are governance and technology starting to go hand in hand?
Corporate governance in the context of regulated BaaS is no longer merely a documentary requirement. It must be operationalized within the systems that manage financial operations. This means that access controls, audit trails, segregation of duties, and transaction traceability must be built into the operation’s technological architecture, rather than simply documented in internal policies.
Companies that operate with legacy systems or with fragmented technological architectures will have difficulty in demonstrating to the regulator that the controls required are effectively implemented. Regulatory pressure, therefore, also acts as a catalyst for the technological modernization of the sector.
The importance of traceability and operational transparency
Operational traceability is one of the pillars that the new standard requires in a more consistent manner. Every transaction, every movement of resources and every interaction within the chain of BaaS must be loggable, auditable, and attributable to the party responsible. Without this capability, the provider cannot fulfill its obligations regarding supervision its obligations regarding supervision over the borrowers, and the regulator is unable to exercise its role of oversight in an efficient manner.
Solutions such as BLOCKBR Management function as a layer of operational organization, enabling control, traceability and governance compatible with the requirements of the financial system.
The role of tokenization in the evolution of digital financial infrastructures
Tokenization does not replace the structuring of a financial transaction.
Elements such as compliance, governance, and legal structure remain mandatory, while technology merely digitizes and optimizes the implementation of these structures.
How should operations be structured under the new regulation?
The new regulations for Banking as a Service mark a turning point in maturity for the market financial digital Brazilian.
More than just limiting business models, it establishes clear parameters so that innovation and security go hand in hand within the financial system.
The infrastructure used to organize financial operations becomes a key a key determining factor for its operational viability, its governance, and its capacity to scale within capacity to scale within the regulated environment.
Companies that understand this shift tend to build operations that are more resilient and sustainable in the long term.
If your company is evaluating how to operate financial services within the new regulatory environment, the first step is not technology, it is structure.
Talk to the experts at BLOCKBR and learn how to make your operation viable with infrastructure that meets governance and regulatory compliance.















