Statement of Guidance
AML/ATF Sector-Specific Guidance Notes for the Securities Sector (Annex III) 2021
Status not confirmedView on BMA's website Source document
Summary
This is Annex III of the BMA's 2021 AML/ATF Guidance Notes, providing sector-specific guidance for the securities sector. It supplements (but does not replace) the general Guidance Notes and applies to entities designated as AML/ATF regulated financial institutions (RFIs) under POCA because they carry on investment business, fund administration, or operate investment funds, as well as non-licensed persons (NLPs), independent professionals, and designated financial groups.
- Who it covers: Investment business providers, investment funds and their operators, fund administrators, NLPs (Exempt Investment Business), independent professionals providing legal/accountancy services in relation to client assets, and financial groups designated by the Minister of Legal Affairs.
- Senior management duties: Senior management must ensure compliance with AML/ATF acts and regulations, approve AML/ATF policies and controls, identify and mitigate ML/TF risks, appoint a Compliance Officer and Reporting Officer, screen employees, provide training, and conduct at least annual independent audits/testing of AML/ATF controls.
- Customer due diligence: Guidance addresses CDD timing, identifying customers and beneficial owners, obtaining intermediary information, reliance on intermediaries, outsourcing, simplified and enhanced due diligence, and refusing/terminating business relationships in the securities context.
- Ongoing monitoring and reporting: RFIs must conduct ongoing monitoring, watch for trigger events, screen against international sanctions, and file suspicious activity reports; failure to report or tipping-off are offenses.
- Record-keeping and risk factors: The annex sets out record-keeping expectations and detailed risk indicators specific to securities sector business, including customer, product, delivery channel and intermediary/third-party risk factors.
- Penalties: Non-compliance with specified regulations is a criminal offence (fines up to $50,000 on summary conviction, or up to $750,000 and/or two years' imprisonment on indictment) and the BMA may impose civil penalties of up to $10,000,000 per breach.
As guidance rather than binding law, the notes use 'must' where a legal provision is directly restated and 'should' where BMA describes expected practice; courts and the BMA will consider adherence to this guidance when assessing compliance breaches, and departures should be documented and justifiable.
Key obligations
- Senior management must appoint a Compliance Officer at managerial level to oversee AML/ATF policies, procedures and controls
- Senior management must appoint a Reporting Officer to process disclosures
- RFIs must screen owners, directors, managers and employees against high standards (Regulation 18(1)(c))
- Senior management must, at least once per calendar year, independently audit and test the RFI's AML/ATF policies, procedures and controls for effectiveness
- RFIs must establish and maintain detailed AML/ATF policies, procedures and controls adequate to forestall and prevent ML/TF
- RFIs with branches, subsidiaries, representative offices or group members outside Bermuda must communicate AML/ATF policies to those entities and ensure they apply measures at least equivalent to Bermuda's requirements
- RFIs must conduct customer due diligence, including identifying customers, beneficial owners and intermediaries, in accordance with the sector-specific guidance
- RFIs must conduct ongoing monitoring of securities sector business relationships and respond to trigger events
- RFIs must file suspicious activity reports and avoid tipping-off when required
- NLPs must register under Section 9 of the POCA SEA before carrying on exempt investment business
Applies to
investment business providers, investment funds and operators, fund administrators, non-licensed persons (NLPs) conducting exempt investment business, independent professionals (legal/accountancy), financial groups designated under POCA
Deadlines
- at least once per calendar year: Senior management must independently audit and test the RFI's AML/ATF policies, procedures and controls for effectiveness